Viruses "removed" but my computer is still acting funny

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Wee.Bee, Jan 31, 2012.

  1. Wee.Bee

    Wee.Bee Private E-2

    Hi. :wave I am not very computer literate so please explain things as you would to a child.

    My problems started on Friday (1/27). My computer wouldn't come out of hibernate; the screen kept stopping at 'Resuming Windows'. Even when I turned the computer off and back on, it still went to that screen, which it shouldn't have. Later that night, randomly, it started up fine.

    The next day, I had the same problem. I had turned my computer off the night before and when I went to start it, it went to 'Resuming Windows' again and got stuck on the same screen. When it finally did start completely, my SuperAntiSpyware and AVG kept popping up that they had found tracking cookies in a place they had never found the need to warn me about before (or maybe they didn't usually find cookies there?). It was in the Documents and Setting's Network Services Cookies folder.

    I ran MalwareBytes and it found seven viruses. It said it quarantined them and deleted them (my first attachment is of that log so you can see which viruses they were). After that, I started looking on the internet to learn more about the viruses and see if I could find out how they got on my computer. That's how I found you.

    I read that one of the viruses can sometimes reappear when the computer is rebooted. I became paranoid about there still being something there. I wanted some way to be completely sure that my computer was fixed/safe (it was also running very, very slowly; like a snail). So, I did the steps on the "Read and Run Me First" on Sunday. Neither MalwareBytes nor SuperAntiSpyware found anything but I don't know about the other because I don't understand them. All the programs ran fine.

    Since then, my computer starts up fine but the longer I have it on the slower it starts running. Almost to the point where it seems frozen. I start to notice a difference after about 30 minutes to an hour. I don't know if there is still something on my computer or if my laptop has been permanently damaged in some way.

    Any and all help will be greatly appreciated. Also, sorry this is so long.

    Wee.Bee

    p.s. My laptop uses Microsoft Windows XP Media Center Edition, Version 2002 Service Pack 3
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We still need the log from running MGTools.....C:\MGLogs.zip.
     
  3. Wee.Bee

    Wee.Bee Private E-2

    Here are the last two logs.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have a faked partition that we need to remove.

    Please follow the instructions here:
    Using G-Parted to Repair Windows Partition Infections'

    You want to remove this partition:
    Partition Disk #0, Partition #3
    Partition Size 4.94 GB (5,305,305,600 bytes)

    Your OS partition is this one:
    TRUE Disk #0, Partition #1 55010672640
     
  5. Wee.Bee

    Wee.Bee Private E-2

    I'm not sure if I picked the correct partition to be flagged as "boot". When I was using GParted there wasn't a partition with the label True Disk #0, Partition #1 or with those numbers. I picked the largest file as it suggests.

    The other reason I'm not sure is when I used the Windows XP boot cd and I typed in 'fixmbr' the computer said "This computer appears to have a non-standard or invalid master boot record. FIXMBR may damage your partition tables if you proceed. This could cause all the partitions on the current hard disk to become inaccessible. If you are not having problems accessing your drive, do not continue. Are you sure you want to write a new MBR?"

    At this point I stopped what I was doing because I didn't want to make a mistake. What should I do?

    Thanks again
    Wee.Bee
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    See if you can boot to normal mode.
     
  7. Wee.Bee

    Wee.Bee Private E-2

    If booting to normal mode is restarting the computer without the boot cd, then that is what I did. Everything seems normal and it started up fine.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
     
  9. Wee.Bee

    Wee.Bee Private E-2

    Here are the logs.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like you didn't remove that partition.

    Go to the control panel / Admin. Tools / disc management and get me a screen shot of your partitions. Please.
     
  11. Wee.Bee

    Wee.Bee Private E-2

    There isn't a file called disc management in Admin. Tools. There's Computer Management. There's a disc management shortcut in that but it only shows my cd drive.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, under Computer management is disc management and it should show all your partitions.
     
  13. Wee.Bee

    Wee.Bee Private E-2

    There must be something wrong because it only shows my cd-rom drive.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now boot off of the newly created GParted CD.
    http://img717.imageshack.us/img717/6546/gpartedsplash01107.th.png
    You should be here...
    Press ENTER
    http://img819.imageshack.us/img819/7286/gpartedkeymaps.th.png
    By default, do not touch keymap is highlighted. Leave this setting alone and just press ENTER.
    http://img404.imageshack.us/img404/9840/gpartedlanguage.th.png
    Choose your language and press ENTER. English is default [33]
    http://img140.imageshack.us/img140/7958/gpartedgui.th.png
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    http://img32.imageshack.us/img32/1122/gpartedo.th.png
    According to your logs, the partition that you want to delete is 5,305,305,600 (5.3 MB)
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    http://img233.imageshack.us/img233/1533/gpartedsteps.th.png
    Now you should be here:
    http://img696.imageshack.us/img696/8471/gpartedsuccessclose.th.png
    Is boot next to your OS drive? According to your logs, your OS drive is the Local Fixed Disk C: NTFS 55010668544 sized partition.
    http://img194.imageshack.us/img194/7753/gpartedboot.th.png
    If boot is not next to your OS drive under Flags, right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    http://img196.imageshack.us/img196/3483/gpartedmanageflagsboot.th.png
    Now press the Close button to save these changes.
    Now double-click the http://img822.imageshack.us/img822/641/gpartedexit.png button.
    You should receive a small pop up like this:
    http://img88.imageshack.us/img88/8986/gpartedexitreboot.png
    Choose reboot and then press OK.


    Now reboot from the Windows XP Recovery Console CD and execute the following commands pressing ENTER after each:

    • fixmbr
    • fixboot
    • exit
    Once back in Windows...
    http://img707.imageshack.us/img707/6703/generalxpicon.gif Re-run another scan with MBRCheckand attach its latest log. (How to attach)
     
  15. Wee.Bee

    Wee.Bee Private E-2

    Here's the log
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry, but I also need a new MGLogs.zip.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  17. Wee.Bee

    Wee.Bee Private E-2

    Sorry it took so long to get back to you. Yesterday, my computer seemed to be fine. I didn't really do anything on it though. However, this morning, once I started it up, I discovered that my Intel Wireless was missing an executable file. The one I needed to connect to the internet. I repaired it in the add/remove programs. I have no idea why it disappeared. It was there when I turned the computer off last night. Or at least I assume it was since I was connected to the internet.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All looks good.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  19. Wee.Bee

    Wee.Bee Private E-2

    Thank you so much for all of your help. You were so fast! Seriously, I can't even begin to describe how grateful I am.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds