Slow compluter, help please?

Discussion in 'Malware Help (A Specialist Will Reply)' started by MonL, Oct 13, 2006.

  1. MonL

    MonL Private E-2

    Hi,
    About a week ago I got some viruses on my computer. I downloaded and ran several different anti-virus- and malware programs, and although they seemed to take care of most of the problems, they kept finding a few new files everyday...so clearly they couldnt get rid of it all. (I don't remember the names of most of the things they found. Just that one of them were winlogonhook and some maxifiles.)

    So yesterday I went here http://forums.majorgeeks.com/showthread.php?t=35407 and followed step 0 to 6 (the only thing I didn't do was download the CCleaner from that link, because I already had both the toolbar and CCleaner). The computer seemed perfect for a few hours, so I thought it was okay. But now it's very slow again so I'm not so sure.

    What should I do? Do everything again and countinue with step 7?
     

    Attached Files:

  2. MonL

    MonL Private E-2

    Last attachment
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I really need the HijackThis log from step 7 of the READ ME too. However, before getting one, follow the steps below and also answer the questions I ask.


    Is your copy of ewido anti-spyware 4.0 a paid or free version? If free, uninstall it now!
    Is your copy of Spy Sweeper a paid or free version? If free, uninstall it now!
    Is your copy of SUPERAntiSpyware Professional a paid or free version? If free, uninstall it now!

    Is your Norman Antivirus and Ad-Aware SE Plus a paid program? Don't uninstall it (at least not yet) if it is a free trial!

    Now uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_04
    Mozilla Firefox (1.5.0.1)
    Viewpoint Media Player <--- should have been uninstalled in step 0 of the READ ME

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Now run this Virtumonde aka Trojan Vundo Removal and attach the log from VundoFix.

    Now attach a new log from ShowNew and also complete step 7 of the READ ME and attach a HijackThis log.
     
  4. MonL

    MonL Private E-2

    Thank you :)

    All free versions - all uninstalled now.

    Not free version and not uninstalled.

    Done.

    Done.

    Didn't install this again since I don't really use it.

    Done.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to distributed.net client
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastednetc into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and
      pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Programfiler\Fellesfiler\{ECF16DE1-0A21-1044-1014-03071520002c}\Update.exe
    C:\WINDOWS\impborl.dll
    C:\WINDOWS\system32\cmmgr32.exe
    C:\WINDOWS\system32\rtutv.ini
    C:\WINDOWS\system32\rtutv.ini2
    C:\WINDOWS\system32\iosdt\iosdt.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK
    to continue (But please let me know if you receive this message!). If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete it if found:
    C:\Programfiler\Fellesfiler\{3CF16DE1-0A21-1044-1014-03071520002c}
    C:\Programfiler\Fellesfiler\{ECF16DE1-0A21-1044-1014-03071520002c}
    C:\WINDOWS\system32\iosdt
    C:\Programfiler\SUPERAntiSpyware

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System
    Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if
    using WinXP or WinMe.
     
  6. MonL

    MonL Private E-2

    Thanks once again for helping!

    It was already stopped, but I changed start-up type to Disabled.


    Done.


    Done.

    Done.

    Done.


    Not sure I did this right. :eek: I copied/pasted all the files at the same time and nothing happened. So I went back and did this step again later, and copied one and one file into the box, and then I got the "PendingFileRenameOperations" pop-up.

    I didn't find "C:\WINDOWS\system32\iosdt", but found and deleted the others.

    Computer seems to be working fine at the moment, but I'm not sure if that means it's fixed or not, since it worked fine for a while a few days ago too and then got slower and slower again. So I might have to use it for a little while and see?
     
  7. MonL

    MonL Private E-2

    Forgot attachments...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since your Norman Ad-Aware SE Plus is a paid program, you should now uninstall Windows Defender to avoid conflicts and also the excess use of system resources.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If you used VundoFix, delete the C:\VundoFix Backups folder.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    5. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds