Possible Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by tclark417, Sep 1, 2010.

  1. tclark417

    tclark417 Private E-2

    Good day...

    I am using a Dell laptop running Vista (32-bit) and lately my CPU usage has been at 100%. I will get a message saying either FireFox is (not responding) or even in a word document the same thing. It will last for a few seconds to almost a minute. While it is not responding, I found that if I click in the middle of the page the document/web page will fade to white then go back. My CPU usage will go back down and everything will run fine. Then the usage goes back up. I was reading through the forum and did the steps to remove malware. I'm trying to figure out how to add attachments here.

    Thank you.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. tclark417

    tclark417 Private E-2

    Hi,

    Thank you for the reply and the info. I have 4 of the 5 files attached for you. I'm having a hard time locating the log for MGTools that I performed. Also, please note that the Combofix had me change the name before it would run the scan.
     

    Attached Files:

    Last edited by a moderator: Sep 1, 2010
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Log from running MGTools.exe will be located @ C:\Mglogs.zip
    Attach that as it is the most important log of them all.
     
  5. tclark417

    tclark417 Private E-2

    Hi,

    I've attached the info that was in the folder. there were numerous .txt files. u Please let me know if these are the wrong ones. Thank you for your patience.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, I don't want you to attach the files individually. There is no need when you are able to attach the complete C:\Mglogs.zip, which is what I requested.

    Thanks
    Kes.
     
  7. tclark417

    tclark417 Private E-2

    Thank you but it's not letting me upload the .zip file. it only opens it up with individual .txt files. I tried to move the whole folder to my desktop but it won't let me do that either, it's saying it's open somewhere.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Use a different browser. I don't see why it wouldn't work.
    Without seeing that log, I cannot be much help to you, with regards to a complete fix.
     
  9. tclark417

    tclark417 Private E-2

    let me try that! thanks!
     
  10. tclark417

    tclark417 Private E-2

    think i have it now!
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Please go to Add/Remove programs and uninstall the following software:

    • Ask Toolbar

    Now we need to use ComboFix to be rid of a not so nice BHO, check out the contents of a certain folder and also kill off some old avg remnants
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\programdata\avg9
    c:\programdata\AVG Security Toolbar
    
    DirLook::
    C:\Windows\System32\%APPDA~1  
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Rename 417.exe back to combofix.exe

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Your last MGlogs incomplete, when you run GetLogs.bat this time let it run all the way to completion, until you see the "hit any key to continue"

    When you see the prompt to agree to the Trend Micro HijackThis license, accept by hitting the accept button twice, it's a bug.

    Also attach the new log from SAS.

    Be sure to let me know how things are running now.
     
  12. tclark417

    tclark417 Private E-2

    Hi,

    Ok, I uninstalled the superspyware and downloaded and reinstalled the new one. I did the combofix as instructed. When the combofix was done running it restarted my computer. Before the computer shut down a box popped up and said something like "the application failed". It happened so fast then the computer restarted. When the computer restarted, another box popped up and said the dell language (or something like that) did not start. Then I went to run the GetLogs.bat file, i double clicked on it and a box came up saying it needed permission and every time i clicked ok the same box came up saying the same thing, over and over again, that I had to get the task manager up to get rid of it. I then tried to run it as administrator and it let me but i didn't get the option to click anything after it was finished.

    Now something extremely odd is happening. It is taking me forever to type this. While typing the cursor will move up 3 or 4 lines while I'm typing. and I will bring it back down to continue and it goes up randomly again. I have no idea why this is happening all of a sudden. It's like someone is doing it but not me.

    I've attached the spyware log and the combofix report for you.

    Thank you very much!
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The log you just posted for SAS is still out of date. It's v4.41, I need a log from 4.42.

    With Vista and windows 7 you should run as admin. Did you disable UAC?

    Check your C:\ drive for a Mglogs.zip and if it isn't there you will have to run the C:\MGTools\GetLogs.bat again and then attach the new log.
     
  14. tclark417

    tclark417 Private E-2

    Good morning,

    Attached you will find the new superspyware log. I ran the getlogs.bat file again as administrator and it did create a zip folder. However, please note that when it was finished running the window just closed and didn't give me an option of anything after that. I did disable UAC and had antivirus and firewall disabled.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    • C:\Windows\temp
    • C:\Users\Tina & Mark\AppData\Local\temp

    What malware problems are you still having, if any? How are things running for you now?
     
  16. tclark417

    tclark417 Private E-2

    Hi, My CPU usage has been staying down now and that's the first time in a long time. My cursor seems to be eratic and i'm not sure why that's happening. This evening I was doing an online class and had a few windows open and all of sudden the teachers voice got all mumbled up and my screen began to flicker and all of the windows were flashing and fading and then a screen popped up saying windows has to close but it didn't and then another popped up and said something wasn't working but was fixed. It all happened so fast with the windows popping everywhere that I couldn't read it.

    and now....

    I think I just made a big error. You asked that I delete:

    * C:\Windows\temp
    * C:\Users\Tina & Mark\AppData\Local\temp

    So I went in and deleted the files in windows\temp and went into Users/Tina & Mark/AppData/Local and then deleted. I didn't go into the temp folder. What is this going to do when I shut my computer off and restart? I'm sure I messed something up now!

    By the way, in the Users/Tina&Mark there is an Application data folder with an arrow on it as well as the AppData

    I'm afraid to restart. I really appreciate all of your help and patience!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just restore it out of the recycle bin, can you do that?
     
  18. tclark417

    tclark417 Private E-2

    I'll try that now. thanks.
     
  19. tclark417

    tclark417 Private E-2

    whew! i was able to restore them. thank you. there are two files left in the temp folder because it says it's in use??


    plugtmp-1 file folder
    ~DF7387.tmp
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're all set! Any further issues you have will have to be discussed in the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  21. tclark417

    tclark417 Private E-2

    Thank you very much. To uninstall Combofix you state to hit start then run. I don't have the "run" option. I'm running vista.
     
  22. tclark417

    tclark417 Private E-2

    Those two files that I couldn't delete in the temp file, is that ok?
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just type run ;)

    Those files that wouldn't delete are fine.
     
  24. tclark417

    tclark417 Private E-2

    Thanks!!! rolleyes

    Appreciate all of your help!
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome. Safe surfing! :)
     
  26. tclark417

    tclark417 Private E-2

    Hello again,

    I'm having 100% cpu usage bad again. While I'm typing this by internet is really slow and will say not responding and the screen will fade briefly to real light then work again then repeat. I opened the task manager and it i it process from all users and one is reading at 69 and that is Symantec Service Framework. I don't know what to do.

    Thank you.
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a malware issue! Ask questions about it in the software forum :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds