win32 neshta

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SalK, May 19, 2010.

  1. SalK

    SalK Private E-2

    Hi

    I am really scared of what happened to my computer now. I have got win32 neshta on it and followed your comprehensive Malware Removal Guide.

    I have made all steps and I was on the part where I run SuperAntiSpyware. I got a blue screen and after that my computer starts up really slow and I am not able to do anything on it because its so slow and doesnt react to what I do. Please help me what to do!!!

    Thanks in advance
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try booting in safe mode to finish running the various scans. We need to be able to see the resultant logs in order to help you.
     
  3. SalK

    SalK Private E-2

    Ok, now I have tried to run all the scans.

    Here are some problems I encountered:

    MBAM_ERROR_UPDATING (12007, 0, WINHTPSENDREQUEST) after install of MB.exe (in safe mode) Because of this I downloaded update on other computer manually.

    When running Combofix it complained about F-Secure running. But I could not stop it because I was in Windows safe mode. (F-Secure wouldn´t start and there was no icon to click on) So Combofix didn't run properly.

    On start of rootrepeal it stated "error-invalid PE image found!"
    Root repeal never finished because it hang up on something. It let it be on for days and run it twice.

    I have added logs below but for above reason ComboFix.txt and RRlog.txt is missing.

    It all started when I got win32 neshta on my main computer it then infected also my laptop (that is the computer having big issues now). I found your malware removal guide when I googled win32 neshta and started to go through it. I didn't notice anything weird until somewhere around when I should run SuperAntiSpyware. I got a bluescreen when running SuperAntiSpyware and my computer started to act very weird. I am not able to use it at all in normal mode, it reacts extremely slow but I can but into safe mode.

    Please help me to find the problem. Dont know if it is a virus or if something went wrong when I was going through your guide. I really appreciate your help since I dont know what to do!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing ComboFix on your desktop. Which is where it should be run from. Perhaps you can re-download it and run it again. So far, I am not seeing any malware, but I would like to see a log from Combo.
     
  5. SalK

    SalK Private E-2

    I have tried run ComboFix and as I remember I followed the instructions but of course I can try run it again.

    The problem is that it complains about me having F-Secure (Telia säker) activated. I wanted to close it but I couldn´t find out how to do because I was in safe mode. I dont know if thats the reason but it didnt run as described in instructions.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. SalK

    SalK Private E-2

    I have already read those instructions. But in safe mode there is no icons to disable the AV. I tried to start the program to unable it but it wouldnt start.

    I dont know if I should run the program even if it complains about the AV or what I should do to disable it.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you not run it in normal mode? That would be best. Then you can disable F-secure. It will not harm anything if you are unable to do that.
     
  9. SalK

    SalK Private E-2

    Actually I was able to run combofix.exe in normal mode after letting the computer be on over the night. Then I also could disable AV.

    Here is the log
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Combo didn't give a complete log. Are you still being prompted about malware and if so, please give me the full path to the file and tell me what is reporting it.
     
  11. SalK

    SalK Private E-2

    Excuse me for my bad english but I didnt understand you really. You mean if my AV is reporting malware? Actually its hard to tell because my computer is not working so I can make a scan nor use it since I started your cleaning procedure.

    What path you mean and what file because it used to be a lot of files?

    Why didnt Combo work? It seemed to run properly this time actually. Only thing is that my AV was activated on restart so I think it blocked combo until I was able to release it due to my unusable computer. :(
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what is happening with your system. Why are you saying it is unusable? What is happening? Does F-secure report any malware or will it not run a scan? You may need to uninstall it until we can get your system clean.
     
  13. SalK

    SalK Private E-2

    I just want to report that problem is solved!

    When I got infected by win32 neshta I was going through your malware removal guide. At some point my computer stopped to work at all and with that I mean you have to wait hours for just one click and nothing seemed to work on the computer. When I ran F-Secure scan it reported some infected files but the scan took days and before it was finished the computer got blue screen and rebooted.

    As I stumbled in the dark I uninstalled F-secure to see what happened and suddenly the computer worked again. I haven't had any problems with F-Secure before and computer has never been that slow. So my guess is that something when I was going through the removal guide went wrong and made F-secure act weird.

    I have now scanned computer with Avast and its clean and now it responds normally. Maybe it should be good for you to know what happened to me.

    Thanks for your help!
    /Klas
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Strange, but good to know.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds