PC slow and files deleted

Discussion in 'Malware Help (A Specialist Will Reply)' started by dc67, Feb 14, 2008.

  1. dc67

    dc67 Private E-2

    I am new and not sure where to post this. My computer is 2 years old and runs very slow. I have tried runniing every kind of cleaner/degraf/malware/adware/virus software, whatever I can find, no help. I ran a regitry tool yesterday and deleted my modem, pci communication controller and many dll files. PC is very slow and even more screwed up now.

    I red all of the pre work and downloaded and ran everything. I will atatch it at the bottom. Any help would sure be appreciated.

    Dell P4 2.8ghz, 1 gig ram
    I have windows XP. I had 512mg ram orginally and upgraded that to 1 gig. That sisn't seem to do much. I have been wanting to buy 2 one gig sticks but old ddr ram is very expensive.

    I am not sure if it is malware or not, I am jsut trying to give as much info as possible to try and find a solution. I do not know what to do to reiinstall the things that plug and play keeps finding. I dont have anything that I can find or on the Dell site. I have ran scf /scannow and it stops about every second and says it cant find dll file...whatever. I have the xp dixk in when it is running. I am thinking about reloading windows over the top for a repair.

    Thanks for any help.
     
    Last edited: Feb 14, 2008
  2. dc67

    dc67 Private E-2

  3. dc67

    dc67 Private E-2

    I just wanted to move this to top. I still need help.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    I have added your logs from your other post to mine here so the malware experts can review them.


    but a heads up on BUMPING your thread as it does not help your cause as having your thread at the top is basically putting yourself at the bottom of the work queue.

    Don't Bump! It Only Hurts You!!!
     
    Last edited: Jan 26, 2009
  5. dc67

    dc67 Private E-2

    OK, Thank you, I will just wait.
     
  6. abri

    abri MajorGeek

    Hi dc67,
    Your other thread was in Software. Did the Software Forum people suggest you should try looking for malware?
    abri
     
  7. dc67

    dc67 Private E-2

    They told me to post my files here. If you find nothing in any of the files than I guess I go back to the software forum.
     
  8. abri

    abri MajorGeek

    Hi dc67,

    GetRunKeys which is part of the MGTools didn't run correctly. Also, your uninstalls list is missing in the newfiles log and your uninstalls list is completely empty. Do you know why? Did you get any errors when you ran the MGTools? If so, what?

    abri
     
  9. dc67

    dc67 Private E-2

    I dont remember any errors when it ran. Can I run it again? If so, I'll run it all again and post.
     
  10. dc67

    dc67 Private E-2

    I just ran them again and got a few errors.

    unexpected error- mod registry_inigetstring.........................
    error#5 invalid procedure call or argument

    c:\windows\system32\cmd.exe
    c:\program~1\symantec error..........................


    I will attach the new file.

    Thanks
     

    Attached Files:

  11. abri

    abri MajorGeek

    Hi dc67,
    I think they're correct this time. Let me take a look.
    abri
     
  12. abri

    abri MajorGeek

    Hi dc67,

    I'm not sure if your problem is malware. You have a lot of module useage registry keys that seem to be related to Sunbelt Counterspy, but I don't find this program anywhere else. Have you installed and uninstalled this and if so, how did you uninstall it?

    1) Your computer is not in normal startup mode, therefore all your startup entries don't show up in HijackThis where they can be fixed. To put your computer into normal startup mode click on Start / Run and type in msconfig and check the box that says normal system start. Accept the change and then click on okay. The computer will probably reboot itself.

    Also, you have Teatimer enabled. Please disable it as follows:

    2To begin with, please disable Spybot's TeaTimer. This can be done two ways.
    First:
    • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
    • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
    • If you have Version 1.4, Click on Exit Spybot S&D Resident
    or Second, For Either Version :
    • Open Spybot S&D
    • Click Mode, choose Advanced Mode
    • Go To the bottom of the Vertical Panel on the Left, Click Tools
    • then, also in left panel, click Resident shows a red/white shield.
    • If your firewall raises a question, say OK
    • In the Resident protection status frame, Uncheck the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active
    • OK any prompts.
    • Use File, Exit to terminate Spybot
    3) Go to add/remove programs and uninstall the below:

    Viewpoint Manager (Remove Only)
    Viewpoint Media Player
    J2SE Runtime Environment 5.0 Update 6


    4) Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

    After you click fix, just close hijackthis.


    5) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger

    6) If you can find this folder, please look at the contents and see if it belongs to Java. If so, please delete it.

    C:\Documents and Settings\doug\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142160}

    Also, delete this:

    C:\delete.bat

    7) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.

    Let me know how things are running now?

    abri
     
  13. dc67

    dc67 Private E-2

    SHEW< Here I go:

    I deleted the two viewpoint programs. I cannot delete the J2SE Runtime Environment 5.0 Update 6, I get an error 1316 a network error occurred while attempting to read from file c:\\windows\installer\jre1.5.0_06-iftw.msi, then I get a fatal error after that. I deleted windows messenger and restarted with a normal start up. I could not find C:\Documents and Settings\doug\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142160} or
    C:\delete.bat. I shut down t timer also. I ran the MGTools again and I am attaching the zip file. It still runs slow. Thanks for looking into it.

    Also, no idea what Sunbelt Counterspy is?
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems do not appear to be related to malware. Back in message # 1 you said this:
    Are you referring to the below tools?
    Code:
    "C:\Program Files\"
    REGIST~1      Dec  3 2007              "RegistrySmart"
    REGSCR~1      Feb  2 2008              "RegScrubXP"
    
    Did you ever try restoring what every deleted from a backup would assume you made with these programs before deleting everything?

    Also when you say your PC is slow, are your just referring to a particular thing like running programs or is it other things like the below:
    1. slow startup?
    2. slow shutdown?
    3. slow opening up/running all programs?
    4. slow browsing the internet?
    5. is it also slow in safe boot mode?
    How long ago did you upgrade from 512Mb to 1Gb of RAM? And did your problems begin after adding more RAM?

    I'm going to give some steps below that you need to do anyway but I really don't think this are going to improve things.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you receive a success message about adding the above to the registry. Also make sure when you return you tell me the result of adding this patch to the registy.

    Now click Start, Run and enter cmd and click OK. This should open a command prompt window. In the command prompt window type the below bold print command and then hit the Enter key. Note there is a space after the sfc but there is no space after the /

    sfc /scannow

    The above command will run System File Checker to look for missing or corrupted Windows system files. If it finds problems that it can not fix from other copies on your hard disk, it may ask for your Windows XP CD so be prepared to insert the CD.

    After doing the above, reboot. And then continue with the below.

    Delete the below folders.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the new C:\MGlogs.zip file that was just created.

    Now answer all of the questions I ask about your PC earlier.
    Also tell me if the registry patch got added in successfully.
    Also tell me if sfc ran and did it find any problems that could not be fixed?
    Also indicate if anything has changed.
     
  15. dc67

    dc67 Private E-2

    Everything was added to the registry fine. I tred to run the sfc scan last week and every second,literaly, the screen popped up and said missing dll file insert cd and hit ok, I did this for over and hour , thought that restored them. It is doing the same thing again. I have hit ok 150 times already. I deleted the Morpheus stuff also. As for your other questions:

    Also when you say your PC is slow, are your just referring to a particular thing like running programs or is it other things like the below:
    slow startup? VERY SLOW

    slow shutdown? average probably

    slow opening up/running all programs? yes, very slow

    slow browsing the internet? not as fast as 5 year older pc with 512 meg of ram.

    is it also slow in safe boot mode? not as slow

    How long ago did you upgrade from 512Mb to 1Gb of RAM? And did your problems begin after adding more RAM? It was slow before, thats why I upgrades. It was a little over a year ago. PC is 2 years old.

    The program that caused the missing hardware was called easy cleaner I downloaded off of another site like this one that I wont name. It didn't back itup either. My problems with it beinng slow go back way before that though. I will run a new check and attach the results. I have not rebooted because it didn't seem like SFC was working anyway. All of the missing DLL files could be part of my problem.

    Thanks for the help, I sure hope you can figure it out.

    I keep getting this error when I run MGTools.exe:
    C:\\windows\system32\cmd.exe
    C:\\Progra~1\symantec\s32evnt1.dll.an installable vertual device driver failed dll installation. Choose close to terminate the application.

    I just hit ignore.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then I suggest that you post this information in the Software Forum where you can get help on with your Windows problems. This is not a malware problem. You have many missing or corrupted Windows files which can cause all kinds of issues. You may have to do a repair or a reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds