Malware plague (error fix caused?)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ibsen3, Jun 8, 2009.

  1. Ibsen3

    Ibsen3 Private First Class

    I think I'm in urgent need of assistance here. In a fit of complacency, I downloaded a perhaps suspicious exe file called Error Fix and I have since been hit by a number of symptoms.

    To begin with, I noticed that my internet would not operate correctly so that when I typed up a search in Google and clicked on the link, I was bumped on to one of a number of really crappy search engines and 'offer' sites, one of which was 'www.findstuff.com'. Others led me to other registry and virus sites such as 'Stopzilla' and back to 'error fix' ( http://errorfix.com/ ). Although I was able to continue surfing as long as I cut and pasted the link into my address bar, it's nonetheless affecting my surfing.

    Far more worrying though was the fact that I observed that I could not back up my files on DVD using Nero Premium 7. The option for choosing my drive was not open to me and, when I accessed it by playing a DVD, which worked, the option appeared in the drop-down bar but the button to press for burning the DVD was unclickable. Now I cannot back up my files.

    So I tried using the 'system restore' option, only to discover that it too was inaccessible. I managed to access the program and choose a restart point but when I clicked 'next' in order to reset, nothing happened!

    I did, however, succeed in finding a bogus account via my control panel which I have currently disabled but, apart from my own account (which I have now passworded), there was some kind of account that had the words ASP.net in the title which, I believe, is some sort of network....?

    I've tried to use my free edition of AVG to neutralise the threat but my PC tends to cut out when I reboot in order to verify the changes made by updating my settings. I found advice about running a scan in safe mode but the only time I tried this (last night), the scan seemed to reach my copy of Photoshop and then stop dead.....I'm not particularly hot with technical stuff. I usually through but so far this has defeated me.....

    ....please help!:cry
     
  2. Ibsen3

    Ibsen3 Private First Class

    Help! This piece of **** is really screwing things up for me...
     
  3. Ibsen3

    Ibsen3 Private First Class

    Okay, I'm reading through the Malware instructions but I can't download the Sun Java RunTime Update. This may be because of the Trial version of Norton I just installed but I have no idea because Norton looks really complicated and I don't know where to go to to change the options.
     
  4. Ibsen3

    Ibsen3 Private First Class

    Now I can't download CCleaner....:cry
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really need to read the stickies. The more you post, the longer it takes to get any answer. See this: Don't Bump! It Only Hurts You!!!

    Also your first step should have been theREAD & RUN ME FIRST. Malware Removal Guide and it specifically tells you not to stop. In bold print before step 1 the below is given
     
  6. Ibsen3

    Ibsen3 Private First Class

    I read the stickies and stopped posting when I noticed the bumping message and have just been chewing my nails since....down to the bone now....

    I've been through the whole guide but the main point is what I was saying: I cannot download ANY exe files! That means that I can't download the Java Update (I think it's up to date anyway), CCleaner or any of the scanning tools at all.

    I think I figured out straying onto Porn Tube 2.0 has caused it...not nice to admit but there you go. There's a blog here that describes it: http://tek-tips.nethawk.net/blog/tag/porntube-20 although I didn't see any links like this. I just ended up on a main page and downloaded a video player exe file. Perhaps the Error Fix program just made it worse. Anyway, all of this happened on Friday 5th June and I made my first post on Saturday.

    My only hope is this AdAware log. It's the only program I know of that I own and can put together a log this kind.

    This is crippling my work and much of my social life as well. Thanks for helping but it's looking pretty bad!
     

    Attached Files:

  7. Ibsen3

    Ibsen3 Private First Class

    Christ! How do I avoid bumped posts if I can't even edit my last one?

    Anyway, Norton just popped up to tell me I had a Trojan Horse on my system that it couldn't remove and sent me here: http://securityresponse.symantec.com/security_response/writeup.jsp?docid=2004-021914-2822-99&tabid=3 . I just wondered if this was the real source of the problem or whether it's more serious. Stopping system restore seems drastic if it means losing my earlier restore points.....

    I've also attached a Scanlog from Norton that I ran earlier to the one posted below. I may even have done this before coming here....not sure.
     

    Attached Files:

  8. Ibsen3

    Ibsen3 Private First Class

    I have to update (I still can't edit my posts) because I managed to successfully transfer the exe files across from a different PC using a USB device. Details as follows:

    • Ran SunJava Update – I’m already up to date.
    • Ran CCleaner and everything went smoothly.
    • Installed SAS but could not launch the program as the same message came up that came up when I tried to install SAS before renaming it from ‘SuperAntiSpyware’. This error message was: “SuperAntiSpyware Application has encountered a problem and needs to close. Sorry for the inconvenience.” followed by the typical MS option of submitting an error report (which I could see but not get a copy of).
    • I tried using this: http://www.superantispyware.com/supportfaqdisplay.html?faq=50 but the setting was already at ‘not configured’.
    • Malware AntiMalware failed to respond to having the Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware checkmarks ticked and did nothing. I also tried double-clicking the desktop icon and loading via the Start Menu, but to no avail.
    • Likewise, ComboFix would not respond when the exe icon was double-clicked on the desktop.
    • I ran through MGTools and have attached the logs.

    The problems (including being 'bumped' elsewhere on seach engines, not being able to burn DVDs and not being able to use system restore) are still occurring.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no malware showing in your logs from MGtools. All I see is that you are running an illegal copy of Windows and it may even be broken which could be part of the reason for various problems you are having. However we will not help you with illegal copies of Windows. See this: Warning about Keygens, Cracks, and other Illegal Software You need to purchase a valid license since we will not continue to try to help you in the future after you have been warned about this once.

    Even though the logs in MGtools do not show anything, that does not necessarily mean you are clean. MGtools is not a malware scanner. It is primarily an information collector. Many things could show in the logs but not seeing anything is not a 100% indication of no malware.

    • Did you try running the other scans in safe boot mode?
    • Have you tried checking for this first: TDSSserv Non-Plug & Play Driver Disable
    • Did you try shutting down Norton or uninstalling it before trying the scans? Since you just installed a trial version of Norton after you already were having problems, it may be best just to uninstall it anyway.
    • Did you try renaming the C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe file before running it?
    • Did you try the Alternate start method for SUPERAntiSpyware? See the selections under Start, All Programs, SUPERAntiSpyware.
    You did not put ComboFix.exe on your Desktop as we requested. You need to do this and try running it in both normal and safe boot mode if necessary. Also try renaming it to cf.exe if it will not run.

    I see you downloaded (Kaspersky)setup_7.0.0.290_11.06.2009_18-50.exe. Did you try running it? Did it find anything? Do you have a log?


    Delete the below file:
    C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job


    Also try running the below and attaching logs:

    Trend Micro Housecall

    Trend Micro RootkitBuster
     
    Last edited: Jun 13, 2009
  10. Ibsen3

    Ibsen3 Private First Class

    Gah! I couldn't find your reply earlier.....Anyway, I wasn't aware that my copy of Windows was illegal. A while ago my old version got corrupted and I repaired it with another disc...maybe that's it...:confused

    I'm now unable to boot up in normal mode and am typing this response in safe mode whilst I conduct a scan using the Kaspersky virus removal tool. However, it's now reached 1% and is saying that it will be over ten hours before it has finished...?!? This 'finish time' is also rising. Given the fact that my PC tends to reboot itself randomly at times due to another error I was unable to fix (this goes back months and months) then I feel the need to post this as soon as possible and will return later.

    In the meantime:
    • I am running Kaspersky now...
    • I couldn't find TDSSserv.sys but I did find something that worries me: C-Dilla. There seem to be reports about it on the internet that are not good and I have no idea how it ended up on my system.
    • I uninstalled Norton as you suggested and am now feeling even more vulnerable...I thought you only had to shut down virus protection if you had more than one protection system...?
    • Yes, I renamed it to mbam.exe
    • No, I didn't try the Alternate start method for SUPERAntiSpyware. I had no idea it existed! I will try it after trying others.
    I now have ComboFix on my desktop and will try running it as soon as Kaspersky is done.
    I don't think Kaspersky ran except now in Safe Mode. I will try to get the others (I have to download them from another PC and transfer them across via USB) and submit reports.
    Likewise Trend Micro.
    Regarding C:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job , I could see no such file even with the option of viewing hidden files and folders...
     
    Last edited: Jun 18, 2009
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No. Doing a Windows repair does not install this antiwpa.dll which you have in your logs. This is something that is used to bypass Windows Activation. You need to get a legal license/copy of Windows.

    C-Dilla is used by software developers of games to protect their software.

    You have you concepts incorrect. You must never even install more than one antivirus program at the same time. Shutting down is almost always necessary now since many antivirus programs now get in the way of actually removing the malware that they do not find or do not remove if they find it. I only suggested uninstalling it as a temporary solution to try and get other scans to run.

    See if you can get the below to run:

    Running RootRepeal
     
  12. Ibsen3

    Ibsen3 Private First Class

    Too late. It took out my internet connection a while back followed by my USB drives and various other stuff. I lost a shedload of data. I would recommend anyone in the same situation to just migrate files to another PC ASAP by whatever means and then to do a complete reinstall. This, for me at least, was a waste of time. Nonetheless, I'm not criticising your expertise and thank you for your efforts....I'm more than just a little unhappy about my situation though.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry to hear you ran into such difficulties. There is lots of new malware out there and some is very destructive. They are also making it harder and harder to fix problems because they are disabling the ability to run many programs. For most, we can still fix the problem. For things like Virut infection that infect all executables on a PC, we immediately recommed reinstall. Not sure what you had but you may have had one of the new forms of CLB type rootkits which are a real PITA. The below often helps us locate some of the files and is now part of the READ & RUN ME since about 6/16

    Running RootRepeal

    Malware changes very frequently and there are thousands of new infections each month. It does take some time to adapt the procedures to the new malware. We have to see it before we can come up with a fix. This is no different that what major antivirus and antispyware companies go thru and they do it for a living and have thousands of people working for them. You should take your frustrations out on Symantec which obviously was a complete was of money for you since it did nothing to protect you.....unless you bypassed warning that it gave you.

    You data is most likely not lost. If your PC is not bootable, you could always copy your data using another PC with your hard disk inserted as a slave. Also there are various special boot disks you could make using another PC that could give you access to your hard disk in your PC.
     
    Last edited: Jun 23, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds