Very stuborn problem.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jory Carson, Jan 1, 2012.

  1. Jory Carson

    Jory Carson Private E-2

    Hello, and thank you for taking the time to read this.

    Recently we had a problem arise on our computer, to the best of our knowledge it was the virus System Fix. My wife thinks that she may have gotten it while the computer was updating. She said that a window popped up asking to update something and that she clicked yes. As soon as this happened the computer bogged down with windows telling her to DL the System Fix. She did NOT do this.

    All of our files vanished along with the Start Menu and Quick Launch. We immediately started looking into the issue on another computer and following directions as close as we could. Every time we DL'ed an Anti-virus (EX: Malware, Spybot, AVG...) they would not work. Finally we ran Trend Micro, along with a few programs listed on your forums (the ones dedicaded to retrieving files and menu items) and this seems to have beat the virus, however now we are having a redirection issue and nothing on your forum seems to help (no doubt I am not running things properly).

    Also, another problem seems to be that we do not feel like our Anti-Virus programs are working properly. First, we use WebRoot (which let the System Fix in in the first place), however after removing that virus (if it is truly gone) I reinstalld WebRoot. Now it runs for a few seconds then claims that there are no threats, or it goes back to the installation page. AVG, Spybot, AdAware, and MalWare claim that our system is clean however, clearly, it is not.

    I have exhausted all my resources on this so its time to turn to the professionals. Any help would be greatly appreciated.

    THANKS!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Jory Carson

    Jory Carson Private E-2

    Thank you for a timely response.

    Because I am initially here for a redirection problem I clicked on said link and tried to follow the steps with the following results:

    STEP 1
    Flushed the Java Cashe
    Flushed the FireFox Cashe (could not find a 'Private Data' but cleared out all history)
    Flushed Internet Explorer Cashed (could not find 'delete files' or 'delete all offline content' but deleted all history)
    Flushed DNS cashe
    --Result: Did not take care of problem

    STEP 2
    Reset modem/router
    --Result: Did not resolve problem

    STEP 3
    DL'ed GooredFix and tried to run.
    --Result: GooredFix – specialist Removal Tool has stopped working

    STEP 4
    Attempted to run TDSSkiller with no success even after changing the name. Ran fixTDSS which brought up a window stating that 'there was something suspicious but the MBR seemed fine and that repair was not complete' (not quoted properly and the computer restarted before I could save the text). Upon restart the computer ran the TDSSkiller which found a threat and 'cured' it.
    --Result: Redirection problem seems fixed.
    Attaching log.

    Do I continue from here?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably would be a good idea anyway based on the infection you had. There could be more.

    Also note, the below two items need to be fixed with TDSSkiller

    22:30:23.0391 2860 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
    22:30:23.0391 2860 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
     
  5. Jory Carson

    Jory Carson Private E-2

    OK, thanks. When I run TDSS again it shows two items but they do not look at all like what you have listed. How do I know if i am deleting the right thing?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attach a new log and I'll tell you.
     
  7. Jory Carson

    Jory Carson Private E-2

    TDSS Log.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those are all fine. You must have cleaned up the other items at some other point.

    I stil suggest that you run the READ & RUN ME to make sure you are clean.
     
  9. Jory Carson

    Jory Carson Private E-2

    So sorry that it is taking me forever to do this, I work alot and I'm not the only user on this computer.

    I think that I ran through everything leading up to and including running SuperAntiSpyware. I ran it and it found some coupon bar thing which I did take off the computer, but I cannot find any logs to attach.

    Are there any and do I need to?
    Thanks.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should just finish ALL of the instructions and then attach the logs.

    Also note, the updated instructions for SUPERAntiSpyware, also tell you where the logs will be. But it is still better to finish everything and attach the logs as we will not provide any fixes until all the logs attached. Ignore the statements in the individual scans about attaching logs until you are finished. Those requests are really there for when an individual scan is run.
     
  11. Jory Carson

    Jory Carson Private E-2

    Ok, again thank you for you time and appologies for how long this is taking.

    I though things were going well on my cleanup process (if lengthy) until a couple days ago when the computer black screened. I had no way of contacting MajorGeeks because while the computer would start up in Safe Mode it would not do so in Safe Mode with Networking. Things got a bit out of hand and with certain users having a dire need for computing a System Recovery was done so...

    Here I am wondering how to determine if my problems will have ceased or not?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is up to you to answer. Only you know if you are having problems or not. We cannot tell how your PC is working unless you tell us.

    However if you are asking if it is free from malware, we also cannot answer that since you have not run the cleaning procedure and given us the logs we ask for. This is how we know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds