Hello- I need some malware help again

Discussion in 'Malware Help (A Specialist Will Reply)' started by kubokawa, Aug 24, 2007.

  1. kubokawa

    kubokawa Private E-2

    Your forum helped me with a malware problem about a year ago. Now I have problems with a very slow computer. Slow to boot, slow to load programs. And it disconnects from the cable internet. I have run the 7 steps in your forum. I am attaching the logs you requested. Any help would be appreciated.
     

    Attached Files:

  2. kubokawa

    kubokawa Private E-2

    The other three logs you ask for are attached here.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How could that be? These are your first two posts.

    You need to post in the proper forum which is the malware forum.

    I will be moving this thread to that forum in a moment.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you notice in the READ & RUN ME where it said that slow PCs are not always due to malware? Well you fit that description. Your problems are more than likely due to what you are running. Two items in particuar could be causing you the biggest problems. And that is the junk from ComCast and also Symantec.

    Let's remove a few minor items and also so unnecessary startups and then see where things stand.

    First start by uninstalling the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\Jim\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Then uninstall Viewpoint Media Player which should have been uninstalled in step 0 of the READ ME

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger.


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now locate the below folder and delete it if found:
    c:\windows\iLookup

    Now delete the below files if found:
    C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
    C:\Documents and Settings\Jim\Favorites\shopping\Best Buy.url

    Now reboot in normal mode

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  5. kubokawa

    kubokawa Private E-2

    I was successful in following all the step you recommended. I reran the Shownew and HJT programs and have attached the logs. Everything seemed to run fine until I lost my internet connection and could not reconnect without powering down the modem. I was not losing the connection until the last week. It seems to be happening very frequently now- maybe 10-15 minutes. The reboot seemed to go a little faster. Any new suggestions?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a malware problem.

    You can use HJT to fix the below lines which will help a little more.

    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1147933943\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"


    Other than that, you will have to bite the bullet and uninstall Norton/Symantec to see if it is your problem.
     
  7. kubokawa

    kubokawa Private E-2

    I did not do the additional two fixes. But the problem has improved a lot. I did go in and update the Microsoft update program. It did not find any critical updates but did update the automatic update program. I have also cleaned up another computer running on my home network. Something has helped. I just wish I knew what it was. Thanks for your help.

     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    You should do them. You don't appear to use AOL so you don't need that process trying to load and you don't need automatic updates of Sun Java always running. You can get them yourself when necessary.

    The C:\Program Files\Support.com\bin\tgcmd.exe process may have been one of your biggest problems. It is a know resource hog.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    2. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds