Virus or Dying HD?

Discussion in 'Malware Help (A Specialist Will Reply)' started by rfurnace, May 16, 2010.

  1. rfurnace

    rfurnace Private E-2

    To whom it may concern,

    First, I want to thank all of you at Major Geeks for making valuable information available to the common user. Your site helped me resolve 2 different issues within the past year and a half. Unfortunately, I have encountered a new problem that I haven't been able to resolve. About a week ago, my PC started running pretty slow. It seemed like it was bogging down. Then about 3 days ago, my wife and daughter both mentioned that they were encountering problems with Facebook and other online sites/games.

    Since their Internet usage is questionable at best, I assumed one of them introduced a virus on our PC. Therefore, I followed the steps listed in the Malware Removal Guide, Win XP Cleaning Procedure. I followed every step exactly. The only tool that would even execute was "MGTools". So, I have the log from that app but none of the others. I included a MS Word doc that contains screen shots of the various error messages I encountered when attempting to launch each of the other executibles in the instructions. With that said, I am able to run other executibles such as IE and Word.

    Does this sound like a virus or a HD on its last leg? Please advise.

    Thanks again!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Tell me exactly what happens with trying to run>
    SAS
    MBAM
    ComboFix
     
  3. rfurnace

    rfurnace Private E-2

    SAS - I execute the program (file located at C:\ root directory) and receive a message that says:
    Open File - Security Warning
    The publisher could not be verified. Are you sure you want to run this software?
    I click on "Run".
    A progress window opens to show extraction of file, then immediately another message opens stating "Corrupt installation detected, check source media or re-download.
    I click "OK" and the app closes.
    I have tried downloading multiple times from multiple locations.

    MBAM - I execute the program (mb.exe located at C:\ root directory) and receive the same message that says:
    Open File - Security Warning
    The publisher could not be verified. Are you sure you want to run this software?
    I click on "Run".
    Immediately, a message appears stating:
    Error
    The setup files are corrupted. Please obtain a new copy of the program.
    I click "OK" and the app closes.
    Again, I attempted multiple downloads from multiple locations.

    ComboFix - I execute the program (ComboFix.exe located on desktop) and receive the same message that says:
    Open File - Security Warning
    The publisher could not be verified. Are you sure you want to run this software?
    I click on "Run".
    A progress meter appears, then a message appears stating:
    Error
    Some installation files are corrupt. Please download a fresh copy and retry the installation.
    I click "OK" and the app attempts to close. There is still a ComboFix window on my task bar as well as the progress meter on my desktop. Those 2 items are frozen.
    Again, I attempted multiple downloads from multiple locations.

    So, I can't tell if the files are actually corrupt or if some type of malware is causing the issue.

    BTW - I REALLY appreciate your help!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried running them in safe mode? You may also try renaming ComboFix to 123.com and see if it will run.

    Try running an alternative scan from HERE.

    Try this one first:
    Kaspersky Virus Removal Tool
     
  5. rfurnace

    rfurnace Private E-2

    I tried running them in Safe Mode and still received the messages stating that the files are corrupt. Then, I tried running Kaspersky and received a similar "files corrupt" message. Finally, I tried renaming ComboFix to "123.com". That actually got the program to load. I received a message stating updates are available, would you like to download. I selected "Yes". The files downloaded and I received another "files corrupt" type message.

    On another note, I also took my PC to a local repair shop. After $170, the technician said he removed a few viruses. My wife picked up the PC, so I don't have details on what he detected and removed. With that said, I am still receiving the "files corrupt" message any time I attempt to run an executible that installs software on my hard drive.

    Is it possible that the virus(es) are gone, but some Windows system file is damaged/corrupt, and that is what is causing the "files corrupt" messages? Please advise.
     
  6. rfurnace

    rfurnace Private E-2

    Another interesting note is that for any file I download, I receive a Windows alert stating that the file is from "Unknown Publisher". I wonder if that could be related to the "files corrupt" message I am encountering?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    For $170 it should have come back in perfect working order!! As I had previously stated, I wasnt seeing any malware in the MGLog.zip, so I doubt that they removed anything that either SAS or MBAM wouldn't have removed if you could have gotten them to run.

    At this point, you need to post in the software forum to pursue this further. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds