Strange happenings with Vista...

Discussion in 'Malware Help (A Specialist Will Reply)' started by bigdarren, Feb 29, 2008.

  1. bigdarren

    bigdarren Private E-2

    Hi, Appox. 5 days ago i started up my laptop, things had changed. Vista asked my permission to open every program/file, i had no sound period, videos in vlc player wouldnt work etc etc.

    i took it to a my work and gave it to the tech guy. he printed this out(pasted below) and told me to follow those steps and see if that worked out. Well when i tried to open up 'runthis.bat, it seemed to open for a mili-second then just disapeared.
    Now im not sure what to do, hopefully someone here will be able to help:wave




    Hello,

    Welcome to the forum, you have a bit of a mess going on.

    Please print out or copy this page to Notepad. Make sure to download all the required tools to your desktop before starting. If there is anything that you do not understand, ask your question(s) before proceeding with the fixes.

    A. Tools to download:
    Right click HERE and Save As (in IE it's "Save Target As") in order to download DelDomains.inf to your desktop.
    Download SDFix and save it to your Desktop.
    Download ComboFix and save it to your desktop.

    **Note: In the event you already have SDFix and/or ComboFix, these are new versions that I need you to download. It is important that they are saved directly to your desktop**


    B. Running the Tools


    1. Run DelDomains:

    Right click DelDomains.inf and select: Install (no need to restart)
    Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.


    Very Important!

    Before running SDFix and ComboFix:
    Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with both SDFix and ComboFix and remove some of their embedded files which may cause "unpredictable results".
    Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    Also, make sure you are physically disconnected from the Internet (unplug the cable) after downloading the programs but before running the files.


    2. Run SDFix:

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Now reboot your computer in Safe Mode by doing the following :
    Restart your computer
    After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually
    Instead of Windows loading as normal, the Advanced Options Menu should appear
    Select the first option, to run Windows in Safe Mode, then press Enter
    Choose your usual account.
    Open the extracted SDFix folder and double click RunThis.bat to start the script.
    Type Y to begin the cleanup process.
    It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to reboot.
    Press any Key and it will restart the PC.
    When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    Finally, copy the content of Report.txt to Notepad and Save it to your Desktop as you will be asked to post it later on.


    3. Run ComboFix:

    WARNING:
    IF you have not already done so ComboFix will disconnect your machine from the Internet when it starts.
    Do not re-connect your machine back to the Internet until ComboFix has completely finished.
    If there is no Internet connection when Combofix has completely finished, just restart your computer to restore the connection.

    Double-click on combofix.exe and follow the prompts. When finished, it will produce a report for you.


    **Note: Do not mouseclick comboFix's window while it's running. That may cause it to stall**


    C. After ComboFix has finished its run:
    Restart/re-enable all the programs that you disabled before running the tools.
    Physically reconnect to the internet.

    D. Posting Logs/Reports:
    Report.txt
    C:\ComboFix.txt
    A new HijackThis log run after all the tools have been run.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure that your problems have anything to do with malware. If you want to find out if you have malware problems, please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds