I think I'm still infected.

Discussion in 'Malware Help (A Specialist Will Reply)' started by kes2tral, May 6, 2011.

  1. kes2tral

    kes2tral Private E-2

    I have completed the READ and RUN ME FIRST Malware removal guide protocol. I will attach my logs.

    The problems started about 2 weeks ago. I believe my son downloaded something when he downloaded a movie. We started getting XP Antispyware popups, google redirect, and it just got worse and worse. The task manager was disabled. It was originally only in his profile, but then started showing up in all profiles. The computer runs constantly, communicating with the internet and who knows what else it is doing.

    Since I have run the protocol, the computer is extremely slow and runs constantly. The pop-ups have stopped, google links are working and the task manager is working, but the Rogers Online Protection (which is Norton, I think) flashes on the screen when the computer turns on, but then does not actually turn on. The task manager says it is not responding. It runs, however, when I manually turn it on.

    If you can help me to figure out what is going on and if I can fix it, I would really appreciate your help!

    Note: I can't find the SAS log or the MBAM log. I ran both programs and saved the logs on the desktop. I looked everywhere. There is no log when I click on the log tab in MBAM. Could something have removed the logs? I was not able to run the whole protocol on one day. Should I run them again?

    The SAS program found 8 spyware?, 1 disable taskmanager, and 1 trojan.

    One last question. I before I started the protocol, I bought an external hard drive (My Book Live) and backed up the computer. But now I am concerned that all these malware are in the back up. How do I deal with that?

    Thanks again!
     

    Attached Files:

    Last edited: May 6, 2011
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It looks like ComboFix and TDSSkiller took care of your malware. Your PC is slow because you are running out of memory. When you attached your logs, the below was shown
    Code:
    Total Physical Memory 1,024.00 MB 
    Available Physical Memory 68.63 MB
    Windows will not run properly with so little free memory. The applications you are running are hogging too much memory. 1 GB ( or 1,024.00 MB ) is the absolute minimum we recommend for Win XP, but 2 to 3 GB is highly recommended.


    Please explain what operations are slow! For example answer the below:
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any/every application?
    • Is it also slow in safe boot mode?
    • Also are any processes showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?
     
  3. kes2tral

    kes2tral Private E-2

    Thanks for the reply.
    I am trying to figure out what's going on.
    To answer your questions, everything seems slow. Start up is especially slow. The internet is slow. If a program opens, it seems to work reasonably well. Shutdown is a little slow. There 50 processes in the task list. I am completely ignorant of what to keep and what not to. I know there are things that start up when the computer turns on that I do not need and slow things down, but I don't know what or how to find out.

    Beyond slowness, my major problem is that in my husband's profile, he has nothing listed in the left side when you click start. The Outlook Express shortcut does not work in the listing of programs. It also does not start from the actual program files. However, it is working from other profiles.

    In all the profiles, the Rogers Online Protection looks like it opens with a flash on the screen, but doesn't. A warning saying something like "Antispyware could not start" and I clicked "run diagnostics". But nothing seems to have happened.

    When I open the internet in my husband's profile, a box comes up that says IE-Search Provider Default as a title. "A program on your computer has corrupted your default search provider setting for Internet Explorer. IE has reset this setting to your original search provider, google (www.google.com). IE will now open Search Settings, where you can change this setting or install more search providers."

    The IE window has two tabs, one is Welcome to Internet Explorer 8. The other is Security Settings at Risk. There is a banner with Your Current Security Settings put your computer at risk. Click here to change your security settings. I can't do anything with the IE window and can only click on the OK for the box described above. When I click OK, a Manage Add-ons box comes up with Google enabled and Live Search Not available. I have tried deleting Live Search but this happens over and over.

    Any suggestions?

    Thanks so much for your help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you attached your logs, you attached them for a user account named testing. If that is not the user account you are having problems with then you need to run the scans on the proper user account and attach new logs.

    I also suggest that you may want to try uninstalling the Rogers Online Protection software just to see if it is what is slowing you down.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds