computers running very slow

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hammers_hero, Nov 9, 2011.

  1. hammers_hero

    hammers_hero Private E-2

    hello my names is luke i have been experiencing problems with my pc for the past couple of months i have tried everything to sort the problem but nothing seems to work i have all of the logs u require and if u could have a look i will be very grateful

    thank you
     

    Attached Files:

  2. hammers_hero

    hammers_hero Private E-2

    here is the final log you need

    thank you
     

    Attached Files:

  3. thisisu

    thisisu Malware Consultant

    Hi and welcome to Major Geeks, Luke!

    I am thinking most of your problems are due to old anti-virus software still trying to load and a shortage of memory. Please complete the below and let me know how the system is running afterwards.

    [​IMG] From Add/Remove Programs (via Control Panel), please uninstall the below:
    • Advertising Center
    • Ask Toolbar
    • Java(TM) 6 Update 15

    [​IMG] Now we need to make use of ComboFix by sUBs
    • Make sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop but do not run it!
      • If it is not on your desktop, the below will not work.
    • Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    • Open Notepad and copy/paste the text in the below code box into Notepad:
    Code:
    [COLOR="DarkRed"]KillAll::[/COLOR]
    [COLOR="DarkRed"]ClearJavaCache::[/COLOR]
    [COLOR="DarkRed"]Driver::[/COLOR]
    MpKsl11f4d375
    MpKsl13716b9e
    [COLOR="DarkRed"]File::[/COLOR]
    c:\windows\system32\win32k(2)(2).sys
    c:\windows\system32\wininet(5)(2).dll
    C:\WINDOWS\system32\crypt32(3).dll
    C:\WINDOWS\system32\ieframe(2)(2).dll
    C:\WINDOWS\system32\iertutil(2)(2).dll
    C:\WINDOWS\system32\url(3)(2).dll
    C:\WINDOWS\system32\urlmon(5)(2).dll
    C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
    [COLOR="DarkRed"]Folder::[/COLOR]
    c:\program files\Ask.com
    C:\Documents and Settings\Gary Fyvie\Local Settings\Application Data\AskToolbar
    c:\program files\AVG
    c:\documents and settings\Gary Fyvie\Application Data\AVG10
    c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware
    [COLOR="DarkRed"]Registry::[/COLOR]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
    [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
    [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
    [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "AvgUninstallURL"=-
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{19CBBCEF-B33B-4A26-A458-BBA66229B9CD}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}]
    [COLOR="DarkRed"]SecCenter::[/COLOR]
    FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
    
    • Save the above as CFScript.txt and make sure you save it to the same location (should be on your desktop) as ComboFix.exe
    • At this point, you must exit all browsers now before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your desktop.
    • Now use your mouse to drag CFScript.txt on top of ComboFix.exe.
      [​IMG]
    • This shall launch ComboFix.
      Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
    • Allow ComboFix to update itself if prompted.
    • When it finishes, a log will be produced at C:\ComboFix.txt
      Note: If after running ComboFix you discover none of your programs will open up because you receive the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    • Attach this log to your next message. (How to attach items to your post)

    [​IMG] Now install the current version of Sun Java from: Sun Java Runtime Environment

    [​IMG] Now run C:\MGtools\GetLogs.bat by double-clicking it (Vista and Win7 right-click and select Run as Administrator)
    Then attach C:\MGlogs.zip to your next message. (How to attach items to your post)
    Note: This will automatically update all the logs inside MGlogs.zip

    LET ME KNOW HOW THE PC IS RUNNING AFTER YOU HAVE COMPLETED THESE STEPS
     
  4. hammers_hero

    hammers_hero Private E-2

    the advertising center and ask toolbar was not on the add/remove programs and when i made the cfscript and added it to combofix it didnt produce a log i tried that twice i have attached the mglogs

    thank you
     

    Attached Files:

  5. thisisu

    thisisu Malware Consultant

    Try again. Remember, you have to left mouse click and hold when you are hovering over the CFScript.txt file on your desktop, now drag it into the ComboFix.exe icon (the cat icon).

    Try to follow the following animated pictures:
    [​IMG][​IMG]

    ComboFix should at least launch itself whenever you do this. Click OK at the prompt and basically it acts like it is scanning again (all 50 stages)

    Let me know what happens. If you still have trouble we can 2 other programs to perform the same functions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds