Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Sluggish computer - please help


  • This topic is locked This topic is locked
40 replies to this topic

#1 Ervin T

Ervin T

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:10:06 AM

Posted 04 February 2016 - 06:29 PM

Hello,

 

Not sure if I'm infected but my computer is very sluggish. Loading of Firefox is very slow and as well as gmail often at times not responding. I've not seen any signs of malware none that I'm aware of but would like to you check my logs just in case. TIA.

 

-I'm not able to post the contents of FRST log.

Attached Files


Edited by Ervin T, 04 February 2016 - 06:30 PM.


BC AdBot (Login to Remove)

 


#2 olgun52

olgun52

  • Malware Response Team
  • 3,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:06 PM

Posted 05 February 2016 - 03:54 AM

Hello Ervin T and Welcome to the BleepingComputer. :welcome:  
 
My name is Yılmaz and I'll help you with the cleanup of malware from your computer.

Before we move on, please read the following points carefully.

  • Please complete all steps in the specified order.
  • Even if tools don't find malware, I want you to post the logfiles anyway.
  • Please copy and paste the logfiles directly into your posts. Please do not attach them unless you are instructed to do so.
  • Read the instructions carefully. If you have problems, stop what you  were doing and describe the problems you encountered as precisely as  you can.
  • Don't install or uninstall software during the cleanup unless you are told to do so.
  • Ensure your external and/or USB drives are inserted during always the scan.
  • If you can't answer for the next few days, please let me know. If  you haven't answered within 5 days, I am assuming that you don't need  help anymore and your topic will be closed.
  • If you have illegal/cracked software, cracks, keygens, etc. on the system, please remove or uninstall them now!
  • I can not guarantee that we will find and be able to remove all  malware. The cleaning process is not instant. Please continue to review  my answers until I tell you that your computer is clean
  • Please reply to this thread. Do not start a new topic
  • As my first language is not English, please do not use slang or idioms. It could be hard for me to understand.
  • Please open as administrator  the computer. How is open as administrator  the computer?
  • Disable your AntiVirus and AntiSpyware applications, as they will  interfere with our tools and the removal. If you are unsure how to do  this, please refer to get help here

Thanks
     
I am currently reviewing your log.I will be back with a fix for your problem as soon as possible.Please be patient with me during this time.
 
Sincerely
:hello:


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#3 olgun52

olgun52

  • Malware Response Team
  • 3,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:06 PM

Posted 05 February 2016 - 05:05 AM

Hi Ervin T,
 

ICBC Infosec CertEnroll Plugins (HKLM-x32\...\icbc_infosec_certenroll) (Version:  - )
ICBC Infosec NetSign Plugins (HKLM-x32\...\icbc_infosec_netsign) (Version:  - )
icbc_ft_usbkey_plugins (HKLM-x32\...\npFTPlugin-5FEFB4B0-398A-4911-8354-0050ACA18ED7) (Version: 1.0.13.1230 - Industrial and Commercial Bank of China)
icbc_gd_usbkey_plugins (HKLM-x32\...\B4A5AD2B915E4DA981ED7060E6B1EF4F) (Version:  - )
icbc_hh_usbkey1g_plugin (HKLM-x32\...\icbc_hh_usbkey1g_plugin) (Version: 1.0.0.5 - Industrial and Commercial Bank of China)
icbc_hh_usbkey2gchinese_plugin (HKLM-x32\...\icbc_hh_usbkey2gchinese_plugin) (Version: 1.0.0.6 - Industrial and Commercial Bank of China)
icbc_hh_usbkey2gmultilanguage_plugin (HKLM-x32\...\icbc_hh_usbkey2gmultilanguage_plugin) (Version: 1.0.0.9 - Industrial and Commercial Bank of China)
icbc_mw_usbkey_plugins (HKLM-x32\...\ICBC_Ukey_plugin) (Version: 1.0.0.17 - Industrial and Commercial Bank of China)
icbc_tdr_usbkey_plugins (HKLM-x32\...\HAAAAAAA-AF3F-431a-B683-A12C772E725Q) (Version:  - )
ICBCChromeExtension (HKLM-x32\...\{5A171EA2-5DBA-4F72-8E4D-8A6D05EE06CE}) (Version: 1.0.4.0 - ICBC) <==== ATTENTION
ICBCEBankAssist (HKLM\...\{EB0A6239-BE34-4E94-9CDE-4E716A684265}) (Version: 1.5.3.0 - Industrial and Commercial Bank of China)
ICBCEbankPlugins (HKLM-x32\...\{179FBE63-24A3-44FF-9B7C-28AA59D2F112}) (Version: 1.0.5.0 - icbc)
ICBCSetupInput (HKLM\...\{C6436884-D620-4213-A7AD-5FE1FCB36D2E}) (Version: 1.0.029 - Industrial and Commercial Bank of China)

Do you use this software. Is it safe for you?
ICBC Chrome Extension must remove
==================================================

C:\Users\Owner\Documents
C:\Users\Owner\Downloads

There are file a lot in this folders
Check them out and remove ones unnecessary
 


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#4 Ervin T

Ervin T
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:10:06 AM

Posted 05 February 2016 - 01:30 PM

Hello Yilmaz,

 

Please help remove ICBC from system. As for the downloads folder, I've deleted the contents of it.



#5 olgun52

olgun52

  • Malware Response Team
  • 3,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:06 PM

Posted 05 February 2016 - 03:46 PM

Hello Yilmaz,

 

Please help remove ICBC from system. As for the downloads folder, I've deleted the contents of it.

Can I remove all the files above?


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#6 Ervin T

Ervin T
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:10:06 AM

Posted 05 February 2016 - 03:48 PM

Yes, please.



#7 olgun52

olgun52

  • Malware Response Team
  • 3,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:06 PM

Posted 05 February 2016 - 04:09 PM

Please If can you see, delete (With RevoUninstaller free) ===> Tendyron Corporation Folder. Please check.


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#8 olgun52

olgun52

  • Malware Response Team
  • 3,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:06 PM

Posted 05 February 2016 - 04:28 PM

Hi Ervin T,

 

 Ensure your external and/or USB drives are inserted during the scan

 

Step 1:
 FRST Script:
 Please download this attached Attached File  Fixlist.txt   18.21KB   2 downloads and save it in the same directory as FRST.

  • Start FRST with Administrator privileges.
  • Press the Fix button.
  • When finished, a log file (Fixlog.txt) pops up and is saved to the same location the tool was run from.
    Please copy and paste its contents in your next reply.

Step 2:
 Please download AdwCleaner by Xplode onto your desktop.

  • Double click on AdwCleaner.exe to run the tool.
  • Click on Search, then Clean.
  • A logfile will automatically open after the scan has finished.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Step 3:
Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista / 7 / 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Step 4:
 Scan with Malwarebytes Antimalware:

Please download Malwarebytes Anti-Malware to your desktop.

  • Double-click the downloaded setup file and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
  • Launch Malwarebytes Anti-Malware
  • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply

Step 5:

ComboFix run:

Please be sure to run our tools with administrator rights.

* IMPORTAN: 1   Place ComboFix.exe on your Desktop

* IMPORTAN: 2   Ensure your external and/or USB drives are inserted during the scan

Next, download ComboFix Save to the Desktop

  • Disable all antivirus and antispyware programs. Get help here
  • Now, close all open windows
  • Double-click combofix.exe to run the program
  • Follow the prompts.
  • If the option is offered, it is in your best interest to allow the download and install of the Recovery Console when prompted.
  • When told that the RC is installed correctly, press YES to continue scanning for malware.
  • ComboFix will run. Please don't click on the window while the program is running, it may cause your system to stall.
  • CF may reboot the computer and resume running when it restarts.
  • When finished, a log, ComboFix.txt, is produced.

Please provide the contents of the ComboFix report in your reply.

 

Have a nice day.

 


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#9 Ervin T

Ervin T
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:10:06 AM

Posted 05 February 2016 - 04:31 PM

Please advise what you mean by below as I only have usb keyboard and mouse plugged in.

 

 Ensure your external and/or USB drives are inserted during the scan



#10 olgun52

olgun52

  • Malware Response Team
  • 3,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:06 PM

Posted 05 February 2016 - 05:36 PM

Just external and/or USB drives


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#11 Ervin T

Ervin T
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:10:06 AM

Posted 08 February 2016 - 02:36 PM

FRST is stuck and not responding

 

Nevermind, it went away. Will continue with your instructions.


Edited by Ervin T, 08 February 2016 - 02:45 PM.


#12 olgun52

olgun52

  • Malware Response Team
  • 3,791 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:06 PM

Posted 08 February 2016 - 04:32 PM

Okay.


Best regards
 
paypal.gif
If you wish to show appreciation and support me personally fighting against malware, then you can consider a donation. Thank you. :thumbup2:
Malware fix forum
If I don't reply within 24 hours please PM me!

 


 


#13 Ervin T

Ervin T
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:10:06 AM

Posted 08 February 2016 - 04:34 PM

I will post the requested logs shortly as I had to run Combofix again as I forgot to save the log.



#14 Ervin T

Ervin T
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:10:06 AM

Posted 08 February 2016 - 04:58 PM

I tried to post the contents of the logs and receive a message saying that I don't have permission for this action.

Attached Files



#15 Ervin T

Ervin T
  • Topic Starter

  • Members
  • 102 posts
  • OFFLINE
  •  
  • Local time:10:06 AM

Posted 08 February 2016 - 05:00 PM

Tendyron Corporation - I believe was removed by Revouninstaller as I no longer see the when it asked which program to uninstall.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users