TechSpot

Viruses suspected

By ozmuse
Mar 23, 2009
  1. Hi - My laptop has been pretty much unusable last few days - extreme slowness, freezing etc.
    I have completed the 8 steps and am attaching my logs here.

    Hoping someone can help me.

    Cheers
    oz
     

    Attached Files:

  2. mflynn

    mflynn TS Rookie Posts: 2,793

    Do this....

    So go here: http://www.adrive.com/public/97c4357781f45c7e443061094b8cfaff3836f57446eb242ab2ee0b6cd68a0107.html

    Download to Desktop then double click it to extract it, then click OK to self extract.

    Once extracted boot to Safe Mode.

    Then dbl click to enter Fixer folder.

    To run it 1st double click Daft, click scan and check any found items and click fix.
    Then just dbl click Fixit.cmd to run it.

    Then boot back to normal mode.

    Then update and run MBAM again Quick scan. It had findings on last run and could find more.

    Once the above is done and log posted do the below..

    Download ComboFix

    Get it here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Or here: http://subs.geekstogo.com/ComboFix.exe

    Double click combofix.exe follow the prompts.

    Install Recovery Console if connected to the Internet!

    When finished, it will open a log.
    Attach the log and a new HJT log in your next reply.

    Note: Do not click combofix's window while its running. That may cause it to stall.

    Mike
     
  3. ozmuse

    ozmuse TS Rookie Topic Starter Posts: 40

    Thanks for that.

    Have followed steps and attached logs.

    MBAM did not find anything this time but during the MBAM scan I kept getting pop up messages fromTrend Micro and Avira re trojans. Wasn't sure what to do so I closed these to allow MBAM scan to continue

    Combo fix and hjt logs also attached

    Thanks
     
  4. mflynn

    mflynn TS Rookie Posts: 2,793

    Great job!

    OK looks good!

    How is computer running now?

    Did you have any problems with Fixit? I recently updated it.

    To be sure lets run one more scan.

    Go here Download DrWeb http://www.techspot.com/vb/post724044-3.html

    Then....

    Boot to Safe Mode only! Not with Networking and run...

    DrWeb will fisrt do an Express Scan on its own when it completes then you should do a full scan.

    The first Virus it finds select Cure and it will use this as the default automatically for all the rest. What it can't fix will be Quarantined!

    This will take a while based on CPU and HD speed and size, but is worth it!

    Mike
     
  5. ozmuse

    ozmuse TS Rookie Topic Starter Posts: 40

    Thanks Mike.

    Have run Dr Web. Express scan was clear. Full scan found 42 items.
    Attached is the report from that scan.

    What could be cured was cured but the remainder, I was not sure what to select from options of delete, move or rename - I selected rename.

    My laptop seems to be running better now, but am worried about a couple of things.

    I constantly have this yellow shied which says I have updates - but on shutdown there is no message re updates - is the yellow shield message real?

    My Trend Micro always has a message which says fix now - fix now button does nothing - I have a message which says personal firewall is shut down but I cannot access the personal firewall controls to turn on - it says try restarting - this does not help.
     
  6. mflynn

    mflynn TS Rookie Posts: 2,793

    Ok that is a good report all it found was in the Trend Quarintine and the ComboFix were false positives.

    Two more steps and we should be done.

    Uninstall comboFix
    Start-Run
    type
    combofix /u
    Click OK

    Then redownload ComboFix and after downoaded rename ComboFix.exe to 12cbf34.exe and run that one and post log.

    then a new HJT log last!

    Mike

    PS I just today updated Fixer/Fixit did it run OK? The files and registry etc not found are normal?
     
  7. ozmuse

    ozmuse TS Rookie Topic Starter Posts: 40

    Thanks Mike - have done this.
    Logs attached.

    I am not sure about your question re Fixit? Did you want me to run this again?

    oz
     
  8. mflynn

    mflynn TS Rookie Posts: 2,793

    All I asked is did Fixit run and exit normally?

    You did a great job. All looks well!

    Give me a status report on how all is working, and if we have other issues to address!

    If all is well I will post my closing with more suggestions on how to stay clean.

    Mike
     
  9. ozmuse

    ozmuse TS Rookie Topic Starter Posts: 40

    Hi Mike - thanks for your help so far. Yes Fixit fid run and exit OK as far as I know.

    So while all the scans look OK now I still seem to be having problems though with slowness.
    There is also a problem with my Trend Micro saying personal firewall is tu,rned off - but it will not allow me to turn it on. So I turn on WIndows firewall instead but I think this slows me down?
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.