PC completely screwed

Discussion in 'Malware Help (A Specialist Will Reply)' started by sam988, Oct 14, 2008.

  1. sam988

    sam988 Private E-2

    Ok my PC is completely screwed beyond repair, i did the very dumb act of installing some a certain program there with all my defenses deactivated.


    But that's not what i want to ask you about. I already turned the PC off and am about to buy an external HD to save my very precious 220GB worth of files.

    I want to know if my files are still safe (i could still open them normally even after PC got completely infected with all the ads and errors and stuff). If i transfer them to the external HD, will they carry the virus(es)?

    What do i do in this situation? I don't even want to turn the PC on because i'm afraid that even more sh*t will happen, now that it is probably completely in control of the crackers.


    Just some info that might be relevant, i got Windows XP Pro. Any more info that you need, i'm here to answer.


    Thanks in advance.
     
  2. sam988

    sam988 Private E-2

    Just to make it clear, i just want to save the files, then i can reformat the PC. I want to know the best and safest strategy to save my files now; is it by taking the HD off the tower and putting it on another PC, or by plugging an externa HD and transferring the files, etc?


    I don't care about how long it takes, or how much it costs, these files are VERY important to me, it is part of several years of my life. Should've been more careful... but i already spanked myself so don't bother to do it yourself, the sh*t is done already.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!


    It will actually be easier to remove the malware then for you to have to go thru the whole hassle of reformating after saving your documents and then reinstalling all your programs and settings.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  4. sam988

    sam988 Private E-2

    Thanks for the answers. I'm a relatively experienced PC and internet user (8+ years), and i've never seen a PC so taken over.

    It's probably not just one malware, but a legion of them. As soon as i installed that program, the pc started getting crazy, a DOS cmd window opened and some commands were written, then it closed, the wallpaper dissapeared and instead some images with links appeared, then some more stuff happened and the PC auto restarted itself.

    When it booted again it was even worse, the icon area had those "your pc is infected" icons, which were viruses of course, i tried to "cut and pasted" a few files but i couldn't do it, and i tried to activate the antivirus and i couldn't do it either. It's a mess.




    My biggest fear is that my files can get deleted somehow in the proccess of fighting all the malwares. Don't you think that it's safer to just get the files out of that mess and then reformat it?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not necessarily.....you may want to copy those files to a cd or thumb drive....but since each are writeable, any virus could also infect that medium.

    I would really like you to try doing the Read and Run instructions....if you need to, follow the suggestions in the notes.
     
  6. sam988

    sam988 Private E-2

    Now why the F*** did i allow myself to get convinced by you :cry

    Situation is far worse now (i'm not on the infected PC now of course, i try to let it off as much as possible so situation doesn't get worse).


    As i said early, this is no ordinary infection. Some facts:

    - I can't access: the control panel, the start - explore panel, the "execute" function.

    - And now after trying to run those programs in the tutorial you gave me (and then i had to connect the PC to the internet which i wasn't doing), the malwares inside the PC kept downloading more malwares, and more and more images with links appear on the workspace.

    - Now the WORST part: when i open the "my computer", the C drive, which is where everything is, has DISAPPEARED (along with the D drive which is the CD's drive with the anti malware programs i was told to use in the tutorial).



    I'm definitely abandoning that sinking ship, if i turn the internet on on that mess, it downloads more and more malwares; i have fought several infections and viruses before but i've never seen anything like this.

    I just hope that all the data in my hard drive isn't gone, although i can't find the C drive anywhere. Do you think that it all got deleted? (unlikely since it only a few minutes passed before i turned the PC off before it exploded on me or something).
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your drives did not get deleted.....and we suggested that you do the scans without updating if you are having internet issues.

    Did you put the tools on your desktop? Did you try running them in safe mode. Did any of them complete so you could be us a log?

    What exactly is happening?
     
  8. sam988

    sam988 Private E-2

    I appreciate the help TimW. I did run all the scans ofthe malware removal guide in safe mode (in normal mode it's impossible), and they did spot and eliminate malwares. But then i started the PC in normal mode and apparently the malwares were there still. Nothing much changed.


    My external HD just arrived, do you know how do i "clean" my files so that i can transport them to the external HD? My personal files are all in one major folder, so cleaning them should be a bit easier. Should i run an antivirus on the folder or what? I did already do this on the whole PC with the programs mentioned in the malware removal guide but apparently they weren't effective.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can not advise you without seeing the results of the scans. I need you to attach these logs:
    SAS
    MWB's
    ComboFix
    C:\MGLogs.zip
     
  10. sam988

    sam988 Private E-2

    Unfortunately i couldn't get SAS' log, hope it's not a problem. The logs are in portuguese, hope it's not a problem either.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I did not ask for a HJT log. I need the C:\MGLogs.zip.
     
  12. sam988

    sam988 Private E-2

    Ok, here it is. Had to run it again now because i didn't find the previous one, so this is the newest diagnosis of my PC.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs show you are running Avira and had or still have Rapid Antivirus. Is Online Armour just a firewall or does it also have active anti-virus? Make sure you only have one active AV installed.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file (in normal mode) by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  14. sam988

    sam988 Private E-2

    The files are attached.

    By the way, The /C now can be accessed in normal mode, but i still can't access the "All Programs" function in the Start menu, neither the "search" or "run" or any other start menu function. They've all gone missing.

    Also, i don't know if you overlooked it or not, but the Rapid Antivirus in my PC is a malware or was downloaded by the malware since i didn't have it before my PC got infected.

    My Avira Antivir i installed in safe mode after my PC got infected but i couldn't update it for the reasons already mentioned in the topic. I uninstalled Online Armor now (i didn't know it was running, since by then i thought it hadn't installed properly in safe mode).
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My bad....I mistook it for a legit anti-virus of a similar name...we will remove it.
    And are now only running Comodo Firewall?
    You should not be installing and uninstalling programs until we get you clean.

    You are a mess....

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  16. sam988

    sam988 Private E-2

    Ok here they are.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet.....just one thing to fix:

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, just exit HJT.

    What issues are you still having?
     
  18. sam988

    sam988 Private E-2

    2 problems only that i can currently identify. By the way, thanks A LOT for what you've helped me with so far. I really appreciate it.


    Now to the 2 problems left. The first is that i get a "VIRUS ALERT!" message beside my clock in the low right corner of the screen. I don't even know what will happen if i double click there and i don't wanna find out.

    The second problem is that i still can't see most of the functions on the Start Menu. I can't access the Control Panel, the Search function, the Run funciont, the All Programs function, etc.



    Ah there's another thing. I haven't accessed the internet on my PC for days, i've been posting here from another PC in the house. I've been using a pendrive to transfer to my infected PC the programs and notepad instructions i've been told to get. I cut off the infected PC from the house network, afraid that it would infect the other PCs. So i won't really know if my PC is ok until i access the internet... and i'm afraid to do so (what if some remaining malware starts downloading malwares again), now that it looks so clean.
     
  19. sam988

    sam988 Private E-2

    One more thing that is related to what i said in my previous post.


    If i right click in my (work space? don't know the word in english.. it's where the wallpaper stays), and click on Properties, then a message appears saying, in English, something like "The System Administrator has disabled ...(such and such)...".


    Apparently i'm not the system Adm anymore? I can only access all functions and be the Administrator when i boot in safe mode.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run ComboFix ...do not worry about the recovery console. Attach that log.

    Then please re-run SAS, MWB's on each user profile....if anything is found, please attach each log.
     
  21. sam988

    sam988 Private E-2

    Yep, that was it. I only ran MWB and it worked like a charm. Everything is back to normal, or so it seems.

    The log comes attached.


    I'm still afraid of connecting the PC to the internet, though.. do you think i'm safe to go now?
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if anything else pops up.

    In the meantime, we can clean up form the scans.

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds