Computer still buggy after doing everything in the guides

Discussion in 'Malware Help (A Specialist Will Reply)' started by BaLaTa, May 30, 2008.

  1. BaLaTa

    BaLaTa Private E-2

    Hi. i found this site very helpful and would like to extend a big thanks.
    Before doing all the scans my pc had many issues:
    - explorer process would shut on and off
    - extremely slow pc
    - games would have serious fps drops that wouldn't occur a while back.
    - internet glitches i never had before.
    - crashes.

    I've used another guide before yours, so i have 2 combofix logs, the second from your guide.

    i also did the scans several times so I'll attach the most recent ones i can have.

    I've done the basic maintenance, alternative scans (a-squared), and the "Keeping your computer safe and secure" step.

    I'm using eset nod32 and did a full scan in safe mode (which took a day!)

    At the moment, my computer runs better and faster. most scans founds a bunch of stuff like vundo and others i cant recall.
    Still. I'm suffering from some issues:
    - crashes and slowness, though less often.
    - games that should run fine still suffer drops and wierd connectivity (to interent) bugs i never had before, like when logging in or updating (taking forever).
    - odd bugs and windows error crashing some software or game. something about dr.watson debugger too whatever that is.

    my impression is something is using up my memory and/or internet bandwidth somehow, thus choking it/them.

    would really appreciate a response to finally finish the long exhausting battle for my pc. thanks :)
     

    Attached Files:

  2. BaLaTa

    BaLaTa Private E-2

    Another attachment :)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    As stated in the READ & RUN ME, we don't want you to do this since it hides the initial root problems from us making it impossible for us to know what the original problems were. Thus when issues may still remain, we cannot begin to guess if they are related.

    Unlikely to be related to any malware since your logs are basically clean.

    What is the below?
    C:\Program Files\Emily\Emily.exe

    It is a service shown running in your HijackThis log:
    O23 - Service: Emily (EmilyService) - Unknown owner - C:\Program Files\Emily\Emily.exe

    I suggest that you uninstall A-Squared now and then do the below but you do not have any remaining malware to be worried about. I would be more concerned about all the services Nero has running.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  4. BaLaTa

    BaLaTa Private E-2

    Hey. Thanks a lot for responding! and sorry for taking so long to reply.

    I did the registry thing and got a successful message.

    Emily is a program belonging to a UPS machine, which helps with electricity issues like shortages and such.

    How can i prevent all the Nero processes from turning on? i unchecked all Nero related startups i saw in Spybot S&D, but many are still running regardless.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before trying this, have you uninstalled A-squared? Did that help?

    What features of Nero do you use? Do you use the below?
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
     
  6. BaLaTa

    BaLaTa Private E-2

    I did uninstall a-squared and i didn't feel any difference.

    I use none of those processes you mentioned. The only thing i need nero for is burning DVDs (data audio and video)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then try the below.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to InCD Helper
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Services (if you do not find them or get any errors, just continue):
      • Nero BackItUp Scheduler 3
      • Nero Registry InCD Service
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste InCDsrv into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below Services (if you do not find them or get any errors, just continue):
      • NeroRegInCDSrv
    • Now exit HJT and reboot when it tells you it needs to.
    Any change? If not, I suggest you post in the Software Forum.
     
  8. BaLaTa

    BaLaTa Private E-2

    the performance has improved slightly but drops and some crashes still occur. I'll take it to software forum.
    is there anything else you think i should do?

    otherwise I thank you a lot, this is a great, friendly and professional forum :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let's also clean up from running the READ & RUN ME and give you some final tips.
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds