Spyware...Malware...and Security OH MY!

P

PSULionRP

Ok. Now I don't mean to open up a whole can of worms here and please don't
tell me I'm in the wrong place because I checked the Security section and it
wasn't very robust.

Our home PC has been sooooooooooo slow lately. I suspect that there is some
sort of Spyware or Malware or other nasty things on this. It is old, probably
5 or 6 years old, so I don't want to invest a lot of money into this venture.
Like so many other suckers out there, I did see the commercial for
finallyfast.com. I ran the diagnostics from it and it said I had 55 Registry
errors. That might be all good, but I'm sure this doesn't explain all my
delays. Plus I read that Registry Error fixes were a bit of a scam.

Can anyone suggest some good Spyware and Malware software out there would
help clean this thing up and hopefully get this PC to be faster and a bit
more efficient???

Is AVG Anti-Virus Free Edition the answer??? Is this going to take care of
malware???

I would really appreciate any feedback and Thank You soooooooo much for your
feedback.

PSULionRP
 
B

Big_Al

PSULionRP said this on 3/29/2009 9:10 PM:
Ok. Now I don't mean to open up a whole can of worms here and please don't
tell me I'm in the wrong place because I checked the Security section and it
wasn't very robust.

Our home PC has been sooooooooooo slow lately. I suspect that there is some
sort of Spyware or Malware or other nasty things on this. It is old, probably
5 or 6 years old, so I don't want to invest a lot of money into this venture.
Like so many other suckers out there, I did see the commercial for
finallyfast.com. I ran the diagnostics from it and it said I had 55 Registry
errors. That might be all good, but I'm sure this doesn't explain all my
delays. Plus I read that Registry Error fixes were a bit of a scam.

Can anyone suggest some good Spyware and Malware software out there would
help clean this thing up and hopefully get this PC to be faster and a bit
more efficient???

Is AVG Anti-Virus Free Edition the answer??? Is this going to take care of
malware???

I would really appreciate any feedback and Thank You soooooooo much for your
feedback.

PSULionRP

I'll toss in my suggestions:

AVG anti-virus, just don't load the link-scanner on a slow pc. Too much
overhead.
Malwarebytes anti-malware remover.
Spybot S&D (search and destroy) anti-spyware. It's recommended, but I
don't use it personally.
Autoruns from MS sysinternals. This will allow you to just remove
some programs from starting on bootup. I kill adobe gamma loader for
example, and a few update programs that I don't care about 'auto
updating'. I do them manually now and then. Still this is personal
preference as to what to stop loading. Obviously you can turn off too
much and hurt.
http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx
CCleaner will allow you to pick items to clean and remove from your PC
all in one tool. It even allow you to clear selective cookies.

You can find all these with google and they are all free. So if you see
any link or screen to pay, you got something wrong. Sorry don't have
the links handy at the moment.
 
K

Kayman

Ok. Now I don't mean to open up a whole can of worms here and please don't
tell me I'm in the wrong place because I checked the Security section and it
wasn't very robust.

Our home PC has been sooooooooooo slow lately. I suspect that there is some
sort of Spyware or Malware or other nasty things on this. It is old, probably
5 or 6 years old, so I don't want to invest a lot of money into this venture.
Like so many other suckers out there, I did see the commercial for
finallyfast.com. I ran the diagnostics from it and it said I had 55 Registry
errors. That might be all good, but I'm sure this doesn't explain all my
delays. Plus I read that Registry Error fixes were a bit of a scam.

Do I need a Registry Cleaner?
http://www.whatthetech.com/2007/11/25/do-i-need-a-registry-cleaner/

Why I donÿt use registry cleaners!
http://www.edbott.com/weblog/archives/000643.html

I'd use:
CCleaner - Free
Cleans temporary internet files, cookies, history, recent URLs, application
MRUs, etc. ... (*Tune out the registry scanning/fixing option!*)
http://www.ccleaner.com/download/builds/downloading-slim

Followed by:
NTREGOPT
http://www.larshederer.homepage.t-online.de/erunt/

Re: CCleaner set-up
If Windows Defender is utilized go to Applications, under Utilities uncheck
"Windows Defender" (so it won't delete the history of WD)
--or--
Setup CCleaner to Automatically Run Each Night in Vista or XP
http://www.howtogeek.com/howto/wind...-automatically-run-each-night-in-vista-or-xp/
Can anyone suggest some good Spyware and Malware software out there would
help clean this thing up and hopefully get this PC to be faster and a bit
more efficient???

Is AVG Anti-Virus Free Edition the answer??? Is this going to take care of
malware???

I would really appreciate any feedback and Thank You soooooooo much for your
feedback.

Preferred practice is to 'flatten' and rebuild a computer that has been
exposed to malware.
http://www.microsoft.com/technet/community/columns/secmgmt/sm0504.mspx
http://technet.microsoft.com/en-au/library/cc512595.aspx

Clean Install Windows XP
http://www.elephantboycomputers.com/page2.html#Reinstalling_Windows - What
you will need on-hand
--and--
http://www.michaelstevenstech.com/cleanxpinstall.html
--or-- (even better because its illustrated and more reader friendly)
How Do I Install WindowsXP
http://xphelpandsupport.mvps.org/how_do_i_install_windows_xp.htm

Step-By-Step Windows Vista: Installation
http://www.w-tweaks.com/html/windows_vista_setup__step_by_s.html

It is defenitely advantageous to create an 'image' of the operating system
and create a data/file backup of the affected PC.
The image can then restored to the impacted PC and the user's data/file is
subsequently restored to the operating system.

An experienced and properly prepared user can do that in substantial less
time than scanning with complex and sophisticated AV applications.

Alas, since many users are less prepared and/or lacking the experience;
Scanning with an AV apps. is the only option, unless the user consults a
computer technician.
If you're one of the many less-experienced users, try to go through the
succeeding steps 1-4:

1.Clear the (IE) temporary Internet files and the history cache.
Click 'Start' and then click 'Run'... then type (or copy/paste)
"inetcpl.cpl" (w/out quotation marks) into the box, then click the 'OK'
button.
In Internet Properties panel 'General' tab, under 'Browsing history', click
'Delete...'button, in 'Delete Browsing History' panel, click the 'Delete
all...' button then place a checkmark into the box beside 'Also delete
files and settings stored by add-ons', Click 'Yes' and exit the Internet
Properties panel by clicking the 'OK' button.

2.Clean HDD
Click 'Start' and then click 'Run...' then type (or copy/paste) "cleanmgr"
(w/out quotation marks into the box, then click the 'OK' button. Select
your drive (presumably WinXP (C:) and click OK.
--or--
2a.Delete files using Disk Cleanup (if on Vista)
http://windowshelp.microsoft.com/Windows/en-US/help/1264bc24-72a8-48aa-84e3-a355327139d91033.mspx

3.Download/execute:
Malwarebytes© Corporation - Anti-Malware
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?tag=mncol
--or--
http://majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html
--direct--
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
--and--
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html
--direct--
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE

Both free versions of MBAM and SAS are on-demand scanners and offer no
'real-time' protection. Keep them installed and use them as
'second-opinion' scanner which is purposely (by design) recommended by
their respective authors.

*--And/Optional--*
Kaspersky® Virus Removal Tool
http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/
http://www.kaspersky.com/support/viruses/avptool?level=2

--and/optional--
Dr.Web CureIt!® Utility - FREE
http://www.freedrweb.com/cureit/

--and/optional--
a-squared (a²) Free or a-squared (a²) Command Line Scanner
http://www.emsisoft.com/en/software/download/

--and/optional--
BitDefender10 Free Edition (*NOT FOR VISTA*)
http://www.bitdefender.com/site/Downloads/browseEvaluationVersion/1/42/

--and/optional
Sophos Anti-Virus (SAV32CLI), is a 32 bit free command line scanner used in
an emergency as a disinfection utility for Windows NT, Windows 2000,
Windows XP and Windows 2003.
To use the Sophos command line software follow the steps below:
a) Download SAV32CLI
http://downloads.sophos.com/tools/sav32sfx.exe
--and--
extract the contents by double clicking the file.
b) Add the latest virus identity files (IDE) to the folder; These can be
downloaded here:
http://www.sophos.com/downloads/ide/
c) Read Scanning Options with SAV32CLI.
http://www.sophos.com/support/knowledgebase/article/13252.html
See removing malicious files with SAV32CLI for basic information on virus,
spyware, Trojan and worm removal with SAV32CLI.
http://www.sophos.com/support/knowledgebase/article/13251.html

--and/optional--
David H. Lipman's MULTI_AV.EXE from the URL:
http://www.pctip.ch/ds/28400/28470/Multi_AV.exe
or
http://212.98.39.7/ds/28400/28470/Multi_AV.exe

http://www.pctip.ch/downloads/dl/35905.asp
or
http://212.98.39.7/downloads/dl/35905.asp

http://www.raymond.cc/blog/archives/2008/01/09/scan-your-computer-with-multiple-anti-virus-for-free/

NOTE:
The above mentioned applications are not capable for real-time protection
of your computer; They are on-demand scanners.

Kaspersky® Virus Removal Tool, Dr.Web CureIt!® have no update feature (so
they don't turn into full blown scanners). As soon as your computer is
cleaned you are supposed to remove these tools from your operating system
and revert back to your (updated) resident (real-time) AV application.
Re: Kaspersky® Virus Removal Tool; To uninstall/move this program 'enable
self-defense' must be unchecked!

To scan your computer with the most up-to-date Kaspersky® AVPTool and
Dr.Web CureIT!® virus databases next time you should download new
Kaspersky® AVPTool and Dr.Web CureIt!® packages.

BitDefender10 Free Edition, a-squared Free or a-squared Command Line
Scanner, Sophos Anti-Virus (SAV32CLI) and the free version of Malwarebytes©
and SuperAntispyware have an update feature; You may wish to keep a couple
of them installed in addtion to your resident AV/A-S applications and scan
frequently.

After the software is updated, it is suggested scanning the system in Safe
Mode (this does not apply to MBAM).

"Malwarebytes actually performs better in Normal Mode" says Dustin Cook,
Malwarebytes Researcher of MBAM.

How do you boot to Safe Mode?
By pressing/tabbing F8 (or F5 on some keyboards) continually during
re-boot.

A description of the Safe Mode Boot options in Windows XP
http://support.microsoft.com/default.aspx?scid=315222
Alternatively:
Click Start==>Run... then type (or copy/paste) "msconfig" (without
quotation marks), click OK. Then click onto BOOT.INI tab and 'check'
/SAFEBOOT then OK and click Restart. To go back to Normal Mode, you must
access the System Configuration utility again and click the General tab
then click/check the radio button 'Normal Startup'- load all device drivers
and services'.

Start your computer in safe mode (Vista)
http://windowshelp.microsoft.com/Windows/en-us/help/323ef48f-7b93-4079-a48a-5c58eec904a11033.mspx
http://www.bleepingcomputer.com/tutorials/tutorial61.html

4.Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

Please, do not post HJT logs to this newsgroup.
Fora where you can get expert advice for HiJack This! (HJT) logs.

http://www.thespykiller.co.uk/index.php?board=3.0
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.tomcoyote.org/index.php?showforum=27
http://www.bleepingcomputer.com/forums/forum22.html
http://www.malwarebytes.org/forums/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://www.theeldergeek.com/forum/index.php?s=2e9ea4e19d3289dd877ab75a8220bff6&showforum=29

NOTE:
Registration is required in any of the above mentioned fora before posting
a HJT log and read the 'stickies' (instructions/guidelines) for the
respective HJT forum.

Additional references:
Malicious Software Removal Tool
http://www.microsoft.com/security/malwareremove/default.mspx
(Skip: Run an Online Scan of Your PC for Malicious Software).

How to optimize or reset Internet Explorer
http://support.microsoft.com/kb/936213
Applies to: Windows Internet Explorer in Windows Vista

How to use Reset Internet Explorer Settings (RIES)
http://support.microsoft.com/kb/923737
Read: "What you must know"
Applies to: Windows Internet Explorer for Windows XP and
Windows Internet Explorer 7 in Windows Vista

GMER - is an application that detects and removes rootkits.
http://www.gmer.net/index.php

For additional assistance in relation GMER scan results consult either:
http://www.thespykiller.co.uk/index.php?board=3.0
--or--
http://antirootkit.com/forums/index.php?sid=9e746bb696ac0bb38781ffe4361c3a17

Routinely practice Safe-Hex.
http://www.claymania.com/safe-hex.html

Good luck :)
 
T

THE C. [MS MVP]

Go to download.com to get Spybot Serach & Destroy, MalwareBytes,
SpywareBlaster. If you don't have an anti-virus then AVAST is a great choice.
Also check out O & O defrag to straighten your whole system out. Make it a
great day.
--
Computer/Software Tech.


Charles Richmond
 
P

PSULionRP

Wow! The Microsoft Forums are the BEST! Thanks to all who replied. One can
learn soooooo much from all of you.

Thanks Again!
 
T

Tom [Pepper] Willett

The security.virus newsgroup is quite robust.
: Ok. Now I don't mean to open up a whole can of worms here and please don't
: tell me I'm in the wrong place because I checked the Security section and
it
: wasn't very robust.
:
: Our home PC has been sooooooooooo slow lately. I suspect that there is
some
: sort of Spyware or Malware or other nasty things on this. It is old,
probably
: 5 or 6 years old, so I don't want to invest a lot of money into this
venture.
: Like so many other suckers out there, I did see the commercial for
: finallyfast.com. I ran the diagnostics from it and it said I had 55
Registry
: errors. That might be all good, but I'm sure this doesn't explain all my
: delays. Plus I read that Registry Error fixes were a bit of a scam.
:
: Can anyone suggest some good Spyware and Malware software out there would
: help clean this thing up and hopefully get this PC to be faster and a bit
: more efficient???
:
: Is AVG Anti-Virus Free Edition the answer??? Is this going to take care of
: malware???
:
: I would really appreciate any feedback and Thank You soooooooo much for
your
: feedback.
:
: PSULionRP
 
P

PA Bear [MS MVP]

Is AVG Anti-Virus Free Edition the answer???

No! Do you not have any AV app installed right now?

There is a very good chance are that you are seeing the affects of a
hijackware infection.

1. See if you can download/run the MSRT manually:
http://www.microsoft.com/security/malwareremove/default.mspx

NB: Rename MRT.EXE to, e.g., SCANNER.EXE before running the tool!

2. Run the Windows Live Safety Center's 'Protection' scan (only!) in Safe
Mode with Networking, if need be:
http://onecare.live.com/site/en-us/center/howsafe.htm

3. Run a /thorough/ check for hijackware, including posting the requested
logs in an appropriate forum, not here.

Checking for/Help with Hijackware
http://aumha.net/viewtopic.php?f=30&t=4075
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://www.elephantboycomputers.com/page2.html#Removing_Malware

**Seek expert assistance in
http://spywarehammer.com/simplemachinesforum/index.php?board=10.0,
http://forums.spybot.info/forumdisplay.php?f=22,
http://aumha.net/viewforum.php?f=30, or other appropriate forums.**

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA) computer repair shop.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top