My CPU Infected...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Epope, Jul 12, 2008.

  1. Epope

    Epope Private E-2

    Hey everyone I could really use some help with fixing my cpu. I seem to have been infected with flec006.exe as well as some other malware. I have run Regrun5 and removed the flec and srosa.sys however, my cpu is still running slow...

    I am not the best with CPU's but I do know a little bit...Hopefully you guys can help cause I really don't have the money to take it to somewhere to have them look at it.

    I can follow directions fairly well and pretty understanding on the things that go on with this site however, I may need a little more instruction than the average. With that said can someone help and if so what would you have me do first. Thanks everyone....I appreciate it...

    Everett:(
     
  2. Lev

    Lev MajorGeek

  3. Epope

    Epope Private E-2

    Alright I did what you asked still having probs....:-/

    Well things are going a little better my cpu is running at a normal idle rate however, I encountered some errors while doing the cleaning which leads me to believe I may still be infected or something was changed by the infection and is causing error..

    1. CCleaner wasn't able to run.
    2. Spybot Wasn't able to run.
    3. My first scan with SuperAntiVirus crashed so I did what you asked set the settings to the kernel and it completed the scan however, when I quarantined the infections and removed when I restarted it crashed. So I had to go back and restart from last known good start. Which I think may have brought back the infections. So I went back in and removed the infections and restarted.
    4. Malware found a bunch of infections which I went back and removed through there.

    So all in all I am going to post this along with my logs and try and go back and run ccleaner and spybot again to see if they will work now. But if someone can look at the logs and let me know if they can see the possible error...

    Either way things are running a lot better than before and I want to thank this forum. You guys ROCK!:)
     

    Attached Files:

  4. Epope

    Epope Private E-2

    Alright I did what you asked still having probs....:-/ HERE IS MY MGLOGS UPLOAD.

    Well things are going a little better my cpu is running at a normal idle rate however, I encountered some errors while doing the cleaning which leads me to believe I may still be infected or something was changed by the infection and is causing error..

    1. CCleaner wasn't able to run.
    2. Spybot Wasn't able to run.
    3. My first scan with SuperAntiVirus crashed so I did what you asked set the settings to the kernel and it completed the scan however, when I quarantined the infections and removed when I restarted it crashed. So I had to go back and restart from last known good start. Which I think may have brought back the infections. So I went back in and removed the infections and restarted.
    4. Malware found a bunch of infections which I went back and removed through there.

    So all in all I am going to post this along with my logs and try and go back and run ccleaner and spybot again to see if they will work now. But if someone can look at the logs and let me know if they can see the possible error...

    Either way things are running a lot better than before and I want to thank this forum. You guys ROCK!:)
     

    Attached Files:

  5. Epope

    Epope Private E-2

    Re: Alright I did what you asked still having probs....:-/

    Alright CC cleaner worked. :) Not sure what to do with it though but the program loaded. Going to try spybot now.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geek!

    You have started 3 threads for your malware problem. I merged all threads back into 1 thread. Please remember to stay in one thread. You should not be starting a new thread each time you post.

    You are running this PC with NO protection at all. No firewall, no antispyware, and no antivirus. WHY???? Your PC was very very badly infected and still had some additional problems. Not having protection is the main reason for being so badly infected.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 14, 2008
  7. Epope

    Epope Private E-2

    Chas buddy you ROCK!!

    Well I think I did everything you said to do...Here is the logs you requested. How is it looking now? Better? Also what should I do with the REG Edit that you had me save to the desktop?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not address my question
    We have a little more to do. A couple items in your registry still did not get fixed.


    Download Registry Search (see the link titled RegSearch Download Link)
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • Enter SROSA.SYS in the top area of the form and then click "OK".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • the log from RegSearch
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. Epope

    Epope Private E-2

    Hey Chas....

    Sorry for getting back to you so late...I have been busy...But I definitely appreciate all the help to date.

    Here are the logs that you asked for...Ohhh and since the last time we spoke I downloaded AVG...:) Thanks again Chas for all your help...

    Computer seems to be running good...Sometimes idles' high but maybe the last few things we did will clear that...

    Let me know if you have any suggestions...:)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will need a real software firewall. The Windows firewall is not adequate. You will see free firewalls listed in the link given in my final instructions.

    Now let's cleanup after SUPERAntiSpyware. Copy the bold text below to notepad. Save it as fixSAS.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    After clicking Fix, exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds