My slow PC. Is it just Windows or is it malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by xypher, Sep 30, 2011.

  1. xypher

    xypher Private E-2

    I ran all the anti-malware tools and have attached the logs. Curiously, I couldn't find a log for SuperAntiSpyware, which I thought was quite odd, since the scan completed and told me it had saved a log. Should I run it again?

    I've now just turned off System Restore and I'm preparing to reboot. I'll probably run SuperAntiSpyware again on reboot to check for any remnants. Does it make more sense to scan in SafeMode?

    Thanks for your help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    No! Based on your log from MGtools, it did not save a log in the normal location for some reason.

    You should not have done this.

    A bunch of issues have already been fixed but it may be that not all of your performance problems are due to malware. You could use at least another GB of memory. And the 31 processes running from Google are not helping you any.


    Let's run a couple more scans.

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller

    Please also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. xypher

    xypher Private E-2

    Thanks for the quick response. Yeah, I know I need to remove some Google Chrome extensions. I went overboard adding those one day.

    Re: System Restore. The malware instructions say to turn it off before you reboot and then turn it on afterwards. I turned it off but I didn't turn it back on after reboot.

    Anyways, I ran the required tools and have attached the requisite logs. I see that SnoopFree was reported in the Kaspersky scan. What is your opinion on this anti-keylogger? Also, MBRCheck reported a corrupt MBR. This seems pretty serious. I remember running some tool a while back that rebuilt the MBR. Unfortunately, I don't remember any details.

    Eagerly awaiting your analysis.

    P.S. I've also attached a screenshot of the SuperAntiSpyware quarantined items in lieu of the scan log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! The instructions have you stopping at step 3 and posting logs if you are still having problems. If you are not having problems then it tells you to move on to step 4 to toggle System Restore.

    Don't really know much about it. Reviews seem to be mixed.

    Do you have your Windows XP bootable CD so that you can use it to boot to the Recovery Console so that the MBR can be fixed.

    Also it is strongly recommended that you backup all important data before the MBR is repaired. Normally this goes without a problem, but there is always the chance that something could go wrong and potentially make a PC unbootable.
     
  5. xypher

    xypher Private E-2

    Whoops. It seems like I misunderstood the instructions. I thought it meant if I had a problem completing the malware scans. Not being a malware expert, I had no idea whether there were any malware problems or not. Maybe the instructions need to be made more explicit.

    No Windows XP cd. I bought this machine in Taiwan and they don't tend to give you the CD. Any alternative ideas for repairing the MBR?

    I already cloned the computer using Clonezilla. I was trying to set it up as a Virtual Machine w/ VirtualBox but having finished the set up yet. My idea was to run Linux on this machine and have WinXP running within the sandbox.

    Rob.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I added a few more details ( and some redundancy at the start of step 4 ) into the instructions that may help clarify things for others in the future. Thanks for pointing out that it was not clear for you. Others may have had the same problem.

    See what was posted in message # 12 of the below thread and see if you can get this CD to run.

    whistler/black internet@mbr again!
     
  7. xypher

    xypher Private E-2

    Thanks for modifying the instructions. I work as a technical writer so I agree with your assessment that others might have been led astray with the previous instructions. Another idea might be to number these steps so they're easier to reference in later communication. That way you can be more clear which step in particular you're both talking about.

    So, back to my problems, I created the BootCD and ran the MBR fix. Everything seemed normal with my PC after reboot. So, I ran the MBRcheck tool again and that confirms that I have a regular WinXP MBR. I've attached the log in case you're interested.

    So, assuming that everything is fixed. What do I do next?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good now.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds