Jump to content

Windows virusbuster ransomware, bypasses safe mode


Recommended Posts

Hi

 

My dad opened an email attachment he shouldn't have today, and inadvertently installed what appears to be some ransomware called 'windows virusbuster'. I would normally run malwarebytes to get shot of this however this program seems to bypass safe mode so I am stumped as to how to get rid of it. I have scanned the pc using Farbar and have attached the txt file to this post, hope someone can help

 

Cheers

 

 

 

FRST.txt

Link to post
Share on other sites

Hello jamfire68 and :welcome:! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
Open Notepad (Start => All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open Notepad and select Paste). Save it on the flashdrive as fixlist.txt

HKU\Kathy\...\Winlogon: [shell] C:\Users\Kathy\AppData\Roaming\guard-rrry.exe [ 2013-11-23] () <==== ATTENTION

2013-11-23 08:05 - 2013-11-23 08:10 - 00002763 _____ C:\ProgramData\connector.swf

2013-11-23 08:05 - 2013-11-23 08:05 - 00001023 _____ C:\Users\Kathy\AppData\Roaming\result1.db

2013-11-23 08:03 - 2013-11-23 08:03 - 00965472 _____ C:\Users\Kathy\AppData\Roaming\guard-ysjl.exe

2013-11-23 08:03 - 2013-11-23 08:03 - 00965472 _____ C:\Users\Kathy\AppData\Roaming\guard-rrry.exe

2013-11-23 08:05 - 2013-11-23 08:05 - 00001023 _____ C:\Users\Kathy\AppData\Roaming\result1.db

2013-11-23 01:02 - 2013-02-17 02:37 - 00000000 ____D C:\Program Files\24x7Help

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system

Now please enter System Recovery Options then select Command Prompt

Run FRST (or FRST64 if you have the 64bit version) and press the Fix button just once and wait.

The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

Reboot Normally.

Link to post
Share on other sites

Hi Borislav

 

Many thanks for the quick reply, your fix has sorted it out for me, many thanks again.

 

here is the fixlog from the scan

 

Cheers

 

Jamie

 

 

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-11-2013 03
Ran by SYSTEM at 2013-11-23 22:28:20 Run:1
Running from F:\
Boot Mode: Recovery

==============================================

Content of fixlist:
*****************
------------ QUOTE ----------
HKU\Kathy\...\Winlogon: [shell] C:\Users\Kathy\AppData\Roaming\guard-rrry.exe [ 2013-11-23] () <==== ATTENTION
2013-11-23 08:05 - 2013-11-23 08:10 - 00002763 _____ C:\ProgramData\connector.swf
2013-11-23 08:05 - 2013-11-23 08:05 - 00001023 _____ C:\Users\Kathy\AppData\Roaming\result1.db
2013-11-23 08:03 - 2013-11-23 08:03 - 00965472 _____ C:\Users\Kathy\AppData\Roaming\guard-ysjl.exe
2013-11-23 08:03 - 2013-11-23 08:03 - 00965472 _____ C:\Users\Kathy\AppData\Roaming\guard-rrry.exe
2013-11-23 08:05 - 2013-11-23 08:05 - 00001023 _____ C:\Users\Kathy\AppData\Roaming\result1.db
2013-11-23 01:02 - 2013-02-17 02:37 - 00000000 ____D C:\Program Files\24x7Help
-----------------------------
*****************

HKU\Kathy\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully.
C:\ProgramData\connector.swf => Moved successfully.
C:\Users\Kathy\AppData\Roaming\result1.db => Moved successfully.
C:\Users\Kathy\AppData\Roaming\guard-ysjl.exe => Moved successfully.
C:\Users\Kathy\AppData\Roaming\guard-rrry.exe => Moved successfully.
"C:\Users\Kathy\AppData\Roaming\result1.db" => File/Directory not found.
C:\Program Files\24x7Help => Moved successfully.

==== End of Fixlog ====

Link to post
Share on other sites

  • 3 weeks later...
  • Root Admin

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.