comp. bogged down

Discussion in 'Malware Help (A Specialist Will Reply)' started by dell1705user, Mar 26, 2007.

  1. dell1705user

    dell1705user Corporal

    Yet, another computer(desktop) I have that needs some looking at.
     

    Attached Files:

  2. dell1705user

    dell1705user Corporal

    and...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this procedure: WareOut Removal


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>;localhost
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O17 - HKLM\System\CCS\Services\Tcpip\..\{71E14568-8BF3-47AE-87D9-35C7D2145D6B}: NameServer = 85.255.113.126,85.255.112.105

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now locate the below file and delete it if found:
    C:\Documents and Settings\All Users\Favorites\Download Free Spyware Remover.url

    Now please download the current version of ShowNew which was just updated to fix a bug! Use it from now on.

    Now attach the below new logs and tell me how the above steps went.

    1. FixWareOut log
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. dell1705user

    dell1705user Corporal

    I was unable to find O17 - HKLM\System\CCS\Services\Tcpip\..\{71E14568-8BF3-47AE-87D9-35C7D2145D6B}: NameServer = 85.255.113.126,85.255.112.105 in the HJT log, therefore I was unable to fix it.

    I now seem to have an ad that replaces my desktop background while processes load up and then it switches to my normal background once they are done loading.

    Log attached below as requested:
     

    Attached Files:

  5. dell1705user

    dell1705user Corporal

    and new HJT log:
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you mean when your PC first starts up or do you mean anytime you load any process?

    Please check to see if the below file exists. If found, delete it:

    C:\Windows\system32\cstgm.exe


    Did you elect not to fix the below line? Do you need it for something?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;127.0.0.1;<local>;localhost
     
  7. dell1705user

    dell1705user Corporal

    I should've been more descriptive. It's when I first start the PC when everything is initializing/loading up that this banner "ad" is the background for maybe a minute or 2 and then disapperas to reveal the real background.

    I must've accidently overlooked that one HJT line, it was early when I followed your previous insturctions. Not much of a morning person here! zzz

    New HJT log below:
     

    Attached Files:

  8. dell1705user

    dell1705user Corporal

    In addition, I looked at the HJT log just for kicks and I noticed that there are some items (Empire Poker, I-tunes, etc.) that I don't use, nor do I care to have on the computer. How could I go about removing them? I know they say it's not a good idea for those who aren't knowledgable with registry items, such as myself, to mess with the reports that HJT produce...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What does the ad say?

    First make sure they do not appear in Add/Remove programs. If they do then uninstall them. If they don't appear in Add/Remove programs, just have HJT fix the lines.
     
  10. dell1705user

    dell1705user Corporal

    "Get the Full Movie Here" - Big yellow letters with a pink background.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you just have something loading a wallpaper image file before loading you regular background. This may be due to something you downloaded and installed. Have you been downloading using P2P or Torrent programs?

    Try doing the below but I'm not sure this will address this issue.

    • Right click on your Desktop and select Properties.
    • Then click the Desktop tab and then the Customize Desktop button.
    • Now in the next window that comes up click the Web tab.
    • Make sure at the bottom that Lock desktop items is unchecked.
    • Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too.
    • Then click OK. Apply. OK.
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Any change?
     
  12. dell1705user

    dell1705user Corporal

    Will that registry addition prevent any pictures from the internet being used as a desktop background?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The changes we are making are only temporary to see if we can locate what is causing your problem. While somethings that we may have to run may cause your background/wallpaper to disappear, you will be able to set them back to what you want later.
     
  14. dell1705user

    dell1705user Corporal

    Additionally, I have windows 2k on the desktop so there is no desktop tab or customize desktop button.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! I forgot that! Use these steps:
    • Right click on your Desktop and select Properties.
    • Now in the next window that comes up click the Web tab.
    • Make sure Show Web content of my Active Desktop is unchecked
    • Then in the box below delete all items but My Current Home Page and make sure it is unchecked too.
    • Then click OK. Apply. OK.
    Then continue on with the registry patch.
     
  16. dell1705user

    dell1705user Corporal

    Still no dice on either. If it helps, I have this computer set to veify a password to log in. As soon as I type the password and click the OK button, the box containing Microsoft Windows 2000 Pro(with Please Wait... in the title bar) appears and THAT'S exactly when the ad banner image is the desktop, processes initialize and boom! The normal desktop appears.

    And as to your earlier question, I do have a P2P/Torrent program on here.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Registry Search (see the link titled
    RegSearch Download Link )
    • Extract the files from Regsearch.zip into a folder.
    • Doubleclick regsearch.exe to start the program.
    • Enter wallpaper in the top area of the form and then click "Ok".
    • Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well).
    • Attach this file to your next reply.
    • Be patient! It takes a little while for this to run.
     
  18. dell1705user

    dell1705user Corporal

    Registry Search log:
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below!


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Any change?
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I forgot something! If the previous fixME.reg patch does not work. Try the below patch.


    Now Copy the bold text below to notepad. Save it as fixWP.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  21. dell1705user

    dell1705user Corporal

    After running fixWP.reg, I shutdown and restarted, as this is the only time I see it, and it was still there.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you also run the other fixME.reg patch first?
     
  23. dell1705user

    dell1705user Corporal

    Ok, I tried the fixWP.reg, restarted and it had made the banner add the permanent background. Then tried the fixME.reg, restarted and it appears to be gone. I am just staring at a flat black background.

    Sound like it's fixed?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds