Still Having Problems (Combofix took forEver & did something odd)

Discussion in 'Malware Help (A Specialist Will Reply)' started by AngelsWilliam, Nov 16, 2009.

  1. AngelsWilliam

    AngelsWilliam Private First Class

    Okay, my laptop has been sluggish for a while from time to time when I was in Firefox or had Firefox, Last.fm, and TweetDeck open at the same time, but I always thought it was because
    1. the low connection to our wireless router
    2. too many memory hogs open at once
    3. Firefox doing its crash thing (it crashed on me every now and again, and the other 2 soon followed)

    My father has also been having trouble with a sluggish computer, but Mom and I just assumed it was because he got impatient and kept clicking and clicking on things in his frustration when things didn't immediately happen.

    We-e-ell, he and Mom both had trojans come up on their Malware Bytes scans. I hadn't run that on my laptop in quite some time, so I did, and it came up fine. Then, I started getting funky messages like my firewall had a fatal error and needed to close or some such.

    Also, as I was dinking around your downloads for something else, I spotted that your pick for antivirus software was PCtools, and I thought to myself that it was probably better to have the same antivirus as I do firewall, so I downloaded that, uninstalled Avast!home, and installed PCTools antivirus. I also installed Threatfire beta, but I have since uninstalled that. I was going to reinstall that, but my system seems to be running more happily without it, so I'm not going to.

    Anyway, after I installed PCTools antivirus, things just went all to hell. I started getting all kinds of messages about how there was a new update for it (even though I had just updated it), and once I had downloaded the update, I got a message saying my computer had to restart in order for the update to be installed. Then when my computer came up, it didn't get past the wallpaper coming on (no icons or taskbar). It brought up the taskmanager when I did ctrl+alt+del, though, so I was able to shutdown that way.

    I ran SAS, and it found 2 occurrences of a trojan called FAKE.ALERT, and I thought "a-ha!" I took care of that, and then I uninstalled Firefox (because it said used rarely in my program list) and went directly to the site (instead of doing the update through the program) and downloaded it and installed it. I then uninstalled PC Tools antivirus and went directly to the PC tools site and downloaded it from there and reinstalled it. It found 2 trojans (3, actually, but one of them was Combofix, so I ignored that) after not finding anything all the other times I'd run it.

    I ran SAS, MBAM, Combofix, RR, and MGTools, and I am still having troubles with PC usage going up to 100% when only 1 thing is open, funky error messages like "spooler subsystem has been shut down to protect your computer from potential risk," or something like that, and just generally odd behavior. Plus, like I said in the heading, Combofix took a lo-o-o-ng time to finish, like maybe 15-20 minutes minimum, and during stage...4, I think it was...it printed out this funky thing that looked like the "about" page for some kind of software. *scratches head*

    Oh, and I've lost my job, so...no rush anymore, other than...it's National Novel Writing Month and this is my writing computer. *bites nails*

    Thanks, folks!

    Um...It won't let me post my Root Repeal log, no matter what I name it. It says I already posted it with one of my previous posts. I did post RRlog, but I didn't post it under another name.... Is there a way you can delete that from that post or something? Or, if the file is identical, maybe you don't need to. I guess I'll just go ahead and post MGlogs to this since RRlog won't attach.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download HostsXpert and then follow the below steps.

    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program


    I strongly suggest that you uninstall ThreatFire. It is a serious resource hog and is virtually useless.

    Your MGLogs did not have any system info, so I can not see how much RAM you have nor how full your hard drive may be. Please run the C:\MGtools\GetLogs.bat and make sure it runs to completion and then attach the new MGLogs.zip
     
  3. AngelsWilliam

    AngelsWilliam Private First Class

    Yep, already noticed and did so. :)

    Odd. Okay, I did as instructed. All of it. Hope it all works better this time. MGLogs.zip attached.

    Thanks for responding so quickly! :wave
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At TimW: In lieu of having the sysinfo.txt log, you can get the info you need from the ComboFix log (for total and free memory) and from newfiles.txt (the free disk space). But note that the ComboFix log should be indicating free memory when no protection software is running thus it would be less under normal conditions of what you would have seen in sysinfo.txt

    From ComboFix:
    Code:
    Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.[B]511.139[/B] [GMT -5:00]
    From newfiles.txt
    Code:
                   3 Dir(s)  16,409,350,144 bytes free
     
    Last edited: Nov 20, 2009
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. So unless you are having any other issues, we shall do our final cleanup.

    I would recommend that you double your amount of RAM.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds