Problems running the READ ME FIRST

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lawstudent101, Mar 31, 2010.

  1. Lawstudent101

    Lawstudent101 Private E-2

    I encountered a rather large infection on my laptop. This is not the first forum I went to in an attempt to resolve this issue so bare with me.

    Basically when I boot up I have a lot of bad processes (Reader_S.exe 1434824278.exe, a lot of other odd and troublesome processes that I KNOW should not be present)

    I could not install malwarebytes as the virus/trojan whatever would delete the .exe, I got around that by downloading the random .exe file and sticking it where the normal .exe should be to run.

    So I have malwarebytes running, I cannot update it, I tried to manually install the definitions to no avail. I CAN however perform a quick scan, after the scan competes, during removal, I get the blue screen of death(BSOD), and an auto reboot.

    I tried rootrepeal, I have downloaded avenger, I have malwarebytes, I tried Vundofix, I tried alot of things. Right now what seems to be working is RKILL.exe while I also have task manager open, manually taking off procseses

    I came here, attempting to run the READ ME FIRST instructions, I was not able to complete almost ALL the instructions, CC cleaner gets me the BSOD, I am not able to uninstall some of programs suggested, like the viewpoint media player.

    Cliffnotes: Blue screen of death whenever I try to do any recommended options I read about here on the forum. What log do you guys need me to upload to start out? =( This is the craziest bug I've ever encountered in my 15 years of using a PC.
     
  2. Lawstudent101

    Lawstudent101 Private E-2

    I will post logs when I get home.
     
  3. Lawstudent101

    Lawstudent101 Private E-2

    Here is the rootrepeal log. Please keep in mind i am trouble doing ANYTHING on this computer. I'll randomly get blue screens of death. I'll try the best I can to get other logs.
     

    Attached Files:

  4. Lawstudent101

    Lawstudent101 Private E-2

    I cannot run combofix, as it says that "it is not safe to continue, you may be infected with a file patching virus viruit"

    Sorry for the multiple posts, I am not bumping but rather trying to update whoever will help me as much as possible.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to at least run MGTools.exe if not in normal mode then in safe mode? (But do try normal mode first and if you have difficully running it then please try a rename to 123.com before trying safemode.)

    Attach the C:\Mglogs.zip into your next reply.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most of the time when you see this message, ComboFix is correct and you do have a Virut infection. If you can get the MGlogs.zip file log from MGtools that Kestrel13! requested, we should be able to determine this for sure. Your RootRepeal log does show other infections like a TDSS rootkit so there may be a chance that you do not have a Virut infection.

    WARNING: If you do have a Virut infection, you will be reinstalling from scratch as there are no reliable fixes for systems infected with Virut or similar PE file infectors.
     
  7. Lawstudent101

    Lawstudent101 Private E-2

    Sadly, I got the blue screen of death before I was able to upload the MGtools.zip log. I know it did run, and I had it on my harddrive.

    I ended up reinstalling windows....however I did not reformat? I simply stuck the install CD and booted from there. I now have a folder called "windows.old" where all my previous stuff is, however I cannot run programs etc. from there. I did however run Superantispyware and Malwarebytes and it ran and I *believe* took care of the remaining infection. Here is the log I ran from the MGtools.zip I know it says hijackthis.txt, not sure why.

    I just need to know if this clean install is safe... =( and if there is anything I need to do to keep my laptop operating safely...

    thanks for the help guys.

    oops! Just found the MGtoollogs you requested. Let me know if this is it or not. Sorry if it isn't, obviously my laptop is a complete mess atm.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see you ran TDSSkiller and it removed the TDSS infection I referred to.

    However your MGtools log is not really of much use now that you reinstalled Windows. Obviously we can look at it and rename anything that was pointing to C:\windows to C:\Windows.old but the registry values are really going to be valid anymore due to the reinstall.

    Please run the READ & RUN ME cleaning instructions now so that we can collect new information on your current status and to see if anything remains to be removed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds