WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
is this all i needed to do? is the coast clear now? lol

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
Please run OTL.exe.

  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :OTL
    O3 - HKLM\..\Toolbar: (no name) - ID - No CLSID value found.
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O33 - MountPoints2\{46e691f7-0676-11dd-8b3c-00038a000015}\Shell\AutoRun\command - "" = setupSNK.exe
    O33 - MountPoints2\{4cd21dfe-9d15-11de-8baa-00038a000015}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{4cd21dfe-9d15-11de-8baa-00038a000015}\Shell\AutoRun\command - "" = E:\autorun.exe -- File not found
    O33 - MountPoints2\{4cd21dfe-9d15-11de-8baa-00038a000015}\Shell\phone\command - "" = E:\autorun.exe -- File not found
    O36 - AppCertDlls: AppSecDll - (C:\WINDOWS\system32\AppCert\wsil32.dll) - C:\WINDOWS\System32\AppCert\wsil32.dll File not found



  • Return to OTL, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.

  • Click the red Run Fix button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTL.exe
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 DXwU4
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 VvYDg

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
ok this is what it said.

========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\ID deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{46e691f7-0676-11dd-8b3c-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46e691f7-0676-11dd-8b3c-00038a000015}\ not found.
File setupSNK.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4cd21dfe-9d15-11de-8baa-00038a000015}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4cd21dfe-9d15-11de-8baa-00038a000015}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4cd21dfe-9d15-11de-8baa-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4cd21dfe-9d15-11de-8baa-00038a000015}\ not found.
File E:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4cd21dfe-9d15-11de-8baa-00038a000015}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4cd21dfe-9d15-11de-8baa-00038a000015}\ not found.
File E:\autorun.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\\AppSecDll:C:\WINDOWS\system32\AppCert\wsil32.dll deleted successfully.

OTL by OldTimer - Version 3.1.28.0 log created on 02062010_233408

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.

  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 DXwU4
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 VvYDg

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
ok i did that...its deleted.. Anything else? :O)

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
How is the machine running now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 DXwU4
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 VvYDg

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
Moderated Message: Hello, your comment has been removed. Please do not post in another member's topic. If you need help, please read this over and click here to open a new topic.

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
its running pretty good..i'm online..its moving pretty fast. I still have got the "you've got a virus" message a couple times but nothings happened so far.

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
When does that happen?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 DXwU4
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 VvYDg

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
it just happens at random. Usually its when i first get online. It shows a little red shield with the "x" through it and then it says I may have something harmful on my computer....but then it dissappears....and also sometimes when I'm on a website it'll close the window and a box will pop up and say "your computer may be infected" and then it'll pop up a page that looks like its scanning for viruses...

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
Hello.

  • Download combofix from here
    Link 1
    Link 2

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:

    My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 CF_download_FF

    My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 CF_download_rename

    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See HERE for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 Cf410

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes

    My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 Cf510

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 DXwU4
My computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 VvYDg

descriptionMy computer is infected by malware! Bankerfox.A  can anyone help?! - Page 1 EmptyRe: My computer is infected by malware! Bankerfox.A can anyone help?!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum