also @ TechSpot: Check your bill: AT&T adds new 'administrative fee' to wireless bills

Need help with 1st step in Malware Removal Procedure

Discussion in 'Virus and Malware Removal' started by geoffd86, Mar 11, 2010.

  1. geoffd86 Newcomer, in training Posts: 50

    Its an ibuypower
    the only model number i could find on the bottom is 600
  2. geoffd86 Newcomer, in training Posts: 50

    and i found the driver for broadcom on the site

    but like i said the installer won't let me install it because its saying i don't have privileges, even though i'm on admin
  3. Broni Malware Annihilator Posts: 39,398   +177

    Install it over the top.
  4. geoffd86 Newcomer, in training Posts: 50

    I don't know what that means
  5. Broni Malware Annihilator Posts: 39,398   +177

    Just download the driver and install it without uninstalling current one.
  6. geoffd86 Newcomer, in training Posts: 50

    That's what I thought....Too late I already uninstalled it
     
  7. Broni Malware Annihilator Posts: 39,398   +177

    That's fine...
  8. geoffd86 Newcomer, in training Posts: 50

    btw are the viruses gone? Is the internet the only problem right now?
  9. Broni Malware Annihilator Posts: 39,398   +177

    We don't know yet about viruses. We'll keep checking, if reinstalling drivers won't help.
  10. geoffd86 Newcomer, in training Posts: 50

    but the installer for the driver i dl'd from the manufacturers site says i don't have privileges because i'm not an administrator, but i'm signed in as administrator.
  11. Broni Malware Annihilator Posts: 39,398   +177

    Please download Sophos Anti-rootkit & save it to your desktop.

    IMPORTANT!
    • Disconnect from the Internet or physically unplug you Internet cable connection.
    • Clean out your temporary files.
    • Close all open programs, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.
    • Temporarily disable your anti-virus and real-time anti-spyware protection.
    • After starting the scan, do not use the computer until the scan has completed.
    • When finished, re-enable your anti-virus/anti-malware (or reboot) and then you can reconnect to the Internet.

    • Double-click sar_15_sfx.exe to begin the installation, read the license agreement and click Accept.
    • Allow the default location of C:\Program Files\Sophos\Sophos Anti-Rootkit and click Install.
    • A message will appear "Sophos Anti-Rootkit was successfully installed. Click 'yes' to start it now". Click Yes.
    • Make sure the following are checked:
      • Running processes
      • Windows Registry
      • Local Hard Drives

    • Click Start scan.
    • Sophos Anti-Rootkit will scan the selected areas and display any suspicious files in the upper panel.
    • When the scan is complete, a pop-up screen will appear with "Rootkit Scan Results". Click OK to continue.
    • Click on the suspicious file to display more information about it in the lower panel which also includes whether the item is recommended for removal.
      • Files tagged as Removable: No are not marked for removal and cannot be removed.
      • Files tagged as Removable: Yes (clean up recommended) are marked for removal by default.
      • Files tagged as Removable: Yes (but clean up not recommended) are not marked for removal because Sophos did not recognize them. These files will require further investigation.

    • Select only items recommended for removal, then click "Clean up checked items". You will be asked to confirm, click Yes.
    • A pop up window will appear advising the cleanup will finish when you restart your computer. Click Restart Now.
    • After reboot, a dialog box displays the files you selected for removal and the action taken.
    • Click Empty list and then click Continue to re-scan your computer a second time to ensure everything was cleaned.
    • When done, go to Start > Run and type or copy/paste: %temp%\sarscan.log
    • This should open the log from the rootkit scan. Please post this log in your next reply. If you have a problem, you can find sarscan.log in C:\Documents and Settings\<username>\Local Settings\Temp\
  12. geoffd86 Newcomer, in training Posts: 50

    it says to delete temporary files...I deleted all the temp files, cookies, etc. from my browsers. How do I delete other types of temp files?
  13. Broni Malware Annihilator Posts: 39,398   +177

    Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.
  14. geoffd86 Newcomer, in training Posts: 50

    I already scanned once, and it didn't detect anything that required removal. They were all unknown hidden files. I couldn't click clean up checked items because i couldn't check anything. Therefore I couldn't finish, so I couldn't get the log files.
  15. Broni Malware Annihilator Posts: 39,398   +177

    Are you talking about Sophos?
  16. geoffd86 Newcomer, in training Posts: 50

    yes. I can't get it to finish because there are no files to remove
  17. Broni Malware Annihilator Posts: 39,398   +177

    I'd like you to uninstall Comodo and see, if that will get your connection back.

    In addition...

    Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log.

    =========================================================================

    Download OTL to your Desktop.

    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * Under the Custom Scan box paste this in:


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT


    * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
  18. geoffd86 Newcomer, in training Posts: 50

    Log Files for OTL & GMER

    I had to attach them because they were too big to post on here

    Attached Files:

  19. Broni Malware Annihilator Posts: 39,398   +177

    That's fine. Sorry for the delay. I went to the movies :)

    Did you uninstall Comodo? Still no connection?

    I'm reviewing the logs right now.
  20. Broni Malware Annihilator Posts: 39,398   +177

    Logs look perfectly fine.