Strange symptoms

Discussion in 'Malware Help (A Specialist Will Reply)' started by RobotTemple, Apr 19, 2010.

  1. RobotTemple

    RobotTemple Private E-2

    I've noticed some 'strange' activity on my computer lately, such as not being able to right click icons, getting an error message that reads "this operation has been cancelled due to restrictions in effect on this computer. please contact your system administrator" even though I am the administrator when I try to access certain folders, or when I try to access Windows Security Alerts panel. Control panel disappeared from start menu also and I was not able to restart in safe mode, it would just freeze my computer. I have since run SUPERantispyware, Adaware, Spybot S&D, Malwarebytes and Ewido antispyware, each coming up with their own separate results, which I would get rid of, but I still had all these problems, so I ran combofix and it seems to have fixed all the problems except for a few things, like google wont even load, and my internet speed is still really slow and it also disconnects frequently. I also still can't boot up in safe mode it just brings up all the numbers and letters and the recovery partion things like normal, then it stops and doesn't go any further and I have to manually reboot.

    Any help would be appreciated, I will attach the logs.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the requested log from MGtools.

    You also should uninstall Ewido which was discontinued and replaced by AVG Antispyware and then AVG Antivirus a long time ago.
     
  3. RobotTemple

    RobotTemple Private E-2

    Alright, I got rid of Ewido, and heres the MGtools log:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are not showing any real obvious malware. Only things that are very questionable and maybe the cause of your problems since you downloaded, installed and ran the recently. And these are Nexon NX Cash Generator.exe and FlashGet3

    ComboFix obviously does not like FlashGet3 and basically broke it by deleting much of it. The proper thing would have been to uninstall it.

    And some websites consider Nexon NX Cash Generator to be unsafe. See: http://www.prevx.com/filenames/2902335753267124421-X1/NEXON+NX+CASH+GENERATOR.EXE.html


    I suggest that you uninstall this stuff and delete all the related files and folder which would include the below:
    Code:
    2010-04-18 23:55 . 2010-04-19 00:33 84992 ------w- c:\windows\Nexon NX Cash Generator.exe
    2010-04-18 23:55 . 2010-04-18 23:55 216800 ----a-w- C:\Nexon NX Cash Generator.zip
    2010-04-18 19:40 . 2010-04-18 19:40 -------- d-----w- C:\Nexon
    2010-04-13 23:47 . 2010-04-13 23:47 4216840 ----a-w- C:\vcredist_x86.exe
    2010-04-07 16:55 . 2010-04-07 16:55 -------- d-----w- c:\documents and settings\Owner\Application Data\FlashGet
    2010-04-07 16:55 . 2010-04-07 16:55 6146304 ----a-w- C:\flashget3.3.0.1092en.exe
    2010-04-06 23:52 . 2010-04-07 00:34 1705656 ----a-w- C:\AllodsOnlineDownloader.exe
    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Other than that, you may want to try using System Restore to return to a point before you started downloading and installing this stuff. If that does not help, I suggest that you post in the Software Forum since it does not appear that you are having real malware issues.
     
  5. RobotTemple

    RobotTemple Private E-2

    Well, I'm not sure what this Nexon even is, but when I deleted all aspects of it my computer seems to be running smoothly now oddly enough. Thanks for your help, chaslang.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds