Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Need Help With Bloodhound Exploit.196 Removal


  • Please log in to reply

#1
aherr023

aherr023

    Member

  • Member
  • PipPip
  • 27 posts
The past 2 weeks or so Symantec has been finding multiple occurrences of this thing called bloodhound exploit.196. Each time, they are quarantined but more and more keep popping up. I'm beginning to get strange messages from programs such as itunes saying that they cannot do certain things because the registry has been changed. When I install new programs there are always issues with the registry. On one occasion when I turned on my computer I was unable tyo load my user account at first and found that, after rebooting, all my personal files (writing, music, pictures) had been removed. I did a system restore then conducted a scan in safe mode and found over 2,000 infections and I'm certain that that number has increased. Now, I've done a little research and have learned that this is a virus that moves through tempfiles, regenerating as it goes and downloading tons of other harmful programs so I'm dying to get rid of it. My question to you is, quite obviously, how?
  • 0

Advertisements


#2
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello aherr023,

Welcome to Geekstogo.

Please download ComboFix from one of these locations:

NOTE: If you are guest watching this topic. ComboFix is a very powerful tool. The disclaimer clearly states that you should not use it without supervision. There is good reason for this as ComboFix can, and sometimes does, run into conflict on a computer and render it unusable.

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#3
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
emeraldnzl,

there's a slight problem, combofix is apparently only compatible with windows 2000 and xp and i'm running vista. is there another program i can use?
  • 0

#4
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
emeraldnzl,

there's a slight problem, combofix is apparently only compatible with windows 2000 and xp and i'm running vista. is there another program i can use?
  • 0

#5
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

there's a slight problem, combofix is apparently only compatible with windows 2000 and xp and i'm running vista. is there another program i can use?


That was certainly the situation in the past and sometimes there are still problems especially if you are running the 64bit version of Vista.

I don't think it will be a problem if you are just running the ordinary Vista.

Actually the real reason I was using it was to see what it would do.

ComboFix will not run with a file infector which is one of the possibilities with your machine's infection. On the other hand it will deal with the other infection mentioned.

However if you are worried about it we can try something else.

It is a pretty big download at 28mb's but is very useful at detecting\cleaning rootkits or whatever it finds.

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file, name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.


  • 0

#6
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0

#7
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Topic re-opened at users request.
  • 0

#8
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
i'm trying to attach the log but every time i do it says i didn't select a file
  • 0

#9
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Is it too big to copy and paste in the forum? That is the preferred reporting method.

However if it is too big then see if these instructions help:

To attach a file, do the following:

* Click Add Reply
* Under the reply panel is the Attachments Editor
* Browse to find the attachment file you want to upload, highlight the file by clicking once on it, then click the green Upload button
* Once it has uploaded, click the Manage Current Attachments drop down box
* On the left you will see a icon like a letter with a little green cross on it. Please click on that and it should upload to the thread.
  • 0

#10
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
I'm going to need to post it in multiple peices, it's really long and the virus is still popping up like crazy

Attached Files


  • 0

Advertisements


#11
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
more

Attached Files


  • 0

#12
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
and another

Attached Files


  • 0

#13
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
and another

Attached Files


  • 0

#14
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
more

Attached Files


  • 0

#15
aherr023

aherr023

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts
the forum isn't letting me upload any more. is there another way? the entire file is 5.25 mb
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP