Nasty Rootkit removal help required

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JonLy, Sep 3, 2009.

  1. JonLy

    JonLy Private E-2

    Hi

    After scouring the internet for help with this i found a site that explained about using UBCD4WIN to remove trojans etc, so i tried that and found that SAS removed something, i think that it was called Trojan/GenA (or something similar). I thought that was the end of it and started using my laptop again. But it wasn't!!!! so I have run through the instructions in the 'Read & Run me first' and then started on the Vista Cleaning procedure. These are my results:



    First I ran SuperAntiSpyware, logged on as local administrator but it did not find anything, results are in the SASlog.txt file attached

    As the sas scan took a while i left it running over night and then took my laptop to work to continue with the instructions. I brought my laptop out of standby but it blue screened and rebooted. I get this error when i login, 'Windows encountered a critical problem and will restart automatically in one minute. Please save your work now' so now i can only log into safe mode. So i carried on in safe mode.



    I then ran Malwarebytes Anti-Malware but it terminated a few seconds after starting, when i restart it i get a message saying i do not have the appropriate permissions.

    I then tried to run ComboFix, it started and the progress bar completed, I waited for 10 minutes but nothing happens.

    I then tried to run RootRepeal but it also terminates after a few seconds, i do manage to see that it finds a few things locked to the locked to windows API.

    and finally tried to run MGtools, which flashes a dos box up and then terminates.

    My symptoms are that I get bogus virus messages from my AV (Kaspersky 6) and when i run a removal program (as above) they terminate, and then when i try again i get a permission denied message. I can not even login to the laptop, except for safe mode.

    Please help!!

    Cheers
    Jon
     

    Attached Files:

  2. JonLy

    JonLy Private E-2

    Hi me again, I've managed to run some of the removal programs so here are the logs. Please help I'm getting to the point where i am going to have to format and reload my os.
    Cheers
    Jon
     

    Attached Files:

  3. JonLy

    JonLy Private E-2

    sorry for yet another reply, i've read the rules about bumping, but i thought that these logs were important. Anyway here is another one from MGtools.
    Cheers
    Jon
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    • Can I ask you, when you ran MGTools did you receive any error messages at all? If so could you try your best to remember what they were, or even better if you noted them down. Perhaps your protection software may have got in the way
    • Also could you tell me if perhaps you could have exited out of the program before it ran completely?
    • Did you agree to the Hijackthis license agreement?

    Thanks
    Kes13!
     
  5. JonLy

    JonLy Private E-2

    Thanks for your reply, but I finally gave in and have reloaded my PC.

    Cheers
    Jon
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry to hear that. Safe surfing :wave
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds