WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


description"Security Center Alert" attack Empty"Security Center Alert" attack

more_horiz
A fully updated Norton Internet Secuity allowed in this malware. I didn't click to install this "Malware Defense", but still, now NIS won't load, internet's down, and MBAM won't run either in Safe Mode or Normal Mode. System Restore just hangs either in Safe Mode or Normal Mode. NIS will do a virus scan in Safe Mode but detects nothing wrong. Yet in Normal Mode the system hangs in about 5 minutes.

From reading the very very patient DragonMaster Jay in this forum, he seems to have helped invisible016 with the same bug -- H8SRTd -- I seem to have. I ranSysProtLog and here's a snippet:

Kernel Modules:
Module Name: \systemroot\system32\drivers\H8SRTpuxjrudujx.sys
Service Name: H8SRTd.sys
Module Base: ---
Module End: ---
hȋdden: Yes

Here is my question: I have a clean Norton Ghost image backup and I want to minimize chance of this virus surviving the Ghost Recovery.
Drive is bootable Primary "C" Drive, 55 GB, with a small 212 MB "Unknown Partition" for HP recovery files.
I'm restoring the bootable "C" Drive, and want to keep the Unknown Partition alone. I'll use the "Restore MBR" (Master Boot Record).

Can this malware survive the normal Ghost Recovery if I also restore the MBR?
Or, should I try and delete the malware, with your help, before using my Ghost image?
Or, is there a way to scrub the hard drive (while leaving alone the small Unknown Partition) to disinfect the drive before running Ghost?

Thanks

description"Security Center Alert" attack EmptyRe: "Security Center Alert" attack

more_horiz
Please download ComboFix "Security Center Alert" attack Combofix from BleepingComputer.com

Alternate link: GeeksToGo.com

Alternate link: Forospyware.com

Rename ComboFix.exe to commy.exe before you save it to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
  • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

"Security Center Alert" attack Query_RC
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
"Security Center Alert" attack RC_successful

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum