Can't complete the removal guide.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cryptisbad, Feb 24, 2009.

  1. cryptisbad

    cryptisbad Private E-2

    Here's what I was doing and what I had when I got infected.

    i had this problem near the first week of Feb.

    I got malware but I don't know how. I had Avira anitvirus free version, Spybot - search and destory, and spyware blaster. I got a firewall (I believe it's a hardware one). I use Firefox and have Windows XP as my OS.

    What I was doing was...doing one of my regular looking up something I shouldn't have :-o (hence all my protection).

    When it did happen, avira sprang up and warned me so I did appropriate thing: deny and delete but one or two pop up appeared so i think I clicked one of them accidentally, since I was trying to okay the deny and delete. After that, all sorts of wacky things started and something started automatically downloading claiming to be antispyware software.

    So you know, I closed everything. Deleted that new stuff that appeared. I did a full scan with avira and spybot at the same time and well, it crashed. So I rebooted again and spybot automatical ran a scan before all ym start ups started. I got some infections and choose to fix the problems. My avira was acting up, like the guard was off. So I turned it on and all these crypt.XPACK.Gen warnings started to flood me after denying them over and over. After a while, I turn the guard off and tried a full scan. It detected the stuff and got rid off it. I got the free AVG rootkit detector and ran that too. It discovered a couple and I did the fix option with it. Then I did the same thing with spybot and it got rid off more stuff.

    So after a few days of scanning, I turn back on the guard, and again all this stuff reappeared. So I tried updating and my computer would slowly update and tried a complete re-scan with my anitvirus.

    Again, it pested over and over. I tried scan after scan and sometimes, when I left for a while and came back, the whole pc would be off even though I did not do anything but did the scan.

    So I tried installing Ad-aware. It didn't install complete even though I restarted over and over again.

    So I left my computer off for about a week and research on the laptop. That's when I found this site. So it took me a couple days to read and get thing down. I found out that I should also check on the firewall and I found that my firewall was turned off by the malware. So I re-enabled it.

    So when I go to the computer again, and you know, spybot ran it's startup scan before everything else and those usually take about 3-4 hours. It would always detect the same three things.

    I tried doing all the steps. It took a while since the guard would warn me over and over and the computer would crash here and there. So I would turn it off and do whatever the guide says, and I got all the way to the step three, in order that was listed. But when it was almost completely installed, the computer black screen on me. The screen was on, but it just turn completely black like it was off. I could ctrl-alt-del or anything on the computer and the tower was still on and the power switch on the monitor indicated it was on. So I held down the tower's power button and shut it down and start it up. This happens either when I am trying to do something or after 30 to an hour has passed by when the computer was on.

    Ccleaner was installed after a couple time doing it. I ran it and it cleared up to about ~800 mb worth of stuff.

    I did step two.

    Step three took a while to download and I definitely had to turn off the guard to get the stuff.

    I did mix up the spybot and SUPERanitspyware part. I figured since I had spybot already, might as well update to the latest one. i would just update it and nothing else.

    So when it came to completion, it black screened again. Turned it off and on, and well, it appeared updated.

    So I proceed with the SUPERantispyware part. Problem is that when scanning the black screen would appear and I could see or do anything. So I do thinkl the scan was complete.

    So I did the Run SuperAntiSpyware

    * In SUPERAntiSpyware under Configuration and Preferences, click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options uncheck the below two options
    o Use Kernel Direct File Access (recommended)
    o Use Kernel Direct Registry Access (recommended)

    and again, the black screen happened.

    So it's a matter of time to get the scan completed and I am not sure if it's possible to get a scan in before the black screen happens. So I am wondering if I should do a quick scan instead to get a log.

    Also, when I updated, I didn't check the box for the teatimer, but I had the teatimer when I had my old one. It's still there but I believe it's disabled but re-enabled every time I switch the computer on and off. So should I unistall and do a reinstall for spybot?

    Also, the guard would pick up TR/Crypt.XPACK.Gen and TR/vundo.gib.6. Not sure if that helps.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you check this:
    TDSSserv Non-Plug & Play Driver Disable

    Have you tried running the scans in safe mode or tried renaming them?

    You should have no problem running the C:\MGTools.exe. Remember that if one tool will not run, move on. WE need to see what ever logs you can provide.
     
  3. cryptisbad

    cryptisbad Private E-2

    Nope, didn't see any of that. I am still completeing the guide so thanks for the help.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know what happens...and get as many logs as you can. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds