Scan Results..logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by RudyG, Jan 28, 2009.

  1. RudyG

    RudyG Private E-2

    I'm new at this, so will give it a whirl here....
    About 2 weeks ago I ran thru all of the downloads and exercises that you have on your site from, ChasLang I believe it is, on malware removal, and got thru the whole thing miraculously including running ComboFix, with it correcting several problems I was having. I still have a big problem with my internet doing bad things like turning off after a few hours...using DSL and that is all working well...taking way too long to re-boot and then not working part of the time unless I shut the system down completely. Also, when it does get back up, it always waits until a screen or site comes up for DISCmygames which I think either my son installed or it got installed automatically as part of Discover Cards services. It always has a IE Script Error box pop up with it that I have to click off and then shut the MyGames site before using the internet, email, etc. Other than that its just IE doing some little weird things here and there but mainly the problem of IE functioning stops periodically and you see it when you click to go to another site and the page where it says something like "IE cannot find this site or whatever". I do have the logs at hand from the results of the malware operation but couldn't find here how to properly send them to you...I could but knowing me it would take too long to find it. So, if you want them please just direct me to how to do that for you.

    I really do appreciate your site and all of your helpful instructions..easy to follow, and your tools.

    Thank you very much!!
    RudyG
     
  2. RudyG

    RudyG Private E-2

    RudyG..Cleaning the System

    To Chaslang....I'm new at this, so will give it a whirl here....

    A few mos. ago I had a bunch of bad virus and malware get into the system. Probably from someone visiting bad sites. I have the AVG 8.0 program for protection but it didn't catch everything. Around 1/9 I ran your Win XP Cleaning Procedure thru Step 3. This helped a lot...like taking the word VIRUS out of my email program and out of always showing in the system tray. Also allowing several selections to re-appear in the Start box like "Run" & "Control Panel" and allow IE to work much better than it was before running your stuff. I still have a big problem with my IE doing bad things like ceasing to function after a few hours, like when trying to move to a different site it says "IE cannot open or find site". I'm using DSL and that is all working well. The system is taking way too long to re-boot to get IE back to functioning and then not working part of the time unless I shut the system down completely. Also, when it does get back up, it always waits until a screen or site comes up for "DISCmygames" which I think either my son installed or it got installed automatically as part of Discover Cards services. It always has a IE Script Error box pop up with it that I have to click off and then shut the MyGames site before using the internet, email, etc. Other than that its just IE doing some little weird things here and there, along with the Screen Saver not coming on as it did just a couple of weeks ago, I do have the logs at hand thru your Step 3 and will attempt to attach them here.

    I really appreciate your knowledge and all your helpful instructions, which have been easy to follow. I look forward to whatever you can give me to really get the system back in shape.

    Thank you very much!!
    RudyG
     

    Attached Files:

  3. RudyG

    RudyG Private E-2

    Cleaning the System #2

    Here are any other logs I could come up with in regard to Windows XP Cleaning. I couldn't find any logs or anything else from ComboFix which ran and did its thing.

    Thank you!
    RudyG
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Cleaning the System #2

    Welcome to Major Geeks!

    It is right where the procedures said it would be. C:\ComboFix.txt

    Please attach it so that we can continue.

    Also uninstall the below old version of Sun Java:
    Java(TM) 6 Update 7

    Now reboot and after reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Did you purchase Spy Sweeper or is it just a free trial? If free, uninstall it now. If paid, you should not be using Spy Sweeper with AVG8? They are not compatible and AVG8 already has built-in spyware protection.

    Have you been using the below?
    Advanced Registry Optimizer
    Registry Mechanic

    How frequently? We don't recommend using tools like this as they can cause more harm then good and they WILL NOT speed up your PC contrary to the hype they tell you. Even the experts at Microsoft will tell you that they will not improve performance.
     
    Last edited: Feb 1, 2009
  5. RudyG

    RudyG Private E-2

    Re: Cleaning the System #2

    Thank you.
    I have attached the "combofix log"..finally found it.

    I will do the Java uninstall/update.

    No, not using the paid version of Spyweeper so will get rid of that and keep using the AVG 8.

    I have had Registry Mechanic running most of the time for the past 4 mos.

    As for Registry Optimizer...can't remember how that one got in there but have not been running it because I knew I had the Reg Mechanic.

    Will remove both of these.

    So, as for registry problems what do you recommend for a novice?

    Thank you and look forward to you reply. Thanks for all the help!



     

    Attached Files:

  6. RudyG

    RudyG Private E-2

    Re: Cleaning the System #2

    Having a tough time trying to completely uninstall Registry Mechanic...saying cannot delete "PCTLicHelper.dll", access denied.

    Thanks!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Cleaning the System #2

    As implied in my last message, you don't need anything. Stay out of the registry and stay away from registry cleaners.

    You need to attach a new log from MGtools after having uninstalled Spy Sweeper so I can see your real current status. You can get it by doing the below:


    Goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the below logs:
    • C:\MGlogs.zip


    What problems (if any) are you currently having now that Spy Sweeper and Advance Registry Optimizer have been removed!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Cleaning the System #2

    Shutdown Registry Mechanic before trying to uninstall it. You are running it at boot up. The below process shows in your logs:

    C:\Program Files\Registry Mechanic\RegMech.exe
     
  9. RudyG

    RudyG Private E-2

    Thanks for the latest instructions and will attach the new MGtools logs here.

    Still having a problem with IE ceasing to function after a few hours, like when trying to move to a different site it says "IE cannot open or find site". I'm using DSL and that is working OK. The system is taking way too long to re-boot to get IE back to functioning and then not working part of the time unless I shut the system down completely. Also, when it does get back up, it always waits until a screen or site comes up for "DISCmygames" which I think either my son installed, or it got installed automatically as part of Discover Cards services, or is one of HP's pre-installed programs. It always has a IE Script Error box pop up with it that I have to click off and then shut the MyGames site before using the internet, email, etc. Other than that its just IE doing some little weird things here and there, along with the Screen Saver not coming on when it should. Don't know if this, the IE stuff, is a malware issue or not.

    What problems (if any) are you currently having now that Spy Sweeper and Advance Registry Optimizer have been removed! None that I know of.

    Thanks for your help, Chaslang.

    RudyG
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your remaining issues are not malware.

    I see Registry Mechanic installed Are you sure you uninstalled it?

    I still suggest that you uninstall Registry Mechanic.

    This may not be malware. It could be related to your DSL connection and PPOE authentication problems. I suggest that you try using FireFox to see if the exact same results occur after a few hours. Only use FireFox during this test. Do not run IE at all.

    This may be more a function of what you are running and the crap that HP runs. I had a friend with a fairly new HP system and the junk it was running at startup to load some stupid HP Advisor or control center and also an HP Update program (who needs to update at every single boot up) that took a very long time to load up. Also you have a service called GameConsoleService for running a bunch of stupid WildTangent games that HP put on your computer. We uninstalled all HP's junk and everything is fine now. Also you have some junk from Support.com loading up that I would not use since it will slow down boot up too.

    The above would be something you would have to decide you want to do or not. This is not a malware topic for this forum. But below are some things for you to think about.

    What is the below from HP doing? It sure does not appear to be optimizing your bootup if that is what it is really for.
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run


    You also have the below junk running:
    DISCover.exe
    DiscStreamHub.exe

    What are the below? A webcam? Why do they always have to load at startup? Can this software just run when you need to webcam?
    O4 - Global Startup: dotPhoto Go by Noromis Camera Detector.lnk = C:\Program Files\Noromis PhotoLab\BNWCAM.exe
    O4 - Global Startup: StealthFix.lnk = C:\Program Files\Noromis PhotoLab\StealthFix.exe

    All the toolbars are not helping your startup either. Like Yahoo and all the junk from Windows Live.

    All the excess baggage that AVG8 added and that is not needed is also slowing down your startup and also normal surfing is affected.


    Not malware. HP junk that as I said above are things I would uninstall as soon as the PC came out of the box.

    Some additonal suggestions:

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.


    Below are some additional non-malware things you can try.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf
    O4 - HKLM\..\Run: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [RegistryMechanic] "C:\Program Files\Registry Mechanic\RegMech.exe" /H

    After clicking Fix, exit HJT.

    Delete the below files left over from ComboFix.
    C:\WINDOWS\system32\CF20113.exe
    C:\WINDOWS\system32\CF20439.exe

    Also delete the below tasks:
    C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
    C:\WINDOWS\Tasks\COMODO Registry Cleaner task.job"
    C:\WINDOWS\Tasks\Easy Internet Sign-up.job


    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\HP_Administrator\Local Settings\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. RudyG

    RudyG Private E-2

    Dear Chaslang,

    Thank you very much for all of your instructions on the IE problems, slow booting, and the DISCgames stuff. I will be going through your suggestions/instructions as soon as possible and report back. It may be a few days but I will do it. BTW, I did shut off everything that was opening on Start-Up and that alone has sped up some things and did take care of the DISCgames crap....along with a lot of other crap.

    Thank you!!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hopefully not by using MSconfig.
     
  13. RudyG

    RudyG Private E-2

    Dear Chaslang,

    Yes, I did shut down anything running at start-up by using MSconfig. How bad have I screwed things up?

    Thats what I get for talking with someone from tech support at HP I guess.

    Flunking Computer 101,
    RudyG
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Not really screwed up, just not the correct way to manage startup items.

    See this thread, Dealing with Startup Processes.

    Exactly! Just shows what idiots they are.:)
     
  15. RudyG

    RudyG Private E-2

    Dear BJGarrick,

    Thank you for your answer. I will check the link you gave me and avoid HP tech support!

    Learning,
    RudyG
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You're Welcome!:major
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds