This thread's last reply is from December 13, 2009, 6:53 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Here they are: Thanks for your patience.
Todd
@lamedmem: I've deleted your post. Don't post to other users' topics, please.
@Todd:
Kaspersky Online Scanner
Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
- Read the requirements and privacy statement then click on the Accept button.
- The program will launch and start to download the latest definition files.
- You will be prompted to install an application from Kaspersky. Click Run
- Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
- Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
- Click on My Computer under Scan.
- Once the scan is complete, it will display the results. Click on View Scan Report.
- Click on Save Report As....
- Change the Files of type to Text file (.txt) before clicking on the Save button.
- Save this report to a convenient place.
- Copy and paste that information into your topic.
- The scan will take a while so be patient and let it run. As it scans your machine very deeply it could take hours to complete, Kaspersky suggests running it during a time of low activity.
If you need a tutorial, see here
Please run Notepad (start > All Programs > Accessories > Notepad) and copy and paste the text in the quote box into a new file:
@echo off
>Log1.txt (
ipconfig /all
nslookup google.com
ping -n 2 google.com
route print
)
start Log1.txt
del %0
- Go to the File menu at the top of the Notepad and select Save as.
- Select save in: desktop
- Fill in File name: test.bat
- Save as type: All file types (*.*)
- Click save.
- Close the Notepad.
- Locate and double-click tast.bat on the desktop.
- A notepad opens, copy and paste the content it (log1.txt) to your reply.
Here is the report from Kaspersky:
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, December 6, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, December 06, 2009 19:33:42
Records in database: 3337124
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Z:\
Scan statistics:
Objects scanned: 133114
Threats found: 3
Infected objects found: 2
Suspicious objects found: 2
Scan duration: 02:40:41
File name / Threat / Threats count
C:\2.js Suspicious: Trojan-Downloader.JS.gen 1
C:\4.js Suspicious: Trojan-Downloader.JS.gen 1
C:\Documents and Settings\Todd\Application Data\Sun\Java\Deployment\cache\6.0\44\3efada6c-5b5e90c5 Infected: Trojan-Downloader.Java.OpenStream.ad 1
C:\Documents and Settings\Todd\Application Data\Sun\Java\Deployment\cache\6.0\58\7b79707a-27e4ca01 Infected: Trojan-Downloader.Java.Agent.ab 1
Selected area has been scanned.
Did you do other part of instructions yet?
Sorry. It was late when I responded. I missed that part.
Hi,
Upload c:\windows\system32\
ws2_32.dll file to
http://www.virustotal.com and post back the results.
Run ComboFix with the following script and post back the results (let ComboFix update itself if asked for a permission):
Folder::
c:\documents and settings\Todd\Application Data\LimeWire
FileLook::
c:\windows\system32\Drivers\SSPORT.sys
File::
C:\2.js
C:\4.js
C:\Documents and Settings\Todd\Application Data\Sun\Java\Deployment\cache\6.0\44\3efada6c-5b5e90c5
C:\Documents and Settings\Todd\Application Data\Sun\Java\Deployment\cache\6.0\58\7b79707a-27e4ca01
Here is results from Virustotal:
MD5: 2ccc474eb85ceaa3e1fa1726580a3e5a
First received: 2009.02.17 13:15:24 UTC
Date: 2009.12.06 00:12:42 UTC [+1D]
Results: 0/38
Permalink: analisis/6e99d2fb4997e54e8b1b7d769cf2c0fae296a6441dc39984850ea26bfeb7e500-1260058362
I ran Combofix, but did not know to run that scipt with Combofix. Here is the log though.
Please run ComboFix with the provided script and let ComboFix update itself.
Sorry, but I do not know how to run Combofix with the earlier provided script. When I started Combofix, it said there was an update and I pressed "Yes". It loaded and Combofix started the scan. I did not have an opportunity to run that script.
Hi,
Open notepad and copy/paste the text in the quotebox below into it:
Folder::
c:\documents and settings\Todd\Application Data\LimeWire
FileLook::
c:\windows\system32\Drivers\SSPORT.sys
File::
C:\2.js
C:\4.js
C:\Documents and Settings\Todd\Application Data\Sun\Java\Deployment\cache\6.0\44\3efada6c-5b5e90c5
C:\Documents and Settings\Todd\Application Data\Sun\Java\Deployment\cache\6.0\58\7b79707a-27e4ca01
Save this as
CFScript
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.
Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log. Let me know about the remaining issues.
Here is the information you wanted. Thank You.
Hi,
You're still getting redirected by Google search results, right?
Please download
SystemLook from one of the links below and save it to your
Desktop.
Download Mirror #1
Download Mirror #2
- Double-click SystemLook.exe to run it.
- Copy the content of the following codebox into the main textfield:
:filefind
atapi.sys
- Click the Look button to start the scan.
- When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled
SystemLook.txt
Yes, problem still here. This is the text file you needed.
Hi,
Click
start->
run->type
cmd.exe and press enter. Type following command in command prompt window:
copy /y C:\WINDOWS\ServicePackFiles\i386\atapi.sys c:\atapi.sys.bak
You should get confirmation message 1 file(s) copied. Let me know if you didn't and stop following instructions below any further.