Everything I do makes it worse!

Discussion in 'Malware Help (A Specialist Will Reply)' started by pcmom, Jan 26, 2009.

  1. pcmom

    pcmom Private E-2

    Sorry if this is too long...Starting Problem:
    xp Home has been slowing down for about 6 months. IE pages would close line by line, and there was always a slight sound delay. Thought I could help myself - Here's what Ive done and the results ( all suggested by forums):
    1. Downloaded Drivermax to update drivers. Before I could finish updating I lost my Wintv2000. Had to start undoing to get it back. I know this screwed up other stuff too.
    2. Did all windows updates. This gave me the res:\\ieframe.dll error. Could not access my connected internet. After so much fiddling and changing settings, I decided to do a system restore.
    3. Did a system restore ( after learning thru all this that it wasnt even turned on!?!) On reboot it said it "could not load personal profile" , so I lost all saved data. Undid the restore back to where I was.
    4. Now the error changed to res:\\ieframe.dll\dnserrordiagoff. Started undoing the windows updates til I found it - for me it was KB960714. Now I dont know which updates to do.
    5. Lost Google toolbar during this. Twice it asked to repair, but it still does not work.
    6. Ran CCleaner ( ok - shoot me now). Did do a backup. Cleaned everyting except tv entries. Im sure this has mucked this further, yes?

    NEW PROBLEMS
    monitor goes black after random periods of time. On reboot it does chkdsk. Computer still slow. Systray icons load in different order every day.

    7. Started at your READ ME OR YOU DIE page. Yes, I have been using msconfig to disable all startups. Changed that. Cleaned, cleared all temp files. Defragged and dusted.
    8. Spybot and Superantispyware are clean.
    9. Malwarebytes has crashed twice now. Errors include "vbAccelerator SGrid II Control...Runtime error = 0., "Malware runtime error 440 authentication error", and then MS has encountered a serious error. I cant find that log file, but it showed two files:
    C:\Docume~1\Owner\LOCALS~1Temp\WER2163.dir00\Mini012309-01.dmp
    " \sysdata.xml

    Phew. I give up and give in to your superior powers. I will not try anything else on my own, and eagerly wait for a savior. Have downloaded Combofix but have not run it yet. Before crashing, Malware showed 11 infections.
    Thank you in advance, and please move to another forum if appropriate.
    Shelley:-o
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Actually none of this really sounds like malware problems. Yes you could have malware, but the problems you are mentioned do not sound like malware. Sounds like you problems within your Windows OS.

    Attach the logs requested in the READ & RUN ME. Yes ComboFix too. Check to see if MBAM made a log. If not, just skip it for now.
     
  3. pcmom

    pcmom Private E-2

    YIKES! Say it aint so...Will start scans again . Where would I find the mbam log?
    thanks so much.
    shelley
     
  4. pcmom

    pcmom Private E-2

    Also, yesterday I deleted all sun java, then installed new ver. 11 Today, java in control panel says cant find path, and all old versions are back in add/remove programs. should I try to remove again?
    Thanks
     
  5. pcmom

    pcmom Private E-2

    sheesh... Tommorow I think I will analyze the string theory.:cry
    Spybot crashed
    superspyware didnt finish
    we've moved from turtle to snail
    Bonus points should be awarded to those who can disable avg8

    The worst of this is I think you may be right. I dont see any malware.
    I await further instruction, and apologize if I have missed steps.
    shelley
     

    Attached Files:

  6. pcmom

    pcmom Private E-2

    Hello again,
    I finally got both scans to run, but I think they are both clean. Disappointing kinda, since now Im left with a sluggish computer. I saw in a thread you recommend deleting adAware. I have used it for years, but if Malwarebytes does the same thing, I will delete. I guess I should delete Combofix as well. One question. You recommend keeping Superantispyware, can I use that as well as avg8?
    thank you all very much for your time and expertise.
    Shelley
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You also need to disable Spybot's Teatimer as requested in the instructions. This will slow you down!!!!! And so will AVG8 in reality when you allow it to install everything. You really should not install LinkScanner.

    You need to put your PC into normal startup mode with MSconfig as requested in step 1 of the READ & RUN ME.

    And you need to attach the log from MGtools which is C:\MGlogs.zip

    Have you installed anything to allow remote desktop access? Like does anything in the below look familiar?
    R4 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2005-03-23 14336]

    The free SUPERAntiSpyware provides no active protection and will not interact in anyway with AVG8's antispyware protection. Ad-Aware is a waste of system resources. Malwarebytes and SUPERAntiSpyware as so much more effective. Just keep them for scanners.

    Do you use and have you ever used BigFix? It is second thing I uninstall from all new PCs. The first thing uninstalled is McAfee or Symantec. The third thing uninstall is anything to do with AOL.
     
    Last edited: Jan 30, 2009
  8. pcmom

    pcmom Private E-2

    Chaslang,
    Thank you very much for the reply. I changed msconfig to normal. I have removed AdAware, ipod, Bigfix(yes I used it for 1 year). Finally was able to re-install correct java. And disable teatimer. Dumped Nortons years ago, and have no AOL. Didnt know about link scanner. Should I disable it or reinstall?
    Found the mglog, but it is old now. should I re-run it?
    Also read the newfile.txt It mentions malware, so Im sending that too. I used remote access to fix my daughters computer. Should I disable that now?

    I beleive now that my problem is with Ram. I have an AMD 64 processor with 512 ram. But on the General page of System info, it only shows 384. CPU usage seems normal, i.e. no large spikes. Page file is 1000mb. Should I turn off DEP? (I checked my husbands laptop - his ram shows as 512, but his cpu spikes to 60% constantly...)

    I know we've left the malware issue, and Ive read your other forums, but I cant seem to free up that ram. shall I start a new topic? I tried running Reimage, but it just stalls. My machine keeps freezing, showing a serious ms error, with different dump numbers every time. Example from Jan 26: BCP4: BA610C4C.

    Also, since windows update gave me that res\ieframe error, I have not updated anymore. Shloud I try them all again, or do one at a time?
    So many questions. thank you in advance.
    Shelley
     

    Attached Files:

  9. pcmom

    pcmom Private E-2

    Hi, I re-ran mgtools
    Shelley
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below but I'm not sure it is still correct as I don't use AVG anymore since I did not like version 8 at all.

    1. Open AVG 8 Anti-Virus Free edition
    2. Look at the top menu and click on TOOLS. A[COLOR=blue! important]drop down menu should [/color]appear.
    3. Click on Advanced Settings. Take a look at the list to your left hand side.
    4. Look on the list for - LinkScanner.
    5. Click on LinkScanner and take a look to the right hand side. You will see two boxes that are checked. Uncheck these boxes
    6. Then reboot.
    See if this helps with your performance at all.


    It's already in MGlogs.zip. You only need to attach what we request.

    Yes for security purposes but are you taking about Windows Remote Desktop or are you referring to the program that I was questioning. I need to know whether you know what that service is for.

    Yes you have the below conditions:
    Code:
    Total Physical Memory 512.00 MB 
    Available Physical Memory 65.38 MB
    That is not enough free RAM to run Windows properly. You need to at least double your RAM to 1 GB. Your graphics card is probably getting its memory by using 128 MB of your 512 MB of Physical memory which is why you are only seeing 384 MB in the report you looked at. Again all the more reason to add more RAM. I belive your PC can have 2 GB max. If you had 2 GB, you would see a tremendous improvement.

    DO NOT disable DEP.

    You need more RAM!!!

    This is a question for the Software Forum but I would get more RAM before you do any more updating.


    Your logs are clean but you should do the below.

    Uninstall the below old versions of software:
    Spybot - Search & Destroy 1.4

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - Startup: services.lnk = ?
    O4 - Global Startup: BigFix.lnk.disabled
    O4 - Global Startup: HP Digital Imaging Monitor.lnk.disabled
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk.disabled

    After clicking Fix, exit HJT.

    Delete the below folder:
    C:\WINDOWS\Temp\AskBarDis

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
    Last edited: Feb 5, 2009
  11. pcmom

    pcmom Private E-2

    :droolGood Morning Chaslang,
    Hearing back from you guys is better than Christmas morning!
    So, I did not walk, I ran out yesterday and had the folks at F* S* install 2G of ram. Of course performance now is better. In an attempt to finish up, I removed Spybot1.4. and AdAware. Reinstalled AVG8, since disabling the scanner leaves an error mark on the icon, so you have to check it every day. I removed the items from HTJ as requested. Deleted all MG, and Combofix
    I dont understand about the remote desktop. I may have done something while connecting with my daughters computer, or when I was trying to get printer sharing working, but I dont need it or want it. Problem is, I cant find the entry or how to delete.
    Also, (ironic since I had no malware to start with), I ran Malwarebytes yesterday and found this:
    C:\REIPostRebootExecuter.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Weird since I use avg, zonealarm, spybot and spyware blaster. The avg scan didnt catch it. But, I am now afraid to flush the system restore. Ran MB agin this morning and it is clean.
    So, to sum up:
    1. I rarely run multiple programs. I keep my process list small. Does ram become insufficient because of all windows updates? My machine used to sing.
    2. How can I remove the NwSapAgent?
    3. Can I flush the system restore?
    Thank you all for your time and patience. Since SWI has died and gone to heaven, I think I will hang around here.
    Shelley
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click on My Computer and select Properties. Then select the Remote tab. Then just make sure the check boxes for Remote Assistance and Remote Desktop are unchecked.

    I don't know what that is but it must have been new since it was not there before.

    Windows Updates especially a Service Pack change can have an effect on RAM usage but the most significant impacts are typically due to the applications you install and run and when they update. Each time your protection software updates, there could be an increase in memory use.

    I cannot find anything really supporting that it is malware so I would just leave it alone as long as everything is running okay.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds