Not sure if I have a malware problem (logs attached)

Discussion in 'Malware Help (A Specialist Will Reply)' started by mdpeterson42, Mar 6, 2009.

  1. mdpeterson42

    mdpeterson42 Private E-2

    I originally posted in the software thread but was told I should try going through the malware removal steps too.

    Basically, my computer closes Windows Generic Host whenever I start my computer because some program(s) is attempting to use it improperly. I then get a couple svchost.exe errors that if I hit OK or cancel will cause problems with my computer, but if I just move them out of my way, my computer seems to operate fine.

    When the problem first started, I used McAfee. I now use PC Tools firewall and Avast anti-virus.

    The first time I started my computer with PC Tools, it asked about several programs that were attempting to use Windows Generic Host and I denied access to all of them - not even knowing if they were harmful or not. But I still get the error messages.

    Anyway, that is basics of my problem. Here are my logs
     

    Attached Files:

  2. mdpeterson42

    mdpeterson42 Private E-2

    MGlogs

    Thanks!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are not showing any malware problems but I do have a few things for you to do as given below.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 11
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

    After clicking Fix, exit HJT.

    Now reboot your PC and after reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run this Running GMER to detect rootkits

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the log from GMER
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. mdpeterson42

    mdpeterson42 Private E-2

    Ok, so I got rid of the old Java versions (I thought I had gotten rid of them all - my bad). I then ran the HijackThis like you instructed and got rid of those lines. When I restarted my computer, I had to do a hard shutdown. It froze up on restart. Then when I restarted again, it was fine - I got the Windows Generic Host error but not the svchost.exe errors.

    I then tried running GMER but it gave me some problems. I restarted the compueter and got a BSOD on restart.

    I have not yet tried re-running GMER because I have not really had time.

    However, the last two times I restarted my computer, I did not get any of the errors, so maybe I am on the path to recovery. Just wanted to give you an update. I will post the logs when I have finished all the steps.
     
  5. mdpeterson42

    mdpeterson42 Private E-2

    OK, so I finished all the steps and my logs are attached

    after my last post and prior to running GMER, I had to restart my computer. Upon restart, I had the svchost.exe error.

    I then ran GMER, CCleaner and MGTools without a problem. I then decided to restart my computer. I got several messages of programs that could not close (this has happened before but I did not think to mention it before): Zrcfg.exe, sprtcmd, CiceroUI (can't remember the whole name) and explorer.exe

    I then had to do a hard reboot

    Upon restart, I got one Windows Generic Host shutdown error but no svchost.exe errors

    So, that is how things are going. Here are the logs
     

    Attached Files:

  6. mdpeterson42

    mdpeterson42 Private E-2

    sorry for the second post, but something I have never seen before just happened

    I was surfing the net and I got a screen like the BSOD but instead it said that I had a Hardware Malfunction and that I had to contact my vendor.

    I turned off the computer and turned it back on and everything booted normally. I didn't get either the svchost.exe error or the Windows Generic Host errors
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your GMER log was also clean so it still appears that you are not having problems related to malware. If you still have crashes, you will have to post specific information on them in the Software Forum.

    It is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. After doing the above, you should work thru the below link:
     
  8. mdpeterson42

    mdpeterson42 Private E-2

    thanks for all your help!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds