Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Fake System Restore - Attempts to Remove/Clean


  • Please log in to reply
6 replies to this topic

#1 mommehK

mommehK

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:32 AM

Posted 20 October 2011 - 10:30 PM

Windows XP SP3
Avast Internet Security


So the hub's netbook landed the fun fun Fake System Restore. Irritated & annoyed, he started clicking things before I had a chance to see what was going on...I believe his temp folder contents were altered.

I have been trying for two nights now to make it through the Remove System Restore guidelines with mixed results.

Here are some issues I've faced:

  • It took a lot of attempts to get rkill on the desktop & run before this crap took over each attempt
  • Rkill knocked out 4 processes
  • TDSS did not find anything
  • Usage of the keyboard & touchpad has been lost -- fully mouse-dependent
  • Unhide.exe has already been run successfully
  • Was able to run SuperAntiSpyware last night -- 4 items removed
  • At one point the infected netbook showed connection to our home wifi, but I cannot get MBAM to update definitions
  • Tried updating MBAM via install exe last night, but got an "access denied" error & update rollback
  • MBAM prompts that last update was 50 days ago; tell it to update & it immediately says I have the latest version
  • Upon windows (XP) launch, Avast (Internet Security) prompts "will not be able to protect mail/news" & check that it's not blocked by firewall
  • Attempts at correcting Avast "Fix Now" item fail (Real-Time Shields are currently off)
  • I cannot get MBAM to complete any scan due to a very quick BSOD/auto-reboot
  • Was able to run MBAM long enough last night for it to find 4 items. Aborted scan & let it clean those up
  • Ran MBAM full scan earlier tonight, found 3 items, then BSOD/auto-reboot
  • Netbook was just sitting here now, after startup, nothing running, showing avast message (above), then BSOD

I'm at a loss for the most part right now trying to figure out what direction to go in at this point. I am attempting another SAS scan right now as I type this (nothing found but cannot update definitions).

mK

Edited by mommehK, 20 October 2011 - 10:37 PM.


BC AdBot (Login to Remove)

 


#2 mommehK

mommehK
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:32 AM

Posted 20 October 2011 - 10:59 PM

I was just able to complete a quick scan in MBAM -- 10 items found & removed. Reboot, same issues as before (no keyboard/touchpad, no updating definitions, no fixing Avast shields). Attempting a full scan with MBAM now to see if it'll complete before a BSOD.


Edit: BSOD. Still pops up too fast & leaves to reboot before I can see any details.

Edited by mommehK, 20 October 2011 - 11:03 PM.


#3 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,661 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:32 AM

Posted 20 October 2011 - 11:27 PM

With the information you have provided I believe you will need help from the malware removal team.
Please make sure that you read the information about getting started first.
Then start a new thread HERE and include or required logs.
Including a link to this thread will be helpful.

Good luck and be patient. Help is on the way!

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#4 mommehK

mommehK
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:32 AM

Posted 20 October 2011 - 11:39 PM

Thank you Broni! Bedtime here, will post all tomorrow.

#5 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,661 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:32 AM

Posted 20 October 2011 - 11:41 PM

Sure thing :)

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#6 mommehK

mommehK
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:09:32 AM

Posted 21 October 2011 - 04:21 PM

Well maybe not. BSOD keeps popping, and finally popped and stayed while trying to use DriveImage XML:

DRIVER_IRQL_NOT_LESS_OR_EQUAL


It's a good thing I have short pixie hair, otherwise I'd have it all pulled out by now. :crazy:



Headed out later for an HDD converter so I can slave that drive to my laptop and pull everything off. I guess reformatting is in my very near future.

mK

#7 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,661 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:06:32 AM

Posted 21 October 2011 - 04:23 PM

Follow mt reply #3.

My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users