New Member with a nasty virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HiPlainsGrifter, Aug 6, 2011.

  1. HiPlainsGrifter

    HiPlainsGrifter Private E-2

    Hi,

    I was having problems with slow internet and malware bytes notifications that sites were being blocked. I did multiple reinstalls of windows but to no avail. I then diligently followed the instructions in the Malware removal guide, but am still experiencing glacially slow internet and believe it to be malware related. I'm including a hijack this log just for good measure. Any help in diagnosing the problem woudl be greatly appreciated.

    Thanks,

    -Cormac
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. HiPlainsGrifter

    HiPlainsGrifter Private E-2

    Thanks so much for getting back to me. I really appreciate it.

    TDS Killer didn't seem to find anything, but MBR did. The plot thickens. See the enclosed logs.

    -C
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am assuming that you have a second hard drive installed ( 1863 GB \\.\PhysicalDrive1 ) which MBRCheck is recognizing as unknown. Nothing else is showing in your logs. I also am assuming you do not have in install disc.

    You can create a Recovery Environment disc from one of these downloads ( depending on whether you have a 64bit or 32bit system):
    http://digiex.net/downloads/downloa.../2660-windows-7-64-bit-x64-recovery-disc.html

    http://digiex.net/downloads/downloa.../2659-windows-7-32-bit-x86-recovery-disc.html

    You can use ImageBurn to create the disc.

    Then go into the bios and change the boot order to have the cd/dvd drive as first boot device, put in the disc and reboot. Once you are in the RE, choose the command prompt and type in this:
    bootrec.exe /fixmbr \device\harddisk1

    Then type exit and reboot into normal mode. Then re-run MBRCheck and attach the new log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds