Could use a little assistence

Discussion in 'Malware Help (A Specialist Will Reply)' started by rgv, Feb 2, 2006.

  1. rgv

    rgv Private E-2

    im working on a laptop at the moment that was running really really slowly. So ive done some of the usual things to try and clean it up, ran spybot/spyware doctor and such to clear it out, updated windows, removed norton in favor of mcafee, and did a hijack this log (checked against hijackthis.de).

    while all this has helped quite a bit it is still noticably slow. its a 1.5ghz dell w/ 512mb. my 600mhz 128mb old as dirt laptop boots in a quarter the time as this thing (it went from a 10 minute boot to a 2-3 minute one now), but regular use is still quite slow and choppy. My only clue comes with the fact that when i go to shut it down it sometimes asks me to end program called "Sample". I have found no mention of this anywhere.

    a search of the forums turned up:
    http://forum.majorgeeks.com/showthread.php?t=71930&highlight=end+program+sample
    and
    http://forum.majorgeeks.com/showthread.php?t=45097&highlight=end+program+sample

    neither of which really explain what this process could be.

    google has returned this little tidbit:
    http://www.google.co.uk/search?q=virus+called+sample.exe&btnG=Search&hl=en
    http://www.sophos.com/virusinfo/analyses/w32nimdad.html

    i did update and run mcafee which is why im at least partially skeptical that a virus dated in 2001 (from more than one site) would still be the culprit but I am honestly stumped here. I can't tihnk it would be anything other than a virus and this is currently the only lead.

    anyone know what this sample process really is? or any other off the wall ideas on what to try?

    thanks in advance for any help/ideas. first time here hoping for a good go of things.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Welcome to MajorGeeks.com!

    Let me warn you of (hijackthis.de), this site is NOT very accurate. It detects items as bad that are really legit entries so I would be really careful using this.

    Now, let's run a basic cleaning, please follow the steps below:


    http://www.majorgeeks.com/images/grenade.gif Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    • Make sure you check version numbers and get all updates.
    http://www.majorgeeks.com/images/grenade.gif Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    http://www.majorgeeks.com/images/grenade.gifAfter doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps in the below thread to properly use HijackThis and attach the log:

    http://www.majorgeeks.com/images/grenade.gif Downloading, Installing, and Running HijackThis
     
  3. rgv

    rgv Private E-2

    ok so as an update the computer has basically imploded. Originally i had given it back for the night because it was still working. magically it no longer decided to work at all this morning now giving me a message saying that the system32/config/system file is corrupted. I've tried to access it via repair console but i cant navigate (dir gives me an enumeration error) i cant chdir or anything of the sort. md says access denied. As an offhand idea im currently running a memtest to see if the ram is ok (just a hunch at this point because even in repair console the computer was taking FOREVER to do things).

    any ideas?
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you have your Windows XP disc, follow me below...

    1. Insert the Windows XP CD into the CD Drive. Make sure your CD-ROM is set to first boot.
    2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
    3. Select the installation that you want to access from the Recovery Console. In your case it should be C:\WINNT
    4. When you are prompted to do so, type the Administrator password. If the administrator password is blank, just press ENTER.
    5. At the Recovery Console command prompt, type the following lines, pressing ENTER after you type each line:
      • md tmp
      • copy c:\windows\system32\config\system c:\windows\tmp\system.bak
        (If you get an error after pressing enter, just procede)
      • copy c:\windows\repair\system c:\windows\system32\config\system
        (You should get message 1 file copied)
      • Type exit to quit Recovery Console. Your computer will restart.
    6. After you complete the above, reboot and see if the error still comes up, if it does let me know!
     
  5. rgv

    rgv Private E-2

    yeah thats where i am at right now. memtest turned up nothing so i was still going crazy till i bothered to check the hd. hdd regenerator returned 1600+ bad sectors!!! it now at least boots into recovery console without any problems. The registry as you might have guessed is in shambles and im going to do:
    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545

    to see if that helps. if its fixed im gonna go back and redo all the malware removal steps (ill post a hjt log if something else turns up). otherwise i think its going to need a format. something tells me when 25% of your hd has major issues with bad sectors its probably not salvage worthy. Either way, thanks for the help. i really liked the outline for malware removal.
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Let me know how things turn out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds