Computer crippling malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by kenzopersona, Aug 16, 2008.

  1. kenzopersona

    kenzopersona Private E-2

    Basically, this started out with my friend's mom seeing if I could fix her computer. After doing disk cleanup, disk defragmenter, and the things mentioned in the basic computer maintainance that everyone should do, I quickly reealized that there must be viruses or malware on the system. On my own I tried spybot, Norton, and avast. Only spybot found something. Result was still the same: an extremely slow computer.

    Somewhere along the line, the internet stopped working. You could only use it in safe mode. So upon googling for an answer I found your malware removal guide. I followed everything in the guide. Spybot found FunWebProducts and MyWayMyWebSearch but could not remove it even when running on system startup. The other tools were able to remove malware. The laptop ran normally until MGtools had to restart, then it was back to normal. I tried defragmenting and used CCleaner to fix 263 registry issues. Still no luck.

    So here are the symptoms. It takes about 4 minutes to load up desktop from login. It takes about 5 minutes to load up a program that you double click. Also, I have a duplicate of internet explorer on the laptop. I'm not sure if it was always there, but I don't think it was. The system activity light remains solid. Most of the pagefile is being used.

    Any help would be greatly appreciated.
     

    Attached Files:

  2. kenzopersona

    kenzopersona Private E-2

    Here is another log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    While you did have some malware that got removed while running the READ & RUN ME, they were not issues that would slow a PC down. I expect your issues are either just due to what you are running or due to hardware or software issues on your PC.

    You should however delete the below file:
    C:\WINDOWS\005932_.tmp

    And also delete the below folders:
    C:\962e0f5eb4218130b6d9560defc6c7
    C:\0c18fd5033729c0cbaec9120b4
    C:\Program Files\Alwil Software

    You can uninstall SUPERAntiSpyware now since we are finished with it. I also recommend uninstall Ad-Aware to avoid wasting any resources on it to since it is just not that useful anymore. If it came down to a choice for a backup scanner you would be much better off dumping Ad-Aware and keeping SUPERAntiSpyware.

    You next options to look at to see what effect they have would be to uninstall Windows Defender and then reboot to see if anything changes. If not, then you could try running the below, reboot and run it one more time to get rid of all the Symantect Software to see if it is the cause of your poor performance.

    Norton Removal Tool (SymNRT)
     
  4. kenzopersona

    kenzopersona Private E-2

    Thank you for your help. There wasn't much change in performance when Windows Defender was uninstalled, but there was a major improvement when norton was taken off. Startup is still a little sluggish but once everything is loaded up, it runs pretty quickly. Page file using is at 133mb instead of the 300-400mb from before. Is it alright to re-install Windows Defender in order to manage my startup items? how good is windows defender as a spyware scanner? Thanks again for your help.
     
  5. kenzopersona

    kenzopersona Private E-2

    Never mind about Windows Defender. I found out from one of the guides that it was inadequate. Thanks for the help. I uninstalled the tools used in the malware removal guide and have put avast antivirus, comodo firewall, and spybot on the laptop.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay hopefully you are referring to the How to protect yourself from malware sticky thread which you should run through.

    As far as managing startups, step 1 of the READ & RUN ME gave you the below link:

    Dealing with Startup Processes


    Just to make sure you are properly cleaned up from running the READ & RUN ME, here are the normal final instructions.

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds