Sorry, I posted my problem with two uploads to this other topic before I realized that maybe it should go here. I am sorry to break the rule (inadvertently) about posting twice. Would love to know what you think about all this stuff I seem to have open and running which is slowing me down.
Thanks,
Hasbro
Just thought of something – I'll go over to the other post and copy the text here. I'm probably breaking the rule even more by doing so. Sorry I'm so screwed up….
Here's the original text:
Have been doing Disc Cleanups regularly. Checking all boxes. Regular scheduled defrags. Lately, slower and slower general operation.
I just ran a full scan using free Malwarebytes' Anti-Malware program. It found nothing objectionable.
Here's a snapshot of my system:
Win 7 Ultimate, Build 6.1.7601
Dell OptiPlex 330
Intel Core2 Duo E4600, 2.4 GHz
Bios Dell A07
Physical Mem 2.0 GB
Total Virtual 4.0 GB
Check out the attached HijackThis log and please let me know what advice you can give me.
Check out the attached file where I show all the "Services" running in Task Manager. Sheesh. I exported them to a text file. How do I know what to get rid of and how to do that?
All good advice appreciated. This computer really worked well for me when fresh and all programs just installed. I think I ruined it.
My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
It's not unusual to have a large number of services running at any given time. Some start with the computer, some only get used when they are needed. While stopping some unnecessary services may give you some improvement, our job here will focus on making sure you don't have any malware hiding that's not being detected. If we find you appear to be malware free, they the Windows forum will take back over with you. So let's get started!
HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.
Download and Run DDS by sUBs
Please download DDS and save it to your desktop.
Disable any script blocking protection
Double click dds.scr to run the tool.
When done, DDS.txt will open.
Save both reports to your desktop.
—————————————————
Please Please copy / paste the scan reults.
DDS.txt
Please attach the second file; Attach.txt.
Download and Run GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
Extract the contents of the zipped file to desktop.
Right-click and choose Run as Administrator on GMER.exe. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
In the right panel, you will see several boxes that may have been checked. Uncheck the following …
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one - make sure it is UNCHECKED)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Greetings. Many thanks for your initial response, the explanation about HJT, and good instructions. And thanks for your diligence in following up a second time.
Attached are the files generated by DDS. Seemed to go with no problems.
GMER, on the other hand, caused problems. I used the first link in your post, and got a file (.exe) which didn't require unzipping. I right clicked, and no choice existed for running as administrator. Program opened, I adjusted the check boxes, and ran the scan. It stalled and I got an error message – program stopped working. I told it to close, and it immediately went blue screen. I rebooted, tried the second link in your post, downloaded from there, it was zipped this time, unzipped, adjusted the check boxes, ran the scan – and the same thing happened at the same place in the scan. This time when the error box popped up I asked the program to shut down and no blue screen.
So, I have no GMER output at this time. I will await your instruction about how to beat whatever it is that is now beating GMER in my system.
Again many thanks for helping me.
OK, Doris, now I think that whatever malware was stopping that GMER program from scanning felt your presence or something, because after writing that last post to you, I tried it one more time, and it seems that it scanned all the way to completion. So, attached is the scan log.
I thank you again.
I'm not seeing any malware in these logs. Let's just do a couple of more scans to be on the safe side.
I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
Click on the tab labeled Update and then click on the button Check for updates.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan. [external image: Posted Image]
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.
http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start. Uncheck Remove found threats.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic.
OK, MWB run and txt file attached.
Running ESET now.
Even though no malware showing up, are you not concerned about the number of services running? Isn't it probable that too many unnecessary processes are running, perhaps many of which could be turned off, thereby saving resources and speeding things back up to the levels of a fresh install, or at least near those levels?
It's not that I'm not concerned about the processes, or that some of them may be able to be safely stopped. You were referred to this forum to ensure that none of those processes are a result of malware infection. Once I can assure you that I don't believe that to be the case, the Windows forum can assist you with the task of looking at what's running and what can be changed/removed/stopped etc.
Thank you for taking the time to do the extra scans. I would suggest you update your Java and Adobe Reader to the latest versions as older versions have security vulnerabilities. But your system appears to be malware free. Head back over to the Windows forum and let them know you are clear.
Have a great evening!