Hello again,
You have a
Rootkit infection, likely from using
BitTorrent. A rootkit is a set of software tools intended for concealing running processes, files or system data from the operating system.
You are strongly advised to do the following:
- Disconnect the computer from the Internet and from any networked computers until it is cleaned.
- Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.
- Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts. If you don't mind the hassle, change all your account numbers.
- From a clean computer, change all your passwords (ISP login password, your email address(es) passwords, financial accounts, PayPal, eBay, Amazon, online groups and forums and any other online activities you carry out which require a username and password).
DO NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.
Due to its rootkit functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be to do a reformat and reinstallation of the operating system (OS). However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.
To help you understand more, please take some time to read the following articles:
What are rootkits from Wikipedia
Why are rootkits dangerous
How do I respond to a possible identity theft and how do I prevent it
When should do a reformat and reinstallation of my OS
Where to backup your files
Restoring your backups
==========================
Before we start: Please be aware that
removing Malware is a hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and
I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.
In light of this it would be wise for you to back up any files and folders that you don't want to lose
before we start.
==========================
With reference to
Malware Removal P2P Programs Policy, please uninstall the following programs before we continue:
- Click on Start > Control Panel and double click on Programs and Features.
- Locate BitTorrent and click on the Uninstall button to uninstall it.
- Repeat for any other P2P programs that are installed.
- Close Control Panel when done.
==========================
Punkbuster warning
I see you have
Punkbuster installed. (read the section on
Published features)
This is spyware. Punkbuster can take control over various aspects of your computer, and some gaming tools not unlike Punkbuster also hinder their removals. By the definition we handle here, Punkbuster is actual spyware. Therefore, I now ask you to decide the following:
- Either we try to leave Punkbuster alone but there is no guarantee a spyware component doesn't 'accidentally' get taken out; so Punkbuster might break. This will, of course, also break your ability to play games using Punkbuster enabled servers.
- Or we can just remove Punkbuster. You can reinstall it afterwards if you wish, but please keep in mind that It is spyware.
- Another option is to not clean this computer at all. This ensures Punkbuster will continue to function.
Please let me know what you would like to do.
==========================
Uninstall Spybot - Search & Destroy
This program must be uninstalled as it can interfere with the cleaning process.
- Go to start > control panel > programs and features.
- Right click on each instance of:
Spybot - Search & Destroy
- Click Uninstall & then follow the prompts to remove them.
==========================
Download
CKScanner from
here
Important - Save it to your desktop.
Doubleclick
CKScanner.exe and click
Search For Files.
After a very short time, when the cursor hourglass disappears, click
Save List To File.
A message box will verify the file saved.
Double-click the
CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.
==========================
Disable Avast
- Right click on the avast! icon in system tray (looks like this:
) and choose (Avast shield control)
- Chose disable permanently.
- Note: Don't forget to re-enable it after the fix.
==========================
Disable WinPatrol
Programs, like WinPatrol, can Interfere with our fix, so we'll need to temporarily, disable them.
- Right click on the Scotty Dog icon near the clock and select Options.... A window will open.
- Select the Options tab.
- Uncheck (untick) the box..."Automatically run Winpatrol when computer starts".
- Close the WinPatrol window.
- Right click on the Scotty Dog icon again and select Exit Program.
WinPatrol has now been disabled.
==========================
TDSSKiller - Rootkit Removal Tool
Please download the
TDSSKiller.exe by
Kaspersky... save it to your Desktop.
<-Important!!!
- Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
Vista - W7 users: Right-click and select "Run As Administrator".
If TDSSKiller does not run... rename it. Right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. ektfhtw.com).
If you don't see file extensions, please see: How to change the file extension. - Click the Start Scan button. Do not use the computer during the scan!
- If the scan completes with nothing found, click Close to exit.
- If malicious objects are found, they will show in the "Scan results - Select action for found objects" and offer 3 options.
- Ensure Cure (default) is selected... then click Continue > Reboot now to finish the cleaning process.
- If Cure is not offered as an option, choose Skip.
- A log file named TDSSKiller_version_dd.mm.yyyy_hh.mm.ss_log.txt will be created and saved to the root directory. (usually Local Disk C:).
- Copy and paste the contents of that file in your next reply.
If, for some reason,you can't locate the text file to paste into your reply, just tell me, but DO NOT run the program a second time.
==========================
Please post the following in your next reply:
- the contents of CKFiles.txt
- the TDSSKiller log
- A description of how your computer is behaving