Is it Malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Novafrk, Aug 26, 2012.

  1. Novafrk

    Novafrk Private E-2

    Hello all,

    I have performed the steps in the Malware tutorial. Here is my log file from RougeKiller. The problem I have is my pc will play commercials all the time... non stop. It's pretty annoying.

    Thanks,

    Novafrk
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You have 4 more logs to attach from the below:

    • Malwarebytes
    • TDSSKiller
    • Hitman Pro
    • MGtools
     
  3. Novafrk

    Novafrk Private E-2

    Oh. I thought I just needed one of them. Ok. I'm on it!
     
  4. Novafrk

    Novafrk Private E-2

    Sorry about that. Here are the other 4 files. Thanks again for your help!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a boot record infection.

    Your Malwarebytes log indicated you took no action. Please run it again and fix anything it finds. Logs need to be saved after fixing not before.

    Also re-run TDSSKiller and if the below items show again, Quarantine/Delete ( which ever is allowed ) them this time. Only fix these lines
    Code:
    14:51:40.0114 6060  ================ Scan MBR ==================================
    14:51:40.0173 6060  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
    14:51:40.0174 6060  Suspicious mbr (Forged): \Device\Harddisk0\DR0
    14:51:40.0247 6060  \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.c ) - infected
    14:51:40.0247 6060  \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.c (0)
    14:51:40.0253 6060  [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk1\DR1
    14:51:40.0446 6060  \Device\Harddisk1\DR1 - ok
    Then immediately reboot your PC. After reboot, continue with the below.

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)

    Now run a new scan with TDSSkiller and attach a new log.
     
  6. Novafrk

    Novafrk Private E-2

    Here are the two log files after performing the last set of instructions. Thanks for your patience.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay those look good. Now run a new scan with RogueKiller and attach the new log. I want to see if it still detects anything.

    Also tell me if you are still having problems?
     
  8. Novafrk

    Novafrk Private E-2

    Here is the log as requested. There were two hits but it looked like it was for the printer... I'm not sure. I have not had the BSOD since performing the tasks as indicated.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach it.

    Well is it still running okay now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds