I dont know what else to do.

Discussion in 'Malware Help (A Specialist Will Reply)' started by oOMcCauleyOo, Aug 4, 2010.

  1. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    I had previously downloaded a player from the internet to watch a movie but then my computers performance dramatically slowed down. I immediately deleted the file but it is still slow. My CPU usage is at 100% always and takes ages to boot up. I have tried nearly every single anti virus software out there (one at a time) but none have found anything. Iv used programs such as CCleaner to clear up disk space and fix registry errors and it has sped up a bit to around 80% CPU.
    I dont know what else to do so I am turning to the experts. Please help me :cry

    I will attach the logs to the message.
     

    Attached Files:

  2. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    Here is the last set of logs
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to Add/Remove programs and uninstall the following software:

    • Messenger Plus! Live
    • Java(TM) 6 Update 20

    Your zipped log is missing the Hijackthis log. Use Windows Explorer (My Computer) to navigate to C:\MGtoools\analyse.exe and double click on it to run it. Do you see a license agreement? If yes, you must click the Accept button Twice.

    Do a System scan only and save a log file. Attach this log as well as other logs I may request at the end of the fix.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\documents and settings\All Users\Application Data\STOPzilla!
    c:\program files\Common Files\iS3
    
    File::
    c:\windows\system32\drivers\kgpcpy.cfg
    c:\windows\system32\config\systemprofile\Application Data\ovczpx.dat
    C:\WINDOWS\system32\2456979063.dat
    C:\WINDOWS\system32\tmp42034.FOT
    C:\WINDOWS\system32\tmp4D234.FOT
    C:\WINDOWS\system32\tmp89654.FOT
    C:\WINDOWS\system32\tmpBB134.FOT
    C:\WINDOWS\system32\tmpFE034.FOT
    C:\Documents and Settings\Administrator\Local Settings\Temp\71.tmp
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the HJT log.

    Let me know how things are running, please.
     
  5. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    Hi there and thanks for your reply. Iv performed all the tasks you told me too and there is still no performance change.

    Here are the new logs you asked for.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    A slow computer is not always due to malware:

    Please explain what operations are slow! For example answer the below:

    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?

    ...Reviewing your last set of logs now. :)
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have you recently downloaded any fonts lately? I am seeing the below in your logs, they could be legit but I just want to be sure they aren't something weird.

    • C:\WINDOWS\system32\tmp42034.FOT
    • C:\WINDOWS\system32\tmp4D234.FOT
    • C:\WINDOWS\system32\tmp89654.FOT
    • C:\WINDOWS\system32\tmpBB134.FOT
    • C:\WINDOWS\system32\tmpFE034.FOT

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\WINDOWS\system32\tmp42034.FOT
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below files and also let me know the results:

    Code:
    C:\WINDOWS\system32\tmpFE034.FOT
    C:\WINDOWS\system32\tmpBB134.FOT
    Your last combofix log was incomplete, please ensure that you do indeed let it run to completion and leave the keyboard and mouse alone until it has finished running.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\System32\drivers\kgpcpy.cfg
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Use windows explorer to delete leftovers from avast!

    • C:\Documents and Settings\All Users\Application Data\Alwil Software

    I see you were very recently using avg but that it is uninstalled now but has left behind remnants. I suggest you run the Official AVG Removal Tool

    Make sure you also delete any AVG folders in Program Files and Documents & Settings/Application Data directories.

    Now Run Ccleaner.

    Then install some anti virus and do a complete scan with it for your own peace of mind.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Also include the jotti results.
     
  8. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    For your previous post.

    Is boot up slow? Yes, but has improved as when the problem first occured i could not even boot up in normal mode because it was that slow. It would take around 30 minutes to fully boot or it would just crash. But now its around 5 minutes.

    Is shutdown slow? I dont think so.

    Is browsing/surfing slow? Yes, it has got better though.

    Is downloading slow? Yes

    Is running any application? Yes, it takes around a few minutes for it to load.

    Is it also slow in safe boot mode? Yes

    Also are any process showing in Task Manager to be using a lot of CPU time?

    1.System idle Process is averaging around 50
    2. SynTPEnh.exe is around 05
    3. Task manager is around 10
    4. Firefox is around 50
    5. Explorer.exe uses around 05
    That is mainly it for the CPU


    * Anything else slow?
    I am not able to watch videos. I can hear sound but the video does not run smoothly and does not refresh the image.

    Q. Is some application running secretly that is using up all of my RAM?

    Also, i found that when i boot windows i get a notepad file desktop.ini appearing which says:
    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787

    I dont know what that means.
     
    Last edited by a moderator: Aug 6, 2010
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We will get to addressing this shortly. In the meantime, what about attaching fresh logs after following my previous instructions?

    and answering my questions about the fonts.
     
  10. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    ok thank you, im currently doing the virus scan and will do the MGTools scan when that is completed. And i have not downloaded any fonts.
    Ill post the logs i currently have.

    http://virusscan.jotti.org/en-gb/scanresult/214de7620e8d20a9573ad1f4deaf2748ffe67cb7

    When i try to scan the other files it says 'This file has been scanned before. The results for this previous scan are listed below' even though it says they are different in the path.

    I will post the MGTools shortly.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, attach the remaining log and we can continue.
     
  12. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    Here are the rest of the logs.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    J2SE Runtime Environment 5.0 Update 6 <--- uninstall this

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Don't forget to install antivirus when we are finished here!!
     
  14. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    Ok done that
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Now run CCleaner.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This still occuring? If so I'll ask Chaslang about it and he will for sure be able to help. :)
     
  17. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    Yes it still happens unfortunately. Thanks for all your help :)

    At least i now know my problem is not related to malware.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is not a malware problem. Normally this happens when the desktop.ini file in your Startup folder is not set to be a hidden-system file. You need to change the attributes on the below files to be hidden and system.

    C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\desktop.ini
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini


    To do this, you can copy and paste the below commands into a command prompt window or alternatively just

    attrib +s +h C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\desktop.ini

    attrib +s +h C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
     
  19. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    Hey Chaslang, when i paste what you said it says 'Parameter format not correct - '
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can access the hidden files by going to the control panel, click on folders, and under the view tab is where you can check the box to not view hidden files and folders.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not the issue and not what we are trying to do. ;)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Put quotes around the file paths so the commands look like below:

    attrib +s +h "C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\desktop.ini"

    attrib +s +h "C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini"



    Did that work okay? If yes, see if you still have the popup you have been having trouble with.
     
  23. oOMcCauleyOo

    oOMcCauleyOo Private E-2

    Thank you for all of your help everyone. I found the issue with my slow laptop. Something must have moved inside because I shook it and now its working perfectly :D

    And chaslang you fixed my problem :) thank you very much.

    Goodbye and all the best.

    Darren:p
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Glad to hear you found your problem.

    Make sure you have completed the final instructions Kestrel13! gave you back in msg # 15.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds