Help removing malware


Recommended Posts

I need help removing malware from my XP Pro machine.

I first noticed something was wrong when Web browsing was unuusally slow on that machine and sometimes wouldn't work at all. Windows Task manager showed a process called ns233.tmp running. Killing it would just restart itself.

Google results would point to go.google.com rather than the result when clicked.

Also when Windows loads NOD32 would display a message that it had blocked access to the URL in the attachment.

First thing I did was to run a virus scan. Although when I came back to check on it, the machine had locked up, NOD32's reports didn't seem to have anything.

Then I ran PC Tools Spyware Doctor, which removed some tracking cookiees and spyware that didn't match the symptoms at all.

I Googled ns233.tmp and found that it seems to be caused by known malware. Unlike that user however, I never installed "XP antivirus". I went to all the computer's user temp folders and cleared them out, deleting an instance of ns233.tmp in a Temp folder would create another instance with another random name xxx.tmp. On restarting however the xxxx.tmp files were back, suggesting rootkit-like activity.

I then Googled "tdss/crcmds/main" and found what seems like another threat. I searched my Windows\SYSTEM32 folder and the registry but found no traces of anything that matched TDSS.

I tried running Spybot but its process just sits there.

I tried installing Malwarebytes Anti-Malware, but it won't install. The installer process sits there but nothing appears.

I even tried booting into safe mode. However it locks up when getting to the logon screen, leaving me a black screen. The words "safe mode" appear in the corners with the build number but otherwise nothing works besides the mouse.

I really don't want to have to reformat. Can someone please help?

post-1865-1228077883.jpg

Link to comment
https://www.neowin.net/forum/topic/704300-help-removing-malware/
Share on other sites

Do you have another machine you can put the drive in and run scans on?

That would be my first suggestion.

I've seen that problem in safe mode occur before. If you want to try it again, when it gets to the point where you think its locked up, try CAD. Then go to file -> new task and run c:\windows\explorer.exe

Another thing you can try is to go to c:\windows\system32\drivers\etc\hosts\ and add an entry to the hosts file of 72.233.114.123 to 127.0.0.1 so that your computer no longer tries to get out to the net and access that site.

Another thing you can try is to go to c:\windows\system32\drivers\etc\hosts\ and add an entry to the hosts file of 72.233.114.123 to 127.0.0.1 so that your computer no longer tries to get out to the net and access that site.

Won't work as the hosts file is only used to resolve domains to IPs, not IPs to IPs. You can check for go.google.com in there though.

What seems to be happening now is that sometimes some Web sites will be accessible and then randomly stop working in all browsers.

Thanks, but Malwarebytes Anti-Malware won't install

Wow. Ironic. I just had this happen to me last week. Althou it was my fault opening a file i didnt trust. I got something like this that would stop browsing, avoided my antivirus(ZoneAlarm, then Kasper. Used a friends PC to use NOD all passed).

Funny thing is, I installed PC Tools and it found it, couldnt remove it. What I had was like this, but it masked as autorun. So all my autorun inf's were now being deleted and recreated with malcious code.

Dumb this is, I didnt notice until i turned on my 1st External, thats when zonealarm passed a popup saying autorun.inf on "drives a b c d" were infected.

I tried my best to remove it. I suceeded somewhat,t hen i got this EXACT tdss and main crap and tried my best and then reformated.

So my advice is, if you cnat get by it, backup stuff, DO NOT IMAGE, and reformat.

I was almost going to Ghost my drive when my friend went "em your gonna be carrying it again after you reformat" to which i facepalmed myself and backed up my stuff and reformatted.

Its been lovely since and I needed a reformat.

I hope you imaged your clean install. If not this would be a good time to do it.

Wow. Ironic. I just had this happen to me last week. Althou it was my fault opening a file i didnt trust. I got something like this that would stop browsing, avoided my antivirus(ZoneAlarm, then Kasper. Used a friends PC to use NOD all passed).

Funny thing is, I installed PC Tools and it found it, couldnt remove it. What I had was like this, but it masked as autorun. So all my autorun inf's were now being deleted and recreated with malcious code.

Dumb this is, I didnt notice until i turned on my 1st External, thats when zonealarm passed a popup saying autorun.inf on "drives a b c d" were infected.

I tried my best to remove it. I suceeded somewhat,t hen i got this EXACT tdss and main crap and tried my best and then reformated.

So my advice is, if you cnat get by it, backup stuff, DO NOT IMAGE, and reformat.

I was almost going to Ghost my drive when my friend went "em your gonna be carrying it again after you reformat" to which i facepalmed myself and backed up my stuff and reformatted.

Its been lovely since and I needed a reformat.

Angel,

PM me. I have a private FTP server with malware removing programs. I can either remote into your computer and help you out, or I can give you specific access to certain files I have for cleaning stuff up.

TDSS is normally followed by karna.dat and some other bad virus' pretending to be a real antivirus program, and other junk. Trojan Remover has almost ALWAYS fixed these problems (On 1 machine the registry become corrupt because of the removal of these files and I had to completely reformat (destructive))

  • 7 months later...

I hope this will solve your problem !!

http://pcrevolutions.blogspot.com/2009/05/...ayed-error.html

What seems to be happening now is that sometimes some Web sites will be accessible and then randomly stop working in all browsers.

Thanks, but Malwarebytes Anti-Malware won't install

Try renaming the file nd then try to execute it

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Waymo recalls self-driving software after cars enter closed freeway work zones by Paul Hill Waymo, the self-driving car maker owned by Alphabet – the parent company of Google –, has recalled some of its fifth-generation Automated Driving Systems (ADS). It did so after some of its cars drove through closed construction zones. According to the National Highway Traffic Safety Administration (NHTSA), the affected vehicles were capable of driving through a closed freeway construction zone and continuing to drive at speed. The listing on the NHTSA website says that Waymo is currently developing a solution to fix this issue, but in the meantime, freeway driving is being restricted. Waymo will update its ADS software so that vehicles can detect when they can avoid entering construction zones. According to the Safety Recall Report, on April 20, 2026, Waymo’s Field Safety Committee began meetings reviewing an event from April 11, 2026, and five events from April 19, 2026, where Waymo’s autonomous vehicles didn’t recognize and drove past ramp closure signs into the pre-planned freeway construction zones. This took place in Phoenix, Arizona. Separately, on May 18, 2026, seven Waymo vehicles entered freeway lanes with active construction in the San Francisco Bay Area by driving between cones that were placed to show the lane was closed. On the back of both of these events, Waymo restricted freeway driving until it could address the issue. In June, Waymo’s Safety Board reviewed the issue and additional information related to ADS performances around construction zones; then, as a result, it decided to conduct a recall. This development is not good for Waymo as it adds to a growing list of technical hiccups its cars have experienced. Ultimately, it will lead to more scrutiny from lawmakers around the world who will be more cautious about letting autonomous vehicles on their roads without tighter regulation. For readers in areas where Waymo operates, does this news make you more wary about stepping into one of these vehicles?
    • I'm still on Windows 10 22H2 because I didn't want to deal with all the issues in Windows 11, so I waited almost a week before installing the latest Patch Tuesday update (KB5094127), I went ahead and did it, and it was a huge mistake—ever since then, my File Explorer has seen a performance drop of about 30% when transferring large files... Once again, Microsoft has outdone itself! This update cannot be uninstalled, either through the Control Panel (via Settings) or by accessing Advanced Startup Options. The only possible alternative would be to use system restore points, but I’d have to reinstall all app and driver updates (and there’s no guarantee it would work). Or there’s the “nuclear option” of a in-place repair without losing files or apps, but even then, all my customizations would be lost! Microsoft just can’t help but mess everything up! Way to go, Microsoft! But I still don’t want your c****y Windows 11!
    • Microsoft: Windows 11 could finally solve a major issue across AMD, Nvidia, and Intel GPUs by Sayan Sen While Microsoft has been trying to improve it, Windows 11 is definitely not flawless, as even today some issues are taking a year to publicly acknowledge. However, one area of trouble that may finally see much better results soon is graphics driver crashes. Work on graphics driver timeouts, also called Timeout and Detection Recovery (TDR), is not new as the latest WDDM 3.2 also has specific improvements regarding it. Windows Display Driver Model (WDDM) version 3.2 is supported on Windows 11 24H2 and 25H2. However, with the upcoming version 26H2, TDR crash diagnosis could go to the next level as Microsoft is introducing a new DirectX 12 API feature called "DirectX Dump Files". Similar to how system memory dump files work when a system crashes or freezes or encounters any such major issue, DirectX Dump Files (DDF) will essentially record a snapshot of the GPU execution right at the moment a graphics-related crash or hang or freeze occurs, so that developers can better understand and diagnoze these TDR and timeout detection errors. The dump will be available as a .dxdmp file for analysis and it will be a comprehensive dump file generated with detailed insights about the hardware, drivers, Windows, as well as the affected application. This should be another welcome change in this department. Earlier at GDC 2026, when the technology was first debuted, Microsoft had shared more details regarding it. The company had explained how DDF is designed to gather data from every layer of the graphics stack into a single file, eliminating the need for developers to manually correlate logs from multiple tools. As mentioned above, the dump can contain a lot of useful details like GPU hardware state information such as register values, shader program counters, page fault virtual addresses, shader memory data, and command buffers. Alongside that, it also captures DirectX runtime and kernel information, including D3D objects, pipeline state objects, device error data, adapter details, and CPU call stacks. Microsoft says the feature has been built around two primary use cases: retail device removals and local device removals. The former allows developers to collect crash information from end users' systems in the field, while the latter helps QA teams and developers investigate issues on test machines. Developers will also be able to include up to 2 MB of custom application data through new D3D12 APIs, providing additional context for troubleshooting. In addition, Microsoft is introducing three dump collection modes ranging from zero-overhead capture, which has no runtime performance impact on supported hardware, to higher-detail modes that collect more vendor-specific debugging data. On compatible Tier 2 hardware, zero-overhead dumps will be enabled by default, meaning developers may begin receiving useful crash diagnostics without making any code changes. The table below explains the three tiers: Tier Description NO_OVERHEAD Enables crash capture with no runtime cost and is suitable for broad deployment MEDIUM_OVERHEAD Provides a balance, capturing additional diagnostic data with moderate impact HIGH_OVERHEAD Collects the most detailed GPU and driver state available, enabling deeper investigation at the cost of higher runtime overhead In terms of availability, the company expects broader release to be around the fall of 2026, which should be right around the time when Windows 11 version 26H2 lands. Right now, DirectX Dump Files are available as a preview and currently, only AMD has the compatible AgilitySDK Developer Preview driver version 26.10.07.02. You can find the official announcement post here on Microsoft's website.
    • And with SO much better perf than the laggy mess that is Files.
  • Recent Achievements

    • First Post
      BizSAR earned a badge
      First Post
    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      598
    2. 2
      +Edouard
      190
    3. 3
      PsYcHoKiLLa
      80
    4. 4
      Michael Scrip
      76
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!