Poss. MBR infection, SP3 netbook

Discussion in 'Malware Help (A Specialist Will Reply)' started by satrow, Sep 5, 2010.

  1. satrow

    satrow Major Geek Extraordinaire

    Hi folks,

    I'm working on a young relatives netbook, as usual, I don't hear of any problems until it stops working.

    Hardware fixed, I began a cleanup, removing old versions, obvious Spyware etc. but can't get a full anti-malware/virus scan to run. Closest I got was a quick Mbam scan (Vundo). PC just freezes part-way through any full scans (Avast!, SAS, Mbam and RR = bluescreen with mbr.sys 0xD1).

    I hope the attached logs are enough for diagnosis.


    Thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have SAS installed but you did not seem to run it. Please run it and attach that log. I am currently not seeing any malware in the rest of your logs. What issues are you currently having?
     
  3. satrow

    satrow Major Geek Extraordinaire

    Hi Tim,

    Ran SAS and the netbook froze as it has done with all full scans, no log. Quick scan came up clean.
    Currently running MSE, 1:05 minutes and it's still running, most other scans seem to trigger a freeze within 40 minutes.

    System logs show IPsec is crashing (the authentication service is unknown).

    Chkdsk comes up clean.

    The last Bluescreen was 0xD1, parameters e36d6000, 0x1c, 0x1, 1791e41d related driver, mbr.sys. Previous Bluescreen; 0x77 with 0x1, 0x0, 0x0, a7bd6cb8.

    Device Manager shows all as good, including hidden devices.

    Combofix installed the Recovery Console but it has a warning on boot; Unsupported Debug="do not select this" (and I can't see any Combofix log).
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There was no evidence of an MBR infection. And since I was not seeing any malware in the MGLogs, I think you are having an issue with the software on the system. What all have you tried to do? Have you tried a repair install?
     
  5. satrow

    satrow Major Geek Extraordinaire

    It's a netbook, still waiting on the CD to create a bootable USB stick to install from ...

    MSE finished and reported a BrowserModifier:Win32/Zwangi - 3 dregs in TIF, related to the Adware.QuestDns removed by the quick Mbam scan.

    I suspect that the nagware software, registry cleaners, etc. that I've uninstalled already have probably caused some damage.

    Oh yes, Avast! has become partially disabled since my original post, the webshield module, happened long before installing MSE (which usually works fine alongside it).
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I think you will need to get that CD to help figure out what is going on. As I said, there doesn't seem to be any malware causing these issues. Let's just clean it up since it looks like a software issue:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  7. satrow

    satrow Major Geek Extraordinaire

    Ok, thanks for the checkup and reassurance Tim.

    Cleanup completed, I had to drop Combofix into a cmd box and add '/uninstall', otherwise all went well.

    Ran a Repair install but all full scans, except MSE, cause a hang, either whilst scanning System Restore files or Windows/Installers/Cache. It's likely that something was damaged by the 3 Registry 'fixers' I removed.

    It's gone back; if it returns anytime soon, it'll be a straight nuke and reinstall :)

    Thanks again.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds