Log'N'Rock: Help needed removing severe virus infection [INACTIVE] - Log'N'Rock

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Help needed removing severe virus infection [INACTIVE]

#1 User is offline   Lexis Icon

  • Garage rocker
  • Pip
  • Group: Members
  • Posts: 1
  • Joined: 11-September 09

Posted 11 September 2009 - 06:04 PM

Hello!

I am running Windows Vista Premium on an HP Pavilion. I dlded a file off the internet and whilst normally i am quite cautious and sensible i opened it without thinking and a blue screen of death appeared, I can't remember the exact error code, but it said something along the lines of ".dll file did not unpack within boundaries???" I know I should have kept a log of what it said, but I didn't think it was so serious. I rebooted my computer and now internet explorer and firefox don't work, and no antivirus/malware tools work, I had AVG installed and Spybot, now neither work, I dled asquared/malwarebytes and a couple more but either they failed to load up completely or once loaded the ran for about 5 seconds and turned off. I tried running some online scans using safari but none of them were compatible. I tried rebooting in safemode but all the above problems still applied with all antivirus/malware apps closing and firefox/ie not booting up.

Next i booted back up in normal mode and ran firefox and ie through a sandbox, this works, although I keep getting error messages about the size of files although I think this is because i didn't configure the sandbox right, I have tried a couple of virus scans, like Housecall(didn't load), panda virusscanner (didn't properly work - froze at 21%) and am currently running a-squared trojan scan which has detected a couple of minor tracking cookies but nothing serious and is still running. I detected with one of the above methods the win32.kryptik.aim trojan and deleted it. ALthough I'm not sure if it was effectively deleted because the virus scanner then froze, and i'm not sure if that is the main culprit behind my symptoms

I also tried to run rootrepeal but it comes up with the following error:

FOPS - DeviceIoControl Error! Error Code = 0xc0000024
Extended Info (0x0000013c)

Looking at the details it also has this error

DeviceIoControl Error! Error Code = 0x1e7



Then when I click ok and click scan it comes up with:

DeviceIoControl Error! Error Code = 0x0

I know this isn't much to go on, but i consider myself fairly computer literate and am stumped as to what to do next, i need some expert advice, I will regularly check this topic in the hopes that someone can help me.

Many thanks in advance for your thoughts and suggestions


Kind Regards


Laurence
0

#2 User is offline   Fred Flintstone Icon

  • Dave Gilmour
  • Icon
  • Group: Malware Experts
  • Posts: 2,515
  • Joined: 20-April 08
  • Gender:Male
  • Location:Somerset

Posted 12 September 2009 - 02:32 PM

Hi Lexis..

Try this one instead of RootRepeal..:

Please download GMER Rootkit Scanner from Here.
  • Right click the .exe file and chose Run as Administrator. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO

    Posted Image
    Click the image to enlarge it

  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)

  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop, and post it in your next reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Note: Do not run any programs while Gmer is running.

Let me know how it goes...
I will log in as often as possible to check the thread, but please be patient as I am battling with a "wayward" lappy myself at the moment so am a bit restricted for online time etc..

Thanks..
Fred.. :thumbsup:
0

#3 User is offline   Fred Flintstone Icon

  • Dave Gilmour
  • Icon
  • Group: Malware Experts
  • Posts: 2,515
  • Joined: 20-April 08
  • Gender:Male
  • Location:Somerset

Posted 24 September 2009 - 09:43 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact a Staff member. Include the address of this thread in your request. This applies only to the original topic starter. Should you have a new issue, please start a New Topic.
0

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users