Another coworker's computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SWario, Jan 6, 2010.

  1. SWario

    SWario Sergeant

    This one seems in much better shape. The only noticeable problem is slowness, and the slowdown seems primarily due to too many processes running with too little RAM. Regardless, it was probably due for a cleaning.

    Windows XP Pro SP3
    Pentium 4 3.20 GHz
    512 MB RAM

    When trying to update SAS with SASDEFINITIONS.EXE, it rolled back the definitions from 4446 to 4415 instead of updating to 4451. I uninstalled and reinstalled SAS to use the more recent definitions from the base installer. Trying to update MBAM with mbam-rules.exe caused MBAM to fail to open, so I uninstalled and reinstalled MBAM, and did not update.

    Trying to install the Recovery Console with ComboFix caused a "Boot Partition cannot be enumerated correctly" error. ComboFix then asked if I wanted to continue or not. I clicked "Yes". It continued to run normally. Had to run ComboFix twice due to manual installation of the Recovery Console (is it okay to just manually install the Recovery Console FIRST if I already know that it's not installed instead of following the ComboFix instructions to run twice?).

    Logs are attached.
     

    Attached Files:

  2. SWario

    SWario Sergeant

    Other logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware left on your system. You may wish to use one of these:

    Startup Manager

    Startup_CPL

    since you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  4. SWario

    SWario Sergeant

    Thanks a bunch! Done with MG uninstallations, and toggling System Restore. Now working my way through uninstalling old unused software and getting their computer set up with protection.

    I've got a question about their current protection setup. They currently have the following installed:
    • CA Pest Patrol Realtime Protection
    • Comcast Antispyware
    • Registry Mechanic 8.0
    • Spyware Doctor 6.0
    • Symantec Endpoint Protection (antivirus, antispyware, firewall)

    Will any of these conflict with each other or cause unnecessary slowdown? It seems like an awful lot of software to me.
     
  5. SWario

    SWario Sergeant

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, sorry. Use CPL. I would dump Registry Mechanic from your list. Otherwise, it looks fine. :)
     
  7. SWario

    SWario Sergeant

    It's really not too much on a system with only 512 MB of RAM?

    Thanks again!
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, xp likes at least a gig of ram. More the merrier!! And you are welcome! ;)
     
  9. SWario

    SWario Sergeant

    Sorry for the delayed response here. The user said that they aren't interested in buying more RAM for the machine as it would be better at this point to put that money towards a new machine instead of improving this one (a 3.2GHz P4, at least 3-4 years old). I'm basically just trying to squeeze as much out of it as I can for them without them putting more money into it. I'd personally put more RAM in it, as it's not a bad system, but I can't force them into it.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not going to get around the slowness aspect regardless of what you use.

    And RAM is cheap these days. They could probably get another 512 for less than $40!
     
  11. SWario

    SWario Sergeant

    Yeah, I hear you, and if it was my system, I'd have already bought the RAM. But their logic is probably that they could put that $40 towards a $200-300 system instead. Well, I've returned the system to them, and await their opinion of whether or not it improved. If not, I'll remind them that I told them it was low on memory when I first got it. Not much else I can do at that point.

    Thanks for all the help! I've just got another one in yesterday (coworker's daughter's laptop; more degrees of separation), so I'll be posting a thread for that in the next day or two. ;)
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Do start a separate thread for the next one. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds