BleepingComputer.com: Virus, Trojan, Spyware?

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 9 Pages +
  • 1
  • 2
  • 3
  • 4
  • 5
  • Last »
  • You cannot start a new topic
  • This topic is locked

Virus, Trojan, Spyware? Windows Vista SLow and C drive missing

#31 User is offline   sweb 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 120
  • Joined: 18-March 09

Posted 14 August 2011 - 07:38 PM

HERE IS THE LOG
IT IS STILL MOVING SLOW. WHEN IT REBOOTS IT TAKES A WHILE TO STARTUP. THEN WHEN I TRY TO OPEN A BROWSER IT DOESNT OPEN IMMEDIATELY, IT TAKE A MINUTE OR SO BEFORE IT OPENS. ALSO ONCE BROWSER IS OPEN (FIREFOX) IT STILL GIVES THE 'NOT RESPONDING" WHEN I TRY TO CLICK ON A LINK ETC.. IT GOES OPAQUED AND I GET THE LITTLE BLUE CIRCLE AND HAVE TO WAIT FOR IT TO RESPOND

All processes killed
========== OTL ==========
Service Qlpqfsvstasu stopped successfully!
Service Qlpqfsvstasu deleted successfully!
Prefs.js: "Search the web (Babylon)" removed from browser.search.defaultenginename
Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1
Prefs.js: "http://search.babylon.com/?babsrc=toolbar2&q=" removed from keyword.URL
C:\Users\nutmeg\AppData\Roaming\Mozilla\Firefox\Profiles\5bt8igp1.default\extensions\ffxtlbr@babylon.com\defaults\preferences folder moved successfully.
C:\Users\nutmeg\AppData\Roaming\Mozilla\Firefox\Profiles\5bt8igp1.default\extensions\ffxtlbr@babylon.com\defaults folder moved successfully.
C:\Users\nutmeg\AppData\Roaming\Mozilla\Firefox\Profiles\5bt8igp1.default\extensions\ffxtlbr@babylon.com\content\imgs\mnRadio folder moved successfully.
C:\Users\nutmeg\AppData\Roaming\Mozilla\Firefox\Profiles\5bt8igp1.default\extensions\ffxtlbr@babylon.com\content\imgs\flgs folder moved successfully.
C:\Users\nutmeg\AppData\Roaming\Mozilla\Firefox\Profiles\5bt8igp1.default\extensions\ffxtlbr@babylon.com\content\imgs folder moved successfully.
C:\Users\nutmeg\AppData\Roaming\Mozilla\Firefox\Profiles\5bt8igp1.default\extensions\ffxtlbr@babylon.com\content folder moved successfully.
C:\Users\nutmeg\AppData\Roaming\Mozilla\Firefox\Profiles\5bt8igp1.default\extensions\ffxtlbr@babylon.com\components folder moved successfully.
C:\Users\nutmeg\AppData\Roaming\Mozilla\Firefox\Profiles\5bt8igp1.default\extensions\ffxtlbr@babylon.com folder moved successfully.
C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4a99-B4B6-146BF802613B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{98889811-442D-49dd-99D7-DC866BE87DBC} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98889811-442D-49dd-99D7-DC866BE87DBC}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
Folder C:\Program Files\Babylon\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\nutmeg\Desktop\cmd.bat deleted successfully.
C:\Users\nutmeg\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: nutmeg
->Flash cache emptied: 1131 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: nutmeg
->Temp folder emptied: 7778965 bytes
->Temporary Internet Files folder emptied: 508406 bytes
->Java cache emptied: 3013699 bytes
->FireFox cache emptied: 54932618 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 476 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 63.00 mb


OTL by OldTimer - Version 3.2.26.2 log created on 08142011_172350

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

This post has been edited by sweb: 14 August 2011 - 07:50 PM


#32 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 14 August 2011 - 08:34 PM

Hi,

McAffee AntiVirus and Firewall may be incompatible with your system and may be causing the slowdowns.

Please uninstall them completely, use the McAfee removal tool after you remove them from your programs and features


Download Microsoft Security Essentials, install it and run a quick scan.

Let me know if uninstalling McAffee resolves the slowness issue and advise if Microsoft Security essentials finds anything

Download and run the McAfee Removal Tool

Instructions can be found here
http://service.mcafee.com/FAQDocument.aspx?id=TS100507


Microsoft Security Essentials

http://www.microsoft.com/security_essentials/

If removing McAfee makes no difference whatsoever, then please reinstall it.




( are you aware that writing in capitals is a socially unacceptable form in online forums, it is considered rude, if that is the message that you are trying to convey, it is not appreciated, I volunteer my time to help people here and am trying my best to resolve your issues, If I'm not doing very well, then please feel free to take your computer to a shop where they will charge you at least $200.00 to do the same as I'm doing )
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#33 User is offline   sweb 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 120
  • Joined: 18-March 09

Posted 14 August 2011 - 09:08 PM

sorry about the all capitals. it wasn't meant to be rude to you at all, it was just simply my frustration and me yelling at my computer more or less. please do not take it as directed to you at all. you have been great and i do really appreciate your help here, and i'm following all of your instructions the best i can.
re: mcafee. i believe i have always had that installed on this computer. it did just expire yesterday.
if i remove it, then wouldnt i be vulnerable to more viruses?

This post has been edited by sweb: 14 August 2011 - 09:13 PM


#34 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 14 August 2011 - 09:17 PM

I suggested installing an alternative product - Microsoft security Essentials, it's excellent and free

I really believe right now, that your remaining issues could be due to incompatibility with McAffee, so it's worth exploring. If it turns out that is not the cause, then we'll move on.

and I do understand your frustration, computers can be such a pain, but it's like trying to find a needle in a haystack sometimes when trying to pinpoint the cause of some of these issues.

Let me know how you get on with Microsoft Security Essentials
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#35 User is offline   sweb 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 120
  • Joined: 18-March 09

Posted 14 August 2011 - 09:58 PM

Ok I see. will do that next and I will let you know.

#36 User is offline   sweb 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 120
  • Joined: 18-March 09

Posted 14 August 2011 - 11:22 PM

Ok I uninstalled Mcafee. then I installed the Microsoft Security Essentials, it asked me to reboot so I did.
upon rebooting i received a popup saying Windows Explorer has stopped working, then a popup appeared that said Windows is checking for a solution, then it said Windows is restarting , but it wont start up fully
it just keeps repeating those over and over and over. what do i do now? it wont startup. did I do something wrong?

This post has been edited by sweb: 14 August 2011 - 11:48 PM


#37 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 15 August 2011 - 07:53 AM

Hi

Please try the following:

Verify that you can access the Recovery Environment

To do so, restart your computer and begin tapping the F8 key to enable the Advanced Start menu.

If the option Repair your computer is available, select it.

Select a language, a keyboard or an input method, and then click Next

It will ask for a password > if you have one > enter it now, or just hit OK if you don't have one.

(If Recovery Environment is not preinstalled, you will need to insert your installation DVD and restart, then press any key when prompted to boot from the CD.

At the Install Windows screen, select Repair your computer
)


In the System Recovery Options dialog box, click Command Prompt

Type bootrec /fixmbr and then press ENTER

You should see "The operation completed successfully"

Type EXIT at the command prompt, then select the RESTART button to reboot your system normally.
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#38 User is offline   sweb 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 120
  • Joined: 18-March 09

Posted 15 August 2011 - 10:36 AM

I was able to get to the Advanced Start menu however and selected "Repair your computer" and hit Enter. It then gave me a window for how to startup, normal etc.. However I did not see the System Recovery Options dialog box, and so it restarted and is doing the same thing again as mentioned above. I get the popup saying Windows Explorer has stopped working, then a popup appears stating Windows is checking for a solution, then Windows is restarting , but it wont start up fully
it just keeps repeating those over and over and over
Did I miss a step?

This post has been edited by sweb: 15 August 2011 - 10:39 AM


#39 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 15 August 2011 - 10:48 AM

It doesn't sound as though the Recovery Environment is preinstalled on your computer if you didn't get the screen pop-up where it asks you to select a language etc.

so you will need to insert your installation CD and access the Recovery Environment from the CD

then follow the bootrec /fixmbr instructions
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#40 User is offline   sweb 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 120
  • Joined: 18-March 09

Posted 15 August 2011 - 04:01 PM

what if i dont have that CD?

#41 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 15 August 2011 - 04:18 PM

do you know anyone that does have one you could borrow? You just need it to access the Recovery Environment
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#42 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 15 August 2011 - 04:20 PM

What happens if you tap F8 on start-up can you reach the safe mode option screen?

If you can > arrow up to "Last Known Good Configuration" and hit enter,

see if your computer will boot now.
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

#43 User is offline   sweb 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 120
  • Joined: 18-March 09

Posted 15 August 2011 - 04:34 PM

ok i found a reinstallation dvd. but when i reboot and hit F8, i dont see an option to boot from it
??

#44 User is offline   sweb 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 120
  • Joined: 18-March 09

Posted 15 August 2011 - 04:38 PM

View PostCatByte, on 15 August 2011 - 04:20 PM, said:

What happens if you tap F8 on start-up can you reach the safe mode option screen?

If you can > arrow up to "Last Known Good Configuration" and hit enter,

see if your computer will boot now.

Yes I do see a "Last Known Good Configuration". trying that now
Ok that did not eork either. same issue

This post has been edited by sweb: 15 August 2011 - 04:40 PM


#45 User is offline   CatByte 

  • Bleepin' curls!
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 7,857
  • Joined: 09-November 08
  • Gender:Not Telling
  • Location:Canada

Posted 15 August 2011 - 04:38 PM

Here is a tutorial (F8 is used if the recovery environment is pre installed)

http://www.bleepingcomputer.com/tutorials/command-prompt-in-windows-recovery-environment/
The help you receive here is free. If you wish to show your appreciation, then you may Posted Image
Microsoft MVP - 2010, 2011

Share this topic:


  • 9 Pages +
  • 1
  • 2
  • 3
  • 4
  • 5
  • Last »
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users