Weird Issues with PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by RichardH, May 26, 2011.

  1. RichardH

    RichardH Private E-2

    Hi
    I have been experiencing some weird issues with my PC recently:
    1. The desktop freezes (stopping & restarting explorer.exe seems to work)
    2. I have been unable to launch programs (they appear in Task Manager as processes but don't launch)
    3. Google Chrome freezes and is intermittent
    4. Unable to Shutdown (says installing update 1 of 1 but never completes) so have to turn off manually

    I did install TuneUp Utilities 2011 which may have had something to do with the errors, I have since uninstalled it fully.
    I have undertaken virus and malware scans and found nothing.

    I've now followed the Malware Removal Guide and the logs are (hopefully) below.
    The only program I was unable to run was RootRepeal.exe - missing drivers.?

    I'd be grateful if someone could have a peek at the files and let me know if there's anything suspicious - or give me pointers to resolving my problems.

    System Details
    • BIOS: Phoenix Tech ASUS P5N-E SLI Rev 0703
    • OS: Windows 7 Ultimate 6.01.7600 x86
    • Processor: Intel Core2 Quad CPU Q6600 @ 2.40GHz
    • Graphics: Dual NVIDIA GeForce 8500 GT (1.7 GHz, 1GB DDR2) x2
    • Memory: 3.25GB (8GB installed)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system, but please tell me what these are:
    C:\1ee4062479d07ad93037882fe2ecbe
    C:\5c30f264da3b5ad9a7a683bd2e
    C:\5c6a8591068139eba33d8e7506
    C:\74f281cb1ec86fcddc05951305
    C:\91716932e18f77640d19
    C:\1ee4062479d07ad93037882fe2ecbe
    C:\5c30f264da3b5ad9a7a683bd2e
    C:\5c6a8591068139eba33d8e7506
    C:\74f281cb1ec86fcddc05951305
    C:\91716932e18f77640d19
    C:\e390ffa854d45ff606c6dc90

    Right click and check properties.
     
  3. RichardH

    RichardH Private E-2

    Hi
    Thanks for the rapid reply...

    The contents of one of the files are as follow:
    $shtdwn$.reg
    1.105.124.0_to_1.105.365.0_mpasdlta.vdm._p
    MpMiniSigStub.exe

    The rest are all similar variations of that.

    The creation date for those files is 26/05/2011 - could they have something to do with the MGtools.exe that I ran today from C:?

    ALSO: there are only 6 of those folders left there now, not the 11 you posted?
     
    Last edited: May 26, 2011
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Some of them got reported twice. I am not finding any malware. I suggest you post in the software forum for additional assistance.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  5. RichardH

    RichardH Private E-2

    Ok thank you... can I remove those files you quoted from C:?

    I've removed all the software as per your post.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you should be able to remove them.
     
  7. RichardH

    RichardH Private E-2

    Thanks Tim, you can mark this as resolved if you want - I've started a thread on the software forum as you suggested :)
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing. :)
     
  9. RichardH

    RichardH Private E-2

    Hi
    Just an update on this:

    I have an icon appearing on the desktop every now and again called "BestCodecsPackSetup". I didn't download anything or choose this software, it just randomly popped up.

    Checking the Properties -Signature list its by "YellowSoft Inc".
    The general security setting state that "This file came from another computer and might be blocked to help protect this computer".

    Obviously I am not going to run this software, but I'd like to know what on my PC is getting it!

    My PC is still very slow to startup as before.

    Any help would be appreciated.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run RogueKiller and then download the latest version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one. Run the exe and attach the new C:\MGLogs.zip.
     
  11. RichardH

    RichardH Private E-2

    Hi
    Re-ran RogueKiller and that came back clear.
    Re-ran MGTools and have attached the zip file here for you.

    Regarding the startup issues I had before that appears to have been resolved by disabling PreFetch.

    It's now this icon that appears on the desktop that concerns me!
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding it in any of your logs. However, you really need to clean up your desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    You also need to run CCLeaner to clean out your temp folders.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds