Slow-running computer, can't connect to Internet due to popups

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by StuffGal, Feb 27, 2009.

  1. StuffGal

    StuffGal Private E-2

    My laptop is experiencing several problems at the moment. To start with, startup usually takes longer then usual. I also get a message about the paging file being too low, either during or shortly after the startup. I also usually run into a few warnings labeled "bad image", and the warning says something about a missing dll. In addition, the computer itself is running very slowly-- if I try to do even the simplest of things, like opening up Notepad, it could take far longer than usual.

    Currently, my computer is offline. Whenever I stick the ethernet cable into it, though, I can get on the Internet just fine... except I suddenly get a bunch of popups trying to load at once. Even if I don't have any browsers open, I'll get popups from both Internet Explorer and Mozilla Firefox. The browsers will go to random websites I've never been to before, or they'll just be an ad for something.

    I tried running all the anti-malware programs and such as described in the sticky a few times, but I couldn't really get anywhere with it. If I was somehow able to miraculously start and run the first anti-malware program on there, it would crash the computer at the end of the scan and I'd have to restart everything and try again.

    The specs are:
    • Running Windows XP 2 Professional, with Service Pack 2
    • Manufactured by VARtek Value Added Technology
    • Intel Pentium III
    • Mobile CPU 1066 MHz, 535 MHz
    • 256 MB RAM
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most of the above is may not have anything to do with malware.

    This does sound like malware.


    Sorry but your PC is on the slow side and 256 MB of RAM is insufficient to properly run and updated Windows XP and all the other software your PC requires (like antivirus, antispyware, firewall..... and everything else). You need at least 4 times that amount of memory. That is 1GB to effectively run Windows XP. However I'm not sure this laptop would support 1 GB of RAM.

    I know you say you have attempted the cleaning procedure, but you need to try again using the below as a reference. Without logs, all I can suggest is that you try to do a System Restore to a point in time where you had no problems, or that you will have to reinstall unless you can get some scans to run so see if any malware is at play.


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:



    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. StuffGal

    StuffGal Private E-2

    All righty, I tried it again. First of all, when I ran SUPERAntiSpyware, it went through all right until the Quarantine and Removal Step. At that point, I got an error message. It was titled, "Microsoft Visual C++ Runtime Library", and it said,

    "Runtime Error!

    Program: C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    R6025
    - pure virtual function call"

    The other programs ran all right. On ComboFix, I couldn't install the Recovery Console, since that computer wasn't hooked up to the Internet.

    After running all the programs, the computer seems to run better. It's back at its normal speed, and after I connected to the Internet, it didn't bring up a ton of popups. Things aren't always what they seem, though, so I've still got the logs.

    Thanks for the help! :)
     

    Attached Files:

  4. StuffGal

    StuffGal Private E-2

    And here's the fourth log, for SUPERAntiSpyware.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You did not download and use the current version of MGtools given in the READ & RUN ME.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O16 - DPF: Win32 Classes -

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds