Lap playing with me

Discussion in 'Malware Help (A Specialist Will Reply)' started by sam9009, Jun 21, 2010.

  1. sam9009

    sam9009 Private E-2

    My entire computer is running very slow form startup to shut down. I keep getting popups from avira anti virus warning me about a trojan I chose to put in quarnatine and I just get another popup right after the popus of the trojan warning doesn't stop
    I get a popup error message about some dr.watson program.

    I also get error message popup saying win explorer needs to close and I did not even try to open win explorer/
    I got a popup from zone alarm but it minimized by itslef and I did not get a chance to see what it said

    The internet works when it wants to and when it does its very slow.

    Help me if possible. Thanks very much.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and then attach the requested logs to your next reply when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    * Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. sam9009

    sam9009 Private E-2

    Issues:
    I had to run superspyware and malwarebytes under safe mode because they both would lock up when I started the scan in normal mode.
    I don't have a cd emulation program

    I did not see any logs under scanner logs for superspywware program to upload
    I can't find log for malwarebytes program to upload
    I did not run combofix because it was telling me that I was running spyware doctor antivirus. I couldn't find this spyware doctor program to disable it so I did not wan to risk running the combofix.

    problems I stilll have:

    spyware doctor antivirus program (can't find it to uninstall)

    popups from shopwiz.net which started today while at the imdb website

    slow startup ( at least 15 minutes)

    concerns:
    task manager says 58 processes, is that a lot?

    Thanks for the help
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    sam9009

    Below are the file locations -

    XP scanner log location:
    C:\Documents and Settings\<insert your username>\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs
    C:\Documents and Settings\<insert your username>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs

    Vista scanner log location:
    C:\Users\<insert your user account name>\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs
    C:\Users\<insert your user account name>\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs

    *It is possible that ComboFix is showing a WMI reference to AV/FW products that are no longer installed, so try it again to completion.

    Please attempt to finish ALL the steps given in the R & R Me guide and attach the requested logs. Without them, I cannot help you.

    dr.m
     
  5. sam9009

    sam9009 Private E-2

    here are the other 3 logs

    Same problems as b4 and got his yesterday and today:

    rundll error loading for wmsvcty.dll and indigonaman
     

    Attached Files:

  6. sam9009

    sam9009 Private E-2

    I guess I didn't upload these so here you ago. Thanks very much.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    sam9009

    <sigh> These instructions from the READ & RUN ME FIRST guide were NOT FOLLOWED:
    *You need to run MSconfig and put your PC into normal startup mode as requested in step 3 of the READ & RUN ME guide.

    Question: Why have you not updated to XP SP3 ?

    Step 1:

    Open Task Manager by pressing ctrl + alt + delete keys simultaneously
    • Click Processes
    • Click Image Name to Alphabetize the list
    • Find the below process
      ApplicationUpdater.exe and click on it
    • Click End Process
    Now close Task Manager

    Step 2:
    Delete this file, as it is no longer needed:
    "C:\Documents and Settings\Computer User\Desktop\MGtools.exe"

    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4:

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Step 5:

    * You ran SUPERAntiSpyware with an outdated definitions database.
    • Open SAS and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new "Complete scan" of your system. And attach this new log.
    Step 6:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 7:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).


    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • updated SASlog.txt
    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
    Last edited by a moderator: Jun 26, 2010
  8. sam9009

    sam9009 Private E-2

    I'm getting the power port on my lap fix, I should get my lap by next week, and I will do these steps. Thanks.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Ok - let me know when you'[re ready to continue with the malware removal.

    dr.m
     
  10. sam9009

    sam9009 Private E-2

    I did everything you said from your last post doc.

    Procedure problems:
    My zone firewall was disabled when doing the combo scan, I don't know why it says it was enabled

    During the getlog.bat process, mg tools got stuck on running processdll.exe and an error message popped up about that and I closed the window and it ask me if I wanted to retry, I click yes but nothing happen so it stopped on the running processdll.exe step.

    I'm not having any malware problems currently.

    Questions:

    Should I just use the win xp firewall and uninstall Zone?
    Should I get AVG antivirus and uninstall Avira?
    What's next?

    Thanks very much.
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, sam9009.

    No - The firewall in XP XP2 does not provide adequate protection and is only an incoming (uni-directional) firewall. My personal choice for an anti-virus program is Avira.

    I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links.[ C:\Documents and Settings\Computer User\desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Using Add/Remove --- uninstall " Dealio Toolbar v4.0.2 " if found

    Using Windows Explorer - find and delete:
    C:\Documents and Settings\Computer User\desktop\GoToAssist.exe
    c:\windows\system32\config\systemprofile\Application Data\qcopjv.dat
    c:\documents and settings\NetworkService\Application Data\qcopjv.dat

    Now open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    *You may want to update to the latest Mozilla Firefox 3 3.6.6 Final

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  12. sam9009

    sam9009 Private E-2

    Did the final procedures

    I got the free edition of outpost firewall to replace the zone firewall

    Can I create a couple of folders on the desktop and put some files in there to consolidate?

    Thanks very much.
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're quite welcome, sam.

    That is not recommended, for the reasons I listed - anything other than links on your desktop invites problems that could be easily avoided.

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds