PC running slow, suspected malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nebraindur, Dec 10, 2012.

  1. Nebraindur

    Nebraindur Private E-2

    Howdy guys/gals.. first time MajorGeek-er here.

    I've been having a problem with my whole system slowing down/running very slowly. Windows are slow to "fade-in/fade-out" in that Windows 7 Aero style, and in general everything runs very slowly. It reminds me of times I had certain processes in the background running at high levels.

    I've run Avast! Antivirus on a boot scan with no virus found.
    I've run the five or so programs the sticky recommends. Logs Attached.

    This has happened once before (the PC running slowly in this way).
    The fix then occurred sometime after a marathon of scanning with avast!, Malwarebytes, TweakNowRegCleaner2012 (recommended by a friend via your site), and a Windows update.

    To clarify: these have all been done again to no avail. Also, when I search via the firefox opening page, the search page is minimalistic and displays "Claro" in the top right corner (this makes me suspect malware/spyware, but I'm no computer expert :-/) Thanks for any help in advance!
     
  2. Nebraindur

    Nebraindur Private E-2

    Sorry, it's not showing the attachments. Trying again:
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  4. Nebraindur

    Nebraindur Private E-2

    Hey there! Thanks for answering. And sorry for the late response (7a-7p worker).

    Here's the file:
     

    Attached Files:

    • JRT.txt
      File size:
      6.4 KB
      Views:
      4
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rescan with Hitman and have it delete Potential Unwanted Programs if it shows any.


    Some of these lines may or may not appear - check anyway.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    After clicking Fix exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. Nebraindur

    Nebraindur Private E-2

    I ran the Hitman program as directed. Nothing found.

    Hijackthis only found the third file to delete:
    ( O20 - AppInit_DLLs: c:\progra~3\browse~1\24897~1.175\{61d8b~1\browse~1.dll)

    Claro still redirects from my Firefox open page browser.

    To note, there was one "string" similar to the second listed deletion request, and none like the first. Logs for the scans here:
     

    Attached Files:

  7. Nebraindur

    Nebraindur Private E-2

    For the record: after going to sleep Tuesday night and waking for work Wednesday morning, my PC had restarted claiming it was for a windows update, running at normal speed again. I don't know what this is about (though I'm glad it's back to normal speed) since I updated all my windows update options and provided a restart some time monday midday @.@

    Claro's still here though :-/
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.

    Also...


    Run this and attach the results.

    Using ESET's Online Scanner
     
  9. Nebraindur

    Nebraindur Private E-2

    Here are the scan files:
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code

    Code:
    :otl
    IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerms}&affID=114508&tt=4412_5&babsrc=SP_clro&mntrId=6ccb82b8000000000000001fbc08f4c3
    @Alternate Data Stream - 1219 bytes -> C:\ProgramData\Microsoft:TvSf0AMyvZNsETLkAPSQX0Nf
    @Alternate Data Stream - 1163 bytes -> C:\ProgramData\Microsoft:itIydtVr6tLBSRkLLE7ZqaWk
    @Alternate Data Stream - 1077 bytes -> C:\Users\Devin\AppData\Local\Y8XgV2Nu3SCG:CygY8Cg5roYrIGTnYSpB
      
    :commands
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.

    is claro gone now?
     
  11. Nebraindur

    Nebraindur Private E-2

    OTL ran per instructions.

    Claro still redirects from Firefox homepage search.

    No notepad file opened upon restart :-/
    Looking for it now.

    P.S. Important to note (maybe), I don't see OTL on the computer at all while searching for the notepad file.

    Edit: Found it! (.exe of OTL still not found though, interestingly)
     

    Attached Files:

    Last edited: Dec 14, 2012
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if running the below helps:

    Reset Firefox to Defaults
     
  13. Nebraindur

    Nebraindur Private E-2

    Well hot dang! It works... and everything seems to be up to speed. Thank you both, so so much, for the long process and immense help!

    Thank you
    Thank you
    Thank you X-D

    Do either of you happen to be Steam users/gamers?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not us, no. :) More of a PS3 girl myself. Chas is too much of a busy man for gaming.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  15. Nebraindur

    Nebraindur Private E-2

    Done and done! Thanks again, mmmmmassively!

    Was going to gift a game or some such digital something as a thank you; steam was my only notion in that vein *shrug*

    Nonetheless, Thank you both!
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are so welcome, and thanks for such a kind offer. That's lovely. Take care and surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds