Problems, unknown cause

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by OliverS, Oct 30, 2010.

  1. OliverS

    OliverS Private E-2

    Hello, I first want to say thank you for reading. I see a lot of people posting their suspected virus/adware in the subject, but I simply don't know enough about viruses to suggest what it is. I'd like to first note before I explain the symptoms that I did read the RUN AND READ ME thread, and attempted to complete as many of the steps that I could. Here's a list of steps which I could not complete:

    - Could not run Combofix: Firstly, the unknown publisher window popped up once, I clicked run, and then it popped up again. Pressing cancel on the second tells me "C:\" folder is not accessible. Pressing run on both has an error message that windows can't open the type of files called 'nircmd.cfxxe'. After a few seconds, that goes away, and the disclaimer I was told would pop up does pop up, but when I click yes, nothing happens. I've tried running in safe mode, the same thing happens.
    -Could not run RootRepeal, its error message is: Decompression error (5)!
    -MG tools was able to run, but throughout the whole thing, it kept giving me errors saying 'Could not create output file (C:/MGlogs.zip)'. When the HJT part came up, I clicked 'I accept', and it came up with a widow: 'For some reason your system denied write access to the host file. If any hijacked domains are in this file, HJT may NOT be able to fix this. If this happens...(etc).' When all that was done, it turns out to not have made the zip, so I ran it a second time, and this time right clicked select all and copied it into a word file. Guess that'll have to do for now.
    -I would also like to note (by way of proof, though it may be meaningless) that I could not run SuperAntiSpyware until after I changed the name to something inconspicuous. I tried this method on the above programs as well, but it didn't work for them.

    Now that I've got the explanations of why some logs aren't attached, let me tell you my symptoms: I downloaded a file on Pirate Bay. Stupid, yeah, and I've seriously learned my lesson. After downloading, my computer made a beep and some weird low crackly/staticy type sounds. When I logged onto my yahoo messenger, I found all of my friends had received messages and emails. I got a new antivirus called Avira (my TrendMicro had expired months ago), and scanned to no avail, so I simply changed my passwords for my accounts-including my windows accounts- and was carefree for a few months with no problems until yesterday.
    Yesterday I noticed that whenever I clicked on a button which was supposed to open a new window in Firefox, nothing happens (though I can right click and open a new tab, but clicking open a new window still won't work), and if I do that, then shortly after, when I go to one of my tool buttons (File, Edit, View) and click on them, I get a barely visible outline of a dropdown menu with no words in it at all, and the only way to close firefox is to then go to task manager and end the firefox.exe process. Clicking on the 'popout' button on youtube freezes the entire window altogether. The fact that nothing seems to be able to detect whatever's causing this fiasco is what mostly concerns me.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you disable UAC and reboot as requested in the READ & RUN ME before trying to run tools like ComboFix and MGtools? Is UAC still disabled?

    Try running the below.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  3. OliverS

    OliverS Private E-2

    Yes, my UAC was and continues to be turned off (I know the instructions say to turn the UAC back on after all the scans are completed, but I didn't see the harm in leaving it off.)

    When I try to run TDSSKiller, it first comes up with a box titled warning with the message: 'Can't initialize log'. When I press ok, there is then another box with the heading Error, and the message 'Can't load driver'. I tried changing the name of the file to Banana.exe, and I still received the same error.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually it does not say to turn it back on after running scans. It says
    So it is okay that you left it disabled for now.

    Does System Restore run?

    If you look in the C:\MGtools folder do you see the runkeys.txt, newfiles.txt, and hijackthis.log files? If so, please attach them
     
  5. OliverS

    OliverS Private E-2

    When I try to run system restore, there's this error message:
    There was an unexpected error: Class not registered (0x80040154) please close System Restore and try again.

    The txt files are there however, so I'll attach them! (Ugh, every time I want to attach files, I have to go to IE, as manage attachments does not respond in firefox).
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    IE is safer anyway. Also see if the below files exist and attach them too:

    ffdata.txt
    procdll.txt
    nwktst.txt
    sysinfo.txt
    UserInfo.txt
    winfiles.txt
     
  7. OliverS

    OliverS Private E-2

    Here you are sir, I exceeded the limit, so I'll have to make it two posts
     

    Attached Files:

  8. OliverS

    OliverS Private E-2

    Oh, I see what the problem was now, the files named

    sysinfo.txt, as well as winfiles.txt exceed the maximum file size for this forum, so it won't allow me to attach them.
    Sysinfo is 1.25 MB, and winfiles is 530KB.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are not really showing any malware problems You may have corrupted Windows.
    Do you have your Vista boot DVD? Or can you get to the Vista Recovery environment at bootup?
     
  10. OliverS

    OliverS Private E-2

    I found my vista recovery disk we made. I hope that's the disk you mean, and that the recovery disk isn't one of a few that would come with a vista package. I didn't buy vista, I bought a new computer several years back and it came with vista already installed, so we were able to make a recovery disk though, so hopefully that's good enough. What would you like me to do with my disk? Also, is this going to wipe all/most of my installed programs? Should I back up everything first?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No that is not what I meant. What you made is likely a disk that will restore the PC to the state it was shipped.

    If the disk is not a Windows Vista boot DVD, it will remove everything you have on the PC while returning to factory state. I suggest that you back on your important information anyway, and then move on to the Software Forum. It is looking more like you have Windows problems not malware. You will likely have to do a restore your this recovery disk you made.
     
  12. OliverS

    OliverS Private E-2

    I'm sorry, I don't mean to sound pushy or like a know-it-all or anything, but are you absolutely sure it's not malware? It just seems a little suspicious that I couldn't install SuperAntiSpyware (tried several times) until I changed its name, and I couldn't even install the rootkit finders and such with or WITHOUT their original name. I can download and install everything else just fine- I downloaded a game and a browser today. I feel as if it implies some sort of intelligence or programming that bars me from being able to install these specific programs.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem. :) We can never be 100% certain, due to how malware changes all of the time. It has become much much more insidious then ever and now malware is frequently breaking PCs beyond the ability to reliably fix them without a reinstall.

    What I'm going on is the fact that absolutely nothing at all is showing up and since you don't seem to be able to run anything, our choices are somewhat limited and in cases like this it often leads to needing to do a repair install or a clean reinstall. Another choice was System Restore, but you could not run that either and the error message you quoted is frequently due to problems with Windows itself. Since you do not have a Vista boot DVD this also limits choices. Have you ever checked to see if it is really a bootable DVD. Check out the below link. If you can do the below there is a System Restore option that can be tried from the Vista System Recovery Options menu.

    See this: How to use the Command Prompt in the Vista Windows Recovery Environment



    If your DVD is not a bootable DVD then let's try a couple of other scans to see if we can find anything. Try the below two online scans and attach the logs:

    Using ESET's Online Scanner

    Running Kaspersky Online Scanner

    If the above online scans also do not run properly then I suggest that you try creating one of the below special boot CDs to attempt scanning of your PC while Windows is not running. Sometimes this can help since while Windows is not running, neither is the malware that could be masking itself. Just try one of the below but I'm listing a bunch of choices since there are many CDs like this and it gives you a few options to try if one does not work.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds