Win32:Niklas-Q{Worm} and Win32:Trojan-gen{Other} has infected my computer

Hello, I am new to this board and this is my first question.

It seem that I have been infected with both of the viruses noted in the subject line and my Avast v.4.8 Professional was unable to delete it.

Now since this has infected my computer and external HD, I cannot log onto the internet.

If someone can assist me in this issue, I would greatly appreciate it.

Thank you in advance!

Download malwarebytes http://filehippo.com/download_malwarebytes_anti_malware/
Update it and run a quick scan.Remove any infected item it finds after the scan is finished.
Then post back a log

Thanks. I couldn’t perform the Update function because that computer cannot log onto the internet but I am performing the Quick Scan right now and I will post the results.

Thank you very much! :slight_smile:

I suggest:

  1. Clean your temporary files.
  2. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
  3. Use MBAM (or SUPERantispyware or even Spyware Terminator) to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete them.
  4. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
  5. Make a HijackThis log to post here or this analysis site. Or even submit the RunScanner log to to on-line analysis.
  6. Clean your Hosts file (replacing it) with HostsMan tool.
  7. Disable System Restore and then reenable it again.
  8. Immunize your system with SpywareBlaster.
  9. Check if you have insecure applications with Secunia Software Inspector.

Here is the Scan Results and log of running Malwarebytes; I deleted the infected files, what should I do next?

Does not seem related to your problem.
Did you run avast at boot time? Why can’t avast delete them? Which were the error messages?

get the updater here : http://www.malwarebytes.org/mbam/database/mbam-rules.exe

yes and I have no idea why Avast was not able to delete them as Avast let me know there was a malware / Trojan Horse but said they were unable to locate it.

My computer’s internet access is still toast.

I installed the updater exe. file and I’m running another quick scan…btw, I deleted the 2 infected files. I hope I can log back into the internet and have this issue fixed today. :frowning:

I was trying your recommendations to rid the computer of the viruses, but Avast won’t let me re-boot the computer. See the attachment…

Well do you have removable media inserted, CD/DVD, USB Flash or external USB hard disk ?

Have you got avast checking/scanning removable media, Program Settings, Common section, (see image) ?

Yes and yes

Yes 1, if CD/DVD, USB Flash, then remove before shutting down, if external HDD I would still suggest only having it connected when required.

Yes 2, if you have something like an external HDD or even USB Flash connected normally on shutdown, I wouldn’t have these options selected as it will greatly slow shutdown due to them being scanned.

Yes 2a, I don’t believe external HDDs would be scanned on a boot-time scan, as far as I’m aware it is local HDDs (internal). In some instances the external HDD may not even be recognised before windows boots.

So to try a boot-time scan I would suggest you disconnect removable/external media to see if the boot-time scan will at least run.

Interesting, it scans them?
On my system it doesn’t seem that way, I thought it just checked to see if something was attached and interrupted the shutdown with the message…

I can’t see the purpose of simply checking if there is removable media in or attached to the system, that really isn’t the task of an AV, but perhaps the OS. To me check implies scan.

Well that is my assumption, given that the options refer to ‘Check other removable media when logging of.’ So it would entirely depend on what their definition of ‘other removable media’ is, mine would include USB Flash and loosely USB HDDs as to windows there is essentially no difference it sees it as a drive/removable storage.

I just placed the eicar file in the memory stick and tried to log off.

no alert on the file, just the removable media message.
Seems like it doesn’t scan…

Weird, I can’t see the purpose in that. Unless given what was said in another topic, fake shutdown trying to infect the system, could theoretically infect removable media.

Personally I have never changed these settings which are disabled by default.

Take care. eicar tests have limitations and you must know exactly what you’re doing before taking conclusions.
I’m not saying that you’re doing something wrong. Just take care.

Any recommendations on how i am going to restart my computer without have to do a hard shutdown?

Since a hard shutdown is a last resort, I am running Avast Virus Recovery Database Generator to see if this can repair any of the infected files and let me log into the internet.

If anyone has anymore ideas, please post them as I am ready to toss this computer out of the window…