Evil malware on Vista, help please!

Discussion in 'Malware Help (A Specialist Will Reply)' started by geminisoup, May 7, 2010.

  1. geminisoup

    geminisoup Private E-2

    Hi, I have run all the suggested items, or at least the ones that I have been allowed to run, as the malware disables installation and running of several items when I try to....

    Detail:

    False antivirus bug is the culprit. Logs attached, with explanations in parentheses after each log. Any suggestions appreciated.

    Ran Defogger, no problems.

    Ran SuperAntiSpyware, no infections reported.

    Ran Malwarebytes, no infections reported, but got an error message that some parts had not been successfully installed.

    Ran Combofix, got the following log:




    Tried to run MGTools, got message that this was an illegal operation, using a registry key that was marked for deletion. Same message is received when running Rkill or Ccleaner or SpyNoMore and RootRepeal.

    Disabled User Accounts and File Recovery and every bloody thing else listed in the "Try me first" page. I am transferring all these files by Thumb Drive, as internet connection is disabled from the infected computer.

    Any and all suggestions welcome. Including instructions on how to just wipe the hard drive and reinstall the OS if necessary.

    Thanks in advance for all responses.
     

    Attached Files:

    Last edited by a moderator: May 8, 2010
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you try to do any of the scans in safe mode?

    Use windows explorer to find and delete:
    c:\windows\system32\windrv.sys

    Have you tried doing a system restore?

    Let's see if you can run MGTools from a command prompt.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The red is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
     
  3. geminisoup

    geminisoup Private E-2

    Thanks for the reply. I have addressed each issue below.

    I attempted to run all of these. On the MGtools, I got an error stating "system cannot find the path specified." All the rest gave me "This is not recognized as an internal or external command, operable program or batch file."

    I do not have a lot of experience with command prompts, so it is possible that I am doing something wrong. Thanks again for the response. This is kind of making me crazy. It's my sister's computer, and she told me it has been acting wonky for quite some time, so this bug has had time to get comfortable in its new home. She was running AVG at the time of the infection, but apparently it didn't help.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have MGTools downloaded directly to the C:\ drive ( assuming that is the root drive of your system)? Did you turn off the UAC? Did you try to rename it or change the .exe to a .com?

    See if you can create this disc and then on the infected machine, boot to it and let it run. Then after it is finished, boot back to safe mode and see if you can run any of the other scans.

    BitDefender Rescue Disk-with-auto-update.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds