New problem, possible rootkit

Discussion in 'Malware Help (A Specialist Will Reply)' started by BaldEagle, Aug 10, 2014.

  1. BaldEagle

    BaldEagle Private E-2

    I've been noticing that everything on my laptop (XP) has been running noticeably slower recently. (2-3 weeks)
    Opening software, closing it, switching browser tabs, opening a directory window - anything, is accompanied by a significant delay, and a LOT of HDD spinning.

    I was getting low on HD space, so I deleted or moved a lot of old setup/installation files, and whatever else seemed to be taking up space and I didn't need on the actual laptop.

    I came across a few files and/or directories that were locked, so I used an unlocker and Eraser to try to delete this. Some success, some not.
    I have 2 directories in my Recycle Bin that I can't delete, and when the unlocker tries to delete them, it says it is successful, but another directory with a similar name immediately appears. Dd276, Dd271, etc.

    I ran all the programs in the READ & RUN ME FIRST thread, and it looked like there were a bunch of notifications in the result tab for rootkit - type malware.

    I haven't touched anything yet, as instructed.
    I'm hoping someone can let me know what to do next.
    Thanks for the help! - I appreciate the amount of effort and dedication it takes to run a volunteer site like this.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your problems are not due to malware. You only have a little bit of junkware that we will cleanup down below. Your main issues are the below related to PC specs
    Code:
    Processor x86 Family 6 [COLOR=red][B]Model 28 Stepping 2[/B][/COLOR] GenuineIntel ~[COLOR=red]1596 Mhz[/COLOR] 
    Total Physical Memory [B][COLOR=red]1,024.00 MB[/COLOR][/B] 
    Available Physical Memory [B][COLOR=red]212.38 MB[/COLOR][/B] 
    This is an old slow PC with insufficient memory the proper run modern applications efficiently. If you wish to continue to extend the useful life of this PC, the best thing to do would be to added another 2GB of memory if it can support it.


    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java(TM) 6 Update 22

    Now install the current version of Sun Java from:
    Make sure that when you install the new version of Java that you uncheck the Install the Ask Toolbar junkware checkbox. Also if it asks if you want to install McAfee Security Scan Plus that you uncheck this too. You do not need to add these unncessary items and to your PC. Also just in case Oracle changes the Java installation in the future to possibly install other junk, uncheck all but just installing Java.
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
    R3 - URLSearchHook: (no name) - {650598e1-b35a-45d3-b607-896d7acb64c3} - (no file)
    O2 - BHO: (no name) - {2D80D778-D383-41AF-BBB9-AD9E303F8AE2} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {8232785C-5C98-4A6E-B7B4-911FFBED7582} - (no file)
    O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)
    O3 - Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - (no file)

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Documents and Settings\Drew\Application Data\Mozilla\Firefox\Profiles\iq59la8j.default\smartbar
    C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    C:\WINDOWS\Temp\*.*
    C:\Documents and Settings\Drew\Local Settings\Temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escortApp.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escortEng.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escorTlbr.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\esrv.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Prod.cap]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_BROWSERPROTECT]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_BROWSERPROTECT]
    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BROWSERPROTECT]
    [-HKEY_USERS\S-1-5-21-2650805779-4212676017-31143968-1005\Software\SmartBar]
    [-HKEY_USERS\S-1-5-21-2650805779-4212676017-31143968-1005\Software\Softonic]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. BaldEagle

    BaldEagle Private E-2

    Thanks for the super-fast reply! And on a Sunday, even. :O

    I deleted the Java 6 file, but couldn't run the Java tool due to an error.

    "The procedure entry point RegDeleteKeyExA could not be located in the dynamic link library ADVAPI32.dll"

    access was denied to hiberfil.sys, pagefile.sys, and System Volume Information during one of the scans.

    On the positive side, Opera Next seems to be showing vastly improved performance, as I can now cycle through the 12 open tabs very quickly rather than expecting a 10-30 second HDD-thrashing with each click.

    Sure, it's "old" and "slow", but I squeeze every last kb and Hz of use out of it that I can. Oftentimes, it's not what you've got, it's what you do with it.

    Any insight on the weird undeletable folder issue? They appear to have "deleted themselves" - but it troubles me....

    What do I have to do now?

    Thanks so much for the excellent assistance!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes but you are running without proper antivirus and antispyware protection and the poor excuse of a firewall from Windows XP. And this is even made worse since Windows XP is not supported anymore and does not get updates and security patches. If you install protection ( which you really need ) your PC is going to crawl without having more memory.

    Not problems. Windoes creates folders for its own use in the Recycle Bin.

    Just the below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  5. BaldEagle

    BaldEagle Private E-2

    Well, let's be honest - it's a poor excuse for an operating system.
    My ex-wife stole my other laptop and Android tablet .... along with the house and everything in it, so this is what I have to use for now.
    "Crawl" is a relative term. I'll work on beefing up the system and see what happens. I started out with a Timex Sinclair 1000, so ....

    Once again, Thanks for all the help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes and it will be alot more relative when/if you install proper protection. ;)
     
  7. BaldEagle

    BaldEagle Private E-2

    Just went to run Arduino software. Couldn't.
    Rebooted. Tried to run again. "Error. Access is denied"

    Same with an Open office spreadsheet.

    Reinstalled Arduino - that works.
    Reinstalled Open Office 4.1.0 - unresponsive desktop icon, nothing happens when I click on the program file executable.

    I haven't hunted down and tried other software, but I find this strange to have this just start happening...

    Any recommendations for further action?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes for non-malware related problems like this please post in the Software Forum. There were no major malware issues in your previous logs. Just some miscellaneous junkware. Thus your problems are more likely related to Windows itself or the applications you have installed having problems for some reason. It is also possible that you are hitting a point where the available memory is getting too low.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds