Author Topic: My system is getting very slow  (Read 2909 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
My system is getting very slow
« on: May 29, 2015, 10:13:32 PM »
Hello,
My system is getting very slow. I've attached the logs here.

I'm not able to attach the aswmbr log as it has crashed twice. with the message "Avast! Antirootkit has stopped working". I'm attaching the screenshot of the same.

Any help from your end is much appreciated.

Thanks,
Bob

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: My system is getting very slow
« Reply #1 on: May 29, 2015, 10:25:01 PM »
Hello bobkayram and welcome to avast!. I will be working on your Malware issues. 

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper



---     ---     ---     ---     ---


Kindly note, maybe I do not get to answer you within 16h ...

We shall go with big boy so let's start ...



1. Please download ComboFix by sUBs () from here and save it to your Desktop.
If you are unsure how ComboFix works, read this guide.

--------------------------------------------------------------------
2. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:
• Right click on the avast! system tray icon () in the lower right corner of the screen and scroll up to avast! shield controls;
• In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.

Note:  Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.


--------------------------------------------------------------------
3. Run ComboFix. Then, on disclaimer window, click I Agree! button.

- ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

-If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
- ComboFix will scan your computer in stages, total of 50 stages.
Do not mouse-click around while ComboFix is running.
- If malware is detected, ComboFix will begin with its removal, and may need to restart Windows.
Note:If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart your computer.

--------------------------------------------------------------------
4. When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt)
=> Attach log report (ComboFix.txt) back to topic.

ComboFix shall also create addition log (typical location: C:\Qoobox\ComboFix-quarantined-files.txt)
=> Please attach that report (ComboFix-quarantined-files.txt) as well.


« Last Edit: May 29, 2015, 10:26:58 PM by magna86 »

REDACTED

  • Guest
Re: My system is getting very slow
« Reply #2 on: May 29, 2015, 11:28:11 PM »
Hello magna86,
Thanks for your guidances.
I'm attaching the Combofix logs.
Thanks
Bob

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: My system is getting very slow
« Reply #3 on: May 30, 2015, 06:11:36 PM »
Hello bobkayram,

How is the computer running now after the ComboFix runs? Things should be a lot better now. Lets run additional ARK scan ...




Please download Malwarebytes AntiRootkit (MBAR) and save it to your desktop.
For full instructions how MBAR works, read this article


> Doubleclick on the MBAR file () and allow it to run.
•  Click OK on the next screen, to allow the package to extract the contents of the file to its own folder named mbar.
•  mbar.exe will launch automatically. On some systems, this may take a few extra seconds. Please be patient and wait for the program to open.
•  After reading the Introduction, click Next if you agree.


•  On the Update Database screen, click on the Update button. Once you see 'Success: Database was successfully updated' click on Next
•  Under Scan Targets ensure all boxes are ticked. Then click the Scan button.

Notice: with some infections, you may see two messages boxes:
'Could not load protection driver'. Click 'OK'.
'Could not load DDA driver'. Click 'Yes' to this message, to allow the driver to load after a restart. Allow the computer to restart. Continue with the rest of these instructions.


>>  If malware is not detected, click the Exit button to close the program and post the mbar-log-year-month-day.txt and system-log.txt reports.

>>  If an infection/s are found ensure Create Restore Point are ticked. Then select the "Cleanup! button to remove threats.
•  The clean up procedure will be scheduled for process, pop-up will be shown.
Select the Yes button and the system should re-boot to complete the cleaning process.


>>  Notice: only if an RootKit are detected, ensure to run fixdamage.exe tool located in mbar folder, \Plugins\fixdamage.exe
- Run fixdamage.exe, at the black window to continue type Y (alias for Yes). Wait few seconds for execution ...
- When you see "press any key to exit" fix is completed, press any key to close the window. Reboot the system.





> The following reports will be created in mbar folder:
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt

Please post both logs in your next reply.

REDACTED

  • Guest
Re: My system is getting very slow
« Reply #4 on: May 30, 2015, 07:45:28 PM »
Hello Magna86,
The response time has improved after yesterday's fix.
I'm hereby attaching the mbar logs. By the way, no cleanup was required.
Regards,
Bob

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: My system is getting very slow
« Reply #5 on: May 30, 2015, 08:00:35 PM »
Yes, and systemlog shows no hardcoded rootkit activity.






Glad I could help. Posted logs appear cleans and show no signs of active infection. You should be good to go ...   

We're gonna remove my used tools now as well as carry out some further cleaning and security settings. To learn more about how to protect yourself I'll give you a few tips for reading. 



The following will implement some post-cleanup procedures:



---     ---     ---     ---     ---



It is necessary to uninstall ComboFix :

  • Click Start (or ) then Run.
    On Windows7 or Vista you may use Start Search field if Run is not available.

  • In the line of text type in (Copy) the following:
Code: [Select]
ComboFix /Uninstall
    Note that there is a space between " ComboFix " and " /Uninstall " .

    • then click OK (or press Enter ).
    Wait for the uninstall process is complete. This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore to prevent reinfection from old restore points.


    ---     ---     ---     ---     ---


    Please download DelFix by Xplode to your Desktop.

    Run the tool and check the following boxes below;
    Remove disinfection tools
    Create registry backup
    Purge System Restore

    Click Run button and wait a few seconds for the programme completes his work.
    At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

    The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
    Tool deletes old system restore points and create a fresh system restore point after cleaning.





    Tip: Do not use security tools such as ComboFix, FRST, Zoek and the like. These are advanced security tool, should not be used without supervision.



    ---     ---     ---     ---     ---



    Learn how to protect yourself:



    =>  In order to stay protected it is very important that you regularly update all of your software and Windows Operating System.

    It is important that you visit Windows Update regularly.
    How to configure and use Automatic Updates in Windows

    It's vital that you keep all your software up-to-date as older versions may have some security vulnerabilities. Keeping Java and Adobe update is priority.
    Download and install latest version of Java
    Download and install latest version of Adobe Reader




    =>  I recommend that you use one of the fantastic opportunities provided by avast! AntiVirus.

    For security protection, an active AntiVirus is required. If you want to reinforce your security setup I recommended additional security software and utilities:
    Download and install Malwarebytes' Anti-Malware and perform 'Threat Scan' from time to time. Malwarebytes will detect and remove all traces of known malware.
    Download and install MCShield Anti-Malware Tool to prevent infections transmitted via removable drives.
    Download and install Unchecky to keeps your checkboxes clear by preventing installing additional adware and other PUP bad software.
    Download and install AdBlock for safe web browser surfing without annoying and malicious advertising ads.




    Extra text for reading:

    Please visit and review PC Safety and Security - What Do I Need? for some helpful information.

    Please visit FAQ - Answers to common security questions - Best Practices to read tips how to protect yourself against malware infection.

    You may also visit and read What to do if your Computer is running slowly? if you like to read some basic geek stuff.




    The specific type of infection:

    Meet CryptoPrevent. Security app that shall attempt to prevent dangerous malware that encrypts certain types of files stored on your disk, like CryptoWall, CryptoLocker and simular clones.

    More information about this family of malicious software: CryptoLocker Ransomware Information Guide and FAQ
    Cryptolocker Ransomware: What You Need To Know and CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ











    Stay safe. 

    REDACTED

    • Guest
    Re: My system is getting very slow
    « Reply #6 on: May 30, 2015, 08:19:44 PM »
    I've uninstalled the combofix and the DelFix-ed the system as you've instructed.

    My sincere thanks to you and the team, magna86 for the wonderful support and timely help. Now the system seems to have get some extra legs.
    Have a great weekend!
    Regards,
    Bob

    Offline magna86

    • Anti Malware Fighter
    • Avast Evangelist
    • Massive Poster
    • ***
    • Posts: 4235
      • Ambulanta MyCity Forum - ASAP Member
    Re: My system is getting very slow
    « Reply #7 on: June 01, 2015, 06:56:33 PM »
     ;)