Significant slow down

Discussion in 'Malware Help (A Specialist Will Reply)' started by tilas, Mar 3, 2013.

  1. tilas

    tilas Private E-2

    Hi,

    Background:
    It's a laptop of my parents, which I am trying to admin remotely (living in other country) through logmein service (https://logmein.com). I am not a computer expert, but can at least perform basic tasks and do speak English, as opposed to my parents.
    The laptop is used mainly for internet surfing, email and skype communication.

    The problem:
    A few days ago I got complaints about connection problems using skype and weird animations/promotions when trying to initiate a call. I have logged in remotely and noticed a very sluggish response. So I suspect there might be some infestation.

    HW:
    Asus Notebook K50u series with Pentium Dual Core CPU T4300 @2.1GHz
    4GB RAM

    OS:
    Windows 7 Home Premium x64 SP1

    To my knowledge there is no illegal/cracked/whatever software

    I have tried to follow the instructions from the read & run me first page. The logs are attached.

    I will be grateful for any advice.
    tilas
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run Hitman and have it remove all of those PUP's.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Program Files (x86)\Babylon

    I am not finding any malware in your logs. Tell me how things are running now.
     
  3. tilas

    tilas Private E-2

    Done. Asked to reboot. Rebooted.

    Ran the C:\MGtools\analyse.exe (HJT), but did not find any of the above.

    FixMe worked.
    Did not find Babylon in the said location. Searched and found only
    C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Plug_ins\Babylon

    Shall I remove it?

    Are the ten items that RogueKiller found previously ok?

    I see some improvement in response speed and parents could use skype without problems. Not sure what happened.

    Shall I activate the UAC now?

    BTW, I have noticed sort of two side effects:
    1. I see two more icons on the desktop now and what bothers me is that both are not links and imho should not be there (attached screenshot). The 'Victor' folder is a complete copy of C:\user\Victor. On my own laptop I only have a link to 'computer'

    2. There are many folders now that are locked (see screenshot) and I can't open them. I get the 'Access is Denied' message when I try. The Account is an admin and previously I could open everything.

    Many thanks for your help.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are going to have to pursue those issues in the software forum. All we did was remove the Babylon crap.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup

    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     
  5. tilas

    tilas Private E-2

    Hi,

    I ran the Windows Repair and it sure enough did something. However the locked folders remain locked (access denied) and the c:\user\victor is still on the desktop.

    If this is not a symptom of some nasty infection, I'll try to get help in the software forum as you suggested.

    Many thanks for your help and time!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds