Malware Issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by b2386, May 17, 2013.

  1. b2386

    b2386 Private E-2

    Hi all,

    Yesterday seemingly out of the blue, my computer came down with a bad case of the malwares. I don’t remember doing anything out of the ordinary, but the first signs appeared after updating my adobe acrobat software. That may or may not be related, though.

    All of a sudden ad.xtendmedia ads started appearing in my IE browser and one of those bogus antivirus programs installed itself. It appears my ESET security program was able to remove the antivirus program, but the ads still keep popping up. I tried using several antivirus/malware programs (ESET, AVG, CCleaner, Malwarebytes) yet none can achieve a successful removal (partly due to the issue explained below).

    In addition, some other issues have arisen since the infection. Every 15-30 min I will get a blue screen saying “Modification of system code or a critical data structure was detected”. I initially believed this only occurred when scanning with my ESET security software, but it also occurred once installing AVG. Now it occurs regardless of what I am doing. This behavior makes it practically impossible to complete a full comp virus scan.

    Also, my computer has lost the ability to play sound during this time. The sound device still appears in the device manager list with an updated driver but the volume icon is no longer in the taskbar and no sound devices appear in the control panel area.

    This has got me stumped so any help would be greatly appreciated.

    Attached are the log files for RogueKiller, Malwarebyte, and HitmanPro. TDSSKiller gave an error saying it could not initialize the log so I took a screenshot of the detections it found. It was not able to remove these detections, however, saying that it “Can’t cure VBR”. The MGtools program did not play nice at all. The command prompt would display multiple instances of “The system cannot find the file specified.” No logs were kept after it “finished” (assuming it did finish).
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try doing this:

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:

    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    Option2: Enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. b2386

    b2386 Private E-2

    Thanks for the reply, Tim. Log is attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. b2386

    b2386 Private E-2

    Logs attached.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest you post in the software forum for further assistance.

    Since you are not having any malware related problems, it is time to do our final steps:

    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall

      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.

    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.

    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds