Dell browsing slow possible spyware

Discussion in 'Malware Help (A Specialist Will Reply)' started by jerrygl, Aug 27, 2012.

  1. jerrygl

    jerrygl Private E-2

    My Dell has started to browse slowly as of late. I ran the usual scans then followed your malware guide before posting and noticed that I may have had something on it. I am confused by one flagged item by hitman, ultimate defrag...by disktrix. Please review the logs attached. Thank you in advance.
    I am running XPSP3 MSE and have 2.0 gig ram.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    http://img853.imageshack.us/img853/6741/addremovexp.gif From Add/Remove Programs (via Control Panel), please uninstall the below:
    • Java(TM) 6 Update 33 (outdated)

    You may also want to consider uninstalling the below as they may be actually slowing your computer down rather than increasing its speed:

    1. Ad-Aware SE Plus
    2. AML Free Registry Cleaner 4.21
    3. Ashampoo StartUp Tuner 2.00
    4. CleanUp!
    5. COMODO Registry Cleaner 1.0.17.23
    6. DefragExpress!
    7. Disktrix UltimateDefrag
    8. Easy Picture Notes
    9. eBoostr 4
    10. Eusing Free Registry Cleaner
    11. Eusing Free Registry Defrag
    12. FixBee Disk Optimizer
    13. Free CraigsList Reader Pro from CraigsPal 4.0.19
    14. FreshDiagnose
    15. Glary Registry Repair 3.2.0.828
    16. Little Registry Cleaner
    17. MailWasher Free 6.5.4
    18. Musicmatch® Jukebox
    19. MV RegClean 5.9 English
    20. Spybot-S&D Boot CD creator
    21. SUPERAntiSpyware
    22. SystemBooster 2.0
    23. TweakNow RegCleaner

    __

    I've only found very light traces of malware so far. Let's run this scan and we'll fix the very few items found afterwards.

    http://img194.imageshack.us/img194/4930/combofix.gif Please download and run ComboFix and attach its log.
    Read these instructions on how to use it: How to use ComboFix
    Do not uninstall ComboFix yet as we may need it to fix remaining malware issues.
     
    Last edited: Aug 28, 2012
  3. jerrygl

    jerrygl Private E-2

    Thanks for the reply thisisu,
    OK, I uninstalled java ver6 update 33 as you suggested. Ran Combofix as specified. Noted that there was a file that trying to attach itself to combofix as follows:
    c:\program files\Preton\Preton Saver\pt32.dll
    Preton is an ink saver program. I do not know specifically about the above named pt32.dll file though if it is legit or not.

    Now, for the hard part. As you can see I am fond of registry cleaners etc. I try various programs out then remove them and what I have found is that NONE of them remove themselves completely. Hence all the utilities you questioned.
    E-boostr and system booster as well as the defrag programs are legitimate which I paid for and in my mind at least they help. E boostr is like readyboost on Vista but even faster as I ran comparisons between the two AND best of all I can use it with XP as well.
    So, I will tell you what, if you can recommend ( I won't tell anyone) a couple of the best registry cleaners to use, I will get rid of the rest. Also I am looking for a nice little program to type in text on my photos :)
    I thought that TweakNow was a pretty well recommended cleaning program but you have it earmarked.
    So what do you think?
    Anyways, attached is the combofix log.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Use Windows Explorer to find and delete these files:
    • C:\Documents and Settings\Rudy\Local Settings\Application Data\7d2f06o35nhdm3kjnu6u6h0di58uv6566861rt
    • C:\Documents and Settings\Rudy\Templates\7d2f06o35nhdm3kjnu6u6h0di58uv6566861rt

    The rest of your logs are clean.

    __

    Legit, it was only disabled, not deleted.

    The only one I've used (sometimes) is the one built into CCleaner. You have to be very careful with the registry but I have never had any issue with CCleaner in the years I've been using it.

    __

    How about mspaint? ;)
    You may want to ask in the Software forum about something like this. Paint is small and can type text onto photos. Very basic photo editing.

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  5. jerrygl

    jerrygl Private E-2

    Hello again Thisiu,
    OK, everything done here. I ran all the uninstall programs you suggested. One question, how ever did you find/know about those two files? and where can I learn about this myself, those log files are quite daunting to look at.
    Two last items, one, why do the icons in the systray appear and disappear at their discretion upon bootup? Sometimes they show and other times they don't.
    Second, is there a way I can reduce the number of running processes? I have 38 before I even get started... I looked at many sites and there seem to be no consistency between them.
    Thank you.
     
  6. thisisu

    thisisu Malware Consultant

    Becoming A Malware Forum Helper

    http://cybertext.wordpress.com/2010/09/07/windows-show-all-system-tray-icons/
    Show all icons in the system tray, even inactive ones.

    Dealing with Startup Processes
     
  7. jerrygl

    jerrygl Private E-2

    Thanks for all your help Thisisu,
    Much appreciated to you and all the volunteers at the board.
    I am in the process of thinning out the utilities on my computer :)
    Best wishes.
     
  8. thisisu

    thisisu Malware Consultant

    You're welcome.
    Be safe.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds