Geeks. we have a problem.

Discussion in 'Malware Help (A Specialist Will Reply)' started by dubina, Dec 17, 2007.

  1. dubina

    dubina Private E-2

    I'm experiencing very long load time for IE pages + not unusual to get a not connected screen.

    Added virus protection to Spy Sweeper and got three viruses on the first sweep. Quarantined them and that seemed to help for a while, but now the problem or some variation of it has returned.

    Had an R3 in hijackthis and got rid of it, but it comes back when I restart.

    Haven't been able to open my Hotmail page for a day now. I get the sign-in page but then it struggles and disconnects.

    I sort of know what to expect, so I'm ready to get started.

    Thanks,
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. dubina

    dubina Private E-2

    I've started doing the stuff your protocol requires, but I have a problem doing. Namely, I can't reach this forum by way of the affected computer. I can log on to Majorgeeks, but when I try to get to the forum with the protocol and links and stuff, the link seems to "time out" after a while and I get "Internet Explorer cannot display web page".

    This is typical of the problem that brought me here for help.

    I can't see a way to make all the checks and follow all the links of the protocol on the affected PC if I can't reach the protocol.

    Do you have any idea what might be causing me to go "waiting for (the URL)" and then time out rather than connecting? (IE tells me at first that the site is "found".)

    My three viruses were these: JS/Istbar-B ... Troj/BagleDI-M ...
    W32/Bagle-BK

    They're presently quarantined and I didn't find any specific removal instructions in your link.

    I had McAfee Antivirus VirusScan, AVG and Spysweeper with antivirus. Giving up Mcafee and AVG (because they didn't detect the three viruses noted above.

    Thanks,
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should only have one anti-virus program! Please uninstall all but one.

    Since you have access to another computer, download the MGTools to that computer and then save it to a disc or a flash drive. Then transfer it to the problem computer (saving it to the C:\ drive and double click the MGTools.exe. It will produce logs for you to, again, copy to a flash drive and then attach to your next post.
     
  5. dubina

    dubina Private E-2

    Looking good.

    So far as I can tell, we're back to normal.

    Lessons learned? Very complex troubleshooting so I'm not sure what the problem was, or what cured it.

    I guess my pre-existing malware/antivirus program(s) were inadequate. It would be nice to always have the right stuff before I get clobbered with crap, but I guess that's the way the cookie crumbles.

    Finally, at the end, I have a question:

    You say,

    "Often times, you may have trouble removing a virus, trojan, spyware, etc. because system restore has saved it as a check point and it can not be accessed. To solve this, you will need to disable system restore, reboot, scan for the problem and finally re-enable system restore."

    When I look at your system restore procedure, I don't see any "scan for the problem" sort of thing, and I'm not really sure what that means anyway. In other words, I kind of get the system restore logic except for scanning after rebooting.

    Any advice?

    Many thanks again. Great to be functional as before.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Without seeing the logs produced by running the MGTools, I can not say what the problem was/is ...nor can I be sure that it is completely solved.

    As to the question ..it means that you remove all of your previous restore points, run your anti-virus software and or an online scan such as BitDefender, and if clean, set a new restore point.
     
  7. dubina

    dubina Private E-2

    Ok, I have done the system restore stuff and scanning yet, but here are the logs.

    More logs to come, I think.

    ******

    On second thought, I think these logs are all you've called for.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are looking good....but lets do these few things:

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 2"
    J2SE Runtime Environment 5.0 Update 9"
    Java 2 Runtime Environment, SE v1.4.2"
    Java(TM) 6 Update 2"
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player

    Reboot and install:
    Java Runtime 6
    Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Disable the guest account.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    How are things running?
     
  9. dubina

    dubina Private E-2

    Hi Tim,

    How are things running? Pretty good...a big improvement over a couple of days ago. It was really snappy at first, but now my wait times are longer, not as bad as before, but somewhat annoying given what I was seeing last night.

    I want to correct something in my last message that may or may not be pertinent. I said that I'd done the system restore, but that was a typo; I still haven't. I thought I'd read something that advised me not to do that until I was "clean". Please advise.

    I'll do as you advised in your last post and post back what happens.

    A question, by the way. Do Macs have these problems too? I've heard they don't have many problems because Apple keeps more control of its OS, no open source, etc. I'm having serious trust issues with my online PCs because they seem to require messing with so often. I think if I was less inclined to get help from people like geeks, I'd be sorely tempted to throw this stuff in the garbage can.

    Thanks again,
     
  10. dubina

    dubina Private E-2

    My page load speeds are good again, but I have a problem that I had before. For some reason my history file gets wiped out or knocked back to a day or less web pages. My options to save web pages says 20 days so I don't know what's going on there.

    Otherwise, great.

    I'll wait for any last advice from you and do the system restore toggle thing and call it good.

    Thanks a ton. (Thank God for Geeks.)
     
  11. dubina

    dubina Private E-2

    Tim, a problem showed up just now when I tried to take a virtual tour online. My new Java didn't like it, gave me "Please Install Java Virtual Machine" at a certain email address. When I naved over then, I found the download was the same as the file Java 6.3 that I'd just installed...and something wouldn't let me install the new one over the old one.

    so I uninstalled the "old" Java 6.3 and installed it again as a MajorGeeks download.

    But that soon led to the same result (couldn't start virtual tour) and the same error message.

    Any ideas?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's possible that Spybot's Teatimer is causing that ...check your settings in the program.

    Mac's are less vulnerable because not many hackers mess with them ---> they are more interested in messing with Microsoft ....but they are still vunerable if not secure as we suggest in the How to Protect yourself from malware!

    Some of your issues might best be addressed in the software section.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  13. dubina

    dubina Private E-2

    I was sailing along yesterday at a good clip when things started slowing down again. Long page load times again. MSN home page and Hotmail open in what looks to be MSN / Hotmail light (as before).

    My PC slowed down more today. A few hours ago, I suddenly got the blue screen of death, soon followed by a blue screen explaination and a memory dump. The onscreen message advised me to look in it for a possible driver problem. As I looked, the blue screen message went away and the PC rebooted. It's running a better now, but not snappy good like yesterday.

    I found a big dump file (99 meg) and a minidump file (64k). Haven't been able to open the minidump. Do you read minidumps in cases like this one? Or, any other ideas?

    Regards,
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  15. dubina

    dubina Private E-2

    Tim,

    Just a word to wrap up. I found a lot of boo-boos by following your advice and my pc ran better for a while. Then, the old symptoms seemed to set in. I thought I might have a rootkit, ran Rootkit Revealer and found some mysterious stuff in the log.

    Yesterday, my pc flatlined so far as Internet pages were concerned. I had a good wireless network signal, but no connection. Eventually, I called Cisco and troubleshot the problem to my network card, a driver conflict problem. After uninstalling and reinstalling the network card software, my PC is running great, better than ever. I take that to mean the bigger part of my problem was the driver conflict in the network card, the lesser part, resolved by MajorGeeks malware removal procedures. My guess.

    One last question: how do I know if I have more than one activated firewall?
    Windows knows if its firewall is turned off, but it doesn't seem to know if one or more other firewalls are turned on. AVG seems to have a firewall, but's called a "resident shield" (I think). How can I know when I have only one active firewall, and what should it be?
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You don't have a firewall according to your last logs ....AVG resident shield is a virus scanner ...not a firewall.

    Check the home page under Top Freeware Picks and you can try Zone Alarm, Comodo or any other that you find works good for you.

    The driver issue no doubt was causing most of your problems. Good you got that taken care of. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds