Problem Getting Worse

Discussion in 'Malware Help (A Specialist Will Reply)' started by Paul Naj, Jul 12, 2009.

  1. Paul Naj

    Paul Naj Private E-2

    Thanks in advance for your help and your valuable service to the community.

    I picked up a nasty virus / malware recently and have tried to use McAfee and several Malware removers over the past 3 days to no avail. Everytime I seem to make progress something new emerges.

    This started with the Antivirus 2009 Pro Malware taking over. It changed my file associations so I couldn't run any .exe's. It even removed the View Folder Options menu so that I couldn't re-associate the file extensions. Fortunately I was able to logon to the adminstrator logon and fix that issue.

    I tried to do an XP repair but was unable to when the application couldn't recognize my administrator password even though I can log into the admin logon with that same password. I then ran Macfee, Spybot and Malwarebytes Anti-Malware. This seemed to clear up most of my problems although I noticed a prior issue of still having one or more iexplore.exe processes running even though I didn't have an IE browser open.

    Sure enough the next day I suddenly was unable to connect to the internet.
    I finally found your forum and started to follow your proceedures for cleaning.

    I was unsuccessful in running several of the procedures. I have found that my DHCP Service will not start and gets the error "Error 1075: The dependency service does not exist or has been marked for deletion". When I try to look at dependencies I get the error "Win32: Access id denied".

    Here were my results:

    1. SuperAntiSpyware- Got the BSOD unless I unchecked the recommended boxes. Then deleted one file. I can't save the log file but the deleted item is as follows: Trojan.Agent/Gen-FraudDrop C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OWZ397BG\UAOBTTGU[1].HTM

    2. Malware Bytes Anti-Malware- Couldn't run App. Got the Error Code: 718 (0, 0)

    3. Combofix- I get constant pop ups saying publisher could not be verified. Are you sure you want to run this software? I continually say run and nothing happens but a system beep and the program aborts.

    4. RootRepeal- RootRepeal runs successfully and finds 94 locked or hidden files but I am unable to save the file and get the error "unknown file type" .

    5- MGTools- I saved MGTools to the Windows directory as suggested and when I ran it it opened a command window but othing else happened

    Any suggestions on where to go from here would be appreciated.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What OS are you running?
    Did you try getting into safe mode and doing a system restore to before this started?
    Did you try renaming the programs, running them in safe mode, or changing the .exe extension to .com?
    Did you disable your AV and AS programs before running any of the scans?
     
  3. Paul Naj

    Paul Naj Private E-2

    I am running XP Pro

    I haven't been able to boot in safe mode, I get a BSOD.

    I solved the original .exe problem prior to the post. The latest problem is that multiple services will not start due to Error 1075: The dependency service does not exist or has been marked for deletion". When I try to look at dependencies I get the error "Win32: Access id denied". I also can't view anything with Event Viewer. Event Viewer opens but when I try to click Application, Security, System etc. I get the error "Unable to complete the operation on "Application" (etc). The interface is unknown"

    Also, I resolved the password problem I was having with XP repair as it was only recognizing my second bootable drive. I removed that drive and the password I was using was correct but repair now goes to a BSOD.

    Also, any Windows .msc file I run opens but has a "Open File- Security Warning. Do you want to open this file? Unknown Publisher"
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At this point my only suggestion would be to copy all your important data and files to cd if possible and do a clean install of windows. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds