Virus that killed admin account, disabled instalations of antiviruses etc.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Generator, Feb 2, 2013.

  1. Generator

    Generator Private E-2

    Hi! I've seen some good solutions here, so i hope u will help me too...

    My machine: ASUS laptop, Windows 7 64x
    Problem: I have a virus that is blocking administrator rights, user account management, disables systemrestore and msconfig etc. There are no pop-ups. It also doesn't let me to modify the files in root of C:. Obviously, i can't switch from guest account and all changes are ignored or denied. That's why i cant run any antivirus, even in safe mode. I can't run DDS utility (bleeping-computer software), says not enough privileges, and i couldn't install MBAM, just like any other software. I did everything you said in the manuals, and only RogueKiller and Hijackthis managed to create a log, others failed. I couldn't disable UAC and do other things. Bitdefender (Bootable USB) found Trojan.Qhost.Gen in some system folder, deleted it, but nothing happened, i'm not even sure it is related to the problem. Even bootable Kaspersky and AVG didn't find the virus.
    What i've done previously: I discovered it when i was trying to make a network with a desktop PC. It wasn't working, so i enabled empty passwords. This other PC is absolutely healthy. I have also been installing some minor applications.
    Antivirus: I try to surf safe, and use fully functional Avira, firewall is on for private networks.

    So it's a specific situation, what should i do? :( :confused rolleyes

    Thankyou and i'm waiting for qualifued help. I attached logs i could find.

    G
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We actually do not ask for DDS logs nor HijackThis logs on this forum.

    Did you install this >> PACE Anti-Piracy

    Are you actually logging in on the Guest user account and not your own account?

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.


    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. Generator

    Generator Private E-2

    First of all, thanks 4 replying.

    Hmm, yes, i did install PACE long ago, its folders still there, scattered all over the system, but no official program.

    Then, i am logged in as "user", but my status is "guest account". Looks i have been downgraded. I can't change it as i told before.
    In users console information is the following:
    user - on
    Administrator - off
    Guest - off

    I will start Farbar.
     
    Last edited: Feb 3, 2013
  4. Generator

    Generator Private E-2

  5. Generator

    Generator Private E-2

    Last edited by a moderator: Feb 8, 2013
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There no real malware showing in your logs. The only issue is the below illegal activation of MS Office:

    2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2012-01-27] ()
     
  7. Generator

    Generator Private E-2

    So what about PACE? Should i uninstall it to keep working? But i know there is a virus. Are there any advanced methods of scanning?
     
    Last edited: Feb 4, 2013
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have no admin permissions so you cannot uninstall it. But it could be that this is how you got yourself into this issue with permissions. I cannot say for sure. Why did you install this to begin with? I have heard if not properly uninstalled, it can cause things to be locked.

    Without proper full scanning with our cleaning procedures, all I can say is the logs you have attached thus far do not show any.

    You can try a special boot CD like the below, however be aware that when running scanners like this offline, there is no protection for Windows System files and offline scanners may deleting infected system files which in turn could mean the PC will not boot at all. This happens in frequently, but it does happen.

    https://support.kaspersky.com/4162

    Also the below may be of use

    Avira Rescue CD - see the Also available in ISO format link at the bottom. Also see Tutorial for Avira Rescue CD
     
  9. Generator

    Generator Private E-2

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have tried what is in that link and it did not help or you have a problem following those instructions, try posting in the Software Forum for help and add that link.
     
  11. Generator

    Generator Private E-2

    Yep, it didn't help either. I will try hack that bugger with NT Password...Editor today.
     
  12. Generator

    Generator Private E-2

    Ok, how to remove all of my attachments, pls? I will answer later.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to as there is nothing in them that requires them to be deleted. If we delete them, then we have no record of anything we were doing if we ever need to refer back to this thread which means we may as well delete the thread.
     
  14. Generator

    Generator Private E-2

    Still i would like to delete one of my attachments since it contains personal information (FRST). Maybe the topic has to be moved since I mistakenly blamed it on a virus whereas it was just a MS glitch. I will post here how i solved the problem.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your FRST attachment has been deleted.
     
  16. Generator

    Generator Private E-2

    Thanks.
    I managed to create a new admin. But the problem is partially still there. The old user's safety policy is corrupt: i can't change files, install some programs etc. How can i transfer program data to new user without damage (CorelDraw, Word etc settings)? I would also like to transfer environment settings, like Desktop, Docs etc.
    I can use Windows Easy Transfer, but i'm afraid won't it move corrupt permissions settings to the new user? rolleyes
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post all your questions for this in the Software Forum.
     
  18. Generator

    Generator Private E-2

    For those who want to know how i solved the problem: i run "NT Windows Password and registry Offline editor" and chose "unlock" built-in admin account. (there's also a way to use installation cd and edit the registry thru it, but i chose to use this awesome program) Then i went back to windows and from there logged into admin with no problems. And i gave the user administrator rights too. And disabled blank passwords just in case, cause that's when the glitch started.
    Yeah, and still, the old profile's permissions are still damaged, so i guess it's better to create a new standard user.
    It is a pretty rare bug, i would call it "admin as guest bug", it appears when you are trying to create a network, enable empty passwords and there are some other glitchy factors only Bill knows.
    :wave
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Glad to hear you got it fixed.
     
  20. Generator

    Generator Private E-2

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I had a suspicion that there still would be problems.
     
  22. Generator

    Generator Private E-2

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry for non-malware issues you need to seek help in the Software Forum and I'm just too busy here to work non-malware issues. Also leaving for vacation in a couple hours.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds