Computer ticking memory...?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by StealthArcher, Jun 21, 2007.

  1. StealthArcher

    StealthArcher Private E-2

    The computer im using seems to 'tick' almost, every second or so, it will say it is reading the hard drive and the mouse cursor will show "busy" for a split millisecond, not very long, just long enough that it is eating our memory like crazy.(not that this comp actually has that much).

    Anyway, i followed all the instructions in your faq(ive been doing so since 10 last night...)

    Here are the first of the log files.
     

    Attached Files:

  2. StealthArcher

    StealthArcher Private E-2

    The remaining log files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not install the version of Spybot given in the READ ME. You have Spybot - Search & Destroy 1.3 installed which has no been used for about 3 years. Uninstall this, reboot, and then install the proper version per the directions in the READ ME.

    Now let's remove a left over service from an incomplete uninstall of Symantec Antivirus.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SymWMI Service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSymWSC into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Also uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_05
    Mozilla Firefox (2.0)"
    Norton WMI Update
    RelevantKnowledge <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    Empty the below Quarantine folder as requested in the READ ME:
    C:\Program Files\Eset\infected


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.gamehouse.com/games/zuma/popcaploader.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\ss3unstl.exe
    C:\WINDOWS\system32\comet.inf
    C:\Program Files\Norton AntiVirus <--- the whole folder

    Now run Ccleaner

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. StealthArcher

    StealthArcher Private E-2

    Alright, all the crud you told me to get rid of is gone, some of it didnt want to go, but its gone.


    The ticking problem is still present however. And BTW, since aboput 5 months ago, everytime i press ctrl, My Computer pops up. Is there a way to stop this?

    Oh and BTW, Relevant Knowledge is not in the programs to remove readme. Just thought id tell you.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean now!

    Are you referring to an audible tick? If not, exact what do you mean. I doubt whatever you are referring too is malware related.

    Not in this forum. Try the Software Forum. It sounds like you have used some software to remap a keypress to do that. Pressing the Windows+E key combo would normally do this. (The Windows key is the graphical Windows key to the right of the CTRL key).

    Sorry about that and thanks for telling me. It used to be there. Must have been edited out by mistake at some point. It is back in now. Thanks! ;)
     
  6. StealthArcher

    StealthArcher Private E-2

    Think of my mouse as a metronome, on 60 tempo. Except whenever it would normally click, it shows the 'busy' cursor, and the HDD light on my comp flashes, and it(the HD itself) makes a short low noise, like it normally does when reading for long periods. This all happens for maybe a tenth of a second then is normal for another 9/10 of a second then repeats. It has been doing thi on and off for a few months. Is the HD in danger of head crashing? If so ill tell my parents they need to transfer and replace. A 60GB HDD isnt priced too bad nowadays.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it is malware.

    Does it happen in safe boot mode?

    If you try disabling various startups & services using MSconfig, do you find that any of them relate to this.

    The more harddisk activity you have, obviously the more wear and tear.
     
  8. StealthArcher

    StealthArcher Private E-2

    Ok i checked some things out,:

    It does happen in normal boot. It doesnt happen in SM SMWN or Diagnostic startup.

    As well, probably should have mentioned this at first, but Autoplay is constantly popping up, almost everytime i run any program other than IE and Opera.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then look at which items are disable in Diagnostic mode and slowly work on enabling 1 or 2 at a time until you find which one causes the problem.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  11. StealthArcher

    StealthArcher Private E-2

    Thanks chaslang, disabled enough stuff to stop the ticking.

    And it never crashed either ;).
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And what was the cause of the ticking.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. StealthArcher

    StealthArcher Private E-2

    All done, thanks again.

    From what i found, the service causing the ticking was an "ITunesHelper"

    Funny though, when i reenabled all services piece by piece, it never came back, i now have my comp running exactly the same as i did when i started(minus the malware), and nothing is wrong, guess it just needed to refresh some of them...

    Anyway, thanks for the help.

    Hopefully someday i can learn to read those log files myself. ;)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds