![]() |
|
|
|||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
My computer was starting to run slower, and I noticed a lot of processes running. Also, with msconfig set to normal startup, there are some extra things starting including two things with nothing but squares as a name (can't read the name, shows squares where characters should be). These display four errors whenever windows is started.
I did all of that was asked in the "READ & RUN ME FIRST". After seeig zlob a couple times, I took a stab and did the "SpywareQuake & SpyFalcon Removal Procedure" but that didn't appear to find anything. I also tried the "About:Blank and HSA Hijacker - Simplified Removal" since I've seen browser windows titled "about:blank" While I'm at it, not malware, but I'm also having problems with windows installer. Ever since I borrowed a printer, and even while I was using the printer, windows installer pops up every time I plug in a device or put in a disc. It says something like please wait while Windows configures to hp psc 1200 series. If somebody can help me stop that too, I'd be thankful. Attached: Couterspy log Bitdefender log Panda ActiveScan log The rest is to come. Thanks for looking! |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Attached:
GetRunKey log ShowNew log smitRem log |
|
#3
|
|||
|
|||
|
Attached:
-The two about:Buster logs. The first one was ran in normal mode, the second in safe mode. -HijackThis log Thanks! |
|
#4
|
||||
|
||||
|
You may have noticed that much of your malware is coming from Messenger Plus, eDonkey, and NewDotNet Browser Plug-in.
Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 F3 - REG:win.ini: load=???? F3 - REG:win.ini: run=???? O4 - HKLM\..\Run: [Pure dead part move] C:\Documents and Settings\All Users\Application Data\Hide Bin Pure Dead\Sign Open.exe O4 - HKLM\..\Run: [Pure dead part move] C:\Documents and Settings\All Users\Application Data\Hide Bin Pure Dead\Sign Open.exe O4 - HKCU\..\Run: [Kou9RRJqW] mmcodak.exe O4 - Startup: Palm Registration.lnk = C:\Program Files\Palm\register.exe O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing) After clicking Fix, exit HJT. Please attach a new: GetRunKeys ShowNew HJT Be sure to tell us how things are running. |
|
#5
|
|||
|
|||
|
Thanks.
That stopped the four errors from popping up when Windows starts, but the computer is still running slow. Also, I noticed that all the same programs loaded on startup, but their icons didn't remain on the taskbar notification area as usual (not sure if that really matters). I attached the new logs Last edited by guyontheleft; 01-24-07 at 00:55.. Reason: files didn't attach |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Run this Disable/Remove Windows Messenger to remove Windows Messenger.
Uninstall the below old versions of software: J2SE Development Kit 5.0 Update 7 J2SE Runtime Environment 5.0 Update 10 J2SE Runtime Environment 5.0 Update 2 J2SE Runtime Environment 5.0 Update 3 J2SE Runtime Environment 5.0 Update 4 J2SE Runtime Environment 5.0 Update 6 J2SE Runtime Environment 5.0 Update 7 J2SE Runtime Environment 5.0 Update 8 J2SE Runtime Environment 5.0 Update 9 Java 1.1: Sample Files Java 2 SDK Standard Edition v1.2.2 Make sure to reboot after uninstall the above. After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment If you need the Sun Java Development kit you can get it here: http://java.sun.com/javase/downloads/index.jsp I see Ewidoe Anti-Malware and Ewido Security Suite installed. Are these paid versions or free trial verions? Okay now uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders left behind by the uninstall: C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software C:\Program Files\Sunbelt Software Did you install Select Cashback? Do you know what the below file is for? Code:
"C:\WINNT\" cadkas~1.exe Mar 9 2006 74752 "cadkasdeinst01e.exe" O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" O4 - HKLM\..\Run: [5F5V35l] mmkntz.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O16 - DPF: {C7932801-AF0C-11D6-8137-0050DA5F0293} - http://www.grokster.com/rdx/RdxIE.cab O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) After clicking Fix, exit HJT. Boot into safe mode and use Windows Explorer to delete: c:\winnt\system32\mmkntz.exe C:\Program Files\Messenger Plus! 2 <--- the whole folder if found C:\Documents and Settings\All Users\Application Data\Hide Bin Pure Dead <--- the whole folder if found Now reboot in normal mode Now run Ccleaner. Now attach the below new logs and tell me how the above steps went.
Things to think about since you are complaing of perfomance!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." |
|
#7
|
||||||||||
|
||||||||||
|
Done, and installed the current Sun Java Runtime Environment
Quote:
Quote:
Quote:
Quote:
Quote:
Quote:
Quote:
Quote:
Quote:
Quote:
Thanks for the help! I have a couple questions for other problems I'm having. What is ccApp? Whenever I shut down windows, a window pops up asking me if I want to wait for it to end or end now. How can I stop this? I also have that problem I mentioned in the first post of the printer trying to be installed every time I load windows and every time I put a disk in or connect a device. I noticed this line O4 - Global Startup: hp psc 1000 series.lnk = ? Would removing this help? Or cause problems? |
|
#8
|
||||
|
||||
|
Quote:
The normal procedure is to uninstall programs first! However these do not seem to be installed so just have HJT fix those DigStream lines. Quote:
Quote:
Windows Installer CleanUp Utility Also download and run this Your Uninstaller! 2006 See if Your Uninstaller can uninstall the below two programs: Select CashBack Window Searching Let mw know what happens! Delete the below file which is of unknow origin: C:\WINNT\cadkasdeinst01e.exe Are you sure you did not install the Picture Taker service? This is from: LANovation's PictureTaker Enterprise Edition 3.1 lets administrators create software update packages and deploy them to network PCs through a third-party network management suite Attach a new log from ShowNew and also run the below procedure and attach the requested log: Getting Uninstall Programs List From The Registry
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Malware | BGEEKINTRAINING | Malware Removal | 1 | 12-22-06 10:11 |
| Help w/malware | je27 | Malware Removal | 10 | 09-18-06 01:21 |
| Is this really malware? | fillip | Malware Removal | 12 | 08-31-06 02:09 |
| Help with Malware | MarieRochelle | Malware Removal | 2 | 08-22-06 14:11 |
| Not sure if there is malware | Hypersonic | Malware Removal | 3 | 05-03-06 19:53 |