Have malware/spyware or something and will just not leave- HEEEEEELP

Discussion in 'Malware Help (A Specialist Will Reply)' started by CARE101, Aug 7, 2009.

  1. CARE101

    CARE101 Private E-2

    I have attempted to rid my computer of something- tried everything under the moon. bought a better router with better firewall- run CA internet security 2009. This whatever has installed itself into my recovery drive and try getting into that! fort knox may be easier. Anyway i ran a HJT and 2 items keep returning yet i cannot find them in the file. i understand not to post anything yet. thank you:confused
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. CARE101

    CARE101 Private E-2

    Thanks Chaslang!

    I did have some infections after running superspyware and malwarebytes. I have had an infection for quite some time, have used system restore many times and each time you hear the chomp chomp of files being deleted.

    i installed a new hard drive and figured out the virus is in the disk to reinstall the operating system and software.

    ok, now i just want to make sure my system is completely clean and running right. there are some AOL items that keep reappearing after being deleted. Also cannot delete bigfix in registry or AOL- they keep coming back! AOL is in the system services and when i uncheck it my system restrts telling me it is in diagnostic/selective mode not normal mode.

    I ran recovery- deleted all adobe, antivirus, java- etc and updated windows plus installed CA internet secuirty. I will include the ca log next. the system was clean, no double anti virus etc.

    I am soooo sick of redoing this i could cry. my posts are attached in the 2 e-mails suggested.

    thank you for all of your help and if i canhelp anyone with real estate ills in sw florida know i am here to help!! I pay it forward in life all the time.
     

    Attached Files:

  4. CARE101

    CARE101 Private E-2

    CA log attached as it said i had something too. i feel as if i am missing filed needed to run things- my antivirus will not allow email scanning and my windows will not update as I get a page error when running the validation tool- (little yellow caution sign at the bottom left corner).
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were just restoring your malware. Once a PC has malware and you get it removed, you need to delete ALL system restore points since they are not trustworthy as they may be infected.

    Huh? If you have an original CD, it is highly unlikely to be infected. If you have a copied CD or a CD you made yourself containing additional files then it could have been infected when it was created.

    Do you use AOL or anything from AOL like AIM?

    At this point, you must STOP doing anything on your own and only do what we ask you to do.

    You need to remember to disable your protection software before running cleaning procedures. Your ComboFix log shows you had CA Antivirus enabled but their firewall was disable.

    Please remove MGtools.exe from your Desktop ( C:\Documents and Settings\Owner\Desktop\MGtools.exe ) this is not where we asked you to save it to.

    Your Malwarebytes log shows that you took no action. Did you save the log before fixing things or did you forget to fix the problems it found?

    Some people seem to think that the below service is malware. I think it may be part of your CA software. Probably related to internet content filtering (like parental controls).
    O23 - Service: WinSock Svchost Manager (WinSvchostManager) - Unknown owner - C:\WINDOWS\system32\svcprs32.exe

    Does this file exist? If so, please put a copy of it into a ZIP file and attach it here.

    Your logs are basically clean other than what has been deleted. What actual problems are you having right now?
     
    Last edited: Aug 12, 2009
  6. CARE101

    CARE101 Private E-2

    some online programs do not work and the error code says it is from badly infected machines. programs not responding and hanging up, my firewall automatically disables at times, i have some system processes taking large system resources at times. email is very slow and shows sending 2 messages when i am sending only 1. I use outlook 2007 an shows 4 email accounts sending and receiving when there are only 2. I have many many Svchost running at the same time up to 10 at times and at times my cursor disappears and will not go where it is needed but only behind open windows, stops at start bar top but will not allow you to hit start. After the CA found 2 issues the firewall disabling on its own has stopped. It seems i am missing some important windows ior registry files now per the tech at the MLS (multiple listing service) i cannot use some features of their system and the error says my machine is badly infected.

    Thank you for all of your help. i am ordering new recovery disks from gateway today just in case. i was stupid not to have made them immediatly upon starting machine prior to ANY internet connection.
     

    Attached Files:

  7. CARE101

    CARE101 Private E-2

    sorry Chaslang i see i am not so good at using quotes- my answers are in the quote box. I am learning!! Thank you again!!
     
  8. CARE101

    CARE101 Private E-2

    Now anti Virus turns off automatically and will not allow me to turn back on.

    Thank you for any help!:(
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are not CompUSA. You need to do only what we ask you to do and nothing else. If you want to work with CompUSA you can do that, but then you should not be working with us. I thought CompUSA went out of business.

    You need to be specific and if it is not occurring all the time then it is less likely to be malware.

    Also may not be malware. Check how many accounts show in Outlook and remove any unneeded accounts.

    Many svchost.exe processes are always running in Windows. Your last logs however only showed 2. You could be seeing more at other times. Your CA software may also impact how many of these are open since it loads an svchost manager.

    Again you will have to be more specific since I don't know what you are referring to. If you are missing entries in your registry that are required to run some software, you will need to reinstall the software.

    Recovery Disks are not what I personally would want. They put your PC back to the way it was shipped. What you want is a Windows XP SP3 installation CD so you can repair problems within the Windows Operating System without having to go back to a state that no one wants (i.e, the state a PC is shipped in with all the useless junk that the company put on it --- like AOL software ---and none of the software you have installed and setup afterwards.)

    I suggest that you uninstall all this CA software that does not appear to be working properly anyway. It also could be just getting in the way of cleanup (i.e., preventing us from removing infections manually. After uninstalling it, reboot your PC.

    After reboot, run Malwarebytes and first update it. After update, run a full system scan which will take longer and is more thorough. DO NOT save a log until after you fix what is found. Make sure you fix/quarantine what is found and then immediately reboot your PC. After reboot run another scan (a quick scan is fine). Attach these two logs.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • the 2 logs from running Malwarebytes twice
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. CARE101

    CARE101 Private E-2

    I did as you requested however I had to do a complete destructive recovery again as my computer was extreamly slow and could not get online.

    CompUSA is open in Fl and a few other states or maybe just TX, they are part of Tiger Direct. I only did what they told me about the CA and new hard drive. I have NOT done anything else but what your message say to do. I do thank you for your help and appreciate it.

    When I did the recovery I deleted all the AOL, BigFix, MSN, adobe, java, flash and anti virus/spyware files. MSN gaming zone will not go away. When i use unlocker to delete it i get that it is tied to Winlogon.exe process and says

    \??\C:\WINDOWS\system32\winlogon.exe

    As for the windows xp media center sp3 disk i have none, only the recovery disk i created per gateways instructions.

    Whatever i have actually makes a sound like chomp chomp chomp i assume it is deleting files?? after i deleted all the flash files it has stopped but that msn gaming comes back.

    I look forward to your reply.

    I included a combofix file as I did everything you said in your first reply just to make sure all was clean and it deleted a recycler file ending in 500.

    Thank you again!!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But I did not suggest another destructive recovery followed by you deleting a variety of things from your computer including MSN gaming zone. You probably just need to uninstall the HP Internet Games that were installed. They should appear in add/remove programs. However none of this is a topic for the malware forum anyway so you can post about issues with doing recoveries and uninstalling factory pre-installed software in our Software Forums if you require help with this.

    Your logs are clean, but your system is unprotected now. The last step in the below covers getting properly protected.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Aug 26, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds