Internet connection slowdown issues & Avira once again detected a Conficker

Discussion in 'Malware Help (A Specialist Will Reply)' started by tintoy, Feb 19, 2011.

  1. tintoy

    tintoy Private E-2

    Good day MajorGeeks, I am again having internet connection slowdown issues and Avira once again detected a Conficker virus. It was detected 3 days ago. I did all the scans and all requested logs are attached.
     

    Attached Files:

  2. tintoy

    tintoy Private E-2

    Re: Conficker among many other malware?

    Here is the MGlog
     

    Attached Files:

  3. tintoy

    tintoy Private E-2

    update: at first i think thought that it might either be malware or just my ISP, but now while surfing on my laptop with the PC turned off I am not experiencing some slowdowns.


    P.S Thanks to whoever separated my new issue, I didn't know that I can create a new one or just reply on my old thread.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs you posted do not show any signs of a Conficker infection.
     
  5. tintoy

    tintoy Private E-2

    Oh, okay. Thanks again chaslang. I guess I have to contact my ISP. Thank your for your time.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Do you have a log from Avira that shows what it thought was a Conficker infection?
     
  7. tintoy

    tintoy Private E-2

    how do you get the log? can I just printscreen the report?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Double click the Avira icon in your tray to open Avira.
    • Then under Overview, select Events.
    • Find the event that shows Conficker in the right part of the window and select it.
    • Then press the F3 key to save it to the Events.txt log. Save the log to your Desktop.
    • Attach the log here.
     
  9. tintoy

    tintoy Private E-2

    Here is the log. Thanks for all your help. :)
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another thing you could do is look in the below folder and find the log which reported Conficker and attach this log.

    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\LOGFILES

    That events.txt log does not really show a real conficer infection
     
  11. tintoy

    tintoy Private E-2

    The path that you gave me only showed events dated from 2-19-2011 up to present, but the malware was detected on 2-16-2011.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay well your logs are clean anyway and did not show any signs of a true Conficker infection.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. tintoy

    tintoy Private E-2

    alrighty! Thanks for your help.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds