Slow start up. Ran the scans, didn't help.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lauras, Dec 20, 2010.

  1. lauras

    lauras Private E-2

    I searched google for something and clicked on a link it gave me. The website wouldn't allow me to close the page until I used the task manager. I turned off the computer for the night and when I turned it back on the next morning, it took a long time to start. I ran all the tools, except MGtools because I wasn't sure what I was supposed to click. There wasn't anything named that when I opened the folder. It takes at least 5 minutes to get to the start up screen on my computer and that only started after visiting that website. Most games won't run either. Can someone help? Thanks for any help.
    Here are the scans:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You just need to download and run MGtools.exe as requested. You can save it to your Desktop if that it easier for you. Thenmake sure your protection software is disabled and then just double click MGtools.exe to run it. When it finishes, it will tell you that the log is C:\MGlogs.zip and that is what you need to attach.


    ComboFix deleted the below. Do you know if these are for your games?
    c:\documents and settings\Laura\Application Data\TMInc
    c:\documents and settings\Laura\Application Data\TMInc\game.cfg
    c:\documents and settings\Laura\Application Data\TMInc\user2.sav

    I see you also recently downloaded and installed the below. If still installed or on your PC, uninstall and delete it. You don't need this or want this.
    Code:
    2010-12-18 04:55 . 2010-12-18 04:55 -------- d-----w- c:\documents and settings\Laura\Application Data\Uniblue
    2010-12-18 04:55 . 2010-12-18 04:55 -------- d-----w- c:\program files\Uniblue
    Also uninstall Ask Toolbar
     
  3. lauras

    lauras Private E-2

    Yes, those files appear to be part of one of the games. I can delete the game if it will help.
    Forgot to add that I deleted the other files. I had uninstalled the program (at least I thought I had) but I guess it didn't get all the files associated with it.

    Here is the MGtools log:
     

    Attached Files:

    Last edited: Dec 21, 2010
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then we will restore them with ComboFix. Your logs are basically clean. You just have some left over folders from previously using AVG and ESET to remove. Also I suggest that you uninstall Ask Toolbar and not install it in the future when you install programs like Glary Tools and other things that package junk like this with their software. You need to read the license agreements and popup messages before just clicking OK.

    So after uninstalling Ask Toolbar, delete any of the below folders that still remain.

    C:\Documents and Settings\Laura\Application Data\AVG10
    C:\Documents and Settings\Laura\Local Settings\Application Data\AskToolbar
    C:\Documents and Settings\All Users\Application Data\AVG10
    C:\Program Files\Ask.com
    C:\Program Files\ESET
    C:\AVGTemp

    Also delete all the below Tasks that you don't need slowing your PC down:
    Code:
    C:\WINDOWS\Tasks\
    apples~1.job  Dec 11 2010         284  "AppleSoftwareUpdate.job"
    expres~1.job  Dec 11 2010         298  "expressburnShakeIcon.job"
    glaryi~1.job  Dec 20 2010         312  "GlaryInitialize.job"
    go5b1f~1.job  Dec 11 2010         886  "GoogleUpdateTaskMachineUA.job"
    go7bdb~1.job  Dec 11 2010         996  "GoogleUpdateTaskUserS-1-5-21-2007217650-2966253982-1599952919-1007UA.job"
    go9834~1.job  Dec 11 2010         882  "GoogleUpdateTaskMachineCore.job"
    google~1.job  Dec 11 2010         868  "Google Software Updater.job"
    google~2.job  Dec 11 2010         944  "GoogleUpdateTaskUserS-1-5-21-2007217650-2966253982-1599952919-1007Core.job"
    google~3.job  Dec 11 2010         926  "GoogleUpdateTaskUserS-1-5-21-2007217650-2966253982-1599952919-1006Core.job"
    google~4.job  Dec 11 2010         978  "GoogleUpdateTaskUserS-1-5-21-2007217650-2966253982-1599952919-1006UA.job"
    schedu~1.job  Dec 21 2010         234  "Scheduled Update for Ask Toolbar.job"
    switch~1.job  Dec 11 2010         278  "switchShakeIcon.job"
    
    Now we need to use ComboFix to DeQuarantine some files
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. lauras

    lauras Private E-2

    I did what you said and my games run again, but start up is still taking 7-8 minutes to get to the sign in screen. Also, I don't know if it has anything to do with these problems, but I got a call from the fraud department of one of my credit cards today and someone had charged a bunch of things on my card.

    I have two users on this computer-me and my son. Should I also be running everything on his side too? Thanks for all your help so far. :)

    Here is the MGlogs:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    It does not appear to be due to any remaining malware. Even what has been removed thus far was just an annoying search toolbar. It may just be all the stuff you load at startup which is quite alot. Much of it would not be something I would ever use or would want to load, but I cannot determine what you need. However there is alot being loaded and it all takes time. And all the games being played and the licensing software (like PSIService.exe from Protexis Licensing ) and nProtect GameGuard Service are also contributing to slow startups. And TVersityMediaServer running is also not helping things. If you need to play games on your PC, you will have to live with the effects they have on PC performance.

    I will give you a few more tweaks ( non-malware) to do below to remove some other left overs but some permanent damage may have been caused by an infection if you are really sure this only occurred after your infection. Seems more likely to be from startup processes to me but we will do some tweaking and see what happens.

    Does not seem to be related to your infection since it was not a password stealer type but if you have been using your PC for online purchases you may want to keep an eye on it an change all passwords ( use another PC to change passwords just to be safe - not a public PC! By public, I mean one in a library, coffee shop....etc ).

    Yes you should repeat all scans except RootRepeal after a clean reboot and logging directly into his account and then attach logs. BUT NOT YET! First let's finish with your account and some tweaks. I'm going to also be removing some items from startup that are slowing you down. You don't need them to load when your PC starts. You should run them only when needed.


    However I have some questions and a couple comments.
    • Do you really need to use this StarDock program and allow it to run at startup???
    • What is MediaMall and why does it always need to be running?
    • Research and consider whether you really need NVIDIA nTune to always load and be running.
    • Comment: You have Roxio software running which has been a known resource hog and impacts startup times. FInd a better CD/DVD recording program like Nero for example.
    • Comment: Some user accounts ( your sons and a Temp account ) have been corrupted 4 times since 2008. You can see all the additional user account folder histories from them
      Code:
      "C:\Documents and Settings\"
      NICKY         Mar 21 2008              "Nicky"
      NICKYH~1.000  Nov  4 2009              "Nicky.HOME.000"
      NICKYH~1.001  Nov 12 2009              "Nicky.HOME.001"
      NICKY~1.HOM   Sep 18 2009              "Nicky.HOME"
      TEMP          Sep 17 2009              "TEMP"
      TEMPHO~1.000  Nov 11 2009              "TEMP.HOME.000"
      TEMP~1.HOM    Nov  3 2009              "TEMP.HOME"
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
    O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
    O20 - Winlogon Notify: AutorunsDisabled - Invalid registry found

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.


    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. lauras

    lauras Private E-2

    Ok, I did all those things. Stardock was something my son installed and I think I deleted all of it. It wasn't in the add and remove programs but I searched and removed all that I could find. MediaMall is PlayOn and I changed the settings to hopefully not run all the time. I tried to do the same with TVersity. I rebooted after everything to see if start up was any better, but it remains the same.

    I also looked up that PSIservice and found it was from Corel products so I disabled that. Apparently the nprotect gameguard is from one of my son's games and I will talk to him about uninstalling the game tomorrow and will try to remove that program. I found a link that tells how to do it.
    Here are the logs:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below services all still show in your last log and the run at start up.
    In addition to them, there are a few others as list below. The last one is due to games and the others for your Epson printer. I don't know if they are necessary or not
    As shown above, it was still in your logs.

    Also remember my comment about Roxio quite often being the cause for slow startups.

    It may be needed and it may be for more than one game. I have seen literally at least 20 to 30 thousand logs from PCs and this PC has to be the worst as far as the sheer number of things installed for gaming. All of the below show in your installed program list which is quite a ridulously large number of games as you can see. I'm not saying that these are slowing down your startup. This is just an observation of excessive gaming and also the copy protection and other startups related to gaming typically cause slow downs.
     
    Last edited: Dec 23, 2010
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After you have read my last very long message, see the below for an additional fix to remove some items showing in your startup list due to your sons account.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKUS\S-1-5-21-2007217650-2966253982-1599952919-1007\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Nicky')
    O4 - HKUS\S-1-5-21-2007217650-2966253982-1599952919-1007\..\Run: [Google Update] "C:\Documents and Settings\Nicky.HOME.001\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (User 'Nicky')
    O4 - HKUS\S-1-5-21-2007217650-2966253982-1599952919-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Nicky')
    O4 - HKUS\S-1-5-21-2007217650-2966253982-1599952919-1007\..\Run: [EPSON WorkForce 600(Network)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEKA.EXE /FU "C:\DOCUME~1\NICKYH~1.001\LOCALS~1\Temp\E_S375.tmp" /EF "HKCU" (User 'Nicky')
    O4 - HKUS\S-1-5-21-2007217650-2966253982-1599952919-1007\..\Run: [Aim] "C:\Program Files\AIM\aim.exe" /d locale=en-US (User 'Nicky')
    O4 - HKUS\S-1-5-21-2007217650-2966253982-1599952919-1007\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount (User 'Nicky')
    O4 - S-1-5-21-2007217650-2966253982-1599952919-1007 Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Nicky')
    O4 - S-1-5-21-2007217650-2966253982-1599952919-1007 User Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Nicky')
    O4 - S-1-5-21-2007217650-2966253982-1599952919-1007 User Startup: Stickies.lnk = C:\Program Files\Stickies\stickies.exe (User 'Nicky')

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. lauras

    lauras Private E-2

    Sorry it's taken me so long to respond. I've had lots of company for the holidays so I couldn't get back to the computer to work on it. I finally actually sat and watched the computer boot and noticed a message so I looked it up. The message said, "Loading PBR for descriptor 2...done". After checking if that message was supposed to be there, it looks like that shows there is corruption on the XP section of the hard drive (or that the hard drive is going bad). That's why it's taking it so long to boot. I haven't done anything about it yet as I'm just now really getting to start to research what I should do. Thanks for all your help.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds