Virus problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by koool71, Feb 16, 2009.

  1. koool71

    koool71 Private E-2

    Yesterday at around 2 P.M - 3 P.M my computer froze up on me while I was playing my game. At first I thought it was lag issues that forced me to shut down my computer manually but then when I started it up again I noticed the startup screen had strange patterns in the backgrond as was moving much much slower. After booting into my desktop (took about 15m total from when i turned on cpu to when i loaded my desktop) i noticed my computer was really moving slow. I pulled up my windows task manager and noticed I have about 50% CPU usage at all times. I've never gone below 50% in the past 24 hours.

    I ran all the steps you have listed in the cleanup topic so I hope that you guys can further help me by looking at my logs.

    Some more things that might help you are I look to see what's taking up the cpu usage and they only 2 things that show up are the System Idle Process and the windows task manager process.

    Hope you guys can help me, thanks in advance.


    -Chris Jordan
     

    Attached Files:

  2. koool71

    koool71 Private E-2

    My last log.
     

    Attached Files:

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gifWelcome! to MajorGeeks.com!http://www.majorgeeks.com/images/grenade.gif


    Pre-Instructions:
    1. First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix.
    2. Print out these instructions or save them to a text file so that you can operate with All Browser Windows CLOSED.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed.


    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.

    Step 3:
    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Step 4:
    Default Security Settings

    To Default Security Settings:
    For Internet Explorer 6 users:
    Click Start > Run > type inetcpl.cpl and press ENTER, when Internet Properties comes up navigate to the Security Tab and click Default Level for the following:
    • Internet
    • Local Intranet
    • Trusted Sites
    • Restricted Sites.
    Click OK to exit.

    For Internet Explorer 7 users:
    Click Start > Run > type inetcpl.cpl and press ENTER, when Internet Properties comes up, navigate to the Security Tab and simply click the "Reset all zones to default level" button. Click OK to exit.

    NOTE: If it's "grey" then it's already at the default level.​
    Step 5:
    Please download ATF-Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: ATF-Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF-Cleaner menu to close the program.​

    Step 6:
    Finally, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  4. koool71

    koool71 Private E-2

    Well here's the bottom line. This has cleaned out a lot and I appreciate the help but I'm afraid I might've wasted your time. Yesterday I discovered my problems could be cause of a device not working properly (code 10), my video card. I'm attempting to fix that now but I've discovered it's most likely not a virus causing this.

    Although this is true I would like to continue the process of cleaning my computer if that's alright with you guys. It's always good to get this crap off every once in a while anyway.

    If you were wondering this hasn't changed the main problem as you might've guessed but I'm sure it's helping my CPU in the long run.

    Thank you for your time and helping me.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there bjgarrick is away at the moment, so i've come to continue to work this thread for you.

    Your logs look clean now but because it has been a while since fresh logs were dropped could you please do the following:

    1) The below software is outdated I would reccommend that you uninstall it and instead use MBAM and SAS which are much more efffective IMO:

    • Ad-Aware SE Personal

    2) Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    3) Run the new MGTools.exe and attach the log it generates ---> (C:\Mglogs.zip)

    Thanks
    Kestrel13!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds