Windows & VIPRE antivirus can’t update, very slow pc, Trojans

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by brunobru, Dec 5, 2010.

  1. brunobru

    brunobru Private E-2

    Hello, I am helping a friend and his pc has become extremely slow and the antivirus says in the task bar that updates are available, but it can’t update. Cannot access windows update, home page was changed, uninstalled viewpoint media player, outdated version of java and tried to rid of FunWebProducts. Ran the scans but still can’t get it clean and updated. Cannot download new java version (it won’t complete the download) to run panda Activescan. Any help would be appreciated. Thank you.
     

    Attached Files:

  2. brunobru

    brunobru Private E-2

    the last log
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. Let's do this however:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now use windows explorer to find and delete:
    C:\Program Files\Common Files\Authentium

    Now let's have you do an online scan:
    eSet Online Scan.

    Attach the log from eSet.
     
  4. brunobru

    brunobru Private E-2

    Thank you for your help. I tried several times to delete those entries in HJT but they are persistent. So I did what you said using MGtools and the same affect. We tried to run eSet online scan but after the activeX is installed it won't go any further. We deleted the Authentium folder as you said and also are trying Panda again. This time we are able to get the ActiveX installed but the scan keeps hanging. We're going to try deleting the entries in safe mode and see if that helps. I don't know if this helps at all but there is a user profile called Owner.YOUR-W04GTXLD67 and I have a screenshot of it and all the users, plus a SAS log file that keep repeating the same offending adware.tracking cookies that lead to porn sites but the profile is not accessible (Owner). What should I do next?
     
  5. brunobru

    brunobru Private E-2

    We finally were able to get Panda activescan to run which took hours and I attached the log. It found 4 hacktools and trojans. We never could get eSet to start a scan. The pc itself is running faster since all of the scans and cleanup, but internet, downloading tiny files and trying to send emails is almost impossible due to locking up or extremely slow. Have not done MGtools in safe mode yet because I don't have access to my friends computer until this afternoon. Thanks for your help.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Get me a new MGLogs.zip when you can.
     
  7. brunobru

    brunobru Private E-2

    Thanks TimW, here is the MGlogs file.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. We just need to do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    I will suggest that you pursue your other issues in the software forum. Post about your issues with slowness and answer these questions:

    Please explain what operations are slow! For example answer the below:

    * Is boot up slow?
    * Is shutdown slow?
    * Is browsing/surfing slow?
    * Is downloading slow?
    * Is running any application?
    * Is it also slow in safe boot mode?
    * Also are any process showing in Task Manager to be using a lot of CPU time?
    * Anything else slow?
     
  9. brunobru

    brunobru Private E-2

    We have done as you instructed (below) several times and those entries always reappear. What does that mean and what are those entries referring to? Ok on the other part about the other issues in the software forum.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Quote:
    O4 - S-1-5-18 Startup: MRI_DISABLED (User 'SYSTEM')
    O4 - .DEFAULT Startup: MRI_DISABLED (User 'Default user')
    O4 - .DEFAULT User Startup: MRI_DISABLED (User 'Default user')


    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run the C:\MGTools\analyse.exe ( which is HJT ) and attach the HJT log so I can see if they came back.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds