08-25-2009 10:09 AM - last edited on 08-25-2009 10:44 AM by shannons
Hi guys, i got this same virus this weekend and i have also downloaded malwarebytes. Ran the program and in about 10-15mins of scanning my whole computer turns off.
Then i try running in under safe mode same thing happened in 10-15mins of scanning.
[edit: Changed subject to reflect move.]
Solved! Go to Solution.
08-25-2009 10:15 AM
Please download SysProt here http://homepages.slingshot.co.nz/~crutches/SysProt and run it.
Choose the Log tab and select all the items in the Write to log box. Then select Create Log to start scanning. When it is done, a message window will appear with the location of the log file.
Please attach the log file to a post here; the Add Attachments links is below the orange Post button. Thanks
08-25-2009 11:07 AM
Did you disable Norton auto-protect before you ran the SysProt? If you have any other antivirus, or antispyware software on board that will need to be disabled as well.
Your SysProt is empty.
You can also try GMER, scan only.
After it is downloaded to your desktop, right click on the icon, go to properties, and click unblock and apply.
08-25-2009 12:21 PM
Re-ran with norton auto-protect disabled. check out the new file.
running gmer i'm guessing about 5-10mins into it i got a blue screen. but i did see 2 lines that were highlighted redwith ****HIDDEN**** after it.
hopeing that the sysprot log file will give you enough info..... wait a minute looking in the log under the kernel module, those first 2 looks like the ones that were red when gmer was scanning.
if that's the case can i just remove those 2 files and then run norton and see if that will fix the rest?
08-25-2009 12:35 PM
Do NOT do anything to remove files or run other programs without instructions from Quads. A couple of people have already run into trouble doing that. Rootkits are tricky.
08-25-2009 12:37 PM
You have two kbiwk rootkits requiring very specialized removal. Quads will be along in a while. We are getting a collection of rootkits this morning.
08-25-2009 05:05 PM
Quads is offline for a while, as he has been at this for about five hours already. I expect he will be at it for the same amount of time this evening or longer.
There are several still being worked on and a few ahead of you. You also have a double rootkit infection of a particular variant that requires a three stage remediation. This is going to take some time.
Also, this is a user to user help forum, which means we actually volunteer from home.
If you are in a hurry due to a personal time commitment, Symantec will be able to remove it for a fee.