Computer problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by skilldave, Sep 22, 2006.

  1. skilldave

    skilldave Private E-2

    Hi, downstairs computer is running painfully slowly, especially at start up. I've done all the instructions, and post the logs. The panda active only found a few problems scanning my computer, and none in the local discs.

    Thanks a lot
     

    Attached Files:

  2. skilldave

    skilldave Private E-2

    (more logs)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't really show any major malware problems that would be slowing you down. You do have a couple things to fix but first you appear to be using AutoRuns to disable startups. This presents similar problems for us as does MSconfig. And you do have couple things in the AutoRuns key that must be remoed. We will try the registry patch below to remove them.

    But first I have a question, what is the below for:
    C:\Program Files\PP Snooper S2 Updater\PPS2SnooperUpdater.exe

    Make sure viewing of hidden files is enabled (per the tutorial).
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {A1F642A5-3C33-1B7B-CD3D-9B09FF7B53C5} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\All Users\Application Data\boobsendcdromball <--- the whole folder

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    If the above does not help alleviate your performance issues then move on to the below.

    Click on Start, then Run and type services.msc into the box that opens up, and click 'OK'. On the page that opens, scroll down to Automatic Updates and right click on it and select Properties and click Stop Service. When it shows that it is stopped, please set the Start-up Type to Disabled. Press 'OK' until you get back to Windows.

    Now reboot and let me know if there is any change to your PC's performance.
     
  4. skilldave

    skilldave Private E-2

    Hi. The snooper thing is linked to a sat nav programme i think, but don't think it's in use so uninstalled it.

    There's been a definite improvement, so thanks for that. Still takes quite a time to be able to do anything at startup. Have to leave it for about 3-4 mins without touching any programmes before anything will load up.

    I did all the steps on the last post, including the last one.
    Here's the latest hijack logs.

    Thanks a lot,
    Dave
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but which part improved the performance? The first part, or the second part where you disabled Autoupdated?


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\All Users\Documents\My Music\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Documents and Settings\All Users\Documents\My Music\PartyPoker.exe (file missing)

    After clicking Fix, exit HJT.
    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and attach a new HJT log.

    Make sure you tell me how things are working now.
     
  6. skilldave

    skilldave Private E-2

    It was the 1st step of the original post which helped improve the performance. The automatic updates change didn't seem to do much.

    It still takes a time to be able to do anything at start up, and takes quite a time after that until it calms down and works reasonable normally.

    Did the steps in the last post, and attached the latest log

    Thanks.
    Dave
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you should go back and Start the Automatic Updates service and set the startup type back to Automatic.

    Based on your logs, it is not malware. It is more than like some other non-malware issue. You have to realize that it does take awhile for your protection software (AVG, Windows Defender, and ZoneAlarm) to hooked and configure itself. This is a necessary evil in order to keep your system safe. But I will give you one more thing to check for (but I doubt it will find anything). Run the steps in the below link:

    Using Sophos Anti-Rootkit

    Then attach the requested log.
     
  8. skilldave

    skilldave Private E-2

    didn't seem to find anything. here's what the log said anyway.

    Thanks.
    Dave
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was what I suspected. As I said, I don't believe you are having malware issues. Whatever you are experiencing appears to be slow downs due to the applications you are running. If things are okay after intitial startup of all applications truly completes then it is probably normal delays for what you are running.

    You could try other things that are not topics for this forum:
    - defragged hard disk
    - registry backup, registry cleanup, and registry defrag (not the same as hard disk defrag)


    Since you really are not having malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds