Jump to content

Virus infected files will not go away.


Recommended Posts

I just got an email which I think could be the email that gave me the virus in the first place.  It was a priority mail tracking email, which I thought was from one of the companies that I do business with.  Now I am afraid to open it.  Especially since I was not expecting it, like I wasn't expecting it then either.

 

Charlie

Link to post
Share on other sites

  • Root Admin

Yes, emails out of the blue like that are SPAM and one should never open them or click on any content in them.

Please copy that file to the root of the C: drive so it will be something like this: c:\srsvc.dll

Once you've saved that file to the root of C: then go ahead and save the attached file CFScript.txt to the same location as Combofix. Then drag and drop it onto combofix and let it run. If it asks to update please go ahead and allow it.

When done it will create a new log file. Please attach that log file on your next reply.

Thanks

CFScript.txt

Link to post
Share on other sites

Ok,  Thanks you for all of your help. 

 

This has been a pain, but it has also been interesting.  Attached is the log file from the Combofix run.  I kept getting a Firefox message that a suspious program was running and that it was confined to the sandbox.  I kept getting a popup asking me if I wanted to terminate the program, I continued it.  I did get 2 messages that said a virus had been found and was stopped before it was executed.  The file was c:combofix/catchme.tmp. 

 

Thanks so much,ComboFix.txt

Charlie

Link to post
Share on other sites

  • Root Admin

Please run the following and I'll check back with you when I can.  Thanks

 

 

dr_web_cureit_zpse80d87bf.jpg

  1. Please download Dr.Web CureIt! antivirus and save it to your computer. The file size is in excess of 100MB
  2. NOTE: Free usage of Dr.Web CureIt! for business purposes is illegal.
  3. Internet Explorer may show a warning when downloading - the file is safe to download from the provided link.
  4. Shutdown your antivirus to avoid any conflicts while scanning.
  5. Once the scans have completed please re-enable your antivirus.
  6. If using Malwarebytes Anti-Malware PRO you can right click over the tray icon and disable the Protection Modules
  7. If needed you can also temporarily disable it from starting with Windows
  8. Temporarily turn off any other security add-ons or applications you may also have.
  9. Once you have downloaded Dr.Web CureIt! you should right click over it and choose Properties and verify it has a Digital Signature.
  10. If it does not have a Digital Signature then do not run it.
  11. Close all open programs including all Web browsers and then double-click on drweb-cureit.exe to start the installer.
  12. You should have your User Account Control (UAC) enabled for improved security and which should then produce a dialog box asking for approval to run the installer.
  13. Click on the Yes button to start the installer.
  14. Click OK to scan your computer in the Enhanced Protection Mode
  15. Click on the check box to agree to participate in their software improvement program.
  16. Then if needed choose your Language by clicking on the small globe like icon in the upper right corner by the wrench.
  17. Then click on the Continue button and then click on the Select objects for scanning link just below the "Start scanning" button.
  18. Place a check mark on all the items except for Temporary files and System restore points - those items should not have a check mark on them.
  19. Then click on the Start scanning button.
  20. If a threat is found you can click on the Action column in the program.
  21. Your options will be Cure or Ignore
  22. If you see an item that you are absolutely sure is OK, then un-check the check box for that item, otherwise keep it on Cure.
  23. Then click on the Neutralize button.
  24. Once completed click on the green Open Report link. It will open the report in NOTEPAD
  25. Save the report to your desktop. The report will be called Cureit.log
  26. Close Dr.Web Cureit!
  27. Reboot your computer to allow files that were in use to be moved/deleted during reboot.
  28. After reboot, attach the log Cureit.log you saved previously in your next reply.
  29. Re-Enable your antivirus and other security programs when all done.


 

Link to post
Share on other sites

  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.