slow laptop

Discussion in 'Malware Help (A Specialist Will Reply)' started by watech, Oct 20, 2010.

  1. watech

    watech Private E-2

    Hello fellow geeks :major

    My specific geekiness is more biology based so i turn to the tech division for assistance for my current problems!

    My laptop has been infected for a while now and as a result I have stopped logging into any accounts on it but this is really REALLY inconvienient so I have decided to deal with the problem head on: Initially I had a virus that would run the process 'iexplore.exe' and give me random pop-ups and provide random audio adverts. I ran a few scans and that got rid of these symptoms but unfortunately the underlying condition still remained i.e. iexplore.exe running in the background.

    So i registered here and ran through the comprehensive set of scans provided in the 'run and read me' guide. Most of the scans seem to have come back clean, apart from combo-fix which detected a bootkit (I have two combo-fix scans as i had accidently left the firewall on in the first scan). However now my pc is very slow at start-up; could this purely due to the fact that I reverted the msconfig option to 'normal start-up' from 'selective'?

    I have attached the logs and would be grately appreciate any help given!
     

    Attached Files:

  2. watech

    watech Private E-2

    The rest of the logs.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread

    Now run this:

    Using BitDefender Online Scan
     
  5. watech

    watech Private E-2

    Hi Kestral!

    Thank you for offering to help me.

    I have run the MBRcheck which produced a log but couldn't run the BitDefender scan, even after several attempts, as the same message kept popping up: 'This webite is not authorised to host this ActiveX control. Please contact the webmaster of this website or report to Bit Defender at the email address: scanonline@bitdefender.com' and the 'start scan' button became unresponsive. :confused
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  7. watech

    watech Private E-2

    Hi Kestral!

    I'm sorry I havent replied sooner, I was in imminent of being buried alive under my paperwork!

    I actually ran the scan twice: The first time it seemed to be stuck at 40-something percent for a while (total scan time had gone past the three hour mark) so I restarted it. During the initial scan it had found a couple of threats that it didnt pick up the second time but were present in the quarantined files section so I copied them into the scan log produced for the second scan.


    Thank you for all your help.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    We'll do this because you have AVG now and CA is no longer installed, this is just a leftover service.

    Open notepad and copy and paste the following text in the quote box into the window:

    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Navigate to:

    c:\program files\CA\CA Internet Security Suite <--- Delete the whole folder.

    Now tell me what malware issues remain? (I think Combofix dealing with bootkit sorted you out)
     
  9. watech

    watech Private E-2

    Thanks for the quick response!

    I've deleted the above as you instructed. It's good to hear the problem seems to be gone but one issue remains....the laptop has become incredibly slow, booting up now takes around 6-7 mins and opening a few tabs in a browser almost sends it into meltdown. Could this be as a result of selecting normal start-up in msconfig or may there be more sinister forces at play?
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:

    Any outstanding issues not related to malware can be further discussed in the software forum.
     
  11. watech

    watech Private E-2

    Hi Kestral!

    Thanks for all your help.....i've worked through the steps in your post so does that mean the laptop is OK? :celebrate

    The laptop is still slower than it was before but has speeded up somewhat so i could live with that for now. A non-malware isssue but i would like your opinion.....a couple of hours ago i dropped my laptop from around 4 feet! There was a fumble and it partly fell on my foot and partly on the carpet but seems to have come out unscathed......should i leave it be or get it checked out?

    Again many many thanks for all your help :-D
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, everything looks good.

    Should be okay as long as you are not experiencing any obvious problems!

    Most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds