Computer is running slow

Discussion in 'Malware Help (A Specialist Will Reply)' started by msauceda, Mar 14, 2006.

  1. msauceda

    msauceda Private E-2

    My computer is running very slow. CPU usage surges from 4% to 98% and I am unable to work properly. Problem started when I couldn't get my email from Outlook. Email provider advised me to disable Norton Internet Security and that worked to retrieve email, but computer still running slow. Ran everything on READ ME. HiJack This, Active Scan and Bitdefender scan attached.
     

    Attached Files:

  2. msauceda

    msauceda Private E-2

    Email still doesn't work. Message:

    A time-out occurred while communicating with the server. Account: 'pop-server.stx.rr.com', Server: 'pop-server.stx.rr.com', Protocol: POP3, Port: 110, Secure(SSL): No, Error Number: 0x800CCC19
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not post your Bitdefender log as instructed in step 6 of the READ ME. What you posted is a log summary that does not provide useful information about where problems are located. It also does not say whether things were fixed or not. Please attach the correct log by following those steps exactly as written.

    Also go back to step 7 and follow those directions and click the link too. You did not install HijackThis properly. You are running the executable directly from inside the ZIP file which we specifically ask that you not do.

    I doubt your email problems are malware related.
     
  4. msauceda

    msauceda Private E-2

    I hope this works. Thanks for the help.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well you got half of it! :) Bitdefender log is okay. But you have HijackThis installed as below:

    C:\Documents and Settings\Owner\My Documents\HJT\HijackThis.exe

    This is still exactly where we specify not put it. The instructions indicate:
    - not a temp folder
    - not on the Desktop
    - no subfolder of C:\Documents and Settings

    Just install it where recommended and you will be okay. We recommend

    C:\Program Files\HJT\HijackThis.exe

    For you email problems (which as I said are probably not malware forum topics) have you seen:

    http://support.microsoft.com/?kbid=813514

    http://www.xtra.co.nz/help/0,,5721-2394723,00.html
     
  6. msauceda

    msauceda Private E-2

    How about now??
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now you have it!

    Did you put the below items in your Trusted Zone?

    O15 - Trusted Zone: www.bls.gov
    O15 - Trusted Zone: http://forums.caller.com
    O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
    O15 - Trusted Zone: http://www.roadrunner.com
    O15 - Trusted Zone: www.safety-usa.com
    O15 - Trusted Zone: www.symantec.com
    O15 - Trusted Zone: http://*.windowsupdate.com


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
    After clicking Fix, exit HJT.

    We recommend against putting anything in the TZ unless it is absolutely required. In most cases it is not. I have nothing in my TZ and have never required it.


    Now p lease download win32delfkil.exe
    • Save it to the Desktop.
    • Double click on win32delfkil and install it (Installeren button)
    • A new folder is created on the Desktop: win32delfkil
    • Close all windows!
    • Open the win32delfkil folder
    • Double click on the fix MS-DOS Batch File
    • The program runs and the computer reboots automatically.
    • After the reboot, and back in Windows, search for the file: C:\windelf.txt
    • Post the contents of the windelf.txt.
    Boot into safe mode and use Windows Explorer to delete the below:
    C:\world.htm
    C:\TEMP\salmau.dat
    C:\WINDOWS\kwv2.dat
    C:\WINDOWS\ubber60.ini
    C:\WINDOWS\usta33.ini
    C:\Documents and Settings\Owner\Start Menu\Programs\SideStep <--- the whole folder
    C:\Documents and Settings\Owner\Favorites\Going Places <--- the whole folder
    C:\PROGRAM FILES\DelFin <--- the whole folder

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now. But as I already stated, I don't think this will fix your problem with email. Did you look at the links I listed.
     
  8. msauceda

    msauceda Private E-2

    Here are the contents of windelf.txt.

    ************************
    * WIN32DELFKIL LOGFILE *
    ************************
    by Marckie


    BEFORE RUNNING WIN32DELFKIL
    ***************************

    File(s) found in Windows directory
    ----------------------------------
    qvphook.dll

    File(s) found in system32 folder
    --------------------------------

    SharedTaskScheduler key
    -----------------------

    SteelWerX Registry Console Tool 1.0
    Written by Bobbi Flekman © 2005

    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
    {438755C2-A8BA-11D1-B96B-00A0C90312E1} REG_SZ Browseui preloader
    {8C7461EF-2B13-11d2-BE35-3078302C2030} REG_SZ Component Categories cache daemon

    Notify key
    ----------



    AFTER RUNNING WIN32DELFKIL
    **************************

    File(s) found in Windows directory
    ----------------------------------
    qvphook.dll

    File(s) found in system32 folder
    --------------------------------

    SharedTaskScheduler key
    -----------------------

    SteelWerX Registry Console Tool 1.0
    Written by Bobbi Flekman © 2005

    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler
    {438755C2-A8BA-11D1-B96B-00A0C90312E1} REG_SZ Browseui preloader
    {8C7461EF-2B13-11d2-BE35-3078302C2030} REG_SZ Component Categories cache daemon

    Notify key
    ----------
     
  9. msauceda

    msauceda Private E-2

    Here is the HJT log. It seems to be better, but still has surges (the System Idle Process) up to almost 100%, which doesn't allow you to use any other programs properly. The email problem is with Norton. I will deal with them later. I can disable Norton and get my email. Thanks.
     

    Attached Files:

  10. msauceda

    msauceda Private E-2

     
  11. msauceda

    msauceda Private E-2

    Have you seen my updated replies?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HJT logs must not be from safe mode and the below should not be used to control startups while fixing malware issues;
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    You did not answer my question about the O15 lines.

    It is quite possible all of your problems with CPU usage could be Norton too.

    Let's check one more thing. Download Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the log file here.
     
  13. msauceda

    msauceda Private E-2

    I didn't think I ran HJT in safe mode, but if you say so, I believe you. I deleted all the 015 entries. I ran the new program and nothing came up. The report is attached. What should I do about the control startup issue. Thanks very much.
     

    Attached Files:

  14. msauceda

    msauceda Private E-2

    Here is another HJT log.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What Startups do you want to control?

    How are things currently working?
     
  16. msauceda

    msauceda Private E-2

    My last reply re: control startups was referring to your quote above.

    I have disabled Norton for now and things are much better.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I was just pointing out what we indicate in step 7 of the READ ME. You probably had it showing in your log because you booted in safe mode. It was gone from the last log so you don't need to do anything.

    Now do you see why my very first statement was that your problem is not malware?


    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link, which also contains some free antivirus programs you can replace Norton with:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds