Malware disables Win SecutityCenter, Defender, Norton, SUPERAntiSpyware, Malwarebytes

Discussion in 'Malware Help (A Specialist Will Reply)' started by PrivateNewman, Jan 8, 2010.

  1. PrivateNewman

    PrivateNewman Private E-2

    Hi! I'm having serious trouble with what I suspect is some kind of malware that affects the security/defense programs in Windows as well as my Norton Internet Security.

    I run a HP stationary PC with Vista SP2

    1) When I log on, the taskbar warns about Security Center not being started.
    2) Then a popup informs that "Windows Defender User Interface has stopped working". After dumping that popup, another occurs about MSASCui.exe Program error (0x80000003).
    3) After a while another popup "Automatic Live Update Sheduler has stopped working"
    4) The computer seems to run normally except for IE and Outlook. IE works slowly and often "Stops working" (popup again...).
    5) When trying to run Norton Internet Security to scan for viruses etc, it refuses to start, nothing at all happens when I try.

    My Home PC support adviced me to backup all important files and do a system recovery, but I decided to give it a shot and try to spare me that by turning to you first.

    5) I went thru the steps of your Maleware Removal Guide, but got stuck when installing SUPERAntiSpyware. With the original name it would not start. After renaming it to SAS.exe the installation started OK, but after a few steps of the installation I got a classic Blue Screen crash.

    6) After reading some of the threads on this fine site, I installed Malwarebytes (succesfully). When trying to run though, I got another popup saying that "Malwarebytes has stopped working".

    So now I feel like I am at the end of the road. Any suggestions are very appreciated!

    //Anders
     
  2. SUPERAntiSpy

    SUPERAntiSpy Private E-2

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Malware disables Win SecutityCenter, Defender, Norton, SUPERAntiSpyware, Malwareb

    As well as what has been suggested by SUPERANTIspy please also let us know if you were able to run RootRepeal, combofix and MGTools. Attach logs from each if you were successful in running them.
     
    Last edited by a moderator: Jan 10, 2010
  4. PrivateNewman

    PrivateNewman Private E-2

    Re: Malware disables Win SecutityCenter, Defender, Norton, SUPERAntiSpyware, Malwareb

    Hi! I tried the SUPERAntiSpyware Online Scan. It worked semi-ok, no problem to download and start, but after some half-hour of scanning it got stuck in c:\ProgramData trying to scan a (system original) shortcut that referred back to the same place. I had to stop that eternal loop, and thus no log or other results from SAS.

    No success running RootRepeal or combofix either. RootRepeal started ok but was completely blank on startup, Combofix wouldn't install. After manually starting the Security Center Service, I was not able to shut down my Norton firewall or AV. Result of malware?

    Everything behaved so strange that I decided to do the abominable System Recovery after all. On startup, something seemed to be wrong with the hard drive, so now the PC is on its way to HP to get a new HD...the Lord works in mysterious ways...:major

    tu, cu and 73

    //Anders
     
  5. SUPERAntiSpy

    SUPERAntiSpy Private E-2

    Re: Malware disables Win SecutityCenter, Defender, Norton, SUPERAntiSpyware, Malwareb

    We have a fix for that coming out this week - you can bypass that problem by scanning in Safe Mode with the online scan and it should work no problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds