Author Topic: 4 days into the virus- really need some help!  (Read 13203 times)

0 Members and 1 Guest are viewing this topic.

Zionstrat

  • Guest
4 days into the virus- really need some help!
« on: September 25, 2013, 06:51:55 PM »
Hello all- I am desperately looking for help- Avast first found a rootkit on 9-15 and things have just gone from bad to worse- I contacted Avast support, but they have had sporadic generic input that doesn't seem to have helped much (I have tried everything they have suggested).

I've had far more direct input on the malwarebytes web site, but I've been non-productive for 4 days and wanted to give the avast crowd another shot-

Here's the thread that outlines everything I have tried (including the avast advice and all the reports I have run)- The most recent thing I did was uninstall Avast and try to install MSE, however, MSE will not install so I have no protection at this point.

http://forums.malwarebytes.org/index.php?showtopic=133799&page=1

http://forums.malwarebytes.org/index.php?showtopic=133799&page=4

Desperately awaiting any and all ideas and thanks in advance!
« Last Edit: September 25, 2013, 06:53:51 PM by Zionstrat »

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #1 on: September 25, 2013, 06:55:22 PM »
One more time logs please. ;D

Run the scans shown in this topic and attach logs please: http://forum.avast.com/index.php?topic=53253.0

When done malware removers will be notified, all used tools will be removed. ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #2 on: September 25, 2013, 06:59:17 PM »
Here are the first four logs from the malwarebytes forum.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #3 on: September 25, 2013, 07:08:56 PM »
ChkDsk Log.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #4 on: September 25, 2013, 07:10:26 PM »
TDSS Killer part 1.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #5 on: September 25, 2013, 07:10:53 PM »
TDSS Killer part 2
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #6 on: September 25, 2013, 07:11:20 PM »
TDSS Killer part3. ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #7 on: September 25, 2013, 07:12:42 PM »
Ive notified Argus. He is online now.

Maybe he or someone else will advise you.  ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Zionstrat

  • Guest
Re: 4 days into the virus- really need some help!
« Reply #8 on: September 25, 2013, 07:26:49 PM »
Thanks!

Yes, ignore dds-toshiba.txt for now- It's the other computer on the network- For now the ASUS is the priority-

Trying to run rogue killer again, reaching the point where I cant keep it running long enough to generate logs-

I do have more logs in the post including rogue killer kasperian and the input regrading maxsecure (recomended by avast support)

Zionstrat

  • Guest
Re: 4 days into the virus- really need some help!
« Reply #9 on: September 25, 2013, 07:29:10 PM »
Thanks so much!
Here's the rkiller log


rkill did not keep the computer from crashing and it went to bsod while combo fix was trying to set a restore point

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #10 on: September 25, 2013, 07:30:15 PM »
OK.

I think the malware remover will look over the thread in the Malwarebytes forum. When one arrives.

You can just wait for now and do what is shown in the Logs in assist to clean malware Thread. ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: 4 days into the virus- really need some help!
« Reply #11 on: September 25, 2013, 07:32:06 PM »
Looks like you have something nasty on there cause it changed something in the Windows Hosts file.

Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Zionstrat

  • Guest
Re: 4 days into the virus- really need some help!
« Reply #12 on: September 25, 2013, 07:39:36 PM »
yes, I'm suspicious that this may have been around a long, long time-

I had a PC die 1.5 years ago exactly like this- Never could find the problem-

Stored the files off (I have a lot of files) and then built a new PC-

Scanned all the files (nothing ever found) and transferred them to the new system- probably a big mistake

I think it's been here  a long long time and avast upset it when it noticed problems on 9-15

It seems clear that it is pretty smart- It crashed the MSE install and now i cant install MSE at all

Zionstrat

  • Guest
Re: 4 days into the virus- really need some help!
« Reply #13 on: September 25, 2013, 07:48:40 PM »
Ok, ran rogue killer again and this time i let it do the delete and the fix shortcuts-
System still went to bsod, but here are the reports-

 

Zionstrat

  • Guest
Re: 4 days into the virus- really need some help!
« Reply #14 on: September 25, 2013, 08:06:57 PM »
I think I figured out how I ended up running maxsecure- The first combofix url I used actually installed maxsecure.

I'm running the real combo fix now, but it did bsod after 25 lines