Page 8 of 8 FirstFirst ... 45678
Results 71 to 79 of 79

Thread: Debugger detected [97]

  1. #71
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Haven't heard any opinions but we can attempt one more thing.

    • Double click on avenger.exe to run The Avenger.
    • Click OK.
    • Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
    • Copy all of the text in the below textbox to the clibpboard by highlighting it and then pressing Ctrl+C.
      Code:
      Files to replace with dummy:
      c:\windows\system32\certstore.dat
    • In the avenger window, click the Paste Script from Clipboard, button.
    • Click the Execute button.
    • You will be asked Are you sure you want to execute the current script?.
    • Click Yes.
    • You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
    • Click Yes.
    • Your PC will now be rebooted.
    • Note: If the above script contains Drivers to delete: or Drivers to disable:, then The Avenger will require two reboots to complete its operation.
    • If that is the case, it will force a BSOD on the first reboot. This is normal & expected behaviour.
    • After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
    • Please post this log in your next reply.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  2. #72
    Member
    Join Date
    Sep 2009
    Posts
    47

    Default

    Here you go


    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows Vista

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    File "c:\windows\system32\certstore.dat" replaced with dummy successfully.

    Completed script processing.

    *******************

    Finished! Terminate.

  3. #73
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    That part went successfully. Now I have to know if the problem still returns.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  4. #74
    Member
    Join Date
    Sep 2009
    Posts
    47

    Default

    The file was replace and I rebooted. The file has not changed since the reboot about 6 hours ago. So I think the rename has stuck.

  5. #75
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Good. Let's uninstall ComboFix and OTL at this point

    Now lets uninstall ComboFix:
    • Click START then RUN
    • Now copy-paste Combofix /u in the runbox and click OK


    Next we remove some other used tools.

    • Double-click OTL.exe.
    • Click the CleanUp! button.
    • Select Yes when the
      Begin cleanup Process?
      prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes, if not delete it by yourself.


    Note: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

    How's the system running?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  6. #76
    Member
    Join Date
    Sep 2009
    Posts
    47

    Default

    Everything seems to be working like it should. I had to uninstall McAfee then reinstall it to get it to work. The .dat file still hasn't changed, so that is good. I don't see any errors when I restart, that is good, as well.

    Just a few follow up questions, if you can.

    I am going to use Spywarebot and Malwarebytes.

    I am going to use McAfee for an antivirus and PC Tools for my firewall. I will turn off all other firewalls.

    I have also installed SpywareBlaster; I think this is for Java.

    Can you recommend anything else or do you know if there are any compatibility issues with any of these products?

    Thanks again for your help

  7. #77
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    I am going to use Spywarebot and Malwarebytes.
    Hopefully you meant Spybot there

    I am going to use McAfee for an antivirus and PC Tools for my firewall. I will turn off all other firewalls.
    Ok.

    I have also installed SpywareBlaster; I think this is for Java.
    SpywareBlaster is designed to block malicious ActiveX controls from installing. SpywareBlaster tutorial can be found here.

    Can you recommend anything else or do you know if there are any compatibility issues with any of these products?
    Those should work well together
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  8. #78
    Member
    Join Date
    Sep 2009
    Posts
    47

    Default

    Quote Originally Posted by Blade81 View Post
    Hopefully you meant Spybot there
    LOL, yeah that is what I ment.

    Thanks again for the help!!

  9. #79
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

    Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

    If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •