Continuing problems in Vista

Discussion in 'Malware Help (A Specialist Will Reply)' started by ellen46240, Sep 4, 2015.

  1. ellen46240

    ellen46240 Private First Class

    Before I opted to scan for malware, since I am having unexplained hangs in Vista, Firefox with Avast AV, I did a registry scan and cleaned it (after saving it). [Please see my posts in Software regarding this problem]. Beginning the Malware removal basics, I then see DO NOT clean the registry! Should I restore it before scanning? Include a copy? None of the above? I'll wait to hear back, before continuing. Thanks
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. ellen46240

    ellen46240 Private First Class

    I did not assume this was malware. It seems browser related, with hangs. Just stops in it tracks. Vista Business, firefox (current), Avast Internet protection, and Malware Premium. Just going to a tab might cause it to hang. 2 different computers showed the same problems, but modem replacement was thought to be the fix. Not so. I had run CCleaner, thinking cleaning the registry might help to fix the problem (before I opted to come here, and do Malware scans). I know the normal procedure, is to do all scans first before posting.. until I saw the big warnings, do not clean registry. So, I asked before proceeding.. do I restore it, or do I complete the scans (now) and include the back up registry file.. or??

    Very frustrated with a new-to-me (supported OS..) computer, which I thought might work right off. Not without problems!!

    Thanks for the help..
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just go ahead and complete the scans. ;)
     
  5. ellen46240

    ellen46240 Private First Class

    Scans are run as noted:
    RK stopped the scan to open up another scan program attempting to load itself.. I had to say no, and then never as it tried again. (Never saw that before). It also tried to sell me a different premium program along the way, declined.
    MB Premium (up to date) is already on my computer, scan found no threats
    HMPro nothing found
    Running MGTools, finally got it into C: but forgot to terminate MWB, and to close Firefox. It ran, but the Agreement form was hidden under Explorer pages. After nearly a hour, I terminated MWB, and tried to extend the disable period of Avast.. only that didn't take. So I did close MB.exe and re-run with MWB off and FF closed. MUCH faster.

    Is the problem fixed? I don't yet know. It occurs in Firefox, and had also occurred in Chrome. The first Vista computer I bought (3 wks ago) was unprotected for several hours downloading AV and AM. It would hang in Firefox, requiring a reboot. It did not appear to create error reports, and could not be exited, w/o power-down/reboot. I took the computer back. They gave me a different one, but put my first Drive back into the new machine as D: (It could have contained the problem?) It too hung in FF. Modem was replaced, which helped. Performance set to best, MS updates current. Driver Booster found one and updated. There may be some I have missed, when I went to Dell for theirs. I may not have fully activated my account, only noticed later. I've cleaned off most all excessive programs, files, etc. Avast scan found PDVDDXSrv as excess, I uninstalled it, and noted WSHReset "problem"(?). Disabled CCleaner run-time, and SoundMaxPnP, and Defender from startup. Noted several warning/failure notices trying to update IE9, but then disabled it, as best I knew how. GMAIL always slow to load, showed "another occurrence on my same IP" at bottom of page, and that was found to be from D: programs apparently, which I then disabled, without any apparent bad consequences.

    With FF open.. it might fail to load Gmail.. or work perfectly, until I go to a tab, or webpage, and it just freezes. Might happen once a day, might happen 15 seconds after opening FF, might be 4 times in a half hour. I have to power off, as waiting does nothing, (while modem still shows some activity).

    Virus? Malware? Operator head-space adjustment incorrect?? I will very much appreciate the viewing of my logs, and any suggestions, or web pages which point to settings that will make this work. So far, about 2 weeks, trying to make this work.

    MANY!!! Thanks! Jerry
     

    Attached Files:

  6. ellen46240

    ellen46240 Private First Class

    How risky is it to "test this" by going on line with UAC disabled? Should I turn it back on, or stay off line? Trying to see if it still bombs.
     
  7. ellen46240

    ellen46240 Private First Class

    Since posting (minus 2 hours doing other things).. the browser has hung twice. Once on ebay (with Gmail account open too), and again when I attempted to load Gmail, it also hung. Problem is still there! Not to say there are not other problems, but this is how it is manifested. Thanks!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sorry for the delay. I'm in the middle of moving house. Are you deliberately set up to use a proxy?
     
  9. ellen46240

    ellen46240 Private First Class

    No problem,.. moving can be a real pain! Hope it goes well for you !

    FF is set to no Proxy
    I don't see any proxy settings in Internet
    And Network doesn't show any proxy settings.

    Where else do I look? (Or am I looking in the right places?) No, it's not set up deliberately to use a proxy
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thankyou. :)

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.


    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix item using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate this detection:
    • [PUM.Proxy] HKEY_USERS\S-1-5-21-2121391171-1027073938-2754388828-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 0.0.0.0:80 -> Found

    Place a checkmark next to this item, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.

    Now run RogueKiller again and attach a log.
    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. ellen46240

    ellen46240 Private First Class

    Kestral,
    Logs attached include A and B on RK (first and second). To accomplish, I did disconnect Ethernet from modem, and disabled AV and AM to run all. The keyboard file found by RK doesn't look good! But then again.. it wasn't working right without coming to malware removal, so hopefully this can all be fixed.

    Again Sincere thanks!
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What RogueKiller found was fine. I'm concerned about the proxy. Can you run RogueKiller once more please and attach log.
     
  13. ellen46240

    ellen46240 Private First Class

    Normal boot, read your post, unplugged modem, disabled AV/AM, closed browser, ran RK, new log posted. :)
    THANKS!
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing anything else to do in this forum. Your issues are not due to malware. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  15. ellen46240

    ellen46240 Private First Class

    Good to hear no malware. Steps 1-6 done. Will goto 7 next..

    Two questions? Should I, or can I, run RK again to elminate PUPs and PUMs? It seemed several were listed. And secondly.. if this problem continues.. do you have suggestions as how to proceed? Different; browser?/AV?/AM?/full updates from Dell?/different OS? I thought (being valid and supported...) that Vista might be a step up from my 2 old XP machines.. yet something is not compatible, and constant hangs on simple browser tasks doesn't really... "compute". I've read more MS posts, and forum notes, and browser fixes for about 3 weeks now, with no end in sight. And the posts in Software forum (here) didn't hit home (or a fix).

    Many thanks however for all of your help, and quick responses in this department. Hope your move is over, and was easy enough ;-) Jerry
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thankyou very much, I'm getting there slowly but surely with the move. :)

    Everything RogueKiller shows is absolutely fine, all legit and nothing for you to worry about. My only concern was the proxy entry which is gone now.

    You can post in the software forum about what steps to take next. Best of luck!
     
  17. ellen46240

    ellen46240 Private First Class

    I do have a few questions, which might apply here. I had disabled drive D: (which was on the first computer I purchased a month ago). When I returned it due to hang problems, they gave me a new computer, but also loaded the original C: drive on it, as D: (so I could recover files, etc.). But nothing on it had been changed, and it was apparently causing some problems, in that GMail showed "another instance of log on, at my current IP address". Looking at D: showed files updated on that same date, so I disabled it. Before doing so, my Documents were listed as "Unavailable" (for reasons I did not understand).

    So the question becomes: If I reactivate drive D: should I again go thru the scan process? Or will I have to uninstall programs from it? Or delete them? Or are my Documents now lost? So far, I have not had another hang since we finished the malware removal (or check..) since nothing was found.

    I plan to load Comodo 8, but uncertain if MalwareBytes Premium would/should be disabled if I do so. Please advise if any of this is valid here? Of if all would be answered in Software forum? I just don't want to bring back potential problems, if I re-enable that drive.

    I do have a year of use on a XP machine, which does have serious problems, which I will begin scanning soon. Could the drive be added to it, since it has not be diagnosed as of yet? Or does Vista have some encryption which would render Documents unreadable on the XP computer? Sorry for so many questions, but my own knowledge is limited. Thanks! jerry
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you can ask about all of that in the software forum. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds