Big problem and very confused :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by FTWchamp, Oct 13, 2005.

  1. FTWchamp

    FTWchamp Private E-2

    I just finished building this computer this past Sunday and had only installed a few programs. All I downloaded was drivers and a few game demos. Everything else installed was from backup, burnt CDs. My original problem is I contracted the zapchast trojan, from either mIRC or AIM is my guess. I also had a Adware.Wheaterbug.A detection in the AIM file folder. I went through the help per posts here -- disabled system restore, already had hidden files and extensions and protected files viewable. Downloaded Ad-Aware, CCleaner, and MS Antispyware.The only online virus scan I've not tried is Panda. Unfortunately I ran those programs in normal boot mode, but I did unplug my internet connection prior to running the programs.

    Those programs appear to have rid me of the zapchast trojan. However I still have the following after many scans, cleans etc. :( (this is the result from BitDefender, which appeared to be the most thorough.)

    C:\System Volume Information\_restore{9211D9A5-9DC3-4555-A671-18679DCFB564}\RP1\A0000065.exe=>wise0038=>wise0008

    C:\System Volume Information\_restore{9211D9A5-9DC3-4555-A671-18679DCFB564}\RP1\A0000070.EXE=>wise0008

    Now I'm sure I compounded the problem. In a fit last night, I simply went to format the drive and to setup a clean install of WinXp. A current scan still checks all my old folders, so I'm guessing my reinstall didn't wipe everything out as I'd hoped. I still see the previous programs installed on my main drive. WinXP is new to me as I'd used Win2k for years.

    So, is there a way I can wipe my drive and start new? I tried formatting through command prompt, but I get promted for a forced dismount of the drive as it's being used by another process. I saw a thread ( http://forums.majorgeeks.com/showthread.php?t=74791 ) that somewhat explains my file situation, but I'm using XP. Will that eraser work?

    Or can I get rid of that last file listed above and get back to a non-infected OS? I'm very demoralized after this and completely lost as to what to do next, short of buying a new HDD and something tells me that won't even work.

    Sorry for the jumbled post and I hope it makes sense.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are finding files in C:\System Volume Information\_restore
    you have not disabled system restore. Check to make sure it is really disabled.
     
  3. FTWchamp

    FTWchamp Private E-2

    Just rechecked and system restore is disabled. Status for the drive is off and not monitoring. BitDefender detects the same, disinfection fails, then status is listed as deleted, the update failed in both cases. :(

     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. FTWchamp

    FTWchamp Private E-2

    Thank you for the link. I have access to the folder and I see a restore folder, MountPointRemoteDatabase system file, and tracking.log. Am I just manually deleting the two files from the BitDefender scan?

     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Give it a try! I'm surprised the System Restore folder is still there.
     
  7. FTWchamp

    FTWchamp Private E-2

    Deleted the folder, since you mentioned suprise that it was still there and scanned with BitDefender. Appears there are no detections now. So I think everything is clean now, at least I hope so. Doubt I can stand much more, as it's been a bad few days. Getting the comp back to normal would definitely be a victory.

    Is there anything left to do? How do I get my desktop back to a normal state with icon shortcuts etc.? :confused:

    Sorry to be such a pain. Thanks again in advance.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is the first time that you are mentioning Desktop problems. Perhaps you have other malware issues and you need to follow standard cleaning procedures given below. If you have run ALL the steps in the READ & RUN ME part, just proceed to the HijackThis part.


    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  9. FTWchamp

    FTWchamp Private E-2

    Thanks Chaslang,for your posts and help last night.

    I resolved the desktop issue by reading through some of the MS support newsgroups. Seems reinstalling XP over a previous install leaves a sort of shadow of past programs. The programs are not updated in the registry after the reinstall, so those programs simply must be reinstalled as well. My previous post was in hoping someone new a shortcut or a cleaner way to updating files after reinstalling XP.

    Seems all is clean and well on my comp now. Yes, the scans completed and I downloaded Ad-Aware, CCleaner, MS Antispyware, which I'll update and maintain from now on, and cwshredder just in case. Now I'm downloading Zone Alarm for better firewall protection. :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds