Please help to clean this machine

Discussion in 'Malware Help (A Specialist Will Reply)' started by vkinetic, Jun 26, 2009.

  1. vkinetic

    vkinetic Private First Class

    Logs attached. Please note that CombiFix could not run in either normal or safe mode - error reported was 'This file has been compromised - please download a freash copy from......'. Could not download from the bleepingcomputers site and downloaded twice from MajorGeeks with the same result. Also, SuperAntiSpyware crashes out before completion, even with the Kernel settings in the scan settings unchecked. IE6 is being redirected in normal mode despite previous attempts to clean the machine. These logs are uploaded using Safe Mode with networking. Smitfraud had been reported by Spybot in earlier attempts to clean the machine - attached is Rapport01.log (to identify instances) and in the next post Rapport (created after running the
    Smitfraud fix)

    Thanks for your help
     

    Attached Files:

  2. vkinetic

    vkinetic Private First Class

    Final Smitfraud fix log.

    Thanks
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to bring you the bad news but this is an example of what can happen when a PC is being used with no protection.

    I can see the reason for your problems. You have multiple infections. However your logs show that one of them (a Virut infection) has infected your Windows Operating system files and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
  4. vkinetic

    vkinetic Private First Class

    Thank you chaslang. I has more or less come to the same conclusion but thought it worth a try.

    Your comments are very much appreciated.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely and avoid the activities that resulted in this infection. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds