Is this a Virus (Victim of an Illegal Activity Warning)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by subby, Jul 8, 2014.

  1. subby

    subby Private E-2

    Never come across this warning before. The computer was a rent to buy computer. From Radio Rentals, explaining their address on the Warning message. I've done a web search and could not find the exact message or image of what i've got. So not sure if its real or an virus. I've attached two images, 1st one showing the warning message. 2nd image showing what happens when i go to login to windows.

    [EDIT by chaslang] Removed external links to images and attached them here [/edit]

    Is it a virus?
    In the meantime i'm gonna scan the HD for weak/bad sectors.
     

    Attached Files:

    Last edited by a moderator: Jul 11, 2014
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It looks like their software messed up. I don't think that this is anything malicious. You should definately inform RR's about it. Did this machine ever let you log in correctly?
     
  3. subby

    subby Private E-2

    Yeh when i click ok on that message, log in screen appears and i can log in, but then computer restarts as shown in second image, cannot get to msconfig to select diagnostic startup. I will windows DVD, and see if can do a system restore.
     
  4. subby

    subby Private E-2

    Hard Drive scan came back healthy. Tried booting into safe mode, warning msg still appears. And computer still restarts on me about 1 minute after being logged in. Ran a chkdsk, didn't find any errors. Unable to refresh the PC as drive is locked. Unable to reset PC as a required drive partition is missing. Have no recovery disc's either.

    Stumped at what to try next.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you contact RR and ask them what's up????
     
  6. subby

    subby Private E-2

    Computer is not under warranty anymore. Customer owns it outright.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm. I'm in a bit of a predicament here. Hope you understand. It *could* be that you want me to wipe out all the RR protection, and it *could* be that this computer still belongs to them. What I can do is have you follow these instructions below and I will check for any possible malware that needs removing.

    READ & RUN ME FIRST - Malware Removal Guide
     
  8. subby

    subby Private E-2

    I thought the same, until the customer showed me the paperwork, and an email from Radio Rentals explaining that the computer is not under warranty. My opinion is its malware, and they're just copied some of the details.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We'll see what the logs tell me. ;)
     
  10. subby

    subby Private E-2

    Other problem is I can't stop the PC from crashing. So only get about 2mins in windows to do stuff.
     
  11. subby

    subby Private E-2

    If I rename the scssifilter64.sys file, would the PC still function. I'm thinking it might stop the PC crashing, so I can run malware scans.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let me know how you get on. I may have to steer the head of the Malware Removal Forum in this direction anyway. His name is Chaslang.
     
  13. subby

    subby Private E-2

    Ok i've stopped the PC from crashing. Gonna proceed to Malware Removal
     
  14. subby

    subby Private E-2

    Ok have ran CCleaner to remove temp files. Enabled viewing of hidden files etc. Downloaded all the programs on my PC, ran RogueKiller first and saved the log file. Attached the log.

    Then I installed Malwarebytes Antimalware and noticed it wasn't updated. So checked network status, Not connections found, checked device manager, network device is working ok. Checked services next. and noticed 95% of all services have been set to disabled. So i've stopped there. And made this post, to seek assistance from here on out.

    I'm off to sleep now, be back to check topic in about 11 hours.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  16. subby

    subby Private E-2

    Attached is Farbar Recovery Scan Tool Log.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have completed all of the READ & RUN ME, but this does not appear to be a malware problem. It looks like the company the PC was purchased from may have installed something to protect their PCs from being stolen and you will have to work from them to find out what it is and how to remove. It could be something installed into flash memory.

    There is some junkware that you should uninstall based on the only the FRST log. Uninstall the below:

    Allin1Convert_8h
    Ask.com or ASk Toolbar
    MyFunCards_5m
     
  18. subby

    subby Private E-2

    I have phoned Radio Rentals, and they asked me to send them an email with a photo of the warning so they can forward it onto their IT Department. Just waiting on an email from them.

    Will remove the junkware you suggested.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad you finally rang them! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds