Malware? -Slow Startup

Discussion in 'Malware Help (A Specialist Will Reply)' started by Robert Benson, Feb 27, 2006.

  1. Robert Benson

    Robert Benson Private E-2

    Have followed Read & Run Me First Before Asking for Support

    There are four users on this WindowXP system. When I click on my name to enter my XP environment, it takes an extremely long time to load up.

    I have run CCleaner, Ad-Aware se, Spy-Bot, CWShredder, Microsoft Malicious Software Removal tool, and BitDefender (log attached as bdscan1.txt)

    When I ran Window Defender.msi it stopped downloading, on two separate occasions, when there was only 2 seconds left - at that point it just kept on showing file transfer, but nothing happened - I had to cancel the function on both occasions.

    When I ran Panda ActiveScan - again on two occasions, when the program was just about finished with its scanning, it closed and dissappeared.

    I have also attached the Hijack This log. Have read the Tutorial re: Hijack This and it may be that I have too many un-needed "04" Startups are causing the extremely slow startup?. But I am not sure if I should allow Hijack This to fix them - this is my first time using this program.

    Any assistance would be appreciated. Thanks in advance

    Bob
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    Please read step 7 of the READ ME again. HJT logs must be posted from normal boot mode.
    Also msconfig must not be used to control startups.

    Before attaching a new HJT log you should uninstall Messenger Plus! 3 as recommended in step 0 of the READ ME. This is an undesirable program.
     
  3. Robert Benson

    Robert Benson Private E-2

    Thanks for quick response

    Have removed Messenger Plus 2 from my E hard drive, I have two hard drives C & E - was only able to locate it with Windows Explorer - it did not show up using Control Panel\Add Remove.

    Have run another Hijack This log, in normal boot. It is attached

    Bob
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was not referring too Messenger Plus 2. You have MessengerPlus3. See it in your HJT log. Are you sure it is not in Add/Remove programs?

    Also are you aware that Ares contains malware?

    You also appear to be running multiple antivirus applications. Did you read step 3 in the READ & RUN ME?
     
    Last edited: Feb 27, 2006
  5. Robert Benson

    Robert Benson Private E-2

    HJT log definitely showes 04 - HKCU\..|Run: [Messenger Plus3]etc. I have tried to locate this file (spend about an hour). It definitely does not show up in Control Panel\Add Remove.

    Tried the 'Start\Search' function in Window XP using the words: MessengerPlus3, Messenger Plus! 3, MSGPlus1.exe, and WinStart - and - no luck locating it. All this searching was done in XP with - Unchecked Hide extensions for known file types and - Unchecked Hide protected operating system files, as explained in How to view hidden files & folders.

    I have also removed the Microsoft Antispyware and the reference to Rogers spyware. I believe I only have Norton Antivirus left.

    Appreciate the help being offered, but, must say, as a 56 year old, not too computer literate individual, who has been working at this most of the day, I think I'm approaching the limit of my capability :)

    I've attached another HJT log, if that will be of any benefit?

    Thanks again

    Bob
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those options have nothing to do with Windows Search. They only apply to Windows Explorer. For Windows XP search requires additional options to look for hidden or system files. For you education read the below link but don't waste any mode time searching for it now.

    Searching for Hidden Files on WinXP

    I'll look at your logs now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Empty your Deleted Items folder for Outlook Express. You have a NetSky infection in there.

    Your Sun Java version is out of date. You will need to get the new version installed and then delete the old. But don't do this until all malware has been fixed.

    You still did not uninstall one of the two antivirus applications you are running. You have BitDefender 8 and Symantec running. Goto Add/Remove programs and uninstall one of them.

    Note I did not tell you to uninstall MS Antispyware earlier. It is not an antivirus application.

    You should also uninstall Ares which contains malware.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).
    Make sure you have uninstalled Ares (but I'm including it in the list below anyway).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {785CEAC8-4B9C-8E07-79EF-CC0D6466787F} - (no file)
    O4 - HKLM\..\Run: [skip dupe upload 64] C:\Documents and Settings\All Users\Application Data\Bags Hide Skip Dupe\2 drv.exe
    O4 - HKLM\..\RunServices: [Windows] system.exe
    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus1.exe" /WinStart
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - blank (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    (only delete exact matches nothing else):
    C:\Documents and Settings\All Users\Application Data\Bags Hide Skip Dupe <--- the whole folder
    C:\Program Files\Messenger Plus! 3 <--- the whole folder
    C:\windows\system32\system.exe
    C:\Program Files\Ares
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. Robert Benson

    Robert Benson Private E-2

    Followed all of the instructions.

    Computer is working a little quicker, but still slow on the startup - still may be too much loading up at startup. Can I simply check some of the "04" items in HJT that I no longer wish to have startup when I commence a session in XP?

    Messenger Plus! 3 is gone in the HJT log. Still was not able to locate it with Windows Explorer and delete it under C:\Program Files\Messenger Plus! 3, though.

    Also, was not able to find C:\windows\system32\system.exe, therefore did not delete this file.

    I've attached my latest HJT log

    Your assistance is much appreciated

    Bob
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below items can be fixed with HJT since they are not really needed (note this is not malware - just unessential and a waste of resources):
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


    Other items you will have to determine whether you need them. Only you know what you need to use.

    I'll tell you one other item I would definitely not allow to always load at startup:

    O4 - HKCU\..\Run: [areslite] "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another item that is not necessary to load at startup is:

    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

    Just run it when you want to connect to them but there is no need for it to always be loaded.
     
  12. Robert Benson

    Robert Benson Private E-2

    Thankyou - appreciated receiving your professional advice

    Bob
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds