Please Help, not sure what it is?

Discussion in 'Malware Help (A Specialist Will Reply)' started by hattrick1, Aug 30, 2008.

  1. hattrick1

    hattrick1 Private E-2

    HI,

    About a week ago I was surfing the net and noticed that something was activating my hard drive for a while, this was not normal. I got off the internet and then noticed that my time on my pc was changed to military time. I also noticed on bootup it was taking twice as long as normal and also on exiting windows it would say windows is closing down and then sit there for like 2 minutes every time(not normal). My performance of the pc is not the way it was either before this incident. :confused

    Any help is greatly appreciated!!

    Thanks!!
     

    Attached Files:

  2. hattrick1

    hattrick1 Private E-2

    :wave
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It does not appear that you are having any malware problems as your logs are all clean. I'm going to have you run one more scan just to look for rootkits but I don't think we will find anything. Please run the below and attach the requested log:

    Running GMER to detect rootkits

    Your problems may be due to what you are running. Perhaps you need to look at what you recently installed and also any updates that may have been performed. Some fairly new items I saw includes the below
    Code:
    "C:\Program Files\"
    NAPOLE~1      Jun 26 2008              "Napoleon's Campaigns"
    NOS           Aug 28 2008              "NOS"
    PANDAS~1      Aug  8 2008              "Panda Security"
    POWERS~1      Jul 12 2008              "Power Sound Editor Free"
    VIDEOLAN      Aug 14 2008              "VideoLAN"
    WARSIN~1      Aug 15 2008              "Wars in America"
     
  4. hattrick1

    hattrick1 Private E-2

    Thanks!!!:clap


    Those files have been on my pc before the problem has started, thanks though!!!


    Ive done and tried everything, will do some more testing then I guess maybe a reinstall of windows.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said your problems began "about a week ago". NOS is newer than a week and VideoLAN and Wars in America are about a week ago. ;)

    Well I don't see any rootkits but I do see a registry entry that is likely an issue. Let's fix it and also cleanup some items from running ComboFix.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Also if your clock is still in 24 hr mode, you can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.
     
  6. hattrick1

    hattrick1 Private E-2

    Hi Chaslang,


    Ok its done and successfull.


    THanks!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. hattrick1

    hattrick1 Private E-2

    Thanks again, youre help was appreciated!:)
     
  9. hattrick1

    hattrick1 Private E-2

    Hi chaslang,


    I know you have done everything you can for me but just wanted to mention this little bit of info that I forgot.

    Everytime on bootup since the problem I get a the little red x popup on bootup, it stays there for two secs and then goes away before I can click on it.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to post about this in the Software Forum to see if anyone has any ideas. Make sure you tell them that you already ran thru the malware cleaning procedures and everything was clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds