Malware or no Malware?

Discussion in 'Malware Help (A Specialist Will Reply)' started by dougdarby10, Dec 15, 2011.

  1. dougdarby10

    dougdarby10 Private E-2

    Hi, I have Windows XP Sp3 32bit

    i am not sure if I have malware? first I had an internet connection problem. Plus everytime I would restore my system, it would be an unsuccessful (unchanged) system restore for all the restore points.Then I had the internet connection fixed in the software section by ThisIsU. That got fixed but my antivirus (CA) deteted trojans and removed them and then malwarebytes detected different trojans and removed them. So I decided to delete them from SafeMode but no luck. Now my system would not enter any safemode or debugging mode. Also nothing (malwarebytes and CA Internet Security Suite) could get updated. Lastly the Windows website was telling me I need to install some highpriority updates but it was not showing on my taskbar and would not install from the Microsoft site. After running the Malware Removal tutorial steps, windows update came back (but did would comeback again and again after installing) and malwarebytes is able to update, but I think it is just illusions:confused by the virus. Now I am without CA antivirus because I uninstalled it to run Combofix. So I wanted to know if I had a virus before I reinstall CA (I need help from my internet providers for the humungous pain in the a** it is) I need to know if this virus exists! About the logs, I was unable to run Rootrepeal (freezes at initializing point for hours) so I dont have a log of that. I also read and followed the "Fixing Google Redirection/hijacking and other redirection problems" thread. So I have those logs too. I think they came back ok except MBRCheck saw an undiscovered or corrupted:confused mbr on my biggest harddrive (not my root drive).

    If u guys can help me, Thank you:)
     

    Attached Files:

    Last edited: Dec 15, 2011
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this an internal or external drive?

    Run TDSSkiller again and this time choose the below items to be cured:

    12:26:21.0640 1272 \Device\Harddisk2\DR2 ( TDSS File System ) - skipped by user
    12:26:21.0640 1272 \Device\Harddisk2\DR2 ( TDSS File System ) - User select action: Skip

    Then run another scan with TDSSkiller and see if they have really been fixed. If not try at least 3 more times to see if they get fixed.


    You definitely have some issues with Windows itself. For one your WMI service is not even running.
     
  3. dougdarby10

    dougdarby10 Private E-2

    Thanks for reply,
    All internal harddrives, and I choose skip because cure was not an option. do u want me to check again if cure shows up, or do u want me to delete when the problem shows itself(and cure is not available)?

    I knew the WMI service was not working when dealing with the internet connection problem, but I was not sure how important it was to get it back working(thought it was going to be too much work).
     
  4. thisisu

    thisisu Malware Consultant

    Hi,

    Yes choose Delete for the TDSS File System detection only. Leave the rest of the detections alone as they are not malware related.
     
  5. dougdarby10

    dougdarby10 Private E-2

    hey Thisisu, good to see u again!
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    You too ;)

    Latest log looks good. Wait for chaslang for further direction.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it may prevent many things from running that you may need or want some day. You may want see if it will start. See the below:

    http://msdn.microsoft.com/en-us/library/windows/desktop/aa826517(v=vs.85).aspx


    Delete the below files:
    C:\Documents and Settings\Kobe24\Local Settings\Application Data\phlxhr7v6qlt6qee4dcb1l078y5x
    C:\Documents and Settings\All Users\Application Data\phlxhr7v6qlt6qee4dcb1l078y5x
    C:\Documents and Settings\Kobe24\Templates\80802730a5d2


    Are you having anymore malware problems? The only additional item of concern is the below unknown MBR. It may or may not indicate an infection.
    Code:
    596 GB  [URL="file://\\.\PhysicalDrive1"]\\.\PhysicalDrive1[/URL]   Unknown MBR code
                SHA1: 639AC5CDF8A5CF3245975932C6A4215450A7B98F


    Oh and one more item I notice. You have some stuck entries in MSconfig to cleanup.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  8. dougdarby10

    dougdarby10 Private E-2

    yup, did all of that and everything seems to work.
    got a success message for the registry merge also.
    and not sure about the mbrcheck error. I ran it again and getting the same thing "unknown mbr code". should i "restore the mbr of a physical drive with a standard boot code" or should i just leave it alone?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having anymore problems, I would leave it alone. If you are still having problems, then I would recommend fixing the MBR. Important data should be backed up first.
     
  10. dougdarby10

    dougdarby10 Private E-2

    yeah, I'll do that. I'm probably gonna wait a couple days and see if I am still symptom free. Then I guess I'll do the last steps of the tutorial and remove the checking programs from my system.
    Thanks for all ur help Chaslang!!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you find that your problems have been resolved then the below final instructions can be followed.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds