Pls, I need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by sokar, Mar 17, 2008.

  1. sokar

    sokar Private E-2

    Hi everyone,

    I think I`ve got a spyware or some kind of trojan. It takes about 2 min to startup my system. I have Kaspersky internet security 7 on my system and although it set to startup with the system, since the problems began, it`s starts up last after the trojan (I think) loads first. I did online scans at Bitdefender (found nothing), Nod32 (found some viruses which I manually deleted - html pages), Kaspersky (give me a list of objects that are locked which it skipped). But this did not solve the problem. Than I run your guide READ & RUN ME FIRST_ Malware Removal Guide. Still nothing. I think the trojan is embaded dip into the system. In the last 6 day I installed my system (win xp sp2 pro) about 5 time due to system erors and network crashes.
    From the list which Kaspersky online scan gave me, after a google search, I manually deleted this files:
    C:\Documents and Settings\Mike\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    C:\WINDOWS\system32\drivers\fidbox.dat
    C:\WINDOWS\system32\drivers\fidbox.idx
    C:\WINDOWS\system32\drivers\fidbox2.dat
    C:\WINDOWS\system32\drivers\fidbox2.idx
    C:\WINDOWS\system32\drivers\kl1.sys
    C:\WINDOWS\system32\drivers\klick.dat
    C:\WINDOWS\system32\drivers\klif.sys
    C:\WINDOWS\system32\drivers\klin.dat
    C:\WINDOWS\system32\drivers\klop.dat
    C:\Documents and Settings\Mike\Local Settings\Temp\~DF77F8.tmp

    After this operation my antivirus (Kaspersky Internet security 7) crashed completly. I also did a scan with Sophos Anti-Rootkit(MajorGeeks Support Forums), turned up empty, dead end.
    I am lost. I need some help. I`ve attached the 3 files which I kindly ask you to look at.
    Thanks in advance.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That would be because you removed files that Kasperski needs to run. I would suggest that you use Killbox restore to replace all but:
    C:\!KillBox\~df3def.tmp
    C:\!KillBox\~df4ba3.tmp
    C:\!KillBox\~df77f8.tmp
    C:\!KillBox\~df77f~1.tmp

    Or just do a system restore ...I'm not seeing any malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds