help with malware removal
I have a nasty malware virus on my computer .. usual situation .. making all anti virus prog. i.e hijackthis, spybot etc read only wont allow me to open and redirecting websites in google etc
my msn also keeps signing out after 10 seconds
attached is my log
any help appreciated
Re: help with malware removal
Welcome to Major Geeks!
Why are you runningt with no protection installed?
Also what haven't you updated Vista to the current service packs? You don't even have SP1 and SP2 is already out.
First you must disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer
Uninstall the below software:
Java(TM) SE Runtime Environment 6
Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\sdra64.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto
O4 - HKLM\..\Run: [combofix] "C:\Windows\system32\CF16558.exe" /c "C:\ComboFix\C.bat"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopRock] C:\Users\LIGGY\AppData\Local\Temp\a.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
After clicking Fix, exit HJT.
Now download The Avenger by Swandog46, and save it to your Desktop.
After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.
Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
Now run Win32kDiag:
Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.
Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.
Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )
Then attach the below logs:
"There are 10 types of people in this world. Those who understand binary and those who don't."
Support Majorgeeks on Facebook:
|Thread||Thread Starter||Forum||Replies||Last Post|
|malware halps/malware removal not running||missin||Malware Removal||2||07-12-09 13:31|
|STOP 24 after removing malware and malware removal apps.||hankyknot||Hardware||0||02-19-09 09:21|
|Trying to follow malware removal procedure, but malware is preventing me?||eagerinsight||Malware Removal||4||12-12-08 01:17|
|Malware - Exists after running MalWare Removal||DebFisher||Malware Removal||2||10-08-08 15:26|
|Malware problem not fixed with Malware Removal instructions||aagarwal584||Malware Removal||9||12-27-07 01:19|