Logs posted. Am I clean yet??

Discussion in 'Malware Help (A Specialist Will Reply)' started by maddog808, Sep 1, 2010.

  1. maddog808

    maddog808 Private E-2

    Mother-in-law's PC was running extremely slow. I went through the "READ & RUN ME FIRST" steps, and the logs are attached.

    Thanks, Matt.
     

    Attached Files:

  2. maddog808

    maddog808 Private E-2

    And here is the MG log.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware in those logs, when you say slow, explain a bit more:

    Please explain what operations are slow! For example answer the below:

    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?

    AVG Free 8.5 <--- Outdated. Either upgrade to the latest version when we are finished here or opt for something else to protect you.

    Could you please get this: 0A075E0D9E.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip


    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\WINDOWS\system32\0A075E0D9E.sys
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Optional fixes to free up some resources:

    After clicking Fix exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now attach the C:\collect.zip and let me know the upshot of the Jotti results.
     
  4. maddog808

    maddog808 Private E-2

    Hello Kestrel,

    Thanks for the help again!!

    The slowness was before I did the READ & RUN ME FIRST steps and updated drivers. I didn't try safe boot mode, but all the other above tasks were AGONIZINGLY SLOW. The machine is actually running pretty smoothly now. I think a big problem was her RAM. She only had 512 MB installed. I went ahead and maxed out the mobo with 2 GB.

    I uninstalled AVG and installed Avira free in its place. I find it a bit odd that AVG wouldn't automatically notify the user about an outdated product. I like Avira better, anyway.

    I have attached the collect.zip file for your review.

    Jotti's scan says no virus found across the board. Here is the link you requested: http://virusscan.jotti.org/en/scanresult/347dded1110c58cceeb4342ef75e843b1fa6498f

    I fixed the lines you suggested in HijackThis, although this one didn't appear in the scan:
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

    I also did the optional fixes. Thanks!! I was beating my head into a wall trying to figure out a way to disable the stupid HP thing without using msconfig!

    Lastly, the regedit was a success.

    Thanks so much for being so thorough with all your help. I think I am almost ready to deliver this PC back to my mom-in-law, and she will actually be able to use it again. She was ready to toss it and buy a new one.

    Sincerely,
    Matt
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am so glad to hear that! You adding the memory was what made things smoother.

    You should never use MSCONFIG to control start up's, you should use third party software instead, something such as StartUpCPL.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds