FOLLOWED READ ME GUIDE TO THE LETTER--logs attched

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sixshot8, Jun 3, 2011.

  1. sixshot8

    sixshot8 Private E-2

    until recently , my quad core proc. / 6gigs ram pavillionwas totally fast (despite vista) haha! suddenly, fans and drives and resources all full bore when on ie, and multipleerrors and slow,slow,slow!!! Tried everything i know!smarter people sent me here. attached are logs per your guide (4 here and hijkthislog to follow)

    hope you can help me out!

    THANKS
     

    Attached Files:

  2. sixshot8

    sixshot8 Private E-2

    part 2:
    hijackthislog attached
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. But we can clean up a few things.

    First you need to put ComboFix directly on your desktop, not here:
    Running from: c:\users\Michael\dad\ComboFix.exe

    Use windows explorer to find and delete:
    C:\Windows\tasks\ParetoLogic Registration.job

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    I suggest that you post in the software forum for additional assistance with your slowness issues.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  4. sixshot8

    sixshot8 Private E-2

    did everything on list....thanx for quick response. Aside from some really strange side effects--no effect. sending snapshot of task manager. notice the mem usage of iexplore *32 process. what could be causing that?

    Sixshot__
     

    Attached Files:

  5. sixshot8

    sixshot8 Private E-2

    forgot to send this mssg!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal. This is how it shows ( and so do other processes ) when you are running 64 bit Windows.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller
     
  7. sixshot8

    sixshot8 Private E-2

    Thanks again for quick response! in the year before last month, my ie process never got anywhere near that level of mem usage. Attached the
    tdsskiller log! GOOD LUCK--i am frustrated !
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How many tabs do you have loaded when it is showing this amount of memory use?

    Also have you tried running IE with No Addons to see what happens? Right click your IE icon and select Start Without Add-ons. Any change running it this way?
     
  9. sixshot8

    sixshot8 Private E-2

    I don't even use tabs, prefer a new window. The snap I sent is oone open window and no add-ons. 1 of 2 iexplore*32 process 20-30 minutes after openong browser. also, it seems to jump up (as one would expect) when facebooking, streaming vid or playing flash/on-line games. However , it does not drop at all when vid/game is closed. been open for 10 min. right now and it is at 98,320. Everything runs allright, (once in a while a game will hang for a moment or two) but it has never done this before and the noise -- the drive sounds like a $%#@ blow dryer is running. Have run every hardware test known to man -- all say no problems!

    I am at a loss!! Thanks! I appreciate the time and effort.

    Oh yeah, strange: I forgot to tell you -- after the series of malware/combo etc. scans, everything from "program files <*86>" directory, unchanged in directory but missing from start/all programs menu. Menu shrunk by more than half. What the.......? lol
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So are you saying that it only occurs after these kind of activities. And that if you just do normal browsing

    This is signs of a different rogue antivirus tool infection which you had not mentioned and it was not in any of your logs. Had you done any kind of cleaning on your own or on another website before coming here? If you have emptied temp folders on your PC in any fashion, all of these problems will not be fixable because the infection puts the original copies in subfolders of your temporary folders and emptying them would thus delete your files meaning they are permanently gone. Even running certain scanning tools ( like Spybot and others ) will empty your temp folders.


    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find your Start Menu, Desktop, Programs,...etc?


    Now let's also cleanup some leftovers that I had seen from AVG in your logs. This can also slow you down and AVG is a pig. Please run this: AVG Removal Tool.

    Also I had seen the below service in your logs:
    O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe

    Do you still have anything from IObit installed? I did not see any but this service still showed. This can also cause problems.


    And also what is the below for? Another service!

    O23 - Service: DAZ Content Management Service (DAZContentManagementService) - Unknown owner - C:\Program Files\DAZ 3D\Content Management Service\ContentManagementServer.exe (file missing)



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 7, 2011
  11. sixshot8

    sixshot8 Private E-2

    Hello--
    OK....first, (re- the mem usage of the iexplore32 preoc), it is true that browsing triggers the climb and game/str-vid exponentialy moreso. That is not unusual tho, as i am surw you know. The problem is that it seems like every new activity in a browser sesion is accumulating, deswpite the game/vid no longer running. At one point earlier today, after 2.5 hours brwsng, The drive noise was buggin me so i checked the task man. ! of the 2 iex procs (the one cooresponding to sole open app) was at a reasopnable 45,424. The other one..998,754 !! ending process, did not close the browser, but refreshed screen and the drive mellowed and started up the same path.

    Second... I am somewhat of a cleanfreak regarding temp files and folders, and run "ccleaner" as well as "delete browse history" more than necessary. On the rare occasion that i have suspected any problem, I run the avg scan or perhaps spybot. I gotta say -- i am a longtime fan and user of avg. I only find there "safesearch" the newer bells and whistle they have added to be piggish, and i dont use those components.

    third-- SOME GOOD NEWS --the unhide thing *** 100% success. All my "all programs" menu entries have returned. Note that i did not need to remove or uninstall avg at all. I simply disabled it for 15 min (option in avg tools menu). Both the unhide and mgtools dnld and ran seemingly fine. I download a $#@load of "video" via frostwire (prev. limewire) and for 5 or more yrs, AVG has always kept me virus free. At a much lower resource cost than say a piece of overe hyped crap like mcafee!!! Do you think AVG really bad?

    Finally- the issue of drive winding up to a fever pitch, I found some error messages referring to the spoolsvc.exe, so i copied one from disc and replaced the one currentgly in sys32. researched a little and disabled a couple more hp services. It seems to be a little better (until facebook), but i just did it, so wont really know till i go browsing tommorrow. meanwhile- have attache requested logs.

    Thanks again-- I am two years away from becoming credentialed Math teacher...so if you ever need some help with say....trig or calc, you have my address.. Sixshot
     

    Attached Files:

  12. sixshot8

    sixshot8 Private E-2

    NO GOOD_

    got on today, drive spinning - noise unbearable browsere hangin up -- about redy to take this thing out and use it for target practice. Sux tho, cuz for past year, this has been my most kickass computer in 25 or so yrs !!

    :cry:cry:cry:cry:cry

    SIXSHOT8
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you run any hard drive diagnostics? Perhaps you should run a chkdsk on the drive. You can open My computer and right click on the C: drive/ properties and click on tools / error checking.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have not run my previous instructions which ask you to remove AVG. You need to do this if you wish to continue in this forum. Otherwise I suggest that you either post in the Software or Hardware Forum as it does not appear that you are having malware problems but rather software or hardware issues of some sort. AVG has been problematic since Version 8 which is around the time frame we stop recommending it to be used and actually suggested uninstalling it.

    You other option would be to format and reinstall ( start with only Windows itself and nothing else just to check performance ) to see if that resolves your problems. If not then your problems may be hardware.
     
  15. sixshot8

    sixshot8 Private E-2

    I actually DID remove avg for the initial series of scans, including running the avg removal tool. wwhen you later saw
     
  16. sixshot8

    sixshot8 Private E-2

    sorry - hit send i gues -
    when you saw avg proc in taskman pic, it was because i had already reinstalled. As I said, I followed the guide to the letter. Also, I have been running the same version of AVG since I bought this computer 14 months ago. While i dont doubt what you have seen, AVG (in the limited way that I use it anyhow) has been effective and problem free. I have run a number oh hard drive diags -- including diskcheck, and hpdiags, etc. All say all well with drive. Thanks for your efforts to date --

    Sixshot8 *
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe you are missing the point of my request. I'm not referring to uninstalling AVG to run the cleaning procedures, I'm suggesting that it be uninstalled ( and to make sure it FULLY uninstalls since it never does ) to see if it is some how affecting your performance. AVG is a frequent source of performance issues. Has been for a long time. How your PC ran 14 months ago or even a few weeks ago is not the issue. It is how it is running now. Programs update all the time. This includes AVG. One small update can sometimes trigger significant changes in a PC. Also other PC problems ( including malware problems ) could sometime trigger issues within existing software and could cause performance issues. Finding the source of problems like this is very difficult if not impossible and often requires a reinstall to resolve. And a resinstall may be a faster solution time wise. Since you problems only seem to appear when you access certain websites or run certain software, it is possible that it is due to those websites and/or software and the interaction they have with your PC ( possibly even graphics card drivers ).

    There are no malware reasons for your problems even though you have had some malware in the past based on what I saw in your logs and from the fact that you needed to run unhide.exe to fix some issues. We are really finished here in the Malware Forum and I was just attempting to give you something to try in hopes I helping you find the issue for your performance problems. If you don't want to try it that's fine. You can then continue to search for help in the Software Forum to see if you can find a source of software/hardware conflicts that may be causing your problem.



    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
    Last edited: Jun 9, 2011

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds