Halt in malware process

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cyberchick, Jan 29, 2012.

  1. cyberchick

    cyberchick Private First Class

    Hi,
    I run Win xp home edition Version 2002 service pk 3. AMD Athlon 64 processor 3000+ 1.98GHz 512 RAM.
    My first problem with the pc was that the DVD drives would not work and because the pc seemed very sluggish I thought I would run the Malware section.
    I have gone carefully through the read me first.
    I then ran the Super anti spyware with 1 infection.
    I tried to run Malwarebytes but the pc would not let me update it, I downloaded the manual update but still no use.
    I thought I would carry on and run Combo fix. This will prepare to scan but does not go any further ( after many hours). I have uninstalled AVG with the removal tool and turned off the firewall.
    What am I missing ?:confused
    Internet is working fine but I will e-mail via my laptop
    Many thanks in advance
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just attach the logs that you can get.
     
  3. cyberchick

    cyberchick Private First Class

    Hi
    I have run SAS and attached log.(Will add SAS log onto new message can't fond file)
    Malwarebytes would not run
    Combofix would not run.
    Ran RootRepeak log attached
    Ran MGTools

    When I ran the Combofix the blue box appeared saying scan time for badley effected machines can vary. This stayed like this for couple hours, I had to restart the pc to close it down.
     

    Attached Files:

  4. cyberchick

    cyberchick Private First Class

    SAS Log (found ) and attached

    Many thanks
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs, but I want you to run one more scan.

    Be aware that your system will be sluggish:
    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  6. cyberchick

    cyberchick Private First Class

    Hi
    I have attached the scan results.

    I your reply you say "Be aware that your system will be sluggish:"
    would you recommend adding more memory and if so how much?
    I thought the pc was sluggish due to malware, but maybe it is the memory.
    Cyberchick:-o
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can go to crucial.com and let them scan your system to see how much RAM it will take. I am not seeing any malware, but we can remove a few things:

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :otl
    :files
    @Alternate Data Stream - 131 bytes -> G:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
    @Alternate Data Stream - 116 bytes -> G:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
    @Alternate Data Stream - 110 bytes -> G:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.


    You may wish to post in the software forum for assistance with your sluggish performance:

    A slow computer is not always due to malware:

    Please explain in your software post what operations are slow! For example answer the below:

    * Is boot up slow?
    * Is shutdown slow?
    * Is browsing/surfing slow?
    * Is downloading slow?
    * Is running any application?
    * Is it also slow in safe boot mode?
    * Also are any process showing in Task Manager to be using a lot of CPU time?
    * Anything else slow?

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  8. cyberchick

    cyberchick Private First Class

    Hi TimW

    Many thanks for your help and advice "VERY MUCH APPRECIATED"

    I will carry out the final steps and attach the OTL txt log.
    As you suggest I will look in software and see if I can quicken the pc up a little .
    Thanks again cyberchick;)
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do check your system for available Ram. And good luck. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds