malware removal - I don't its name!

Discussion in 'Malware Help (A Specialist Will Reply)' started by mgbinnewhaw, Aug 23, 2007.

  1. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rename the host files ....If you can't rename it to hostold ...then just do the avenger fix that I gave you. A new host file will be created when you reboot.
     
  2. mgbinnewhaw

    mgbinnewhaw Private E-2

    Couldn't do it because "file is being used...."

    Ran Avenger and got the attached log file - got the same answer "can't rename etc." when I tried moving Hosts into a new Hosts folder!!
     
  3. mgbinnewhaw

    mgbinnewhaw Private E-2

    It is attached to this one!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm determined to kill this thing!!!!

    Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
     
  5. mgbinnewhaw

    mgbinnewhaw Private E-2

    Round 1 : Windows ahead on points!:D
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Meaning? Avenger didn't run correctly?
    If you use explorer to open the host files ...can you not hit control + A and then hit the delete key?
     
  7. mgbinnewhaw

    mgbinnewhaw Private E-2

    Round 2 : TimW wins with a KO!:clap - see attached log.

    Unfortunately, screen repainting and opening anthing is still very, very, sloooow.

    I am now going to reboot into SafeMode to run smitfraudfix.
     

    Attached Files:

  8. mgbinnewhaw

    mgbinnewhaw Private E-2

    I finally got into Safe Mode without difficulty and ran Smitfraudfix - I attach the log file.

    Incidently in Safe M|ode I noticed that the speed of response was much faster - normal in fact.

    I trust my attempt at humour is now clearer:)
     

    Attached Files:

  9. mgbinnewhaw

    mgbinnewhaw Private E-2

    I have no idea - I do not improvise when following your instructions, especially when operating in Administrator mode and manipulating system files, even in the unlikely event that I see another way of doing what I think you want me to do.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In normal mode .....run new scans and attach the logs for:
    ShowNew
    GetRun
    HJT

    The fact that things are at normal speed in safe mode would indicate that there is either a driver issue or a program conflict issue.

    Did you try safe mode with networking? If so, how was that speed?

    If you device manager ....are there any ? or ! or X's showing?
     
  11. mgbinnewhaw

    mgbinnewhaw Private E-2

    here they are attached.
    No I didn't, though I did inadvertently select that mode - however I will try it after this message.

    As for Device Manager, do I not have to be logged on as Administrator to see it? I have seen the directory with the marks you indicate and indeed resolved a conflict issue 12 mnths., but at present I find only MSN device manager. I have for the last few weeks logged on as a user, because it is more secure. How do I change that to Administrator? Windows Help is frigging useless in this respect!
     
  12. mgbinnewhaw

    mgbinnewhaw Private E-2

    Opened in Safe Mode Networking with the same speed of opening Photoshop as was normal afew weeks ago - i.e. bloody fast!

    Another curious thing, when shutting down Windows I always close important programs (Opera, Word, Photoshop, etc.) before selecting Turn off Computer on Start Menu. The last 2 or 3 times I see a pop-up saying that Opera is not responding and am given the option to End Now or Cancel. Which is curious because this last time I am 100%certain that Opera was shut down before logging off.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click My Computer / Properties / hardware / device manager ......make sure there are no problems there.

    Next.....before you shut down ...Control + Alt + Delete and look at running processes ...see if Opera is still listed (sometime users click more that neccessary and more than one instance will be running).

    Then read this and see if it helps in normal mode:
    Computer Maintenance

    You didn't attach your logs.:)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    TIP: Look at the obvious! All of the below are running:
    • Ad-Aware 2007
    • a-squared Free
    • BitDefender10
    • CounterSpy
    • SpywareDetector
    • STOPzilla!
    • TrojanHunter 4.7
    Start by uninstalling CounterSpy which is no longer necessary. See what effect that has. Then if you still notice performance issues. uninstall the below:
    • Ad-Aware 2007 - a huge resource hog due to the service being added.
    • a-squared Free
    • SpywareDetector
    • STOPzilla!
    • TrojanHunter 4.7
    And then see what your performance is like.

    Also the below is a known resource hog which you probably do not need:
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

    I also wonder whether the below is really necessary:
    O4 - HKLM\..\Run: [Broadbandadvisor.exe] "C:\Program Files\Virgin Broadband\advisor\Broadbandadvisor.exe" /AUTORUN
     
  15. mgbinnewhaw

    mgbinnewhaw Private E-2

    There is nothing shown.

    I monitor Task Manager almost on a daily basis and the only abnormality I note is that Opera starts off (after a shutdown) running at 14Mb memory use and over a few days increases to 250Mb and 50% memory use. There definitively is not a second image running.

    I do all here, as a general rule, once a week approx.

    I have this time! And I swear I did last time, but obviously I am not doing something to ensure their attachment.
     
  16. mgbinnewhaw

    mgbinnewhaw Private E-2

    I don't f****** well believe it!!:banghead
    No attached files?
    Let's try again.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why is HJT now running from here:
    D:\Downloaded Stuff24_08_07\HiJackThis.exe


    As has been stated by chaslang.....you have a redundance of security programs that are probably causing your problems with "speed".

    Attach a new/properly installed HJT log.
     
    Last edited by a moderator: Sep 6, 2007
  18. mgbinnewhaw

    mgbinnewhaw Private E-2

    Bloody good job, then, that I didn't try to delete it! When I did a mouse-over it showed up as an MS file which, despite their crap reputation for issuing half-baked software, I doubted very much was a trojan! Incidently, when something is corrected, as chaslang did on this occasion, it would be much, much better if it were clearly and plainly stated that "xyz is wrong and should read abc" - not hidden in "edited by nnn". Don't forget that your reader may not be the most observant!:) I barely noticed the correction, but I was already suspicious of the statement about vmiprvse.exe.

    HJT is resident on D: because it is my default backup USB caddy. Will you please tell me why the fact that HJT is run from D:, not C:, makes any difference, when the files being checked are still all on C:?

    On the subject of my redundancy of security programs, I have uninstalled Ad-Aware 2007 and SpyDetector. I am loathe to uninstall anything else because they have been present, with the exception of a2Free and Sophos Anti-RootKit, since before this current speed problem manifested itself, and therefore are not culpable. I might add that I installed a2Free simply because it is recommend by this forum as a useful addition to firewall protection.
     
  19. mgbinnewhaw

    mgbinnewhaw Private E-2

    I overlooked two points made by chaslang - the first is regarding
    which I have uninstalled (no idea where that came from!!).

    The second point regards
    which again sneaked in under my radar but is now uninstalled.

    I tried to uninstall CounterSpy but am unable to delete some files because "access is denied" - there is no uninstall provided by the program. How can I overcome this denial of access? please.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The problem with HJT is not that it is on the D drive..it is that it was not renamed (analyse) as many infections will hide (esp. Vundo) if it is not renamed.

    You can put those files that you can't delete into Avenger and have it delete them.

    Additionally, you may wish to use a startup program to limit your running programs.

    You are not showing malware, so I would suggest that you post in the software section for further assistance.
     
  21. mgbinnewhaw

    mgbinnewhaw Private E-2

    In the meantime I removed the surplus security programs and everything is now running at normal speed!:) So, problem solved.

    Thank you very much indeed for your help.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome...safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds