New Logs - For Review

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by HafDawg, Feb 16, 2009.

  1. HafDawg

    HafDawg Private First Class

    Thanks again for your help.

    I'm trying to improve the performance of this computer. Everything on startup loads so slowly.

    I'd appreciate you reviewing the logs and letting me know where to go fromk here on them.

    Also, if you could pass along other ideas to help improve startup time. I've done the startup cleanup with CCleaner, etc. Is there anything else I can do to make my computer load faster? Heck, even IE and Firefox load slowly nowadays.

    Thanks!
     

    Attached Files:

  2. HafDawg

    HafDawg Private First Class

    Also, I got this upload error when trying to get the combofix log on here...

    combofix.txt:
    Your file of 931.2 KB bytes exceeds the forum's limit of 250.0 KB for this filetype.

    Any idea what I should do?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! You should always uninstall ComboFix as our final instructions request after malware cleanup is completed. You should not keep any of ComboFix laying around. That way if you ever run it again (like this time) you will not have all the information from a SnapShot file created last time which we really don't need to look at most of the time and it makes logs way to large too. You can compress you current log into a ZIP file and see it you can attach it.


    Does this have anything to do with the PC you were just working on in the below thread?
    http://forums.majorgeeks.com/showthread.php?t=182311
     
    Last edited: Feb 20, 2009
  4. HafDawg

    HafDawg Private First Class

    Nosir, that was a different computer.

    I might have used ComboFix in the past and uninstalled it incorrectly. I do apologize. On the post you referenced, I uninstalled it properly.

    Attached is the zipped ComboFix.

    I do, again, apologize. Once we're done here, I'll follow the proper directions on uninstalling combofix.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If does not appear that malware is the cause of slow startup. Below are a few things for you to do though that may help a little.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)

    Optionally consider whether you really need to load the below at startup. Fix any that you don't need to load at startup.
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. HafDawg

    HafDawg Private First Class

    Attached are the logs.

    Startup is great, the computer loads quickly.

    I guess my remaining issue is programs like Firefox, IE, Microsft Word and Excel, etc... they take so long to load up (Firefox took at least 15 seconds to load just now), when previously they loaded almost instantly.

    Any idea what might be causing that?

    Thanks, my friend!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My best guess at this point would be McAfee. You could try uninstalling McAfee to see if there is any change, but you are not having malware problems. If removing McAfee does not have any effect then you need to reinstall it to get your protection back in place.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds