Thought I got it all, but still problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by sebray, Jul 5, 2008.

  1. sebray

    sebray Private E-2

    I was having problems about a week ago...unable to right-click/save photos that were opened in a new tab in IE...some tabs not connecting when opening a link in a new tab. There was once that I had a problem shutting down because of teatimer. I have uninstalled and reinstalled Spybot without it. Those problems are fixed now.

    The problem I'm still having (it happened at the same time as the previous ones but wasn't fixed with them) is with an online game I play - Star Wars Galaxies. I'll do my best to explain it but let me appologize for my lack of tech speak.

    If you know the game I'm talking about then you'll understand me when I say that it's like I'm in the middle of Mos Eisley during a Pex event...

    If you have no clue, then I'll try to explain. My game runs really slow. It's slow to log in, slow to move, my curser is jerky, as is any kind of movement I attempt to do. It's pretty painful to play. A friend says that it's like I've got malware or an anti-virus going but again, I've followed everything as best as I could and all my logs are clean - well the programs say that no problems have been found. I also never had a problem playing it with Norton running before the problems started.

    The only thing I can think of to do now is to uninstall and reinstall the game...game's 5 years old...think 5 years of updates, patches, expansions....I'd rather slit my wrists.

    I have followed the "Read and Run Me First", "Vista Cleaning Procedure", and "Basic Computer Maintenance Everyone Should Do" threads to the best of my ability.

    I could not delete my Norton files because my sub is out of date and even though it's expired I don't feel comfortable without having an anti-virus on the laptop (if there is a recommended free one then I'm all ears).

    So here are my logs and thanks in advance for all the help.

    ps...please don't make me reinstall the game...I'll do anything...you can even have my 1st born son...really, I won't miss him...rolleyes
     

    Attached Files:

  2. sebray

    sebray Private E-2

    and the other log...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Note that I doubt your problems are due to malware. Issues like you are mentioning are more frequently related to what a person is running on their PC and the PC's specs. Note you appear to be running MSconfig to control startups. Did you ignore that part of step 1 in the READ & RUN ME.

    I'm looking at your logs now.
     
  4. sebray

    sebray Private E-2

    No, I checked it but it was already set to the way it was supposed to be. I didn't have to change anything.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are dozens of stuck registry entries due to having used MSconfig at sometime.

    Did you add any new hardware into this PC recently? I see multiple video cards sharing interrupts and I/O addresses.

    You do not appear to be having malware issues. There are some misc non-malware things we can cleanup but they will not improve your problem. You may get more improvement by dumping Norton Internet Security and also removing all the junk that Roxio has running. Both of these have been known to cause major performance issues.
     
  6. sebray

    sebray Private E-2

    Go ahead and walk me through the clean up. I don't like having extra junk on the laptop, especially since I use it for school.

    Hardware?? My mom hooked up her printer/fax about a week ago or so, not sure if that uses a video card or would cause what you're seeing. And as far as I know, I only have one video card...but then again, I'm a math geek not a computer geek :)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Working on it now.

    Look inside of the C:\MGtools folder and view the sysinfo.txt file with notepad and you will see what I'm referring too. The first place you see reference to 2 card is under the [Conflicts/Sharing] heading.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's fix the misc items I see which should be done anyway.


    First answer what the below is and why does it need to load at startup? I assume it is from your ISP but is it needed? It also appears to be new.
    O4 - HKCU\..\Run: [1&1 EasyLogin] C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe


    Uninstall the below old versions of Sun Java:
    J2SE Runtime Environment 5.0 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6
    SUPERAntiSpyware Free Edition <-- We are finished with this now!

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - (no file)
    O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    Optionally, I also suggest you fix the below. Only run them when you need them rather than always running them.
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your PC
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below log:
    • C:\MGlogs.zip
    Any change at all. Don't forget, I did not expect these minor things to change much.
     
  9. sebray

    sebray Private E-2

    It is from my web host. It is new, and no it doesn't need to run on start up.

    Working on the rest, will post the log shortly.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then I would fix it with HijackThis too.
     
  11. sebray

    sebray Private E-2

    I got an error when I ran C:\MGtools\analyse.exe. Here's the log - probably not complete because of the error.

    Error said:
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Almost everything in your log is old which means the scans did not run. Please delete the current C:\MGlogs.zip file and the run the GetLogs.bat file again. If you get any error messages just click okay and allow the program to finish running. Attach the new log.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well maybe not! Perhaps you did not run the registry patch or did not get a success message. I ask you to tell me if you received a success message.

    Also the below is still there. Are you going to fix it?
    O4 - HKCU\..\Run: [1&1 EasyLogin] C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe
     
  14. sebray

    sebray Private E-2

    sorry, yes it gave me a success message.

    Will rerun the GetLogs.bat file again
     
  15. sebray

    sebray Private E-2

    done, same error but different numbers to it

    Process id=0x1200 (4608), Thread id=0x12f8 (4856)
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The registry patch did not work properly. Let's try a new one.


    Copy the bold text below to notepad. Save it as fixMSC.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Attach another new MGlogs.zip file after running GetLogs.bat again.

    By the way is there any change to how your PC is running.
     
  17. sebray

    sebray Private E-2

    I did get a success message. My computer definatly loads up faster on startup...however there's been no change to the issue I'm having with my game. I'll probably have to take that problem to their forum since I'm pretty sure now it's not my computer.

    You said something before about dumping NIS and Roxio...can I still do that?

    Got another error at the end of running the GetLogs.bat

    Process id=0x11b4 (4532, Thread id=0xf0 (240).

    Do you still need me to type these errors, or are they all the same? Oh, and I'm just clicking OK to terminate, I know nothing about debugging.
     

    Attached Files:

  18. sebray

    sebray Private E-2

    lacking a delete post button ... rolleyes
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it worked properly this time.

    I did not think it would impact it as I said earlier.

    Yes if you want to? Do you use Roxio for burning CDs/DVD or for anything else? Do you have another program to replace it with?

    For NIS removal follow the below steps exactly as written:
    • Download but do not install this Avast! Home Edition
    • Now download and run this Norton Removal Tool (SymNRT)
    • Then reboot your PC
    • Now run the Norton Removal Tool one more time and reboot again
    • Now install the Avast program you downloaded
    • Now run GetLogs.bat again and attach a new MGlogs.zip file so we can check that all of Norton was removed.
    This particular error is not a problem as the program is working anyway. It is just one process that the program is having a problem reading information on.
     
  20. sebray

    sebray Private E-2

    The only thing I use to burn CDs is iTunes and as far as I know I've never used Roxio. Will work on the rest in a bit. Thanks :)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are sure you don't need Roxio then just uninstall all components of it from Add/Remove programs.
     
  22. sebray

    sebray Private E-2

    I downloaded both programs, ran the Norton Removal Tool and rebooted twice like you said to. I installed the Avast and rebooted. Durring that reboot, Avast ran and towards the end my computer froze/shut down (I'm not too sure because I was on the phone and it was running one moment and then the next, I've got a black screen but all my power lights were on.) so I just hit the power button to make sure it was off and went to work. This morning when I got home, I started the computer and it said something about Windows not starting properly, prompted for a system restore, that fixed it and I was able to get on again but Norton is still there.

    Did I do something wrong??
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The system restore brought everything back to the restore point. If you had uninstall Roxio, it will be back too. Thus if you had uninstall it, you need to uninstall it again.

    Start over again with the Norton Removal Tool. This time do not install Avast. Just run a little bit after Norton has been removed to see how things are working and then reboot again just to make sure it work properly. Then also run GetLogs.bat and attach a new MGlogs.zip file. I want to make sure Norton was all removed. Do not stay online too much without protection in place but do not reinstall Avast or any other antivirus yet until I look at your log.
     
  24. sebray

    sebray Private E-2

    Here's my log...was unable to re-uninstall the one Roxio program that came back, got an error that said "Unable to find a certificate file".
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe

    Note: You may receive an error message about the above being critical services or similar, just ignore and continue.
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop (yes overwrite the old file). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! I know we do not have an antivirus installed yet. I just want to know how things look right at this time.
     
  26. sebray

    sebray Private E-2

    Ok, here's the logs

    I got the success message about adding to the registry.

    Also, When I moved that file to ComboFix it started up but then restarted my machine...I restarted the program after my computer started again.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The fix did not work. Try again. Make sure you drag & drop using left click not right click. Also you cannot just run ComboFix by double clicking on it which is what your log show was done. You need to create the CFScript.txt file and drag and drop it.

    Attach new logs but only if ComboFix works properly.
     
    Last edited: Jul 8, 2008
  28. sebray

    sebray Private E-2

    Ok, I created the CFScript.txt file and drag and dropped it using left click not right click....and it started...did a few things...then restarted my computer :(
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is what it is supposed to do. Attach the new ComboFix log and also get a new MGlogs.zip file to attach.
     
  30. sebray

    sebray Private E-2

    ok, here is my MGlog but ComboFix didn't create a log because it didn't run, it started then restarted my computer without finishing like it did last time - sorry if I wasn't clear
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your MGlogs.zip file is incomplete.
    • Did you wait for it to finish running?
    • Do you still have UAC disabled? (this could cause problems for both ComboFix and MGtools)
     
  32. sebray

    sebray Private E-2

    I'll run it again. As far as I know Istill have UAC disabled...I havent' changed that since I disabled it in the begining, but I'll double check
     
  33. sebray

    sebray Private E-2

    yes, the UAC is still disabled. Here's the log
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it ran properly this time.

    Since we are having a problem getting ComboFix to run properly, let's try another tool to finish the fixes.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  35. sebray

    sebray Private E-2

    I have no idea what's going on, but I'm starting to really get frustrated with this. I did exactly as you said and when it restarted I got a message that windows failed to start and to launch startup repair (reccomended) or start windows normally. I did the recomended option and it did a system restore.

    I'm not sure what's going on but I really really don't like running without an antivirus and these issues are making me worried :(

    and no, there was no log file made. I also didn't run CCleaner.
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why you are having so many problems with these tools but it may indicate other problems (not malware - as stated in my first message you have not malware issues) within your Windows Operations system.

    Let's try to finish this manually.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Roxio Hard Drive Watcher 9
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteRoxWatch9 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot if it tells you it needs to.
    Now delete the below files if found:
    C:\Windows\System32\drivers\SYMEVENT.CAT
    C:\Windows\System32\drivers\SYMEVENT.INF
    C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Alison.job

    Now delete the below folders if found:
    C:\ProgramData\Symantec
    C:\Program Files\Alwil Software
    C:\Program Files\Common Files\Roxio Shared
    C:\Users\Alison\AppData\Local\Temp\_avast4_

    After doing the above, you can reinstall your choice of antivirus now.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).





    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 13, 2008
  37. sebray

    sebray Private E-2

    Was already stopped - just disabled it

    Didn't have permission - weird..

    Reinstalled Avast

    Here is the MGlog.


    Had absolutely no problems this time. Very strange. But thank you soooo much for sticking with this. Let's hope everything is clean and running good now :)
     

    Attached Files:

  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I would not worry about it since everything is running good.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  39. sebray

    sebray Private E-2

    Thanks for all your help. I've finally been able to take care of this last step. My computer is running much better now...but the game is still the same. Not sure how to fix that but I'm sure I'll find someone who can.

    Thanks again :)
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Try the Game forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds