Is there anything else I need to do?

Discussion in 'Malware Help (A Specialist Will Reply)' started by sharpconnect, Aug 17, 2007.

  1. sharpconnect

    sharpconnect Private E-2

    I have an EMachine T5212 w/ 1GB(2-512s) RAM, ISP RoadRunner, CA Security Center(provided by RoadRunner) for my AV, Firewall, Antispyware and antispam. Has Windows Media Center. Use Firefox2.0.0.6 and occasionally IE 6.0.2900..... HDD include C: (OS), D: (recovery partition), E: (dvd writer),F-I for removable cards,K 125GB Maxtor internal secondary drive for data, and J :80GB Maxtor for additional backup (also where I tend to save all files while on other network computers --laptop).Also netgear router.

    It had been bogging down, freezing up, and just being a pain in the neck. Very slow to start. Several months ago I reformmated the OS hard drive in an attempt to start clean again. Getting slow and stuttering again, I decided it was time to try to clean it up and find out what was infecting it. So I followed the instructions at MG on basic computer maintenance and Stop & Red this first Malware Removal guide. Panda would not work on my computer(the sign in screen came up with error on page and froze every time I tried to enter my state).

    I admit it is starting a bit quicker. I am attaching the logs that I was able to generate during these processes. Is there anything else I need to remove? or change? or fix?
    And what can I do about the slow startup? I have not figured out how to genertae a copy of my startup items. I do not know enough to know what to remove there. One other thing that bothers me is that when I type in any program, I have to wait for the screen to catch up to what I have typed, if that makes any sense. I would appreciate any help you can give me.

    Here are the first 3 attachments:
     

    Attached Files:

  2. sharpconnect

    sharpconnect Private E-2

    I have also "toggled system restore". Again, thanks for your help.

    Rest of attachments:
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what this is?
    C:\Documents and Settings\Owner\Application Data\gtopala

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  4. sharpconnect

    sharpconnect Private E-2

    Here is the rescan of HJT as request per the email I just got: "abri has just replied to a thread you have subscribed to ... Hi Sharpconnect! Welcome to Major Geeks! Your system is not yet clean. Toggling system restore is what you do after your computer is clean. There's something very odd about your HJT log. You ran it in the right place, but it doesn't have any form. Do you know anything which could have led to this? Would you run it again and see if the log comes up normal and repost it? The one you have now is missing all the carriage returns so everything is lined up in one long text from top to bottom. Thanks. abri"

    I will let you review this second scan before I make any changes.

    Do you know what this is?
    C:\Documents and Settings\Owner\Application Data\gtopala
    I believe it is related to a freeware program siw.exe that gives me information about my system.

    Please review and advise.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go ahead and do the fix that I asked of you .....:)

    You are not showing alot of problems ( BigFix is a resource hog and can slow you down)..but I need to see the new GetRun and ShowNew logs.
     
  6. sharpconnect

    sharpconnect Private E-2

    I did the corrections you indicated. Here is the post correction HJT log and the new GetRun and ShowNew logs also.

    Is BigFix necessary? It came with the EMachine software and is automatically installed when I restored the HDD. Is there a way I can automatically get updates from EM without BF? Or that I can schedule updates without using BF if I take it off?

    Is it OK to shut down and install the new RAM I bought (=2 - 1GB sticks)? Or should I wait until the computer is running like it should?

    ;) Thanks.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing any malware ...however, did you have problems with the reg. patch?
    You are still not showing hidden files......
    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    What updates are you worried about? You can always visit the gateway site for any updates ...though I doubt that you will need to do that. Big fix could be one of the reasons you are slow.
    You might wish to download a startup manager:
    StartUp 1.3


    And yes, you can add your new ram.

    I still would like to see a getrun log with the hidden files and folders showing.
     
  8. sharpconnect

    sharpconnect Private E-2

    I don't understand why the hidden files are not showing. I followed the instructions in Read & Run First when I first started to clean my system. I rechecked -- Explorer is set to view all of them as per the instructions.

    I redid the fixMe.reg file and I think it worked this time. Here are the 2 logs done after that.

    I have uninstalled BigFix and will install my new memory. I also have Webroot Spysweeper here which I have not had a chance to reinstall. I will reinstall it now.

    I did install the start up manager program you suggested. I don't see much that can be removed -- except maybe Adobe reader speed launcher. The rest seem to be CA security suite, real player or part of windows.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would hope things are running a little faster without BigFix ...however, I would also say that most "security suites" are also resource hogs. Have you tried totally uninstalling CA and seeing how you run before re-installing?

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds