I'm having problems again

Discussion in 'Malware Help (A Specialist Will Reply)' started by jeremia18v4, Oct 10, 2008.

  1. jeremia18v4

    jeremia18v4 Private E-2

    Okay, I'm having the same problem as before pretty much. the startup time is like ten minutes. It's taking my computer forever to come on. My CPU usage is like 6% right now. I don't know what that means, but you asked me what it was last time. Anyway, please help me if you can. I appreciate it.
     

    Attached Files:

  2. jeremia18v4

    jeremia18v4 Private E-2

    I'm having problems again-here other log

    here's the other log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your slow startup problems are not due to malware. They are due to what you have installed and are running at startup. Also a contributing factor is that you only have 1 GB of RAM and Available Physical Memory is only 167 MB. I would double the amount of RAM.

    Below I will give you some non-malware things to do that may help. First is did you purchase PC Checkup. If not, uninstall it. If you did, then stop loading it at startup.

    Who install Super Winspy v3.3 and why? It is a new addition and it is slowing down your PC.

    Do you really need Window Vista Parental Controls to load?

    Run SUPERAntiSpyware and select Preferences and the on the General and Startup tab uncheck the option to Start SUPERAntiSpyware when Windows Starts.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)

    The below are all unnecessary Startups which you can have HJT fix to improve startup time.
    O4 - HKLM\..\Run: [PC-Checkup] "C:\Program Files\PC Check-up\PCCheckUp.exe" -mini
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [SkinClock] C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log
    C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
    Last edited: Oct 13, 2008
  4. jeremia18v4

    jeremia18v4 Private E-2

    Thank you so much for responding. As you can see, I'm not very smart about computers. I did everything you said to do. The regedit was successful. one thing...did it stop windows parental controls from loading?? I didn't know that they were loading. I only use one accout and it is the administrator account. I restarted and the startup was much faster after I did what you suggested.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your MGlogs.zip file was not updated properly. You need to run C:\MGtools\GetLogs.bat again and make sure you let it finish running all the way. Also make sure that UAC is still disabled before doing this.

    No! You need to do this yourself. The below link shows an example of how to enable and disable this.

    http://www.askdavetaylor.com/turn_on_parental_controls_in_windows_vista.html
     
  6. jeremia18v4

    jeremia18v4 Private E-2

    okay, the first time I tried, I did have UAC on. I went to the link you suggested and tried to turn off the parental vista controls, but it won't let me do it because the account I have is the administrator account.

    I ran the Kaspersky online scanner and it came back and said that I had...
    Adware.Win32.Relevant.n
    Adware.Win32.IeSearchBar.a
    Adware.Win32.BetterInternet.jn
    Do I need to worry about these? I tried to get the log from Kaspersky, but it would not work.

    Anyway, thanks for your time!
     

    Attached Files:

  7. jeremia18v4

    jeremia18v4 Private E-2

    I did another scan...here's the report
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not make any sense. I'm guessing that you read the message wrong. Perhaps it said something about being disabled by the Administrator or similar. You may have to work this problem out in the Software Forum since it is not malware issue.

    Without seeing a log that shows exactly what file names and where these are found, I cannot comment. It could well be that these are just being found in quarantine folders or in System Restore. Since your logs are clean ( the GMER log is clean too), let's finish final instructions and see what happens.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    Anyway, thanks for your time![/quote]
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds