![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
First of all, hello to everyone.
I got infected just like him: http://forums.majorgeeks.com/showthread.php?t=157182 Any anti-malware program finds exactly the same files. Should I proceed the same way? In my case, the rootkit disabled my soundboard. cheers, Filipe Last edited by filipetolhuizen; 09-21-08 at 22:17.. Reason: last changes |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks!
Please follow the instructions in the below link and attach the requested logs when you finish these instructions. READ & RUN ME FIRST. Malware Removal Guide
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#3
|
|||
|
|||
|
The malware is blocking CCleaner... I'm not being able to run it
|
|
#4
|
|||
|
|||
|
It seems that it's Bagle.GI (reported by XoftSpy, but not cleaned)
I can remove the files manually if I get the exact list. I have bootable linux from Pen Drive. I read rumours that even formatting the PC and reinstalling Windows it'll not go, is it actually true? |
|
#5
|
||||
|
||||
|
Quote:
Quote:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
filipetolhuizen (09-24-08) | ||
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Thank you very much for your attention. I managed to remove it by using Combofix.
Best Regards, Filipe |
|
#7
|
||||
|
||||
|
You're welcome.
Now we need to cleanup some items from running ComboFix. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#8
|
|||
|
|||
|
Sorry it took long. The registry strings were successfuly updated. Gonna try to do the next steps. One more thing: I noticed I cannot close most services in Task Manager. Is there anyway that I can repair this?
Last edited by filipetolhuizen; 09-28-08 at 21:52.. |
|
#9
|
||||
|
||||
|
I'm not exactly sure what "services" you are referring to but you should not be trying to kill services. The operating system will just restart them. This is normal.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#10
|
|||
|
|||
|
I know which services I cannot close. I always used to close the IPodService upon closing ITunes and now I can't do it through Task Manager because an access denied message always comes up. The only way I'm able to close it is through 'services' in admin tools.
|
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
That is the correct way to stop a service. If you don't want it to run, then stop it and set it to disabled.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#12
|
|||
|
|||
|
It's just that before I got this malware I could close them in the Task Manager. The one thing that worries me is when an app freezes and I cannot close it in the Task Manager because I get the same message (and logged in as admin). I'm sure it's something that needs to be repaired.
|
|
#13
|
||||
|
||||
|
Quote:
But it is not a topic for this forum as it is not malware. Please continue this in the Software Forum if you wish to pursue this further.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Rootkit.bagle and Rootkit.Agent - No Internet, No Safe Mode, No Antivirus | raremedium | Malware Removal | 14 | 04-19-08 22:48 |
| SmitFraud-C Rootkit.Win32.Agent.EQ | Hattenator | Malware Removal | 0 | 01-19-08 02:02 |
| Startpag.qr.dll1 & Rootkit.agent.af | pecunji | Malware Removal | 0 | 08-19-05 06:24 |
| can anyone pls help me remove Rootkit.Win32.Agent.l ? | captain oats | Malware Removal | 1 | 07-20-05 20:01 |