Machine a bit slow - can someone look at HiJack This?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wiseloki, Mar 17, 2006.

  1. Wiseloki

    Wiseloki Private E-2

    Hi,

    I have a Dell C840 laptop, 1.8 MHz, 1GB ram, 40 GB HDD. XP Pro SP2 with latest updates, ZAP firewall v6.1.737.000, Norton 2004 antivirus v10.0.1.13. I have SpywareGuard v2.2.0, and SpywareBlaster v3.4 installed and regularly updated. I have Windows Defender running in background and I do a full scan about every week; I also scan with SpyBot S&D, Ewido v3.5, and Ad-Aware SE as well as scanning with NAV - full scans, usually weekly. I have done this before saving the HiJack This log, although the scans were not done in safe mode.

    I have also used Registry Mechanic and CCleaner to check temp files and registry and have used Wintasks and SpyBot utilities to selectively limit the startup list (startup currently takes about 3 min). I use Broadband internet via BT and an Intel AnyPoint DSL modem, so the laptop can be connected to the internet for days on end. I use Firefox 1.5.0.1 rather than IE6, except when I have no choice.

    I have used GRC.com's ports scanner to make sure that the machine is fully "stealth" when on-line.

    I have noticed that the machine seems to be running slower than usual and occasionally 'hangs' on shutdown, although no other real problems. I just wondered if one of the experts could run an eye over my Hijack This log to make sure nothing nasty has sneaked in.

    Thanks in anticipation.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well not really! In fact this is way out of date! See SpyWare Blaster

    Procedures required for removing malware or at least checking for it are to run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support and then attach the three requested logs. HijackThis is not the find all or cure all. In fact it is far from it.

    Many problems with PCs running slow are due to what you are running. For example Symantec stuff is notorius for this and on several threads here this week alone that was the problem. Also it is not recommend that you have 3 spyware blockers like MS Windows Defender, Ewido, and SpywareGuard all installed as a permanent solution. If you purchased Ewido keep it and uninstall the other two. Otherwise keep Windows Defender and uninstall the other two.

    Many times slow logoff is not malware either. You should check this out: http://majorgeeks.com/download.php?det=4841

    You do show a rogue service in you HJT log:

    O23 - Service: JUQLO - Unknown owner - C:\DOCUME~1\DELLMA~1\LOCALS~1\Temp\JUQLO.exe (file missing)

    So you can try fixing this but a simple fix may not work. You really should run the READ & RUN ME to make sure nothing else is hiding in your system.
     
    Last edited: Mar 17, 2006
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    You also need to update ZAP ZoneAlarm Pro 6.1.744.000

    The hanging on shutdown can be from running clean up routines ( I get same after running CCLeaner and registry cleaning apps ) and as you have an nVidia GFX card, the NVIDIA Display Driver Service needs to be stopped and disabled in Services as its known to slow shutdown down.
     
  4. Wiseloki

    Wiseloki Private E-2

    Chaslang,

    Thanks for the info - I checked and I have actually updated SpywareBlaster to 3.5.1, but I forgot to update my text file that contains the record my machine specs - sorry. :eek:

    Ewido does not run in the background (at least it shouldn't as my subscription has long expired). I only want it for manual scans (it seems to find tracking cookies like no other app.) so I'll de-install and re-install without the realtime components. I wasn't aware that SpywareGuard could interfere with MS Defender - I knew you can't run multi AV apps, but I thought a couple of anti-spyware were OK. I'll think I'll de-install SpywareGuard and leave Defender.

    I'll run through the process in the stickie and repost - apologies, didn't want to waste your time, just thought by having a quick look at the HJT log you could tell if I have a problem, which it appears I might from the registry key you pointed out. Definitely a newbie to this malware stuff.

    Halo,

    Thanks for pointing out ZAP was out of date - I usually get alerts telling me when a new version is out and tend to rely on these. :rolleyes:

    Also, I didn't realise that using CCleaner could cause a hang. On reflection that's pretty consistent with what I have obseved, just never made the connection until now. Doh! :confused:

    I wasn't aware I had a nVidea GFX card - the video system is running as it came out of the box back in 2003, except I updated the drivers from the Dell site a few months back.

    I mainly use the laptop in a docking station with a Dell 17" flatscreen monitor - is it still OK to shut down the NVIDIA display driver service and, if so, how would I go about that? (I realise that this is a little off topic - shout at me if required and I'll put a separate post in "hardware" :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right now your log shows the below for Ewido:
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe

    Which means it is running?

    Yes multiple full malware protection programs like this can interfere with each other making it difficult to fix/detect problems. Tools like SpywareBlaster, Spybot (without Teatime) Immunize and SDhelper are fine to have in with a program like MS Windows Defender (or another full realtime protection tool). SpwareGuard may or may not be too big an issue with a program like MS Windows Defender. But I don't think it is really needed.

    I never have any problems with this myself on any PCs (more than a dozen) I have run it on. Perhaps if you use the registry repair tools it is an issue but we do not recommend using that in the sticky.

    There are mixed opinions of whether the Service is needed or not. Some say it is important and others say you do not need it. See:

    http://www.liutilities.com/products/wintaskspro/processlibrary/nvsvc32/

    http://www.answersthatwork.com/Tasklist_pages/tasklist_n.htm

    Perhaps Halo can shed some more light on it along with his opinion.
     
  6. Wiseloki

    Wiseloki Private E-2

    OK,

    I have now followed instructions.

    I have de-installed Ewido, rebooted and re-installed without the two resident components (I like it, but can be pursuaded to ditch it if it's a problem).

    I have de-installed SpywareGuard and manually removed the folder in the Registry.

    I have updated ZAP to 6.1.744.000; I did a clean install then imported my security settings. Because of Chaslang's comment on conflicting antispyware, I've turned off ZAP's antispyware feature - let me know if this should be on.

    Updated Spybot, AdAware

    I rebooted into safe mode -

    Ran CCleaner

    Ran Windows Malicious Software Removal tool - No malicious software detected

    Ran AdAware - full scan - No critical objects, fixed one MRU list

    Ran Spybot. Immunised then scanned. No threats

    Windows Defender - full scan - No unwanted or harmful software.

    Tried to connect to internet in Safe + networking, but couldn't get my DSL modem to work (it uses a dail-up type connection). Rebooted in normal mode.

    Ran Bitdefender - No problems found. Log attached. (As an aside, I had to reduce my ActiveX security controls before it would run - it might be useful to add this as a warning in your sticky. Also, I had to hunt in the Bitdefender tabs to find the 'save report' option, unless that's just because it found nothing).

    Ran Panda - scanned 'My Computer' - 74 items of spyware found, none disinfected. Log attached. The items all appear to be cookies, most in somewhere called "Recycler".

    Ran HijackThis - log attached.

    Any advice on how to proceed?

    Thanks for the input thus far.
     

    Attached Files:

  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    CCleaner may not be a full cause of slower shutdowns but inconjunction with running a few of them before shutdown I've noticed that a shutdown at those times is slower ( maybe 30secs to a minute ), especially around the saving settings part, than times when I havnt done any cleaning routines.

    as for the nVidia service, you dont remove just disable it from running.. I have done this for years with no ill effects. My personal reason for not having it running was back when I was using Photoshop6 is that I tracked it down to being the cause of why the Adobe Gamma Loader wouldnt load, so since then, most of what I have read says its not really needed so I have alwasy disabled the service ( does have to be re-done on each new driver update tho ).

    Best thing is to disable it and see if shutdowns is any quicker but as you seem to have some malware infections I would only do this after those are removed and I will leave our resident expert Chas to cover those steps.

    ZAPs Antispyware app for me anyway doesnt seem to interfear with MS Defender as it seems to me ( and Chas will correct me if wrong ) that the ZAP Antispyware scanner is only an on-demand or scheduled scanner and not a resident live scanner.. so woudl be fine to leave on as I do.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still show an Ewido process/service running. If it is running it is using resources. You are complaining about a slow PC but yet you still seem to be using too many things that you really to not need. What is the Anonmizer Toolbare you have running? Is it for their antispyware program? I did not notice a AS program from them. Exactly what do you have installed from them.

    Do you have a paid version of ZAP or the free version. I believe Halo is correct in that their Antispyware part is really only an on demand scanner. The rest of their protection is really at the firewall level.

    You just need to empty your Norton Nprotect folder. It is saving old garbage. This is a stupid feature that most people do not use or even know they have. And it always winds up being a storage place for malware that you thought you deleted.


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to JUQLO ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    JUQLO

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://*.windowsupdate.com
    O23 - Service: JUQLO - Unknown owner - C:\DOCUME~1\DELLMA~1\LOCALS~1\Temp\JUQLO.exe (file missing)

    After clicking Fix, exit HJT.:

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell us how things are working now. If you still have problems, itemize exactly what they are.
     
  9. Wiseloki

    Wiseloki Private E-2

    OK, Chas, please don't take offence, but I'd like a little more info before I start fixing and changing things. Based on my post, you seem to be giving me advice on two subjects: a possible infection and a slow machine. To be clear, my machine is not particularly slow, with the exception of a three-minute boot-up. What I said was that it seemed subjectively slower, and I was concerned in case this change indicated some sort of infection, which is why I just initially posted my HijackThis log, for an expert to tell me if I had a problem.

    So if we could split the advice into two:

    1) Have I got an infection? If yes, I think it is compulsory for me to get rid of it. I'd appreciate your help with this.

    2) Tips on how I could speed up my machine by closing down or deleting legitimate but unnessecary services. This is purely optional for me, in my opinion. I would still like your opinion on this, but I may or may not take it (e.g. on Ewido - I checked in Task manager and ewidoctrl.exe is currently using 0 cpu and 1836 k memoery - not exactly tasking my machine. Obviously if I start it, I expect it to use more as I do a manual scan).

    Please, please, please don't think I don't appreciate your efforts, particularly as you volunteer your time. As I don't really understand what you are asking me to do, I prefer to understand at each step whether we are fixing (a Must) or optimising (a Maybe).

    Thanks in anticipation.
     
  10. Wiseloki

    Wiseloki Private E-2

    Oh, and to answer your questions:

    ZAP is the paid-for firewall, not the security suite. I originally bought just the firewall, but Zone Labs have added the spyware scanner as a part of a firewall upgrade. I have no idea if it just scans to a schedule or if it has a resident component giving real-time protection. I will not loose any sleep if I'm told to turn this off in favour of Defender - ZAP will just nag me every time I open its control panel. I thought Defender runs in the background as well as performing quick scans daily.

    Anonymizer is Anonymizer 2005, a paid-for utility that allows me to route my surfing through Anonymizer's secure USA servers, thus hiding my IP if I want to surf a little on the dark side. This is set to be manually started, so I thought it would not use resources unless I'd manually started it (a bit like Word). I had no idea it had a toolbar, so I checked and it has added a toolbar to IE without me noticing - I use IE6 so rarely and don't tend to customize it. I've turned this off now in IE's "View" menu. I don't think it has added anything to Firefox - I think I would have seen it.
     
  11. Wiseloki

    Wiseloki Private E-2

    Bye the way.

    I didn't realise that Messenger was running - I thought I'd deleted it, but it may have reinstalled itself when I played Internet Checkers.

    I've just deleted it (I don't message) using the "Add/Delete Windows components" option in Control Panel > Add/Delete Programs.

    I re-checked and the Messenger button has gone from IE6 menu options.
     
  12. Wiseloki

    Wiseloki Private E-2

    Final question

    Why would you want me to fix the key

    "O15 - Trusted Zone: http://*.windowsupdate.com"?

    Surely this is just one of the two entries of the Windows Update sites URLs in IE6's Trusted Zone? I would have thought I could fix this by taking Windows Update out of the IE trusted zone directly in the "IE Tools > Internet Options.." menu, rather than messing with registry keys, but why would I want to do that anyway?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My previous message already gave you steps for this

    Also already given! Uninstall Ewido and leave it uninstalled. It is slowing down your startups! If you don't want to uninstall it, don't. But then please do not ask why you PC takes so long to startup. The more things (processes and services) that need to install at startup, the longer bootup takes. If you really want to see a speed up in boot up time, just leave Ewido for now, and uninstall all the Norton/Symantec stuff and see what happens. You can always reinstall (that is if you still do after seeing the change).
     
    Last edited: Mar 19, 2006
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    99% of the time there is absolutely no reason for anything to be in the Trusted Zones. And no sites should be allow to be their unless you just cannot get them to work without it and you need the website. This should not be the case! Not even for Windows Update. Also this shortened URL matches some malware sites too.

    I also believe the correct URL for Microsoft Windows Update is:
    http://update.microsoft.com

    I have 17 PCs at home and there is nothing in the TZ on any of them and I never have any problems accessing any sites anywhere. There is no reason for you to implicitly trust any website on the net (not even Microsoft)..
     
  15. Wiseloki

    Wiseloki Private E-2

    OK, thanks for the patience and the input.

    I have left Ewido for now - I'll check its effect on boot-up speed when we've finished and then decide whether the penalties outweigh the benefits.

    I've fixed the issues you mentioned and have cleaned out the Norton Protected recycle bin.

    Machine seeems to be fine. Attached is a new HJT log, as you requested.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. Wiseloki

    Wiseloki Private E-2

    Thanks for that Chas. :D

    Over and out, as they say. Another success for the MajorGeek team. :cool:
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds