Followed Read&Run Me First Guide to a 't' but still malware infected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by in_distress!, Sep 10, 2009.

  1. in_distress!

    in_distress! Private E-2

    Hello,
    people on this forum seem to be incredibly helpful and i would appreciate any time that someone has to help me out.

    I followed your Read&Run Me First guide to a 't' but my malware infection is very persistent.

    I cannot even supply you with any logs from any of the programs (SAS, malwarebytes, MGtools, etc.) because these processes get killed during their scanning procedures.

    My System: Windows XP, 64 bit, McAfee virus scanner

    Background of my Problem:
    About 10 days ago, I updated FireFox to the current version, but this version from the get-go ran VERY slow on my comp (old version ran just fine). Therefore I started using IE.

    Using IE yesterday, I definitely visited the wrong site but i dont know exactly which one (it was one of those pdf downloader sites, serves me right for going to these sites). Then Windows Police Pro starts popping up and my IE starts getting hijacked (when i click on a search result from google it redirects me to some random site, for eg datacenter.com). I run through the Task Manager and look for suspicious processes. I find b.exe. Even after killing it in task manager and deleting from my computer, it keeps initiating upon windows start-up. So I remove this by booting in safe mode and removing the 'archive' attribute through the command line prompt and then deleting it. After doing this b.exe does not start up again and is seemingly not present on my computer, but the IE hijacking still happens and Windows Police Pro and some other random malicious anti-spyware program keeps popping up. McAfee runs in the task manager but the icon in the taskbar is not there and the program does not scan or work at all. So i pay for PC Tools Spyware Doctor and run a scan and it finds some stuff (Trojans it says) which i delete. I also run Avast and use this to do a full scan before windows actually starts up. This Avast scan i was doing late last night and it was going VERY slow and looked like it was going to take a couple hours for sure, so i let it run while i slept. When i wake up in the morning and look at the screen, theres an ad pop-up for a gay hotline...Can you freakin believe this freaking virus?!! its one thing to try to dupe me of my money with these phony anti-spyware programs, but thats just taunting. When i run IE otehr random pop-ups show up every once in a while and IE is still hijacked. And sometime when i start windows this Discover Games program randomly starts up.

    So then i run SuperAntiSpyware, which takes a very long time, and it finds some things including a Vundu Trojan. After the scan it says that it has to restart windows to remove these things so i restart windows but the SuperAntiSpyware does not restart. I tried everything to get it to restart but it just wouldnt and has never worked since. So then i downloaded VunduFix but this did not detect anything at all.

    So then i found your forum and when I followed your Read&Run Me First guide precisely, this is what happened for each anti-malware program you recommended running:

    SuperAntiSpyware: it installs fine after all the steps you mentioned, and when i ran it it scanned fine for about 3 1/2 minutes but then it suddenly terminated. When i try running it again it doesnt start at all, and when i try installing it again i get the error: "Windows Installer has insufficient proveleges to modify this file: C:\SAS\SuperAntiSpyware.exe". All of this is after all the possible walk-arounds you suggest in your guide.

    MalwareBytes' Anti-Malware: It installs fine but when I scan, it terminates after exactly 4 seconds.

    Combofix and rootrepeal i should not run per your instructions because i have a 64 bit processor.

    MGTools: install fine but when i try to run it it just terminates like the other 2 programs.

    And for all of these above programs, i am unable to get a log, even after going into each of their directories and looking for a txt file.

    If it makes any difference, the 1 anti-virus i kept on throughout the downloading of the above malware products was the PC Tools Spyware Doctor.

    I am sorry that this has been a very long post, but i wanted to tell you every single thing that happened to give you maximum information. I've also attached 2 screen shots of my task manager as it is now in case you see something awry here.

    Would greatly appreciate any help that anyone could give me this thing is driving me up the wall!
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, in_distress!

    I'll post back with a plan of action shortly.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds