Old/small Acer Netbook Glitchy

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by linuxpowers, Jul 6, 2024.

  1. linuxpowers

    linuxpowers Specialist

    Was given an old Acer Netbook w/windows 7 Starter from my son only to find it very glitchy. Had Malwarebytes installed but would only show logs...full of pups. Had to use malwarebyte removal tool to deal with it as it would not update or run. Been years since I've visited MG and the Read & Run thread for malware but, once again, I'm back for the duration!

    I'm posting the logs I've collected from the scan instructions. Thanks for time and effort in advance. BTW, I see Kestrel13! is still here! You helped me so much in the past (10 or more years!), I just wanted to say HI and a BIG THANKS to you once again, it's good to see you still around. :)

    In ref to the scan logs, the new install of Malwarebytes didn't detect anything but the MGTools I placed in my root directory so, I didn't upload that log.

    NOTE: Signature file does not apply at this time!
     

    Attached Files:

  2. Oh My!

    Oh My! Malware Expert Staff Member

    Greetings and welcome back to the Major Geeks Malware Forum.

    I would like to get a couple more reports. Please do this

    ===================================================

    Farbar Recovery Scan Tool (FRST)

    --------------------
    • Download FRST64 and save the file on your Desktop
    • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
    • Right click on the icon and select Run as administrator
    • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
    • Click Yes to the disclaimer
    • Click Scan and allow the program to run
    • When completed, FRST.txt and Addition.txt reports will be saved on the Desktop
    • Please attach the reports to your reply
    ===================================================

    Things I would like to see in your next reply.
    • Attached reports
     
  3. linuxpowers

    linuxpowers Specialist

    No false positive warning but it does state that the version of FRST64 is not compatible with my version of windows. Reason - (32-bit) vrs (64-bit) and will not run (as admin). This OS is Windows 7 Starter, Service Pack 1, 32-bit Operating System.
     
  4. Oh My!

    Oh My! Malware Expert Staff Member

  5. linuxpowers

    linuxpowers Specialist

    That was rough. Probably took 30-45min just to get the page to load before the download would start and had to reload that page several times. But, finally got there!
     

    Attached Files:

  6. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you for going through all of that.

    Although the computer is clean there is some work we can do to try to help things. I am surprised the system can function at all given the lack of sufficient available memory. Keep in mind there is only so much that can be asked of the system even after our efforts to improve things.

    I am ending for the evening but my plan would be to clean up some things and remove as much software as possible leaving only the things you need. Since a lot of the software is quite old it will require some research on my part to determine what is essential and what is not. I see you ran AdwCleaner already. If you did not delete the items identified as Pre-Installed Software I would recommend running AdwCleaner again and selecting to remove all of it. Those items are safe to delete.

    I will be posting again in the morning, West Coast time. This is going to be fun. I will break out my Windows 7 test computer!

    For now,

    Gary
     
  7. linuxpowers

    linuxpowers Specialist

    Complete!
     
  8. linuxpowers

    linuxpowers Specialist

    You know, I know this thing is small but I thought it might at least run a browser. I guess I'm sorta used to My desktops whereas I install the Linux OS on those and even the smallest of those will run fine. I got online last night and did some searching and found that some of these models has the option to upgrade to a 2GB chip. Looked around and found them for sale in quite a few places, even walmart, for about $10.

    I looked at Task Manager and familiarized myself with running services and what was using memory and quite frankly, there's not much to play with. I removed a few background programs that were running and was able to go from 98% down to 69% but I feel an upgrade will help . I also know that trying to find a browser that will run on such an old os will be a challenge, that was why I finally jumped from windows to linux on my desktops, just no more functionality, even online sites were demanding windows 10 upgrade. I bank online and was worried the banks would eventually prompt me for the same.

    If you want to take your time and see what else we can accomplish, I'm more than willing to give it a shot but eventually, I will try upgrading to 2GB and play around with it. I'm only setting it up for browser use anyway!
     
  9. Oh My!

    Oh My! Malware Expert Staff Member

    Do you have the original installation disk?
     
  10. linuxpowers

    linuxpowers Specialist

    No, no installation disk. Only the device and it's power cord.

    It also needs a new battery as the one installed is 0%. It was connected to wifi but I hard-wired it via Ethernet cable while downloading scanning software... a bit faster!
     
  11. Oh My!

    Oh My! Malware Expert Staff Member

    Let's start with this. I haven't pulled out my Windows 7 but I believe the Clean Boot instructions are accurate for that operating system.

    ===================================================

    Farbar Recovery Scan Tool Fix

    --------------------
    • Right click on the FRST64 icon and select Run as administrator
    • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
    • There is no need to paste the information anywhere, FRST64 will do it for you
    Code:
    Start::
    CreateRestorePoint:
    CloseProcesses:
    cmd: sfc /scannow
    Emptytemp:
    End::
    
    • Click Fix
    • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
    ===================================================

    Clean Boot

    --------------------
    • Press the Windows Key + R at the same time.
    • Type msconfig and press Enter
    • If you are prompted for an administrator password or for a confirmation, type the password, or provide confirmation
    • Click on the Startup tab
    • Note down each entry listed as Enabled then right click on the item and select Disable (you will need this list during subsequent steps)
    • Close the Task Manager windows and you should be back at the System Configuration window
    • Click the Services tab
    • Click to select the Hide All Microsoft Services check box
    • Click Disable All, and then click OK
    • Click Apply, then OK
    • When you are prompted, click Restart and boot into Normal Mode
    • Check your computer performance
    • Run a FRST scan in this environment and attach the reports to your reply
    ===================================================

    Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
    • Fixlog
    • Attached FRST reports
    • How does the computer run in Clean Boot?
     
  12. linuxpowers

    linuxpowers Specialist

    OK, before I go any further, I have the "System Configuration" window open and am at the "Startup" tab. I have about 15 items listed and two buttons at the bottom..."Disable All" & "Enable All". The "Enable All" button is grayed out at the moment.

    If I right click on any item, nothing happens. But, I notice that each item has a check box and every item is checked. If I uncheck an item, the "Enable All" button now becomes active. Maybe I should uncheck instead of right click?

    And, how much information of each Startup Item do I need to make note of? I ask because there are some multiple entries with the same Startup Name but they show a different Startup Command.
     
  13. Oh My!

    Oh My! Malware Expert Staff Member

    Thanks for being flexible.

    Let's put Clean Boot on hold for now. Rather than that, boot into Safe Mode and run a FRST Scan. That will give us a picture of how much available RAM there is when the system is in bare bones operation. Attach the reports to your reply.

    Currently the FRST reports are showing the worse case scenario when it comes to memory usage. Safe Mode will show us the best case scenario. If Safe Mode shows very little available memory we will be stuck. There will be no reason to carry on until more RAM is installed.

    In anticipation of us doing more work I would also like you to complete the below.

    ===================================================

    Autoruns

    --------------------
    • Please download Autoruns and save it to your Desktop
    • Right click on the autoruns64 icon on your Desktop and select Run as administrator
    • Wait until the lower left hand corner of the window shows Ready
    • Hit the Ctrl + S key at the same time
    • Save the file onto your Desktop using the default File name:
    • Please zip and attach it to your reply
    ===================================================

    Things I would like to see in your next reply.
    • FRST scan reports (2)
    • Attached zip file
     
  14. linuxpowers

    linuxpowers Specialist

    RST scan reports (2)
    Zip file

    I had to do the Autorun scan with the system in Safe mode with Network!
     

    Attached Files:

  15. linuxpowers

    linuxpowers Specialist

    while still in safe mode, I took a look at resource monitor and saw I was using 56% physical memory. Most of the processes were Chrome! I shut down Chrome and dropped to 32%.
     
  16. Oh My!

    Oh My! Malware Expert Staff Member

    Nice work on your part.
    There is a disconnect between your numbers and the numbers being reported by FRST. I am wondering if it is because FRST is running when the data is captured thereby increasing overall memory usage.

    There are different ways to approach this. I prefer a more measured approach but if you want to go right to removing programs and software let me know.

    What I would like you to do now is capture the memory usage while not running FRST. Check Normal Boot and Safe Mode and report the numbers. In addition, identify the top 5 memory hogs as best you can in each boot environment. The numbers may shift while you are evaluating it so do the best you can.

    I have my Windows 7 up and running so hopefully I can provide better instructions going forward.
     
  17. linuxpowers

    linuxpowers Specialist

    OK,

    NORMAL BOOT (after disk activity)
    49%

    TOP 5 MEMORY HOGS
    svchost.exe (LocalSyatemNetworkRestricted)
    svchost.exe (netsvcs)
    explorer.exe
    perfmon.exe
    IAStorIcon.exe

    SAFE BOOT w/NETWORKING (after disk activity)
    33%

    TOP 5 MEMORY HOGS
    explorer.exe
    svchost.exe (secsvcs)
    perfmon.exe
    svchost.exe (netsvcs)
    svchost.exe (LocalSystemNetworkRestricted)

    :( Don't look like there's much to play with here! I did take note that when I started Chrome (while in safe mode) to respond to this thread, 7 instances popped up as the largest memory hogs at just over 450mb. Not sure if that is normal with only 2 tabs open in the browser.
     
  18. Oh My!

    Oh My! Malware Expert Staff Member

    Yes, all of those listed under Memory are necessary.

    That is normal for Chrome.

    Did you happen to run the Fixlist from Post #11?
     
  19. linuxpowers

    linuxpowers Specialist

    Sorry about that, here ya go!
     

    Attached Files:

  20. Oh My!

    Oh My! Malware Expert Staff Member

    Thank you, your file system looks good.

    We are going to disable a few startup items and see if there is any difference.

    ===================================================

    Disabling Autoruns Entries

    --------------------

    Autoruns Explained

    Many programs, when installed, create registry or file entries which instruct the program to launch at system startup whether or not that program is essential or advantageous to run in the background. By disabling the autorun feature we do not delete or otherwise prohibit the program from running, rather the program is not started until it is needed. Think of it like a car. Sometime today you might to use the car to go to the store. The car can be in one of two conditions before you decide. You can leave the car running all day long even though you may or may not use it (enabling autorun) or you can start the car when you are ready (disabling autorun then launching a program). Either way the car will work for you it is just a matter of how ready it will be if/when it is time. Just as gas is wasted by leaving the car running, your computer resources are "wasted" because programs are running in the background that you may not be using.


    ===================================================

    Disabling Autoruns Entries

    --------------------
    • If necessary, download Autoruns and save it to your Desktop
    • Right click on the autoruns64 icon on your Desktop and select Run as administrator
    • Click on the Logon tab
    • Leave only the below items checked (uncheck the rest)
    Apoint
    IAStorlcon
    IgfxTray
    Persistence
    RtHDVCpl
    cmd.exe
    • Reboot your computer and check the memory usage and computer performance
    ===================================================

    Things I would like to see in your next reply.
    • Results?
     
  21. linuxpowers

    linuxpowers Specialist

    So I rebooted, (Normal Boot) and waited till things settled down. I recorded the physical memory usage at 52%. Then, since I already had Autoruns on my desktop, I went ahead and ran that, unchecked everything other than what was listed and rebooted. Now I see that number has dropped to 38%. I still haven't started anything other than task manager. That's a pretty good drop!
     
    Last edited: Jul 8, 2024
  22. Oh My!

    Oh My! Malware Expert Staff Member

    Go ahead and run the computer like you will want to and see how you do.
     
  23. linuxpowers

    linuxpowers Specialist

    Alright then! Thank you so much for your time and efforts, I appreciate everything you've done.

    Haec cognitio Petro oriri non potuit in « carne et sanguine ».
     
  24. Oh My!

    Oh My! Malware Expert Staff Member

    It has been a pleasure working with you. Thank you for your ongoing kindness.

    Gary
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds