Need another set of eyes on this one

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by axlmastr, Jan 5, 2012.

  1. axlmastr

    axlmastr Private E-2

    Spent some time cleaning but I'm missing something. Need another set of eyes to finish cleaning. Sony Vaio VGN-FJ170 Notebook with XP Home SP3 2GB DDR2 160GB WD Scorpio Blue (label on palmrest says it has a 100GB drive) given to me to fix because it would no longer boot. The teenage son of the owners tried to fix it after it was acting strange and slow. Owner claims the machine was taken to a retail place a year ago and they "fixed" it only to have it running slow after two weeks. I had so many of these machines that someone else fixed but this one is one of the worst.
    What I started with:
    Gets to splash screen and auto restarts after a brief BSOD about unmountable volume 0x00000ED. Two user environments- (1) used by middle-aged adult (2) used by teenager both have admin rights. CPU fan running won't go into safe mode or LKGC.

    What I did:
    Slaved it to a desktop with XP Pro SP3 and used the AVG 2012 Free, Malwarebytes, Super Antispyware, Spybot 1.62, TDSS Killer, HijackThis, Rootkit Revealer, CCleaner, Eset online scanner (though IE wouldn’t let me run it) etc. to clean it. I wanted to check the drive with Spinrite 6.0 back in the notebook to make sure the drive was good. Spinrite gave me an error and flagged the primary partition in red stating "Invalid Partition for Drive Size – This partition exceeds the size of this drive as defined by the system’s BIOS or BIOS extension”. At the end of my efforts, before this writing, I ran Spinrite anyway and corrected some disk errors. I was successful enough with the cleaning to get the drive to boot to a welcome screen. Had to restart and crack the password on the Owner user account so I could get in. Once at the desktop I turned off System Restore, uninstalled odd programs, show all files, and ran Combofix without internet connected (because internet was screwed) and it removed files and noted a folder of file in a temp folder. Each of the other programs except TDSS Killer HijackThis, Rootkit Revealer, removed objects either viral or malware both disconnected and connected to the internet. I didn’t see any Java installed and I removed Flashplayer. I cleaned out the unused startup keys from the registry. The machine got better and actually began updating through Microsoft Update and IE worked again. The machine is slow booting and still acts strange. I have a folder “Wlidui_WLIDSVC” with files in it in the All Users/Application Data/Microsoft/IdentityCRL/temp/. I have references to Porn movies in Owner/Application Data/dvdcss. The Memory Stick drive icon is missing in My Computer. The CPU fan revs every minute or so and CPU usage goes to 80-100% with nothing running. I have a Local Disk “Q” that is inaccessible. Event Viewer/Application has errors referencing Application Virtualization, CVHSVC, and MsiInstaller.

    The machine is much better than it was but needs an extra look over so let me know what you want me to do and post.

    Thanks
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. axlmastr

    axlmastr Private E-2

    Here are the logs per MG instructions
     

    Attached Files:

  4. axlmastr

    axlmastr Private E-2

    additional report attached
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest you pursue the rest of your issues in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds