xp/hp notebook way slow

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by garyt53, Dec 13, 2014.

  1. garyt53

    garyt53 Private E-2

    But then it's packed with MS updates.

    Please evaluate as it supports my outdated but expensive engineering programs.

    Have attached the 5 utility's logfiles, following instructions best I could except for HitmanPro where the illustration was conflicted by the text. I followed the text.

    Thanks in advance. And hope yyou're able to make this tedium fun. ha

    gt

    Yes, am also evaluating my desktop win7 in another thread, both systems being dual/boot with linux.....I intend to keep my xp off the net after this cleansing as I do the xpVM I run on win7 to accommodate my outdated CAD utilities.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you deliberately set up to use a proxy?
     
  3. garyt53

    garyt53 Private E-2

    Hi Kestrel -

    Nope, not for over 5yrs. Used "ProxyWay" for awhile way back. WHy? Does this have something to do with my system integrity?

    gt
     
  4. garyt53

    garyt53 Private E-2

    Couldn't understand why you would ask that so went to the web....and here's what I found (attached). HA! haha

    Read the thread but still have no idea though.

    gt
     
  5. garyt53

    garyt53 Private E-2

    forgot to attach (shouldn't even be up)
     

    Attached Files:

  6. garyt53

    garyt53 Private E-2

    Hi K -

    Just realized the ver of mbam I regularly use was outdated so updated, ran scan and attached the log.

    Will have to do same on notebook (separate thread).

    gt
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi Gary. :)

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.


    Re run Hitman Pro and have it remove all that it finds.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - AutorunsDisabled - (no file)
    • O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    • O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
    • O24 - Desktop Component 0: (no name) - (no file)
    After clicking Fix exit HJT.



    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.




    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] HKEY_CLASSES_ROOT\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179} -> Found
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\catchme (\??\C:\DOCUME~1\GARYTI~2\LOCALS~1\Temp\catchme.sys) -> Found
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\catchme (\??\C:\DOCUME~1\GARYTI~2\LOCALS~1\Temp\catchme.sys) -> Found
    • [Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\catchme (\??\C:\DOCUME~1\GARYTI~2\LOCALS~1\Temp\catchme.sys) -> Found
    • [PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Found
    • [PUM.Proxy] HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 127.0.0.1:80 -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-21-498550216-2054699890-1586058166-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 127.0.0.1:80 -> Found
    • [PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 127.0.0.1:80 -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.



    • Now re run RogueKiller (just a scan) and attach log.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    • Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  8. garyt53

    garyt53 Private E-2

    Hi K -

    Used to use autoruns, but between msconfig and ccleaner I just turn most of them off. So go msconfig back to normal. What about all the stuff I have turned off in ccleaner? Turn it all back on?

    Will await your reply before continuing on what looks like is going tobe an adventure. ha linuxlinuxlinuxlinuxlinuxlinuxlinuxlinuxlinuxlinuxlinuxlinux

    gt

    that last mbam run took out a coupla useful false-positive utilities and can't recover from qt - hope that's all it killed

    will run scannow while I'm waiting jic
     
  9. garyt53

    garyt53 Private E-2

    oops, already ran scannow on desktop (other thread) and haven't yet updated and rerun mbam on notebook but already running scannow on that for nothing!

    just can't tell my senior moments from my medicated moments anymore, ha

    gt

    will rerun updated mbam and repost results
     
  10. garyt53

    garyt53 Private E-2

    must make it clear for you:

    disregard last mbam log as it applies to my desktop pc, updated program log coming after this unnecessary scannow that I should have run on the desktop

    will really try to differentiate correctly in the future now that I understand how easy it is to make this mistake while running 2 threads

    gt
     
  11. garyt53

    garyt53 Private E-2

    OK.....looks like you discontinued my other thread refarding my desktop.

    Please advise. Already invested a lota work in this effort and would hate to see it tossed.
     
  12. garyt53

    garyt53 Private E-2

    Hey K -

    Here's the real-deal mbam log. I qt'd the results as per.

    Well, I guess there's not that much desktop pc work to toss yet since I still have the logs to repost. Would really like to run 2 threads, one on desktop and one on notebook, so I can get this done fast....and I can handle that now, but you probably have some stupid rule preventing that. And since I believe stupid rules are not made to be broken cause they're there for a reason.....on the other hand, authority in general has really gone south in a big way lately. Unless you believe tv.

    gt
     

    Attached Files:

  13. garyt53

    garyt53 Private E-2

    Hi Kestrel -

    Regedit fixME worked! I love it when stuff works. ha

    The RK nomenclature wasn’t very straightforward but I sorted out all but the following 2 items:
    • [PUM.Proxy] HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 127.0.0.1:80 -> Found
    • [PUP] HKEY_CLASSES_ROOT\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179} -> Found

    AdwCleaner: all results look like stuff I didn’t ask for nor want, except the registry entries I don’t know about.

    RK opened website indicating SSDHook infection. ?
    And yeah, seems to be running better already.

    Man, the tools sure are more sophisticated these days. ha

    gt
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is why you should ONLY be doing what I ask you to do!!! Just follow instructions please. :)

    Sorry? I don't know what you mean? I work ALL my threads, I have discontinued none. It will be dealt with. ;)

    Re run Adwcleaner and have it remove what it finds...

    The proxy entries are STILL there. Let's see if running adwcleaner removes them.

    Once you have run Adwcleaner again, re run RogueKiller and attach latest log. If the proxy entries still show you might have to uninstall your antivirus.

    You also forgot this part at the end of my last post:
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There is no other thread in this forum regarding a desktop computer. :confused
     
  16. garyt53

    garyt53 Private E-2

    Hi Kestrel -

    Hey thanks for looking for my lost thread even though I can't understand why it's gone if I wasn't breaking any rules regarding multiple threads. Been working mostly from this laptop touchpad though and I probably accidentally deleted it? Still strange. Will rethread after we're done with this, and we almost are, huh.

    Sorry I overlooked the final step. I cut&pasted the instructions to keep exposure to minimize web exposure and the window missed the last instruction.

    So NIS (Symantec) went south on me and uninstalled with Symantec utility. Will reinstall after this…..boy I sure didn’t want to do that. Machine has suffered for it (ironic, ha). But as it turns out I should not have chose Symantec, ironically (and typically) the corp delegated our national cyber-infrastructure protection. Actually that's worse than Gates being a fake humanitarian. haha

    Now, I restored normal boot in msconfig but still have a lotta stuff disabled in CCleaner, if that’s an issue. I use CCleaner instead of msconfig or autoruns.

    Off topic but related: I conduct regular maintenance by CCleaner (both options) and Sym and mbam scans, and boot defrag (Puran). Still current best practice?

    gt
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run RogueKiller in safe mode please and have it remove any proxy entries it sees. Then rescan with it in normal mode (just a scan) and attach log.
     
  18. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, that is an issue because you shouldn't be using CCleaner to control startups.

    Dealing with Startup Processes
     
  19. garyt53

    garyt53 Private E-2

    figured out what happened to my desktop thread: since I neglected to attach my logs, it was likely deleted by admin as inappropriate.

    The proxy results seem to be gone now. We done? Pretty close, huh. Will restart desktop win7 thread when we are.

    gt

    running better now - wonder if it still will be after NIS reinstall, ha

    Like MS and GoldmanSucks....Symantec has become too big to jail. haha
     

    Attached Files:

  20. garyt53

    garyt53 Private E-2

    Hi Kestrel -

    Reinstalled NIS and, even though it takes a few min to boot cause there's like 50 autostarts on when I usually only permit 4, this thing's like.....like snappy-new! Takes a while to really get booted with 50 startups on when I usually run like 4, but snappy is the word.

    gt
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So everything is running nicely again now? Ready for final steps? The logs look good...
     
  22. garyt53

    garyt53 Private E-2

    Not nicely....SNAPPY! Snappy-crisp!

    I knew over the years weird stuff squeezed by NIS and mbam. Such a frenzy of greed and fraud going on. Certainly makes things interesting, huh.

    Yup, if logs look good, let's wrap it up and call the notebook "fixed", both by being fast again and by shutting down the xp internet access. ahhahaha Linux can do that duty safely now. You know, now xp is snappier than linux! And xp partition has only 20% headspace!

    You may advise as to what typ xp crap I can safely remove from my 40GB xp partition if that's appropriate. Like MSUpdate backups. Hoggy stuff like that that only a cyber-hep sysad would know about. Like turn off the pagefile if I got a lotta memory?

    gt
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:

    You can ask about the other non malware related stuff in the software forum. ;)
     
  24. garyt53

    garyt53 Private E-2

    Great! Will follow all the instructions even though I intend to disable internet capability that I will restrict to Ubuntu14 only.

    Hey Kestrel, thanks for putting me back together and not taking me apart like MS and Symantec/India have before, even getting me to pay them on occasion for the privilege. ha

    May have a few general questions for you or a colleague later that have not been addressed well on the web (like the pagefile issue) but we can consider this thread closed - I don't see an option for me to close it though.

    Bye. And remember, don't be afraid.....get mad. Like Howard Beale. In that is our hope. Sorry, I'm old enough now I no longer consider myself strictly bound by forum protocol. ha

    gt
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :) You can post your other questions in the software forum or wherever's relevant.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds