Computer Slows Down - then Freezes

Discussion in 'Malware Help (A Specialist Will Reply)' started by ESnyder, Feb 8, 2007.

  1. ESnyder

    ESnyder Private E-2

    I ran steps 1-6 of the Malware Removal Guide - attached are the results. I couldn't find the log for CounterSpy, but would be happy to post it if someone could point me to it.

    BitDefender found some issues, including one called Generic.Malware.SVWk!.E2291F8A, and seemed unable to fix them. Am I just to delete the infected file?

    Many thanks in advance for the help.
     

    Attached Files:

  2. ESnyder

    ESnyder Private E-2

    Here are the HJT and Panda logs.

    Thanks again.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall these thru Add/Remove in the control panel
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_03

    Is Spyware Doctor still installed....?

    Reboot and install Java Runtime 6

    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/1225f8dbc043ba2e1c05/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.

    Now attach new logs for:

    * GetRunKey - please download the current version first!
    * ShowNew
    * HJT
     
    Last edited by a moderator: Feb 9, 2007
  4. ESnyder

    ESnyder Private E-2

    Hi Tim, thanks for the response. I deleted the files and performed the uninstalls you mentioned. Here are the scans you requested.

    No, Spyware Doctor is not still installed, or at least I cannot find it in Add/Remove programs.

    I could not find a newer version of GetRunKey - do you have a link? The attached log is from the version in the Malware Removal Guide.

    Hope this helps.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what any of these are?
    Right click the folders and choose properties and tell me what is reports.

    Unless you know what they are, I'd suggest deleleting them.
    C:\7d2ca63bd33ed795b5d180d9e406
    C:\lxcf.log
    C:\lxcffire.csv
    C:\lxcfinst.csv
    C:\lxcfunst.000
    C:\lxcfunst.csv

    Please tell me how things are running.
     
  6. ESnyder

    ESnyder Private E-2

    Thanks again, TimW.

    Those files were mysteries to me and have been deleted. The computer seems to be running more smoothly - I havn't seen any problems yet but I am still testing.

    What's the verdict so far?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs looked clean (other than those suspicious ones that you have deleted).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  8. ESnyder

    ESnyder Private E-2

    What should I do about the threats reported by BitDefender?

    Thanks for the help.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing ...they were deleted ...some were in your system restore files, which is why we ask you in the final cleanup to turn system restore off, reboot and turn it back on.
    Are you having other issues/problems?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The lxc.... files are more than likely for a Lexmark printer. You do have a Lexmark printer to according to your log.

    The other file with the long hex string is probably due to a failed Windows Update.
     
  11. ESnyder

    ESnyder Private E-2

    I deleted those files as originally requested. I do have a Lexmark printer - although it still works after the deletion.

    Last night I again saw very slowed performance in the "New Account" user name and was forced to reboot. However, using the "Josh" user name has so far presented no problems.

    Two days ago, AVG Free ran an automated virus scan and found no errors. Is there anything else I can check?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs you have been posting in this thread thus far were only for the user account named Josh. If you have problems on other user accounts, you need to clean them up too. Attach logs for the problem account and TimW can assist you if there are any malware issues in the other account.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds