[ViRuS] FiX it - I pay

healzer

Elite Member
Joined
Jun 26, 2011
Messages
2,974
Reaction score
3,063
I have been a target by malware, rootkit, maybe even a bootkit.

I have searched google - no luck.
It's something new, it's been on the news 2 weeks ago, VPS are being targeted by a worm ,and these worms are then finding their way to the users main computers...

I have been a target, of maybe 2 rootkits, No AV can find them,

I tried IceSword & rootkitrevaler: I get error & cannot start them (rootkits are designed to eliminate them) doesn't work in safemode eaither.


I tried the Kaspersky recovery disc (fail)
I have ESET NOD32 AV
I tried to Reinstall Windows 7
I tried to isntall windows 7 on a other HDD

This virus multiplies from one drive to another...

The reason I HAVE FOUDN THIS VIRUS is because: My Online Bank Account gets a Malware Popup redirecting me to a website to unblock my account, which is fake & made by crackers.

It could also be possible that the Bank I use is the target, but I doubt it, Belgian banks are pretty secure

Any Forum you recommend for me to post my story?
I will pay - 20$ if you can find the problem. (or more)

I use GMER, if you want any log files just ask, I'm not a Security expert.

:pirate:
 
Last edited:
Type in cmd

msconfig

then check everything that is starting when your computer is booting. If it looks suspicious better uncheck it.
If you are not sure, just google the filename.
 
First, Google "autoruns" by Sysinternals and install that. Send me screen shots of your start up configuration.
Second, download HiJackThis and send me a report.
Third, send me your mapping from within your hosts file (not sure if it's the same on Win7 but should be in %system%\drivers\etc)
Forth, download avast! AV and run a boot-time scan.
Fifth, get Malwarebytes anti-malware and run a full scan.
Sixth, PM me your Skype or w/e you use.
 
use malwarebyte in safe mode or try to scan with kaspersky 2012 if yor are able to install
 
I will fix it for you. I will charge $30 - that is cheap:) I can do it now, I want payment up front, via paypal, I will come in via logmeinrescue - I will send you email link. Let me know via pm.

Btw if I cannot fix, I will give full refund.
 
David, if others are doing it for free let them try first. It's not that complicated.
 
I won't be able to pay right now, but I will promise to pay if you fix it, at the beginning of september, thats when my Affiliate pays me (8th sept, I get the Cash)
@Crazy: I will do it right now
@ericsson, add me on skype

(skype: healthchants)
 
@davids355: Go away with your red earned pennies. I can fix it in less than 30 mins for free but since ericsson already offered his help to OP, thanks ericsson.
 
You could try booting with Hirens BootCD (hiren [d0t] info) and using some of those tools, a couple of the tools people have already mentioned are on there.

You won't be booting to windows so you'll have a better chance of finding the problem and getting rid of it. You may need to change a BIOS setting for the boot order, so the CDROM is before the infected HDD.

Good luck.
 
@davids355: Go away with your red earned pennies. I can fix it in less than 30 mins for free but since ericsson already offered his help to OP, thanks ericsson.

Calm calm, anyone would jump up if they hear someone is paying you for things you used to do usually. :rolleyes:

If he is good in fixing it up, and if he see someone is paying for it, he will jump up, or even I would if I knew. :p
 
@davids355: Go away with your red earned pennies. I can fix it in less than 30 mins for free but since ericsson already offered his help to OP, thanks ericsson.

I'm not arguing because I noticed people don't do it here.

I repair pcs and remove viruses every day, I know from experience these things are "sometimes" easy - if you can go in Msconfig (if your a noob) or hjt if your a pro and take out the prob and it's sorted, but sometimes it's not that easy, sometimes the redirect is built in to the tcp stack and sorting the problem is different story - so I'm not going to offer to do it for free or I might regret it. I also know that often (very often) people who know a little bit can cause more problems, I offered a fair price around what op wants to pay.

If I buy articles/link pushes I don't mind paying the pro's - as I don't have the skills! So I don't feel guilty charging for what I am good at.

Anyway, I don't mean ANY offence to anyone, as I said I will happily give step by step to op if he wants to do the work, and I am also happy to offer my services.

IF op gets it fixed free-great, if you still have issues, send me a PM.
 
I have been a target by malware, rootkit, maybe even a bootkit.

I have searched google - no luck.
It's something new, it's been on the news 2 weeks ago, VPS are being targeted by a worm ,and these worms are then finding their way to the users main computers...

I have been a target, of maybe 2 rootkits, No AV can find them,

I tried IceSword & rootkitrevaler: I get error & cannot start them (rootkits are designed to eliminate them) doesn't work in safemode eaither.


I tried the Kaspersky recovery disc (fail)
I have ESET NOD32 AV
I tried to Reinstall Windows 7
I tried to isntall windows 7 on a other HDD

This virus multiplies from one drive to another...

The reason I HAVE FOUDN THIS VIRUS is because: My Online Bank Account gets a Malware Popup redirecting me to a website to unblock my account, which is fake & made by crackers.

It could also be possible that the Bank I use is the target, but I doubt it, Belgian banks are pretty secure

Any Forum you recommend for me to post my story?
I will pay - 20$ if you can find the problem. (or more)

I use GMER, if you want any log files just ask, I'm not a Security expert.

:pirate:

Its not recomended to install AV programs on a infected computer, but if you like you could do online scans

Do you know the name of the worm?
 
My bank which I use has told me to scan with the HouseCall.Trendmicro AV shit, it didn't find anything , I didn't expect it to find anything...

people , this is a TARGETED attack, people have control over the worm they are spreading, it's not on auto-pilot...

Crazy & ericcson have been helpful, but we are still trying to find the prob...

Watch out, if you have a VPS, then the chance of you being targeted is 60% :p
 
Back
Top