what shall i do next ? :-X
usually i dont come in between when essexboy is on the job but this is a rootkit and i suggest this:
1.download kaspersky tdss killer from here:http://support.kaspersky.com/viruses/utility
2.save it to your desktop and extract its contents and double click on tdsskiller.exe.
3.and run a scan the window will look like this:
http://i1116.photobucket.com/albums/k567/com155/kastdsskiller.png
4.once the scan is complete the tool will show u the results and will show the actions that will be taken against the malware or rootkit.
http://i1116.photobucket.com/albums/k567/com155/kastdsskiller1.png
5.it may ask u to reboot.
http://support.kaspersky.com/images/support_new/2663_3_en.png
6.do so and reboot and post logs on next comment.
NO THING WAS FOUND IN THE SCAN :-[
i again Boot scanned and those viruses are still there firmly & unshaken. i have moved those files to chest despite of it’s warning not to move the files which are in windows folder
i’m afraid what might happen when i re boot the system :-[
Userinit is infected - so we will see if there is a spare somewhere
-
Close any open browsers.
-
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
-
Open notepad and copy/paste the text in the quotebox below into it:
SRPeek:: c:\windows\system32\userinit.exe
Save this as CFScript.txt, in the same location as ComboFix.exe
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
when i dragged the file into combofix it updated to new version and again restarted the combofix to complete updating. when combofix restarted it continued to the process by itself.
did the updating broke the process of what u stated above or is it alright.
any how i have attached the log file please find it .
i sincerely appreciate you people’s job here, please guide me till the end.
thanks ans looking forward.
Well 'tis no longer reporting that userinit is infected ;D
Could you now see if Avast is able to delete the files… If not then let me know the file names - I will then do a search for them and then delete
actually i moved them to chest. they are in chest now. should i restore them and do the scan of combofix with that log file ? or just delete them from the chest. ?
what shall i do to the VIRUS IN THE CHEST as they were in the C:\windows\system32
shall i delete them from the chest? will it not effect the OS ?
please CHECK THE ATTACHMENT
You’d better leave the in the chest for 1 week or so.
i’m puzzled ??? what will make the difference if i leave it for a week or so ?
what will happen by then :
Files cant target you if it is in the chest. If you leave it a week or more you will see if it still detected and if it isnt then its was a false positive.
So you better let it in the chest like he said just for be sure.
Mr.Agent
They are quite safe in the chest
There will be no ill effect if you delete them as they are not windows files
Let it run for a day or so and if you are happy I will remove my tools
hi, it’s been a week i didn’t find any virus.
though i have not done a boot scan (where i found this viruses)
so how shall i proceed with this viruses in chest ?
Thanking you for your co-operation
Try to Install Norton DNS and check the redirection.
where shall i download Norton DNS ?
I need a little guide please, coz when i searched in google most of then where directing towards below link.
http://www.nortondns.com/DNS-setupWin.html
and i found this link which will change the DNS settings of my network :o
is this link the correct one, where i will get the file to said me to download :-\
Are you getting redirections ?
[/quote]
Are you getting redirections ?
[/quote]
after Installing Norton DNS my internet network got disconnected, after that i uninstalled it.
when i opened mozilla, it redirected to yahoo.com but my home page is google, this redirecting to yahoo happens even some times in “internet explorer browser 8”… not always but some times…
Would you like me to take a look ?