3 Malware (Possibly More) On My PC - Need Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by HasSanK, Jul 3, 2008.

  1. HasSanK

    HasSanK Specialist

    Here's what I have running at all times:

    AVG Anti Spyware
    AVG Free
    Zone Alarm
    I also use Firefox & I'm running XP Media Centre Edition (SP2).

    Something seems to have gotten past all these though. I have been playing this certain MMORPG (Guild Wars) now for around 2 years without any problems at all, but during the past 2 weeks the game has been CONSTANTLY (every 15 mins or so) disconnecting and sending me back to the login screen. The weird thing is, that when this happens the rest of the Internet still works fine (e.g. browsing websites, using MSN Messenger etc).

    Although, just now it happened once again & my whole Internet wouldn't run including websites, MSN Messenger etc.

    Anyway, I figured it must be a virus or something, so I rebooted into Safe Mode, turned off System Restore & scanned my PC using the following programs: Ad-Aware 2008, AVG Free, AVG Anti Spyware & Spybot.

    The only program that found anything was Ad-Aware (as shown in the picture below)

    http://img387.imageshack.us/img387/9207/31828926xu2.jpg

    I then clicked "REMOVE" & rebooted into normal mode, but the problem is still ocurring. Before I removed the programs, I did a broadband speed test (I'm using 8mb Cable Broadband) & the speed seemed EXTREMELY slow, like something was limiting my connection:

    http://www.speedtest.net/result/291188482.png


    AFTER I removed the program I did another speed test & the speed seems to have increased, although for 8mb Broadband it still seems very slow:

    http://www.speedtest.net/result/291428666.png


    What else do I need to do to prevent these connection drops from ocurring?

    Thanks in advance!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems may or may not be due to malware. The best way to know is by having you do the below.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. HasSanK

    HasSanK Specialist

    OK did everything & no malware problems were found, which is weird.

    Attached are the logs from the programs.

    Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not to me! I did say that your problems did not sound like malware. ;) I will give you one more scan to run just to be on the safe side but if I do not see any problems in it, you will need to look elsewhere for either hardware issues or software conflict problems.

    First you should uninstall this old Sun Java version: Java(TM) 6 Update 3

    Now run this Running GMER to detect rootkits and attach the requested log.
     
  5. HasSanK

    HasSanK Specialist

    Hi again, sorry for the late reply, but here is the attached GMER log.

    Thanks.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The GMER log is clean. You wil have to look into other potential issues with hardware or software. Here are somethings to try before posting in the Software or Hardware Forum.
    • Power cycle any routers and cable or DSL modems.
    • Clear browser caches too.
    • Temporarily shutting down your ZoneAlarm firewall to see if there is any impact.
    • Temporarily shutting down your antivirus to see if there is any impact.
    Since you are not having malware problems, we need to cleanup from running the READ & RUN ME.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. After doing the above, you should work thru the below link:
     
  7. HasSanK

    HasSanK Specialist

    OK did all that and it got successfully entered into the registry, but I'm STILL experiencing the problem, and it's occurring every 10 minutes or so now which is extremely annoying.

    I have my router placed on 2 CD cases on a carpeted floor... could this have anything to do with it? (I'm thinking static?)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware problem. You will have to work this in the Networking or Gaming Forum. I suggest that you first try bypassing your router and using a direction connection from your PC to your Cable modem as a test to see what happens. You will have to reboot your PC or use ipconfig to get a new IP address assigned to your PC from the cable modem.

    Doubt it.
     
  9. HasSanK

    HasSanK Specialist

    OK thanks a lot Chaslang, you've been a great help so far as I've now established it's NOT a malware problem. Anyway, I'll go over to the Network forum & see if they can help any further.

    Thanks again!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Did you try the direct connection yet?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds