Did all the steps for Read & Run and still have issue

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jennrad1, Nov 26, 2008.

  1. jennrad1

    jennrad1 Private E-2

    I was looking at different websites for a myspace code when all of a sudden my computer started acting crazy and so I immediately closed the site. (can't remember the name of the site) and from then on I've been getting pop ups like crazy. Even when I'm not at my computer. I did all the steps you suggested but now my computer is running slow. So I'm just wondering what's wrong with it and if I can fix it?
     

    Attached Files:

  2. jennrad1

    jennrad1 Private E-2

    Here is my other log
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  4. jennrad1

    jennrad1 Private E-2

    Sorry I thought I did that. Here it is. Also my computer is running even slower today and I was wondering if I needed to put my computer back to the way it was before I changed things....like showing hidden files and such. If so how do I do that. I just feel like I'm all exposed now...lol.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems with a slow PC are not due to malware. They are due to what you are running and how little memory you have. You only have:
    Code:
    Total Physical Memory:   512.00 MB 
    Available Physical Memory: 83.64 MB
    You really should double your memory to have at least 1 GB. I will give some steps below to help alleviate the memory use a little but this has nothing to do with malware as your logs are clean after running the READ & RUN ME.

    In addition to so litle memory, McAfee and SpySweeper are the two largest hogs of your resources. Did you purchase SpySweeper or is it just a free trial? If only a trial, uninstall it now.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now. Remember these are not malware! They are just unnecessary and are slowing your PC down.

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
    O18 - Protocol: bw+0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw+0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw-0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw00s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw10s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw20s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw30s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw40s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw50s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw60s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw70s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw80s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bw90s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwa0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwb0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwc0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwd0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwe0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwf0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: bwg0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwg0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwh0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwi0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwj0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwk0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwl0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwm0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwn0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwo0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwp0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwq0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwr0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bws0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwt0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwu0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwv0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bww0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwx0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwy0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: bwz0s - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
    O18 - Protocol: offline-8876480 - {0C45732C-A5C9-46E4-A51D-0CB89AFE48FC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

    Additionally you should research to see if you really require the below which has been known to use large amounts of memory.
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"

    After clicking Fix, exit HJT.

    Now reboot your PC.


    After reboot, delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Jenn.YOUR-55E5F9E3D2\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. jennrad1

    jennrad1 Private E-2

    It is going faster now...thanks. My new question now is do my logs thatI have sent you tell if I have any virusus on my computer? The main reason why I contacted this site was to see if I had a virus or something because I kept getting constant pop ups even when my computer was idle. After running all those scans I am no longer getting those pop ups... so did they take care of it?? I would also like to know if I can now remove all the malware scanners that I've installed to do the steps for Read and Run and put my computer back to the way it was? and is that the last step in the Read & Run? If not can you direct me to where I should go to do this? Please and Thank you...lol.

    Oh and do you reccommend another security for my computer besides McAfee because I'm not sure that I'm completely happy with it?
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    jennrad1

    Yes, you did have malware on your pc, but it's been removed. There's one file I wish to look at - please follow these instructions:
    If everything still looks good after reviewing that file, I'll post the final instructions and other information for you.

    Thanks!
    dr.m
     
  8. jennrad1

    jennrad1 Private E-2

    Here it is.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    * If you intend to change your AV, download the .exe file for your new AV(do not install at this time) before you uninstall McAfee. Also download the McAfee Consumer Product Removal tool. Then make sure you are not connected to the internet. Uninstall McAfee. Run the McAfee removal tool > Reboot > Run it again > Reboot > run CCleaner. Then go ahead and install the new software.

    Safe surfing! [​IMG]
     
  10. jennrad1

    jennrad1 Private E-2

    Thank you guys for your help!
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're Welcome, jennrad1 !

    dr.m
     
    Last edited by a moderator: Dec 5, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds