Computer repeatedly hanging and cannot complete malware/cleaning procedure

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ark07, Aug 25, 2012.

  1. Ark07

    Ark07 Private E-2

    Hi, my computer has been infected by malware/spyware.

    I started Vista and Win 7 Malware Removal/Cleaning Procedure today. There were no problems when I ran the Rogue Killer application. Then, I ran the Malwarebytes-Anti Malware scan and successfully removed the objects which it detected. I restarted my computer when prompted to restart after the scan. But now when I login to my User-account - I get a dll error (I have posted a screen-grab as an attachment) After I click ok/cancel the desktop screen hangs/freezes. How do I finish the Malware/spyware cleaning procedure? I would appreciate any help. Thanks in advance.

    ps: My computer runs on Windows 7 Ultimate OS & I have ESET smart security anti virus.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to complete the cleaning procedures in safe mode at all?
     
  3. Ark07

    Ark07 Private E-2

    I have now been able to successfully complete the Malware Removal/Cleaning Procedure. I think I have removed all the threats using malwarebytes. A few 'threats' were detected by Hitman Pro and I have ignored them as per instructions and I have attached all the logs.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this 1 detection:
    • [SUSP PATH] HKLM\[...]\RunOnce : ClearTemp ("C:\Users\ANOOPK~1\AppData\Local\Temp\hsperfdata_temp\~temp~clear~68222.exe" * cleartemp) -> FOUND
    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.


    Does this folder exist in this location?
    C:\Users\Anoop Kashyap\AppData\Roaming\Program Files

    Can you attach the log from MalwareBytes where it deleted items and you started having trouble?

    Re run RogueKiller - just a scan and attach log.
     
  5. Ark07

    Ark07 Private E-2

    I ran Rogue killer and deleted the object you mentioned and have attached RKreport[2].txt. I reran the Rogue Killer and attached it's report RKreport[3].txt below. I have also attached the log from MalwareBytes where it deleted items.
    No. No such folder exists now.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It did not remove anything that should cause problems with logging into your user account. Are you still having trouble when you try and log into it now?

    C:\Users\ANOOPK~1\AppData\Local\Temp\hsperfdata_temp <--- Are you able to delete this folder?
     
  7. Ark07

    Ark07 Private E-2

    No. I should've mentioned in my earlier reply that I don't get that error now when logging in but my computer froze/hanged a couple of times when I logged in after I had put in 'sleep mode' and then I had to manually restart.
    And No, I can't remove that folder. It reappears almost 10 secs after I delete it.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Users\ANOOPK~1\AppData\Local\Temp\hsperfdata_temp
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Has it gone now?
     
  9. Ark07

    Ark07 Private E-2

    No. That folder is still there. I ran the OTM scan and have attached the log. BTW I noticed another thing today - my computer freezes when I open 2 browsers simultaneously.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Why would you want two browsers open at the same time? Let's focus on getting rid of this.

    Run Ccleaner, reboot, Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. Ark07

    Ark07 Private E-2

    Okay. Done.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  13. Ark07

    Ark07 Private E-2

    Done. Why is this malware so hard to remove?
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well at first I was not convinced it was malware. You do not use any temporary file cleaning software that runs on start up, or never have, do you?

    C:\Users\ANOOPK~1\AppData\Local\Temp\hsperfdata_temp\~temp~clear~46856.exe <--- You *might* be able to rename this file to something else. For now try to rename it to abc.com so we know what it is. Are you able to do this? If so, let me know. If NOT... run the below.

    [​IMG] For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  15. Ark07

    Ark07 Private E-2

    I was able to rename the file but a new ~temp~clear~46856.exe appears a few seconds later.
    and No, I have never used a temporary file cleaning software that runs on start up. I always delete temporary files using disk clean-up.
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue with my other instructions then please.
     
  17. Ark07

    Ark07 Private E-2

    I have followed your instructions and attached the log. BTW I noticed another thing when I plugged in a flash drive to my pc. After I clicked 'Open Containing folders' in autoplay options, 2 .exe files appeared which were not there in the flash drive before. I scanned them using malwarebytes but it did not find them malicious - I'll attach that log too.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.

    -------------------------------

    Run FRST normally now like you did the first time, just a scan, and attach log.
     

    Attached Files:

  19. Ark07

    Ark07 Private E-2

    Done. The folder still exists.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    But the registry value does not I don't think. Try and delete the folder now. Hmm this is strange. Also... Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip
     
  21. Ark07

    Ark07 Private E-2

    The folder still reappears after I delete it but it is empty and does not contain ~temp~clear~46856.exe file.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then that is just fine. :) Everything else okay?
     
  23. Ark07

    Ark07 Private E-2

    Unfortunately all is not ok. :( My PC still hangs.. especially when I log in from 'Sleep mode' and my antivirus just detected a new threat. I'll attach a screen grab of my quarantine and a log file.
    ps: I want to thank you for your time & patience in helping me.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    All I can say is re run a new scan with your AV and see if it finds anything else.
     
  25. Ark07

    Ark07 Private E-2

    I scanned my computer again yesterday and the AV found 5 infections. I'll attach the log.
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Mostly stuff that I removed, and is being held in quarantine folders. ;) Any other problems? (I don't mean the hanging PC I cannot help with that)
     
  27. Ark07

    Ark07 Private E-2

    No other problems. But why do you think my computer hangs repeatedly and what can I do that can stop it? In the last hour or so, it froze thrice.
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can ask the guys and gals in the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  29. Ark07

    Ark07 Private E-2

    Alright. Thanks for all the help. :)
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds