Full R&R me first run - Partially Fixed - Help Needed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jgtierney, Nov 26, 2011.

  1. jgtierney

    jgtierney Private E-2

    Here's the background:
    Lenovo e520 - Win 7 HP 64
    -I was asked to look at this PC. "It has been running slow/stalling" (I realize this could be cause by non-malware issues, but the other items I found made me suspicious.)
    -Found Microsoft Security Essentials not updated
    -Found Windows updates were failing
    -Checked event viewer and found that update failures started early Nov. (Desktop PC in the same house has similar symptoms. I’ll post on that seperatley.)
    -Tried Malware Bytes and found nothing
    -Tried several other web based virus scanners and rootkit detection tools – nothing
    -Ran MBRCheck and results looked suspicious (Not that I’m and expert, but the “non standard or infected MBR” seemed fishy.)
    -Ran full R & R me first
    -re-enabled UAC
    -Was able to update windows and MSE
    -Let PC run overnight and rebooted this am. Still getting event viewer errors. (See attached log)
    -PC still stalling and sluggish
    -Do I really have a malware problem, or am I looking for something that’s not there?

    Any help is much appreciated.
    -John
     

    Attached Files:

  2. jgtierney

    jgtierney Private E-2

    Additional Files

    Additional files
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are your internet browsers being redirected? Please go to disk management and attach a screen shot of your partitions. It looks like you have one that is faked. It appears to be about 1.17 GB.

    In the meantime, use windows explorer to find and delete:
    c:\windows\system32\SETA67F.tmp
    c:\windows\system32\SETA5D2.tmp
    c:\windows\system32\drivers\SETA554.tmp
    c:\windows\system32\SET991E.tmp
    c:\windows\system32\SET8BCD.tmp
    c:\windows\system32\4385.tmp --> check properties of this one to be sure it is not something needed.

    Do you have a Win7 disc? If not, please create one here:
    Win7 64bit Recovery Environment

    Win7 32bit Recovery Environment

    You can use ImageBurn to create the disc.
     
  4. jgtierney

    jgtierney Private E-2

    Thanks for the reply.
    -Neither Firefox or IE appear to be getting redirected
    -Here's the snapshot of disk management (it appears there is some sort of additional partition there)
    -I deleted to the recycle bin all the SET*.tmp files you listed plus several others with similar names. I also deleted the 4385.tmp file.
    -I have a bootable Win 7 x64 HP disk
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Usually the faked drive does not have a title. This one is System_DRV. Curious. And you would usually be redirected with your browsers. I am wondering if this drive holds your system drivers. I am not sure about Lenovo set ups. What issues are you having?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds