cwagoner
Topic Starter
So I'm finally posting what's going on and seeking your help. It's been almost a week and countless hours doing scans and trying to remove this thing. Now it's you turn, here's what I got…
About a week ago I started getting pop ups for that AntiVirus 2009 fake program. It disabled my internet and killed all my virus scan software (list is below). McAfee said it quarantined a trojan about 10 times. I used LSPfix to restore the internet connection. Everything seemed fine.
The next day, BOOM! All the icons for anti-virus-anything were just blank, generic icons. Like it was windows 3.12 again. So I uninstalled and reinstalled over and over again to no avail.
Nothing seems to get this and there isn't any help online that is useful. I need you awesome techs to help me. I cannot scan using hijackthis, malewarebyte's, SpyHunter, Spybot Search & Destroy, Exterminate It!, Norton Online (or any online scans), Lavasoft Adware, ComboFix won't run, and McAfee cannot scan or update. SuperAntiSpyware won't install. VundoFix didn't find anything. DrWeb CureIt found nothing. RootRepeal cannot be ran from desktop, it is blocked - I have to run it from .rar file. I can do everything in RootRepeal except scan "files". The program closes when it scans c:/WINDOWS/$hf_mig$
If I remember I found that there are two processes attached to a win32 file. Sorry I'm not sure which program found this, I've been trying so many options found on web it has been tough to keep track because they keep getting shut down.
Nothing works in SafeMode either, so please don't ask me to run anything there. Everything is blocked via permission changes.
I used f-scan which found 2 files and changed their names. Didn't work. I tried Avira Rescue System Boot-disc. Found trojans. Didn't work either. I'm currently running a-squared, but it never finds anything…seems to just monitor traffic.
I locked the processes with ProcessScan. Then I ran RootRepeal. With winlogon.exe suspended RootRepeal would get stuck when scanning, a process for lsass would show in McAfee. I would resume winlonon.exe and RootRepeal would close. I tried again and lsass showed in a different process, not winlogon.exe - probably so it wouldn't get suspended.
MSIEXEC can't ever be found, neither can 'cmd' when trying to run dds.scr.
I'm currently running eScan Anti Virus & Spyware Toolkit Utility which says it found 1 called "NULL.Corrupted". But I must purchase to remove.
F-scan found the following problems, w32/virut.gen, tr/agent.fv.14, windows/PSEXESVC.exe, windows/systems32/cmd.exe - F-scan renamed them but I couldn't find the files afterwards.
I opened firefox and a popup showed with an address of, adserving.cpxinteractive.com
Okay, so what do you think? I hope I'm not notgood. Thanks for your help.
PS. I cannot run scans so don't ask for log files! All scans get shutdown/closed automaticlly
About a week ago I started getting pop ups for that AntiVirus 2009 fake program. It disabled my internet and killed all my virus scan software (list is below). McAfee said it quarantined a trojan about 10 times. I used LSPfix to restore the internet connection. Everything seemed fine.
The next day, BOOM! All the icons for anti-virus-anything were just blank, generic icons. Like it was windows 3.12 again. So I uninstalled and reinstalled over and over again to no avail.
Nothing seems to get this and there isn't any help online that is useful. I need you awesome techs to help me. I cannot scan using hijackthis, malewarebyte's, SpyHunter, Spybot Search & Destroy, Exterminate It!, Norton Online (or any online scans), Lavasoft Adware, ComboFix won't run, and McAfee cannot scan or update. SuperAntiSpyware won't install. VundoFix didn't find anything. DrWeb CureIt found nothing. RootRepeal cannot be ran from desktop, it is blocked - I have to run it from .rar file. I can do everything in RootRepeal except scan "files". The program closes when it scans c:/WINDOWS/$hf_mig$
If I remember I found that there are two processes attached to a win32 file. Sorry I'm not sure which program found this, I've been trying so many options found on web it has been tough to keep track because they keep getting shut down.
Nothing works in SafeMode either, so please don't ask me to run anything there. Everything is blocked via permission changes.
I used f-scan which found 2 files and changed their names. Didn't work. I tried Avira Rescue System Boot-disc. Found trojans. Didn't work either. I'm currently running a-squared, but it never finds anything…seems to just monitor traffic.
I locked the processes with ProcessScan. Then I ran RootRepeal. With winlogon.exe suspended RootRepeal would get stuck when scanning, a process for lsass would show in McAfee. I would resume winlonon.exe and RootRepeal would close. I tried again and lsass showed in a different process, not winlogon.exe - probably so it wouldn't get suspended.
MSIEXEC can't ever be found, neither can 'cmd' when trying to run dds.scr.
I'm currently running eScan Anti Virus & Spyware Toolkit Utility which says it found 1 called "NULL.Corrupted". But I must purchase to remove.
F-scan found the following problems, w32/virut.gen, tr/agent.fv.14, windows/PSEXESVC.exe, windows/systems32/cmd.exe - F-scan renamed them but I couldn't find the files afterwards.
I opened firefox and a popup showed with an address of, adserving.cpxinteractive.com
Okay, so what do you think? I hope I'm not notgood. Thanks for your help.
PS. I cannot run scans so don't ask for log files! All scans get shutdown/closed automaticlly