799 Posts

November 15th, 2008 14:00

Hello Undertaker_282, Can you boot into safe mode and try to do a Restore from an earlier date before you started having this issue? Many times you cannot, because the nasty code disables the restore points. There are very many of these types of viruses so unless you know exactly which one you have, it will be difficult to address. In order for it to run, it has to be loaded when Windows is booted, so it will almost certainly have a registry entry to let it run on Windows startup. If you know how to edit the registry, you can look into it and remove the entry. It would be found in the registry under HKey_Local_Machine\Software|Microsoft\Windows\Current Version\Run\. It should be an executable file listed. You can remove that entry and usually the program will not run anymore. This does not always work however. If you are not certain about a registry edit, DO NOT do it. Hope this helps.

November 15th, 2008 16:00

Yeah I don't think the Safe Mode thing will work, and I don't want to mess around with the Registry Keys unless I'm told specifically by one of the Mods or someone who takes care of this topic to do it. Thanks for the help though, I did find some stuff under the place you told me to look under but don't want to mess around with anything.

3 Apprentice

 • 

20.5K Posts

November 15th, 2008 17:00

I apologize for not posting sooner. I actually tried, but the temporary site slowness interfered and I lost the post.
I will try again ...

 

Do you have access to a clean computer? Try running Malwarebytes' Anti-Malware. If you are unable to download or install MBAM on your computer, see if you can use a friend's or family member's computer to download MBAM from Here or Here

 

Use this update link here to manually download the update. Once downloaded, rename the program installer "mbam-setup.exe" file to something else like "undertaker.exe". Copy the installer file and the update file to a CD or flash drive. Transfer the file to the infected computer. Install the "undertaker.exe" file; then run the update so that you will have the current definitions. After that, run a full system scan.

 

    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checkedPhotobucket
      Click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • If you are still having problems and/or would like a follow-up check to be sure the infection as well as vulnerabilities are gone, copy and paste the entire report into a New Message on the Malware Removal forum. Also include a fresh HijackThis log. Instructions for downloading HijackThis are at the top of that forum.
      1. Just click the Start A New Thread button (upper right) in the Malware Removal forum here:
      http://en.community.dell.com/forums/3521.aspx

      to start your own thread requesting assistance for a follow-up check to be sure the malware is gone.
      2. In the discussion window that opens, simply Right-Click and select Paste.

  •  

    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

November 16th, 2008 11:00

Sorry if it's a double post...I can't tell with my internet freezing so much so here it is again: Alright I will try that from a laptop, but one another thing: I tried to download Malware Bytes from this computer, and when I double clicked to open the installer file, I got a "Is not a valid Win32 application." This happens for ALL the anti-virus programs I try to download, so won't the same thing happen when I just transfer it over? Isnt that the same thing as me just downloading the installer file right now? Sorry I'm not good with this stuff but just thought about it and wanted to make sure I gave you all the information to make things better. I downloaded it from download.com, and the files name is "mbam-setup.exe" which gave me the message I said. Thanks a lot again

3 Apprentice

 • 

20.5K Posts

November 16th, 2008 11:00

Did you remember to rename the MBAM  installer file BEFORE transferring it to the infected computer?

The virus has been programmed to stop anything from running that has the name or link to the site of an anti-virus, anti-spyware, etc.. Therefore, as soon as it sees anything named MBAM or malwarebytes on it, it kills it.
If you rename MBAM's installer before you put it on the infected machine, the nasty does not know what "undertaker.exe" is so it (hopefully) won't keep it from running.

November 16th, 2008 19:00

Alright I tried what you told me to, and this time I didn't get the Win32 error, and it installed and stuff correctly and is on my desktop.  But the problem is, now that I click it, nothing happens.  I double click it, I have restarted to make sure that wasn't the problem, and have done everything, but even though I don't get the error anymore, now nothing is happening when I try to get the program running.

 

What should I do next?  Should I try doing stuff on Safe Mode or something?  Just a few ideas I guess, I'll wait for your advice and instructions.

Thanks

3 Apprentice

 • 

20.5K Posts

November 17th, 2008 04:00

Yes, try it in Safemode.

November 17th, 2008 19:00

Alright I tried it in Safe Mode, and it didn't work, and the same thing happened with clicking the it and nothing happening.

 

I tried downloading around 10 differeent anti-virus programs, and only because I wanted to see if any even worked.  All of them gave me similar errrors with not being able to "find an internet connection" to update or something.

I did get to somehow download Avira though.  I ran that scan in Safe Mode, and it found a few things and I removed them/restarted it.  I also ran an online scan in Safe Mode, most of the sites didn't work but this one did for me:

http://www.windowsecurity.com/trojanscan/trojanscan.asp

That one found a ton of things, I removed/deleted them, and restarted my computer. 

 

So now, I don't see the Red X on the bottom right YET, it will probably appear later, I'm not sure.  I don't have to refresh that much anymore because the pages are coming out normally on Internet Explorer.  But I do know that the virus is still there though because when I go to Google, and click on one of the searches, it opens a whole new window, and redirects me to some Ad sites and stuff.

Thanks

3 Apprentice

 • 

20.5K Posts

November 17th, 2008 19:00

Are you able to run MBAM yet?

Are you able to download HijackThis?

November 18th, 2008 19:00

None of them work.  I can download HJT and it lets me, but after that I click Run, or open it up, and nothing happens.  When I bring up the Task Manager, I can see that it is active under Processes and I see it there, but like I said nothing comes up when I click it so I can't actually see it.

3 Apprentice

 • 

20.5K Posts

November 19th, 2008 05:00

Please go to the Malware Removal forum here: http://en.community.dell.com/forums/3521.aspx

Start a New Thread.


Please download DDS and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.

---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt

Attach the following report to your post by clicking the Options tab at the top of your post. Add/Update. Click the BROWSE botton to browse to where you saved the file  Attach.txt, and click SAVE

 

November 20th, 2008 14:00

I've clicked the DDS link you posted, but it doesn't open up/Internet Explorer can't display the webpage.  I'm not sure if it's only me that can't open it, but I'm pretty sure it isn't.  I'll wait for a link to the download before I make a new topic like you said.

3 Apprentice

 • 

20.5K Posts

November 20th, 2008 16:00

The DDS download opens for me. Are you using a pop-up blocker that could be interfering?

* You will not be able to attach the .txt file.  Dell has not activated that feature yet. Therefore, simply copy and paste the text of attach.txt into your post on the other forum.

If you are still unable to download DDS, please try Avira's Anti-vir Rescue System.

Please print these instructions:

This requires access to a working (CLEAN) computer with a CD/DVD burner to create a bootable CD.
 Download Avira AntiVir Rescue System from here:
http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html

Double-click on the rescue system package to burn it to a CD/DVD. You can then use this CD/DVD to boot your computer.
The Avira AntiVir Rescue System is updated several times a day so that the most recent security updates are always available.

Once you've booted up your computer with Avira Rescue System, you get a boot option to either boot from hard drive or AntiVir Rescue System.

Press the number 2 on your keyboard to boot into AntiVir Rescue System. It will start loading Linux and you will need to select either Deutsch or English.

Next, drivers will be loaded, and when it completes, the Rescue System main menu will show.

To scan a computer, select the second option "Scan" and hit enter.
You have the option to select whether to scan all files, only program files or only boot sectors.
You can then select either to log scanning events or try to repair infected files.

 If Rescue System is unable to repair infected files, you have the option to rename the files.

Finally, you can select additional file types to scan such as dialers, jokes, games, and security privacy risk software.
The whole process simplifies the command-line arguments so you do not need to manually type the commands.

The open command at the main menu will launch Linux console, not DOS command prompt.
 Unless you're familiar with Linux commands, I do not recommend that you select that option.
** If you accidentally get into the Linux console, press CTRL+F1 simultaneously to go back to Rescue System Main Menu.

Following that, see if you can proceed with DDS or HijackThis.

November 24th, 2008 14:00

I have a clean laptop but it doesn't have a burner, but my current computer (the one that isn't clean) does have a burner.  Can I still just go through with it and download/burn/boot the directions up on this computer?  I didn't understand why I needed to do it on a clean computer or when exactly on which step we were supposed to do the directions on a clean computer. 

Thanks

November 24th, 2008 15:00

Just a few questions:

- I think it might be the link, do you have any other places I can download it from? I tried looking it up on google and couldn't figure it out, but if there are other places/ I'm sure some links have to open up on this computer and I can then do the DDS thing.


- Can't I just download the DDS thing on my clean laptop, put it on a USB, and transfer it over to this computer and run it or something.


-You said that for the

Avira AntiVir Rescue System: "The download needs to be done on a clean computer because the infection may corrupt the download. Obviously the type of infection that you have has disabled some security and is preventing you from cleaning." So I can download the program on my laptop, put it on a USB, transfer the file to an infected computer, burn it (my infected computer has the burner) and go from there? Or do I have to both DOWNLOAD and BURN it on a clean computer.

Let me know if I can try out that first thing with the DDS, I'm guessing if I can do it, then I won't have to do the Avira cd burning stuff right? Since that stuff is being done to make DDS work.

No Events found!

Top