Maleware Problem

User avatar
omega0401
StarLounger
Posts: 84
Joined: 13 Mar 2010, 18:17

Maleware Problem

Post by omega0401 »

My son has some kind of maleware bug in his PC. It keeps popping up a message about a virus and to press ok to run his antivirus software (with no name of the antivirus software) to get rid of it. But it’s a bogus message. His antivirus wouldn't run that way.

When he tried to run his antivirus program manually it finds something but then the PC immediately boots itself preventing the antivirus from removing it.

He tried installing Adaware but when he installs it the PC boots itself to prevent that from starting.

He then tried booting to safe mode and then run the Adaware installer but it comes back with a message that it needs a few things like a C++ library. It's probably in his PC but not running because it is in safe mode.

I think if he could get Adaware running it would remove this maleware bug but so far he gets blocked.

I'll have him try to install Spybot and/or Windows Maleware remover and see if that works. He may have the same problem though.

If he restores his system from a previous restore point, does that physically get rid of the maleware file?

Are there any other suggestions he might try doing to get these maleware removers to install and run?

User avatar
HansV
Administrator
Posts: 78485
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: Maleware Problem

Post by HansV »

The free version of Malwarebytes Anti-Malware has a good reputation of purging fake anti-virus software.
Best wishes,
Hans

User avatar
John Gray
PlatinumLounger
Posts: 5408
Joined: 24 Jan 2010, 08:33
Location: A cathedral city in England

Re: Maleware Problem

Post by John Gray »

Agreed - but it might be necessary (or even preferable) to download, update, and run it in Safe Mode.
I would also run SuperAntiSpyware and HitMan Pro 3.5, again initially in Safe Mode, probably.
John Gray

"(or one of the team)" - how your appointment letter indicates you won't be seeing the Consultant...

User avatar
omega0401
StarLounger
Posts: 84
Joined: 13 Mar 2010, 18:17

Re: Maleware Problem

Post by omega0401 »

Reporting back. We didn’t try everything mentioned but this is what happened. We ran SuperAntiSpyware in safe mode. It gave the message: Adware.Tracking Cookie 483 found. It quarantined those. That’s all it found. Ran Malwarebytes in Safe mode and found nothing.

Booted to normal mode and the virus popups started again as well as IE starting by itself to porno sites. Ran Nod32 antivirus and it found nothing.

Tried to run Malwarebytes and SuperAntiSpyware in normal mode and neither would run. Excel and Word would not run. Task Manager, System Maintenance, and System Restore do not run. The uninstall programs did run so it isn’t every program just most programs.

Something opens behind any window that is open that we launch a program from but then disappears. I think it may be the virus program intercepting most programs that are trying to launch.

We’ll try a few more things suggested perhaps Hitman. In the meantime is there anything else we could try? He has a Windows 7 PC.

How the bug may have happened…
He was doing a google on: *Watch V*. V is a tv show that he wanted to see. He clicked on a link and that’s when the popups started.

He has some programs he downloaded recently that I don’t recognize but I think they are safe. They are: Steam, Panda Media Booster, AA2Deploy, and PunkBuster Services.

User avatar
StuartR
Administrator
Posts: 12605
Joined: 16 Jan 2010, 15:49
Location: London, Europe

Re: Maleware Problem

Post by StuartR »

Try running Sophos anti-rootkit.
StuartR


User avatar
omega0401
StarLounger
Posts: 84
Joined: 13 Mar 2010, 18:17

Re: Maleware Problem

Post by omega0401 »

StuartR wrote:Try running Sophos anti-rootkit.
Thanks Stuart. I'll give this a try. I will probably have the same problem running it as I do the other programs. I'll try safe mode first but if the virus isn't running in safe mode I hope it will find it anyway.

User avatar
John Gray
PlatinumLounger
Posts: 5408
Joined: 24 Jan 2010, 08:33
Location: A cathedral city in England

Re: Maleware Problem

Post by John Gray »

I have found that on occasion HitMan Pro finds and fixes a few things that Malwarebytes and SuperAntiSpyware didn't - but Your Viruses May Vary!
John Gray

"(or one of the team)" - how your appointment letter indicates you won't be seeing the Consultant...

User avatar
jonwallace
5StarLounger
Posts: 1120
Joined: 26 Jan 2010, 11:32
Location: "What a mighty long bridge to such a mighty little old town"

Re: Maleware Problem

Post by jonwallace »

Perhaps booting from a bootable recovery CD like UBCD4Win and running the anti-spyware tools from there may help. Note that when you create the CD, take the time to update Malwarebytes antimalware etc.

A good resource is http://www.bleepingcomputer.com/forums/forum103.html" onclick="window.open(this.href);return false;
John

“Always trust a microbiologist because they have the best chance of predicting when the world will end”
― Teddie O. Rahube

User avatar
omega0401
StarLounger
Posts: 84
Joined: 13 Mar 2010, 18:17

Re: Maleware Problem

Post by omega0401 »

Update.
We turned on the PC to run a few things. Before we could do that, NOD32 lite up red saying there was a virus in RAM. We ran a complete scan and it found two virus files which it deleted. They were

Content.IE5\N6SNXRQN\na[1] - Win32/Adware.SpywareProtect2009 application - cleaned by deleting
00154995.exe - a variant of Win32/Kryptik.JLH trojan - cleaned by deleting

NOD32 probably had a database subscription update that may have found the virus or it may have been the same one my son found but he didn't write it down. But he said it only found one and then the PC rebooted.

We then had difficulty getting his browsers and online games working. We had to turn off Proxy Servers in IE and check on Automatic Detect Settings. Everything seems to be working fine now.

I think a root kit finder will be our next step just to make sure.

Thanks for everyone's comments.

User avatar
HansV
Administrator
Posts: 78485
Joined: 16 Jan 2010, 00:14
Status: Microsoft MVP
Location: Wageningen, The Netherlands

Re: Maleware Problem

Post by HansV »

You seem to have gotten rid of the nasties - very good!

I'd run a rootkit finder indeed, but treat the results cautiously - some rootkit-like items are legitimate.

I hope this'll be a lesson for your son - even with an up-to-date antivirus program you still have to be cautious!
Best wishes,
Hans