Still have problem after doing read and run me

Discussion in 'Malware Help (A Specialist Will Reply)' started by Listenclear, Nov 15, 2009.

  1. Listenclear

    Listenclear Private E-2

    Hi, this is my first post on the forum but would really appreciate some help.
    I recently downloaded some kind of trojan which was affecting the C:\WINDOWS\system32\drivers\ndis.sys,MRT.exe and \svchost.exe files - according to AVG 8.5.

    I follwed the anti malware from the READ and RUN ME sticky and i thought it had cleared the virus. However, after some time i started getting the messages again so i followed the advice given to someone else getting the same messages.
    Please see - http://forums.majorgeeks.com/showthread.php?t=198379

    All seemed well but although i do not get any messages anymore i do still get the blue screen and my laptop restarts. This also happened after using MBAM the first time (incase thats important).

    I hope this message is not too lengthy but i wanted to give as mush detail as i could.
    I will attach all my logs from all the procedures carried out.

    Thank you for your time in reading this and for any help you can give.
     

    Attached Files:

  2. Listenclear

    Listenclear Private E-2

    The rest of the files
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is never a good idea to apply any fixes intended for a different computer!!

    Your logs are clean. However Combo is reporting a MBR infections. This may be a false report, however, lets do this anyway>

    You will need to boot to the Recovery Console that you have installed (perhaps when you installed ComboFix) to remove this infection.

    Now boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    Then boot back into normal mode.

    Now re-run COmbofix and attach the new log.
     
  4. Listenclear

    Listenclear Private E-2

    Hi and thanks very much for your reply, it is much appreciated.

    I tried to get into the recovery console but i get an error messgae saying the following file is missing or corrupt <Windows root>\system32\hal.dll
    So, following the link i tried to download XP SP2 using method 1 on this page http://support.microsoft.com/kb/900871/.
    After the transfer it said some files were missing and therefore i could go no further.

    I have been getting avg messages again saying that it is detecting a threat in system32\svchost.exe again.

    Is there anything i can do?

    Thanks again
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then retry doing the recovery console fixmbr command.

    Tell me if you are successful.

    If so, then re-run Combofix and also the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  6. Listenclear

    Listenclear Private E-2

    Once again thanks you for your time.
    However, it seems i cannot use the texed based system when i boot from the cd. What i assume is the text based system window only appears for about 2 seconds and is replaced by another window which gets me to select my language. That then leads me to only one option which is the erase the hard disc.
    I tried to install the recovery consle from the cd using the advice here http://support.microsoft.com/kb/307654 but when i type in the command in RUN it says it cannot find the file.
    Therefore i am unable to carry out the fixmbr command from the recovery console. :cry
    I fear i may be running out of options. Is erasing the hard disc looking like my only option?

    Paul
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sorry, I don't understand what you are saying.

    When you boot from the cd, it should first check your system files and then give you options to do a repair or to install. That repair option should take you to the recovery console. What exactly is happening?

    If you can't do this, then one option is to slave the drive to a different computer and then copy the hal dll into your sys32 folder. If you need instructions on doing that, please post in the software forum.
     
  8. Listenclear

    Listenclear Private E-2

    I dont understand what was happening either - i just was not getting any options other than cleaning the hard disc completely. No repair option at all.
    However, as of today i have sent it off to be fixed by someone who has been recommended.
    I thank you very much for your help and time - i just feel totally out of my depth and feel it's worth the investment of getting someone else to try and fix it now. I would have let you know sooner but it's been hard getting online without my laptop.
    Kind regards
    Paul
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. I hope they get you straightened out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds