Troj/Rustok-N need help removing it please [Closed] |
![]() ![]() |
Troj/Rustok-N need help removing it please [Closed] |
Apr 27 2009, 10:01 PM
Post
#1
|
|
|
New Member ![]() Posts: 8 OS: Vista |
I have been gettting redirected to www.xalab.com on yahoo and other various sites. I was told this virus is what I have! please help.
I am on vista. I also wanna say Malwarebytes' Anti-Malware... i cannot get to the site.. it is blocked. This post has been edited by awakenedsleepingbeauty: Apr 27 2009, 10:43 PM |
|
|
Apr 28 2009, 06:43 AM
Post
#2
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
hello
Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall** |
|
|
Apr 28 2009, 10:02 AM
Post
#3
|
|
|
New Member ![]() Posts: 8 OS: Vista |
won't let me use comb-fix because I have vista and its for 2000 and xp only
|
|
|
Apr 28 2009, 12:25 PM
Post
#4
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
hello
Download RootRepeal.zip and unzip it to your Desktop.
Note: The scan can take some time. DO NOT run any other programs while the scan is running If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead. To attach a file, do the following:
|
|
|
Apr 28 2009, 04:10 PM
Post
#5
|
|
|
New Member ![]() Posts: 8 OS: Vista |
It says there is a mismatch between the windows kernel and the hardware scan.. then i get a driver error.
|
|
|
Apr 28 2009, 05:37 PM
Post
#6
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
give this a whirl
Download the GMER Rootkit Scanner. Unzip it to your Desktop. Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised by a trained Security Analyst If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Post the contents of GMER.txt in your next reply. |
|
|
Apr 28 2009, 07:12 PM
Post
#7
|
|
|
New Member ![]() Posts: 8 OS: Vista |
|
|
|
Apr 29 2009, 07:05 AM
Post
#8
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
can you try combofix again ?
Also if you have a router you need to reset it |
|
|
Apr 29 2009, 07:07 AM
Post
#9
|
|
|
New Member ![]() Posts: 8 OS: Vista |
That actually took it off... i scanned again... and nothing... no annoying redirects.
I am in a college apartment buidling... I use wireless.. so I cannot restart the router. Update- actually tried Combofix again... still same problem... Windows 2000 and Xp only. This post has been edited by awakenedsleepingbeauty: Apr 29 2009, 07:09 AM |
|
|
Apr 29 2009, 07:10 AM
Post
#10
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
ok well can you try combofix anyway
|
|
|
Apr 29 2009, 07:11 AM
Post
#11
|
|
|
New Member ![]() Posts: 8 OS: Vista |
I did and got the same...
Incompadiable... works with windows 2000 and xp only |
|
|
Apr 29 2009, 07:16 AM
Post
#12
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
hello
|
|
|
Apr 29 2009, 07:33 AM
Post
#13
|
|
|
New Member ![]() Posts: 8 OS: Vista |
edit : removed log
|
|
|
Apr 29 2009, 12:38 PM
Post
#14
|
|
![]() GeekU Teacher Posts: 35,115 From: Dublin OS: XP |
ok good
Please download ATF Cleaner by Atribune.
Under Main choose: Select All Click the Empty Selected button.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. Please download Malwarebytes' Anti-Malware from Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Go to Kaspersky website and perform an online antivirus scan.
|
|
|
Apr 29 2009, 06:27 PM
Post
#15
|
|
|
New Member ![]() Posts: 8 OS: Vista |
it wouldn't let me download the second program...
and the third one told me i had to be online to use it... and i am. So only one that worked was the first one This post has been edited by awakenedsleepingbeauty: Apr 29 2009, 10:01 PM |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 348 | 12th February 2006 - 11:43 AM lizzie_16 started - last by Trevuren |
|||||
![]() |
4 / 636 | 1st December 2007 - 03:25 PM onelostchicken started - last by greyknight17 |
|||||
![]() |
9 / 792 | 26th December 2008 - 07:30 PM krankenstein started - last by greyknight17 |
|||||
![]() |
2 / 229 | 7th June 2009 - 12:33 PM Aloysius_Jr started - last by skate_punk_21 |
|||||
|
Time is now: 21st November 2009 - 07:32 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising