Computer Freezes, IP Address Gets changed, Need Help with Malware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hannamax, Jul 17, 2013.

  1. hannamax

    hannamax Private E-2

    I have a dell laptop running Windows XP home edition. I run Avast with Paid Malwarebytes version. This morning I couldn't add a driver because I didn't have rights?? I am the administrator. No I am able to run and add driver since I am connected to internet. My laptop freezes and I have to reboot, Windows explorer was crashing in safe mode (NOT IE). My IP address changes to different IP range at home for wireless network 192.167.15.115 is my network and when I look to see my connection it is changed to 192.168.1.x which I definately did not do. Computer seems to run better when connected to internet as though something gets activated and it works. I have run all the preliminary scans and have attached the files. I use Teamviewer and am worried this malware maybe be on 3 other home machines. Please help!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue, you need to use MSCONFIG to put the machine into normal start up mode.


    Re run Hitman and have it delete Potential Unwanted Programs.


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this 1 detection:
    • [HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Rerun Hitman and RogueKiller again, just scans, and attach the resulting logs please.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. hannamax

    hannamax Private E-2

    I was able to run but had to reboot. Worst freeeze was after running second RogueKiller. I got the log but then pc froze. Still getting Windows explorer errors occassion. See attached reports you requested. I had 3 Rkiller files so I know the final is correct but not sure if I sent one the right first one will send in separate post
     

    Attached Files:

  4. hannamax

    hannamax Private E-2

    here is other file
     
  5. hannamax

    hannamax Private E-2

    still getting internet explorer freezing
     
  6. hannamax

    hannamax Private E-2

    I included the reports you wanted. It is very strange that my post is not in my user control panel. I have to search to find it?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you rescan now again with Hitman does it find anything?

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Please save the work in your browsers before proceeding.
    • Double-click JRT.exe to run (Vista/7 right-click and select Run as Administrator)
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Please attach JRT.txt to your next message. (See: HOW TO: Attach Items To Your Post )
     
  8. hannamax

    hannamax Private E-2

    No threats when I ran hitman. I attached both files requested. My computer takes forever to boot and particularly on home network. Getting to internet connection takes a long time as well. It almost seems like laptop is taken over briefly since homescreen refreshes. Then I couldn't even load this page at home to reply to you so I brought laptop to work.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I suggest you post about any remaining issues in the software forum. :)

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds