Computer still slow after directed malware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by magu1, Dec 26, 2007.

  1. magu1

    magu1 Private E-2

    Hi, I'm quite new in the malware removal scene. A week ago, I followed the general instructions of the Read and Run..., and Spybot and Spyware terminator did not detect anything. The info says that Spyware terminator can be used instead of AVG. Bit defender online detected a Trojan.Fursto.A which could not be fixed. As you can see, I took note of the malware names. Panda online detected Trj/Downloader.RKS and reported having fixed the problem. I then turned off system restore and switched it back on, on restarting the computer. I remember saving the logs, but they would not open as I saved them so I deleted them. I tried Read and Run again after that, but nothing was detected. I just recently discovered and tried the Windows XP malware removal on your site. I have done everything from the ComboFix to the MGtools extraction. Attached are the logs. Please help me get my computer back on track. IE7 takes like 20 minutes to load (I've done update after update), Firefox loads after a shorter wait, when I'm typing an email message or any text typing, like now, the words only visually appear after I've finished typing the 4th word. The computer refuses to go into safe mode (I've only used the usual method of pressing f8 after the restart beep). Lastly, but quite important: Spybot takes forever to load after I've clicked the Icon a number of times (note: no online access and cable disconnected at the time) so I can run a scan. Spyware terminator loads a little faster. Worst of all is my purchased Symantec refuses to perform a full scan and the Auto protect has been disabled (I have updated the antivirus successfully, but the online auto fix does not work for my computer). Everything used to happen immediately before the malware incidents. It's all really new and strange for me, do help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it does not say that. The READ AND RUN ME specifies that you must scan your PC with AVG Antispyware and attach the log. Please run it as requested and attach the log.

    You did not allow MGtools to finish running before you closed the command prompt window. Please run C:\MGtools\GetLogs.bat by double clicking on it and do not close the command prompt window until you see the information shown in the snapshot given on the instructions page for MGtools (see: this Using MGtools ) Then attach the new C:\MGlogs.zip file that is created.

    Where am I supposed to see what you are referring to?

    According to our instructions in the READ AND RUN ME you must not touch System Restore until your PC has been declared clean. Whose instructions are you following?


    Most likely due to the fact that you have registry corruption. Even ComboFix noted this.

    Spybot 1.5 is very slow to load. DO NOT click the icon multiple times. Just try to run it once and wait.

    You will probably have to uninstall ALL of Symantec after any malware is removed from your PC. Then you will have to cleanup all remaining Symantec files....etc because it rarely uninstalls properly. Then after a reboot, you will then be able to try reinstalling but I would not do this yet and it may not even work properly afterwards. If it does fail to work after reinstall, you will have to speak to Symantec to resolve issues of why their software is so easily broken by malware and why a reinstall cannot fix the problem.
     
  3. magu1

    magu1 Private E-2

    Hi there, thanks for your response. It turns out, something must have really been wrong, coz when I next switched on the computer it would not go further than a blank page titled <Windows root>system32\hal.dll. I couldn't get hold of an XP reboot CD, and I got so frustrated with the whole thing-( after three weeks of trying to restore the performance of my computer!!), I just decided to go to recovery mode and back to fresh-from-the-factory mode.Now I could open windows. I hadn't made recovery disks prior to the malware attack, and so I lost everything--the only serious thing was my music files, photo albums and my Microsoft 2007 (of which I don't have the original installation CD any longer--it will have a bit of an impact on my writing--The 60 day trial Microsoft 2003 is not as equipped). Is there a program to help recover , for example, my Microsoft 2007 and My documents folder--or it wouldn't be a good idea, as it may put me at risk again?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you restored to factory ship mode. Everything else you had may be gone permanently. You could search around on your harddisk to see if anything you need is there but I tend to doubt it. Any further questions about this now belong in the Software Forum.. This is no longer a malware topic; however, restoring or reusing any files (especially executable type files) could potentially cause an infection if the files you restore are infected.
     
  5. magu1

    magu1 Private E-2

    Hi there, it seems we're back to square one again--even after all that, the computer is once again acting slow--I think there's something going around in the network, but whatever it is has by-passed all my running anti-malware programs. I have Comodo Firewall running, Spyware terminator(with the realtime shield), Spyware blaster and Symantec antivirus(with autoprotect running) and CCCleaner to help with the cleaning and registry check. I updated all the programs today. However, I am having difficulty completing the Symantec update--the last successful attempt was on 3 Jan. I am also having difficulty installing Windows Updates, which is the first measure in computer security. Please help. Should I download and run MGtools and Combofix again?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could have potentially become reinfected from using a USB drive or a CD based on what I saw in you first log. If you had used a USB drive or created a CD on this PC while it was infected, then those items may have become infected.

    You need to re-run ALL of the READ & RUN ME from beginning to end and attach the logs that are requested. Make sure you download fresh copies of all the tools so that you are sure to have the current versions.
     
  7. magu1

    magu1 Private E-2

    I performed the XP READ AND RUN, and there doesn't seem to be any malware according to this process. See attached. My antivirus did catch and delete a "W32 Dotex"
    Another question, everytime I restart Windows, or sometimes just anytime whilst I'm working, my windows installer comes up and attempts to install Quicken 2005. Does this mean there's some kind of hidden malware in the system?I longsince deleted Quicken 2005 in program files. I have also searched in My Computer and deleted anything related to Quicken 2005 in name (one time Quicken 2005 was in a folder called Intuit which I also deleted. Intuit was in Application Data under WINDOWS in the Local Drive. Should I be concerned about these sudden attempts by who knows what, to install Quicken 2005, having not prompted such?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    What is drive F: ?

    I see references to this file: F:\vorlnwj.exe

    You need to delete any copies of this file from all drives.


    If it was deleted, we don't need to worry about it.


    No it means you have problems with Windows Installer. You can post questions about this in the Software Forum.


    Do you have any idea what the below file is for?
    Code:
    C:\WINDOWS\system32\
    unl.exe       Dec 28 2007      102400  "Unl.exe"

    You do need to uninstall the below outdated Sun Java version and install the current version, but I would not do this while still having problems with Windows Installer.

    Java 2 Runtime Environment, SE v1.4.2_05
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds