Ques about Combofix and AVG

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jackie2000, Dec 15, 2007.

  1. jackie2000

    jackie2000 Private E-2

    My computer was running at a snail's pace so I went through all the cleanup suggested (ridding unused files, ckg startup files, running CCleaner, degragmenting). But when I ran Combofix, it said "completed stage" 01, etc through 40 but then my screen went blank except for it's window that said "deleting files and folders:" but nothing was displayed and it just stayed there like that. After several hours, I had to reboot to get my screen back and reset my clock. I read the text file but all it said was a descr of the system it was running on. It doesn't sound to me like it ever finished.
    Then I ran Spybot successfully. Then I ran AVG antispyware and it finished (deleted 50 files; 30 tracers) but when I selected "Reports" it said there were no reports (and yes I did put the setting to "generate report after every scan" and unchecked the "only when threats are found"--so why no report? I also ran MGtools and did not get any error messages so I'm assuning it was fine.

    Computer still seems slow but not as bad. Maybe now it's just my impatience--it seemed like it took a long time to pull up MS Word2000 but it was really only 15 seconds. I'm running on Windows home edition XP SP2. My computer is about 5 years old--Pentium 4 2.2 GHz 512mb ram. I have Norton Antivirus (free with my internet service). I live in the boonies and have dialup from the Stone Age (I'm not kidding--the phone lines are so old-remember 28.8k connections?).

    Thanks for having such an informative website.
     
  2. jackie2000

    jackie2000 Private E-2

    Forgot the attachments the first time.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks

    While I look thru your logs, please complete the below instructions.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_04
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Jackie\Local Settings\Temp
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well there is not too much to remove in the way of malware, but let's cleanup what I see.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.6.0_03\bin\jusched.exe
    O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O20 - Winlogon Notify: ddcya - ddcya.dll (file missing)

    After clicking Fix, exit HJT.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.

    Make sure you tell me how things are working now!

    If you are still having performance issues, you will have to look into the things that you are running.
     
  5. jackie2000

    jackie2000 Private E-2

    The Mglogs zip file has yest's date. When I ran the getlogs.bat file it said the log would be in MGtools/getunkey.txt so I attached that file too.
    Startup time was reduced by 1 minute so that is an improvement. I downloaded SunJava (took 4 tries, it wouldn't let me use their download manager, some error about the license but I finally got it downloaded). I may switch from Norton to another antivirus--I only have it because it was free from my internet provider and on a CD so now big download required but I saw where it said it's resource heavy so maybe another one might be better for me. I had AVG but thought Norton must be better since people pay for it (not always true).

    Do you know how I can get my old clock format back--I don't like seeing 13:00--I want 1:00?

    Everytime I shut down or restart, I get an error message for dwwin.exe (applic failed because windows is shutting down)--any idea what that is? I get that same message from Norton's ccapp file.

    Thanks alot for your help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the correct batch file. You ran GetUnKey.bat. You need to run what I requested and that was GetLogs.bat which will create all new logs and put them in C:\MGlogs.zip. The C:\MGlogs.zip file is all that we need you to attach. We don't need the individual logs in the MGtools folder. They are all put into the MGlogs.zip file for easy upload.

    I need the new log so I can veryify the last fix.

    That is a correct assessment!


    You change these setting under Control Panel -> Date and Time

    You have a problem in your Windows software or an issue with another program. You will have to debug this in the Software Forum. They will more than likely want to see an Eventlog so you should get one of them too. See this: http://support.microsoft.com/kb/308427
     
  7. jackie2000

    jackie2000 Private E-2

    I did run getlogs.bat
    I ran it again and tried to copy the output but couldn't (it looks like a Dos job to me). So I wrote it down:
    Getlogs.bat (c) 10/02/2006 by Chaslang
    This small batch file is used to automatically run getrunkey.bat and shownew.bat. It is normally just called after installation of the two programs into the C:/MGtools folder but it can be run at anytime.
    Then it showed some dates/beta (last mod 10/24/2007 Vers 2.04) then
    Updating: getunkey.txt
    All finsihed getting uninstalllist
    The log is in C:/MGtools\getunlist.txt


    The Control Panel date/time lets me change the change or time but I don't see where I can change the format from a 24hr to 12hr. I never had it show 13:00 till I ran that Combofix program. Maybe the synchronication server needs to be changed?

    I'll check on the software. Thanks for the link.
     
  8. jackie2000

    jackie2000 Private E-2

    I looked again and it looked like the zip file was updated 12/16 (could there be a delay somehow) so I am attaching it again.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to wait for the programs to finish running! Double click GetLogs.bat and do not do anything in the command prompt window. Let the program run until it finishes. Everyone has a different speed PC with a different amount of other background processes running so how long it takes to run can vary from 35 seconds to a couple of minutes. If you don't do anything else and keep the command prompt window as the top windows, it will run as fast as possible. If you pull another window to the front, the scans will run significantly slower.

    When the scans are finished, the last few lines in the command prompt window will look somethings like the below (click the thumbnail to expand it).

    GetLogs-Final.jpg


    Sorry about that! I'm not sure what I was thinking. The setting you need are under Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.
     
  10. jackie2000

    jackie2000 Private E-2

    Sorry. As soon as I saw the words "all finished", well, you can figure out what conclusion I made. I let it run all the way through this time. Again I do apologize for my stupidity and impatience.

    Thanks for the info on the clock--it was driving me crazy, Don' know why I didn't think of that but I didn't.
     

    Attached Files:

  11. jackie2000

    jackie2000 Private E-2

    I'm so excited. I uninstalled Norton and that took care of my "software problem" plus speeded up shutdown and startup. I can do a complete restart in 1 min 45 secs compared to 5 mins before to do all that. Next step to select and install a less hoggy antivirus software.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean but you should not have started using MSconfig to control startups again. You defeated the purpose of a couple of fixes I was having you do with HijackThis. MSconfig should not be used as long term startup manager. Use a real startup manager (like Startup CPL ) if you really need one but typically there is no real reason to have one.

    You also did not do the below:

    Since you are running Comodo BOClean, I recommend that you uninstall Windows Defender which will also give a boot speed and overall performance improvement.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  13. jackie2000

    jackie2000 Private E-2

    okay. Thank you.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds