Please help - logs attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nomiballou, Mar 5, 2009.

  1. Nomiballou

    Nomiballou Private E-2

    Hi there,

    Computer's been very slow lately; CPU at 100% a lot. Opened an email attachment from a friend yesterday and got a weird sound, the video didn't play through, computer rebooted and I swear I saw some new text flash by after initial page of reboot.

    I ran SuperAntiSpyware and Spybot with no results. Spybot start-up menu indicated a couple of trojans. Did your malware removal process. MGTools stopped in middle: "no procdll.txt file found". No log for SAS. Available logs attached. Will attach printscreen of Spybot startup in next email.

    I have ZoneAlarm firewall, AVGfree Antivirus and SAS. Run Spybot once a week or so.

    Sure would appreciate any help. I'm about ready to reformat my drives!

    Thanks very much,

    Dale
     

    Attached Files:

  2. Nomiballou

    Nomiballou Private E-2

    Here is Spybot startup printscreen.

    Thanks,

    Dale
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What was the problem running SAS?

    Use windows explorer to find and delete:
    C:\~VM16D.tmp
    C:\~VM16C.tmp
    C:\~VM16B.tmp
    C:\~VM16A.tmp
    C:\~VM169.tmp
    C:\~VM168.tmp
    C:\~VM167.tmp
    C:\~VM166.tmp
    C:\~VM165.tmp


    Now lets see what this will find:
    Using BitDefender Online Scan.
     
  4. Nomiballou

    Nomiballou Private E-2

    Hi Tim,

    Thanks very much for looking at this for me.

    SAS ran normally, as far as I can tell, and reported that no problems were found. There was no log, but I don't have "Show Empty/Clean Logs" checked off so this makes sense to me. (I had deleted the previous logs as suggested in an earlier point in the instructions.) Should I check this box?

    I deleted the temp files you listed. Noticed there are other system files in that folder with 0KB also. These are okay?

    Had a few problems getting BitDefender to run, apparently because I have SP2, but got a successful scan and have attached the log. (There was no naming option except for html so I appended .txt to the name when saving and am hoping it will work properly for you.)

    I notice that all the infected files appear to be e-cards sent to me from my boyfriend at work - didn't see any dates but I think most are quite old. Is it more likely to assume that the viruses were picked up at the e-card site than at his work site in a hospital?

    Also noticed that none of the infected files seem in any way related to the trojans that were identified in my SpyBot Startup list.

    Don't want to be too wordy here, but after the last edition of IE came out, it became so ridiculously slow that I switched to Firefox. I apparently still have to have IE in order for some programs to work but wish I didn't. Could the origination of my current problems have begun in IE?

    Look forward to hearing from you.

    Thanks, Dale
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What IE version are you running? There is an IE addon for FireFox so you can use it for updates thru MS.

    Malware detected in email databases has to be cleaned up by you. You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/196990 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.

    You need to tell me exactly what SPybot is reporting ( image is too fuzzy for my eyes..:()

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file so I can take a new look at it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds