Several Weird Malware (?) Symptoms

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by boweasel, Feb 15, 2012.

  1. boweasel

    boweasel Private E-2

    Looking at an XP Pro PC for a friend.
    1. It won't boot into safe mode. Pressing the F8 keys does nothing
    2. When I run MSConfig, there is no Boot.INI tab (so I can't initiate safe mode that way), which could be related to
    3. The hard disk is not on C: - instead it's on the I: drive. I cannot change it to C: with Disk Management. And a registry change was disastrous. Thankfully I created a restore point beforehand
    4. I've installed MalwareBytes, and when I click on it it brings up a box that the database is outdated by 33 days, giving me a 'Yes' or 'No' box to update. However, clicking Y ends the malwarebytes process. Clicking N brings up the normal screen, and I can click on Qick or Full scan, but as soon as I select Scan the process terminates. Renaming mbam.exe to something else did nothing
    5. I have downloaded ComboFix (the PC does have good and fast internet access) and after I disable real-time scanning from Security Essentials, CF creates a new restore point, and tells me that for 'times badly infected machines may easily double'.... and it just stays there. At least an hour now without a 'stage 1'. Taskmgr does show that CF31997.exe is running, along with rmbr.exe. Is that second process normal?
    I have run RKill prior to both MB and CF, without any change.

    Any help would be appreciated.
     
  2. thisisu

    thisisu Malware Consultant

    Hello boweasel,

    Yes

    http://img805.imageshack.us/img805/9659/rktigzy.gif Please download RogueKiller to your desktop.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    When it is finished, there will be a log on your desktop called: RKreport[1].txt
    Attach RKreport[1].txt to your next message. (How to attach)

    Now complete as many steps as possible in this thread: Fixing Google Redirection/hijacking and other redirection problems
     
  3. boweasel

    boweasel Private E-2

    Sorry.... No can do...

    I'd already had the PC for a day, and had fixed it so it was at least running decently and would connect to the internet.

    But my friend needed it back - his son had schoolwork that required the PC. I guess I was naive in thinking I'd get some help with this in under 24 hours, but he just picked up the tower about a half hour ago.

    I don't know if the problems I listed are likely to cause grief to a casual user, but I just couldn't keep it any longer.

    And BTW, there seemed to be no problem with any sort of search redirection.
     
  4. thisisu

    thisisu Malware Consultant

    No problem and thanks for letting me know.

    The anti-malware forums have been very busy lately. We try our best to address your problems as soon as possible but with so many people ahead of you, it can take a while.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds