Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 14th, 2009, 06:08 PM
dc116 dc116 is offline
Infrequent Poster
 
Join Date: Jul 2009
Posts: 7
Default Computer Virus!! Need help on removal.

I did a scan with MalwareBytes and it showed that I have 3 files infected:
C:\Users\Public\Favorites\netservice.e… (Backdoor.Agent)
C:\Users\Public\Favorites\NginuL_na.ex… (Worm.AutoRun)
C:\Users\Public\Favorites\plug\001.dll (Backdoor.Agent)
however, Malwarebytes took NO ACTION in removing them

these viruses obviously look VERY DANGEROUS, so I attempted to manually delete them by going to the folders. HOWEVER, after entering the "users" folder and then the "public" folder, I COULD NOT FIND the "favorite" folder (it was not there). WHAT IS THIS SUPPOSE TO MEAN?
1) the viruses have cleverly concealed themselves so that I cannot find them
2) malwarebytes is bs
3) they were already neutralized by malwarebytes or spywareblaster (that I also have on my laptop) and they are perfectly harmless
4) something else??

Additional Details
I use windows vista
I also have SuperAntispyware, Avast pro, and windows defender but I have not scanned the PC using those software yet as they take too much time.
  #2  
Old August 14th, 2009, 09:03 PM
prairie dog's Avatar
prairie dog prairie dog is offline
Regular Poster
 
Join Date: Jun 2009
Posts: 129
Default Re: Computer Virus!! Need help on removal.

Not allowed to work on logs here at wilders. I would post your logs in the Malwarebytes forum. They have excellent support

follow the instructions here

and post your logs here

They should help remove any issues you are having
__________________
Avira Antivir Personal and MBAM Pro
Firewall-online armor premium
on demand:Hitman Pro and SAS
FF3-noscript, adblock plus, keyscrambler, Betterprivacy, TrackMeNot and WOT
Sandboxie
  #3  
Old August 14th, 2009, 11:28 PM
Toby75's Avatar
Toby75 Toby75 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 461
Default Re: Computer Virus!! Need help on removal.

Quote:
Originally Posted by prairie dog
Not allowed to work on logs here at wilders. They should help remove any issues you are having

Not allowed to POST logs...but we can help him.

dc116,

Download A2 Free...update...then run a deep scan...let me know how it goes.
http://www.emsisoft.com/en/software/free/

I am more than willing to help anyway I can.

Toby
  #4  
Old August 15th, 2009, 12:26 AM
prairie dog's Avatar
prairie dog prairie dog is offline
Regular Poster
 
Join Date: Jun 2009
Posts: 129
Default Re: Computer Virus!! Need help on removal.

Quote:
Originally Posted by Toby75
Not allowed to POST logs...but we can help him.

dc116,

Download A2 Free...update...then run a deep scan...let me know how it goes.
http://www.emsisoft.com/en/software/free/

I am more than willing to help anyway I can.

Toby

I guess what I should have said is post there if he would like to have someone look over his logs to verify everything has been removed, even after running any scans.
__________________
Avira Antivir Personal and MBAM Pro
Firewall-online armor premium
on demand:Hitman Pro and SAS
FF3-noscript, adblock plus, keyscrambler, Betterprivacy, TrackMeNot and WOT
Sandboxie
  #5  
Old August 15th, 2009, 12:54 AM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: Computer Virus!! Need help on removal.

Following a scan with the excellent MBAM, the scan report will appear.
It is then up to the user to select the "remove selected" button. (Look for it-it's not hard to see.)
Select the items you want removed, first, of course.
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #6  
Old August 15th, 2009, 10:22 AM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,464
Default Re: Computer Virus!! Need help on removal.

Try an Antivirus Rescue CD to get rid of the Malware. (It is my understanding that a Rescue CD can easily detect and remove Malware since Windows is not loaded during the scan/removal process.) I have had good hardware compatibility with both the AVIRA AntiVir Rescue System and the Kaspersky Rescue CD.

The AVIRA AntiVir Rescue System download is an exe with the latest virus definitions (so you do not need to update it). You run the exe and it will walk you through burning a bootable CD. Then you boot off of the CD, change the language from German to English (Click on the British Flag.) and scan your hard drive(s). By default the AVIRA AntiVir Rescue System scans and Reports Only. If you want to clean the Malware you will have to change the options before scanning.

http://www.free-av.com/en/products/1...ue_system.html

The Kaspersky Rescue CD is downloaded as an ISO Image. You will need to burn the ISO as an Image so that the CD will be bootable. Once you have booted off the CD you will need to update the virus definitions. The default settings is to Prompt the user for Action each time Malware is found.

http://downloads5.kaspersky-labs.com...ds/RescueDisk/
__________________
NOD32, Sandboxie (Paid), AppGuard, Malwarebytes Anti-Malware, Emsisoft Emergency Kit, DrWeb Cureit, AVIRA Rescue CD, Image for Windows/Image for DOS/Image for Linux, Firefox (Adblock Plus, Subscriptions: EasyList+EasyPrivacy+Malware Domains), Norton DNS
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:24 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums