Various Items Removed???

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bsqr, Feb 7, 2007.

  1. bsqr

    bsqr Private E-2

    Hello,

    Thanks for reviewing this info. I have followed all the steps in the READ ME FIRST thread. Prior to that I removed various Cool Web Search items, weatherbug items, System Doctor & Personal Antispy. Computer is very slow to boot. Norton Antivirus comes up disabled for first five minutes or so. My Computer comes up with the scanning flashlight for a period, etc. CPU usage doesn't appear to be the problem.

    Attached are the requested logs bdscan.txt, Activescan.txt & runkeys.txt

    I will followup this post with the newfiles.txt and hijackthis.txt logs

    Any help and advice would be greatly appreciated.

    Thank you
     

    Attached Files:

  2. bsqr

    bsqr Private E-2

    Additional Logs

    Following up with Newfiles.txt & hijackthis.txt logs

    Thanks
     

    Attached Files:

  3. bsqr

    bsqr Private E-2

    I forgot to mention that there is no CounterSpy log attached since I had a problem with the files going to Quarantine and they were removed. I can tell you that 34 registery keys with Weatherbug were removed by CounterSpy. There was nothing else detected by CounterSpy.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't really have any major malware problems. We just have some minor cleaning to do. Also you need to get some updates and uninstall a couple programs. But first you need to go back and follow the directions in step 2 of the READ ME. You did not do all of the steps exactly as specified.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    While we are deleting, here are a few other folders to delete:
    C:\Documents and Settings\Lloyd Bergstedt\Application Data\PersonalAntiSpy
    C:\Program Files\Common Files\PersonalAntiSpy
    C:\Program Files\Common Files\SystemDoctor 2006

    Also delete the below file:
    C:\WINDOWS\system32\SystemDoctorSetup.exe


    Uninstall the below old versions of software:
    Java 2 Runtime Environment Standard Edition v1.3.1
    Java 2 Runtime Environment Standard Edition v1.3.1_02
    Viewpoint Media Player (Remove Only) <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Did you set the below search pages to about:blank?
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank


    Now attach a new log from ShowNew

    How are things running now?

    I would also like you to tell me if you know what the below files are for?
    C:\WINDOWS\system32\SBBD.exe
    C:\WINDOWS\system32\SBFC.dat
    C:\WINDOWS\system32\SBRC.dat
    C:\WINDOWS\system32\drivers\sbhr.sys

    If you don't know, please put them into a ZIP file and attach the ZIP file here.
     
  5. bsqr

    bsqr Private E-2

    Thanks for your help. It is much appreciated. This is actually my Dad's computer I'm trying to get cleaned up. Please see responses inserted below


    Thanks again for your help. I will be out of town this weekend so I may be a day or two to resond.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see which is the bigger problem. First uninstall Comodo! And see how things are working. Other free firewalls are listed here: How to Protect yourself from malware! see step 3.

    At first I thought is may be due to READ ME step 2 not being completed but your ShowNew log does not have these files in there anymore. I'm not sure what removed them because I don't think anything we did was related to them. Unless SB in SBBD stands for SunBelt????? But I never noticed that before. I'll have to reasearch this.

    The other two .dat file in the ZIP were truly empty file and did not reveal anything.
     
  7. bsqr

    bsqr Private E-2

    I uninstalled Comodo and there was no difference in the startup. Norton comes up disabled and stays that way for the first five minutes or so and everything runs at about 10% speed for a longer period. Eventually everything comes around and works at a reasonable speed (although probably not 100%).

    I also tried temporarily disabling all the HP related services since I don't have the HP All-In-One connected here. That didn't make any difference either. The machine is setup to connect to Verizon DSL. A bunch of Verizon setup stuff was installed on the machine. I'm currently connecting to cable broadband via router. Is it possible that some of the Verizon setup could be bogging things down since there's no DSL connection??

    I will be out of town this weekend so it may be a few days before I respond.

    Thanks for your help
     
    Last edited by a moderator: Feb 9, 2007
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure about the what is really required for your Verizon connection to work. You would have to check with them what the bare minimum is. Most ISPs are guilty of installing tons of junk you don't need and in most cases do not want since it will affect performance.

    My suggestion is to uninstall ALL of your Norton software then reboot and check your HJT log to make sure everything is really uninstalled. Norton can be as difficult to remove as malware. Then reinstall Comodo and also install the below as a replacement for Norton AV.

    AVG Free Edition


    I also recommend taking either of the below actions (your choice on which one):
    1. Uninstall BigFix is you don't use it. It is a massive resource hog
    2. Or if you want to keep it around, at least have HJT fix the below line to stop BigFix from loading at startup. You can run it when needed which may be never. I uninstall it from all PCs.
      • O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    Then tell me how things are working!
     
  9. bsqr

    bsqr Private E-2

    Please see comments inserted below...

    Performance is far superior, but the startup process still takes longer than it should to stabilize. Once it all stabilizes, the speed the machine runs at is quite manageable.

    Avira anti-virus now comes up first on startup instead of last (as Norton did) and activates before I get the Windows Security warning. Maybe it makes no difference, but that startup sequence makes me feel better.

    Thanks again for all you help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please use another color other than red for normal messages! Red is harder to read and should be for emphasis only. If you put quote boxes on only my parts of messages, it makes things easier. See how I did it in message number 6 for example.


    Let's see what else is loading but I don't believe any issues you are seeing now are due to malware. Please attach the below new logs and tell me how the above steps went.

    1. GetRunKey - please download the new version first.
    2. ShowNew
    3. HJT
     
  11. bsqr

    bsqr Private E-2

    OK (sorry about the red) - New logs are attached as requested

    Thank you
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use Microsoft Money? If not, uninstall it! If you use it, then run it only when needed and not at startup by fixing the associated line in HJT. Reference line:
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"

    Also have HJT fix the below two unnecessary startups:
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    Do you use Microsoft Office and if so, do you need the following feature explained here? http://support.microsoft.com/kb/282599 If not, follow those steps to remove it.

    You have stuff left over from Norton. Do you see Norton WMI Update in Add/Remove programs? If yes, uninstall it. If not, run this Getting Uninstall Programs List From The Registry and attach the log.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Delete the below folder if it exists!
    C:\Program Files\Symantec


    After doing all of the above, how is your startup speed now?
     
  13. bsqr

    bsqr Private E-2

    Well I've done all the tasks listed above
    Removed Money
    HJT fixes
    MS Office used so I elected to leave cftmon in place
    Removed remaining Norton progs via Add/Remove Programs
    Performed Fixme.reg.
    Deleted Symantec Folder

    I messed up and did the Fixme.reg twice as first time I forgot to save the file under the "all files" type. The file name was Fixme.reg without a txt extension though and it seemed to execute as it should. I then created a new file named Fixme.reg that was saved under the "All Files" format as directed and double clicked on it...

    Startup is still a labored process. Antivirus sometimes stays disabled until turned off and on and sometimes "enables" itself without any input. It takes about four minutes to stabilize and work normally. Although the startup takes a bit it is bearable. Perhaps a compromise worth accepting?

    Thanks again for your help. It is much appreciated.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying Antivir is disabled. Try uninstalling it. Reboot (don't skip) and then reinstall. Did that help? What version do you have?

    Attach new logs from ShowNew and HJT!

    Perhaps you have some other things running at startup which may also be doing auto updates or scanning. You should check. However note that for any normal startup with an antivirus, antispyware, and firewall, it does take a while for them to get all hooked in. Time can be dependent upon you PC's speed, how much RAM you have, and how many and what other startups are all loading at the same time. You could try this program StartRight to prioritize what runs at startup and to have them run in a controlled fashion. Read the info on the download page.
     
  15. bsqr

    bsqr Private E-2

    OK - New logs attached

    Antivirus uninstalled / reboot / reinstalled
    (downloaded latest version)

    To clarify antivirus disabled comment - sometimes on start up antivirus disabled icon comes up and stays that way until I right click on the icon and remove the check next to "activate avira antivir guard" (at which time the windows security warning comes up) and then replace the check next to "activate avira antivir guard" which causes the icon to change to enabled and the windows security warning goes away. Most of the time the disabled icon comes up to start with and then after a few minutes it changes to the enabled icon.

    Thanks
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not say whether uninstalling, rebooting, and reinstalling resolved your problem?

    If not, uninstall again, reboot, and delete all folders related to Antivir. Also make sure you delete the below two files if they are still present:
    C:\WINDOWS\system32\drivers\avgntdd.sys
    C:\WINDOWS\system32\drivers\avgntmgr.sys


    Then reininstall Antivir. Does that help! If not, try uninstalling Comodo. Reboot, does AntiVir come up enabled? If so, perhaps you blocked something with Comodo or there is an incompatibility.
     
  17. bsqr

    bsqr Private E-2

    I appreciate all of your help. I believe about 98% of the performance issues at this point relate to the age of the computer. It's really not that bad right now so I think I'll call it good enough. Thanks again - you've been a great help.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds