rootkit or/and worse

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by joshGosh, Nov 9, 2012.

  1. joshGosh

    joshGosh Private E-2

    not sure where to begin. my problems started installing something i thought was activeX to my fujitsu xp sp2 2002 laptop(not able to upgrade to sp3). i know the date and time as well. half of my desktop disappeared along with half of the start/programs. loads of popups and a mighty sirupy internet connection. instantly scanned with malwarefighter/superantispyware/spybot/symantec antirus/ccleaner.. and later anything i could think of. think it was the malwarefighter which found rootkit infection.(rootkit0access c:system volume info/restore..... exe). things seemed back to normal for half a day, only to come back worse than before. my missing desktop icons/programs, start/programs came back as i learned they only were made hidden. though most systemtools etc were gone..(later installed back)

    now my problems/symptoms are as follows :
    at (every!!) startup im told there is hardware found, other pci device.
    my wave sound (in advanced mode is muted)
    internet slow with constant avast popups
    control has no parent windo.
    tidserve activity 5
    generic host process for win32 services problem.
    my avast pops up messages constantly when connected to the internet.most mention explorer.exe.
    the fan usually runs wild when browsing

    combofix says rootkit activity
    mbrcheck says c: error, physical drive0 mbr code faked, found non standard or infected mbr.
    rkill says xSystemrootx\system32svchost.exe -k rpcss incorrect imagepath
    gmer wont run(most of these programs wont run at all)

    this was way over my head from the beginning. im surprised the computer runs at all.

    it would please me greatly getting any feedback regarding this.

    -jo:)
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. joshGosh

    joshGosh Private E-2

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach your log from running ComboFix.


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
    You also need to install SP3.
     
    Last edited: Nov 12, 2012
  5. joshGosh

    joshGosh Private E-2

    i did unfortunately run and fix mbr right before this thread. log also attached. my internet seems much better after.
    also unable to find any combofix log or program. :(
    regarding sp3 : when trying, im told to uninstall a sp2 update which i seemingly don't have.

    thanks
     

    Attached Files:

    Last edited: Nov 13, 2012
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you still having?
     
  7. joshGosh

    joshGosh Private E-2

    "other pci bridge device , hardware found"... at every startup.
    internet seems ok, but im only using int expl now .. chrome acted really crazy earlier,so i didnt dare using it anymore.
    should i delete anything found from the scans you told me to run?
    i dont feel especially safe regarding using password etc on the internet before i trust the computer is clean clean.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You'll need to use the computer so we can tell if anything else is broken. Use a different computer and change your passwords. Then get on the net and tell me how things are running.
     
  9. joshGosh

    joshGosh Private E-2

    my internet experience is as good as i would want. especially as reinnstalling chrome.
    works like a charm. no cpu usage and explorer.exe is acting normal. the fan is not going crazy as before..back to normal :) there are no redirections..or popup-activity of any kind.

    only things bothering me are the other pci bridge device thing, while waiting for things going crazy again.

    wave is no longer muted at startup.

    i cannot install sp3 as the installer tells me first to uninstall a previous update,which i cannot see.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, then ......


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link

    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  11. joshGosh

    joshGosh Private E-2

    great. thanks. just one final question.
    should i delete whatever's found in the scans of step2 for the *Windows XP Malware Removal/Cleaning Procedure* ?
    till now i have only scanned, and left the results as they were... then exited.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm sorry, but what do you want to remove?
     
  13. joshGosh

    joshGosh Private E-2

    rougekiller found 7 registry entries
    here's one of them :
    HJPOL HKCU SOFTWARE\windows\currentversion\explorer\Advanced start_show 0

    should i delete as suggested?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They are no big deal, but yes, you can have it fix them. :)
     
  15. joshGosh

    joshGosh Private E-2

    great .. thanks for your time and help.
    *oh i'm afraid the deflector shie....*

    -Jo
     
  16. joshGosh

    joshGosh Private E-2

    while not looking for it,i did stumble upon my comboFix log.
    please have a look
     

    Attached Files:

    • log.txt
      File size:
      12.1 KB
      Views:
      1
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your Combo log is clean as well. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds