![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I've been dealing with zero access rootkit and other malware for a week now..
Can't run most programs, or get online and can't seem to access ip configuration address. Any help would be greatly appreciated. Ran malware, super antivirus and combo fix...results below. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Hi and welcome to Major Geeks, deeps!
Now we need to run TDSSKiller by KasperskyFollow the instructions here and attach your log when you are finished. (How to attach items to your post) Have you attempted going through this yet? READ & RUN ME FIRST. Malware Removal Guide If not, you need to at this time. Let me know what did not run. You don't have to complete the scans you have already completed again. |
|
#3
|
|||
|
|||
|
Yes, i have done the read and run me malware removal...followed the steps.
Here is the tdsskiller log...thanks again. |
|
#4
|
||||
|
||||
|
You made no mention of MGlogs.zip. Please attach that file if you were able to run MGtools.exe
Also attach the log from running DeFogger. Then complete the following:
|
|
#5
|
|||
|
|||
|
Apologize for the missing files...thanks again for all the help.
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
From Add/Remove Programs (via Control Panel), please uninstall the below:
Please download Disable/Remove Windows Messenger by Doug Knox to your desktop.
Put your computer back into Normal Startup Mode and reboot before proceeding to the next step >> Use MSconfig to setup for Normal Startup Mode buttonNote: This automatically updates the OTL.txt log on your desktop. Attach OTL.txt to your next message. (How to attach items to your post Then attach C:\MGlogs.zip to your next message. (How to attach items to your post) Notes:
LET ME KNOW HOW THE PC IS RUNNING AFTER YOU HAVE COMPLETED THESE STEPS Last edited by thisisu; 10-24-11 at 22:04.. Reason: ipsec entry |
|
#7
|
|||
|
|||
|
Attached the OTL run fix and scans but can't access C:\MGtools\GetLogs.bat
Getting an error stating 'Windows cannot find 'C:\MGtools\GetLogs.Bat'. Make sure you typed the name correctly, and then try again.' Still can't access the internet. |
|
#8
|
||||
|
||||
|
Quote:
Inside you will see a bunch of files, look for the one named GetLogs.bat Then double-click GetLogs.bat. Let this run unhindered. Afterwards, attach the MGlogs.zip file -- It's at C:\MGlogs.zip |
|
#9
|
|||
|
|||
|
I understand, i tried that, when i double click the file GetLogs.Bat in the MGTools folder, that's the error prompt i get.
|
|
#10
|
||||
|
||||
|
Please download Tweaking.com - Windows Repair by Tweaking.com to your desktop.
Code:
KillAll:: DirLook:: c:\mgtools FileLook:: c:\mgtools\getlogs.bat c:\mgtools.exe C:\WINDOWS\system32\drivers\ipsec.sys C:\WINDOWS\system32\dllcache\ipsec.sys Folder:: C:\WINDOWS\$NtUninstallKB33688$
Please download SystemLook by jpshortstuff to your desktop.
|
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Ran tweaking window repair unhindered even though a prompt box kept telling me 'execute processes remotely has encountered a problem and needs to close.'
...rebooted after program finished. Dragged CF Script file into combofix and froze up on last command Output folder C:\32788R22FWJFW Rebooted manually in safe mode w/ networking. |
|
#12
|
||||
|
||||
|
Quote:
Quote:
Quote:
You can try the same steps from Safe Mode with Networking if you need to. |
|
#13
|
|||
|
|||
|
Quote:
|
|
#14
|
||||
|
||||
|
Quote:
Let's try the some of the same fixes another way. Now download exeHelper by Raktor.
Please download Win32kDiag to the root of your C:\ drive. It must be saved here or the below will not work!
Download Junction by Mark Russinovich to your desktop.
After junction, try the CFScript and SystemLook directions again.
|
|
#15
|
|||
|
|||
|
the exe.helper DL came up as a trojan threat and was quarantined by AVG
|
| Sponsored links |
|
|
|
#16
|
||||
|
||||
|
Did you install AVG or any other AntiVirus recently?
|
|
#17
|
|||
|
|||
|
No, i'm Dling all the files through a separate laptop and using thumb drive to my infected desktop.
|
|
#18
|
||||
|
||||
|
Quote:
Run the Microsoft FixIt tool from Normal Mode whenever you get to that step |
|
#19
|
|||
|
|||
|
So just bypass the exehelper command?
|
|
#20
|
||||
|
||||
|
|
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Rootkit or malware. | chappychapman | Malware Removal | 9 | 11-18-10 10:25 |
| malware and rootkit infection | BigDatC | Malware Removal | 14 | 10-08-10 18:19 |
| May have malware/rootkit but not sure | itshothere | Malware Removal | 3 | 01-16-10 17:39 |
| help ! rootkit, malware, spyware ? | mattmatt | Malware Removal | 3 | 11-30-09 22:23 |
| Is this malware/rootkit? | Hum | Malware Removal | 1 | 01-08-09 11:45 |