Page 1 of 3 123 LastLast
Results 1 to 10 of 28

Thread: Please help...can't get rid of this one

  1. #1
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Unhappy Please help...can't get rid of this one

    The malware on my computer is redirecting my browser. My Avast! is deactivated and I can't get it to run, can't get spybot or any other security software to run. I downloaded HighjackThis, but can't get it to run either. I know I have PC AntiSpyware 2010 on my computer, but can't get rid of it since I can't run any security software. Help please!

  2. #2
    Security Expert shelf life's Avatar
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    5,859

    Default

    You can try this:

    Boot your machine into safe mode. To reach safe mode you would tap the f8 key during a computer restart. chose the first option from the list: safe mode.
    Once at the safe mode desktop try running your AV and any anti-malware apps you have. See if this helps any.

    Until clean I suggest using the machine as little as possible, in fact when not in use you can pull the plug on your modem or router or just shut it down so there is no network connectivity.
    How Can I Reduce My Risk?

  3. #3
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Default

    First off, thank you for helping me.

    Here is what I have done so far:
    Booted in safe mode, tried to run Avast! and SpybotSD with same result, error message "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item" Renamed Spybot and tried to run it. It comes up, but as soon as I chose to perform a scan, it shuts down and I can't open it again.

    I have tried HJT and it will not run in safe mode or in normal mode. I have also renamed it, but still will not work.

    I have backed up registry with ERUNT.

    I also have a Kaspersky log if that would be helpful. Their online scan is the online thing I have been able to run so far and I have kept the log. Let me know if you need it.

  4. #4
    Security Expert shelf life's Avatar
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    5,859

    Default

    Do you have access to another machine that you could read a guide on?

    We will try combofix, there is a guide to read first. Read through the guide then download combofix onto the infected machine. Before you save it to your desktop rename combofix.exe to combofix1.exe then save it to your desktop.

    Double click the saved icon on your desktop and follow the prompts.

    Another possibility is to rename and save the combofix1.exe to a usb flash drive then transfer it via usb to the infected computer. If you do this leave the usb drive in the infected computer. Its possible for some malware to infect usb drives and spread to a non-infected computer if inserted back into one.

    Guide to using Combofix
    How Can I Reduce My Risk?

  5. #5
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Default

    Downloaded ComboFix and renamed it. When I double-click on it, the window "Open File - Security Warning" opens and it says "The publisher could not be verified. Are you sure you want to run this software?". I click run, the window goes away and then nothing happens.

  6. #6
    Security Expert shelf life's Avatar
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    5,859

    Default

    try booting into safe mode to run combofix. To reach safe mode you would tap the f8 key during a computer restart. Chose the first option: safe mode. Once at the safe mode desktop try running combofix.
    How Can I Reduce My Risk?

  7. #7
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Default

    Still exactly the same problem even in safe mode. After I click Run, the window disappears and nothing happens.

  8. #8
    Security Expert shelf life's Avatar
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    5,859

    Default

    Not good. See if you can get RootRepeal on board. And use the machine as little as possible, pull the plug on router/modem when not in use and no bank/financial stuff.

    Please download: RootRepeal

    http://ad13.geekstogo.com/RootRepeal.exe

    Click the icon on your desktop to start.
    Click on the Report tab at the bottom of the window
    Next, Click on the Scan button
    In the Select Scan Window check everything:

    Drivers
    Files
    Processes
    SSDT
    Stealth Objects
    Hidden Services

    Click the OK button
    In the next dialog window select all the drives that are listed
    Click OK to start the scan

    May take some time to complete.
    When done click the Save Report button.
    Save the report to your desktop
    To Exit RootRepeal: click File>Exit
    Post the report in your reply
    How Can I Reduce My Risk?

  9. #9
    Junior Member
    Join Date
    Aug 2009
    Posts
    15

    Default

    This actually worked. Here is the RootRepeal Report:

    ROOTREPEAL (c) AD, 2007-2009
    ==================================================
    Scan Start Time: 2009/08/25 21:39
    Program Version: Version 1.3.5.0
    Windows Version: Windows XP SP3
    ==================================================

    Drivers
    -------------------
    Name: dump_iaStor.sys
    Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
    Address: 0x99116000 Size: 778240 File Visible: No Signed: -
    Status: -

    Name: rootrepeal.sys
    Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
    Address: 0x985DA000 Size: 49152 File Visible: No Signed: -
    Status: -

    Name: win32k.sys:1
    Image Path: C:\WINDOWS\win32k.sys:1
    Address: 0x9A784000 Size: 20480 File Visible: No Signed: -
    Status: -

    Name: win32k.sys:2
    Image Path: C:\WINDOWS\win32k.sys:2
    Address: 0xA0B5F000 Size: 61440 File Visible: No Signed: -
    Status: -

    Hidden/Locked Files
    -------------------
    Path: C:\hiberfil.sys
    Status: Locked to the Windows API!

    Path: C:\WINDOWS\system32\eventlog.dll
    Status: Locked to the Windows API!

    Path: c:\documents and settings\user\local settings\temp\~df2f60.tmp
    Status: Allocation size mismatch (API: 16384, Raw: 0)

    Path: c:\documents and settings\user\local settings\temp\~df9370.tmp
    Status: Allocation size mismatch (API: 16384, Raw: 0)

    Processes
    -------------------
    Path: C:\WINDOWS\system32\braviax.exe
    PID: 1032 Status: Hidden from the Windows API!

    SSDT
    -------------------
    #: 025 Function Name: NtClose
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa39516b8

    #: 041 Function Name: NtCreateKey
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa3951574

    #: 065 Function Name: NtDeleteValueKey
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa3951a52

    #: 068 Function Name: NtDuplicateObject
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa395114c

    #: 119 Function Name: NtOpenKey
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa395164e

    #: 122 Function Name: NtOpenProcess
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa395108c

    #: 128 Function Name: NtOpenThread
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa39510f0

    #: 173 Function Name: NtQuerySystemInformation
    Status: Hooked by "C:\WINDOWS\System32\Drivers\Beep.SYS" at address 0xb7dbb1a0

    #: 177 Function Name: NtQueryValueKey
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa395176e

    #: 204 Function Name: NtRestoreKey
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa395172e

    #: 247 Function Name: NtSetValueKey
    Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa39518ae

    ==EOF==

  10. #10
    Security Expert shelf life's Avatar
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    5,859

    Default

    not much there. I was expecting more. rerun rootrepeal. this time:

    Click the icon on your desktop to start.
    Click on the Report tab at the bottom of the window
    Next, Click on the Scan button
    In the Select Scan Window check:

    Processes


    Click the OK button
    In the next dialog window select all the drives that are listed
    Click OK to start the scan
    When finished, in the main window, right click on "terminate process and delete file" for this single entry:

    C:\WINDOWS\system32\braviax.exe

    reboot machine and see if you can run anything.
    How Can I Reduce My Risk?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •