Malware again -- does it ever go away?

Discussion in 'Malware Help (A Specialist Will Reply)' started by sharpconnect, Dec 17, 2007.

  1. sharpconnect

    sharpconnect Private E-2

    I have an EMachine T5212 w/ 1GB(2-512s) RAM, ISP RoadRunner, AVG AV Commodo Pro Firewall, Spysweeper. Has Windows Media Center. Use Firefox2.0.0.6 & occasionally IE 6.0.2900..... HDD include C: (OS), D: (recovery partition), E: (cd-rw/dvdplayer),F-I for removable cards,K 125GB Maxtor internal secondary drive for data, J :80GB Maxtor for additional backup (also where I tend to save all files while on other network computers --laptop) and L: Lite On Ext DVD-RW. Also just upgraded my Netgear router to NG Range Max WPN824V2. Just installed Nero7 with the Lite On.

    I cleaned it up last summer and it was working find until a few weeks ago. Then it started again -- bogging down, freezing up, and just being a pain in the neck. Very slow to start.This weekend I found a warning several times in the taskbar that I was using 100% of the CPU resources(when it was unable to do much). I have cleaned up a lot(not all) of my files.I am also getting about:blank when I long on in IE. So I began to follow the instructions at MG on basic computer maintenance(before I go to Stop & Read this first Malware Removal guide). I started with diskcleanup. Comp says none of my HDD need to be defragged so did not do that.

    I have run CC Cleaner to clear uneeded files. For the registry using CC Cleaner, it found
    the following entries:
    HKCU:RUN BgMonitor_{7966E04-7C6C-4d9f-84C7-88D8A56B10AA}
    "C:\Program iles\CommonFiles\ Ahead\Lib\ NMBgMonitor.exe"

    HKCU:RUN Power2GoExpress
    "C:\Program Files\CyberLiink\Power2Go\Power2GoExpress.exe"/Startup

    HKCU:RUN WMPNSCFG
    "C:\Program Files\Windows Media Player\WMONSCFG.exe:

    HKCU:RUN ctfmon.exe
    C:\WINDOWS\system32\ctfmon.exe

    HKCU:RUN InCD
    "C:\Program Files\Nero\Nero7\InCD.exe

    Is it OK to clear these? Without losing the programs they refer to? The only 2 that I recognize are Power2 Go and Nero. I know Ahead is part of Nero -- do you know if this line is what has given me the obnoxious nero search box with non working drop down menu on my taskbar that I cannot find a way to get rid of?:banghead

    While I await your answer, I will proceed to Read & Run Me First and start working on that stuff.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. sharpconnect

    sharpconnect Private E-2

    OK. Finally got through the instructions in R&RMF and Win XP Here are the logs.
    Compressed the AVG log into a zip file as it was too large to send the other way.

    Thanks again.:tired
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I see is this:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    If running this: CWShredder
    doesn't remove it ...then we can reset your IE defaults.

    You might want to decide if you want AVG or Windows Live One Care....

    Otherwise this is not a malware issue and should be addressed in the software section.
     
  5. sharpconnect

    sharpconnect Private E-2

    CWShrsedder says it did not find anything. I attached a report from the scan anyway.

    Where do I find this/how do I delete it? Or how to reset IE defaults you are talking about?

    I want to use AVG AV. I have Spysweeper at present for AS.Is there a better AS?Should I just use Addd/remove programs and delete one care?

    You also suggested I take my slow computer issues to another forum-- would it be tetter to start in software or hardware one?

    Thanks for your help. :wave
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open Internet Explorer and see if you have assigned a home page ...otherwise you can go to the software section....however, I don;'t see what you need to remove in CCleaner if those programs are still active on your computer.

    You may wish to use a Startup Manager
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds