Virus-gone?

Discussion in 'Malware Help (A Specialist Will Reply)' started by jennifergib7, Dec 18, 2012.

  1. jennifergib7

    jennifergib7 Private E-2

    4 days ago Malware Bytes detected a virus. I thought I had removed it. This computer has been out of service for a while, and I just replaced power supply. Also cannot provide virus info found because I had remove Malwarebytes to install Avira Antivirus.

    My issues are IE and FF are freezing up and staying connected to the internet via cisco linksys AE1000 wireless N adapter. Constantly having to repair the connection.

    Came to your website and followed the 'READ AND RUN'. I have only run the RogueKiller. I did the scan only, did not fix. See attachment. Can you tell me where to go from here?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    You need to run ALL of the READ & RUN ME and then attach the other 4 requested logs so that we can properly help you.
     
  3. jennifergib7

    jennifergib7 Private E-2

    Okay, ran the MB, TDSS, then HitmanPro. The first two scans showed nothing and I have the logs, however ran HitmanPro and blue screen came up 'Problem has been detected...windows shutdown' I cannot read the full screen because it's off-centered. I can read:

    'NEL_STACK_INPAGE_ERROR'
    and also 'STOP: 0x00000077 (0xC0000015, 0xC0000015, 0x00000000, 0x18897000) PHYSICAL MEMORY DUMP COMPLETE....etc.....

    Left @ blue screen...waiting for further direction.
     
  4. jennifergib7

    jennifergib7 Private E-2

    I will be away from this pc until Jan 9. I will be back to post the logs then. I sincerely hope you can come back to help me. Thanks
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. jennifergib7

    jennifergib7 Private E-2

    I eventually got the blue screen of death. This desktop was down for over 3 weeks. Found a download on cnet for EASEUSPartition recovery software and got myself back in windows so that I could finish the reports. I hope you are still there. Also I could not find the hitmanpro report.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're BSOD still may not be due to malware. The only thing that remains to be done is to cleanup a hosts file hijack that will redirect you to the Ukraine and will will empty your temp folders too. And then will will run a tool for repairing Windows to see if it helps.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
    O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
    O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
    O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
    O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
    O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
    O1 - Hosts: 217.20.175.74 www.reviews.download.com
    O1 - Hosts: 217.20.175.74 reviews.download.com
    O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
    O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
    O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
    O1 - Hosts: 217.20.175.74 reviews.pcmag.com
    O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
    O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
    O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
    O1 - Hosts: 217.20.175.74 reviews.reevoo.com
    O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
    O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
    O1 - Hosts: 217.20.175.74 www.reviews.techradar.com
    O1 - Hosts: 217.20.175.74 reviews.techradar.com
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\WINDOWS\Temp\*.*
    C:\Documents and Settings\Bricerific\Local Settings\Temp\*.*
    
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.
    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. jennifergib7

    jennifergib7 Private E-2

    Here they are. I still cannot reboot to windows. I have to insert the usb sandisk with the EaseUSPartition.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to post in the Software Forum about this as it is not due to malware. Or try system restore or you will have to reinstall. You have system restore points that go all the way back to Dec 19.

    In the last fix did you run the part with C:\MGtools\analyse.exe ? None of those items were fixed. Was your antivirus shutdown and did you have browsers closed when trying the fix. While this has nothing to do with your startup problem, it is an issue that will redirect you to the Ukraine.
     
  10. jennifergib7

    jennifergib7 Private E-2

    Its possible my anti-virus was on, but I don't think so. I re-ran but I didn't see those items there.
     
  11. jennifergib7

    jennifergib7 Private E-2

    I'm having trouble attaching ziplog. It says I have already attached it. I thought this one would be new..?
     
    Last edited: Feb 3, 2013
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to rerun C:\MGtools\GetLogs.bat to create a new log.
     
  13. jennifergib7

    jennifergib7 Private E-2

    Sorry, overlooked that. Here it is.
     

    Attached Files:

  14. jennifergib7

    jennifergib7 Private E-2

    Right after I submitted my last report, it crashed again and I could not get windows to boot up. It just so happened UPS delivered my CD for windows xp reinstall today, so I gave it a try. I started with a clean install and got all the way to where Win XP was loading on the machine and it crashed again. I guess I am going to have to order a hard drive.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How do you know it is your hard disk? It could be something else. Like memory. You may want to try posting in the Software or Hardware Forum for some help.
     
  16. jennifergib7

    jennifergib7 Private E-2

    Thanks and I will do that.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. .
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds