Can you check my hijackthis log?

Discussion in 'Malware Help (A Specialist Will Reply)' started by I Love Grits, Jan 30, 2006.

  1. I Love Grits

    I Love Grits Private E-2

    I followed the directions the Read and Run me directions first located at:

    http://forums.majorgeeks.com/showthread.php?t=35407

    I ran all the reccomended searches and deleted all the items found. Here is my hijackthis. Some background information though: The computer seems to have trouble loading and starting program, mainly lag. For example, i will move the mouse when trying to load a program or a webpage, and it will not move until 5-15 sec or so later (and even then it is very jumpy). i have already run a memory diagnostic for the computer RAM as well as surfacescan, chkdsk and disk degramenter. The problem still seems to exist. I found , using bitdefender, an AIM virus that it could not get rid of completely.

    Thanks in advance for your help,
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete the other required steps of the READ & RUN ME.


    You did not do step 6. There are two required scans to be run and the logs must be attached.

    Also you did not run CounterSpy as requested and attach the log from it.

    EDIT: Okay I now see Counter Spy! Why did you install it like that? That is bad thing to do. Always install software in their recommended default folders.

    This looks like malware trying to pose as CounterSpy:
    C:\DOWNLOADED VIRUS SCANS\SUNSERVER.EXE
    C:\DOWNLOADED VIRUS SCANS\SUNPROTECTIONSERVER.EXE
    C:\DOWNLOADED VIRUS SCANS\SUNTHREATENGINE.EXE
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the BitDefender and Panda logs and then also do the below.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O2 - BHO: AIM Helper - {D70E6A20-7060-4829-B3D7-B6624A1DE7C6} - (no file)
    O4 - HKLM\..\Run: [p76X37h] MSMLPAPI.EXE
    O4 - HKLM\..\Run: [mkezrjkfrtjr] C:\WINDOWS\SYSTEM\cdarmwky.exe
    O4 - HKLM\..\Run: [qxqv] C:\WINDOWS\qxqv.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\MSMLPAPI.EXE or C:\WINDOWS\SYSTEM\MSMLPAPI.EXE
    C:\WINDOWS\SYSTEM\cdarmwky.exe
    C:\WINDOWS\qxqv.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. I Love Grits

    I Love Grits Private E-2

    I re-ran Bitdefender and it did not find any files that were contaminated. I deleted the AIM virus that i was talking about in my first post, and re ran the seach with nothing. I have attached my Panda log, and i will do what you told me to do with hijackthis.

    On a side note, i made that file b/c in the READ and RUN ME FIRST tutorial it states" Download the following tools and save in your favorite download folder or create one, for example C:\Spyware Tools or C:\Downloads" How was i supposed to do it?

    Thanks
     
  5. I Love Grits

    I Love Grits Private E-2

    Sorry, here is my Panda
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We said to download them there! We did not say install them there. Downloading and installing are not the same thing!

    I just noticed you did that for the other tools too. Like Spybot: C:\DOWNLO~1\SPYBOT~1\SDHELPER.DLL

    You should uninstall all tools you installed this way and install them properly.
     
  7. I Love Grits

    I Love Grits Private E-2

    Ok , here is how I sit now. I uninstalled and reinstalled all the spyware programs like you told me to. Here are my findings:

    All in safe mode unless otherwise specified:

    CCleaner- 8 cookies and some temp files
    AdAware- 1 Negligible - a MRU list , 0 Critical
    Spybot S&D- Found Wild Tangent registry value
    Counterspy- 1 Spyware- Wildtangent, 0 memory processes infected, 0 files infected, 4 registry keys infected and deleted

    CWShredder- Coolwebsearch not found
    Kill2ME- No signs but continued and removed Look2Me , jsut in case it existed.

    Bitdefender- no problems found
    Panda Scan- See attached log.

    Hijackthis- see attached log.

    As a side note, when i booted in safe mode, i could not find the files in windows explorer that you listed above. None of them. I did make sure my hidden files can be viewed via the tutorial so....

    My problems still exist- major major lag at start up , and the computer takes around 10 minutes to fully load at start up. Programs take a while to load, and so do some web pages. When trying to load, there is lag (mabye a few seconds). Any ideas??

    Thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt your problems are related to malware. It is potentially just due to the way Win98 works after a while. It does get slow. Even things like delete files from the recycle bin can take minutes. I had a Win98 pc once where I, right click on the Recycle Bin icon and told it to Empty and there was only one file in it. It took almost 3 minutes for it to complete and during that time the PC was basically unusable. There was no malware at play either.

    In your particular case I would ask home much memory your have and what is your CPU speed?

    Is your PC very slow when booting into safe mode?

    What kind of connection to the Internet do you have (dial-up, DSL, cable)?

    If DSL or Cable, have you tried booting without the ethernet cable plugged in? This is the cable from your PC to the DSL or Cable modem (or to a router if you have one).

    You may want to try completely uninstalling McAfee and see if it improves. McAfee and Norton are tremendous resource hogs.

    Also you should try getting rid of unnecessary items you are running at startup and other junk hung on to IE (like toolbars).

    You don't need the below:
    O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE <--- fast find is a massive resource hog
    O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE

    Do you really need the AIM & Google Toolbars?
     
  9. I Love Grits

    I Love Grits Private E-2

    Here is what i guess you are asking for:

    Bios Version- A07
    Processor- Pentium III 500MHz
    Cache Ram- 512 KB
    System Memory- 352 MB

    My PC is very fast at booting into safe mode.

    I have DSL.

    I disabled McAfee from my startup programs list, and now the computer starts up great ! There is also no lag when im trying to load various programs websites etc. I guess it was just that much of a resource hog. I plan to keep in on though so i can periodically run scans , is that agood idea or no?

    I got rid of the find fast and the aim and google toolbars.

    Everything seems to be good again,

    Thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to have an antivirus actively running or you will have problems. If McAfee is causing you that much of a problem, dump it and try the free ones mentioned in the below link (which you should read and do anyway):

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds