Slow System, ComboFix and RootReveal don't run.

Discussion in 'Malware Help (A Specialist Will Reply)' started by LGMcCaw, Feb 18, 2012.

  1. LGMcCaw

    LGMcCaw Private E-2

    It's a friends computer, brought it to me because it was running very slow and had numerous popups when browsing internet. She had run SuperAntispyware and security essentials and one of them had removed something, but she'd deleted the logs. So, here we are......

    I've attached a SAS log, and a MalwareBytes log. Combofix is going into limbo - it extracts and then diappears, no error message or anything. RootRepeal begins a scan, but throws an error - the error window is transparent. I can see the window behind it, it's just a frame no buttons or text. There is a red X, I click on it 4 times and closes, along wih thte main rootrepeal window. MGTools completed and I'll attach those log files also.

    I've also run checkdisk on both partions (The system drive C: and the recovery partion D:), it came up clean.

    Thanks in advance!
    L.G.M.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you attached two logs from SAS. Do you have the log from Malwarebytes.

    The reason the PC is slow is that there is way too little free memory to run anything. Your logs show the below:
    Code:
    Installed Physical Memory (RAM) 1.00 GB 
    Total Physical Memory 0.99 GB 
    Available Physical Memory 97.1 MB 
    If you look at Task Manager, which processes are using the most memory? Is it your browser?

    Do you have a log from TDSSkiller to attach? I see you ran it.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's also try to free up memory by uninstalling a few non-malware programs now. These can always be reinstalled again later once you have resolve the reasons for excessive memory use. Also note, we recommend 2 to 3 GB of memory for Vista anyway, so 1 GB is too low to start with.

    Uninstall the below:
    Google Earth
    Google Update Helper
    iTunes
    Java(TM) SE Runtime Environment 6
    Malwarebytes Anti-Malware version 1.60.1.1000
    Microsoft Security Client
    Microsoft Security Essentials
    SUPERAntiSpyware
    WeatherBug


    Also run HijackThis to fix the below indicated entries. Note that some/many of these may not be seen if the uninstalls above worked properly.
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
    R3 - URLSearchHook: MHURLSearchHook Class - {1C4AB6A5-595F-4e86-B15F-F93CCE2BBD48} - C:\Program Files\Family Toolbar\tbhelper.dll
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: MHTBPos00 - {0C37B053-FD68-456a-82E1-D788EE342E6F} - C:\Program Files\Family Toolbar\tbcore3.dll
    O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll
    O3 - Toolbar: Family Toolbar - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - C:\Program Files\Family Toolbar\tbcore3.dll
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    After clicking Fix, exit HJT.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. LGMcCaw

    LGMcCaw Private E-2

    Thanks for the help & quick response!

    As requested, I uninstalled the apps, SAS uninstaller threw an error, took me to a website, then disappeared from the installed programs list. Combofix still runs the extraction process then ends up in limbo, no errors just nothing.

    Rootrepeal is still beginig the scan, then throws an error and creates a bunch of crashdump files on the desktop. The error dialog is transparent, just a frame. I've attached the missing mbam logs and the mgtools logs. Also one of the crash dump files from rootrepeal. I also included a tdsskiller log. The machine seems a little more responsive and soon as it's clear I'll add some additional ram.

    Anything else, just let me know,

    L.G.M.
     

    Attached Files:

  5. LGMcCaw

    LGMcCaw Private E-2

    For got to answer your other question - according to task manager when I looked SVCHOST.EXE is using the most ram at 45,540k, then
    IExplore.exe @ 42,296
    Explorer.exe @ 17,224
    2nd SVCHost.exe @ 11,450
    dwm.exe @ 10616

    Hope that helps!
    L.G.M.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it looks like the steps we took to uninstall a bunch of programs and the items we removed from Startup have increase your free memory a bunch so things are should be better right now.
    Code:
    Installed Physical Memory (RAM) 1.00 GB 
    Total Physical Memory 0.99 GB 
    [B][COLOR=darkgreen]Available Physical Memory 263 MB[/COLOR][/B]
    But you are running with no protection which is not a good idea. You need to triple your memory.

    Let's run another scan to dig a little deeper.

    Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows Vista boot DVD and another when you have your DVD.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.


    Option1: Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    Option2: Enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:

    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  7. LGMcCaw

    LGMcCaw Private E-2

    Yes things are much improved, and I'll bump up the ram for her soon as we're done. I've attached the results from the latest scan. Thanks again, looking forward to being done with this one.

    L.G.M.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. This last log is also clean.

    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  9. LGMcCaw

    LGMcCaw Private E-2

    Thank you very much! I'll get the cleanup procedures done ASAP. Any idea why ComboFix and RootRepeal still don't run to completion? Could it be the shortage of memory? Combofix still just goes off into space, and rootrepeal just throws a bunch of crashlog files on the dektop and stops. If karma is one of those things that come back to you, you should be in great shape!

    Take care,
    L.G.M.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rootrepeal always has had problems running on many PCs. If I had to guess I would say it just fails to run about 40% of the time and it has nothing to do with malware. ComboFix sometimes runs into similar problems but much much less frequently. You could attempt to run ComboFix in safe boot mode. Sometimes this works because other software or drivers that could be causing a conflict, are not loaded in safe mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds