Problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by reight8, Oct 19, 2007.

  1. reight8

    reight8 Private E-2

    My computer is super slow from the time it loads up until i try to click and run anything. The internet wont even connect and the desktop has a desktop recovery screen on. Also control alt delete takes forever to show up too.

    i read the read me, im some what familiar with it, but without getting on the internet i cant download anything to it...

    what should i do?

    i already went through the add/remove programs and removed outerinfo and viewpoint media player.
     
  2. abri

    abri MajorGeek

    Hi reight8!
    Welcome to Major Geeks! A slow computer can have several causes, one of which is malware. It could also be that you have a bad sector on your harddrive. If you have any access to a Norton's Disk Doctor, please run it and see if it can locate any bad sectors that could be causing the problem. If it finds something, it will reroute your process around it. You may also want to ask in the Software Forum for other tools that do the same thing.
    As for checking for malware, can you get to another computer that has an internet connection and download a few of the installation programs there onto either a cd or a flash drive? If so, please attempt to get the installation programs for the following and run them. Try to run Combofix before you install the others. If your problem is malware-related, it may give you some relief. If your problem is not a malware problem, you may need to use your operating system cd to attempt a recovery.

    Run this utility:
    Whether you are able to run Combofix or not, please try to get the following three scans:
    Using ShowNew

    Using GetRunKeys

    Downloading, Installing, and Running HijackThis

    If this is still too much, please try to get a hijackthis log to us.

    abri
     
  3. reight8

    reight8 Private E-2

    i am using the infected computer now. i ran downloaded combo fix and put it on a cd then ran it on here. it made the internet start working and made the computer a little faster.

    also on the desktop the wall paper is a message saying spyware is detected from an ip address and it has it in red.

    im going to download the other programs now. ill send the combo fix log right now though. thank you.
     

    Attached Files:

    • log.txt
      File size:
      17.6 KB
      Views:
      1
  4. reight8

    reight8 Private E-2

    alright heres the hijack this log. Also i ran spybot and found

    smitfraud-c.
    aconti
    mirar
    win32.agent.pz
    win32.trafficsol.c
    adbreak
    microsoft windows security center override

    i fixed the selected and re ran the program. the only thing that came back was the win32 agent.pz
     

    Attached Files:

  5. abri

    abri MajorGeek

    Hi reight8!
    Please do the following next:
    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:

    * GetRunKey
    * ShowNew
    * HJT

    How are things working now?
     
  6. reight8

    reight8 Private E-2

    alright so here is the first log from the tool.
     

    Attached Files:

  7. reight8

    reight8 Private E-2

    heres the other rapport log.. i will get you the others in a little. i have a few things to take care of.

    the wallpaper on the desktop returned to normal and it hasnt showed any signs of any problems yet. thank you for your time and help.
     

    Attached Files:

  8. reight8

    reight8 Private E-2

    Oya i also ran hijackthis real quick and have the log.
     

    Attached Files:

  9. abri

    abri MajorGeek

    reight8

    please do the following:

    Scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    Please attach a fresh log from HijackThis and then work through the READ & RUN ME FIRST and post the requested logs.

    abri
     
  10. reight8

    reight8 Private E-2

    alright i will do that now. do i still need to get you the getnewkey and save new logs???
     
  11. reight8

    reight8 Private E-2

    alright heres the log
     

    Attached Files:

  12. abri

    abri MajorGeek

    Hi reight8!

    The F2 entry didn't get deleted, so I need for you to work through the instructions in the READ & RUN ME FIRST. Both Counterspy and Panda pick up this infection, but I'm not sure yet whether they can delete it. Please be sure to have Counterspy fix what it finds! You may have to run it in normal mode. When you finish you will have 6 logs to post to us and you will need to post twice for the attachments.

    -Counterspy
    -BitDefender
    -Panda
    -ShowNew (newfiles.txt)
    -GetRunKeys (runkeys.txt)
    -HijackThis

    abri
     
  13. reight8

    reight8 Private E-2

    Alright so, did everything that you asked. Bitdefender didnt work and panda didnt work..

    ill attach all the logs i have right now.

    spybot still found the win32 agent pz
     
  14. reight8

    reight8 Private E-2

    logs....
     

    Attached Files:

  15. reight8

    reight8 Private E-2

    logs 2
     

    Attached Files:

  16. abri

    abri MajorGeek

    Counterspy picked up a ton. The F2 entry is unfortunately still there. We will work on it again tomorrow. Was the commercial keylogger something you installed yourself?

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds