Virus/Malware Removal Advice (post 1)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lifeonmars, Sep 23, 2009.

  1. lifeonmars

    lifeonmars Private E-2

    I suspect my PC has been infected for a while (running slow) despite running AVG daily which hadn't flagged anything, but yesterday had an svchost warning and found some malware with AVAST.

    Went through your malware removal procedure, but think there may still be problems - i.e. slow operation, and have attached the logs (one to follow).

    Would be VERY grateful for any help/advice.

    Charlie
     

    Attached Files:

  2. lifeonmars

    lifeonmars Private E-2

    Re: Virus/Malware Removal Advice (post 2)

    The final log is attached.

    Charlie
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. lifeonmars

    lifeonmars Private E-2

    Chaslang,

    Thank you for taking the time to help me with my malware problem.

    I have attached the Combofix.txt and MGlogs.zip files as requested.

    Best wishes,

    Charlie
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix did not finish running properly to complete the fix. Let's finish things off manuall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Now attach the below log:
    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  6. lifeonmars

    lifeonmars Private E-2

    Chaslang,

    Thanks again for your reply.

    The fixme file merged successfully with the registry.

    I've attached the updated MGtools log.

    My PC is still running slow and taking an age to open programs (I'm running XP Pro with 2GB of RAM and a Core 2 Duo E4600 @ 2.40).

    Charlie
    P.S. Comodo warns me about a services.exe file, but I'm not sure if this is a legitimate Windows operation, something to do with an Avast update, or something malicious.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you recently run scans with a tool from Kaspersky? Like on Oct 5th?

    Please run this: McAfee Consumer Product Removal Tool


    Now delete the below folders if they still exist:
    C:\Documents and Settings\All Users\Application Data\McAfee
    C:\Documents and Settings\All Users\Application Data\McAfee Security Scan


    If may just be what you are running. First uninstall the extremely outdated Spyware Guard which you do not need anyway since you have Avast, Comodo, and SUPERAntiSpyware Pro installed. Then reboot.

    Now please explain what operations are slow! For example answer the below:
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?

    C:\WINDOWS\system32\services.exe is part of Windows and you need to allow it or you could be causing yourself problems.


    Now please download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the log from Win32kDiag
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. lifeonmars

    lifeonmars Private E-2

    Chaslang,

    Thanks for your patience.

    I haven't used Kaspersky.

    Things have improved since the last set of instructions you sent me, and Avast did find and delete a Trojan called 'alegusob'.

    Although the boot up process is not particularly slow, there is a long period between the desktop appearing and the PC becoming usable. I know Avast/Comodo and SuperAntiSpyware take some time to load in, but it can take several minutes.

    Firefox also takes up to 3 minutes to open first time (though it's fairly quick to open after that initial load) - but I've read that quite a few people have the same problem.

    Although there are a lot of processes listed in the task manager, none are using much CPU time.

    I have noticed that mDNSresponder is quite prominent. Although I don't use any Apple products like iTunes, I do have Safari installed, which must be how this was downloaded?

    As I say things have improved (the cursor moves much smoother for instance), but I still feel there's some malware lurking!

    Here are the logs.

    Thanks again,

    Charlie
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually all it found is what we already deleted and was in ComboFix's Quarantine. It did not find it before when it was active.

    Normal now a days. Due the complex malware that now exists, protection programs and even the Windows OS have become equally more complex and will slow down startup while they get themselves hooked in. It is the price you pay for security/piece of mind.

    Quite typical. I'm not sure about the 3 minutes but it is much slower the first time you run it after system power up. And the more addons you have and the more protection you have, the slower it will be (and the same applies to any browser). And you have one addin for FF that may be missing for FireShot: fsaddin-0.69.dll

    It is not "prominent" according to your logs. If you don't need it, uninstall it or disable it. A topic for the Software Forum.

    Not according to your logs. Your logs just show lots of toolbars, processes and services many of which I would not run but it is not my PC. These are all having an effect on your PC's performance.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. lifeonmars

    lifeonmars Private E-2

    Chaslang,

    Thanks so much for the time you've taken working through my logs.

    I'll follow your closing instructions and make a concerted effort to get rid of all those unnecessary toolbars!

    You've been a great help.

    Best wishes,

    Charlie :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds