Can't identify infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pariah, Dec 28, 2011.

  1. pariah

    pariah Private E-2

    Hi there. Just bought a used machine. Have yet to be able to put an anti-virus on it, but it looks like it's already infected.

    The system has a tendency to chug at times. And when it does, the screen flickers and sometimes changes the desktop format like it's about to hijack it. And the task manager has a suspicious number of svchost processes running in the background.

    I've finished the readme and run all the diagnostic/cleaning programs. However, all of them have come up with zero errors--with the exception of Root Repeal, which just ends up with a blue screen every time I run it (thus its absence).

    Thank you for your assistance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  3. pariah

    pariah Private E-2

    Thank you for your reply.

    Here are the logs.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is inside of these folders? They might show like this... (I also see certain programs installed with strange characters, could just be a language thing)

    C:\Documents and Settings\Administrator\Local Settings\Application Data\ƒLƒ~‚Ì~1
    C:\Documents and Settings\Administrator\Local Settings\Application Data\ŠÄ–‚R~1


    Or like this:

    C:\Documents and Settings\Administrator\Local Settings\Application Data\ƒLƒ~‚Ì‚¿‚ñ‚¿‚ñAŽÊƒ‚点‚Äô
    C:\Documents and Settings\Administrator\Local Settings\Application Data\ŠÄ–‚r`‚P‚O‚c‚`‚x‚r

    What is this file?
    C:\Documents and Settings\Administrator\Desktop__rzi_05.484

    What is this?
    C:\Documents and Settings\Administrator\Start Menu\Programs\‚r‚h‚k‚j‚xf‚r

    Delete this:
    C:\WINDOWS\jyokyoushi.ini Reboot and check it is still gone.
     
  5. pariah

    pariah Private E-2

    Those are Japanese characters for a game file. Not really important.

    I have no clue. I can't even open it.

    Pretty large too. Should I delete it?

    More Japanese characters.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Documents and Settings\Administrator\Desktop__rzi_05.484 Delete it then, reboot and see if it is still gone.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds