Newbie needs a hand... is it malware or hardware

Discussion in 'Malware Help (A Specialist Will Reply)' started by jvk_goober, Jun 4, 2006.

  1. jvk_goober

    jvk_goober Private E-2

    Ok I am sorry I am a newb... So if I goof in my post or when following (what appear to be relatively simple) instructions I am truly sorry I am no good at this kinda stuff. ok so here we go.

    Comp Specs:

    OS:MS Win Xp (Media Center Edition) SP2
    Manufactured by & type: DELL (Dimension DIM4700)
    CPU: Intel Pentium 4 3.20 GHz
    RAM: 1.00 GB

    Ok I hope that is enough info for now. So here is my problem. I have noticed something burning up my memory and my cpu speed. I was having problems with programs running choppy and having difficulty shutting down. I did some personal looking around ( before I found this site) and I noticed I had SVCHOSt files running high memory and trying to access the internet and use my comp as a server. I denied access and tried a few different virus scans... I found nothing so I figured if all else fails save important info and reinstall OS. It appeared to work Now 2 weeks later I am having the same problems. I went through all of your steps and nothing was found...Also I did not do them in safe mode because I could not get in... all my prof's require password entrance and it would not let me use the keyboard in safe mode... After completing all of the steps in your list I rebooted and was allowed to enter safe mode for my internet scans. Like the last time nothing on the comp has been found. I am no computer wiz but I think I have an issue and I have no Idea how to find it so here is my HiJack report
    View attachment 36243
    I hope you can help. I am sorry if I goofed up my post or messed up any steps thanks for your time.
     
    Last edited: Nov 25, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    svchost.exe is a valid Windows process (as long as running from the system32 folder) and it requires internet access but does not need to be a server.

    Are you saying this is not your PC and that you do not have the administrator priviledges to boot into safe mode? If so, get the person who is the Admin to fix the PC. The steps that we would be giving you require adminstrator priviledges and typically will require that you have to be able to boot into safe mode. If you are not the owner of this PC, it is not a good idea for us to be helping you.

    You never completed step 6 of the READ ME! Please complete step 6 and attach the two requested logs. Your HJT logs shows not real malware issues. Just some minor stuff to cleanup.
     
  3. jvk_goober

    jvk_goober Private E-2

    I am the user/owner but I keep my profiles password protected...When I reboot in safe mode I can use the mouse but NOT the keyboard and therfor can not load any profiles...Sorry for the confusion.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What kind of keyboard are you using that does not allow use in safe mode. I would not use whatever it is since that is a major short coming.
     
  5. jvk_goober

    jvk_goober Private E-2

    It worked in safe mode before I started having the problems. After I did all the scans, it started working in safe mode again??? I am using a hardwired dell generic keyboard nothing special. I really hope I am giving enough info I am sorry I'm such a newb. Not really good at this kinda stuff. Thanks for the help sao far I really appreciate it
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to finish what I requested at the end of message number 2!
     
  7. jvk_goober

    jvk_goober Private E-2

    Sorry I will reacomplish and repost those logs TY...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! This are very important logs to see. Especially in cases like your since your HJT log does not show anything of major concern. If you are really having problems, they may not be malware. Seeing the two logs from the online scanners will help us determine that.
     
  9. jvk_goober

    jvk_goober Private E-2

    Ok I feel ike a total retard but for the life of me I can't get pandasoftware to work... keep getting an error message saying activeX controls will not load... I checked my settings under the security tab and they were set to allow ActiveX...So I am lost. I did get Bitdefender to run & I attached the log file. It says it found nothing so I am wondering If I have an internal setting messed up, a piece of hardware not working right, or something over heating. Cause my memory and CPU usage keep spiking to Like 50% and more. Sorry it took so long to get this up TY for the help.

    View attachment 36337
     
    Last edited: Nov 25, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well as previously stated, your don't have any malware issues that are of major concern. There are a few things I will give below to fix with HJT and I'll also suggest you fix some other un-necessary items to help free system resources.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

    The below are not necessary to load at startup. You can fix them to save system resources.
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    After clicking Fix, exit HJT.:
    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Other than this the above there have been no other problems showing in your log. I will suggest you run one more scan but I'm doubting it will reveal anything else.

    Please download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the Blacklight log file here.
     
  11. jvk_goober

    jvk_goober Private E-2

    Ok Sorry it took so long to reply but I am in the USAF and they have me doing some intensive leadership training and it takes up a minimum of 10 hours out of my days... not counting homework. So I did the scan and cleaned out those items and reset my Explore settings. No Files found with that program like u had previously suspected. I am still worried about my comp even though nothing has been found. I am still having weird problems with my win 32 files. My firewall keeps telling me that it is trying to access the net (Normal right?)... and that it is trying to act as a server (um...not normal???). OK so I am confused or I am just a newb with to little knowledge. Either way I really appreciate your help with the situation. Is there anyway to check my hardware for malfunctions seeing that it does not look like it is a virus? I just wish I knew why all of a sudden my processes are using super high CPU and Memory resources.

    Thanks,

    SrA Josh
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you allowing svchost.exe (called Generic Host Process for Win32 Services in your ZoneAlarm Program Control --> Programs list) to be set as follows?

    Access should allow Trusted and Internet
    Server should be blocked for Trusted and Internet

    When configuring your firewall for applications you must tell it what to do and whether you always want to do the samething, otherwise it will keep asking you.
     
  13. jvk_goober

    jvk_goober Private E-2

    I have adjusted the settings like you said it is now denied server access... So I guess there is nothing left for me to do but reformat my HD and try all over again or should I check my hardware...and how?


    TY again
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    With it adjusted that way, exactly what problems are you still having. Make sure you provide specific information. I don't think you have a problem other than possibly misunderstanding what your firewall is telling you and also how you are suppose to respond. You must make sure for things you do not want to have internet access that you deny it and also tell it to ALWAYS take the same action.
     
  15. jvk_goober

    jvk_goober Private E-2

    That explains why my program was trying to access as a server that problem is fixed it definetly stopped. I thought that if that program was trying access the net as a server then maybe I had a virus or something, and that it was maybe what was causing my original problem...apparently it is not.

    Original problem and still happening. There has recently been a significant drop in system resources. Really slow start up and shut down. My CPU has been having an increase in usage spikes on various programs...most notably those that use the internet. I have seen it go all the way up to 80% for explorer just loading a web page. I used to be able to multi task a little bit, now if I have anything downloading or if I am surfing the net I dare not use any other programs or risk their performance being slow and/or choppy. I guess what I could do is make a log of all the problems I incur in the next few days and let you see and hopefuly you can lead me in the right direction. Again I dunno exactly how to describe it all in one sitting so maybe if I write down all the problems it will give a better picture. Thank you so much for your time and patience in helping me with this. I know it can't be easy helping goofballs like myself fix these problems
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Be careful with what application names. I believe you mean Internet Explorer which is iexplore.exe (your browser). Explorer is explorer.exe which is the Windows Shell and what you see when you double click My Computer.

    How long ago did the problems start and how long ago did you install CA\eTrust EZ Armor


    Yes provide me with as much detail as possible but right now, I don't suspect that you are having malware issues.


    Also please attach a new HJT log so I can see your current status.

    Let's get an installed programs list from HijackThis too!
    • Run HijackThis, click Open the Misc Tools section
    • Click Open Uninstall Manager
    • Click Save List (generates uninstall_list.txt)
    • Click Save, to save it to a file where you can find it.
    • Attach the uninstall_list.txt file to your next message.
     
  17. jvk_goober

    jvk_goober Private E-2

    Ok so what I have found in detail over the last day or 2. The following applications run slow and or choppy and use (what I think might be) an overabundance of system resources (at times up to 80% cpu). All Video's and Music players run as if something else is running at high speed. Also ALL applications requiring internet usage have the same problem. I have Broadband Cable internet and some pages load as if I had dial up. Any thing I attempt to download causes ALL other programs to slow down or act choppy. Like they keep cutting in and out (they don't shut down or close they just seem to pause an action like hitting play pause on vcr or something). I don't know a better way to describe it. Also Shutdown takes nearly 4 times as long to accomplish then it ever has. Startup is especially slow before it gets to the actual Win Login screen...then it picks up speed...but as it loads the Win Login sounds act like they are being turned on and off. I have had ETrust software on my comp for over ayear...But I only recently activated their firewall. I activated this firewall when my previous firewall subscription ended (McAfee) and my comp started going stupid (comp had been acting stupid for a few days before firewall expired). I will update more as I find things but in the mean time here is my HJT log you asked for.

    I hope you don't think I am some crazy spaz who does not know how to use a comp. I mean these problems are a legit reason to think something is wrong right? I just don't want to waste your time or mine I feel bad that I keep bugging you with this. I really appreciate everything!




    View attachment 36464
     
    Last edited: Nov 25, 2007
  18. jvk_goober

    jvk_goober Private E-2

    I forgot to add this to my last post.

    View attachment 36676

    OK, so there really isn't much else I can figure out that is wrong with it other then it is running like I am trying to use 30 programs and not one. Also I checked all my bios entries and all things are good it shows my memory and CPU are both functioning correctly? thanks...
     
    Last edited: Nov 25, 2007
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This still may or may not be a malware issue. While malware can create similar problems, often time it can also be legit software causing similar issues.

    No we never think people are crazy. We know something is wrong, it is just a matter of determining the true root cause of the problems. As I said above, it may not be malware.

    Goto Add/Remove programs and uninstall the below:
    Java 2 Runtime Environment, SE v1.4.2_03
    Notifier

    Do you know what the below item in Add/Remove programs is?
    Banctec Service Agreement


    Now please download this 2 week trial version of WebRoot SpySweeper

    Click the Free Trial link under "Downloads/SpySweeper" to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post.
    Now ollow the directions for Running WinPfind by OldTimer.

    Attach the WinPFind.txt log.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Something that you should consider trying is to use MSconfig to disable all Startup processes and Services related to CA\eTrust EZ Armor and then reboot and let me know if things are still working slow. Save a HJT log from this mode so I can see that you got everything disabled. DO NOT remain connected to the internet for too long in this mode. Just stay connected long enough to quickly checkout browsing. Then disconnect from the internet (unplug cable) and check out your other issues like playing videos etc. Then you can re-run MSconfig and select Normal Startup on the General tab and that will bring you back to normal.
     
  21. jvk_goober

    jvk_goober Private E-2

    Ok I am in the process of working these... I found out that Banctec is a sort of warranty program run through dell. I guess they offer support on defective parts. I will reply again as soon as I have finished the rest. Thank You Again.
     
  22. jvk_goober

    jvk_goober Private E-2

    Ok So I got 2 of the three log files you wanted. I could not get webroot spysweeper to Download. It would not get above 35%. It would get a 353 K start and then just stop. It looked as if it was still going but the status bar would not move no matter how long u waited. I guess they r updating the link or something, I dunno. So I did the MSConfig thing... Nothing changed; Start up still took 1 minute and 45 secs to load. All programs ran choppy and Slow. CPU usage reached 99% many times during system loading. I am completely and Utterly lost. I have the HJT file from when I changed the msconfig settings and restarted. I also have the WinPFind log. I really hope they get us some info as to what the heck is wrong. I mean are you as curious as I am to see what the problem is? How often do you guys run into problems you can't solve or problems that just don't make sense?



    View attachment 36720

    View attachment 36721
     
    Last edited: Nov 25, 2007
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not disable everything for CA with MSconfig. You must disable all the processes and all the Services too. Look at your HJT log and you will see the below still running.
    Try it again and make sure you disable ALL processes and services from loading. If you cannot figure out how to do this, uninstall the program completely. You can always reinstall it later if we determine that it is not a problem.
     
  24. jvk_goober

    jvk_goober Private E-2

    Ok I so I removed all CA ETrust files from start up in MSConfig. Restarted... Still they were there. I uninstalled the entire program and did a HJT log after yet another restart. View attachment 36751

    The computer still took a long time to load but after it loaded it appeared to be running a little bit smoother. I tried a media Application and it worked ok (not great but better then it has been) then I opened up Explorer... Then everything went to crap again. It was as if I opened up 10 programs and not the 2 I had running. I figured I still needed my Firewall and Antivirus so I reloaded them (if later you tell me to ditch them I will) because I do not want to be on the net with out them. I also finally downloaded spysweeper. After reinstalling CA ETrust and spysweeper I ran another HJT log just in case you needed it (I remeber being told to try to give as much info as possible) ok so here it all is. I am really ready to throw this thing out a window! I know it is trivial to let something like a computer malfunction aggrivate you but, I am really getting tired of this. I really am glad you are here to help (I would have "bounce checked" this thing in my driveway long ago) thanks again... I hope I gave you adequate info.

    View attachment 36752 View attachment 36753
     
    Last edited: Nov 25, 2007
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you purchase Spy Sweeper? If so, keep it and uninstall Windows Defender.
    If Spy Sweeper is a free trial and you are not going to buy it, uninstall it and keep Windows Defender.

    Did you uninstall the below when I asked in message number 19?
    Java 2 Runtime Environment, SE v1.4.2_03
    Notifier


    When you boot in safe mode do you still have problems?

    I'm really starting to believe that your problems are not related to malware, but let's check a little further.


    I want to see if anything is attaching itself to Internet Explorer. Please download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on iexplore.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
    Now I want to run Kaspersky Online Virus Scanner! It is only a scanner, it will not fix anything. Follow the below steps:

    [/quote]
    Make sure all browsers are closed except for the one needed to run this procedure.
    1. Click on this link: http://www.kaspersky.com/virusscanner
    2. Click the "Kaspersky Online Scanner" button (Do NOT Click "Kaspersky File Scanner").
    3. In the next window that opens, click the "Accept" button to accept the user agreement, install the ActiveX control, and download the program.
    4. When you see the Windows dialog asking if you want to install this software, click the "Install" button.
    5. The scanner will download the latest definition files. When the "Update progress" line changes to "Ready" and the "NEXT ->" button lights up with a green arrow, click it.
    6. Click on the "Scan Settings" button, and in the next window select the "extended" database, and click Ok.
    7. Under "Please select a target to scan:", click My Computer to start the scan.
    8. When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop.
    9. Close the Kaspersky On-line Scanner window.
    10. Please attach the kavscan.txt file to your next message!
    [/quote]
     
  26. jvk_goober

    jvk_goober Private E-2

    OK I too am starting to believe my problems are not malware. The Kapersky scan found absolutely nothing so I didn't save the log... However, I got a blue screen of death last night I had this same screen about a month ago but it shut itself off before I could see what it said. This time I had the time to write it all down so I saved it to a text file... I really hope you can help me with this one...Good Luck

    View attachment 36829
     
    Last edited: Nov 25, 2007
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not a malware related problem. Try the Software or Hardware Forum fo that error message.
     
  28. jvk_goober

    jvk_goober Private E-2

    how do I link them here from there do I cut and paste or just start the process all over again over there?


    Sorry I took up all your time on this...
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are better off starting a new thread and explain your current problem exactly. You can use the below to reference this thread:

    http://forums.majorgeeks.com/showthread.php?t=93765


    But since there are already 28 messages here, it is better to only state your exact problem and clearly tell them you already worked thru the Malware Forum cleaning steps.
     
  30. jvk_goober

    jvk_goober Private E-2

    Thanks for all the help Chas I really appreciate it. What you guys do here is nothing short of incredible. Good luck in all you do.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! And good luck with your remaining problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds