Help, my PC is soooo slow

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mwkogut, Jan 19, 2007.

  1. mwkogut

    mwkogut Private E-2

    Hi,

    I've gone through all of the steps on your "read & run me first" pages. My PC seems to be fine in safe mode, but in normal mode it is excruciatingly slow. I did all of the scans (except Panda, I couldn't get that to work) and have all of the logs to upload.

    Any help would be AWESOME
     

    Attached Files:

  2. mwkogut

    mwkogut Private E-2

    Second half of my post with remaining logs...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You do have a few malware items we will fix but you speed problems may not improve all that much. Your largest contributors to your slow PC may be BigFix and McAfee.

    Let's complete the below where we will fix malware and stop a few unnecessary (non-malware) applications from loading and we will see if this is sufficient.

    First a question, why does the below need to be running?
    O4 - HKLM\..\Run: [SSP Notifier] C:\Program Files\Fisher-Price\FP3 Player\sspnotifier.exe

    Okay let's get started!

    Uninstall Sunbelt CounterSpy now. We are finished with it.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now Run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [corn beep flap test] C:\Documents and Settings\All Users\Application Data\Long Wipe Corn Beep\time dog.exe
    O4 - HKCU\..\Run: [Hold base] C:\DOCUME~1\Owner\APPLIC~1\FORKJU~1\titlemediamess.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now locate the below folders and delete it if found:
    C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Long Wipe Corn Beep
    C:\Documents and Settings\Owner\Application Data\FORK JUGS COAL
    C:\Program Files\FORK JUGS COAL
    C:\Program Files\Sunbelt Software
    C:\Program Files\Torrent101

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. mwkogut

    mwkogut Private E-2

    [EDIT] Unnecessary long quote removed Please don't quote unless it is needed![/EDIT]

    Chaslang,

    Thanks for looking at my stuff. My PC is about the same after finishing all of the items in your reply. This all started a few weeks ago when I went to a torrent site and then started getting pop-ups. I renewed my McAffe (which I have been running, along with bigfix, for the past year with no performance issues) and reinstalled it, followed by picking up a new modem at the local ISP. It still takes over a minute to load a new webpage.

    I can't seem to upload my new hijackthis.log because it says I've already loaded it. If I need to do it again, please let me know how. If you see anything else suspicious in the oher logs, let me know and I'll nuke it!

    Thanks again,

    Melinda in Vermont
     

    Attached Files:

    Last edited by a moderator: Jan 21, 2007
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember that is what I said at the beginning of my message.

    Both McAfee and BigFix are massive resource hogs! If you want to see how big, uninstall them and watch the difference that you see.

    This means you did not get a new log! If the log was new, you would not have received that message. The message means you were trying to upload the same exact log as last time.

    Once I see your NEW HJT log a may be able to give you a couple other non-malware items to stop from loading that will help a little but I don't think it will be like night and day changes.

    Also please delete the below two items I did not see last time:
    C:\Documents and Settings\Owner\Desktop\OiUninstaller.exe
    C:\Documents and Settings\Owner\Application Data\Torrent101
     
  6. mwkogut

    mwkogut Private E-2

    DONE. THANKS.

    I WAS SO DISCONNECTED WHEN MY COMPUTER WAS DOWN...YOU HAVE REALLY SAVED ME FROM AN ISOLATED EXISTENCE UP HERE IN THE MOUNTAINS!

    MELINDA IN VERMONT
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For your problems with playing flash videos, you will have to work this in the Software Forum since it is not a malware problem.

    Okay now that McAfee is gone you need to complete the below ASAP!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  8. mwkogut

    mwkogut Private E-2

    chaslang,

    Thank you SO much. I followed your steps, installed avast! and zonealarm and shut off my windows firewall. I've even switched to Firefox. I also figured out how to fix my flash viewer! All is well with the world...

    Melinda in Vermont
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds