Desparate Need for Help!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by MadameButterfly, Nov 18, 2004.

  1. MadameButterfly

    MadameButterfly Private E-2

    My computer is running very sluggishly, and I'm at my wit's end for what to do. I have a Pentium III 825 MHz, 256 Mb Ram, Windows XP.

    My problems started when I was doing my regular Spybot and F-Prot virus scans. When updating F-Prot I had to install a new version (3.16). I uninstalled my current version, and then installed the new one (which means my computer was without protection for about a minute). I ran a virus scan, which I had to abort after about an hour when the computer was hanging (this has never happened before). I ran Spybot, which found some malicious files in the following folders:

    Documents and Settings\Jabba\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

    Documents and Settings\Jabba\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\

    I deleted the files specified, but I had to disable F-Prot Realtime Protector first, since it was going nuts every time I just put my cursor over those files.

    At this point my computer had started to run really slow, and every operation was a chore taking several minutes. When I checked the task manager, 99% of resources was being used by one of the svchost processes. I did some searches on the Internet to find out if anyone else have had the same problem. I came across Majorgeeks, and I read the Basic Spyware, Trojan and Virus Removal thread, and performed all the steps.

    Housecall found some malicious files identified as Java Bytever.A and Java Nocheat.A in the same folders as above. These files were deleted.

    A Symantec security Scan showed my computer as safe, but a virus scan identified a Trojan Horse and Trojan.ByteVerify again inside the same folders as above. I deleted the files.

    McAfee Avert Stinger found nothing.

    I ran CCleaner, and then Ad-Aware, which found 26 entries that were then blocked. Another Spybot scan found no malicious items.

    I also ran RavAntivirus online scan, which found nothing.

    My computer is running slightly better now, but when I navigate any folder on the harddrive it will suddenly hang for about a minute and during that time 99% of resources are used by explorer.exe. Also, when I try to start Opera, the program won't appear for about two minutes, and the task manager shows resources being split approximately 50-50 between opera.exe and one of the svchost processes.

    I'm not sure whether I'm still infected with a virus or anything, or whether something else is going on here. I have considered reformatting and reinstalling Windows, but the problem is that I have numerous files that I need to burn on CD, and I'm afraid that my sluggish computer will sabotage any attempt at burning these files. Any help on this matter would be greatly appreciated!
     
  2. Kodo

    Kodo SNATCHSQUATCH

    have you run the alternate scans listed at the bottom of the READE ME FIRST?
     
  3. MadameButterfly

    MadameButterfly Private E-2

    There were just a couple I didn't run. Bitdefender, RavAntivirus and TrojanScan all found nothing. I just ran a-squared, and it found Trojan.Win32.Editstar, which it then removed. I also just ran avast! which found nothing. I couldn't run ADS Spy because it said it could only be used on NTSF systems.

    My system is still sluggish, so nothing has changed. The computer boots up fine, but when I get to the desktop, ZoneAlarm takes a long time to load. When I check the Task Manager, 99% resources are used by explorer.exe. If I then try to open Opera, the Task Manager first shows a division (about 50-50) of available resources between explorer.exe and opera.exe. After a few seconds, one of the svchost processes also starts to draw resources, and it becomes a three-way split until Opera finally loads after about five minutes. Right now I'm using Internet Explorer (which I hate!) because Opera is just way too slow. As I write I'm watching the Task Manager, and it just now started showing System Idle Process at 99%. Up until now (after Opera was done loading) it had shifted resources between explorer.exe and one of the svchost processes with most resources always with explorer.exe.

    I'm so frustrated about this. I stayed up all of last night running different scans, and nothing has changed. If anyone has any input on this I'll be eternally grateful!
     
  4. fastacker

    fastacker Private E-2

    Have you tried running hijackthis ? You might need to post the log results to let an expert tell you what to delete.
     
  5. MadameButterfly

    MadameButterfly Private E-2

    Yes, I was thinking of that. However, I was reading everywhere that I shouldn't post a hijack logfile until an expert tells me to, so I was just trying to be respectful... Is it OK for me to do that?

    Except for Internet Explorer, my computer is useless right now, and even Explorer is running sluggishly at times. If I try any other program or even just try to navigate the harddrive the response time can be measured in minutes.

    Does anyone have any clue as to what might be wrong? I'm absolutely tearing my hair out over this!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds