storage protector removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by edward.lang, Aug 20, 2008.

  1. edward.lang

    edward.lang Private E-2

    I have been fighting this storage protector now for about 6-8 hours. my wife wants to kill me. I have almost completely beat this accept for a big red x icon next to my c: drive in My computer. (XP Pro SP2) I followed the directions so heres my attachments
     
  2. edward.lang

    edward.lang Private E-2

    attachments
     

    Attached Files:

  3. edward.lang

    edward.lang Private E-2

    the computer is not connected to the internet so I had a hard time updating. also attached is the updated scan of sas
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to find and delete:
    C:\Program Files\Common Files\iirf
    C:\Documents and Settings\Katina\Application Data\jcnds.exe

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Drivers::
    rdpwdd
    
    File::
    C:\WINDOWS\system32\drivers\rdpwdd.sys
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    Be sure to tell us how things are running.
     
  5. edward.lang

    edward.lang Private E-2

    Thanks Again, I raelly appreciate your help.
    could this be the reason that automatic updates will not run successfully? Im hopeing that once this combofix trick is done we should be back in order
    attachments are comming soon.
    Thanks
    Edward
     
  6. edward.lang

    edward.lang Private E-2

    attachments. the red x next to the c: drive is still there and I cannot update windows.. this is so fun...
    Edward
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start / run / type "services.msc" without quotes...scroll down and see if Background Intellegence service is started as well as auto updates.
     
  8. edward.lang

    edward.lang Private E-2

    background intelligent transfer service is set up as manual. automatic updates is also started and it is automatic. I still have the big red x next to my c: Drive.
    After automatic updates faled(again) i clicked on the Configure automatic updates button. its is configured to automatic . this keeps getting better and better. maby I should just reinstall XP. anybody got an unused product key?
     
  9. edward.lang

    edward.lang Private E-2

    I found a fix for the red x.
    delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons
    now, all I need is automatic updates functioning properly and I got this beat.
    thanks
     
  10. edward.lang

    edward.lang Private E-2

    I reinstalled the windows installer 3.1 and tried again , still no luck.....
     
  11. edward.lang

    edward.lang Private E-2

    update. I ran malware bytes again just to do it, 2 more viruses poped up
    see attachment
    also got one with sas
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Only one of those files was important to remove...the other two where in either quarantine or your system restore files.

    You have not installed any Java.....Java Runtime 6

    I don't believe this is a malware issue.....you may have to post in the software section for your updates. Have you gone to MS Updates and tried to do a manual update?
     
  13. edward.lang

    edward.lang Private E-2

    ok I deleted them all anyway. I will re-enable system restore and move onto the software issue. A million thanks. You have helped me greatly.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds