Big problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by XJadynX, Nov 16, 2010.

  1. XJadynX

    XJadynX Private E-2

    Okay this will take a little to explain.

    I recently figured my computer is infected. I have the full version of AVG antivirus. After running it it picked up several Trojans and other bad items. It was able to remove 5 and vaulted the other 5 asking me to reboot.

    After Rebooting I noticed it takes quite a bit longer for my computer to boot up. When it goes to boot to my desktop it boots to a black screen. I can over come this by starting the task manager and manually start explorer.

    When this happened I choose to run ComboFix. After shutting down AVG so combofix can run I booted it up. Well not 1 minute later and CF informs me that the MASTER BOOT is infected. 30 seconds later I get told CS has detected Rootkit activity and needs to reboot. I allow it to reboot and same thing, black screen. I manually boot up explorer and CF starts back up on it's own. It runs as normally untill it reaches the 4th Process. At that point I get a blue screen that says windows shut down to protect itself. Reboot back to black screen, manually start explorer, try combofix again and it's back to telling me about the Master boot and rootkit activity.

    I'm really worried here and could really use some help. I do have some computer abilities so will be able to follow whatever you tell me to do.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You will need to uninstall AVG before continuing with the below, doing as much as you can, skipping steps you can't complete and noting it down to tell me later.

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.


    Also run this:

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread
     
  3. XJadynX

    XJadynX Private E-2

    Thank you for responding. I might have solved the problem. < I opened my eyes and saw your how to clean windows thread > I've run everything except RootRepeal which won't run for some reason.. including ComboFix. So far so good I think. If problems continue to show themselves I have all the logs and will include the one you posted for here and will attach them to this post with an update.

    Again Thank you ^_^
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Running the scans does not guarantee that all traces of the malware are removed, so you should go ahead and attach the requested logs. ;)
     
  5. XJadynX

    XJadynX Private E-2

    Well that didn't take long.. I'm still have boot problems and had to re-install foxfire. here are the logs
     

    Attached Files:

  6. XJadynX

    XJadynX Private E-2

    I cannot upload RootRep logs as it will not run for some reason.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  8. XJadynX

    XJadynX Private E-2

    here is the log.. it did find something
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good!! That should have fixed any issues you were having. I am about to log off, so I will let Kestrel finish up with you. Make sure to tell her what issues, if any, that you are still having. ;)
     
  10. XJadynX

    XJadynX Private E-2

    Big thanks. It seems to be running good again. I'll chime back if anything else pops up ^_^ Needless to say lesson learned to up my caution level a few more notches.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There were a couple of items that could be removed that I saw in your logs.....nothing real important, but I will let Kestrel go back thru your logs and advise you if there is anything else that needs doing. My dinner calls and she should be back on in a little while. Good to know things are running better!! :)
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please use MSCONFIG to put this machine back into NORMAL start up mode before we continue. You should always be in normal start up mode.

    Disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    What do you know about these files all sat in C:\ProgramData ?

    What about these?

    C:\Windows\a.lic
    C:\Windows\System32\a.lic

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    REBOOT your machine

    Now run Ccleaner.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds