Bum computer Please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by riproaren, Sep 28, 2006.

  1. riproaren

    riproaren Private E-2

    I have done all the steps in the read and run me first. I have windows xp sp2
    The scans showed numerous things that cant be good lurking in here. This all started a couple of weeks ago when my comp started shutting itself down. Also sometimes my desktop goes rippley? I could not run the windows defender (ran counterspy instead) as I bought this computer through the newspaper (I'll never do that again) for school and apparently this version of windows is not genuine. Unfortunatly I can't afford a new one right now so this will have to do. I have attatched all the logs. Thanks for the help.

    Gary
     

    Attached Files:

  2. riproaren

    riproaren Private E-2

    Here are the rest.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Weclome to Majorgeeks!

    You really don't have that many problems!

    You did not empty your Norton AntiVirus Quarantine as requested in step 1 of the READ & RUN ME. This made all scans take longer and i t made your logs larger.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MSVersion] C:\WINDOWS\System32\internetfeatures.exe

    And since you don't seem to have anything for Symantec installed anymore, fix the below too:
    O4 - HKLM\..\RunOnce: [VcCleanUp.exe] C:\DOCUME~1\LaDonna\LOCALS~1\Temp\VcCleanUp.exe /F C:\PROGRA~1\COMMON~1\SYMANT~1\LiveReg\ /RemoveAll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\internetfeatures.exe
    c:\windows\system32\MYDLL.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode!

    Now open a command prompt window by Clicking Start -> Run, and enter cmd int the box and then click OK!

    At the command prompt, type the following (ignore any error messages):

    regsvr32 /u mwsvm.ocx.

    Still in the command prompt, type the following (ignore any error messages):

    regsvr32 /u ieasst.dll

    Close the command prompt window by typing Exit!

    Now attach a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Sep 29, 2006
  4. riproaren

    riproaren Private E-2

    Ok I think I did all of that right. Things seem to be working ok but still feels like I am lagging. Thought I should mention that a warning about windows virtual memory being to low keeps popping up is that bad?

    Gary
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is more than likely not due to malware. My guess is McAfee is slowing your system down. We can uninstall this and use some free tools to see if this helps resolve this problem. Just let me know if you want to try this.

    Yes this could be a problems too, but this is not malware either. Try the below.

    1. Click Start, then Control Panel.
    2. Double-click the System icon and then click the Advanced tab.
    3. Click the Settings button under Performance option.
    4. Click the Advanced tab, and then click the Change button under Virtual Memory.
    5. Select System Managed Size if it is not already selected. This setting is preferred.
      Optionally, you can adjust this setting manually by selecting Custom, entering numbers into the two fields under Custom, and then click the Set button:
      • In the first field, the number entered should be twice the amount of system memory (in MBs).
      • In the second field, the number entered should be four times the amount of system memory (in MBs).
    6. Click OK and restart the PC.
     
  6. riproaren

    riproaren Private E-2

    Set it to system manage size. Worked like a charm thanks so much Greatly appreciated.:)

    Gary
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds