MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 09-05-11, 07:55
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default I have a slow computer Please Help, may be a rootkit,LOG included

Each time i run reformat it begins slowing down again
programs take for ever to load,
Attached Files
File Type: txt sas log.txt (681 Bytes, 2 views)

Last edited by Kestrel13!; 09-05-11 at 08:20.. Reason: attached inline SAS log!
Reply With Quote
Sponsored links
  #2  
Old 09-05-11, 08:10
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

(Removing inline logs, MGlogs.zip should be attached as a whole not like this)

Last edited by Kestrel13!; 09-05-11 at 08:18..
Reply With Quote
  #3  
Old 09-05-11, 08:11
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

(Removing inline logs, MGlogs.zip should be attached as a whole not like this)

Last edited by Kestrel13!; 09-05-11 at 08:18..
Reply With Quote
  #4  
Old 09-05-11, 08:15
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,122
Thanks: 1,004
Thanked 3,786 Times in 3,687 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

Hi there, you have made a mess posting all these logs inline (We prefer them to be attached) Please take a look at this.

HOW TO: Attach Items To Your Post

Then you will know how to attach all of the requested logs instead. I am going to remove all the inline postings now.

Here's the link to our procedures for reference. READ & RUN ME FIRST. Malware Removal Guide
__________________
Have we been helpful? Did our services here at MajorGeeks save you a whole lot of cash? If you would like to bequest a small amount as a token of your appreciation, please look out for the yellow 'Donate' button on the top right of any page. Thanks!
Reply With Quote
  #5  
Old 09-05-11, 08:16
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

(Removing inline logs, MGlogs.zip should be attached as a whole not like this) Please read the "How to attach" link I gave you!!! Going to delete your below post as I have not got time to keep editing like this. Thankyou.

Last edited by Kestrel13!; 09-05-11 at 08:24..
Reply With Quote
Sponsored links
  #6  
Old 09-05-11, 08:59
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

Sorry for posting the logs wrong, Hopefully these are right
Attached Files
File Type: zip MGlogs.zip (93.5 KB, 4 views)
File Type: txt mbam-log-2011-09-04 (09-27-27).txt (900 Bytes, 1 views)
File Type: txt RRlog.txt (690 Bytes, 1 views)
File Type: txt ComboFix4.txt (3.9 KB, 2 views)
Reply With Quote
  #7  
Old 09-05-11, 10:13
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,122
Thanks: 1,004
Thanked 3,786 Times in 3,687 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

Quote:
Originally Posted by mary7 View Post
Sorry for posting the logs wrong, Hopefully these are right
Don't worry about it.
Quote:
I have a slow computer Please Help
Please explain what operations are slow! For example answer the below:

  • Is boot up slow?
  • Is shutdown slow?
  • Is browsing/surfing slow?
  • Is downloading slow?
  • Is running any application?
  • Is it also slow in safe boot mode?
  • Also are any process showing in Task Manager to be using a lot of CPU time?
  • Anything else slow?

I want you to run TDSSKiller so refer to the below for how to do so.

TDSSkiller - How to run

-------------------------

Please also download MBRCheck to your desktop
  • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
  • It will show a Black screen with some information that will contain either the below line if no problem is found:
    • Done! Press ENTER to exit...
  • Or you will see more information like below if a problem is found:
    • Found non-standard or infected MBR.
    • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
  • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
  • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
  • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

Also, you ran MGTools.exe in safe mode. I would prefer if you could do this in NORMAL mode now if at all possible.

Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful? Did our services here at MajorGeeks save you a whole lot of cash? If you would like to bequest a small amount as a token of your appreciation, please look out for the yellow 'Donate' button on the top right of any page. Thanks!
Reply With Quote
  #8  
Old 09-05-11, 10:58
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

Boot up is not slow,
Shutdown is not slow,
browsing/Surfing is slow,
downloading not slow,
running all aplications is slow,
safe mode with networking was not slow,
system idel process shows 98 under cpu everything else shows mostly 0,
Nothing else is slow,

I noticed the MBR scan found something, non standard or infected MBR

Here are the logs,
Attached Files
File Type: txt TDSSKiller.2.5.18.0_05.09.2011_04.40.06_log.txt (44.8 KB, 3 views)
File Type: txt MBRCheck_09.05.11_04.47.04.txt (8.7 KB, 3 views)
File Type: zip MGlogs.zip (113.2 KB, 3 views)
Reply With Quote
  #9  
Old 09-05-11, 12:07
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,122
Thanks: 1,004
Thanked 3,786 Times in 3,687 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

Do you have your XP boot CD?
__________________
Have we been helpful? Did our services here at MajorGeeks save you a whole lot of cash? If you would like to bequest a small amount as a token of your appreciation, please look out for the yellow 'Donate' button on the top right of any page. Thanks!
Reply With Quote
  #10  
Old 09-05-11, 12:10
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

I don't have the Cd
Reply With Quote
Sponsored links
  #11  
Old 09-05-11, 12:36
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,122
Thanks: 1,004
Thanked 3,786 Times in 3,687 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

Earlier on ComboFix installed the Recovery Console. We're going to use that now.

Reboot your machine and when the Boot Menu flashes up - select "Microsoft Windows Recovery Console"
(you need to be very fast with the arrow key as you only have a couple of seconds before it defaults to the windows XP bootup)






When you get to the above screen, take note of the number that references your operating system.

If it's '1' like the picture above, type 1 and press Enter



Next type FIXMBR

If it ask if you're sure you want to write a new MBR, answer 'Y'

Then type EXIT to reboot the machine.

With that done, re-run MBRCheck, and attach the new log. Let me know how things are now.
__________________
Have we been helpful? Did our services here at MajorGeeks save you a whole lot of cash? If you would like to bequest a small amount as a token of your appreciation, please look out for the yellow 'Donate' button on the top right of any page. Thanks!
Reply With Quote
The Following User Says Thank You to Kestrel13! For This Useful Post:
mary7 (09-06-11)
  #12  
Old 09-05-11, 14:14
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

It doesn't show the windows recovery option or windows xp home, just a cuser flashing
Reply With Quote
  #13  
Old 09-05-11, 14:21
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,911
Thanks: 453
Thanked 4,702 Times in 4,439 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

This is a download of an .iso file of just the Recovery Console for XP.
Burn to CD with Nero or other 'disc image' capable tool and boot.

XP Recovery Console.

You can use ImageBurn to create the disc.

After you create the disc, boot into the bios and change the boot order to CD/DVD as first boot device. Put in the disc and reboot. Once you are in the Recovery console, type:
fixmbr

Exit out and remove the disc.

Now once back into normal mode, re-run MBRCheck and attach that log.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
The Following User Says Thank You to TimW For This Useful Post:
mary7 (09-06-11)
  #14  
Old 09-05-11, 16:34
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

My Computer is faster now,although when i minimize, maximize internet explorer is showing odd behaviour I can see the blue bar at the top spreading up the page it only takes a few seconds to open and drags to fill the screen, I dont know if this is normal, but before now it took ages to open, I also noticed a small box opening each time i log on it says via raid tool in the middle and shuts after about 3 seconds,

Here is the MBR Log,
Attached Files
File Type: txt MBRCheck_09.05.11_10.22.15.txt (8.3 KB, 3 views)

Last edited by mary7; 09-05-11 at 16:43.. Reason: add details
Reply With Quote
  #15  
Old 09-05-11, 16:52
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,911
Thanks: 453
Thanked 4,702 Times in 4,439 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

Good job. I suggest that you post in the software forum for your additional issues, esp. the raid message.

If you are not having any other malware problems, it is time to do our final steps:
  1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
  2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /uninstall
      • Notes: The space between the combofix" and the /uninstall, it must be there.
      • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


  3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
  4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
  6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  7. Go to add/remove programs and uninstall HijackThis.
  8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
  9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
    • Refer to the cleaning procedures pointed to by step 7 of the READ ME
      for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.

  10. After doing the above, you should work thru the below link:


Malware removal from a National Chain = $149
Malware removal from MajorGeeks = $0

Help Support MajorGeeks
Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

MajorGeeks on FaceBook
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
Sponsored links
  #16  
Old 09-06-11, 05:15
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

I have done the below and my pc did speed up but slowed down again after I turned off system & turned back on again and I had to log into safe mode with networking as internet explorer wouldnt load, when i tried to enter safe mode with networking windows xp I got this error<system root>\system32\hal.dll. is missing
I also installed comondo firewall ccleaner & comondo antivirus, it blocked RECGUARD.EXE and said it is a unreconised file and has been sandboxed , here is a new log below run in safe mode
Attached Files
File Type: txt MBRCheck_09.05.11_23.14.57.txt (6.5 KB, 1 views)

Last edited by mary7; 09-06-11 at 05:24..
Reply With Quote
  #17  
Old 09-06-11, 08:29
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,122
Thanks: 1,004
Thanked 3,786 Times in 3,687 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

Quote:
when i tried to enter safe mode with networking windows xp I got this error<system root>\system32\hal.dll. is missing
Not topic for the malware forum. You can post about this in the software forum.
Quote:
I also installed comondo firewall ccleaner & comondo antivirus, it blocked RECGUARD.EXE
This too.
__________________
Have we been helpful? Did our services here at MajorGeeks save you a whole lot of cash? If you would like to bequest a small amount as a token of your appreciation, please look out for the yellow 'Donate' button on the top right of any page. Thanks!
Reply With Quote
  #18  
Old 09-06-11, 16:07
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

I still have a problem with Malware, my computer did speed up until i disabled system restore restarted & renabled system restore, it is now a lot slower than it was, I think the problem has somehow reinstalled itself Internet Exlorer wont open except is safe mode, my Computer is extreamly slow, I can't run anything- only in safe mode,

Kind Regards,

Mary.
Reply With Quote
  #19  
Old 09-06-11, 16:20
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,911
Thanks: 453
Thanked 4,702 Times in 4,439 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

You will need to redo the Read and Run First instructions and attach the requested logs.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #20  
Old 09-08-11, 14:42
mary7 mary7 is offline
Private E-2
 
Join Date: Sep 2011
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: I have a slow computer Please Help, may be a rootkit,LOG included

I have rerun all the scans as reqested,

Here are the logs,

kind regards,

Mary
Attached Files
File Type: log SUPERAntiSpyware Scan Log - 09-08-2011 - 08-42-07.log (578 Bytes, 1 views)
File Type: txt NEW2mbam-log-2011-09-07 (08-47-46).txt (900 Bytes, 1 views)
File Type: txt COMBOFIXNEWLOG.TXT (13.9 KB, 1 views)
File Type: txt RRRlog.txt (690 Bytes, 0 views)
Reply With Quote
Sponsored links
Reply

Tags
root kit, rootkit, slow, trojan, virus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer start up is slow. Computer running slow - completed required steps TheBlackClap Malware Removal 15 09-25-09 22:20
Slow Computer with Malware is it true files included silas Malware Removal 5 05-07-09 18:54
Avira AntiVirus Disabled rootkit & possible keystroke logger; Log files included nadsab Malware Removal 18 04-19-09 23:41
help!! computer infected.. HJT included dkninja Malware Removal 1 05-18-06 09:22


All times are GMT -5. The time now is 13:22.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger