Help with Virus Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by JGordonisone, Apr 27, 2012.

  1. JGordonisone

    JGordonisone Private E-2

    It all started awhile back while searching Google for something legit and I click one of the results and poof everything that I had opened closed out and a fake win security antivirus whatever it was I forgot the name of it, took over my computer which blocked any program I tried to open including browsers and blocked task manager and also safe mode I could not get into either and system restore restricted also..

    Well Lucky I had some recovery disc that I used to enable Administrator account to log into that and the virus did not inject itself into that account and found the source files of virus and deleted them, got access to programs again, downloaded a tool to un-restrict task manager etc..

    Now my computer is ruining slow and Firefox lag very bad at times. Safe mode is still not working..

    I did all the required steps and attached all logs except root appeal as I have 64 bit version of windows 7 and ComboFix as it got stuck on Preparing Log phase for a few hours..


    Please help me resolve this nasty virus,:)

    Thank you,
    JGordonisone
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You may have a faked partition:
    Partition Disk #0, Partition #2
    Partition Size 8.93 GB (9,585,033,216 bytes)

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. JGordonisone

    JGordonisone Private E-2

    Thank you for the reply.

    The scan did not pick up any threats and I attached the log file.

    Edit
    Forgot the MBR check, i attached that log too
     

    Attached Files:

    Last edited: Apr 27, 2012
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should back up your important files and data, then:

    Preferably from a clean computer, I need you to download: gparted-live-0.11.0-7.iso (114 MB)
    Create a bootable CD for GParted. You can useImgBurn to accomplish this.
    If you need help on how to use ImgBurn, please view this guide by dr.m -- Using ImageBurn to Burn an ISO image
    Now boot off of the newly created GParted CD.
    http://img717.imageshack.us/img717/6546/gpartedsplash01107.th.png
    You should be here...
    Press ENTER
    http://img819.imageshack.us/img819/7286/gpartedkeymaps.th.png
    By default, do not touch keymap is highlighted. Leave this setting alone and just press ENTER.
    http://img404.imageshack.us/img404/9840/gpartedlanguage.th.png
    Choose your language and press ENTER. English is default [33]
    http://img140.imageshack.us/img140/7958/gpartedgui.th.png
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    http://img32.imageshack.us/img32/1122/gpartedo.th.png
    According to your logs, the partition that you want to delete is 8.93 GB
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    http://img233.imageshack.us/img233/1533/gpartedsteps.th.png
    Now you should be here:
    http://img696.imageshack.us/img696/8471/gpartedsuccessclose.th.png
    Is boot next to your OS drive? According to your logs, your OS drive is the 187.70 GB sized partition.
    http://img194.imageshack.us/img194/7753/gpartedboot.th.png
    If boot is not next to your OS drive under Flags, right-mouse click the OS drive while in Gparted and select Manage Flags
    In the menu that pops up, place a checkmark in boot like the picture below:
    http://img196.imageshack.us/img196/3483/gpartedmanageflagsboot.th.png
    Now press the Close button to save these changes.
    Now double-click the http://img822.imageshack.us/img822/641/gpartedexit.png button.
    You should receive a small pop up like this:
    http://img88.imageshack.us/img88/8986/gpartedexitreboot.png
    Choose reboot and then press OK.

    Now reboot from the Windows 7 Recovery Disc and execute the following commands:

    • bootrec /fixmbr
    • bootrec /fixboot
    • exit
    Once back in Windows...
    http://img707.imageshack.us/img707/6703/generalxpicon.gif Re-run another scan withMBRCheck and attach its latest log. (How to attach)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. JGordonisone

    JGordonisone Private E-2

    That 8.93 partition that you wanted me to delete is my recovery partition that came with my laptop, don't want to mess with that and also Boot was already checked by default on my main partition.

    I don't really think i need to run those scams for logs again as I did not make any changes.


    Now whats next you want me to do?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, then just tell me what issues you are still having, if any.
     
  7. JGordonisone

    JGordonisone Private E-2

    Safemode not working and laptop running really hot with temps up to 190* to 205* F, before I had the virus the temps were around 145*F
    Also computer is running quite slow with firefox and i went through all the cleaning procedures that were recommended on here and none of it helped..
     
    Last edited: Apr 28, 2012
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I didn't find any malware. I think you should post in the software forum for further assistance.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds