Unsure of what infected my PC and Slowing it down badly.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by PoignantStory, Dec 26, 2010.

  1. PoignantStory

    PoignantStory Private E-2

    Hi,

    I'm just a noob and new here.Sorry to bother but i really need some help on discovering what has happened to my laptop.It was really running well and smoothly till recently.My Laptop are pretty well off and has no shortage of memory but recently something has been causing lags and delays.
    I'm attaching the required scans as i have done them all, thank you in advance and any advice would be warmly welcome. :)
     

    Attached Files:

  2. PoignantStory

    PoignantStory Private E-2

    Last required attachment.:)
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe | c:\windows\system32\userinit.exe
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. PoignantStory

    PoignantStory Private E-2

    Hey,
    Kestrel13!!!
    Thank you so much i'm going to do it right away!
     
  6. PoignantStory

    PoignantStory Private E-2

    Hello,
    Thank you for your help once again. ;)
    Btw, My comp is still running slowly =( and it's memory is used up with almost no active programs turned on.
    Here are the attachments
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run combofix again just by right clicking and running as administrator.

    Next..

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. PoignantStory

    PoignantStory Private E-2

    Once again thank you so much :)
    Here they are
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to virustotal and upload the following files for analysis, and let me know the results.
    • c:\windows\system32\userinit.exe

    Could you please get this: userinit.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip
     
  10. PoignantStory

    PoignantStory Private E-2

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmmm, combofix keeps complaining about an infected file. Run combofix again and attach the log. C:\combofix.txt. Don't worry about MGTools this time.
     
  12. PoignantStory

    PoignantStory Private E-2

    Hello!!!
    There you go =))))
    Computer still lagging sucks! Thanks for the help =)
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well Combofix is no longer showing problems. If your PC is running slowly, it is not due to malware. You will have to visit the software forum to further discuss this.

    However a couple things we can do first.

    Question:

    Did you knowing install Windows Live Mesh and are you using it to synchronize file systems on multiple computers accross the internet or over a network?

    Run this and attach the results.

    Using ESET's Online Scanner

    I am seeing all of the below is running at start-up. We can run a fix to stop them, as you can start them manually when you like. This may free up some resources.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Also address this:

    Please explain what operations are slow! For example answer the below:
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?
     
  14. PoignantStory

    PoignantStory Private E-2

    Hey,
    I am doing the scan right now.Just a few questions does fixing all those means when i start up all those would be gone????? And would not start automatically??
    And i would address to those question in the next reply so sorry wwaiting for the scan to be done!!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Exactly right, fixing those entries will prevent them from running at start up. It does not however delete any of the files, so do not worry about that.
     
  16. PoignantStory

    PoignantStory Private E-2

    Once again,
    thank you for everything you have done =))) The best forum for help on pc!

    Did you knowing install Windows Live Mesh and are you using it to synchronize file systems on multiple computers accross the internet or over a network?
    Nope.


    Done the scan after a long while!



    Also address this:

    Please explain what operations are slow! For example answer the below:
    • Is boot up slow?
      Nope
    • Is shutdown slow?
      Nope
    • Is browsing/surfing slow?
      Yes
    • Is downloading slow?
      Nope
    • Is running any application?
      Yes, almost all application runs slowly now.
    • Is it also slow in safe boot mode?
      Haven't tried it.
    • Also are any process showing in Task Manager to be using a lot of CPU time?
      There is this process svchost.exe it has like 4 duplicates and uses up lots of CPU time.
    • Anything else slow?
      Games,Running softwares.
    [/QUOTE]

    Lastly,Thank you for everything !!! CHEERS!
     

    Attached Files:

    • ESET.txt
      File size:
      428 bytes
      Views:
      5
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome!

    Then uninstall it ----> Windows Live Mesh
    Then please do so and let me know.
    See this to understand What is svchost.exe And Why Is It Running?

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  18. PoignantStory

    PoignantStory Private E-2

    Hey!
    Alright i will do those as soon as possible and get back to you.
    :waveSee you!
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay, but you may ultimately have to visit the software forum to further discuss the "slowness" :)
     
  20. PoignantStory

    PoignantStory Private E-2

    Hey,
    Kestrel! I ran my computer in safe mode and it boot up normally.
    However when i ran ComboFix again it stated Infected copy of c:\windows\system32\userinit.exe was found and disinfected .
    PLease have a look thank you =)

    I attached the log too!!
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then apart from combofix, you need to re-run the whole malware removal procedures which you ran originally. Attach the logs and I will review them later on.
     
  22. PoignantStory

    PoignantStory Private E-2

    Hey,
    Alright i would do them again . Thank you for your patience!
    See you soon!
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. If you recall before I mentioned that combofix kept finding infected files but when I had you run it the last time it came back clean. I guess we will have to dig deeper. :) I will be here waiting.
     
  24. PoignantStory

    PoignantStory Private E-2

    Hey Kestrel!
    So I have scanned using Malwarebytes and it detect two threats.
    Besides this i have something to inform you.That my Notron(Symantec Endpoint Protection) have detect over 20 Trojans,Bloodhound,Trojan Gen. They are all files stored in the Temp folder. I have been having this problem for a while now and Notron Antivirus has quarantine them. But it seems like every single time it quarantines them it comes back sooner or later.=('
    As I don't know how to accquire the log.Im attaching the MAlwarebtyes one here. And Malwarebtyes twoo detected 2 threats which are from the Temp folder simliar to the rest of the threats that Notron quarantined.The files names are about the same too! Help please , any would be greatly appreciated like always =)))))))
     

    Attached Files:

    Last edited: Jan 2, 2011
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Remember what I said:

    I need you to attach the rest of the logs too. Not just the MBAM log.
     
  26. PoignantStory

    PoignantStory Private E-2

    I understand i just want to know your opinion on the constant trojan horse that my norton has been detecting. =)
     
  27. PoignantStory

    PoignantStory Private E-2

    Hey there.
    Finally got everything done! Btw the norton thingy ! hahaha thanks alot!'
    There you go!
     

    Attached Files:

  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run Ccleaner.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\users\abrial\appdata\local\temp
    C:\Users\abrial\AppData\Local\NPE
    C:\Users\abrial\AppData\Local\temp
    C:\Users\abrial\AppData\Local\wj32
    C:\Users\abrial\AppData\Roaming\adma
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Re run MBAM and see if it finds anything.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know if Norton is still flagging anything.
     
  29. PoignantStory

    PoignantStory Private E-2

    Hey there!
    As I'm working now I'm unable to do those. But hey thank you so much for the quickly reply ! :)
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Attach logs when ready.
     
  31. PoignantStory

    PoignantStory Private E-2

    Hey Kestrel,
    I have done all of that. Ok i shall attach MBAM, ComboFix and the MGTOOLS log.
    And Norton has been still detecting virus from that same location!
    Ok maybe you take a look the logs again . Thank you!
     

    Attached Files:

    Last edited: Jan 4, 2011
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Certainly. If you attach them. ;)
     
  33. PoignantStory

    PoignantStory Private E-2

    Yup just edited and added them in the previous reply =)))
    com dying hahaha
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm?
    You need to give me the exact files and file paths of these threats. Generic names given by Norton are not much use to me.

    Delete these folders:

    • c:\users\abrial\AppData\Local\NPE
    • c:\users\abrial\AppData\Local\wj32
    • c:\users\abrial\AppData\Roaming\adma

    Reboot the machine, then run Ccleaner again.

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new C:\MGTools.exe and attach the new C:\MGlogs.zip.
     
  35. PoignantStory

    PoignantStory Private E-2

    hey kestrel sorry for the late reply!!!!
    Really busy with work these days!
    its c:\users\abrial\appdata\local\temp\dwh8e3.tmp!
    c:\users\abrial\appdata\local\temp\DWH(xxx).tmp and so on ! the dwh is always the same only the last digits or alpha are different!
    Ok will do so!!!
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then delete them if it lets you, and yes, follow the rest of my instructions when you are ready. :)
     
  37. PoignantStory

    PoignantStory Private E-2

    Done!
     

    Attached Files:

  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So is Symantec still complaining about anything now?
     
  39. PoignantStory

    PoignantStory Private E-2

    Yup!.
    Those files that start with dwh , like everytime i restart =(
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm I am just not seeing what Norton is seeing. I am having a word with the others about this, so hang in there. ;)
     
  41. PoignantStory

    PoignantStory Private E-2

    Hey kestrel
    btw i have lots of those files too in the quarantine folder of notron whats shoudl i do with those?? and yyup they always seem to return after i re-boot and my com runs super slowly with games application internet browers yup i hope this helps =)
     
  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you attach a log of what Norton is finding please.
     
  43. PoignantStory

    PoignantStory Private E-2

    Hey kestrel
    I have no idea how to do that. Could you guide me in doing so????Sorryyy

    Got it!!
     

    Attached Files:

    Last edited: Jan 11, 2011
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download Cleano 0.61

    Download it to your desktop, Right click the cleano.exe file and run as admin > and place check marks in the boxes as follows

    • Clean user's temp
    • Clean windows temp

    Click clean now and exit the program.

    Is Norton still finding these threats in temp locations?
     
  45. PoignantStory

    PoignantStory Private E-2

    Hey kestrel,
    I don't know what happened but i tried using trojan remover 6.8.2 to scan my pc and stuffs.Now my com is twice as slow and is almost impossible to unless in safe mode. :cry i really dont know what to do anymore. =(
    Thank you , erm right now i scan them and they don't detect anything but after a while after i reboot my pc they would detect them again and put them into quarantine should i delete them in the quarantine foldeR????
     
  46. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please don't do anything that we have not instructed you to do whilst we are still working together! :)

    Yes, empty quarantine.

    I want you to disable and enable system restore as per these instructions in step 6

    Then I want you to run Ccleaner. Then I want you to use the computer a while and let me know if Norton is still complaining.
     
    Last edited by a moderator: Jan 13, 2011
  47. PoignantStory

    PoignantStory Private E-2

    Hey kestrel,
    So sorry was desperate! Thank you I will do it right away!
    CheerS!
     
  48. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also I had a word with Chaslang, who says, if Norton reports any of those temp files again, do not have it quarantine them but navigate to the location of the temp folder, and zip one of the files up to attach here for us to take a peek at.
     
  49. PoignantStory

    PoignantStory Private E-2

    Hey kestrel,
    Thank you and also many thanks to Chaslang! :) I will do that alright =)
     
  50. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay then, see if you can capture one and attach it. I will be back from work in a few hours.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds