XP Pro Viral Issues, AGAIN!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by timw128, Mar 5, 2014.

  1. timw128

    timw128 Corporal

    Hello- I have had this pc shut down and disconnected from the internet for approx. 7-8 mos. while I was away out of state. I came home 3 days ago, had Charter come and reconnect cable/internet, reinstated my expired avast! Internet Security (2014) and I am having all kinds of issues.
    Desktop background has disappeared, start up/ shut down is slow- just all kinds of weird stuff is happening. eset online sscanner found toolbar.widgi.e and MBAM found PUM.Hijack.StartMenu.
    I have completed the 'READ ME, RUN ME FIRST' and the logs are attached here.
    Please help!
    Thanks-
    tim
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    YOu are not having malware problems. Your logs are all clean. Try uninstalling Avast and then reboot.

    Any change? If not, reinstall Avast and I suggest that you post in the Software Forum.

    It could just be that you are getting impacted by 7 to 8 months worth of updates for all of your software including Windows
     
  3. timw128

    timw128 Corporal

    You are correct regarding the updates- Windows, Java, and Adobe had them waiting. However, with that said how do we explain the following reappearing daily?:

    - Win32/MyPCBackup.A
    - Win32/Preview
    - Win32/OneClick.H

    Thank you for your help.

    tim
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I can only comment on problems that you show me logs for. Your logs do not show this. Give me logs from whatever you are getting this info from. It could just be that you have things in System Restore that you have not cleaned out.
     
  5. timw128

    timw128 Corporal

    Something is going on chaslang. MBAM has found stuff, I followed your direction as to uninstall/ reinstall avast!. I posted in Software regarding possible Registry issues. This is driving me nuts. It all started after upgrading to avast! Internet Security 2014. Their Tech Support wants me to subscribe to this remote technical assistance for $179/ yr. No way!

    Progs and Comodo Dragon load slow, pc shuts down slowly, and boots up slow.

    I just don't no what to do here. (Please see attachment)

    tim
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just new junkware that was not present in your first logs. You must have installed some junk like Yahoo stuff after posting your first logs. Why didn't you let MBAM fix these.

    Also what do these have to do with the below you mentioned in a previous message?
    - Win32/MyPCBackup.A
    - Win32/Preview
    - Win32/OneClick.H



    After uninstalling Avast? Let's run one junkware cleaning tool and then check the current status.



    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the JRT.TXT log
    • C:\MGlogs.zip
     
  7. timw128

    timw128 Corporal

    Thanks, 'chaslang'... Of further note, I have a post over in Software regarding my OS. I haven't got the help as needed yet. I need some guidance on possibly repairing a corrupt registry. Also, I may be having HDD issues although HD Tune indicates it is healthy. Some of the numbers do not look good.

    I'll attach the Junkware and MGTools logs per your request.

    NOTE: I have NO idea how or why that 'driver cure' showed up in 'D &S'!

    Thanks!

    tim
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still see Avast installed.
     
  9. timw128

    timw128 Corporal

    Yes. Why wouldn't it be?... I have repaired it, uninstalled and reinstalled it, all to no avail. I ran HDD diagnostics and posted in Hardware Forum and been told the HDD is good. I have posted in Software Forum and am working with a guy over there. Ran MBAM quick scan this morning and found nothing.

    I'll mention it here- OS slow to boot to desktop: 2-3 minutes (used to be lightening fast), Avast! loads slow, along with browsers and other progs: another 2-3 minutes, come to MajorGeeks and can't log in: pointer just hovers above log in box and doesn't change to cursor for about a minute, and that by rt. clicking/ clearing a couple of times.

    Thanks-

    tim
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because I had asked you to try uninstalling it and you never commented on how things behaved with it uninstalled. Also you stated the below:

    Avast is just about the only main thing loading at startup other than a Comodo service. You stopped everything else with MSconfig which by the way you should not be using as a startup manager. Read this to better understand why not to use MSconfig: Dealing with Startup Process


    Also let's cleanup a left over servce I noticed from IoBit.
    Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

    sc stop AdvancedSystemCareService5
    sc delete AdvancedSystemCareService5
     
  11. timw128

    timw128 Corporal

    Sorry, 'chaslang', I must have misunderstood... Yes, I did an uninstall with Revo (not the avast! tool) and the progs and apps still loaded at the same slow rate.

    I have turned off a couple of settings on the Comodo Dragon browser and it appears to have helped slightly. (1)Enable phishing and malware protection and 2)Enable malware domain filtering (Comodo Secure DNS)).

    I noticed the iObit services you mentioned, too, and I'll remove as you suggested.

    I also have noted that my ISP download speed has deteriorated to 8.2 Mbps from 40+, all the while the upload has remained constant at 4.15 Mbps.

    Recovery Console- FIXMBR and FIXBOOT, along with a clean boot procedure in msconfig. This enabled and/or changed some services that I had changed the settings on to speed XP up (per Black Viper). The Black Viper recommendations were implemented over a year ago, so that eliminates the possibility of causality.
     
  12. timw128

    timw128 Corporal

    'chaslang', if it is OK with you, I'll run that HJT and post the log in that specific location to your attention.

    Please advise.

    Thanks-

    tim
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Huh? We don't need a HJT log. We already saw all the info we needed in the logs you posted. You are not having malware problems.

    The only thing I suggest besides fixing the service from IoBit, is to uninstall both Avast and Comodo and then reboot. Run without them for awhile to see how things work. Also try running in safe boot mode to see if there is any difference. Other than that, I suggest your work in the Software Forum.
     
  14. timw128

    timw128 Corporal

    This is confusing advice... Run without AV and without Comodo. Online without AV and IE8?... doesn't sound like a safe proposition to me.

    I have just been informed by the ISP Tech that Charter Communications is going through some internal server upgrades, etc. and it is affecting the internet speeds. This has become an issue within the OS software.

    Thanks for all your help.

    tim
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not safe long term especially if you do lots of questionable surfing but it is fine short term. I do it all the time for test purposes and I have to specifically download and/or click on things that would be known problems. I did not say run this way long term. I said to test it. And anything you would possibly pickup, we could fix anyway.

    You could also test without your ethernet cable plugged in to see how things work. The point of this is to see how Avast and Comodo are impacting startup and shutdown. Not on how they are impacting surfing.

    This has nothing to do with your complaints that your PC startup and shutdown is slow which is what I was focused on. This would only relate to your download speed issue mentioned in message # 11 which was a new or at least first time mentioned problem which I would still have said is not due to malware.
     
  16. timw128

    timw128 Corporal

    At present, I am chasing a bunch of broken signature DLL's. Quite possibly a result of malware chewing at the Registry. The Registry is messed up, and I am adamantly trying to avoid a repair of my XP Pro. Event Viewer along with some other tools is helping. 'sfc /purgecache' and 'sfc /scannow', followed by 'chkdsk /r' seem to be temporal exercises. AVG keeps finding this little 'threats' noodling about and that is verified by running 'depends.exe'.
    Today, the machine just rebooted while idling- all by itself! Threw a System Error Event 1003, among a bunch of 'atapi' Event 9's.

    Sorry, getting off topic, but I am confident some sort of viral content is behind all this- to some degree over time.

    Thanks-

    tim
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think you are misinterpreting this. Many of the Windows system files do not have signatures. In addition, if you have run sfc /scannow, it would repair any broken, missing or incorrect version Windows DLL files thus you should not have any if sfc /scannow ran to completion without needing a CD to fix anything. And if you had to insert a CD, it would repair from the CD.

    More likely it is just normal Windows wear and tear. While it is not impossible that some malware issue you had in the past has caused some registry damage, the logs you have posted show no malware issue. You only showed some junkware/aware which would not damage the registry or the file system. Windows crashing, hard power downs ( by holding in the power button when Windows gets stuck ), application installs/uninstalls, or power hits....etc are all more likely to have caused potential registry damage and/or file system damage. In fact, even running a registry cleaner can cause problems.

    Either way this would not be a topic for the malware forum.
     
    Last edited: Mar 12, 2014

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds