Did all the steps, still running slowly ...

Discussion in 'Malware Help (A Specialist Will Reply)' started by exectechy, Aug 24, 2010.

  1. exectechy

    exectechy Private E-2

    Hello there, any help anyone can give would be greatly appreciated, please and thank you in advance.

    I have a computer with Windows XP Home Edition. It didn't have enough RAM, so I bought another 512 MB and added it in, matched set to give a total of 1GB of RAM now. It was running XP SP2, so I upgraded to SP3. Still running slowly.

    I followed all the instructions in the READ ME FIRST and it did find malware etc, I'm attaching logs.

    When starting up the computer it tells me several error messages that I'm having trouble fixing, usually I say "OK" and then it closes the error message boxes and the computer seems to run, just incredibly slowly:

    Program: AirGCFG.exe "procedure entry point apsSearchInterface could not locate wlanapi.dll"

    wzcsldr2.exe could not be found

    error loading: C:\Windows\System32\lxujyuqe.dll
    error loading: C:\Windows\System32\osqznsmOkZ.dll
    error loading: C:\Program Files\yhcbyvuf\wfkrydip.dll

    process DLL.exe failed to initialize properly (0xc0000135). Click on ok to terminate the application.

    Please help! We're a non-profit organization and can't really afford to send the computers to a techy at $70 per hour.

    thanks again, rebecca
     

    Attached Files:

  2. exectechy

    exectechy Private E-2

    Here's the last file to attach:

     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like SAS and MBAM took care of the malware, however, I would like you to run both on each user account. Attach any logs that find any malware ( be sure to identify the account ).

    What issues are you still having?
     
  4. exectechy

    exectechy Private E-2

    Ok, sorry this took so long to do. And thank you for clarifying for me that I should have run the tools on all user accounts.

    I've run the tools on the other user account now, which in the beginning it wouldn't even attempt to do. That's why I originally ran it on the secondary user account. Had a terrible time running MGTools, finally deleted the mgtools.exe icon, then redownloaded the file, and then ran ok except for error message #4 which recommends I should download Microsoft .Net framework. Should I?

    I'm attaching the logs for the other user today. It appears to be starting faster, ie: the desktop appears much more quickly. However, as soon as you click on anything and try to use it, the computer freezes with the hourglass icon and slowly, 8 mins or more, finishes booting up.

    Then the following error messages appear:

    1. AirGCFG.exe - Entry Point Not Found
    "The procedure entry point apsSearchInterface could not be located in the dynamic link library wlanapi.dll"

    2. WZCSLDR2.exe - Entry Point Not Found
    "The procedure entry point apsInitialize could not be located in the dynamic link library wlanapi.dll"

    Once finished booting up it finally gave me wireless internet access, but now it's saying I have a very low signal strength, which it didn't say before. Ran repair, and it still says the same thing.

    Is there any way to get it booting up more quickly, and to get rid of the warning messages it's giving me? thanks again for your help,

    Rebecca
     

    Attached Files:

  5. exectechy

    exectechy Private E-2

    Here is the final log file for the recent tools run.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    WZCSLDR2.exe is the driver for you wireless connection. Have you looked in device manager to see if there are issues with your wireless card?

    AirGCFG.exe is for a D-link wireless. Also look in device manager.

    I am not seeing any malware remaining in your logs. I suggest you post in the software forum ( or networking ) to try to resolve your internet issues. One suggestion is to uninstall Comodo and see if that helps with your startup times.

    Boot into safe mode and see if your startup is also slow.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  7. exectechy

    exectechy Private E-2

    Thanks for your help getting rid of all the malware. I'll post in the other forums as you mentioned.

    Thanks again,
    Rebecca
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds