I am not sure that you have the same infection as the others. Sounds like you have a bigger mess going on....
If you are able to install MBA-M, try this:
First, Rename mbam.exe to zappa.com
See if it will run.
If so, please have it remove all that it finds and post the log for us.
If it does not run, you can try the following, but it is strictly a "Run At Your Own Risk!" proposition:
* Download KILLBAD.zip and EXTRACT the KILLBAD folder to your C:\ Drive
* Use START > RUN >Command.com to get a command prompt
* TYPE C:\KILLBAD\KILLBAD.bat ENTER
* If the tool is able to run, a log should eventually pop up in notepad.
Please post that for us.
-- I gotta say, though, it sounds like you have a larger issue at play and I am not sure this would be the best idea...
Best Luck :)
PP
PhilliePhan
Central Scrutinizer
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
New linky for KILLBAD.zip
KILLBAD.zip
You might be able to run it by navigating to C:\KILLBAD\KILLBAD.bat and DoubleClicking the .bat file - that ought to work.
PP :)
PhilliePhan
Central Scrutinizer
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
I have not yet tried to rename the mbam.exe yet, but does it seem like i might have to reformat? What things could happen if i were to run the killbad.zip? I feel like my drivers might have not been updated correctly. Steam had asked me a while back to update my drivers which was kinda wierd. I did what valve asked but it kinda screwed some stuff up. Do you think that might have to do with anything? I need to reformat anyways i havent in like 2 years so i feel its time. Do you think that it might be best if i were to just do that instead of try to save my PC?
Well . . . If you are going to format anyway, there is probably no harm in trying the other options first.
Try renaming mbam.exe first.
Killbad probably won't do any harm.
Let us know how you want to proceed....
PP :)
PhilliePhan
Central Scrutinizer
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
As it turns out, this infection is a real pain in the ass! My simple little batch ain't gonna do it, lol!
Looks like there are some serious rootkit components to this.
Generally, when I see baddies such as this, I advise a reformat because of the nature of the rootkit beast.
However, if you'd like to give cleaning this a shot, we can try to get combofix to run.
To do that, we'll need to take a different tack.
If you'd like to continue, please do the following:
Please Download Win32kDiag and save it to your Desktop.
• http://ad13.geekstogo.com/Win32kDiag.exe
• http://download.bleepingcomputer.com/rootrepeal/Win32kDiag.exe
-- DoubleClick on Win32kDiag.exe to run it. Let it run for as long as it needs to.
-- When it says Finished – Press any key to exit, do that to exit the program.
-- You should now have a Win32kDiag.txt on your Desktop. Please post the entire log for me and we’ll go from there.
I will check back as soon as time permits.
Cheers :)
PP
PhilliePhan
Central Scrutinizer
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
I will try again to see if i can get it to work?
Yes - try that.
Delete your copy ofWin32kDiag and then download a fresh copy and try it again.
PP :)
PhilliePhan
Central Scrutinizer
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
I am not sure that you have the same infection as the others. Sounds like you have a bigger mess going on....
I think my initial suspicion was probably on target.
You could try running KILLBAD as per posts 4 & 5 and see if the log comes up. At the least, it'll show a key registry entry that we might need to fix to try to get Win32kDiag to run.
Other than that, I'm not sure I have any tricks up my sleeve.....
PP:)
PhilliePhan
Central Scrutinizer
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110