any help, or a torch for my comp, would be appreciated

Discussion in 'Malware Help (A Specialist Will Reply)' started by melmar98, Jun 8, 2008.

  1. melmar98

    melmar98 Private E-2

    This all started about a month ago when I got my laptop, and the children began using the desktop on a more regular basis. (At least I'm pretty sure, and will be blaming them anyway.) Son (age 7) was looking for cheat codes for his danged video games unsupervised.

    Computer got slow, so I ran a scan on avast. It had a few things come up - deleted them. It was still slow, so I opened and ran adaware. It found close to 300infections - some in my avast files. It then occurred to me avast had not been updating.

    I removed those files, and them, removed avast all together. (I have since been told that may not have been a smart thing to do)

    Looked at majorgeeks forum and thought it seemed like a lot of complicated work.

    Bought spyware doctor - it found another hundred or so infections, and a trojan or two.

    bought uniblue registrybooster 2, ran it.

    Ran defrags.

    turned off system restore, ran spyware dr in safe mode, found another crap load and removed it.

    I think that was all - and then it was still incredibly slow. Scans show a clean computer, but start up is excruciately slow. Starting apps such as IE, firefox, paint, control panel.... all slow.

    Back to major geeks, and over a series of days I have completed basic comp maintainence, read & run me, and XP cleaning procedures.

    I don't know what to do at this point - I am at the mercy of the MG gods. :major


    attached will be the logs requested, and a jpeg of warnings new since running the XP cleaning procedures.
     

    Attached Files:

  2. melmar98

    melmar98 Private E-2

    :major <---- I love this guy!! ;)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your problems are not due to malware. Most are due to what you are running and the fact that you do not have an adequate amount of RAM installed. You have only have 256.00 MB installed. I recommend 4 times that be installed at a minimum for truly proper operation of Windows XP with todays type applications.

    Let's do a few things that should help (but you do need to add more RAM).

    • Why do you need O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe running? Is this for an ADSL Modem. Why does it need this service?
    • Uninstall SUPERAntispyware now since we are finished with it.
    • Uninstall Ad-Aware 2007 which is a waste of resources for what it detects. It also keeps a service running full time. SUPERAntispyware or Malwarebytes are many times more useful/effective to have as scan only tools.
    • Also uninstall Ewido which was discontinued long ago (since it may not show in add/remove programs, I have steps below to remove its servic) and you have Spyware Doctor installed now (which can be quite resource greedy itself).
    • You appear to have a broken uninstall of McAfee wasting resource. Run this McAfee Consumer Product Removal Tool and then reboot. You have no antivirus program installed!!
    Now Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to DSBrokerService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Service (if you do not find them or get any errors, just continue):
      • ewido security suite control
    • Click OK until you get back to Windows.
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab

    Optinally have HijackThis fix the below which are not required to always run
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Delete the below folders if found:
    C:\Program Files\ewido\security suite

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.




    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! You do still need to install an antivirus which will cause a performance hit.
    It also looks like you may need to reinstall Spyware Doctor based on the error message snapshot you posted.
     
  4. melmar98

    melmar98 Private E-2

    working on it...

    I cannot uninstall Adaware. Getting an error. What info I find online says install 2008, then uninstall it all. I wanted to ask you, since we're in the middle of all of this.
    Also - starting the HJT now... if I needed Adaware gone first, let me know to re-do.

    Thank you for all your help.

    This computer has never been this slow... even with more program ("crap") on it.
     
  5. melmar98

    melmar98 Private E-2

    oh - and the Tango was the software for the modem. Tango Manager, efficient networks, Alltel DSL Support, connectivity, monitoring, test and repair.


    -------------

    Successfully entered into the registry.


    Do not know where the following was to occur.

    Delete the below folders if found:
    C:\Program Files\ewido\security suite
     
    Last edited: Jun 10, 2008
  6. melmar98

    melmar98 Private E-2

    all done but the removal of ad aware.

    also - the spyware doctor is "with anti-virus". Is this sufficient?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use the below steps.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Ad-Aware 2007 Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteaawservice into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot when it tells you it needs to.

    After reboot, delete the below folder if it exists:
    C:\Program Files\Lavasoft

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know what it is for. My question is why do you need to have it running all the time. Things like this are a waste of system resources and you were complaining of a slow PC which is a result of running unnecessary software. If your DSL line is broken all the time and needs this software everyday then find a new ISP otherwise, uninstall it (or at least disable this service so that it is not always running) and only run things like this when they are need which should be rarely. Again if it is not rarely, you need a new ISP.


    SpywareDoctor with AV is fine but I see you installed it around May 21st. When did your PC get slow?


    How are things running now? As I said earlier 256 MB of RAM is not adequate these days.
     
  9. melmar98

    melmar98 Private E-2


    Tango - oh... I understand what you're saying now. I assumed Tango needed to be open for the DSL to work. So if it is only for communication - no, I haven't used it in a year? Maybe longer.

    Spyware doctor - I guess it was May 21, or a dqay or so before that I noticed how incredibly slow the computer had suddenly become. That's when an adaware scan found spyware located in my avast files. So I uninstalled avast, found Spyware doctor and installed it.

    I have no idea what RAM really is, or how much is needed for what. :eek: I admit that and I am at the mercy with full, honest, sincere gratitude of anyone that can help me.... what I don't understand though, is this: I understand you're telling me I need more RAM, that 256 is not adequate... but up until - say - 2 months ago, it was completely adequate, and none of these problems existed. The only changes made was the deletion of a crapload of spyware, cookies, a few trojans, and I added Spyware Doctor. (And all the advice given here) I will gladly remove spyware dr to see if it makes the difference.
    Out of curiosity - could deleting the spyware have deleted something by accident thatthe computer needed?


    As for how it's running - it's pretty much not.

    Spyware Doctor has been "starting" for about 20 minutes. It will not let me click anything anymore.
    Double click Mozilla on Desktop, IF it starts at all, it's 2 minutes from double click to google page displayed.
    IE - 2 minutes as well, when it doesn't freeze up. It's not what I typically call freezing, since the cursor moves, it just doesn't recognize anything as clickable. One double click took a minute and a half before the computer even recognized I had clicked, then another 2 minutes to open.
    When a browser does come up - I tried to minimize it, it took 20 seconds to minimize.

    It doesn't sound like it's even running anymore. It's back to a "frozen" state.

    I am using my laptop to make this post.:cry
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try uninstalling all of Spyware Doctor just to see if there is any noticeable effect.

    One other item I see running is C:\WINDOWS\System32\wbem\wmiprvse.exe which is a valid Windows process however there have been issues where this has been the cause of noted slow downs on a PC. I'm not sure what the fix is though. Do you have all of your Windows Updates? Dp you see wmiprvse.exe using lots of your CPU in Task Manager?



    Performance issues can sometimes occur due to physical problems too. For example:
    • hard disk could be starting to go.
    • memory failure issues (not just inadequate amount of RAM, actual bad RAM)
    • issues within the Windows files system
    • hardware or driver issues that are affecting the PCs performance
    • overheating
    Normally when there is no evidence of malware and issues like this are occurring the above are more likely the issues. Some of the above could be cured by doing a total reinstall. Real physical hardware issues obviously would not be cured by a reinstall.

    After uninstalling Spyware Doctor, reboot and then do the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below log:
    • C:\MGlogs.zip
    Is there any visible improvement?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds