Ohiomike Malware HELP

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ohiomike5150, Sep 27, 2009.

  1. ohiomike5150

    ohiomike5150 Private E-2

    Hello...

    I'm pretty new at this, but think I've followed your instructions very closely. I'm attaching all the log files as requested. My scans did find quite a bit of malware etc.

    I look forward to your replies. Thank you for your time and patience with this.

    Regards,
    Mike
     

    Attached Files:

  2. ohiomike5150

    ohiomike5150 Private E-2

    Ohiomike malware help 2nd attachments

    MG tools log files attached as a .zip file...
     

    Attached Files:

  3. ohiomike5150

    ohiomike5150 Private E-2

    Hello, I'm new to this forum so please bare with me. My computer has been running slow and my web browser has been acting up as well. Closing or freezing up more frequently. I found your site... and followed the instructions in the Remove Malware part. I've ran all the scans... and have created all the log files.

    THe scans did find a lot of malware on my PC. I'm attaching all the logs with the hopes that a professional might be able to have a look and see if I am clean or need to do anything else.

    Since removing the malware... the browser seems to have less problems than before and it's still running slow. Below are the details of my system.

    Compaq Presario Desktop
    Intel P4 1.8GHz
    1GB DDR
    WinXP Home edition SP3
    80GB HD... 58GB free
    Running Norton AV2009


    Hoping someone can help me out.. it would be appreciated.

    Thanks,
    Mike
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should have read the sticky thread link you were given: Don't Bump! It Only Hurts You!!!

    This post was unnecesary and cost you more than 2 more days of waiting time.

    You performance issues may be more related to Symantec/Norton which was installed or updated on Sept 20. Howeve, let's finish your cleanup and see what happens.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {656EC4B7-072B-4698-B504-2A414C1F0037} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Support - {8B385B89-EBEE-471A-B505-C79F2395FEDC} - C:\Program Files\Internet Explorer\SIGNUP\Presario.htm (file missing) (HKCU)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. ohiomike5150

    ohiomike5150 Private E-2

    Hey Chas...

    Thank you for your assistance with this. Below are the log files you requested. PC is running better than before but it's still a little slow. Prior to all this work it would start piping in music and/or commercials to my PC, even when I didn't click on anything or wasn't even on the internet. I knew I was infected with something. That seems to have stopped so far.

    Please let me know how to proceed. Thanks again for your time.

    Regards,
    Mike
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    This may not be malware. It could just be what you are running (like Norton). But you will have to be much more specific.


    Please explain what operations are slow! For example answer the below:
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds