having issues with windows explorer after malware removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by brandon3420, Jun 28, 2010.

  1. brandon3420

    brandon3420 Malware Magnet

    Hello MajorGeeks,
    Yesterday my sister contracted some nasty malware by clicking on a fake link or what have you. I think it was AV Security Suite, or something along those lines. I immediately ran MSE and then Malwarebytes Anti Malware. This did not make a difference so I system restored to a few days earlier. I was still having problems so I system restored back to the most current restore point.

    Problems at this time were:
    Windows installer issues. Could not install or uninstall any programs
    Drive access or windows explorer problems (when I click on my computer it searches forever and either takes a long time or the window freezes.)

    I then went through the cleaning procedure for windows xp: I had to run SAS portable as I couldnt install anything and malwarebytes was already installed. Everything went as planned aside from the Java uninstalling/installing. After completing the procedure I was able to install again so I proceeded to complete the java step. I still however having the windows explorer issue. It searches forever and the pc gets real slow. it dosnt seem to happen until I goto My computer... and after that folders and files open quickly as usual. Odd problem but perhaps you all can help me out.. I will attach my logs.. Thank you very much
     

    Attached Files:

  2. brandon3420

    brandon3420 Malware Magnet

    here is my malwarebyes log
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your mglogs.zip was missing some logs. Let's have you do this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  5. brandon3420

    brandon3420 Malware Magnet

    Thank you very much for the prompt reply. Not sure what happened but here is the log as I dont believe I received any error messages.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are about 6 months out of date with your version of MGtools. You must not keep old copies around. You need to always download and use the current version given in the cleaning procedure. Delete your current, C:\MGlogs.zip file. Then please download the current version of MGtools and run it. Then attach the new MGlogs.zip file.

    However ComboFix may have already fixed your problem. Are you still having any issues?
     
  7. brandon3420

    brandon3420 Malware Magnet

    here are the files from the new mgtools

    the problem with windows explorer is still incredibly slow. 30 seconds plus to load files and folders
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The issues that you now have should be worked out in the software forum. As Chaslang pointed out, it looks like combofix healed an infected file. There is not much more to be done here.

    Delete the below file from the desktop

    • ~ps7CF.tmp

    Can you tell me if these are related to Kodak software?
    C:\KA <--- What is inside of this directory?

    C:\Windows\ka.ini <--- also related top kodak?

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can see from the ComboFix header and also from the lack of information in the sysinfo.txt log ( part of MGlogs.zip ) that Windows itself is having problems. For one thing, the missing info mentioned above is likely due to the Windows Management Instrumentation service not running.

    Using System Restore or a repair install may be worth trying.
     
  10. brandon3420

    brandon3420 Malware Magnet

    Thank you everyone for your help. I completed the below steps. all except I cannot delete the file Perflib_Perfdata_e8.dat in the c:\windows\temp directory... i tried file assassin and it failed to do it as well. Everything went as planned and I will now switch to the software forum... thank you!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Hope you are able to get things worked out in the Software Forum.
     
  12. brandon3420

    brandon3420 Malware Magnet

    i havnt gotten any help there yet... cant figure it out
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using System Restore to go back to a restore point from before the problem began.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds