Trojan Problems?

Discussion in 'Malware Help (A Specialist Will Reply)' started by dkkdeb, Nov 18, 2007.

  1. dkkdeb

    dkkdeb Private E-2

    I had a problem about a month ago where everything came to almost a complete standstill. The most obvious problem was a message at start-up saying my firewall had been disabled, but Control Panel seemed to have disappeared. I could access it in Safe Mode, but it still wouldn't open Windows Firewall. I went through the Read & Run Me First steps and by the time I finished, the problems seemed to be gone and it was working better and faster than it has in two years! Now, this weekend, things are slowing way down again. I went through the Read & Run Me steps again and both BitDefender and Panda found things that they apparently can't fix.

    Any help with this would be greatly appreciated!

    Debbie
     

    Attached Files:

  2. dkkdeb

    dkkdeb Private E-2

    Here are the rest of my log attachments.....
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are not using the Windows Firewall. You have ZoneAlarm installed. Does you BitDefender software also include a firewall?

    You don't appear to be having malware problems. I will give some non-malware things to do below that may help a little but your performance issues are most likely due to what you are running.

    First uninstall the CounterSpy trial since we are finished with it now?

    Now uninstall the below:
    ewido anti-spyware 4.0 <-- this is no longer supported and was replaced by AVG Antispyware a long time ago.
    iWin Games (remove only)
    Select CashBack

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Discover deskshop Browser Helper Object - {8DB3D69D-DA5E-4165-B781-72A761790672} - C:\WINDOWS\system32\BhoDshop.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - Startup: Reminder-hpc40404.lnk = C:\Program Files\HP PhotoSmart\Photo Finishing Software\OnLineReg\Remind32.exe
    O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
    Last edited: Nov 19, 2007
  4. dkkdeb

    dkkdeb Private E-2

    Thanks for the reply. Between work and holiday traveling, I'm probably not going to be able to work on this until the weekend, but had a couple of quick questions (and answers) before I start on it.

    I put in ZoneAlarm when I couldn't access Windows Firewall and then kept it after reading some of your protection advice; should I keep it? My version of BitDefender doesn't have the firewall included. CounterSpy isn't the trial version (anymore), should I still get rid of it?

    Thanks again for your help!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    No! If you purchased it then keep it as your realtime antispyware protection but note that it can be rather resource intensive on some PCs.
     
  6. dkkdeb

    dkkdeb Private E-2

    I completed the list of steps you suggested and there really isn't any noticeable difference, though it is a relief to know you don't think it's a malware problem. My speed problem isn't severe, just incredibly slow start-up and a little sluggish in opening programs, nothing I can't live with. There was just such an INCREDIBLY dramatic improvement for the first 3 weeks after I went through the Read and Run Me First steps that I just got concerned when it suddenly reverted to it's old evil ways. Oh well, it was nice while it lasted!

    I'm attaching the new logs you asked for, and thanks again for your help and advice. (One more log to follow).

    Debbie
     

    Attached Files:

  7. dkkdeb

    dkkdeb Private E-2

    Here's the HijackThis log.....
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but as I inferred, CounterSpy can slow down some PCs. It will definitely have an effect on startup time and overall performance. And you installed it around Oct 17th? Did your apparent slow down occur after that? You could try uninstalling CounterSpy to see if that has a direct effect on your problems.

    Another thing worth trying is to use Comodo Firewall instead of ZoneAlarm. I know I said to keep ZoneAlarm but since you are complaining of performance issues, it is worth trying since ZoneAlarm can be a little resource hungry for some people.
     
  9. dkkdeb

    dkkdeb Private E-2

    Thanks for taking so much time with me, but ZoneAlarm was added before I found your site during my October malware attack and CounterSpy was added during the Read and Run Me process. As I said, after the Read and Run Me appeared to clean up my problems, everything was running like the machine was brand new! That lasted for about 3 weeks and then slowed down suddenly again for no apparent reason, so I don't think either of those are the problem; though I am going to change to Comodo after reading about it. The sudden slow down made me suspect something from my original October problems had resurfaced, which is what prompted me to post here.

    But since you've reassured me that malware doesn't appear to be my problem, I really don't want to wear out my welcome in this forum! My speed issue is annoying, but no biggie, so if it's not malware, I'm not going to worry about it (or expect you to, either). Thanks so much for taking the time to help me and for all the great advice!

    Debbie
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Sometimes it is still worth taking the course of uninstalling possible suspected software. Software updates can cause changes in the way the software behaves overtime and thus just because it worked okay previously does not mean it still will. You have nothing to lose but the time it takes to try uninstalling and then reinstalling if the uninstall does not help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds