Question:
How can I fix the garbage a rogue malware thing left behind?
?
2010-07-22 13:29:22 UTC
I went to a site to download a patch for a game and before I clicked anything I got bombarded with the Malware Doctor junk. It completely screwed up my computer and brought along 1800 different viruses and spyware. My Spybot Search & Destory did not detect it all, and even after I downloaded Malwarebyte's Anti-Malware and Stopzilla (which I feel is a scam now that I fell victim to it), there are still issues.

Stopzilla claimed to remove all of it and then prompted a reboot. I went through this process at least 8 times, and each time it found the same critical issues, claimed to clean them, and restart it. Keep in mind I actually paid for this program out of desperation and stupidity. Malwarebyte's Anti-Malware actually did remove some of it, but Spybot Search & Destroy goes nuts every time I start up my computer asking me to allow or deny changes.

The main leftovers of this fiasco are Winlogon and Boot.execute issues. Upon start up, a prompt from Spybot comes up saying:

Category: Winlogon Notifiers
Change: Value deleted
Entry: TPSvc
Old Data:
New Data:

And all I can do with that is allow the change. here is no option to deny the change, unless I hit ctrl+alt+del and end the task. I allowed it a few times, but it still pops up every time I start up.

The Boot.execute one only comes up half of the time I restart.I don't remember the exact wording, but the prompt says:

Category: Boot.Execute
Change: Value deleted
Entry: I don't remember
Old Data: boot.execute/ls*delete (something to that effect anyway)
New Data: boot.execute/

I can allow or deny that change, and I always deny it. Also, I had a search hijacker which redirected anything I clicked off of Yahoo, Google, or Bing into whatever it pleased. I could click a link to bestuy.com and it would take me to a fake website for the best buy on pottery. Again, all 3 programs claimed to delete that hijacker, but it still does it, and two IE pages open up with such fake websites in addition to my homepage when I open one Internet Explorer browser. I always end task before they can fully load.

So, is there anything I can do, or should I just smash the laptop on the pavement outside?
Six answers:
The Phlebob
2010-07-22 18:19:52 UTC
In my opinion, the main trick in finding and deleting malware is the use of Safe Mode With Networking. That sometimes keeps the malware from hiding or protecting itself.



Also, turn off System Restore to evict any copies of bad stuff that might be lurking there.



To get into Safe Mode with Networking:



1. Log out and reboot your machine.

2. When the machine starts the reboot sequence, press the F8 key repeatedly.

3. Select Safe Mode with Networking from the resulting menu.

4. Login. If the malware has changed your password, try logging in as Administrator. By default, Administrator has no password.

5. The machine will continue booting, but the Windows desktop will look different.

6. When you're finished doing what you need to do, log out and reboot back into normal mode.



Good luck.
Aurora
2016-08-24 07:44:07 UTC
2
2010-07-22 13:34:51 UTC
Here is how you remove the browser hijacker,

it might clear the other problem too.



First

click on Start > Run. Type in the following into the open box.



devmgmt.msc



then Click on OK. This will run Device Manager. In Device Manager,

click on View > Show Hidden Devices.



expand all the devices by clicking on the "Plus" sign. Now try to find

TDSSserv.sys or clbdriver.sys or oUltraf or seneka.sys,

right click on whatever one you found and select Disable.

Please make sure that you do not select the Un-Install option

otherwise infection will be back once you reboot your computer.



if none of them are there do not worry,

it could be something simpler but follow what comes next.



you will have to enable view hidden folders in folder options > view.



Delete everything in the windows temp folder,

C > Windows > Temp



Delete all cookies,

Delete all temporary internet files(not to be confused with windows temp files)

these are best deleted via your internet browsers.

it will save you messing about in the the hidden system files



reset internet explorer,

tools > internet options > Advanced tab > reset .



Delete everything in the prefetch folder.

C > Windows > Prefetch



Delete the hosts file,

C > Windows > System32 > drivers > etc > HOSTS

A clean hosts file will be written by windows when you reboot later.

Note: if you were using a custom Hosts file

you will need to replace any of those entries yourself.





Delete the flash cookies found in the macromedia, #Shared Objects folder.

c > users > "your name" > App Data > Roaming > macromedia > Flash player > #Shared Objects

delete everything you find in the #Shared Objects folder





Run a full scan with this

Sophos Anti-Rootkit : http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

and remove everything suspicious it finds.



Sophos Anti-Rootkit DOWNLOAD : https://secure.sophos.com/support/cleaners/sar_15_sfx.exe



Then run a full scan with this and remove what it finds.

Super anti spyware Pro : http://www.superantispyware.com/



Super anti spyware Pro DOWNLOAD : http://downloads.superantispyware.com/downloads/SUPERAntiSpywarePro.exe

this has a tool built in that can reset the URL prefix's

USE IT.



reset your router to default.



your redirect virus should now be gone.



download then run,

tdss killer to double check.



tdss killer : http://support.kaspersky.com/downloads/utils/tdsskiller.exe











.
Joey
2010-07-22 13:38:18 UTC
If it's that bad, reinstall the OS. If you can't do a system recovery, Just download an ISO off the internet of the same OS that you have now and you can use the product key found on the bottom of the laptop to activate it. Before doing that though, scan the ISO for viruses just in case and make sure you don't get a cracked version. Check the sources for some good ISOs.
2010-07-22 13:33:36 UTC
Did you do a full update of malware bytes prior to scanning?



Just uninstall the spybot search and destroy then. If malware bytes doesnt find anything your system is clean. Also try booting into safe mode by tapping f8 as your system boots and then run a scan with malware bytes.



You can also just do a factory reset on the machine by tapping F8 as it boots and choose repair computer.



Vote best if it works:)
Albundy
2010-07-22 14:02:27 UTC
Apart from the good tips you allready been given from our friends remember that windows it created a windows system restore and a virtual memory this two has to be disable any time you whant to do a trough out cleanign, disable or delete those services then clean up, after you cleaning up you can restore these services and most system are in control panel,system.


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...