I've been infected. Please help me.

Discussion in 'Malware Help (A Specialist Will Reply)' started by JayMonteil, Dec 10, 2007.

  1. JayMonteil

    JayMonteil Private E-2

    Hmmm... alright. It's really strange that that keeps happening, and it's sort of a bugger... but if nothing bad happens from it, then I think I'll be fine till the next problem that comes up or so. If something wonky starts happening, I'll bring it up.

    Thanks for your help, by the way. Despite the intensity, I'm glad this worked out and that my compy seems to be running normally now. Really, I appreciate it a lot.
     
  2. abri

    abri MajorGeek

    Hi Jay,

    The main test really is that your computer is working okay. I think that will give us more information than anything else. Let me know whether it continues to work properly or if you notice some of the symptoms returning. There are still some online scans like the one from BitDefender which you can do and my next step would be to send you through those. Let's wait and see how it goes.

    abri
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me suggest another method of removal of this driver that keeps showing up. Part of the reason if may be so easily reinfecting you could because you do not have adequate protection installed. You have no antivirus and no real birdirectional firewall. But I did notice that you did have a very old Norton 2004 installed when you started this thread and that you probably uninstalled it to see if it was causing the driver to show up. Also Ad-Aware's Adwatch is not one of my favorites. I will post something to try using ComboFix in a few minutes. Hopefully you still have ComboFix and it runs for you. It you deleted it, download it from the READ ME again and make sure you download and save it to your Desktop. This is necessary!

    I'm also going to remove a driver from TrendMicro which you don't have installed and thus do not need.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have the below icons on your Desktop (double click the thumbnail to expand it)
    CFScript.jpg
    • Now refer to the above image and use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.

    Make sure you tell me how things are working now!


    Please do not reboot or powerdown after attaching your logs. If the driver has renamed since posting your previous logs, the above fix may not be valid. Often this kind of infections will rename their files at each power down or power up.
     
    Last edited: Dec 16, 2007
  5. JayMonteil

    JayMonteil Private E-2

    The big reason I uninstalled Norton AntiVirus 2004 was because it was terribly slowing down my computer's overrall performance due to it's hogging resources, which was quite a bother when trying to run the programs I've been using lately to help my computer, so I decided I'm going to try and look for a newer version, as I heard they fixed that problem in later versions or so (at least that is what I have read). At least that's what I'm hoping for, anyway... It sounds stupid, I know.

    Had a bit of minor trouble working with ComboFix earlier, accidentally uninstalling it at one point, so it took me a while to get things up off the ground here. Might have gotten a little confused too...

    Computer's been running as normal as can be... just without an antivirus program... but I do intend to invest in an improved version, which I hope won't slow down my compy's strength any like the one I currently have does... (my computer is not very powerful). I hope that's not a big deal, though. ^^;;

    Hope these logs help.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true. The newer versions are bigger and worse than ever. Especially if you buy one of the Internet Security Suites. Stick to the free tools give in the How to protect youself link. They work just fine and are not resource hogs.

    Okay this worked! The problem driver file is now gone! ;)

    So make sure you do work thru this: How to Protect Yourself from Malware and get your antivirus and firewall software installed.
     
  7. JayMonteil

    JayMonteil Private E-2

    Oh? Really? I see... I must have misunderstood what I have read, then.

    Thanks for your help. I'm glad this whole thing has been cleared up. ^^
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome from me and Abri!

    Yes we go thru this every week on several PCs where people are complaining of some kind of performance issue. Often times we find no malware and the root cause is a massive resource hog security suite. And Norton/Symantec is at the top of the list.
     
  9. JayMonteil

    JayMonteil Private E-2

    I'm just posting here to let Abri or Chaslang know that I have not had any problems with my computer since the fix. Again, thanks guys. :3
     
  10. abri

    abri MajorGeek

    So glad to know that, Jay. Thanks for letting us know.
    Hope you have time to look at some of the other forums too, now that your computer is working again!

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds