BleepingComputer.com: Virus takeover

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Virus takeover

#1 User is offline   BMTex 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 06-September 10

Posted 13 February 2012 - 03:46 AM

As soon as I log into windows by typing my password, it either freezes or loads the desktop icons then freezes. Have run combofix and MBAM but no avail. Have CF log.

#2 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,026
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 13 February 2012 - 06:12 AM

Hello,
Do you have any idea why this happened? Have you tried Safe Mode?
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#3 User is offline   BMTex 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 06-September 10

Posted 13 February 2012 - 06:33 AM

I have no idea why this happened, mainly use this computer for online gaming. I scan all downloads with avast. I am on it in safe mode currently, seems to work fine.

This post has been edited by BMTex: 13 February 2012 - 06:35 AM


#4 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,026
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 13 February 2012 - 07:08 AM

Try to do a clean boot and see if you can determine which process/application causes the problem.
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#5 User is offline   BMTex 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 06-September 10

Posted 13 February 2012 - 06:09 PM

I have done that and it seems to be working ok. At least it doesnt freeze immediately. Now what should I do?

#6 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,026
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 14 February 2012 - 03:41 AM

Re-enable processes one at a time and see which one causes the freeze.
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#7 User is offline   BMTex 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 06-September 10

Posted 14 February 2012 - 12:13 PM

How would I do that?

#8 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,026
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 14 February 2012 - 12:59 PM

See Step 3 in the article I linked you to. :)
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#9 User is offline   BMTex 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 06-September 10

Posted 14 February 2012 - 02:16 PM

Ok I have started all the services in the system configuration. No problems to report. Am I missing something?

#10 User is offline   BMTex 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 06-September 10

Posted 14 February 2012 - 03:55 PM

Update. Have started all processes and drivers and am now using normal startup in msconfig. No problems to report after clean boot. A Pre clean boot Combofix log shows removal of something in main user application data called pricegong. As I am writing this a window pops up labeled data execution prevention. windows has closed the program named windows update. Program named wuauclt.exe has encountered problem.

#11 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,026
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 15 February 2012 - 02:33 AM

Pricegong is indeed a resource hog and an undesirable program as well. I do not recommend to run Combofix unsupervised though; it is quite a powerful program and can cause serious damage in some cases.

At this point it would be good to run a scan with a program like Malwarebytes Antimalware (if you do not have it installed, let me know and I'll post more detailed instructions).
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#12 User is online   noknojon 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 2,721
  • Joined: 13-March 10
  • Gender:Male
  • Location:Victoria Australia

Posted 15 February 2012 - 04:15 PM

View PostBMTex, on 13 February 2012 - 03:46 AM, said:

As soon as I log into windows by typing my password, it either freezes or loads the desktop icons then freezes. Have run combofix and MBAM but no avail. Have CF log.

Quote

I do not recommend to run Combofix unsupervised though; it is quite a powerful program and can cause serious damage in some cases.
At this point it would be good to run a scan with a program like Malwarebytes Antimalware

From Post #1; Both have already been run -

This may be a better topic to move into Malware Removal as there is no (actual) extra help being offered -
XP SP3 Pro Desktop - Windows 7 SP1 Home Premium Toshiba Laptop - Malwarebytes - SUPERAntiSpyware - Microsoft Security Essentials -
HiJack This - SpeedFan - Cannon Printer - ATF Cleaner - TFC Cleaner - ORCA and Internet Explorer Browsers -
Secunia PSI - And I Use GOOGLE -

#13 User is offline   BMTex 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 06-September 10

Posted 15 February 2012 - 05:42 PM

Yes as I said, I have run both programs now. MBAM finds nothing still. Avast appears disabled and will not restart. MBAM didnt catch pricegong when I ran it, but combofix did. Although I am not experiencing the original problem now, I feel the problem/malware has not been addressed.

#14 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,026
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 16 February 2012 - 02:40 AM

In that case best is to start a new thread HERE and include a link to this thread. Please make sure that you read the information about getting started before you start your thread.

It would be helpful if you post a note here once you have completed the steps in the guide and have started your topic in malware removal.
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users