serious system faults...please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by s1mpl1fy, Sep 11, 2007.

  1. s1mpl1fy

    s1mpl1fy Private E-2

    I am having several problems with my laptop, and don't know what to do next. I have run a variety of virus checkers, anti-spyware, and defragmenters. They always find problems, but I'm guessing the root of it all is much deeper.

    I've run all the recommended searches and checks from the 'read and run me first' instructions and now put the question out to all of you: what the hell is happening?

    The problems started about a month ago with my Internet Explorer window taking an increasingly long time closing when I clicked the 'close' button.

    Now, in the past few days, the Windows XP black startup screen takes about five minutes with just that little blue progress bar spinning its wheels. Then as windows opens, the musical chime sounds all clipped and overly digitized. It also takes approx. 10 minutes to finish cycling through its Start menu programs that load in the lower right corner. On top of all this, the CPU usage in the processes (when you look in the Windows Task Manager) hovers at approx 90% for about 1/2 an hour.

    Obviously, there's something wrong...I just don't know what. Please help.

    (I will attach all necessary logs to this and a reply post)

    Thanks so much in advance,
    s1mpl1fy
     

    Attached Files:

  2. s1mpl1fy

    s1mpl1fy Private E-2

    the other log files are attached below...

    again, thanks

    s1mpl1fy
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 6"
    J2SE Runtime Environment 5.0 Update 8

    This may be why you are having slow performance at start up:
    XoftSpySE
    Windows Defender
    Spybot - Search & Destroy 1.4"
    SpywareBlaster v3.5.1"
    SpywareGuard v2.2"
    SUPERAntiSpyware Free Edition
    NoAdware v5.0
    AVG Anti-Spyware 7.5
    Ad-Aware SE Personal

    Please look at this thread:
    How to Protect yourself from malware!

    You need to pare down that list ....otherwise I am not seeing any malware.
     
  4. s1mpl1fy

    s1mpl1fy Private E-2

    So, first off, thank you for the tips. I have done the suggested repairs in HijackThis and removed the old Java installs. Also, I have removed AVG Anti-Spyware 7.5 (only installed it to do the step-by-step instructions from the 'read and run me first' instructions), SpywareGuard 2.2, and NoAdware 5.0. The only stuff that actively runs on my system is BitDefender v10 and ZoneAlarm. The other stuff doesn't get used unless I have a problem.

    1st question: do I still need to remove more of the antispy stuff?

    2nd thing: Although i did everything you suggested, my system is still running strangely. All of the problems from the original post are still occuring and (which I didn't mention before), the overall performance of the PC is incredibly slow compared to just a few days ago...

    when I move the pointer around the screen, it's clipped and jumps around, the CPU usage in the Task Manager still shows the capacity running between 75-100% for the first 30minutes the computer is on, sound and video is all clipped and choppy.

    Even after the CPU has seemed to calm down, if I start to open any program, it starts to bog down to the point where, when I open 'My Computer', the damn flashlight pops up, searching for files, when it never did this before.

    I've gone onto the Windows update and added new patches... I've done everything I can think of. I honestly don't know if there's a malware problem, or if something else is affecting my system, but it's beginning to drive me crazy.

    I have attached new runkey, newfiles, and hijackthis files after applying your suggestions... is there anything else I can do, or am I stuck going to Geek Squad and forking over cash to figure out this problem?

    Again, any help is greatly appreciated!
    s1mpl1fy
     

    Attached Files:

    Last edited: Sep 11, 2007
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The two items in HJT were not fixed ....which could be due to your virus and spyware programs blocking the fixes.

    Turn off all active protection and try it again after doing this:
    CWShredder.

    It is possible that we may have to send you to the software section to help after we remove the small items that are showing.

    After doing the above, attach a new HJT log.
     
  6. s1mpl1fy

    s1mpl1fy Private E-2

    OK...

    So, I followed your suggestions...CWShredder didn't find anything.

    I reran the HJT fix after I disabled all web access and scanning/protection programs. I believe it cleared them from the system this time. Attached is the NEW NEW HJT log file.

    I'm concerned that this may be a serious core problem, as the black Windows XP screen continues to take between 5-7minutes to get through before ever loading anything other than core Windows files. Is it possible that some basic operating system files have been infected and are causing the slowdown?

    s1mpl1fy
     

    Attached Files:

  7. s1mpl1fy

    s1mpl1fy Private E-2

    I don't know if this will help or hurt, but last weekend when I started having trouble, I got suckered into buying a different antispyware program as it was finding a bunch of things nothing else could. It's Uniblue SpyEraser...

    I just ran a scan with it of my system, and again it found a bunch of crap. I've attached a transcripted log of what it found in a .txt file.

    Is this a scam program dropping new stuff onto my system just so that it has viruses to find, or is it a legitimate antispyware product that's finding things all my other programs seem inept at detecting?

    If it's legit, where is all this stuff coming from/hiding?

    thanks in advance,

    s1mpl1fy
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Windows Defender need to be uninstalled.

    SpyEraser is pretty dubious ....you'll note that it doesn't display where it finds these items.

    I would be far more trustworthy of the results of the Bitdefender logs and the AVGAnti-spyware logs ....

    Could you not run Counterspy? Have you installed it before?

    As to the slow problems ....have you attempted a repair installation?

    You may also wish to download a Startup manager.....
     
  9. s1mpl1fy

    s1mpl1fy Private E-2

    I'll work with your suggestions...

    CounterSpy seemed to be taking forever as I was downloading it and thought I may have done it and then gotten rid of it in July '06 so I went with AVG instead...

    What did you mean a 'repair installation'?

    s1mpl1fy
     
  10. s1mpl1fy

    s1mpl1fy Private E-2

    So, Windows Defender is gone.

    I'll try downloading CounterSpy again, although with all the various scans I've done, I'm not sure it'll find anything all the others didn't... but I'll give it a shot.

    I was a little confused about you saying 'SpyEraser is pretty dubious ....you'll note that it doesn't display where it finds these items.' In the txt file I attached a few posts ago, it listed where the infections were...am I not reading that correctly?

    I downloaded the Startup Manager you suggested, although I think I have the capability to do what it does in other programs (CCleaner, etc)...I've attached a txt file of the log it created of all my start up files. Any suggestions as to what doesn't need to be there?...(BTW: I forgot to adjust the startup option on SpyEraser so, that's why it's showing up in the log...it isn't there now.)

    A friend of mine suggested that something like a connection for the motherboard or the RAM or even the CPU may be loose...would this cause the slow loading times... I'm incredibly hesitant to start unscrewing things on the base of my laptop to check if everything is seated properly...could this be the cause?

    And again I've jumped ahead in your suggestions... what are we talking about with a 'repair installation'?

    thanks again for all your help...looking forward to having all this sorted out!

    s1mpl1fy
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Using the startup manager, you can stop these:
    GoogleToolbarNotifier
    Windows Media Player Network Sharing Service Configuration
    HP QuickPlay Resident Program
    Quick Launch Buttons
    DeleteLog
    hpWirelessAssistant
    TkBellExe
    SSBkgdUpdate
    HP Software Update
    SunJavaUpdateSched
    QuickTime Task
    iTunesHelper
    Adobe Reader Speed Launch.lnk
    HP Photosmart Premier Fast Start.lnk
    Microsoft Office.lnk

    Then reboot and tell me how it is.
     
  12. s1mpl1fy

    s1mpl1fy Private E-2

    Unfortunately, disabling all those programs/items actually caused the system to start up SLOWER!

    I appreciate your efforts, but I have taken my laptop into the Geek Squad for service...it was covered under warranty so no cash outta my pocket. They won't know until tomorrow, but their feeling is the hard drive is taking a crap (my words, not theirs) and after doing some various system diagnostics, their thought is either the hard disk is failing, or possibly the motherboard...I'll know tomorrow.

    Again, thanks for the help, and when I get it back, I'll absolutely be back to tweak it out and get it running even quicker with the help of you guys.

    I'll post again when I know what the verdict is and when I may be getting it back.

    take care,
    s1mpl1fy
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let us know.
     
  14. s1mpl1fy

    s1mpl1fy Private E-2

    Sorry for the delay in reposting.

    After taking my laptop to the geek squad, they informed me my hard drive had tripped over into PIO mode, however they did not have a particularly concise explanation as to why it would do that on it's own.

    Anyway, after resolving this, I've rerun all my tests from the 'read and run me first' instructions... notably absent is the CounterSpy scan; I ran it in safe mode and it never gave me an option of saving a log file. However, it did not discover anything when it ran its scan.

    I've attached everything else in this post and the next...please let me know if there's anything I need to clean up/disable/etc.

    thanks,
    s1mpl1fy
     

    Attached Files:

  15. s1mpl1fy

    s1mpl1fy Private E-2

    I'm having trouble posting the activescan file as your system is telling me I've already posted it. I even tried renaming it, but it won't let me post it. Let me know if you still need it, and how to get it posted if you do.

    thanks,
    s1mpl1fy
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The activescan is no doubt the same as the first run ....I'm not seeing anything malware related in your logs.

    If you are still having startup issues, you may wish to post in the software section or the hardware section ( where you can be guided to fun hard drive diagnostics).

    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds