Infected - I have run malware and virus software but cannot cure this

Discussion in 'Malware Help (A Specialist Will Reply)' started by loudnrg, Jun 7, 2010.

  1. loudnrg

    loudnrg Private E-2

    A few days ago I was visiting a website and my browsers (firefox) immediately crashed and puter froze up. I restarted and got annoying pop-ups such as Resident Shield Alerts etc and it also installed antimalware doctor. I figured out that it was a malware infestation and have been trying to clean it up for 3 days.

    Other symptoms:
    - computer freezes and/or crashes when I try and run malware software etc - I get the blue screen that says: Problem has been detected and windows has been shut down to prevent damage to your computer...

    - error messages: Linksys wireless network monitor access violation at address 004z6059 in module WMP54GSv1_1.exe. Read of address 00000368

    - RUNDLL
    Error loading ercloqqn.dll
    The specified module could not be found.

    - avg antivirus blocked the following: somesite.ru:port 8080 or something like that.

    - sluggish slow performance, especially when accessing the internet


    Heres what I've done so far:

    ran rkill to stop known malware processes
    ran malware btyes, spyware doctor and superantivirus
    ran avg 9

    I cleaned my temp files prior to running these using tfc.exe from Oldtimer tools, backed up my registry and cleaned it using pc tools registry mechanic

    I've ran and rerun the malware and virus scans many times in safe mode (puter would freeze if scanned in normal mode) and they found lots of trojans etc. Now am able to scan in normal mode and I keep finding stuff - doesnt seem that I am fixing everything and although the puter seems somewhat better, its still not working properly. It still runs slow, crashes and gives me the blue screen mentioned above when I run gmer.exe for example and I still get the rundll error on startup. Note - I also uninstalled and reinstalled the above software with different install file names to help avoid detection.

    I may access to a windows install disk or boot cd.

    Note - my puter crashes when I try and run gmer, even in safe mode. Here is some info on the blue screen after it crashed.

    "the problem seems to be caused by the following file: fxtdqpoc.sys
    iE_FAULT_IN_NONPAGED_AREA

    Let me know what logs/files you need to see and I can provide them.

    Thanks in advance for the help!
     
  2. loudnrg

    loudnrg Private E-2

    Here are my log files:

    Note - I could not run combofix - got a file could not be found error. I could not run MG Tools, no matter what anti-virus etc I shut down, it kept throwing errors.

    The two persistent problems at start up are still the RUNDLL error for a dll that I have never heard of and occasional I get a Linksys access violation error - see above post for details.
     

    Attached Files:

  3. loudnrg

    loudnrg Private E-2

    more log files.
     

    Attached Files:

    • avg.txt
      File size:
      960 bytes
      Views:
      5
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try uninstalling AVG and then see if you can't run MGTools. Please go here and download and run the AVG Removal Tool.

    Rename ComboFix.exe to ComboBatch.bat and then copy the below red text.

    "%userprofile%\desktop\Combobatch.bat" /stepdel

    Go to Start > Run > then paste in the the text you copied into the run box then click OK. Does Combo now run?
     
  5. loudnrg

    loudnrg Private E-2

    Cannot uninstall AVG even with the utility you provided. Am trying to get combofix running and will report back with my logs once I have them.
     
    Last edited: Jun 8, 2010
  6. loudnrg

    loudnrg Private E-2

    I got combofix running, it rebooted once after I got the message "combofix has detected rootkit activity and needs to reboot the machine"

    Then it ran up to stage 50 of its scan and then I got the blue screen saying windows has been shut down to prevent damage to your computer.

    Now I cannot boot the puter in safe mode or anything - it crashes immediately and goes to the blue screen...

    Any ideas - I could not keep my puter working well enough to backup my data so its important to get it working at least long enough to get my data off it.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you cannot boot in any mode ( safe or normal mode ) and you cannot run any of the READ & RUN ME there is not much we can do for you except suggest what is in the below quote box
    I would try the Kaspersky Rescue disc first. It may take a long time to run, but has been effective in such situations.
     
  8. loudnrg

    loudnrg Private E-2

    Luckily my network uses roaming profiles and the server seems to be ok and originally it didnt look like all my data synced with the server but that has been solved so my data is safe and I think it will just be easier to wipe the machine clean and reinstall a new OS (windows 7) and then reload the apps I was running and then re-add the data.

    Thanks for your help.

    BTW - can you recommend the best anti-virus, malware and firewall software. I'm done with AVG...
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds