Split Second Lag/Freeze

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Zeraton, Jul 23, 2010.

  1. Zeraton

    Zeraton Private E-2

    Ok a week or two ago I had this internet explorer virus where my computer WAV sound would constantly be muted and i would hear clicks as if webpages were opening in the backgrounds. I saw many other people had the same problem so I just did what you guys told that person to do. The problem seemed fixed and everything, and it also seemed like my computer was fine for another week or two, and maybe this new problem has nothing to do with it.

    However, I have noticed that my computer is just getting slower. When I open new webpages with firefox it sometimes takes a while and/or it will kind of freeze for a split second and my mouse will disappear or something and the webpage will then load up fine. When I open things like my documents it will show a blank white screen on the folder and then all of a sudden load really fast. I also play a flash game where it's hard to play if you get even a little bit of lag. My FPS seems to be a little bit worse and I get a tiny bit of lag in my movement... I was wondering what is causing this?

    I checked the task manager and it seems like nothing is taking up too much CPU...
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to Major Geeks!

    We need to check for any remaining malware. *Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide

    and then attach the requested logs to your next reply when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    * Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated - our system works the oldest threads FIRST.
     
  3. Zeraton

    Zeraton Private E-2

    Ok well it's still going on and I'm getting this ridiculous lag in the flash game I play... After I click spawn it freezes for a second or two and then I get a speed burst for a few seconds...

    Here are my attachments...

    I also have left the side panel of my computer off for a while, and I notice that sometimes firefox is taking up too much CPU, I was wondering if dust could be part of the problem, but would dust cause that?
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Zeraton

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    *Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    Also note if you have a Dell PC which uses a non-standard MBR ( or another manufacturer's who does similar to Dell) , fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not continue but you risk serious problems leaving this infection in place and thus your only other option would be to try using the Dell Restore Utility to return a factory ship state which will remove everything you additional you have put onto the PC.

    Please also attach the requested
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe. DO NOT attach any logs seen in the MGtools folder.
     
  5. Zeraton

    Zeraton Private E-2

    Done.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Zeraton

    This machine was in terrible shape!


    Why don't I see an anti-virus program installed?

    You need to increase the installed RAM to atleast 1GB for running XP without experiencing system lags.
    Move ComboFix directly to your desktop as instructed - not here:
    c:\documents and settings\Greg J.GREG\My Documents\Downloads\ComboFix.exe

    *Also delete this which is in an improper location:
    C:\Documents and Settings\Greg J.GREG\My Documents\Downloads\MGtools(2).exe

    Question: What can you tell me about this folder?
    C:\Documents and Settings\Greg J.GREG\.narya

    Step 1:
    Please run the AVG Remover(32bit) version from the below link:
    AVG Remover

    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 3:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    DirLook::
    C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
    
    File::
    C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc(3).dll
    
    Folder::
    C:\Program Files\AVG
    C:\Program Files\Internet Explorer\iexplore(2).exe
    C:\$AVG
    
    RegLock::
    [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
    @Denied: (2) (LocalSystem)
    "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
       d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,18,01,09,e3,b3,0e,3d,4f,be,ef,20,\
    "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
       d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,18,01,09,e3,b3,0e,3d,4f,be,ef,20,\
    HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    @DACL=(02 0000)
    "Installed"="1"
    @=""
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    @DACL=(02 0000)
    "Installed"="1"
    "NoChange"="1"
    @=""
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
    @DACL=(02 0000)
    "Installed"="1"
    @=""
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{465E08E7-F005-4389-980F-1D8764B3486C}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Please run the below online scanner and post the results:

    Using ESET's Online Scanner

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please post the ESET scan results and attach the new C:\MGlogs.zip and the sarscan.log files to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
    **NOTE to Zeraton - review my fix before implementing, I've made edits!!
     
    Last edited: Jul 29, 2010
  7. Zeraton

    Zeraton Private E-2

    The narya folder has nothing in it.

    It is weird because I never use to get so much lag in this game, but sometimes when I load a webpage it's like it freezes before it actually starts loading, and in the flash game I just get constantly lag in my frames per second. I don't get it =/

    I have a feeling I'm getting lag in the flash game due to my flash player/browser.

    I use firefox and i've been fooling around so much with different versions of both firefox and adobe flash and I still havn't found the right combination. When I update everything to the most recent, I get this choppy gameplay type of thing ALL the time, even when there aren't any other players around me.

    When I downgraded to flash 10.0 instead of 10.1, I only get lag when there are other players around me but I get absolutely no lag when i'm just by myself in a game.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    **Notes: Using an incomplete malware protection scheme resulting in infections dating back to Jan.'10, using Limewire, downloading hacks(GAIA Hack _v3.2.2), installed RAM inadequate.

    Ignoring our instructions complicates malware detection and can lead to experiencing more problems and having to deal with broken software installs.
    Using Windows Explorer, delete these folders:
    C:\Program Files\Internet Explorer\iexplore(2).exe
    C:\Documents and Settings\Greg J.GREG\.narya

    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    *Otherwise - your logs are clean of malware and it's time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
    Safe surfing! [​IMG]

    Support MajorGeeks!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds