BankerFox.A...I can't get MWB to Run, Java to update etc

View previous topic View next topic Go down

BankerFox.A...I can't get MWB to Run, Java to update etc

Post by Amy_Isaac on 17th August 2009, 1:25 pm

I'm getting the false anti virus security messages and constant pop ups in Internet Explorer associated with BankerFox.A and Win32/Nuqel.E.

I tried to update java, and got an error that the file is infected - which is the error I am getting for all files I try to download and run - and certainly associated with this virus thing my computer has.

I Installed Malware Bytes AntiMalware and tried to run it but get two run time errors and then the popup saying it is infected.

I was able to download HJT and run it.

I think these programs are being corrupted during download.

Any suggestions on what I should do??

Amy_Isaac
Beginner
Beginner

Posts Posts : 2
Joined Joined : 2009-08-17
OS OS : XP
Points Points : 26714
# Likes # Likes : 0

View user profile

Back to top Go down

Re: BankerFox.A...I can't get MWB to Run, Java to update etc

Post by Belahzur on 17th August 2009, 1:57 pm

Please download SystemLook from one of the links below and save it to your Desktop.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:

    :filefind
    scecli.dll
    netlogon.dll
    eventlog.dll

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

System Look v1.0 results

Post by Amy_Isaac on 18th August 2009, 2:05 am

SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 18:49 on 17/08/2009 by amy (Administrator - Elevation successful)

========== filefind ==========

Searching for "scecli.dll"
C:\WINDOWS\$NtServicePackUninstall$\scecli.dll -----c 180224 bytes [04:10 29/12/2008] [12:00 10/08/2004] 0F78E27F563F2AAF74B91A49E2ABF19A
C:\WINDOWS\ServicePackFiles\i386\scecli.dll -----c 181248 bytes [07:35 27/08/2008] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\scecli.dll --a--- 181248 bytes [23:48 18/08/2006] [00:12 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084

Searching for "netlogon.dll"
C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll -----c 407040 bytes [04:10 29/12/2008] [12:00 10/08/2004] 96353FCECBA774BB8DA74A1C6507015A
C:\WINDOWS\ServicePackFiles\i386\netlogon.dll -----c 407040 bytes [07:34 27/08/2008] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\netlogon.dll --a--- 407040 bytes [23:47 18/08/2006] [00:12 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550

Searching for "eventlog.dll"
C:\Program Files\Protector Suite QL\eventlog.dll --a--c 23552 bytes [00:50 06/05/2006] [00:50 06/05/2006] 885972DF728A6C0600C0133DCF7CDD78
C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll -----c 55808 bytes [04:10 29/12/2008] [12:00 10/08/2004] 82B24CB70E5944E6E34662205A2A5B78
C:\WINDOWS\ServicePackFiles\i386\eventlog.dll -----c 56320 bytes [07:32 27/08/2008] [00:11 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656
C:\WINDOWS\system32\eventlog.dll --a--- 56320 bytes [23:47 18/08/2006] [00:11 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656

-=End Of File=-

Amy_Isaac
Beginner
Beginner

Posts Posts : 2
Joined Joined : 2009-08-17
OS OS : XP
Points Points : 26714
# Likes # Likes : 0

View user profile

Back to top Go down

Re: BankerFox.A...I can't get MWB to Run, Java to update etc

Post by Belahzur on 18th August 2009, 2:56 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum