Malware that cannot be removed

BKLounger

Golden Member
Mar 29, 2006
1,098
0
0
I am trying to help my uncle clean up a computer he has. Currently it will not boot into windows normally (it hangs when you click on a user). The machine can only boot up in safe mode. I have tried various boot discs and anti-virus programs. Everything from kaspersky, clamwin, mcaffee, webroot, panda, etc. Inside of safe mode i tried to install malwarebytes but cannot get it to install. Basically this malware/virus opens IE and directs you to an ip address for a site called popeo info auction. This still runs on startup even in safe mode. What else can i try to get rid of this? Reimaging the machine really is a last option if at all possible. Is there any additional info I can give to help get an answer?
 

BKLounger

Golden Member
Mar 29, 2006
1,098
0
0
i never even thought of that. thanks for kickstarting the thinking. i just plugged it in and avg starting going crazy finding all the virus. i've been scribbling down the virus names as i go. so far they are mostly all variations of SHeur2
 

Lemon law

Lifer
Nov 6, 2005
20,984
3
0
You can try various anti viruses in the hopes of finding the culprit, but in my experiences, the most effective method is to post a hijackthis log file on something like spywarewarriors.com. Trained log file readers should spot the ah heck real quick. Its in the registry somewhere unless its a rootkit.

I have also had times when spyware Terminator was able to identify the culprit but not remove it. But once you have a name for it, you can google it and find ways to remove it.

And once you help your Uncle remove it, finish the job by setting up a multilayered security system to prevent any future malware.
Before the fact prevention is always easier than after the fact removal.
 

BriGy86

Diamond Member
Sep 10, 2004
4,538
1
91
Originally posted by: AFurryReptile
Pull the drive and slave it to another machine. Then try Malwarebytes from that machine.

This is probably the best action. Just make sure it doesn't infect the host computer. a co-worker also suggested superantispyware
 

Gamingphreek

Lifer
Mar 31, 2003
11,679
0
81
There are some last ditch things you can try in the event that the slave solution didn't work.

First off, you can boot from a Windows disk, use the recovery console and try and grab one of the shadow copies.

If that doesn't work, you can try to run just safe mode. Do NOT use safe mode w/networking.

If that doesn't work, you can try to run safe mode with startup prompt. As the machine starts up, you will be prompted for each of the "necessary" system libraries. Only approve those that you know are valid.

With all this in mind; honestly, it sounds to me like you have a rootkit - especially since safe mode is affected.

I honestly would not bother trying to clean the machine. If a rootkit is the culprit, who knows what kernel files have been infected - I doubt you want to disassemble numerous files that simply look suspicious.

Use a LiveCD and grab the documents that you know are safe. After that, format and reinstall.

-Kevin
 

BKLounger

Golden Member
Mar 29, 2006
1,098
0
0
just noticed this thread popped back up. My solution was to update all the anti-virus/spyware tools on my machine and then just slave the other machines drive to mine and it worked fine. I was able to remove all viruses and spyware.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |