Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

FBI Ransom virus [Solved]


  • This topic is locked This topic is locked

#16
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Am I suppose to try to use the computer as normal now?
  • 0

Advertisements


#17
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Yes but sparingly just to see what symptoms it has and then let me know the remaining issues and I will attack those and cleanup :thumbsup:

CompCav
  • 0

#18
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Thank you, I will let you know. What anti-virus protection do you recommend?
  • 0

#19
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
I normally recommend the following:
These are among the best free antivirus/antispyware products.
*Please note* You should never install more than one anti-virus program on a PC because it will cause conflicts.

But we can deal with that after we get a little further along in the process when it will be safer to remove your existing AV and install another one.

Regards,

CompCav
  • 0

#20
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
it seems to being running like it did before the problem
  • 0

#21
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Step 1.

Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application. Please do not accept the trial right now. We just want to run it on demand.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.


Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



Step 2.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan.

Vista / 7 users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

Please go here then click on: Posted Image

If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the following instructions work with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: Posted Image
  • When prompted allow Add-On/Active X to install.
  • Make sure that the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: Posted Image
  • The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close, make sure you copy the logfile first!
  • Now click on: Posted Image
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.


Step 3.

Security Check
Download Security Check by screen317 from here or here.

Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Step 4.

Please post:


mbam log
eset log
security check log


Please give me an update on how your computer is doing!
  • 0

#22
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.09.19.12

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
User :: IAN-PC [administrator]

9/19/2012 4:29:52 PM
mbam-log-2012-09-19 (16-29-52).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 188524
Time elapsed: 3 minute(s), 34 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 1
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\User\Local Settings\Application Data\xry.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
  • 0

#23
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
[email protected] as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=1553e242156f31469ee1643c7b8b22e5
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2012-09-19 10:15:05
# local_time=2012-09-19 05:15:05 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=1024 16777215 100 0 97711137 97711137 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=59613
# found=10
# cleaned=10
# scan_time=1730
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\6.0\17\28e3c751-60bff257 a variant of Win32/Kryptik.PMQ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\6.0\59\76b23bfb-52c26bf9 multiple threats (deleted - quarantined) 00000000000000000000000000000000 C
C:\FRST\Quarantine\JfCqQ5JC.exe a variant of Win32/Injector.WPH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\FRST\Quarantine\ms.exe a variant of Win32/Injector.WPH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\User\Local Settings\Application Data\bb73b.dll.vir a variant of Win32/Kryptik.PMQ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\User\Local Settings\Application Data\xry.exe.vir a variant of Win32/Kryptik.PMQ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{36F0D524-0E35-44FE-A32A-2A7F68D475EE}\RP671\A0048756.dll a variant of Win32/Kryptik.PMQ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{36F0D524-0E35-44FE-A32A-2A7F68D475EE}\RP671\A0048757.exe a variant of Win32/Kryptik.PMQ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{36F0D524-0E35-44FE-A32A-2A7F68D475EE}\RP671\A0048867.exe a variant of Win32/Injector.WPH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{36F0D524-0E35-44FE-A32A-2A7F68D475EE}\RP671\A0048868.exe a variant of Win32/Injector.WPH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
  • 0

#24
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
Results of screen317's Security Check version 0.99.51
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.65.0.1400
CCleaner (remove only)
Java™ 6 Update 14
Java version out of Date!
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 10.1.102.64 Flash Player out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (Toolbar.)
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbam.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 12% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
  • 0

#25
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
computer is running well.
  • 0

Advertisements


#26
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
We have some updates to do to improve your security.

Step 1.

Update adobe flash player

We need to uninstall the existing flash player(s). Please go here
Follow steps 1. to 4.
Once flash player is uninstalled go on to the next paragraph.

You will need to download and install both the IE and non-IE versions of Adobe Flashplayer. (If you do not have installed a non IE browser like Firefox, Chrome, or Opera then you do not need the non-IE version) Make sure to uncheck the install of the McAfee tool before downloading. You will need to select your operating system (Windows XP 32-bit) and then each version to download and install separately.



Step 2.

Update Java

Please download JavaRa to your desktop and unzip it to its own folder

Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.


Step 3.

Update Adobe Reader

Recently there have been vulnerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version.

Uninstall all previous versions.
Download the latest version from: http://www.adobe.com.../readstep2.html

If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.


Step 4.


Please confirm you are still running well or if there are any issues you have noticed since my last post.
  • 0

#27
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
which version of JAVA am I suppose to select?

Windows x86 Online 0.85 MB jre-7u7-windows-i586-iftw.exe
Windows x86 Offline 29.73 MB jre-7u7-windows-i586.exe
Windows x64 31.18 MB jre-7u7-windows-x64.exe
  • 0

#28
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
This one:

Windows x86 Offline 29.73 MB jre-7u7-windows-i586.exe
  • 0

#29
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
thanks. All updates and reinstalls made.
  • 0

#30
gbtx01

gbtx01

    Member

  • Topic Starter
  • Member
  • PipPip
  • 24 posts
still running normal
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP