I'm pretty sure this computer is still infected.

Discussion in 'Malware Help (A Specialist Will Reply)' started by kirk48, Oct 15, 2008.

  1. kirk48

    kirk48 Corporal

    This is a neighbors computer. They told me it was running really slow and then they began to get messages telling them the computer was infected. I ran the proceedures in Read This First, but I'm sure there are still malware problems that I can't detect. I've found junk all over the place including Bearshare. Any help here would be most appreciated.
     

    Attached Files:

  2. kirk48

    kirk48 Corporal

    This is the 4th log.txt
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    Just to let you know we're reviewing your logs now and will get back to you as soon as possible.

    Thanks
    Kes13!
     
  4. kirk48

    kirk48 Corporal

    Thanks for the heads up, I'll keep an eye out for progress.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The main reason for this PC being slow is that the Total Physical Memory = 256.00 MB and only 42.59 MB is free.
    I recommend 4 times this amount of memory ( that is 1 GB ) to most effective run Windows XP these days.

    There are some left over items from Symantec that need to be removed. Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Now uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {37B85A29-692B-4205-9CAD-2626E4993404} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    Important note!! You have AVG6 installed which is very outdated and needs to be replaced by an up to date antivirus program to have proper protection but also note that newer programs also are more resource hungry and will need more RAM.
     
  6. kirk48

    kirk48 Corporal

    This is really embarrassing, but the the neighbors didn't want to wait any longer and took the computer. I assume they took it into a shop. Thanks for your great efforts and I apologize for not telling you this last night when they took the system. I did tell them they needed more ram, and I hope they don't just format the computer. Thanks again.

    kirk48
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Fixing those remaining items would have help a little but it would not cure there main complaint of the PC being slow. In fact this PC was did not even have proper protection on it. Besides AVG being old, they needed an antispyware realtime blocking tool and a much better firewall than the Windows XP firewall. Adding those will slow them down even more. Adding more RAM is the correct fix.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds