Very persistant Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cloud007, Jul 24, 2009.

  1. cloud007

    cloud007 Private E-2

    Hello there, Im having some very annoying issues with a very resistant/persistant malware.

    --> Initially I was getting a few things...
    Popups: install this and that fake security suite, your pc is under attack, amongst other windows-looking messages.

    Fake Bsod: A BSOD telling me that windows had to shutdown (when it didnt). I started paying attention to when it occurs and what it mentions in it. BOGUS_DRIVER and IRQL_NOT_LESS_OR_EQUAL. Occurances seem to be based on it not wanting certain processes or programs run, sometimes at startup when I didn't login with Admin account, and also sometimes just randomly as my computer was idle.

    Denying certain websites: Access to various websites was also cut off. Some of these include Microsoft, any website pointing to Trend Micro Housecall (amongst other online scanners).


    After becoming extremly frusturated with the virus and deciding it would be easiest to simply reformat my machine, I did the following:
    - I reinstalled Windows XP Pro, repartitioning the C drive via the NTFS (Quick) option. This attempt failed. The popups, and Fake Bsod still lingered - though website access no longer seemed to be denied.
    - I reinstalled Windows XP Pro, again, this time opting for the non-quick Fat32 option; hoping that changing the format of the OS should kill the Malware, and if not, then the more thorough reformat should at least get it. No luck. Fake Bsod lingered, though both pop-ups and website denial seemed to be gone.
    - I noted that the fake Bsod sometimes mentioned Easdrv.sys and sometimes mentioned AegisP.sys.. I looked them up and while I have Nod32 antivirus, it always occured while Nod32 was disabled. As for AegisP, I dont have either of the wireless devices its related to. I all occurances of AegisP and Easdrv, now the fake Bsod doesnt attribute itself to any driver whatso-ever.

    It's worth noting that one of the processes that provokes the fake Bsod is driver installation. Quite annoying being unable to install your Chipset, VGA, and other drivers... quite slow too for everything else.

    Anyways. I then came here, read the malware removal guide and followed it to the T. The only problem I ran across during the process was that RootRepeal was not able to file scan my E drive (I verified this by setting it for only my E drive, which returned an instant crash).. Crash log will be attached.

    Even though various programs detected and deleted/quarntined/etc various files, the fake Bsod screen lives on.


    Hoping to get this issue resolved ASAP! Need my work computer back.

    Thank you for reading and taking your time!!
     

    Attached Files:

  2. cloud007

    cloud007 Private E-2

    The remaining log files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are using an illegal copy of ESET Smart Security which we cannot help you with. You need to uninstall this and get a legit set of security programs installed. I also notice you are downloading other cracks which is a bad idea and we cannot support fixing PCs that are getting infected due to downloading illegal software.

    Also note if you have been formatting and reinstalling, you are reinstalling from infected backups because your C:\Windows\explorer.exe and C:\WINDOWS\system32\ctfmon.exe files are not valid and there could be more. These files being changed like this are possibly signs of a Virut infection and if this is really the case, you would need a total clean reinstall. By clean reinstall, this would mean you need to stop using what ever backups you are reinstalling from since they are most likely reinstalling the infection and all use clean original CDs to reinstall your Windows OS.

    In addition to the above possible Virut infection, your logs indicate some Windows system files may be missing. The below two show as missing but there could be many more:
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\ups.exe

    This could be due to the infections or it could be due to bad reinstalls.
     
    Last edited: Jul 26, 2009
  4. cloud007

    cloud007 Private E-2

    The version of windows I'm re-installing is from a CD a friend gave me. Functions like a modified Windows XP Pro and goes by the name `Windows Awesome Edition`. Since ESET came bundled with it, along with several other programs, I'm guessing they are all illegal.

    Which security program/suite would you recommend I purchase? I have a slightly dated Norton (2008), but never liked Norton because it lags my PC very very badly.

    I believe this was the problem. At the time, I didn't have my original Sony Vaio Recovery CD or I would have re-installed off of that; which I now have done. I ran a scan with the free Housecall by TrendMicro and it detected over 34 files being infected with that Virut thing (is Virut very popular amongst viruses?).

    Running a clean copy of Windows now from the Recovery CD and after running that scan with Housecall, everything seems to be working properly.


    Thanks for your help! Wouldn't have suspected that the copy of Windows I was re-formatting to was infected as well.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can purchase programs if you like, but I recommend you try before you buy by using any of the free ones given in the below link. Once you decide which you like, you can buy it to show your support.

    How to Protect yourself from malware!

    In fact since you have now reinstalled, you should complete all instructions in the above.


    Good news! :)


    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds