Worm Blaster in Windows 8

Discussion in 'Malware Help (A Specialist Will Reply)' started by gman863, Oct 16, 2013.

  1. gman863

    gman863 MajorGeek

    I'm working on a Sony VIAO running Windows 8 64-bit (factory installed) that appears to have (among other issues) Worm Blaster.

    A generic (and highly suspect) program simply called "Internet Security" is keeping me from installing or running any executable software (TDDS, Hitman Pro, IO Bit Malware Fighter, Windows Worm Blaster Removal, etc.). When I try, I get a balloon-style pop-up at the bottom right of the screen saying something to the effect of "Windows cannot run nameoffile.exe - infected with Worm Blaster. Please activate security software."

    If I try to go into Windows settings, the computer automatically goes back to the Windows 8 metro (tiles) screen.

    This is a UFEI board. It has no options ("F12", "Esc", etc.) allowing me to boot to the CD drive or a USB drive, so I cannot run a DOS or Linux-based cleaning program.

    There is nothing in the "Read Me First" thread that addresses this. Any ideas on how to get to the point where I can either run the Windows 8 reset or reinstall Windows 8 from a DVD would be appreciated. Thanks in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not likely at all. That is an old infection that impacted older OS's.


    Not true. Everything in there pertains to every infection. The logs collected tell us what to do next even when the cleanup process has not successfully fixed the current problem.

    Are you sure that you cannot run anything? Does Task Manager work? If yes, shutdown suspect processes. What about safe boot mode?

    Are you able to get to the Advance Boot Options to get to System Recovery Menu?

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.


    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. gman863

    gman863 MajorGeek

    The Worm Blaster is what the fake security software claims is infecting the PC. Other than the symptoms described, I have no way of knowing what the exact infection is.

    Pushing "CTRL-ALT-DEL" brings up the screen with the option to select Task Manager. Once I click on it, the Task Manager box will show for about one second before closing itself. If I try to change any system settings, I can't even get to the options screen to do so - Windows immediately reverts back to the metro tile screen.

    Based on what I have read at Microsoft TechNet (http://social.technet.microsoft.com...-it-crashes-during-boot?forum=w8itprohardware), the switch to Safe Mode must usually be done within Windows 8 prior to a reboot. Again, the malware/virus is not allowing access to any system changes or program installs.

    FARBAR will not run. When I attempt to access the command prompt, it opens for one second and closes automatically.

    The UFEI system seems different from a traditional BIOS. I have worked on several PCs with UFEI, none of them (including this one) have recognized the traditional "F8" (Safe Mode) or "F12" (Boot Select) options when the PC is turned on. This is also noted in the MS TechNet article referred to above.

    I did not mean any disrespect about the “Read Me First” comment. It’s just that the PC will not allow me do any of the steps listed in it.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then you are sort of hosed due to all the limitations you posted. Possible work around other than reinstall is to take the hard drive out and then connect to a different PC as a slave drive. The attempt to access the file system and navigate to various folders within the user account that malware can typically place itself and manually delete the files.
     
  5. gman863

    gman863 MajorGeek

    I thought about removing the drive and doing a full (not quick) reformat of it, but ditched the plan.

    Since the PC is still under mfr. warranty, I am telling the client to take it to Fry's service dept. where he purchased the PC. He will still have to pay them for whatever it takes to reinstall Windows; however I don't want any fingers pointed in my direction if the UFEI/motherboard was somehow damaged by the infection.

    Sometimes you just have to cut your losses. Thanks for at least trying to help me solve the problem.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm sure this will not be the last time issues like this come into the forum with these UFEI boards.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds