Also, received error report that C:\$mft is corrupt
Rootkit Trojan Can't be Automatically Removed
#1
Posted 14 February 2012 - 08:15 PM
Also, received error report that C:\$mft is corrupt
#2
Posted 14 February 2012 - 08:24 PM
Link 1
Link 2
* IMPORTANT !!! Save Combo-Fix to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See HERE for help - Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Click on Yes, to continue scanning for malware.
When finished, ComboFix will produce a log.
Note:
1. Do not mouseclick combofix's window while it's running. That may cause it to stall!
2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Attach logs for: (USE THE "MORE REPLY OPTIONS" BUTTON TO BE ABLE TO DO THIS)
- ComboFix (C:\combofix.txt)
Arthur Wilkinson [Support/Quality Assurance]
Emsisoft Team - www.emsisoft.com
#3
Posted 15 February 2012 - 04:43 PM
It finally came to the window stating that a report was being prepared,but then it froze and no report was created.
#4
Posted 15 February 2012 - 04:55 PM
Since ComboFix had issues, go ahead and follow the instructions at this link for running TDSSKiller, and remove anything it finds. Let me know if it detected anything.
Arthur Wilkinson [Support/Quality Assurance]
Emsisoft Team - www.emsisoft.com
#5
Posted 15 February 2012 - 05:48 PM
I did get a message that rootkit.ZeroAccess had inserted itself into the tcp/ip stack, and also that rootkit was detected.
I will run TDSSKiller.
#6
Posted 15 February 2012 - 06:02 PM
Arthur Wilkinson [Support/Quality Assurance]
Emsisoft Team - www.emsisoft.com
#7
Posted 15 February 2012 - 07:02 PM
#8
Posted 15 February 2012 - 07:04 PM
Arthur Wilkinson [Support/Quality Assurance]
Emsisoft Team - www.emsisoft.com
#9
Posted 16 February 2012 - 12:51 AM
#10
Posted 16 February 2012 - 04:12 PM
Do you have a Windows XP CD (or at least an ISO image of a Windows XP CD)? You should be able to recover your computer with a UBCD4Win disk, but you need a Windows XP disk (or possibly a Windows 2003 disk) in order to build a UBCD4Win disk.
Arthur Wilkinson [Support/Quality Assurance]
Emsisoft Team - www.emsisoft.com
#11
Posted 16 February 2012 - 08:26 PM
I do have a XP CD
#12
Posted 16 February 2012 - 09:10 PM
Once you have created a UBCD4Win disk, you will need to start your computer up off of it. When you first turn your computer on, there should be a button on your keyboard that you can press to open what is usually called the "Boot Menu". Your computer will tell you what button to press. Most will say it in one of the corners of the screen, and Toshibas will have it below the Tohiba logo in the middle. Once you get the Boot Menu open, select your CD or DVD drive, make sure the UBCD4Win disk is in the drive, and press Enter on your keyboard.
Before starting up, you will be presented with a menu of options. Make sure that Launch "The Ultimate Boot CD For Windows" is selected (it should be highlighted in black) and then press Enter. If you don't do anything, then it should start automatically after 20 or 30 seconds.
It make take several minutes to start up, since it is essentially loading a Windows environment off of a CD. Once it is done, you will see a Windows XP desktop (if you see any options as it is starting up, then you can ignore them, and it will continue loading after a few seconds).
Once the desktop starts to load, it will ask you if you want to start network support. You can tell it No unless you want to pull up the instructions on the Internet, or unless you feel you will need Internet access at any point during the process.
There is an icon on the desktop for EZPCFix, however when I click on it I get an error message, so I assume that it won't work for you either (it probably needed a plugin to be enabled in order to work properly).
Go ahead and click on the Start button, go to Programs, go to Disk Tools, go to Diagnostic, and go to Check Disk. In the window that pops up, type in the letter of the drive you want to scan, such as C: and then press Enter on your keyboard. You can answer n for 'no' to the question about scanning for bad sectors. Make sure you answer y for 'yes' to the question about fixing errors. And then confirm y for 'yes' if you entered everything correctly. It will begin a check of your hard drive, and fix anything that is wrong with the filesystem.
If that does not work, then please let me know, and we can go from there.
Arthur Wilkinson [Support/Quality Assurance]
Emsisoft Team - www.emsisoft.com
#13
Posted 20 February 2012 - 04:01 AM
Reason: Lack of Response
PM either ShadowPuterDude, or GT500 to have this thread reopened.
The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist.
All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread.
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users




This topic is locked









