Potential Virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hartsville, Jan 25, 2005.

  1. Hartsville

    Hartsville Private E-2

    Hello All,

    My computer is running very slow. AVG Anti-Virus told me I has a virus so I tried to delete/heal/remove all to no avail. I ran Adware and Spybot they both removed spyware but Adware had problems removing everything it found. It said it would remove what it couldn't previously on my next re-boot. So I rebooted and now it takes forever for the Internet Browser or even opening My Computer takes 1 to 2 minutes after I click on the icon.

    Any ideas??? Please help???
     
  2. Hartsville

    Hartsville Private E-2

    Somebody please respond. Chaslang are you out there?
     
  3. Quinndrew5

    Quinndrew5 Corporal

  4. Hartsville

    Hartsville Private E-2

    Allright, I have gone thru the steps as illustrated in the Sticky Post. Adware and the Micro's Scan and Spybot all found problems. The problems were all "fixed" and I continued to finish out the instructions in the Sticky Post. I rebooted in to Normal Mode and the same problem exist. When I click on My Computer or Internet Explorer it takes 2 to 3 minutes before a window opens. I am now in Safe Mode b/c everything runs as normal in Safe Mode.

    Please Help

    Thanks.
     
  5. Hartsville

    Hartsville Private E-2

    How bout it Chaslang??
     
  6. Hartsville

    Hartsville Private E-2

    Any body else got any ideas.
     
  7. Hartsville

    Hartsville Private E-2

    I will post a HiJack This Log when instructed to do so. This is becoming a real pain in th rear.
     
  8. Hartsville

    Hartsville Private E-2

    Hello again. I guess my posts got lost in the shuffle. If any one has any ideas please let me know.
     
  9. Hartsville

    Hartsville Private E-2

    Did I do something wrong? If I did it was not on purpose
     
  10. Hartsville

    Hartsville Private E-2

    Went back and re-ran all the steps in the Sticky Post. Spybot found a problem it couldn't fix.

    Exact Bargain Buddy


    I am still up the preverbial creek.

    Please Help

    Thanks.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Quinndrew,

    Please do not post steps to help users if you cannot follow up on them. I understand you are trying to help and get the user started but you need to stick with it. And if you run into a problem you need to ask for help. (You should turn on PMs). PhilliePhan and myself cannot read every single thread, and threads with no responses typically get more attention then ones with responses.
     
  13. Hartsville

    Hartsville Private E-2

    Done. Thank you for responding.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is that log from normal boot mode or safe boot mode? We need logs from normal boot mode as specified in the HJT tutorial thread.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what this is:

    C:\Program Files\Matinsoft\GoldTach\GoldTach.exe
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I really needed the normal boot mode log to finalize this but try the below anyway.

    Make sure you have system restore disabled and viewing of hidden files enabled.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
    O2 - BHO: Search Relevancy - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~2.DLL
    O4 - HKLM\..\Run: [AdStatus Service] C:\Program Files\AdStatus Service\AdStatServ.exe
    O4 - HKLM\..\Run: [ss8X35O] maglgs.exe
    O4 - HKCU\..\Run: [dBr7RRi5V] ir4ilib.exe
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/ClickYesToContinue/ie/Bridge-c135.cab
    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\CxtPls <--- the whole folder
    C:\Program Files\SEARCH~1 <--- the whole folder
    C:\Program Files\AdStatus Service <--- the whole folder
    C:\winnt\system32\maglgs.exe
    C:\winnt\system32\ir4ilib.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Question:

    Why is this Lime Wire entry in the Matinsoft GoldTach folder? Do you use Lime Wire?
    O4 - HKCU\..\Run: [] C:\Program Files\Matinsoft\GoldTach\Lime Wire
     
  17. Hartsville

    Hartsville Private E-2

    Safe Mode. Sorry.

    "C:\Program Files\Matinsoft\GoldTach\GoldTach.exe" is my Firewall


    Yes I do use Lime Wire. Is that bad??
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All P2P stuff is bad! Why would you install it to your firewall directory anyway?
     
  19. Hartsville

    Hartsville Private E-2

    I have absolutely no answer to why it is installed to my firewall directory.

    Does Limewire make me more vulnerable? If so I may have to get rid of it.

    Things seem to be back to normal. Attatched is the HiJack This Log

    Thanks.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it does make your more vulnerable and it also contains its own malware! See this link:

    http://www.spywareinfo.com/articles/p2p/
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds