Spy/adware causing slowdown?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by frustr8td, Sep 19, 2004.

  1. frustr8td

    frustr8td Private E-2

    I am currently using an HP pavilion ze5600 laptop with integrated wireless.
    Every now and then, this machine picks up a nearby wireless signal.

    This computer has been running SLOW ever since we picked up that wireless signal, and the machine is only 5 months old. (P4 2.29Ghz, 192mb memory) This thing runs slower than my 4-yr-old eMachine! It is not a secure connection, so some spy/adware got itself on this machine. I ran the latest adaware and spybot, but my hijackthis is showing a lot of stuff.

    My HijackThis log is below. I know you are good at reading this stuff. Please take a look and tell me what we can do with this thing.

    thanks,
    frustr8td
     
    Last edited by a moderator: Sep 19, 2004
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Everyone needs to start here:

    http://forums.majorgeeks.com/showthread.php?t=35407

    And report back with specific symptoms if they persist so we can help you more.


    Hijack This log has been deleted because it is not useable as is. Your Hijack This is out of date. Your running it from the desktop. You did not close all running programs. All of these cause problems. Inaccurate scans, no backup and we have to read all the processes running because you didnt close everything as clearly explained in the sticky thread at the top of this forum.

    P.S I see WebRebates, make sure you go to add\remove programs and uninstall anything you did not install, ESPECIALLY if it contains words like search, casino or shopping. :)
     
  3. frustr8td

    frustr8td Private E-2

    Thanks for the tips, I will get on it and get back to you. Sorry about that.

    thanks.


     
  4. frustr8td

    frustr8td Private E-2

    Ok guys, I followed all the steps from MA, and this is my new HijackThis log:

    I am having a particular issue with the hpcmpmgr.exe. Everytime I shut down, I get a message saying "hpcmpmgr.exe is trying to close..." and I have to push "end now" to get the machine to continue shutting down.

    Let me know what you think.

    thanks to you all.
     

    Attached Files:

    Last edited by a moderator: Sep 19, 2004
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Sorry for the delay, was playing a game of poker while i did this..

    Remove:

    C:\Program Files\Web_Rebates\WebRebates0.exe
    C:\PROGRA~1\Web Offer\wo.exe
    C:\Program Files\Web_Rebates\WebRebates1.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/googlesidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.begin2search.com/googlesidesearch.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.begin2search.com/googlesidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.begin2search.com/googlesidesearch.html
    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll (file missing)
    O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINDOWS\SYSTEM32\winb2s32.dll
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINDOWS\SYSTEM32\winb2s32.dll
    O4 - HKLM\..\Run: [Mmgsvc] C:\WINDOWS\mmgsvc.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
     
  6. Matacumbie

    Matacumbie Rocky Top

    The hpcmpmgr.exe program is installed on most computers to support HP products, such as the HP Photosmart, Deskjet, and All-in-One printers. I would look for updates and see if any are available, for now I would remove the hpcmpmgr.exe from Startup using the MSConfig utility and see if that stops the error messages.

    1. Click Start and Run.

    2. Type MSCONFIG and press Enter.

    3. Click the Startup tab.

    4. Clear the checkbox related to hpcmpmgr.exe.

    5. Click OK.

    6. Restart the system.

    Steve
     
  7. frustr8td

    frustr8td Private E-2

    Major:

    I removed what you said, this is my latest log:


    What does it look like?

    thanks!
     

    Attached Files:

    Last edited by a moderator: Sep 21, 2004
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Still seeing issues, which is rare at this point, here they are:

    C:\WINDOWS\System32\mqoqdf.exe
    O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:\WINDOWS\localNRD.dll
    O4 - HKLM\..\Run: [pfeurrvkm] C:\WINDOWS\System32\mqoqdf.exe
    O4 - HKCU\..\Run: [Mmgsvc] C:\WINDOWS\mmgsvc.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

    Close your browser, remove those, I suggest virus scanning from safe mode immediately as well.

    From here, let us know of specific symptoms so we can address them directly, hopefully there will not be any. At that point, get your Windows up to date at Windows Update. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds