BleepingComputer.com: rootkit tcp/ip detected on my laptop

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 10 Pages +
  • « First
  • 8
  • 9
  • 10
  • You cannot start a new topic
  • This topic is locked

rootkit tcp/ip detected on my laptop need help please- Combofix

#136 User is offline   jackeduplaptop 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 79
  • Joined: 24-September 11
  • Gender:Male
  • Location:Washington state, United States

Posted 05 October 2011 - 04:07 PM

After I rename combofix "uninstall", do i need to open it or something?

The last note just said rename it, but nothing happened after that except a screen asking me if I wanted to rename it.

Thanks,

#137 User is offline   Farbar 

  • Just Curious
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 17,816
  • Joined: 08-December 07
  • Gender:Male
  • Location:The Netherlands

Posted 05 October 2011 - 04:42 PM

Yes, please run the renamed Combofix.
Posted Image

#138 User is offline   jackeduplaptop 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 79
  • Joined: 24-September 11
  • Gender:Male
  • Location:Washington state, United States

Posted 05 October 2011 - 05:03 PM

Combofix removed. Olt removed.

Are there any safe search features you recommend that don't interfere with active running antivirus' (Symantec Endpoint is installed)?

Any good back up tools you recommend?

Are defraggler, HD tune good programs to keep things in good running order? Computer shop that couldn't fix infection recommended now i question them :huh:


I appreciate your help very much. I hope my token donation is enough to keep around.

#139 User is offline   Farbar 

  • Just Curious
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 17,816
  • Joined: 08-December 07
  • Gender:Male
  • Location:The Netherlands

Posted 05 October 2011 - 05:31 PM

Thank you for the donation, it is more than a token.:)

These are my favorites:

  • I recommend using Site Advisor for safe surfing. It is a free extension both for Internet Explorer and Firefox. When you search a site it gives you an indication of how safe a site is.

  • I recommend installing this small application for safe surfing: Javacoolsİ SpywareBlaster
    SpywareBlaster will add a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs.
    • Download and install it.
    • Update it manually by clicking on Updates in the left pane and then Check for Updates.
    • Then enable all the protections by clicking on Protection Status on the left pane. Then click on Enable All Protection.
    • The free version doesn't have an automatic update. Update it once in two or three weeks and enable all protection again.

  • I am not really familiar with defraggler and HD tune. But I'm not generally in favor of using those tools that claim improve performance.

    This small application you may want to keep and use to keep the computer clean.
    Download CCleaner from here http://www.ccleaner.com/

    • Run the installer to install the application.
    • When it gives you the option to install Yahoo toolbar uncheck the box next to it.
    • Run CCleaner. (make sure under Windows tab all the boxes of Internet Explorer and Windows explorer are checked. Under System check Empty Recycle Bin and Temporary Files. Under Application tab all the boxes should be checked).
    • Click Run Cleaner.
    • Close CCleaner.

  • Once in a few weeks defragment your hard drive:
    • Go to start. Select All Programs.
    • Click Accessories then System Tools.
    • Click Disk Defragmenter.
    • Select derive C and click Defragment.

Take care.:)
Posted Image

#140 User is offline   jackeduplaptop 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 79
  • Joined: 24-September 11
  • Gender:Male
  • Location:Washington state, United States

Posted 05 October 2011 - 06:27 PM

It was worth every penny. Take care yourself.

#141 User is offline   Farbar 

  • Just Curious
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 17,816
  • Joined: 08-December 07
  • Gender:Male
  • Location:The Netherlands

Posted 06 October 2011 - 01:22 AM

Just forgot the question about backup. There are a lot of programs, the best of them work with re-imaging like your IT method. I personally keep a copy of personal files on an external HD.

This thread will now be closed since the issue seems to be resolved.

If you need this topic reopened, please send me a Private Message and I will reopen it for you. If you should have a new issue, please start a new topic.

Every one else should start a new topic.
Posted Image

#142 User is offline   Farbar 

  • Just Curious
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 17,816
  • Joined: 08-December 07
  • Gender:Male
  • Location:The Netherlands

Posted 07 October 2011 - 03:59 AM

Topic reopened to remove the leftovers.

From PM:

Quote

I am not able to delete the SuperAntivirus file. It says I can not delete SAScore.exe? tried several times and in safe mode.

Trying to delete leftovers. I tried to reinstall from web in case the uninstall file was missing but it would not deleted the existing file. It is not listed in my add/remove programs. The file is in my C:\programs\SAS. Tried to deleted but SAScore.exe would not let me. I removed it from msconfig services and rebooted. Now it won't let me deleted because of SASctxmn.dll. I thought this program was on our side?


  • Please run msconfig and enable any SAS service if it is disabled, click Apply and restart.

  • Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double click on the OTL icon on your desktop.
    • Click the "Scan All Users" checkbox.
    • Under Output select "Standard Output" checkbox.
    • Set Services, Drivers to All.
    • Click Run Scan button.
    • Two reports will open, copy and paste OTL.txt and attach Extra.txt to your reply:
      • OTL.txt <-- Will be opened
      • Extra.txt <-- Will be minimized

Posted Image

#143 User is offline   jackeduplaptop 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 79
  • Joined: 24-September 11
  • Gender:Male
  • Location:Washington state, United States

Posted 07 October 2011 - 10:04 AM

I found this post from an admin on SAS forum:

Posted 24 April 2008 - 03:32 PM
If you are having problems uninstalling, please use our SUPERAntiSpyware Uninstallation Assistant here:
http://www.superanti...s/SASUNINST.EXE

Ran program and SAS finally installed. Apparently it isn't an uncommon issue.

Thanks but that resolved the problem.

#144 User is offline   Farbar 

  • Just Curious
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Instructor
  • Posts: 17,816
  • Joined: 08-December 07
  • Gender:Male
  • Location:The Netherlands

Posted 07 October 2011 - 11:31 AM

The link is broken but I'm glad it is resolved.:)

This thread will now be closed since the issue seems to be resolved.

If you need this topic reopened, please send me a Private Message and I will reopen it for you. If you should have a new issue, please start a new topic.

Every one else should start a new topic.
Posted Image

Share this topic:


  • 10 Pages +
  • « First
  • 8
  • 9
  • 10
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users