Cleaned My System, But It's Still Slow

Discussion in 'Malware Help (A Specialist Will Reply)' started by langel, Mar 27, 2008.

  1. langel

    langel Private E-2

    Good Evening and thank you for your time!

    My Windows operating system is XP SP2. AVG detected a few trojan horse downloaders a few days ago that I have since cleaned (I think) from my system. I have run all of the cleaners as instructed, yet my system still is running slow. I was hoping you could take a look at my logs to see if I have missed something.

    Additional background information: I was only running XPs firewall prior to discovering the trojans. I have since installed ZoneAlarm. I have run the SmithFraud fix to remove a Zlob trojan. I have deleted all other downloaders that AVG quarantined.

    The logs are attached as instructed. Thanks in advance for your help.

    Laurie
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good...the only things to fix are:

    (First turn off TeaTimer as it will block the HJT fix)
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    The tell me what this is:
    C:\DISNEY

    Use windows explorer to find and delete:
    C:\Windows\unins000.dat
    C:\Windows\unins000.exe

    Now use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 6"
    Java(TM) SE Runtime Environment 6 Update 1

    Reboot and install:
    Java Runtime 6
     
  3. langel

    langel Private E-2

    Thanks so much, Tim. I found the source of my memory hog (documents waiting to be printing on an old lexmark printer queue). I had tried to delete the printer when I installed my new one, but it wouldn't let me. I disabled it but didn't realize that it was still trying to print!! Thanks to MajorGeeks I found the solution purely by accident in a different thread. I ran the process explorer program and it found the culprit immediately. Regardless, I still want to make sure I have all of the nasties off my system so I appreciate you looking at my logs. I did the following as recommended:

    I deleted the Disney file. My daughter had downloaded a Disney game that she no longer plays.

    I also deleted the files that you recommended and have attached a new HJT log.

    I noticed that I had viewpoint on the HJT log and that I should have removed it in my initial cleaning. Is viewpoint associated with AOL instant messenger? If so, do I need to keep it if my teenagers use instant messenger?

    Also, I searched for information about PrismXL.exe and see that it is possibly associated with Gateway remote access for assistance. I'm guessing I can delete that since I never used this service nor plan to, but would like your opinion.

    One last file that I cannot seem to purge from is LEXBCES.exe. I no longer have the lexmark printer. Will HJT take care of purging this if I run a fix on it?

    Please take your time responding as my system is running much much better.

    Thanks again! You guys are the best.

    Laurie
     
  4. langel

    langel Private E-2

    Re: Cleaned My System, But It's Still Slow( Here's the Log)

    Sorry, I forgot to upload the log.
     

    Attached Files:

  5. langel

    langel Private E-2

    Tim,

    I decided to run another HJT scan this morning and found

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    had returned. As you can see from my previous post I removed it after reading your response. Is there something else that I need to do after I delete it using HJT?

    Thanks again,

    Laurie
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    About blank can be difficult to remove....so please attach a new MGLogs.zip

    Viewpoint is not related to AOL ...it can be removed as it is often bundled with adaware.

    If your printers are un-installed...go to start / printers and faxes and delete (uninstall) all that are no longer being used.
     
  7. langel

    langel Private E-2

    Tim,

    I have attached a new mglog.zip. I have uninstalled and tried to delete the lexbces file multiple times, but cannot get rid of it. I tried through HJT again just now, but no luck.

    The aboutblank shows up every time I reboot. System Restore is off.

    Thanks for looking.

    Laurie
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What do you mean it shows up? Shows up where? It is not in your most recent logs.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
     
  9. langel

    langel Private E-2

    Sorry for the delay in replying!

    I ran the ATF cleaner and have attached a new MGlogs.zip.

    I changed my homepage from about:blank to my schools website so that I could tell if it changed. The R0 line is showing still in the most recent HJT log, as well as the LEXBCES.exe Lexmark file--both after running the ATF cleaner.

    Googling the LEXBCES tells me that it is a real booger to remove. I suppose I can live with it on there if I have to though.

    By the way, should I still have my System Restore turned off?

    Thanks again for your help.

    Laurie
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....but lets try this:

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    If there is a Lexmark folder on your C:\ drive ---> delete it.

    Now see if you can't find and delete:
    C:\WINDOWS\system32\LEXBCES.EXE
     
  11. langel

    langel Private E-2

    WooHoo!!!! It worked like a charm! I rebooted, ran another HJT log and it's gone.

    Thank You!

    Any final instructions?

    Laurie
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome......If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  13. langel

    langel Private E-2

    Tim,

    Apparently when we ran the command prompt to remove the old Lexmark file, it affected my current printer! I just tried to print and got a message that I must first add a printer. I went to the Printer and Faxes section and there is no printer listed at all. I thought I would just go ahead and reinstall the printer, but when I try to Add Printer I get a message that the print spooler is not running and can go no further than that.

    I suspected it had to somehow be related to the LEXBCES file that I removed so I googled it and found that that file makes the print spooler dependent (?) and basically disables any other printer. I'm not sure if this is something you can help me with or if I should post it in a different forum. Please feel free to move it.

    Thanks in advance for your help/guidance!

    Laurie
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to start / run / type "services.msc" without quotes and scroll down to print spooler and see if it is started. If not, right click and set to auto.
     
  15. langel

    langel Private E-2

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yup...that'll work! :) Glad you got it sorted and happy to have helped!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds