Virus: Help!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by sirbrianwilson, Sep 18, 2011.

  1. sirbrianwilson

    sirbrianwilson Private E-2

    Hey everyone. THANK YOU FOR THIS FORUM!!!

    So, here's my dilemma. I have an aging HP Pavilion desktop that runs Vista (eek!). I've had pretty good luck until a few days ago. I definitely caught some sort of virus. It froze up our computer and basically stopped all functions.
    The virus hid all user files for one of the user accounts. On restart, I'd go to sign into said account and it would lead me to an all black screen with just
    a cursor. After some reading, I ran unhide.exe and it fixed the hidden files problem. The computer still is disfunctional in normal mode (I'm posting this from safe mode with networking).

    I run AVG and Spyware Doctor (purchased version). Both scans show nothing.

    I've followed the posted "read and run me first" instructions. Here's what happened.

    I attempted to uninstall previous java versions. I would run the uninstall program and it would hang on "gathering required information." I waited an hour and it hadn't changed so I moved on to the next step. FYI - I have the newest version ready for install but am waiting to get the go-ahead from you guys.

    System type: x86-based PC
    Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4400+, 2310 Mhz, 2 Core(s)

    I attempted the "how to view hidden files" instructions. There's no menu bar in explorer so I couldn't find "organize." Moving to the next step...
    MSConfig is in Normal setup mode.
    I went through the "uninstall Malware" List. none of the listed programs were on the computer. Although *NOTE* I accidently clicked on the bottom of the screen (in the task bar) and it made the screen go blank, "HP Advisor" appeared, and it seems fishy. It's never done that before. Not to mention, "Yahoo! Search" is in the task bar but it's not listed in the task bar menu nor was it installed before. It seems like a redirect.
    I ran defogger.exe and restarted the computer.
    I turned off teatimer and changed the IE tweaks as suggested.

    Thank you for everything. You guys can't get enough praise!!

    Brian
     
    Last edited by a moderator: Sep 24, 2011
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  3. sirbrianwilson

    sirbrianwilson Private E-2

    Most apologies for posting an incomplete topic before! Here's the scan results and commentary.

    SASLog:
    [Edit: Removed in-line SAS log]

    ===================================================

    MBAM Log:
    [Edit: Removed in-line MBAM log]

    ************************************************8

    I ran combofix by following the instructions. It got through all of the stages

    then at the end it crashed, citing a problem with "PEV.exe"

    I then ran rootrepeal. i let it run for 36 hours (literally) before it froze

    up. Then, somehow, my keyboard deactivated. So I restarted.

    I ran MGTools and it seemed to work! Score!

    Thanks again!!!

    Brian
     

    Attached Files:

    Last edited by a moderator: Sep 22, 2011
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do the below in NORMAL mode if possible, safe mode if not.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  5. sirbrianwilson

    sirbrianwilson Private E-2

    Finished both scans. Attached are the reports:
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. What malware issues are you still having, if any?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds