Computer slow some malware removed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by trisha, Apr 22, 2011.

  1. trisha

    trisha Corporal

    I'm not sure if this is going to require a reinstall or not. The computer was not booting into WindowsXP. It only got as far as the screen that shows F1 and F10. I finally got it to boot into WindowsXP by booting from a restore CD.

    I tried to go to a previous system restore point so I could avoid having to reinstall the system. Several attempts proved unsucessful at going back to a previous restore point.

    Now, when I boot the computer, I get the following error message:

    OsCheck has encounterred a problem and needs to close. There is the option to report to Microsoft. After closing the error window the computer finishes loading.

    I ran all of the programs in Read and Run First. I had to go to bleepingcomputer.com to download ComboFix because all I got was a blank page when I tried downloading it from your site.

    I could not run RootRepeal. Every time I tried to run it, the program would appear to freeze and then the Windows Virtual Memory is low message would appear. It would happen even after a fresh reboot.

    Malwarebytes and SuperAntiSpyware both found malware.

    Logs are attached. Thanks for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First off, you have two AV programs installed:
    Norton Internet Security
    Security Shield 2010

    You need to uninstall one of them, and my suggestion would be Norton!!

    Next, you need to, at a minimum, double your RAM:
    Code:
    Total Physical Memory    512.00 MB    
    Available Physical Memory    181.01 MB
    Now let's remove some junk:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\Tasks\Norton PC Checkup Setup.job
    C:\WINDOWS\system32\rezumatenoi.dat

    Let me know if you have any problems doing that.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. trisha

    trisha Corporal

    I think I am going to uninstall Security Shield because I think the registration has expired. Most likely I will install Avast! Free edition.

    As far as Norton is concerned, it does not appear in Add/Remove Programs and it does not appear in All Programs either; so there is no Remove Program option. The same holds true for Weatherbug, although it does appear in All Programs.

    Yes, I understand it needs more RAM;)

    Now let's remove some junk:
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Done

    I performed this action and it was successful.

    I didn't have any problems doing the above. However, when I rebooted the computer I still received the "OsCheck has encountered a problem and needs to close" error message. I was still able to complete the reboot.

    I ran the file. I never was prompted for the license agreement for TrendMicro HijackThis

    Then attach the below logs:

    * C:\MGlogs.zip

    Log attached

    Make sure you tell me how things are working now!


    I tried to boot the system in Safe Mode. The system loaded the drivers and then it stalled. I had to perform a hard boot. The computer then went into CheckDisk when it started before completing the normal boot.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. The issues at start up should be addressed in the software forum. Maybe the checkdisc run in safe mode will fix it. Maybe not.

    Norton is still showing in your logs, so run this:
    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    If you are going to install Avast, uninstall Security Shield 2010.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  5. trisha

    trisha Corporal

    After installing Avast! Free Edition I performed a Complete Scan including a boot scan.

    The scan found some files that were corrupted and I moved them to the Chest.

    It also detected two files infected with win32-killapp-w. One of these files was located in the C drive, the other was located in the Restore area. I moved those files to the Chest as well. I thought I would mention this to you before flusing the System Restore. I will wait for your reply.

    <snip> Removing un-necessary quote clutter
     
    Last edited by a moderator: Apr 22, 2011
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only way to remove infections in system restore files is to toggle System Restore. You should do that now and then re-scan with Avast. Let me know if you are still having malware issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds