I had the same problem last night with the Win32/nuquel.E & Bankerfox.A. I managed to download Malware Bytes onto a thumb drive and run it on the infected computer. The virus is clean but now I can not access the internet at all from that computer.
When I attempt to access the internet, I get "Internet Explorer cannot display the webpage". (IE 8) I diagnose connection problems and it states that My port 80, 443 & 21 connections are disabled.
Below are my two Malware Bytes logfiles
#1:
Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
2/1/2010 7:05:10 AM
mbam-log-2010-02-01 (07-05-10).txt
Scan type: Quick Scan
Objects scanned: 112774
Time elapsed: 6 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\plvwjkps (Trojan.FakeAlert.N) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\plvwjkps (Trojan.FakeAlert.N) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
#2:
Malwarebytes' Anti-Malware 1.44
Database version: 3510
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
2/1/2010 9:21:57 AM
mbam-log-2010-02-01 (09-21-57).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 174347
Time elapsed: 46 minute(s), 27 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\(name deleted)\Local Settings\Application Data\tubeyf\oldwsysguard.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\(name deleted)\DoctorWeb\Quarantine\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
I am posting this on several forums, as I need to get this computer up and running as quickly as possible. I am not terribly knowledgeable about system processes and computer jargon so if you can help me, please provide details. I have tried fixes on several tech websites such as this one and nothing has worked at all. (Internet Options/Connections/LAN Settings; ip reset; etc.)
Thank you!!