Help needed with ongoing Virus/Spyware issue.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mkgibbo, Nov 24, 2006.

  1. mkgibbo

    mkgibbo Private E-2

    Hi. I have been having problems with laptop running slow and small changes with the setup of the computer. Start up time is over 5 minutes. Security centre gets turned off. PC-cillin could never find a problem.

    I have a Toshiba Satelitte A60, Mobile Intel Pentium 4 CPU 3.06 GHz, 192MB RAM. Windows XP Home 2002 SP2.

    Have read and followed through Malware Removal read me process.

    All seemed to do their job appart from Panda Scan which would close the two explorer pages that were open when running when it got near the end of it's scan.

    The most notable find was Trogan Bagle.

    Have included "newfiles", "runkeys" and "HJT" logs. I have logs for counterspy and Bitdefender also.

    I hope I have done the right things as am new to all this.

    I appreciate any help that comes my way.
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Yes please do attach all the logs you have as they all help and speed up the malware removals process :)
     
  3. mkgibbo

    mkgibbo Private E-2

    Thanks Halo.

    Have included bitdefender and counterspy log files as requested.

    Another note, I can't run regedit. Comes up with error box saying windows can't find it.

    In regards to counterspy I have run another scan (that shows nothing) as there was no scan history for the first one I ran? It certainly found problems but I cant remmember what they were.

    Anyway,

    Cheers.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only malware item that I can see from your logs is the Trojan Bagle (as you mentioned) that Bitdefender found in your Outlook email. You will need to delete the reference email with the referenced file attached =>[From: Emily.mallard]=>The_new_prices.zip

    I see no obvious reason for your PC to be running slow. How much free disk space do you have?

    I do recommend that you now uninstall CounterSpy since it found no problems and because you already have Windows Defender. Uninstalling CounterSpy will help speed things up.

    You should also run the below to remove the unnecessary Windows Messenger:

    Disable/Remove Windows Messenger

    I did notice that the logs from GetRunKey and ShowNew were incomplete. This is definitely related to the fact that you said regedit is missing. If regedit is missing, other files could be missing. Do the below.

    Click Start, Run, and enter sfc /scannow and click OK! This may ask for your Windows XP SP2 CD so hopefully you have one.

    Did sfc find any problems and repair them?

    Is regedit still missing? If so, use Windows Search to look for another copy on your PC. Tell me if your find one or not.
     
    Last edited: Nov 26, 2006
  5. mkgibbo

    mkgibbo Private E-2

    Thanks Chaslang,

    I have deleted the infected email and attachment. Nice.

    Laptop has 18.8GB free disk space from an available 29GB.

    I have found the initial run of Counterspy log (I ran it in safe mode as administrator but then it doesn't come up in the scan history when I logged on as a user?) and it confirms the Trojan Bagle. But will still uninstall as runs out in 10 days anyway.

    Is Windows messenger bad as my partner uses it a fair bit and would be sad to see it go?

    Have run scannow and it has detected some missing files. No copy of SP2 CD with me but will get one soon and add missing files.

    Yer the slowness is strange I guess but very painful. Start up and shutdown both very slow. Even when opening "My Computer" the little flshlight comes up for a few seconds before icons appear. Frustrating!!

    Anyway, will track down a disk and get those files in place.

    Cheers.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did uninstalling it help your performance at all?

    Are you sure it is Windows Messenger? Many people confuse it with MSN Messenger which is not the same thing. Windows Messenger is not malware it is just an outdated program that is part of Windows that very few people use and it is a security risk and a frequent source of popups occurring on many systems. You really should not use it if it is being used. Look into using MSN Messenger or one of the other dozen or so instant messengers around.

    Replacing the missing file could have an effect on your performace. Obviously it is having an effect on the ability of certain things to be run on your PC.
     
  7. mkgibbo

    mkgibbo Private E-2

    Thanks Chaslang,

    Have removed Counterspy, no difference in performance unfortunately.

    Have also removed messenger. Thanks for the heads up on that one.

    Getting my hands on a copy of SP2 CD and will run scannow again and install the missing files. Here's hoping that helps.

    Cheers.
     
  8. mkgibbo

    mkgibbo Private E-2

    Hi Chaslang,

    One other thing whilst I am looking for CD. Some one told me I may have a copy of Regedit in windows\system32\dllcache. Not sure if this was worth following but I now know that "dllcache" is missing from "system32".

    I ran a search and found a copy under "Windows\lastgood\" which was only created yesterday (27th). It only contains 2 files though (one an ethernet driver and the other a LAN driver)

    Not sure if this is related.

    Cheers.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is why one of my previous messages told you:
    Yes it normally does have a copy there and also in other folders too. Like an i386 folder which contains backups for most of your XP install. The i386 folder is not always on a PC though. Also in the i386 folder regedit may still be compressed so it would show as regedit.ex_ instead of regedit.exe. Searching for regedit without the extension would be a better way to search. See what you find. But ALSO. You must configure Windows Search to properly look in ALL folder. See this: Searching for Hidden Files on WinXP

    I doubt that your dllcache folder is missing. It is a folder that Windows requires and uses all the time. Are you sure about this? Are you sure you have done step 2 of the READ & RUN ME exactly as written?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds