Help - Windows XP (malware?)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sqqs, Jul 19, 2011.

  1. sqqs

    sqqs Private E-2

    Hello,

    I have a Windows XP (32 bit) laptop that has been experiencing issues for possibly over a month now. Issues started after my father in law had been surfing on line (foreign sites - porn? i'd rather not think about it rolleyes).

    Issues have included:
    1) not being able to access any C:Drive folders directly without causing some sort of a crash and error message (for some reason I am able to access it through Firefox by choosing to open the destination folder to which downloads are being saved)
    2) intermittent pc crash upon running Symantec AV or MalwareBytes, as I have been able to run after multiple attempts
    3) additional tab popups on Firefox upon surfing
    4) very slow pc where the PC Usage is close to 100% for extended periods

    Finally got sick of these issues and started the process as detailed in the "Read & Run Me First" sticky. I was able to progress through all the steps as detailed in the "Windows XP Malware Removal/Cleaning Proceure" sticky. The only major hangup was that although "RootRepeal" ran I was unable to save the log. Every time I attempted to the program crashed and there was a warning that it was unable to save the log.

    Attached below are the logs from everything else. I am hoping that my laptop is not "toast" now :eek.

    Thank you in advance for your help, it will be much appreciated!
     

    Attached Files:

  2. sqqs

    sqqs Private E-2

    Last attachment (MGlogs)
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs, other than what was removed by the scans. Please run this:
    TDSSkiller - How to run
     
  4. sqqs

    sqqs Private E-2

    I was able to run TDSSSkiller and something malicious was found.

    After reboot, I am still unable to access the C:Drive directly as the folder will open momentarily, then close immediately and hang up the computer (the screen will flash displaying the desktop without any of the files on it) before returning to the normal desktop view. :cry:cry

    Attached below is the log. Please let me know what steps to take next. Thanks!
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Now please go here and run an online scan:
    eSet Online Scan.
     
  6. sqqs

    sqqs Private E-2

    Hi TimW,

    I've run both MBRCheck& eSet Online Scan and attached the logs below. I have tried accessing the C:drive by double clicking on the "My Computer" icon on the desktop, but it is still not working. The same issue occurs where the screen flashes and displays the background without icons before flashing again and showing desktop with all icons, and the "My Computer" folder does not open. Starting a search via the Start Menu shortcut also results in the same issue and outcome.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MBRCheck is showing an unknown MBR. What brand is this laptop? And do you have your XP install disc?
     
  8. sqqs

    sqqs Private E-2

    Hi TimW,

    It is an IBM/Lenovo Thinkpad. I'd have to search around and see if I have the XP install disk. Supposedly, there is a segregated sector in the hard drive that contains the XP OS and all Thinkpad tools. Yikes! Am I going to need to reinstall the OS and wipe out everything?:cry
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is going to be up to you as your logs are basically clean. I think you now are only suffering from a software problem or two. You might consider trying to backup your data and files and then doing a clean install. Which is something you can discuss in the software forum. But if you can find your install disc, we can try having you do a fixmbr through the Recovery Console to be sure. But it is also possible that MBRCheck is just not recognizing the MBR.
     
  10. sqqs

    sqqs Private E-2

    Would you be able to provide me with the steps, assuming I can find the Windows install disk? Also, at this point should i follow the steps detailed in the instructions that are to be taken once all Malware has been removed?

    Thanks!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Assuming you can find your install disc, boot to the bios and change the boot order to cd/dvd as first boot device. Put the disc in the drive and reboot. Once in the Recovery Console ( your first chance to do a repair by pressing the R key) you will simply type:
    fixmbr

    Exit and reboot to normal mode and re-run MBRCheck and attach the new log.

    If you want, you can also do a "repair install" which can be explained in the software forum. It is just like the above, only you will first choose to do an install, and once the original install is found, it will ask if you want to do a repair, which is your second time to choose "R". Then you just follow the prompts. It will retain all your files and progams.
     
  12. sqqs

    sqqs Private E-2

    Thank you for all your help.

    Is there anything else I need to do in terms of changing settings and uninstall of the various programs used?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds