Help me please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by DJ1011, Sep 8, 2007.

  1. DJ1011

    DJ1011 Private E-2

    I am not new to maintenance of a computer, but I just downloaded hijackthis and I am unfamiliar with the program. would someone please view my log and tell me which malware to remove and where to find them manually if at all possible. Thank you very much for your time. This laptop was given to me, and I have tried to clean it up, how have I done so far?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Most people are under the very mistaken misconception that HijackThis is a scanning and detection tool. It is not! HijackThis is simply a tool that is used to identify browser hijackers and in some cases it will show entries for some malware that is for instance running at startup. A HijackThis log shows the following:
    • a running process list with no reference to good or bad
    • it lists the contents of a selected group of registry keys that is an an extremely small subset of the tens of thousands of keys that may exist. Again no reference to good or bad.
    • and some of the above keys that are shown may show some non-Microsoft system services that are running. Again with no reference to good or bad.
    The decision on what is good or bad is left a person with significant Windows and malware cleaning experience.

    HijackThis does not come close to showing all malware that could be hiding on a PC. Anyone who has an infected computer and is relying on HijackThis without the benefit of running other scans such as Spybot, Windows Defender, BitDefender & Panda, CCleaner, etc. are more than likely still infected. In most cases, where there is one virus/trojan there are more.

    The goal of this forum is to remove all malware, and this cannot be done properly by just seeing a HijackThis log.

    If you wish to know whether your PC is free of malware, run the READ & RUN ME FIRST Before Asking for Support sticky thread and also make sure your properly installed and renamed HijackThis.
     
  3. DJ1011

    DJ1011 Private E-2

    Thank you very much for your time and effort. I am currently following the steps in the "READ&RUN ME..." thread. I am downloading Counterspy. My problems began after I began courses at my university.
     
  4. DJ1011

    DJ1011 Private E-2

    I seem to have a problem running BitDefender, but other than that, everything has been good. I manually removed a worm that was deep into my registry last evening, and I have not had a problem since then, however, i'm not sure if I have been completely rid of the problem.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Unless you attach all the logs requested in the READ ME, we cannot tell you anything about your malware status.

    What problems did you have with running BitDefender?
    What browser did you use?
    Does PandaActiveScan run?

    Even without the above two logs from the online scans, there are 4 other requested logs.
     
  6. DJ1011

    DJ1011 Private E-2

    As of right now, BitDefender is running. Pandascan will come next, I have Hijackthis, CCleaner, Counterspy, GetRunKey, and ShowNew. However, due to the slowdown, the BitDefender scan is taking a VERY long time. I hav just uploaded my Hijackthis scan.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HijackThis log is of no use for several reasons:
    • you did not install it in the proper folder as requested
    • you did not rename the executable file as requested
    • it needs to be the last thing run.
    We don't need or want CCleaner logs. They are not useful.

    What slowdown? This is the first time you mentioned it.
     
  8. DJ1011

    DJ1011 Private E-2

    I see, I did not intentially skip that, but I had done so, I have installed and renamed, but I have not yet run the program. I restarted BirDefender because the last time I did not save a log, this will slow me down for a few more hours.

    The slowdown I am speaking of is just my laptop's speed. Everything from the moment i start up is much slower, sounds are distorted and choppy.
     
    Last edited: Sep 9, 2007
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you have to follow the directions in step 7 of the READ ME. It tells you exactly what to do.

    However you never said what malware problems you are having.
     
  10. DJ1011

    DJ1011 Private E-2

    Well, I do not exactly what malware i causing the problem. I have followed the hiackthis thread directly. But I am still ding activescan and BitDefenderso I will wait. I am fairly certain it is a malware issue because I regularly tend to maintenance my computer.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you have not said what the problem is other than " i start up is much slower, sounds are distorted and choppy." which more than likely not malware as stated in the begining of the READ ME. However we will not know for sure until all logs are posted.
     
  12. DJ1011

    DJ1011 Private E-2

    I read the other guide about computer issues and basic maintenance. I did everything in the guide, and I still seem to have the problems. This is the reason for my assumption that the cause of the problem is malware of some sort.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay when you attach the below list of logs requested in the READ ME, we will know if you have malware problems or not:

    • CounterSpy - only for Windows XP, 2K, & NT users
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
    Right now my guess would be that eTrust EZ Armor is slowing you down.
     
  14. DJ1011

    DJ1011 Private E-2


    Do you believe that eTrust EZ Armor is a reliable program? And can I run the Panda Active scan at the same time as my BitDefender scan?
    I still have to run the Panda scan, BitDefender has just finished.
     

    Attached Files:

    Last edited: Sep 9, 2007
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a matter of reliable. It is a matter of how much of your system resources it is using up which will make your system slow. All internet security suites are resource hogs.

    Absolutely not. As stated in the READ ME, Panda is to be run after BitDefender. In addition running them at the same time will cause each to run much much slower and they could interfere with each other.

    Where is your CounterSpy log which should already have been run?
     
  16. DJ1011

    DJ1011 Private E-2


    I have to run Counterspy a second time as I did not save the log during the initial running. I am running Active Scan currently. If I uninstall the security suite, what is a positive recommendation to replace it with?

    I have come across my previous problem of Active Scan freezing, what should I do at this point?
     
    Last edited: Sep 10, 2007
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't bother with rerunning CounterSpy or with Panda. I don't believe you have malware problems. Just attach the GetRunKey and ShowNew logs. Then uninstall CounterSpy immediately.


    You can uninstall your security suite and replace it with some free tools from the below link:

    How to Protect yourself from malware!


    I suggest you try AVG Antivirus, Comodo Personal Firewall, and Comodo BOClean Antimalware.
     
  18. DJ1011

    DJ1011 Private E-2

    Active Scan says I have 3 spyware programs, but I do not know what files they are, attached here will be getrunkey, and shownew. I have already shown you the BitDefender log. The runkeys.txt file is the result of the program just finishing, newfiles.txt is coming. I will attach both.
     

    Attached Files:

  19. DJ1011

    DJ1011 Private E-2

    I seem to have no malware currently due to the help I received from you all, however, Comodo Firewall PRO is using all of my computer's resources, and other programs are suffering as a result. How can I solve this problem while remaining to use the software?
     
  20. DJ1011

    DJ1011 Private E-2

    In bootup and logging onto my user account specifically, the time is substantially higher. And Comodo firewall uses the most system resource, however, the problem persists, when I open any other program besides Mozilla Firefox after closing. the computer slows once more, I will run analyse.exe and post a log of my results.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall A-Squared. Also stop automatically running CCleaner at startup which is adding to your slow startup. Then reboot and tell me if there is any improvement.

    Attach new logs from ShowNew and HJT.


    General comment: All protection software is going to have an impact on system performance. There is no way to avoid this. It is just a matter of how much of an impact the software has. Some are worse than others.


    What are your PC specs?
    • Processor type & speed?
    • how much RAM
     
  22. DJ1011

    DJ1011 Private E-2

    I own the HP DV5020. i've got an 80 GB hard drive, 1 GB of RAM and a 1.8 GHz AMD Turion 64 ML-32 with 512 KB L2 cache processor. Specifically, the bootup process takes more time than it should, and logging on, seem to be when the most resources are being used at the time. The windows start-up theme causes a problem, and I am wondering if there is a way I can turn it off.
     

    Attached Files:

    Last edited: Sep 10, 2007
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not say what the impact or uninstalling A-squared and not running CCleaner at startup had.



    Compared to what? What reference point are you referring to? Are you saying it is slower now then when you had all of those processes and service from eTrust?

    Yes this is always the case for all PCs.

    What do you mean by Windows Startup Theme?

    Do you have a hi-resolution desktop image for wallpaper? Get rid of it and use no wallpaper. Just use a plain desktop with a solid color.

    If you feel that Comodo's Firewall and BOClean are slowing you down too much then uninstall them and use one of the other programs from the how to protect yourself link. However you are going to find that ALL programs like this will have an impact on startup time. It is required for the programs to hook into your system to protect you. Also to provide active protection, they will also have an effect on normal system performance. It is a necessary evil. You can either sacrifice startup time and system performance or you can spend lots of time trying to recover from malware issues and some of them that could occur without proper protectionm, may result in loss of data.

    In reality your PC is a little on the slow side in the current day and age and how demanding various security applications have become.

    You should delete the below folders which are left over from various uninstalls:
    Code:
    C:\Documents and Settings\All Users.WINDOWS\Application Data\
    CA            Jul 12 2007              "CA"
    VIEWPO~1      Jul 13 2007              "Viewpoint"
     
    "C:\Program Files\"
    A-SQUA~1      Sep 10 2007              "a-squared Free"
    CA            Jul 12 2007              "CA"
    Also you should delete the below file wasting over 1.3 Gigabyte of disk space. Do you know what this is from?
    Code:
    "C:\"
    228.tmp       Sep 10 2007  1348685824  "228.tmp"
     
  24. DJ1011

    DJ1011 Private E-2

    The files have been deleted. And the system startup is now faster than before, I realize that my laptop is no longer at the current standard, but it is much higher than my previous computer. Uninstalling A-squared increased speed as well as no longer CCleaner at start. I also switched to a solid color background.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, if you are not having any other malware problems, it is time to do our final steps:
    1. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    2. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    3. After doing the above, you should work thru the below link which you have already started looking at but make sure you work thru all of it:
    .
     
  26. DJ1011

    DJ1011 Private E-2

    I just re-enabled, system restore as the thread said, I believe I am currently free of malware, and I heavily appreciate the help you have given me. I inserted my university's computer center CD-ROM and it has many of the programs you mention on it. once again, I thank you for all of your help. And I hope that in the future I may be able to help those with problems similarly to the way people are helped here. Have a nice evening.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds