Hoping one of the Majors can take a look at logs :)

Discussion in 'Malware Help (A Specialist Will Reply)' started by sdmt, Sep 23, 2006.

  1. sdmt

    sdmt Private E-2

    I have gone through all the steps in the Read & Run Me First thread and am posting my logs here. Only the PandaActiveScan detected anything besides ISearch that was found on SpyBot. My computer just suddenly started running slooooow about 3 days ago. Hope one of you will be kind enough to take a look at the log files here and let me know how to proceed. BTW, your site has been extremely helpful now and in the past!! Thanks!! :)
     

    Attached Files:

  2. sdmt

    sdmt Private E-2

    Here are the other 2 files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgees!
    • Had you downloaded and installed anything new just prior to your problems starting?
    • Are your sure?
    • Had you been using Limewire to download anything?
    • What about an getting any updates for any programs?
    • Don't forget any Windows Updates.
    • Did any install automatically?
    Why are you running your PC with no antivirus and no software firewall? You also probably had no antispyware application until you installed Windows Defender while running the READ ME.

    Is Hypersend something you downloaded and installed? If so, what is it? Is it this http://www.hypersend.com/Home/Welcome/Entry

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
    O9 - Extra button: (no name) - {44EFB53C-C965-43CF-9F45-52242D134187} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com (file missing) (HKCU)
    O16 - DPF: {34805D32-AD89-469E-8503-A5666AEE4333} (RdxIE Class) - http://207.82.221.103/291ed47832225eeb2416/netzip/RdxIE.cab
    O16 - DPF: {625AECAE-0E47-4290-AF53-7BEB17E191CD} - http://209.120.156.13/funflow/FunFlow.exe
    O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.25.152/code/PWActiveXImgCtl.CAB

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\documents and settings\all users\start menu\programs\startup\PrecisionTime.lnk
    c:\windows\system32\exclean.exe
    c:\GatorPatch.log
    c:\windows\iedisco.exe
    c:\program files\Aveo <--- the whole folder
    c:\program files\Need2Find <--- the whole folder
    c:\program files\WebRebates <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\default\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore
    per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. sdmt

    sdmt Private E-2

    Thanks for looking over my logs! :) As far as downloading and installing anything new, the problem started after an automatic McAfee update last Thursday. I kinda think I've narrowed the problem down to that. I had uninstalled it somewhere in the process of running diagnostics. My computer seemed to perform fine in safeboot and when I had McAfee uninstalled. I have McAfee Security Center V7, build 7.0.331, Virus Scan v11 build 11.0.213, Personal Firewall v8, build 8.0.207, and Site Advisor v 1.6 build 1.6.3540. I've been reading on the McAfee boards that several others have had problems with their computers running slow after VS updates. I reinstalled McAfee last night after thinking things were running fine. It took 5 minutes or more (or seemed like it) for my computer to shut down last night. When I booted up this morning, it looked like Mcafee updates were downloading...It was still showing downloads 4 hours later. I'm guessing something was hung up. I went to their site and downloaded a file called MCPR.exe and ran it as one of the posts said that the problem might be caused by previous versions not being uninstalled properly. That didn't help either. So, now I have disabled everything in Mcafee and installed AVG for the timebeing. I have a paid Mcafee subscription through the middle of next year. :(

    I do have auto Windows updates but don't remember anything updating at that particular time. Nothing was being downloaded on Limewire at that time and probably hadn't been for several days. I'm pretty sure I hadn't updated any other programs, besides the Windows updates. I think the last one was a security fix.

    As far as the antispyware, I have Ad-Aware and Spybot and run them often.

    Hypersend is an email encryption site. I am a medical transcriptionist and use that site to email patient reports to the company I work for. My employer has used them for years with no problem. That is the correct web address that you listed.

    I have hidden file viewing enabled.

    I'll work on the rest and let you know the results. Thanks again!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They provide no active protection (unless you use Spybot's Teatimer). They are just after the fact scanners.

    And running without an antivirus and also no firewall is very dangerous. It can take as little as 10 seconds for malware to find unprotected PCs connected to the internet.
     
  6. sdmt

    sdmt Private E-2

    Okay. I finally got a chance to finish doing what you suggested. Computer is better, but still slow. It takes a good 10 seconds for a new IE page to open, and the CPU is grinding the entire time. I'm posting the new logs below.

    I realize I now have both AVG and Mcafee running. I had only the AVG this morning, but having Mcafee disabled was keeping my other work computer from having internet access... had to work..so enabled it again.

    Any suggestions about my McAfee problem other than uninstalling?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But now you are running with TWO antivirus applications. This is not acceptable. You must uninstall one of them immediately. I see no reason why not having McAfee on this PC should have anything to do with another PC not having internet access. How does the second PC connect to the internet? Do you get your connection via the first PC?

    McAfee (especially the security suite you are using) is massive resource hog. I cannot help you with your performance issues if you cannot uninstall McAfee. McAfee is the most like your biggest problem.
     
    Last edited: Sep 26, 2006
  8. sdmt

    sdmt Private E-2

    Ok, I have removed McAfee. It only took my PC a 2 or 3 minutes to reboot compared to 20 minutes with McAfee installed!

    My second PC is set up with a wireless router. I don't really know why that would affect it, but McAfee was coming up with a msg saying that another IP was trying to connect with this PC. My second PC wouldn't connect to the internet until I clicked allow connection on McAfee.

    Now that I have that taken care of, is there anything else in my log files that I need to take care of? I'll just use AVG and try to ask for a refund from McAfee for my subscription. What about a firewall program? I've read that the Windows firewall really isn't sufficient.

    Thanks for all your help!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your last logs were clean so the only problems you had at that time were due to McAfee.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link. This link will also answer your question about a firewall.

    How to Protect yourself from malware!
     
  10. sdmt

    sdmt Private E-2

    THANKS!!! I have AVG and Zone Alarm installed and have reset the System Restore. Everything is running great now!!! :)

    I have also asked for a refund from McAfee. I have used McAfee for 7 or 8 years with few problems. I am very disappointed that they released V 7 before it was ready. I know a lot other people must be also.

    Anyway, thanks again for all your help!!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I doubt they feel it was not ready. They just have expanded to program into this whole internet security suite package and have made it too big and too complex to make it useful while at the same time not being a problem itself to the end user. The problem is as you have experience first hand that they require too much horsepower from your system for their own use. All the internet security suite's I have seen (including Symantec, F-secure, ...etc) cause similar problems. I believe that some are even more of a hog than McAfee!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds