Win32:Trojan-Gen: Deleted (unable move to chest), CPU high, disk space low, slow

To continue the post after I got bored waiting for the forum

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[
]Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

When OTL ran, the disk space was fine, no low disk space. Since I found out I had a virus, the Low Disk Space warning box has appeared 3 times. Also, when looking at the C drive disk space at random times, the space is constantly changing for some odd reason (each time I check). Sometimes it will show half full, near full or or show less than 6mb left on the drive and thats when the warning box appears.

Vents look clear. The fan and high CPU usage problem have been like this since the virus was found.

Another problem I noticed is that Windows updates are failing. The last two updates I tried to install (Definition Updates for Windows Defender) have failed.

Attached is the ComboFix log. One thing I want to mention is that while it was nearing the end process, a warning box appeared, with something along the lines of “cpxxxe.exe(sp??)” caused an error and the program either needed to be troubleshot or closed.

OK lets now check the MBR area

Please download MBRCheck.exe to your desktop.

[]Be sure to disable your security programs
[
]Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
[*]A window similar to this should open on your desktop:

http://i677.photobucket.com/albums/vv132/RPMcMurphy_album_photos/mbrcheck.png

[*]If you are prompted with options, enter N at the prompt and press [i]Enter[/i]
[*]Press [i]Enter[/i] again
[*]A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your deskop. Please post the contents of that file.

MBR log attached. Happy New Year!

All areas look clear now - are you losing drive space still ?

Please download and run Winstatdir

When the little pacmen have finished investigating the drive you will be presented with a visual image of your folders
Select the folder using the most space by clickin the little + sign alongside it
Locate the folder that is using the most space
If there is a + alongside that then click it to dig deeper
Highlight the offending folder and press Ctrl + C this will copy the path to your clipboard
Then right click the folder and select open
This will then open explorer to that folder… Do you recognise it ?

Then open note pad and select paste… Post the file path in your next reply plus the size

C:\Program Files (x86)\Common Files\PC Tools\sMonitor

Folder Size:99GB

Biggest File Size: cputime.xml (94.9GB)

I happened to run this software when the C: drive disk space was low.

N/A

OK that is an apparent problem with registry mechanic - Make sure that you have the latest version of RM 9.0.0.128

Otherwise the recommendation is to uninstall it

http://www.pctools.com/forum/showthread.php?s=ca1e1cad4b1993235209ba351f092115&t=61494&page=2

It looks like that was it. I deleted PC Tool Registry Mechanic and all the files associated with the program. I now have 110 GB of disk space, and CPU usage is down to 1% (idle). Thank you very much for your time and assistance with this problem. I greatly appreciate what youve done in helping me resolve the issue!!!

OK lets clear away my rubbish then

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:Commands [resethosts] [purity] [emptytemp] [EMPTYFLASH] [Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that

[*]Click Start.
[*]Open My Computer.
[*]Select the Tools menu and click Folder Options.
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[
]Click OK.

http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:

[*]Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 23.
[*]Click the “Download” button to the right.
[*]Select your Platform and check the box that says: “I agree to the Java SE Runtime Environment 6 License Agreement.”.
[*]Click on Continue.
[*]Click on the link to download Windows Offline Installation (jre-6u23-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager…
[*]Close any programs you may have running - especially your web browser.
[*]Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
[*]Check any item with Java Runtime Environment (JRE or J2SE) in the name.
[*]Click the Remove or Change/Remove button.
[*]Repeat as many times as necessary to remove each Java version.
[*]Reboot your computer once all Java components are removed.
[*]Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u23-windows-i586-p.exe and select “Run as an Administrator.”)

SPRING CLEAN

To manually create a new Restore Point

[*]Go to Control Panel and select System and Maintenance
[*]Select System
[*]On the left select Advance System Settings and accept the warning if you get one
[*]Select System Protection Tab
[*]Select Create at the bottom
[*]Type in a name i.e. Clean
[*]Select Create

Now we can purge the infected ones

[*]Go back to the System and Maintenance page
[*]Select Performance Information and Tools
[*]On the left select Open Disk Cleanup
[*]Select Files from all users and accept the warning if you get one
[*]In the drop down box select your main drive i.e. C
[*]For a few moments the system will make some calculations
[*]Select the More Options tab
[*]In the System Restore and Shadow Backups select Clean up
[*]Select Delete on the pop up
[]Select OK
[
]Select Delete

Final stretch

Download and run Puran Disc Defragmenter
For the first run I would recommend a boot defrag and disck check

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programme:

http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Malwarebytes. Update and run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
[*]Microsoft Windows Update

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wave: