Sality Virus and Win98Se Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by necro61, Feb 19, 2009.

  1. necro61

    necro61 Sergeant

    Hello World,

    Have had a rather nasty encounter with this virus, it seemingly may have removed the internet explorer icon, outlook express got shot down by bitdefender free, which initialy found the Sality virus but then deleted or moved the infected outlook express folder and or shortcut and so as of now cant access outlook express file to delete the file which bitdefender keeps claiming is infected - pain in the posterior - the Bitdefender may have also nailed the I.E shortcut / .exe and couldnt even find a link by using find / searching for an I.E link - to access the i-net.

    Tried booting in safe mode "Bitdefender" the antivirus just doesnt run / load.
    Cant seem to locate the Bitdefender quarantine folder either not that i ever looked for this before.

    I did manage at one stage to open a ms word file and enter in an email address www.google.com put a space and thus turning it into a link and accessing the net that way and trying to download an app but of course like all these one stop 100% download fixes said it was for the wrong version etc... although nothing on the site suggested versions variants or anything else begining with V.. After downloading this it turned out to be a one off internet access, as this method now also fails, I.E just pops-up with "there was an error" well wip-de-do dont bother telling me that without an error code "expletive" 98

    This unit is the print server for a small workgroup of 15 units and given the nature of this virus it needs to be removed and the sooner the better, would prefer not to have to registry tweak this or delete entries just need this to function for another month or two prior to it being upgraded.

    Software environment is Win98 SE with office 2000 Bitdefender Free antivirus - updated earlier this week.
    Hardware platform is is Hp Vectra DL-400 CPU is P/3 @ 733Mhz

    Thanks to all who respond with info or an assist on this one. :wave
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. necro61

    necro61 Sergeant

    Thanks for the response Tim,

    I could potentialy go through the trouble shooting process, but decided easier - as far as time and effort goes to just image a little used identicle unit in this workgroup and re-add the printer drivers, set the static I.P and call it lunch.

    The units bound to be quicker than it ever was with all the years of the old "junk files" on it - so thats my solution...not a Gee?...eek! fix as such but a work around.

    P.S I've put a several threads up since joining awhile ago, can someone please inform me how to close a thread when the issue has been resolved.:confused

    Sorry working 11 - 12 hour days all the text just blurs together after awhile. As a suggestion it would be great if the person who has created the thread had a check box or similar, perhaps near the "submit reply" or "preview post" that said "post and close thread" or similar so you can add last minute thank-you's and close it...only a suggestion.

    Thanks again.:wave
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We do not "close" threads in case someone decides to come back to the thread if the issues re-occurs.

    Sound like you are taking a route that will work for you, so let us know if you have any difficulties with this. :)
     
  5. necro61

    necro61 Sergeant

    Thanks for clarifying that Tim.

    Have nothing further to add, have completed a re-image just fine, thanks.:)
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem......safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds