TechSpot

Virus/malware help

By lord gore
Jan 20, 2009
Topic Status:
Not open for further replies.
  1. I have a problem with my toshiba laptop.
    Whenever i connect to the internet, after a few seconds the laptop freezes as in i cannot open any software but the windows that are already open work normally, i think it is some virsu...
    Any help will be greatly appreciated!
  2. suedschwede

    suedschwede TS Rookie

    Vundo to be removed - good luck

    Hi,
    YOUR MBAM file reports several infections with vundo.
    Why did you not remove it?
    First step to protect your system: Apply 8-steps cleaning procedure.
    I did it on my own and it worked very effective
  3. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    suedschwede, I just left a reply to you on another thread telling you to go through the malware removal steps then post your logs for review.

    Please don't tell a poster to do this on their own. The logs need to be reviewed, inappropriate entries need to be removed and occasionally, additional program need to be run.

    lord gore, your Mbam, log shows this: (Trojan.Vundo) -> No action taken

    This means you did not foollow the dirtection in Malwarebytes to * Make sure that everything is checked, and click Remove Selected.

    Please update and run Malwarebytes again, with everything checked.
    Your HijackThis log also has numerous entries to be removed. But you need to run SuperAntispyware taking care to check for removal also, AFTER MalwareBytes, then scan with HijackThis again.

    You should follow the Steps here: http://www.techspot.com/vb/topic58138.html

    Please attach all three logs
  4. lord gore

    lord gore TS Rookie Topic Starter

    I did the scan again deleted the virus but the problem still persists. Thanx a lot for ur prompt reply.
  5. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Okay, we have some work to do!

    Please re-open HiJackThis and click on System Scan Only. Check the boxes next to all the entries listed below.
    Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot into Safe Mode.

    Stsrt> Run> msconfig> enter> Selective Startup> Startup tab> UNCHECK any entries for:
    Trend Micro Security Suite and/or any components, in particular Transaction Protector> Apply> OK

    Control Panel> Add/remove Programs> UNINSTALL Trend Micro Security Suite and/or components.

    To remove the 024 Desktop entries:

    Start> Control Panel> Display> Desktop> Customize Desktop> Web tab> uncheck and delete everything you find in there (except for "My current home page")> Also remove the check mark from the the Lock Desktop Items box if it is checked> Apply> OK> Close.[/QUOTE]

    Reboot into Normal Mode: NOTE: You will get a nag message that you can ignore and close after checking 'don't show this message again.' Stay in Selective Startup.

    Please download ComboFix from HERE

    With ComboFix, at the download window, please rename it to Combo-Fix(.exe) before downloading it.

    Please disable all security programs, such as antiviruses, antispywares, and firewalls.
    Also disable your internet connection.

    • Run Combo-Fix.exe and follow the prompts.
    Do not click on the ComoboFix window, as it may cause it to stall.

    CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

    Run HijackThis again and attach new log and ComboFix report.

    Please verify the following:
    Did you set these proxies up?
    Is this your ISP?
  6. lord gore

    lord gore TS Rookie Topic Starter

    It just became worse. After I installed combofix last night, today morning the laptop won't work... At times it gets stuk on the startup screen( user account selection screen) as in if I click on my account it will just keep loading and sometimes it starts but then nothing works, I can't even open notepad, and so I am replying to u via my mobile. Please help me out and keep in mind I can't connect to the internet from my laptop. Thank you very much.
  7. lord gore

    lord gore TS Rookie Topic Starter

    And yea thts my internet proxy and isp. Thnx
  8. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Uninstall Combofix
    * Click START then RUN
    * Now type Combofix /u in the runbox
    * Make sure there's a space between Combofix and /u
    * Then hit Enter.

    * The above procedure will:
    * Delete the following:
    * ComboFix and its associated files and folders.
    * Reset the clock settings.
    * Hide file extensions, if required.
    * Hide System/Hidden files, if required.
    * Set a new, clean Restore Point.

    Let me know the status after removing ComboFix.
  9. lord gore

    lord gore TS Rookie Topic Starter

    ok its alright now. i rolled back the chnages from system restore and its working normally but i wasnt able to uninstall combofix. if i type combofix /u it just start combofix. i feel there is more virus in this laptop because the laptop freezes randomly whenever i m connected to the internet.
    And thanks a lot everyone, greatly appreciated your help.
  10. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    I'm sorry you used System Restore. You will have infected the system all over again and undone what was previously done to clean it! Malware gets in the restore points. they are protected files and the cleaning programs don't remove them. We have people drop all their old restore points after the system is clean.

    Would you like to start over> If so, do this:

    Download OTCleanIt HERE & save it to your desktop.
    This will remove the cleaning programs.

    Then start HERE.

    Attach the new logs when through.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.