also @ TechSpot: Intel confirms a smartwatch is in the pipeline

Need help removing trojan-clicker.win32.wistler.a

Discussion in 'Virus and Malware Removal' started by ramonsterns, Aug 24, 2010.

  1. ramonsterns TechSpot Enthusiast Posts: 752   +12

    Full, I think.

    I right clicked on the drive, clicked on "Format", then clicked on "Restore Device Default" and left quick format unchecked, then I let it format in peace until it was done.

    Also, here's the MBRCheck log.

    Attached Files:

  2. Broni Malware Annihilator Posts: 40,051   +187

    There is something wrong here and even, if your computer behaves fine, I don't like it.

    Let's double check something.
    If you have any Combofix file on your desktop, delete it.

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
  3. ramonsterns TechSpot Enthusiast Posts: 752   +12

    ComboFix log.

    Attached Files:

  4. Broni Malware Annihilator Posts: 40,051   +187

    OK, Combofix doesn't see any infection and it definitely detects Whistler bootkit, if one is present.

    Let's run one more tool.

    Download Bootkit Remover to your Desktop.

    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
    • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator.
    • It will show a Black screen with some data on it.
    • Right click on the screen and click Select All.
    • Press CTRL+C
    • Open a Notepad and press CTRL+V
    • Post the output back here.
  5. ramonsterns TechSpot Enthusiast Posts: 752   +12

    Too big, uploaded file instead.

    Attached Files:

  6. Broni Malware Annihilator Posts: 40,051   +187

    Nothing found:
    The result in bold is exactly what you expect on a clean drive.

    At this point, I have no other choice, but to declare your computer as being clean.
    I see nothing wrong there.
     
  7. ramonsterns TechSpot Enthusiast Posts: 752   +12

    Alright, guess I'll have to deal with it since it's not causing me any problems.

    Thanks for the help, Norton would have charged me an eye and a tooth just to get it fixed, then gave me no guarantee it would remain fixed.

    I just hope it is actually a false alarm and doesn't bite me in the butt down the road.
  8. Broni Malware Annihilator Posts: 40,051   +187

    You should be perfectly fine.
    If anything, you know, where to find me :)

    Just to be safe, reset your restore points to create fresh, clean restore point.

    Good luck :)