Need someone to look at my Combofix log, at your convenience.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by fritzb43, Jul 20, 2014.

  1. fritzb43

    fritzb43 Private E-2

    Hi all: I am trying to fix my wife's computer Win XP. I have the log if anyone could possibly give it a looksee. Many thanks in advance. fritz
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We really need to know what problems you are trying to fix. Combofix is not a comprehensive malware scanning tool and it is definitely not the first thing that should be run. In fact in most cases it should be avoided or at least put off until a much later point in time. If you are having malware problems, we would more likely have you run the below


    READ & RUN ME FIRST. Malware Removal Guide
     
  3. fritzb43

    fritzb43 Private E-2

    Sorry the token has expired - been at the hospital today. Hi! Thanks for your reply - I am at my wits end here. Computer in question is an older computer running Win XP, svc pack 3. The primary complaint is that it runs very slowly. I have paid Avast plus Anti-malware. Total scans by either one produce produce very little positives. When I run either in Safe mode, the PC shuts down after about 15 sec. I confess that I panicked and ran CCleaner. Can provide PC specs + Ccleaner log. Starting over now.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not needed. I only need what is requested in the READ & RUN ME link. Note that most slow PCs are not due to malware....especially older computers trying to run modern applications. Also shutdowns are more indicative of hardware problems especially if it is a laptop.
     
  5. fritzb43

    fritzb43 Private E-2

    Have set today aside to run the tests. Have finished RogueKiller - says I have a rootkit (root-necurs). Report generated. Moving on with the tests (testing only, per you guys) Many thanks. fritz
     
    Last edited: Jul 23, 2014
  6. fritzb43

    fritzb43 Private E-2

    Have one more log, which I will upload separately. I did run into several issues during the scans, especially with Hitman Pro. Which I will share with you soon.

    Rebooted and it took nearly 5 five minutes to settle down and display the desktop. Don't see any improvement, to be honest.

    I apologize for any goof-ups I made in this whole process. I am a humble guitar player, not really comfortable going at it with computers, viruses, etc.
     
  7. fritzb43

    fritzb43 Private E-2

    Enclosed is the zipped log.

    It occurs to me that I didn't press 'Upload' with the first bunch. *sigh* Will send again. Thanks in advance for you patience (wife Barb seconds that.)
     

    Attached Files:

  8. fritzb43

    fritzb43 Private E-2

    Here are the first six.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes because as I stated it is not a malware problem.


    Reasons contributing towards poor performance:
    • Old slow processor - Processor x86 Family 15 Model 107 Stepping 1 AuthenticAMD ~2109 Mhz
    • You really could use another GB of memory - Total Physical Memory 2,048.00 MB
    • Big problem lack of free diskspace - Drive C: Free Space 7.86 GB (8,437,018,624 bytes) you should remove unnecessary files from this drive to help with performance. I recommend keeping at least 10% of you hard disk size as free space. Since you have a 246.10 GB drive this means about 24 GB free. This is not a hard rule but when you get down below10 GB and also do not have enough memory, free disk space is important.
    Howeverthat being stated I do see some junkware to remove and I can also give you instructions to remove some unnecessary ( not malware ) startup processes which may help. I will try to get back to you with these instructions later tonight.
     
  10. fritzb43

    fritzb43 Private E-2

    Items causing sluggishness noted, thank you.

    I did want to point out three issues that I had while doing the tests. I will leave it to you to determine their importance.

    1. A number of the download screens are also showing download buttons for other, unassociated software. This can be extremely confusing to those who can't tell the difference and are apt to click on the largest button, rather than the correct button.

    2. Hitman Pro - the sequence of screens must have changed. Now, and not in agreement with your directions, you must click on the blue Save Log link *before* the NEXT button. With this new setup, if you simply click NEXT, you are taken to a screen which asks for your serial number or encourages you to buy the product.

    3. The How To Attach Items paper contain a number of graphics, which are (I guess) images of buttons. Anyway, these are showing up as red X's on a white background.

    That's it. Maybe this will help other folks. Thanks. fritz
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The instructions did inform you where to click. It gave you info like the below with images.
    I'll look into this. Many programs are constantly changing the way the work which is quite frustrating for self-help sites like this because it thus requires frequent changes to procedures.

    This is a problem on your end. Possibly in your browser settings or firewall. You must be blocking various images which may possibly explain comment #1 of yours. Do you see the images I posted above for DOWNLOAD LOCATIONS ?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What us the below file?

    C:\charlesbuzzardService3170.exe

    It shows as remote access tool which could be a problem if you did not know about it.

    Did you put the below as main Internet Explore start page?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Tools/MYSTARTP.HTM

    Your logs showed you are running both Firefox and Internet Explore browsers at the same time. This is not a good idea with your low memory and performance issues.

    Also not a good idea to run programs like the below at startup. Only run them when you need them.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Documents and Settings\Buzz\Local Settings\Application Data\Conduit
    C:\Documents and Settings\Buzz\Local Settings\Application Data\OpenCandy
    C:\Program Files\Conduit
    C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    C:\ComboFix.exe
    C:\ComboFix.txt
    C:\Combofix_results.txt
    C:\WINDOWS\temp\*.*
    C:\Documents and Settings\Buzz\Local Settings\temp\*.*
     
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\WMHelper.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415c-8A37-763AE183E7E4}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Conduit]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Uniblue\SpeedUpMyPC]
    [-HKEY_USERS\S-1-5-21-1004336348-1078145449-839522115-1003\Software\AppDataLow\Software\Conduit]
    [-HKEY_USERS\S-1-5-21-1004336348-1078145449-839522115-1003\Software\Conduit]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{4A1C6093-14F9-44D7-860E-5D265CFCA9D9}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{DECA3892-BA8F-44b8-A993-A466AD694AE4}"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{26D0D2D9-63E6-4f90-9D78-E68FC5704BAC}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. fritzb43

    fritzb43 Private E-2

    Quick reply to issues you mentioned. The file charlesbuzzardService3170.exe is no doubt left over from when I had DSL. A guru from Portforward.com was laboring to forward ports on my old and not-missed Westell modem-router. Took him quite awhile, but he succeeded. Used remote-controll software - they are very good and very persistent.(Now on Comcast - modem-router is by Technicolor.)

    My start page (mystartp.htm) is simply one large HTML table, laboriously put together by yours truly, from an idea in PC Magazine years ago. It is simply a matrix with categories of web sites in the first column and links pertaining to the subject in the cells of that row. Screen shot on request. Works for me and I even learned to edit the HTML code for revisions.

    As for FF and IE running at the same time, I almost never do that - no need to. I am a long-time FF user, but you know how IE will butt in and try to take over. That's what's happening here. Shutting down FF right now.

    Will conduct your specified tests in about 3 hours from now. Thanks! fritz

    It is *hardware* that hates me. For example, the current PC in question.
     
  14. fritzb43

    fritzb43 Private E-2

    OK, finished the testing. The things I noticed right away were 1. the hard drive activity light isn't on continuously now, and 2. when I click on an app, it starts to load right now, as opposed to a minute or so later.

    This PC is not worth putting much money into, so we will be looking at new laptops this fall probably. In the meantime, I am going to do the following:

    1. Thin out the stuff on the C drive [pictures of cats, YouTube videos of cats, stories about cats & posters of kittens] grrr. They will be archived or be gone.

    2. Once the capacity is less than 90%, I am going to defrag using Auslogics Disk Defrag, which I tried, then bought. I like it really well, but it needs > 10% free.

    I really appreciate your efforts and time spent working with me. I will be donating shortly - the least I can do.

    I am having an continuing problem with the onboard sound in my Win7 system, where the sound becomes progressively more ragged & scratchy until a reboot clears it up (until the next time), but that's an issue for another day. My brother, who knows everything, persuaded me to buy an actual sound card and disable the onboard sound. I told him, "Great, now come over and do it because hardware hates me."

    Computer hardware, that is. I am completely comfortable with the wood and steel of guitar hardware <LOL>. Thanks again, fritz b.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds