MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 07-04-12, 13:41
mooth mooth is offline
Private E-2
 
Join Date: Jul 2012
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Default C:\Windows\System32\drivers\smb.sys

Hi

I've gone through the malware removal guide up to step 4 but AVG is still popping up telling me I have Trojans in System32 and it can't do anything about the smb.sys one. I havent had the internet for a few weeks and as soon as I got internet access at home these things kept on popping up. Just before I lost internet access I downloaded some games a few of which never worked, that's the only place I can think it would have come from but I've never had a problem before.

I've attached 3 of the 4 files but the Hitman Pro log says it's an invalid file so I've had to paste it below

<?xml version="1.0"?>
-<Log filesProcessed="18020" timeSpentInSecs="292" date="2012-07-04T18:33:00" version="3.6.0.160" scan="Normal" computer="HOME-PC">-<Item status="None" score="119.0" malwareName="Malware" type="Malware">-<Scanners><Scanner name="Gen:Variant.Barys.2378 (Engine A)" id="G Data"/><Scanner name="Trojan.Hosts.5758" id="DrWeb"/><Scanner name="Trojan.ZeroAccess!IK" id="Ikarus"/></Scanners><File hash="C24D0F2ADF13FC5AC12F3EACD3D155AE368CD542BFA6CAF1A958DAD0C596A359" path="C:\Windows\system32\drivers\smb.sys"/></Item></Log

Thanks a lot for any help.
Attached Files
File Type: txt RKreport[1].txt (1.4 KB, 7 views)
File Type: txt mbam-log-2012-07-04 (00-11-23).txt (2.3 KB, 7 views)
File Type: zip MGlogs.zip (607.5 KB, 7 views)
Reply With Quote
Sponsored links
  #2  
Old 07-04-12, 17:26
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: C:\Windows\System32\drivers\smb.sys

Welcome to MajorGeeks, mooth

Let HitmanPro Replace this detection.
Then rescan with HitmanPro and attach the latest log. You need to attach it as a .zip as the forum does not allow .xml. This is explained in the instructions on how to obtain the log.

Reviewing the rest of your logs now.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #3  
Old 07-04-12, 17:38
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: C:\Windows\System32\drivers\smb.sys

From Programs and Features (via Control Panel), please uninstall the below:
  • AVG 2012
  • Java(TM) 6 Update 31
  • Java(TM) 7 Update 4
  • Java(TM) SE Development Kit 7 Update 2

__

Please download and run AVG Remover

__

Please download and run ComboFix and attach its log.
Read these instructions on how to use it: How to use ComboFix
Do not uninstall ComboFix yet as we may need it to fix remaining malware issues.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
  #4  
Old 07-05-12, 16:59
mooth mooth is offline
Private E-2
 
Join Date: Jul 2012
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: C:\Windows\System32\drivers\smb.sys

I did what you said but combofix sat doing nothing for ages, it said it was scanning and would normally take ten minutes but could easily take double but I left it for 40 minutes and it didn't say anything else and now my recycle bin keeps telling me it's corrupted for some reason.
I've attached the HitmanPro log, I don't seem to be having any problems but it's not been that long.
Why have I got rid of AVG?
Attached Files
File Type: zip log.zip (630 Bytes, 4 views)
Reply With Quote
  #5  
Old 07-05-12, 18:11
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: C:\Windows\System32\drivers\smb.sys

Did you uninstall AVG?
The reason I requested this is to increase the chance of ComboFix running successfully.

__

Try deleting these manually:
  • C:\ProgramData\Ask <-- Folder
  • C:\Windows\$NtUninstallKB14204$ <-- ZeroAccess folder

__

Let me know if you were successful or not and then experiment with the PC some more and let me know if there are any other problems.
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Sponsored links
  #6  
Old 07-09-12, 12:40
mooth mooth is offline
Private E-2
 
Join Date: Jul 2012
Posts: 3
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: C:\Windows\System32\drivers\smb.sys

I did uninstall AVG. I deleted Ask but I couldn't delete $NtUninstallKB14204$ but it seems to have been on my computer for ages. ComboFix still didn't run but it's been a few days now and I havn't had any problems so it looks like it's fixed.

Thanks
Reply With Quote
  #7  
Old 07-10-12, 14:12
thisisu's Avatar
thisisu thisisu is offline
Malware Consultant
 
Join Date: Apr 2006
Location: Houston, TX
Posts: 8,143
Thanks: 263
Thanked 1,409 Times in 1,348 Posts
Default Re: C:\Windows\System32\drivers\smb.sys

I understand the computer is working fine but that folder is actually a trace of ZeroAccess. These types of folders do not belong on Vista/7 computers.

Here is the recommended action:

Please download BlitzBlank to your desktop.
  • Double-click BlitzBlank.exe to open (Vista/7 right-click and select Run as Administrator)
  • Press OK at the warning prompt.
  • Click the Script tab
  • Copy the text inside the code box below and paste it into the text-field.
Code:
DeleteFolder:
C:\Windows\$NtUninstallKB14204$
  • Now click the Execute Now button.
  • The fix will require a reboot in order to complete successfully.
  • Upon reboot, locate C:\blitzblank.log and attach this log to your next message. (How to attach)
__________________
Facebook . Twitter . Blog . VirusTotal
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
\windows\system32\DRIVERS\AVGIDSEH.Sys thelewisfam Software 13 01-19-12 19:33
c:\windows\system32\drivers\ndis.sys jaxsgeek Software 1 08-21-08 04:47
WINDOWS\System32\Drivers\Mup.sys XP won't boot andromeda623 Software 0 01-26-08 15:33
windows\system32\drivers\detect.htm ??? Dolo20 Malware Removal 3 12-12-07 10:29
WINDOWS\System32\Drivers\Mup.sys XP won't boot mhmcleod Software 3 03-11-07 07:52


All times are GMT -5. The time now is 15:49.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger