Virus killed WIndows, cannot even log in

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ZenMotorcycle, May 1, 2011.

  1. ZenMotorcycle

    ZenMotorcycle Private E-2

    My computer has a virus. My son (11) clicked on one of those false virus warnings and downloaded Vista Internet Security. Vista Internet Security then downloaded a whole host of other things. I was able to run an anti-spyware program and remove most things, however, the Vista Internet Security started messing with my ability to log on and off, and to switch users. I just logged into "Safe Mode" and all I get is a black screen and the curser.

    I've had a similar virus before and I was able to log in from another user and eliminate the virus. But now, I cannot log in at all, and I have no idea what to do.

    The computer is a Sony Viao running XP.

    THanks
     
  2. ZenMotorcycle

    ZenMotorcycle Private E-2

    Ok, I'm not trying to bump. Just to give more information.

    I am able to log into the computer now, however when I try to log into the main user/admin account, windows does not function at all. I get a black screen and the cursor. I am able to force explorer to come up from time to time from the Task Manager, but its intermittent.

    I can log into one of the other users. When I do that, I can run anti-virus. I ran both Superantivirus and Malwarebytes, and then both claim to eliminate the virus, however, they clearly do not. Because when I log in again, the virus is still there. I cannot run either from the admin account because the virus stops it. I cannot download rkill to stop the virus, because I cannot access the internet from that account.

    I tried a system restore, but that was damaged and will not work. I get an error message.

    I tried using an external drive and running the antivirus from a thumb drive on my admin account, but I cannot get the admin account to recognize the thumb drive.

    I was wrong, btw, I'm running Vista on that computer, which I suppose makes sense since the virus is the Vista Internet Security 2011 virus. It also loads all these trojans and things onto the computer.

    I really don't know what to do. I don't know what I can't remove the virus when the virus seems to get removed from the other user account. Also, every time the system system restarts, I get a blue screen error where the system tells me its dumping memory or something. Huh?

    Thanks
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If the user account that you can log into has Admin. privileges, go ahead and do as much of the below as possible. We need to see some logs in order to assist you.

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. ZenMotorcycle

    ZenMotorcycle Private E-2

    I was able to run Malwarebytes and Superantivirus. Everything else won't download or run. I'll post what I can as soon as I can figure out how to get the logs up to the net, because the virus is blocking my access to the internet.
     
  5. ZenMotorcycle

    ZenMotorcycle Private E-2

    I got this log. So far, that is all I've gotten to work.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may need to download the tools to a different computer and transfer them via thumb drive or CD. What happens when you try to run the C:\MGTools.exe? Can you run it in normal mode? If not, try safe mode. What about ComboFix? Same suggestions. Though you can also try renaming it to 123.com. I need to see as many logs as you can get me.
     
  7. ZenMotorcycle

    ZenMotorcycle Private E-2

    I'll try safe mode. At the moment I'm having issues getting the system to boot at all. I'm booting from a disk. I'll try a thumb drive. Can I run them all from the thumb drive somehow?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you are booting from your Vista disc, try doing this:

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr, and then press ENTER.

    Note the space between the exe and the /fixmbr.

    Reboot and see if you can run any of the tools.
     
  9. ZenMotorcycle

    ZenMotorcycle Private E-2

    I tried that. Didn't seem to change anything. I've been trying to get rkill to run based on suggestions from another board. However, every time I move the program to the desktop, even on the other account, I get kicked to a blue screen error. Safe mode and regular mode doesn't matter. Running them from the thumb drive doesn't work either.

    I tried something called tdsskiller. I changed the name. Nothing. Blue screen error.

    Combofix doesn't even get as far as loading. I get an error even after I rename the program.

    I can't copy the MG tools to the C: I get a windows explorer fail. I can copy it to the deesktop, although I'm not sure that helps?

    What the heck is on my computer? I've never had a virus like this before. It seems to have corrupted windows quite a bit.

    I am starting to wonder if I just need to reinstall windows.
     
  10. ZenMotorcycle

    ZenMotorcycle Private E-2

    The account I am trying to use doesn't have administrator rights. Is there a way to change that from the dos prompt? I can get in there from the boot disk. This means that I cannot copy MGTools to the C: root drive. Trying to do anything on my other account is pretty pointless. As soon as I log in there, 15 windows pop up and the system totally freezes.
     
  11. ZenMotorcycle

    ZenMotorcycle Private E-2

    I got this to run.
     

    Attached Files:

  12. ZenMotorcycle

    ZenMotorcycle Private E-2

    I got MGTools to run by sneaking in through the explorer window and downloading from a thumbdrive.

    I'm sorry I am not doing this in the order you ask for. I am just getting anything I can run to run in any way possible.

    :(
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any Av software installed on this system?

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  14. ZenMotorcycle

    ZenMotorcycle Private E-2

    I was running Iolo antivirus. I have no idea where it went or why. It came as a package with system mechanic, but obviously it sucks, so I'm switching to something else.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's about time for me to shut down for the night, but let me know if you have any problems doing my fix. You have a ton of malware to remove. It's pretty obvious that your AV software was inadequate.
     
  16. ZenMotorcycle

    ZenMotorcycle Private E-2

    I think I'm getting there. However, I have not been able to do everything you suggested. I was able to run hijack this and remove the things you suggested.

    I FINALLY got Malware-bytes to run and it cleaned up a lot of things, and made the system respond faster. Then I ran CCcleaner and dumped all the TEMP files. THere were a lot of them. I could not get the register repair to run, and I couldn't open the Swandog program. My Iolo Antivirus reappeared (it had been disabled) and was able to run. Iolo sucks, btw. Tell everyone to avoid it like the plague. I can't understand how they can claim to be anti-virus when they obviously suck. ANd, yes, I updated regularly.

    Grrrrrr

    THEN on a reboot the stupid Vista 2011 virus was back again. For some reason it disables my windows so I can't see anything but a black screen on my admin account. I can get into the desktop by a trick... but when I try to run things I get the dreaded blue screen.

    Is there a way to force another admin account on this computer so that I can run the antivirus and everythign else from there?

    Thanks for all your help so far.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you boot into safe mode? If so, you can create a new user account there. Do you have your install disc?

    What happens it you control + alt + delete? Does task manager come up? Can you start a new process by typing in explorer?
     
  18. ZenMotorcycle

    ZenMotorcycle Private E-2

    I can boot in safe mode, but I still get the same issue. I can't see my desktop. I CAN bring up the task manager and launch a new process. That is actually how I get into my desktop.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then try starting Avenger.exe.
     
  20. ZenMotorcycle

    ZenMotorcycle Private E-2

    I can run avenger in safemode.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, then try doing my last fix. We need to remove those files. Then see if you can do the registry fix.
     
  22. ZenMotorcycle

    ZenMotorcycle Private E-2

    I'm having trouble figuring out how to get the script into the program.
    Can I save it to a file? Is there something I could use that does not require opening.
     
  23. ZenMotorcycle

    ZenMotorcycle Private E-2

    I might need to type it by hand. Oh well.

    :(
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you not just copy my fix and paste it into the program? Let me also give you another program to try:

    Download OTM by Old Timer and save it to your Desktop.

    Are you able to do that? If not, can you download it to a different computer and transfer it via cd? Does it open?
     
  25. ZenMotorcycle

    ZenMotorcycle Private E-2

    The virus stops me from launching an internet browser. I am working on another computer. I need to get the text from this one to the other one. I have Avenger open, and I'm afraid to close it. If I put the text on a thumb drive I can move it, but I am not sure I can open the text when I get it on my system.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I know it's a PITA, but you may need to just type in the text. Make sure you include the two directives:
    "Drivers to delete" and "Files to Delete". Then for the first round, do the drivers removal and all the exe files. That may be enough to get you to be able to run the programs. And do try to do the reg. fix!!
     
  27. ZenMotorcycle

    ZenMotorcycle Private E-2

    Ok. The program runs. Then, instead of shutting down normally, which I assume would allow the program to run at startup, I get kicked into the blue screen memory dump. I am assuming that kills anything that might eliminate viruses after a reboot.

    I am wondering if there is anything that can be run from a command line prompt outside of windows? The issue is not running the programs right now, the issue is the reboot. The programs all run properly, say they will get things done after the reboot, and then when trying to reboot instead of going normally, I end up with the blue screen error.

    I can also download that other program you are talking about. I'll try that next.

    When I try to do the registry fix I get the same blue screen error.

    Should I try rkill again?
     
  28. ZenMotorcycle

    ZenMotorcycle Private E-2

    DOn't ask me how I managed, but I was eventually able to get malwearbytes to run, and superantispyware to run. And I ran them over and over after several failed attempts, and after trying both user accounts, and safe mode, and the admin account.

    AND...

    I finally got that registry fix to load!!!

    YAY!

    However, I am still getting the blue screen of death when I try to run Combofix. That makes me think the virus is still lurking there.

    And my browser cannot access the internet.

    Tell me what to do next? Run everything again from the start and post the logs?
     
  29. ZenMotorcycle

    ZenMotorcycle Private E-2

    OK, so I was able to run this program called RogueKiller and this fixed some stuff and eliminated some stuff. I ran it three times, but the last two were pointless and did nothing. I ran Malwearbytes two times and SUperantispywear two times. Both came up clean. I ran Spybot search and destroy and the iolo anivirus. Also clean. Rogue killer allowed me to access the internet by fixing permissions on internet explorer.

    HOWEVER,

    If I run Combofix or root killer or (sometimes) Hijack this I get dumped to a blue screen error.

    Also, every time I log in I get a Windows error. Plus, sometimes when I try to get windows explorer I get a blue screen error. SOmetimes I can recover from the error and get my regular desktop, and sometimes I cannot and I get a black screen. However, when I DO get the black screen, this time I can easily run programs and access explorer where in the past I have not been able to.

    SO.... my questions are:

    Is this b***d of a virus REALLY gone.
    How can I fix this error in windows?
    Why does combofix dump me to a blue screen error?

    I am pretty sure, just for your information, that I got this through a vulnerability in Adobe reader. Does this mean my anti-virus sucks, or is this just because Adobe sucks.

    :)

    You've been amazing. When this is over I'm gonna give you a hug and kiss.

    Eve
     
  30. ZenMotorcycle

    ZenMotorcycle Private E-2

    OK, the MB is infected I think. I got rid of just about EVERYTHING, and things looked really good. However, when I rebooted after a system failure, I got the google redirect virus and a few others. They weren't there before, so they are new.

    Every time I try to shut down the computer it does not shut down, I get the BSOD with some random warning. Usually the warning is "Internal Power error" but this varies.

    I tried a couple fixes I saw elsewhere.. getting into the command prompt from the recovery disk and trying to repair the MB using various commands. NO go.

    I believe this prevents my antiviruses from ever REALLY eliminating the malware which just then reinstalls the next time my computer boots up. I am running antivirus now, but without repairing the MB I am not sure I can beat this one.

    I got everything important off the computer. I'm starting to think a total clean wipe and reinstall might be the solution. I've been told that reinstalling the OS does nothing, and that you have to totally clear the drive, or even replace the hd entirely.

    Bleah.

    If you have brilliant suggestions or plans, let me know. Is there a utility for getting rid of these master boot viruses and for repairing the damage done?

    At this point, I'd be willing to take the risk of screwing up my system and play around a little since the system is already screwed either way.

    I am running the entire malware removal guide from the start. When I get logs I will post them, but I don't think they will help.

    Eve
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for not getting back to you sooner. Yes, you should re-run the scans and get me the new logs. However, we do probably need to fix your MBR. We can do this the following way:

    *** Please print these instructions ***

    1. Download Hiren's BootCD Iso to the desktop of a clean computer.
    2. Extract the zipped HirensBootCD.zip to your desktop.
    3. Open the extracted HirensBootCD folder and extract the zipped HirensBootCD.iso.
    4. Double click the BurnToCD.cmd bat file contained in the HirensBootCD folder. This will launch BurnCDCC.
    5. Insert a blank CD in your drive.
    6. Press Start. This will burn the image to disc. After it has completed...
    7. Restart your sick computer and boot from the HBCD you created.
    o If your PC is not booting from the CD, you need to change the boot order:
    + Restart your PC
    + As soon as you get an image, press the Setup key. This is usually F2, F10, F12 or Del. On some machines the key can also be a different one. It should, however, be stated on the screen which key is the setup key.
    + Once you enter the computer's BIOS, use the arrow keys and tab key to move between elements. Press enter to select an item to change.
    + Navigate to the tab, where you can set the boot order. It should be called Boot or Boot order
    + The tab should now show your current boot order.
    + If the CD-drive is not at the top, please navigate to the CD-Rom drive with the keys arrows. Then move it to the top of the list. The keys for switching boot position are usually + to move up and - to move down. However they can be different, but they should be stated in the help, so that you can find them easily.
    + Once the CD-drive is on top of the boot order, navigate to Exit and select Exit saving changes.
    o Your PC should now boot from your CD.
    o Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted.
    8. When the CD boots choose "DOS BootCD".
    [​IMG]
    At the Hiren's BootCD main menu, select Next and hit Enter.
    [​IMG]
    At the second menu select 1 MBR (Master Boot Record)Tools
    [​IMG]
    In the list of MBR Tools select 1 MBR Work 1.08
    [​IMG]
    This screen will show the hard drive configuration.
    [​IMG]
    Type 5 to Install standard MBR code then hit Enter
    Type 1 to select Standard then hit Enter
    Type Y then hit Enter to confirm
    Type E then hit Enter to exit
    Press Ctrl+Alt+Del to restart the machine

    If you are successful, then try to run this:
    TDSSkiller - How to run
     
    Last edited: May 5, 2011
  32. ZenMotorcycle

    ZenMotorcycle Private E-2

    Ok!!

    IT restarted normally!!!

    :)

    I was having google redirect problems too, but I followed that guide for ending that. And, it seems to be gone.

    Here are some logs.
     

    Attached Files:

  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good!! I only suggest that you now use windows explorer to find and delete:
    C:\Windows\System32\hat4gz6.log
    C:\Windows\System32\ig2odxt.log
    C:\Windows\System32\o486c.log

    Tell me how things are running now!! ;)
     
  34. ZenMotorcycle

    ZenMotorcycle Private E-2

    Runs as well as the system did when brand new. Maybe better.

    :)

    Thank you SO much. You totally rock.

    Eve
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Now let's do the final cleanup:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds