malware issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by ska_t_meladd, Dec 4, 2013.

  1. ska_t_meladd

    ska_t_meladd Private E-2

    i was contacted by my provider. they said i was using 20Gigs of data per day and suggested changing SSID and PW. problem persisted. i came to your run read me forum .i ran all the programs. malwarebites found some infected files and all the others did not. computer was running better than ever! internet usage dropped to 2 gigs per day even was able to update all windows components(previously would fail on download.) about a week later windows could not update and the processes showed it was bogged down with multiple svchost.exe files slowing everything down to a crawl. usage online is still at 2GIGs. so i ran malwarebites again and found nothing. unfortunately i did not to a system restore toggle,also it also wont restore to earlier dates even though it goes through most of the process. i feel i have dug myself into a hole here. so i re did the run read me and these are the most recent logs. which might not help you so i will add the malware logs from when it found issues in the next post.
    THANK YOU FOR YOUR TIME
     

    Attached Files:

  2. ska_t_meladd

    ska_t_meladd Private E-2

    log (21-39-33) was run in safe mode after a restart thother log was run first and found most of the issues i experienced.

    once again thankyou for your time
     

    Attached Files:

  3. ska_t_meladd

    ska_t_meladd Private E-2

    win xp media center version 2002 sp3 32bit sorry for not adding this too
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi. :)

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - (no file)
    • O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
    • O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -

    After clicking Fix exit HJT.



    Delete these:
    • C:\Documents and Settings\HP_Administrator\Application Data\Search Settings
    • C:\Program Files\Common Files\Spigot


    Give Ccleaner a run, not the reg scanner, just the cleaner itself to be rid of some temp files.



    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. ska_t_meladd

    ska_t_meladd Private E-2

    ok, I have completed all steps as described above. they only issue encountered was after the restart. my firewall blocked some part of the getlogs.bat while in progress. Let me know if this is an issue.

    Beyond that I will perform normal operations on the comp to see how well it is working. I have noticed that svchost.exe file slowing my computer is still doing that(i know this comp going to be somewhat slow as it only has a little Processor (x86 Family 15 Model 47 Stepping 2 AuthenticAMD ~2405 Mhz). Went to windows update and no updates needed too

    My firewall is Privatefirewall 7.0 and I am running Microsoft Security Essentials, IObit Malware Fighter v2.2 and Avast antivirus (all updated). is this what you would prefer? is it too much? not enough?

    I previously used Comodo, But searched the antiviral forum in MajorGeeks.com and found it was not preferred anymore.

    I will post any other issues if found within the next week.

    THANK YOU FOR SPENDING TIME ON THIS! Your help is very much appreciated
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. The logs look good. Ready for final steps? :)
     
  7. ska_t_meladd

    ska_t_meladd Private E-2

    Yes I am
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  9. ska_t_meladd

    ska_t_meladd Private E-2

    The spigot file came back on the system. Bogging everything down again. Now what?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What Spigot file exactly? :confused

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. ska_t_meladd

    ska_t_meladd Private E-2

    computer suddenly got slow suspect something was up i ran HJthis and found

    [*]O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"

    which was removed previously. i did just that again along with following the steps as described in the above quote.

    here is the log after i performed those steps
     

    Attached Files:

  12. ska_t_meladd

    ska_t_meladd Private E-2

    windows update seems to be not working too
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I'm not seeing anything else spigot related.

    What happens when you try to update Windows? Any error messages? This may be topic for the software forum though.
     
  14. ska_t_meladd

    ska_t_meladd Private E-2

    I recieve the following message when on the update website:

    The website has encountered a problem and cannot display the page you are trying to view. The options provided below might help you solve the problem.

    makes me think there is something blocking the updates
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What happens when you go to start > all programs > Windows Update and try that way? :confused
     
  16. ska_t_meladd

    ska_t_meladd Private E-2

    that is the way i have tried. And thats where i receive the error message from the site.
     
  17. ska_t_meladd

    ska_t_meladd Private E-2

    Error number: 0x8024402F is the error msg.

    THANKS FOR ALL YOUR HELP! AND TIME! much appreciated
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you keep installing too many protection programs, nothing is going to work.
    • You have 3 antivirus programs install
      • Microsoft Security Client
      • Privatefirewall 7.0
      • AVAST
    • You have 4 antispyware protection programs installed
      • Microsoft Security Client
      • Privatefirewall 7.0
      • AVAST
      • IObit Malware Fighter
    I suggest that you recover from this mess by uninstalling ALL of them right now include uninstalling this too Advanced SystemCare 7. In fact, all of the below are from IObit and should be removed to recover from this mess.


    Advanced SystemCare 7
    Driver Booster
    IObit Apps Toolbar v8.4
    IObit Malware Fighter
    IObit Uninstaller
    Smart Defrag 2
    Surfing Protection


    You need to uninstall all of them to hopefully fix the chaos cause by installing all of these.


    Then reboot your PC.

    After reboot and before reinstalling anything, check if Windows Update works. Make sure that you have not block Windows Update in your firewall. If Windows Update works then pick one and only one Antivirus and antispyware program protection and install it.
     
  19. ska_t_meladd

    ska_t_meladd Private E-2

    will do.
    useful info.

    thankyou
     
  20. ska_t_meladd

    ska_t_meladd Private E-2

    everything removed, Rebooted, firewall disabled, and still the same error

    [Error number: 0x8024402F]

    recommended anti virus/antispyware program?
     
  21. ska_t_meladd

    ska_t_meladd Private E-2

    noticed in safe mode avast was in the admin menu...

    downloaded uninstaller from avast.

    that cleared out avast and now windows updates works! :D

    how bout a recommendation for firewall/antispyware/virus protection without being redundant as I was
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avira or Avast are fine as are several others. You must have caused some issues due to too many being installed and it wound up blocking Windows Update. PrivacyFirewall is a better firewall than the Windows firewall so you could use it but I do not add back all the IObit stuff on top of this. In reality Privacy can probably run along side Avast of Avira even though Privacy has anti-virus-spyware-malware protection due to the fact that it is more in the firewall realm.

    I suggest running the below though so we can check to make sure everything was cleaned up.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file
     
  23. ska_t_meladd

    ska_t_meladd Private E-2

    OK, I will go with Avira, and PrivacyFirewall. but will not download Avira until every thing checks out .

    I will not download an IObit stuff either as recommended.

    Its also obvious to me I should either buy a new comp or upgrade the processor as it is about 6 years old, and is maxed out on CPU. But not to the point where nothing works, its just not fast. which is fine I do no gaming on this comp, mostly online surfing to major sites only or basic office work.

    Thanks Again for helping it is appreciated
     

    Attached Files:

  24. ska_t_meladd

    ska_t_meladd Private E-2

    it took a lot to remove the IObit Crap as i now call it, jeez. had to use IObit uninstaller to remove most of the junk left on the computer,after removing it using ccleaner
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're e welcome. Looks good so onto final instructions again. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds