spyware I think is all gone..but computer sucks now

Discussion in 'Malware Help (A Specialist Will Reply)' started by scaryone, Jan 22, 2008.

  1. scaryone

    scaryone Private E-2

    I have used all teh spyware removal tools that I can think of on this machine and I think its clean now, but that darn thing was a lot faster before I started. Please help.
     

    Attached Files:

  2. scaryone

    scaryone Private E-2

    Also it says my virtual memory is low.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    According to your logs, I would say this is because you were previously running without any protections software. Now you just installed AVG AntiVirus, AVG Antispyware, and Ad-Aware 2007 (by the way we did not ask you to install Ad-Aware 2007 and do not recommend it). Adding protection software will have an effect on performance but it is a necessity. Based on the logs nothing was really removed.

    You have dozens of things disabled with MSconfig which we clearly requested that you not do in the first step of the READ ME. You MUST NOT use MSconfig as a startup manager. It was designed as a temporay debugging tool. Due to using like you are you have things trapped in there that aren't even installed anymore.

    How to deal with startup processes.
    • First you should uninstall any software that you do not use.
    • Second if you have processes still trying to load at startup even though you have uninstalled them. You can simple use HijackThis to easily remove the startup. That way you will not have to manually edit the registry.
    Third for software you do not want to uninstall but you don't want it to load at startup, look in the program for an option not to load when Windows starts and disable it this way. If you cannot find an option like that you have two possible actions:
    • if you never want it to load at startup, use HJT to permanently remove the startup.
    • if you sometimes want it to load at startup, use a program like Startup CPL to enable or disable as you see fit.
    You also did not uninstall Viewpoint Media Player (Remove Only) as requested in the READ ME. Uninstall it now.

    Also uninstall the below old Sun Java versions:
    Java 2 Runtime Environment, SE v1.4.1_02
    Java 2 Runtime Environment, SE v1.4.2

    Also delete the below folder:
    C:\Program Files\rypvkvyu


    Now Disable MSconfig now per the READ & RUN ME and then get a new MGlogs.zip file by running C:\MGtools\GetLogs.bat . Attach the new C:\MGlogs.zip file.
     
  4. scaryone

    scaryone Private E-2

    Ok I enabled all the msconfig stuff. and removed view point... Sorry didnt see it the first 10 times I looked in the add and remove folder. Removed ad_aware 2007 and uninstalled old javas. and deleted the folder u told me too. Here is the new scan folder. Thanks for your patience and help!!!!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay below are a few non-malware things you can do which will also help with performance.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"

    Do you use MusicMatch Jukebox? If not then uninstall it. If you do use it, fix the below lines as you don't need them to load at startup.
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) -
    O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -

    After clicking Fix, exit HJT.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  6. scaryone

    scaryone Private E-2

    Thanks 4 all your help!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds