Post malware removal, 30 minute startup, then computer works fine

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rkeric, Dec 12, 2010.

  1. rkeric

    rkeric Private E-2

    In the past six months my computer has been infected with both AV Security Suite and ThinkPoint. Using the tools on this website, I have removed the malware/viruses but I am still having problems and could use some help.

    I have read and followed the instructions in the Read and Run Me First and XP Cleaning Procedure threads and will attach my scan logs in this and a second message.

    Basically, a quick recap. After removing AV Security Suite several months ago, the computer seemed to work fine until ThinkPoint arrived. I followed the steps outlined to remove it but after doing so the computer lost the ability to connect to the internet and had a very slow startup procedure (about 30 minutes) before applications would run. After the slow startup, everything seemed to work (except internet connections ie7 and firefox). I stopped turning the computer off because after hibernation the startup was not delayed and used my desktop when I needed to use the internet (my laptop was the infected computer with continuing issues, my desktop did not have the infections described above).

    I finally got some time to deal with this and have been able to restore the internet connection on my laptop using Winsockxpfix. But I still have the slow startup issue and I get a popup message during startup as follows:

    "RUNDLL

    Error loading C:\Windowst32rvcr.dll

    The specified module could not be found."

    When i hit the OK icon, the message goes away and startup continues. The only other message I remember getting (this would happen before my latest cleaning procedures) would be a box that would appear on the Windows User login screen when the OS was in hibernation that said:

    "Insufficient system resources exist to complete the API."

    The laptop is a Dell Precision M90 running Windows XP Pro (Service Pack 3) with 2 GB of memory. I used to use McAfee anti-virus software, but switched my laptop to Avast because I had problems reinstalling McAfee after removing AV Security Suite.

    I hope I have described the problems adequately and would really appreciate any assistance.
     

    Attached Files:

  2. rkeric

    rkeric Private E-2

    And here is the MGTools log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You attached the wrong log. We need the C:\MGLogs.zip.
     
  4. rkeric

    rkeric Private E-2

    Sorry. Hope this is what you need.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is a very bad idea to allow all users to have Admin. privileges!! Make one account an Admin. and the others limited.

    You have traces of McAfee still on your system as well as:
    avast! Free Antivirus
    EMBASSY Security Center
    LiveUpdate 3.1 (Symantec Corporation)
    LiveUpdate Notice (Symantec Corporation)

    You need to uninstall all but Avast.

    Also, use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 13

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\documents and settings\Reed Erickson\Application Data\37318.bat
    C:\WINDOWS\Bguhamiyumihoy.dat
    c:\windows\t32rvcr.dll
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Jfegevoy"=-
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. rkeric

    rkeric Private E-2

    I followed the instructions carefully and believe that I have done everything asked. The startup time was 28 minutes, so that has not improved. I did not get any error messages during that process. I should note that the delay occurs after I have logged on to a user account (as administrator) and the desktop has populated. I can perform some simple tasks on the desktop (the start button works) but no programs will open and run. I get the same delay if I log onto any of the 3 user accounts after the machine boots.

    The logs you requested are attached.

    Thanks for your continued help.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not sure why your system is lagging. It is not a malware issue, but we still need to cleanup a bunch of leftovers from McAfee.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    0167661286460343mcinstcleanup
    mfefire
    mfevtp
    mfetdi2k
    mfefirek
    
    File::
    C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    c:\docume~1\REEDER~1\LOCALS~1\Temp\016766~1.EXE
    c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe
    c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe
    c:\windows\system32\drivers\mfetdi2k.sys
    c:\windows\system32\drivers\mfefirek.sys
    
    Folder::
    C:\Documents and Settings\Reed Erickson\Application Data\MCAFEE
    C:\Documents and Settings\All Users\Application Data\MCAFEE
    C:\Program Files\McAfee"
    C:\Program Files\McAfee.com
    C:\Program Files\Common Files\MCAFEE
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
    
    [HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters]
    "DhcpNameServer"="192.168.1.1"
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds