Trojans & Blue screen

Discussion in 'Malware Help (A Specialist Will Reply)' started by sasquatch88, May 4, 2011.

  1. sasquatch88

    sasquatch88 Private E-2

    Hi guys I'm having a lot of trouble with some trojans and now I'm getting the blue screen everytime I shutdown/restart my computer.

    I followed your instructions in the malware removal thread and here's what happened:

    CCleaner worked fine with no problems.

    SuperAntiSpyware crashed after about an hour and had detected about 15 trojans/malware/etc. so I changed the preferences as instructed and once again it crashed after about an hour

    **I forgot to add the blue screen message is usually INTERNAL_POWER_ERROR when I try to restart and now I keep getting an IRQL_NOT_EQUAL_OR_LESS message when my computer isn't even restarting.

    Malwarebytes Anti-malware works with no problems but like I said I crash everytime I try to restart and there are always trojans again when I run Malwarebytes.

    RootRepeal worked fine with no problems.

    ComboFix crashes my computer with the IRQL message, I right click the icon and run as administrator and a little green bar starts loading where my mouse cursor is. When the bar is just about to fill completely(same thing everytime I try) the computer crashes. I've noticed a new tab in firefox open as it crashes that I couldnt identify in time and I've noticed Microsoft Security Essentials(which apparently was removed from my computer somehow) pop up to prompt me to activate it as the computer crashes from starting ComboFix.

    MGTools worked fine with no problems.

    I will also attach a Hijackthis log that I will run immediately before I post this thread.

    Also on a side note, I'm also getting search engine redirects infrequently/randomly but I think it's related to this problem and I wanted to go through this lengthy malware removal before I investigate that.

    Any help with this would be greatly appreciated, thank you very much!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sounds like you have an MBR infection. Try and run the below. If it gets only to 80% then you will need to follow the instructions further down.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    If TDSSKiller fails...

    Do you have your Vista install disc? If not:

    Vista and Win7 Recovery disc


    For fixing the boot issues:
    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe, and then press ENTER.

    Then you can do this:

    Bootrec.exe /fixmbr

    NOW try and run TDSSKiller again and attach the log.
     
  3. sasquatch88

    sasquatch88 Private E-2

    Thanks for the quick reply I'm already downloading the disk that you linked. Is it okay for me to re-enable daemontools to run the iso file and repair my OS? Is there any risk of it reformatting my hard drive or is this just for repairing the windows system files?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you can re-enable Daemon Tools. Should not be any risk involved, but the MBR is infected and we need it repaired.
     
  5. sasquatch88

    sasquatch88 Private E-2

    The recovery disk torrent downloaded smoothly and I re-enabled but I have no idea what to do from there unless I'm supposed to burn it to a CD and follow the instructions you gave for starting up the computer with the disk inside. I hope it doesn't come to that I'm trying to download TDSSkiller but the download just kinda "froze" ...my browser is working fine but the download just says something like 19kb/s (my computer can download up to 1.7Mb/second so that's strange) but the download bar never moves and when I try to refresh the Kapersky page and try to download again the page doesn't load or the download doesn't start... I can't believe I'm having such rotten luck with this.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, use the CD now to follow my instructions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds