laptop PC locking up - virus?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by xor0, Jun 7, 2011.

  1. xor0

    xor0 Private E-2

    Windows vista home premium SP2 Acer 5920G

    While web browsing the browser became unresponsive, then the whole pc, so nothing could be clicked on. Finally even the mouse cursor freezes. On rebooting there is a few seconds where it works, then starts to lock up again. Booting into safe mode seems fine, can access internet. Ran the set of diagnostics (all in safe mode), rebooted and all seemed fixed for a couple minutes, had time to reactivate the windows antivirus, but then started locking up again.

    Logs attached except root repeal which gave the error:

    'Unrecognized partition type 6'

    Including 2 MG logs cos I mistakenly cancelled the Hijackthis popup the first time.

    Grateful for any help!
     

    Attached Files:

  2. xor0

    xor0 Private E-2

    MGlogs
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    I'm reviewing your logs.

    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, xor0

    Before we get started, you need to run MSconfig and put your PC into normal startup mode as requested in step 4 of the READ & RUN ME guide.
    Use MSconfig to setup for Normal Startup Mode

    Question: Did you have problems running RootRepeal?

    Step 1:
    Please run TSDDKiller per the following instructions:
    TDSSkiller - How to run

    Step 2:
    Now download Sophos Anti-Rootkit 1.5.4 and save to a location you will be able to find such as your desktop
    1. Run sar_15_sfx by double clicking on it.
    2. Click Accept to agree to the EULA
    3. Click Install (if you wish to change the default installation location do so here but remember where you install to, the default is C:\SOPHTEMP)
    4. Once it finishes copying files, exit the installer

    Running the scan
    1. Navigate to the location that you installed the software to (Default: C:\SOPHTEMP)
    2. Run the sargui Application by double clicking on it. (Note: if using Vista or Windows 7, use right click and select Run As Administrator).
    3. Ensure that all three of the options are checked
    4. Click Start Scan
    5. Once the scan is complete, close Sophos Anti-Rootkit by closing the scan window and clicking Exit in the main window

    Do NOT click 'CLEAN UP CHECKED ITEMS' or attempt to have Sophos Anti-Rootkit fix anything unless specifically instructed.

    Finding the logs
    1. Click on Start --> Run
    2. Type in %TEMP%\sarscan.log and press enter
    3. The log file will open in the default editor (probably Notepad)
    4. Click File --> Save As and save the file to your desktop or other location for easy retrieval.

    Step 3:
    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Step 4:
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 5:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 6:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 7:
    Now install the latest Sun Java Runtime Environment


    Step 8:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • sarscan.log
    • MBRCheck_xx.xx.xx_xx.xx.xx.txt

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  5. xor0

    xor0 Private E-2

    Thanks for helping me, much appreciated.

    The basic problem is that the computer becomes unresponsive and locks up in normal mode. I have been using F8 to run in safe mode as this is the only way I can use the computer.

    When I try to access msconfig I get the error message:

    "windows cannot find 'msconfig'."

    When I click on file/scan in RootRepeal I get the error:

    "Unrecognized partition type 6"

    TDSSkiller ran, log attached.

    Sophos gave the following error message:

    "Error: Could not initialize kernel driver memsweep.sys. Please restart and try again.

    This service cannot be started in Safe Mode"

    I attached the log but it didn't really run.

    Mbrcheck ran and found bad mbr's on both the main and data hard drives, logs attached.

    Uninstalled "Conduit Engine"

    When trying to uninstall the three java 6 updates I get the error:

    "windows installer service could not be accessed"

    I guess cos of running in safe mode.

    When running the combofix script, it opened the window extracting all the files (green text) but then hung there for a while, then a total black screen, then an error message something like:

    "cannot initialize login security process"

    then it rebooted. While rebooting I pressed F8, it hung for a long time on the driver loading screen, then it rebooted again and I could F8 back into safe mode. I didn't try a second time.

    Deleted everything in C:\WINDOWS\Temp
    When trying to access C:\Documents and Settings\ got the error:

    "C:\Documents and Settings\paul\Local Settings\TEMP Access denied"

    Didn't install new java since old updates not uninstalled (see above).

    MGtools ran ok, log attached.

    That's about it!
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, xor0.

    You didn't deal with the two objects that TDSSKiller detected. Please re-run it paying close attention to the instructions. * Select "Cure".
    Next - run this online scanner:
    Using ESET's Online Scanner

    * NOTE: This scanner can take awhile - please be patient.

    Now, again run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • ESETScan.txt

    How is your machine working now?
     
  7. xor0

    xor0 Private E-2

    The two objects TDSSKiller detected were only suspicious so cure wasn't an option. This time I deleted them instead.

    Eset only found the MGtools process, which I restored.

    The problem seems to be gone though, great! The computer is running fine as far as I can tell. Thanks very much.

    There are still a couple of things, like windows still doesn't find 'msconfig' and the problems MBRcheck found.
     

    Attached Files:

  8. xor0

    xor0 Private E-2

    I spoke too soon, unfortunately. An hour later, the same problem: Firefox becomes non-responsive which spreads to the whole computer. Back to safe mode...
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    There are more than a few manufacturers who use a non-standard Windows MBR (Master Boot Record).

    My thoughts are that your problems are with your Windows OS itself and not malware. *I'm conferring with my colleagues about your problems.

    dr.m
     
  10. xor0

    xor0 Private E-2

    OK, but I wonder how that happened. The computer has been working perfectly for years.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Does the same problem exist when you use Internet Explorer, when using an older version like Firefox 3.6.17?

    Using Add\Remove - please uninstall Microsoft Security Essentials for now. *Do not re-install it until instructed.

    Please re-download the latest TDSSKiller, over-writing your older version. Re-run it using the instructions below:

    TDSSkiller - How to run

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      [b]:filefind
      msconfig.exe[/b]
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please attach this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt


    Now, again run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file and the SystemLook.txt to your next reply.
     
  12. xor0

    xor0 Private E-2

    Using IE the lockup happened again after a little under two hours, so its not specific to Firefox.

    Microsoft Security Essentials uninstalled.

    Redownloaded TDSSKiller, it didn't find anything.
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Tell me if you are now able to use msconfig. What malware problems are you still experiencing?

    dr.m
     
  14. xor0

    xor0 Private E-2

    All the fixes ran ok. Computer has been running for 10 hours in normal mode so perhaps the main problem is fixed. However still getting the msconfig error:

    "windows cannot find 'msconfig'."
     

    Attached Files:

  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Let's first an online scan. Be patient as this scan may take 2 hours!

    Using ESET's Online Scanner

    Do you have a Windows Vista SP2 DVD?

    Please attach the ESETscanresults.txt to your next reply.
     
  16. xor0

    xor0 Private E-2

    Eset only found mgtools process as last time.

    The attachment manager says I have already uploaded this file in this thread and won't let me upload it even if I change the filename.

    My Windows Vista DVD is in a different continent right now unfortunately.
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Then re-boot your pc.

    Please attach that log to your next reply.

    *Please re-install your preferred anti-virus application now.

    :( If the above script doesn't solve your problems, I believe that you should seek help in our Software Forum as it is not a malware issue.

    dr.m
     
  18. xor0

    xor0 Private E-2

    OK still getting the msconfig error, should I post in the software forum, referencing this thread?

    Also since the combofix crash a few days ago I have two files called "desktop.ini" visible on the desktop that weren't there before, is there an easy way to get rid of them?

    Should I turn user account control back on?
     

    Attached Files:

  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :-o

    OK - I didn't give you the proper CFscript.

    Using again ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named C:\DeQuarantine_log.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Please attach the C:\DeQuarantine_log.txt
    These files are normally hidden from view - visible now because we had you set your machine to view hidden, system files & folders.
    Not yet, I'll give instructions when to do so.

    dr.m
     
  20. xor0

    xor0 Private E-2

    That seemed to do it - msconfig works again. Looks like all is back to normal, thanks very much.

    What went wrong and how can I stop it happening again?
     

    Attached Files:

  21. xor0

    xor0 Private E-2

    Are you still there?

    Should I turn UAC back on etc?
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If all is well... :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds