Help removing malware


Recommended Posts

I need help removing malware from my XP Pro machine.

I first noticed something was wrong when Web browsing was unuusally slow on that machine and sometimes wouldn't work at all. Windows Task manager showed a process called ns233.tmp running. Killing it would just restart itself.

Google results would point to go.google.com rather than the result when clicked.

Also when Windows loads NOD32 would display a message that it had blocked access to the URL in the attachment.

First thing I did was to run a virus scan. Although when I came back to check on it, the machine had locked up, NOD32's reports didn't seem to have anything.

Then I ran PC Tools Spyware Doctor, which removed some tracking cookiees and spyware that didn't match the symptoms at all.

I Googled ns233.tmp and found that it seems to be caused by known malware. Unlike that user however, I never installed "XP antivirus". I went to all the computer's user temp folders and cleared them out, deleting an instance of ns233.tmp in a Temp folder would create another instance with another random name xxx.tmp. On restarting however the xxxx.tmp files were back, suggesting rootkit-like activity.

I then Googled "tdss/crcmds/main" and found what seems like another threat. I searched my Windows\SYSTEM32 folder and the registry but found no traces of anything that matched TDSS.

I tried running Spybot but its process just sits there.

I tried installing Malwarebytes Anti-Malware, but it won't install. The installer process sits there but nothing appears.

I even tried booting into safe mode. However it locks up when getting to the logon screen, leaving me a black screen. The words "safe mode" appear in the corners with the build number but otherwise nothing works besides the mouse.

I really don't want to have to reformat. Can someone please help?

post-1865-1228077883.jpg

Link to comment
https://www.neowin.net/forum/topic/704300-help-removing-malware/
Share on other sites

Do you have another machine you can put the drive in and run scans on?

That would be my first suggestion.

I've seen that problem in safe mode occur before. If you want to try it again, when it gets to the point where you think its locked up, try CAD. Then go to file -> new task and run c:\windows\explorer.exe

Another thing you can try is to go to c:\windows\system32\drivers\etc\hosts\ and add an entry to the hosts file of 72.233.114.123 to 127.0.0.1 so that your computer no longer tries to get out to the net and access that site.

Another thing you can try is to go to c:\windows\system32\drivers\etc\hosts\ and add an entry to the hosts file of 72.233.114.123 to 127.0.0.1 so that your computer no longer tries to get out to the net and access that site.

Won't work as the hosts file is only used to resolve domains to IPs, not IPs to IPs. You can check for go.google.com in there though.

What seems to be happening now is that sometimes some Web sites will be accessible and then randomly stop working in all browsers.

Thanks, but Malwarebytes Anti-Malware won't install

Wow. Ironic. I just had this happen to me last week. Althou it was my fault opening a file i didnt trust. I got something like this that would stop browsing, avoided my antivirus(ZoneAlarm, then Kasper. Used a friends PC to use NOD all passed).

Funny thing is, I installed PC Tools and it found it, couldnt remove it. What I had was like this, but it masked as autorun. So all my autorun inf's were now being deleted and recreated with malcious code.

Dumb this is, I didnt notice until i turned on my 1st External, thats when zonealarm passed a popup saying autorun.inf on "drives a b c d" were infected.

I tried my best to remove it. I suceeded somewhat,t hen i got this EXACT tdss and main crap and tried my best and then reformated.

So my advice is, if you cnat get by it, backup stuff, DO NOT IMAGE, and reformat.

I was almost going to Ghost my drive when my friend went "em your gonna be carrying it again after you reformat" to which i facepalmed myself and backed up my stuff and reformatted.

Its been lovely since and I needed a reformat.

I hope you imaged your clean install. If not this would be a good time to do it.

Wow. Ironic. I just had this happen to me last week. Althou it was my fault opening a file i didnt trust. I got something like this that would stop browsing, avoided my antivirus(ZoneAlarm, then Kasper. Used a friends PC to use NOD all passed).

Funny thing is, I installed PC Tools and it found it, couldnt remove it. What I had was like this, but it masked as autorun. So all my autorun inf's were now being deleted and recreated with malcious code.

Dumb this is, I didnt notice until i turned on my 1st External, thats when zonealarm passed a popup saying autorun.inf on "drives a b c d" were infected.

I tried my best to remove it. I suceeded somewhat,t hen i got this EXACT tdss and main crap and tried my best and then reformated.

So my advice is, if you cnat get by it, backup stuff, DO NOT IMAGE, and reformat.

I was almost going to Ghost my drive when my friend went "em your gonna be carrying it again after you reformat" to which i facepalmed myself and backed up my stuff and reformatted.

Its been lovely since and I needed a reformat.

Angel,

PM me. I have a private FTP server with malware removing programs. I can either remote into your computer and help you out, or I can give you specific access to certain files I have for cleaning stuff up.

TDSS is normally followed by karna.dat and some other bad virus' pretending to be a real antivirus program, and other junk. Trojan Remover has almost ALWAYS fixed these problems (On 1 machine the registry become corrupt because of the removal of these files and I had to completely reformat (destructive))

  • 7 months later...

I hope this will solve your problem !!

http://pcrevolutions.blogspot.com/2009/05/...ayed-error.html

What seems to be happening now is that sometimes some Web sites will be accessible and then randomly stop working in all browsers.

Thanks, but Malwarebytes Anti-Malware won't install

Try renaming the file nd then try to execute it

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • If I ever get that issue I will let you know how I fix it
    • As I've been usually saying lately - we all can thank "AI" for this.
    • Friday Windows 11 preview builds are here. Insiders in the Experimental (formerly Dev) and Beta Channel can download builds 26300.8697 and 26220.8690. My Windows11 device on the Preview Channel just got 26220.8728. My guess is this build is a nightly update from 26220.8690.
    • Traffic has a surprisingly unexpected impact on your surroundings by Sayan Sen Image by Radik 2707 via Pexels A collaborative study by researchers from several Israeli institutions found that everyday pollution from traffic and industrial activity measurably changed the atmospheric electric field over the Tel Aviv metropolitan area, providing new evidence of how human activity can influence the lower atmosphere. The research was led by Dr. Roy Yaniv of the Hebrew University of Jerusalem and the Gertner Institute at Sheba Medical Center, Dr. Assaf Hochman of the Fredy & Nadine Herrmann Institute of Earth Sciences at the Hebrew University, and Prof. Yoav Yair of Reichman University. The study also involved Itay Froomer, a student from Hadera High School and the Israeli Museum of Medicine and Science (Technoda), who carried out the work as part of the Ministry of Education's 5-unit physics research track. The researchers focused on the atmospheric electric field under fair-weather conditions. Even in the absence of storms, a weak electric field naturally exists between Earth's surface and the atmosphere. One of the main ways scientists measure this field is through the Potential Gradient (PG), which is the inverse of the vertical component of the electric field. PG is a key part of the global electric circuit, a planet-wide system of electrical currents maintained by thunderstorms and electrified clouds around the world. Scientists have long known that the atmospheric electric field can be influenced by factors ranging from large-scale atmospheric processes to local weather conditions such as dust, fog and clouds. Human-made pollution is also known to play a role, but understanding exactly how urban emissions affect the electric field close to the ground has remained an area of ongoing research. To investigate this relationship, the team analyzed measurements from a newly installed electric field mill, an instrument used to continuously monitor the strength of the atmospheric electric field. The instrument was installed at the Center for Technological Education (Roter House) in Holon and became operational in August 2024. It was funded by Israel's Ministry of Education and the Holon municipality. The electric field mill forms part of a broader monitoring network that includes nearby meteorological stations and air-quality monitoring sites. This allowed researchers to compare electric field measurements with detailed weather data and pollution records to better understand what was driving changes in the Potential Gradient. The study focused on two major urban pollutants: fine particulate matter (PM2.5) and nitrogen oxides (NOx), both commonly produced by vehicle traffic and industrial activity. PM2.5 refers to microscopic airborne particles small enough to remain suspended in the atmosphere for extended periods, while NOx is a group of gases released during fuel combustion. Researchers examined daily, weekly and seasonal patterns in the atmospheric electric field and compared them with changes in pollutant concentrations. Their analysis revealed a clear relationship between NOx levels and changes in the Potential Gradient, particularly during morning and evening rush hours when traffic emissions were at their highest. “What we observe is a direct physical link between emission peaks and electrical variability,” explained Dr. Roy Yaniv. “NOx reduces atmospheric conductivity very quickly, so the electric field responds almost instantaneously during traffic rush hours.” Atmospheric conductivity describes how easily electrical charges move through the air. According to the researchers, nitrogen oxides rapidly alter this conductivity, causing a near-immediate response in the electric field. PM2.5, however, was associated with a delayed response. The researchers attributed this difference to the particles' longer atmospheric residence time, meaning they remain in the atmosphere for longer periods, as well as their different microphysical interactions with surrounding air and atmospheric components. The study also identified a pronounced "weekend effect." In Israel, traffic volumes and some industrial activity decline significantly on Fridays and Saturdays. During these periods, concentrations of both NOx and PM2.5 dropped, and corresponding changes were observed in the atmospheric electric field. “The weekend signal demonstrates just how sensitive the electric field is to changes in human activity,” the researchers noted. “When emissions decline, the electrical environment adjusts at once, providing a high-resolution indicator of urban atmospheric conditions.” The findings showed that pollution levels can influence not only the chemical composition of the atmosphere but also its electrical properties. Researchers said the results strengthened the case for using atmospheric electricity as an additional tool for environmental monitoring, particularly in densely populated urban areas where anthropogenic, or human-caused, influences are most pronounced. The study also pointed to potential public health applications. By combining air-quality measurements with observations of atmospheric electricity, researchers said they could gain a more complete picture of how urban atmospheric conditions change over time. “Integrating air-quality data with electric-field measurements gives us a clearer picture of how the lower atmosphere evolves moment by moment,” the researchers added. “It’s a framework that can support both scientific insight and practical environmental decision-making.” Beyond the scientific findings, the project highlighted a collaboration between universities, public institutions and secondary education. Researchers said the work demonstrated how students could take part in real-world environmental research while contributing to studies of air quality, atmospheric processes and their potential effects on society. Source: Hebrew University, ScienceDirect This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing
  • Recent Achievements

    • Week One Done
      AMV earned a badge
      Week One Done
    • One Month Later
      AMV earned a badge
      One Month Later
    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      540
    2. 2
      +Edouard
      186
    3. 3
      PsYcHoKiLLa
      80
    4. 4
      Michael Scrip
      77
    5. 5
      Steven P.
      72
  • Tell a friend

    Love Neowin? Tell a friend!