Just let it run. ![]()
Rebooting after like an hour :d posting logs when it reboots( 3 minutes or so)
And here is the log ![]()
Hi,
Seems like we have some files to look for…
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
[*]Right-click and Run as Administrator SystemLook.exe to run it.
[*]Copy the content of the following codebox into the main textfield:
:filefind
*sfcfiles.dll
*ipsec.sys
*psched.sys
[*]Click the Look button to start the scan.
[*]When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Found nothing ;'(
Hi,
Do you have your Windows CD available or are you able to borrow one?
We may need it later.
Edit found my recovery discs, And i do have a 32bit copy, not the 64bit one though;*
Another edit… Opened the Windows Disk case, and it has a 32 bit copy AND 64bit so im ready for the next step;)
Great! I am glad that you found it. ![]()
Please download [url=http://download.bleepingcomputer.com/farbar/FSS.exe][b]Farbar Service
Scanner[/b][/url] and run it on the computer with the issue.
[*]Make sure the following options are checked:
[*]Internet Services
[*]Windows Firewall
[*]System Restore
[*]Security Center
[*]Windows Update
[*]Press “Scan”.
[]It will create a log (FSS.txt) in the same directory the tool is run.
[]Please copy and paste the log to your reply.
Farbar Service Scanner Version: 22-02-2012
Ran by Owner (administrator) on 25-02-2012 at 16:12:35
Running from “C:\Users\Owner\Downloads”
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
Internet Services:
Connection Status:
Localhost is accessible.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.
Windows Firewall:
Firewall Disabled Policy:
System Restore:
System Restore Disabled Policy:
Action Center:
Windows Update:
File Check:
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****
Question, will the disc still work if it was used on another pc?(not 64bit but 32bit disk)
Hi FireCubic,
Let’s check something out before we continue…
Please delete the current version of Combofix.exe from your desktop and download a new version from here to your desktop.
Disable your AntiVirus and AntiSpyware applications.
Right-click and Run as Administrator on the Combofix.exe and follow the prombts on your display. When finish, it will create a C:\Combofix.txt. Please post this log for further review.
OMG I TRY TO OPEN ANYTHING AMD IT SAYS " illegal operation attempted on a registry key that has been marked for deletion. And then where the items at Help!!! It’s just stuck at " pecFind by billy o’neal III version 1.5.6. Syntax error and then when it was created… Heelppppp
Now combo fix screwed up my comp… Great
Edit… System restored now everythings back to normal…except i think the Rootkits still on my computer…
Hi,
If I would have seen this in time I would have had you just reboot the system once or twice and that would have fixed the problem. It just means that ComboFix had not released the registry yet.
Let’s see what we have to work with now. ![]()
Please run a new scan with OTL. In the Custom Scan place the following:
netsvcs
Post the log created by OTL into your next reply. Maybe we will get lucky and not have to do too much work to get back to where we were. ![]()
Can I just clean install windows without a back up because this is really taking long and is possibly not even gonna kill the rootkit…
Sure you can do that too if that is something that you would like to do.
Yea, but what happens if I don’t have backup files?
Well if you don’t have your files backed up someplace than what ever you don’t have backed up will be lost if you format your system and start anew. If you are on your computer now and able to access those files you could start backing up your personal files (pics, music, letters…)
Well, I just recovered my computer to before first use and backed up my files as I forgot about dell data safe. Do u wantt me to run anything to see if the rootkit is still there or anything?
That would be good.
If you would run OTL again I would have a pretty good idea of what we are looking at. When you get that completed just post the log into your next reply.
Alright