hard drive has started running on its own? laptop dead slow

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by buttmunch, Jul 11, 2005.

  1. buttmunch

    buttmunch Private E-2

    ive been getting alot a times just recently ,where my laptop goes deadly slow . its defragged i run noton av on xp service pack 2 ,i use lavasot with vx2 plug , i have spyblaster and spybot s+d all installed and have regscrub.
    i keep it all up to date .
    i cant understand what the hd is actually doing when it runs ?
    im not doing anything , i close everything down and check my processes/applications running and nothing ? my system idle shows 94% but still my hd is working away?
    i have to turn it off to stop it then its fine for x amount of time before it decides its going to do it again?

    ive got a hjt log if you need to see it.

    i also ran scan spyware prog and it found several hi risk things that my other afformentioned spyware progs dont find! why?

    it found in my reg keys

    grokster
    kazaa
    searchsquire

    and in windows

    agobot
    alexa
    vx2

    can someone begin to sort this messs out

    cheers
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have Kazaa and Grokster installed, uninstall them.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. buttmunch

    buttmunch Private E-2

    run all the progs found nothing ,never had kazaa or grokster so cant uninstall.

    please find hjt log and result of scan that i did withscan spyware,please not this is the only prog that finds them , however it does not remove them!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not install HJT as requested. You installed it exactly where requested not to install it.

    C:\Documents and Settings\jacko\Desktop\HijackThis.exe
     
  6. buttmunch

    buttmunch Private E-2

    sorry will do ,my mistake
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download LSP - Fix

    Run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the newdotnet6_38.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move newdotnet6_38.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    Do you know what the below it for?
    O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
     
  8. buttmunch

    buttmunch Private E-2

    sorry for this how do i create that folder ?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To get hijackthis.exe extracted from the ZIP File into the location we requested do the following.
    The below will work for WinXP based system since it can deal with ZIP files.
    You need to create the C:\Program Files\HJT folder. Do the following:
    - Click START and select Explore.
    - Select the drive where Windows is installed (normally C:)
    - Navigate to the C:\Program Files folder and select it.
    - Now click the on the top menu where it says File and then select New.
    - Then select Folder
    - A new folder is created and highlighted.
    - Just type HJT to overwrite the default name (New Folder)

    To extract hijackthis.exe:
    - locate the HijackThis.zip file you downloaded and right click on it
    - Select Extract All and click Next
    - Browse your way to the C:\Program Files\HJT folder created above
    - Select the folder and click Next
     
  10. buttmunch

    buttmunch Private E-2

    done that removed it ,no i dont know what this is for , do you still want me to run a hjt in that folder? i dont know how to create that folder?


    O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
    O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing <--- LSP-fix may have fixed this already


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    c:\program files\newdotnet <--- the whole folder


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. buttmunch

    buttmunch Private E-2

    here it is sorry for delay :)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not indicate how things are working.

    Did you fix those lines with HijackThis and did you reset web settings exactly as requested?

    You must not have C:\Program Files\Internet Explorer\IEXPLORE.EXE running when using HJT !
     
  14. buttmunch

    buttmunch Private E-2

    the folder newdotnet is not there? what next do i continue? sorry im at the newdot net point not done rest yet?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have indicated that when you posted your log. Not a problem! It was probably already gone.

    Answer what I asked in my last message?
     
  16. buttmunch

    buttmunch Private E-2

    i havent got to the point of running a new log that last post log was an old one, im at the point in your instructions thats says next delete newdotnet , but it isnt there to delete ,ive done the hjt deleting as fist asked now waiting to see what you say before moving on to reseting browser
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I already said
    You really should not be online while doing these steps. Unless you are posting from another computer.
     
  18. buttmunch

    buttmunch Private E-2

    2 pc' s :)
     
  19. buttmunch

    buttmunch Private E-2

    done all you said, heres the up to date hjt log
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So are you still having any problems?
     
  21. buttmunch

    buttmunch Private E-2

    it seems to be a lot better now thanks mate
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  23. buttmunch

    buttmunch Private E-2

    chas ive just taken your advice and got mozilla , does this not now make changing the settings in malaware for ie defunkt ?
    are there settings in mozilla that need changing ,my first question has just arisen it asked me to allow majorgeeks as the info i was sending wasnt encrypted ?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    IE is not defunkt. You will still need it to connect to some websites. Especially Microsoft sites. Without it, you cannot do updates. Make sure you fix the settings as directed.

    I would expect that all the default settings in Firefox should work OK.
    When did you get the message about majorgeeks? When you connected to www.majorgeeks.com or when you tried to login to the forums?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds