my web search tool bar; slow PC

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by webgal318, Oct 10, 2012.

  1. webgal318

    webgal318 Private E-2

    The PC was running slow so I scanned with malawarebytes.
    I checked all infections to remove then rescanned. Several instances remained so I came here.
    Please check the logs attached.

    Please note: No infections found after my last Malawarebytes scan.
    The TDDS scan did not reveal anything.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you posted at the below forum first:

    http://forums.techguy.org/virus-other-malware-removal/1071406-mypup-websearch-slow-computer.html

    You should not cross post to multiple forums as it occupies the precious resources of multiple experience malware experts which is frowned upon. Also it can cause problems if actually working to fix things a two locations at the same time. If you with to continue here at Major Geeks, post back in your other thread asking for it to be closed because you are already receiving help elsewhere.

    You have multiple other issues on this PC with junkware which we will address below.

    Did you knowingly install and do you use Crawler Toolbar ?
    If not, I would uninstall this now.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.6.2\PriceGongIE.dll
    O2 - BHO: RewardsArcadeSuite - {B6EF6C45-5E8D-4c3b-B580-A5073261A381} - C:\Program Files\RewardsArcadeSuite\RewardsArcadeSuite.dll
    O2 - BHO: WeCareReminder - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\Documents and Settings\All Users\Application Data\WeCareReminder\IEHelperv2.5.0.dll
    O23 - Service: McAfee Application Installer Cleanup (0300431342135042) (0300431342135042mcinstcleanup) - Unknown owner - C:\DOCUME~1\Barb\LOCALS~1\Temp\030043~1.EXE (file missing)


    And optionally if you wish to improve performance, have HijackThis fix the below too by checking them and Fixing them. These are not malware. You just don't need them wasting your system resources and slowing down startup.
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
    O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
    O4 - HKUS\S-1-5-21-293596920-1555376896-3197627524-500\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (User 'Administrator')
    O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


    After clicking Fix, exit HJT.


    Now also uninstall the below now:
    J2SE Runtime Environment 5.0 Update 11
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 31
    Java(TM) SE Runtime Environment 6 Update 1
    PriceGong 2.6.2
    Uniblue DriverScanner
    Viewpoint Media Player


    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now please download OTM by Old Timer and save it to your Desktop.
    • Right-click OTM.exe and select Run as administrator to run it.
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Documents and Settings\Barb\Application Data\PriceGong
    C:\Documents and Settings\Barb\Application Data\Uniblue
    C:\Documents and Settings\Barb\Local Settings\Application Data\Conduit
    C:\Documents and Settings\All Users\Uniblue
    C:\Program Files\Conduit
    C:\Program Files\PriceGong
    C:\Program Files\Uniblue
    C:\Documents and Settings\Barb\Desktop\o4mqgkqv.exe
    C:\WINDOWS\system32\CA07C09176.sys
    C:\Documents and Settings\Barb\Local Settings\Temp\22AE1416.dmp
    C:\WINDOWS\Tasks\"DriverScanner.job
    C:\Program Files\Ask.com
     
    :Reg
    [-HKEY_USERS\S-1-5-21-293596920-1555376896-3197627524-1005\Software\Microsoft\Windows\CurrentVersion\run]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DEF9C3D6-5F78-43A3-8CAE-0A33572BF084}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnUpdater]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Google Desktop Search]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RealTray]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg]
     
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
     
     
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. webgal318

    webgal318 Private E-2

    Please find the files that you asked for: OTM moved files and MGlogs.zip

    Note: I had to disable my AVG in order to run the OTM exe file.
    I hope this does the trick.

    Thanks a lot.

    Sylvia
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay looks better. That left over service from McAfee did not get removed. Try the below


    Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

    sc stop 0300431342135042mcinstcleanup
    sc delete 0300431342135042mcinstcleanup


    Then see if the below line is now gone from the analyse.exe ( hijackthis.exe ) scan:

    O23 - Service: McAfee Application Installer Cleanup (0300431342135042) (0300431342135042mcinstcleanup) - Unknown owner - C:\DOCUME~1\Barb\LOCALS~1\Temp\030043~1.EXE (file missing)


    Is everything working okay now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds