blue scrren

Discussion in 'Malware Help (A Specialist Will Reply)' started by johnsz, Apr 19, 2009.

  1. johnsz

    johnsz Private E-2

    Have the Html/virut ...malware and tried going through the cleanup procedures..cc , super antispyware...at this point blue screen after detecting 6 problems..never get to finish...
    now what...how can I do the preliminary part..?
     
  2. johnsz

    johnsz Private E-2

    Got the blue screen to go away. But this win32 Virut kills any installation of an antivirus and won't let combifix run. I got superantispyware in..please advise how I can send the log without passing on this infection.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    You can not pass along a virus by attaching a log to your post.

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.

    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide


    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid addtional delay in getting a response, it is strongly advise that after completing the READ & RUN ME you also read this sticky Don't Bump! It Only Hurts You!!!. Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  4. johnsz

    johnsz Private E-2

    I've attached logs from super as, malware, and mgtools. could not get combofix to run at all.
    had to do them in safe mode
    getting blue screen on reg boot now reading: driver_irql_not_less or =
    registry key "windows" in hklocal machine/software is hijacked
    will try combofix again
    wanted to get logs to you before total death occurs
    thanks for your patience, newbieish here.
    jz
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didnt attach anything. :(
     
  6. johnsz

    johnsz Private E-2

    sorry..thought they were uploaded
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's hope it hasn't gotten worse.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Then check these folders:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\John Zic\Local Settings\temp\

    Now see if you can run the ComboFix and attach the log if you can.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * Avenger
    * C:\MGlogs.zip
     
  8. johnsz

    johnsz Private E-2

    Followed your instructions.

    Everything in your instructions ran successfully, except combofix would not run, it comes up with a warning message indicating that the program has been changed. Same thing happens when you rename combofix.exe and rerun it.

    I've attached the logs. Thank you.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disconnect your computer from the internet. Physically unplug.

    Your logs are confusing in that each time we remove things, they show as still existing on the same day as you post your logs.

    So we are going to try doing this differently. Make sure you do this in the order that I have given you.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now re-run both SAS and MBAM and attach those logs.

    Now run Ccleaner.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Now remove Combo from your desktop and download a new copy and see if you can run it. If so, attach that log as well.

    Now do this:
    Using BitDefender Online Scan.
     
    Last edited: May 5, 2009
  10. johnsz

    johnsz Private E-2

    Followed your instructions to the letter. In MGTools, fixed all the noted lines, except did not find "F2 REG:system.ini: userinit=c:\windows\system32\userinit.exe...." I have attached four logs. I am unable to get online on the infected computer so i could not run the final instruction "bitdefender online scan."
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you trying to run a new copy of ComboFix? Please try downloading from here and transferring to the other computer:
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    And tell me if you were able to run Combo and get a log.
     
  12. johnsz

    johnsz Private E-2

    Hi, I ran avenger, and MG tools. the two log files are attached hereto. I downloaded a new copy of combofix, saved to thumb, transferred to infected desktop. however, when i run combofix, i receive an error message saying that this version of combofix has been compromised and that i am possibly infected with a virut. Thank you for your help.
    (when i put the thumb drive in to the infected computer, the virus copies an autorun.inf and a dll file to the thumb, which i then delete).
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That message from Combo means that your Windows Operating system files have become infected and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possible become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.

    Once you backup, you need to perform a total reinstall of Windows and all other necessary software. DO NOT reinstall from any executable files you backed up because they are most likely infected.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds