I need help. Nothing is working for me!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ~BeCcI~, Jul 28, 2008.

  1. ~BeCcI~

    ~BeCcI~ Private E-2

    Hi everybody, I'm new to this whole forum thing so sorry for any blonde questions etc.

    Well i've had this "Worm.Win32.NetBooster" virus thing on my computer since yesterday. It has put 3 icons on my desktop, has changes the background to white and put virus alert! near the time and so on... i'm sure you know the effects...

    Well i've tried to procedures...
    first one.

    Follow the steps below to clean your machine:

    Try to perform a full Antivirus/Antispyware scan but in SAFE MODE WITH NETWORKING.

    1. Disable system restore;
    2. Reboot in SAFE MODE WITH NETWORKING
    3. Manual run ZASS (ZA firewall will be OFF but Antivirus/Antispyware will be functional)
    4. Set ZA antispyware to 'deep scan' (advanced options of the antivirus/antispyware tab)
    5. Run a full ZA AV/AS scan
    6. Reboot in Normal Mode
    7. Ensable System restore
    8. Restore ZA antispyware to default scan

    DIDN'T WORK!


    and

    Download SmitFraudFix to your Desktip from one of the below links and use the steps indicated for either link which are slightly different.

    Primary Download Link: SmitfraudFix (by S!Ri)
    The above link is to a file named SmitFraudFix.zip. Save this file to your Desktop.
    Now double click the ZIP file on your Desktop and Extract the contents to your Desktop too. This will create a SmitFraudFix folder on your Desktop.
    Double click the SmitFraudFix folder to open the folder.
    There will be two parts to how we will use SmitFraudFix
    Searching
    Cleaning
    Double click the smitfraudfix.cmd file to start the tool.
    Now jump down to Step 1 below.
    Alternate Download Link: SmitFraudFix (byS!ri)
    The above link is to a file named SmitFraudFix.exe. Save this file to your Desktop.
    There will be two parts to how we will use SmitFraudFix
    Searching
    Cleaning
    Double click SmitFraudFix.exe to extract all the files to your Destop. This will create a SmitFraudFix folder on your Desktop. And it will automatically start running the program..
    Now jump down to Step 1 below.
    Note: process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.
    http://www.beyondlogic.org/consulting/proc...processutil.htm

    STEP 1: Searching for the infection!

    You should now see the below window on your monitor (click to enlarge the thumbnail).

    Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt
    Attach this current C:\rapport.txt log file to a message in your thread now before before doing the second step of the procedure or you will overwrite and loose this info. (See: HOW TO: Attach Items To Your Post )
    STEP 2: Cleaning the infection!

    Please print out or copy these instructions to Notepad as the internet may not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
    Reboot your computer into Safe Mode : Starting your computer in Safe mode
    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.
    Select 2 and hit Enter to delete infect files.
    You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
    A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt Don't forget to attach this new log to your next message after you finish running the cleaning step and reboot into normal mode.


    So can anyone Help me please. I'm losing hope. :cry
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. ~BeCcI~

    ~BeCcI~ Private E-2

    Hi, I'm halfway through the READ & RUN ME FIRST. Malware Removal Guide and I logged into my partners name to run the CCleaner and he hasn't got the virus or any sings of it. I'm still going to continue with the READ & RUN ME FIRST GUIDE steps guide but i'm just wondering is it normal for only one log on to have the virus?:confused
    Or would it work if I deleted my logon? or is it in the computer so it would be pointless?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is not unusual for one profile to be infected and not others....we often need to run the scans on each user account even after they are run from an administrator account......which is what you should do first and attach the logs. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds