Slow machine, junk mail gone out.

Discussion in 'Malware Help (A Specialist Will Reply)' started by BigShot, Jan 18, 2011.

  1. BigShot

    BigShot Private First Class

    I've just run the ReadMe procedure on a machine that has been running slowly for some time now.

    Intel Atom N280, 2GB RAM, Windows XP Home SP3.
    Hard drive has about 50GB (of 70 or so) free and just 1% fragmented.

    I uninstalled a few unneeded programs (some of them unnecessary stock EEE PC ones) which seemed to help things for a short but it's slowing down again.

    Earlier today a few email "Delivery Failure" messages came through - junk mail bounced back from dead addresses.

    I'd appreciate if someone could take a look over the logs and let me know if there's anything else that needs doing.


    (Oh, and if Kestrel reads this... Thanks for your help in my previous thread, things seemed better after the end of logs being posted on the first user account - and then the computer died completely and has since been replaced. Obviously there was little point continuing the thread after that. Thanks again.)
     

    Attached Files:

  2. BigShot

    BigShot Private First Class

    Zip attached.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the READ & RUN ME, slow machines are not always due to malware, which is the case here too. I suggest that you see how it performs in safe boot mode. Also see how it performs in normal boot mode if you uninstall Avast and ZoneAlarm. Then if still having problems post your results in the Software Forum and indicate exactly what operations are slow.
     
  4. BigShot

    BigShot Private First Class

    So, logs show nothing suspicious? That's handy.
    If not malware... any suggestion what might have caused the email account (hotmail) used on this machine to fire off a load of junk mail?

    I'll try your suggestions re: safe mode and uninstalling the antivirus and firewall... obviously that's not a long term solution though. What's the solution if it is the security software causing the slowness?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not in the logs we have thus far.

    Not sure. Let's see if a couple deeper scans for MBR infections or TDL infections find anything. I will give these instructions down below.

    Replace it with something else.;)


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )



    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • If TDSSKiller does not run, try renaming it. To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123tdk.com).
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  6. BigShot

    BigShot Private First Class

    Scans run, logs attached.

    It's possible that the problem arose elsewhere, that email account has also been used on a machine Kestrel is helping me with at the moment so if nothing comes of this it's not something to sink too much energy into... the junk went out at different times and contained different spam (maybe not unusual, I don't know) so not necessarily connected, but it's possible.

    Can you suggest a decent antivirus and firewall which are more lightweight than Avast and ZoneAlarm? I thought they were meant to be pretty easy going on system resources (not that it's particularly lacking with 2GB of RAM).
    Or is that a question for elsewhere?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also clean.

    Yes this is quite possible since all the logs here are clean.

    Avast is fine. ZoneAlarm became a resource hog log ago and also became much less highly rated long ago too. See the link in my final instructions for some suggestions.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  8. BigShot

    BigShot Private First Class

    As far as I can tell there's no other malware trouble.
    Thanks very much for your help on this and for your advice on firewalls. I hadn't heard that ZoneAlarm had become bloated. I've removed it and put Comodo in its place, Things seem to be a bit quicker now.

    Thanks again.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It is not just that ZoneAlarm became bloated. It is also not as highly rated as is once was. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds