I have a virus that slows my internet to a snail

Discussion in 'Malware Help (A Specialist Will Reply)' started by volkmt, Jan 28, 2007.

  1. volkmt

    volkmt Private E-2

    I am currently downloading hijackthis because I have run all of the other programs listed in a previous thread. I will post the scan log and hopefully someone can help me. Thank you.
     
  2. volkmt

    volkmt Private E-2

    I have attached what I believe is the logfile you are looking for. I apologize if this is not exactly correct. Thank you again for your help
     

    Attached Files:

  3. volkmt

    volkmt Private E-2

    I was also wondering if someone could give me a quick walkthrough of Firefox for increased internet speed... or could direct me to the place I should post it. Thanks
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Among other things..you have a Wareout infection.

    Please re-do the Read and Run Instructions and attach all the requested logs.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NO YOU HAVE NOT! If you are referring to what you posted in August of 2006, that is too old to be of any use what so ever.

    As TimW stated, you need to run the whole READ & RUN ME FIRST Before Asking for Support sticky thread which has changed tremendously since you last posted here. Then attach ALL 6 requested logs (including a new HJT log that is obtained AFTER running all the other steps. HJT is the last thing to be performed before posting.)
     
  6. volkmt

    volkmt Private E-2

    Ok I believe I have run everything the way you want it. I also found that when I went into my task manager the program Owner.exe was running. It made a world of difference when I ended the process on that program. I also made a new HJT log file.
     

    Attached Files:

  7. volkmt

    volkmt Private E-2

    It will take a second to find the last log that you want.
     

    Attached Files:

  8. volkmt

    volkmt Private E-2

    Thank you again for any help you can give me
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since TimW is not here right now, I'll give you the next steps to keep you moving.

    Run this WareOut Removal and attach the requested log.


    Then also attach a new HJT log.

    Also please do step # 2 of the READ ME properly!!!!
     
  10. volkmt

    volkmt Private E-2

    Ok I am sorry about not following step 2 correctly. Thank you for putting up with my nitty gritty mistakes. I have the logs you said to attach.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'll save TimW the effor since I have a free moment!

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [Microsoft] Owner.exe
    O4 - HKLM\..\RunServices: [Microsoft] Owner.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{575640C6-1274-4097-93E2-9DD9A9DDCA1A}: NameServer = 85.255.114.58,85.255.112.196
    O17 - HKLM\System\CCS\Services\Tcpip\..\{61E092D8-1180-4CF0-85D8-FB40C54D06E2}: NameServer = 85.255.114.58,85.255.112.196
    O17 - HKLM\System\CCS\Services\Tcpip\..\{AAA67ABE-942B-41A3-812C-BB99CA36C43C}: NameServer = 85.255.114.58,85.255.112.196
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.58 85.255.112.196
    O17 - HKLM\System\CS1\Services\Tcpip\..\{575640C6-1274-4097-93E2-9DD9A9DDCA1A}: NameServer = 85.255.114.58,85.255.112.196
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.58 85.255.112.196
    O17 - HKLM\System\CS2\Services\Tcpip\..\{575640C6-1274-4097-93E2-9DD9A9DDCA1A}: NameServer = 85.255.114.58,85.255.112.196
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.58 85.255.112.196

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete the below (if found - it may already be gone).
    c:\windows\system32\Owner.exe

    Now run Ccleaner.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Jan 29, 2007
  12. volkmt

    volkmt Private E-2

    I havn't noticed any 56k type slowness at all so I think there has been an improvement. If the logs are ok can I go ahead and readjust my settings with the hidden file folders and extensions? Is there a better freeware firewall than the standard windows firewalls system so that I have less of a chance of another virus? Or is there another suggestion you might have for me? any advice would be appreciated. Thank you.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We are not quite finished yet. You have an important update to get.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 6
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment



    Not necessary but if you feel more comfortable that way, you can change them back. However note that doing this also gives malware an easy hiding place since you will not see it either.

    Covered in my final steps since your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  14. volkmt

    volkmt Private E-2

    Well everything seems to be working out pretty good. I installed Zone Alarm in place of the standard Windows Firewall. I Installed AVG Free edition, and to top it all off I installed Mozilla Firefox. Thanks for all your help.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds