Is my computer infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rick Sorrentino, Mar 18, 2009.

  1. Rick Sorrentino

    Rick Sorrentino Private E-2

    Hello all,
    I am a newbie & computer illiterate...hope you can bare with me. I cannot install updates or connect to poker or music sharing sites, as far as updates, they seem to download but I then get an error, poker & music sites tell me that there is a connection or firewall issue..well connection isnt the problem because I am on line & they are checked on exceptions in the firewall, I have even turned the firewall off & it still doesnt allow me to connect to the sites or the update to install(security update MICROSOFT.NET framework version 2.0)...
    My system is Windows XP home SP2 & seems to be running slower than before this all started or should I say stopped...I thank anyone who is willng to help!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. Rick Sorrentino

    Rick Sorrentino Private E-2

    Thank you for the response, wasnt sure if these were signs of malware...I will do as you advise!!!
     
  4. Rick Sorrentino

    Rick Sorrentino Private E-2

    no change, I did everything, still get no connection found or firewall blocking type messages from several sites, cant install AVG because I lose all internet & have to do a restore...I have several logs to attach, may take 3 post's & I truly appreciate any help
     

    Attached Files:

  5. Rick Sorrentino

    Rick Sorrentino Private E-2

    more logs...
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note your other new thread has been closed. Please remain in one thread.

    We have a little more cleaning to do but any problems you are having do not appear to be due to malware.

    Also if you keep running your PC without protection (like it is now) you are going to get infected.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Rick Sorrentino

    Rick Sorrentino Private E-2

    First of all let me say THANK YOU VERY MUCH!!!!
    I appreciate any assistance, I am a bit computer illiterate so I dont know if its malware or not, I tried doing as you advised but dont know if what i did was right, you said to remove whatever possible from the desk top but I dont know what can actually be removed or not, I am not familiar with whats an actual programs or if its something needed for one, I dont want to remove something & maybe lose it(if that makes sense)...I put everything that would move into a folder & moved it to my D drive, I have 3 drives(did I just move the problem somewhere else?)...the recycle bin, my computer, my documents,my network places & microsoft outlook icons wouldnt move, they are still on the desktop with combofix & ccleaner...I also have mb.exe & sasdefinitions.exe on the desktop...they are from the original malware removal instructions...otherwise I did as instructed, & have the logs which you requested.... hopefully you will tell me if i did it right or not & need to repeat or so but either way I still cant get access to several sites or get any updates, I dont get redirected anywhwere just messages for connectivity problems, firewall blocking or page not found & maybe a few pop ups, not sure.... one more thing, in the malware removal process it advised to go to msconfig & turn it to normal start up which I did but I have gone back to selective but now my ATI luanchpad keeps turning on, cant get it to stop, I also keep losing my quicklaunch icons from my bottom screen toolbar...In ref to anti virus I tried installing AVG but then I lose all internet....I sure hope you can help ...THANKS AGAIN!!!!!
     

    Attached Files:

    Last edited by a moderator: Mar 22, 2009
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Only things that were not links or shortcuts is what I'm referring to. You should not keep saving EXE files, DOC files, URLs, HTM.....etc to your Desktop. If you are really using certain files very frequently and really need quick Desktop access, then just make a shortcut to the real file on your Desktop.

    These are links or shortcuts and do no need to be moved.

    ComboFix.exe does belong on you Desktop since we need it there. The link to run Ccleaner does belong on your Desktop as do other links ( .lnk files are links or shortcuts to run programs ).

    These should not be on your Desktop. It is better to save them in a folder somewhere (like C:\Downloads )

    What sites can't you access? Disable your firewall and see if you get access.

    Read the step again. You should not be using MSconfig as stated. It should only be used for temporary debugging. Put your PC back into Normal Startup mode and then attach a new log from MGtools ( you need to run GetLogs.bat again after going back to normal startup).

    Do you mean it is there sometimes and then goes away?

    Which version of AVG? We just deleted all of it with the last fix I gave you. Why are you trying to reinstall it right now? That would just undo what I was trying to cleanup.


    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds