Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Begin your free trial now
Pay-as-you-go options starting at $10/user/month
Pay-as-you-go options starting at $10/user/month
Solved:I have the Downloader-BEW virus, need help!
|
|
Thread Tools | Search this Thread |
|
#1
|
|||
|
|||
|
Solved:I have the Downloader-BEW virus, need help!
I have McAfee AV and while doing some computer work it popped up and started notifying me of files infected with the Downloader-BEW virus. It says it's cleaning them, but I would like to proactively remove this from my system. I've seen other users on this forum who have been helped. After reading the warnings concerning NOT using the instructions given to others, I have decided to begin a new thread and await further instructions. Please help!
Michael |
|
#3
|
|||
|
|||
|
I'm on it! Be right back with all that you've requested! Thanks so much!
|
|
#4
|
|||
|
|||
|
Hello and welcome to Techspot.
Before following any other instructions, please do the following. [color=red]Very Important:[/color] Before deciding whether you should clean or reformat your system, go and read this thread [color=blue]HERE[/color] and decide what it is you want to do. If after reading the above, you wish to clean your system, do the following. Please download FindAWF to your Desktop. Double-click FindAWF.exe to start the tool. Select "option #1 - Scan for bak folders" by typing 1 and press Enter When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt as an attachment. Also, please post a HJT log as per these instructions. Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
|
#5
|
|||
|
|||
|
awf.txt
Here is my awf.txt file, BUT, when I click on the "HERE" link to download the HJT software, I get the following message ...
"Fatal error: Call to undefined function checknum() in /home/majorgee/public_html/download.php on line 32" |
|
|
|
#6
|
|||
|
|||
|
The Major Geeks site must be down. I have now fixed the link and HJT can be downloaded directly from the Trend website.
Please post the HJT log in your next reply. Right click on this link DelO15Domains.inf and choose Save As. Save it to your desktop. Right click on that file and choose Install. It will run immediately (you won't be able to see anything happen). You may delete it afterwards. NOTE: This script will delete any sites you may have added to the Trusted Sites. So if you want them back, you have to add them back to the Trusted Sites again. Double-click FindAWF.exe to start the tool. Then, do the following Select "option #2 - Restore files from bak folders" by typing 2 and press Enter . A text file will open up. Please copy/paste the following text from the quote box (all except the word QUOTE) into the text file. Quote:
Close the .txt file and click Yes to save the changes. When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt in your next reply as an attachment. Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
|
#7
|
|||
|
|||
|
OK, finished with that! Ready for the next step! See my attached awf.txt and hijackthis.log files.
|
|
#8
|
|||
|
|||
|
Please double-click the FindAWF icon once again
This time we are going to remove some folders. Use the following option: Press 3 then Enter to remove bak folders A text file opens called: folders.txt Click below the line and paste the following list of folders to be removed: Quote:
When done with the above, FindAWF automatically runs a new scan and opens a new log that you need to post. Please provide the new FindAWF log Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
|
#9
|
|||
|
|||
|
Folders removed! See attached awf.txt file! I appreciate your fast responses. I'm here for the duration! As long as it takes!
|
|
#10
|
|||
|
|||
|
There`s just one more bak file to deal with.
Double-click FindAWF.exe to start the tool. Then, do the following Select "option #2 - Restore files from bak folders" by typing 2 and press Enter . A text file will open up. Please copy/paste the following text from the quote box (all except the word QUOTE) into the text file. Quote:
When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt in your next reply as an attachment. Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
|
#11
|
|||
|
|||
|
Done! Ready for the next step.
|
|
#12
|
|||
|
|||
|
Please double-click the FindAWF icon once again
This time we are going to remove some folders. Use the following option: Press 3 then Enter to remove bak folders A text file opens called: folders.txt Click below the line and paste the following list of folders to be removed: Quote:
When done with the above, FindAWF automatically runs a new scan and opens a new log that you need to post. Please provide the new FindAWF log Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
|
#13
|
|||
|
|||
|
And here you go again, Howard!
|
|
#14
|
|||
|
|||
|
Still there, please do the following, though you will probably have to reinstall Nero once done.
Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE. In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE. Open your task manager, by holding down the ctrl and alt keys and pressing the delete key. Click on the processes tab and end process for(if there). InCD.exe Close task manager. Locate and delete the following bold files and/or directories(if there). C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Ahead\InCD\bak<Delete the entire folder. Reboot into normal mode and rehide your protected OS files. Please download FindAWF to your Desktop. Double-click FindAWF.exe to start the tool. Select "option #1 - Scan for bak folders" by typing 1 and press Enter When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt as an attachment. Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
|
#15
|
|||
|
|||
|
Well, I knew that was going way too smoothly!
We have a slight problem. My computer won't let me boot in Safe Mode. I hit F8 and then I select "Safe Mode". It moves on and then comes back with the following screen ..."We apologize for the inconvenience, but Windows did not start successfully. A recent software of hardware change might have caused this. If your computer stopped responding, restarted unexpectedly, or was automatically shut down to protect your files and folders, choose Last Known Good Configuration to revert to the most recent settings that worked. If a previous startup screen attempt was interrupted due to power failure or because the Power or Reset button was pressed, or if you aren't sure what caused the problem, choose Start Normally. Safe Mode Safe Mode with Networking Safe Mode with Command Prompt Last Known Good Configuration Start Windows Normally" I tried to choose "Safe Mode" several times, but continue to end up on this screen. The only way past it is to wait the 30 seconds and let it start normally. Then, here's what I did. I ran msconfig and turned off the InCD option in the startup, then restarted my PC. So, InCD is no longer running. I'll let you tell me what to do next! |
|
#16
|
|||
|
|||
|
You`ll need to reinstall Nero, as incd is part of Nero and we had to delete it.
See if that helps. Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
|
#17
|
|||
|
|||
|
Hello again, Howard! I'm back! OK, here's what I did. I tried reinstalling Nero, but during the installation, it said there were files missing and that I should reinstall it (which is what I was doing, so that was rather confusing). When I'd try to run Nero after the "installation", it told me files were missing. So ... for now, I just went into Control Panel and uninstalled the entire thing. It's gone, and now I CAN boot up in Safe Mode! I'm just gonna leave it like that for now until we're through ridding this machine of the virus (my MAIN concern!).
So, what's next?
|
|
#18
|
|||
|
|||
|
Please download FindAWF to your Desktop.
Double-click FindAWF.exe to start the tool. Select "option #1 - Scan for bak folders" by typing 1 and press Enter When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt as an attachment. Also post a fresh HJT log. Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
|
#19
|
|||
|
|||
|
Here are the awf.txt and hijackthis.log files you requested.
|
|
#20
|
|||
|
|||
|
That`s odd. the InCd bak file is there again.
Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE. In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE. Open your task manager, by holding down the ctrl and alt keys and pressing the delete key. Click on the processes tab and end process for(if there). InCD.exe Close task manager. Locate and delete the following bold files and/or directories(if there). C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Ahead\InCD\bak<Delete the entire folder. Reboot into normal mode and rehide your protected OS files. Please download FindAWF to your Desktop. Double-click FindAWF.exe to start the tool. Select "option #1 - Scan for bak folders" by typing 1 and press Enter When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt as an attachment. Regards Howard ![]() [color=red]This thread is for the use of[/color] lemkorusyn [color=red]only. [color=blue]Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our[/color] security and the web forum.[/color] |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Sagipsul Virus - Have solved some problems, but I need more help
|
4 | Virus and Malware Removal | ||
Js/downloader agent virus
|
1 | Virus and Malware Removal | ||
JS/Downloader Virus infection
|
30 | Virus and Malware Removal | ||
I have the Downloader-BEW virus, need help! Please
|
11 | Virus and Malware Removal | ||
Downloader.BEW - mostly solved - need logs reviewed
|
8 | Virus and Malware Removal | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 06:11 AM.




Sagipsul Virus - Have solved some problems, but I need more help