Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
Double click the exe file.
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.
In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi CatByte,
Thanks for your assistance.
These problems I am having are on my wife's laptop, so I am using mine for downloads and communications since hers is ill. I downloaded the file to my laptop and transferred it to her desktop using a USB drive. The first time I tried to scan, I got a blue screen of death and a restart prior to completing the scan. I tried again and got the same message. Thinking the problem may be some software associated with the USB drive (cruzer), I downloaded the file to my laptop again, this time to an SD card and again transferred to my wife's desktop and tried to scan. Once again the blue screen and restart. Partial message below:
PFN_LIST_CORRUPT
Technical information:
***STOP: 0x0000004E (0x00000007, 0x000A74B7, 0x00000001, 0x00000000)
Bottom line, no GMER scan yet.
hope this helps. Thanks again
try running GMER in safe mode. Make sure her security programs are disabled or they will interfere, try running it with just "sections" and the "c:\" drive checked.
If you still can't get it to run, try this following program;
Please download this file, and save it to your Desktop. Once you have downloaded it, save and close all other programs and run it by double-clicking on the file named "RootRepeal.exe".
Once the main window shows up, please click on the "Report" button on the bottom of the window. Next, please click the "Scan" button.
Another window will pop up asking you to select what to include in the scan. Please uncheck everything except for the "Stealth Code" checkbox, and then click OK.
Once the program has finished scanning, the results will appear. Click on the "Save Report" button, and save the report to your desktop.
Finally, please open this report with Notepad, and post it here.
OK, first scan in safe mode with only Sections checked found no modifications. On second run in safe mode using previously suggested checks and unchecks, received message that the file has stopped working. Downloaded RootRepeal and installed on wife's desktop. Tried to run in safe mode but immediately got blue screen. Restarted in normal mode, disabled Kaspersky and re-ran. And blue screen again…. Restart in safe mode and re-ran. Blue screen : pool_header_error
Sorry, I did not previously mention that she had also started getting Host process for Windows Services stopped working and was closed message shortly after the touble started…..
Download Combofix from either of the links below, and save it to your desktop.
Link 1 Link 2
**Note: It is important that it is saved directly to your desktop**
——————————————————————– IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Double click on ComboFix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the C:\ComboFix.txt for further review.
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish, so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and clickRemove Selected. <– very important
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy&Paste the entire report in your next reply.
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
NEXT
**Vista users - right click on the IE icon and run as administrator
Go here to run an online scanner from ESET.
Note: You will need to use Internet explorer for this scan
Turn off the real time scanner of any existing antivirus program while performing the online scan
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activeX control to install
Click Start
Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic and also let me know how things are now.
Hey CatByte,
Looks like we finally got some results! Here are the two reports, one from Malware bytes and one from ESET online. I was encouraged when I was able to get updates for malware bytes since we havent been able to get anything from the internet lately.
Thanks! Let me know what's next.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4190
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18904
6/12/2010 7:49:12 AM
mbam-log-2010-06-12 (07-49-12).txt
Scan type: Quick scan
Objects scanned: 128485
Time elapsed: 8 minute(s), 56 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
************************
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=8c3fc8ab281f9b4da7229258a6d8d86c
# end=stopped
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-06-12 12:42:17
# local_time=2010-06-12 08:42:17 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=1280 16777215 100 0 42207290 42207290 0 0
# compatibility_mode=5892 16776573 100 100 0 112951955 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=95998
# found=2
# cleaned=2
# scan_time=2109
C:\Qoobox\Quarantine\C\Windows\System32\drivers\pdrv.sys.vir Win32/Koobface.NDA worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\9LFDLJW2\setup3249000[1].exe Win32/Koobface.NCT worm (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.
NEXT
[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
Download the latest version of Java Runtime Environment (JRE) 20 and save it to your desktop.
Scroll down to where it says JDK 6 Update 20 (JDK or JRE)
Click the Download JRE button to the right
Select the Windows platform from the dropdown menu.
Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6u20 with JavaFX 1 License Agreement". Click on Continue.The page will refresh.
Click on the link to download Windows Offline Installation and save the file to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u20-windows-i586-p.exe to install the newest version.
After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
On the General tab, under Temporary Internet Files, click the Settings button.
Next, click on the Delete Files button
There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
Trace and Log Files
Click OK on Delete Temporary Files Window Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
Click OK to leave the Temporary Files Window
Click OK to leave the Java Control Panel.
NEXT
Delete the DDS and GMER programs and logs from your desktop
NEXT
Set a new restore point:
press the Win key on the keyboard, type Restore then press enter to get to the System Restore section.
Click "Create a restore point" Click on the "Create" button to create a new restore point. You may be prompted for permission to continue - ALLOW it to continue. You'll be prompted for a name, and you might want to give it a useful name that you'll be able to easily identify later.
Click the Create button, and then the system will create the restore point.
When it's all finished, you'll get a message saying it's completed successfully.
You will now have a new restore point
Then remove all previous Restore Points
Click Win key on the keyboard, type cleanmgr to access the disk cleanup
choose all files on the computer, then choose the C: drive, press OK Disk cleanup calculates the files, this takes a few minutes > another menu will pop up.
At the top, click on the More Options tab, under System Restore and Shadow Copies group,
Click the Clean up button,
Vista will ask you if you’re sure, click on the Delete button, click OK > Delete Files
NEXT
Below I have included a number of recommendations for how to protect your computer against malware infections.
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them Then consider a password keeper, to keep all your passwords safe.
Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.
Make Internet Explorer more secure
Click Start > Run
Type Inetcpl.cpl & click OK
Click on the Security tab
Click Reset all zones to default level
Make sure the Internet Zone is selected & Click Custom level
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
Next Click OK, then Apply button and then OK to exit the Internet Properties page.
DownloadTFCto your desktop
Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.
WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for both Firefox and IE
Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles: Think Prevention. PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.
Thank you for your patience, and performing all of the procedures requested.
Please respond one last time so we can consider the thread resolved and close it, thank-you.