Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
Pentium 4, 2 GHz, 2 G ram. Computer is exhibiting very slow start up on Quicken-not unexpected as files date back at least 6 years, and IE 7 takes 1-2 minutes to render any page.
Tried to run AVGfree 8 this morning, says it needed to be reinstalled. Downloaded a fresh AVGfree 8, disconnected the wireless, uninstalled, when trying to reinstall says I have another anti vius running on the machine. I don't. Uninstalled McAfee six months ago, as the firewall kept turning itself on and blocking GoToMyPC.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:51:52 AM, on 08/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Have tried on line scans in previous months, as this is an ongoing problem, but can only be worked on when machine is free from it's full time work load. The operator can and does live with the slowness, but if anyone else needs to use it...we go
TIA
Didn't find the information you thought to find? Check out these Similar Threads
Hi Jepinto
Did you go into add/remove and remove the old AVG first?
That would be my best guess as what it is seeing.
Download and run this to get rid of all the temp garbage and see if it helps with the slowness.
Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
Click Opera at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
When was the last Defrag and CHKDISK ran? That may help also but will take a while to run and complete, so some down time will be needed.
Yes, I removed AVG from the Add/Remove CP first. Should have mentioned that upon the recommended restart, there was a tray balloon saying McAfee was out of date, followed by the AVG installer message about two AV programs.
Ran ATF Cleaner, took a goodly number of files, just in Fire/fox-which is seldom to never used-it said 12,000 KB.
Ran chkdsk, removed a large number of gif files. Am defraging now, it is, as you said, slow, so allowing it to do its thing.
I think both chkdsk and defrag were done within the past 6 months, defrag shows, graphically, very little fragmentation, but this time I am following the directions
Last edited by Jepinto; 20th August 2008 at 20:59.
there was a tray balloon saying McAfee was out of date
OK, well no McAfee showing in the HJT log.
Let's see if this will show anything.
Download ComboFix by sUBs from here, saving the file to your desktop.
Important! ComboFix.exe must be on your desktop!
Close all open programs and windows
Click Start>Run and type or paste the following command.
"%userprofile%\desktop\combofix.exe" /skipfix
ComboFix will run ..... follow the prompts.
It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log in your next reply.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Geri-Thank you for your help so far. It'll be a day or two before I can do more with the box. We're on the outer edges of Fay and, while not directly affected, are staying preoccupied.
I will try again in two days to get back with updates.
ComboFix 08-08-24.03 - Owner 2008-08-25 16:57:49.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1494 [GMT -4:00]
Running from: C:\Documents and Settings\Owner\desktop\combofix.exe
Command switches used :: /skipfix
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
backup=C:\WINDOWS\pss\hp center UI.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=C:\WINDOWS\pss\hp center.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk.disabled
backup=C:\WINDOWS\pss\Microsoft Office.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^HotSync Manager.lnk.disabled]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\HotSync Manager.lnk.disabled
backup=C:\WINDOWS\pss\HotSync Manager.lnk.disabledStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^McAfee.com SpamKiller.lnk.disabled]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\McAfee.com SpamKiller.lnk.disabled
backup=C:\WINDOWS\pss\McAfee.com SpamKiller.lnk.disabledStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Registration-Studio 7SE.lnk.disabled]
path=C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Registration-Studio 7SE.lnk.disabled
backup=C:\WINDOWS\pss\Registration-Studio 7SE.lnk.disabledStartup
Well, Combofix ran because I opened it wrong. I thought to shut it down, but it was doing what seemed right, so I left it alone. (Note to self-read ALL the directions.)
Those two files look to be some excel ss that mistakenly got saved in the wrong place, but I'll check tomorrow. I have to ask the creator of the ss.
I'll get those two McAfees out first thing!
IE will not load a page faster than I can go outside and come back in. But the operator of the machine says she can live with it... but that was where all this started, trying to get a browser to load page faster. Neither IE or Firefox will load except extremely slowly.
AVG is doing one strange thing, just started after Combofix. It keeps shutting Resident Shield off. When I check, it says it is on, but if I turn it off, then turn it back on, it says it is on, Did it twice after Combofix, but now I can't remember whether I've restarted since then.
Last edited by Jepinto; 26th August 2008 at 03:17.
Can you tell what are?
C:\WINDOWS\Tasks\EasyShare Registration Task.job
They could be for a number of programs, This would be my guess.
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Registration-Studio 7SE.lnk.disabled
Here some info on these.
C:\WINDOWS\Tasks\ISP signup reminder 3.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe
C:\WINDOWS\Tasks\Registration reminder 2.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe http://www.softwaretipsandtricks.com...bebalnexe.html
Quote:
AVG is doing one strange thing ...but now I can't remember whether I've restarted since then.
Try a reboot, haven't heard of that problem with combofix before.
When was the last defrag and chkdisk ran?
Lets also clean up the temps and get a on-line scan.
Please do this.
Download ATF Cleaner by Atribune and save it to your Desktop.
This is a good tool to get rid of the temporary garbage you pick up while surfing the net.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
Recycle bin
The rest are optional - if you want it to remove everything check "Select All".
Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK.
Click on “Accept” If your pop –up blocker blocks any windows from opening.
Click Run on the window that opens. Windows Vista users you must open the web browser using the Run as Administrator command.
The program will launch and then begin downloading the latest definition files:
Under Scan on the left side.Click on My Computer
This will start the program and scan your system.
Click the “Scan Report” On the left side.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Click the Save Report As button, and in the Browse dialog box, type a name for the scan report file that you want to create and select its type Text file. Click OK to save the file.:
Save the text file to your desktop.
Copy and paste that information in your next post.
Cannot find C:\Documents and Settings\Owner\Start Menu\Programs\Startup\McAfee.com, it does not show up in that folder
C:\WINDOWS\pss\McAfee.com is now deleted.
ckdsk and defrag were run 6 days ago.
Reran ATF Cleaner, took 2,002 KB out.
Am running Kaspersky WebScanner now
Couple of oddities-AVG Resident Shield was running, said it had been running for 12 hours plus, but am still getting alerts that it is not active. AVG is turned off while Kaspersky WebScanner is running, so I'll look again in the morning.
Windows Security during the periods when Resident Shield is running gives no errors, but as soon as Resident Shield kicks off, Windows Security Center says "You may be at risk". Opening WSC, I get a message that there are several antivirus programs but all report they are either off or out of date.
Downloaded Malwarebytes' Anti-Malware, for future use. While trying to install it, kept getting another program's set up window. That program requires a CD to install, it is our MLS program, EZList MLS. Canceled the set up of EZList, it did, Malwarebyte's window comes back, click for next step, EZList comes back up, cancel EZ, Malwarebytes comes back, did this another 2 times.
Still very load loading the browser pages, but the machine seems to be starting up MUCH faster, and this is good.
Thank you for hanging with me through this-and yes, I will show my appreciation by utilizing the link click in your signature
Will post the next log upon completion, but I want to say thank you again.