Please help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by KJW, Feb 5, 2015.

  1. KJW

    KJW Private E-2

    I am unable to use my anti-virus, AVIRA, because I get an error message when trying to open it that says something to the effect that it has been closed due to some policy and I must contact the administrator(its my personal PC, I am the administrator). When I try to access the control panel, it flashes on the screen for a second or two then disappears. I cannot access the safe mode because the mouse pointer will not move when I try to log in. I tried to use system restore, which worked once but now I cannot use it because I am not allowed by whatever is involved in this.

    I have windowsXP and although I have used my PC and windows for years, I am not much of a computer whiz.

    I have run Spy Bot and Malwarebytes which removed all they found but they find nothing now although what I have described continues. I am posting from my phone internet. Thank you. Please understand I am pretty much a novice.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. KJW

    KJW Private E-2

    I think whatever occurred was accomplished with Malware which was removed but
    left behind its damage. What I do not understand is that I think the malware was removed before I attempted to restore the computer. This occured as attempted but when the system was, apparently, restored that function was disabled. Can this be done WITHOUT active malware?

    I attempted the restoration believing the malware to be gone but not being able to do anything about the dysfunction left behind.

    I hope I have not posted this problem incorrctly.

    I will try to follow your guidance fully. Thank you.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't understand what you are trying to tell me. What function was restored?
    Again, I can't help you without looking at the requested logs.
     
  5. KJW

    KJW Private E-2

    After I believed that the malware had been removed I used the System Restore function.
    When that was done, because I still saw the things I described in my initial post, I attempted
    another use of the System Restore function but this time that second attempt was not allowed.

    I am an extreme commuter so PC time is limited at home, where the troubled computer is.
    I will do what you ask as time allows. You are my "lifeline". I am not likely going to ignore
    your request(s) or advice regarding my call for help. Hang in there with me. I appreciate your
    help.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Using System Restore may not work because the restore points could be infected. Again, I can't say for sure without seeing the requested logs.
     
  7. KJW

    KJW Private E-2

    I suspect you hit the nail clean on the head with the System Restore comment!

    I will try to get through the entire "to do list" this weekend provided the weather
    cooperates and we, somehow, dodge the bullet of the predicted heavy snowfall
    coming from early Sunday through part of Monday in my neck of the woods.
    Snow removal is one of my obligations and I am no spring chicken. I go back to
    the days of slide rules, the Lone Ranger and before the "Day the Music Died"; that
    particular February still makes me shiver.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When ever you are ready, I will be here.
     
  9. KJW

    KJW Private E-2

    Here you go. I hope the attachments are as you requested.

    I am still having issues, but one issue was resolved. Function has been restored to Internet Options on the Control Panel, THANK YOU!

    I still am unable to launch my Avira Anti-Virus program and I cannot use the System Restore function, both due to policy restriction(s).

    After posting this message with the requested logs attached I shall endeavor to run in Safe Mode.

    For some reason the Hitman log would not upload. I will try to upload it again after I attempt to launch in Safe Mode. It is 3.26 MB which is significantly larger that the other attachments. TDSSkiller is 154KB and the second largest of all five.

    Thank you.
     

    Attached Files:

  10. KJW

    KJW Private E-2

    In order to send you the large Notepad File I had to send it in a Zip file. I hope it works. Never done this before.

    I was once again unable to use Safe Mode because the mouse was not able to move the pointer/cursor, so I could not log in.

    Thank you for being patient with me.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGTools did not run to completion. You need to run it again and let it finish.

    In the mean time, Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    Code:
    ¤¤¤ Registry : 18 ¤¤¤
    [PUP] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} -> Found
    [PUP] HKEY_CLASSES_ROOT\CLSID\{44CBC005-6243-4502-8A02-3A096A282664} -> Found
    [PUP] HKEY_CLASSES_ROOT\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96} -> Found
    [PUP] HKEY_CLASSES_ROOT\CLSID\{80703783-E415-4EE3-AB60-D36981C5A6F1} -> Found
    [PUP] HKEY_CLASSES_ROOT\CLSID\{D8278076-BC68-4484-9233-6E7F1628B56C} -> Found
    [PUP] HKEY_CLASSES_ROOT\CLSID\{F297534D-7B06-459D-BC19-2DD8EF69297B} -> Found
    [PUP] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7} -> Found
    [PUP] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | ApnTBMon : "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"  -> Found
    [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | {bdd08425-8fa4-0fcb-178f-481f050299a4} : "C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\{bdd08425-8fa4-0fcb-178f-481f050299a4}\{bdd08425-8fa4-0fcb-178f-481f050299a4}.exe"  -> Found
    [Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | {bdd08425-8fa4-0fcb-178f-481f050299a4} : "C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\{bdd08425-8fa4-0fcb-178f-481f050299a4}\{bdd08425-8fa4-0fcb-178f-481f050299a4}.exe"  -> Found
    [PUP] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\APNMCP ("C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Found
    [PUP] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\APNMCP ("C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Found
    [PUP] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\APNMCP ("C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe") -> Found
    [PUM.Desktop] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore | DisableSR : 1  -> Found
    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message.

    Now rerun Hitman and have it fix everything it finds. Then attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C;\MGLogs.zip.
     
  12. KJW

    KJW Private E-2

    Here you go with the latest logs.

    I had to run Hitman Pro a few times to remove all and I had to activate it for a 30 free trial to delete the things that it found. Ultimately all were removed, so I will send you only the final log.

    I hope that MGlogs show that the program ran to completion. It stopped and said hit any key to continue. I waiting a bit before I hit a keep to see if it was just an internal pause but the screen stayed unchanged so I tapped a g and the program closed on its own, which I find an odd way to "continue".

    My system still will not allow opening of Avira or System Restore due to policy blocks and I cannot move the icon/cursor in Safe Mode so I cannot use it.

    Thank you. The saga continues.....
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MyGTools still did not run properly. You are not showing any malware, so it may be a problem with your system.

    Let's try this:

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.

    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup

    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.


    After it completes, disable all protection software and try to run C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
     
  14. KJW

    KJW Private E-2

    Not sure what you mean, specificly/accurately about disabling all protection software. My Avira is not accessible. Plus, I do not know how to disable a program other than to uninstall it. Are programs like Malwarebytes, SpyBot and the programs I downloaded to deal with this "protection programs"? Do I disable my firewall? I promise you, I am not trying to be difficult. I am just simple guy.
    Thanks.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you uninstall Avira for the time being? That's all I want you to do before you try running MGGet logs.
     
  16. KJW

    KJW Private E-2

    The program will not uninstall. Physically I cannot remove some Avira files as it says, Access is denied. I have removed all related files that I can but numerous will not delete.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try to run the Windows Repair tool, but other than that, if it doesn't help you will need to post in the software forum as this does not appear to be a malware issue.
     
  18. KJW

    KJW Private E-2

    In Tweaking.com, should I unselect all, first, and then only check those which you have specifically requested?

    As a default, there are many repairs selected.

    I want to be sure that I follow your instructions to a T.
     
  19. KJW

    KJW Private E-2

    I am going to leave the default settings as they are preset but check those repairs which you have indicated that are in addition to the already checked default repairs.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Be patient with the scan....it takes a while. Let me know how you make out.
     
  21. KJW

    KJW Private E-2

    After the scan(I sat by the PC until it shut down and rebooted) I attempted during the rebooting to route into Safe Mode, which I was able to do successfully, unlike earlier. This time the pointer/cursor worked allowing me to log in. In Safe Mode I tried to access System Restore which said "System Restore is not able to protect your computer. Please restart your computer, and then run System Restore again." System Restore did not work when I did that any yields the same message as above.

    Back in Safe Mode I ran Spy Bot S&D, which found only tracking cookies. Malwarebytes found nothing.

    I was able to manually remove evrything related to Avira, using search and then deleting what I found. I was not able to uninstall Avira SearchFree Toolbar but when I search my entire only drive for "Avira", nothing shows up. I tried to download Avira, again, but was blocked with Policy again mentioned during the installation attempt. I did not try to download it to a flash drive and then try to move that onto my drive, however, which I probably should have. But I suspect if that was successful when I would try to use it it would be blocked again. But that that is a guess that is not so educated.

    I am posting this then will run Windows Repair Tool again, with the settings you gave me and the default settings, followed by a run of MGGet logs, which I will attach when they are done.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try to run it in normal mode.
     
  23. KJW

    KJW Private E-2

    Everything was run in Normal Mode. I included both sets of logs.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you are having some issues running the MGtools program properly, I'm going to jump in here for a bit. Make sure you run things as requested below! That is do not run MGtools.exe anymore and do not run the M.G.exe that you have been running. In fact the below will delete it.

    We are going to also finish cleaning up after Avira since it did not uninstall properly.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Services
    AntiVirSchedulerService
    AntiVirService
     
    :Files
    C:\Documents and Settings\Administrator.ME-8E7FF9DC8427\Desktop\M.G.exe
    C:\Program Files\Avira
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{656EC4B7-072B-4698-B504-2A414C1F0037}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{41564952-412D-5637-00A7-7A786E7484D7}"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  25. KJW

    KJW Private E-2

    I have been frustrated by the fact that the MGTools program seemed not to be running completely but I had no idea what to do to remedy that. I will do as you request.

    As before, when I just ran MGTools\GetLogs.bat, in the middle of its operations is opened a window titled

    ProcessDll.exe - Common Language Runtime Debugging Services

    which was a window which said the following:

    Application has generated an exception that could not be handled.

    Process id = 0 x 9a0 (2464), Thread id = 0 x 228(552).

    Click ok to terminate the application
    Click cancel to debug the application


    Clicking ok, continued the processing to an end which said to hit any key to continue, which when you hit any key terminated the process. Clicking cancel
    said something to the effect that a: Registered JIT debugger is not available, an attempt to launch JIT debugger resulted in an error message:

    cordbg.exe ! a 0x5bc

    which gace two choices of ok and cancel, I believe, one of which left the opportunity to manually load a debugger and the other continued the processing to the same end as mentioned earlier.

    I hope that is useful information for you. I am trying.



    Regarding how things are.

    Only two issues seem to have remained:

    1. I cannot access System Restore, getting the same message that System restore can not protect my computer and to reboot and try again....which simply yield the same message....System restore cannot protect....

    2. Since I have removed, manually, what I could relative to Avira, I am not sure if you want me to try to download it again and try to install it, which was not allowed last time. I just checked the "Change or Remove Programs" window to see if all references to Avira were gone but the Avira Toolbar remains(I was unable to remove it do to a previously mentioed error or file that could not be found).

    I do not, therefore, know if these latest procedures have done anything. perhaps the logs will yield some answers/information/give direction?

    Keep me posted. I may be out shoveling more snow or going to work if the snow lets up, so when I can respond is an unknown at this point, but I will.

    Thank you and Tim W.
     

    Attached Files:

  26. KJW

    KJW Private E-2

    Please forgive me if the link I am about to post is not proper because, I believe it relates to the same problem I have but it is so long and involved that I have not yet been able to make an understandable sense of it yet. I found it on my cell phone in the middle of the night last night when I could not sleep.

    http://www.windowsbbs.com/malware-v...avg-antivirus-sotware-restriction-policy.html

    Please let me know if it is understandable to you and if useful info can be extracted that might help in my case.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is okay for now. The rest of the program ran properly this time and now your logs are more complete.

    Let's investigate a little further on your issues with System Restore. It did notice that there are a few Windows Services that are not running that should be. However do note that I see that this PC as had several issues with your user accounts and possibly registry hives for them. There are multiple secondary transfer accounts that were create automatically by Windows which is what happens when there are problems like this in Windows itself. This could be part of your problems and it may not be addressable in this forum.

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.



    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
     
  28. KJW

    KJW Private E-2

    I will follow your instructions when circumstances allow for it. Thank you.
     
  29. KJW

    KJW Private E-2

    Here you go. Sorry for the delay. Long day.
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay there are still a bunch of items from Avira to remove and also there are some policy restrictions to remove.


    Download this >> View attachment fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST.exe on your Desktop.
    • Run FRST.exe by double clicking on it
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now rerun the Farbar Service Scanner and save a new log

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • the new FSS.txt
    • C:\MGlogs.zip
     
  31. KJW

    KJW Private E-2

    Got the same issue as before with the MGTools.

    Here you are.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask you to run MGtools.exe. Your logs show you ran the below

    C:\Documents and Settings\Administrator.ME-8E7FF9DC8427\Desktop\MGtools.exe

    Please delete this file and stop running it. You need to follow the instructions as given. I asked you to run C:\MGtools\Getlogs.bat

    You don't need to run it again right now though but please pay closer attention to the details of the instructions.

    Okay now we need to repeat the running of Farbar Recovery Scan Tool
    • Double-click to run it. When the tool opens click Yes to disclaimer if there is one.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
     
  33. KJW

    KJW Private E-2

    Oops, you are right. I stand corrected.
     
  34. KJW

    KJW Private E-2

    Here you go.
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay there are still a few things from Avira that are not cleaning up since FRST is being run in normal boot mode which is the only way it can run on Win XP. Let's run ComboFix as below.


    Now download and save a copy of combofix.exe and save it directly onto your Desktop folder.
    • Then double click on it to run it. Do not disturb it by clicking in the window that opens or it may stall.
    • After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.
    • If after running Combofix you discover none of your programs will open up because you receive the following error:
      • Illegal operation attempted on a registry key that has been marked for deletion
    • Then you will need to reboot your computer which will normally fix this problem.
     
  36. KJW

    KJW Private E-2

    Here it is.
     

    Attached Files:

    • log.txt
      File size:
      21.5 KB
      Views:
      4
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix to cleanup after Avira
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  38. KJW

    KJW Private E-2

    Here are the logs.

    Things seem to be working ok. I still have functional System Restore. I have not loaded Avira again. I will, when you say it is time. I searched and all traces of Avira folders are gone and the Security Center said that windows did not find any anti-virus software on the computer, which is what I expected. Thus outside of no anti-virus program, things seem to be working well for an ancient operating system.

    There appear to be no infections that I can find, although, when combofix was running and about to reboot it opened a window that said it detected rootkit activity but mentioned no name and I had earlier today run Malwarebytes with the box checked to scan for rootkits and it found none. MGtools\GetLogs.bat had the same glitch as it always has on my machine indicating the need for a manual debugger, which I bypassed to continue, as I had no debugger to load.

    This time, though, I double clicked on GetLogs.bat, which I neglected the last time.

    I am heading to bed now. Been a long day. It seems we are "neighbors". I live in southern NY, just north of northern NJ. Going to Paramus or Ridgewood before the snow tomorrow, I hope.

    Let me know how things are based upon the info in the logs. I do, very much appreciate the help that both you and Tim have been. I do my best because I was the one who needed the help. I am not perfect but I always try in earnest to follow directions. Later.
     

    Attached Files:

  39. KJW

    KJW Private E-2

    Having run the PC for part of the day late yesterday and this morning, I want you to know that it boots somewhat faster than before and it shuts down noticeably faster, as well.

    When all of my mess is cleaned up and I am said and done my question then becomes, are there tweaks that I can do to make this old operating system quicker/more efficient that are easily and not dangerously done by someone who knows enough to check the plug and the house electricity when the darn PC won't start up and to make sure it is plugged in, but has not had formal training with computers since I once learned and forgot(early 70's) Basic and Fortran?

    Then, since this old PC that I use is described under System Properties as:

    Intel(R) Pentium(R) 4CPU 2.80GHz 2.7GHz, 1.99GB of Ram

    I presume it is a fossil by "today's" standards.

    Do you have any suggestions, or where can I(without an IT PhD) read up on what is reasonably inexpensively available(without sales pitches other than the facts in an understandable fashion) to "replace" this dinosaur? I am not in a rush but it is becoming increasingly obvious to me that I need to "move on" but I do not want to be foolishly fast in my decision(s).

    My brother who has a newer PC uses Windows 8.1 and is mostly lost, as am I(with respect to Windows 8 or 8.1), since I have not used it except to fight through on his to try to help him with the mess he makes of it. He is 7years my senior and seriously less capable than I regarding operation and maintenance of a functional PC. If I am out of line asking such things just be kind when you respond, but the inquitry is sincere and well intentioned. I do not want to "hang my brother to dry". He is a a good man.

    Thank you.
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your logs look good now.

    All of your non-malware related questions are better served by posting in the Software Forum. But if you plan on keeping this PC for awhile then the first thing you should do is add another gigabyte of memory to it.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  41. KJW

    KJW Private E-2

    I have been quite under the weather for the past few days and I apologize for not having responded to you before this.

    I have gone through everything you suggested and made numerous changes..

    Please be aware that when following your text through here, "How to Protect yourself from malware!", I came to Step 10 and attempted to follow this, "Spyware Info's Clean and Infected File Sharing Programs", and I got to this:

    "Internal Server Error


    The server encountered an internal error or misconfiguration and was unable to complete your request

    www.spywareinfoforum.info"


    I am very grateful for all the help that you and Tim W have given me. I would not likely have been able to deal with the issues that I had, otherwise. I have often recommended this site to others, over the years, having received help, in a less complicated circumstance, numerous years ago. I stop by semi- regularly just to see "what is going on" and will continue to do so for the foreseeable future, God-willing.

    The help that you give to others is much appreciated and I can see from the many other entries here that you folks(gals and guys(I am old so do not be put off)) just "keep on giving". Well done and keep it up!


    Karl
     
    Last edited: Feb 21, 2015
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for reporting this. I removed that reference now since it is no longer available. And fixed another link too while I was at it. ;)


    You're welcome and surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds