Unprotected Laptop Crippled by Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by sergeantpuffer, Feb 18, 2014.

  1. sergeantpuffer

    sergeantpuffer Private E-2

    Greetings Geeks!

    I was helping a friend with their laptop which had obvious malware, but after doing an initial scan with Malwarebytes and removing objects, the virus/whatever it is clamped down and Windows 7 (x64) will no longer boot (gets stuck on the Welcome screen after entering password).

    I've gone through the read me, run all the scans and have attached the logs from each of those. I rebooted the laptop after performing what was requested, and was able to get through the Welcome loading screen. However, the desktop never loaded, I saw the mouse cursor for a moment before the display went completely black. Hard boot was required - the laptop will still run in Safe Mode with Networking, however.

    Please let me know if any other information is required. Any help is thoroughly-appreciated!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you get me the logs from running Hitman and RogueKiller?
     
  3. sergeantpuffer

    sergeantpuffer Private E-2

    The RK report is attached. I get the following when I try to attach the Hitman log:

    Your file of 414.7 KB bytes exceeds the forum's limit of 375.0 KB for this filetype.

    Is there another format I can save it as?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just rerun Hitman and have it fix everything. Then reboot and rescan and attach that log. Be sure to tell me what issues are happening.
     
  5. sergeantpuffer

    sergeantpuffer Private E-2

    I had to split the log as it was still too big for uploading here.

    I ran Hitman, eliminated files, rebooted, and when I logged into windows the screen was black with only the mouse cursor. Couldn't access task manager or anything, so I had to hard boot and run in safe mode again.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need to see it to tell what is going on.
     
  7. sergeantpuffer

    sergeantpuffer Private E-2

    Not sure why the logs weren't attached to my last post. Here you go.

    Thanks very much for your help.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Again, rerun it and remove everything it found. Then reboot and rescan and attach the new log.
     
  9. sergeantpuffer

    sergeantpuffer Private E-2

    I deleted all entries found, rebooted with the same result (type in windows password, desktop begins loading but never appears, the screen is black with only the mouse cursor and inability to access task manager).

    Attached is the new scan results. It said nothing was found. Is it possible the Malware damaged video drivers or something related to that in the registry...?
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Option1: Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    Option2: Enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  11. sergeantpuffer

    sergeantpuffer Private E-2

    Here's the log from that process.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is not the log I asked for.
     
  13. sergeantpuffer

    sergeantpuffer Private E-2

    Apologies, here's the right one.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, that didn't find much but lets go ahead and do a fix:

    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now see if you can boot normally.
     

    Attached Files:

  15. sergeantpuffer

    sergeantpuffer Private E-2

    Thought I'd replied with this. Busy week! Thank you.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me how things are running now.
     
  17. sergeantpuffer

    sergeantpuffer Private E-2

    I was able to get to the desktop for the first time since last Monday, but Windows explorer became unresponsive almost immediately. Desktop icons and taskbars, etc., failed to load. I was unable to get into the task manager, and was forced to hard-boot.

    Again, I'm only able to boot using safemode.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are going to have to pursue this in the software forum. I do hope you have installed some AV software now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds