We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Servicing my laptop - has anyone used the Geek Squad?

12467

Comments

  • TakeThis
    TakeThis Posts: 2,909 Forumite
    closed wrote: »
    mcafee is probably part of the problem, uninstall it, replace with avast free, and switch on windows firewall in control panel

    http://www.filehippo.com/download_avast_antivirus/

    It's highly unlikely that removing temporary files would affect your speed at all.

    There was/is an infection of some kind.
  • cit_k
    cit_k Posts: 24,812 Forumite
    Thanks for info re expanding RAM. Hate to sound like a wimp, but that's probably a job for a professional. Will get it sorted as soon as I can. Ta.


    What model dell is it?
    [greenhighlight]but it matters when the most senior politician in the land is happy to use language and examples that are simply not true.
    [/greenhighlight][redtitle]
    The impact of this is to stigmatise people on benefits,
    and we should be deeply worried about that
    [/redtitle](house of lords debate, talking about Cameron)
  • macman
    macman Posts: 53,129 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Hi TakeThis. I tried to send you a copy of the Malware log and the CClean text, but as a new user I am apparently unable to send replies with links.

    If it's ok with you, I can email you the info but no prob if not.

    Thanks so much for taking the time to help.

    Rgds
    Janice

    Just copy and paste from Notepad into your post.
    No free lunch, and no free laptop ;)
  • VSC
    VSC Posts: 90 Forumite
    When's the last time you defragmented the drive?

    Also uninstall any programs you no longer use.

    Get in the habit of CCleaner once a week. You can also use that to check your Registry and remove any dead entries.
    "Out of excitement comes invention" Charlie Chaplin
  • I did cut and past the Malware log and the CCleaner text but will try again separately. My first Malware scan found and fixed two probs, then I did a full scan and it was fine. Will definitely do a CClean once a week.

    It's a Del Inspiron 9300

    I'm embarrassed to say that I personally have never defragmented the drive, although it was probably done by someone else some years ago.

    Also, can you tell me how to take Messenger off my system. It loads up every time I switch my computer on, but I don't really use it thesedays.

    Things have definitely improved, THANKS............who needs The Geek Squad!
  • CCleaner text:


    Yes HKCU:Run CTFMON.EXE C:\WINDOWS\system32\ctfmon.exe
    Yes HKCU:Run Google Update "C:\Documents and Settings\janice\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    Yes HKCU:Run swg "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    Yes HKCU:Run HW_OPENEYE_OUC_T-Mobile Internet Manager "C:\Program Files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe"
    Yes HKCU:Run msnmsgr "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    No HKCU:Run BTAgile C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe
    No HKCU:Run Google Update "C:\Documents and Settings\janice\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    No HKCU:Run swg "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    Yes HKLM:Run HP Software Update "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    Yes HKLM:Run HP Component Manager "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    Yes HKLM:Run DVDLauncher "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    Yes HKLM:Run Ulead Photo Express Calendar Checker C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
    Yes HKLM:Run Symantec PIF AlertEng "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    Yes HKLM:Run GoToMyPC "C:\Program Files\Citrix\GoToMyPC\g2svc.exe" -logon
    Yes HKLM:Run mcui_exe "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    Yes HKLM:Run BCSSync "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    Yes HKLM:Run Ulead AutoDetector C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
    Yes HKLM:Run AppleSyncNotifier C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    Yes HKLM:Run DataCardMonitor
    Yes HKLM:Run Adobe Reader Speed Launcher "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    Yes HKLM:Run Adobe ARM "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    Yes HKLM:Run SunJavaUpdateSched "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    Yes HKLM:Run QuickTime Task "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    Yes HKLM:Run iTunesHelper "C:\Program Files\iTunes\iTunesHelper.exe"
    Yes HKLM:Run btbb_McciTrayApp "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
    No HKLM:Run BTHelpNotifier C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
    No HKLM:Run ccApp "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    Yes Startup Common HP Digital Imaging Monitor.lnk C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Yes Startup Common HP Image Zone Fast Start.lnk C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    Yes Startup Common Logitech Desktop Messenger.lnk C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    Yes Startup Common McAfee Security Scan Plus.lnk C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
    Yes Startup Common Microsoft Office.lnk C:\Program Files\Microsoft Office\Office\OSA9.EXE
    No Startup Common BT Broadband Desktop Help.lnk C:\PROGRA~1\BTBROA~1\bin\matcli.exe -boot
  • Malware Log:


    Malware Log:

    Malwarebytes' Anti-Malware 1.51.2.1300
    https://www.malwarebytes.org

    Database version: 7938

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    13/10/2011 18:10:21
    mbam-log-2011-10-13 (18-10-20).txt

    Scan type: Quick scan
    Objects scanned: 185902
    Time elapsed: 17 minute(s), 50 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
  • closed
    closed Posts: 10,886 Forumite
    edited 14 October 2011 at 12:33PM
    if you don't want to follow the guide, post a hijackthis log and commit charge instead of defragging - instructions are in the link in post 2, it takes less than a minute. if mse doesn't let you post http's edit them out of the log.

    install avast free, uninstall mcafee,

    start, run, msconfig - startup tab to disable startup items like messenger

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    you only did a quick scan with malwarebytes, it should be a full scan
    !!
    > . !!!! ----> .
  • TakeThis
    TakeThis Posts: 2,909 Forumite
    CCleaner text:


    Yes HKCU:Run CTFMON.EXE C:\WINDOWS\system32\ctfmon.exe
    Yes HKCU:Run Google Update "C:\Documents and Settings\janice\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    Yes HKCU:Run swg "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    Yes HKCU:Run HW_OPENEYE_OUC_T-Mobile Internet Manager "C:\Program Files\T-Mobile\T-Mobile Internet Manager\UpdateDog\ouc.exe"
    Yes HKCU:Run msnmsgr "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    No HKCU:Run BTAgile C:\Program Files\BT Broadband Talk Softphone\BTAgile.exe
    No HKCU:Run Google Update "C:\Documents and Settings\janice\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    No HKCU:Run swg "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    Yes HKLM:Run HP Software Update "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    Yes HKLM:Run HP Component Manager "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    Yes HKLM:Run DVDLauncher "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    Yes HKLM:Run Ulead Photo Express Calendar Checker C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
    Yes HKLM:Run Symantec PIF AlertEng "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    Yes HKLM:Run GoToMyPC "C:\Program Files\Citrix\GoToMyPC\g2svc.exe" -logon
    Yes HKLM:Run mcui_exe "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    Yes HKLM:Run BCSSync "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    Yes HKLM:Run Ulead AutoDetector C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
    Yes HKLM:Run AppleSyncNotifier C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    Yes HKLM:Run DataCardMonitor
    Yes HKLM:Run Adobe Reader Speed Launcher "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    Yes HKLM:Run Adobe ARM "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    Yes HKLM:Run SunJavaUpdateSched "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    Yes HKLM:Run QuickTime Task "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    Yes HKLM:Run iTunesHelper "C:\Program Files\iTunes\iTunesHelper.exe"
    Yes HKLM:Run btbb_McciTrayApp "C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"
    No HKLM:Run BTHelpNotifier C:\Program Files\BT Broadband Desktop Help\bin\BTHelpNotifier.exe
    No HKLM:Run ccApp "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    Yes Startup Common HP Digital Imaging Monitor.lnk C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Yes Startup Common HP Image Zone Fast Start.lnk C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    Yes Startup Common Logitech Desktop Messenger.lnk C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    Yes Startup Common McAfee Security Scan Plus.lnk C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
    Yes Startup Common Microsoft Office.lnk C:\Program Files\Microsoft Office\Office\OSA9.EXE
    No Startup Common BT Broadband Desktop Help.lnk C:\PROGRA~1\BTBROA~1\bin\matcli.exe -boot


    Go back to the CCleaner > Tools > Startup page, click on the first in the list; CTFMON.EXE and then press and hold Ctrl on your keyboard and whilst holding it down, press 'A'.
    All of the options should now be highlighted. Click on the 'Disable' button on the CCleaner interface.

    Once complete, produce a new Startup log and post it here.

    You forgot the Uninstall log. :)
  • TakeThis
    TakeThis Posts: 2,909 Forumite
    closed wrote: »
    post a hijackthis log and commit charge instead of defragging - instructions are in the link in post 2, it takes less than a minute. if mse doesn't let you post http's edit them out of the log.

    install avast free, uninstall mcafee,

    start, run, msconfig - startup tab to disable startup items like messenger

    C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

    you only did a quick scan with malwarebytes, it should be a full scan

    She indicated that she did so in post #36.

    Messenger's startup will be disabled when she completes the CCleaner task(of course you know that, but the post is not for your benefit :) ) .
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.