x22 virus help needed please (gasfky rootkit?)

Performance, hardware, software, general buying and gaming discussion..
Post Reply
Message
Author
blink
Sophomore Member
Posts: 130
Joined: Sun Oct 05, 2008 9:06 am
Location: Manchester England

x22 virus help needed please (gasfky rootkit?)

#1 Post by blink » Wed Jan 26, 2011 6:57 pm

Hi Guys i have posted this in the general section as this query isnt really machine specific.
I recently purchased a couple of rather heavily virus/spyware infected x22s for a reasonable price (again i must stop this) with the intention of cleaning up & selling one on & perhaps keeping the other as maybe a dual boot xp linux machine for myself?

Now heres the rub. I was going to do a clean intall of xp on them both but i cant. When i try to enter bios the padlock symbol comes up, i just press enter & can get into bios but i am not allowed to change any settings. Unfortunately on boot both removeable devices & CDROM have been disabled so i only have hard drive & network boot available.
So i guess no options of a clean install?
I have now cleaned up both machines the best i can using a few combinations of anti virus/spyware software, defragged, wiped previous data, cleaned registry et with ccleaner blah blah & they are both running quite nicely with the existing xp they have on the hard drives.
One seems totally clean from any infection now but the other still has a very pesky gasfky rookit virus that i am having trouble clearing & avast finds but cant fix.
I am starting to think that the only way of clearing it maybe by manually deleting its hidden registry files & any other places it may have spread to but am really very wary about playing around in the registry as i have never done this before & if it goes wrong, obviously i probably cant do a fresh install!
I have tried googling for solutions but havent found a straight forward fix & i would certainly really appreciate any ones help who has more experience with such matters that could perhaps offer some guidance on what my best way forward would be.
To be honest I doubt i will keep any machine now unless there is a solution to the bios limitation, however if i do sell i would certainly like it to be clean & trouble free for the next owner, I could easily just put microsoft security essentials on it which shows the machine as clean, maybe its a false positive in avast? But to be honest i would really like to get to the root(kit) of the issue (sorry! :D ) I couldnt sell something in good conscience that may possibly have a problem.
Many Thanks for any help.
Many Thanks for any advice, shared knowledge & wisdom is a wonderful thing.
1st Thinkpad T42 (Old 570,600e, A21,X31,X40,X41) Current X60s, T60, Z61T,X200

Neil
Senior ThinkPadder
Senior ThinkPadder
Posts: 2915
Joined: Sun Aug 07, 2005 5:41 pm
Location: Paragould AR USA

Re: x22 virus help needed please (gasfky rootkit?)

#2 Post by Neil » Wed Jan 26, 2011 7:20 pm

I would pull the hard drive and either put it in another computer or a USB enclosure and wipe the drive clean with an application that will write zeros to it. Then if you want to install a new OS on it, Linux is fairly friendly about installing on one computer and then booting on another, some distros more so than others. Or, if you want XP, then I would make the drive bootable with a Win98 boot disk and copy the i386 folder to the drive. Then you could put it back in the X22, boot up, and install XP from the hard drive itself.
Last edited by Neil on Wed Jan 26, 2011 7:42 pm, edited 1 time in total.
Collection = T500 - R400 - X300 - X200 - T61 (14" WXGA+) - T61 (14.1" SXGA+) - T60 (15" SXGA+) - X40 - T43p - T43 - T42p - A30P - 600E

billp117
Senior Member
Senior Member
Posts: 945
Joined: Thu Dec 21, 2006 2:19 pm
Location: Kirkland, WA

Re: x22 virus help needed please (gasfky rootkit?)

#3 Post by billp117 » Wed Jan 26, 2011 7:25 pm

The bios is password protected...unless you can get the password from the previous owner you will not be able to make any significant changes.

Can you remove the hard drive and install it on another ThinkPad that is not password protected? That would give you the ability to remove the hidden partition...it does not solve your bios problem. Or perhaps there is some software that will give you the same ability using a USB adapter. Someone else on the forum may have some ideas.

I cannot help you on the gasfky problem and it looks like that question has been asked by a lot of people. Your problem is complicated even further because your bios is locked.

edit...Neil has you on the right track. Thanks
Billp117, Kirkland, WA

T410-SSD, X200, X100e, 2-T61, T60, 3-T43, T43p, TR451, X41t, X21, 701c

wackyD
Sophomore Member
Posts: 145
Joined: Sat Jan 09, 2010 9:23 pm
Location: Atlanta/Barnesville, GA

Re: x22 virus help needed please (gasfky rootkit?)

#4 Post by wackyD » Wed Jan 26, 2011 8:06 pm

Have you tried Malware Bytes? How about the Norton Power Eraser?

I don't think I have dealt with the gasfky myself.


I have found pulling the drive and cleaning with another machine to be the only option in a numberof cases of late.

A word of caution - don't try to clean it with your primary machine, if you have the option. I had the activation section of XP wiped amoungst other things with my last salvage work. Fixed theirs, lost mine. Not good explanation and I may have my self to blame if I missed a check box, but you do run the risk of infecting the host machine when you work on the other drive in an enclosure.


Daniel
Daniel
T420 (4236-BR7) Win 7
X201 (3626-GQ1) Win 7
X301 (2774-CTO) Win 7
X200 (7458-WA2) Win 7 (needs to go)
X61 (7673-4NU) Win 7 (needs to go)
Parts pile of T60/T61/X61t

GACrabill
Junior Member
Junior Member
Posts: 402
Joined: Thu Jul 22, 2004 11:26 pm
Location: Indiana

Re: x22 virus help needed please (gasfky rootkit?)

#5 Post by GACrabill » Wed Jan 26, 2011 10:56 pm

blink wrote:One seems totally clean from any infection now but the other still has a very pesky gasfky rookit virus that i am having trouble clearing & avast finds but cant fix.
Have you tried using the free TDSSKiller rootkit cleaning tool from Kaspersky ?
http://support.kaspersky.com/faq/?qid=208283363

It is a simple executable that can be run from a USB stick.

It has fixed two problems for me in the past that nothing else seemed to be able to fix.

There are a number of serious viruses, rootkits, and malware which cannot be found and fixed if the hard drive is connected as a 2nd drive on a different PC.

If the infected PC will boot into Windows, use the "portable" versions of CCleaner, SuperAntiSpyware, and TDSSKiller to do some cleaning before trying to "install" clean-up tools.

frankausmtank
Freshman Member
Posts: 111
Joined: Thu Aug 03, 2006 5:06 am
Location: Berlin, Germany

Re: x22 virus help needed please (gasfky rootkit?)

#6 Post by frankausmtank » Thu Jan 27, 2011 5:13 pm

Don't know about the x22, but on my t60, F12 during startup brings up a boot device selection regardless of the bios boot order.

RealBlackStuff
Admin
Admin
Posts: 17512
Joined: Mon Sep 18, 2006 5:17 am
Location: Mt. Cobb, PA USA
Contact:

Re: x22 virus help needed please (gasfky rootkit?)

#7 Post by RealBlackStuff » Thu Jan 27, 2011 5:56 pm

@blink: check your PM
Lovely day for a Guinness! (The Real Black Stuff)

Check out The Boardroom for Parts, Mods and Other Services.

blink
Sophomore Member
Posts: 130
Joined: Sun Oct 05, 2008 9:06 am
Location: Manchester England

Re: x22 virus help needed please (gasfky rootkit?)

#8 Post by blink » Sat Jan 29, 2011 6:40 pm

Many Thanks for you all your input & suggestions guys its appreciated, I seem to have yet another problem with it now! I decided to take the extra memory stick out & when using just the onboard 128mb it normally just about boots windows & then bsods & says irql_not_less_or_ equal, some general troubleshooting blurb, error codes & then does a physical memory dump! Any Ideas

.Neil & billp you have certainly given me some food for thought, I am not very au fait with making drives bootable & technical stuff but i will certainly look into that if i cant clear the virus by traditional means. I think tthe installing on another machine way may be how the current version of xp was installed as floppy is listed in device manager & obviously their isnt one on these. The only definate working TPs i have are sata now, I have a couple of old 600s & a 570 knocking around but im pretty sure they have been left that way for so long was due to them all having issues.
wackyD yeah malwarebytes was my first port of call but thanks for the heads up on Norton i may have to look at that. GaCrabill, I have tried a couple of anti Rootkits but i will definately give the kapersky one a bash next as im sure i read this virus was based on tdss? Fingers Crossed many thanks for the tip & advice on running portable apps thats great. Frank i tried f12 & the options i get are hdd & Iba, i have to confess i dont know what iba is but thanks for the suggestion.
Cheers again for the pm RBS
Many Thanks for any advice, shared knowledge & wisdom is a wonderful thing.
1st Thinkpad T42 (Old 570,600e, A21,X31,X40,X41) Current X60s, T60, Z61T,X200

Mike Blake
Sophomore Member
Posts: 248
Joined: Sun Mar 30, 2008 4:28 pm
Location: Warwick, Rhode Island

Re: x22 virus help needed please (gasfky rootkit?)

#9 Post by Mike Blake » Wed Feb 02, 2011 4:31 am

These older posts may help you with part of your problem:

"IRQL _NOT_LESS_OR_EQUAL"
http://forum.thinkpads.com/viewtopic.php?t=41566

"W700 - IRQ_NOT_LESS_OR_EQUAL STOP 0x0000000A BSOD"
http://forum.thinkpads.com/viewtopic.php?f=48&t=78994

"New Ram, new problem (beep codes)"
http://forum.thinkpads.com/viewtopic.php?f=2&t=89294

In brief: often bad RAM, RAM slot, or a recently-installed driver that's bad.
--Mike Blake

blink
Sophomore Member
Posts: 130
Joined: Sun Oct 05, 2008 9:06 am
Location: Manchester England

Re: x22 virus help needed please (gasfky rootkit?)

#10 Post by blink » Sat Feb 05, 2011 10:33 am

:D Good News everything seems fine now!!
Many Thanks to all who contributed in trying to help me resolve this. An extra Special Thanks & a cyber Pint to GACrabill as it was the TDSSkiller that really got to the root of the problem so to speak. After running this all the remaining remnants of it on the machine were found (7 i think) 6 were deleted & the last bit put into a state that could be cleaned & eliminated through Avast.
What a great little program!! Thanks again.

Mike, Some great info there about RAM & IRQs Thank you much appreciated.
After the virus was eliminated the machine no longer bsods & now works albeit at less than a crawl using the onboard 128mb, but rather decently with an additional 256mb added.
Just ran memtest from within windows for 3 hrs & RAM comes up clean.
So fingers crossed it is ok now?
Cheers
Andre
Many Thanks for any advice, shared knowledge & wisdom is a wonderful thing.
1st Thinkpad T42 (Old 570,600e, A21,X31,X40,X41) Current X60s, T60, Z61T,X200

RealBlackStuff
Admin
Admin
Posts: 17512
Joined: Mon Sep 18, 2006 5:17 am
Location: Mt. Cobb, PA USA
Contact:

Re: x22 virus help needed please (gasfky rootkit?)

#11 Post by RealBlackStuff » Sat Feb 05, 2011 11:29 am

Even with the max. 512MB RAM that machine will be slow.
It would run better with Windows 2000/SP4, or Windows FLP (= minimalist XP) if you can find it.
Lovely day for a Guinness! (The Real Black Stuff)

Check out The Boardroom for Parts, Mods and Other Services.

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Thinkpad - General HARDWARE/SOFTWARE questions”

Who is online

Users browsing this forum: No registered users and 2 guests