Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by rpraying, Sep 3, 2007.

  1. rpraying

    rpraying Private E-2

    My PC runs WIN XP Home Ed., SP2. It has and AMD Duron Processor, 1.20 GHz. The Physical Memory is 224 MB Total, 43 MB Free, and the Memory Load = 81%. Virtual Memory = 572 MB Total, 239 MB Free. I have two hard drives: Disc C: 30 GB Available, 57 GB Total, 30 GB Free. Disk D: 139 MB Available, 3084 MB Total, 139 MB Free.
    I have had very few problems w/my PC since I purchased it. It has started acting up in the last year, however, and lately has been running like a turtle for re 2 months, growing increasingly slower and freezing up more frequently. When I print something, for example, I can no longer type in a different document or check my mail or open a URL, etc., until the print job is complete. A few times a week now I have to manually shut off the PC and reboot; occasionally it also simply reboots on its own (which is quite disconcerting).
    I have been checking for viruses and spyware w/the programs I had on my system and have continually found nothing, so I didn't think that was my problem. Instead I thought that perhaps the RAM had gone bad. My mother (who raves about you all) finally convinced me to register here and work through the Read & Run Me First and contact you - b/4 deciding hardware was the problem. I have completed everything in the Read & Run Me First (through step 6 at the moment), incldg the basic computer maintenance items. The first three files are attached to this msg as instructed. I will complete Step 7 and attach the other files in a moment.
    The programs I ran via the Read & Run Me First found quite a few things on my PC that the other virus and spysweeper programs were missing. Unfortunately not all of those problems were able to be disinfected or deleted, and I do not know how to proceed from here.
    Also, running my PC w/MSConfig set to Normal Startup really bogs down the system; it takes 15-20 minutes to fully start up. During the scans, I had to close multiple items after start up b/4 the scans would run. (I hope that wasn't a mistake.)
    How do I get rid of the rest of what shouldn't be on my PC? How do I know what to get rid of? If the problem isn't all malware, but is hardware, is there some way to determine if the memory is going bad or if the mother board is going bad?
    Have I given you too much information?:eek:
    Please let me know if there is anything else I need to tell you and what else I need to do.

    Thank you.
     
    Last edited: Sep 4, 2007
  2. rpraying

    rpraying Private E-2

    Here are the rest of the logs. Also, here is the memory information from SIW. Does this mean that when we finish cleaning my PC that I can put four 512MB memory sticks in my PC? And is there a specific kind I should purchase?

    Maximum Memory Module Size: 128 MBytes
    Maximum Capacity: 512 MBytes
    Memory Slots: 4
    Name: Physical Memory Array

    Device Locator: ROW-0
    Capacity: 256 MBytes
    Memory Type: SDRAM
    Bank Label: RAS 11 4
    Form Factor: DIMM

    Thank You.
     
    Last edited: Sep 4, 2007
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    As stated at the top of the READ & RUN ME, slow PC syndrome is not always due to malware.

    I'm going thru your logs now and will let you know what I see. I will also post any performance tips that I may notice.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis should not be here:
    C:\Program Files\analyse.exe

    It should be here:
    C:\Program Files\HijackThis\analyse.exe

    All the stuff being detected by BitDefender and Panda in various email boxes and folders like Inbox impaired that you have all over the place need to be manually cleaned up by you.
    • Do you really need JUSearch from Juno? Do you need their Toolbar? Uninstall the Juno software if you don't need it. It is just adding to your slow down.
    • Do you use Microsoft Money? If so why do you need it to always load at startup?
    • Do you ever make use of LogitechDesktop Messenger? I personally recommen uninstalling this.
    • Embarq TotalAccess - which is probably the same as Earthlink's TotalAccess has been know to bog PCs down. If you don't need this sotware just to get your internet connection to work, consider uninstall it.
    If the below are items you need, you should move them someplace safer and more permanent. You should avoid cluttering up your root folder (and also your Desktop) which can slow down your PC too.
    Code:
    "C:\"
    1stsem~1.qpw  Jul 24 2007      231657  "1st Sem Grades 0607.qpw"
    2007re~1.doc  Aug 25 2007       29184  "2007Registration.doc"
    ba5130~1.wbk  Aug 16 2007       29696  "Backup of Pannell August 2007.wbk"
    ba6397~1.wbk  Aug  9 2007       28160  "Backup of Pannell 2007.wbk"
    backup~1.wbk  Aug  9 2007      239104  "Backup of Wake Tech 134ApplicationforEmployment.wbk"
    backup~2.wbk  Aug  6 2007      321536  "Backup of Gregus Section 2 Questions.wbk"
    backup~3.wbk  Aug  6 2007       31232  "Backup of Pannell Cvr Ltr.wbk"
    backup~4.wbk  Aug  6 2007       25088  "Backup of Pannell Cvr Ltr Chapel Hill.wbk"
    dmaadl~1.doc  Jul 23 2007      124416  "DMA ADL DISABILITY FORM.doc"
    fightl~1.doc  Aug 14 2007       57856  "Fight Like a Girl CHAP 1 Sample.doc"
    gregus~1.doc  Aug  6 2007      318976  "Gregus Questions.doc"
    pacd7d~1.doc  Aug 16 2007       31232  "Pannell August 2007.DOC"
    pae581~1.doc  Aug  6 2007       33280  "Pannell RESUME and Cvr Ltr.DOC"
    pannel~1.doc  Jul 19 2007       67072  "Pannell 07.DOC"
    pannel~2.doc  Aug 22 2007       28672  "Pannell 2007.DOC"
    pannel~3.doc  Aug  6 2007       30720  "Pannell Cvr Ltr.DOC"
    pannel~4.doc  Aug  6 2007       33792  "Pannell Cvr Ltr Chapel Hill.DOC"
    quixta~1.doc  Aug 13 2007       20480  "Quixtar Comments.doc"
    wakete~1.doc  Aug  9 2007      238592  "Wake Tech 134ApplicationforEmployment.doc"

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below folders which may be left behind by the uninstall:
    C:\Documents and Settings\Rachel P\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Uninstall the below old version of FireFox:
    Mozilla Firefox (1.5)
    Then install the current version of FireFox from: Mozilla Firefox

    You missed some items that should have been uninstall in step 0 & 6 of the READ ME. Uninstall the below now.
    J2SE Runtime Environment 5.0 Update 4
    Java 2 Runtime Environment Standard Edition v1.3.0_01
    Java 2 Runtime Environment, SE v1.4.1_02
    Java 2 Runtime Environment, SE v1.4.2_05
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    Viewpoint Toolbar (Remove Only)

    Since you do not have any Symantec software installed the below items should be uninstalled via Add/Remove programs. Tell me if you don't find these:
    LiveUpdate 2.5 (Symantec Corporation)
    Symantec Network Driver Update

    Is your copy of SpySweeper a paid version or free trial version?


    The below items to fix with HijackThis are all unnecessary items that are adding to your slow performance.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
    O4 - HKCU\..\Run: [LDM] "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Delete the below file if found:
    C:\Documents and Settings\Rachel P\Desktop\Dwnlds\SmileyCentralSetup2.0.3.16.exe

    Now reboot your PC!


    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    The software you got from your ISP for protecting your PC may possibly be part of your slow down issues. We shall see after all other steps are completed.
     
  5. rpraying

    rpraying Private E-2

    Thank you for your quick reply.

    I could not find the 2nd Symantec item you said to delete (it might have been removed when I uninstalled the Symantec Live Update). I did find several other Symantec folders on my PC. Should I manually delete all of those?

    I think I got everything listed in Panda, but I have not done anything w/the BitDefender items yet. How do I view the list of items that BitDefender is saying need to be fixed/deleted? When I open the text file it's a mess of HTML code, which is very hard to read through.

    What is 'Avenger'? It is one of the logs you said to attach this time, but I have no idea what it is.

    I use Embarq DSL, so I don't know if I should delete the Embarq Total Access or not; I don't know that I use it though.

    My copy of SpySweeper is a free trial version I think; it updated the other day b/4 I ran it.

    I do use MS Money, but I never told it to load at start up; it auto installed that way, and when using the MSConfig "Normal" Start Up, it loads; usually I use the Selective Startup function and don't select it for loading. Is that what you're talking about?

    After completing all but the items above as explained, the PC is still taking a good 10 minutes+ to boot up, but the MSConfig is still set to "Normal Start Up," and there are 16 items in that StartUp List, most of which I usually disable and use 'Selective Startup' instead. There are a lot of items in the Services list too, but I've never messed w/those. Any suggestions?

    If I missed anything, please let me know.
     
    Last edited: Sep 4, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rename the file locally on your PC back to have a .html extension rather than a .txt extension. The just double click on the file and your browser will popup and show it nicely formatted.

    Sorry, I forgot to delete that request when I changed your procedure to manually delete a file. You did not run Avenger so don't worry about it.

    Leave it for now but I would be some of it is not required.

    Free trials do not normally update anymore. If you do not have a valid license (i.e, you did not buy it and I think you would know that unless it was a trial that came with your PC or was given to you by your ISP).

    Yes and no! You don't need to and should not use MSconfig like that. For startups like this, you should just permanently remove them or configure within the program not to load at startup. You can use HijackThis to remove the MSMoney startup. It will not affect normal operation. But I believe we did this already in my previous instructions.

    What items did you normally disable and why? Explain what you never use, and what you use sometimes.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see Symantec Network Driver Update in your newfiles.txt log. Does it not appear in Add/Remove programs. If not, run the below and attach the log:

    Getting Uninstall Programs List From The Registry

    Do you really use Yahoo Toolbar? I find it to be a waste of system resources and unnecessary.

    Do you still use NetZero? Since Earthlink seems to be your ISP, why is the software (including a toolbar) from NetZero installed.

    You should have HijackThis fix the below line:
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll (file missing)


    Your logs are clean!
     
  8. rpraying

    rpraying Private E-2

    Goodness, I should've thought of the file extension switch for the bdscan file; I feel foolish!

    The Symantec Network Driver Update does not appear in Add/Remove programs. GetUnKey.txt is attached.

    I double checked SpySweeper, and I've had it since February 2007. It says Subscription Service Active Through 2/1/2008. I wasn't thinking about it as a "subscription" per se, b/c I installed it from the program CD.

    I don't think I've ever used Yahoo Toolbar? I know it's part of Internet Explorer, which I also don't use unless required to do so by a specific web site. I can delete this using Add/Remove Programs.

    My son uses NetZero, and occasionally uses my PC. It does occur to me that he probably doesn't ever need to dial in from my PC b/c of my DSL, so I can go ahead and delete the program; I Just never thought about it b/4.

    I began using MSConfig that way after installing Embarq DSL and all the related software; my PC was bogging down a lot, and when I called them for help they had me disable some of these items in the MSConfig Start Up. The items I normally disable from MSConfig include:
    earthlink total access (I never use this, but they had me install it when I got Embarq DSL, which comes w/earthlink e-mail). Do you think I can get rid of this?
    earthlink protection center (This really bogs down my PC, so I usually just run it manually a couple times a week and then immediately shut it back down.) I did just talk to a tech at Embarq, and he said I could delete the Embarq Total Access and anything Earthlink related on my system. Is there something you would recommend I replace the protection center with that won't bog down my PC but will accomplish the same tasks?
    TaskPanl - c:\programfiles\Emb.... (I never use this, but I had to install it when I got Embarq DSL)
    InCD (I usually let this start up, but then if the PC is slow I manually close it; I think it has to do w/a CD or DVD drive we installed last year).
    iTunesHelper (I never use this program, but my son does when he occasionally uses my PC)
    eFax 4.3 (I use this program prn; I don't need it to load at StartUp.)
    Exif Launcher (I use the related program prn; I don't need it to load at StartUp.)
    Mozilla Thunderbird (I use this often, but I'd rather open it myself when I have time to chk my e-mail; sometimes other work is much more important, so I'd rather the PC boot faster and let me choose what to open, which seems to require disabling Thunderbird from the Start Up process.)
    SpySweeper (when it used to be in the list; it isn't now.)

    I don't know how to permanently remove the above items from the Startup. For example, I checked every option I could find in Thunderbird, eFax Messenger, and FinePix Viewer (Exif Launcher), and there isn't one to uncheck that will remove it from opening at start up.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach this log. I need it so that we can continue.

    Yes uninstall Yahoo! Toolbar

    The uninstall this. You said multiple times you son sometimes uses your PC. Does he have his own user account? He should. That way things he needs can load at startup in his account but not in yours.

    You can always reinstall any particular software you need of theirs so I would try to determine exactly what you really NEED and do not need. You probably don't need too much of it. But read further down.

    I'm going to give you some items to download. Just download them first. We will then uninstall some of your software and then install the items I'm having you download. What we will be trying to do is remove all of your ISP's protection software and any other junk you don't need from them. And we will replace it with free and better tools. Now download the below:
    Now uninstall the below from your ISP:
    • Authentium FW SDK
    • Authentium
    • EarthLink Protection Control Center
    • EarthLink Toolbar
    • Protection Control Center
    • TotalAccess Core Applications
    They have other things installed but you may or may not need them. This are things you will have to determine.
    • EarthLink Common Authentication
    • EarthLink FastLane
    • EarthLink MailBox
    • EarthLink Software
    Now install the and get any updates for the programs I just had you download. These will give you a new antivirus and firewall program. Also SpywareBlaster will not use any system resources (i.e. will not effect performance) but adds some addition behind the scenes protection. Download Latest Protection Updates for SpywareBlaster, Check for Updates, and then Enable All Protection, then exit. It will add protection for both IE and FireFox.

    This is from Nero and allows for drag and drop type packet writing. Like using your CD/DVD drive almost like a hard disk. If you never use this, you can just have HijackThis fix that startup line:

    O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"

    Note anything you fix with HJT is saved to a backup and can always be restored if you change your mind later. Just don't delete the HijackThis folder or backups folder which is saved in the HJT folder.


    Have HJT fix the below startups:

    O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\Embarq TotalAccess\TaskPanl.exe" -winstart
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - Startup: Mozilla Thunderbird.lnk = C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    O4 - Global Startup: eFax 4.3.lnk = C:\Program Files\eFax Messenger 4.3\J2GTray.exe
    O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe


    Why is it gone? You need this to provide your realtime antispyware protection but note while Spy Sweeper is a great tool, it does cause some PC's to slow down a lot.


    After doing ALL of the above tell me how things are working. Also attach new logs from:
    • ShowNew
    • HijackThis
    Also attach the GetUnKey log you did not attach (I recommend getting a new one and attaching it since we just uninstalled a bunch of things).
     
  10. rpraying

    rpraying Private E-2

    I'm sorry, it said the GetUnKey log had uploaded, so I'm not sure what I did that it wasn't there.

    The following items are not showing up in my Add/Remove Programs Menu, so I could not uninstall them:
    * Authentium FW SDK
    * Authentium
    * Protection Control Center
    * TotalAccess Core Applications
    * EarthLink Common Authentication
    * EarthLink FastLane
    * EarthLink MailBox
    * EarthLink Software
    Is there someplace else I should look for these?

    I have downloaded the programs you recommended but waited to install them b/c I was unable to delete the above items.

    I don't know why SpySweeper is gone from the MSConfig Startup list; I was actually surprised that it wasn't there.

    In the latest run of HijackThis, I noticed several lines that referred to Juno, Access-4-Free, and BigZoo.net. These programs are not in use on my PC anymore; should I have HijackThis delete those lines?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you go back and delete your previous logs today? This was a bad thing to do and it is unnecessary. In addition, you are not even supposed to be able to edit those messages after 5 minutes but bugs in the vBulletin code sometimes allow it. I know have no old information to base comments and fixes on.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is more than likely because they were all considered part of something else that you already uninstalled. They are all gone now.

    Is your PC running any better right at this immediate time?

    Yes.



    Did you decide that you did not want to fix the below as suggested?
    O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
    O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"

    You do need to also fix the below:
    O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now delete the below folder if found:
    C:\Program Files\Common Files\Symantec Shared


    You now need to install the software I recommended. Then attach new logs from ShowNew and HJT and tell me how everything is working.
     
  13. rpraying

    rpraying Private E-2

    I wondered why it prompted me to delete those logs, but there was some error the 2nd time I tried to upload the GetUnKey.txt file, and it took me to that delete logs page and said I had to do it to be able to upload the new file.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you try to attach the exact same logs, it will not let you. It will tell you they are already posted and show you where. You should not delete old logs as it is never the reason for having a problem. The problem occurs when you try to post duplicates. Also sometimes attaching logs does not work properly because you just need to flush your broswer cache and then do a refresh..

    You still need to respond to message # 12.
     
  15. rpraying

    rpraying Private E-2

    I did decide to leave the Nero related item alone; I just didn't realize what the InCD was related to.

    I deleted the C:\Program Files\Common Files\Symantec Shared. There are at least two other Symantec folders that I've found on my PC under:
    * "C:\Program Files"
    * "C:\Documents and Settings \Rachel P\Application Data"
    * "Windows/system32\config\systemprofile\Application Data"
    Can these be manually deleted w/o causing any problems?

    Also, I noticed a Norton SystemWorks folder under Program Files. Can I get rid of that? Is there some special way I need to go about it? I haven't had Norton on my PC for a few years now.

    I also had HiJackThis fix the Juno and other items in the list, but then when I ran it again just now for this reply post, there were more Juno lines. Is there some reason they continue to come back? Do I just keep deleting them? I noticed Earthlink and Embarq lines this time too, but I already removed Earthlink programs w/the Add/Remove programs function as previously discussed.

    Umm, what is svchost? I often see a lot of those in the task menu, and Comodo just asked me if I wanted to allow or deny an svchost.exe that was trying to access the internet. I had no idea what to tell it to do.

    My system is booting faster than it was, though still a bit too long for my preference. As near as I can tell it's down to b/t 7 and 10 minutes b/4 I can open a program I want to run. Of course that is much btr than b/t 15 and 10 minutes! I haven't tried to print anything yet.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    Yes! Nothing special, just delete it.

    Since you have Spy Sweeper installed you probably have it setup to block changes to those settings. You need to either approve the changes or you will need to shutdown Spy Sweeper to make the changes. Not however that Spy Sweeper may remember the current settings and restore them as soon as you restart or reboot. You may need to approve the changes at that time. Sometime for people like yourself that may not understand all of these protection software settings, it can be easier to uninstall it, make your changes and then reinstall it. See the end of this message for more on Spy Sweeper!!!

    It's a valid Windows process that you will normally see 3 to 6 running. You can allow it.

    There is not too much more we can change. Some of this is due to the protection software having to configure/hook in as your PC loads. There is no way around this. The time it is taking could be due to your PC's specs. What kind of processor do you have (Intel or AMD), what speed is it, how much RAM do you have, how fast is your hard disk and how old it it? When is the last time you did a defrag?

    However since we have a potential issue with Spy Sweeper blocking your changes, please try uninstalling Spy Sweeper. Then reboot. How does your boot time look now? You can reinstall Spy Sweeper anytime you like.


    Other things I noticed.

    You can have HJT fix this next line which you really should not need to load:

    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

    Do you use the below? Is this software still installed?
    O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
    O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
     
  17. rpraying

    rpraying Private E-2

    The SQL Server is used for a home school computer curriculum; when I'm not using the program for the day, I exit out of it immediately after the computer boots.
    Network Magic is related to my DSL, to my Router as far as I know.

    I finally figured out how to take out the Juno, access-4-free, etc., references in SpySweeper so that the HiJackThis fix to those lines would stay fixed.

    The computer only took 6 minutes to boot last night; I actually timed it w/a stop watch. I then left it on overnight to see what would happen; of course, this morning some AVG test was running, and the computer was terribly slow when I tried to open any programs.

    My PC runs WIN XP Home Ed., SP2.
    It has an AMD Duron Processor, 1.20 GHz.
    I have two hard drives:
    * Disc C: 30 GB Available, 57 GB Total, 30 GB Free. (Ran IObit defrag on 9/3)
    * Disk D: 139 MB Available, 3084 MB Total, 139 MB Free. (Ran IObit defrag on 9/4)

    The Physical Memory is 224 MB Total, 43 MB Free, and the Memory Load = 81%. Virtual Memory = 572 MB Total, 239 MB Free.
    Also, here is the memory information from SIW.
    * Maximum Memory Module Size: 128 MBytes
    * Maximum Capacity: 512 MBytes
    * Memory Slots: 4
    * Name: Physical Memory Array
    * Device Locator: ROW-0
    * Capacity: 256 MBytes
    * Memory Type: SDRAM
    * Bank Label: RAS 11 4
    * Form Factor: DIMM
    Does this mean that when we finish cleaning my PC that I can put four 512MB memory sticks in my PC? And is there a specific kind and type I should purchase?

    Also, is there any way to find out if my mother board, processor, or hard drive are going bad? Or any other hardware that might be contributing to this slowdown?

    I get messages every day that my Virtual Memory is too low.

    Finally, of the software that I've installed during this Malware Removal process, should I keep all of it on my PC? Should SpyBlaster, SpySweeper, and Spybot all be running?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well now that makes a little more sense. Your PC is on the slow side and has way too little RAM to be running Windows XP and the additional other software that your are running.

    You should post additional questions on trying to upgrade your RAM in the Hardware Forum. This is not a topic for this forum. Neither is the low virtual memory issue. You need to increase the size of your virtual memory. You can also discuss this in the Software or Hardware Forum.


    My recommendation (besides uprading your RAM to 1 GB) would be uninstall Spy Sweeper because I don't think you have enough CPU speed or RAM to run it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds