Disappearing netbt.sys

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Coniver, May 14, 2015.

  1. Coniver

    Coniver Private E-2

    Hello! Thank you so much for your assistance!

    History:
    Two weeks ago Avira Free did not complete its scans anymore, and didn't create any completed logs (update error 556). Uninstall and re-install did not fix the problem.

    A week later the wired local area connection did not connect to the router anymore. The connection repair option showed an error message "cannot renew IP address". Pasting the missing netbt.sys from the ServicePack into the system32\drivers folder was only a temporary fix. It disappeared frequently.

    Running the Avira scan in safe mode revealed two instances of TR/Crypt.ZPACK.146939 in the System Volume Information and 51 instances of TR/Trash.Gen. I removed them. I toogled System Restore later. It also found ADWARE/CrossRider.Gen4 in cmdupd.exe of the Comodo Internet Security folder. I removed it.

    I also ran an AwdCleaner scan and removed several entries.

    Today:
    Avira completes scans, and the wired connection has so far still connected well. Avira, Malwarebytes and SuperAntiSpyware don't show any infection. However I am concerned if the initial TR/Trash and TR/Crypt viruses made space for other infections. HitmanPro apparently still found something in the attached log.

    PS. I had run HitmanPro before getting started with this thread, and now realize that I should not have deleted anything; by mistake I had deleted about a dozen entries. Sorry. I attached the log from my scan I did together with all the other instructed scans from today. Let me know if you need the HitmanPro log from several days ago with all the deletions.

    I appreciate your time. Thank you!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    :Files
    C:\WINDOWS\system32\63F7~2       
    C:\WINDOWS\system32\63F7~1        
    C:\WINDOWS\system32\141A~1        
    C:\WINDOWS\system32\A2B7~1
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    You have COMODO Internet Security Premium installed as well as Avira. What components of the Comodo suite are active? Firewall, antivirus. or just the firewall?
     
  3. Coniver

    Coniver Private E-2

    Attached is the OTM log.
    Comodo shows the Firewall and the Viruscope active, Sandbox is inactive.

    Thanks.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I see this file from your logs:

    C:\WINDOWS\system32\drivers\netbt.sys

    It's not missing now....
     
  5. Coniver

    Coniver Private E-2

    I was able to connect the last few days and the netbt.sys seems to stay.

    Should I do anything with the suspicious file found by HitmanPro? C:\WINDOWS\system32\RLAPEDec.ax

    Should I keep the viruscope in comodo active when I have avira free running as antivirus?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good.

    No it's fine.
    Sorry, thought you said before it's virus scanner was inactive. No, you shouldn't have the virusscope active when you have Avira installed, let alone running.

    Any firther issues before we wrap up? :)
     
  7. Coniver

    Coniver Private E-2

    So far so good.
    Thank you so much for your help!!!:)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds