Need help HiJack This log file

Discussion in 'Malware Help (A Specialist Will Reply)' started by Newbie1, Sep 26, 2007.

  1. Newbie1

    Newbie1 Private E-2

    My computer seems to be running extremely slow over the past few days. I am using Nod32 on a windows XP machine. I went and downloaded HiJack this but have no idea what the log file means. If some one could please take a look at it and tell me, what I have to do. Thank you for any assistance


    Just trying to learn
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi Newbie1
    Welcome to Major Geeks!
    There are a number of reasons why computers run extremely slowly. Please give me a few more details about when it started and what symptoms you're having. Is it slow at bootup or after you boot up? Is it slow loading webpages, loading programs (like opening up your audio player or word processing). What is slow?
    HijackThis gives us a small amount of information in the bigger picture of what is going on with your computer. For us to help you, we need for you to do as much of the following procedures in the large box and links below as possible so we can look in more detail at your machine. Before you begin with those, I would like for you to fix the following two lines of HijackThis, if you did not put them that way. To do this, please do the following:


    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    After you finish this, please do the instructions below. When you get as far as running HijackThis in the instructions, do not forget to rename hijackthis.exe to analyse.exe. If you have trouble running things because of the length of time it is taking, stop and go on. Some of the scans are lengthy. Counterspy, BitDefender and Panda (just for an estimate - with dial-up can take around 4 hours per scan, with a fast connection about an hour or so each but it depends entirely on how many files you have on your computer). They are useful because they clean up problems which other scans miss. Therefore, try to do them if at all possible. If they get too bogged down, please at least get us the ShowNew, GetRunKeys and HijackThis.

    abri
     
  3. Newbie1

    Newbie1 Private E-2

    Thanks abri for your help,

    I am in the process of trying to run all the scans and create the logs, so I can post them. My pc has become considerably slow when loading up windows,opening up any applications as well as surfing the web. let me know if I can provide any other helpful information while I am waiting to run all these scans.

    Thanks again,

    newbie
     
  4. Newbie1

    Newbie1 Private E-2

    abri,

    Here are the log files that I got. I also wanted to let you know that I had to run the scans in normal operating mode. I could not run them in safe mode. Obviously none of this makes any sense to me so any help would be appreciated.

    Thank you,

    Newbie
     

    Attached Files:

  5. Newbie1

    Newbie1 Private E-2

    And here are the other logs. I also wanted to let you know that I completed all the other steps as far as spybot, defrag, startup programs ect...

    Thank you

    Newbie
     

    Attached Files:

  6. abri

    abri MajorGeek

    Hey Newbie1 :)

    Please go to add/remove programs and unstall:
    After you finish this, please rerun Counterspy and have it fix everything it finds by quarantining what it detects! Then post the new log it creates. If you need the instructions for that, they're under Step 5 of the READ & RUN ME FIRST.

    Thanks!
    abri
     
  7. Newbie1

    Newbie1 Private E-2

    abri,

    Here is the new log for counter spy after I deleted java from ad and remove.

    thanks ;)

    Newbie
     

    Attached Files:

  8. abri

    abri MajorGeek

    Hi Newbie!

    Do you know why these are on your desktop? What is in them?
    I'm not finding much evidence for malware, leaving me to think that the reason for your slow loading times may be elsewhere. We need to finish a few things here and then I'm going to send you to the Software Forum and see if they might guide you in checking your computer with diagnostic tools. You have a lot of items in your startup menu, updating programs and toolbars, things which you don't really need. Some of them can be removed with no problem. The others you should look at and see if you want them or not. I'll list them in the instructions for HijackThis below as fix these and optionally fix these also. Look at the optional ones and see if you necessarily have to have them. They use resources. If any are missing, just skip them and go on.


    1) We're finished with Counterspy now. Please look in Add/Remove Programs and uninstall it. If you get any errors just make a note and proceed.
    Then delete the below folders which may be left behind by the uninstall:

    C:\Documents and Settings\user 1\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software



    2) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger
    3) Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )
    Again, make sure ALL browser windows are closed when you click FIX.


    4) Please post a fresh HijackThis log after you've completed the above.

    Also, after we finish everything here (there are a few more things to finish), I would like to recommend you back up your data. Slowness can be due to simply having too much on the computer, but it can also be an indication there are bad sectors on the hard drive.
    abri
     
    Last edited by a moderator: Sep 28, 2007
  9. abri

    abri MajorGeek

    Hi newbie!
    There's one correction needed in post number 8, in case it hasn't been corrected already. Please remove this entry from the 3rd box:
    04 - Global Startup: OKI LPR Utility.lnk.disabled
    It's right after the first 02 lines.

    Thanks.
    abri
     
    Last edited by a moderator: Sep 28, 2007
  10. Newbie1

    Newbie1 Private E-2

    abri,

    I am in the process of doing the last couple of things you mentioned. But as to your question, I do not know why these 2 things are on my desktop.

    C:\Documents and Settings\user 1\Desktop\%SystemDrive%
    C:\Documents and Settings\user 1\Desktop\%USERPROFILE%"

    They showed up when I set my pc to show hidden files.As far as what is in them

    C:\Documents and Settings\user 1\Desktop\%USERPROFILE%\Local Settings\Application Data\Microsoft\Feeds Cache....... and inside that folder is alot of desktop.ini configuration files

    And this is where the other one goes
    C:\Documents and Settings\user 1\Desktop\%SystemDrive%\Documents and Settings\user 1\Application Data\Microsoft\SystemCertificates\My
    There are 3 folders under \MY but nothing is inside the folders

    Not sure where they came from. I will repost in a little bit after I complet everything.

    Thanks Again

    Newbie
     
  11. Newbie1

    Newbie1 Private E-2

    hey abri,

    Here is the log file for hijack this. just out of curiosity what have you been having me do?:confused

    newbie
     

    Attached Files:

  12. abri

    abri MajorGeek

    I've been having you clean up your computer and in the last post, trying to get rid of stuff that might be slowing it down. There are many reasons for a slow computer, but you have an excessive amount of startup items and toolbars that could be loading your system down. The old versions of Java make you vulnerable to all kinds of things you don't want, so that's why we ask you to uninstall them. The same with Windows Messenger.
    If what we do doesn't help the problem you originally came here with, I would first suggest you go back to a restore point from before you noticed the slowdown. A number of htings can happen to make your computer slow down. You can get something on it like an update that doesn't work for you or a driver that's bad. Having system restore is useful to undo things like that without having to track down what they are. If you end up doing this, you will undo what we've done so far, but the instructions won't change really, and you can go back and fix the things you fixed here afterwards.

    When you notice a difference in the way your computer is acting, it's good to note the date, even the time when you first noticed it, if possible. Keeping a log of what was installed when is a good idea in general, so you can always go back to an earlier restore point.

    The Weather Channel Desktop bothers me. As far as I know, it's a free weather predicting program. It's not listed as a bad program, but I noticed that Counterspy picked up a lot on it and listed it as potentially unwanted, because it puts a lot of stuff onto your computer that isn't needed. Any kinds of free programs like this, or like screen savers, wallpapers, free cards ... they often have a lot of adware associated with them and it's hard to get rid of it afterwards. If "The Weather Channel Desktop" is something you can part with, I would in this case. You can find it under "The ..." in add/remove programs.

    If your computer doesn't improve by what we try, I'll give you some choices about how to proceed and afterwards, if you're still in the same boat, I'll send you to the software and hardware forums to see if you might be having problems with your ram or your settings.

    Before I ask you to do anything further, I want to find out what those two folders are doing on your desktop. I'll get back to you about that.

    abri
     
  13. abri

    abri MajorGeek

    Hi Newbie1!

    Your computer doesn't have any bad infections on it. There was spyware, which was quarantined or removed by Counterspy except for The Weather Channel Desktop. I would recommend uninstalling this and seeing if it makes any difference in how your computer is running. I don't think there is anything else that can be done with regard to malware.

    The two folders on your desktop which are usually hidden are not malware and you should NOT remove them!

    Did you understand what I was talking about in my last post with regard to System Restore or returning to an earlier restore point? Have you ever done this? I would like to ask you about that before going on with the final steps we give you.

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds