laptop infected win32:dialer-ABP

Discussion in 'Malware Help (A Specialist Will Reply)' started by gibbyr@t, Dec 30, 2012.

  1. gibbyr@t

    gibbyr@t Private E-2

    Hi - I did an Avast scan today as my laptop has been running slow for a while, especially when using Chrome, and it came up with a Win32:Dialer -ABP [Trj] infection which it put in the virus chest.

    I'm not sure whether it's gone or not though - I've run all the scans from the malware removal guide, and some of them seemed to indicate there was a problem - can anyone help? The logs are attached.

    Let me know if you need more info - thanks for your help :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    All or your logs are clean.

    Your slow PC is just that! It is a slow old PC with inadequate memory to properly run current modern day Windows XP SP3 and other software. It was sort of fine in 2004, but not anymore.

    Your logs show the below:
    Code:
    Processor x86 Family 6 Model 13 Stepping 6 GenuineIntel ~1294 Mhz 
    BIOS Version/Date Dell Inc. A11, 16/08/2005 
    Total Physical Memory 768.00 MB 
    Available Physical Memory 184.27 MB
    We recommend a minimum of 2 GB ( equal to 2048 MB ) or memory. You have just a little more than 1/3 of that. And your processor is old and slow.

    Everytime you update Windows and other applications there is an effect. Eventually the effect is the same as "the straw the breaks the camel's back".

    Per the below, it looks like your PC may be upgradeable to 2GB which could extend the useful life of the PC, but it is simply gettng to old and the processor will still be old:

    http://www.crucial.com/upgrade/Dell-memory/Inspiron+Laptops%2FNotebooks/Inspiron+510m-upgrades.html
     
    Last edited: Dec 30, 2012
  3. gibbyr@t

    gibbyr@t Private E-2

    Thanks for your help - yeah, I know my computer is ancient :-o luckily I've budgeted for a new one in 2013 so it's nearly ready for retirement :)

    Good to know it's clean though - it did seem to be running even slower than usual, but I guess like you say it only takes one update to overload the poor thing.

    Thanks again :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Well if you want to improve the startup time and overall performance while you wait to get the new PC, you can do the below. This is not a malware fix. It is just some tips/tricks to remove things you don't need.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Liz Sargeant\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    After clicking Fix, exit HJT.

    Also you don't need the below services from Google to be running:

    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    But you cannot simply stop these with HijackThis. You would need to do the below to first stop them and then disable them.


    Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

    sc stop gupdate
    sc delete gupdate
    sc stop gupdatem
    sc delete gupdatem
    sc stop gusvc
    sc delete gusvc

    Then reboot your PC and check to see what kind of performance improvement there may be. It should help somewhat but it may not be night and day difference. When you free up memory from one program not running, other programs tend to grab more than previously used. Thus when you have so little memory in a PC, it can be difficult to make it significantly better.
     
  5. gibbyr@t

    gibbyr@t Private E-2

    Thanks for that, it has actually helped a bit, certainly my browser was faster to open, it still hung for a while after opening, but not as badly as it was before. Makes life a bit less frustrating!

    Much appreciated :)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.



    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds