Reply
Stone Emissary
xleyba
Posts: 51
Registered: ‎04-23-2012
Accepted Solution

Computer locked by malware

Hi

 

Seems my computer got locked by a malware that shows a screen with a police logo requesting money to unlock it.

 

I have been able to boot in safe mode and run otl (log attached). It is the second time it happens to me but I am not able to clean it/fix it.

 

Also I am wondering how to get my Vista desktop protected against this malware...

 

Thanks in advance

 

J

Please use plain text.
Epic Talent
malwarekiller
Posts: 3,835
Registered: ‎08-08-2011

Re: Computer locked by malware

[ Edited ]

Welcome back!Posted Image

 

I will need to give me some malicious files from your computer for tranmission of them to trend after this fix

 

Warning This fix is only relevant for this system and no other, using on another computer may cause problems 

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot 


If u have malwarebytes 1.5 or later disable it for the duration of this run


Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=toolbar2&q="
[2012/05/29 11:54:19 | 000,000,448 | ---- | M] () -- C:\ProgramData\ilfpeanzmjqxmjt
[2012/05/29 11:54:17 | 000,057,344 | ---- | M] () -- C:\ProgramData\vojwxshdfallqufdooal.exe
[2012/05/29 11:54:17 | 000,057,344 | ---- | M] () -- C:\Users\admin\ms.exe
O4 - HKU\S-1-5-21-2525868930-1968600409-2025159413-1000..\Run: [vojwxshdfallquf] C:\ProgramData\vojwxshdfallqufdooal.exe ()


ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Please attach the log generated after the fix completion

 

 

 

Also please bare in mind your previous topic was left open and u didnt run my fix here:

http://community.trendmicro.com/t5/Malware-Discussions/Computer-locked/td-p/72953/page/2

—————
Was this post helpful? Say “thanks” by giving me a “Kudo”!
Was your question answered or issue solved? Mark that post as an “Accepted Solution”!
Please use plain text.
Stone Emissary
xleyba
Posts: 51
Registered: ‎04-23-2012

Re: Computer locked by malware

 

Hi

 

Thanks for your post.

 

I have followed your instructions but malware is still there.

 

BTW, I have run OTL again after fix reboot. (both logs are attached)

 

Regards

 

C

Please use plain text.
Epic Talent
malwarekiller
Posts: 3,835
Registered: ‎08-08-2011

Re: Computer locked by malware

Oops! my error..corrected my fix

 

Warning This fix is only relevant for this system and no other, using on another computer may cause problems 

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot 


If u have malwarebytes 1.5 or later disable it for the duration of this run


Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following:
:OTL
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=toolbar2&q="
[2012/05/29 11:54:19 | 000,000,448 | ---- | M] () -- C:\ProgramData\ilfpeanzmjqxmjt
[2012/05/29 11:54:17 | 000,057,344 | ---- | M] () -- C:\ProgramData\vojwxshdfallqufdooal.exe
[2012/05/29 11:54:17 | 000,057,344 | ---- | M] () -- C:\Users\admin\ms.exe
O4 - HKU\S-1-5-21-2525868930-1968600409-2025159413-1000..\Run: [vojwxshdfallquf] C:\ProgramData\vojwxshdfallqufdooal.exe ()


ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Please attach the log generated after the fix completion
—————
Was this post helpful? Say “thanks” by giving me a “Kudo”!
Was your question answered or issue solved? Mark that post as an “Accepted Solution”!
Please use plain text.
Stone Emissary
xleyba
Posts: 51
Registered: ‎04-23-2012

Re: Computer locked by malware

 

Hi

 

It worked, thank you very much!!

 

After fix log file attached....

 

Please let me know if you need some files from me.

 

Regards

C

 

Please use plain text.
Epic Talent
malwarekiller
Posts: 3,835
Registered: ‎08-08-2011

Re: Computer locked by malware

[ Edited ]

Hi yes...

 

Please open up your C: drive...  Then open up the OTL quarantine folder[otl folder]...and zip up this file vojwxshdfallqufdooal.exe and keep it password protected and upload to www.mediafire.com and post sharing link please.

 

Password to be kept: infected

—————
Was this post helpful? Say “thanks” by giving me a “Kudo”!
Was your question answered or issue solved? Mark that post as an “Accepted Solution”!
Please use plain text.
Stone Emissary
xleyba
Posts: 51
Registered: ‎04-23-2012

Re: Computer locked by malware

[ Edited ]

As requested...

 

http://www.mediafire.com/?rxy6cztc3xk4a1x

 

Regards

Javier

Please use plain text.
Epic Talent
malwarekiller
Posts: 3,835
Registered: ‎08-08-2011

Re: Computer locked by malware

[ Edited ]

I have submitted the file to trend micro lab for analysis...its brand new ransomware i guess:

https://www.virustotal.com/file/c3dd2e3cf0ebeec7a6c280e187a044a32b54b369a78aaaa89c600a0767b49704/ana...

 

just 16 scannners detected it out of 42

 

Open OTL and hit the cleanup button

  

As an addition step it's recommended that you download other free anti-malware software from the list below and run a full system scan :

—————
Was this post helpful? Say “thanks” by giving me a “Kudo”!
Was your question answered or issue solved? Mark that post as an “Accepted Solution”!
Please use plain text.
Stone Emissary
xleyba
Posts: 51
Registered: ‎04-23-2012

Re: Computer locked by malware

Hi

 

I have run ESET and it found the following:

 

C:\Users\admin\Local Settings\Temp\msnnovb.bat    a variant of Win32/Kryptik.AEVG trojan    cleaned by deleting - quarantined

Seems I am safe...by now. :smileyhappy:

 

Thank you very much for your help.

 

Regards

Javier

Please use plain text.
Epic Talent
malwarekiller
Posts: 3,835
Registered: ‎08-08-2011

Re: Computer locked by malware

[ Edited ]

your welcome!

—————
Was this post helpful? Say “thanks” by giving me a “Kudo”!
Was your question answered or issue solved? Mark that post as an “Accepted Solution”!
Please use plain text.