Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.
Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.
DO NOT RUN ComboFix unless requested to.
Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
This post has been edited by gringo_pr: 04 August 2011 - 09:53 PM
I will be online from 5-31 to 6-4 in a very limited amount
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here --><-- Don't worry every little bit helps.
So I actually hit fix instead...it went to the blue screen again but at least no screeching noise this time. Windows prevented my laptop from having an "unexpected shutdown" so I didn't lose any files, etc. Said it "recovered" from one.
Then it proceeded to ask me how I wanted to reboot, selected normal mode, and rebooted as normal. It seems to me that this rootkit won't allow any programs to get rid of it. Like it won't allow Windows to shutdown normally because doing so would threaten its hold on my laptop.
I don't know what else to do. I want my laptop back. Anything else we can do??
To access the System Recovery Environment in Windows 7, simply boot your PC,
just before the system loads the Windows operating system, hit the [F8] Function 8 key on your keyboard which will launch the Advanced Boot Options menu.
There you will see a new option 'Repair Your Computer', select this option and hit 'Enter' on your keyboard.
Now, from the System Recovery Options dialog, select the "Operating System" you want to repair, then click Next:
From the "Choose a Recovery Tool" dialog menu, select "Command Prompt":
Type the following into the "Command Prompt Window": and press enter
bootrec.exe /fixmbr
If you have problems booting the computer after you have run that command boot back into the System Recovery Environment and Type the following into the "Command Prompt Window": and press enter
bootrec.exe /fixboot
I will be online from 5-31 to 6-4 in a very limited amount
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here --><-- Don't worry every little bit helps.
So I can only hit the fixMBR during the scan, afterward it is shadowed and won't let me. Why is it different than the fix button? What is the MBR? I hit it during the scan and it warned me I might lose all my partitions. I cancelled it because I wasn't sure what that meant.
To clarify, everytime I turn off my laptop, it asks me to force shut it down because there are programs running in the background. It says doing so I might lose work if not saved, do I want to proceed, etc. I usually have no choice because it proceeds to shut it off anyway.
aswMBR is unable to fix and remove those rootkits for whatever reason. Do you think by using the System Recovery Environment will aid that program in getting rid of those rootkits? Let me know, I will run it if you say so.
So I tried the System Recovery Environment and my computer wouldn't boot afterward. I did bootrec.exe /fixboot and it still won't boot. Startup repair automatically started and is attempting repairs. I tried to cancel it but it said this action cannot be cancelled. What is the next step?
Click on the folder that represents your USB drive (sdb1 ?)
Confirm that you see driver.sh that you downloaded there
Press Tool at the top
Choose Open Terminal
Type bash driver.sh
Press Enter
After it has finished a report will be located on your USB drive named report.txt
Remove the USB drive and insert back in your working computer and navigate to report.txt
Please note - all text entries are case sensitive
Copy and paste the report.txt for my review
I will be online from 5-31 to 6-4 in a very limited amount
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here --><-- Don't worry every little bit helps.
It has been more than 48 hours since my last post.
do you still need help with this?
do you need more time?
are you having problems following my instructions?
if after 48hrs you have not replied to this thread then it will have to be closed!
Gringo
I will be online from 5-31 to 6-4 in a very limited amount
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here --><-- Don't worry every little bit helps.
Due to the lack of feedback, this topic is now closed.
In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
I will be online from 5-31 to 6-4 in a very limited amount
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know
If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic
Please Only Copy And Paste Reports Into Topic - Do Not Attach
My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here --><-- Don't worry every little bit helps.