Jump to content

computer slow, sites won't load, regsvr32 gobbling processor


Recommended Posts

A couple weeks ago (I think) my PC, running Windows Vista, started having problems after I switched to the Firefox browser (when Google chrome announced it would soon stop updating because VIsta wouldn't be supported).  After I stopped being able to print or attach documents to emails I switched back to Chrome, but problems have continued.  Sites open very slowly, and I frequently get a message that they're not available.  When I check processes, regsvr32.exe is taking up to 500,000k of memory.

 

Malwarebytes quarantined

 

 
Rootkit.Fileless.MTGen, HKU\S-1-5-21-2991280784-2447642418-4385585-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^3c1a2be3, Quarantined, [dd9c5016eaaf03332e073d9cdb2808f8], 
 
on February 29.  I didn't delete it until today (oops, didn't read everything like I should have).  I have run MBAM several times since then and no new malware has been found.
 
Does this information give you any idea what is wrong or what I could try to restore functionality in my PC?
 
 
Link to post
Share on other sites

Hello, 
 

Rootkit.Fileless.MTGen, HKU\S-1-5-21-2991280784-2447642418-4385585-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^3c1a2be3, Quarantined, [dd9c5016eaaf03332e073d9cdb2808f8], 

This is a variant of Xswkit/Gootkit, and is known to download additional malware to the compromised computer. 
 

Does this information give you any idea what is wrong or what I could try to restore functionality in my PC?

Given additional malware is likely present, I suggest seeking assistance in the Malware Removal Help section. Please read the I'm infected - What do I do now? before posting.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.