operating at molasses speed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kruegekm, Jan 3, 2006.

  1. kruegekm

    kruegekm Private E-2

    About two weeks ago, my computer started working SO slow -- I would say at about 5-10% the speed that it normally does. I went through your "Do this before you post" list and did everything, although AdAware SE never finished a scan, because it always froze up in the middle of one. Spy Sweeper found things, and deleted them, but I am still having the same problem.

    I am all out of tricks and am hoping that you can help. I have attached my hijack this log.

    Thank you for your help!
     
  2. kruegekm

    kruegekm Private E-2

    Im not sure that the attachment worked the first time. I am retrying to attach it here. I apologize if this is unnecessary.
     
    Last edited: Jan 4, 2006
  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You have not completed all of the steps! You have a Wareout infection, so it's important you follow ALL steps in the READ ME including the below.

     
  4. kruegekm

    kruegekm Private E-2

    If you only had a quarter for everytime you have to patiently tell someone to go back and read ALL the directions....

    Sorry about that! I ran Bitdefender, Panda ActiveScan and then HijackThis again. I have attached the logs. Everything is moving so slow, Im not sure if the logs actually attached, but if they didn't I will try again.

    Thank you for helping out.
     
  5. kruegekm

    kruegekm Private E-2

    My attachments don't seem to be working. The Manage Attachment Pages says "Upload Errors" and then says the uploads are "in progress." Any suggestions?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still are not attaching anything. Look at the directions in the link for HijackThis given in step # 7 of the READ & RUN ME. It gives a pretty detailed set of steps on how to attach a HJT log. The same can be done for all attachments.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I just saw your last message. Does this happen for all logs or only certain ones?

    How large are each of the files?
     
  8. kruegekm

    kruegekm Private E-2

    It happens for all logs.

    Their sizes are:

    Bitdefender: 17.7KB
    Panda ActiveScan:1.24K
    HJT: 7.16KB
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FIrst try clearing your IE cache and if that does not help post them inline and I will attach them for you.
     
  10. kruegekm

    kruegekm Private E-2

    alright, i think they worked this time.

    fingers crossed
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay a couple of problems. You did not follow the steps for HJT properly.

    Your log is from safe mode and must be from normal boot mode.
    You did not disable msconfig from controling startups. You must select Normal Startup.

    But first I would like one more tool to be run so we can look for more potential hidden problems especially some for WareOut.

    Download WinPFind
    • Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program.
    • Once it is launched, click on the Configure Scan Options button. And to the right side in the white box below the Run Addons checkbox, select the Qoologic.def and WareOut.def check boxes. Then click Apply.
    • Now click Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.
    • When it is done, it will show the results of the scan. Right Click in the window and choose Select All. Then Right Click again and select Copy which will copy to the contents of the log to your clipboard. Then open a notepad window and paste in the log by pressing CTRL-V. Save it to a file and upload the text file here as an attachment.
    Afterwards post a new HJT log after disabling msconfig and from normal boot mode.
     
    Last edited: Jan 4, 2006
  12. kruegekm

    kruegekm Private E-2

    Ok, thanks. Im going to try and go back to normal mode tonight and follow our suggestions, but I may have to call it quits before Im finished. If so, I will try again tomorrow. Again, thank you for your help.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Just sure msconfig is set to Normal Startup and you have rebooted to normal boot mode. Also attach the WinPfind log. Then one of us will be able to get you all fixed up. ;)
     
  14. kruegekm

    kruegekm Private E-2

    Im feeling encouraged.

    I ran WinPFind and attached what I think is the completed log. However, during the scan a pop-up said there was an "Invalid data type for "system" '. Not sure if that is relevant.

    I also reran HJT, hopefully with all the correct settings. I have attached that log too.

    Thanks again!
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it looks like the WinPfind process was aborted due to some kind of error. Not sure if the malware cause it or not.

    Do you use a Palm Piolet? The reason I ask is the below process being loaded:
    O4 - HKLM\..\Run: [P-Install] D:\Install\installerp1.exe e

    What is it for?

    Use Windows Explore to locate and delete this file: C:\WINDOWS\SYSTEM32\SetupCarnival.exe

    Let's fix the WareOut problem.

    Look in Add/Remove programs for UnSpyPC and uninstall if found.

    Please download FixWareout from one of these sites:
    http://downloads.subratam.org/Fixwareout.exe
    http://swandog46.geekstogo.com/Fixwareout.exe
    • Save it to your desktop and then run it by double clicking on it. It creates a folder named c:\fixwareout.
    • Click Next, then Install.
    • Then make sure Run fixit is checked (this runs C:\fixwareout\fixit.bat). And then click Finish.
    • The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so.
    • Your system may take longer than usual to load; this is normal.
    • When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items if they still exist:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DBA509D4-D60B-49D5-9C08-A7A41E9F1214}: NameServer = 85.255.113.124,85.255.112.15
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E3833268-D6FD-44BD-A4AC-6225D4802A55}: NameServer = 85.255.113.124,85.255.112.15


    After clicking Fix Checked, close HijackThis, and click OK to proceed.

    Now reboot into normal mode and please attach the contents of the logfile C:\fixwareout\report.txt

    Also attach a new HijackThis log.
     
  16. kruegekm

    kruegekm Private E-2

    Thanks for your continued help. I followed your suggestions, here is what I did:

    Hmm, I did have a Palm pilot a while back, but do not use it any more and could easily delete this. Do you think I should?

    Found and deleted SetupCarnival.exe!

    Regarding the WareOut problem:

    I ran FixWareout and when it was finished, I deleted the two lines of O17 you listed in HJT.

    I then ran HJT again, and have attached that log with the FixWareout log.

    One thing that may (or may not) be relevant is that during the FixWareOut, I got a pop up with the following:

    Note: ipconfig.exe
    The application failed to initiatlize properly (0xc0000006)​

    I think things are going a bit quicker, but judging by my computer's speed I would say that there are still some bugs in there.
     

    Attached Files:

  17. kruegekm

    kruegekm Private E-2

    sorry to have to do this, but my HJT log would not attach. Not sure why, but i have posted it here, inline.

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: Jan 5, 2006
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably because of this line: C:\WINDOWS\System32\cmd.exe
    Why did you have a command prompt window open? Or was it opened and you did not know it (due to malware)?

    Do you have a paid version of SpySweeeper installed that you keep upto date? If so what version is it? And what is the reference file version?

    If you do buy it and keep it up to date, you should uninstall MS Antispyware. Keeping both running all the time hogs resource and will slow your PC down.
    If you don't but SpySweeper, you should uninstall it and keep MS Antispyware.

    Your log show no malware but you do have a lot of stuff running and should consider not loading some them.

    Yes have HJT fix the below line since you do not use it anymore:
    O4 - HKLM\..\Run: [P-Install] D:\Install\installerp1.exe e
     
    Last edited: Jan 5, 2006
  19. kruegekm

    kruegekm Private E-2

    Thanks again for the help.

    Im not sure why my command prompt was open. I did not open it intentionally, so I suppose it could be malware.

    I uninstalled MS AntiSpyware and just updated my paid SpySweeper. I have:
    Version: 4.5.8
    Definition: 597

    I guess I do have a lot of stuff running. I apologize for my ignorance, but what do you mean by "not loading" them? Do you mean that I should uninstall them, or rather keep them on my computer and not run them? I am unfamiliar with how to decide what does and does not start when I start my computer.

    I have attached the latest HJT log, hoping you can double check it for malware that may have opened my command prompt if that is the case.

    Thanks so much for your help.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. Before worrying about not loading (this means removing them from the list of items that run everytime you startup - it does not mean uninstall), tell me how things are working now.

    You can also just do a search on Google or Excite and just do a little reading.
    Like do a search of one of your processes listed in the O4 lines of the HJT log, like this one:

    hpztsb07.exe

    One of the links is: http://www.liutilities.com/products/wintaskspro/processlibrary/hpztsb07/

    You would read and decide if you need the feature. If not, you can have HJT fix the line or you could use a startup manager program like Startup CPL to control startups.
     
  21. kruegekm

    kruegekm Private E-2

    Things are working good now -- it seems to be back to normal. Starting up is a bit slower, but Im sure that is because I have a few more programs (an antivirus and anti-spyware program).

    I am so grateful for your help, and I can't believe that it is free. Other than sending my friends to your site, is there a way I can support y'all?

    I will continue to read up on the processes that HJT found, and determine whether or not to keep them. Your forums are a great resource too!

    Merci beaucoup!:)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you check out the below info too:

    How to Protect yourself from malware!

    As far as supporting us:
    - send your friends here
    - try to get all your file download from our main page file systems at www. majorgeeks.com
    - you can buy some MG's geek wear. See the link in the right most column on the home page.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds