Hard drive restores itself to previous state, unable to remove malware.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Creativeballance, Mar 8, 2008.

  1. Creativeballance

    Creativeballance Private First Class

    Ok, I´m working on a relative´s computer. I´m sure it´s got at least some malware. It´s running XP SP2, but some individual decided to install VistaMizer on it, which makes it look like Vista. That´s a problem. It´s got a couple programs that I´m flagging as bad for now: Babylon, Winning Eleven 7 International, and possible WinAmp Remote.
    Flagged Tasks running: Domino.exe, ZSSNP211.exe, and FrzState2k.exe
    Antivirus program is Avira AntiVir Personal edition.

    Every time I restart the computer, even from safe mode, everything is back to the way it was before. Temp files I deleted are back. Programs I removed are back. Programs I installed are gone. I´m working on doing the basic removal steps now, and I´ll post my logs as soon as I have them.
     
  2. Creativeballance

    Creativeballance Private First Class

    Here´s my logs.
     

    Attached Files:

  3. Creativeballance

    Creativeballance Private First Class

    And the reason I´m not able to get anything to remove, I think, is that there´s a program called DeepFreeze6 on here that won´t let me make any changes. Right now I´m trying to figure out how to kill it (Removing registry entries that point to it, the dam thing doesn´t have any unistaller)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    None of the items you mentioned are malware. You should just uninstall all programs that are not needed. Whoever installed DeepFreeze will have to help you uninstall it. It is also not malware so you are in the wrong forum for dealing with it. It did create the below file on the PC:
    Code:
    "C:\"
    $persi0.sys   Mar  8 2008    11055616  "$Persi0.sys"
    And it loads a service named DeepFrz which uses this file: C:\WINDOWS\system32\drivers\DeepFrz.sys

    You do have some malware though which needs be uninstalled as was requested in step 1 of the READ ME. Uninstall Messenger Plus! Live & Sponsor (CiD)


    Now let's remove the LOP infection that occured whn Messenger Plus! Live was installed. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now delete the below files:
    C:\WINDOWS\Tasks\AC68611291841886.job
    C:\Documents and Settings\Administrador\Datos de programa\softtr~1\mix dart multi.exe

    And delete the below folder:
    C:\Archivos de programa\soft trans meta

    Other than the above the logs are clean.
     
  5. Creativeballance

    Creativeballance Private First Class

    Unfortunately, this computer is in Peru, and the technicians here are not the same you and I are used to. Basically, the techs here are kind of unethical, which is why deepfreeze was installed...."If you want to put something else on your computer, you need to call ME, not anyone else". There´s no way for me to remove the other malware on it unless I can unlock deepfreeze. I was going to just reformat the HDD, and reinstall windows but apparently the a-hole took the windows CD with him. (Which I think is a boot-leg version of it anyway). Next time I come down here, I´m building a new system and I´m tossing either a legit copy of windows 2000 on it or throwing lunix on it. I´d spend more time working on it, but I´m going back to Lima tommorow morning.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As long as this is a personally owned PC and the Deepfreeze software was not installed by a company to block you from doing anything they don't want you to do..... well then you can try the below which may help with Deepfreeze and with the other files and folder. Make sure you uninstall Messenger Plus! Live afterwards.


    Now we will to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Creativeballance

    Creativeballance Private First Class

    Well....that didn´t work. Deepfreeze is not gone, nor is it accepting changes. Oh well. Don´t worry about it, I´m getting on the bus to go in an hour. Thanks for trying though.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. It was worth a try. It may have other hidden files and registry keys that are blocking the changes. A reinstall may be easier unless you can get the info required for uninstalling DeepFreeze from the person who installed it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds