Slow browsing... is it bloatware or malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by boston_019, Aug 14, 2011.

Thread Status:
Not open for further replies.
  1. boston_019

    boston_019 Private E-2

    Not sure what's going on. Firefox is consuming more CPU than normal, and overall my browsing seems less efficient. I have run Microsoft Security Essentials, MalwareBytes, AdAware and Spybot, which have not remedied the issue. I'm uploading my HijackThis... I hope you guys can make some sense of it.

    I'm running XP (32) on a Toshiba, hence all of the bloatware. I've gotten rid of a bunch, but some of the other stuff seems important, based on what i found on each on Google.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hi and welcome and Major Geeks!

     
  3. boston_019

    boston_019 Private E-2

    I know I'm not supposed to bump, but it's been almost 2 months. Bump.
     
  4. thisisu

    thisisu Malware Consultant

    I am still waiting on your logs.
     
  5. boston_019

    boston_019 Private E-2

    My HijackThis log is in the original post. Super AntiSpyware and MGTools both register as Trojans/viruses with ESET and Panda.
     
  6. thisisu

    thisisu Malware Consultant

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think we both know that those tools are not infected files. ;) Therefore if Panda or ESET is being problematic and not letting you run them then you need to disable it or temporarily uninstall it.
     
  8. boston_019

    boston_019 Private E-2

    Here's my MG Tools log... let me know if formatting is an issue.

    I'm running the SAS scan right now.
     

    Attached Files:

  9. boston_019

    boston_019 Private E-2

    Last edited by a moderator: Nov 8, 2011
  10. thisisu

    thisisu Malware Consultant

    Hi,

    Read this for the instructions on how to attach items to your post: How to attach items to your post

    Attach the following logs whenever you are ready:
    • log from SAS
    • log from MBAM
    • log from ComboFix
    • log from RootRepeal
     
  11. boston_019

    boston_019 Private E-2

    Regarding RootRepeal, it seems like I have a few options of what to scan, based on the tabs at the bottom. Drivers, Files, Processes, SSDT, Stealth Objects, Hidden Services, Shadow SSDT. Which do I scan? I'm running it for Files right now.

    Also, would you prefer that I attach all the logs onto one post?
     
  12. thisisu

    thisisu Malware Consultant

    Files >> Running RootRepeal
    Yes
     
  13. boston_019

    boston_019 Private E-2

    Here you go:
     

    Attached Files:

  14. thisisu

    thisisu Malware Consultant

    I see you are not very keen on following directions... You have to help me help you if you want your PC cleaned. When you decide to ignore simple instructions that are already outlined in the READ and RUN ME First thread, you delay the entire process of getting your system cleaned as it has already been nearly 3 months since you originally posted before you attached some logs I could review.

    First, decide which of the below Antivirus software you want to keep and then uninstall the other one. Then DO NOT install ANYTHING until we are finished with removing malware. I will help you remove the traces of Microsoft Security Essentials and AVG as well.

    Pick one and uninstall the other
    • Ad-Aware
    • Panda Cloud Antivirus

    Secondly, MGtools was NOT supposed to be run from this location
    It was requested that you run this FROM THE ROOT OF YOUR C: Drive (C:\MGtools.exe)

    Third, your computer is NOT in Normal Startup mode which was also requested.
    Follow the directions here and put your system in Normal Startup Mode >> Use MSconfig to setup for Normal Startup Mode

    Once you have rebooted...

    [​IMG] Please download Disable/Remove Windows Messenger by Doug Knox to your desktop.
    • See the download links under this icon: [​IMG]
    • Double-click MessengerDisable.exe
    • Place a check-mark in Uninstall Windows Messenger
    • Click Apply
    • Click Exit

    [​IMG]Please download OTL by Old Timer to your desktop.
    • See the download links under this icon: [​IMG]
    • Double-click OTL.exe to run (Vista and Win7 right click and select Run as administrator)
    • When OTL opens, copy the text in the code box below and paste it into the [​IMG] text-field.
      Code:
      [COLOR="DarkRed"]:services [/COLOR]
      LUVM
      MpKsl223e52b9
      MpKsl2a0093e4
      MpKslb9bdf4b3
      MpKslc7bf93a1
      MpKsld742f5f7
      MpKsleeefb4df
      MpKslfe391501
      [COLOR="DarkRed"]:files[/COLOR]
      C:\Documents and Settings\Christopher\Local Settings\Temp\LUVM.exe
      C:\Documents and Settings\Christopher\Local Settings\Application Data\uhyxeogsf
      c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates
      C:\Documents and Settings\Christopher\Local Settings\Application Data\AVG Security Toolbar
      xcopy %temp%\smtmp\1 "%allusersprofile%\start menu" /s /i /h /y /c
      xcopy %temp%\smtmp\2 "%userprofile%\application data\microsoft\internet explorer\quick launch" /s /i /h /y /c
      xcopy %temp%\smtmp\3 "%appdata%\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar" /s /i /h /y /c
      xcopy %temp%\smtmp\4 "%allusersprofile%\desktop" /s /i /h /y /c
      sc config LUVM start= disabled /c
      [COLOR="DarkRed"]:commands[/COLOR]
      [purity]
      [emptytemp]
      
    • Now click the [​IMG] button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • Click the OK button.
    • When complete, Notepad will open.
    • Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (How to attach items to your post)

    [​IMG] Now run C:\MGtools\GetLogs.bat by double-clicking it (Vista and Win7 right-click and select Run as Administrator)
    Then attach C:\MGlogs.zip to your next message. (How to attach items to your post)
    Note: This will automatically update all the logs inside MGlogs.zip

    LET ME KNOW HOW THE PC IS RUNNING AFTER YOU HAVE COMPLETED THESE STEPS
     
    Last edited: Nov 9, 2011
  15. boston_019

    boston_019 Private E-2

    Ok, thank you, this will probably take me a day or two. bbl.
     
  16. thisisu

    thisisu Malware Consultant

    No problem.
     
  17. boston_019

    boston_019 Private E-2

    So are these directions still current? I was fortunate enough to use a different computer for several months, but I have to use the Toshiba as I'm traveling, and so I need to handle this stat.
     
  18. thisisu

    thisisu Malware Consultant

    No they are not. Chaslang has updated the Read and Run me thread. I would recommend that you go through it from start to finish and post the logs in a new thread.

    I'm closing this one as it is very old.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds