System slowdown-Infected with rootkit/Trojan.FakeAlert?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by michealjohn, Nov 1, 2009.

  1. michealjohn

    michealjohn Private E-2

    Problem:
    ========
    Facing slowness in IE and firefox loading and system slow down and CPU shows 100%.

    Env:
    =====
    1. Windows Vista Home Edition.
    2. Used AVG 8.0 freeware as antivirus and after AVG detected some trojan related virus, performed the following steps.

    a. Ran Malwarebytes Anti-Malware (it removed some of the infection)
    b. Ran a complete scan with free curing utility Dr.Web CureIt! (result: no thread found)
    c. Ran the anti spyware removal programs spybot (it removed some of the infection)
    d. Installed ThreatFire and scanned again (result: no threat found)
    e. Ran Windows Live OneCare safety scanner (online scan, it removed some of the regitry and other clean up.

    Finally I have bought Norton Internet Security 2009 and installed in my machine and removed the Dr.Web CureIt, spybot and threatfire since confidence on Norton.

    But I am still experiencing the system performance to be slow and I don't know whether the above mentioned trojan is removed or not.
    Whenever opening IE/FF it's very slow and CPU goesto 100%.

    Followed as per the guidelines provided in this site.

    Step 1: Getting Started
    ========================
    1. Removed programs no longer used
    2. Cleaned my hard drive of unneeded files using CCleaner
    3. Removed invalid registry entries using CCleaner

    Step 2: Uninstalling Multiple Protection Applications
    =======================================================
    1. My system currently installed with only Norton Internet Security 2009.
    2. My system currently having Norton Antivirus only

    Step 3: House Cleaning
    =========================
    1. Below programs not found in Add/Remove Programs:
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    Viewpoint Toolbar
    Viewpoint Toolbar (Remove Only)

    2. Emptied ALL Quarantine type folders for Notron antivirus and antispyware applications.
    a. Removed Quarantine --> Risks in compressed file "dataintl.cab" has been fully resolved. (Notron Internet Security 2009)
    b. Removed Quarantine --> Removed the below Quarantine from Malwarebytes Anti-Malware
    Vendor Category Items
    ------ -------- -----
    Trojan.Downloader File C:\Windows\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
    Trojan.FakeAlert Registry Key HKEY_CURRENT_USER\SOFTWARE\XML

    3. Emptied my Recycle Bin
    4. Empty Norton Nprotect folder (Not present)
    5. Downloaded and installed CCleaner and followed the instructions.

    Step 4: Configuration & Setup
    ================================
    1. Enabled viewing of hidden files, system files and file extensions
    2. MSconfig set for Normal Startup mode

    Step 5: Uninstall Known Malware and Unwanted Software
    =====================================================
    1. Dont' have any malware to uninstall.

    Step 6: Select and run the all steps in the cleaning link below based on your Windows Operating System
    ======================================================================================================

    Step 1: Downloading Tools
    ============================
    SUPERAntiSpyware --> Downloaded to desktop
    Malwarebytes Anti-Malware --> already my system installed with Malwarebytes Anti-Malware and it has removed some of the infections. To follow the steps as per this site, I have unimstalled it and downloaded it again and performed it again.
    combofix.exe --> downloaded in desktop
    RootRepeal --> dowmloaded in desktop
    MGtools --> not able to download it to c:\

    Step 2: Disabled User Account Control
    =======================================
    Disabled UAC

    Step 3: Installing Tools and Running Scans
    ===========================================
    Installed the following:

    SUPERAntiSpyware
    Malwarebytes Anti-Malware

    combofix.exe
    Note: WHEN I PERFORMED COMBOFIX, I GOT THE MESSAGE "Combofix has detected the presence of rootkit activity and needs to reboot the machine."

    RootRepeal
    MGtools

    Step 4: Do You Still Have Problems
    ==================================
    Yes. Still I am experience slowness in IE/FF and CPU 100%

    Step 5:
    ======
    Attached the following logs:


    Logs:
    1. SASlog.txt log from SuperAntiSpyware.
    2. Malwarebytes Anti-Malware log
    3. ComboFix.txt (normally C:\ComboFix.txt)
    4. RRlog.txt (from RootRepeal)
    5. MGlogs.zip - normally it is C:\MGlogs.zip
     

    Attached Files:

  2. michealjohn

    michealjohn Private E-2

    Attached the MGTools.zip file.
    Note: Before came to this site, I have already ran the Malware antispyware and it has removed some of the infections. That log file I have attached with this thread.
    As per this site guideline I have followed all the steps and took the Malware antospyware log which I have attched in the previous thread. Hope this won't confuse you. Please help to advice to get rid of all infections (rootkit? torjan?) thanks in advance and expecting the help from this forum.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It's MGlogs.zip and you did not attach it. We need this to continue. The logs you have attached thus far show no problems.

    Actually I am confused since you only have one thread which I'm reading right now. So I'm not sure what you are referring to. Did you start a thread on a different website?

    What process or processes are using all of the CPU time?

    Your problems may just be what you are running (i.e. Symantec and ThreatFire) and amount of memory available.
     
    Last edited: Nov 2, 2009
  4. michealjohn

    michealjohn Private E-2

    Hi chaslang,

    Attached the MGlogs.zip. PLease help to advice.
    I am having 2GB of RAM. I have attached the screen shot of process running in task manager. I can able to see many svchost.exe is running.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is incomplete. Did you follow the instructions for Vista users. That is did you do all of the below:
    1. Disable UAC?
    2. Reboot after disabling UAC?
    3. Right click on MGtools.exe and select Run As Administrator?
    Did you have any other noticeable problems while running MGtools? Did Norton interfere with it? If so, shut down Norton before running. It still does not look like you are having malware problems though.


    You did not attach a snapshot of running processes. Look at what you attached yourself.;)

    There is nothing wrong with svchost.exe running many times. This is normal.
     
  6. michealjohn

    michealjohn Private E-2

    Yes, I have disabled UAC and Rebooted after disabling UAC and disabled Norton antivirus before running MGtools.exe as Administrator.

    I will do it again and attach the log.

    Sorry for wrongly uploaded the wrong document. I have attached the right document. Can you please help to delete the wrong document?
     
  7. michealjohn

    michealjohn Private E-2

    oops. I think I haven't uploaded the document propely. Uploaded it again.
    Whenever I am working with IE browser the mouse pointer is always showing it's being processed.
     
  8. michealjohn

    michealjohn Private E-2

    Hi chaslang,
    I have disabled UAC abd rebotted and disabled the Norton Anitvirus and firewall and right clicked the MGTools.exe and ran as administrator and attached the log file and also attached the screen shots. thanks.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not having malware problems. Your logs are all clean and as stated earlier, svchost.exe is always running many times especially on Vista and the more applications you have running the more svchost processes you will see. Oh and by the way you do have 2 GB of memory installed but your graphics card is using 256 MB of it so you only have about 1.79 GB for the rest of your system to use.

    You do need to do the below though.

    Uninstall the below old versions of software:
    J2SE Development Kit 5.0 Update 15
    J2SE Runtime Environment 5.0 Update 15
    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.



    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
    Last edited: Nov 9, 2009
  10. michealjohn

    michealjohn Private E-2

    Hi chaslang,

    Glad to know my system is not had any infection. Thank you so much for your effort and help. I have followed your steps and fixed those two entries using Hijack tool and uninstalled Hijack, enabled UAC, cleaned MGTools, uninstalled ComboFix.

    However for my development work with java, I am requiring Java 1.5 and I don't want to upgrade it.

    Once again thasnk you som much!!:)

    Thanks & Regards
    Mike
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. And if you are developing applications for others to use that will require this old version, you are leaving your customers at risk of infection and you at risk of a lawsuit. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds