Think it's a virus... but it survived a clean format!

Discussion in 'Malware Help (A Specialist Will Reply)' started by charco, Jan 3, 2008.

  1. charco

    charco Private E-2

    Got a strange problem that has arisen in the past few days (running WinXP sp2). I keep a fairly tight ship running AVG pro and Spy Bot as well as Windows Defender and usuallly clean out everyting one a month or so (temp folders) or daily history, Internet files, etc. Every so often I do a defrag.
    1. When I boot up the PC it operates fine for up to about 30mins then....
    2. Windows Explorer can be opened, but any selection reverts back to the default 'My Documents' highlight immediately it is selected. i.e. it is impossible to browse the filing system.
    3. Internet Explorer returns back to the homepage (in my case, google.com)
    4. If IE is closed and reopened it opens to no page - i.e. it doesn't say 'about blank' there is just an empty window and although you can write to the address bar nothing happens, it does not even search for the url. All of the favorites URLs have the same effect, i.e. none at all.
    On reboot everything is OK again until it starts to go awol after a random amound of time.

    AVG, CCleaner, MG etc found nothing unusual. The problem is still there and I am tempted to reinstall the operating system.

    This is becoming a nightmare, I have done more than a bare metal reformat, I bought a new hard drive and reloaded window XP sp2 and the problem is still here.
    Windows Explorer jumps from the selected folder or file right back to the top folder (My Documents) in the tree.
    Internet Explorer just fails to find any pages and returns no error of any kind - just silence.
    I am completely flummoxed. What can survive a new hard drive and new operating system? Is there any way that I have the bios infected with something? I know nothing about bios infections (if they exist)
    Does anyone have any ideas???
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. charco

    charco Private E-2

    reformatted with the data deisks disconnected

    reinstalled WinXP on clean disk

    uploaded all software for anti this and anti that

    problem still there!
     

    Attached Files:

  4. charco

    charco Private E-2

    Another thing - when I run the MG program (HJT) after it has finished a javascript type pop up appears with a message saying "the application couldn't initialise correctly ( 0xc0000135). Click OK to close the program"
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The clean disk is clean ....(if I can understand the language :)) ...hook up the data disks and do an online scan:
    Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  6. charco

    charco Private E-2

    Thanks for your help. I really appreciate it as I'm sure all of the other lost souls do.

    Well the situation is this:

    I reformatted (again) the new hard drive (thiws was no simple matter, I had to use a floppy with a win98 start up - is there no way of doing this directly? The Win XP CD refused to give me the reformatting option)
    I reinstalled windows XP without updating
    I used another (hopefully clean) computer to download all of the necessary tools and burned them onto a CD
    I copied the tools onto the new windows hard disk
    I connnected to internet to update all of the antivirus tools
    I ran the tools and found nothing
    I updated windows XP

    ... and so far (after 6 hours ) there is no sign of the problem. :)

    The difference being that this time I did not use the flash drive to upload all of the AV tools. It seems possible that the flash drive is infected with the virus (or whatever it is)

    Question - Should I just throw the flash drive away or is there some hope for it (it's a 2Gb flash bought this Xmas)? :confused

    Now I'm going to reconnect the data drives and run checks using all of the tools (AVG, AVG rootkit, AVG spyware, Registry cleaner etc etc.) and then I'll run the online tool that you suggest

    Happy New Year and Felices Reyes...

    PS Sorry for the previously unintelligible language - I'm at my wits end after staring at a computer screen for four days.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is very possible your flash drive is infected ....reformating it will reinfect your system...let me quote from one of our members:

    So it is up to you as to whether you want to trash or try the reformat of the stick and then run the BitScan with IE and go through the cleaning procedures again. :)
     
  8. charco

    charco Private E-2

    Trash seems the best option doesn't it? It's hardly worth another entire day of loading and testing.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unless you want to take it to the Geek Squad and have them reformat it ....LOL.
     
  10. charco

    charco Private E-2

    How's that work then? ..

    Seriously though ...

    I am very impressed with the service that you provide here, but I would like to know what it is that you look for in the logs. What I'm trying to say is that I am pretty computer savvy and would be very happy to help out with the many calls for help if you were able to point me in the right direction.

    Cheers and saludos

    Charco
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How's what work? If you mean the comment about the Geek Squad...I guess that would fall under the heading of an inside joke ;).

    As to learning the malware removal process...there are a few sites out there that have "training forums" such as:
    http://www.malwareremoval.com/forum/viewtopic.php?t=233

    The other way is to view the threads here and start making note of the logs and which items are removed in the fixes. Mostly it is a matter of learning what is legit and what isn't.
     
  12. charco

    charco Private E-2

    24 hours into reloading programs and no issues have arisen... I may be clean.

    Guess I'll look into the malware training stuff.

    Thanks again for your help
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome ...we're here if you have any questions. :)
     
  14. charco

    charco Private E-2

    OK I spoke too soon.

    The system was stable for about 24 hours but then this afternoon I closed it down and it returned the message that Windows Update has 84 (yes, eighty four) updates to install. Considering I had updated windows only yesterday this was somewhat surprising. However I let the computer sut down (not having a choice). On start-up the same old problem is back again. Internet Explorer is dead, Windows explorer jumps to 'My Documents'.

    I have put nothing into the computer except programs from CD (read-only) all of which are more than two years old. The flash drive has gone nowhere near the computer. How on earth can it have reinfected?

    I'll go through the Malware removal process again and attach the logs as soon as they have finished.:hammer
     
  15. charco

    charco Private E-2

    here are the logs
     

    Attached Files:

  16. charco

    charco Private E-2

    OK I have written this using notepad as the virus/malware or whatever doesn't give me enough time on internet to write anything before the IE stops working again.
    Symptoms:
    IE (or firefox) stops working and immediately reverts to the homepage if there is one in cache.
    IE occasionally makes new shortcuts of itself on the desktop
    Windows explorer jumps from the selected folder directly to the default folder - usually 'My Documents'
    In WE I can select a folder using rightclick 'Explore' to see the contents and can select files from there.
    On reboot the system operates normally for a variable amount of time (in the order of five minutes) before the problems return.
    I have just run:
    AVG which has reported nothing
    AVG anti spyware - nothing to report
    Spybot - nothing to report
     
  17. charco

    charco Private E-2

    Do you think that the problem may not be a virus but something to do with the latest updates from Microsoft.

    Take a look at this: http://support.microsoft.com/kb/946627

    This doesn't describe my symptoms exactly but is fairly similar.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well...your logs are still clean so it very well may be the update...remove it and see if things return to normal ...or do a system restore to before the updates. Then set your updates to only inform you so you decide which updates to install.
     
  19. charco

    charco Private E-2

    I tried to do a system restore but the problem was still there.

    When I look at the updated installed there are more than 50 of them. They mostly say 'Security Update'. I have tried deleting all of the updates back to December (when the problem started) but the computer still does not work. It's strange, sometimes I turn it on and IE works fine for five minutes or so then returns to the same old problem of jumping back to the homepage. IE 'tools' is also disabled but can be accessed in other ways.

    Likewise Windows Explorer jumps back to the default folder (My Documents) but I can navigate by right clicking and selecting 'explore'. This opens the folder and I can select the contents.

    The way I see it (and I'm no expert) there are three possibilities:

    1. A Windows Update that is interfering with the files needed for both Explorers
    2. A MBR virus that was not wiped during the reformat process
    3. Some kind of hardware overheating (yeah not very likely I know)

    Any idea where I can go from here?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Two thoughts ....Have you scanned the cd for malware before reinstalling the software that was on it?
    Yes this may be a hardware issue, but if it is it's one I am not familiar with.

    Re-Run ComboFix and attach the log for me to see, please.
     
  21. charco

    charco Private E-2

    The CD was a RW that I loaded from my laptop (which is clean)


    Here's the ComboFix log

    Thanksfor all your help - I appreciate that this is a somewhat unusual case. AVG experts have redirected me back to Microsoft and they are maintaining a discrete silence.

    I have searched the internet and downloaded a memory test program which caqme up with no problems after 24 hours of testing.

    My local computer shop experts are stumped.

    Where to go?
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The log is clean ...did you ever run the BitDefender scan? Have you gone to start / run / and typed
    sfc /scannow

    and seen if it found any missing or corrupt files?

    Where did you get the xp cd from?
     
  23. charco

    charco Private E-2

    I ran the online BitDefender scan and it found nothing

    I'll do sfc/scannow right away

    The Windows XP sp2 CD was bought from a company called Microlyne - website with the same name - a large computer company Madrid. It's the Gold Disk with labels etc etc - the real McCoy unopened
     
  24. charco

    charco Private E-2

    Just ran sfc /scannow. It took a long time and then just stopped without returning any log or error of any kind.
    Is that expected?
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is expected if it doesn't find anything ...though I usually recommend running it at least twice ...however, tell me what environment you are in ....on a network? In a residence? are there other computers nearby? Do you use a wireless mouse?
     
  26. charco

    charco Private E-2

    No the computer is on a desktop at home. It is not networked, although there is a wireless connection in the house for the laptop, but it doesn't go through the computer.

    Mouse USB
    Keyboard was USB currently using normal connection
    No camera
    Epson C64 printer and drivers

    Programs loaded:

    Windows XPsp2
    AVG Antivirus
    AVG Spyware
    AVG Rootkit
    Dreamweaver
    Fireworks
    Flash
    Photoshop
    Firefox
    CCleaner
    Spybot SAD
    Registry Booster
    Bluetooth
    VLC media player


    Nothing else that I can think of...

    I just ran another PC windows memory test utility fPC wizard and it came up with no problems. I'm out of ideas.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have any other programs running when this happens?
    Have you done something with MSSoap?

    I'm reaching for straws here ....you should post in the software section where more will see and be able to assist with this.
     
  28. charco

    charco Private E-2

    No other programs running.

    I've posted in the hardware section 'cos I thought it might be a memory problem.

    However, the computer seems to be running correctly now after I scanned it using the Windows Boot Disk Utility that I downloaded. It's strange because the utility does not fix memory problems only reports them!

    I have absolutely no idea what has been going on, why it started, or how it seems to have fixed itself, all I can say is thanks for your time and efforts. Please be assured that you have helped my massively psychologically knowing that I wasn't battling whatever it was alone.

    Cheers

    Charco
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ....hope everything stays good.

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  30. charco

    charco Private E-2

    Hi TimW - just to let you know that I have found out the problem, it was the keyboard!

    I had a USB multimedia keyboard that was somehow causing the malfunction in programs. I removed this keyboard to do the scans with the Windows Boot disk as the boot disk works directly from the CD without loading an operating system, replacing it with a normal keyboard.

    Since that moment the computer has responded correctly.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sometimes it's the simplest things ...:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds