Gen-Nullo Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by IBleed4Thee, Aug 30, 2013.

  1. IBleed4Thee

    IBleed4Thee Private First Class

    Not sure what is going on with my system. But this is my second cry for help in less than two weeks. My logs are usually clean. The only change that I did make was to change from using Avira to AVG. So I'll start from there.

    Yesterday AVG ran a full scan and it came up clean. No alerts went up during the entire day/night showing that it picked anything up. This now makes me now pleased with AVG. Last night I ran SuperAntiSpyware before going to bed...and let it run. This morning is showed that it had found a the Trojan Gen-Nullo and that it needed to be removed. I kept a log of that on desktop. Strange that AVG didn't pick that up. So I ran a scan of that folder and it did not pick it up. The log is clean. So I removed the Trojan via SuperAntiSpyware. I use MalwareBytes but on occasion (once a month) will run SuperAntiSprware to see if MB has missed anything. 99.9% of the time both of those logs are clean maybe except for a few trackings.

    After AVG missing it I wasn't completely comfortable that it was completely gone so I ran the Malware programs and the logs are attached. I am attaching the SuperAntiMalware logs also. So things have shown on the logs that look like they need attention.

    I am super careful where and what websites I go to...and especially what is downloaded. The only time (which is very rarely) I download anything is via Download.com and I always run the antivirus on it before I open it. Everything is up to date and ran on a weekly basis.

    This is what SuperAntiSpyware found which I'll attach first and then the required logs.

    Trojan.Agent/Gen-Nullo[Short]
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{D3A05601-4E56-4A91-B0A1-2109F59F571B}\RP3\A0001063.EXE
     

    Attached Files:

  2. IBleed4Thee

    IBleed4Thee Private First Class

    Attached required logs.
    The computer is a Dell and Windows XP and browser is Comodo Dragon.

    Also since this morning I've been getting a pop up that states in more or less terms...Reminder, your computer is not backed up. There is a link to do so, I guess, but I just close it. I've never seen it before and I have a pop up blocker on. There is no company logo associated with it.

    There was no TDSSKiller log as it showed nothing. Unless I'm not looking in the correct place for it. I found a folder with a few but they are marked quarantined.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it fix everything except:\
    C:\Documents and Settings\Owner\Desktop\tdsskiller.exe

    Toggle system restore and on your reboot ( enable system restore ) and rescan with Hitman.

    Tell me how things are running now.
     
  4. IBleed4Thee

    IBleed4Thee Private First Class

    Tim
    Thanks for replying so quickly.

    I ran Hitman Pro again but was unable to fix anything. The trial license has expired.

    I did not do the system restore as I wanted to wait to hear from you.

    The pc is running very slow. Pages are loading at a snails pace which was not the happening before this got onto the machine. As I stated I use Comodo Dragon and on my very old pc it's very quick unlike the other browsers.

    I did uninstall AVG and used RevoUninstaller to remove everything that came with it. If it let that trojan through I'm not pleased with the performance.
     
  5. IBleed4Thee

    IBleed4Thee Private First Class

    Wasn't sure if you needed a copy of the current scan from Hitman. Attached.

    Also I am still getting pop ups for :back up: Latest one states that my PC has free back up space. Click here! Of course, I just closed that down.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    :Files
    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\81ZQH52N\SPSetup[1].exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit
    C:\Program Files\Conduit
    :Commands
    [purity]
    [ResetHosts]
    
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    Not disable system restore, reboot and reenable system restore.

    Rescan with Hitman and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip.
     
  7. IBleed4Thee

    IBleed4Thee Private First Class

    Managed to run what you requested but no without issues.

    While running OTM a window popped up stating that it couldn't create:C:\Windows\System32\drivers\etc\Hosts. Otherwise that went without issue.

    Here is the info you requested from those logs.


    All processes killed
    ========== PROCESSES ==========
    No active process named explorer.exe was found!
    ========== FILES ==========
    File/Folder C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\81ZQH52N\SPSetup[1].exe not found.
    File/Folder C:\Documents and Settings\Owner\Local Settings\Application Data\Conduit not found.
    Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key.
    Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key.
    Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key.
    Unable to locate HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce key.
    Folder move failed. C:\Program Files\Conduit\CT3306059\plugins scheduled to be moved on reboot.
    Folder move failed. C:\Program Files\Conduit\CT3306059 scheduled to be moved on reboot.
    Folder move failed. C:\Program Files\Conduit\Community Alerts scheduled to be moved on reboot.
    Folder move failed. C:\Program Files\Conduit scheduled to be moved on reboot.
    ========== COMMANDS ==========
    C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.

    Then the next issue was I disabled System Restore and rebooted and went to enable and a screen popped up...stating it encountered a error. The screen closed so quickly I didn't catch everything but it was something to do the drivers and suggested I reboot again. I did and was able to enable.

    Ran Hitman Pro and was unhappy to see that it found more this time than on the first logs.

    Attached are the logs you asked for. Except I'm not seeing a log file for OTM. I have a folder named MovedFiles and there are folders inside of that. I have clicked and open each one and none of them have a log. Unless I'm not looking in the correct place. I attempted to upload the entire Moved Files folder but it wouldn't allow that. I'll keep looking and if I find it, will attach.

    As far as the pc running. It's very slow to load after reboot. Once the Windows XP screen appears it turns black for what seems to be a minute or two, then goes to the Windows screen and slow loading.

    Another issue is on the desktop or attempting to click on a program on the start menu...they are almost refusing it open and when they finally do it's taking forever.

    Also I need to search for folder and while the search was running it put shortcuts of almost everything in the search.

    Thanks for your help and time.
     

    Attached Files:

  8. IBleed4Thee

    IBleed4Thee Private First Class

    TimW

    Update for the last post.

    "Except I'm not seeing a log file for OTM."

    I just found a screen behind my browser that states there was a error and no logs were created. So I guess that explains why I couldn't find them.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Then rerun Hitman and attach that log as well.
     
  10. IBleed4Thee

    IBleed4Thee Private First Class

    Ran both programs and that went smoothly.
    The logs look good.

    Attached.

    Again thanks so much.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\81ZQH52N\SPSetup[1].exe

    Then telll me what issues remain, if any.
     
  12. IBleed4Thee

    IBleed4Thee Private First Class

    File is deleted.

    Everything seems to be running 99% better, everything is loading quicker and folder's are opening all of which were a issue.

    The only lingering issue and I don't know if it's related to what was going on. My desktop icons disappear and come back. For example if I minimized the browser the icons will disappear then come back a few at a time.

    Otherwise everything seems to be running super. I've been on the computer for a good amount of time today and no issues other than the icons.

    One other thing was I had uninstalled AVG when this issue began, mainly because I was annoyed that it missed finding this Trojan and installed Avast but had to change back to AVG as the Avast was bogging down my very old and short of memory computer. So that was a no brainier as far as issues though I prefer using Avast over AVG.

    I can't thank you enough for all your help and guidance and especially patience.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Post in the software forum for your icon issues.

    If you are not having any other malware problems, it is time to do our final steps:

    We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.

    Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.

    Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.

    Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:

    • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
    • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
    • Then we want you to Enable System Restore to create a new clean Restore Point.


    After doing the above, you should work thru the below link:





    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  14. IBleed4Thee

    IBleed4Thee Private First Class

    Carried through with the rest of your directions.

    Will post in the software forum if the issue continues past today.

    Again, thank you. You and your staff provide a invaluable service and I'm more than grateful to be able to use it when necessary.

    Have a great week.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     
  16. IBleed4Thee

    IBleed4Thee Private First Class

    TimW

    The computer is running fine with the exception of constant "page not responsive". It was a ongoing issue with Firefox and Chrome so I switched to Comodo Dragon which was much quicker and that issue seems to be gone but has now reared it's ugly head.

    I have a question, as you were so helpful in getting my machine clean. Usually when I run MalwareBytes or SuperAntiSpyware they come up clean or will have a few tracking cookies.

    When the Gen-Nullo was discovered it was found by SuperAntiSpyware and the AVG has missed it. I had always used Avast but my computer is "vintage" and memory is a issue but right now a new computer is out of the question. I found that Avast was bogging down the pc so I switched to AVG and it doesn't seem to interfere with it as much.

    Last night I set MalwareBytes up to do a full scan so it would be complete by morning and it found 24 PUP's. I was amazed...and now I'm wondering if it has anything to with AVG or not. I surf very safely, don't download anything (especially music/video's)and if I do on a rare occasion always check to see if it's clean of virus/or malware before I open it and I usually go to the same websites.

    Is there a way to keep this stuff from getting on the computer or could it be AVG is missing things? Seems strange to me that all this has occurred since using it a few weeks ago. I've attached the files from the scan just in case you needed to see them.

    Thanks.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am assuming that you fixed what MBAM found.

    Run this:

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Tell me if MBAM still finds anything.
     
  18. IBleed4Thee

    IBleed4Thee Private First Class

    Thanks for replying so quickly.

    Sorry I should have stated that I had MBAM fix what it found.

    I ran Junkware Removal Tool and it found one item to delete. I'm clueless at to what is or how it got on the pc.

    Running a follow up MBAM and will post what it or if find anything.
     

    Attached Files:

    • JRT.txt
      File size:
      778 bytes
      Views:
      9
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know what you find.
     
  20. IBleed4Thee

    IBleed4Thee Private First Class

    I ran MBAM and it came up clean. Have attached.

    Any ideas why suddenly my computer seems to be getting hit? The only change as I said was going from Avast to AVG and not sure if that is the issue, that maybe AVG is missing things it shouldn't.

    I surf safely, don't download and basically go to the same sites. The AVG is always enabled and I run MBAM and CC Cleaner weekly. I also have SpywareBlaster installed and keep it up to date.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! On Aug 30th you download and installed the below either knowingly or unknowling along with something you were doing:

    Connect DLC 3 Toolbar
    MyPC Backup

    Your logs do not lie. These were put on your PC on this date and that is where the junkware being removed in this thread originated from.

    And then after this date ( probably around the Sept 2nd or 3rd date you returned ) you had allowed more junk to be installed. This time TopArcadeHits and more Conduit junk. You really should have run the whole cleaning process over again because you may have more to do than just what was shown by JRT and MBAM which were the only new logs you attached. There is a good chance that a new Hitman and new MGtools log would show more.
     
    Last edited: Sep 9, 2013
  22. IBleed4Thee

    IBleed4Thee Private First Class

    chaslang
    I'm well aware of what the logs showed and I would doubt that they lied. That was never in question. It's one thing to knowingly install stuff on your computer without knowing your are asking for trouble/issues.

    So in my defense I will have to say they were installed unknowingly. As I stated more than once, I don't download music, video's, games and any other programs. The only programs I install are those that are recommended for the safety of the computer. And as I stated, I always run my antivirus and MABM on the files before I open them or anything else. I don't click on links in emails or on websites that I don't trust 100%. Actually about the only thing I do download are digital images to color and they are always from a trusted site and I always run my antivirus and malware program before opening even though I have been purchasing them from this person for years, you just never know what could be on another persons or companies computer/files.

    As I also stated it seems strange that these infections appeared after I changed from using Avast and installed AVG, from Download.com, made sure the files were clean before I opened them, that the issue started. In fact, as I stated, AVG missed these completely. It could be a coincidence or not but it's strange that these two events started after using AVG and the Trojan was not picked up by AVG.

    I've never heard of TopArcadeHits, so I know I did not install that on my computer. I will search my history to see what sites I went to on the days you have stated to see if I can get to the bottom of how this got on my computer. As I stated, my logs are usually clean except for a few tracking cookies. As far as what logs were attached or not, I attached the two logs that were requested by TimW. I didn't attach any further logs, as they have not been requested and I was not having computer issues that made me suspect that more malware had been installed. I was waiting for his next reply to see if he was going to suggest running anything else.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since new junkware has been installed, I suggest you rerun RogueKiller, Hitman and also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Attach the new C:\MGLogs;zip.
     
  24. IBleed4Thee

    IBleed4Thee Private First Class

    Ran and logs attached.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many legit programs now are supported by junkware toolbars and in some cases adware. Even programs from IObit, Norton/Symantec, Comodo, AVG, Adobe .....etc all come with junk that you don't necessarily want and you have to take care to opt out of the installation of this stuff otherwise it will be installed. AVG even installs AVG Safe Surf which many people ( me too ) consider mild malware or at least foistware because in most cases people don't know it is getting installed and it does not uninstall when you uninstall AVG and may not properly uninstall even when you specifically uninstall it.

    Many of these unwanted ( PUP ) type programs are not really going to show up as problems when downloading. They may only show up on after the fact scans.

    Yahoo is also guilty of installing a junkware search hijack on PCs. We have to remove this many times per day. And again here people don't even realize they installed when they installed or used something related to Yahoo!

    Not a great place to download from. They do not check all their downloads to make sure they are free from malware. Major Geeks does. But as stated above, many free programs now come with addons and you need to be careful when installing to opt out of the additional baggage. Even Oracle's Java ( formerly Sun Java ) comes with a check box to opt out of installing a McAfee Security scanner. I see dozens of people here each which with this program instaled and most do not know they even installed it. It is not malware, but the problem is that it is being installed automatically unless you opt out and most people are too click happy to read what is appearing on the screen.


    Your logs are basically clean but there are a bunch of left overs from Adware. Avast, ESET, IObit, Connect DLC 3, etc. So let's do some cleanup.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    :Files
    C:\TDSSKiller_Quarantine
    C:\Documents and Settings\Owner\Application Data\Ad-Aware Antivirus
    C:\Documents and Settings\Owner\Application Data\IObit
    C:\Documents and Settings\Owner\Application Data\LavasoftStatistics
    C:\Documents and Settings\Owner\Application Data\TuneUp Software
    C:\Documents and Settings\Owner\Local Settings\Application Data\Connect_DLC_3
    C:\Documents and Settings\All Users.WINDOWS\Application Data\IObit
    C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\WinPatrol
    C:\Program Files\ESET
    C:\Program Files\IObit
    C:\WINDOWS\system32\drivers\aswSnx.sys.sum
    C:\WINDOWS\system32\drivers\aswSP.sys.sum
    C:\WINDOWS\system32\drivers\aswVmm.sys.sum
    C:\WINDOWS\system32\drivers\gfibto.sys
    C:\WINDOWS\TEMP\*.*
    C:\Documents and Settings\Owner\Local Settings\temp\*.*
     
    :Reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
     
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  26. IBleed4Thee

    IBleed4Thee Private First Class

    chasling
    Thank you for taking the time to explain this. It now makes more sense and though I appreciated the service you provide greatly, the last you and your staff want to see if people coming back for the same issues constantly.

    I'm more than convinced this issue of repeat infection started with my choice of using AVG and their Safe Search.

    Perhaps you could suggest a free antivirus that is free of this malware but won't bog down my "vintage" computer. It is low on memory but replacing the computer anytime soon is out of the question and I don't know if it's worth spending money to add more memory. I do notice the op out on a great deal of programs and always make that choice.

    Ran the suggested programs and logs attached. Move It was ran successfully.

    I was amazed to see how much you wanted OTM to move. This and all the other programs were run when I found the Gen-Nullo, how come they weren't picked up then?

    Everything seems to be working fine except my constant page not repsonsive which is a never ending issue no matter what browser I install.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    There is no such thing. Modern infections require modern PC's to run modern software. ;) Current AV/AS and firewall software requires significantly more horse power these days. You could try uninstalling all the protection software you have now and using Microsoft Security Essentials. It may be less demanding. However, you will sometimes still notice your PC bogged down when you first bootup while it downloads updates and installs hem. This is fairly typical of any AV program though. They take almost 100% of the processor while doing this update. If you have not used your PC for a week, you will have larger updates to get which means more time.

    As you mentioned your PC is old and it is slow by todays standards of dual and quad core processors. And to make matters worse, you only have 512 MB of memory which is 1/6 of what I recommend for Windows XP SP3 even with faster processors. This is where your problem with slow response is coming from. You simply do not have enough memory free to run smoothly. You last log only showed about 61 MB free. Your PCs is constantly swapping applications from memory to disk and back and forth as the applications need to run. This slows things down tremendously.

    How come what wasn't picked up. This last fix only removed one junkware folder from Connect_DLC_3 and fixed two bad searchscopes. The rest were just left overs from programs you no longer have installed. It is not really in the scope of malware removal to fix these nor necessary. I was just trying to help you cleanup a little from this which sometimes can help slightly with performance.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  28. IBleed4Thee

    IBleed4Thee Private First Class

    Well I've tried every other protection software, I guess it wouldn't hurt to try this and see if it doesn't bog down the computer as much as the others. Nothing to loose by trying it.

    I think it's at least 10 years old and other than the lack of memory everything else runs great. I just don't know if it's worth it to invest in adding memory. And replacing the computer is not on my list of I can afford this, right now. It now makes more sense why I constantly get the "page unresponsive error"...just not enough memory. They are making online time painful, as I can get hit with 20 just while trying to read a email. I've asked several people on forums about this issue and they all had a different explanation.

    Thanks for explaining and taking the time to help with my performance issue. I was thinking it was malware connected and that alarmed me, so I thought I would ask.

    I don't see any other issues so completed what you suggested.
    Again, thank you and TimW for all your help and for going the extra mile to explain some things that I was confused on.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can go to Crucial.com and it will scan your pc and let you know how much ram you can add to the system. Ram is pretty cheap.
     
  30. IBleed4Thee

    IBleed4Thee Private First Class

    TimW
    I will check that out and see what it states about my computer. My only concern is the advanced age of the computer. It is really worth invested any money into...but if added some Ram would alleviate the issue with it being so slow it would be worth it.

    Thanks.
    Sande
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    If you are not going to buy a new PC, yes it is well worth it. Your PC should perform much better with 2 to 3 GB of memory. However before doing that, how old is the hard disk in the PC. If it is also very old, you could also be suffering from a hard disk that is starting to go. You may want to stop by the Hardware Forum to look into run some hard disk tests.
     
  32. IBleed4Thee

    IBleed4Thee Private First Class

    I will check and see about the hard disk tests.
    It's actually only about a year maybe year and half old. I had to replace the original one and did that myself.

    I did check Crucial and it's not nearly as costly as I had thought. 1GB is $25, so that really could be a option that I can handle financially.

    Again thanks for all your and TimW's help, it's invaluable.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Go fo more if you can afford it. The more the better. It would extend the useability life of your PC.
     
  34. IBleed4Thee

    IBleed4Thee Private First Class

    I ran the Crucial test one more time to double check what I could order. This is the test results. So I can order 2 1GB or leave the 512MB and order one 1GB. With the age of the computer and issues I've been having with performance, I ordered two 1GB's.

    Thanks for all your help and suggestions.

    Memory Type: DDR PC2700, DDR PC3200, DDR (non-ECC)
    Maximum Memory: 2GB
    Currently Installed Memory: 512MB
    Total Memory Slots: 2
    Available Memory Slots: 1
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I have many PCs, one is an old Win XP system probably of similar age to yours and I have 3 GB in it. It still works perfectly fine for me. It is a little faster than yours though as it is a 3 GHz processor.
     
  36. IBleed4Thee

    IBleed4Thee Private First Class

    Good to hear.

    After I get the new RAM installed, I'll post and let you know how things are working.

    I also took your advice and ran a test on the hard disc and it past 100%, temp was 42 and it found no errors on it. So that was good news.

    Have a great weekend.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent! You do the same. :)
     
  38. IBleed4Thee

    IBleed4Thee Private First Class

    Re: Gen-Nullo Trojan Update

    chasling and TimW

    Ordered the new memory and it arrived today. To start I am not on the computer that has been having the issue, I had to borrow my grand daughters. As I had installed a hard drive and replaced the DVD drive in the computer I wasn't uncomfortable opening the machine and installing the new memory.

    It couldn't have been easier and it took seconds to complete. Shut the pc and while I had it disconnected, gave it a clean with the canned air I always use. Hooked all cables back, turned the pc on and from there it went downhill...from a slow machine to no machine.

    Sorry if this is long but I said I would update you. The Dell screen came up, a black screen came up and stated that a change in memory had been detected and I'm like, Yes! It worked. From there a black screen came up stating that the Primary Drive was not detected, press F1 or F2 to set up. I pressed F1 and it went to the screen asking what Windows you wanted to us. There was only 2 options...debugged or Windows XP Home Edition. Though there use to be a 3rd...last known configuration, that was missing. I chose Home Edition and expected it to go to the Windows screen and load. It did not. It just sat there. I shut the pc down, rebooted and the same thing. So I'm like what possibly could have gone wrong. I simply snapped in the new memory. I shut it down again, unplugged it from it's electric source and walked away for a hour or so. Came back and powered it back up and it did the same thing. At this point I'm not happy and thinking everything that wasn't backed up is trapped in there on a machine I don't want to invest any more money in.

    The hard disc were found to have no errors, I added the memory we talked about...what now. So I rebooted once again. Was finally able to get into F12 and checked everything and the only change was that it recognized the new memory upgrade. I exited out of there, got back to the Dell screen, hit F1 as suggested and a black screen appeared that states that a file in Windows is corrupted....system32 and needs to be repaired. Grrrr! So I called Dell they ran a few diagnostic tests and had me do a few other things but we've not been able to get past this Windows corrupt file screen.

    Needless to say I'm not very happy, beyond pissed off and at a loss to how this happened by just adding memory. Is it just bad timing or is one not connected to the other. Dell's only suggestion was to run the installation disk (if I can lay my hands on it)and attempt to repair the corrupt file and hope that my data is not lost and I'll have a clean install.

    So right now..I am without a computer. Did adding the memory have anything to do with this or is it just ironic that it happened when I installed the memory?

    Thanks for any help, suggestions and should I post this in a different forum or hurl it over the balcony hoping that it doesn't land on a person or car....lol!
     
  39. IBleed4Thee

    IBleed4Thee Private First Class

    Re: Gen-Nullo Trojan+Update

    Okay...the beast is alive!

    I just never give up when it comes to fixing or doing things.

    Let's just say it was a duh! moment that caused the issue. One should not attempt to repair their computer on the floor with a 2 year old grandson and his puppy running around. But I did...I wanted it done.

    The memory sticks were in silver packages and I cut those open, opened the computer and removed the old memory. Installed one of the news one and the baby was running and tripped and when I came back I must have picked up the old one instead of the second new one.

    Well it didn't work I had opened it, made sure they were seated so that wasn't the issue. So I was thinking what could have gone wrong, Windows worked perfectly before I installed it. So I opened it and removed the two new memory sticks only to discover that one was new and one was the old one..as the new ones have Crucial labels on them. Duh! So praying that I discovered the issue, made sure the two sticks were installed, put the cables back on and hoped for the best. The Dell screen came up, Windows came up! The beast is alive and hopefully much quicker. I still have to hook the router back up to it as I have it hooked to my granddaughter's laptop.

    Just wanted to update you and let you know that I fixed it.
     
  40. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. ;)
     
  41. IBleed4Thee

    IBleed4Thee Private First Class

    chasling

    Just wanted to let you know after I finally got the memory installed properly, see posts before this, that the computer is super quick. Like it is new and not 9+ years old. I was really amazed after I got the router hooked back up that it is a fast as it is. I expected some improvement but not this fast. The pages are loading in a blink of the eye and I've not had one pop up stating the page is non responsive which I was having tons of every day.

    The best change is that it's no longer bogged down if a program, for example AVG is updating. It was almost impossible to even go from one website to another when it was updating.

    I can't thank you enough for taking the time to explain it all to me even though it was not associated with my malware issue at the time. That is going up the call of duty...and I am more than grateful for the service MajorGeeks provides free of charge. Once again, you and your team are a life saver.

    I know that donations are not accepted but I did read that donations to a favorite charity are...so I will make a donation to that, it's the least I can do.

    Again, thank you!

    :drink are on me....!



     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent news. Glad to hear you figured out the problem. Sorry I was not around too much the last couple days as I have been working my real job almost around the clock. :zzz

    Also glad to hear our recommendation for more memory was spot on. ;)

    And thanks for the contribution to a charity no matter which one it is. :)
     
  43. IBleed4Thee

    IBleed4Thee Private First Class

    And here when I didn't see you around I thought you were lucky enough to be on vacation. Too much work is never fun.

    As always the recommendations from you and your amazing team are always spot on, not once have I been steered in the wrong direction or given bad advice.

    Much as I like this place, hopefully I won't have to be posting anytime soon. ;)
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    :-D Surf safely !
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds