Fake Antivira Av killing my processes - please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by walkingalchemy, Feb 17, 2011.

  1. walkingalchemy

    walkingalchemy Private E-2

    I have a fake Antivira Av virus which has taken over my computer. It loads at startup and breaks my internet connection. It then proceeds to pop up various viral alert windows which cannot be closed and some of which can not be moved. The nasty part though is that it does not allow other programs to run. It kills everything I try to run within under a second of opening. This is true for all of the scanners, task manager and even command prompt.

    The only scan I got to run at all was MGTools from c:/ directory, but I am loathe to use a jumpstick to bring that over to this computer and have it get infected as well. (gotta have something to work with here :/ ) I will if someone here directs me to. Please let me know how to proceed.

    Thanks for any help. You all are the saints of the intarnest.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you do not want to use the flashdrive then use a disk? :confused
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    In step 1 of the READ & RUN ME, did you see and try the below
     
  4. walkingalchemy

    walkingalchemy Private E-2

    With some fast keyboard fingers I managed to get Ccleaner opened and disabled all startup processes before the bugger loaded. What now wyatt earp? I will begin again with the scanners and get you all the info you ask for in RTF.. uh R&RM. Up later this evening.
    (and I will check the proxy server)
     
  5. walkingalchemy

    walkingalchemy Private E-2

    Here are the logs from my scans. Sorry that I had run MGTools and RootRepeal before combofix, was before I disabled the startups. After I got rid of the startups I began again from the top of the Vista Malware removal thread.

    Step one worked like a charm, suprise suprise.
     

    Attached Files:

  6. walkingalchemy

    walkingalchemy Private E-2

    Last log.
     

    Attached Files:

  7. walkingalchemy

    walkingalchemy Private E-2

    Ah right. And things seem to be working fairly well. I will wait for your go ahead before reinstalling AV's etc. and going back to work.

    Thanks.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete this file unless you know what it is.
    C:\Users\Todd\AppData\Roaming\CBE2.E30

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread
     
  9. walkingalchemy

    walkingalchemy Private E-2

    Attached are the logs you asked for.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your Vista install disc? If not:

    Vista and Win7 Recovery disc

    You will need to change the boot order in the bios to make the cd-rom the first boot device.


    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr, and then press ENTER. ( There is a space after the .exe and the / ).


    Reboot into normal mode and run MBRCheck again. Attach the log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds