Websites access and download very sluggish

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by thai_american_42, Jun 28, 2008.

  1. thai_american_42

    thai_american_42 Corporal

    I run Windown IE, Microsoft XP, and Norton 360. Yesterday, I tried to visit a website and received a virus warning. The website did not load. However, ever since then, my general access to websites, including MajorGeeks has become very sluggish. I've run Spybot - Search & Destroy and Spybot - Search & Destroy, but neither found anything. I ran CCleaner and defrag. I tried system restore, but that does not let me restore to a time before getting that virus warning.

    I ran speed tests at speedtest.net and speakeasy.net, both of which show my download speed as 4,800+ Kbps and an upload speed of 480 kbps.

    It takes about three minutes or more to open a MajorGeeks window. MGTools now is downloading at 254 bytes/sec (with an estimated download time of 17 minutes) and SUPERAntiSpyware is downloading at 2.09 KB/sec (with an estimated download time of 1 hour 27 minutes.)

    I have combofix.exe and MGtools.exe downloaded. PLEASE HELP!
     
  2. Lev

    Lev MajorGeek

  3. thai_american_42

    thai_american_42 Corporal

    SUPERAntiSpyware is downloading at 2.09 KB/sec and estimates that it will be another 1 hour 27 minutes before the software is downloaded. Can we do something in the mean time, such as by pass SUPERAntiSpyware, run the remainder, and attached the logs?
     
  4. thai_american_42

    thai_american_42 Corporal

    Never mind. I was able to download SUPERAntiSpyware from the Australian site.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have extremely slow download speeds, then skip download Malwarebytes Anti-Malware and Spybot if you do not have them and continue with the rest of the READ & RUN ME. I noted that you already have ComboFix and MGtools as stated in your first messsage. So make sure you run these scans and attach the logs.
     
  6. thai_american_42

    thai_american_42 Corporal

    I've been working since 19:03 and finally was able finish the steps fo Read & RUN ME FIRST. Attached are the first two files.
     

    Attached Files:

  7. thai_american_42

    thai_american_42 Corporal

    Here are the remaining two files. The scans seemed to pick up some bugs. However, accessing websites still is very slow and seems to be getting slower. Any help you can offer will be much appreciated.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems do not appear to be due to malware. Answer the below questions.
    1. When did your problems begin?
    2. Did the occur before or after installing Norton 360?
    3. Did they occur before or after installing Win XP SP3?
    4. Do they happen in safe boot mode?
    5. Did you previously have Outpost Firewall installed? I see a service still on your system from it and it could be conflicting with Symantec.
    6. Is IE Privacy Keeper still installed?
    7. Did you knowingly download and install CrazyTalk Serve? This often appears on PCs without the users knowledge.
    Here are a couple things to do, most of this will not have any impact on surfing.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. thai_american_42

    thai_american_42 Corporal

    Hi Chaslang,

    I'll answer your questions in this post, take the steps you recommend, and then post once I'm done taking the steps you recommended.

    Q. When did your problems begin?
    A. June 27, 2008, when I tried to visit a website and received a virus warning. As far as I know, the website did not load.

    Q.Did the occur before or after installing Norton 360?
    A. The problems began long after I installed Norton 360 (which I thought was supposed to prevent these things). I installed Norton 360 six (?) months ago and it has not been much of a problem.

    Q.Did they occur before or after installing Win XP SP3?
    A. The problems occured June 27, 2008, perpaps a week or two after I installed Win XP SP3.

    Q. Do they happen in safe boot mode?
    A. I cannot access the Internet in safe boot mode, so I am unsure if the problems happein in safe boot mode.

    Q. Did you previously have Outpost Firewall installed? I see a service still on your system from it and it could be conflicting with Symantec.
    A. I was unaware that I had Outpost Firewall installed. Please ensure that I remove it.

    Q. Is IE Privacy Keeper still installed?
    A. IE Privacy Keeper still is installed. I've had IE Privacy Keeper installed for a few years and like it. If it is causing problems, please let me know.

    Q. Did you knowingly download and install CrazyTalk Serve? This often appears on PCs without the users knowledge.
    A. I had no idea that CrazyTalk Serve was downloaded and installed.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then also have the analyse.exe program fix the below line:


    O4 - HKLM\..\Run: [CrazyTalk Serve] rundll32.exe C:\WINDOWS\system32\CrazyTalk.dll,DllServeMediaFile

    Then after a reboot, delete the below file if found:
    C:\WINDOWS\system32\CrazyTalk.dll
     
  11. thai_american_42

    thai_american_42 Corporal

    Hi Chaslang. I took the steps you recommend. On selecting Fix Checked, the MGtools screen went white. After running combofix.txt, Norton 360 popped up and suggested that I change the default phoshing filter to Norton 360. I selected the yes option. For fixme.reg, I received a success message about adding fixme.reg to the registry.

    On testing my computer on a few websites, things seem to be running better. Attached are ComboFix2.txt and MGlogs2.zip. I added a "2" to the name to give then a name different from the prior uploaded files. Please review these and let me know if all is good or if there is something else I can do.

    ADDENDUM - Looks like our posts overlapped. I'll follow the instructions in your 13:05 post.
     

    Attached Files:

  12. thai_american_42

    thai_american_42 Corporal

    Hi Chaslang.

    (1) I had analyse.exe fix:
    O4 - HKLM\..\Run: [CrazyTalk Serve] rundll32.exe C:\WINDOWS\system32\CrazyTalk.dll,DllServeMediaFile

    (2) After a reboot, I found and deleted:
    C:\WINDOWS\system32\CrazyTalk.dll

    (3) The two attached files in my 13:15 post, ComboFix2.txt and MGlogs2.zip were obtained before I addressed the CrazyTalk Serve issue. If you would like me to obtain new ComboFix.txt and/or MGlogs.zip, please let me know. Thanks.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not necessary! Your logs are fine now. How is everything working on your end?
     
  14. thai_american_42

    thai_american_42 Corporal

    Things seem to be working fine on my end. If I experience any more sluggishness in the next few days, I'll post again. Thank you for your help, chaslang! :wave
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds