Not finding much Spyware but still computer slow down...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Yakodi, May 27, 2005.

  1. Yakodi

    Yakodi Private E-2

    This is a bit confusing for me as I sometimes get what seems like the effects of spyware... For example Firefox and IE are going slow. Especialy when I load several pages on different tabs at the same time. It just seems like the computer doesn't like it. Games are running at much slower FPS to normal. Even old games such as Counter-strike have slow fps.
    I ran Ad-Aware (up to date) and it found nothing. SpybotS&D found one item but then messed up last time I tried it. It said it was making a system restore point but never stopped saying that and never removed the problems. I'm running it again right now too.
    I have Avast anti-virus which is up to date too and Kerio firewall.
    I just need someone to check if my HJT log is clean and then I can go to see if something else is causing the problem...
    Thankyou.
     

    Attached Files:

  2. Yakodi

    Yakodi Private E-2

    SS&D only finds "ISearchTech.SideFind"
    This time it didn't get stuck it just said it would sort the problems on the next system startup.
     
  3. Yakodi

    Yakodi Private E-2

    oh and SS&D couldnt remove it on start up... Even then it said it was still in use, in memory...
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. Do not post HJT logs unless they are requested.

    Download and install Microsoft® Windows AntiSpyware and make sure you get the updates but do not run a scan yet.

    Now reboot into safe mode with no network support, make sure you have no browsers opened and then run a full scan with MS Antispyware and let it fix what it finds.

    Now reboot into normal mode and let me know if it found anything and if you are still having problems.

    Also post your Spybot log if it still detects anything.


     
  5. Yakodi

    Yakodi Private E-2

    That program gives me a Critical error (code 101) When it is run, in either safe or normal mode...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. Yakodi

    Yakodi Private E-2

    Ok well running it the way you sasid also didnt work so i went though my computer program and ran it... ok it's on the start menu bar next to the clock now. I double clicked the logo and after I let it pass my firewall a splash screen for Microsoft Anti Spyware beta 1 came up and this time it said 'error code 102' and other stuff... So I clicked ok.. The icon down on the start menu is still there though and I enabled the Real-time protection... Tried to run a scan but same code 102 error again.

    I'll try re-installing to see if it helps...

    I take it this Microsoft Anti Spyware program is pretty new too ye?
     
  8. Yakodi

    Yakodi Private E-2

    Oh and yes I took it from your link

    It says that uninstaling is only a valid option if I've actualy got the program installed. lol. buggy.
     
  9. Yakodi

    Yakodi Private E-2

    Hmm well I re-downloaded the file, from a different mirror. And installed in the same place as it already is... I didn't delete as it wouldn't let me uninstall properly... Well it works now... So I'm going to try that scan in safe mode now.
     
  10. Yakodi

    Yakodi Private E-2

    Ok well thats running as it should now.

    Hmm well the computer seems to be going faster than it was but I still think it is going slower than it should be (looong start up too). I'm not sure realy. But it is better than it was erlier though. I'm not sure if it's completely clean. Would you like the log from MS:ASw and maybe then you could tell me what it could have been slowing the PC so much?

    Oh I also checked to see wether Windows was running its own firewall or virus checker to see if that was clashing and it isn't.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sure! Post the MS AS log.

    Do you still see the below Kerio process loading and running twice in you HJT log.

    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
     
  12. Yakodi

    Yakodi Private E-2

    Oh s**t lol. I didn't notice that!
    Yes C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe does show two times. Should I click fix on one of them or should I stop the process another way. I don't know how it could have done that though...

    I saved the log stuff by copy and paste into a text doc cuz i couldn't see a save option...
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to figure out how it is loading the process multiple times. Killing it now will only fix it during this session. It will just do it again on your next reboot. Running it twice can be a big waste of system resources, I'm not sure why the program even allows it.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like MS AS fixed everything it found. Are you having any particular problems at this time?
     
  15. Yakodi

    Yakodi Private E-2

    Heh I don't know if i'll be able to find out why... I think I may have to try uninstalling the firewall completely then do a re-install
     
  16. Yakodi

    Yakodi Private E-2

    Why does it say that in the log file and in my task manager but not in the scan results actualy int he HJT program...?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Task Manager and HJT's process list show what is currently running.

    The other lines in HJT show certain registry locations that are used for a variety of reasons. They do not show all possible ways that a program could be loading. You could look at a StartupListLog from HJT to see if anything else can be seen.

    Generate a StartupList log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.
     
  18. Yakodi

    Yakodi Private E-2

    Well here is the start up list...

    Sure enough kpf4gui.exe is there twice.

    I haven't had time to re-install the firewall yet. I do tonight. Should I do that or can the problem be solved another way?
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it appears twice but that is still just in the process list like the HJT log showed.

    I checked around a little and it looks like this may be standard operating procedure for Kerio. I don't know why but every log I found with Kerio installed shows this file running twice. So for now I would just ignore it as it is probably normal.

    Are you having any other problems?
     
  20. Yakodi

    Yakodi Private E-2

    Yeah it is still running slow. Avg fps in counter-strike is still about 10-20 when it *can* go to 60 and stuff. It seeme slow on desktop work too.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear to be related to any visible malware problem. You could try stopping the some processes (only temporary until next reboot) like your firewall and see if it changes anything.

    You can try running MS antispyware again to make sure it really fixed everything reported last time. Other than that I would say you should run through the full cleaning process jsut to make sure. Here is the procedure:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds