Need Help With Malware Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by scgms1, May 8, 2008.

  1. scgms1

    scgms1 Private E-2

    I noticed a couple of weeks ago that my CA anti-virus had a pop up box that said 3 viruses were detected and removed from my computer. This happened a few more times, but I didn't notice any problems with the computer so I continued on my merry way. Yesterday the computer had slowed noticeably and went to Windows Task Manager and on the CPU Usage svchost.exe SYSTEM was using 50%. There were multiple instances of svchost.exe SYSTEM and svchost.exe NETWORK SERVICE. I don't know if this has anything to do with the problems I'm having, but...
     

    Attached Files:

  2. scgms1

    scgms1 Private E-2

    I also attached a Kapersky on-line virus scan.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Based on your logs, you are not having malware problems. I would suggest that you take a close look at your CA logs and make sure that it is just not detecting files from programs you installed like SmitFraudFix and VundoFix. svchost.exe is always running multiple times. It is normal to see 4 to 8 of them.

    Attach a log that shows what CA is finding if it still is finding anything.

    I suggest that you delete the below files which are doing the opposite of what they say.
    C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job
    C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job


    I also suggest that you do the below.

    Uninstall SUPERAntiSpyware not since we are finished with it.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 5

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Then reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  4. scgms1

    scgms1 Private E-2

    Hi chaslang,

    Thanks for the reply. I did as suggested and there is still a problem with the computer. I contacted CA about the 3 threats detected and removed pop up that was being displayed with no log file. I went to their live chat and talked to some nice guy from India, VBG, who said to try this,...http://crm.my-etrust.com/CIDocument...ExternalCallID=0&Ver=&AddBookmark=0&KDId=3099

    I was unable to get Windows to update as after an 1/2 hour it finally got to installing the Geniune Advantage Tool and then hung up after that. Something is seriously wrong here. I did boot in safe mode and ran CA virus scan which detected nothing. I've also noticed that one of the programs for spyware, I believe it was Super Anti-Spyware changed the clock to 24 hours and then it never did change back. Todays date is also 2008-05-09 instead of 05-09-2008.

    I'm almost at the point of reformatting the hard drive unless you have some other suggestions. I really don't want to go through that, but....sigh

    Thanks for you help!
     
  5. scgms1

    scgms1 Private E-2


    Well I got this problem figured out. I went to..

    Control Panel

    Regional and Language Options

    Click Customize button

    Adjusted the date and time
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was not going to help you since you problems are not malware as I stated earlier. You may even being having physical hard disk issues & Windows OS file permissions issues based on some of the messages in your ComboFix log.

    This is not a malware issue.

    No this was from ComboFix. It happens when the scan does not run 100% properly.

    You can try the Software or Hardware Forums.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds