Help Soo Slow!!!!!!!!! :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by ktiz, Jan 25, 2006.

  1. ktiz

    ktiz Corporal

    Hi, I was wondering if someone could look at my HJT log. I haven't run the sticky thread due to this computer would take days (literally) to finish that thread. So, I figured that getting ride of most of the spyware and what not through HJT would be the most effecient way to speed things up so I can run the rest of the programs. ( I have run, Adware SE Personal ). Thanks, for the help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not are standard mode of operation. Why is it that you want us to exempt you from the normal procedures? What problems are you having?

    HJT logs are not the cure all the most people believe. In fact the show very little of the possible amount of malware that exists.

    How do you connect to the internet (dial-up, cable, dsl )?
     
    Last edited: Jan 25, 2006
  3. ktiz

    ktiz Corporal


    It's Dial up, I am at my gf's house, but I am gonna send the log to my place and maybe post it there if allowed. otherwise i will try to d/l as many programs as I can and put it on a usb drive and do it at a later date.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So you are saying you are working on your girlfriends PC and she has dial-up?

    Yes download the tools at your house and bring them to her PC and run them. Since you are on dial-up and having slow PC porblems you can skip step 6 of the READ & RUN ME. But please do not skip anything else. Make sure you follow the directions in step 7 and get HJT installed properly. Then attach a log.
     
  5. ktiz

    ktiz Corporal

    that's correct. thanks chas. I'll do that, and get back to ya next week.. :S
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Please stay in this thread when you post with results.
     
  7. ktiz

    ktiz Corporal

    Back again... So I've been working on the comp for about 2 hours now and not much is being accomplished, :(. CCleaner is slowly doing its thing, it has been running for about an hour now, and I am also in the works of getting antispyware going and updating windows cause apparently it's still on SP1. I'll get back to ya if this ever finishes. :S
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should only run ONE tool at a time. You should not be installing anything while scanning. ALSO DO NOT do a Windows update while the PC is infected with malware.
     
  9. ktiz

    ktiz Corporal

    ya, no worries, everything was done, one at a time... well I have ran all that read me first stuff, and the computer is still running slow, I guess I should tell u the specs. It's an amd 2600+, with 512 mb shared ram and running windows xp home.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Completing the READ ME means you need to attach the two logs requested in step 6.

    Also you need to follow step 7 and the link in it exactly and attach a HJT log.

    Without doing this, you have not completed the READ ME and we cannot help you.

    A processor speed would be more helpful. Is that a 1.8 Ghz processor?

    Describe what is slow? Booting, normal offline application running, online (surfing) browsing, downloading????? What is your reference point to when you thought it was fast? Is it also slow in safe mode?
     
  11. ktiz

    ktiz Corporal


    I know, I haven't quite finsihed that as of yet, I'll get to that tomorrow I think, as for slowness, booting is extremely slow and opening any application takes a lot of time to, I can't tell about the internet because it's just dial up and I dunno how fast it should be downloading, seems to limit itself to 5 kb/s, I'm assuming that's probably normal d/l speed. and the processor is 2.2 ghz. Why do i know it's slow... It honestly takes 10 mins to boot up, and 5 mins to open a web browser and 1-5 mins to change web pages. I'll post the rest of the logs tomorrow, thanks! :D
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! After we see all the logs we may have a better idea of what is going on. Just as an additional check (since we are seeing more and more of these) also do the below:

    Please follow the below steps...
    1. Please download and unzip Rootkit Revealer to your desktop.
    2. Please leave the defaults set as they are to:
      • Hide NTFS Metadata Files: this option is on by default
      • Scan Registry: this option is on by default.
    3. Launch rootkit revealer on the system and press the Scan button.
    4. RootkitRevealer scans the system reporting its actions in a status area at the bottom of its window and noting discrepancies in the output list. It may take a long time please disconnect from the internet and leave the PC to be scanned until it is finished.
    5. The log can be very large please edit out the items in the following folders in the log : C:\System Volume Information, if in the log, before attaching it.
    6. Please attach the the log here in this thread to your next post.
     
  13. ktiz

    ktiz Corporal

    Hey

    So here is the HJT logs, as for the other logs, u told me at one point not to worry about them, however if I do NEED to do them i will, it'll just take a very very long time. anyways, here's the HJT log. Thanks :D
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not complete what I requested in message number 12.

    Part of your problems with slow boot up is just all the stuff being used. Like several different instant messenger programs, multiple toolbars, Ares P2P program, also I see Limewire running and many versions of it contain malware too., AOL in general, and the biggest ressource hog may be Symantec AV. However, lets first address known malware problems and see what that does.

    First go to Add/Remove programs and uninstall Ares which is known to bundle with malware. Also let's uninstall Limewire. See both of these listed in the below link:
    http://www.spywareinfo.com/articles/p2p/

    Also uninstall Party Poker if found in Add/Remove programs.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\apsi\wtta.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {8796235C-E7C5-9A6F-BA8E-E39B1BAC6997} - (no file)
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [Patdy] C:\WINDOWS\System32\??rvices.exe
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O4 - HKCU\..\Run: [Notn] C:\Program Files\apsi\wtta.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm39696US
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
    O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/SmileyCentralFWBInitialSetup1.0.0.8-2.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\PartyPoker <--- the whole folder
    C:\Program Files\apsi <--- the whole folder
    C:\WINDOWS\System32\??rvices.exe <--- note that this is NOT services.exe. It looks like it is but it is not. There will be two files showing in your system32 folder that look like services.exe. One will not be in alphabetical order. That is the one you need to delete.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Feb 8, 2006
  15. ktiz

    ktiz Corporal

    ya, sry about step 12, that ran overnight. The HJT stuff, I will do when I have some time and I will give u the msg 12 info. Thanks Chas.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome just attach the logs when finished and let me know how things are working in this account.
     
  17. ktiz

    ktiz Corporal

    Heres the after HJT log.

    There was nothing in the other log from step 12.

    This comp still runs at 100% at all time pretty much. Rundll32.exe takes up most of it at all times. It also loads so many processes at the same time which I think could be slowing things down alot. thanks for ur time
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you look at CPU usage in Task Manager, which process shows as taking up all the CPU time?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! You have some new problems now! Have you installed anything new on here?

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\StubInstaller.exe


    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealOne Player\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O23 - Service: LCMQP - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\LCMQP.exe (file missing)
    O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\WildTangent <--- the whole folder
    C:\Documents and Settings\Owner\Local Settings\Temp\LCMQP.exe
    C:\StubInstaller.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  20. ktiz

    ktiz Corporal

    ya, sorry chas, I dunno if they have d/l more stuff, it's been a long time since I have been able to look at it. Rundll32.exe is taking up 98-99%. I'll do that new HJT stuff and other steps as soon as I can get there again. thanks for the help :D
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! After doing the below and we see the new HJT log, we will see where things stand.

    Is this a laptop PC? Is it a Thinkpad?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also run the below!


    Please download GetRunKey125b.zip to your PC someplace you can locate it. Then extract the files from the ZIP. Locate the getrunkey125b.bat file and double click on it to run it. It will create a file named runkeys.txt in the root of drive C: (C:\runkeys.txt) . This log will also popup in a notepad window which your can just close. Upload the runkeys.txt file here as an attachment.

    This scan will only take a few second to run. It will take longer for you to attach than it does to run.
     
  23. ktiz

    ktiz Corporal

    Back again Chas.
    No, it's not a laptop, it's a Desktop... Compaq :S.
    Here are the to logs...
    As for how things are running... I believe we have made a little progress, however, it still took 3 mins to save the HJT log file, :S lol. Boot time is still slow. In safe mode, booting is fairly fast, in comparison. I am wondering if I should just reformat, or do u think that this will help greatly?
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the limited logs we have seen you have no malware showing.

    If you are still seeing problems with high cpu usage, you may want to discuss these in the Software Forum. Where I would suggest looking first is:
    1) does it happen in safe mode
    2) does it still happen if you uninstall all Norton/Symantec AV stuff
    3) does it happen if MS Antispyware is uninstalled.
    4) also check that Messenger Discovery application to see if it is an issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds