Malware System Security |
![]() ![]() |
Malware System Security |
Jul 5 2009, 07:33 AM
Post
#1
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
My computer has become infected with a little nasty. I followed the Malware and Spyware Cleaning guide but the problem is still there. It actually seems to be worse now. I can not open any program. I tried reopening malwarebytes again to run another scan cause I can't seem to find the log from the one I did the other day. Not sure if it automatically saves or if I was supposed to do it. I can't open rootkiller or otl. I was originally able to open into safe mode but now it seems like when I try to it just reboots in to my normal windows. When ever I try and opening an application I get a warning bubble down at the bottom saying application can not be executed the file is infected please open your anti virus software but the bubble is coming from the system security icon.
I'm not sure what to do know seeing as how I cannot open any of the programs that I need to clean up my computer. |
|
|
Jul 9 2009, 04:47 PM
Post
#2
|
|
![]() Trusted Helper Posts: 3,952 From: The United States OS: Windows XP SP3 & Windows Vista SP1 |
Hi Deadpool57,
Welcome to Geeks to Go! My name is SpySentinel and I will be helping you fix your computer problem. Sorry for the delay, we have been very busy lately, and I apologize for your wait. Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop. Link 1 Link 2 ![]() ![]() -------------------------------------------------------------------- Double click on Combo-Fix.exe & follow the prompts.
|
|
|
Jul 11 2009, 09:00 AM
Post
#3
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
When I try to download to my desktop the download gets to 99 percent and then says cannot copy combofix[1]: Access denied. Make sure the disk is not full or write-protected and that the file is not currently in use.
Also I did forget to mention that even my internet browser is not opening and I am posting from a second computer. |
|
|
Jul 12 2009, 06:06 PM
Post
#4
|
|
![]() Trusted Helper Posts: 3,952 From: The United States OS: Windows XP SP3 & Windows Vista SP1 |
Hi Deadpool57,
Sorry for the delay. Lets see if we can disable this threat: Download RootRepeal.zip and unzip it to your Desktop.
Note: The scan can take some time. DO NOT run any other programs while the scan is running If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead. To attach a file, do the following:
|
|
|
Jul 14 2009, 01:02 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
RootRepeal is like all of the other applications that I have tried to run. I just get the bubble at the bottom of my screen that says "Application cannot be executed. The File RootRepeal.exe is infected. Please Activate your antivirus software."
|
|
|
Jul 14 2009, 02:34 PM
Post
#6
|
|
![]() Trusted Helper Posts: 3,952 From: The United States OS: Windows XP SP3 & Windows Vista SP1 |
Let me know if this works:
Download the GMER Rootkit Scanner. Unzip it to your Desktop. Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised! If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Post the contents of GMER.txt in your next reply. |
|
|
Jul 15 2009, 05:09 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
Same problem with this one.
|
|
|
Jul 15 2009, 06:34 PM
Post
#8
|
|
![]() Trusted Helper Posts: 3,952 From: The United States OS: Windows XP SP3 & Windows Vista SP1 |
You have an infection that monitors for new processes being created, and when ANY new process is being created, and then terminates it and shows an error.
1. Go to Start->Run and type in notepad and hit OK. 2. Then copy and paste the content of the following codebox into Notepad: QUOTE @echo off tasklist /V > %userprofile%\Desktop\Processes.txt 3. Save the file as "Show.bat". Make sure to save it with the quotation marks. 4. Double click Show.bat. It will create a file on your desktop called Processes.txt Post that in your next reply. |
|
|
Jul 16 2009, 03:55 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
It blocks notepad as well.
|
|
|
Jul 16 2009, 05:15 PM
Post
#10
|
|
![]() Trusted Helper Posts: 3,952 From: The United States OS: Windows XP SP3 & Windows Vista SP1 |
You have an infection that is disallowing any new processes from running, and enumerating and then terminating any processes that start. So lets see if we can trick it.
Please delete ComboFix from your desktop. Download Combofix from any of the links below. You must rename it before saving it. When it asks you for a save location, navigate to C:\Windows and save it as svchost.exe Link 1 Link 2 ![]() -------------------------------------------------------------------- Double click on svchost.exe & follow the prompts.
This post has been edited by SpySentinel: Jul 16 2009, 05:23 PM |
|
|
Jul 18 2009, 08:02 AM
Post
#11
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
It got farther than the others but still got blocked. I received a little loading type bar to show it was opening and then after it was full I received the bubble at the bottom saying something like n.pif was infected.
|
|
|
Jul 18 2009, 03:32 PM
Post
#12
|
|
![]() Trusted Helper Posts: 3,952 From: The United States OS: Windows XP SP3 & Windows Vista SP1 |
We are making progress, navigate to C:\ComboFix and if there is a log file please post it. If not let me know.
|
|
|
Jul 19 2009, 08:22 AM
Post
#13
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
There is no log file.
|
|
|
Jul 19 2009, 02:35 PM
Post
#14
|
|
![]() Trusted Helper Posts: 3,952 From: The United States OS: Windows XP SP3 & Windows Vista SP1 |
Lets try this:
Please remove RootRepeal if you still have it. Download RootRepeal.zip When it asks you to save it, make sure you rename it to svchost.exe and unzip it to C:\Windows.
Note: The scan can take some time. DO NOT run any other programs while the scan is running If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead. To attach a file, do the following:
This post has been edited by SpySentinel: Jul 19 2009, 02:36 PM |
|
|
Jul 21 2009, 01:10 PM
Post
#15
|
|
|
Member ![]() ![]() Posts: 20 OS: Windows XP |
This one got a little farther but I was unable to run the scan. When I opened it I recieved a svchost error and then a rootrepeal screen that looked like the following picture but with not buttons or tabs or anything.
Sorry for the poor quality picture I just snapped a quick picture with my cell. This post has been edited by Deadpool57: Jul 21 2009, 01:11 PM |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
0 / 327 | 8th January 2009 - 07:18 PM scorpio55 started - last by scorpio55 |
|||||
![]() |
0 / 366 | 3rd April 2009 - 06:38 PM deadfoot13 started - last by deadfoot13 |
|||||
![]() |
0 / 541 | 8th May 2009 - 03:06 PM suzanne431 started - last by suzanne431 |
|||||
![]() |
17 / 421 | 26th August 2009 - 05:06 PM JonMajor started - last by Transience |
|||||
|
Time is now: 7th November 2009 - 06:32 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising