Slow System

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by goliano, May 17, 2007.

  1. goliano

    goliano Corporal

    My system runs slow at times. It seems intermittent.

    I really noticed after installing the driver and software (ArcSoft) for a generic digital cam. I had already uninstalled them and ran AdAware before starting the tutorial.

    Spybot S&D - Found nothing
    CounterSpy - Time limit exceeded
    AVG Antispyware log (if you ran it instead of CounterSpy) - Attached
    BitDefender - Found nothing
    PandaActiveScan - Wouldn't run
    GetRunKey - Attached
    ShowNew - Attached
    HiJackThis.log - Attached in following message

    Thanks,
    Goliano
     

    Attached Files:

  2. goliano

    goliano Corporal

    Re: Slow System (hijackthis.log)

    Thanks,
    Goliano
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see the below folder. Yu should delete this folder if the software is uninstalled.

    C:\Program Files\ArcSoft

    I see some stuff for Spy Sweeper still trying to load on your system but it does not appear to be installed. I'm going to add removing these Spy Sweeper items to my fix.



    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot in safe mode and located the below files and delete them if found:
    C:\Windows\System32\Msbb.exe
    C:\Windows\System32\Systmesy.exe
    C:\Windows\System32\localsrv.exe
    C:\Windows\System32\WRLogonNTF.dll

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
     
  4. goliano

    goliano Corporal

    Deleted folder C:\Program Files\ArcSoft

    Executed fixME.reg

    Only found C:\Windows\System32\WRLogonNTF.dll and deleted it.

    Attached logs for:

    Startup and navigating Windows Explorer seems normal, but like I said, it's intermittent. Some web pages are taking longer than normal to load. I'll see how it's running in the morning.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it is probably due to items you are running at startup. Some of which are autoupdate programs. When they are getting updates it will slow down startup and surfing. For example, things like Google Toolbar, GoogleToolBar Notifieier, Google updater, and LogitechSoftwareUpdate.
     
  6. goliano

    goliano Corporal

    So, there's nothing in any of the logs that requires my attention?

    Also, how does SpywareBlaster compare with AVG Anti-Spyware? I realize that resident shield protection is unavailable in the free version of AVG A-S, but is it worth purchasing the full version and chucking SpywareBlaster?

    Thanks,
    Goliano
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No there is nothing related to malware that requires your attention.

    SpywareBlaster is totally differnet than AVG Antispyware (even without the active protection of AVG-AS). SpywareBlaster is also not a scanning or removal tool.

    Keep SpywareBlaster installed (it does not use any system resources) and purchase AVG AS to get full active protection and scanning/removal capabilities.


    In addition to the above make sure you keep Spybot (without Teatimer) installer and use the Immunize feature (after each update, immunize again) and also use the SDHelper (bad download blocker feature). This also uses minimal system resources (just for the SDHelper) and gives you a backup scanner.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost forgot this!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds