Slow PC, many viruses, logs inside

Discussion in 'Malware Help (A Specialist Will Reply)' started by Phanatic, Oct 31, 2008.

  1. Phanatic

    Phanatic Private E-2

    Smitfraud-C, Virtumonde, and Antivirus 2009 are among a few of the viruses I've seen through the MANY scans I've done. Luckily I came across this forum VIA McAfee, and I was hoping you guys could help.

    This is my laptop I use for school, but all my buddies have been using this computer as well. Once I get it fixed, this laptop is off limits. I've read the READ & RUN ME FIRST guide, and followed it to the T.

    My main problems with this laptop: it boots up slower than normal, I feel I have many unnecessary running processes (but afraid to close them in fear of shutting off the wrong process), and I can't even load up my FireFox browser anymore. FireFox will appear in my processes for a second, then disappear. I can only get FireFox to load in Safe Mode.
     

    Attached Files:

  2. Phanatic

    Phanatic Private E-2

    MGlogs.zip attached.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You forgot to accept the license agreement for TrendMicro HijackThis. Make sure you accept it later when I ask to to run a scan with MGtools again at the end of this message.

    You still have a bunch of malware to remove. I will also give a few tips to help things run better since you are complaining about performance. In fact, let's start with these tips.

    • Did you purchases Spyware Doctor and Uniblue Registry Booster? If not, uninstall them now before continuing.
    • Also uninstall Viewpoint Media Player as requested in step 1 of the READ & RUN ME.
    • Also uninstall MySidesearch Search Assistant Bfinding
    • I suggest that you cleanup all the files you have saved to your Desktop. Remove everything but links and ComboFix.exe which we need. A cluttered Destop is malware's playground and also it slows your PC down especially when you save lots of large files there like you are doing. Save your EXE's in a Downloads folder somewhere else (not on your Desktop).


    Now we need to use ComboFix to remove a bunch of malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 3, 2008
  4. Phanatic

    Phanatic Private E-2

    Thanks for the quick response. You guys are great! I cleaned up my desktop like you suggested, and it looks much better.

    It seems to load at a decent pace now, but I have a some problems still bugging me.

    1) TrayApp. Upon starting the computer, it launches a "TrayApp" installation. In the 3 years I've had my laptop, I've never even heard of TrayApp. I read on a website that some people associate this file with HP Printers, but I've never hooked up a printer to this laptop... so I don't have the HP disk that some people suggest. The ONLY way I can close TrayApp is by ctrl+alt+dlt. It will constantly reload until I kill the process.

    2) InstallShield Update Manager. Also upon starting the pc, this program runs and states I need to download updates. Unfortunately, when it runs, it shows me an error has occurred. I'm not quite sure what InstallShield even is associated with, or if I can somehow remove it.

    3) Move Networks Media Player for Internet Explorer. This is inside my "Add or Remove Programs" list. I don't recall this being in the list before, but I could be mistaken. It says it's 81.14MB and dated 5-22-08. I'm not too worried about this, just wanted to bring it up.

    4) FireFox. When I double click, it loads for a second in my process list, but then it disappears. Since I became infected, I can't open FireFox. I removed and re-downloaded and installed, but it still doesn't work.

    5) 70 Running Processes. Is that too many running at one time? It says it's only between 2-7% cpu usage, but 70 seems a bit high. I suppose once I remove some of the anti-spyware programs this will help.

    I believe that sums up the last of my problems. Once again, thanks for your help. Logs requested are attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly it is something related the software your still have installed related to HP. All of the below are installed. If you don't need these then uninstall them. Notice the last one is TrayApp.
    HP Imaging Device Functions 6.0
    HP Photosmart Cameras 6.0
    HP Photosmart Essential
    HP Software Update
    HP Solution Center and Imaging Support Tools 6.0
    hpiCamDrvQFolder
    HPProductAssistant

    TrayApp

    It was installed on the PC when it was shipped. It is an automatic software update program. It is not a malware problem. It is being used to update your iPod and other Apple related software and also some Dell Software and a bunch of other software Dell installed on the PC when it was shipped. It you don't want InstallShield to run then you can remove the two below startup processes:
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup


    I suggest that you try again and after uninstalling, reboot and then delete all FireFox folders. Then reinstall. Other than that, I suggest you work this (and any further questions on other items above) in the Software Forum since these are not malware problems.

    The only item from the READ & RUN ME that is running is a Tray icon for SUPERAntiSpyware. It will not change things significantly. McAfee is your largest adder to running processes. Then all the junk from Dell that you are running. Again none of this is a topic for the Malware Forum. See the tips given in step 1 of the READ & RUN ME for Dealing with Startup Processes.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  6. Phanatic

    Phanatic Private E-2

    Thanks for all your help. Everything seems to be working nicely. To fix my remaining problems, I uninstalled my HP photo software and my errors went away. Oddly enough, my FireFox browser started working again as well. I feel confident I can go about my business as usual now.

    Thank You
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Be sure to run Step 7 in the final instructions to flush your system restore points.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds