Malware Removal on Windows 7 Starter

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by linuxpowers, Aug 3, 2013.

  1. linuxpowers

    linuxpowers Corporal

    Just received a netbook from a friend of mine and was wondering if I can use the "Cleaning Instructions" from the READ & RUN ME FIRST thread on a Windows 7 Starter OS? :confused

    I am assuming I would use the instructions for Vista, 7 and 8 systems...correct?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Correct. ;)
     
  3. linuxpowers

    linuxpowers Corporal

    OK! Now, I started the process and have noticed a couple issues already.

    First of all, I'm not so sure that it makes any difference but my RogueKiller report does not have the file name of, "RKreport[1]" but rather "RKreport[0]" but, it is there!

    Secondly, I renamed the MalwareBytes installer file to mb.exe and ran it but it stops during the installation process with an error;

    C:\Program Files\Malwarebytes' Anti-Malware\mbamservices.exe

    An error occured while trying to copy a file:
    The request could not be performed becasue of an I/O device error.


    Not sure where to look on this issue. I did check out "Device Manager" with no issues shown and I went to the directory, "C:\Program Files\Malwarebytes' Anti-Malware\" and saw that 8 other files have successfully been copied there. Keep in mind, there was an older version of MalwareBytes installed on this system but it was removed via IOBit-uninstaller.
     
  4. linuxpowers

    linuxpowers Corporal

    OK...I decided to "Abort" the installation process for now and just reboot the system. But, during the boot process, windows encountered errors and wouldn't start! I was given the option to run "Startup Repair".

    Now, I've got the report back on that and it tells me that Startup Repair cannot repair this computer automatically. The problems listed are as follows:
    Of course, I'm given the options to send or not send the information about this problem.

    Keep in mind, I could always USB this HD to my desktop and work on it from there IF, I'm not looking at a hardware issue.
     
  5. linuxpowers

    linuxpowers Corporal

    After this Startup report, this computer shut down...powered off! So I hit the power button and started it back up. I wanted to see if it would load in safe mode so, I held down the F8 key and sure enough, I got the boot menu for it. So I went ahead and loaded it in Safe Mode w/Networking and it let me log in.

    After it settled down, I got a "Windows" message pop up that tells me that "Windows has recovered from an unexpected shutdown and that Windows can check online to find a solution for the problem"

    Looks like the some of the same info the Startup had with a bit more details.

    Anyway, that's where I'm at now....sitting in safe mode w/networking capabilities!
     
  6. linuxpowers

    linuxpowers Corporal

    OK...I ran all the tools (except Malwarebytes for which could not be installed)

    After I ran all these, it dawned on me that I could have connected this netbook to my desktop and ran Malwarebytes on it that way! If this is exceptable and desired, just let me know!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. However, do this:

    [​IMG] Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now work through the below:

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup

    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.


    Tell me what issues remain, if any.
     
  8. linuxpowers

    linuxpowers Corporal

    OK ran both Junkware Removal Tool & Windows Repair, log file attached.

    After letting Windows Repair do it's thing, it shut down and restarted my system as instructed but, Windows still won't let me in with a normal startup...have to use safe mode. It did balk at me at first because I was already in safe mode!

    So until I can get in windows in a normal mode, that's the only issue I'm aware of right now!
     

    Attached Files:

    • JRT.txt
      File size:
      47.5 KB
      Views:
      2
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try one more thing before I send you to the software forum.

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  10. linuxpowers

    linuxpowers Corporal

    OK, I checked on this netbook last night and found that it was hung up so, I had to force a reboot and then the problems started. :eek

    The computer wouldn't even let me boot in safe mode! I noticed that windows was trying to load because I was getting the splash screen for a couple seconds before it crashed out and rebooted. So the first thing I did was hit f8 again and this time I enabled Boot Logging. I'll have to attach that log in the next message since I'm typing this message on my desktop computer. I did watch the drivers being loaded and noticed that it always stopped after loading CLASSPNP.SYS (so I wrote that down thinking it significant)

    Anyway, I got up this morning and tried again, without any luck. After several more attempts, I just had this idea to pull out the memory card and give it a once over. I cleaned the contacts with a pencil eraser, tissued it off and replaced. This time I didn't try to boot in normal mode but I was able to get in in safe mode w/networking.

    BTW, if this is becoming an issue other than Malware, should I stop here and start another thread in say, Software or Drivers?
     
  11. linuxpowers

    linuxpowers Corporal

    Wow TmW, just missed you by 6 minutes.

    Anyway, after I read your post, I thought I shouldn't attach the log file just yet.

    Still want me to give it a try....Combofix?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since I wasn't finding any malware in your previous logs, then I suggest that maybe you do post in the hardware forum. Once you are sure it is not a hardware issues, then try the software forum.

    I'll try to keep an eye on your threads.
     
  13. linuxpowers

    linuxpowers Corporal

    OK TimW, will do!

    Thanks for all your help and thanks for keeping an eye on me!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows
          defaults.


    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ &
      RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall,
      don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking
      on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if
      running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any
      others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and
      deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore
      points:
      • Refer to the instructions for your WIndows version in this link:

        Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which
        could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:



    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds