also @ TechSpot: Intel Haswell-E enthusiast chip to carry eight cores and support DDR4

Aggressive, unremovable rootkit infection

Discussion in 'Virus and Malware Removal' started by videoart, Dec 17, 2011.

Post New Reply
  1. videoart Newcomer, in training Posts: 40

    Manually input the Winsock command, and still no luck after restart. Error 720.
  2. Broni Malware Annihilator Posts: 40,022   +187

    Let's try to uninstall/reinstall TCP/IP stack.

    1. Download winsock.zip
    Unzip it.
    Right click on Winsock.reg, click "Merge".
    Allow registry merge.

    2. Restart computer.

    3. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
    • On the General tab, click Install a popup window opens.
    • Select Protocol from the list and then click Add.
    • A new window opens, click Have Disk....
    • In the browse... box type c:\windows\inf
    • Click OK.
    • Select Internet Protocol (TCP/IP), and then click OK.
    • Restart and check the connection.
  3. videoart Newcomer, in training Posts: 40

    I receive this message:

    "Cannot import C:\Documents and Settings\Chris Wright\Desktop\Winsock.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor."
  4. Broni Malware Annihilator Posts: 40,022   +187

    My fault. Incorrect file.
    I edited it.
    Delete yours and download new one from the very same link.
  5. videoart Newcomer, in training Posts: 40

    Success in getting a net connection! What should my next step be--the ESET scan?
  6. Broni Malware Annihilator Posts: 40,022   +187

    WOW! I was losing hope :)

    If you completed both steps from my reply #18, go ahead withe Eset.
     
  7. videoart Newcomer, in training Posts: 40

    Running the Java Update, I get the following sequence of alerts:

    bin\jqs.exe: Old File not found. Hoever, a file of the same name was found. No update done since file contents do not match.

    Java(TM) Update fails to apply changes to your system.

    Error 1722.There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor.

    Installation Failed

    The wizard was interrupted before Java(TM) 6 Update 30 could be completely installed. To complete installation at another time, please run setup again.
  8. Broni Malware Annihilator Posts: 40,022   +187

  9. videoart Newcomer, in training Posts: 40

    Java updated, Eset run, here's the 1 file it found:

    C:\Documents and Settings\Chris\My Documents\Downloads\asc-setup.exe a variant of Win32/Toolbar.Widgi application deleted - quarantined

    Everything's running smooth and glitch free now.
  10. Broni Malware Annihilator Posts: 40,022   +187

    Your computer is clean [IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.

    [IMG]
  11. videoart Newcomer, in training Posts: 40

    You have my deepest gratitude--your help has been invaluable!

    My PC is running like a champ, and I've saved your recommendations to a .txt file so I can keep things running smooth and virus-free...

    Be well and I hope you've had a wonderful Christmas!
    Chris
  12. Broni Malware Annihilator Posts: 40,022   +187

    Way to go!! [IMG]
    Good luck and stay safe :)