Would appreciate any help I can get with this Pain in the a$$

Discussion in 'Malware Help (A Specialist Will Reply)' started by connect, Jun 18, 2012.

  1. connect

    connect Private E-2

    Running Windows XP - SP3, Asus P5GC-MX/1333 Motherboard, Dual Core E-2180 Intel Processor - all was working fine until about 2 months ago, when it slowed to a crawl in normal mode (safe mode - no problem).

    I've ran most every tool I can thing of - I don't detect anything - all drivers appear OK, file structure seems fine.... I normally run avast A/V, Windows firewall, the usual crap - it's my buddy's 'puter so I'm not sure what he may have done, but I simply can't seem to detect it.

    Download speeds are fine - but opening programs is slow - computer freezes on some tasks (can't even select from the start menu until I wait a minute for it to respond). It will not restore to an earlier point (may have been me running glary utilities that caused it....)

    I've been snooping around here for a few years and gleaning potential answers to problems - this is a first post, simply because I've been working this for a couple of weeks, and I'm about ready to use a shotgun to fix the damned thing once and for all. A bit extreme - but it might make me smile :)

    I've attached logs - Instructions followed to the letter.

    Never failed to fix one before - but this one has me absolutely perplexed.

    Thanks in advance if you can lend a hand,
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing any malware, let's just do this.

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:



    What is inside of these folders? If they are empty, simply delete them away.

    C:\Documents and Settings\Goldcar\Application Data\Govo
    C:\Documents and Settings\Goldcar\Application Data\Rypou

    Delete this file: C:\Windows\Tasks\gncqeazk.job

    Running any better at all or not?
     
  3. connect

    connect Private E-2

    Significantly better - still slow at boot, but I have normal boot enabled. Waaaaay faster on opening new apps. It's not back to what it was before this - but with some tweaking and selective startup, should be able to be restored.

    Alright, understand the mywebsearch key deletion (never use ie anyway), but
    02-BHO... and
    04-HKLM....

    I'm unsure why they would cause problems as they should have been empty keys.

    ALCMTR I looked at as a process, but left alone as it was a realtek piece of s/w....

    And as for the most important part - THANK YOU VERY MUCH for your assistance. It's nice to know that there are people out there that will help other for no other reason than to help. It tends to restore one's faith in Humanity.

    Again, thank you. (But if you did feel like telling me what just happened..........)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Precisely, so let's just be rid of them (and we did) it's just clean up. I like things neat and tidy.
    Yes, but they do not need to be running at start up ;)
    You are most welcome. No idea what happened though. Sorry.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds