Computer running slowly after removing virus received via msn messenger.

Discussion in 'Malware Help (A Specialist Will Reply)' started by scottie, Dec 2, 2007.

  1. scottie

    scottie Private E-2

    Hello there,

    A couple of days ago my son clicked on a link sent via msn. It said something like "are these your photos". Turned out it was some sort of virus or bug. Another friend of mine took a bit of a look and reckons he's fixed it but the computer is running very slow, almost like it has no ram. Everything takes a long time to run, opening web pages, programs....the works.

    I've run the run and read me steps over the last day (it takes ages at the moment for scans and what not).

    My logs are attached and thanks in advance for any assistance you can give me.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you just install Spy Sweeper to help cleanup these probems? Is it a paid version or a free trial version? It can be very resource intensive which will slow many PCs down.

    How much RAM do you have and what processor type do you have and what speed?


    You don't really have any malware problems. Do the below which will help a little but SpySweeper could still be your problem. The below could help improve the issues with SpySweeper though since we have seen it have issues with the Sun Java BHO.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 10
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

    After clicking Fix, exit HJT.


    Did doing any of this help?
     
  3. scottie

    scottie Private E-2

    Thank you for that, I have done what you suggested.

    Unfortunately it's not had much effect, the PC is still running quite slowly. It's like the system's using all of it's resources so everything you do is running slow. For example, calling up task manager takes about 10 seconds. likewise, opening web pages and the like also takes a lot longer than usual. I just instaled the latest AOE expansion game. That took 35 minutes. Normally that sort of thing is done in under 5.

    The PC has 2gig of RAM and is a P4 3.0, all about 3 1/2 years old. Up until this thing from messenger it had been running great. It was reformatted about 4 months ago, which I do from time to time.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Including uninstalling Spy Sweeper?




    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    C:\Documents and Settings\Scott\Start Menu\Programs\Startup\services.lnk

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Any change to your status? If not, follow the instructions in the below link and attach the GMER log.

    Running GMER to detect rootkits
     
  5. scottie

    scottie Private E-2

    Yes, sorry I forgot to mention I uninstalled spy sweeper. It was the demo.

    I’ve gone through your latest instructions. I get to avenger and after I confirm execution after pressing the traffic light I get three errors in a row;

    1) Selected file does not appear to be a valid script
    2) Press OK to log error and continue or cancel to abort ( I press OK)
    3) Error Code: 0

    It doesn’t appear to save a log file, as the folder you mention is empty. I did get a text file on my desktop though, which I've attached.

    I rebooted after that.

    Still the same issues though unfortunately.

    (whoops..posted by accident.....currently editing)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you copy everything in the quote box?? Including the first line which is Files to delete:
     
  7. scottie

    scottie Private E-2

    Yes sorry.....I accidently posted before....didn't mean to as I had realised what you had said. It worked ok, log is attached...along with the others you requested.

    Will reboot now and edit with performance update in a moment.
     

    Attached Files:

  8. scottie

    scottie Private E-2

    Some improvement now, although still not at 100%. Probably about half way there.

    (off to work now)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most of the remaining issues could be due to what you are running but I did see something else in your GMER log that is suspicious. We will work on that further down.

    Why are you running eMule while trying to fix this? It will slow your PC down too.

    The below may be using a load of resources. How do things look if you don't load this at startup?
    CCC (C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe)


    Now print the below instructions because at a point during them you MUST (this is can be critical) shutdown all browsers. I will tell you when to exit the browsers during the muti-part procedure.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktip or the below will not work. Do not run it!
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have the below icons on your Desktop (double click the thumbnail to expand it)
    CFScript.jpg
    • Now refer to the above image and use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Now run Ccleaner!


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.

    Make sure you tell me how things are working now!
     
    Last edited: Dec 4, 2007
  10. scottie

    scottie Private E-2

    I have emule running most of the time. When the PC is running OK it doesn't seem to affect the speed at all. I'll close it for the time being though so as to eliminate it from the equation.

    I don't have that second icon on the screen that you mentioned (CF script). When I drag the text file I created over Combofix it runs for a moment then I get a pop up error headed "CFScript name error" along with the text "were you trying to run CF script?" then "The name, CF fix seems to be incorrectly spelt"
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry. I forgot to rename the ComboFix-do.txt file to CFscript.txt . I just edited the procedure to put in the correct name. Run it again and this time create the CFscript.txt file which was what I intended to do.
     
  12. scottie

    scottie Private E-2

    Here we are:

    It's definately improving. Seems now that the lag is now pretty much comfined to when you open up programs, web pages et. al. Anything where (and I think this is how it works) something new is using the ram and the lag is where it's transferring to it. You can hear the hard drive whirring like it does when it's "busy".

    Once it's there, after a moment it works fine. Games, although taking longer to run, are working fine when they are loaded. Windows media player is taking about 10 seconds to open, then about 10 more seconds to get itself organised for it's menu's and content to come up. But once that's done you can come back to it from a web page or program and it works fine. if you close it though it takes time again to open up.

    Generally, that sort of thing is pretty much instantaneous. So it's getting better though.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just one more item to remove and then we are finished with cleaning.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  14. scottie

    scottie Private E-2

    Yes, it's getting almost back to how it was now. Not 100% but infinitely better than it was a couple of days ago.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good. We are finished with your malware removal. Everything else that may be impacting your speed is just what you are running. You will have to decide whether you need all the other processes/software and either uninstall them or stop them from loading if they are unnecessary.
     
  16. scottie

    scottie Private E-2

    Thanks for your help!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds