HELP ME! I have a major deliverable due on Fri

Discussion in 'Malware Help (A Specialist Will Reply)' started by pfran42, Dec 4, 2008.

  1. pfran42

    pfran42 Private E-2

    I have never posted about this and in all of my years (in technology) I don't think I have ever got a virus.

    I have Dell 630m with a 2GHz Core 2 Duo and 4 GB of RAM.

    Computer started freezing up last night (as in super jerky) and so slow I cant use it. It misses every 5 keystrokes and pop-ups galore. This my work laptop and it is useless right now.

    I use Trend Micro AV and run CCleaner all the time. My IT guy spent 4 hours on it this afternoon and it ran great for about 20 min.

    I read that I should post a Malwarebytes andHiJackThis log after I run a pass with each.

    Here goes: I have to have this fixed tonight so I would be willing to work something ou with PayPal if someone would be kind enough to take me under their wing

    Thanks!!!
     
    Last edited by a moderator: Dec 5, 2008
  2. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    the logs
     

    Attached Files:

  3. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

  4. pfran42

    pfran42 Private E-2

    Ok..I read the sticky and I am ready to try again

    Post 1 of 2 (with 3 logs)


    On 12.03.08 I started noticing extreme jitteriness when trying to drag windows. It felt like I was trying to run 20 applications on a PIII with 256 MB of RAM (if that makes any sense). Over the work day I noticed that Firefox and IE were launching windows with adds on them (even though I had "block pop-ups" selected for both browsers). I ran CCleaner and cleaned the registry about 4 times which didn't do a whole lot. I then started uninstalling applications to no avail. Reboots started taking over 10 minutes so I called It and they worked on it for about 4 hours over LogMeIn. After the IT support call, the laptop was around 80% more responsive but I started degrading shortly after and by that night I was back to a severely slow state. THe odd thing was that when I would look at Task Manager, It would show CPU usage at 10% and memory usage was around 500 MB (out of 4 GB).

    The only thing that I think could have caused this is a TuneUp Utilities 2009 application that I got from a file share. I scanned the zip file before installing it and it came back clean (used Trend Micro Client/Server Security Agent)


    I have completed the tasks necessary to post my logs and I would appreciate any help that avails itself.

    *NOTE
    I just noticed that my AV software just completed a scan and came back reporting that I have 1 infected file. TROJ_VUNDO.YD located in: C:\Documents and Settings\administrator\Local Settings\Temporary Internet Files\Content.IE5\JP83X324\apstpldr[1].htm

    Funny thing is that even though I have set my folder view options to show hidden files and folders, NOT Hide extensions for known file types, and NOT to hide protected operating system files...There is NOT a Content.IE5 folder nor a JP83X324 folder nor a apstpldr[1].htm file

    I have noticed that this virus has been removed several times by various tools I have tried after reading posts on this form.

    Basic Hardware Setup:

    OS Name Microsoft Windows XP Professional
    Version 5.1.2600 Service Pack 3 Build 2600
    OS Manufacturer Microsoft Corporation
    System Name (removed from this post by owner)
    System Manufacturer Dell Inc.
    System Model Latitude D630
    System Type X86-based PC
    Processor x86 Family 6 Model 15 Stepping 10 GenuineIntel ~1994 Mhz
    BIOS Version/Date Dell Inc. A14, 10/30/2008
    SMBIOS Version 2.4
    Windows Directory C:\WINDOWS
    System Directory C:\WINDOWS\system32
    Boot Device \Device\HarddiskVolume1
    Locale United States
    Hardware Abstraction Layer Version = "5.1.2600.5512 (xpsp.080413-2111)"
    User Name (removed from this post by owner)
    Time Zone Eastern Standard Time
    Total Physical Memory 4,096.00 MB
    Available Physical Memory 2.53 GB
    Total Virtual Memory 2.00 GB
    Available Virtual Memory 1.96 GB
    Page File Space 6.83 GB
    Page File C:\pagefile.sys

    Please let me know if there is anything else I can provide that will assist the experts in troubleshooting this issue.

    Thank you for your time!

    *NOTE 2

    Just as I am about to post this it looks like something is changing the names of my files on C: root to non-English (non anything gibberish)...this sucks big time.
     

    Attached Files:

    Last edited: Dec 6, 2008
  5. pfran42

    pfran42 Private E-2

    Post 2 of 2 (with 1 log)
     

    Attached Files:

  6. pfran42

    pfran42 Private E-2

    Thanks, I read the guide and followed the directions. I can't PM you b/c I don't have enough posts and I don't want to spam the boards in order to get from 3 to 50 in 15 minutes. You can just change my name to pfran42 if that is OK with you.

    Thanks again!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like the cleaning procedure removed most of your malware problems. We have a little bit left to do.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - AppInit_DLLs: pvfiav.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. pfran42

    pfran42 Private E-2

    Thank you again for the prompt responses! I have complete these additional instructions and have attached the ComboFix.txt and MGlogs.zip files.

    Overall the laptop is performing better. I hope the situation does not deteriorate during the workday.
     

    Attached Files:

  9. pfran42

    pfran42 Private E-2

    Made it 8 hours without a glitch. Am I cured doc?
     
  10. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member


    good point. done
     
    Last edited: Dec 15, 2008
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds