Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Malware, cannot access tools or safemode (long)  (Read 6204 times)

0 Members and 1 Guest are viewing this topic.

Memmy

  • Guest
Malware, cannot access tools or safemode (long)
« on: October 27, 2009, 07:00:46 PM »
Hello- I'm having my first serious problem with my PC. (For the record I have disconnected it from everything but the printer and am currently on my laptop) I'm running WindowsXP Home edition, and I'm 99% sure I've got the SP3, 100% sure I've got at least SP2. I use Mozilla Firefox for most of my internet needs, although sometimes I use IE for things not supported by Firefox such as PCPitStop's test center. I tried to follow evilfantasy’s malware removal guide before posting, but the computer locked up on me while trying to access the Add or Remove programs(mouse still moved but nothing could be selected- reset by pounding Ctrl+Alt+Del), the installation files for SUPERAntiSpyware and Malwarebytes’ Anti Malware are will not open(from flash drive), as well as the programs CCleaner and HiJackThis which I already had installed.
   
The computer is used by my husband, myself and our roommate. With both of them being 100% male, I'm almost certain one of them has accidentally downloaded something from a dirty site (even though I've warned both of them not to accept ANYTHING, EVER!) :angry:

Backstory- I returned from work today at about one o'clock (PST), my husband says computer is off due to a 15 minute power outage (wonderful). He tells me that he was on Firefox today at about 10:30-ish, and after he closed the window he cleared the private data (I have it set to ask to be cleared when Firefox is closed) and after he clicked the clear data now button an antivirus firewall thing (his words) came up and filled the screen. It was shortly after that that we lost power. This confused me because non of my anti-anything programs come up unannounced. I turned the computer on, first things first I tried to log into the admin account, but it wouldn't load and the computer froze. Double wonderful. I do a hard reset and try to log onto the guest account, which I do successfully. First thing I notice is the nasty links on the desktop, youporn.com, porntube.com and nudetube.com.

Immediately an IE page opened up (since I didn't initiate it I closed it before it could load) as well as a strange program popped up the looked like a virus scanner, SecurityTool. It's icon is a blue shield with two gears. Having seen phony scanners before, I just said *censored*? and closed it down. Then I started getting bubbles on my task bar tray:
"Security Tool Warning sndvol32.exe (or ccsetup223.exe, or scvhost.exe, or whatever other program I've recently tried) is infected with worm Lsas.Blaster.Keyloger. This worm is trying to send your credit card details using sndvol32.exe to connect to remote host."
"Your PC is still infected with dangerous viruses. Activate antivirus protection to prevent data loss and avoid the theft of your credit card details. Click here to activate protection."
"Spyware.IEMonster activity detected. This is spyware that attempts to steal passwords from Internet Explorer, Mozilla Firefox, Outlook and other programs. Click here to remove it immediately with Security Tool."

Even though it says Security Tool, it comes from the blueshield icon of SecurityTool, not the Windows Security shield.

Checking the properties of the SecurityTool shortcut that had appeared on the desktop, I found that the target is C:\DocumentsandSettings\AllUsers\ApplicationData\06615927\06615927.exe

It was created at 9:59 am this morning, which is strange to me since my roommate left for work at 7:30, my husband didn't wake up until 10:30, and I was at work until 1pm.

After closing the windows, my desktop blanked out to blue- no icons, no picture, just the task bar. Next step was to try and run my CCleaner- I open it from the start menu and get the error "C:\Program Files\CCleaner\CCleaner.exe Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item."

Hmm. So I decide to try reinstalling CCleaner, just to see what happens. It tells me I have to be logged in as an administrator (oops, I forgot I limited the guest account), so I log off and try to log in under the admin account, and success, it worked this time! So I reinstall CCleaner it in the same place and get the error that it cannot open the location (sorry I didn't copy the exact error, I didn't think this problem would be so tough I needed help!). So I try to install with the name CCleaner2, and it works. I open the CCleaner, hit analyze, it starts, and immediately closes. Crap. I try again, renaming the installation folder Help (I need it!) and try again. Same results, it installs, opens, then closes.

I try everything I've got, Ad-Aware, HiJackThis, SpyBot, AVG... nothing opens, much less works. I cannot even access the Task Manager. I tried booting the computer in SafeMode but all I get is this error:
“We apologize for the inconvenience, but Windows did not start successfully." I can, however, start Windows normally.

I've been searching online for help here on my laptop for a while, and after ignoring the PC's repeated popups demanding that I remove the infections the PC suddenly went to a blue screen with white letters. Here is what is said, exactly. The grammatical errors are left in place.

A problem has been detected and windows has been shut down to prevent damage to your computer. The problem seems to be caused by the following file: SPCMDCOM.sys
PAGE_FAULT_IN_NONPAGED_AREA
In this is the first time you've seen this Stop error screen restart your computer. If this screen appears again, follow these steps:
Check to make sure any new hardware of software is properly installed. If this is a new installation, ask your hardware or software manufacturer for nay windows updates you might need.
If problems continue, disable or remove and newly installed hardware or software. Disable BIOS memory options such as your caching or shadowing. if you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup Options, and then select Safe Mode.
Technical information:
*** STOP: oxoooooo5o (0xFD3094C2, 0x00000001, 0xFBFE7617, 0x00000000)
***SPCMDCON.SYS - Address FBFE7617 base at FBFE5000 DateStamp 3d6dd67c

((Grammatical errors on the page:
Windows not capitalized
"In this is the first time...", In not If
"...any new hardware of software..." of not or
"...manufacturer for nay windows updates" nay not any
"...or shadowing. if you need..." If not capitalized))

The errors are a dead giveaway that it's not a legit screen. After pounding the heck out of Ctrl+Alt+Del I got the comp to reset.

(After typing most of this post out I relogged in on the PC to find that some (apparently) random images from an file I have has shown up on the desktop, there is still no desktop image, and unfortunately my anti-malware programs still will not run. I cannot even access CCleaner’s installation file anymore.)

I'm sorry this is so long, I just wanted to give all the information I could think of. If there's some information I'm missing, or something you think I could try please let me know!
Thank you!
~Shyla

osccutieo

  • Guest
Re: Malware, cannot access tools or safemode (long)
« Reply #1 on: November 15, 2009, 08:53:50 PM »
Did you every find out what was wrong? My uncle called me to his house tonight because his computer was "messed up". So I went over there, and it is doing the same exact thing you described. He said my younger cousins  were on the computer earlier today and were downloading games, he said it was fine until they got on it. And now it is doing what you described with the Security Tool, and Advanced Virus remover etc. It will not let you into my computer or the add/remove programs it says C:/windows/system32/rundll32.exe is not a valid Win 32 application any time you try to click on those. It gave me that same blue screen you described as well. And I noticed in almost every pop up from the tool bar there were misspelled words. Please let me know if you figured out what was wrong and how to fix it. Thank you.

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Malware, cannot access tools or safemode (long)
« Reply #2 on: November 17, 2009, 04:23:37 PM »
Osccutieo, you will have to start a thread of your own in order to get help. Please do not hijack another person's thread.

Hello Memmy and welcome to Computer Hope Forum. My name is Superdave but you can just call me SD. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

1.I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2.The fixes are specific to your problem and should only be used for this issue on this machine.
3.If you don't know or understand something, please don't hesitate to ask.
4.Please DO NOT run any other tools or scans whilst I am helping you.
5.It is important that you reply to this thread. Do not start a new topic.
6.Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7.Absence of symptoms does not mean that everything is clear.

The first thing I will need to know if whether or not you can access and download things from the Internet.
Windows 8 and Windows 10 dual boot with two SSD's

Codename47

  • Guest
Re: Malware, cannot access tools or safemode (long)
« Reply #3 on: January 12, 2010, 05:25:26 AM »
I'm having this same issue... well not entirely but I have the icons

harry 48



    Egghead

  • lay back , relax and chill out
  • Thanked: 129
    • Yes
    • Yes
    • Yes
    • Dribbling Pensioner
  • Certifications: List
  • Experience: Familiar
  • OS: Windows 7
Re: Malware, cannot access tools or safemode (long)
« Reply #4 on: January 12, 2010, 09:14:15 AM »
codename47, you will have to start a new topic of your own in order to get help. Please do not hijack another person's topic.
« Last Edit: January 12, 2010, 11:59:31 AM by harry 48 »