slow computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jablonski_1, Apr 5, 2009.

  1. Jablonski_1

    Jablonski_1 Private E-2

    Hey guys, I apologize if I'm posting this in the wrong forum but I recently had a few viruses including virtumonde on my computer and you helped me remove them. Thanks! Im still running slow. I was poking around on the forums and came across a page that had registry cleaner downloads on it. My dumbass closed the page and I cant find it on here. I've searched far and wide!The page included pc tools registry cleaner. I'm just looking for that page with the downloads. I think it was written by major attitude. Thanks for taking the time to read this and I'm looking forward to your reply. :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This is your first thread! Where/when did we help you? Or are you saying you ran our cleaning procedure but never posted?

    We do not recommend registry cleaners in the Malware Forum so you are in the wrong place for that. But perhaps you are referring to the below page:

    http://www.majorgeeks.com/page.php?id=20
     
  3. Jablonski_1

    Jablonski_1 Private E-2

    You guys helped me a few years ago through my brother. He was talking to you because I'm not computer savvy. I've learned so much since that time. And yes, I ran the read and run me programs and got rid of the problems we had. There was a website that I was going to where I got the viruses form their log in page. I let them know what happened and they fixed their problem. The computer was still running slow, so I did and probably shouldn't have, but I ran the programs again. All the logs came up clean, so I was poking around on your forums looking for threads that included slow computers. I came across a thread that had registry cleaners on them and they usually solved the problem. I closed out of that page and when I went back I couldn't find it, so I posted a thread.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have hundreds of threads where users complain of slow computers; however, as I stated, we don't use registry cleaners in the malware forum. At least not on a regular basis. It would only be done in special cases and that is rare. So if you saw a registry cleaner being used, it may have been in the Software Forum. It is not likely that you will see any significant performance change in your PC by performing a registry cleaning.

    Many slow PCs are due to what you are running and your PC's specs (like which Windows version and processor speed and amount of RAM).

    Attach your logs from the READ & RUN ME and I will give you my opinion.
     
  5. Jablonski_1

    Jablonski_1 Private E-2

    Sorry it took me this long to get back to you.

    Here are my logs. I'll post the first ones and if you want the others I can post those too.

    Just so you know my computer is still running slow and I ran ccleaner again and this time the files that it removed have doubled!! I also updated to internet explorer 8, if that makes any difference.

    Thanks for looking at this for me. Your help is greatly appreciated!

    I'm retarded and I can't find my spybot and combo logs!! I dont know where to look! I'm sorry!!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the logs from ComboFix (C:\combofix.txt as stated) and MGtools which is c:\Mglogs.zip The READ & RUN ME does not even ask you to run Spybot nor do we want a log from it.

    Your versions of SUPERAntiSpyware and Malwarebytes are way out of date. You need to do the below.

    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.
     
  7. Jablonski_1

    Jablonski_1 Private E-2

    Here are the logs for mgtools and combofix
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the two new logs that were requested from SUPERAntiSpyware and Malwarebytes after updating them as requested.

    Also you are way out of date with MGtools. I will give you are starting fix below and then have you update to the current version to get a new log.

    However I can already point out the most likely reason for your PC being slow. You don't have enought memory in your PC. You logs show the below
    You need to at least double your memory to 1 GB.

    I will give you a few things to do though which are not malware problems, but will help a little.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Also optionally uninstall unnecessary toolbar like Google and MSN.
    Also optionally uninstall Google Desktop.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
    O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)

    Also to help with performance, optionally fix the below which are not necessary startups. You will have to determine if you really depend on using any of these.
    O4 - HKLM\..\Run: [UserFaultCheck] "C:\WINDOWS\system32\dumprep.exe" 0 -u
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
    O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000

    After clicking Fix, exit HJT.

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the new log from an update SUPERAntiSpyware
    • the new log from an update Malwarebytes
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 26, 2009
  9. Jablonski_1

    Jablonski_1 Private E-2

    Here are the new logs for SAS and MB.

    Dont know if this is related, but I cant log on to one website. It's been 3 days since I could log on there. Might be the site is having major difficulties, but I'm Not sure. It's not a banking website, it's my state unemployment website and I need to fill out an online claim. Its also where I check my debit card statement. It would be a site that if I was infected, would be one to get all the info from.

    Thanks again for helping me!
     

    Attached Files:

  10. Jablonski_1

    Jablonski_1 Private E-2

    Here's the new MGTools log.

    Things are working faster! Still having some slowing, but that could be just because I haven't fully updated my memory. I added 256 tonight so it's a little faster. I also ordered 2 gb from newegg.com and that will be here in a few days. I hope that will put this to bed!

    You guys have been wonderful to work with. I really appreciate all of your help!
     

    Attached Files:

  11. Jablonski_1

    Jablonski_1 Private E-2

    In that last MGTOOLS log it will say that I didn't uninstall windows messenger. I didn't before the scan. I wasn't able to connect to the internet while I was running through your program. I just removed it. If you want me to run MGTOOLS again I will.

    Thanks!!!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds