|
#21
|
||||
|
||||
|
No problem, I may have something better worked out for you by then, so check the thread before following the above
|
|
#22
|
||||
|
||||
|
If you can get MBAM to run, I found one instance where it was able to unhook and remove this one.
I also recommend you uninstall both Norton and Avast -> Norton removal tool found here -> http://service1.symantec.com/Support...05033108162039 ---------------------------------------------------------- Get Avira Anti-virus - update it - run full scan http://www.download.com/Avira-AntiVi...dlPid=10831109 Install Avira Antirootkit tool (takes seconds to run) http://www.free-av.com/en/tools/4/av...tkit_tool.html After scanning click view report and attach here. Last edited by Blind Dragon; 06-18-2008 at 08:58 PM.. |
|
|
|
#23
|
|||
|
|||
|
Quote:
Should i still go on with what you suggested in your last post? |
|
#24
|
|||
|
|||
|
Just to be sure, I completely deinstalled all Norton stuff via your link of the removal kit, and also deleted Avast. Currently, im running the avira rootkit, and after that i will run the avira scan. When both are done, i will post he logs.
|
|
#25
|
|||
|
|||
|
And here are the 2 new logs.
|
|
#26
|
||||
|
||||
|
I think we can move this with OTMoveit
OTMoveit2 by OldTimer Please download the OTMoveIt2 by OldTimer.
Last edited by Blind Dragon; 06-20-2008 at 12:21 AM.. |
|
#27
|
|||
|
|||
|
Here you are!
|
|
#28
|
||||
|
||||
|
Good, Now please run a fresh combofix or DSS log
|
|
#30
|
||||
|
||||
|
Can you run MBAM now? I know for a fact that they have added this to the definitions this week. If you can update it and run a full scan, it may need to reboot your system to remove it.
Right click MBAM and select run as administrator |
|
#31
|
||||
|
||||
|
if not follow below
'The Avenger by Swandog46'
|
|
#32
|
|||
|
|||
|
Okay, so i did the Avenger scan. Still havent done the MBAM scan. Is that scan still necessary?
Here's the Avenger & HJT log. |
|
#33
|
||||
|
||||
|
Avenger by Swandog
Note: This program must be run from an account with Administrator priviledges.
Code:
Registry values to delete:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks | {57A52E74-004C-464B-96CC-4DFE5366EA02}
Files to delete:
C:\Windows\system32\awtrSjgd.dll
|
|
#34
|
|||
|
|||
|
Thnx again for the help. Here's the log.
|
|
#35
|
||||
|
||||
|
I think that may have got it but for some reason it didn't find the file. As you can see rootkits can be tricky sometimes. Just to be sure please do the following:
Run CFScript Open notepad and copy/paste the text in the code box below into it: NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it. Also .. Pay particular attention to this :- Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it) Quote:
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below. ![]() This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log. |
|
#36
|
|||
|
|||
|
Here it is ...
|
|
#37
|
||||
|
||||
|
Gone
![]() Now please update and run MBAM to pick up leftovers, I don't think you will have any problems with it now, as it doesn't have to try and remove what we just took off. |
|
#38
|
|||
|
|||
|
Scanning right now .... it found a Trojan TR/Vundo.Gen in C:\!KillBox\vtUImmmI.dll
I assume i can select 'Deny access', since it probably some quarantined file? Also; Can i remove all the programmes used in this thread (KillBox, Combofix, etc), and their respective folders, from my HD? Can i delete them manually, or should i do it via the add/remove programmes option in my control panel? |
|
#39
|
||||
|
||||
|
just post log when done, I have a certain way to remove the programs we have used, anything that is left at the end you can remove through add remove, but leave them on there till we are done.
|
|
#40
|
|||
|
|||
|
Here's the MBAM log. It found some files (4 quarantines), which i deleted just to be sure everything's gone now
![]() Thnx again, Blind Dragon, for all the great help. Due to your services, ive been able to keep on using my laptop the last week, whereas otherwise i would have needed to set it back to factory defaults. That would taken me some 2 full days at least, to get my laptop back on the configuration i have it now. Your help is really appreciated. If i can do anything in return, and its within my power, please name it ![]() Cheers! |
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Advanced Malware removal | Virus & Malware removal | 8 | 01-05-2008 07:03 PM | |
| Malware popups keep reinstalling after removal | Virus & Malware removal | 13 | 11-24-2007 06:10 PM | |
| Malware Removal Logs | Virus & Malware removal | 7 | 11-24-2007 08:37 AM | |
| Help, 3 in 1 regenerating malware ( error cleaner privacy protector/ spyware malware | Virus & Malware removal | 1 | 07-09-2007 06:02 AM | |
| Following the virus/malware removal steps would like to know something? | Virus & Malware removal | 23 | 05-17-2007 04:41 PM | |
All times are GMT -4. The time now is 06:07 PM.





