Another plea for help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by rsusanmiller, Jan 28, 2006.

  1. rsusanmiller

    rsusanmiller Private E-2

    Hi! I've been a lurker on this sight for a while now, and thouroghly enjoying it! Chock full of wisdom, tricks and specials. You guys are the bomb. But alas I fell pray to the slooooooow running puter. My suspicions are malware/spyware. I printed out and followed the first page, download what had to be downloaded, ran the scans and still my puter is behaving slow and strangely! I am but a wee novice in this huge puter land. Be gentile with me. Below is my log!
    Crossing my fingers and my toes that this attaches correctly!
     

    Attached Files:

  2. rsusanmiller

    rsusanmiller Private E-2

    OK, i redid everything and I hope its right this time! blast me if its not! Just kidding!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To help keep you moving along for D3, you still need to follow the directions in the link given in step 7 of the READ & RUN ME. You have HJT running as below:

    C:\Documents and Settings\Owner\Local Settings\Temp\wzef1f\HijackThis.exe

    This is exactly where we specify that it not be installed. Follow the directions to create the proper folder and put the hijackthis.exe in the folder specfied. If you have a problem doing this, you could download the below file and extract the VBS script file from it and run it (you may get a pop message from your antivirus program or from MS Antispyware - you will need to give the script permission to run). This script should create the proper folder and move hijackthis.exe to it.

    http://downloads.subratam.org/Move_hijackthis.zip
     
  4. rsusanmiller

    rsusanmiller Private E-2

    Please smile and say this worked!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! For some reason it did not. You should juist check your log before uploading.
    You are still running HJT from:
    C:\Documents and Settings\Owner\Local Settings\Temp\wz75d1\HijackThis.exe

    Delete the above follow and follow the step by step instructions that are given in:

    Downloading, Installing, and Running HijackThis
     
  6. rsusanmiller

    rsusanmiller Private E-2

    Thank you for your patience!
     
  7. rsusanmiller

    rsusanmiller Private E-2

    One last time before I scream!
     

    Attached Files:

  8. rsusanmiller

    rsusanmiller Private E-2

    Ok, I ran hijackthis again, clicked fix, ran CCCleaner, and deleted everything in C:\Windows\Prefetch. I really appreciate your help and patience. You guys rule! Now, next question. I probably should bump this to Software, but how do I speed things up. My system is really running slow. I have the following
    2.0 GHZ processor AMD
    512 MB Sdram
    160 GB HD
    XP
    I have 95% free space on C and 68% on drive D
    I can't think of anything else to add!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well first I would suggest you fix the below lines using HJT:
    O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Owner\LOCALS~1\Temp\200612816254_mcinfo.exe /insfin

    This seems to be something possibly left over from running McAfee at some point. I'm not exactly sure which application from them adds this. Perhaps it came with their Antispyware component. Do you use the McAfee Antispyware application you have installed and do you like it?

    You should delete the below file too:
    C:\Documents and Settings\Owner\Local Settings\Temp\200612816254_mcinfo.exe
     
  10. rsusanmiller

    rsusanmiller Private E-2

    Hi Chas, I fixed using hijackthis the line O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Owner\LOCALS~1\Temp\200612816254_mcinfo.exe /insfin
    I cannot locate this file to delete it!
    C:\Documents and Settings\Owner\Local Settings\Temp\200612816254_mcinfo.exe

    Honestly, I don't like McAfee and tried to delete and uninstall all of it! It came with this system along with Norton. I see I had some remaining files. I didn't like the antispyware either. I am currently using Zone alarm and Spybot and A-squared!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying there is no uninstall in Add/Remove programs for McAfee's Antispyware?
     
  12. rsusanmiller

    rsusanmiller Private E-2

    Hehehe, Oh no, I am not saying there is no uninstall. I just said that I had thought I had uninstalled all off MacAfees programs! I had assumed that that would remove the antispyware too! I think preferences on these programs are much like the Ford/Chevy contraversies. Trial and error! And my opinion doesn't hold much stock, trust me! hehehe! I value ya'll opinions, but don't have much experience to offer back!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So if you do not like the McAfee Antispyware then uninstall it. You now have MS Antispyware installed and therefor do not need or want McAfee to also be installed. This can cause your PC to slow down.

    I would also suggest having HJT fix the below line:
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
     
  14. rsusanmiller

    rsusanmiller Private E-2

    That file is HJT 'd! Thanks Chas and D3 for all your time!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you get McAfee Antispyware uninstalled?

    Are things working any better?
     
  16. rsusanmiller

    rsusanmiller Private E-2

    Yes Chas, I believe I got all the MacAfee Antispyware removed and my computer is still running sluggish! Got any more suggestions?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the below and attach the Ewido log:

    Running Ewido Security Suite

    Then also attach a new HJT log.
     
  18. rsusanmiller

    rsusanmiller Private E-2

    Hi Chas! I ran the Ewido and the new HJT log. Whew!
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! As D3 said, all Ewido really found was a bunch of cookies! You should uninstall Ewido now to free up system resources.

    Do you have the Windows XP SP2 firewall disabled? If not, you must disable it since you have ZoneAlarm.

    I would also suggest running the below to uninstall Window Messeneger which you do not need or want:
    Disable/Remove Windows Messenger

    Also I suggest having HJT fix the below entry (not malware but not typically very useful and wastes resources):
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ALLTEL~1\SMARTB~1\MotiveSB.exe

    You should consider whether you really need and use all the toolbars you have installed. Uninstall any that you do not use, here are some items I see:
    Yahoo! Toolbar
    Yahoo!\Companion
    eBay Toolbar2
    MSN Toolbar

    It is your decision to decide which you ned and do not need.
     
  20. rsusanmiller

    rsusanmiller Private E-2

    Hi guys! I have windows firewall disabled and uninstalled windows messenger. I ran HJT and fixed that file. I got rid of yahoo toolbar and msn toolbar! I haven't located the yahoo companion, but I'm ready to get rid of the whole yahoo gang. Its appears I am running better and will check on it more in the morning. wheres the kissing emoticon when ya need it huh? Theres light at the end of the tunnel! Thanks guys!
     
  21. rsusanmiller

    rsusanmiller Private E-2

    Morning! I deleted everything I could find Yahoo wise! I have attached a new log for you! My pages are still loading slow!
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Add/Remove programs to uninstall (if found)
    AOL Toolbar

    Since you are removing all the Yahoo stuff, doo you still want yahoo.com to be your start page?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/

    You can have HJT fix the below lines:
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll (file missing)
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll

    Then delete the below folders:
    C:\Program Files\Yahoo!
    C:\Program Files\AOL Toolbar

    Let us know if this helps at all. Other than that you may want to try a different browser like FireFox. You will see it mentioned in the link given below too.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  23. rsusanmiller

    rsusanmiller Private E-2

    Hi Chas, I deleted the yahoo files, but couldn't find any aol files. I ran the HJT and fixed the files per your instructions. I have gone over to the firefox side and still have some questions. Are there any residual IE files that need to be deleted? Also, the programs that were downloaded per instructions from "Read & Run Me First" , should I hang on to them or uninstall them. We are still sluggish though!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you cannot delete IE. It is an integral part of the OS and you will need it on may websites especially Microsoft. Without it, you cannot get updates for your OS.

    No there is nothing from the READ & RUN ME you should uninstall. They are all good to have.

    There is only one more thing to check, and that is for a rootkit. After that, I would say your problems may be due to your connection speed or it is just normal for your PC.

    Download Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of log.

    Attach a new HJT log to so we can verify the other stuff from Yahoo was removed.
     
  25. rsusanmiller

    rsusanmiller Private E-2

    Here's the logs from the blacklight beta scan and the new HJT log!
     

    Attached Files:

  26. rsusanmiller

    rsusanmiller Private E-2

    Hi Guys! Like a pesky lil gnat, I'm back! this morning every time I try to use Firefox I keep getting an error message.
    Problem downloading page Mozilla Firefox
    Server not found
    Firefox can't find the server www.google.com

    Should I start all over again with the REad me first page?
     
  27. rsusanmiller

    rsusanmiller Private E-2

    And I'm running miserably slow toooooooo!
     
  28. rsusanmiller

    rsusanmiller Private E-2

    I am still getting the error on Firefox as per previous reply! I rescanned everything again per Read this , but couldn't run Panda in Safe mode. I have attached new logs! Pretty please, something is rotten in Denmark. My puter has never ever ran this slow and miserable.
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are still clean! Your problems are not due to malware. At least none that are recognized by normal scans.

    When you say your computer is running slow, exactly what do you mean?
    Do you mean surfing the internet? Or do you mean everything you run on it (even non-internet related)?
    Is it slow if you unplug your cable to the internet?
    Do you notice the same slowness in safe mode?

    What do you use the below for:
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
     
  30. rsusanmiller

    rsusanmiller Private E-2

    Yes, it was slow even in the Safe mode. I will unplug my internet connection to see how slow it is on every thing else. On the internet, when I click on or type something in the address bar it will show the address in the bottom and takes a long time to bring it up. I can walk off and get some coffee and it still be loading when I get back. I do not know what that file is. I am still getting that error on Firefox too.
    Problem downloading page Mozilla Firefox
    Server not found
    Firefox can't find the server www.google.com
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still do not think you should be posting in this forum but let's try one more thing:

    Please see the below thread on how to install and run Spy Sweeper. After you run it, attach the log to your next post.
    When is the last time you did a disk defrag and also an Error check on your disk. ( not malware issues either)?

    Please answer questions:
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  33. rsusanmiller

    rsusanmiller Private E-2

    Chas, I ran the spy sweeper and it found nothing. I guess I am convinced its not a malware problem. I have attached the new HJT and the spysweeper logs. I still get the error page when trying to use Firefox to go online. I tried the link you gave me and it brings up a whois page.
    I have no idea what the following file is. I am unable to locate it!
    What do you use the below for:
    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    It takes a while, at least 12 seconds, at the best time to get a page to come up! And those 12 second pages are the fastest. Before I could even refresh at least 5 to 7 seconds, now it just drags. I am stumped. Please point me in a direction I need to go. should I be calling my isp and complaining? This has just came up in the last week. I usually defrag and do a disc cleanup at the very least one time a week as I am on the puter a lot. I know I have taken up a lot of your time, and you'll never know how much I appreciate it! I am perplexed!
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not update Spy Sweeper to the latest definitions before running it. You should do that, but I doubt it is going to find anything causing your problem.

    Sorry about the IP address. I gave you the wrong one, but the fact that it brought up a page means FireFox works. Try this IP addres to get to Google: 64.233.161.104

    PRISMXL.SYS file is showing in your services list. If you are sure you did not install it, first look to see if you can find it in Add/Remove programs. If so, uninstall it. Otherwise we will fix it manually.

    Please don't post any HJT logs unless requested! We are not chaning anything yet that would cause it to be different.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  36. rsusanmiller

    rsusanmiller Private E-2

    That PrismXL is nothing I recognise. It does not show up in my add/remove list. I am assuming it needs to go. I ran spysweeper again, updated it and attached it to this reply. The alltel files are through my ISP which is Alltel. They have a Alltel DSL Checkup link that will test the connectivity and help problem solve. I am assuming this is good. I was not aware that there where files from them that needed to be unzipped though.
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should answer all of the message at once.

    What about:
     
  38. rsusanmiller

    rsusanmiller Private E-2

    Sorry! Yes that ip address works to google. Thank you!
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you may have a problem in your router or with your ISP's DNS server. (Do you have a router).

    Click Start, Run, and enter ipconfig /flushdns and click OK! Now see if you can use www.google.com.


    Let's get rid of PrismXL!
    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to PrismXL ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    PrismXL

    Now exit HJT and reboot when it tells you it needs to.

    After reboot, attach a new HJT log so we can make sure this service is gone.

    Also delete the below folder if found:
    C:\Program Files\Common Files\New Boundary
     
  40. rsusanmiller

    rsusanmiller Private E-2

    I have an external modem provided by my ISP service. I have no other computers at home that are hooked up. I ran the ipconfig/flushdns and I got an error page saying "windows cannot find "ipconfig/flushdns". Make sure you typed the name correctly , and then try again."
    I went in and removed the c:\program Files\common files\new boundary
    and attached is the new HRT
     

    Attached Files:

  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not what I gave you "ipconfig/flushdns" There is a space between ipconfig and /flushdns
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay PrismXL is gone. Is there any change in system performance?
     
  43. rsusanmiller

    rsusanmiller Private E-2

    yes, I can use google now. Sorry about my lack of attention!
     
  44. rsusanmiller

    rsusanmiller Private E-2

    Sorry, its still not up to its normal speed! You guys have the patience of Job long O. I feel I have exhausted you guys and do not want to misuse your valuable time! Should I address this to my isp?
     
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That may be a good idea. But first you could try a few things to see if for some reason they are causing you problems.

    1) uninstall ZoneAlarm - any change
    2) uninstall AVPERSONAL - any change
    3) uninstall Spy Sweeper - any change

    Do not run for too long without an AV or firewall in place! I'm just suggesting the last bit that you can try to see if it is a software issue. If it is not these, then either it is your ISP or some other configuartion/hardware issue on your PC.
     
  46. rsusanmiller

    rsusanmiller Private E-2

    Yes, I deleted all three and it is a marked improvement. Running Just like before! Do you think Windows firewall is better than Zone alarm ? I had used Zone Alarm before with a previous computer and really liked it. I'm getting nervous and feeling nakey with me firewall. hehehe!
     
  47. rsusanmiller

    rsusanmiller Private E-2

    Ok, I installed spygate and am gonna try it for a while. Its seems to not be affecting my speed. you guys rule!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds