Can you diagnose these symptoms?

Discussion in 'Malware Help (A Specialist Will Reply)' started by rgATL, Apr 8, 2008.

  1. rgATL

    rgATL Private E-2

    Hello, thank you for your help. Let me try to breakdown my issue:

    History:
    * I went to a song lyrics site (plyrics.com I think) and got some sort of malware. It was taking over my laptop (launching IE windows, installing software, etc).
    * I was trying to run my Antivirus software (Symantec 10) as well as to download and run Spybot S&D. Within minutes, I wasn't able to do anything (CPU overwhelmed by malware), so I turned it off to back up the data from the D drive.
    * (I run a laptop with 2 hard drives and save most of my data on the D drive (hereafter "data drive"), but either can boot WinXP if needed).
    * I removed the infected drive and booted from the data drive, pulling off some of my data on an external hard drive). Then I installed the infected drive as the slave and ran Symantec 10, Spybot 1.5.2, and Ad-Aware 2007 Free.
    * Symantec found Trackware.Webhancer, and Ad-Aware found Virtumonde; both of which they said they removed.
    * So, thinking that everything was now fixed, I put the infected hard drive back in as the system drive and booted from it. Windows XP was extremely slow to load, and when it did, I got 10-20 RUNDLL errors reading:
    Code:
    Error loading C:\DOCUMEN~1\"username"\LOCALS~1\Temp\dcfqpsfml.drv
    The specified module could not be found.
    This error also comes up if I try to open any application (Spybot install file, IE browser, etc) or try to access the desktop properties -- this happens in BOTH normal boot AND safe mode -- but I can open things like text files and images.

    Other Symptoms:
    * Task manager has been disabled.
    * When the computer idles, a "screensaver" of beetles eating the desktop comes on.
    * Desktop wallpaper has changed to a blue background with a "warning" in the middle of the screen with something to the effect of, "your computer may be infected with spyware."
    * Some (fake) anti-spyware shortcut has appeared on the desktop.

    Diagnosis?

    At this point I get that RUNDLL error when I try to run any program, so I'm not sure I can run Spybot or HijackThis directly from the infected drive. Are there other options (command line, D drive)? Can this be recovered?

    Thank you for reading all of this and for your help. Any thoughts would be tremendously appreciated.

    Thank you,
    rg.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. rgATL

    rgATL Private E-2

    Hello, thank you for your reply. I read the "read me" instructions before creating this thread. However, I canNOT run any programs when booting from the infected drive:

    Are there other options to generate useful logs?

    Thank you,
    rg.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does the PC boot up to Windows?

    What about running things in safe boot mode?

    If you cannot run anything, then we cannot help you. This is rather a simplistic view in that if nothing runs, then we cannot run anything to fix your problem. Thus, you can either attempt to scan it and clean the drive in another PC, or you can try a Windows Repair, or you can format and reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds