1. maineearle

    maineearle Private E-2

    Need help I think I'm infected. Please see attached logs and seperate post with HJT log

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you should not be starting another thread. You should stay in one thread as instructed in forum rules and guidelines. Also we do not want you to post HijackThis logs. See: Forum Rules and Guidelines

    You need to attach the lock from MGtools that was requested.
     
  3. maineearle

    maineearle Private E-2

    Stand corrected
    Mglogs.txt attached
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do you think this?

    If you are going to say because your PC is slow then we mentioned what I'm going to say in the beginning of the READ & RUN ME. And that is you do not have enough memory to properly run Windows XP. You logs show
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 64.03 MB 
    
    In addition, your Windows boot drive is too small and getting too low on free space:
    Code:
    Size 15.01 GB (16,113,319,936 bytes) 
    Free Space 5.11 GB (5,489,491,968 bytes) 
    This cause issues with disk caching / page files which need lots of space.

    There are a few things we can suggest to help improve things a little but most are not related to malware at all. However I seriously doubt it will improve things as much as you would like. You need to have at least 2 GB of RAM and you should always keep your free space on your Windows boot drive greater than 8 GB to achieve better performance.

    Would you like to try a few things to improve performance ( I'm still assuming this is why you posted )?
     
  5. maineearle

    maineearle Private E-2

    That is the problem.
    I'm willing to try what ever is suggested. This computer is used only by my grandchildren to play online games

    Thanks
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use AOL?

    Uninstall the below:
    Advanced SystemCare 5
    Smart Defrag 2

    Stay away from Regisrty cleaning tools, they can and do frequently cause more harm then good especially when just blindly removing everything they show. Most of what they show are not problems and sometimes are even required entries. For example I saw the below in your logs:
    Wise Registry Cleaner

    And the below too:
    Code:
     
    "C:\WINDOWS\system32\"
    regist~1.exe  Oct 19 2011       20312  "RegistryDefragBootTime.exe"
    
    Uninstall the above if you have an uninstaller for them.

    What is the below that I see running?
    C:\Program Files\AutoInstall\ZD1211B_Auto_Install_CD_Only_Gen_0ACE20FF\AutoEJCD.EXE


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server
    O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
    O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O16 - DPF: {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -

    After clicking Fix, exit HJT.




    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. maineearle

    maineearle Private E-2

    Thanks

    Unistalled Advance System Care 5
    and Smart Defrag 2

    C:\Program Files\AutoInstall\ZD1211B_Auto_Install_CD_Only_Gen_0ACE20FF\AutoEJCD.EXE

    This is part of the Sony Wireless Adaptor Installation also listed in the HJT log. Is this nessary?

    Things seem to be somewhat better but bogs down some in after a couple of minutes. I check on upgrading memory, it will cost around $100.00. I'm not sure I want to spend that much to play online games.

    Thanks again
     

    Attached Files:

    Last edited by a moderator: Dec 10, 2011
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you install more software??????

    You are not supposed to be doing anything except what we ask you to do while working here. You just defeated the whole purpose of my last fix by installing something else that is slowing your PC down. And that is HotSpot Shield which added all of the below services to your PC
    You can uninstall Hotspot Shield and maybe see a little more improvement. And perhaps you can find a couple more startup processes that you don't need to have started with your PC. But you need more memory and more free space on your Windows boot drive to get any further improvement.


    Just to be comprehensive, I want to run two more scans.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  9. maineearle

    maineearle Private E-2

    Here is the latest logs
     

    Attached Files:

    Last edited by a moderator: Dec 10, 2011
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those logs are clean to.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  11. maineearle

    maineearle Private E-2

    Again I thank you. Enjoy your holidays. It's been nice working with you
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely and enjoy your holiday season too. Thanks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds