Virus Help, followed tutorial. Cant Boot in normal mode, Possible trojan.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Warm Pancakes, Dec 27, 2010.

  1. Warm Pancakes

    Warm Pancakes Private E-2

    Hi,

    I am currently running Windows Vista 32bit Buisness premium.

    A couple days ago, my Antivir Antivirus program started go go off almost every ten seconds, warning me of different viruses infecting my computer. I immediately downloaded spybot, performed a scan, and got rid of the viruses it found. I continued to recieve constant popups from antivir though. I turned off my computer, hoping to work on the problem more the next day.

    The next day, my computer would not turn on in normal boot mode. The computer would just stay put on a black screen. I booted it in safe mode with networking. Downloaded malwarebytes, scanned, and deleted what it found, but the scan did not change the situation. I was still unable to boot in normal mode, and when i would browse the internet, i would be redirected to different websites. Also, google chrome was not working for me, so i started to use internet explorer.

    Using safe mode with networking, I stumbled across the "read me" pinned thread in this forum on how to remove malware from your computer, and i followed that to the best of my ability.

    This is the log from the Super-anti spyware program i ran.
    View attachment 152004

    This is the log from the Malwarebytes scan i ran from the turorial.
    View attachment 152005

    I installed combofix, but everytime i tried to open it, i would immediatly get a blue screen crash, therefore i was not able to open it. I installed rootrepeal, but when i opened it, i recieved the error code "0xc0000024". I then proceeded to go to the files tab, then i proceeded to scan. When it started, an error code came up saying "Could not initiliaze driver. Please contact the author." Therefore i was not able to run rootrepeal.

    This is the .zip file from MGtools, although it did not look like MGtools did much at all.
    View attachment 152006

    I tried installing Norton internet security 2010 in safe mode and every time I'd, it freezes at a certain number of files. The last thing i did with the computer before Antivir started warning me of the visures was that i had just downloaded an audio program using torrents. I unzipped the winrar it came in, but was never able to start/ install the program. A couple hours later is when antivir started going bezerk.

    Any help would be appreciated, and i will be happy to try to add any extra info that is neede as I'd like to figure this out before the holiday break is over. Thanks a lot!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Most of the malware was removed with the scans, however, let's do this:

    First, go to add/remove programs and uninstall:
    Messenger Plus! Live


    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Warm Pancakes

    Warm Pancakes Private E-2

    Hi,

    Removed messenger plus live. Computer told me to restart so it can officially remove the program and its contents. I tried to reboot the computer, but i guess it got frozen in the process, so i had to turn it off the hard way.

    Downloaded avenger, ran it, copy/pasted the quote, and executed. Computer told me to reboot it so i did. The same thing happened where i had to hard boot it off. Either way, a log was still saved on my C Drive, so i presume it was succesful.

    Ran Ccleaner as i normally would, did not open any other programs.


    Ran the C:\MGtools\GetLogs.bat file, here are the requested logs.

    Avenger text file
    View attachment 152017

    MGlogs .zip file
    View attachment 152018

    I have yet to notice any changes in the computer thus far. After i publish this post, im going to restart the computer, and try to run it in normal mode. I will edit my post with the results.

    Thanks alot for the help, it is very much appreciated!
     
  4. Warm Pancakes

    Warm Pancakes Private E-2

    Still cant run in normal mode, and my google chrome still does not work, but this doesnt pose a huge problem, as i am using internet explorer in the meantime. I havent noticed any change on my computer is acting.

    Any other ideas?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  6. Warm Pancakes

    Warm Pancakes Private E-2

    This okay?

    Sorry about that.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\Program Files\Messenger Plus Live

    I am not seeing any malware in your logs, however let's do this:

    Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!


    Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version 2.3.2.2 of the tool.

    • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
      Vista/Windows 7 users right-click and select Run As Administrator.
    • If TDSSKiller does not run, try renaming it.
    • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
    • Click the Start Scan button.
    • Do not use the computer during the scan
    • If the scan completes with nothing found, click Close to exit.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_14.17.05_log.txt) will be created and saved to the root directory ( usually Local Disk C ).
    • Attach this log to your next message
     
  8. Warm Pancakes

    Warm Pancakes Private E-2

    Scanned, it found something, so i selected cure and rebooted, but i had to hard boot it off, and i turned it on in safe mode.

    attached is the log from TDSSkiller.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just to be sure:

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  10. Warm Pancakes

    Warm Pancakes Private E-2

    i got the
    "Found non-standard or infected MBR.Enter 'Y' and hit ENTER for more options, or 'N' to exit" response.


    attached is the MBR log.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have two separate drives or just two partitions? Do you have your windows disc?

    If you do:

    You will need to boot to the Recovery Console to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654

    You will have to do this on both partitions/drives.

    Then boot back into normal mode.

    Then re-run MBRCheck and attach the new log.
     
  12. Warm Pancakes

    Warm Pancakes Private E-2

    if i go along with this step, will it affect any of the data on my PC? i do have some important files that cannot be backed up that i really need.

    Thanks for all your help, i really appreciate all the effort you have put into helping me out!
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, it will not effect any files or folders on your system. We are only wanting to fix the MBR. Both partition 0 and 1.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds