Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: THINKPOINT boot virus  (Read 37383 times)

0 Members and 1 Guest are viewing this topic.

Iwishiknew

    Topic Starter


    Beginner
    Re: THINKPOINT boot virus
    « Reply #15 on: November 04, 2010, 06:50:10 AM »
    Please help me Super Dave  :'(

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: THINKPOINT boot virus
    « Reply #16 on: November 04, 2010, 12:27:47 PM »
    I sent a message to Administration to see if they can figure out why you can't send or attach the logs.
    Windows 8 and Windows 10 dual boot with two SSD's

    Iwishiknew

      Topic Starter


      Beginner
      Re: THINKPOINT boot virus
      « Reply #17 on: November 04, 2010, 01:52:43 PM »
      Thanks SuperDave, I still can't copy and paste or attach the HJT log for some unknown reasonbut can copy and paste the Mbam log...


      Iwishiknew

        Topic Starter


        Beginner
        Re: THINKPOINT boot virus
        « Reply #18 on: November 05, 2010, 07:45:53 AM »
        This Virus (Thinkpoint) is nasty, it attacks the sound card also, i'm going crazy as i use this computer for audio editing, shall i ask elseware for help ?

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: THINKPOINT boot virus
        « Reply #19 on: November 05, 2010, 12:28:53 PM »
          Ok. Let's try this: If you still can't copy and paste or attach the log, try sending me a pm and copy and paste the log in the message.

          Please download ComboFix from BleepingComputer.com

          Alternate link: GeeksToGo.com

          Rename ComboFix.exe to commy.exe before you save it to your Desktop
          Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
          Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
          As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
          Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console[/list]

          Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

          Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


          Click on Yes, to continue scanning for malware.
          When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

          If you have problems with ComboFix usage, see How to use ComboFix
          Windows 8 and Windows 10 dual boot with two SSD's

          Iwishiknew

            Topic Starter


            Beginner
            Re: THINKPOINT boot virus
            « Reply #20 on: November 05, 2010, 08:53:23 PM »
            Thanks for helping SuperDave, I tried to copy and paste the Hijackthis log in a PM to you but i get the same server error message, i then installed ComboFix, changed the name but it won't run normaly  :( i did a quick scan with Malwarebytes but it didn't find anything this time although it did yesterday.

            The only way i can post the hijack this log is the way i did it, in parts earlier in this thread, perhaps you could take a look at that ?

            I am getting a message from the built in anti virus on my motherboard when i boot up that the computer is infected with a boot virus.

            The virus is trying to change my browser startpage but i get a Windows alert first.

            Other symtoms are random music playing that does not exist on my computer  :o snipits of 80's pop songs  >:( ,disabling the soundcard, browser windows randomly opening, crashing etc.. and sometimes it seems to be fine.

            very strange stuff, i hope you can help somehow because i'm at a loss.

            LizzyE

            • Guest
            Re: THINKPOINT boot virus
            « Reply #21 on: November 06, 2010, 12:35:13 PM »
            I got this same virus while using SENuke.  It took me two days to get rid of it,.  Now I'm much more careful.

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: THINKPOINT boot virus
            « Reply #22 on: November 06, 2010, 01:26:55 PM »
            I've sent you a pm. Let's try that method to get the log to me.
            Windows 8 and Windows 10 dual boot with two SSD's

            Iwishiknew

              Topic Starter


              Beginner
              Re: THINKPOINT boot virus
              « Reply #23 on: November 08, 2010, 11:24:48 AM »
              SUPERAntiSpyware Scan Log
              http://www.superantispyware.com

              Generated 11/08/2010 at 05:50 PM

              Application Version : 4.45.1000

              Core Rules Database Version : 5823
              Trace Rules Database Version: 3635

              Scan type       : Complete Scan
              Total Scan Time : 01:33:01

              Memory items scanned      : 482
              Memory threats detected   : 0
              Registry items scanned    : 5402
              Registry threats detected : 0
              File items scanned        : 51923
              File threats detected     : 7

              Adware.Tracking Cookie
                 C:\Documents and Settings\LocalService\Cookies\system@bizzclick[2].txt
                 C:\Documents and Settings\LocalService\Cookies\system@casalemedia[2].txt
                 C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt
                 C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt
                 C:\Documents and Settings\LocalService\Cookies\system@exoclick[2].txt
                 C:\Documents and Settings\LocalService\Cookies\system@weborama[1].txt
                 C:\Documents and Settings\LocalService\Cookies\[email protected][2].txt

              Iwishiknew

                Topic Starter


                Beginner
                Re: THINKPOINT boot virus
                « Reply #24 on: November 08, 2010, 11:25:45 AM »
                Malwarebytes' Anti-Malware 1.46
                www.malwarebytes.org

                Database version: 5030

                Windows 5.1.2600 Service Pack 2
                Internet Explorer 8.0.6001.18702

                11/8/2010 7:20:26 PM
                mbam-log-2010-11-08 (19-20-26).txt

                Scan type: Full scan (C:\|)
                Objects scanned: 216832
                Time elapsed: 42 minute(s), 25 second(s)

                Memory Processes Infected: 0
                Memory Modules Infected: 0
                Registry Keys Infected: 0
                Registry Values Infected: 0
                Registry Data Items Infected: 0
                Folders Infected: 0
                Files Infected: 0

                Memory Processes Infected:
                (No malicious items detected)

                Memory Modules Infected:
                (No malicious items detected)

                Registry Keys Infected:
                (No malicious items detected)

                Registry Values Infected:
                (No malicious items detected)

                Registry Data Items Infected:
                (No malicious items detected)

                Folders Infected:
                (No malicious items detected)

                Files Infected:
                (No malicious items detected)

                SuperDave

                • Malware Removal Specialist


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: THINKPOINT boot virus
                « Reply #25 on: November 08, 2010, 12:10:55 PM »
                Thank you. Now please run HJT and post the log.
                Windows 8 and Windows 10 dual boot with two SSD's

                Iwishiknew

                  Topic Starter


                  Beginner
                  Re: THINKPOINT boot virus
                  « Reply #26 on: November 08, 2010, 01:41:53 PM »
                  SuperDave, it still won't accept the HJT log as a copy and paste or as an attchment here on the thread so i've emailed it to you, thanks.

                  SuperDave

                  • Malware Removal Specialist


                  • Genius
                  • Thanked: 1020
                  • Certifications: List
                  • Experience: Expert
                  • OS: Windows 10
                  Re: THINKPOINT boot virus
                  « Reply #27 on: November 08, 2010, 04:55:13 PM »
                  It would appear from the HJT log that your AVG is out-of-date. Please update it ASAP.

                  I strongly recommend that you remove Ask from your computer because it;

                  •Promotes its toolbars on sites targeted to kids.

                  •Promotes its toolbars through ads that appear to be part of other companies' sites.

                  •Promotes its toolbars through other companies' spyware.

                  •Installs without any disclosure whatsoever and without any consent whatsoever.

                  •Solicits installations via "deceptive door openers" that do not accurately describe the offer; failing to affirmatively show a license agreement; linking to a EULA via an off-screen link.

                  •Makes confusing changes to users' browsers -- increasing Ask's revenues while taking users to pages they didn't intend to visit.

                  See Here for more info.

                  If you choose to follow my recommendation then please go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

                  AskBarDis or anything related to Ask

                  Then please find and delete this folder in bold (if present):
                  C:\Program Files\AskBarDis. or anything related to Ask.
                  ****************************************************

                  Open HijackThis and select Open the Misc Tools section. Select open process manager. select
                  C:\WINDOWS\system32\mshta.exe
                  C:\Program Files\Search Settings\SearchSettings.exe
                  C:\Program Files\Application Updater\ApplicationUpdater.exe

                  and click on kill process.

                  Close HJT
                  ************************
                  Please go to Jotti's malware scan
                  (If more than one file needs scanned they must be done separately and links posted for each one)

                  * Copy the file path in the below Code box:

                  Code: [Select]
                  C:\WINDOWS\SYSTEM\RevHDD.exe
                    * At the upload site, click once inside the window next to
                  Browse.
                  * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
                  * Next click Submit file
                  * Your file will possibly be entered into a queue which normally takes less than a minute to clear.
                  * This will perform a scan across multiple different virus scanning engines.
                  * Important: Wait for all of the scanning engines to complete.
                  * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
                  ***************************************
                  Open HijackThis and select Do a system scan only

                  Place a check mark next to the following entries: (if there)

                  O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
                  O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
                  O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
                  O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                  O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


                  Important: Close all open windows except for HijackThis and then click Fix checked.

                  Once completed, exit HijackThis.
                  **************************************
                  Add or Remove Programs

                  1. Click on the Windows Start button and click on the Control Panel
                  2. In the Control Panel window, double-click Add or Remove Programs icon.
                  3. When the Add or Remove Programs window has fully populated, check for Search Settings and Application Updater and uninstall them.

                  ****************************************
                  Download Security Check by screen317 from one of the following links and save it to your desktop.

                  Link 1
                  Link 2

                  * Unzip SecurityCheck.zip and a folder named Security Check should appear.
                  * Open the Security Check folder and double-click Security Check.bat
                  * Follow the on-screen instructions inside of the black box.
                  * A Notepad document should open automatically called checkup.txt
                  * Post the contents of that document in your next reply.

                  Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
                  ******************************************
                  Please download ComboFix from BleepingComputer.com

                  Alternate link: GeeksToGo.com

                  Rename ComboFix.exe to commy.exe before you save it to your Desktop
                  Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
                  Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
                  As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
                  Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console[/list]

                  Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

                  Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


                  Click on Yes, to continue scanning for malware.
                  When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

                  If you have problems with ComboFix usage, see How to use ComboFix

                  Windows 8 and Windows 10 dual boot with two SSD's

                  Iwishiknew

                    Topic Starter


                    Beginner
                    Re: THINKPOINT boot virus
                    « Reply #28 on: November 09, 2010, 06:08:25 AM »
                    SuperDave, I followed your instructions but ran into these problems:

                    cant kill processes :

                    C:\Program Files\Application

                    Updater\ApplicationUpdater.exe

                    C:\WINDOWS\system32\mshta.exe
                    -----------------------
                    can't copy and paste or type out this file or

                    find it using browse to scan with Jotties :

                    C:\WINDOWS\SYSTEM\RevHDD.exe
                    --------------------
                    can't find:

                    AskBarDis or anything related to Ask

                    3. When the Add or Remove Programs

                    window has fully populated, check for

                    Search Settings and Application Updater

                    and uninstall them.
                    --------------------
                    Security check runs but doesn't save a

                    checkup.txt filefile

                    -----------------------------------

                    Combofix won't run while AVG is installed, i

                    diabled AVG but it still won't run, should i

                    remove AVG ?

                     -

                    SuperDave

                    • Malware Removal Specialist


                    • Genius
                    • Thanked: 1020
                    • Certifications: List
                    • Experience: Expert
                    • OS: Windows 10
                    Re: THINKPOINT boot virus
                    « Reply #29 on: November 09, 2010, 12:51:26 PM »
                    Were you able to update AVG?

                    Quote
                    cant kill processes :
                    What happens when you try to kill the processes?
                    Please try this:

                    Copy and paste the text in the code box below into Notepad.
                    Code: [Select]
                    @echo off
                    del C:\WINDOWS\system32\mshta.exe

                    del blackpudding.bat
                    exit

                    Then click File > Save as
                    Save to the Desktop as blackpudding.bat
                    And Save as type: All Files.

                    Double-click on blackpudding.bat to run it.
                    *****************************************

                    Quote
                    can't find:

                    AskBarDis or anything related to Ask
                    Ok. Please try this:

                    Delete An Uninstall Entry

                    •Start HijackThis

                    •Click on the Open the Misc Tools section

                    •Click on the Open Uninstall Manager button.

                    •Highlight the entry you want to remove.
                    (AskBarDis or anything related to Ask,
                    Search Settings and
                    Application Updater)
                    •Click Delete these entries
                    Exit HJT
                    ********************************
                    Quote
                    Combofix won't run while AVG is installed, i diabled AVG but it still won't run, should i remove AVG ?
                    No. We'll deal with this later.

                    Windows 8 and Windows 10 dual boot with two SSD's