WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyThreats from Win32/Nuquel.E and Bankerfox.A

more_horiz
My computer has been working slower that usual and when i click on a link it redirects me to another page. Also, a white box now pops up in the middle of my screen and another white box pops up in the lower right corner of my screen that says:
Attack from: 245.138.102.57, port 28978
Attacked port: 57985
Threat: Win32/Nuqel.E
and
Attack from: 166.79.121.229, port 22322
Attacked port:m 13861
Threat: Bankerfox.A

it also seems that my computer wont let me download any anti-virus programs and i have no idea what to do. I am not computer savvy at all so I'm trying not to do anything to mess my computer up even more!

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyAlso....

more_horiz
the numbers in the white box in the lower right corner change every once in a while, they are never the same numbers

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
Please download the current version of HijackThis from HERE

  • Double click and run the installer.
  • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
  • After installing, you should get the user agreement, press accept and Hijack This will run.
  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
When i click the link it says Page Load Error.
Firefox can't establish a connection to the server at download.bleepingcomputer.com.







Though the site seems valid, the browser was unable to establish a connection.

* Could the site be temporarily unavailable? Try again later.
* Are you unable to browse other sites? Check the computer's network connection.
* Is your computer or network protected by a firewall or proxy? Incorrect settings can interfere with Web browsing.

it seems that this has been happening with any link that will lead me to getting rid of these viruses

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
A rootkit is blocking you access to the site, lets remove it:



1. Please download The Avenger by Swandog46 to your Desktop
Link: HERE or HERE.

  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

Note: This tool was posted specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, start The Avenger program by clicking on its icon on your desktop.

  • Leave the script box empty.
  • Leave the ticked box "Scan for rootkit" ticked.
  • Then tick "Disable any rootkits found"
  • Now click on the Execute to begin execution of the script.
  • Answer "Yes" twice when prompted.

    The Avenger will automatically do the following:

  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
3. Please copy/paste the content of c:\avenger.txt into your reply.

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
The same thing is happening as before, i click on the link and it says there is a page load error.

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    Link 1
    Link 2
  • Double click DDS.scr to run
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
clicked both links and both of them are still Page Load Error

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
Me thinks there is a proxy set, the tools Origin wanted to use are hosted across different sites, I know some of the bigger names like BC are blocked by the malware, but I don't think foro is.

Remove the Proxy setting in Internet Explorer and/or in FireFox.

    In Internet Explorer
  1. Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox
  1. Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection > Choose "No Proxy"
  2. Click the apply button and restart that computer in normal mode.


See if you can download Hijack This now.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Threats from Win32/Nuquel.E and Bankerfox.A DXwU4
Threats from Win32/Nuquel.E and Bankerfox.A VvYDg

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
on firefox it was already set to "no proxy"

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
Okay, guess we'll need to use another machine.
Do you have a USB stick/external drive and another machine Origin can have you use to transfer tools over?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Threats from Win32/Nuquel.E and Bankerfox.A DXwU4
Threats from Win32/Nuquel.E and Bankerfox.A VvYDg

descriptionThreats from Win32/Nuquel.E and Bankerfox.A EmptyRe: Threats from Win32/Nuquel.E and Bankerfox.A

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum