Logs. (My pc is currently infected)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Coreano, Aug 14, 2012.

  1. Coreano

    Coreano Private E-2

    Using Win XP and followed procedure correctly, please refer attached four logs.

    The logs might show my computer is not infected, but the Melawarebyte and SuperAntiSpyware did found problems before and fixed/quaranteened some of them. I have those logs but I didn't attach it because they are old.. plus I had to remove Melawarebyte and reinstall as mb.exe as instructed..

    Weird Event-

    When I was trying to delete left over folder of MWB after uninstalling it, msg poped up saying 'access denied', and during that time, my MWB which I dled as mb.exe was half way installed. I thought it might had to with installation so I exit the installtion, and tried to delete the folder, but it still showed access denied. So I hit Task Manager and saw mbamservice (or something like that) was running which I already know it's MWB so I try to end that process. The computer froze.... although I could move my mouse.. I couldn't click anything.

    Turned off pc by pressing power button and when restarted, weird thing happened. The folder was deleted but Recycle Bin was empty !!! I installed MWB regardless... but it's so strange..

    Problems I'm having -

    Computer becomes mega slow, esp with anti-virus programs. But when I was trying to get thsoe logs, all my anti-virus was uninstalled. My labtop was somehow faster without anti-virus for some reason.
    Something happened to my keyboard, some kind of delay on typing even though I put fastest on Keyboard from Control PANEL !! although this is fixed, my mouse is still having problem. I'm very sensitive person. I know there's definately some kind of skippy lag feeling going on on my mouse so I had to increase mouse sense by 1. But still, I feel that weird lag. This can be proven from my game experience, it doesn't move as before.. I'm quiet expert in the game I'm playing known as counter strike... Ranked top5 ..
    whenever I download something, the download window becomes white and if u put mouse on it it shows hourglass.. even if i'm downloading something below 1MB file, it will freeze for quiet awhile,,, VERY ANNOYING AS HELL!

    The viruses I had but fixed by Superantispyware before -

    Trojan horse
    Hijacker - changed my location and IP to Korea.. couldn't websurf AT ALL
    adware
    SpywareOnline

    I deleted SuperantiSpyware as well because it was making computer super slow after few days of fixing viruses... not really sure why.

    -Computer Restoration point probably infected

    I'm definately sure my restoration is infected. First of all, I can't choose any date to restore. Second of all, when AVAST try to create RESTORATION point, the error message poped up saying that I can't do it. The same message poped up when I downloaded ALback (from Alyac corporation (anti-virus) which helps to create restore point.
     

    Attached Files:

    Last edited: Aug 14, 2012
  2. Coreano

    Coreano Private E-2

    I really wanted to edit the 1st post but it seems I can't..

    I just want to add info that my labtop in Safemode (both non-networking and network) is VERY slow .. of course it wasn't like this before the infection.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not finding any malware in those logs. I would suggest that you post about your problems in the software forum. Thanks.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds