Results of Initial Scans - any help appreciated

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cupros, Nov 12, 2006.

  1. cupros

    cupros Private E-2

    I've been through the steps as pointed out in the 'Read and Run This' thread and was wondering if anyone is kind enough to have any advice about where to go from here.

    A quick summary of the problem - my CPU is maxing out at operations and programs are opening slowly, especially Firefox and Media programs (WMP, RealPlayer), but all operations seem 'hungrier' than before and there never seems to be a single culprit. Also my RAM is consistently high and when I free up space and switch off/block applications it runs high again within a short space of time.

    This has occured in the past few weeks when I have joined a local LAN network (I live in Poland), set-up and installed Norton 2007 and started using Azureus for bit-torrents - I'm not sure if this is significant or not but I guess the more information the better?

    So the results:

    0) Nothing found in Add/Remove Programs - although Viewpoint has been removed in previous weeks.
    5) Windows Malicious Software - nothing found
    Spyware Blaster - Microsoft.WindowsSecurityCenter - disabled - I have been using SB before now and have found this problem on a number of occasions, and of course fixed it each time.
    Windows Defender - PowerRegScheduler found and fixed
    6) Bitdefender - log attached
    Panda ActiveScan - had some problems here, but eventually ok - no problems found in search on 'My Computer' or 'Local Disk' but unfortunately I couldn't get a log.

    Getrunkey, shownew and HT logs I will attach to a following post.

    So is there anything apparent from this information that I should do? And anything I shouldn't do while I'm waiting?

    I've interpreted the instructions to toggle system restore 'once you are sure all malware problems have been removed' that I should wait for the all clear, as it were, before proceeding. Or should I do it ASAP?

    Sorry for loading so much information on here - thanks so much for all your help so far - the guide is nice and easy to run-through and gives hope even to non-geeks!

    Thanks again

    Rob
     

    Attached Files:

  2. cupros

    cupros Private E-2

    And the other logs as promised...
     

    Attached Files:

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

    Again, make sure ALL browser windows are closed when you click FIX.

    Next, run CCleaner to clean up cookies and temp files.

    Next Reset Web Settings & Default Security Settings

    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK

    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.

    Note for IE 7 users:
    Select Internet Options, then the Advanced Tab and then the Reset button under Reset Internet Explorer Settings.

    After you complete the above, reboot and let me know how things are running and if any problems remain.
     
  4. cupros

    cupros Private E-2

    Thanks! Everything seems a lot smoother and more reactive now, but time will tell. Start-up was quicker than it has been for some time and having multiple programs on doesn't seem to offend my PC so much...

    Obviously this is an initial judgment based only on a few minutes - can I post again in this thread if problems resurface?

    Two final questions:

    1) Should I do anything to reset Firefox? Or avoid using it? I tried to find an equivalent to resetting but to no avail. Interestingly, or maybe just coincidence, when I tried to access this site earlier through Firefox it couldn't find the page... and I've had all sorts of phantom 'cannot find page' dialogs - should I come back if this continues? Maybe I'm putting two and two together and getting five.

    2) Should I toggle the system restore now, as mentioned in the guide, or wait a while longer?

    And of course if there is anything else I should do just let me know.

    Thanks so much for your help again and working through it all so quickly and simply!

    Rob
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Personally I use IE7 primarily however I do have Firefox installed. I use both, each for different things. They are both good browsers and both do a great job. I use both browsers with default settings and havn't had any problems.

    You can do it now or later whichever you prefer.
     
  6. cupros

    cupros Private E-2

    OK - thanks again
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Not a problem!:)
     
  8. cupros

    cupros Private E-2

    Ha! Maybe spoke too soon - toggled the system restore, rebooted and unchecked the box now I 'seem' to be back where I started, though with one major difference.

    Explorer.exe and Quickset.exe are dancing merrily away managing to use up just about all of the CPU I have - Explorer at between 50 and 65%, Quickset 30-45%. Any more information or logs I should post?

    Sorry to bug you again...
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I don't believe it's malware related unless you have got infected within the past few hours.

    Attach a current HJT log and we can check that for any suspicious processes.
     
  10. cupros

    cupros Private E-2

    OK - here it is. If not malware, then... contact my manufacturer, or some other steps before going that far?
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log looks good, I would reboot a few times and see how things are running. I don't think it's malware, it could be anything causing those processes to do that.

    After rebooting a few times see how it runs and if it is still doing it. You may want to post in the Software Forum, those guy may be able to help you a bit more.
     
  12. cupros

    cupros Private E-2

    OK - thanks again...
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Np! Let me know what you come up with.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds