Malware Removal 4-8-11

Discussion in 'Malware Help (A Specialist Will Reply)' started by peteschulte, Apr 8, 2011.

  1. peteschulte

    peteschulte Private E-2

    Problems:
    Started last December or earlier
    Recieved an alert
    "Generic Host Process for Win 32 Services has encountered a problem and needs to close..." This would happen in nearly half of my user sessions.​
    sometimes programs would not open -- often I could use the computer for an hour or so, then this behavior would start.
    often the computer would hang when shutting down, especially on

    "Saving your settings...​

    Yesterday I went through the malware removal process described in the Forum. The only exception was that I couldn't get RootRepeal to run. I got the window
    "Initializing, please wait"​
    and waited several times for more than half-an-hour. This morning I started again at that point, downloading a new RootRepeal exe. No programs were running; Avast was turned off. MB protection was off. Disabled internet connections. Task Manager showed it not responding. Tried repeatedly. Then went on to MGLogs.

    I did notice different behavior while shutting down once this morning. Windows installed 21 updates. Then on start-up, instead of a long-lasting black screen before the Windows XP logo followed by the password window, there was a quick blue window with immediate Windows XP logo followed by the password window. That looked like the good XP blue background. The lack of delay on a black screen seemed healthier.

    The system might be okay now. The previous error was so erratic, sometimes it would be a couple of hours before it would manifest, or not at all -- so it's hard for me to tell. Still, I'm concerned about being unable to run RootRepeal.

    Thank you so much for your help! :cool
     

    Attached Files:

  2. peteschulte

    peteschulte Private E-2

    After an hour or so of use, the system seems okay. Previously, Avast would frequently block an outgoing connection, which it has not been doing. No Win 32 Services message. Programs open okay. Shuts down and restarts okay, though I'll try that again now. Only did it once since posting.

    Now that I have so many choices, on a continuing basis should I run Avast, Malwarebytes, or Super-anti-spyware? I have the free version of each.

    Again, thanks very much for your answer, your tools and support!

    -- Peter
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. However, you did not attach the MBAM log.

    I would highly recommend you install SP3!!

    The only things I see that I don't recognize is this:
    C:\Documents and Settings\All Users\lxdj

    If you don't know what it is, delete it.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  4. peteschulte

    peteschulte Private E-2

    Thank you, Tim W!

    I deleted the file that you pointed out.
    MBAM log is attached.
    I followed the steps in your reply up to #9.

    Since yesterday I have tried 4 times to install SP3, without success. Should I start a new thread for this?

    The last try was an encouraging step, because it was the first one initiated by Windows Update rather than my download from MS.

    I have screen caps of the failure messages and am attaching the first 2. The others are not interesting, just failure notices.

    Looking forward to your reply -- thanks again!

    Peter
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you should post in the software forum regarding your error messages when trying to install SP3.

    Let's have you do one more thing:
    eSet Online Scan.
     
  6. peteschulte

    peteschulte Private E-2

    Hi Tim,
    You wrote, "Let's have you do one more thing: eSet Online Scan."

    Whenever I run it, the machine is left in such bad shape, all I can do is press the power button to turn it off.
    The last two times, it finished and reported no infections. These were the downloaded version.
    Before that I was using barf IE and I think that dropped Internet connections made it impossible to finish.
    I'll try one more time to get a log.

    Thank you!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem since it reported no infections. Do post in the software forum for assistance with SP3. ;)
     
  8. peteschulte

    peteschulte Private E-2

    Hey Tim,
    thanks -- I finished Part 9, clearing the restore points and resetting one. Before that I tried SP3 again and documented what I could. Will proceed to a new thread.
    Thanks again!
    Peter
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck. :)
     
  10. peteschulte

    peteschulte Private E-2

    Could you please take a look at my current thread?

    So far, two locked registry keys have been preventing installation of SP3.

    A lot of effort has occurred and one key has been unlocked. Maybe others will show up after these are brought under control.

    http://forums.majorgeeks.com/showthread.php?p=1613061&posted=1

    Thank you!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Answered, hope it helps. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds