This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Quick Question?

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

I didn't want to ask in the Virus section because I'm unprepared with logs and other info.

My other computer is being reloaded for the 5th time as I write this, it was infected with something three days ago. Friends with quite a bit of knowledge were directing me on what to do. I used Combofix, SDfix, and a few others to try to detect and solve the problem. And I was directed here to seek expert help. While serching, I found other people with what seems to be the same problem.

It started with my Webroot crashing! Then my McAfee suite crashing! Then FireFox crashed and IE within minutes after that! So I was off the web. At least I had the second computer to work with! The ComboFix found infections, but I couldn't post the logs, and I didn't want to transfer anything to my other computer. I threw everything at it! And the virus was just playing games! It would contently post that files called pev.cfxxe needed to close! It was hiding in Office, or FireFox chrome, or even the files of the program that was looking for it! If I had it on the run, and it was in danger, it would just crash the computer and say it recovered from a serious error! This cat & mouse game went on for two days! Then I threw in the towel, and reformatted and reloaded Windows. It's been a non stop error fest! When I finally got a clean copy and updated at Windows Update, I reloaded McAfee, and the troubles started all over again!!! It started to kill the protection, then it disabled my USB's so I couldn't use a copy protect able drive to bring things from my other computer like I did before with loading the Combofix's and the like. This thing became self aware! It was suggested that it could have been hiding in the BIOS, or in a secret partition and just reinfecting?? So I reflashed the BIOS before reloading this last time, but I didn't find out about removing the recovery partition till after it already started. So now I'm waiting for it to finish to double check that.

Is this something new, because it appears I'm not alone with this one!
AntZ,

Sorry to hear of your troubles. But to answer your question:

Is this something new, because it appears I'm not alone with this one!

It depends on what you mean by new. Malware writers derive no joy from just infecting one system. You can be fairly certain that with any infection that you might get… you won't be the only person. Also, every day is a new day in the malware world. Virus's change daily. So I guess my answer is, you are probably infected with malware that is less than 3 months old.

Secondly, it if very dangerous to your system to be running ComboFix, SDFix, and probably a few other programs that you threw at your machine without actually knowing what you are doing. There are infections that are designed to "destroy" your system when certain advanced tools are used against them. The tools you have named should never be used until an expert has determined that your system is prepared properly to have them run. As a side note - SDFix has not been updated in over a year and is therefore not safe to use against current infections in most cases.

That all being said. I suggest that you follow the directions here : http://forums.whatthetech.com/Welcome_New_…rs_t106388.html and post in the infections removal forum. Please be patient. It might take a couple days before someone gets to your log. Rest assured that we will get to you within a few days.
Thanks for the reply, I'm not a novice, though I'm no expert either. I've worked with these programs in the past, and I knew their dangers. When I started using them here, it was after countless hours of conventional cleaning with no luck. And I was already prepared with the fact that I would wipe it clean and reload. I'm a firm believer in backing up everything! That explains the stacks and stacks of data DVD's in my office. But when it appeared that this thing was able to jump to the reinstall, I knew that it was out of my league, that's why I'm here! ;)