erratic laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jan Scrivens, Mar 4, 2010.

  1. Jan Scrivens

    Jan Scrivens Private First Class

    Hello, please could someone look at the attached logs for me and see if they can identify a problem. my laptop is behaving erratically. I have read and worked through the 'run and read me first' instructions and attached the requested logs. I have attached the 'ComboFix' log to a reply to this thread, I hope that is OK.
    About 1 month ago I downloaded and installed 'Webroot security'. It clogged the laptop up totally with a CPU of 100% constantly. I have since removed it and reinstalled AVG free, but ever since then it has been running as if infected. I tried to install McAfee but it would not install as it said I still had Webroot on. I have removed it with 'Revo Uninstaller' and have even downloaded and run the official Webroot uninstaller, but it still shows as being on the laptop. could this be the problem?
    Also, my DVD player is not running correctly, the sound is 'tinny' and the picture 'jumpy'. This is the same whether I actually put a disc in the drive or play a recorded film from an external hard drive.
     

    Attached Files:

  2. Jan Scrivens

    Jan Scrivens Private First Class

    Here is the 'ComboFix' log to go with this posting. Thank you very much for taking the time to look at these for me. Jan
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are not having malware problems, we can do something to help get rid of the rest of webroot though. But for any remaining problems you will have to visit the software forum. :)


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    ArcSoft Connect Daemon 
    Webroot Client Service
    SecCenter::
    {77E10C7F-2CCA-4187-9394-BDBC267AD597}
    {63671000-11A2-46DD-BADD-A084CABCDEAE}
    Folder::
    c:\documents and settings\Rod & Jan\Application Data\Webroot
    c:\program files\Webroot
    C:\Documents and Settings\Rod & Jan\Application Data\Webroot
    C:\Documents and Settings\Rod & Jan\My Documents\My Webroot Restores
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  5. Jan Scrivens

    Jan Scrivens Private First Class

    Hello Kestrel 13, Thank you very much for replying to my question and for sending the instructions. I followed the instructions and dragged the CFScript into ComboFix on the desktop. I was asked to disable AVG but could find no way to disable it so decided to uninstall it instead. I used Revo uninstaller. It said it had a problem at first then said it had made a complete un-installation. When I went back to CF it still said AVG was there and may interfere but as I was sure it must be disabled I clicked to go ahead anyway. Then CF displayed a message saying “Current date is 2010-03-07 ComboFix has expired Click YES to run in REDUCED FUNCIONALITY mode. Click NO to exit. I clicked yes as I had no internet connection to be able to update CF. The blue command prompt box disappeared then, and nothing else happened. The CF l has gone off the desktop, but the CFScript.txt is still there. Could you please advise me what to do next. Also my CPU is keep running at 100% with ‘system’. If this is not relevant to your forum, please can you tell me which forum to try for help with this. It is really slowing down everything. Your help is very much appreciated. Jan
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you now followed final steps?
     
  7. Jan Scrivens

    Jan Scrivens Private First Class

    Hello, Thanks for reply. I'm sorry if my description of what happened is not clear. The instructions said to be sure to update CF but i did not have a connection so was unable to do this. Then, CF displayed a message saying “Current date is 2010-03-07 ComboFix has expired Click YES to run in REDUCED FUNCIONALITY mode. Click NO to exit. I clicked YES. The blue command prompt box immediately disappeared then, and nothing else happened. I do not know if what was supposed to happen DID happen as there were no indications of anything.
    I have not yet gone on to remove CF, but as the instructions are to remove it only if it is 'on the desktop' I did not know how to go ahead.
    Should I now go ahead from "If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)" ? Thanks, Jan
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ah, I see what you're saying now!

    Just locate any of the below and delete them. Run a search for Combofix and delete anything else related to it.

    • C:\ComboFix (folder)
    • C:\QooBox (folder)
    • C:\WINDOWS\nircmd.exe
    • C:\combofix.txt
    • C:\ComboFix-quarantined-files.txt logs that was created.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds