Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Re: Potential Malware Virus Problem  (Read 9683 times)

0 Members and 1 Guest are viewing this topic.

jackhmom

    Topic Starter


    Rookie

    Re: Potential Malware Virus Problem
    « on: March 02, 2010, 07:58:59 PM »
    We're having the same problem -- computer still freezes up after the internet has been on for awhile.  It looks like there may still be a virus or malware.  Do I start a new thread or need to post new logs?  Any recommendations for other tools we can try?

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Potential Malware Virus Problem
    « Reply #1 on: March 03, 2010, 11:35:08 AM »
    Hello jackhmom and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    The first thing I will need you to do is to go to this link and follow the directions precisely. If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. If you can't run any step, just jump to the next one. Please let me know how you are doing or have any questions. Initially, I will need the SuperAntiSpyware, MBAM and HJT logs. Please post any logs that you can generate.
    Windows 8 and Windows 10 dual boot with two SSD's

    jackhmom

      Topic Starter


      Rookie

      Re: Potential Malware Virus Problem
      « Reply #2 on: March 06, 2010, 09:26:03 AM »
      Here are the 3 logs.

      [Saving space, attachment deleted by admin]

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Potential Malware Virus Problem
      « Reply #3 on: March 06, 2010, 01:31:13 PM »
      Other than the freezing, does the computer run well? HJT is not designed for Windows 7 therefore, it doesn't give true information. Let's try this tool.

      Download random's system information tool (RSIT) by random/random from here and save it to your Desktop.

      •Double click on RSIT.exe to run.(Vista users: right-click and run as Administrator

      •Click Continue at the disclaimer screen.

      •Once it has finished, two logs will open.
      log.txt <will be maximized and info.txt <will be minimized

      •Please post the contents of both logs in the next reply.
      Windows 8 and Windows 10 dual boot with two SSD's

      jackhmom

        Topic Starter


        Rookie

        Re: Potential Malware Virus Problem
        « Reply #4 on: March 24, 2010, 12:48:15 AM »
        We just have the freezing problem (with various programs even when Internet Explorer isn't open).  Here are the two logs you requested.

        [Saving space, attachment deleted by admin]

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Potential Malware Virus Problem
        « Reply #5 on: March 24, 2010, 01:08:26 PM »
        Quote
        We just have the freezing problem (with various programs even when Internet Explorer isn't open). 
        What happens when it freezes? Do you have to reboot?

        Download Security Check by screen317 from one of the following links and save it to your desktop.

        Link 1
        Link 2

        * Unzip SecurityCheck.zip and a folder named Security Check should appear.
        * Open the Security Check folder and double-click Security Check.bat
        * Follow the on-screen instructions inside of the black box.
        * A Notepad document should open automatically called checkup.txt
        * Post the contents of that document in your next reply.

        Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
        ============================
        Open HijackThis and select Do a system scan only

        Place a check mark next to the following entries: (if there)

        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        Important: Close all open windows except for HijackThis and then click Fix checked.

        Once completed, exit HijackThis.

        I found your original thread and again we can't find anything that would indicate why your computer is freezing. I'm going to have a consult with others and I'll get back to you.
        Windows 8 and Windows 10 dual boot with two SSD's

        jackhmom

          Topic Starter


          Rookie

          Re: Potential Malware Virus Problem
          « Reply #6 on: March 31, 2010, 08:58:26 PM »
          Yes, we have to reboot when it freezes.  Here are the results of the scan.  Thanks for the help!

          Results of screen317's Security Check version 0.99.2 
           Windows Vista  (UAC is enabled)
           Out of date service pack!!
          ``````````````````````````````
          Antivirus/Firewall Check:

           Windows Firewall Disabled! 
           ESET Online Scanner v3   
           Norton Internet Security   
           WMI entry may not exist for antivirus; attempting automatic update.
          ```````````````````````````````
          Anti-malware/Other Utilities Check:

           Malwarebytes' Anti-Malware   
           HijackThis 2.0.2   
           CCleaner     
           Java(TM) 6 Update 18 
           Java(TM) 6 Update 5 
           Out of date Java installed!
           Adobe Flash Player 10 
          Adobe Reader 9.2
          Chinese Traditional Fonts Support For Adobe Reader 9
          ````````````````````````````````
          Process Check: 
          objlist.exe by Laurent

           Norton ccSvcHst.exe
          ````````````````````````````````
          DNS Vulnerability Check:

           GREAT! (Not vulnerable to DNS cache poisoning)

          ``````````End of Log````````````

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Potential Malware Virus Problem
          « Reply #7 on: April 01, 2010, 12:30:31 PM »
          You do not have the latest up-dates for Vista (SP2) Please go to the MS website and download this important up-date

          Update Your Java (JRE)

          Old versions of Java have vulnerabilities that malware can use to infect your system.


          First Verify your Java Version

          If there are any other version(s) installed then update now.

          Get the new version (if needed)

          If your version is out of date install the newest version of the Sun Java Runtime Environment.

          Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

          Be sure to close ALL open web browsers before starting the installation.

          Remove any old versions

          1. Download JavaRa and unzip the file to your Desktop.
          2. Open JavaRA.exe and choose Remove Older Versions
          3. Once complete exit JavaRA.
          4. Run CCleaner.

          Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.

          I'm still checking as to why your computer keeps freezing.
          Windows 8 and Windows 10 dual boot with two SSD's

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Potential Malware Virus Problem
          « Reply #8 on: April 04, 2010, 12:43:13 PM »
          It's been almost a month since we started this cleaning process. We need to update and run some more scans.

          SUPERAntiSpyware

          If you already have SUPERAntiSpyware be sure to uninstall it and get the newest version!


          Download SuperAntispyware Free Edition (SAS)
          * Double-click the icon on your desktop to run the installer.
          * When asked to Update the program definitions, click Yes
          * If you encounter any problems while downloading the updates, manually download and unzip them from here
          * Next click the Preferences button.

          •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
          * Click the Scanning Control tab.
          * Under Scanner Options make sure only the following are checked:

          •Close browsers before scanning
          •Scan for tracking cookies
          •Terminate memory threats before quarantining
          Please leave the others unchecked

          •Click the Close button to leave the control center screen.

          * On the main screen click Scan your computer
          * On the left check the box for the drive you are scanning.
          * On the right choose Perform Complete Scan
          * Click Next to start the scan. Please be patient while it scans your computer.
          * After the scan is complete a summary box will appear. Click OK
          * Make sure everything in the white box has a check next to it, then click Next
          * It will quarantine what it found and if it asks if you want to reboot, click Yes

          •To retrieve the removal information please do the following:
          •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
          •Click Preferences. Click the Statistics/Logs tab.

          •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

          •It will open in your default text editor (preferably Notepad).
          •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

          * Save the log somewhere you can easily find it. (normally the desktop)
          * Click close and close again to exit the program.
          *Copy and Paste the log in your post
          =============================
          Please uninstall your version of MBAM and download and update the newest version.

          Please download Malwarebytes Anti-Malware from here.

          Double Click mbam-setup.exe to install the application.
          • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
          • If an update is found, it will download and install the latest version.
          • Once the program has loaded, select "Perform Full Scan", then click Scan.
          • The scan may take some time to finish,so please be patient.
          • When the scan is complete, click OK, then Show Results to view the results.
          • Make sure that everything is checked, and click Remove Selected.
          • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
          • Please save the log to a location you will remember.
          • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
          • Copy and paste the entire report in your next reply.
          Extra Note:

          If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
          ===============================
          Download OTM by OldTimer to your desktop.

          Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator.

          * Save it to your Desktop.
          * Double-click OTM.exe to run it.
          * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

          Code: [Select]
          :Processes
          explorer.exe

          :reg
          [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{456cb445-3046-11df-b8c6-00226865bee9}]

          :Commands
          [purity]
          [emptytemp]
          [start explorer]
          [Reboot]

          * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
          * Click the red Moveit! button.
          * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
          Close OTM

          Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

          ===============================

          Please download RootRepeal from GooglePages.com.
          • Extract the program file to your Desktop.
          • Run the program RootRepeal.exe and go to the Report tab and click on the Scan button.


          • Select ALL of the checkboxes and then click OK and it will start scanning your system.

          • If you have multiple drives you only need to check the C: drive or the one Windows is installed on.
          • When done, click on Save Report
          • Save it to the Desktop.
          • Please copy/paste the contents of the report in your next reply.
          Please remove any e-mail address in the RootRepeal report (if present).

          =================================
          ESET Online Scan

          Scan your computer with the ESET FREE Online Virus Scan

          * Click the ESET Online Scanner button.

          * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
          * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
          * Double click on the esetsmartinstaller_enu.exe icon on your desktop.
          * Place a check mark next to YES, I accept the Terms of Use.

          * Click the Start button.
          * Accept any security warnings from your browser.
          * Leave the check mark next to Remove found threats and place a check next to Scan archives.
          * Click the Start button.
          * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
          * When the scan completes, click List of found threats.
          * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
          * Click the Back button then click Finish.

          In your next reply please include the ESET Online Scan Log
          ==============================
          Your flashdrive may be infected also, so please do this.

          Panda USB and AutoRun Vaccine

          Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

          Download Panda USB and AutoRun Vaccine and save it to your desktop.

          * Extract (unzip) the file to your desktop and a folder named USBVaccine will be created.
          * Open that folder and double-click on USBVaccine.exe to start the program.
          * Click Run
          * Click the button to Vaccinate computer.
          * Insert your USB flash drive.
          * When the name of the drive appears in the dialog box, click the button to Vaccinate USB drive(s).
          * Exit Panda USB and AutoRun Vaccine when done.

          Note: Computer AutoRun Vaccination will prevent any AutoRun file from running, regardless of whether the removable device is infected or not. USB Vaccination disables the autorun file so it cannot be read, modified or replaced by malicious code. The Panda Resarch Blog advises that once USB drives have been vaccinated, they cannot be reversed except with a format. If you do this, be sure to back up your data files first or they will be lost during the formatting process.

          ===================================================
          Windows 8 and Windows 10 dual boot with two SSD's