Packed Rolex got me, need help

Status
Not open for further replies.
Ok, been trying to remove this for hours now....no luck.

Please help me out. I appreciate it.

Hijack log attached.

Also, I tried to go to a command prompt (Vista) but it would not let me paste the entire below, it cuts it off and I cannot type anymore:

@echo off

attrib -h -s -r /s c:\SKYNET*.*
del /f /q /s c:\SKYNET*.*

exit
exit

I get to a promt by running CMD.

I paste all of the above but only see:


attrib -h -s -r /s c:\SKYNET*.*

Then it locks up and never exits...

Help! Thanks!

Working on the rest of the 8 steps now...will keep you postes. Scanning now. :)
 
Man, with Avira installed, I can barely even navigate or use my box.

It keep beeping like crazy and popups everywhere on this Skynet Packed.Rolex....

Let me know what else you need.

SAS also seems to lock up about 40 minutes into the scan when it hits a reg file...
 
Hello Gruson

Please download combofix here ->
ComboFix
Before Saving it to Desktop, please rename it to 321.com to stop malware from disabling it.

Now, please make sure no other programs are running, close all other windows.

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall.
It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after
scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted.
Usually located in c:\combofix.txt, please attach it to your next post
 
Thank you so much.

Combofix looks to have got it. Funny, it did not run all the way through the first time (before I started this thread).

Working on the other scans now via remote.
I will post more later.
 
Status
Not open for further replies.
Back