Got Fresh Logs here.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tweak-Hunter, Dec 2, 2007.

  1. Tweak-Hunter

    Tweak-Hunter Private E-2

    Ok, here are what I THINK are the necessary malware removal logs you require, I'm not sure anymore because you changed the method for malware removal. I'm doing a little cleaning up my old desktop computer so I can use it for games again, so i'm getting rid of unnecessary things and am trying to update my ATI drivers.
    Here are my first four logs.
     

    Attached Files:

  2. Tweak-Hunter

    Tweak-Hunter Private E-2

    rest of logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There are a few items that need attention ....please tell me what problems you are having.

    Please use add/remove programs to uninstall:
    Viewpoint Media Player

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  4. Tweak-Hunter

    Tweak-Hunter Private E-2

    Ok, here I have the zip file attached...

    ~"please tell me what problems you are having."
    My computer is running quite slow in comparison to a few years ago, I use to run games like Hl2, CS, and Fear to name a few on my computer. But I've been in school for a while and other siblings have been *Shudders* screwing with my computer. Anyway, now it takes 100% cpu usage just to run simple starcraft game. So I'm trying to optimize everything and get rid of everything I don't need anymore.

    PS, yeah I put that keylogger on there but I did forget about it and it needed to be removed.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One of your problems is that you have two anti-virus programs running and causing conflict:
    Trend Micro Internet Security Pro
    Norton Internet Security Professional
    (Both are resource hogs)
    You need to remove one. You also need to disable the one you keep while we do the following (Trend micro has a service that stops changes!)

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    You may wish to use a Startup Manager

    If you would like I will give you instructions for setting up a gaming profile that should speed things up for you .

    You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.

    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  6. Tweak-Hunter

    Tweak-Hunter Private E-2

    Hmmm, I noticed the multiple anti-viruses as I was thumbing through add/remove programs, thanks. It seems that my family hired a “computer guy” to uninstall Norton’s and install Trend Micro and (evidently) did a bad job. :( I went in and removed all files related to Norton and Uninstalled anything I could find In add/remove programs, also I used Hijack This to remove additional Norton stuff…

    As for the instructions on setting up a gaming profile, I would like that very much if you could help me with that, or anything which can increase speed.
    100% CPU usage for Star Craft is bad X_X
    I will say, I just updated the drivers for the Radieon 9600 xt graphics card, and since the model is discontinued I don’t believe there’s anything I can do in that regard.
    Thanks for your continuing assistance. :)
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Gaming profile:

    http://forums.guide2games.org/index.php?showtopic=2716

    ok, here's how you make a gaming profile...now...it can be somewhat hard but don't be intimidated...

    go to control pannel user accounts...now create one called gaming...CONGRATES!!! you've made a "gaming" profile...

    now that your in that profile, take out the background and put a boring solid blue one that they have in there...right click on my computer, choose advanced>visual effects and then click on adjust for best performance.

    take away all of the apps that shouldn't be running...
    and here's some other slightly more advanced tips..


    To increase system performance

    Right click my computer. Click properties.
    Click advanced.
    Click settings (under performance).
    Click Adjust for best performance.
    Scroll to the bottom and check the last one “use visual styles on windows and buttons”.

    How to disable XP's -crud- built in CD Burner

    Click the start button.
    Select Run.
    Type services.msc and click ok.
    Go to IMAPI CD-Burning Com Services open it and click on start up type, change to "Disabled".


    These Settings will fine tune your systems memory

    You need at least 256MB of ram to do this:

    Go to start\run\regedit -and then to the following key:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management

    1.DisablePagingExecutive -double click it and in the decimal put a 1 - this allows XP to keep data in memory now instead of paging sections of ram to harddrive yeilds faster performance.

    2.LargeSystemCache- double click it and change the decimal to 1 -this allows XP Kernal to Run in memory and improves system performance a lot.

    3.Create a new dword and name it IOPageLockLimit - double click it and set the value in hex - 4000 if you have 128MB of ram or set it to 10000 if you have 256MB set it to 40000 if you have more than 512MB of ram -this tweak will speed up your disckcache.

    Reboot


    Unable to delete from Avi files from HD

    XP holds files in it's memory even after you have closed the application using them making it impossible to delete them from your harddrive. To fix this:

    Start -> Run -> Regedit
    Find the HKEY_CLASSES_ROOT\SystemFileAssociations\.avi\shellex\PropertyHandler\ directory and delete the "DEFAULT" key.

    Tweak The Swap File

    For Users with 256 MB RAM or more this tweak will boost their Windows- and Game-Performance.
    What it does: It tells Windows not to use any Swap File until there is really no more free RAM left.

    Open the System Configuration Utility by typing msconfig.exe in the RUN command. There in your System.ini you have to add "ConservativeSwapfileUsage=1" under the 386enh section.

    Restart your Windows and enjoy better Game performance

    Disable Services

    XP Pro runs a lot of services by default that are pointless if your not on a corporate network, the following services are ones that I safely disable thereby freeing up memory but check what each one does first to make sure your not using it for something:

    Go to Run and type services.msc, right click on each service, properties and choose disable.

    Alerter
    Application Layer Gateway Service,
    Application Management
    Automatic Updates
    Background Intelligent Transfer
    Clipbook
    Distributed Link Tracking Client
    Distributed Transaction Coordinater
    Error Reporting Service
    Fast User Switching Compatibility
    IMAPI CD-Burning
    Indexing Service
    IPSEC Services
    Messenger
    Net Logon
    Net Meeting
    Remote Desktop Sharing
    Network DDE
    Network DDE DSDM
    Portable Media Serial Number
    Remote Desktop Help Session Manager
    Remote Registry
    Secondary Logon
    Smartcard
    SSDP Discovery Service
    Telnet Themes
    Uninterruptible Power Supply
    Universal Plug and Play Device Host
    Upload Manager
    Webclient
    Wireless Zero Configuration
    WMI Performance Adaptor


    Speed Up The File System

    NTFS is a great file system, but its feature-set comes at a slight cost in performance. You can negate this a little with the following tips:

    * By default NTFS will automatically update timestamps whenever a directory is traversed. This isn't a necessary feature, and it slows down large volumes. Disable it by going to Run and type regedit:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem and set 'DisableNTFSLastAccessUpdate' to 1.

    * NTFS uses disparate master file control tables to store filesystem information about your drives. Over time these core MFT files grow and become fragmented, slowing down all accesses to the drive. By setting aside a little space, MFT's can grow without becoming fragmented.

    In the same key where you disabled the last access feature creat a new DWORD value called 'NtfsMftZoneReservation' and set it to 2.


    Disable DLL Caching

    Windows Explorer caches DLLs (Dynamic-Link Libraries) in memory for a period of time after the application using them has been closed. This can be an inefficient use of memory.

    1. Find the key [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer].

    2. Create a new DWORD sub-key named 'AlwaysUnloadDLL' and set the default value to equal '1' to disable Windows caching the DLL in memory.

    3. Restart Windows for the change to take effect.


    Tweak The Prefetch

    1. Run "Regedit"
    2. Goto [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters\EnablePrefetcher]

    3. Set the value to either 0-Disable, 1-App launch prefetch, 2-Boot Prefetch, 3-Both ("3" is recommended).

    4. Reboot.

    It will decrease the boot time but double and increase the performance of your XP.


    SpeedUp Your Connection By 20% (Cable Users Only)

    1.Log on as "Administrator".
    2. Run - gpedit.msc
    3. Expand the "Local Computer Policy" branch.
    4. Then expand the "Administrative Templates" branch.
    5. Expand the "Network" branch.
    6. Highlight the "QoS Packet Scheduler" in left pane.
    7. In the right window pane double-click the "Limit Reservable Bandwidth" setting.
    8. On the settings tab check the "Enabled" item.
    9. Change "Bandwidth limit %" to read 0.
    10. Then go to your Network connections Start=>Control Panel>Network & Internet connections>Network Connections and right-click on your connection. Then under the General or the Networking tab, (where it lists your protocols) make sure QoS packet scheduler is enabled.

    It may take effect immediately on some systems. To be sure, just re-boot.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds