Win XP, issues and more

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ElCaminoGirl, Mar 3, 2011.

  1. ElCaminoGirl

    ElCaminoGirl Private E-2

    First I need to say this is not my computer and I didn't do it... That being said,

    I do home health care and one of my clients has a comp that is all gummed up and messed up. The first thing I noticed was she has tons of different search bar add ons, which of course is the first thing I know that needs to be removed and am currently in the process of doing.

    Next, it's very slow to load, if it loads at all, the browsers (IE7, FF and Chrome) won't always connect to the internet even when it shows a good connection, when it does go online, you have to highlight the URL and click enter to go anywhere or you get a "this page cannot be displayed error and many more things.

    I read the post with the first steps to do and DL'd everything but MGTools and SAS. That was because it would not, for anything, go to either site or anywhere else to get them.

    With that, here's what I've done so far: I have run CCleaner in reg mode and safe mode, I have run Mbam and SSD in both reg and safe mode. Both popped 67+ hits, I then re-ran CCleaner. Still having the same issues and now the comp will only boot into safe mode all the way. I also went into processes and turned off any and all toolbars that were still showing active and this still didn't speed up the load time (5+ min).

    She has W7 to load onto the computer, but it won't load because it says there isn't enough room, on a 1TB drive... Go figure...

    So I need help fixing this thing as this is, for the most part, her main connection to the world.

    Help me please,

    ECG
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try downloading MGtools here. If you can't run it from the root drive ( typically the C: drive) you can try running it from the desktop.

    You can download combofix.exe and download it to the desktop. If you can't download on that computer, use a different computer and transfer via cd or thumb drive.
     
  3. ElCaminoGirl

    ElCaminoGirl Private E-2

    Can you do the same with MGTools? If you can, then I could pull it onto her computer that way too.

    Oh and I was able to get ComboFix on there, just not the MGTools and SuperAntiSpyware.


    Thanks,
    ECG
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, of course. You can use a cd or thumb to transfer the two files. ;)
     
  5. ElCaminoGirl

    ElCaminoGirl Private E-2

    I promise I'm not trying to bump this, I just wanted to ask to not close this due to no response or anything. I only have 3 hours a day to work in this particular computer and am trying to get through the steps as quickly as possible.


    Thank you!!
    ECG
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Take your time. It's more important that you complete the process than post without the logs. I will be here when you are ready. ;)
     
  7. ElCaminoGirl

    ElCaminoGirl Private E-2

    Okay, so far I have only been able to run SAS and MBAM. ComboFix is prompting me to remove AVG, which I have attempted multiple times to no avail. I googled "Unable to uninstall AVG" and found a removal tool, but it still will not uninstall. I also went into registry via regedit and deleted all AVG files and still no luck. I can't run CF without it gone. I will attach the 2 logs I have so far and will be back tomorrow for my 3 hour session:wave


    ECG
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you removed registry items for AVG, it is probably broken now. See if you can't run this removal tool:

    AVG Removal Tool.
     
  9. ElCaminoGirl

    ElCaminoGirl Private E-2

    WooooHoooo!! Finally got AVG off the books~~:celebrate

    Okay so now for my CF, RR and MGT logs (possibly not in that order, but not a problem)


    I will be back in the morning for another session.

    Actually I was going to try to do remote access, but for what ever reason it wouldn't set up for us.

    ECG


    Oh and just for a heads up, future reference type of thing, I had to go in and "take control" of the HKEY windows folder to finish the removal of AVG 9.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have an awful lot of toolbars installed. But if they are not causing any conflicts you can leave them.

    Please make sure your computer is in normal startup mode through msconfig.

    Also, you need to slide ComboFix off your C: drive and drop it directly on your desktop.

    You will need to install an AV program once we are finished.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now, if you have moved Combo to your desktop:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    Viewpoint Manager Service
    rfjbvzey
    
    File::
    c:\windows\system32\drivers\rfjbvzey.sys
    AtJob::
    
    Folder::
    C:\Program Files\Common Files\PARETOLOGIC
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "AVGIDSAgent"=-
    "avgfws9"=-
    "avg9wd"=-
    "avg9emc"=-
    "AVG Security Toolbar Service"=-
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0cda128-b425-4eef-a174-61a11ac5dbf8}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  11. ElCaminoGirl

    ElCaminoGirl Private E-2

    Okay, lets see, it appears that everything is running smoothly. Since this is my patients computer, I'll have to check with her in the morning to see what she says. I did explain to her the "hazards" of all of the toolbars (so we'll see there). Unfortunately, she is legally blind and doesn't see the small print when installing programs (like the tons of them she has).

    The one thing I do see (or I should say hear) is that pesky background clicking. If I remember correctly that was an ongoing problem with XP, but not sure. Is there a way to stop that? Short of that, we did fix the URL in the address box issue (right off the bat), it does seem to be loading quicker and doesn't seem to need to be rebooted every time you turn around. Like I said though, I'll have to check with her after she uses it.

    Anyhow here are the new logs as requested:


    Thank you,
    ECG
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What background clicking? Is it coming from the hard drive? If it is, that could be indicative that the drive is beginning to fail. If that is the case, you need to backup her important data and files and prepare yourself to replace the hard drive. :(

    As for her difficulty in seeing, you are aware that you can hold the control key and tap the + or - keys to enlarge the print in any window?

    I am not seeing any other issues in your logs. You do need to install an AV program now!!

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  13. ElCaminoGirl

    ElCaminoGirl Private E-2

    The clicking is just a pesky noise that seems to be from a program or something. It's not a clicking from the hard drive. I had it once on an old computer w/ XP and since having Vista on one and 7 on my other I haven't heard it. Like I said I think it was something that was only with XP. Actually I did a search and found out how to turn it off. It's the sound that is made when you select a link or a folder.

    I asked my client this morning how things were running, she was up all night "fixing" what I cleaned out :cry She said everything is great and all she wants me to do now is pull down the tower and clean out the case... WHEW! Oh, and fix it so when it reboots she doesn't have to go through the log in screen. Any quick tips? It's been a while, I've forgotten XP.


    Anyhow you have been a GREAT help and short of putting a stick of dynamite in it and saying oops, I don't know what I would have done.


    Thanks Again
    ECG:wave
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. If she wants to bypass the log in screen, you only need to remove the user password in User Accounts in the control panel. However, if others have access to this computer, I wouldn't recommend doing that. Her user account should ideally be password protected in both normal mode and safe mode. However, without a password, you will probably be seeing her again. :-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds