This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Malware Assistance - can't remove with my own small brain :(

47 min read

This thread's last reply is from January 14, 2009, 12:05 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

OK,
Here's my last shot... :)

Scanner results
Scan taken on 08 Jan 2009 21:55:57 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
G DATA Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
Hi

Yes, that one is clean! Let's use it now to replace the infected files :)

Download Combofix
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


Please download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Do not run ComboFix yet!!


COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    FCopy::
    c:\windows\ServicePackFiles\i386\userinit.exe | C:\WINDOWS\system32\userinit.exe
    c:\windows\ServicePackFiles\i386\userinit.exe | C:\WINDOWS\system32\dllcache\userinit.exe

  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

If ComboFix didn't reboot your computer yet, please do it now by yourself. Then, go again to jotti and upload this file:
C:\WINDOWS\system32\userinit.exe

Post the results in your next reply.

Also, let's have a look if there are any other copies present which may be infected:
Download FileFind by Atribune and unzip it to your Desktop.
  • Double click on FileFind.exe to open the programme.
  • Enter userinit.exe into the File: box.
  • Click on the Search button.
  • After a while a list of file locations will appear in the List of Files: box.
  • Click on the Export button.


This will create a Notepad file named Export.txt located in the C:\ folder, copy and paste it to your next post please.

In your next reply, please post:
1) The ComboFix log
2) The Jotti results
3) The FileFind log
Hi again

It's been 3 days since my last reply - do you still need help? If not, please tell us so we can close the thread.

If you don't reply within 2 days, this thread will get closed.
lack of Response