
05-29-2012 12:36 PM
Hi
Seems my computer got locked by a malware that shows a screen with a police logo requesting money to unlock it.
I have been able to boot in safe mode and run otl (log attached). It is the second time it happens to me but I am not able to clean it/fix it.
Also I am wondering how to get my Vista desktop protected against this malware...
Thanks in advance
J
Solved! Go to Solution.
05-29-2012 09:00 PM - edited 05-29-2012 09:02 PM
Welcome back!![]()
I will need to give me some malicious files from your computer for tranmission of them to trend after this fix
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
If u have malwarebytes 1.5 or later disable it for the duration of this run
Run OTL
FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=toolbar2&q=" [2012/05/29 11:54:19 | 000,000,448 | ---- | M] () -- C:\ProgramData\ilfpeanzmjqxmjt [2012/05/29 11:54:17 | 000,057,344 | ---- | M] () -- C:\ProgramData\vojwxshdfallqufdooal.exe [2012/05/29 11:54:17 | 000,057,344 | ---- | M] () -- C:\Users\admin\ms.exe O4 - HKU\S-1-5-21-2525868930-1968600409-2025159413-1000..\Run: [vojwxshdfallquf] C:\ProgramData\vojwxshdfallqufdooal.exe () ipconfig /flushdns /c :Commands [purity] [resethosts] [emptytemp] [EMPTYFLASH] [Reboot]
Also please bare in mind your previous topic was left open and u didnt run my fix here:
http://community.trendmicro.com/t5/Malware-Discuss
05-30-2012 03:14 AM
Hi
Thanks for your post.
I have followed your instructions but malware is still there.
BTW, I have run OTL again after fix reboot. (both logs are attached)
Regards
C
05-30-2012 03:16 AM
Oops! my error..corrected my fix
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
If u have malwarebytes 1.5 or later disable it for the duration of this run
Run OTL
:OTL FF - prefs.js..keyword.URL: "http://search.babylon.com/?babsrc=toolbar2&q=" [2012/05/29 11:54:19 | 000,000,448 | ---- | M] () -- C:\ProgramData\ilfpeanzmjqxmjt [2012/05/29 11:54:17 | 000,057,344 | ---- | M] () -- C:\ProgramData\vojwxshdfallqufdooal.exe [2012/05/29 11:54:17 | 000,057,344 | ---- | M] () -- C:\Users\admin\ms.exe O4 - HKU\S-1-5-21-2525868930-1968600409-2025159413-1000..\Run: [vojwxshdfallquf] C:\ProgramData\vojwxshdfallqufdooal.exe () ipconfig /flushdns /c :Commands [purity] [resethosts] [emptytemp] [EMPTYFLASH] [Reboot]
05-30-2012 05:00 AM
Hi
It worked, thank you very much!!
After fix log file attached....
Please let me know if you need some files from me.
Regards
C
05-30-2012 05:19 AM - edited 05-30-2012 05:21 AM
Hi yes...
Please open up your C: drive... Then open up the OTL quarantine folder[otl folder]...and zip up this file vojwxshdfallqufdooal.exe and keep it password protected and upload to www.mediafire.com and post sharing link please.
Password to be kept: infected
05-30-2012 06:45 AM - edited 05-30-2012 06:50 AM
05-30-2012 09:29 AM - edited 05-30-2012 09:34 AM
I have submitted the file to trend micro lab for analysis...its brand new ransomware i guess:
just 16 scannners detected it out of 42
Open OTL and hit the cleanup button
As an addition step it's recommended that you download other free anti-malware software from the list below and run a full system scan :
05-30-2012 11:21 PM
Hi
I have run ESET and it found the following:
C:\Users\admin\Local Settings\Temp\msnnovb.bat a variant of Win32/Kryptik.AEVG trojan cleaned by deleting - quarantined
Seems I am safe...by now. ![]()
Thank you very much for your help.
Regards
Javier
05-31-2012 04:23 AM - edited 05-31-2012 04:23 AM
your welcome!
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
