My Computer is having major issues - I have done everything - Please Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cmcchesney, Feb 8, 2008.

  1. cmcchesney

    cmcchesney Private E-2

    Hello,

    I have been having computer 'issues' for the past three days. I have completed all of the 'suggestions' on the Basic Computer Cleaning Steps as well as the Windows XP Cleaning Procedures... I have run ComboFix, Spybot, AVG Anti Spyware, MGTools, HijackThis, and nothing seems to work.
    I have attached the MGLogs and my HiJackthis log. However, the AVG Anti Spyware program took about 6 hours to run and I didnt save the log. :-( Hopefully you can help with the information provided. If you need any further details, please let me know.

    Thank you so very much!!!

    I appreciate your help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We don't need you to attach HijackThis logs. We do need the log from Combofix though. Did you have a problem running it? If so, what was the problem. If it ran okay, please attach the log we requested.

    Next time please follow instructions more carefully. You did not download MGtools.exe to your C drive root folder as the READ ME instructed. You ran it directly from the website. I can tell this from the process show in your logs:

    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6R15XMW3\MGtools[1].exe

    Since it was show running from your Temporary Internet Files folder is means you Opened it instead of downloading it. You are lucky it work at all. Is that what you did with ComboFix too? If so, that may explain why you had problems with it.

    Also you said
    but this does not tell us anything useful. Please tell us exactly what problems you are having.


    What is the below process for?
    C:\Program Files\oa\oaLaunch.exe

    Uninstall Viewpoint Media Player as requested in step 1 of the READ ME.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKLM\..\Run: [combofix] C:\WINDOWS\system32\kmd.exe /c C:\ComboFix\Combobatch.bat
    O4 - Global Startup: OALaunchShortcut.lnk = C:\Program Files\oa\oaLaunch.exe

    Do you recognize the below? If not, fix it too?
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Owner/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you follow the below instructions properly!! You must download the file not run it from the website. And you MUST extract the Avenger.exe file from the ZIP file not run it from the ZIP file. It you do not follow these instructions, the below will not work.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  3. cmcchesney

    cmcchesney Private E-2



    Hello!

    Thanks so much for your response. I was beginning to think that I was going to have to uninstall/reinstall my OS.

    I apologize for not following the directions more carefully. I thought that I was doing things correctly. However, I am not a professional, so I am sorry.

    For the past several days my computer has been taking a really long time to boot and load the desktop (icons and start up programs). It has also been quite slow and acts 'challenged' when I have a program opened. It usually goes to the all white screen saying (Not Responding). It pretty much freezes up for a few minutes and then goes back to normal. On a typical day, the only programs that I use are MS Outlook, MS Word, Internet Explorer, Windows Media Player and a program called Workstation Coordinator which is used along with Internet Explorer which provides me access to my agency management system (AMS Systems, Inc.) for my business. It is basically an online database of my clients, accounting, etc. which uses the Workstation Coordinator software. I am not certain how it works but that shouldnt have anything to do with the problem... Just an FYI.

    Today, I completed the following:

    1. Uninstalled Viewpoint Media Player.
    2. Ran MGTools.analyse.exe, exited all browser sessions, fixed all of the lines you requested including the 'Desktop Component' as I did not know what that was.
    3. Saved and Opened the FixMe.reg which added it to the registry.
    4. Downloaded The Avenger, saved to Desktop, Ran Avenger, copied into box, restarted, etc.
    5. Deleted files in C:\WINDOWS\Temp and C:\Document and Settings\Owner\Local Settings\Temp.
    6. Downloaded ATF Cleaner, Selected all and emptied.
    7. Ran C:
    MGTools
    GetLogs.bat
    8. Restarted Computer...

    At that point my computer took 5 Minutes to load to the 'User Login' screen. Once I logged in, it took another 7 minutes to load the desktop including the icons and start up programs. It is still acting really slow and freezing.

    I checked where the combofix.exe program's properties.... It is saved as C:\Documents and Settings\Owner\Desktop so I do not believe that it is/was stored in Temp File.

    Attached are my Log Files for Avenger and MGLogs... Thanks!!!!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you still have not attach the C:\ComboFix.txt log that you should get from running ComboFix.exe. Did you follow the instructions and run it yet? I need this log.

    In your first set of logs you only had AVG7 antivirus running. Why did you now install Symantec antivirus? You are violating important first steps given in the READ & RUN ME and you are making the performance of your PC even slower. You MUST uninstall Symantec right now and it probably will not even uninstall properly. And do to that you will than need to run the below:

    Norton Removal Tool (SymNRT)


    Also I see too many antispyware type programs installed. Is Spyware Doctor a paid program or a free trial? Based on the installation date I'm betting it is a free trial. If this is true, then uninstall Spyware Doctor now.

    You need to stop doing things on your own because you are only making things worse by installing all of these programs. Please only do what we ask you to do and nothing else.

    Now reboot your PC and after reboot run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds