1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

hello and need help please "reveton trojan"

Discussion in 'Virus & Other Malware Removal' started by jam1980uk, May 11, 2012.

Thread Status:
Not open for further replies.
Advertisement
  1. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    wot does that tell you lol
     
  2. kevinf80

    kevinf80 Malware Specialist

    Joined:
    Mar 21, 2006
    Messages:
    10,146
    Tells me you may also have ZeroAccess rootkit infection, but lets plod on....

    OK, see if we can replace ipsec.sys. Do the following:

    Open Notepad, check the Format Menu and make sure Word Wrap is NOT selected. Then copy and paste the following from inside the code box to Notepad:

    Code:
    @echo off
    copy /y C:\WINDOWS\ServicePackFiles\i386\ipsec.sys C:\WINDOWS\system32\drivers >>log.txt
    notepad log.txt
    

    Next, Click on the File Menu, then Save As ... and click on the drop down menu to change the file type to All Files.
    Next navigate to your desktop, and enter the file name fixme.bat, and click Save.

    You should now find a new file on your desktop named fixme.bat. Double click on fixme.bat. Windows 7 or Vista users right click and select "Run as Administrator" agree any alerts.

    Then reboot.

    Next,

    Double click the reg file that you unzipped to the Desktop, agree the merge.

    Then reboot.

    Rerun Farbar Service Scanner exactly as before and post the log....
     
  3. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    just rebooting wots zeroaccsess
     
  4. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    Farbar Service Scanner Version: 17-05-2012
    Ran by John (administrator) on 19-05-2012 at 01:29:47
    Running from "G:\"
    Microsoft Windows XP Home Edition Service Pack 3 (X86)
    Boot Mode: Normal
    ****************************************************************
    Internet Services:
    ============
    Connection Status:
    ==============
    Localhost is accessible.
    There is no connection to network.
    Attempt to access Google IP returned error: Google IP is unreachable
    Attempt to access Yahoo IP returned error: Yahoo IP is unreachable

    File Check:
    ========
    C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
    C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
    C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
    C:\WINDOWS\system32\svchost.exe => MD5 is legit
    C:\WINDOWS\system32\rpcss.dll => MD5 is legit
    C:\WINDOWS\system32\services.exe => MD5 is legit
    Extra List:
    =======
    Bridge(11) BridgeMP(10) fssfltr(12) Gpc(3) IPSec(5) JSWSCIMD(9) NetBT(6) PSched(7) Tcpip(4) WSIMD(8)
    0x0C0000000500000001000000020000000300000004000000060000000700000008000000090000000A0000000B0000000C000000
    IpSec Tag value is correct.
    **** End of log ****
     
  5. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    and thanks again i cant thank you enought for every thing you have done thank you
     
  6. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    i gotta go bed now cant stay awake any more up at 5 again for work so ill check tommrow and post reply soon as i can shame you live so far i would have loved to buy you a pint thanks again and speak tommrow
     
  7. kevinf80

    kevinf80 Malware Specialist

    Joined:
    Mar 21, 2006
    Messages:
    10,146
    You`re very welcome....

    You should have connection available now, run the following:

    Delete any versions of Combofix that you may have on your Desktop, download a fresh copy from either of the following links :-

    Link 1
    Link 2

    • Ensure that Combofix is saved directly to the Desktop <--- Very important
    • Disable all security programs as they will have a negative effect on Combofix, instructions available Here if required. Be aware the list may not have all programs listed, if you need more help please ask.
    • Close any open browsers and any other programs you might have running
    • Double click the [​IMG] icon to run the tool (Vista or Windows 7 users right click and select "Run as Administrator)
    • Instructions for running Combofix available Here if required.
    • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
    • When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review

    ****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

    Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
    Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell us when you reply. Read Here why disabling autoruns is recommended.

    *EXTRA NOTES*
    • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
    • If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
    • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)

    Post the log in next reply please...

    Kevin
     
  8. kevinf80

    kevinf80 Malware Specialist

    Joined:
    Mar 21, 2006
    Messages:
    10,146
    Where are you from UK?
     
  9. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    im in bolton m8 and please can you point me to a good free anti virus plz and how you learn all this stuff
     
  10. kevinf80

    kevinf80 Malware Specialist

    Joined:
    Mar 21, 2006
    Messages:
    10,146
    I`ll sort you out with good security set up when we`re finished, see if you can run Combofix... Bolton eh, ah well I guess someones gotta live there...lol
     
  11. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    when i click on link it just give me a page with loads of symbols on it m8
     
  12. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    its ok sorry found it
     
  13. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    its runnng now m8 what that other infection you found m8
     
  14. jam1980uk

    jam1980uk Thread Starter

    Joined:
    May 11, 2012
    Messages:
    129
    combo fix found that root infection trying to fix it now
     
  15. kevinf80

    kevinf80 Malware Specialist

    Joined:
    Mar 21, 2006
    Messages:
    10,146
    Do not touch your PC as CF runs!!!
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/1052883