Running Slow-ran HJT...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JoyceG, Jan 29, 2006.

  1. JoyceG

    JoyceG Private E-2

    My computer runs really slow. I've already ran all the programs the READ FIRST thread said to. I've run HiJack This and saved a log. Does it say that anything is wrong?
     

    Attached Files:

  2. Novice

    Novice MajorGeek

    Welcome to Major Geeks!:) It is best to post questions pertaining to HJT and such in the Malware Removal forum!:)
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Moved into the malware forum for the guys to look at.
     
  4. JoyceG

    JoyceG Private E-2

    *bump*
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. JoyceG

    JoyceG Private E-2

    Chaslang, thank you for the interest.

    -I didn't uninstall Spyblocs because I couldn't find it on my computer (it's not in the add/remove window).

    -I did the other 2 scans but did not include a log file from Bitdefender because it came up with nothing wrong and wouldn't let me have a log of the scan.

    -My SpySweeper is the paid version, and nothing comes up in its scans.

    Can anyone check out the attached scans and see if there's something bad on my computer? Trees grow faster than this computer can start up!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is Spy Sweeper running the current detections version?

    Is the below in Add/Remove programs:
    need2find
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what the below stuff is for? Did you add this to your PC?
    O15 - Trusted Zone: http://crmls.fnismls.com
    O16 - DPF: {0854D220-A90A-466D-BC02-6683183802B7} (PrintPreview Class) - http://crmls.fnismls.com/Paragon/Codebase/FNISPrintControl.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/101ef60e7f20c376d806/netzip/RdxIE601.cab
    O16 - DPF: {D270FE47-4F7B-4AFF-BCF8-B023A6FF4DFA} (SystemChecker.CheckerCtrl) - http://crmls.fnismls.com/Paragon/Codebase/SystemChecker.cab

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {00000000-0000-4BFC-91EC-E6F6EA7992A8} - C:\Program Files\ProSiteFinder\ProSiteFinder.dll (file missing)
    O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - (no file)
    O4 - HKCU\..\Run: [SpyBlocs] C:\Program Files\eBlocs\SpyBlocs\GLF3F.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\eBlocs <--- the whole folder
    C:\Program Files\ProSiteFinder <--- the whole folder

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. JoyceG

    JoyceG Private E-2

    -SpySweeper has always been updated.

    -Need2find is not in Add/Remove Programs

    Do you know what the below stuff is for? Did you add this to your PC?
    O15 - Trusted Zone: http://crmls.fnismls.com
    O16 - DPF: {0854D220-A90A-466D-BC02-6683183802B7} (PrintPreview Class) - http://crmls.fnismls.com/Paragon/Cod...intControl.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/101ef60e...p/RdxIE601.cab
    O16 - DPF: {D270FE47-4F7B-4AFF-BCF8-B023A6FF4DFA} (SystemChecker.CheckerCtrl) - http://crmls.fnismls.com/Paragon/Cod...temChecker.cab

    -I've added this all myself. It's all affiliated with Realty USA, where I work. This is so I can work from home.

    -I have had hidden folders made visible this whole time for over a month.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {00000000-0000-4BFC-91EC-E6F6EA7992A8} - C:\Program Files\ProSiteFinder\ProSiteFinder.dll (file missing)
    O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - (no file)
    O4 - HKCU\..\Run: [SpyBlocs] C:\Program Files\eBlocs\SpyBlocs\GLF3F.exe

    -Ok, did all that.

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\eBlocs <--- the whole folder
    C:\Program Files\ProSiteFinder <--- the whole folder

    -When I tried this I could not delete either of the folders above because I couldn't find them. I even did a seach on both (hidden folders included).

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    -Ok, did all that.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
    -Done.

    -I should also note that now whenever I reboot, a notepad window pops up called BackWeb-137903.exe, which is blank.

    -I'm running on Windows XP.
     

    Attached Files:

  10. JoyceG

    JoyceG Private E-2

    I forgot to mention that now my computer is faster but the start-up is still very slow.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log is clean! I don't see anything there related to loading Backweb.

    See the below thread on how to run WinPfind and attach the log from it
    Improving startup time is really not a malware problem. You should just not load some of the items you are loading. However first let's remove something we installed. Uninstall MS Antispyware. You do not need it since you subscribe to Spy Sweeper. This will help startup faster.

    Then have HJT fix the below items that you do not need to load at startup:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    Also do you really need the below? I doubt it:
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
     
    Last edited: Feb 1, 2006
  12. JoyceG

    JoyceG Private E-2

    Ok, I got rid of everything you said to and I downloaded WinPFind and ran a scan. I also got rid of MS Antispyware.

    Any Yahoo crap on this computer is from my husband :mad: so feel free to let me know what I can delete. Thanks.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did doing any of those previous steps help you startup issues?

    If you don't need the Yahoo stuff, then just look in Add/Remove programs and uninstall anything related to Yahoo. I know I saw Yahoo Pager in your log. There could be more.

    The Winpfind log did not show any problems.
     
  14. JoyceG

    JoyceG Private E-2

    Yes, starting up is now about 5 times faster now, which is nice considering it was taking about 15 minutes to begin with. It's still not as fast as it used to be before all this stuff plus all the other viruses and spyware I've had to get rid of. Perhaps over time damage has been done that I cannot fix. It's an HP pavillion 533w and it's roughly 1yr old.

    I cannot thank you enough for all the help you've provided. You've made my computer practical to use again and you should be getting paid a lot of money. I have one final question: Can you get viruses, malware, and other bad stuff through yahoo chatrooms or yahoo messenger?

    Thank you :) .
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some speed (boot & normal operation) degradation is necessary and will occur from using all the tools necessary to protect you from the malware that exists. If you uninstalled all antivirus, antispyware, and firewall (and any other protection tools) your PC would boot and run noticeably faster. Even surfing would be faster. However you would also get infected a lot faster and would be spending all your time recovering from the damage that malware can do. Some malware can completely kill your PC make a format necessary. Some can steal your personal info, credit card info, passwords etc causing you financial headaches. The performance hit is a necessary sacrifice that you must pay to enjoy the good things the internet has to offer. It is sort of like paying a load of money for car i nsurance. You would prefer not to pay for it but the risk is too great and the expenses could be too high if you had an accident.

    Did you uninstall all the remaining Yahoo stuff?

    You're welcome. You can get malware from just about anywhere. If they can send you attachments or things to click on then you can get infected if you open the attachments or click on links that you should not. You have to be very careful no matter where you go. That brings us to the below with some important tips!

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds