Slow Computer/Internet After ZA-AntiVirus Cleaned Trojan.Win32.Hosts2.gen

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by trip777, Mar 16, 2013.

  1. trip777

    trip777 Private E-2

    Zone Alarm Free AntiVirus/Firewall detected Trojan.Win32.Hosts2.gen on my system and seemingly disinfected it but now I have slow computer and internet service immediately afterward.

    I'm concerned about doing any sensitive online/computer work like online banking etc without knowing that I'm safe or not.

    I have downloaded/run the tools recommended and all seems OK except RogueKiller. After running, it has entries in the registry tab "SUSP PATH" that has me concerned.

    This all started over the last few days.

    Could someone be so kind to read these logs to let me know if my system is compromised?

    TIA!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It does not appear that you are having malware problems. Your logs are all basically clean other than some Yontoo junkware we will remove further down.

    This could have been a false detection of the large hosts file that you installed when installed this >> http://winhelp2002.mvps.org/hosts.htm

    Just items you should recognize as files you saved there which by the way is not a good idea for just this reason. They look suspicious and like malware. Do not save executable files and other downloads to your Desktop ( not even in a folder on your Desktop ). They are prone to deletion, they look like malware or at least suspicious and saving too many files or large files there can have an effect on performance.


    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  3. trip777

    trip777 Private E-2

    Yes, I do recognize these files and thanks for the tip to save elsewhere.

    Thank you soooo much for your help!

    Here is the log for JRT...
     

    Attached Files:

    • JRT.txt
      File size:
      2.2 KB
      Views:
      1
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that removed a bunch of things from Yontoo, but it missed a bunch too. So let's remove them manually.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now reboot your PC and tell me if there has been any improvement to performance. I'm not sure much may have changed since your problems are likely not due to malware.
     
  5. trip777

    trip777 Private E-2

    OK, did that and got a message "The keys and values have been succefully added to the registry."

    My PC started running normal today so perhaps JRT helped...

    I looked for Paypal on this site so I could drop a twenty but couldn't find one. Do you fine folks have Paypal here?

    Thanks again!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No we do not! Only privately.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. trip777

    trip777 Private E-2

    I couldn't PM you since I have less than 50 posts so if you could PM me with some way to compensate I would be more than happy to do so!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds