Hijack this log (and other logs)

Discussion in 'Malware Help (A Specialist Will Reply)' started by Rudyard, Nov 22, 2006.

  1. Rudyard

    Rudyard Private E-2

    I have tried my best to follow all the steps in your guide, I hope I havent stuffed up!

    PC spec:
    P4 2.6ghz
    1gb ram
    win xp home SP2
    nvidia gforce 5200 video card
    bitdefender 9 anti virus
    zone alarm (free) firewall
    behind a dlink di-704p router which provides internet sharing
    spyware blaster installed, updated and run frequently
    spybot search and destroy installed, updated and run frequently
    adaware installed, updated and run frequently

    My big PC problem is that right clicking on a file can take anywhere from 10 to 30 seconds for the properties box to open. Cuting and pasting files is the same and if I double click a file to load it there is again a massive delay before the associated program loads and runs the file.

    I apologise if ive done anything wrong here but attached are all my logs from the various steps in the read and run first thread.

    Thanks for any help you can offer me.
     

    Attached Files:

  2. Rudyard

    Rudyard Private E-2

    And the others!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I'm not sure that we are going to find malware to be the cause of your problem. But let's fix a few things (mostly non-malware) and see what happens.

    The first thing I suggest is that you remove all the clutter from your Desktop. You have loads of unnecessary files stored there (MPGs, JPGs, PDFs, ZIPs,...etc) and this not a good idea and it is not a safe long term stroage location. Move all of those files to another permanent location if you really need them. Just keep your shortcuts to run programs and remove everything else.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Mozilla Firefox (1.5.0.7)

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Well not quite correct. You are using Spybot version 1.3 which has not been used in over two years. Follow the directions in the READ ME and install the new version. First you will have to uninstall the old version and reboot.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Attach new logs from GetRunKey and ShowNew

    Now are you still having the same problems? I would expect not much has changed. So here is what I suggest you try, uninstall your Bitdefender Antivirus application. Reboot and see if you still have a problem. If not, you can try two things:

    1) reinstall Bitdefender and see if the problem comes back or not
    2) reinstall another antivirus like one of the ones in step 2 of this link: How to Protect yourself from malware!
     
    Last edited: Nov 23, 2006
  4. Rudyard

    Rudyard Private E-2

    chaslang,

    Thanks for your response, I will get to the suggestions you made and report back.

    Just on the spybot search and destroy, that is odd that it says it hasnt been used in 2 years because I used it yesterday and everytime I use it I do the latest updates....which i why i wrote it was used and updated.

    I figured using update would keep me updated but apparently not! WIll fix that to.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you are not running the current version! I did not say that you did not use the program. I said the version you are using has not been used in over two years. i.e., it is outdated. You need to always click the links in the READ ME and make sure that is the version you are running. Version 1.3 will not autoupdate or tell you about the current version which is 1.4 (as you now have realized). ;)
     
  6. Rudyard

    Rudyard Private E-2

    Done, funny since I started using firefox and it auto downloads stuff to the desktop I have become very sloppy at removing it....this was the spring clean that was along time coming!

    Done

    Done now, thanks for the heads up that I was using an old version. The new scan found only a couple of cookies.

    Done, if it isnt to much to ask, could you please point me to a guide or explain what the theory was behind those registry changes?

    Done


    Ok I am still having the problem but I have discovered something as I tested when right clicking away to see if it worked. The problem only exists if I right click a file, doesnt happen if its a folder or a shortcut it has to actually be a file.

    I dont know if that helps.

    Also before I uninstall bit defender I have some more background on it and a question.

    First can I use the system restore so that if the problem keeps happening I can just restore as opposed to reinstall? Or does it have to be uninstalled for the test to work properly (i dont know exactly how system restore works i.e. will it be as if the program is not there even though for it to be restored it technically still is?).

    And the extra background info I forgot in the first post was I originally had Norton antivirus and firewall when I first got this PC about 3-4 years ago. I upgraded it all the way to 2005 when after reading many internet sites there seemed to be a general concensus that NIS was bloatware and a resource hog and that there were many better products which is how I ended up this year cancelling NIS and going with the bit defender/zonealarm combo. (zone alarm was free and bit defender cost me $70 for 3 years - WAY cheaper than norton was was about $80 a year)

    Now the problem always existed when I had norton, it didnt start after i installed bit defender/zone alarm but I do feel the problem is slightly worse now (whether its in my head I dont know) and there are definate problems with emailing attachments through outlook express since the change. Even when I shut zone alarm and bit defender down, if I send an attachement (ive noticed it more with larger ones say 500kb and up) sometimes the recipient doesnt recieve the file, sometimes they do and other times they get it but say it is corrupt and cant open it. I can open it fine through my sent files and when taking the exact same files on a disk to the person it opens no problems so it isnt an incompatible file type.

    Just some background info that may shed some light to a technical brain.

    And one last question, since using the tools in the guide I now have AVG anti spyware installed.....do I still need it if I run spyware blaster or is it overkill and just taking up resources to have both?

    If only one is needed is there a better one?

    Thanks again for your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is an option in FireFox that can be used to change the default folder to dowload to. Create a folder like C:\Downloads and download files there. But also when downloading the file, take it a step further and create a folder for the download and name it something that will tell you what the file is when you look at it a month or two down the road. For example you had a file named DefragSetup.exe Is this SmartDefrag and if so what version (like 1.1)? My method would do the below (assuming it was SmartDefrag Version 1.1.)

    C:\Downloads\SmartDrag V1.1\DefragSetup.exe

    You can take this idea even further and use subcategories under the downloads folder like:

    C:\Downloads\Antispyware\Spybot - Search & Destroy
    C:\Downloads\Antispyware\Spy Sweeper
    C:\Downloads\Antispyware\SuperAntispyware
    C:\Downloads\Antivirus\AntiVir
    C:\Downloads\Antivirus\Avast
    C:\Downloads\Antivirus\AVG


    Get the idea.....??? I makes finding things and knowing what they are at a later date, so much easier.


    • You had a left over Symantec process trying to load. I removed it.
    • Registry editing tools of any type was disabled! We were trying to remove that restriction.
    • You had not completely follow the directions in step 2 of the READ ME, so I made a registry patch to set it up properly for you. You did not uncheck the option to hide extensions for know file types. Now it should be unchecked.
    I'm still not sure what is the cause of this but it is more than likely not due to malware. Another guess on my part (same as I was saying for Bitdefender) would be to try uninstall ShellExView and see what happens.

    How are you going to know which restore point to go back to that did not have Bitdefender installed? Also you could revert back to a point with malware installed. No it would not be exactly the same as uninstalling it since the files will still be on your PC, but registry entries for it would change. It is actually easier to uninstall. (Try the uninstall of ShellExView first)!

    Yes I know because of the left over from Symantec I was fixing in the fixme.reg patch. Yes Norton is a huge resource hog. Bitdefender is not nearly as bad but AVOID the everything security suite packages from anyone. They are all massive resource hogs.

    I'm not sure I follow this. If it always existed when you had Norton, are you saying it went away when you uninstall Norton. And then you install BitDefender and the problem was still gone. But then the problem came back some time later?


    Do you have any filesize limits on emailing attachments? Is your ISP limiting your attachment size? Do you have bandwidth limits upstream? Email to yourself.....do they come thru okay.

    Well actually you also have Spybot too. However Spybot (without Teatimer) and SpywareBlaster are not realtime malware blocking agents. You need a realtime blocker. Pay ones are better but there are a few free tools to choose from too. The free AVG Antispyware you installed also is not a realtime blocker and less you puchased the program. Then it will give you full capabilities. So if you are going to buy AVG Antispyware, keep it. Otherwise uninstall it and use other free tools to block (Avorax Shield, SpywareGuard, Windows Defender are a few examples).
     
  8. Rudyard

    Rudyard Private E-2

    No sorry, what I meant was the problem never went away after removing norton and installing bitdefender - the problem has been there constantly.

    I had thought (hoped) it was norton related as norton came with the PC and had been on it the whole time but nothing changed after removing it.

    I uninstalled ShellExView and there is no change ( i think from memory i installed that program as it was suggested to me that it is a bad context menu handler or something causing the problem and this program let me shut the down one by one to see which was causing the problem but I followed the guide and nothing changed).

    I have now uninstalled bitdefender and the problem is still there.

    Again I have extra info that may help from testing, as well as it only happening on files (not folders or shortcuts) it seems that after the massive delay I can happily right click any file in the same folder for a short period until it happens again. I clicked on about 8 different files until the hour glass popped up again with the delay. Though this isnt consistant, it could be 3 times before it happens there is definately a (very) short reprieve.

    Also if I change folders to a different group of files it will usually happen instantly the first time i try a file.

    This is also true for loading the file i.e. if its a jpeg there is a big delay until windows picture viewer pops up or if an mp3 a delay until wmp loads.

    I dont have file size limits (or not that im exceeding - ive sent much larger emails before) and ive just tested emailing to myself and they came through just fine and I could open the attachments no problems.

    I did this after uninstalling bit defender and will try again after I reinstall it.

    Thanks again for helping.
     
  9. Rudyard

    Rudyard Private E-2

    Ok I have reinstalled bitdefender and it would appear that it is the cause of my email headaches but not my long standing problem of slow right click and loading file problem.

    I sent the same emails to myself after I reinstalled it and at first it kept saying my something hasnt responded in 60 seconds which went away after I disabled bitdefender from scanning outgoing mail.

    Now the emails actually send but when I recieved them one opened but others only one of the 2 attachments came through for starters (the exact same emails I sent after uninstalling bitdefender) and when I tried to open it it said the file was corrupt (it was a PDF) and could not be repaired.

    So next I closed down bit defender, reopened outlook express and sent it to myself again. Same problem even when it was closed down.

    I dont get how bit defender can intefere with my emails when A. it isnt meant to touch outgoing mail anymore and B. It is closed down so it shouldnt be active anyway.

    I recieve emails no problems (from others).

    Any ideas on some settings that could stop this problem?

    At least I have the cause of one so I can now look for the cure!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was not clear whether or not you other problem with right clicking was tested while Bitdefender was totally uninstalled (and after a reboot with it still uninstalled too). Did you test this? Your problems are more than likely not malware and I will probably have to refer you to another forum. Sounds more like a software interaction. You may need to observe Task Manager's process list to see which processes hog CPU time when you do a right click. The reason I suggest uninstalling Bitdefender (and I would say the same for any other antivirus if installed) is that when files are accessed the antivirus could cause delays while the file is being scanned.

    I'm not sure what you mean by "closed down" but if you just shutdown some active processes, that is not good enough. All antivirus programs (at least good ones) have services running at all times. Which means the AV always has something running. The only way to truly get around this is to uninstall the program and run your tests (which you already did). You can try playing with different features and options in your Bitdefender program and tell it not to scan outgoing emails to see what happens. Again this is not a topic for this forum. Discussions like this are better suited to the Software Forum.
     
  11. Rudyard

    Rudyard Private E-2

    No problems, thankyou for your help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds