BleepingComputer.com: Fake System Restore - Attempts to Remove/Clean

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Fake System Restore - Attempts to Remove/Clean BSOD Interference

#1 User is offline   mommehK 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 13
  • Joined: 19-October 11

Posted 20 October 2011 - 10:30 PM

Windows XP SP3
Avast Internet Security


So the hub's netbook landed the fun fun Fake System Restore. Irritated & annoyed, he started clicking things before I had a chance to see what was going on...I believe his temp folder contents were altered.

I have been trying for two nights now to make it through the Remove System Restore guidelines with mixed results.

Here are some issues I've faced:

  • It took a lot of attempts to get rkill on the desktop & run before this crap took over each attempt
  • Rkill knocked out 4 processes
  • TDSS did not find anything
  • Usage of the keyboard & touchpad has been lost -- fully mouse-dependent
  • Unhide.exe has already been run successfully
  • Was able to run SuperAntiSpyware last night -- 4 items removed
  • At one point the infected netbook showed connection to our home wifi, but I cannot get MBAM to update definitions
  • Tried updating MBAM via install exe last night, but got an "access denied" error & update rollback
  • MBAM prompts that last update was 50 days ago; tell it to update & it immediately says I have the latest version
  • Upon windows (XP) launch, Avast (Internet Security) prompts "will not be able to protect mail/news" & check that it's not blocked by firewall
  • Attempts at correcting Avast "Fix Now" item fail (Real-Time Shields are currently off)
  • I cannot get MBAM to complete any scan due to a very quick BSOD/auto-reboot
  • Was able to run MBAM long enough last night for it to find 4 items. Aborted scan & let it clean those up
  • Ran MBAM full scan earlier tonight, found 3 items, then BSOD/auto-reboot
  • Netbook was just sitting here now, after startup, nothing running, showing avast message (above), then BSOD


I'm at a loss for the most part right now trying to figure out what direction to go in at this point. I am attempting another SAS scan right now as I type this (nothing found but cannot update definitions).

mK

This post has been edited by mommehK: 20 October 2011 - 10:37 PM


#2 User is offline   mommehK 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 13
  • Joined: 19-October 11

Posted 20 October 2011 - 10:59 PM

I was just able to complete a quick scan in MBAM -- 10 items found & removed. Reboot, same issues as before (no keyboard/touchpad, no updating definitions, no fixing Avast shields). Attempting a full scan with MBAM now to see if it'll complete before a BSOD.


Edit: BSOD. Still pops up too fast & leaves to reboot before I can see any details.

This post has been edited by mommehK: 20 October 2011 - 11:03 PM


#3 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 20 October 2011 - 11:27 PM

With the information you have provided I believe you will need help from the malware removal team.
Please make sure that you read the information about getting started first.
Then start a new thread HERE and include or required logs.
Including a link to this thread will be helpful.

Good luck and be patient. Help is on the way!
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#4 User is offline   mommehK 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 13
  • Joined: 19-October 11

Posted 20 October 2011 - 11:39 PM

Thank you Broni! Bedtime here, will post all tomorrow.

#5 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 20 October 2011 - 11:41 PM

Sure thing :)
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




#6 User is offline   mommehK 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 13
  • Joined: 19-October 11

Posted 21 October 2011 - 04:21 PM

Well maybe not. BSOD keeps popping, and finally popped and stayed while trying to use DriveImage XML:

DRIVER_IRQL_NOT_LESS_OR_EQUAL


It's a good thing I have short pixie hair, otherwise I'd have it all pulled out by now. :crazy:



Headed out later for an HDD converter so I can slave that drive to my laptop and pull everything off. I guess reformatting is in my very near future.

mK

#7 User is offline   Broni 

  • The Coolest BC Computer
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 22,167
  • Joined: 01-February 08
  • Gender:Male
  • Location:Daly City, CA

Posted 21 October 2011 - 04:23 PM

Follow mt reply #3.
My Website

Posted Image

My help doesn't cost a penny, but if you'd like to consider a donation, click Posted Image




Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users