Malware cleaning help needed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hydrodave, Sep 7, 2006.

  1. hydrodave

    hydrodave Private E-2

    My computer has been running VERY slow lately and I suspect malware. I have an older Dell P4 running at 1.7 MHz with 1 GB ram. I instlled XP Pro over Win2000.

    I am using CounterSpy and SpySweeper, AdAware and Search&Destroy along with CA Antivirus and ZoneAlarm Pro.

    I ran GetRunKey and Shownew, then I downloaded and ran MS Defender and Malicious Software Removal Tool (Safe Mode) as directed in "READ & RUN ME FIRST Before Asking for Support". I also ran AdAware and S&D, CCleaner, and then disabled system restore. I scanned with Bitdefender and then Panda Active Scan. Finally, I ran Hijack this. System still seems slow.

    I have attached the Hijack this, Bitdefender and Panda files.

    I would appreciate any suggestions on how to proceed.

    Thanks in advance!
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome to Majorgeeks

    Please run the guide as laid out as your Hijackthis log is not installed and run from the location we request, with the rename of Hijackthis to Analyze.exe
    G:\Downloads\SpyBot software\Hijack this\HijackThis.exe you have no signs of having run Windows Defender in your HJT log as you have the old and outdated Microsoft Antispyware installed.

    Please re-run the guide in order specified as skipping steps are only prelonging you being infected with malware, our malware experts have a great record of being able to remove malware from a PC if the initial steps are followed.


    Hi and Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis

    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. hydrodave

    hydrodave Private E-2

    Actually I did rename HijackThis.exe to Analyze.exe and ran it from the C:\Program Files\HJT directory as instructed. There still exists a HijackThis.exe file in my downloads directory, but not the one you indicate in your post. G:\Downloads\SpyBot software\Hijack this\HijackThis.exe does not exist on my computer. It resides in I:\Baldwin Data Drive\Downloads\SpyBot software\Hijack this.

    As for Windows Defender, I downloaded the newest version from the Microsoft site just before I ran it.

    Please indicate how I should proceed. Do I need to delete HijackThis.exe from downloads, even though I didn't run the program from that location? Do I need to rename the HijackThis.log to Analyze.log before running it? Should I download Windows Defender and run it again?

    Thanks for your help.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    I would run through the whole guide again as your 1st Hijackthis log indicated to me those discrepancies I mentioned, and my post only refected what your HijackThis log reported in that the location I posted was the run location and name of the Hijackthis .exe log you attached and that MS Antispyware is installed ( F:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe ) and not Defender.... take a look yourself as I'm not in the habit of posting things that are not their.

    But do run the full guide and post attach all the requested logs and then one of the malware guys will post some removal instructions for whatever malware is on your PC.
     
  5. hydrodave

    hydrodave Private E-2

    Halo,

    My computer won't even boot into Safe Mode now - I guess I'm out of luck. Probably will just have to re-install XP. What anti-virus program do you recommend?

    Thanks for your help.
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Did you try the msconfig route and in the Boot tab ticked SafeBoot > Apply and reboot.


    But to answer your question............

    I would recomend either Avast or AVG free, but with some other basic security applications too, good read is this guide How to Protect yourself from malware!


    As a guide I have the following installed and have never been infected with malware,

    Avast Free
    Spywareblaster
    Microsoft Defender
    A-Squaired Free
    Ad-Adware SE Free
    ZoneAlarm Free
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds