Stuck on step one for removal of null0.***

Discussion in 'Malware Help (A Specialist Will Reply)' started by opal219, May 7, 2011.

  1. opal219

    opal219 Private First Class

    I have read the thread

    http://forums.majorgeeks.com/showthread.php?t=222773

    and attempted step 1, for TDSSKiller. It downloaded fine.
    I attempted the exe (as administrator) file as is.. no luck at all. I renamed the file as suggested - it seemed to start a setup but failed to get to the run screen. I downloaded it on another computer - renamed it there, burnt it to CD and tried to use that CD on the infected computer - again, no luck getting the program to initialize.

    The infected computer is running windows 7 ultimate and (thankfully) has more than one administrator account. The main account (my husband's account.. his computer) is the infected account. My account is password protected on that computer.

    From his account, nothing runs. I cannot get avast pro to run (though it ran a complete scan from my account and found nothing) Task manager won't stay open - it tries then shuts down. cCleaner wouldn't open either. This file is affecting IE, FF and google chrome also. None will open and stay open.

    To get out of that account, I had to do a forced shut down *power switch* and have it come up to the command prompt. I ran a chkdsk/f and it said it fixed some files. Then it came up in safe mode where I logged into the uninfected account - did a complete virus scan with avast pro, ran windows defender then cCleaner. None of those found anything, so I switched users back to the infected account. The infection file is still right there on the desktop.

    The infected account displays warning popups about a virus scan hunk of software that requires purchase to run. Also there's a small green icon on the task bar that looks similar to the windows defender icon - except for the color.

    The file name on the desktop is Isswkvmxsic.exe It has no uninstaller - does not come up on the uninstall list from the control panel and also does not appear on the uninstall list for cCleaner.
    When clicking properties on that file, I'm shown this file name
    null0.28879140392445.

    I have not attempted to just drag that sucker to the recycle bin - have had awful results doing that with other things in the past. Right click on it does not present the option to rename the file.

    Might anyone have any ideas on what to do now since the rootkit tool won't do it's thing?

    I'm a new user of windows 7 - directly from XP, no stops at vista. Might there be another task within windows 7 that I'm not aware of that I could try?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. opal219

    opal219 Private First Class

    oh..I'm sorry... I read this by Kestrel13

    http://forums.majorgeeks.com/showthread.php?t=236958&highlight=null0

    Default Re: Null0 & no connectivity
    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Then continue with the below.

    So, since I was not able to run TDSSkiller.. and it says THEN do the malware removal process, I posted - unsure if I should continue without running that program.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you can't run TDSSKiller, I would need to see the logs that are requested by the Read and Run First instructions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds