Slow computer, popups, IE lockup, Ad-aware lockup

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by drkelly, Jun 14, 2005.

  1. drkelly

    drkelly Private E-2

    First off, I read the bottom sticky, 'READ ME FIRST BEFORE ASKING FOR SUPPORT', and have followed the instructions in that thread. I have downloaded all the software listed that it lists to get an put it in a new folder. I successfully completed the first section labeled, 'Getting Prepared; Steps to be sure your system is ready to be scanned:'. I moved on to the second section labeled, 'Scanning And Cleaning Steps:' The first problem I encountered was going to 'trend micro's free online virus scan' site. I can get to the site, but an error message pops up and it will not scan. I decided to skip that and move on. I ran Symantec Security Check, and it found a few things. Most of them had .'abetterinternet' at the end of them. I then ran McAfee Avert Stinger successfully. Next I successfully ran CCleaner. Then the problem happend with Ad-aware SE. It would run, but get hung up and read 'busy' after finding about 200 or so infections. I do not know what to do next. The instructions say to install Ad-aware VX2 Cleaner plug-in, but I do not know how to do that or where to get it. I am a dunce when it comes to computers.

    My system is a four year old Dell. It is running Windows XP.

    The problems I have been encountering are numerous popups with Aurora in the title. IE also locks up regularly and I have to go to the task list where it shows 'not responding', and manually end the task. The computer is also generally MUCH slower than it was when new in trying to do most everything.

    Can anyone help?

    Thank you,
    Danny
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running Ad-Aware until you have only around a 100 problems (any place less than were it hangs). Then stop it and fix the current list. Then start it again and try similar steps. The VX2 cleaner plugin is listed in the READ ME FIRST. The download link tells you how to install it. If you cannot get Ad-Aware to complete, skip it and continue (by the way, are you in safe mode?).
     
  3. drkelly

    drkelly Private E-2

    Whoops! I read the instructions in that thread carefully before beginning, then forgot to boot up in safe mode. I did that, and was able to successfully run ad-adware which found a bunch of infections. I then started back where I had problems first and ran Trend Micro's free online virus scan. It found four items. All four were labeled un-cleanable. I was able to use the delete option though and get rid of three of them though. When I tried to delete the fourth one, I got the following message:

    Unable to clean file C:\Windows\System32\gjfdrjn.exe because it is currently in use.

    I was able to do a search and find this file. Should I try and delete this file?

    I then went to the next step that I was unable to perform before and tried to run Symantec security check, but it just got hung up.

    I am still having a tremendous amount of pop ups with 'Aurora' in the title. It is very frustrating. Plus my computer still seems slow. Definitely much slower than when it was new.

    Thanks!
    Danny
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could have just ended the gjfdrjn.exe process using Task Manager and then have Trend delete the file if it could. That process may have renamed itself by now. What you should do is just complete all steps in the READ ME FIRST. I am going to include it in the steps below. Pleae follow the below steps completely to the end. If you have any problems along the way, just note them and continue. Report them when you come back.


    - download Nail/Bolder/Aurora Remover 0.3.1 Beta and save it to its own folder like c:\ABIremover

    - Now extract the abiremover.exe file from the ZIP file into the folder you created but do not run the EXE yet. We will run it later.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates for all programs.

    - Now while still in safe mode, run the abiremover.exe but make sure you are physically disconnected from the internet (unplug your cable to be sure). Just click install, wait (explorer window will disapear)

    - When abiremover finishes just reboot into normal and continue with the below steps.


    Also download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.



    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. drkelly

    drkelly Private E-2

    First I would like to say thanks for the help. My computer is much better and like new again after all the fixes that you have recommended.

    The aurora download fix solves the problem, but then the aurura problem shows back up on my computer the next day and I have to reinstall/run the aurora fix again. Next day, same thing again. I have to rerun the fix everyday. When it finishes, it gives me the following message:

    Don't forget to reboot into safemode again and remove the random part (random regkey and the random file)

    I am assuming by not having done the above, it is still lurking in my computer and comes back some how. I have no idea how to do what it is asking. Please help.

    Thank you,
    Danny
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete ALL the steps that I gave you!
     
  7. drkelly

    drkelly Private E-2

    I'm guessing you need the log file from running hijack this?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need you to run ALL steps in the READ ME FIRST. You did not. At a minimum, I can see the online scanners were not run. Anything else not run? Perhaps part of the problem here is that you waited 3 months to respond. The READ ME FIRST has changed and so have the require online scanners. And in 3 months you would have to re-run the whole READ ME FIRST anyway since all the tool have gone thru many updates.

    Also you did not install HJT properly. You have it here:

    C:\DOCUME~1\DANIEL~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    That means you are running it from the ZIP file. Please read and follow the directions.

    Also goto Add/Remove programs and uninstall WeatherBug.
     
    Last edited: Sep 26, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds