Please could someone take a look

Discussion in 'Malware Help (A Specialist Will Reply)' started by Uli, Jan 15, 2010.

  1. Uli

    Uli Private E-2

    Hi

    I use windows XP SP3.

    My computer started having problems about three days ago.

    It started either when I installed NCH Software Switch Audio Converter or when installing Threatfire (within an hour of installing the audio converter). I downloaded Threatfire's installer to the external HDD M: but can't remember where I installed the Audio Converter installer. I have since uninstalled both programs.

    The problem is that when booting up my computer hangs on the last screen before the desktop appears. This only happens when I have the external HDD plugged in (M: and G: ).

    I have run through the 'read and run first' sticky and attached the logs.

    When running RootRepeal I got the following error message twice:

    Could not read the boot sector. Try adjusting the Disk Access Level in the Options Dialog.


    Otherwise all ran smoothly.


    Thanks for any help

    Uli
     

    Attached Files:

  2. Uli

    Uli Private E-2

    Hi

    The final log

    Uli
     

    Attached Files:

  3. Uli

    Uli Private E-2

    Really sorry to post again like this but forgot some info.

    The problem on boot up only happens if I actually turn my computer off and then on. If I simply click 'restart' everything runs fine.

    Thanks

    Uli
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First....ComboFix is reporting multiple AV and Firewall apps:
    AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
    AV: Prevx 3.0 *On-access scanning enabled* (Updated) {D486329C-1488-4CEB-9CC8-D662B732D901}
    FW: Filseclab Personal Firewall *disabled* {EB4DA513-3B0A-4FCB-86A7-F1243757EFF2}
    FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
    FW: PC Tools Firewall Plus *disabled

    Plus there are traces of AVG as well as Norton in your logs.

    You should uninstall:
    ThreatFire
    Filseclab Firewall or PC Tools Firewall since only one should be installed.
    Prevx 3.0

    Your logs are clean of malware, so I suggest that you post in the software forum for additional assistance.

    We can remove the above items if you so want assistance with that.



    Since you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
    Last edited by a moderator: Jan 17, 2010
  5. Uli

    Uli Private E-2

    Hi TimW and thanks for your reply.

    The only security apps I am running are prevx and now xp's firewall. (I had to uninstall pctools firewall because it blocked access to the web) so I don't know why all the others are showing up. I have used norton and AVG before now but not for some time.

    I will carry out the rest of what you say.

    I have only one question though and I hope it's okay to ask but doesn't the RootRepeal log say an MBR rootkit detection?

    Thanks for your help.


    Uli
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have a G:\ drive....which is what RootRepeal is reporting:
    Volume G:\
    Status: MBR Rootkit Detected!

    Your C:\ drive is where your MBR is, not the G:\ drive.

    And you are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds