Computer slows to crawl, not responding

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by glasgowrangers23, Aug 19, 2011.

  1. glasgowrangers23

    glasgowrangers23 Private E-2

    basically what happens is I have something from kapersky called TDSkiller which scans for rootkits, normally takes 30 secs but now takes 12 mins!

    cant use mozilla or internet explorer as keep getting not responding
    any chance you can help please
     

    Attached Files:

  2. glasgowrangers23

    glasgowrangers23 Private E-2

    rabn the mg tools but didnt run it as admin so kept coming asking so shut it down and did it again under admin and screen didnt come up
     

    Attached Files:

  3. glasgowrangers23

    glasgowrangers23 Private E-2

    av found win32/Prcview appliaction
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Most likely just a false detection of the process.exe file that is embedded in MGtools. It is just a simple command line drive process listing tool.

    Your logs are all clean so it is not looking like you are having malware problems and you may need to work your issues in the Software Forum. However let's first dig a little deeper to be sure nothing else could be hiding from view by running the below two scans.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now also lease also download MBRCheck to your desktop.


    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Have you tried shutting down Norton before running TDSSkiller. Also with Norton shutdown, do IE and Firefox work better?
     
  5. glasgowrangers23

    glasgowrangers23 Private E-2

    I was trying to deposit money into an accoun and no script stopped an hijack attempt earlier

    the mbrcheck says it green windows 2007 mbr code detected, that a worry?
     

    Attached Files:

  6. glasgowrangers23

    glasgowrangers23 Private E-2

    mbrchecker still says 2008 mrb code

    here is the tdskiller log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are all clean. You do not appear to be having malware problems. Try uninstalling Norton and see how things work. Also it is highly recommend to run the below after uninstalling Norton because it rarely uninstalls properly.


    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)


    Also something else to try if the above has no effect. Stop using Firefox for the moment and use IE and see what happens. Do not even open Firefox!!!!!
     
  8. glasgowrangers23

    glasgowrangers23 Private E-2

    so I need to find a new AV and firewall ?

    what about mbrcheck which says I had 2008mrb code detected??

    Is firefox no good? I thought it was better than IE? why not even open it?

    i was playing poker today and it was stuttering so seems something is still wrong?

    thanks
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only if this test shows that it is your problem. ;)

    Normal

    Your logs show it was using over 340 MB of memory. Is it good? Lots of people like it. I prefer IE which is actually safer/more secure. However my instructions are a test to see if it is your problem. By not opening it, it will not be running and using any memory and thus you may be able to answer whether or not it is causing you a problem.

    Still does not mean it is malware. And playing online poker games is not something we recommend. Many people get infected at these sites. And if you were using Firefox and if Norton is still running, they still could be the source of your problems.
     
  10. glasgowrangers23

    glasgowrangers23 Private E-2

    will try and let you know

    I have a partion the guy in the comp shop did for
    i got to windows, type in restore and it has an image of how my computer was when it was new
    is there anyway that could be infected on my d:\

    thanks
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This came from Dell not from a person in your computer shop. Your PC is a Dell Computer and they install factory recovery partitions on their computers instead of doing the correct thing and giving you to DVDs you need to properly fix a PC when it has problems. Your logs showed me this information.
    Code:
    Item Value 
    Drive C: 
    Description Local Fixed Disk 
    Compressed No 
    File System NTFS 
    Size 288.32 GB (309,584,719,872 bytes) 
    Free Space 261.69 GB (280,988,610,560 bytes) 
    Volume Name  
    Volume Serial Number DED96327 
     
    Drive D: 
    Description Local Fixed Disk 
    Compressed No 
    File System NTFS 
    Size 9.77 GB (10,485,755,904 bytes) 
    Free Space 3.89 GB (4,174,716,928 bytes) 
    Volume Name Recovery 
    Volume Serial Number 3E204527 
    It is not causing you a problem.

    Let me repeat this again.... You don't have any malware.
     
  12. glasgowrangers23

    glasgowrangers23 Private E-2

    thank you for your help

    if it is norton is there any reason why that would be causing this ?

    what firewall/av would you recommend

    thanks again for all your help
     
  13. glasgowrangers23

    glasgowrangers23 Private E-2

    One final thing
    ran the Norton removal tool a number of times and nothing happens?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes because in the past it has always been a resource hog. Supposedly newer versions are not as bad, but I'm not convinced that is true.

    Reference this: How to Protect yourself from malware!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall it first via Add/Remove Programs?

    Do you still see any of it running? Do you see files for it on your computer?
     
  16. glasgowrangers23

    glasgowrangers23 Private E-2

    the norton removal tool finally popped up after 4 hours, so am just using it now
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let us know the results.
     
  18. glasgowrangers23

    glasgowrangers23 Private E-2

    hi
    not made much difference to be honest
     
  19. glasgowrangers23

    glasgowrangers23 Private E-2

    can I ask one final question
    what was the 2008 mbr code detected all about, I thought mbr code was bad esp when mrchecker finds it?

    thanks
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!!! All PCs have a Master Boot Record. It is when they are infected or faked that it is a problem. Windows 7 shows as you saw.

    Are you sure Norton is gone. Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  21. glasgowrangers23

    glasgowrangers23 Private E-2

    here it is
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you installed Avast now which I did not request. Did you purchase this?

    Uninstall all of the below and reboot your PC. Then tell me how things seem to run.

    avast! Internet Security
    PeerBlock 1.1 (r518)
    Secunia PSI (2.0.0.3003)

    Now Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  23. glasgowrangers23

    glasgowrangers23 Private E-2

    I didnt purchase avast its a 30 day trail, as I took Norton off I had no firewall and AV so I needed one and used that, you still want to be take it off as then I will have no protection?
     
  24. glasgowrangers23

    glasgowrangers23 Private E-2

    log.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But the goal was to also see how your performance is without this protection installed and running. It is only going to be for the time frame it takes for us to do the experiment and to also look at your logs while no protection is installed.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the below? I don't see it in your installed programs list:

    O4 - HKCU\..\Run: [GoTrusted] C:\Program Files\GoTrusted.com\GoTrusted Secure Tunnel v2.3.1.5\GoTrusted Secure Tunnel.exe


    How are things running without Avast installed?

    Your logs still show you are using Firefox too which is using quite a bit of memory. I suggested not running this earlier too to see how things work.

    At this point I suggest that if you still have performance problems, that you uninstall Firefox, reboot, redownload and then reinstall with NO PLUGINs. Then see what happens. If still having problems, please reinstall your protection since it is not the problem and then post in the Software Forum for help.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Aug 26, 2011
  27. glasgowrangers23

    glasgowrangers23 Private E-2

    go trusted is a vpn I use

    The MGclean.bat file is not there in the mg tools, do I delete the mg tools file

    also a file called nethood has appeared which i cant access

    thanks
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is. It showed in all of your logs. Check again. Make sure that you are looking in the C:\MGtools folder. Also if you do not have viewing of file extensions enabled, you will only see MGclean not MGclean.bat
     
  29. glasgowrangers23

    glasgowrangers23 Private E-2

    found it thanks and its all gone now. Anything else?
    thanks
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Nope. You're finished. ;)
     
  31. glasgowrangers23

    glasgowrangers23 Private E-2

    thanks for your time and help :)
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds