Hi..Important question before I post prob re: "Read and Run Me First"

Discussion in 'Malware Help (A Specialist Will Reply)' started by bobgure, Apr 20, 2006.

  1. bobgure

    bobgure Private E-2

    Hi,
    Better to be safe than sorry. I followed all the steps required in the "Read and Run Me 1st" thread.

    However...I couldn't use 'Safe Mode with Networking' to connect for BitDefender and PandaScan. I needed to be in normal boot mode.

    When running both the Bitdefender and Panda scans I still had my McCafee
    Antivirus enabled.
    Whilst using Bitdefender (is it usually so slow?) McCafee detected a new virus.
    Question: I'm assuming now, that I need to disable McCafee before and throughout the online scanning. Is this Correct?

    If this is so, i'll start over.
    Thanks!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes online scanning takes a long time. In reality we do not want your antivirus disabled while doing the scans, however with McAfee enabled it will probably slow you down even more since it is probably running a scan on every single file being accessed during the scan. What did McAfee actually say it found and where did it say the file/problem was located?

    Try disabling McAfee while doing the scans.
     
    Last edited: Apr 21, 2006
  3. bobgure

    bobgure Private E-2

    Hi and Thanks for replying!!

    What McAfee found was incidental to my original reason for coming here.
    It was actually adding insult to injury as it popped up during the BitDefender
    scan.

    McAvfee:

    "The file C:\Docs & settings\Robert\Local settings\Temp\ tmp0000
    is infected by the New Poly Win32 virus and cannot be cleaned"
    (or deleted or quarantined).

    My original problem which started only yesterday presented itself as:
    1) things really slowing down and not responding or hesitating or suddenly freezing.
    2) Booting up and loading taking an alarmingly long time
    3) sound files distorting, breaking up and warbling

    My intention was to include my Panda Active Scan report and perhaps a HJT log to be anayzed.

    All other applications required in the "Read me First" came out negative for any malware, including BitDefender.

    Anyway, i'll most likely start over with the protocol, but will leave my Panda report here anyway....what the heck.

    Thanks ---Bob
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot in safe mode and use Windows Explorer to navigate to the below folder and delete all files and subfolders (a couple from the current boot date will not be deleteable):

    C:\Documents and Settings\Robert\Local settings\Temp

    There is nothing in your Panda log except cookies!
     
  5. bobgure

    bobgure Private E-2

    Hi Chas,
    I went through all of the clean up procedure and nothing came up.

    My computer is still booting up at an alarmingly slow speed and I'm quite worried about this new problem with the sound (breaking up, distorted)
    as well as everything slowing down....something's interfering.


    Could I post a HJT log ? Maybe there's something in there.

    Thanks,
    Bob
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes go ahead and attach your HJT log. It could be just what you are running.

    Have you done a disk defrag recently? If not, you may want to do one.
     
  7. bobgure

    bobgure Private E-2

    Hi Chas,
    Yes, I defragged yesterday, as well as going through the cleaning protocol, disabling system restore and rebooting afterward.
    I'm enclosing my HJT log.

    More info:
    Dell Dimension 3000
    WinXP Home sp2
    512 , 80 GB
    IE Explorer 46.0.2900
    Dsl connection 768 kbps
    Two users on computer, myself as administrator and another with limited use.
    I do not have a OS start disc or recovery disc.

    Symptoms of problem:
    1.Very slow start up (the XP loading page stays on for what seems like minutes instead of the expected 10 secs or so)
    2. Slowing down functioning of computer...clicking and opening of files, hesitation of program activating, sluggish. I'll click on icon, often over and over and then wait... until it activates. Slow page loading, sometimes freezing or 'trailing' when scrolled...Icons (like in control panel) 'filling up' slowly.
    3. Media/music files - wobbly and distorted, sound breaking up.

    Thanks for your time and attention. I don't know how to approach this.
    Anyway here's the HJT. I guess we'll look to 'plan B' when the time comes.

    --Bob
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this a 2.4 Ghz Celeron?

    Still may not be malware! I'll give you some things to do below to see how much it helps.

    Do you really to to load all that stuff from NetZero? Is it all realy needed to get an internet connection?

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
    O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Program Files\Nitro\components\NOWImaging.dll (file missing)
    O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll (file missing)
    None of the below are malware but they are unnecessary, waste resource, and slow down boot up. Fix them too!
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. bobgure

    bobgure Private E-2

    Hi Chas,
    Thanks for your continued help - I really appreciate it!

    A few clarifying questions before I run the HJT, to be on the safe side:
    (BTW , I'm using a Pentium 4 processor.)

    Gosh, I didn't know I had any Netzero files left! I uninstalled it a while back and thought I had deleted all files and folders. All I can find here is something called NZSearch. How do I get rid of all things Netzero?

    2. Do I run HJT in safe mode with networking or doesn't it matter?

    3.
    I'm sort of left hanging there.

    My comp's not the only thing running slowly today (lol) so forgive possible dumb question - Since I 'm presently not running HJT, I'm not sure of the above.
    "and use Windows Explorer to delete" what exactly? Is "delete: " referring to the Prefetch files you mention a paragraph later? Or HJT reg files that i've already supposedly exited?

    Thanks for your infinite patience:eek:
    -Bob
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What speed?

    If you don't need it, look for it in Add/Remove programs and uninstall it. If you do not use NetZero, we should probably fix all that stuff showing in your HJ log.

    Just follow the directions and if it does not say safe mode, then assume normal mode. When we want you to boot in safe mode, we always tell you. Like where I said to delete the files. However (and this answers your other question) you had nothing to delete and I just forgot to edit the boilerplate message to remove those lines for your case. Ignore the boot into safe mode, emptying of prefetch and running Ccleaner steps. Just Reset Web Settings (you can do that in normal boot mode) and then reboot and attach the new log.
     
  11. bobgure

    bobgure Private E-2

    Hi Chas,
    Enclosed is new HJT log after following suggested steps.
    System problems still remain.
    Shall I do another HJT, this time removing all Netzero entries?

    thanks again!
    Bob
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I repeat my question, what is your processor speed!

    Also is Ewido the free trial version or the paid version?

    Did you look in Add/Remove programs for anything from NetZero? Uninstalling is the first approach that should be used before I give manual cleaing steps.

    In fact, let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  13. bobgure

    bobgure Private E-2

    Hi,
    Processor P4, 3GHZ
    Edwido is the free trial version.
    There is nothing in Add/Remove programs for Netzero.
    Enclosed is the ininstall list txt you requested.

    Thanks again,
    Bob
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove programs and uninstall Viewpoint Media Player


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=s...H3&N=PL&O=A&UT=
    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
    O8 - Extra context menu item: Display All Images with Full Quality - "res://C:\Program Files\NetZero\qsacc\appres.dll/228"
    O8 - Extra context menu item: Display Image with Full Quality - "res://C:\Program Files\NetZero\qsacc\appres.dll/227"


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\NZSearch <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  15. bobgure

    bobgure Private E-2

    Hi Chas,
    A quick double check before proceeding with instructions.

    In message #10 I was told to ignore the boot into Safe mode, emptying of prefetch and running Ccleaner.

    Am I to ignore that again?

    Thanks!:)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! This time I did give you something to delete whereas in message # 10 (which was referring to the message # 8 procedure), there was nothing to delete.
     
  17. bobgure

    bobgure Private E-2

    Hi Chas,
    I completed instructions and i'm posting newest HJT log.

    Things are running as before. Even had a freeze in safe mode and had to reboot.

    Thanks once more,
    Bob
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please explain what you mean! Is this good or bad?

    This I know I can interpret as bad but I don't know exactly what you mean or when it occurred.


    Is Ewido a free trial or a paid version? If free, uninstall it since you have MS Antispyware installed. If it Ewido is a paid version then uninstall MS Antispyware.

    You need to goto http://java.com/en/ and download and install the current version (5.0 update 6) of Sun Java and then uninstall all old versions like .4.2 update 3.
     
  19. bobgure

    bobgure Private E-2

    Hi Chas,

    The original problem still remains...slow performance, occational freezing, sound breaking up with distortion and 'wowing'.

    Free Version of Edwido has been uninstalled.
    Current version of Java 5.0 installed.
    Old version in add/delete programs was Java 2 runtime env. SE v1.4.2_03
    and was uninstalled.

    The freeze I mentioned in the previous post was just a reaction, because it had never happened to me in safe mode before. No other significance.

    thanks,
    -Bob
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm starting to think your problems are not malware related. Let's try digging a little deeper.

    Download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the Blacklight log file here.

    If BlackLight shows nothing, you may want to try the below:

    1. first just try uninstalling Ewido. If there is no change, go to step
    2. uninstall your McAfee software and rebooting. Then tell me how things are working. If this clears up the problems, goto the below link and install one of the free antivirus applications and free firewall ASAP.
      • How to Protect yourself from malware!
     
  21. bobgure

    bobgure Private E-2

    Hi Chas,
    Blacklight showed nothing.
    I've enclosed the log anyway.
    I'm hesitant to uninstall McAfee because I don't know how to re-install it if necessary.:confused: I initially installed it online so I don't have the software (disc).

    Somehow I suspect that my probs might have something to do with the recent adding of a second user acct. to my computer (as Admin - two admins on same computer)....then changing that 2nd acct. to the type that has limited access. Hmm. Maybe something 'happened' during that process.

    Yours,
    Bob
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well the free stuff works well and is not so resource hungry but the decision is yours in the end. All I can say is it is not a malware problem.

    I doubt it has anything to do with it.
    Login to the other accounts on the PC. Do things seem slow there too?
     
  23. bobgure

    bobgure Private E-2

    Hey,
    Things are just as bad on the other acc't as well.
    Can there be malware on one acc't and not on both or does it not work that way with the hard drive?

    Bob
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Malware can be on one account and not on others!
    Or it can be on all accounts.

    However your PC has shown no signs of any malware. You problems could be either some other component of software or could be hardware related.

    Does it also behave this way in safe mode?
     
  25. bobgure

    bobgure Private E-2

    Hi,
    In safe mode sound drivers appear to become disabled which I assume happens in safe mode, so I can't tell about the audio problems.

    Otherwise, general performance seems quicker in Safe.
    Fan is running very loud.
    Would it be worth my while to to a system restore back to a point before these problems started or would that possibly be harmful?

    Thanks again for your attention,
    Bob
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal on most systems!

    Probably because a few other processes are not running (like AV, AS, and firewall ) You could just try using MSconfig to disable all the McAfee startups and also the services related to McAfee and then reboot your PC. See if this improves things. At least this way McAfee has not been uninstalled and you can just re-enable it.

    Defective fans or PCs running too hot are a topic for the Hardware Forum. If you PC is having temperature issues, that could be causing you a variety or possible problems.

    We did not remove any malware! All we did is remove a bunch of unnecessary and unused applications. Doing a restore would possible bring all of that back. It's up to you if you really think malware is the problem. I have not seen any evidence of malware so I tend to doubt it has anything to do with whatever problems you are experiencing.
     
  27. bobgure

    bobgure Private E-2

    Hey,
    I disabled McAfee startups and services and the problem remained.
    Any suggestions as to where I should go from here?

    Thanks
    Bob
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it is a software related problem, a good way to try to isolate it is to keep doing what your are doing with msconfig. Try slowly choosing various startups and services to disable from loading and see it any of them are related to your problems.

    One thing to quickly try is to run msconfig and disable the below by unchecking them. So run msconfig and select Selective Startup then uncheck the below.
    • Process SYSTEM.INI File
    • Process WIN.INI File
    • Load System Services
    • Load Startup Items
    With these uncheck you will not be able to do very many things and will have no internet access, but it is a good starting point to see if you still have a problem. If you don't you can enable one of those 4 items (one at a time) and when you find the offending one then you can go to that individual tab in msconfig and slowly control each of the items under that tab. This way you can isolate the problem software. Obviously this is all assuming that the problem is related to something loading at startup.
     
  29. bobgure

    bobgure Private E-2

    Hi Chas,
    Sorry for my delay in responding to the last post.

    • Process SYSTEM.INI File
    • Process WIN.INI File
    • Load System Services
    • Load Startup Items

    I unchecked the above (strangely, I didstill have internet access after rebooting!) but with these disabled, the extra slow boot and load with sound breaking/distortion etc still occurred. No base line from which to work in add-eliminate "suspects".
    Oh well.
    I uninstalled itunes. I also unchecked all processes connected to realplay (another hog) and deleted the 2nd user acct. on my computer after panda-scanning it and adaware, both coming up negative.
    It would seem that what I'm experiencing is somesort of conflict that's draining memory but there's no evidence for that.
    The second user account concern was based on the 1st symptom I noticed. After adding the acct and setting a screen saver for it, that setting would never seem to take and would always default to the plain black screen. And I would have to reset it again. It was around that time I noticed all of the other probs happening. Obscure, yes. Relevant? Maybe.

    Anyway, as you said, it doesn't appear to be a malware problem or , after disabling those startup processes, rooted there either.

    Any other suggestions are gratefully received, if only to refer me to another forum.

    Thanks again for all of your efforts and time.
    Bob
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At this point Bob, I would suggest visiting the Software Forum to see if they have more ideas. We have cleaned up all the unnecessary programs from loading and even disabled all startups which would seem to point to a hardware or software issue some place.

    Post a new message there and clearly state your current problems. Post a link to this thread in the Malware Forum and let them know you worked thru the cleaning steps here and appear to be clean. That way no one will try to send you right back here.

    Good luck.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds