Still having trouble with FBI virus

24121

New Member
Thread author
Jan 22, 2013
1
 

Attachments

  • OTL.Txt
    67.9 KB · Views: 151
  • Extras.Txt
    53.5 KB · Views: 133
  • aswMBR.txt
    1.7 KB · Views: 92

Fiery

Level 1
Jan 11, 2011
2,007
Hi and welcome to MalwareTips! :)

My name is Fiery and I would gladly assist you in removing the malware on your computer.

Before we start:
  • Note that the removal process is not immediate. Depending on the severity of your infection, it could take a long time.
  • Malware removal can be dangerous. I cannot guarantee the safety of your system as malware can be unpredictable. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system. Therefore, I would advise you to backup all your important files before we start.
  • Please be patient and stay with me until I give you the green lights and inform you that your PC is clean.
  • The absence of symptoms does not mean your PC is fully disinfected.
  • If you are unclear about the instructions, please stop and ask. Following the steps in the order that I post them in is vital.
  • Lastly, if you have requested help on other sites, that will delay and hinder the removal process. Please only stick to one site.

<hr>

Open OTL. Under custom scan/fixes, copy and paste the following:

:OTL
O4 - HKCU..\Run: [pvtkvacxosr] C:\Users\Christy\AppData\Roaming\rrmquile_n_.exe (IncDev Tech.)
[2013/01/22 15:39:02 | 000,166,400 | ---- | C] (IncDev Tech.) -- C:\Users\Christy\AppData\Roaming\rrmquile_n_.exe
[2013/01/21 20:24:40 | 000,166,400 | ---- | C] (IncDev Tech.) -- C:\Users\Christy\AppData\Local\rrmquile_n_.exe
[2013/01/21 20:24:39 | 000,166,400 | ---- | C] (IncDev Tech.) -- C:\ProgramData\rrmquile_n_.exe
[2013/01/22 16:27:31 | 000,228,596 | ---- | M] () -- C:\ProgramData\1358889969.bdinstall.bin
[2013/01/22 15:35:56 | 000,087,861 | ---- | M] () -- C:\ProgramData\1358886873.bdinstall.bin
[2011/03/18 20:38:52 | 000,013,368 | -HS- | C] () -- C:\Users\Christy\AppData\Local\63m4a76h2d8fvd5653vcu6v5m1rpw6n8c604l1q840jn43x
[2011/03/18 20:38:52 | 000,013,368 | -HS- | C] () -- C:\ProgramData\63m4a76h2d8fvd5653vcu6v5m1rpw6n8c604l1q840jn43x
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5D432CE3

:Files
C:\Program Files\Defender Pro
ipconfig /flushdns /c

:Commands
[EMPTYTEMP]
[RESETHOSTS]

Then click Run Fix. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.




Please download ComboFix from one of these locations:

<a title="External link" href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" rel="external"><>Link 1</></a>
<a title="External link" href="http://www.infospyware.net/antimalware/combofix/" rel="external"><>Link 2</></a>

<>* IMPORTANT !!! Save ComboFix to your Desktop as ComboFix.exe</>
<ul>
<li>Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See <a title="External link" href="http://www.bleepingcomputer.com/forums/topic114351.html" rel="external">HERE</a> for help</li>
<li>Double click on Combo-Fix & follow the prompts.</li>
<li>As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's ly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.</li>
<li>Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.</li>
</ul>
**Please note: (This applies to Windows XP systems only) If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

<img src="http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif" alt="Posted Image" />
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

<img src="http://img.photobucket.com/albums/v706/ried7/whatnext.png" alt="Posted Image" />
Click on <>Yes</>, to continue scanning for malware.

When finished, ComboFix will produce a log.

<>Note:</>
1. Do not mouseclick combofix's window while it's running. That may cause it to stall!
2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
 
Last edited by a moderator:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top