Malware Problems (?)

Discussion in 'Malware Help (A Specialist Will Reply)' started by BluGoat, Mar 22, 2010.

  1. BluGoat

    BluGoat Private E-2

    Hello,

    Hoping for some help from the illuminated ones here - Not very tech savvy.

    SYSTEM:
    Running P4 WinXP v.2002, SP3 34bit, CPU 2.40GHz, 2.9GHZ, 760 MB of RAM

    SOFTWARE:
    Anti Malware I've Been Using: SpywareGuard, Winpatrol Pro, Avast free, Spybot S-D, ZoneAlarm free - no problems in the last few yrs. Avast is newer on the sys (3mths) as I switched from AVG

    PROBS:
    -For the past 1 1/2 wks my computer has been re-booting, moreso in the past 3 or 4 days (every 10 or 15 mins).
    - Firefox hanging
    - any app/prog randomly hanging
    - mouse freezing so I have to restart the computer
    - Avast, Spybot and/or Zonealarm will all disappear from the task bar and I'll find them shut down.
    -ZoneAlarm will crash and pop back up with all its previously monitored programs cleared from its program list.

    What I've done so far:

    - ran MS malicious software removal tool
    - updated Java
    - performed MG suggested 'housekeeping' procedure found on another thread
    -downloaded MG suggested anti-malware and ran it after disabling My own

    (I realise this is potentially a memory prob, but, it doesn't 'feel like it', nevertheless, I will check that out once I've exhausted the questions at hand-is that the correct way to go about this?)

    ATTACHMENTS:
    MGlogs.zip contains 9 files, 1 of them a HJT log. Therefore, I must ask, should I post all of them? I will wait to hear from you on that.

    Attached are logs from mbam-log, ComboFix and Root Repeal. SUPERAntiSpyware would not complete it's scan, it kept hanging and freezing the mouse, causing Me to reboot.

    I hope I was able to explain myself clearly. I'm off to bed as it's 4AM.

    Many thanks in advance if you've even taken some time to look at this,

    Sincerely,

    ~Blu
     

    Attached Files:

  2. BluGoat

    BluGoat Private E-2

    Re: Malware Problems (?) Additional file - Avast Log

    I just checked the Avast logs and it's reporting a trojan; WIN32:Delf-MZG[Trj].

    Computer still rebooting randomly.
     

    Attached Files:

  3. BluGoat

    BluGoat Private E-2

    RE: My 2nd post. I'm aware that Avast was "falsely reporting WIN32:Delf-MZG[Trj] ( http://tinyurl.com/ygbt68l ) but, these files are in my Avast virus chest. Should I simply restore them?

    ~Blu
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes restore the files that avast quarantined.

    We request that you attach the whole zipped file and then there is no need to attach individual logs ;) Do this and then I can review the logs.

    C:\Mglogs.zip
     
  5. BluGoat

    BluGoat Private E-2

    I was able to restore all but one file without errors. The last was restored with the error message; "restored with errors because file in use". I could not find where to disable it ( C:\PROGRA~1\SPYBOT~1 ) before attempting to restore it again.

    Thank you! done.
     
  6. BluGoat

    BluGoat Private E-2

    I must have done something wrong on my last attempt to upload MGlogs. Here goes again.

    ~Blu
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\WINDOWS\system32\PerfStringBackup.TMP
    • At the upload site, click the browse button.
    • Next click Submit file
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    When you last ran MGTools.exe you should have had the option to agree to the Trend Micro Hijack This license. There is a bug, and you have to accept to it by clicking "yes" twice. Please re-run MGTools.exe by double clicking it's file and this time let's see if we can get a HJT log.

    I am not seeing anything much in your logs other than the file I just want you to run through jotti. More than likely it is legit.

    So it may be that I will be sending you to the software forum soon, where you can discuss reasons for your problems, perhaps a possible protection software clash....

    Don't forget to attach the C:\Mglogs.zip as well as posting the jotti results. :)
     
  8. BluGoat

    BluGoat Private E-2

    Hi Kestrel13, Thanks for your help with this!

    Please excuse me if I'm being obtuse, I'm not sure what you mean by (If more than one file needs scanned they must be done separately and logs posted for each one). If you could clarify that statement, it would be helpful.

    I'm assuming you wanted me to run PerfStringBackup.TMP through Jotti and, I did just that. Here is the link http://tinyurl.com/yzkn4st

    Attached again is the MGlogs zip

    ~Blu
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No worries, it's often the case that there are a couple of files we want jotti to scan and not just the one, so we say: "If more than one file needs scanned they must be done separately and logs posted for each one" :)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. BluGoat

    BluGoat Private E-2

    I am still having malware problems, my computer keeps rebooting. Therefore, I'm not even able to follow your, "final steps" cleanup procedure until I can get that to stop. One thing I found in ZoneAlarm today which is disturbing is that, ZA has recorded a file which I've blocked from internet access - that file is as follows:

    Product name NirCmd
    File name C:\32788R22FWJFW\NirCmdC.cfxxe
    Last policy update Not applicable
    Version 2.35
    Last modified date 4/20/2009 12:56:26
    File size 30 KB


    I cannot find this file in ZA's specified path as above. This is the link I found for it http://www.nirsoft.net/utils/nircmd2.html. I did not download this thing (not knowingly anyway) nor have I ever seen it before. Can you advise on how I can get rid of it, I can't even find where it is...well, not yet

    ~Blu
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    nircmd is a valid tool from NirSoft ( see http://www.nirsoft.net/utils/nircmd.html ) It was put on your PC by ComboFix.

    Also, considering your logs are malware free, as I said, you will have to visit the software forum now to resolve any outstanding problems. :)
     
  13. BluGoat

    BluGoat Private E-2

    Thank you!
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're welcome. safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds