This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Machine running slow and hard drive space disappearing

11 min read

This thread's last reply is from November 5, 2009, 11:39 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hello and Welcome to Malware Removal Forums.
  • My name is xixo_12 and i will guide you to encounter the problem that you have now.
  • We will work together and I need your attention to read all those instruction carefully.
  • You may wish to print them off or copy them into Notepad.
  • If you have any question please don't hesitate to ask.
  • The instructions that i will give to you later are specific to your current problem and shouldn't be used on other systems.
  • If you are receiving help or have received help on this problem elsewhere, please let us know.
  • Please post your replies to this thread only and keep interact with me until your computer is clean.


Everything I post to you will be review by MRU Teacher. This process will impact my response time to you. Be patient. ;)
Please! If you need more time to do all the instructions, let me know before 72hours is done. Otherwise, your thread will be closed

Next,
Uninstall List.
  • Run the HiJack This.
  • Click at Open the Misc Tools section button.
  • Click at Misc Tools tab.
  • Under the System tools, click at Open Uninstall Manager button.
  • Find the Save list… button and save to the Desktop
  • Copy the content and paste the uninstall list here.


Next,
Checklist.
Please post.
  • uninstall list.
Hi,
Let's proceed.

First,
ATF by Atribune.
Please download HERE and save to the desktop. Double-click ATF Cleaner.exe to open it.
Under Main choose:
    choose: Select All
    Click the Empty Selected button.

if you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

if you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.


Click Exit on the Main menu to close the program

Next,
MGADiag.
Please download from HERE and save to the desktop.
  • Right click on MGADiag.exe and choose to Run as administrator.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file MGADiag.txt and post it in your next reply.


Next,
Discussion.
What is the purpose of this program:

Orbital Viewer
QCharts 5.1
QCharts 6.0.3.2


Is it business PC/laptop?

Next,
Checklist.
Please post.
  • MGADiag.txt
  • Answer for discussion.
Hi,
Let's proceed.

Note : Windows Vista require user to right click > run as administrator to run the program.

First,
Remove programs.
Please Click Start > Control Panel > Programs and Features
Remove these programs by clicking Uninstall/Change.

Java(TM) SE Runtime Environment 6
Adobe Reader 8.1.7

If some programs listed are not present, please do not panic and proceed to next step.

Next,
Java SE Runtime Environment (JRE).
Please download from HERE.
  • Find Java SE Runtime Environment (JRE) 6 Update 16.
  • Click on Download.
  • Choose the correct Platform and Multi-language. Next, check the box that says I agree to the Java SE Runtime Environment 6 License Agreement.
  • Click the Continue button.
  • Click on the filename under Windows Offline Installation and save it to your desktop.
  • Close all active windows.
  • Install the program.


Next,
Update Adobe Reader
  • Recently there have been vunerabilities detected in older versions of Adobe Reader.
  • It is strongly suggested that you update to the current version: Adobe Reader 9.2
  • You can download it from HERE


Note : Adobe 9 is a large program and if you prefer a smaller program you can get Foxit 3 instead from Foxit Software
Reminder : Do not install anything dealing with AskBar presented as an installation option.

Next,
Important.
WEATHERBUG
WeatherBug is a system tray icon that offers weather information and includes built-in ads. WeatherBug is controlled by AWS Convergence Technologies (weatherbugmedia.com). There is some controversy over whether WeatherBug should be targeted by anti-parasite software. AWS strongly deny their software is 'spyware', and by the definition used here, it is not, as it does not leak information back to its controlling servers. However, WeatherBug has in the past been silently installed by the FavoriteMan parasite and Freeze.com screensavers, and more recently has been bundled by software such as AIM and Blubster. This makes it 'unsolicited', and since it is installed to raise money for its creators through the built-in ads it is certainly 'commercial'. So it does meet the definition for 'parasite': unsolicited commercial software. It is nonetheless listed as a borderline case because it is not overtly harmful and many people do install it deliberately. WeatherBug bundles the MySearch parasite in its standalone distribution and has in the past, installed Gator and SVAPlayer.

I recommend that you uninstall WeatherBug and choose one of these alternatives:


Please uninstall WeatherBug now.

Next,
Fix entries.
  • Go to HiJackThis Main menu.
  • Click at Do a system scan only button.
  • Search for below entries and tick it.

    O2 - BHO: agcore.AGUtils - {0bc6e3fa-78ef-4886-842c-5a1258c4455a} - mscoree.dll (file missing)
    O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
  • Close any other program and leave HiJackThis alone.
  • Click Fix checked


Next,
Delete folder
  • Navigate to the directory as below.
  • Delete the file or folder in red color (if exist).
    Folders :
    C:\Program Files\AWS



Next,
RSIT.
Please download Random's System Information Tool by random/random from HERE and save to the desktop.
  • Right click on RSIT.exe and run as administrator to run the tool.
  • Click Continue at the disclaimer screen.
  • Once it finishes, two logs will open...
    • log.txt will be opened maximized
    • info.txt will be opened minimized
  • Please post the contents of both logs in your next post.

***You can find manually the log at C:\rsit

Next,
GMER.
Please download from HERE and save to the desktop.
  • Unzip/extract the file to its own folder.
  • Disconnect from the Internet and close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.
  • Right click on Gmer.exe and run as administrator to start the program.
  • Allow the gmer.sys driver to load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan,click NO.
  • Click on >>> symbol and choose on the Rootkit tab.
  • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
  • Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
  • Click on the Scan and wait for the scan to finish.
    Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
  • When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
  • Note: If you have any problems, try running GMER in SAFE MODE"

Important! Please do not select the "Show all" checkbox during the scan..

Next,
Checklist.
Please post.
  • Content of log.txt.
  • Content of info.txt
  • Content of GMER.txt
Hi,
I don't see any weird entries in your system.
Most probably not malware related.

Next,
This fix is optional fix that will reduce the amount of program that will run on startup. This will help your system running pretty fast.

Fix entries.
  • Go to HiJackThis Main menu.
  • Click at Do a system scan only button.
  • Search for below entries and tick it.

    O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
  • Close any other program and leave HiJackThis alone.
  • Click Fix checked


Next,
ATF by Atribune
Proceed with the instruction if you didn't delete the copy before this.
Please download HERE and save to the desktop.
Double-click ATF Cleaner.exe to open it.
Under Main choose:
    choose: Select All
    Click the Empty Selected button.

if you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

if you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.


Click Exit on the Main menu to close the program

Next,
ESET Online Scanner
Go here to run an online scannner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic


Next,
RSIT.
Please run RSIT again to produce log.txt.
***You can find manually the log at C:\rsit

Next,
Checklist.
Please post.
  • Content of log.txt (Find it at C:\Program Files\Eset\Eset Online Scanner\log.txt)
  • Content of log.txt (Find it at C:\rsit)
  • Any question if you have.
Hi,
I'm still waiting ESET online scanner (log.txt) as the bold green part.
You missed it.
Please provide.

Next,
Checklist.
Please post.
  • Content of log.txt (Find it at C:\Program Files\Eset\Eset Online Scanner\log.txt)
  • Content of log.txt (Find it at C:\rsit).
  • Any question if you have.
Hi,
Let's try another one.

Kaspersky Online AV Scan
Note: Internet Explorer should be used.
Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan and then put the kettle on!
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place like your Desktop. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Copy and paste the report into your next.


Next,
Checklist.
Please post.
  • Content of kaspersky log report.
Hi,
Good! Your system appear to be clean. :thumbright:

Since I noticed this :
System drive C: has 5 GB (2%) free of 226 GB
The free space just 2%!

Here is a few advices from me.

You need to free up some space on your hard drive. Put some of your files on CD or DVD and then erase them from your drive.
You can check the Free Space on the drive by going to Start > My Computer > right clicking on the C: drive, and choosing properties.
You need to have 35 Gb free space on the C: drive for this machine to work properly.
If you don't know how to transfer files to DVD or CD, you can visit one of these forums:

System/Hardware forums


You may need to do free registration in order to post at their forum ;)

Next,
ATFCleaner.
  • I gave the instruction about this program previously.
  • Keep that program to clean temporary files and will give you some free space


Next,
Antivirus.
  • Antivirus help you to give the maximum protection for the system.
  • You are advice to have only ONE antivirus running on the system.
  • Keep your antivirus updated.


Next,
WinPatrol.
  • Unwanted things always occur behind your knowledge. Let's this software take the snapshot of it.
  • For more information and installation can be found HERE


Next,
Information.


Happy safe surfing! :)
No problem ;)
As this issue appears to be resolved,