![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Internet explorer has been getting progressively laggier and sluggish so I ran malwarebytes and it found nothing. Over the course of a month it became unusuable, I looked at the running proccesses and found Cd_2somethingorother, ended it, and IE ran perfectly.
Logfile of Trend Micro HijackThis v2.0.2 Last edited by TimW; 05-09-12 at 10:23.. Reason: Removed inline HJT log. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
If you want us to check your system for malware, please do the following:
READ & RUN ME FIRST. Malware Removal Guide
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#3
|
|||
|
|||
|
Windows xp, 32 bit, service pack 3.
Malware bytes and SuperAntiSpyware found nothing, so not including those logs.(Was already using SAS to clean random junk out) Mgtools won't work. I click on it and a black window flashes and disappears, than nothing. Can't find any advice on how to fix that. Still having browser issues on restart. Google chrome doesn't lag, but it doesn't connect to sites. IE lags and has a lot of issues. I went into task manager, ended a lot of processes and was able to get chrome going. WMP still closes instantly. |
|
#4
|
||||
|
||||
|
I still want you to attach the logs from SUPERantispyware and Malware Bytes even if they did not find anything.
What happened with Combofix? Did you run that? If so attach the log please. I understand MGTools did not work. You need to run the below too now. I want you to run TDSSKiller so refer to the below for how to do so. TDSSkiller - How to run Please also download MBRCheck to your desktop
Download OTL to your desktop.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Attach both of these logs into your next reply.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
Combofix log is the log.txt file in second post.
So, all these scans are after i've ended the c2c.exe process with taskmanager to get google chrome working. Maybe something would show up if i scanned while that was running? |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#7
|
|||
|
|||
|
yeah
|
|
#8
|
||||
|
||||
|
Please re-run TDSSKiller and fix these:
Quote:
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#9
|
|||
|
|||
|
okay
Edit: wth. it looks like it deleted the log where I removed that file. This is after scan after I deleted it i guess Edit: Windows media player works again. Last edited by candys; 05-10-12 at 18:58.. |
|
#10
|
||||
|
||||
|
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
mkay
|
|
#12
|
||||
|
||||
|
Java(TM) 6 Update 21 <--- uninstall outdated java.
We need to run an OTL Fix
Code:
:otl
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
[2012/05/02 16:16:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot
[2011/06/02 16:22:25 | 000,000,152 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~21946148r
[2011/06/02 16:22:24 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\~21946148
[2010/07/08 18:23:54 | 000,004,866 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\bltofzsb.qlf
[2008/08/11 08:38:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
:commands
[EMPTYTEMP]
[RESETHOSTS]
[REBOOT]
Reboot your machine and install the most current and up to date version of Java available here at the below link: Java Runtime 6 Now run OTL again like you did in post # 4 and attach the log.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#13
|
|||
|
|||
|
The otl extra's text isn't appearing anywhere. IE still messed up and c2c.exe process still running.
Edit: Ran otl again and it only opens otl.txt after scan, no extras.txt to be found anywhere on my system - I ran a search for it. Last edited by candys; 05-12-12 at 09:24.. |
|
#14
|
||||
|
||||
|
Quote:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#15
|
|||
|
|||
|
Dunno how to do that, but I file searched for c2c.exe and nothing. Everything else seems to be working fine, but I re-tested it and when I end the c2c.exe process, IE immediately starts working. Google Chrome works fine, btw.
Edit: NM, found a way to get file path and im working on it. |
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
Looks likes it's skype, which would make sense - just got it a couple weeks ago. On restart, IE worked fine even with c2c.exe running, but google chrome wasnt working. I ended c2c.exe and it instantly connected to webpage. |
|
#17
|
|||
|
|||
|
I deleted skype and Both IE and Google chrome are working fine, c2c.exe is gone. No problems on the system now that im aware of.
Edit: Looks like one of my posts was eaten, but c2c.exe's file path led to skype. |
|
#18
|
||||
|
||||
|
If you are not having any other malware problems, it is time to do our final steps:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| MSE only finds: trojan:dos/alureon.a | whey | Malware Removal | 1 | 01-29-12 10:42 |
| AVG finds this, will not remove it | tofu5 | Malware Removal | 6 | 06-26-11 18:19 |
| Spybot Finds | taxximom | Malware Removal | 1 | 12-11-05 15:32 |
| Should everything that Ad-aware finds be deleted? | ColonelAngus | Software | 7 | 07-12-03 00:29 |