Question

system infected can not open any desktop icons, AVG, IE, ETC.

Asked by: nickg5

I was able to get here thru Firefox.
I know these files are infected::
windows\syssvc.exe
system32\iehelper.dll

Windows keeps telling me I'm infected but all these "unknown virus scanners pop up"
I think it is Malware. but Malwarebytes won't open from my desktop, nothing opened except Firefox

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-10-06 at 06:23:41ID24788721
Topics

Desktop Anti-Virus

,

Anti-Virus

,

Internet Security

Participating Experts
4
Points
500
Comments
52

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. PC infected with  spyware / malware
    Hi Experts! My computer is again infected with spyware. I use Win XP Pro SP2. A month ago, I reformatted the HDD because I was not able to remove all of these spyware. Now they are back and I don't want to reformat the HDD again. My anti-virus software is Panda and it stopp...
  2. infected computer keeps getting re-infected (logs attached)
    The computer is a windows xp home sp3 desktop. I've fixed an infection of "Antivirius 2009" (The rogue2008 one) using a combination of combofix and malwalrebytes. plus spybot for good measure. Computer got infected a second time, and I did the same. Then last we...
  3. Malware Doctor Infection
    Hi all, A friend of mine has a Sony Vaio he uses for his Topography and he got it infected with Malware Doctor last week. Apparently he wanted to install some defragging app and NOD32 was stopping him from doing so (and for good reason). So he disabled the antivirus and insta...
  4. System Infected with a virus
    Helped my computer is infected with a virus and I've used superantispyware and there was probally well over 55 different things it removed. everything from fake virus,trojans,rootkits anyways after it got done removing the virus and spyware it restarted and there still a few ...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: nickg5Posted on 2009-10-06 at 06:24:17ID: 25504690

barely able to submit this question due to all the popups.

 

by: nickg5Posted on 2009-10-06 at 06:25:51ID: 25504706

ytbb.exe is infected........endless warnings from windows....
I cut my system off within 5 seconds of the attack. I'm pretty sure it was malware.

 

by: nickg5Posted on 2009-10-06 at 06:30:00ID: 25504744

Windows is preventing me from doing anything....closing, yes or no always is the wrong answer to clear my damn screen so I can see what is what.
Windows keeps wanting to let Anitvirus System Pro do a scan. It's already done one....

 

by: nickg5Posted on 2009-10-06 at 06:31:36ID: 25504763

according to some unknown source.....the htreat is Win32/Nuqel.E

 

by: nickg5Posted on 2009-10-06 at 06:33:08ID: 25504783

also infected: igfxserv.exe

 

by: nickg5Posted on 2009-10-06 at 07:05:00ID: 25505114

A couple other files said to be infected are:
logonIE.exe and rundll.32

I rebooted in safe mode
did a system restore to Oct. 4th.
rebooted in safe mode
doing an AVG scan but it on the "command" page and I have not used this much so not sure if AVG will remove any infections or I'll need to give some command.

Anyone with detailed help on what should I do next?

 

by: nickg5Posted on 2009-10-06 at 07:09:01ID: 25505159

AVG is finding alot of locked files.
all are local service, network service, local settings, ntuser.dat, pagefilesys, etc.

Due to safe mode?

 

by: nickg5Posted on 2009-10-06 at 07:19:14ID: 25505297

I guess running AVG and malwarebytes in safe mode is no value?

What about downloading new versions using Firefox? Can't open any program from my desktop except in safe mode.

Is Antivirus System Pro a Microsoft product? It parks itself in my tool bar near the clock.

 

by: BitsBytesandMorePosted on 2009-10-06 at 07:20:42ID: 25505315

Nick..... what brand is your computer? Model? ..... Do you have your drivers and restore discs?

 

by: nickg5Posted on 2009-10-06 at 07:27:34ID: 25505397

custom made, I have Intel Express Installer driver CD, Windows XP disc, never heard of a restore disc.
This is not my first attack....maybe the 4th, so gotten thru them before with a series of steps........without safe mode......
This one could be unique.

Is all my safe mode scans zero value since I am in safe mode?

 

by: nickg5Posted on 2009-10-06 at 07:35:50ID: 25505504

Intel Desktop board D945Gcz

 

by: nickg5Posted on 2009-10-06 at 07:46:38ID: 25505624

a few system 32 files locked from AVG in safe mode.
system32
\default
\sam
\security
\software and software.log
\system and system.log

 

by: BitsBytesandMorePosted on 2009-10-06 at 07:51:43ID: 25505695

Hello Nick.... I feel bad for you... you have been dealing with all these issues for months now....

Although, on the bright side.....you've learned a lot about your system, viruses, startup items, services, etc....

My last advice on your initial post, after clearing out all the malware and spending days on it remains......After a severe infestation.....many files are damaged.......at this point you have repaired, got infested again....repaired.....if you want to go through this again....trust me.....it's a can of worms........

 

by: nickg5Posted on 2009-10-06 at 07:54:16ID: 25505732

oh well, AVG scan over in the command box but it disappeared from my screen.
My only choices in the command line composer is start scan or close.

 

by: BitsBytesandMorePosted on 2009-10-06 at 07:54:48ID: 25505741

I would reccomend....and let me post this again just to avoid the "Die Hard" repair advocates.... a clean install:


We repair several thousand machines every year and my opinion on this is sometimes controversial but I will keep saying it again and again unless someone convinces me otherwise.


Most of us, including myself, tackle a repair as a challenge... we enjoy the fight , the satisfaction of being able, the knowledge acquired on every repair..... this said, when a virus or any other malware attacks a computer it does a lot of damage. Most of this damage can be reverted by removing and replacing the infected files and reverting some of the changes made to the registry (notice I said most).


The problem is with multiple infestations and automatic removals. You get the machine back to a "working" level but it is always left somewhat limping.... with some kind of a  "...lingering problem...".


As a challenge, ideally you would address each one of these infestations and correct each one of the issues (if you know them) created by these malwares. The problem is that every one of these malwares does different damage, behaves differently and even the same one is created sometimes to name itself at random and make different changes so, in reality, it is very seldom when you can address every one of the issues created......it is just not cost and time efficient.


It is a task that requires a trained and knowledgeable individual, someone who has to keep himself updated and trained of all the new technologies and threats, which would theoretically make him an "expensive" individual. This person would have to have the time to invest in performing these repairs and someone willing to pay for this time.
Look at your own example.....you've spent a minimum of "...7 hours...." (I know that probably much more) trying to get your pc back to normal. Time-wise it would have been better and more efficient if you backed up all your data and did a clean install of Windows XP. Reinstalled your drivers and favorite programs. It would have taken you about 2 or 3 hours if you did not have a previously made image of your computer.......15 to 20min if you have an image of your computer.


My point is....... if you ask me .....a clean install is most often the best solution. Not always, but "generally".....


My advice again: backup your important files such as pictures, documents, favorites, etc..... after this....WIPE OUT the computer completely...

 

by: BitsBytesandMorePosted on 2009-10-06 at 07:56:05ID: 25505766

If you need assistance on how to wipe it out and start fresh...let me know.

 

by: BitsBytesandMorePosted on 2009-10-06 at 07:57:43ID: 25505785

By the way..... don't install any 3rd party software until we get your machine working clean and fully protected....

 

by: nickg5Posted on 2009-10-06 at 07:59:52ID: 25505807

All I know to do is locate the thread from many months ago on my last infection and follow the instructions, if I can find it, but this infection seems to make all shortcuts on the desktop to be unable to be opened.

I can wait here in safe for for some instructions.

BitsBytesandMore:
what is your advice as I wait for others who might want to jump in?

I've got to remove these infections one way or the other.
I've got my system, monitor, on a surge protector, and that button is a few inches from my left knee. I saw the warning of a malware attack and immediately killed power to everything.

How can I run Malwlarebytes? Is that any help?

 

by: BitsBytesandMorePosted on 2009-10-06 at 08:03:07ID: 25505837

After spending many hours ... you can probably repair your computer.....but again: after spending many hours or days. At the end....it will be in a working condition but you will have all kinds of "bugs" and/or "lingering problems"....

 

by: nickg5Posted on 2009-10-06 at 08:12:08ID: 25505941

Firefox lost it's ability to locate the EE server, so I'm using IE.

"Time-wise it would have been better and more efficient if you backed up all your data and did a clean install of Windows XP. Reinstalled your drivers and favorite programs".

Can you provide a list of the drivers you mention above?

backup data is totally unknown to me. I've been asked to do that many times. Do not know how. PERIOD. and the  instructions were too advanced except for me. I've never used a floppy.

I have no problem spending the next many hours fixing things. Nothing better to do.
>>>> ok, suppose I'm ok doing that, many hours, what is the current answer on how to access diagnostic tools in normal mode?

So, what has been infected? My Windows XP?

 

by: BitsBytesandMorePosted on 2009-10-06 at 08:18:12ID: 25506018

The drivers are specifically for your system....this is why I asked you before if you had the drivers disc....

You can download them from this site and save them to a safe place.....an external drive, a flash drive.....

http://www.intel.com/support/motherboards/desktop/D945GCZ/

 

by: BitsBytesandMorePosted on 2009-10-06 at 08:19:58ID: 25506042

In your case specifically..... your most important driver to have is the one for your ethernet (Network Card or NIC)..... if you don't have this one you will not be able to connect to the internet to download anything else...

 

by: BitsBytesandMorePosted on 2009-10-06 at 08:23:22ID: 25506070

These are the drivers you will need..... make sure you save them onto a CD, external hard drive...anywhere off the computer that you can later access.... Also make sure you download the ones for "YOUR" OS .... if you are using XP, it would make no sense to download the one for Vista......(some of the drivers say that will work on several OS's.... this is Ok..)

 

by: nickg5Posted on 2009-10-06 at 08:31:26ID: 25506164

save them onto a CD, external hard drive...anywhere off the computer that you can later access

download them from this site and save them to a safe place.....an external drive, a flash drive

do not know how to save anything like above.
-----------------
After spending many hours ... you can probably repair your computer.....but again: after spending many hours or days. At the end....it will be in a working condition but you will have all kinds of "bugs" and/or "lingering problems"....

Can the above be Step 1.....and re-install, driver's etc. be step 2...?

 

by: nickg5Posted on 2009-10-06 at 08:49:10ID: 25506412

here are 2 threads from last time:
http://www.experts-exchange.com/Software/Internet_Email/Anti_Spyware/Q_23991702.html
and another thread within the one above.

 

by: nickg5Posted on 2009-10-06 at 09:10:19ID: 25506664

IE is THE BEST in safe mode.......!!    fast, quick,

 

by: Kelly_WPosted on 2009-10-06 at 09:16:02ID: 25506727

Hello,
I would run combofix in safe mode then reboot and run malwarebytes and then a registry cleaner from registry-cleaner.net
This has always worked for me over thousands of machines
Thanks,
Kelly Wilke

 

by: BitsBytesandMorePosted on 2009-10-06 at 09:24:53ID: 25506816

Nick... when you are in safe mode you are not loading anything else but the most essential drivers and services for Windows to work. This is why IE is working fast.

If you do not know how to save files, it might not be a good idea to do a clean install because if you get stuck on the way and loose access to the internet ......without someone to advise you, ... you will be in deep trouble.

At this point I would suggest you click on the "Request Attention" button at the top of the screen (at the right of your question).... try to request that rpggamergirl look into this issue and assist you....she is the most knowledgable person I know in regards to removing and repairing virus and malware damage.

Make sure she is aware ....(make her aware) ....of the history of this issue. You do not have to type everything out....just point her (copy the links of the questions) to the last 3 or 4 threads so she can review the repair steps taken and the results.....

 

by: warturtlePosted on 2009-10-06 at 10:26:34ID: 25507485

Hello nickg5,

Running ComboFix as already advised would be a good idea at this point in time, but don't run it in safe mode unless the computer cannot actually boot into normal mode.

The URL to download ComboFix is here:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Make sure to read the instructions carefully before running ComboFix. If ComboFix runs for a second, then disappears then download it again and rename it to jabba.exe and run it again.

rpg is probably going to ask you to run ComboFix as well, so it would be best to do it anyways.

Hope it helps.

 

by: BitsBytesandMorePosted on 2009-10-06 at 10:33:24ID: 25507557

Experts,

If I may, and with all due respect....before replying to this question, it would be wise and would help a lot more if you would please take a look at the background of this problem. We have been driving Nick "Nuts"......

This is the first one I saw.....but it is my understanding that there was a previous one:

http://www.experts-exchange.com/Software/Internet_Email/Web_Browsers/Internet_Explorer/Q_24767067.html

This is the one that followed:

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/XP/Q_24774412.html

Bits.

 

by: pankusareenPosted on 2009-10-06 at 11:05:46ID: 25507915

Scan ur pc with the bootable rescue cd
Download FREE Bootable Rescue CDs from Kaspersky, BitDefender, Avira, F-Secure and Others
http://www.askvg.com/download-free-bootable-rescue-cds-from-kaspersky-bitdefender-avira-f-secure-and-others/

Personally i recommend
Kaspersky Rescue CD:

 

by: nickg5Posted on 2009-10-06 at 12:27:46ID: 25508861

warturtle:
I can boot in normal mode, but when I first booted today, Any attempts to download anything from the desktop resulted in alot of popup warnings and unwanted websites opening themselves.
I've been in safe mode since.

Kelly:
I could not open up Malwarebytes in safe mode.
I went into safe mode and ran AVG. It found some locked files but as far as it removing anything I'm not sure it did.
Are you saying to run Combofix in safe mode and re-boot and do the other steps in normal mode?
I did not think Combofix would FIX anything until it's results were looked at and certain entries removed.

pankusareen:
does Download FREE Bootable Rescue CDs from Kaspersky involve burning to a CD?

Also been away from my pc for 3 hours...........sorry.

 

by: warturtlePosted on 2009-10-06 at 12:53:45ID: 25509126

You can download ComboFix on a USB disk and then transfer it to the PC or alternatively, you can download in safe mode and reboot in normal mode and run it.

 

by: BitsBytesandMorePosted on 2009-10-06 at 13:09:00ID: 25509330

Hello again Nick,

I thought I had been through before when I explained how to remove viruses and/or malware..... I guess I wasn't:


Go into Safe Mode.
Then go to this website and download these programs:

MalwareBytes Anti Malware.... http://www.malwarebytes.org/mbam.php  
and/or SuperAntiSpyware http://www.superantispyware.com/  

Make sure you update to the latest versions.

Once downloaded (you may need to rename MalwareBytes, Combofix or other tools before saving their files to the desktop as Malware can recognize the name and block them unless renamed)

While still in Safe Mode, Go to Start-Run and type:

Msconfig

Once in the application, go to the services tab and "hide all microsoft services" select the remaining and disable". Then go to the Startup Tab and disable all entries.

Reboot.

After the system boots it will give you a warning regarding the changes made by msconfig. Select do not warn me again.

Now you can run the anti Malware applications recommended above.
 
If the problem persists...go to http://www.bleepingcomputer.com/combofix/how-to-use-combofix  and follow the instructions.  

 

by: nickg5Posted on 2009-10-06 at 13:50:18ID: 25509815

BitsBytesandMore:
sure I knew all those instructions, did them last week.
However, that was just a couple IE issues and not an actual attack like I had last night.

I thought last night's REAL attack was totally different than the reason for what we did last week.
-----------------------------------
warturtle:
I was in safe mode and ran Combofix. (my error on a log, I was thinking of HijackThis - but I do have the combo fix log from today).
I had to proceed without disabling AVG. I could not disable it and tried to just remove it and re-download. I could not un-install AVG because 1 file could not be found.

The Combofix deleted 2 files:
Windows\Installer\1283ffc.msi
Windows\system32\msblcd32.dll
Do they mean anything to anyone?

It rebooted my system in normal mode, and there is a log if someone should see it.

I am not getting any security alerts or anything. No current indication of infiltrations.

I should be able to run Malwarebytes.com and
repeat the process I did last week with help from BitsBytesandMore:

BitsBytesandMore:
Since that article on yahoo answers about the "sigmatel shutdown end of program" thing, did not work, I'll try disabling all the entries in the startup tab within Msconfig (as suggested by the 1st responder in that other thread) and see if that helps. If so, I can go back and re-enable them one at the time to eliminate the one causing the problem.

 

by: BitsBytesandMorePosted on 2009-10-06 at 13:53:07ID: 25509850

Nooooo....wait.....

 

by: BitsBytesandMorePosted on 2009-10-06 at 13:55:24ID: 25509866

The " ....as suggested by the 1st responder ...." advise was a troubleshooting advice......it was only the first step towards eliminating which one of the entries in your "Startup Items" was creating the problem...... unfortunately he never answered you again and clarified this for you....

 

by: BitsBytesandMorePosted on 2009-10-06 at 13:56:31ID: 25509877

By the way....we don't know if the yahoo answers about the "sigmatel shutdown end of program" thing worked or not since you got yourself infected before actually rebooting ...and testing...

 

by: BitsBytesandMorePosted on 2009-10-06 at 13:58:56ID: 25509899

Nick.... really .... I'm serious about this.... I posted a set of instructions for you to follow in order...... you are not following them..... first you've got to get the machine clean..... NO TESTING OF THIS OR THE OTHER..... it first has to be clean......

Follow the instructions above..... then ..... after we know it's clean... you troubleshoot any "lingering issues".....

 

by: BitsBytesandMorePosted on 2009-10-06 at 14:08:02ID: 25509972

By the way Nick.... Once you see the message about Malware ..... your already infected. Things like:

".....I've got my system, monitor, on a surge protector, and that button is a few inches from my left knee. I saw the warning of a malware attack and immediately killed power to everything...."

can actually damage your hard drive.....never ....never....kill it like that....Those things are only on TV......

 

by: nickg5Posted on 2009-10-06 at 14:11:20ID: 25510003

BitsBytesandMore:
sorry....I do not see any instructions above, where you told me to repeat last weeks fix. I see instructions about drivers and backup disc, re-install, etc. I asked if getting things in workable condition could be step one and then re-install step two.

I see the below: (after someone suggested combofix and those other 2 members posted their comments) >>> I will now do the following <<< (I could not do the below because I could not boot in normal mode due to the popups and warnings and unwanted sites opening up very quickly, I could not run Malwarebytes, it could not be opened from my desktop).

I can now do the below (vvvvvvvv) since my system seems stable and no indications of any problems. I apologize for not knowing how to do those other things, drivers, etc. before the Combofix comment.

(vvvvvvvv)
Go into Safe Mode.
Then go to this website and download these programs:

MalwareBytes Anti Malware.... http://www.malwarebytes.org/mbam.php  
and/or SuperAntiSpyware http://www.superantispyware.com/  

Make sure you update to the latest versions.

Once downloaded (you may need to rename MalwareBytes, Combofix or other tools before saving their files to the desktop as Malware can recognize the name and block them unless renamed)

While still in Safe Mode, Go to Start-Run and type:

Msconfig

Once in the application, go to the services tab and "hide all microsoft services" select the remaining and disable". Then go to the Startup Tab and disable all entries.

Reboot.

After the system boots it will give you a warning regarding the changes made by msconfig. Select do not warn me again.

Now you can run the anti Malware applications recommended above.
 
If the problem persists...go to http://www.bleepingcomputer.com/combofix/how-to-use-combofix  and follow the instructions.  

 

by: BitsBytesandMorePosted on 2009-10-06 at 14:21:30ID: 25510083

There are many ways of dealing with Malware.....the problem is that everyone will tell you a different way.... and most of them are right.....there are 100 ways of doing the same thing...just stick to one way until you understand it.

The most basic thing you need to do is to disable the startup items, disable all non microsoft services and sometimes even disable system restore.....depending on the malware.....

I remember talking about this with you......this is the most basic approach to diagnosing any problem whether it be malware or other issue.....

 

by: nickg5Posted on 2009-10-06 at 14:23:26ID: 25510096

I'll repeat the above, and then run combo fix again.
My system shows no indication of virus.
I ran AVG in safe mode before any comments were made. That may or may not have removed anything.
The scan results disappeared.

I'll leave the sigmatel thread open until the rest is done.

If no one here has a comment on the two files removed by Combofix or seeing the Combofix log, I guess I can close this.

I did not do pankusareen's idea but it can be given poiints as something that can be of future help.
I am not knowledgable on doing backup disc, etc.
I do have two Kingston USB data traveler's one is 1GB and the other is 2GB (never used).




 

by: nickg5Posted on 2009-10-06 at 14:32:39ID: 25510158

The most basic thing you need to do is to disable the startup items, disable all non microsoft services and sometimes even disable system restore.....depending on the malware.

ok...............good..........

I'll run Malwarebytes again and also check those IE problems from last week, but as I said yesterday, they were back, and the only hint I had as to why was my system had not been re-booted for 11 hours.
I have not been able to review that thread or any others.
The attack last night was after I had detected a return of the IE browsers that can not load pages.

with things workable I can aggressively explore the re-install of XP?

 

by: BitsBytesandMorePosted on 2009-10-06 at 14:39:40ID: 25510218

The first thing you need to know is how to save your drivers to your Kingston USB drive..... it is basically saving the download to whatever drive letter your system assigns to your flash drive....

 

by: BitsBytesandMorePosted on 2009-10-06 at 14:41:08ID: 25510230

Once you have all your drivers......you can play and play knowing that you can recover your system withing an hour or so if you make any mistake or get attacked by any malware.... but you need to learn first....how to install your XP and how to install the drivers.... do a Google search..... it's easy..

 

by: BitsBytesandMorePosted on 2009-10-06 at 14:43:51ID: 25510246

Here is the link again.....save (download) all the drivers to your Kingston Flash drive...

Understand...you must read it...what each one is for..... the most important one is the one for your ethernet or you will be "incomunicado"....

 

by: nickg5Posted on 2009-10-06 at 16:02:43ID: 25510826

BitsBytesandMore:

Here is the link again.....save (download) all the drivers to your Kingston Flash drive...

...did you intend to provide a link?

 

by: BitsBytesandMorePosted on 2009-10-06 at 16:09:00ID: 25510874

 

by: nickg5Posted on 2009-10-07 at 09:22:58ID: 25517125

Everything seems to be working the way it was before the attack.
Before any one responded to my question, I ran AVG in safe mode and did a system restore back to Oct. 4th, 2 days before the attack.

I ran Combofix and will also complete the process detailed in comment  25509330 above.


I have not used Kaspersky Rescue C or a registry cleaner at this point:

 

by: nickg5Posted on 2009-10-07 at 09:25:02ID: 25517158

The first mention of combofix was by Kelly_W.
I've used that before and went straight to it.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...