hnic Topic Starter
Posts: 16
|
 |
« on: August 30, 2008, 08:20:11 PM » |
|
My computer recently became infected this has happened before so i kinda knew the path i needed to take i ran smitfraudfix and Mbam and all the problems are still here so i weant to go download combofix but i can't download it it just brings me to a window saying Failed to connect and can't establish a connection the same goes for not sure how it's spelled but keospry scanner or something like that and also the site bleepingcomputer.com. Any Help would be amazing Thanks.
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #1 on: August 30, 2008, 09:11:49 PM » |
|
|
|
|
|
hnic Topic Starter
Posts: 16
|
 |
« Reply #2 on: August 31, 2008, 02:43:15 PM » |
|
1.Unable to Download any Antivirus program. 2.Unable to Remove any known unwanted programs. 3.Downloaded CCleaner and ran the program. 4.Unable to download SUPERAntiSpyware 5.Ran MBAM found 2 infections (Ran it also last night in safe mode and found and deleted 7 infections. let me know if you would like that log as well.) 6.Tried to download new Java but says it needs to be opened with an application not sure what to open it with. 7.Unable to download HiJackThis
MBAM LOG
Malwarebytes' Anti-Malware 1.12 Database version: 722
Scan type: Quick Scan Objects scanned: 34756 Time elapsed: 5 minute(s), 11 second(s)
Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: (No malicious items detected)
Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
Registry Values Infected: (No malicious items detected)
Registry Data Items Infected: (No malicious items detected)
Folders Infected: (No malicious items detected)
Files Infected: C:\Documents and Settings\User\Local Settings\Temp\.ttD.tmp (Trojan.Downloader) -> Delete on reboot.
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #3 on: August 31, 2008, 02:48:08 PM » |
|
See if you can download ComboFix. Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1Link #2**Note: It is important that it is saved directly to your DesktopClose any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.
|
|
|
|
hnic Topic Starter
Posts: 16
|
 |
« Reply #4 on: August 31, 2008, 02:55:54 PM » |
|
I am unable to download Combofix. Is their any other link to download it?
|
|
|
|
|
|
|
hnic Topic Starter
Posts: 16
|
 |
« Reply #6 on: August 31, 2008, 03:24:28 PM » |
|
I was able to get it to my Desktop but when i tried to download it it said ComboFix found a rootkit and must restart it did that about 3 times. 
|
|
|
|
|
|
|
hnic Topic Starter
Posts: 16
|
 |
« Reply #8 on: August 31, 2008, 03:31:08 PM » |
|
I don't have any Anti Virus on this computer except for the pop-up when i start up which is apart of the infection. i double clicked and it had the little combofix with progress bar below it it finishes or appears to and that's when the rootkit problem will pop-up or nothing at all will happen.
|
|
|
|
|
|
|
hnic Topic Starter
Posts: 16
|
 |
« Reply #10 on: August 31, 2008, 03:42:22 PM » |
|
It doesn't get that far the only thing it does is i'm guessing the very first step like right after you click it to open it up.
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #11 on: August 31, 2008, 03:46:59 PM » |
|
Download SDFix by AndyManchesta and save it to your desktop. http://www.filedropper.com/sdfix_1Print out these instructions or copy them into a Notepad file and then save them to your desktop so you can read them in Safe Mode When using this tool, you must use the Administrator's account or an account with Administrative rights- Double click SDFix.exe and it will extract the files to %systemdrive%
- (this is the drive that contains the Windows Directory, typically C:\SDFix).
- DO NOT use it just yet.
Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". Open the SDFix folder and double click RunThis.bat to start the script. - Type Y to begin the cleanup process.
- It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
- Copy and paste the contents of the results file Report.txt in your next reply .
|
|
|
|
hnic Topic Starter
Posts: 16
|
 |
« Reply #12 on: August 31, 2008, 03:55:37 PM » |
|
I tried to download it and when i go to open the file it says windows has encountered a problem and needs to close. Is this the same file as SmitFraudFix? Because i had that previously installed.
|
|
|
|
|
evilfantasy Malware Removal Specialist Moderator
Thanked: 462 Posts: 11,769
Experience: Beginner OS: Windows 7

Calm like a bomb
|
 |
« Reply #13 on: August 31, 2008, 03:58:09 PM » |
|
No it's different. Try this and then try downloading again. Go to download the program HostsXpert- Unzip HostXpert to your Desktop
- Open up the HostXpert program.
- Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.
- Click Create Back Up
- Then click on Restore Microsoft's Host Files
- Close the HostXpert program
. ---------- Download to your desktop FixPolicies.exe, a self-extracting ZIP archive from HERE. Double-click FixPolicies.exe. Click the Install button on the bottom toolbar of the box that will open. The program will create a new Folder called FixPolicies. Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmdA black box will briefly appear and then close. Restart the computer so the changes can take effect.
|
|
|
|
hnic Topic Starter
Posts: 16
|
 |
« Reply #14 on: August 31, 2008, 04:01:02 PM » |
|
The Link to that first download doesn't exist it says. 
|
|
|
|
|