Ping.exe virus problems [Solved]
#1
Posted 13 December 2011 - 09:56 PM
Register to Remove
#2
Posted 15 December 2011 - 10:38 AM
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.
Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
----------
**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.
Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.
If you would like to format and reinstall your Operating System please let me know and we can assist you with that.
If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help.
----------
GMER
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following ...
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries.
----------
Please download TDSSKiller.zip
- Extract it to your desktop
- Double click TDSSKiller.exe
- Press Start Scan
- Only if Malicious objects are found then ensure Cure is selected
- Then click Continue > Reboot now
- Copy and paste the log in your next reply
- A copy of the log will be saved automatically to the root of the drive (typically C:\)
If you have chosen to attempt to clean your system please post the logs created by GMER and TDSSKiller into your next reply.
#3
Posted 15 December 2011 - 12:51 PM
#4
Posted 15 December 2011 - 01:02 PM
Don't worry about running GMER. Go to My Computer and see if you have a D:\ folder that is could be your backup folder.
Go ahead and run TDSSKiller. Post the log created into your next reply and let me know if you have that backup folder.
#5
Posted 15 December 2011 - 01:06 PM
#6
Posted 15 December 2011 - 01:11 PM
When that is done post the log and we will go from there.gmer is already running
Don't worry about that Microsoft Office Click-to-Run. It isn't what I was looking for.
#7
Posted 15 December 2011 - 01:52 PM
i ended up running gmer twice because i accidentally hit a key while watching it run and the 'ok' button shut it down.
this came off the first:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-15 14:22:28
Windows 6.1.7601 Service Pack 1
Running: gmer.exe
---- Files - GMER 1.0.15 ----
File C:\TDSSKiller.2.6.23.0_15.12.2011_13.55.15_log.txt 76108 bytes
---- EOF - GMER 1.0.15 ----
and this came off the second:
GMER found no system modifications. the log is empty.
#8
Posted 15 December 2011 - 02:09 PM
Thanks for that additional info about the ext hard drive.
------------
Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2
**Note: It is important that it is saved directly to your desktop**
--------------------------------------------------------------------
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
--------------------------------------------------------------------
Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the C:\ComboFix.txt for further review.
#9
Posted 15 December 2011 - 02:57 PM
#10
Posted 15 December 2011 - 03:02 PM
Looks like it ran just fine. Good job.
----------
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
- Right-click and Run as Administrator SystemLook.exe to run it.
- Copy the content of the following codebox into the main textfield:
:filefind consrv.dll
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Register to Remove
#11
Posted 15 December 2011 - 03:10 PM
#12
Posted 15 December 2011 - 04:11 PM
#13
Posted 15 December 2011 - 06:34 PM
You can use AVG free and that will be fine. I prefer either Microsoft Security Essentials or
Avast
Were you able to get SystemLook run yet? If so please post the log that was created.
#14
Posted 15 December 2011 - 06:37 PM
#15
Posted 15 December 2011 - 07:47 PM
Ok...please delete your copy of ComboFix using right click >> delete and then download a fresh copy. Then run a new scan with ComboFix and post the new log into your next reply.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users