kernel32.exe to a gradual downfall

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by intellecton, Dec 9, 2005.

  1. intellecton

    intellecton Private E-2

    Thank you for taking time to read this. My computer was running a bit slowly, so I was going through MSConfig and checking out processes and startup processes to see what was what, thinking that was the problem. I found kernel32.exe (not kernel32.dll) and had a feeling it was bad so I looked it up, and iamnotageek.com confirmed that it was apparently a problem. I didn't know what to do from there, but I did stop the process and restart.

    Upon restarting, I figured I should check the computer for spware and such, and I've come here before with problems. So I went to follow the READ ME BEFORE... page.

    I ran Bitdefender, which found NewDotNet and 180solutions. And then I ran Kaspersky. About 81% into that scan, I got a blue screen with the error MULTIPLE_IRP_COMPLETE_REQUEST. The scan had said it had found 4 viruses and 9 infected files at that point, but I didn't get to see what they were. I restarted from the blue screen, and then IE wouldn't work. So I couldn't continue any online virus scans.

    I then went into safe mode, most of the programs went off without a hitch. AdAware found WhenU and some cookies. And then Microsoft AntiSpyware wouldn't start (critical error 101). So I tried restarting in safe mode and trying again, and then restarting in normal mode and trying again. Then I tried uninstalling/reinstalling, and I still got the error.

    All of these combined problems sound like a file-sharing problem, and I did find Shareaza on the system, which I removed. But the only other thing here is a BitTorrent client (ABC, if that's important). So I'm sort of at a loss. IE still isn't working, and the computer, which is usually very fast, is taking forever to do anything.

    As for specs, I'm not sure what is needed, though I read the Announcement post. But I use Windows XP Service Pack 2 with a Intel Pentium 4 1.60GHz.

    I'll attach a HJT log, and again, thank you for taking the time to read and assist, if possible.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read step 3 of the READ ME again and make sure you only use one antivirus. You have both Avast and AVG7 right now.
     
  3. intellecton

    intellecton Private E-2

    Yeah, actually this problem also happened last time I posted here. I don't have Avast. At all. And I hadn't at that time either. Maybe it was on the system a long long time ago and uninstalled improperly? It doesn't show up in Add/Remove Programs. Nor does it show up in Program Files. I also checked the Uninstall lists in WindowsXP Manager and CCleaner, and it isn't there either.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To fix Avast, we need to get rid of the below service showing in your HJT log.

    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (file missing)

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to avast! iAVS4 Control Service (if you do not find that, look for aswUpdSv ) ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    aswUpdSv

    Now exit HJT and reboot. Afterwards look at a new HJT log and make sure that O23 line is gone.

    See if there is any change in performance.

    Do you have the WinXP SP2 firewall disabled? You should since you have Sygate!
     
  5. intellecton

    intellecton Private E-2

    The service was already stopped, but I did disable/delete it with no problems whatsoever. And it didn't up in the log I did upon restarting. Also, the Windows Firewall is already off.

    My system is still acting a lot lot slower than usual. Maybe it is just from downloading the software or something, if the log was clean. Internet Explorer loaded this time, just really slowly.

    But thank you for helping me get rid of that Avast service, anyway, and for looking over the log any everything!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    A clean HJT log does not necessarily mean you are clean. Let's did a little deeper. Hang on awhile while I work something up.
     
  7. intellecton

    intellecton Private E-2

    Sure thing. There aren't any huge immediate problems, so if you need to help someone who is having constant restarts or something, go for it. I'm just whining with impatience over the suddenly slow system. :)

    Thanks, though.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run CCleaner and let it cleanup all Cookies and Temporary Internet Files and other temp folders? If not, please do so.

    Do you use AOL?

    Do you use the below feature of PowerDVD:
    http://www.liutilities.com/products/wintaskspro/processlibrary/PDVDServ/

    It is in your log here:

    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

    This next item from Quicktime is a waste of resources:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    Now Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
    Now follow the steps in the below link and post the requested log:
    Running Spy Sweeper

    Now reboot! Any change in performance?
     
  9. intellecton

    intellecton Private E-2

    I ran CCleaner already, yeah.

    I don't use AOL, but I downloaded AIM Triton, which runs AOLsoftware for some reason (if that is what you were talking about).

    I'm not even sure was PowerDVD is, but I don't see it on my system anywhere.

    And I usually don't have qttask running, but I had to set to Normal startup in MSConfig for the HJT log. :)

    Hoster ran without a hitch.

    I started doing the steps for Spy Sweeper. I installed it, and it started up, but said my trial was already expired (I didn't have it installed prior). I tried uninstalling/reinstalling, which didn't help. So I went to the site and downloaded the trial from there instead. And I got the same problem. Doesn't seem that program likes me much...
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For things like qttask, it is best to just remove the registry entry rather than using msconfig which can also slow you down. HJT can fix that line which removes it from the registry so that it will not load at startup. You can also have HJT fix the PowerDVD line. It is for playing DVDs and may have come on your PC. This will not uninstall the software. It just unloads that unnecessary feature.

    I do not believe you need those two items for AOL to load at startup for AIM to work. You could experiment on them using msconfig and see if AIM works OK without them. The items are:
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1133965141\ee\AOLSoftware.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp

    Yes you ran CCleaner but specifically which items were selected? Were cookies and the TIF selected?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. intellecton

    intellecton Private E-2

    I did get rid of the PowerDVD and qttask lines. That was a good recommendation, thanks.

    I tried not starting the AOL things with MSConfig, and AIM wouldn't validate my name when I tried to run it. I set the processes going again, and there wasn't a problem, so they must be neccessary.

    And, yes. Both of those options were selected. All of them were except the Advanced ones.

    Also, I posted this before seeing the Ewido/Panda directions. So I'll do that and attach the logs right away. :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I'll catch up with you later tomorrow.....well later today! :D Been popping in and out! I'm pushing on watching the sun come up (maybe not since it is snowing) while working of some tools to aid in malware fighting.
     
  14. intellecton

    intellecton Private E-2

    Ha! I don't blame you. Just respond whenever you can. I can be patient. :)

    So, Ewido didn't have a problem (except an hour worth of scan time). It found a lot of stuff and I'll attach that log. (Oddly enough, the cookies seem to be a problem in other names. So I guess I need to monitor others' usage better :)).

    The Panda scan went really fast, and only found one thing. I've attached it as well.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try to delete the below folder:

    C:\PROGRAM FILES\VVSN

    If you cannot delete it in normal boot mode, do it in safe mode.

    How are things working now? If you still think it is slow, describe when it is slow and what makes you believe it is slow. What is your comparison point? What may have been changed or added since you last thought it was normal. Besides the tools from here.

    By the way Ewido will take some resources too, so you can uninstall it before commenting on your current situation.
     
  16. intellecton

    intellecton Private E-2

    Hey, I was able to delete the VVSN folder, no problem. I also noticed a Viewpoint Media Player folder. Is that program required or something? I uninstall it often, and it keeps coming back...

    Anyway, the system seems to be doing much better. Thanks. :)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Viewpoint (there is a family of things with this name) all get installed whenever you install anything from AOL. Like their ISP software or AIM. It is something that most people do not need, want, or will ever use. It is something they should not be installing without asking you. We always recommend uninstalling it. But you will have to constantly key a watch for it because it will get reinstalled if you install or possible upgrade anything related to AOL.

    Sounds like we are all fixed up. If you are not having any other malware issues, please check out the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds