Stubborn Virus I Caught From Facebook

Discussion in 'Malware Help (A Specialist Will Reply)' started by andrea85, Nov 21, 2010.

  1. andrea85

    andrea85 Private E-2

    A couple of weeks ago someone posted a link that leaded to a video. Then it started downloading a file onto my computer... Ever since, the following has happened... Sometimes when I click on things, another window will pop up with junky websites, occasionally I see pop ups from my antivirus program Avast saying, 'Threat has been detected', but it says the shield is blocking it and no further action is needed... Also, the computer freezes sometimes and I can only shut it off manually (don't know if that's because of the virus or because Avast blocking it or trying to fight it... I've tried running virus removal programs and nothing works. I've even tried Webroot, but no matter how many times I scan the computer with it (I've even done it in safe mode), the scan stops after around 121,000 files have scanned, and I see no options to delete the infected files it has found at that point. Apparently you have to complete the scan to remove them. But it just won't finish. Guessing this virus is so damn good that it actually stops it from working... I'm very frustrated and feel like just reformatting the drive or reinstalling Windows, but I don't really want to do that. Is there any other way to get rid of this? Thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. andrea85

    andrea85 Private E-2

    Thanks Tim, so when I'm done do I just attach the logs as a continuation to this post or somewhere else?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach them to your next reply. You should be able to attach the main 4 logs:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip --> from running the C:\MGTools.exe.
     
  5. andrea85

    andrea85 Private E-2

    Tim, I'm on the last steps where I'm told to download the tools for the Windows XP Cleaning Procedure, and it says, "Make sure you download the tools to the exact locations specified below in the procedures to avoid problems later. It is not a good idea to download them to any folder within C:\Documents and Settings"... Well, while going through the setup, it asks for my Destination Folder, and when I click on Browse, the only places I can downloaded SAS is within C:\Documents and Settings. Doesn't give me any more options... And how the directions in the forum says, "Make sure you download the tools to the exact locations specified below in the procedures to avoid problems later", I don't see any details of what I should do when downloading SAS. Just says, "Now download the below tools ( PLEASE only download at this point ):

    * SUPERAntiSpyware"

    And then it just goes onto the next one, Malwarebytes Anti-Malware. So how should I download SAS?

    Thanks
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should just download the installers to your desktop. They will then install properly. ComboFix stays on your desktop.
     
  7. andrea85

    andrea85 Private E-2

    I went to do that but the destination folder still starts with C:\Documents and Settings. But as long as you say that's okay
     
  8. andrea85

    andrea85 Private E-2

    All reports are attached

    *Please note that I ran the SAS scan in Safe Mode with Networking. I noticed that the scan only took a couple of minutes, but when I ran the next one, the Malwarebytes Anti-Malware, in normal Windows mode, it took a lot longer. So please let me know if I need to redo the scan in normal Windows mode. Also, I've had this copy of Windows installed for a few months now, and Windows said it said was genuine. Automatic updates were even on so I know it was, plus I never had a notification saying it wasn't. But now all of the sudden after running ComboFix, after it rebooted the computer, it says, This copy of Windows did not pass genuine Windows validation. What is going on? Thanks


    *Also here is the RootRepeal log incase you need it. You didn't ask for it, but you asked me to download it. And sorry for all the text, but the maximum of files I could upload are five. If you would like me to create another post with the actual file, please let me know. Thanks again
     

    Attached Files:

    Last edited by a moderator: Nov 23, 2010
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may need to re-input your xp key. This is something to discuss in the software forum. I am not seeing any malware in your logs. Tell me exactly what issues you are still having, if any.

    Also, you need to slide ComboFix out of this folder and onto your desktop:
    Running from: c:\documents and settings\Andrea\My Documents\Downloads\ComboFix.exe
     
  10. andrea85

    andrea85 Private E-2

    Might not be necessary. Ever since I completed all the steps, I haven't gotten one pop up, or one detection from Avast. That's weird that you didn't see any malware. I remember SAS read some malware during the scan. But since the directions here told me to remove all the bad files before getting the log info, maybe the malware wasn't listed in the log?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What I meant was that the scans seemed to have taken care of the malware as the remaining logs were clean. Are you having any issues still?
     
  12. andrea85

    andrea85 Private E-2

    Oh, lol, sorry. No, I believe one of the programs I ran completely removed it. Still don't know what could've brought on that Windows Validation thing though. Thanks a lot for all your help. I appreciate it
     
  13. andrea85

    andrea85 Private E-2

    Actually I do have one problem left... I cannot delete three files from my desktop. They are DLL files from SAS. And every time I try to delete them, a box with a red x comes up saying, 'Cannot delete: Access is denied. Make sure the disk is not full or write-protected and that the file is not currently in use.' This isn't good, every time this happens, I can never get rid of them. And I don't want to look at these files every time my desktop comes up. Is there any way to get ride of them? Thanks
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exacty what these files are.....the exact path. Then if you haven't done the Final Cleanup instructions, you can try going to the Control Panel / folders/ and under View, check the "hide system files".
     
  15. andrea85

    andrea85 Private E-2

    SASCTXMN.DLL, SASWINLO.DLL, the other one I accidentally renamed but it's very similar to the other two
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not have installed SUPERAntiSpyware to your Desktop folder. All programs with installers should be installed to their default folders which is normally C:\Program Files. TimW told you to save the installer files to your Desktop. He did not say to install the programs themselves to your Desktop.

    Uninstall SUPERAntiSpyware and then cleanup any leftovers from your Desktop since you have have now broken it anyway.
     
  17. andrea85

    andrea85 Private E-2

    READ & RUN ME FIRST. Malware Removal Guide - Windows XP Cleaning Procedure - Step 1: Downloading Tools

    In this section we are going to download tools we will use. We will install and configure the programs and then run scans at a later point so please only download right now.

    Make sure you download THE TOOLS to the exact locations specified below in the procedures to avoid problems later. It is not a good idea to download them to ANY FOLDER WITHIN C:\DOCUMENTS AND SETTINGS.)

    ... So yeah, I was told to do that. And if that's not what was meant, then it should've been more specific. It says not to download the tools to any C folder, so anyone would think that means anything in the installation processes. And I've already uninstalled SUPERAntiSpyware. That's why I asked for help about getting rid of DLL files. I've uninstalled all of the programs I was told to download in the directions
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No one asked you to uninstall anything. You are supposed to be only following the instructions given to you once you start the cleaning process. Supposed we asked you to run scans again to get new logs! You would have to download and reinstall again. You are supposed to wait for us to give you all instructions including any final cleanup. SUPERAntiSpyware and Malwareytes are actually programs that we recommend you keep installed on your PC and we recommend then you update and run scans frequently.


    You are mixing together to separate and distincts functions.
    • downloading
    • installing
    When you downloaded SUPERAntiSpyware.exe, you downloaded and save the installer file for the program. When you ran SUPERAntiSpyware.exe, you began the installation process for the program. It is here that you should have allowed SUPERAntiSpyware to install into its own default folder which is C:\Program Files\SUPERAntiSpyware

    You decided to install the program to your Desktop instead. This is dangerous and can cause one program to overwrite the files for another program since they could possible have similar names on some files. This can result in broken programs, unexpected behavior, and inability to uninstall. Also installing these files where they do not belong can result in them being detected as malware and being deleted. For example: Having C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL is good but having C:\Documents and Settings\Andrea\Desktop\SASWINLO.DLL is not bad.

    Another example, take the necessary and valid C:\Windows\explorer.exe file and copy it to your C:\ root folder. Almost every scanner you run will detect it as malware and delete it from the oot folder because it should not be there.

    Are you sure that your truly already uninstalled SUPERAntiSpyware? Or did you simply just start deleting files? It was not uninstalled in previous logs. It still showed in Add/Remove Programs. Programs that are installed, must be uninstalled otherwise many drivers, registry entries, files and folder...etc will still be in use and cannot be deleted.
     
    Last edited: Nov 28, 2010

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds