malwarebytes not finding malware, issues with running scan and bluescreen

Fiery

Level 1
Jan 11, 2011
2,007
Hi,

Before we continue any further, there is something urgent we have to do first.

Upload a File to Virustotal
Please visit Virustotal.com
  • Click the Browse... button
  • Navigate to the file c:\users\Michelle\Desktop\Combo-fix.exe
  • Click the Open button
  • Click the Send button
  • Copy and paste the results back here please.

Either copy the analysis link or the report.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
also, when loading the webcam it says im missing CtrlFactory.dll and reinstalling it may help???
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
it said it was already scanned... and those results were as follows.. however i will reanalyze and post those following this post:


SHA256:

4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333





















File name:

ComboFix.exe















Detection ratio:

31 / 45



Analysis date:

2013-01-29 20:53:26 UTC ( 3 hours, 44 minutes ago )







1



4


More details
Analysis
Comments
Votes
Additional information







Antivirus

Result

Update




Agnitum

Win32.Sality.BL

20130129



AhnLab-V3

-

20130129



AntiVir

W32/Sality.AT

20130129



Antiy-AVL

-

20130129



Avast

Win32:Sality

20130129



AVG

Win32/Sality

20130129



BitDefender

Win32.Sality.3

20130129



ByteHero

-

20130129



CAT-QuickHeal

W32.Sality.U

20130129



ClamAV

-

20130129



Commtouch

W32/Sality.gen2

20130129



Comodo

Virus.Win32.Sality.Gen

20130129



Emsisoft

Win32.Sality.3 (B)

20130129



eSafe

-

20130127



ESET-NOD32

Win32/Sality.NBA

20130129



F-Prot

W32/Sality.gen2

20130129



F-Secure

Win32.Sality.3

20130129



Fortinet

-

20130129



GData

Win32.Sality.3

20130129



Ikarus

Virus.Win32.Sality

20130129



Jiangmin

Trojan/JmGenGeneric.boe

20121221



K7AntiVirus

Virus

20130129



Kaspersky

Virus.Win32.Sality.gen

20130129



Kingsoft

-

20130121



Malwarebytes

-

20130129



McAfee

Artemis!C71B0515EF12

20130129



McAfee-GW-Edition

Artemis!C71B0515EF12

20130129



Microsoft

Virus:Win32/Sality.AT

20130129



MicroWorld-eScan

Win32.Sality.3

20130129



NANO-Antivirus

Virus.Win32.Sality.beygb

20130129



Norman

Sality.ZGZ

20130129



nProtect

Win32.Sality.3

20130129



Panda

W32/Sality.AA

20130129



PCTools

-

20130129



Rising

Win32.KUKU.ky

20130129



Sophos

Mal/Sality-D

20130129



SUPERAntiSpyware

-

20130129



Symantec

-

20130129



TheHacker

-

20130129



TotalDefense

-

20130129



TrendMicro

PE_SALITY.RL-O

20130129



TrendMicro-HouseCall

PE_SALITY.RL-O

20130129



VBA32

Virus.Win32.Sality.bakc

20130129



VIPRE

Virus.Win32.Sality.at (v)

20130129



ViRobot

-

20130129
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
this sality virus was the name i mentioned to you earlier when you said we could remove it because it detected combofix as a virus but here is the reanalysis:


SHA256:

4524611a78ddd40afa7e13238da230302786c546d1f824e6e7dea480a5d55333



SHA1:

9b4126eea8439fa7473c2be59c4ce1dbed9ecd5f



MD5:

c71b0515ef1200755ae61a5c4c9e8a86



File size:

4.9 MB ( 5102942 bytes )



File name:

Combo-fix.exe



File type:

Win32 EXE



Detection ratio:

32 / 45



Analysis date:

2013-01-30 00:40:35 UTC ( 0 minutes ago )







1



4


Less details
Analysis
Comments
Votes
Additional information







Antivirus

Result

Update




Agnitum

Win32.Sality.BL

20130129



AhnLab-V3

-

20130129



AntiVir

W32/Sality.AT

20130130



Antiy-AVL

-

20130129



Avast

Win32:Sality

20130130



AVG

Win32/Sality

20130130



BitDefender

Win32.Sality.3

20130130



ByteHero

-

20130123



CAT-QuickHeal

W32.Sality.U

20130129



ClamAV

-

20130130



Commtouch

W32/Sality.gen2

20130129



Comodo

Virus.Win32.Sality.Gen

20130129



DrWeb

Win32.Sector.22

20130130



Emsisoft

Win32.Sality.3 (B)

20130130



ESET-NOD32

Win32/Sality.NBA

20130129



F-Prot

W32/Sality.gen2

20130129



F-Secure

Win32.Sality.3

20130129



Fortinet

-

20130129



GData

Win32.Sality.3

20130130



Ikarus

Virus.Win32.Sality

20130129



Jiangmin

Trojan/JmGenGeneric.boe

20121221



K7AntiVirus

Virus

20130129



Kaspersky

Virus.Win32.Sality.gen

20130129



Kingsoft

-

20130121



Malwarebytes

-

20130129



McAfee

Artemis!C71B0515EF12

20130130



McAfee-GW-Edition

Artemis!C71B0515EF12

20130130



Microsoft

Virus:Win32/Sality.AT

20130130



MicroWorld-eScan

Win32.Sality.3

20130130



NANO-Antivirus

Virus.Win32.Sality.beygb

20130129



Norman

Sality.ZGZ

20130129



nProtect

Win32.Sality.3

20130129



Panda

W32/Sality.AA

20130129



PCTools

-

20130130



Rising

Win32.KUKU.ky

20130129



Sophos

Mal/Sality-D

20130130



SUPERAntiSpyware

-

20130130



Symantec

-

20130130



TheHacker

-

20130129



TotalDefense

-

20130129



TrendMicro

PE_SALITY.RL-O

20130130



TrendMicro-HouseCall

PE_SALITY.RL-O

20130130



VBA32

Virus.Win32.Sality.bakc

20130129



VIPRE

Virus.Win32.Sality.at (v)

20130130



ViRobot

-

20130129
 

Fiery

Level 1
Jan 11, 2011
2,007
Ok, please stop what you are doing! We have a major issue here. Last night, Combofix has been infected by the Sality Virus and thus, it has been pulled off use, temporary. You can find more information about this security breach here: http://www.bleepingcomputer.com/forums/topic483431.html

Unfortunately, your version of Combofix is the infected version. We must clean your system first before we fix your webcam issues.

Download SalityKiller from here. When using this tool, you should disconnect from your network first. Follow the instructions on the Kaspersky website to run the tool.

Next,

Run Eset NOD32 Online AntiVirus

Note: You will need to use Internet Explorer for this scan.
Vista / 7 users: You will need to to right-click on the Internet Explorer icon and select Run as Administrator
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your current antivirus software. You can usually do this with its Notfication Tray icon near the clock.
  • Click Start
  • Make sure that the option "Remove found threats" is Un-checked, and the following Advance Settings are Checked
    • Scan unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • Re-enable your antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
okay, I need to copy this down and will follow the instructions, I really thought something was wrong bc my pc has been laggy which is never has been/is.. I will be back with the next post.. I wasn't sure if sality was reading bc of the prog or an actual post but im reallllllly glad you caught that!!!
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
I have a problem, I have dl'ed and unzipped the salitykiller but its not opening anything that i can use.. but as i read further, the 1st one is for connected to network and there is one further down for no network, i will paste what i see, can u paste back the section u need me to follow so i can begin, if no response i will try the bottom directions on my own, i just dont want to make an error..
How to disinfect my computer from Virus.Win32.Sality?
Back to "Viruses and solutions" section ID: 1874Complexity2012 Dec 13



The recommendations given concerning disinfection of a computer from Virus.Win32.Sality should be applied only if NO Kaspersky Lab product is installed on an infected computer, and/ or if the computer is already infected and a Kaspersky Lab product cannot be installed by regular means. Kaspersky Lab experts also recommend using Rescue Disk to disinfect an infected computer.

The SalityKiller.exe utility given in this article allows detecting and disinfecting only the following Sality modification Virus.Win32.Sality.aa, Virus.Win32.Sality.ae, Virus.Win32.Sality.ag, Virus.Win32.Sality.bh.


In order to disinfect a computer from Virus.Win32.Sality, do the following:



If infected computers are in the local network under domain control:

Step 1. Preparation to disinfection:

•Download the file SalityKiller.zip
•Unpack the file SalityKiller.zip
•Run the file SalityKiller.exe on each computer in turn (for example, through Kaspersky Administration Kit, or the server group policy).
◦on all computers on which the domain administrator can register and work
While disinfecting this group of the computers do not log on under domain administrator on any other computers to prevent further spread of the infection in the network.

◦on all other computers
Do not stop or terminate work of the utility until all computers in the network have been disinfected.



Step 2. Algorithm of computer disinfection.

Computers on which you log on under a domain administrator rights should be disinfected first. Once these computers are disinfected, start disinfecting other computers in the network.

•Run the utility SalityKiller.exe on the infected computers once again (no additional commands to run the utility are needed).
•A reboot might require after disinfection.
•Make sure that the anti-virus icon in system tray has turned red thus indicating the anti-virus software is fully functional. If otherwise, reinstall the anti-virus via Kaspersky Administration Kit.
•Update the anti-virus databases (signature threats) for the Kaspersky Lab’s product installed on your PC. If you cannot download the updates from the Internet, update from the zip-archives.
◦how to update Kaspersky Lab’s products version 5.0 from the zip archives.
◦how to update Kaspersky Lab’s products version 6.0 from the zip archives
◦how to update Kaspersky Lab’s products version 7.0 from the zip archives
•set the full scan options to their maximum scan level
•run full computer scan
Step 3. Signs of a disinfected/ clean computer

•Kaspersky Anti-Virus is running and works in normal mode
•full computer scan does not detect infected objects on the computer
Step 4. Cleaning the registry of infected computers in the domain network:

•download the file Sality_RegKeys.zip
•unpack the file Sality_RegKeys.zip
•run the file Disable_autorun.reg from the archive Sality_RegKeys.zip


You can also disable autorun from all devices by running the SalityKiller utility with parameter -a.

•Click Yes to confirm adding the information to the registry


•once the scan is over, from the archive Sality_RegKeys.zip run the file of the registry key:
◦under Windows 2000 run the registry file SafeBootWin200.reg
◦under Windows XP run the registry file SafeBootWinXP.reg
◦under Windows 2003 run the registry file SafeBootWinServer2003.reg
◦under Windows Vista / 2008 run the registry file SafebootVista.reg
◦under Windows 7 / 2008 R2 run the registry file SafebootWin7.reg


If infected computer are not in the network

•Disable the technologies iSwift and iChecker, if one of the following products is installed and running on your PC:
◦Kaspersky Anti-Virus 7.0
◦Kaspersky Internet Security 7.0
◦Kaspersky Anti-Virus 6.0
◦Kaspersky Internet Security 6.0
◦Kaspersky Anti-Virus 2009;
◦Kaspersky Internet Security 2009;
◦Kaspersky Anti-Virus 2010;
◦Kaspersky Internet Security 2010;
◦Kaspersky Anti-Virus 2011;
◦Kaspersky Internet Security 2011;
◦Kaspersky PURE;
◦Kaspersky Anti-Virus 6.0 for Windows Workstations
◦Kaspersky Anti-Virus 6.0 SOS
◦Kaspersky Anti-Virus 6.0 for Windows Servers
•Download and unpack the file SalityKiller.zip
•Run the file SalityKiller.exe
•A reboot might require after disinfection.
With an installed Kaspersky Lab product you might be prompted to allow any activity to the process Sality_killer.exe

◦Go to Start > All programs > right-click Startup > select Open




◦Right-click any place in the Startup folder
◦In the menu select New > Shortcut
◦In the Create Shortcut window click Browse
◦Browse the folder into which the file SalityKiller.exe was unpacked
◦Highlight the file SalityKiller.exe
◦Click the OK button
◦Click Next
◦Click OK


•Download the file Sality_RegKeys.zip
•Unpack the file Sality_RegKeys.zip
•Run the file Disable_autorun.reg from the archive Sality_RegKeys.zip


You can also disable autorun from all devices by running the SalityKiller utility with parameter -a.

•Click Yes to confirm adding the information to the registry




•Update the anti-virus databases (threat signatures) for the installed Kaspersky Lab’s product. If you cannot download the necessary databases (threat signatures) form the Internet, update the databases from the zip archives:
◦how to update Kaspersky Lab’s products version 5.0 from the zip archives
◦how to update Kaspersky Lab’s products version 6.0 from the zip archives
◦how to update Kaspersky Lab’s products version 7.0 from the zip archives
•set the full scan options to their maximum scan level
•run full computer scan
•once the scan is over, from the archive Sality_RegKeys.zip run the file of the registry key:
◦under Windows 2000 run the registry file SafeBootWin200.reg
◦under Windows XP run the registry file SafeBootWinXP.reg
◦under Windows 2003 run the registry file SafeBootWinServer2003.reg
◦under Windows Vista / 2008 run the registry file SafebootVista.reg
◦under Windows 7 / 2008 R2 run the registry file SafebootWin7.reg


You can restore the registry branch SafeBoot which is needed for a PC to be able to boot in safe mode, by running SalityKiller.exe with parameter -j.

Additional parameters to run SalityKiller.exe from command line:

-p <path> - scan a specific folder;
-n - scan network disks;
-r - scan flash drives, scan removable hard disks connected via USB and Fire Wire;
-y - close the window when the utility finishes;
-s - scan in "silent" mode (without opening console box);
-l <file_name> - write log to the file;
-v - detailed logging (must be used in combination with -l);
-x - restore possibility to view hidden and system files;
-a - disable autorun from any devices;
-j - restore the registry branch SafeBoot (if it is deleted, the PC will not be able to start up in Safe mode);
-m - monitoring mode to protect the system from getting infected;
-q - scan the system and then go to monitoring mode;
-k – the utility will scan all disks, detect files autorun.inf created by the virus Virus.Win32.Sality and eliminate them. It will also delete the executable file linked by autorun.inf, even if such file has been already disinfected.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i did dl the salitykiller, i ran it and my pc blue screened in the middle, i needed to know if i was supposed to dl Sality_RegKeys.zip before running it bc it says to dl one but half way down after the 1st one it says to dl that file and i was unsure if i was to dl after the 1st salitykiller scan or not, bc your instructions say to run the Eset NOD32 Online antivirus.. thats why i posted the onscreen instructions so u could copy n paste what u need me to follow, im confused at this point.. and i do not want to make errors as im really concerned about downloading a file that was supposed to be safe..so i dont need to make anymore errors at this point.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i have a error screen that says Files that help describe the problem:
C:\WINDOWS\Minidump\Mini012913-01.dmp
C:\Users\Michelle\AppData\Local\Temp\WER-65738-0.sysdata.xml
C:\Users\Michelle\AppData\Local\Temp\WER30CF.tmp.version.txt
would u like those logs?
 

Fiery

Level 1
Jan 11, 2011
2,007
Hmm, let's try a different tool. I won't need those logs for now. Don't run the ESET scan just yet.

http://free.avg.com/us-en/remove-sality

Download that file and run it. Let me know if it finds any infected files.

It is quite frightening to see how a tool used so frequently and by so many users daily get infected.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
OMG, i cant access them, my pc cannot find them? I know they are accessable bc I have accessed them before I joined this forum. What do i do next? or can u suggest another way to attempt.. OR what do i try next.. do i need to dl the Sality_RegKeys.zip first?


ok sorry, must have been sending last msg as u sent urs, i will dl that tool now
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
i agree, i thought it was safe.. i myself thought it was a false pos when it said infected earlier.. i do understand u did not intentionally send me an infected file.. i mean why spend all this time helping to just reinfect it..lol.. be back with results..
 

Fiery

Level 1
Jan 11, 2011
2,007
Gbaby614 said:
OMG, i cant access them, my pc cannot find them? I know they are accessable bc I have accessed them before I joined this forum. What do i do next? or can u suggest another way to attempt.. OR what do i try next.. do i need to dl the Sality_RegKeys.zip first?


ok sorry, must have been sending last msg as u sent urs, i will dl that tool now



Please don't panic, Sality is a very old virus, all antivirus vendors can detect the virus and there are many ways to cure it.

We will fix one issue at a time :)
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
quick question.. does this scan require disconnect from internet as well/ it does not say either way...
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
for some reason it just told me ... This tool requires administrator tool to work properly, do you wish to continue, Y or N

So has this virus messed up my admin rights? is that why i couldn't find my appdata folder or my logs??? OMG im panicking..
 

Fiery

Level 1
Jan 11, 2011
2,007
Your Appdata folder is a hidden folder. To access it, you will need to enable "Hidden files and Folders". It is not a folder you should not be accessing since there isn't any useful files there. If however you want to access it, click Start > Computer > organize > folders and search option > view > Show hidden files and folders > Ok

Right click the tool you just downloaded and select "Run as Adminastrator." The tool needs elevated priveledges to run. This is NOT the virus' doing.
 

Gbaby614

New Member
Thread author
Verified
Jan 28, 2013
232
well it is scanning before i could disconnec, i will rerun it again after it stops if u would like, i tried to wait for an answer to the last question not knowing it was going to begin immediately after clicking Y, so im still here til it is done, then i will disconnect and try to scan again.. sorry.. i knew i would make an error sooner or later :|
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top