bankerfox.a and win32/nugel.e viruses

Page 1 of 4 1, 2, 3, 4  Next

View previous topic View next topic Go down

bankerfox.a and win32/nugel.e viruses

Post by CRC on Fri 09 Jul 2010, 2:58 am

Both of the viruses have appeared on my computer. They will not permit me to use explorer or safari to access the internet. i am not able to access any web sites or download any programs. What should i do from here?

CRC

I am sending this from another computer i will not be with the infected computer until 7 pm central time, usa


Last edited by CRC on Fri 09 Jul 2010, 3:01 am; edited 1 time in total (Reason for editing : more info)

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Belahzur on Fri 09 Jul 2010, 3:21 am

Hello.

Remove the Proxy setting in Internet Explorer and/or in FireFox.

    In Internet Explorer
  1. Tools Menu -> Internet Options -> Connections Tab ->Lan Settings > uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox
  1. Tools Menu -> Options... -> Advanced Tab -> Network Tab -> "Settings" under Connection > Choose "No Proxy"
  2. Click the apply button and restart that computer in normal mode.

See if the infected machine can access the internet now.

Download OTL by OldTimer to your Desktop.

  • Close all windows and double click OTL.exe
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
  • You may need to use two posts to get it all.


@RealBelahzur - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur

Manager | Tech Officer
Manager | Tech Officer

Posts : 34917
Joined : 2008-08-04
Operating System : XP SP3 Media Centre

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Fri 09 Jul 2010, 11:02 am

Ok...I have tried step one but unable to connect to the internet. I looked over the steps and my proxy server box was checked again, so i repeated the steps but still no internet.

For some reason the box is checked everytime i return to the LAN settings window. It also will not give me the option to click "apply".

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Fri 09 Jul 2010, 11:10 am

The proxy server box is checked everytime i return to the LAN settings window. When i uncheck it i don't have the option to click "apply"

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Belahzur on Fri 09 Jul 2010, 11:14 am

Okay, guess we will need to use another method.
Can you download programs from a working machine with internet access and transfer tools across via USB/external hardware?


@RealBelahzur - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur

Manager | Tech Officer
Manager | Tech Officer

Posts : 34917
Joined : 2008-08-04
Operating System : XP SP3 Media Centre

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Fri 09 Jul 2010, 11:23 am

I'm having trouble navigating this site...the only way i can view your response is to back up a select the preview button.

But ok...uhhh i am on a wireless laptop from work and i don't think i have a cable to connect the two

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Fri 09 Jul 2010, 11:26 am

will a ethernet cable work

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Fri 09 Jul 2010, 11:34 am

This is frustrating....i am not viewing any new posts or replies in the forum underthis topic....i know they are there i'm just not geting them

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Fri 09 Jul 2010, 11:56 am

lets try this again....seems to be working now

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Fri 09 Jul 2010, 12:53 pm

Belahzur?......Belahzur?

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Belahzur on Sat 10 Jul 2010, 4:39 am

Have some patience, I do tend to sleep ever now and then you know. Is the site working now?


@RealBelahzur - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur

Manager | Tech Officer
Manager | Tech Officer

Posts : 34917
Joined : 2008-08-04
Operating System : XP SP3 Media Centre

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Sat 10 Jul 2010, 2:09 pm

ok.....still no change on the virus

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Sat 10 Jul 2010, 2:29 pm

I have a transfer cable now to help witht the solution

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Sat 10 Jul 2010, 5:42 pm

I transferred the otl file via flash drive to the infected computer and tried to run it. I got an error message saying "otl.exe is not a valid win32 application"

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Sun 11 Jul 2010, 5:19 am

Now now......are you asleep again?

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Belahzur on Sun 11 Jul 2010, 5:21 am

Hello.

We need to use the RKill Tool by Grinler

Rkill.com <--- Download site

  • Please Download Rkill.com. Save it to your Desktop.
  • Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.

  • NOTE: If you are unable to connect to the site to download rkill, then you should download it to a clean computer and copy it to the infected one via a USB flash drive or CDROM.

  • Once it is downloaded, double-click on the rkill.com in order to automatically attempt to stop any processes associated with Rogue programs.
  • Please be patient while the program looks for various malware programs and ends them.
  • When it has finished, the black window will automatically close and you can continue with the next step.
NOTE: If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by the rogue program, when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate the rogue program. So, please try running Rkill until the malware is no longer running. You will then be able to proceed with the rest of the steps.

If you continue having problems running rkill.com, you can download:
iExplore.exe or eXplorer.exe
which are renamed copies of rkill.com, and try them instead.

Try OTL now.


@RealBelahzur - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur

Manager | Tech Officer
Manager | Tech Officer

Posts : 34917
Joined : 2008-08-04
Operating System : XP SP3 Media Centre

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Sun 11 Jul 2010, 7:07 am

I downloaded the rkill program to a flash drive installed it on the infected computer, ran the program which gave me a black box then a white box of the reults.

Then i double clicked on the otl program but same error message appeared, "Not a valid win32 application"

ARRGH

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Belahzur on Sun 11 Jul 2010, 8:10 am

Hello.

Please download OTH.scr to your desktop

Save all work and close all programs, the next step will stop nearly every process on your computer!

Double click the OTH file and select Kill All Processes, your desktop will go blank



Then select Start OTL
OTL will now run

  • Double-click on the Custom Scans box and a message box will popup asking if you want to load a custom scan from a file
    Select Scan.txt that you downloaded

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Copy and paste the contents back here.


@RealBelahzur - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur

Manager | Tech Officer
Manager | Tech Officer

Posts : 34917
Joined : 2008-08-04
Operating System : XP SP3 Media Centre

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Sun 11 Jul 2010, 12:21 pm

Not able to start the program.....when i try to open the file i get the security warning, "Application cannot be executed. the file oth.scr is infected. Do you want to activate your antivirus software now?

This is the same message i get when trying to open any file, including my ad-aware and ad-watch?

ETA: After playing with the computer i was able to Get the ot helper box to saty on the screen long enough to select kill all processes, which blanked the desktop. Next i selected start otl which i wasn't sure if it was running or not, the screen stayed the same. I let the program run all night and the screen is still the same, an empty desktop and the otlhelper box in the upper left corner.

CRC

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Belahzur on Mon 12 Jul 2010, 7:54 am

Hello.

Please then reboot your computer in Safe Mode by doing the following :

  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

Try OTL In Safe Mode please.


@RealBelahzur - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur

Manager | Tech Officer
Manager | Tech Officer

Posts : 34917
Joined : 2008-08-04
Operating System : XP SP3 Media Centre

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Tue 13 Jul 2010, 3:00 pm

Does not work that way either

I feel like we're missing something because so many things are not working

CRC

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Belahzur on Wed 14 Jul 2010, 9:07 am

We are going to be using a Windows Recovery Environment to help disinfect the system so it may boot again.

Download the OTLPE Standard REATOGO Windows Recovery Environment.
  • Place a blank CD-R disc in to your CD burning drive.
  • Download OTLPEStd.exe and double-click on it to burn to a CD using ISO Burner.
  • Reboot your system using the boot CD you just created.

    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to Non-Microsoft
    • Press Run Scan to start the scan.
    • When finished, the file will be saved in drive C:\_OTL\MovedFiles
    • Copy this file to your USB drive if you do not have internet connection on this system
    • Please post the contents of the OTL.txt file in your reply.


@RealBelahzur - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur

Manager | Tech Officer
Manager | Tech Officer

Posts : 34917
Joined : 2008-08-04
Operating System : XP SP3 Media Centre

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Thu 15 Jul 2010, 3:11 am

Ok.....i burned the disc using my non infected computer (an old 486 that is barely running), so how do i get the REATOGO-X-PE on the desktop of my infected computer in order to follow the rest of the directions?

CRC

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Belahzur on Thu 15 Jul 2010, 9:52 am

Hello.
You need to burn the disc with ImgBurn.


@RealBelahzur - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur

Manager | Tech Officer
Manager | Tech Officer

Posts : 34917
Joined : 2008-08-04
Operating System : XP SP3 Media Centre

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by CRC on Thu 15 Jul 2010, 3:04 pm

I don't know what imgburn is.

CRC

Rookie Surfer
Rookie Surfer

Posts : 106
Joined : 2010-07-09
Operating System : xp

View user profile

Back to top Go down

Re: bankerfox.a and win32/nugel.e viruses

Post by Sponsored content Today at 9:16 am


Sponsored content


Back to top Go down

Page 1 of 4 1, 2, 3, 4  Next

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum