Jump to content

Paladin Virus & Malwarebytes Freezes


stepan

Recommended Posts

Hi All,

I know the Paladin Virus had been mentioned numerous times and solved for many people but it seems as though everyone has a unique solution so here is my post. I contracted the Paladin Virus and am attempting to remove it using the bleedingcomputer instructions (rkill & malwarebytes). rkill seemed to work and last night I ran the mwb scan but when I went to remove the malware this morning it froze. I rebooted and checked the mwb log to see it had removed 4 of 28 hits. I ran the scan again and it froze again this time during the scan.

I tried following these directions but the defogger tool didn't ask to reboot (log file below). I rebooted anyway and tried to run the dds.scr tool but that resulted in a notepad file with garbled text (attached). I tried running the gmer.exe but it resulted in launching the fake firewall and virus protection programs. Internet explorer won't run. I am accessing the internet from a macbook and placing downloaded files onto a shared directory on the infected PC.

Please help!

Defogger Log:

d

dds.txt

Link to post
Share on other sites

Hi,

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Copy-paste following contents into custom scan -area:
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    /md5stop
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please try to run GMER by following these instructions:

Download GMER here by clicking download exe -button and then saving it your desktop:

  • Double-click .exe that you downloaded
  • Click rootkit-tab and then scan.
  • Don't check
    Show All
    box while scanning in progress!
  • When scanning is ready, click Copy.
  • This copies log to clipboard
  • Post log (if the log is long, archive it into a zip file and attach instead of posting) in your reply.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.