Concerned of Trojan and IE problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Brokenbones, Jul 6, 2012.

  1. Brokenbones

    Brokenbones Private E-2

    Hello I'm new to this but want to learn. The person I had set up my personal PC a couple years ago didn't do a very good job! I'm starting to notice some problems accumulating in regards to security,slow PC,programs using high memory and a possible Trojan virus present. Is there way you can help? I have system info if needed also.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing anything except:

    C:\WINDOWS\system32\cmdhide.exe <--- Did you purposely install anything to hide command windows?
     
  3. Brokenbones

    Brokenbones Private E-2

    Sorry it took so long to reply the day after i posted this something happened to my internet connection through my computer something got changed??Really weird I finally did a older restore point. Anyways no I have never touched C:\WINDOWS\system32\cmdhide.exe. What does that mean? Does providing a highjack this log show anything different?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\WINDOWS\system32\cmdhide.exe <--- You can delete it then. I have already seen yoour HJT log, it's in the MGlogs.zip. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  5. Brokenbones

    Brokenbones Private E-2

    I wanted to say thanks for your help so far normally i find it tough to get help on these type of forums because i don"t know as much as I'd like to. But it doesn"t seem like i"m out of the woods yet. I removed everything you asked except for combo fix. I can delete the icon on desktop but the Qoobox in C drive says access denied in use by program. I've tried reading forums on how to uninstall. Tried run combofix /uninstall can"t locate tried safe mode nothing still. I tried reinstalling not running program still no removal. Now it also seems like my CPU is running slower than ever explorer.exe is running at 68000k mem usage which i has never been ever. I've had the paid version of SUPERAntiSpyware professional on my CPU for two years. What should I do
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If we used ComboFix, you can delete the

    • ComboFix.exe file
    • C:\ComboFix folder
    • C:\QooBox folder
    • C:\WINDOWS\nircmd.exe
    • C:\combofix.txt
    • C:\ComboFix-quarantined-files.txt logs that was created.
     
  7. Brokenbones

    Brokenbones Private E-2

    Okay good to know cause I searched and read up on how to remove for couple hours and still nothing.I deleted C:\WINDOWS\system32\cmdhide.exe also. There"s a bunch of questions I'd love to pick your brain on but so want to sound like a window licker.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What's the matter? What would you like to ask? :)
     
  9. Brokenbones

    Brokenbones Private E-2

    I guess it's cause you can look it up but trying to find what your looking for is pain in the butt. One is is about the permissions on your computer,what should they be set to exactly?it's so over my head. Recommended browser?Windows update doesn"t work. When I scan with wise registry cleaner 7 gzip archiv, Rar-archive, Tar-Archiv, ,Gziptar-archiv, and Ms-cabinet-archiv come up is that normal? Just feel dumb asking you this stuff anyways combo fix what can I do
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What permissions?

    Hmm, whatever you prefer! I use Firefox personally.

    What error message do you get?
    Yes, but it is not advisable to fix anything with registry scanners! ;)
    I told you what to do already with deleting related files/folders.
     
  11. Brokenbones

    Brokenbones Private E-2

    Firefox I use it but hear nothing but complaints. surprised.
    [Error number: 0x8007050A
    So I'll uninstall wise registry cleaner.
    Ok sorry on combo fix stuff except Qoobox says C:Qoobox/backend/ acess denied
    Service Control Manager error %%1290
    Dcom error %%1290 attemp to start service wuauser says from not enough ram I thought there was tons on this computer.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't worry about the combofix back up folder for now. You can post about the other issues in the software forum. :)
     
  13. Brokenbones

    Brokenbones Private E-2

    See Window Licker. Thanks again for your for the help I really do appreciate it. I may ask other dumb ? sometime. Do you mind if i just send you a message instead of me looking like tard spot through threads? If not no worries. Lates.

    Oh ya one last thing read in a bunch of places that having Qoobox by itself can be dangerous True or N??
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. :) And no, sorry, we do not operate via private message system. :(

    It would only be dangerous if bad stuff was in there that you decided to restore. ;) Let's get rid of it.

    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
     
  15. Brokenbones

    Brokenbones Private E-2

    Thanks removed it
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good, good! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds