Hello Undertaker_282, Can you boot into safe mode and try to do a Restore from an earlier date before you started having this issue? Many times you cannot, because the nasty code disables the restore points. There are very many of these types of viruses so unless you know exactly which one you have, it will be difficult to address. In order for it to run, it has to be loaded when Windows is booted, so it will almost certainly have a registry entry to let it run on Windows startup. If you know how to edit the registry, you can look into it and remove the entry. It would be found in the registry under HKey_Local_Machine\Software|Microsoft\Windows\Current Version\Run\. It should be an executable file listed. You can remove that entry and usually the program will not run anymore. This does not always work however. If you are not certain about a registry edit, DO NOT do it. Hope this helps.
Yeah I don't think the Safe Mode thing will work, and I don't want to mess around with the Registry Keys unless I'm told specifically by one of the Mods or someone who takes care of this topic to do it. Thanks for the help though, I did find some stuff under the place you told me to look under but don't want to mess around with anything.
I apologize for not posting sooner. I actually tried, but the temporary site slowness interfered and I lost the post. I will try again ...
Do you have access to a clean computer? Try running Malwarebytes' Anti-Malware. If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM from Here or Here
Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "undertaker.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the file to the infected computer. Install the "undertaker.exe" file; then run the update so that you will have the current definitions. After that, run a full system scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked Click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
If you are still having problems and/or would like a follow-up check to be sure the infection as well as vulnerabilities are gone, copy and paste the entire report into a New Message on the Malware Removal forum. Also include a fresh HijackThis log. Instructions for downloading HijackThis are at the top of that forum. 1. Just click the Start A New Thread button (upper right) in the Malware Removal forum here: http://en.community.dell.com/forums/3521.aspx to start your own thread requesting assistance for a follow-up check to be sure the malware is gone. 2. In the discussion window that opens, simply Right-Click and select Paste.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.
Sorry if it's a double post...I can't tell with my internet freezing so much so here it is again: Alright I will try that from a laptop, but one another thing: I tried to download Malware Bytes from this computer, and when I double clicked to open the installer file, I got a "Is not a valid Win32 application." This happens for ALL the anti-virus programs I try to download, so won't the same thing happen when I just transfer it over? Isnt that the same thing as me just downloading the installer file right now? Sorry I'm not good with this stuff but just thought about it and wanted to make sure I gave you all the information to make things better. I downloaded it from download.com, and the files name is "mbam-setup.exe" which gave me the message I said. Thanks a lot again
Did you remember to rename the MBAM installer file BEFORE transferring it to the infected computer?
The virus has been programmed to stop anything from running that has the name or link to the site of an anti-virus, anti-spyware, etc.. Therefore, as soon as it sees anything named MBAM or malwarebytes on it, it kills it. If you rename MBAM's installer before you put it on the infected machine, the nasty does not know what "undertaker.exe" is so it (hopefully) won't keep it from running.
Alright I tried what you told me to, and this time I didn't get the Win32 error, and it installed and stuff correctly and is on my desktop. But the problem is, now that I click it, nothing happens. I double click it, I have restarted to make sure that wasn't the problem, and have done everything, but even though I don't get the error anymore, now nothing is happening when I try to get the program running.
What should I do next? Should I try doing stuff on Safe Mode or something? Just a few ideas I guess, I'll wait for your advice and instructions.
Alright I tried it in Safe Mode, and it didn't work, and the same thing happened with clicking the it and nothing happening.
I tried downloading around 10 differeent anti-virus programs, and only because I wanted to see if any even worked. All of them gave me similar errrors with not being able to "find an internet connection" to update or something.
I did get to somehow download Avira though. I ran that scan in Safe Mode, and it found a few things and I removed them/restarted it. I also ran an online scan in Safe Mode, most of the sites didn't work but this one did for me:
That one found a ton of things, I removed/deleted them, and restarted my computer.
So now, I don't see the Red X on the bottom right YET, it will probably appear later, I'm not sure. I don't have to refresh that much anymore because the pages are coming out normally on Internet Explorer. But I do know that the virus is still there though because when I go to Google, and click on one of the searches, it opens a whole new window, and redirects me to some Ad sites and stuff.
None of them work. I can download HJT and it lets me, but after that I click Run, or open it up, and nothing happens. When I bring up the Task Manager, I can see that it is active under Processes and I see it there, but like I said nothing comes up when I click it so I can't actually see it.
--------------------------------------------------- Please include the contents of the following in your next reply:
DDS.txt
Attach the following report to your post by clicking the Options tab at the top of your post. Add/Update. Click the BROWSE botton to browse to where you saved the file Attach.txt, and click SAVE
I've clicked the DDS link you posted, but it doesn't open up/Internet Explorer can't display the webpage. I'm not sure if it's only me that can't open it, but I'm pretty sure it isn't. I'll wait for a link to the download before I make a new topic like you said.
The DDS download opens for me. Are you using a pop-up blocker that could be interfering?
* You will not be able to attach the .txt file. Dell has not activated that feature yet. Therefore, simply copy and paste the text of attach.txt into your post on the other forum.
If you are still unable to download DDS, please try Avira's Anti-vir Rescue System.
Double-click on the rescue system package to burn it to a CD/DVD. You can then use this CD/DVD to boot your computer. The Avira AntiVir Rescue System is updated several times a day so that the most recent security updates are always available.
Once you've booted up your computer with Avira Rescue System, you get a boot option to either boot from hard drive or AntiVir Rescue System.
Press the number 2 on your keyboard to boot into AntiVir Rescue System. It will start loading Linux and you will need to select either Deutsch or English.
Next, drivers will be loaded, and when it completes, the Rescue System main menu will show.
To scan a computer, select the second option "Scan" and hit enter. You have the option to select whether to scan all files, only program files or only boot sectors. You can then select either to log scanning events or try to repair infected files.
If Rescue System is unable to repair infected files, you have the option to rename the files.
Finally, you can select additional file types to scan such as dialers, jokes, games, and security privacy risk software. The whole process simplifies the command-line arguments so you do not need to manually type the commands.
The open command at the main menu will launch Linux console, not DOS command prompt. Unless you're familiar with Linux commands, I do not recommend that you select that option. ** If you accidentally get into the Linux console, press CTRL+F1 simultaneously to go back to Rescue System Main Menu.
Following that, see if you can proceed with DDS or HijackThis.
I have a clean laptop but it doesn't have a burner, but my current computer (the one that isn't clean) does have a burner. Can I still just go through with it and download/burn/boot the directions up on this computer? I didn't understand why I needed to do it on a clean computer or when exactly on which step we were supposed to do the directions on a clean computer.
- I think it might be the link, do you have any other places I can download it from? I tried looking it up on google and couldn't figure it out, but if there are other places/ I'm sure some links have to open up on this computer and I can then do the DDS thing.
- Can't I just download the DDS thing on my clean laptop, put it on a USB, and transfer it over to this computer and run it or something.
-You said that for the
Avira AntiVir Rescue System: "The download needs to be done on a clean computer because the infection may corrupt the download. Obviously the type of infection that you have has disabled some security and is preventing you from cleaning."So I can download the program on my laptop, put it on a USB, transfer the file to an infected computer, burn it (my infected computer has the burner) and go from there? Or do I have to both DOWNLOAD and BURN it on a clean computer.
Let me know if I can try out that first thing with the DDS, I'm guessing if I can do it, then I won't have to do the Avira cd burning stuff right? Since that stuff is being done to make DDS work.
Hanspuppa
799 Posts
0
November 15th, 2008 14:00
Hello Undertaker_282, Can you boot into safe mode and try to do a Restore from an earlier date before you started having this issue? Many times you cannot, because the nasty code disables the restore points. There are very many of these types of viruses so unless you know exactly which one you have, it will be difficult to address. In order for it to run, it has to be loaded when Windows is booted, so it will almost certainly have a registry entry to let it run on Windows startup. If you know how to edit the registry, you can look into it and remove the entry. It would be found in the registry under HKey_Local_Machine\Software|Microsoft\Windows\Current Version\Run\. It should be an executable file listed. You can remove that entry and usually the program will not run anymore. This does not always work however. If you are not certain about a registry edit, DO NOT do it. Hope this helps.
Undertaker_282
145 Posts
0
November 15th, 2008 16:00
Bugbatter
3 Apprentice
•
20.5K Posts
0
November 15th, 2008 17:00
I apologize for not posting sooner. I actually tried, but the temporary site slowness interfered and I lost the post.
I will try again ...
Do you have access to a clean computer? Try running Malwarebytes' Anti-Malware. If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM from Here or Here
Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "undertaker.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the file to the infected computer. Install the "undertaker.exe" file; then run the update so that you will have the current definitions. After that, run a full system scan.
Click Remove Selected.
1. Just click the Start A New Thread button (upper right) in the Malware Removal forum here: http://en.community.dell.com/forums/3521.aspx
to start your own thread requesting assistance for a follow-up check to be sure the malware is gone.
2. In the discussion window that opens, simply Right-Click and select Paste.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.
Undertaker_282
145 Posts
0
November 16th, 2008 11:00
Bugbatter
3 Apprentice
•
20.5K Posts
0
November 16th, 2008 11:00
Did you remember to rename the MBAM installer file BEFORE transferring it to the infected computer?
The virus has been programmed to stop anything from running that has the name or link to the site of an anti-virus, anti-spyware, etc.. Therefore, as soon as it sees anything named MBAM or malwarebytes on it, it kills it.
If you rename MBAM's installer before you put it on the infected machine, the nasty does not know what "undertaker.exe" is so it (hopefully) won't keep it from running.
Undertaker_282
145 Posts
0
November 16th, 2008 19:00
Alright I tried what you told me to, and this time I didn't get the Win32 error, and it installed and stuff correctly and is on my desktop. But the problem is, now that I click it, nothing happens. I double click it, I have restarted to make sure that wasn't the problem, and have done everything, but even though I don't get the error anymore, now nothing is happening when I try to get the program running.
What should I do next? Should I try doing stuff on Safe Mode or something? Just a few ideas I guess, I'll wait for your advice and instructions.
Thanks
Bugbatter
3 Apprentice
•
20.5K Posts
0
November 17th, 2008 04:00
Yes, try it in Safemode.
Undertaker_282
145 Posts
0
November 17th, 2008 19:00
Alright I tried it in Safe Mode, and it didn't work, and the same thing happened with clicking the it and nothing happening.
I tried downloading around 10 differeent anti-virus programs, and only because I wanted to see if any even worked. All of them gave me similar errrors with not being able to "find an internet connection" to update or something.
I did get to somehow download Avira though. I ran that scan in Safe Mode, and it found a few things and I removed them/restarted it. I also ran an online scan in Safe Mode, most of the sites didn't work but this one did for me:
http://www.windowsecurity.com/trojanscan/trojanscan.asp
That one found a ton of things, I removed/deleted them, and restarted my computer.
So now, I don't see the Red X on the bottom right YET, it will probably appear later, I'm not sure. I don't have to refresh that much anymore because the pages are coming out normally on Internet Explorer. But I do know that the virus is still there though because when I go to Google, and click on one of the searches, it opens a whole new window, and redirects me to some Ad sites and stuff.
Thanks
Bugbatter
3 Apprentice
•
20.5K Posts
0
November 17th, 2008 19:00
Are you able to run MBAM yet?
Are you able to download HijackThis?
Undertaker_282
145 Posts
0
November 18th, 2008 19:00
None of them work. I can download HJT and it lets me, but after that I click Run, or open it up, and nothing happens. When I bring up the Task Manager, I can see that it is active under Processes and I see it there, but like I said nothing comes up when I click it so I can't actually see it.
Bugbatter
3 Apprentice
•
20.5K Posts
0
November 19th, 2008 05:00
Please go to the Malware Removal forum here: http://en.community.dell.com/forums/3521.aspx
Start a New Thread.
Please download DDS and save it to your desktop.
---------------------------------------------------
Please include the contents of the following in your next reply:
DDS.txt
Attach the following report to your post by clicking the Options tab at the top of your post. Add/Update. Click the BROWSE botton to browse to where you saved the file Attach.txt, and click SAVE
Undertaker_282
145 Posts
0
November 20th, 2008 14:00
I've clicked the DDS link you posted, but it doesn't open up/Internet Explorer can't display the webpage. I'm not sure if it's only me that can't open it, but I'm pretty sure it isn't. I'll wait for a link to the download before I make a new topic like you said.
Bugbatter
3 Apprentice
•
20.5K Posts
0
November 20th, 2008 16:00
The DDS download opens for me. Are you using a pop-up blocker that could be interfering?
* You will not be able to attach the .txt file. Dell has not activated that feature yet. Therefore, simply copy and paste the text of attach.txt into your post on the other forum.
If you are still unable to download DDS, please try Avira's Anti-vir Rescue System.
Please print these instructions:
This requires access to a working (CLEAN) computer with a CD/DVD burner to create a bootable CD.
Download Avira AntiVir Rescue System from here:
http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html
Double-click on the rescue system package to burn it to a CD/DVD. You can then use this CD/DVD to boot your computer.
The Avira AntiVir Rescue System is updated several times a day so that the most recent security updates are always available.
Once you've booted up your computer with Avira Rescue System, you get a boot option to either boot from hard drive or AntiVir Rescue System.
Press the number 2 on your keyboard to boot into AntiVir Rescue System. It will start loading Linux and you will need to select either Deutsch or English.
Next, drivers will be loaded, and when it completes, the Rescue System main menu will show.
To scan a computer, select the second option "Scan" and hit enter.
You have the option to select whether to scan all files, only program files or only boot sectors.
You can then select either to log scanning events or try to repair infected files.
If Rescue System is unable to repair infected files, you have the option to rename the files.
Finally, you can select additional file types to scan such as dialers, jokes, games, and security privacy risk software.
The whole process simplifies the command-line arguments so you do not need to manually type the commands.
The open command at the main menu will launch Linux console, not DOS command prompt.
Unless you're familiar with Linux commands, I do not recommend that you select that option.
** If you accidentally get into the Linux console, press CTRL+F1 simultaneously to go back to Rescue System Main Menu.
Following that, see if you can proceed with DDS or HijackThis.
Undertaker_282
145 Posts
0
November 24th, 2008 14:00
I have a clean laptop but it doesn't have a burner, but my current computer (the one that isn't clean) does have a burner. Can I still just go through with it and download/burn/boot the directions up on this computer? I didn't understand why I needed to do it on a clean computer or when exactly on which step we were supposed to do the directions on a clean computer.
Thanks
Undertaker_282
145 Posts
0
November 24th, 2008 15:00
Just a few questions:
- I think it might be the link, do you have any other places I can download it from? I tried looking it up on google and couldn't figure it out, but if there are other places/ I'm sure some links have to open up on this computer and I can then do the DDS thing.
- Can't I just download the DDS thing on my clean laptop, put it on a USB, and transfer it over to this computer and run it or something.
-You said that for the
Avira AntiVir Rescue System: "The download needs to be done on a clean computer because the infection may corrupt the download. Obviously the type of infection that you have has disabled some security and is preventing you from cleaning." So I can download the program on my laptop, put it on a USB, transfer the file to an infected computer, burn it (my infected computer has the burner) and go from there? Or do I have to both DOWNLOAD and BURN it on a clean computer.
Let me know if I can try out that first thing with the DDS, I'm guessing if I can do it, then I won't have to do the Avira cd burning stuff right? Since that stuff is being done to make DDS work.