Hey (Slow Pc)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Dynex, Feb 25, 2009.

  1. Dynex

    Dynex Private E-2

    I have had Malware in the past, and I remember how good you guys are, so I came back here and did my best to follow the instructions.. probably not 100% but hey I tried!

    So Attached are the logs.. I know im infected with VUNDO, not sure if its gone now. My computer was extremely slow. When loading the startup programs it would literally freeze for 5 minutes. MY computer is super fast, with amazing hardware, so that was a good tip that I had a virus. It would also not load things like online MUSIC, or Yahoo Videos when I was trying to watch a news report. And It would not enter GMAIL. Those were other signs something was wrong.

    For some reason SUPER anti spyware did not save any logs. Its checked that I want it to save logs, and I followed the specific instructions for SAS. Yet I see no logs in the preferences, and I physically checked the Superantispyware folder in C drive also. No logs. I ran the scan twice, for 20 minutes, (total of 40 minutes) and It saved no logs each time. MY exe was renamed to SAS.EXE before i started the scans. No clue whats up with this. I dont even care, I am not going to waste another 20 minutes unless its absolutely necessary, hopefully the other three programs will be enough to deal with my problem.

    Thanks please let me know if I did anything wrong..
     

    Attached Files:

  2. Dynex

    Dynex Private E-2

    So people who posted today get replies but I dont? Okay...

    Also you dont need all those LOGS that come with the MG zip file. There is something in the world and online called, PRIVACY. And this is an invasion of privacy for you to see what programs I have installed on my computer.

    All I have are games, And I gave you all the required logs, but that doesn't mean I approve of what your doing. In the past you easily removed malware with just a HIJACKthis log.

    All that extra information although maybe helpful, is not needed.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but that is not how it is supposed to be. But when you add a message you bump your thread and will not get an answer any sooner.

    Yes we do which is why we run those scans. If you are such an expert at what is needed to remove malware, why are you posting here for help? If you don't like it, then you don't have to post here. We are a malware removal forum! Not a HijackThis reading forum which by itself is basically useless against today's malware.

    This was absolutely never true. HijackThis was meant to report browser hijackers and it showed a few running system processes and a very small number of registry keys. There are tens of thousands of registry keys. A HijackThis log alone will not allow your PC to be properly cleaned. It never has.

    If you want our help, you still need to attach the ComboFix log. If you don't want our help, I will simply delete your thread since you are worried about info in the logs which is really not a problem.

    Your SAS log should be in the below folder:
    C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs

    Since no log is shown, this normally means it was not run thru to completion or somehow you stopped it from saving the log. The above is the default and it always saves logs there even if nothing was found.

    By the way the Vundo infection you have may have well been cause by Messenger Plus! Live which you have installed and we recommended in the READ & RUN ME to uninstall. This program and its sponsor program are responsible for tens of thousands of infected PCs.

    Your MBAM log shows that you Took No Action. Did you actually fix what it found and just save the log before fixing?

    Did you knowingly install Freecorder Toolbar? It is not recommended. Neither is BearShareMediaBar. See the below:

    http://www.spywareremove.com/removeBearShareMediabar.html
     
    Last edited: Feb 28, 2009
  4. Dynex

    Dynex Private E-2

    Yes I need your help.

    I know, I read someplace here that older threads will get replies first. But I was noticing I made my thread on the 25th and people who made their thread on the 26th were already getting replies. Which is why I made a second post.

    Well I posted here around a year ago, maybe more. Superantispyware, MBAM, COMBOfix, all never existed. You used to tell people to run two browser virus scans, and we would install Adaware, and Spybot, then we would send a hijackthis log, and someone would help us select what to remove.

    I knowingly installed freerecorder toolbar because I can record sounds off my web browser and turn them into MP3 files. So Songs off of You tube usually, which i cant find anywhere else.

    My Limewire wasn't working so I installed bearshare temporarily but I didnt like it so I removed both limewire and bearshare. I guess bearshares media bar lingered behind. Usually I dont let programs install other applications, like toolbars or sponsor porgrams, but I wasn't paying attention this time since I was in a hurry. Ill remove bearshares media bar.

    I forgot to install and run combofix.. no idea why.. I downloaded it though

    Also I use Msn messenger, so what should I do? If I uninstall it then how do I talk to people? Install an older version?

    I found a folder called APPLOGS, not LOGS, and inside the format for the files are.. .SDB, my scan fully ran, and was completed both times. In preferences its checked to save logs. So any idea why the logs aren't being saved? Unless the .SDB files are the logs you need?

    Ill attach the combo log soon.

    Also is Jetico Personal Firewall a good firewall?
     
    Last edited: Feb 28, 2009
  5. Dynex

    Dynex Private E-2

    Combo log Looks the same like every log to me. Has Program files, Registrys etc.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This can sometimes happen for two reasons.
    • the people who are answering other threads, are not sure how to deal with your problems
    • people who are answering could be at working and have limited time to answer and thus only answer threads they can answer quickly since they do not have time to compose longer fixes.
    Yes about 3.5 years ago we ran PandaActiveScan, BitDefender, Ad-Aware, Spybot and HijackThis and wanted logs from all of them. But just like malware has evolved, so has our cleaning process. We had to evolve to be able to fix all the newer forms of malware as those other scans and logs were not adequate....especially HijackThis. If we did not change, and add tools like MGtools and ComboFix we would have missed many malware files and registry entries over the last few years. And if we did not dump useless programs like Ad-Aware and start using SUPERAntiSpyware and Malwarebytes, are manual cleanup steps would be very long and complex.

    I did not say MSN Messenger. I said Messenger Plus! Live which is not from Microsoft.

    Not the same thing. The Logs folder is where text logs will be saved when the scanner is run. If there are no logs here, it means either the scan was not run, or the scan did not run properly.

    Don't worry about it now. You can run it again if you wish to see if it saves a log but right now I'm not sure I need it unless it is still finding problems.

    Yes but it is shareware not free. See this: How to Protect yourself from malware!
     
    Last edited: Mar 2, 2009
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only to the untrained eye. There is a lot of additional info in there and even in the very beginning you can see that additional malware files and a malware driver were removed.

    You forgot to answer my question about whether you actually had MBAM fix what it found. Your logs shows you took no action.

    Do you know what the below folder is for that showed up on Feb 21, 2009?
    C:\Program Files\BlackIsle


    Uninstall the below software:
    Java(TM) 6 Update 11
    Java(TM) 6 Update 6
    Java(TM) 6 Update 7
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Mar 2, 2009
  8. Dynex

    Dynex Private E-2

    I have Black Isle folder twice.

    One folder contains. Baulders Gate, Icewindale

    And the other folder has Fallout 2

    Yes when I ran MBAM I fixed all the problems it found. And It required me to restart the PC to fix 3 of the problems. So I did that.

    I uninstalled Bearshare media bar
    Viewpoint
    Java 11,6,7
    And Messenger Live Plus

    Im trying to run combo fix but it keeps going to a blue screen and does nothing.. Ill post the log when i figure this out.
     
  9. Dynex

    Dynex Private E-2

    Ok here they are, sorry for the delay.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean but you forget to install the current version of Sun Java so you do not have a Java version installed right now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  11. Dynex

    Dynex Private E-2

    Ok thank you chaslang. :)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds