Computer Slow Opening Programs & Browser Windows

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sdorsey, May 18, 2008.

  1. sdorsey

    sdorsey Private E-2

    Hi,

    I have an HP Pavilion laptop that is about 8 months old. About 2 weeks ago I noticed that my computer was running slowly when opening any program or changing browser windows. I use Firefox as my default browser but did not notice that a new Gmail account that I opened was linked to IE and was opening IE for a couple of times. About 3 days ago I noticed an unfamiliar icon in my startup toolbar. It was a maroon colored box with a diagonal line running across it. It would not do anything when you right or left clicked on it and no message would appear when you hover over it. I ran my McAfee Secure Center scan and it got rid of the icon but the problem with the slowness has not gone away. I just completed running the Start Here Malware Guide and am attaching the logs that I have after following the guide. Any help or advice on how I can regain the speed of my computer would be greatly appreciated.

    Sandra
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    You need to attach the 4th log that was requested. That is the C:\MGlogs.zip file from running MGtools.exe

    Is humyo.com Client something you installed?

    How many antivirus programs do you have installed???? You must only have one and I see more than one!!!
     
  3. sdorsey

    sdorsey Private E-2

    Thanks for the reply. I am attaching the additional log.

    The humyo is an online storage plan that I got to save files on from my old computer.

    I thought I only had the McAfee antiviral program left on my computer. It came with a trial Norton Antivirus but I thought I had removed it. Thanks again for taking a look.

    Sandra
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have some leftovers from Symantec and from running a Kaspersky tool.

    I will give you a few things to try that may help performance a little but your problems may not be due to malware. They may be cause by what you have installed. McAfee is a known resource hog.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Kapernsky AntiVirus
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    Uninstall SUPERAntiSpyware now since we are finished with it.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

    Do you really need the below always running when you start your PC? If not, have HJT fix it too:
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe

    After clicking Fix, exit HJT.




    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.




    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. sdorsey

    sdorsey Private E-2

    Hi again,

    I was only able to get to the portion where I drag the CFscript.txt file onto Combofix.exe. I tried it a couple of times and would get a message saying:
    "system cannot execute specified program" and it goes to a whole blue screen and the system restarts itself.

    Sandra
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you shutdown McAfee first? If not please do that and try again. If that does not work, try the steps after booting into your account in safe boot mode.
     
  7. sdorsey

    sdorsey Private E-2

    I turned McAfee off but still did not get any further. I tried it a couple of times in safe mode and got a little different message from Combifix:

    Cannot print route table: the system cannot find the file specified

    then the system just restarts itself.

    Sandra
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay ignore the rest of the previous fix and do this one.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. sdorsey

    sdorsey Private E-2

    Hi,

    I must apologize for the late response but I had a family emergency. I really do appreciate you taking the time to help me. I am attaching the two log files you requested.

    My computer seems to be working fine now as far as the speed is concerned. The McAfee Security Center takes some time to load on startup but no problems once it does.

    Sandra
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. sdorsey

    sdorsey Private E-2

    Hi,

    I have completed all of the steps but in Step 10 it says I need to work thru the below link but I don't see a link.

    Sandra
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. sdorsey

    sdorsey Private E-2

    Thanks again for your help.

    Sandra
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds