Some sort of infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by bjornhall, Sep 18, 2010.

  1. bjornhall

    bjornhall Private E-2

    Hi,

    One of our computers has been showing these types of symptoms (second hand information, so I am sorry that it is so vague):

    - Everything running super ultra slow, to the point where the computer is practically useless; even opening a web page or document takes forever
    - Popups saying things like "Insufficient memory to complete this operation" and "Not enough quota...".
    - Symantec AntiVirus history shows these two recently: grpconv.exe, Trojan.Bredolab
    - Sometimes problem booting, might have to try a few times (no clue if that is malware related)

    Tried doing the steps in the read me with mixed success:

    - SuperAntiSpyware crashed partly into the scan (tried it twice)
    - Malwarebytes AntiMalware ran ok, log created
    - Combofix seemed to run as it should and claimed to fix various things, but did not seem to create a log when it was done
    - RootRepeal: Little gray window saying “Initializing, please wait”. Waited about fifteen minutes, TaskManager showed CPU usage bouncing around between 46 – 50%, no change. Tried it twice, same result.
    - MGTools ran ok, logs created.

    Not sure where we are at now since all scans did not ran. Could you have a look?

    Thanks! : )
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your MGLogs is missing some items. Did you not get an agreement to run HJT? Please run it again and let it continue until it shows it is complete:
    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Attach the new C:\MGLogs.zip.

    Also try re-running ComboFix. The log should be at C:\ComboFix.txt.
     
  3. bjornhall

    bjornhall Private E-2

    I am not sure MGTools ran completely; it did a lot of stuff, and then just stopped. No HJT agreement popped up. I am attaching the new log, it looks similar to the first one though...

    ComboFix: When running it, a window pops up starting "Windows can not find grpconv.exe...", and then disappears. Then "There is a new version of ComboFix, would you like to update?", answer yes, it seems to download, then closes and nothing more is seen.

    I forgot to mention (sorry!) that we worked around that first time we ran ComboFix by creating an empty file named grpconv.cmd and save it to the windows/system32 folder. That way ComboFix would run, but I am not sure if it completed and it did not generate a log. We removed grpconv.cmd afterwards and ComboFix would not run now.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This may not be a malware issue. Please go to C:\MGTools\analyse.exe and run it. Attach the HJT log that is produced.

    Then, assuming you have your OS cd, go to start / run / type:
    sfc /scannow and let it run twice.
     
  5. bjornhall

    bjornhall Private E-2

    Ok, ran analyse.exe and it produced the log below.

    Don't have an OS CD, just some funky recovery disk. Will investigate that disk and if it has an i386 folder in it I will copy it to the C: drive, slipstream XP SP2 into that folder (turns out SP3 is not even installed, will do when we're done here!), tell sfc to use that folder as the source instead of the CD by editing the right registry key and run sfc. Sounds good?

    The computer is doing much better already so it seems we already did something that helped. ComboFix did say it found and fixed all sorts of stuff, did not write down what since I thought it would leave a log behind...

    Again thanks for your help! : )
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your HJT log is clean. And I would recommend you install sp3. What malware issues are you still having, if any?
     
  7. bjornhall

    bjornhall Private E-2

    Not sure, it seems to be running ok at the moment. Will do some updating of various things (this PC has been messed up for a while so it needs some general maintenance). Will do that and see how things are, will come back if there are still problems.

    Thanks, you are really doing a great job here and it is very much appreciated! : )
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. I will be here. I will give you the final cleanup instructions, but you may wish to hold off on them until you are sure your system is running OK.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds