Pending Virus or worm has disabled internet, hidden program and other files

Discussion in 'Virus, Spyware and Malware Removal' started by pigskinzen, Aug 10, 2012.


  1. pigskinzen Bronze Member

    Bronze
    Message Count:
    30
    Likes Received:
    0
    My System
    Loading...
    Sunday afternoon I received a notification of a "serious error" or something to that affect. It has disabled my Internet Explorer and Firefox from connecting to the internet. It has also hidden Control Panel, all programs and virtually everything from my desktop.

    I have run Malwarebytes and Super AntiSpyware and it located a worm and trojan virus, removed them but upon reboot the problem comes back. I read through other solutions that have you find and delete "autorun.ini" and "scvhost.exe" files from windows/system32 but those files are not located in that directory.

    I am a novice and would really appreciate any assistance from anyone with some patience that can walk me through removing this virus.

    System is Windows XP

    Attached Files:

  2. Pancake Security Team

    PCHF Staff
    Message Count:
    13,481
    Likes Received:
    591
    My System
    Loading...
    Can I have the aswMBR log please.as well.




    Please download Malwarebytes Anti-Malware from Malwarebytes.org
    Alternate link: Download Mirror

    (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

    Double Click mbam-setup.exe to install the application.

    (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
    Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    If an update is found, it will download and install the latest version.
    Once the program has loaded, select "Perform Full Scan", then click Scan.
    The scan may take some time to finish,so please be patient.
    When the scan is complete, click OK, then Show Results to view the results.
    Make sure that everything is checked, and click Remove Selected.
    When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
    Please save the log to a location you will remember.
    The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Copy and paste the entire report in your next reply.
    If Malwarebytes fails to download please use the following link:

    http://malwarebytes.org/mbam-download-exe-random.php
  3. Pancake Security Team

    PCHF Staff
    Message Count:
    13,481
    Likes Received:
    591
    My System
    Loading...
    Can I have the aswMBR log please.as well.

    Please post the Malwarebytes Anti-Malware log if you still have it.



    Download Combofix from any of the links below, and save it to your desktop.
    Link 1
    Link 2
    When saving ComboFix rename it to PCHelpForum.exe to prevent it from being blocked by malware.

    Refer to this image:
    To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
    • Close any open windows and double click PCHelpForum.exe to run it.
      You will see the following image:
    [IMG]

    Click I Agree to start the program.
    ComboFix will then extract the necessary files and you will see this:

    [IMG]

    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections
    being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.
    This will not occur in Windows Vista and 7
    It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a
    problem after an attempted removal of malware.
    If you did not have it installed, you will see the prompt below. Choose YES.

    [IMG]

    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree
    to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware
    removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [IMG]

    Click on Yes, to continue scanning for malware.
    When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
    Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do
    so.

    Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
  4. Google Advertisement

  5. pigskinzen Bronze Member

    Bronze
    Message Count:
    30
    Likes Received:
    0
    My System
    Loading...
    "Can I have the aswMBR log please.as well."

    how do i get that?
  6. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,851
    Likes Received:
    3,648
    My System
    Loading...
    It is in the Prework as well
  7. pigskinzen Bronze Member

    Bronze
    Message Count:
    30
    Likes Received:
    0
    My System
    Loading...
    okay, I think that found it

    Attached Files:

  8. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,851
    Likes Received:
    3,648
    My System
    Loading...
  9. pigskinzen Bronze Member

    Bronze
    Message Count:
    30
    Likes Received:
    0
    My System
    Loading...
    okay, I tried to run the aswMBR but there is no reaction on the PC
  10. pigskinzen Bronze Member

    Bronze
    Message Count:
    30
    Likes Received:
    0
    My System
    Loading...
    should I download and run combofix?
  11. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,851
    Likes Received:
    3,648
    My System
    Loading...
  12. pigskinzen Bronze Member

    Bronze
    Message Count:
    30
    Likes Received:
    0
    My System
    Loading...
    I am running combofix and receive an error message that states "detected the following real time scanner(s) antivirus: AVG free edition 2012"

    but that sogftware is not on the PC
  13. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,851
    Likes Received:
    3,648
    My System
    Loading...
    You can proceed past that by clicking ok
  14. pigskinzen Bronze Member

    Bronze
    Message Count:
    30
    Likes Received:
    0
    My System
    Loading...
    thanks, it is running.... create new system restore point
  15. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,851
    Likes Received:
    3,648
    My System
    Loading...
    Ok let it run
  16. pigskinzen Bronze Member

    Bronze
    Message Count:
    30
    Likes Received:
    0
    My System
    Loading...
    combofix suggests to install the Microsoft Windows Recovery Console but since my internet connection has been disabled is scanning without this

Virus or worm has disabled internet, hidden program and other files