Laptop Extremely Slow

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SWario, Jul 22, 2008.

  1. SWario

    SWario Sergeant

    Unlike the last thread I made, this time it's MY laptop that's running slow. Explorer.exe seems to spike CPU usage every five minutes or so. Overall, the system is very laggy. SUPERAntiSpyware took over five hours to run, and SpyBot's scan took at least four hours on a machine that used to do it in under one. I manually updated SUPERAntiSpyware's definitions, though it doesn't seem to realize this. Also, I only deleted the three CoolWedSearch entries in its results. I'm pretty certain that the Final Fantasy XI entry is NOT a trojan, and that made me unsure enough to leave the registry entries alone unless someone here can give me a reason otherwise. SpyBot did not find anything. Malware Bytes did not find anything.

    Norton (despite me disabling it beforehand) interrupted ComboFix's as it was preparing its log, and in doing so, it almost locked up my computer. I had to open Task Manager to End Task Norton's security popups, after which ComboFix completed and closed itself. I glanced at ComboFix's log, and it seems that it found some items worthy of deletion, but I don't know exactly what they were.

    I'm going to be replacing my antivirus and firewall software after this. I'm considering trying out AVG8 (without the link scanner) and Comodo Firewall. If AVG8 disappoints, then I will switch to AntiVir or Avast, but any of those is better than my current solution (NIS 2005).

    Logs are attached.
     

    Attached Files:

  2. SWario

    SWario Sergeant

    Last log attached.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't already, please disable the Guest account in User accounts.

    Now use windows explorer to find and delete:
    C:\WINDOWS\NV23723392.TMP
    C:\DOCUME~1\RYANFO~1\LOCALS~1\Temp\cel90xbe.sys

    This needs to be cleaned up as it is a good place for malware to hide:
    C:\Documents and Settings\Ryan Foster\Desktop\

    Please use add/remove programs to uninstall:
    J2SE Development Kit 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 10"
    Java(TM) SE Development Kit 6"
    Java(TM) SE Runtime Environment 6

    Reboot and install:
    Java Runtime 6

    Now tell me what issues you still have.
     
  4. SWario

    SWario Sergeant

    Neither of those files were there when I browsed to their locations.

    I feel that my desktop icons are organized enough that I would notice something being added, though I will clean it up a bit after this is over.

    I had kept JDK 5.0 around because my university had their feet stuck in the mud about whether or not to upgrade to 6.0 until just recently. I hadn't gotten around to removing it. I am removing it now, but I will stick with the stable 6.0u7 instead of the beta update 10.

    Also, on closer examination, it appears to be Msmsgs.exe that spikes in CPU usage every minute or so, not explorer.exe.

    I've just finished removing the old Java installations and installing the new one. I haven't used the computer enough to make any assertions about whether or not it has improved.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run thisDisable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    You did not show any malware ......please let me know it you do have some issues.

    In the meantime.......If you are not having any other malware problems, it is time to do our final steps:

    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\combo-fix" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.

    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:

    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  6. SWario

    SWario Sergeant

    Removed Windows Messenger. The system seems to be running better, but still a little sluggish at times. I left SUPERAntiSpyware installed for now, but disabled its "startup with Windows" option. I removed ComboFix - it also seems to have generated a "Bug.txt" file on the C Drive which was not previously mentioned. I deleted the MGTools files and folders. I will uninstall HijackThis later (I simply forgot to since I have been moving locations all day). I toggled System Restore (disable, reboot, enable) and I created a new restore point.

    Currently, I am running the Norton Removal Tool to remove Norton Internet Security 2005. After reading up more about AVG8's detection of SpyBot's and SpywareBlaster's protections as malware, I've become less confident in choosing it, but I'm not sure what to choose over it. I saw chaslang mention once that Avast detects more false positives than AVG7.5, so that didn't help convince me that Avast would be the route to go. I don't usually hear much about AntiVir, but I'm not sure if that's a good thing or a bad thing. AV-Comparatives judged AntiVir's premium version to be on par with their previous "best", Eset's NOD32, but that doesn't tell me how their free version holds up. Comodo AntiVirus is still in beta. I think, if I recall correctly, you prefer Avast. Do you have any opinions regarding any of the other free AntiVirus software that I have mentioned?

    I will be sticking with Comodo v3 for my firewall for now, since it currently outranks Online Armor on Matousec's Firewall Challenge.
     
  7. SWario

    SWario Sergeant

    Since I cannot edit the previous post, I must make a new reply! This is an update to my earlier musings on antivirus software.

    I have done some searching on currently available free antivirus solutions. It appears to me that AVG8, coming from a line of reliable scanners, has unfortunately become rather bloated as of late. While it is possible to remove or disable some of its bloatware features (Link Scanner, Safe Surf, Safe Search), it now detects many protections by other anti-malware products as dangerous items.

    Avast seems to have its own issues with false positives, but they aren't anywhere like what AVG is doing. I haven't heard anything particularly horrible about Avast. However, I have read that AntiVir generally does a better job at detecting viruses, in less time, with less false positives than Avast. Unfortunately, AntiVir's free edition does not offer e-mail scanning, but I do not recall Norton ever catching a virus in the 6 years that I have been using it, so I think that as long as I pay attention to what I'm opening, then I should be able to live without this feature. If I find AntiVir to my disliking, then I can always uninstall and switch to Avast or something else later. For now, it's definitely better than no antivirus.

    Interestingly, I've also read that Norton AntiVirus has astonishingly high detection rates. It's a shame that it's so bloated. Any opinions on Symantec AntiVirus Corporate Edition 10.1.7? My university provides it to us for free, so perhaps it is something to consider if I don't like AntiVir.

    Some links to information that I found helpful are below for the benefit of others.


    Discussion on how to leave Link Scanner out of AVG8's install and disable the "upgrade to pro" nag screens:
    http://www.neowin.net/forum/index.php?showtopic=634374&pid=589374906&st=0&#entry589374906
    (included in discussion is the following link to AVG's official instructions on "How to install AVG without LinkScanner"):
    http://free.grisoft.com/ww.faq.num-1338#faq_1338

    More forum discussion on AVG8:
    http://www.wilderssecurity.com/showthread.php?t=212306

    List of AntiVirus software on Wikipedia:
    http://en.wikipedia.org/wiki/List_of_antivirus_software

    Lightspeed Systems' AV comparison:
    http://www.lightspeedsystems.com/Compare/AntivirusComparison.aspx

    Mega Antivirus Test (old, but insightful):
    http://www.overclockers.com/articles1260/

    Anti-Virus Comparison 2008:
    http://boards.msn.com/Techboards/thread.aspx?threadid=716513

    AntiVirus Comparison - CastleCopsWiki:
    http://wiki.castlecops.com/AntiVirus_Comparison

    I also referred to the user ratings for AVG, Avast, and AntiVir here on MajorGeeks.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In my opinion, it is a crap shoot. No program is going to provide you with much more protection than any other well rated program. It is functions of how fast they keep up with new viruses, how well it/you do updates, what kind of internet surfing you do, etc. That is why we give you the guide for keeping yourself safe.

    As to an anti-virus choice, it's kind of an individual decision. Which again relates to the above as well as how it works on your setup. You mention Norton.....I feel ( as I haven't actually counter) that more of the systems I help clean are running it. We also see systems protected with Avast, AVG, etc. I certainly would not pay for any of the programs.

    And then there are a few here that pride themselves on never being infected.....because of their computer usage, not because of any particular protection software.
     
  9. SWario

    SWario Sergeant

    It's a shame that adding a new post to provide an information update bumps my thread down in the queue. Alas, c'est la vie.

    I installed Comodo Firewall with Defense+ and Avira AntiVir. I manually updated Avast, and ran a complete system scan which took about 5 hours to scan 600,000+ files. It detected five infected files, all of which were successfully quarantined. Afterward, I hooked it up to the Internet for a test run, hoping that everything was gravy. I was so very wrong.

    My system has slowed to a crawl. It takes at least 15 seconds for any mouse click to register, and that is after the 10+ seconds it takes for my system to acknowledge that the mouse has, indeed, moved. I tried disabling Defense+ and AntiVir's "Guard", but neither action helped my system recover.

    I've shut the laptop down currently to give it a rest, and hope that a full restart will help things. I'm not sure if this huge slowdown is Comodo's fault, or AntiVir's, or something else, or a some unforeseen combination, but it's rottenly unfair. *grumble* I have to attend class now, or I would continue trying to see if this reboot will help. I will be able to continue this sometime after 2:00PM.

    Tim, I hope that you have some magical words of wisdom for me, because I could really use some good news. :cry


    ** EDIT **
    Tim, I just saw your previous post. I hope that you can get to this new one of mine soon. As for the not getting infected and such, I have a pretty good track record for avoiding serious infection, and I usually only have to run the whole shebang of scans when something feels seriously wrong with my machine. Most other maintenance I come here for is for other computers that are not my own, and I've had Norton Internet Security 2005 with outdated definitions for about two years now. However, my reason for not updating was that my subscription had ended. I didn't feel like paying to renew, and I never felt like committing the time to uninstalling, researching for a new AV and firewall, installing and updating that, and dealing with all of the system integration again (which apps should it let run whenever, e-mail scans, spam configuration, app/net access, etc. etc. etc.). I just finally figured that it was time, and now I'm honestly a little upset that I bothered, given all the trouble it's giving me. :cry


    ** EDIT 2 **
    I forgot to mention that Task Manager showed nothing suspicious while my computer acted like molasses. Nothing was repeatedly hogging CPU, and my RAM usage was at 399MB/1800MB (I have one gigabyte of physical RAM sticks and the rest is virtual memory). Hence why I cannot figure out exactly what is causing my massive slowdown.
     
    Last edited: Jul 24, 2008
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you telling me that you are now running multiple anti-virus programs? I would suggest that you post in the software section in regard to your slowness after you remove all but one anti-virus program.
     
  11. SWario

    SWario Sergeant

    No, I am not silly enough to run multiple antivirus programs at once. Unless Comodo Firewall's Defense+ feature IS an antivirus software, in which case they should really mention that and call it Comodo Firewall + Antivirus. To be clear, I:
    1. Used the Norton Removal Tool to uninstall Norton Internet Security 2005
    2. Rebooted
    3. Installed Comodo Firewall Pro 3.0.25.378 with Defense+ (sometimes referred to as Comodo Personal Firewall, but the official name is as I have typed; I assumed that Defense+ was just an additional set of firewall functions since it didn't say otherwise)
    4. Installed Avira AntiVir Personal Edition 8.1.0.326 and manually updated with definitions file obtained from MajorGeeks.com
    5. Ran a complete system scan with AntiVir
    6. Quarantined the 5 results that it found

    Everything SEEMED okay, but then when I tried to use the computer it was just completely bogged down, even though Task Manager did not indicate this. In an attempt to alleviate the problem, I then:
    1. Disabled Comodo's Defense+
    2. Deactivated AntiVir's Guard

    However, this did not seem to affect my computer's sluggishness. I shutdown the machine, and I have been out of the building since then, so I have not powered it back on yet. My current solution, unless you provide an alternative one, is to uninstall the either Comodo, AntiVir, or both, and simply leave the machine offline untill I can correctly resolve the problem. Analysis? Advice?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Maybe that was a typo?

    Again, I believe this is not a malware issue and could better be addressed in the software section.
     
  13. SWario

    SWario Sergeant

    Yes, the part with Avast was a typo; I was just extremely tired at the time. I will see if I can get any insight from the Software forum.

    Thanks for all your help!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I more than understand .....nodding off myself sometimes ....LOL

    I'll try to monitor your software post....good luck. :)
     
  15. SWario

    SWario Sergeant

    This may be worth noting, though I don't think it's the sole cause of my problems. My system time is still set at 24-hour time from when I ran ComboFix. This implies that ComboFix did not run, or at least clean up, correctly (it DID have an interruption courtesy of Norton). I don't know if that would have created a problem in other places on my computer, but I wanted to check and see if there was a suggestion for what to do about this. Fixing the system time format is easy, but I was more concerned about making sure that ComboFix didn't leave behind any other loose ends.

    Currently, I'm off to the Hardware forum to ask about determining if overheating is my problem or not. Not my ideal problem to have, but it's progress towards figuring something out, I suppose.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    ComboFix removal is supposed to reset the time format....in some cases, it doesn't, so we reset it manually. It doesn't do anything else that might be related to your problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds