PLEASE HELP!!!! This is my HIJACK THIS scan

Discussion in 'Malware Help (A Specialist Will Reply)' started by rezgeek, Dec 2, 2008.

  1. rezgeek

    rezgeek Private E-2

    I need help with removing some processes. I have already removed some services from my computer but now I am at a stand still and it takes forever to search the net to find out if I should remove a prog. My CPU is running somewhere between 4%-35%...Very low... I am spiking constantly... I need help with removing Unwanted Processes from the startup and anything else not needed running in the background until I need it. GEEKS?GOD help me!

    Logfile of Trend Micro HijackThis v2.0.2
     
    Last edited by a moderator: Dec 3, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. rezgeek

    rezgeek Private E-2

    Tim,
    Thanks for the help I am running the requested material you posted for me. I did not realize you couldn't post a HJT log on here as I wasn't reading all the forums. Due to my nature of "Help me now, I need this done." lol.
    I did look through the net on how to read a HJT log and remove some items but only after viciously scanning the net to make sure it was ok to remove them. Also I just recieved an update for my Windows XP.
    I will post up the logs from the mailware in little bit.
    Jen
     
  4. rezgeek

    rezgeek Private E-2

    Ok, on the Basic Computer Maintenance Everyone should do this is what I did, I went to my Add/Delete Prog Files and removed anything I didn't use. Next, I downloaded the CCleaner Slim for cleaning up my hard drive and ran it. 475.0MB removed. Next up is the registry cleaning I did with the CCleaner. There was 133 missing MUI references. I scaned for issues and clicked fix. That was easy. I also disabled some startup progs at startup on my puter.
    Next was to run the defrag. I already have IObit defrag so I reran it. The first step in the House Cleaning & Setup I did the uninstall Adware via Add/Remove prog. I only had one to remove and it was View Point Media Player, everything else was good. I am going to be running the Msconfig on my Windows XP, so I will post another reply of the last of everything I did when I come back.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    All you need to do with msconfig is to make sure it is normal startup mode.

    Then run the scans and attach the logs. :)
     
  6. rezgeek

    rezgeek Private E-2

    Well, I am back with no problems as of yet, knock on wood. After Msconfig on my puter I went and enabled all my hidden files as per told in the House Cleaning and Setup link you provided. Then I went and did the cleaning for the Winidows XP I started to download the requested items such as SuperantiSpyware, Spybot,Malewarebytes Anti Maleware, combofix.exe and last but not least MGtools.exe, but for some reason I am unable to change there download destination. I see they are being downloaded into a Temp folder. Is this ok? I don't want to proceed because the forum states to not download anything to a temp folder. Let me know and I will continue when I here a reply.

    Thanks again,
    Jen
     
  7. rezgeek

    rezgeek Private E-2

    Holy stupidness I am a retard...lol basic download proceedure. Hit save as ...
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Move them from the temp folder to your desktop....all but MGTools, which should be moved directly to your C:\ drive ---> C:\MGTools.exe

    You should be able to change your download destinations.
     
  9. rezgeek

    rezgeek Private E-2

    Ok I am downloading everything now and will move them to my desktop, Question though, since I have started doing this I have noticed on my desktop that I have a new little notepad that is named desktop.ini and when opened it says [LocalizedFileNames]
    Windows Media Player.lnk=@C:\WINDOWS\inf\unregmp2.exe,-4

    Anything I should be worried about?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No..it is a result of allowing hidden files and folders to show.

    I am leaving work and will get back to you after I can check your logs.
     
  11. rezgeek

    rezgeek Private E-2

    Ok Mr.TimW, I hope I did all of this correctly. If I didn't I am goning to scream....lol Here are the LOG files for the proceedure operated on my computer... Let me know... Thank you,
    Jen
     

    Attached Files:

  12. rezgeek

    rezgeek Private E-2

    And here is the 4th LOG...:clap
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you look at your Combo log, you will see what was the main problem.

    So we are going to do this:

    Please use add/remove programs to uninstall:
    iWin Games (remove only)"
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player

    Reboot and make sure that these are no longer there:
    c:\program files\iWin.com
    c:\Program Files\iWin Games

    If they are, just delete them.
    Now download and install:
    Java Runtime

    You also need to install a lot more ram in this system:
    Code:
    Total Physical Memory    256.00 MB    
    Available Physical Memory    65.59 MB
    
    Please tell me how things are running.
     
  14. rezgeek

    rezgeek Private E-2

    Everything is moving much more smoother and faster. I am no longer sitting there waiting for Windows to load or shutdown. Also now my wireless connection is moving at a Very Good rate. Before I was only recieving at around 36.0Mbps now I am at 54.0. Since I am 20 feet away from the router box as it is. All though I did configure the router box and change the channel settings, cloned the Mac IP from the main computer and a few other tweaks.

    Now about thie Ram, do I take the computer somewhere to have it installed? I have never added Ram to a computer before... I might just surf the net to find that answer... ALl in all Mr.TimW a fine job you did helping me out!!!

    THANK YOU.

    :p
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can go to crucial.com and let them scan your system and report what you can install.

    The the actual installation is very simple. Post in the software section or check the web for instructions. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds