GeekPolice
Would you like to react to this message? Create an account in a few clicks or log in to continue.

GeekPoliceLog in

 


descriptionWinBlueSoft will not allow malware removal program to run EmptyWinBlueSoft will not allow malware removal program to run

more_horiz
I have read the postings and suggested fixes on this web site. However, the computer that is infected with WinBlueSoft will not allow me to run the malware removal program suggested (Malwarebytes' Anti-Malware), or access the Internet. I can look at some of my folders, but not the c: drive. Is there a way to remove this program (or run the anti-malware program) from a command prompt? I appreciate any help you can give me. Thanks.

descriptionWinBlueSoft will not allow malware removal program to run EmptyRe: WinBlueSoft will not allow malware removal program to run

more_horiz
Hello,

Please read this first: http://www.geekpolice.net/-t3821.htm


If you can't post a HijackThis log;

1. Please download The Avenger by Swandog46 to your Desktop
Link: HERE or HERE.

  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

Note: This tool was posted specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, start The Avenger program by clicking on its icon on your desktop.

  • Leave the script box empty.
  • Leave the ticked box "Scan for rootkit" ticked.
  • Then tick "Disable any rootkits found"
  • Now click on the Execute to begin execution of the script.
  • Answer "Yes" twice when prompted.

    The Avenger will automatically do the following:

  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
3. Please copy/paste the content of c:\avenger.txt into your reply.

descriptionWinBlueSoft will not allow malware removal program to run EmptyRe: WinBlueSoft will not allow malware removal program to run

more_horiz
Unfortunately I cannot download Hijack on the computer that is infected, since the malware program will not let me access the Internet. If I copy the program to a flash drive and then onto the infected computer, the malware program will not let me run Hijack.

descriptionWinBlueSoft will not allow malware removal program to run EmptyRe: WinBlueSoft will not allow malware removal program to run

more_horiz
Follow the instructions above to run The Avenger.

descriptionWinBlueSoft will not allow malware removal program to run EmptyRe: WinBlueSoft will not allow malware removal program to run

more_horiz
Here is the log file of Avenger:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "gxvxcserv.sys" found!
ImagePath: \systemroot\system32\drivers\gxvxcyxxvkayxmlsupxbddvmkmrnsbpjdlirq.sys
Driver disabled successfully.

Rootkit scan completed.


Completed script processing.

*******************

Finished! Terminate.

descriptionWinBlueSoft will not allow malware removal program to run EmptyRe: WinBlueSoft will not allow malware removal program to run

more_horiz
Hello.

1. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):


Drivers to delete:
gxvxcserv.sys

Files to delete:
C:\WINDOWS\system32\drivers\gxvxcyxxvkayxmlsupxbddvmkmrnsbpjdlirq.sys


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, start The Avenger program by clicking on its icon on your desktop.

  • Under "Input script here:", paste in the script from the quote box above.
  • Leave the ticked box "Scan for rootkit" ticked.
  • Then tick "Disable any rootkits found"
  • Now click on the Execute to begin execution of the script.
  • Answer "Yes" twice when prompted.

    The Avenger will automatically do the following:

  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
3. Please copy/paste the content of c:\avenger.txt into your reply.

descriptionWinBlueSoft will not allow malware removal program to run EmptyRe: WinBlueSoft will not allow malware removal program to run

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum