Slowness, Trojans, problem running scan

Discussion in 'Malware Help (A Specialist Will Reply)' started by jessleighj, Feb 2, 2009.

  1. jessleighj

    jessleighj Private E-2

    I had AVG and all of a sudden it said I had to restart to complete an update. I did and was overrun with virus notifications. I did a virus scan and nothing was found. My internet has been slow for a while now, especially when I try to watch video online. I followed all instructions for vista users, but when I tried to run the mgtools.exe it kept asking me about a registry key and I would say yes, then it would pop up again and ask the same thing. I kept saying yes and it never stopped. I tried it a couple more times and it didn't work. I am attaching the log files from the other programs I ran . Lots of trojans were found.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need the log from running the MGTools.exe --> C:\MGLogs.zip
     
  3. jessleighj

    jessleighj Private E-2

    I can't run MG Tools. There is some problem with User Account Access - I get a window altert that pops up and I press continue, but then it pops up over and over and every time I press continue it keeps popping up.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read and follow the instructions for Vista users that was given in the Using MGtools link in the READ & RUN ME. This was all explained.
     
  5. jessleighj

    jessleighj Private E-2

    I'm sorry. I went back and realized I skipped a whole step. My log file for MGTools is attached. Please advise! Thank you in advance!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you still having?
     
  7. jessleighj

    jessleighj Private E-2

    My internet is slow. The speed comes and goes - it will be normal, then it will fall away completely for a while, then come back. It goes up and down like that the whole time. I have free AVG and it updates all the time, but it didn't catch all those viruses I had. Should I switch to something else? Do you think my computer is rid of all those viruses now? I think the virus hijacked AVG because everything happened after AVG demanded a restart after an update. This makes me nervous about using it now. Are my log files okay?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are fine. I would suggest that you try using a different browser (FireFox) and see if you have the same issues. If you do, you might want to check with your ISP for problems on their end.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  9. jessleighj

    jessleighj Private E-2

    I found the run file (not on my start menu - vista issue?) and tried to uninstall the combofix. I got a message that said "prep.com has stopped working" then a virus notification from AVG - Virus detected C:\Users\User\AppData\Local\TCMP\637.tmp\b2e.dll and it said it was a Trojan horse BackDoor.SmallX.VX and then made me close the combofix uninstall program. I said to move the virus to the vault and tried to run it again and the same thing happened. What should I do?
    Thank you for your help.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can manually delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that were created. I don't know if what AVG is reporting is related to Combo, but once you remove it, run CCleaner and scan again with AVG and see if anything comes up.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds