Malware Read & Run Me Complete and Ready for Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by QuartetmanIA, Apr 18, 2009.

  1. QuartetmanIA

    QuartetmanIA Private E-2

    The Problem:

    I have been experiencing logins that have taken up to 10 minutes before I can bring up a FireFox browser and even with that, the FireFox browser takes way too much time before it starts. In addition, I run AVG Antivirus (Free Version) that takes 7 hours to complete. My computer is basically slow and my C: drive is constantly "chattering". I was thinking it may have something to do with MalWare that none of my other scanning programs (Spybot, etc.) isn't finding. A Google search brought me to your website.

    While going through the Read and Run Me list which suggests that I defrag my disk using one of the defragmentors other than the default Windows Defrag, I notice that the analysis defrag screen looked like "Red Dawn" and after it defraged my C: drive, it eliminated 100% of the fragmented files. EXCELLENT product. I think that may fix the problem with my AVG scans.

    Secondly, the only problem I've had during the entire Read and Run Me was that I could not delete Red Swoosh EDN program, which you listed that should be removed with the Add & Remove program. When I click on uninstall, the Remove program would freeze up. I had to open Task Manager to cancel the program before I could get control again. Considering that Red Swoosh could cause problems, I would like some help getting the program deleted.

    I have completed all the steps suggested and ran all the malware scans and have created logs for you to view. If you see anything that may be cause other problems for me, I would welcome your advice.

    As for now, I am happy that I don't hear my C drive clicking away for hours on end. (Perhaps because the instructions said to stop TeaTimer from running at StartUp. Things seem to run a little faster, but I think startups are still slower than they should, but maybe that is the way it goes. I'm running Windows XP and AVG and ZoneAlarm are the programs that start up when I power up. But now I see that SuperAntiSpyware is running to on Start Up. Do I really need to have this running now that my scans are done? Last thing I need is unnecessary programs running.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are clean as far as malware is concerned. And the answer to your question is no, you do not have to let SAS be a startup program.

    The reason for your slowness is this:
    We can do a little cleaning by doing the below:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  3. QuartetmanIA

    QuartetmanIA Private E-2

    Thank you Tim and to all the Malware experts at MajorGeeks for your selfless help. Just to followup, while I was waiting for my post to get worked on, I was able to delete Red Swoosh EDN after going thru the READ ME FIRST. Also, after running DiskKeeper Lite, I noticed I have 12 gig of free space, so I up'd the allocation of the Virtual Page Space area from 385 MB to 500MB with a maximum of 700MB, hoping that will speed things up.

    I feel like whatever was slowing me down and causing my C: drive to be constantly "chattering" is now fixed and very much improved. I suppose I should upgrade to 1GB of RAM to fix the issue of slow loading of startup programs? I'll look into it. As for now, things are running so smoothly that I am greatfull for this improvement.

    Much regards,

    Dave
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know...go forth and surf. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds