Nasty problem even after reformatting several times. Please help me Major!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by blueberry84, Feb 19, 2009.

  1. blueberry84

    blueberry84 Private E-2

    Dear Majorgeeks generals,
    I have been an avid follower of your site since my problems began back in december. I hate to bother you guys with new posts, but even after reformatting several times, I can not get rid of my problem. I have gone through your malware removal procedures several times. I am mortally wounded and I have lost all hope. I am beginning to worry about my Mac as well. Here are the logs please help me! SAS, and MB failed to detect anything so I will not post a log unless requested. Thanks again guys.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You neglected to tell us what the problems you are having. If you have done complete reformats and reinstalls, then your system would be clean except for any thing you may have installed from a cd / thumb drive or infected download.
     
  3. blueberry84

    blueberry84 Private E-2

    thanks for the reply, and at first, virtumonde was detected when I ran the clean up steps. I have paid webroot internet security for two of my PC's, and it detected the virtumonde after I ran your scans. I got impatient last night, and downloaded seatools for dos, and did zero all for my hard drive on my first PC. and it would stop in the middle. My windows xp cd is a legitimate cd that I purchased, and when I popped that cd in to do a reformat, it said I had a bootsector virus. and therefore unable to install windows. does that help in any way? Now im sure this computer has problem too because virtumonde was on this as well. I haven't tried formatting this one yet, because I need to figure out how to clean my first pc. Would my Mac be affected at all by all these problems that Im encountering with my pcs on the same network?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, your MBR could be infected which would or could continue depending on how you reformat.

    GMER's MBR.exe

    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.
     
  5. blueberry84

    blueberry84 Private E-2

    seatool for dos completed zero all this time...after about fifth try...and before even doing that i ran the long test which passed. so i popped in the original xp sp2 cd, and this is the screen I got... BootSector Write! VIRUS: continue? (y/n) I pressed Y and its formatting it on NTFS right now. this is before running MBR.exe, I just downloaded that file onto a floppy, and will run it when installation is complete.
     
  6. blueberry84

    blueberry84 Private E-2

    I ran MBR.EXE after reformatting. here is the log. it says no rootkit...but why did I see that VIRUS warning before installing xp just now?
     

    Attached Files:

    • mbr.log
      File size:
      179 bytes
      Views:
      5
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is a difference between a quick format and a full format.......that is the only thing I can think of.
     
  8. blueberry84

    blueberry84 Private E-2

    i did full format...do you think I should be ok?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The full format is what you always want to do if you are re-installing windows. So I do think you will be fine. :)
     
  10. blueberry84

    blueberry84 Private E-2

    Last quick question before being dismissed major. Apple CPU on the network should be ok right?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't see how that would be a problem. :)

    You may wish to discuss this in the software forum.
     
  12. blueberry84

    blueberry84 Private E-2

    OMG...i found it... you won't believe this... it automatically hides virus definitions... it started from two files i can see from defraggler. i dont know how to explain this...im going to run your malware guide again. I forgot to tell you, before i bought real xp sp2 cd, i used to run illegal crack copy on this. this wasnt me by the way my so called smarter little brother...
     
  13. blueberry84

    blueberry84 Private E-2

    After running up to MBAM, only search & destroy found firewall override, but I wish i could show you the screenshot of defraggler, but .bmp file is too large for me to upload. after search and destroy, it created an extra file on top of those two files of about 7.4mb in size. c:\MFTmirr 4kb, c:\Bitmap 7,453kb, and aports.dll 34kb created by search & destroy. everytime I tried to wipe my freespace, it would stop at around 33 percent and wouldnt let it go further. Im dying...
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have lost me now. You did a full reformat and installed a legit copy of xp? And now you cant defrag the hard drive? If you did that, as I already stated, you would not have any malware on your system. So I am inclined to think that you are having software issues and should post in the software forum.
     
  15. blueberry84

    blueberry84 Private E-2

    I can defrag. but its not defragging properly. Remember when I did Zero All before install, and I had issues with it? And When I was installing legit xp, it gave me the virus sign. I guess there is a way to get around a full reformat, and a zero all. You guys never had anyone with this type of malware?
     
  16. blueberry84

    blueberry84 Private E-2

    see, the file is acting like a back door. When I reformat my hard drive, that was my about 20th time reformatting since december. at first it seems dormant, and it starts installing malware as I leave the computer on hooked up to the internet.
     
  17. blueberry84

    blueberry84 Private E-2

    are the logs that I first attached showing signs of clean computer?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The fix mbr log was clean....perhaps you should rescan and attach the logs for:
    SAS
    MBAM
    ComboFIx
    C:\MGLogs.zip

    Being hooked into the internet would normally not be an issue unless your AV, AS and/or firewall programs are not running.
     
  19. blueberry84

    blueberry84 Private E-2

    ill do that now...so could this possibly be that worm microsoft knows about that can't be fixed? because i have tried to format with legit cd about 30 times now no joke in that number at all...and can't be removed. When you reformat and do reinstalls, your disk image from defragging should show files all at the front of the drive right?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not necessarily.....and a zero fill would remove everything. I have not heard of this problem but please be specific once you have run the scans and tell me what problems you are seeing.
     
  21. blueberry84

    blueberry84 Private E-2

    jesus my Mac is infected too! on my Mac, I did erase free space, and all of sudden my available harddrive space goes from 190 GB to 0kb. and Norton internet security for mac says my last update was 1969 june 4pm.
     
  22. blueberry84

    blueberry84 Private E-2

    right now on this pc, webroot internet security with antivirus is giving me pop up message like crazy saying its blocking connection from all these malware sites. this happened after doing spybot search and destroy scan, and fixing firewall override. i have no files installed on this except legit windows, legit office 07 and antivirus/firewall software. somehow this malware has a way to get through a zero all. im not crazy major, you have to believe me. this has been going on since december of 08 and i have reformatted and i have zero all countless times, and countless sleep less nights.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm afraid I can't help you with your Mac.

    Have you tried re-immunizing with Spybot? And if Webroot is reporting blocked "attacks", then it is doing what it is supposed to do. You may just need to set Webroot to not tell you.

    What actual problems are you having other than these reports?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds