Very slow computer and a trojan or 2

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jackyaz, Nov 3, 2009.

  1. jackyaz

    jackyaz Private E-2

    Hi there, about a week ago my computer started running slowly, instead of the usual 5 minute boot time, its taking close to half an hour before its even usable. The clock freezes along with the computer for 10 minutes at a time. I tried system restore but no help, and when running Malwarebytes Antimalware it picked up some trojans and registry keys blocking windows firewall and security centre!

    However, the computer boots fairly quickly into safe mode. I have followed the readme and performance has increased a little. Could you please look through the logs to see what is going on with my computer, I cannot afford to replace it! Thanks for any help in advance :)
     

    Attached Files:

  2. jackyaz

    jackyaz Private E-2

    Here is the fifth and final log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Apparently you did not read this link in the Read and Run First Instructions:
    Uninstall Malware via Add/Remove Programs. Had you looked at that you would have found the main cause of your problems:
    Messenger Plus! Live --> Uninstall this!!

    Now, I will chastise you once more. :( It is a very bad idea to allow all users to have Admin. privileges!! Once malware gets on your system via an Admin account, it has free reign to infect all your user profiles as well as access to all files and folders.

    Code:
    Users on this computer:
    Is Admin? | Username
    ------------------
       Yes    | Administrator
              | ASPNET
       Yes    | Cally
       Yes    | Greg
              | Guest
              | HelpAssistant (Disabled)
       Yes    | Jack
              | MCX1
              | MCX2
       Yes    | Miriam
              | SUPPORT_388945a0 (Disabled)
    
    I am not seeing much in your logs. You will have to tell me what was reported as trojans and what reported them ( I need the exact path to the file).

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    I have no idea what this is, so unless you know, lets rename it by right clicking the file and rename it to .old:
    C:\WINDOWS\zwcm.bin --> so it is now C:\WINDOWS\zwcm.bin.old
    Let me know if something stops working correctly. But I am fairly sure it needs to go.

    You need to start using a startup manager. You have a lot of items running at startup that do not need to run.
    You may wish to use one of these:

    Startup Manager

    Startup_CPL

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. jackyaz

    jackyaz Private E-2

    I use Messenger Plus on other computers and I know plenty of people who use it with no issue, I do make sure I dont install the sponsor program with it, but if it is necessary to remove it then I shall. (edit) Just read the link you posted, I think I will uninstall it on all of my computers, the only thing that I use it for is the lock feature anyway. (end edit) Is it possible for me to carry out these instructions in safe mode, as this is the only mode I can get it to boot and respond within a reasonable time?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes you can use safe mode to do the fixes. You still need to tell me what the reported trojans were and the path to them.

    Didn't see your edits. :)
     
  6. jackyaz

    jackyaz Private E-2

    I will let you know tomorrow when I put the computer on, the trojan was reported by MBAM, so I should be able to find the log for it.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The MBAM log that you attached found two items and removed them. After doing my fix, tell me what problems you are having.
     
  8. jackyaz

    jackyaz Private E-2

    hi, i followed your steps but it still wont work properly in normal mode. i have attached the original MBAM log that flagged up the trojan. from switch on to being able to log in, it takes about 5 minutes. once logged in, it proceeds to load, and after about a minute or so the hard drive access light on the front of the computer comes on constantly and the computer ceases to respond to anything. ive used a startup manager and removed what i dont think should be loaded on startup. do my logs show what is loaded on startup? is there anything there that could be causing the problem?
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system. You are still allowing all users to have Admin. privileges, so I suggest you try to log into each account, see if you have the same problem on each, and to be sure, run both SAS and MBAM on each account. Attach any logs that show infections ( making sure that you identify which account they are).
     
  10. jackyaz

    jackyaz Private E-2

    Im really sorry I haven't replied sooner to this, I've been swamped with work etc. The computer is back working again, is still a bit slow to boot but its a tolerable 5 minutes or so. Many thanks!
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you try using a start up manager:

    You may wish to use one of these:

    Startup Manager

    Startup_CPL

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds