Humbled by failure, in need of help

Discussion in 'Malware Help (A Specialist Will Reply)' started by zelmo, Jul 4, 2008.

  1. zelmo

    zelmo Private E-2

    Sorry to repost here. I'm a previous client and a refugee from the software forum:click here to read history

    I had a very compromised laptop, with some variation of W32\Brontok-x. So I wiped the harddrive clean and reformated it. After reinstalling all my applications, I reconnected my external backup drive. I'm not a complete idiot. I scanned the backup drive 3 times with 3 different antivirus/malware programs. It came up clean. I was in the Software Forum because after reformatting the drive, I got a Blue Screen. The error message seemed to be relating to the RAM, or a type of driver issue. Not the case, as I discovered. As I was running diagnostics, I decided to upgrade to a new firewall, Comodo. That's when I found out the backup drive was not clean. Comodo found Brontok-x hiding in a hidden folder called System Volume Information. It contained all my restore points. Comodo deleted the virus and I deleted the files. But they immediately came back, as soon as I deleted them. I turned off System Restore, deleted them, and they did not return.

    However, with System Restore still off, the file System Volume Information has shown up in my C drive. Is this normal? I know I eventually need to turn System Restore on, but I want to hear form you guys what to do next.

    Then Webroot quarantined the Trojan EICAR-AV-TEST. I deleted it and moved over to Malware Removal forum.

    I have followed the Read and Run Me. I am attaching the logs. I await your advice.
     

    Attached Files:

    Last edited: Jul 4, 2008
  2. zelmo

    zelmo Private E-2

    One more log to post.

    Thanks
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It will be gone until you re-enable System Restore. If you want to have the System Restore feature, you need to reenable.



    This is just a false positive. Some antivirus programs create this as a test file. See this: http://www.eicar.org/anti_virus_test_file.htm

    You do not have any malware to remove. You do however need to get your PC properly protected. You have no antivirus and no real firewall installed.
     
  4. zelmo

    zelmo Private E-2

    Thanks for your reply Chaslang. I am confused, however.

    I have Webroot with anitvirus installed. Also installed: All the programs I downloaded for Read & Run me, plus a Comodo firewall. I now have my doubts about Webroot's effectiveness, but doesn't it count for something?

    More pressing matters:
    Today, I turned the laptop on to get to work, and it immediately went to Blue Screen, Scrolled text for an instant, and then died. I could not even read the error report. Repeated attempts yeilded the same results until I finally got it to start loading safe mode, and again it went to black. Not even a Blue Screen, unless it flashed so quickly I missed it. If it ain't Malware, its something else. All of the diagnostics I've run have shown no problems with RAM or drivers. Your opinions on the matter would be greatly appreciated.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what I saw in your logs which is just Spy Sweeper, I assumed all you
    had was the antispyware program which is what that normally means is installed. If WebRoot would be a little smarter in their program naming and call
    it something different (at least the installed program) we would then know it was also an antivirus as it sure does not look like one. Are you 100%
    sure that what you have installed is both an antispyware and an antivirus?

    None of those provide any realtime protection.

    Sorry! I just did not notice it.


    At this point I'm not sure what your problems is especially since nothing that was run found any malware and thus nothing was removed. You should locate your Windows boot CD and post in the Software Forum. You may need to do a repair.
     
  6. zelmo

    zelmo Private E-2

    This is a much delayed follow up/resolution to the problem I was having.

    Chaslang, you were correct in stating it was a repair issue. The Toshiba authorized dealer closest to me ( who will remain nameless) turned up nothing in their original diagnostic scans. They gave my laptop a clean bill of health despite my clear explanation of its various blue screens.

    A few days later: another blue screen. I took it back, they redid the test, and the 1G of additional RAM I put in a year ago came up as faulty.

    They removed the stick. I'm getting a repalcement from the online memory company I bought it from (lifetime warranty). No blue screen so far.

    Some questions I have about the whole incident:

    I really did have a virus infection. Can a virus corrupt RAM?
    If not, what are the odds of a viral infection and a RAM failure at the same time? Really odd.
    On my old Thinkpad (back in the day), with Windows 98 SE, I could run a hardware diagnostic myself. It was very user friendly and uncomplicated. Why the change with XP, and Vista (I assume)? A RAM problem is easy to fix, if I had just known about it.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for reporting back on what your problem was. I'm happy to hear you have it resolved.

    Highly unlikely!

    Probably higher than you would think but that is mostly due to the fact that probably 60 to 80% of all PCs have some form of malware on them. The odds for have a serious infection and a RAM failure at the same time are significantly lower.

    There are many diagnostic tools that you can run. See the below download folder on Major Geeks!

    http://www.majorgeeks.com/downloads7.html

    Also there is a folder for Memory related programs which also has memory testers. See the below folder:

    http://www.majorgeeks.com/downloads26.html

    A couple of popular memory test programs are:

    MemTest

    Memtest86+
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds