badly infected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by PaGrrl, Mar 23, 2009.

  1. PaGrrl

    PaGrrl Private E-2

    Hi there. I have a few virus's I tried to get rid of the one I knew I had and that was the Win32trojan. But my computer still is not running correctly. It freezes up, IE closes itseld out. Takes forever to load up or load any program up. Reboots itself. Also when Im trying to surf the web the IE cant display the pages. Says Im not online which I am. This is what I know that I can give yas so far. Im running WinXp Home. I downloaded and ran finally fast.com And ran the scan and this is what its telling me. I didnt do anything at this point. please help me

    It tells me that I have 42 Class errors, 74 Missing shortcut errors, 35 Missing shared files errors, 2 Missing Application errors, 7 Missing help files, 111 Invalid file extension errors. I didnt buy the program so it wont give me a log but if there is another way to do it Id be more then happy to do it so you can see what all the errors are.

    And now here are the steps I folled from your website
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Get this JUNK off your PC immediately and never download stuff like this. Yes I know it is on commercials. It is still pure junk that you don't need and even if you purchase this, it is not going to fix any real problems that you have. In fact it would not have fixed all the problems fixed just be running our cleaning procedure and it is free. Uninstall PC SpeedScan Pro (which is what they install) immediately. Also uninstall Performance Center if it shows which they also install.

    While uninstalling things also uninstall Java(TM) 6 Update 3 which is an old out dated version.

    Also uninstall a-squared HiJackFree and a-squared Free which you don't need and will just add to your slow PC problems since you do not have any memory to spare.

    Also uninstall Ad-Aware which is a waste of system resources and SUPERAntiSpyware and Malwarebytes we asked you to install are far more superior applications.

    If the reason you started all of this is because your PC is slow, it is not due to the minor infections you had. It is due to the fact that you have one-quarter of the amount of memory in your PC that you really need to run Windows XP SP3 and all of your applications. Your logs show:
    You need 1 GB which is 4 x 256 MB. You cannot run your PC smoothly with such little free memory (81.84 MB) available.

    My steps be low will help remove a few other unnecessary items from startup, but you need more memory if you want your PC to run better. This is the first thing FinallyFast should have told you because there is nothing it could do for you other than making your PC go slower.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner to remove temp files!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 26, 2009
  3. PaGrrl

    PaGrrl Private E-2

    Yeah I know that I need to update the hardware in it. But thats not why I posted it. I just knew it was not running correctly thats why I was asking for help. I had that win32 trojan virus and was deleting it manually and wanted to make sure that I had gotten it all out and to make sure I didnt have anything else. I did follow your steps that you told me to do and here are the logs you asked for. So far Ie seems to be running better. I havent gotten an error yet. Keeping fingers crossed
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to do the below to get rid of the last of the junkware.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  5. PaGrrl

    PaGrrl Private E-2

    I got the success window pop up. So far Im not having trouble but at times I still get an error with IE like Im not on the internet.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to be more explicit and if this is not happening all the time, it is unlikely to be malware. If that is the case, you would be better off posting in the Software Forum. It's possible that it is residual effects from running finallyfast.
     
  7. PaGrrl

    PaGrrl Private E-2

    It was doing that before I downloaded the finally fast. But since Ive done all that youve told me and updated soemthings it dont seem to be doing it that much now. Thank you for all your help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds