Recommended Posts

I don't make it a habbit to self infect. I get enough examples that I don't need to search.

here is a sample file from 2011.

http://www.ziddu.com...4/TDL4.rar.html

Password : infected

another

http://download.soft...rootkit+sample/

do a search for rootkit sample file download

This guys site has a bunch but you need to contact him/her for the password

http://contagiodump....paj-sample.html

[email protected]

You should know that there are many different sample files that you can get with all sorts of infections in them to see if your av/antimalware software can detect them. This is how many companies test the softwares capabilities as well as many third party companies rate new softwares, but they usually have internal lists and usually are pretty large.

Like I said google it and pick any, not my fault you don't know the search terms.

Yeah Malwarebytes doesn't get Rootkits at all, I use TDSSKiller for that.. Along with Malwarebytes and Combofix to clean the rest.

tdsskiller is pretty good, I use that with a quick scan of gmer afterwards (tdsskiller isn't 100% neither is gmer, the two together make a good team).

AVast scan completed both in windows and boot time, removed some items. The FBI scam thing appears to be gone but this happened last time too. Also ran malwarebytes and that also found a few entries. I told my friend they are on their own if it shows up again. I did everything I could - I ran out of time on the hijack this report as I had to have it packed up last night.

This malware is pretty easy to remove

Just boot to safe mode and tell it to show all hidden files and folders and system files.

There are 3 main folders the ransom malware always hides.

c:\programdata

c:\users\(username)\Appdata\local

c:\users\(useranme)\appdata\roaming

You'll find a weird exe in the root of those folders.

Check to make sure the malware didn't remove any of your program shortcuts (Start / all programs). if your program folders appear to be empty go to c:\users\(username)\local\temp and look for a folder called smtp. Inside that folder (if you have it) you will find folders numbered 1 through 4. One folder contains desktop icons, another folder contains your program shortcuts it deleted. Remember to restore those before you run ccleaner, other wise it will delete them.

if all of your files appear to be hidden then download and run this application. http://www.bleepingc...ownload/unhide/ This will go through and remove the hidden file attribute from all of your files. if your files are not hidden then skip to the next step.

Now run the following apps

ccleaner

tdsskiller

hitman pro

malwarebytes

and then make yourself a Kaspersky Rescue disc, and boot from it, update it and and do a full scan

http://support.kaspersky.com/viruses/rescuedisk

Then download and run patchmypc from www.patchmypc.net which will check to make sure all of your 3rd party software is up top date, such as Adobe reader, flash, java and a bunch of others. it will then update all of the software with 1 click.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • My problem with FF is I have to jump through hoops to get at least somewhat close to what Vivaldi gives me out of the box, with no real advantage that would make it worth my while. (But hey, apparently there's now at least experimental support for HDR in FF. I mean it's about a decade too late, but still...finally!) Brave I was never the least interested in, never saw the point, not to mention there's been quite a bit of drama surrounding them over the years. But I've been a faithful and very happy Opera user all the way back to 2001(ish), so once Vivaldi showed up following that awkward period of time after the key people left Opera and the company was sold, I never really looked back. And they never once made me question my choices.
    • Need to dust it again dangit, come on McDonalds, do your thing !?
    • I see it has more memory, more storage, a better CPU, and a stylus, as you said. Might be a good alternative. I see some refurbished for $150-200. I'm not scared of refurnbished, as a lot of parts in my house are refurbished/used. All are working atm.
    • "TeamViewer is the fast, simple and friendly solution for remote access over the Internet" Regarding the "friendly" description, has is stopped unceremoniusly booting your session after a couple of minutes accusing you of using it in a commercial environment?!
  • Recent Achievements

    • One Month Later
      Sopa flores earned a badge
      One Month Later
    • First Post
      StaticMatrix earned a badge
      First Post
    • Week One Done
      StaticMatrix earned a badge
      Week One Done
    • Rookie
      lamborghiniv10 went up a rank
      Rookie
    • One Month Later
      pinnclepd earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      PsYcHoKiLLa
      205
    3. 3
      +Edouard
      155
    4. 4
      Steven P.
      91
    5. 5
      ATLien_0
      79
  • Tell a friend

    Love Neowin? Tell a friend!