BitDefender slow??

Discussion in 'Malware Help (A Specialist Will Reply)' started by tombrown, Nov 16, 2006.

  1. tombrown

    tombrown Private E-2

    I am walking through the read & run me first steps and am up to the Bitdefender scan - but its so slow...

    At the moment the scan is at
    "Files: 3791 of 38266, Scan Time : 00:27:34, Est time left : 04:12:57"

    Is this normal

    I do have an old PC (450MHz PIII) ... but even so :confused:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Yes it is slow but it does a very comprehensive scan and will fix any problems it finds. Yes it will run slower on an older slower PC and it is also affected by:
    • the speed of your internet connection
    • how many files there are on your PC
    • how much and which malware infections you have
    • and what else you are running or you are doing while the scan is running.
     
  3. tombrown

    tombrown Private E-2

    Am I still infected

    I had a problem emerge recently whereby all my search engine results were getting redirected to spurios sites when i followed the link. I ran a AVG scan which I think cured it, but to be sure I then followed your read me process (includign uninstall AVG as I aslo have McAfee).

    I had problems with Bitdefender as it just seemed to grind to a halt after analysing 3000 files, so I aborted (the partial log is here). I can run again, but it would need to be an overnighter and I want to post what I have so far, if it is of use. I am awy for the weekedn so it will be Sunday before I can post the BitDefender log

    Anyways - attached are the logs for
    Activescan
    BitDefender (partial)
    CounterSpy
    HJT
    Newfiles
    Runkeys

    Please let me know if I am clean ? :)
     

    Attached Files:

  4. tombrown

    tombrown Private E-2

    Re: Am I still infected

    and the rest ...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Am I still infected

    Looks like you did not completely follow the directions in step 2 of the READ ME. It looks to me like you did not Uncheck the option to hide extensions for known file types. You must do this or you may not see things you need to see. Go back and make sure you have follow step 2 exactly. Do this before continuing.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\system32\wydaaaaa.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\system32\ipv6mons.dll (file missing)
    O2 - BHO: (no name) - {EE1E31A5-F28E-4F38-837B-9C578A0391B6} - C:\WINDOWS\system32\nltrp.dll
    O4 - HKLM\..\Run: [wydaaaaa] C:\WINDOWS\system32\wydaaaaa.exe
    O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\system32\hbvlwaaa904160.exe
    O4 - HKCU\..\Run: [wydaaaaa] C:\WINDOWS\system32\wydaaaaa.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\SYSTEM32\hbvlwaaa904160.exe
    C:\WINDOWS\SYSTEM32\tvywlpck.exe
    C:\WINDOWS\SYSTEM32\wydaaaaa.exe
    C:\WINDOWS\SYSTEM32\hcmpikyo.dll
    C:\WINDOWS\SYSTEM32\nltrp.dll

    Now run Ccleaner.
    Now reboot in normal mode

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\TomJussie\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. tombrown

    tombrown Private E-2

    Thnaks for the response. It will be Sunday before I get to this, so I will post the information then.

    I left the BitDefender scan running on my PC this morning - if it has completed do you want me to include that log too?

    PS - apologies for starting two threads
     
  7. tombrown

    tombrown Private E-2

    One further question, just to be sure.

    When you ask for a HJT log I assume you want me to run a second HJT scan after I have finished all the steps above - i.e. not the log from the scan where I fix those various lines?

    No I don't really care about the Bitdefender log now, but If it found any of the stuff I asked you to fix then you may not see certain items that are listed in my procedure.
     
    Last edited by a moderator: Nov 17, 2006
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you need to get a NEW HJT log after all steps have been followed. Just fixing things with HJT does not give you a log. You would have to save a log but I don't want one until where it is requested.
     
  9. tombrown

    tombrown Private E-2

    OK - I ran through the steps you asked. I did have the hide extentions option unchecked - but I re-applied it & also applied the settings to all folders.

    All the other steps ran OK - there were only today's files (7) in LocalSettings\Temp

    Attached are the logs

    Seems the search enginer problem has gone, but the PC now seems to be running real slow and the hard disk is constantly thrashing. Soemtimes the CPU is being hogged by one of the followign processes (all legit I am sure), but mostly the CPU is relatively unused and yet the HD is still thrashing like mad.

    CPU Hogs:
    - wuauclt
    - sunThreatEngine
    - svchost
    - McScript_inUse
    - Services
    - mcupdate

    A windows update download was automatically kicked off, and stalled after downloading 8% - I have temporarily disabled automatic updates to stop this getting in the way.

    This browser window just froze on me for a couple of minutes

    So a lot of this may be down to my old PC, or an unreliable internet connection (its wireless & I am constantly onto the provider complaining that it intermittently runs slow)

    Disk still thrashing ...
     

    Attached Files:

  10. tombrown

    tombrown Private E-2

    Immediately after I posted the last reply IE closed down
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This could be due any of the below:
    • your system is getting updates and you may need a bunch
    • McAfee is running a scan or is updating or is just hogging resources
    • the fact that you missed a couple of the malware items I said to fix
    First uninstall Counter Spy so that we are sure it is not getting in the way of the below fixes. (It is only a 15 day trial anyway if you installed the one from the READ & RUN ME).

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\system32\ipv6mons.dll (file missing)
    O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\system32\hbvlwaaa904160.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\hbvlwaaa904160.exe
    C:\WINDOWS\system32\ipv6mons.dll

    Now run Ccleaner.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Also please run this Getting Uninstall Programs List From The Registry and attach the log to a second message.

    Make sure you tell me how things are working now!
     
  12. tombrown

    tombrown Private E-2

    OK - I followed the instructions as follows:

    Uninstalled CounterSpy

    Checked that viewing of hidden files is enabled

    Ran HJT & fixed the lines suggested (but note below item on second HJT scan)

    Booted into safe mode & tried to delete the two files suggested:

    hbvlwaaa904160.exe - not present
    ipv6mons.dll - not present, but ipv6mon.dll was, so I deleted that

    Ran ccleaner (12.1MB removed)

    Booted into normal mode

    ran GetRunKey, ShowNew, HJT & GetUnkeys (logs attached)

    Note that when I ran the HJT scan I noticed that the item
    O4 - HKCU\\..\Run: [WinMedia] c:\WINDOWS\system32\hblvwaaa904160.exe was present again

    PC seems to be running OK now
     

    Attached Files:

  13. tombrown

    tombrown Private E-2

    GetUnKeys log
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Never delete anything we do not ask you to delete. If it is not an exact match you should always ask first. The file you deleted is a valid Windows system file. You may be able to restore it from another copy on your system. You can do a search to locate one. Windows may have eeven automatically restored it. Check to see.

    Try using HJT again to fix it. Does it stay fixed? (Is it still fixed even after a reboot?)
     
  15. tombrown

    tombrown Private E-2

    Couldnt find another copy of ipv6mon.dll - silly me ! Is it critical? Can I copy it from another PC or is it specific to this PC?

    I ran HJT scan and fixed the item. Exited HJT, and then opened it again reran the scan and the item is still fixed.

    Then i rebooted the PC and ran the scan again - seesm the problem remianed fixed this time

    I have attached the latest HJT log. Am I now clean?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you need it and yes you could copy it from another WinXP SP2 pc. Or you could download it from:

    http://www.nodevice.com/dll/I/page18.html


    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  17. tombrown

    tombrown Private E-2

    Thabk you - I really appreciate your help
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds