RUcrzy trojan wont stay removed

Discussion in 'Malware Help (A Specialist Will Reply)' started by runlittlejimmy, Apr 28, 2007.

  1. runlittlejimmy

    runlittlejimmy Private E-2

    Ndis.sys is 168,192 bytes
    created on 3-10-03
     
  2. runlittlejimmy

    runlittlejimmy Private E-2

    Files im talking about copying over are some like the ones in this picture. This is the process's running for explorer.exe. and system restore only comes up with a blank white screen to, i almost have to be missing some sort of files right or no.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to copy them and in some case your would not be able to overwrite them anyway since the OS has them in use.

    Is the size & date of ndis.sys you just gave me from your laptop or the problem PC?
     
  4. runlittlejimmy

    runlittlejimmy Private E-2

    ohh i just though you could use killbox and replace the files on restart
     
  5. runlittlejimmy

    runlittlejimmy Private E-2

    the problem pc

    the labtop is 182,912 bytes
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please be more careful in the future. I did not ask for this!

    I would like you to get a copy of the ndis.sys file from your laptop into your problem PC's c:\windows\system32\drivers folder. Do you think you can do this? You will more than likely have to do it in safe boot mode.
     
  7. runlittlejimmy

    runlittlejimmy Private E-2

    ok i got the file copyed to my flash drive and plugged it into the problem computer now what should i do and what do u mean by "Please be more careful in the future. i did not ask for this." ask for what?, sorry im alittle slow.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you in safe boot mode?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask for the size of the ndis.sys file on your problem PC! I had asked for the size from your Laptop.
     
  10. runlittlejimmy

    runlittlejimmy Private E-2

    oh my gosh im an idoit, i really feel dumb now, im sorry about that. jeese ok i got my computer started in safe mode
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try copying the file from your flash drive (hopefully you can access it in safe mode) directly over the top of the c:\windows\system32\drivers\ndis.sys file.
     
  12. runlittlejimmy

    runlittlejimmy Private E-2

    ok i succesfully replaced the file, now what should i do, OHHHHHHH i started my computer up in normal mode again and guess my local area connection is connected. Sweet, oh my i can even access the web now
     
  13. runlittlejimmy

    runlittlejimmy Private E-2

    ok my network connection i working great(interent, network, and firewall all work) But the search and User accounts still dont work properly.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was why I wanted to replace it! The previous copy we used to replace the infected file was from Windows XP SP1 not from SP2 which your PC is currently running. When you said you had a laptop and then also told me the size, I knew we could now replace it. Previously when all I knew was that you did not have a Windows XP CD, there was not much I could legally do to help you. The infected file had to be removed, but you did not have any other copies on your PC except for the outdated version which I was hoping would work.

    Attach a new log now from ShowNew.

    Are you having any malware problems now? The search and user accounts problems are not malware.
     
  15. runlittlejimmy

    runlittlejimmy Private E-2

    Nope so far computer seems to running just fine except for the part that i cant search or change user preferences for some reason. Hers the logs, i just want to thank you so much for your help and I would like to donate, but hows donations work do they go to u or the site. And if you know any way to get the seach and user accounts work that would be awsome.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can donate to me via PayPal if you would like. Just PM me with an email address.

    These are really issues for the software forum but first let's finish the below and then see where things stand.

    First delete the malware backup file we created: C:\WINDOWS\SYSTEM32\DRIVERS\ndis.sys.bak

    Now complete ALL of the below steps! Make sure you do the Windows Update step, it may help resolve some of your problems. You also have to get one of the recommended antivirus and firewall applications installed ASAP. These are all covered in the How to protect link given below.


    It is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. runlittlejimmy

    runlittlejimmy Private E-2

    im unable to update microsoft
    Ok i go to www.microsoft.com Then i click on security and updates then i click on Microsoft Update, and the screen just loads up blank white.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is another sign of other problems on your PC that are not malware related.

    Did you connect to Microsoft using Internet Explorer?
     
  19. runlittlejimmy

    runlittlejimmy Private E-2

    yes cause when i tried with firefox it said "to use this site you must be running micorsoft interneet exploreere 5 or later, and i just found out that my dang ebay account was hijacked, errrrr
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just skip the MS Update step for now and complete ALL other steps. I suggest you use AVG AntiSpyware, Comodo Firewall, Comodo BO Clean AntiMalare. Make sure you read and complete all steps in the How to protect thread. Once you finish ALL steps. Attach new logs from ShowNew and HJT.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds