1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

Is This A Virus?

Discussion in 'Malware Removal Help' started by wegg, Mar 17, 2011.

  1. wegg

    wegg

    Joined:
    Mar 17, 2011
    Messages:
    7
    Location:
    US
    Operating System:
    Windows Vista Enterprise
    Noticed a problem when I tried to play a video on firefox and it wouldn't play properly (no sound, video freezing). Tried to open internet explorer, and nothing happened (tried opening without add-ons, as well). Opened task manager, and my username is now listed as "(unknown)", and it won't let me show processes from all users. Computer says I am not authorized to restart, shut down, or open the control panel.

    A spybot scan didn't find anything, but it wouldn't let me download any updates (clicked updates, nothing happened). When I try to open malwarebytes (previously installed) I get this message: "the endpoint mapper database entry could not be created". I tried to download rkill, thinking maybe a virus was preventing malwarebytes from opening, but when I download it (tried all variations, .com, .exe, .scr, etc) it asks me to select a launch application to open the file with. The same thing happens when I try to install exehelper, and when I try to re-install malwarebytes I get the "endpoint mapper" error. Firefox won't update to the newest version--it downloads, but then fails to install. I tried to install the new version of firefox over top of the old one, but I get the endpoint mapper error, same as with MBAM.

    My OS is Vista.

    Any help would be hugely appreciated, and by way of warning: I am not all that computer literate, you may need to spell things out for me. Thank you.
     
  2. BeeCeeBee

    BeeCeeBee ADMINISTRATOR IN MEMORY

    Joined:
    Apr 20, 2009
    Messages:
    7,201
    Location:
    New Jersey "Stronger than the Storm"
    Operating System:
    Windows 7
    Welcome to Computer Help Forums! :)

    The quick answer is that it does appear that you have been infected with something (Well probably not you, but your computer.) I would suggest that our malware removal experts are probably sleeping in the UK at the moment but will probably see this in the morning. Have a look at THIS POST it may get you started. But don't get too frustrated if some of it seems to be blocked by the very problem you are encountering.
     
  3. wegg

    wegg

    Joined:
    Mar 17, 2011
    Messages:
    7
    Location:
    US
    Operating System:
    Windows Vista Enterprise
    BeeCeeBee,

    Thanks for the heads up and the info. You're right, the suggestions in that post appear to be unavailable to me. I didn't try to install and run TFC, because that post says I should backup the system with ERUNT first and that one would not install (just like everything else, it asks me to select a launch program).

    I'll try to be patient and wait for the experts :)
     
  4. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    Hi Wegg, BeeCeeBee has given good advice in his suggestion to prepare for one of the resident malware experts to post. But one thing you could try now is to start your computer in safe mode with networking, and then see if you can run malwarebytes. (Don't forget to update it before the scan)
    Let us know how you get on.
     
  5. wegg

    wegg

    Joined:
    Mar 17, 2011
    Messages:
    7
    Location:
    US
    Operating System:
    Windows Vista Enterprise
    Thanks DSTM,

    Unfortunately, my computer won't let me restart it. It says "the system administrator has disabled some power states for this user" (note: I am the only user on this computer). Is there a way to bypass this?
     
  6. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    Sounds like you are not getting into safe mode.

    Tapp F8 repeatedly on startup.

    Try and do a system restore from Safe Mode.

    May take a few tries to get it right.

    Then run Malwarebytes in Safe Mode.
     
  7. wegg

    wegg

    Joined:
    Mar 17, 2011
    Messages:
    7
    Location:
    US
    Operating System:
    Windows Vista Enterprise
    Alright, so I am now running malwarebytes in safe mode. I did not do a system restore because I didn't read your post until after I'd restarted. Oddly, when I hit the power button the computer went to the user sign-on screen rather than turning off, BUT there was no cursor on the screen and the user name was in the form of "MY USERNAME-PC my username". I didn't type anything in, at that point I turned off the power supply and that's how I got the computer to shut down finally so that I could restart.
     
  8. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    What Vista CD'S have you?

    What is the make and model of your Computer?

    Is this what you are seeing in Safe Mode?

    Initially you use the keyboard Arrow keys to navigate, then press enter and wait a couple of minutes normally.

    TEST.png
     
  9. wegg

    wegg

    Joined:
    Mar 17, 2011
    Messages:
    7
    Location:
    US
    Operating System:
    Windows Vista Enterprise
    Yes, that's how it looked. I selected "safe mode with networking". Malwarebytes is still scanning right now, but it hasn't found anything yet.
     
  10. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    Let Malwarebytes finish.

    Often a system Restore in safe mode to a time before all this started, will fix the "the system administrator has disabled some power states for this user" issue.
     
  11. wegg

    wegg

    Joined:
    Mar 17, 2011
    Messages:
    7
    Location:
    US
    Operating System:
    Windows Vista Enterprise
    Thank you for all your help so far DSTM. Malwarebytes identified "Rogue.AntivirusSuite.Gen" and "PUM.Bad.Proxy", and I had them deleted. Is there something that I should do next or should I just restart the computer normally?
     
  12. DSTM (Dougie)

    DSTM (Dougie) Registered Members

    Joined:
    May 3, 2009
    Messages:
    8,270
    Location:
    SYDNEY AUSTRALIA
    Operating System:
    Windows 7
    You are indeed infected and I would do nothing more at this stage.

    By deleted I presume these Viruses are Quarantined.

    Wait for our Malware expert (Starbuck) to advise you further.

    I have Emailed Starbuck on your behalf.
     
  13. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi wegg

    If you can't get in to normal mode, we'll have to try working with 'Safe mode with networking'.

    Download RogueKiller and save it to your desktop.
    • Close all the running processes
    • Double click RogueKiller icon to run the program
      Vista/Win7 users should right click the icon and select Run as Administrator.
    • When prompted, type 1 (SCAN) and then press Enter
    • A report will open, please copy and paste this report in your next reply.
    A copy of the RKreport.txt can be found on your desktop.

    Note:
    If RogueKiller is blocked, do not hesitate to try running it again.
    If it still fails to run, right click on the downloaded icon and select 'Rename'.....rename it to winlogon and try again.
     
  14. wegg

    wegg

    Joined:
    Mar 17, 2011
    Messages:
    7
    Location:
    US
    Operating System:
    Windows Vista Enterprise
    Starbuck, after running malwarebytes I've gotten into normal mode and things seem to be running smoothly again. I also did download AVAST and ran a scan, which found nothing. Should I still download roguekiller, or is that unnecessary? I also ran hijack this and have logs that I can post, if that would help. A site moderator at a different help site (when this happened I posted everywhere I could think of, panicked a bit I suppose) also suggested that I download gmer, but it seems to have pretty negative reviews on cnet. Would you suggest I download this software?

    You guys have been a lot of help so far.
     
  15. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Wegg,

    Once you start receiving help from a site/forum, you should follow just one set of instructions.
    Following multiple suggestions only confuses things and doesn't help the person replying to you.

    RogueKiller specializes in searching for this type of program, so it may help in finding any leftovers on the system.

    Not really.
    Hjt is very outdated now and won't give us the info we need.

    Step 1
    Still run RogueKiller
    as per the previous instructions.


    Step 2
    • Download OTL to your desktop.
      right click on the link and select 'Save Link/Target As'.

      if you have problems, try this download link:
      OTL
    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check
    .

    .
    .

    • Now copy the lines in bold below.

      netsvcs
      msconfig
      %SYSTEMDRIVE%\*.*
      %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\System32\config\*.sav
      %PROGRAMFILES%\*
      HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
      CREATERESTOREPOINT


    • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.

      .
      .
    • Click the Run Scan button.

      [​IMG]
    • Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.


    In your next reply, please submit:
    RogueKiller report
    both reports from OTL.


    Thanks.
     
    Last edited by a moderator: Feb 4, 2014

Share This Page