Residual damage from windows xp repair virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pianodactyl, Jun 22, 2011.

  1. pianodactyl

    pianodactyl Private E-2

    So upon returning from university, I found the home desktop in disarray. When I went to use firefox, I had a window popup from what turned out to be the windows xp repair virus. I took the necessary steps to remove it, but upon running supplementary scans with Malwarebytes and Symantec, there was other garbage still there (at least one thing that both programs said they couldn't remove). Things seem overall better now (no more website redirects), but it still seems slower than it should be and whenever the computer is turned on, there's a message from Malwarebytes that pops up and says it failed to complete what I'm assuming is removing the virus.
     

    Attached Files:

  2. pianodactyl

    pianodactyl Private E-2

    Aaaand the MGtools log
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    The version of MGTools you are using is roughly two years out of date!!!

    Go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new C:\MGTools.exe and attach the new C:\MGlogs.zip

    How are things running?
     
  4. pianodactyl

    pianodactyl Private E-2

    Things are running pretty well, but firefox is still slow to load and the system just slows down randomly (to be fair, the computer is 8 years old running off half a gig of ram).
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is this file?
    C:\Documents and Settings\Benjamin Provost\Desktop(2)

    What is inside of this folder?
    C:\Documents and Settings\Benjamin Provost\Recent(2)

    Does this still occur? :confused
     
  6. pianodactyl

    pianodactyl Private E-2

    C:\...\Recent(2) seems to be a small collection of recently accessed files. When I went to find C:\...\Desktop(2), even going as far as typing the path in directly, it didn't seem to exist.

    Yes, that is still occurring. When I initially ran Malwarebytes, it said the system needed to reboot to finish deleting, and since then every time I turn on the computer one of the first things to load is this error message: [OpenEvent] Failed to perform desired action. Error Code: 2

    Also, I turned Symantec back on (only running Steam and SuperAntiSpyware [Symantec was disabled so I could run another SAS scan just in case]) and a bit after the SAS scan finished it gave me the following warning:
    Backdoor.Tidserv!inf
    Action: None found
    Filename: A0127501
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Likely just something in System Restore.
    Then see if you still get this detection.
     
  8. pianodactyl

    pianodactyl Private E-2

    Nope, after the system restore bit the notification still comes up.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then attach a log showing exactly what is found because what you showed in your previous message ( Filename: A0127501 ) is really likely to be a file in the System Volume Information folder which is System Restore.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds