Turtle slow, redirecting and warning noise

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ferox, Aug 31, 2011.

  1. ferox

    ferox Private E-2

    Two days ago, my main computer ground to a halt - all at once, it's not like it went slowly downhill - constantly whirring as if it were working on something, even if I had no windows open. Google redirects - at least, it did when I could still open an internet browser - and if I have the computer on long enough, I will occasionally get the "warning noise" that occurs when a computer pop up window is displayed, but there is no pop up. :/ When I try to shut down the computer, I get a ton of "not responding/end now" messages, if it goes through shut down procedures at all; sometimes it won't.

    I've gone through the read me thread, as well as the read & run. Here are four of the five logs; RootIt was the only one that refused to come up at all, hanging on the Initializing window.

    (You'll see that simple quick scans took HOURS, though, when in the past it's only taken them about ten minutes.)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you using for AV protection?

    Please put ComboFix directly on your desktop, not here:
    Running from: L:\ComboFix.exe

    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\HP_Owner\Local Settings\Application Data\32o40833yulh26ah0x8as26054g65rar3sfgns0ydi57
    C:\Documents and Settings\All Users\Application Data\32o40833yulh26ah0x8as26054g65rar3sfgns0ydi57
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. ferox

    ferox Private E-2

    Nada; was keeping them off to speed up computer, ironic. Will be going through the "how to keep malware" thread after this clears up. *wryyyy*

    Still getting the Google redirect and a lot of whirring...

    edit: in fact, hitting "post" just caused a window pop-up...
     

    Attached Files:

    Last edited: Aug 31, 2011
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the below link and follow the instructions for running TDSSKiller from Kaspersky

    Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  5. ferox

    ferox Private E-2

    Oh! I may be wrong, but Google doesn't seem to be redirecting... hooray!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you have your XP disc, boot to the bios and change the boot order to CD/DVD as first boot device. Put in the disc and reboot. Go into the Recovery Console and once there, type:
    fixmbr

    Exit out and reboot to normal mode. Re-run MBRCheck and attach the new log.

    If you don't have your CD, you can create one here:
    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.

    You can use ImageBurn to create the disc.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds