Is this computer clean?

Discussion in 'Malware Help (A Specialist Will Reply)' started by ppreheim, Jul 27, 2011.

  1. ppreheim

    ppreheim Private First Class

    I just was given a used computer and it just seemed a little "off" to me so I did the "Read me first" and followed the steps. Please read the logs and let me know if there is anything else I need to do. It seems to have a lot of processes running. Where can I go to find out which ones I need and which ones I can get rid of?

    Thanks for the help
     

    Attached Files:

  2. ppreheim

    ppreheim Private First Class

    Last log attached
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ppreheim

    I am reviewing your logs and will get back to you with instructions as needed. Please be patient as the logs produce alot of information to go over.
     
  4. ppreheim

    ppreheim Private First Class

    Take your time and thanks!!
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    I agree, however they are not malware related. You can receive help with trimming what you feel you don't need in our Software forum.

    Step 1:
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall the below crapware. If you get any errors just make a note and continue on.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 2:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Notes:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    *If after running Combofix you discover none of your programs will open up, and you receive the following error: "Illegal operation attempted on a registry key that has been marked for deletion", then you will need to reboot your computer which will normally fix this problem.

    Step 3:
    Delete this leftover folder using Windows Explorer:
    c:\documents and settings\Administrator\Application Data\searchquband

    Step 4:
    Now Copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Step 5:
    Let's run some additional scans

    TDSSkiller - How to run

    Please also download MBRCheck 1.2.3 to your desktop.
    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See:HOW TO: Attach Items To Your Post )
    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • updated C:\MGlogs.zip
    • TSSKiller log.txt
    • MBRCheck .txt

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  6. ppreheim

    ppreheim Private First Class

    Thanks!

    Ran the tasks as asked without any obvious problems. MBRCheck did find something. Logs attached

    Computer seems to be running well and also seems to be faster.

    Thanks again!

    PS - Attached combofix log as well. Didn't know if it was in the zip file or not so I just threw it in to make sure.
     

    Attached Files:

    Last edited: Jul 29, 2011
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Do you have your Windows Install disc? Do you have your important data backed up?

    Using Windows Explorer, navigate to and delete this folder:
     
  8. ppreheim

    ppreheim Private First Class

    Folder deleted,

    Ouch, that bad huh? Will check and see if I can get it. I do have some data on here but I will store it on an external hard drive. Does it have to be the install disc that came with his computer, or could it be from any computer that uses the same OS?

    Thanks!
     
    Last edited: Jul 29, 2011
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    * Regarding your question about data backup:
    Yes, an install disc from another machine using the same OS can be used to boot into the Recovery Console. Another option would be -
    You will need to first boot into the bios and change the boot order to cd/dvd as first boot device. Then insert the disc and reboot. Once you get to the command prompt in the Recovery Console, type fixmbr and hit enter. After it finishes type exit to reboot and remove the CD to allow Windows to boot normally.

    If you were able to run fixmbr, rerun MBRCheck and attach a new log. Also tell me how things are working.
     
  10. ppreheim

    ppreheim Private First Class

    Burned the ISO Image and booted from it. Tried it twice and got the blue screen twice. I am looking for an xp repair disc
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please download this zip, extract it and burn the .iso file, repeating my instructions for using it in post#9.

    Windows XP Recovery Disc.zip
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    What is the exact BSOD message? Can you post a screencapture (taken by a cellphone camera maybe)?
     
  13. ppreheim

    ppreheim Private First Class

    Here is the pic of the BSOD. Downloading the new ISO image now.

    THANKS!!!!
     

    Attached Files:

  14. ppreheim

    ppreheim Private First Class

    Tried the new iso image and got the same bosd message. With both boot discs it starts to load files and then it goes to the same bsod.
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ppreheim

    I'm conferring with my colleagues on this. It may have something to do with the Protector Suite and the Lenovo fingerprint reader software.

    dr.m
     
  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    A quick question-

    Can you re-burn the image to disc, using the slowest write-speed available (1x) and try again?
     
  17. ppreheim

    ppreheim Private First Class

    Will do. I am a bit worried this may be the problem. I do not have a lot of experience writing the iso image to disc. I am using the software that came with my dell desktop I purchased last year (PowerIso). Is a CD large enough to take the file or should I use a dvd?
     
  18. ppreheim

    ppreheim Private First Class

    Reburnt the image to a DVD using the slowest setting (4x). Got the same bsod. I really hope I am not wasting your time because this is something I am doing wrong in burning the image.
     
  19. satrow

    satrow Major Geek Extraordinaire

    Hi ppreheim,

    To confirm exactly what the BSOD error is, can you confirm that the screenshot shows (0xC0000005, 0xF748E0BF, 0xF78DA208, 0xF78D9F08) please?

    Then, to rule out anything more random, like memory errors, could you please reboot to 2 of the disks you've created and confirm that the memory addresses in each of the errors are identical to the original? IE: that it is exactly the same error every time?
     
  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  21. ppreheim

    ppreheim Private First Class

    Tried the new image writer and followed the guide. Got the same stop numbers as listed below and confirmed by satrow. The address for each disc

    Latest disk with image burn - pci.sys - address F748EOBF base at F7487000, datestamp 3b7d855c

    DVD - Stop: 0x0000007E (0xc0000005, 0xF748E0BF, 0xF78DA208, 0xF78D9F08)

    Address was the same as above

    Cd burnt at slow - stop: same as DVD

    Address was the same above

    CD burnt fast - stop: same as DVD

    Address was the same as above.

    Again, I can't thank you enough for your time
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Thanks for sticking with us. I've ask chaslang to look into the problem for a solution.

    dr.m
     
  23. ppreheim

    ppreheim Private First Class

    I should be saying that to you.

    Thanks for all the help!
     
  24. satrow

    satrow Major Geek Extraordinaire

    Sorry to keep you waiting so long, I think the following should enable you to run the Recovery CD correctly:

    Change the SATA settings in the BIOS from AHCI to compatible. Then boot to the RC CD to fix the MBR.
    Reboot and enter the BIOS again to set it back to AHCI then boot up normally to check that the MBR is now clean.
     
  25. ppreheim

    ppreheim Private First Class

    Tried to change the Sata to compatible but it does not have that setting. It did have IDE? I changed it to that and tried to boot from a disc but still got the same bsod.

    Thanks for not giving up!!
     
  26. satrow

    satrow Major Geek Extraordinaire

    The IDE setting should have worked but I have seen computers that don't save and reboot to set the new BIOS settings immediately; perhaps you can try again, watching for the reboot after changing the settings and saving them? Also try one of the other discs too?
     
  27. ppreheim

    ppreheim Private First Class

    When setting it to IDE it does try to reboot but upon reboot it crashes to restart when loading windows. Tried all 4 recovery discs I have made anyway and all went to BSOD.
     
  28. satrow

    satrow Major Geek Extraordinaire

    Ok, what motherboard make/model do you have?
     
  29. ppreheim

    ppreheim Private First Class

    How do I find out the make/model of the motherboard?
     
  30. satrow

    satrow Major Geek Extraordinaire

    If it's a desktop or tower computer, by opening it and getting the data directly from the motherboard. But I see it has a 2.5" laptop sized hard drive, is it a laptop? If so, there should be a make/model# somewhere underneath - similar if it's a branded PC, there should be some info on a sticker on the rear.

    From within Windows, SIW will show the details, hardware > motherboard.
     
  31. ppreheim

    ppreheim Private First Class

    It is built by rugged notebooks. Don't know if that helps.

    did the SWI file and got unknown for everything motherboard related(Manufacturer, Model, Version, Serial Number)

    Still looking for a tag/sticker with the motherboard on the computer

    It is a laptop
     
    Last edited: Jul 31, 2011
  32. ppreheim

    ppreheim Private First Class

    doing some research and found that it is a GammaTech D14RM-WKE computer
     
  33. satrow

    satrow Major Geek Extraordinaire

    I'm going back into conference about this.

    There was only one place in the BIOS where SATA was mentioned, yes? And the only other option there was IDE?
     
  34. ppreheim

    ppreheim Private First Class

    correct, it was onder the advanced heading. Rechecked and couldn't find any other setting for sata or any other place in the bios to change it.
     
  35. satrow

    satrow Major Geek Extraordinaire

    Ok, according to the (brief) manual for the D14RM, there should be a setting in the Advanced settings of the BIOS for AHCI mode. What is this currently set for and what other options are there?
     
  36. ppreheim

    ppreheim Private First Class

    Yes. In Advanced mode under "Configure Sata As" there are two options. It is currently set to AHCI. The only other option is IDE. When I try to set it to IDE th computer will automatically restart but it will never boot. It crashes mid reboot back to a restart.
     
  37. satrow

    satrow Major Geek Extraordinaire

    So your Advanced BIOS page isn't the same as the attachment, with disabled as an option?
     

    Attached Files:

  38. ppreheim

    ppreheim Private First Class

    Nope, not the same as the image.

    Using SWI to get this info for the Bios
    Manufacturer - American Megatrends Inc
    Version - 08005
    Date - 3/30/2010
    Size - 1024 kb
    Starting Segment F000h
    DMI Version - 2.5

    I also found a security part of the Bios. Said TCG/TPM support and that it was active.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds