Reply
Stone Noble
melody406
Posts: 32
Registered: ‎02-14-2012

Re: Need help, I believe my computer is infected with malware or a virus

Hi, I already have a CD burner on my computer; would I still need to download the CD burner?  Also, I dont have any blank CDs, so I'll have to go to the store and get some before I can finish this task.  Thanks so much!

Champion Noble
malwarekiller
Posts: 3,550
Registered: ‎08-08-2011

Re: Need help, I believe my computer is infected with malware or a virus

If u have a cd burning software no need to download imgburn.

Stone Noble
melody406
Posts: 32
Registered: ‎02-14-2012

Re: Need help, I believe my computer is infected with malware or a virus

Went out and bought CDs.  Would not burn to my media player so I installed IMGBurn.  Was able to do all 5 points of yours until the 6th point where Loading didn't open up a dialogue window.  On top of that I now have something on my computer called Searchqu (tool box and app) that I think came up with the IMGBurn.  I don't know what to do at this point.  I don't have money to buy a new computer.  Please advise me.  Thanks!!

Champion Noble
malwarekiller
Posts: 3,550
Registered: ‎08-08-2011

Re: Need help, I believe my computer is infected with malware or a virus

[ Edited ]

Hi dont worry! we will make a offline scan.

 

Please download to your Desktop: Dr.Web CureIt

https://www.freedrweb.com/download+cureit+free/?lng=en

  • After the file has downloaded, disable your current Anti-Virus and disconnect from the Internet
  • Doubleclick the drweb-cureit.exe file, then click the Start button, then the OK button to perform an Express Scan.
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click on the Complete scan radio button.
  • Then click on the Settings menu on top, the select Change Settings or press the F9 key. You can also change the Language
  • Choose the Scanning tab and I recomend leaving the Heuristic analysis enabled (this can lead to False Positives though)
  • On the File types tab ensure you select All files
  • Click on the Actions tab and set the following:
    • Objects Infected objects = Cure, Incurable objects = Move, Suspicious objects = Report
    • Infected packages Archive = Move, E-mails = Report, Containers = Move
    • Malware Adware = Move, Dialers = Move, Jokes = Move, Riskware = Move, Hacktools = Move
    • Do not change the [bAF0-Rename extension[/b] - default is: #??
    • Leave the default save path for Moved files here: %USERPROFILE%\DoctorWeb\Quarantine\
    • Leave prompt on Action checked
  • On the Log file tab leave the Log to file checked.
  • Leave the log file path alone: %USERPROFILE%\DoctorWeb\CureIt.log
  • Log mode = Append
  • Encoding = ANSI
  • Details Leave Names of file packers and Statistics checked.
  • Limit log file size = 2048 KB and leave the check mark on the Maximum log file size.
  • On the General tab leave the Scan Priority on High
  • Click the Apply button at the bottom, and then the OK button.
  • On the right side under the Dr Web Anti-Virus Logo you will see 3 little buttons. Click the left VCR style Start button.
  • In this mode it will scan Boot sectors of all disks, All removable media, and all local drives
  • The more files and folders you have the longer the scan will take. On large drives it can take hours to complete.
  • When the Cure option is selected, an additional context menu will open. Select the necessary action of the program, if the curing fails.
  • Click 'Yes to all' if it asks if you want to cure/move the files.
  • This will move it to the %USERPROFILE%\DoctorWeb\Quarantine\ folder if it can't be cured. (in this case we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your Desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously to your Desktop in your next reply.
    Posted Image
Stone Noble
melody406
Posts: 32
Registered: ‎02-14-2012

Re: Need help, I believe my computer is infected with malware or a virus

Sorry taking so long. Dr cureit takes a lot of time. Ill have to finish tomorrow when i get home. Its almost 1 oclock am. I am on point 24. The scanner found 13 items trojans and possibly backdoor trojan also some adware. Will send you report tomorrow.
Champion Noble
malwarekiller
Posts: 3,550
Registered: ‎08-08-2011

Re: Need help, I believe my computer is infected with malware or a virus

no  problem! time is no barrier

Stone Noble
melody406
Posts: 32
Registered: ‎02-14-2012

Re: Need help, I believe my computer is infected with malware or a virus

Hi,  I ran into a snag on your points you gave me: 

Details:  Leave Names of file packers and Statistics checked)   Under "Details" there are 4 items already checked.

Do you want me to UNCHECK the other 2 and only check "File Packers" and "Statistics" or should ALL 4 be checked??

 

I think I did it wrong the first time around.....     Thanks!

 

Champion Noble
malwarekiller
Posts: 3,550
Registered: ‎08-08-2011

Re: Need help, I believe my computer is infected with malware or a virus

Leave everything checked there...

Stone Noble
melody406
Posts: 32
Registered: ‎02-14-2012

Re: Need help, I believe my computer is infected with malware or a virus

Because I did the scan wrong yesterday, I don't have a Report List from yesterday.  I do see a CureIt.log from 3/1 but I couldn't attach it to my last post, the site wouldn't let me.  Maybe I can copy and paste it to you.  It is the log that caught most of yesterday's viruses.  The names were VikPev00, TrojanFraudser179, C/Program/Max Tech.  Do you need that log as well?

Stone Noble
melody406
Posts: 32
Registered: ‎02-14-2012

Re: Need help, I believe my computer is infected with malware or a virus

and here is the log from today with all 4 DETAILS checked.

 

searchqutoolbar-manifest.xml;C:\DOCUME~1\DELORE~1\LOCALS~1\Temp;Adware.Bandoo.4;Invalid path to file ;
searchqutoolbar-manifest.xml;C:\Documents and Settings\Delores Lewis\Local Settings\Temp;Adware.Bandoo.4;Moved.;