windows/system32\drivers\ndiswan.sys file infected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ranchbabe, May 31, 2011.

  1. ranchbabe

    ranchbabe Private E-2

    I have gone through the procedures outlined in Chaslang's thread for removing malware with the exception of the combofix as I could not uninstall AVG. Things were humming along. Then ran an AVG scan at end of it all and it found two files of which one was taken to the vault and the above file remains with 'white listed warning'. Any suggestions? - it is now 4:13 am and I have to get up for work at 6:00 so will check back. I appreciate any info being offerred, thanks so much.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to tell me what the file is that you are describing.

    You should also attach the requested logs if you have been through Chaslang's procedures.
     
  3. ranchbabe

    ranchbabe Private E-2

    it's a hard drive file c:\WINDOWS\system32\drivers\ndiswan.sys

    virus is trojanhorse BackDoor.Generic 13.BKVZ

    Does that help

    tried to add the avg.log.cab file but said it was invalid
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still need to attach these logs:
    ComboFix
    C:\MGLogs.zip
     
  5. ranchbabe

    ranchbabe Private E-2

    i could not run combofix as i was unable to uninstall AVG, here is mgtools log
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ask Toolbar <--- Uninstall this.

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :files
    C:\Documents and Settings\Owner\Local Settings\Application Data\{AC54ECB7-10EA-4AEA-9EA2-D918A13F406C}
    C:\Documents and Settings\All Users\Application Data\22404900
    C:\Documents and Settings\All Users\Application Data\~22404900
    C:\Documents and Settings\All Users\Application Data\~22404900r
    C:\windows\Jlizikapakukak.bin
    
    
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Please go to virustotal and upload the following files for analysis, and let me know the results.

    C:\WINDOWS\system32\drivers\nfau.sys


    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      ndiswan*
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds