Removed many viruses. Still VERY slow. Pls help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by bclondon, May 24, 2006.

  1. bclondon

    bclondon Private E-2

    Hello,
    Thanks for your help. I've attached the HJT log. I've ran every program and most in reg. and safe mode. I'm now getting iexplore.exe app errors and it takes a good 3 min. to initially start up anything. It's very frustrating. I'm trying to help my sister out and I've been staring it down for almost a week.

    Computer freezes during Ad-Aware scan in Windows\$hf_miq$ file. Freezes during Bitdefender search as well.

    Programs ran:
    Panda Titanium, Spybot S&D, Ad-Aware SE, Windows Defender, online Panda scan, CCleaner, ewido

    Hating this computer. Thank you again for your time and help!
    Bridget
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    We need the logs from step 6 of the READ ME.

    You problems may just be due to the Panda Titanium 2006 Antivirus + Antispyware using all of your systems horsepower. Look at all the processes it has running:
    When did you install this? Was it just recently? When did your problems begin?


    However, uninstall Windows Defender & Ewido, since your Panda program contains an antispyware application. You are wasting a lot of additional resources running Windows Defender & Ewido while having Panda's antispyware already running.
     
  3. bclondon

    bclondon Private E-2

    Hello,
    Thanks for responding. It took all of those programs just to get most of the bugs out. It was running really slow before I did anything. I uninstalled AVG anti-virus and installed Panda. It didn't run any better after most of the bugs were found.

    It's taking 2 to 5 minutes per keystroke now and I'd appreciate anyone pointing out any remarkable entries. I'm now getting rundll32.exe errors and having a hard time getting it to do anything. It runs well in safe mode.

    I read and followed the directions, including #6. Bittorrent will NOT work. It crashes the computer. I followed the directions. The computer did not. The stupid thing is not working.

    I uninstalled ewido but can't get a "proper" uninstall of Defender in safe mode. I'll keep trying for awhile longer on Defender.

    Sister's computer so I don't know how long it's been like this. They don't update or run scans. She also has children and a porn loving ex-. That's why the computer is having some issues.

    Thanks again,
    Bridget
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you did not follow the directions in step 6. Where are the logs?

    No one asked you to run BitTorrent. Or did you mean Bitdefender?

    You don't need to be in safe mode to uninstall Windows Defender.

    Did you knowing install Weather Studio? It is not really malware but it is considered annoyance software:

    O3 - Toolbar: Weather Studio - {C6139A57-16FB-4FA4-8045-A847FBFFD695} - C:\Program Files\Weather Studio\bin\WeatherStudio.dll

    You may want to consider uninstall it.

    Look in Add/Remove programs for FCAdvice and uninstall if found.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [Installed] 562
    O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
    O20 - AppInit_DLLs: Runner.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\Program Files\FCAdvice <---- delete the whole folder
    c:\windows\system32\562.exe
    c:\windows\system32\562.dll
    c:\windows\system32\Runner.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: May 26, 2006
  5. bclondon

    bclondon Private E-2

    Thank you so much for your help!!!

    It runs fast without antivirus programs. I'll reinstall Panda even if it is a process hog. Hopefully it won't be too noticeable. Bitdefender now works without crashing and didn't find anything. Woohoo!

    The modem driver was wiped and after installing a new driver it says it's working fine. I'm plugged into the router. The wireless is down and I can't fix it. Think they'll notice... Grrr.

    Ad-aware crashes on this folder windows\$hf_mig\KB883939\SP2QFE . I'm on a Presario 2200 laptop running XP SP2. I wonder what screwed this up and how to fix it.

    I think about everything is fixed. THANK YOU!!!!
    Bridget
     

    Attached Files:

    Last edited: May 28, 2006
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have not completed step 6 of the READ ME. HJT logs by themselves are not that useful and show very little of the possible malware world. I know you said BitDefender was clean but your HijackThis logs indicates that neither Bitdefender or PandaActiveScan were run. If run, follow the directions in step 6 and attach the logs so we can be sure nothing is hiding anywhere.

    The only thing wrong in your HJT log is not malware. It is the fact that Panda did not uninstall completely:

    O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll


    Also you must not keep running the PC like this. You have no protection in place at all. Not even a firewall. Consider yourself very lucky if you do not get some bad infections before even reading this. You should read the below:


    How to Protect yourself from malware!
     
  7. bclondon

    bclondon Private E-2

    Thanks for pointing out the bad uninstall.

    I'll fix the other issues myself. You can close this post.

    Thank you for looking at the HJT log.
     
    Last edited: May 29, 2006
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds