Slow, Freezes and PopUps! I Can Not Kill It!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Almost_Done, Feb 19, 2005.

  1. Almost_Done

    Almost_Done Private E-2

    I ran the list of programs that found and removed numerous items from the computer but I've yet to remove all of the problem causing code. Please help me stop this worm or virus that has attacked my computer. My computer operates very slowly after it is booted for a few minutes and then it acts like it runs out of memory and freezes up. When I am browsing with IE, I continue to have random popups. I have attached my Hijackthis log so that you may be able to assist me. :mad:
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must run all steps of the sticky thread. You have not done that. Also please follow guidelines about posting HijackThis log and only post them when requested. And DO NOT post them as .doc files. Only post as .log or .txt attachments.

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.


    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99.1 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. jarcher

    jarcher I can't handle a title

    have you already gone through this sticky if not please do so. . .
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal:
    if you have double check everything and make sure you did do everything
    and all software is up to date(and make sure to disable your system restore)

    Please download the following tools and have them handy (Perhaps create an Anti-Spyware Folder for them). Make sure to get them from the links below:


    and run through this before attaching a log
    NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting:
    *Note that your HijackThis should be up-to-date (v1.99) and MUST be extracted to its own safe folder - C:\Program Files\HijackThis! Please do this!!!*

    C:\DMI\BIN\DNAR.EXE <- - - - I believe should be removed

    these can be fixed by HJt before you rescan and post a log


    O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - (no file)
    O2 - BHO: (no name) - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - (no file)
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)
    O4 - Startup: Microsoft Find Fast.lnk = C:\\Program Files\\Microsoft Office\\Office\\FINDFAST.EXE
    O13 - WWW. Prefix: http://
    O16 - DPF: {5E6B281D-436A-11D3-80CB-0090276F843F} -
    O16 - DPF: {94349FB6-37A0-4385-BADA-1B48DE3CA833} -
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
    O16 - DPF: ppctlcab -
     
  4. Almost_Done

    Almost_Done Private E-2

    Some People just can not follow simple directions, like me. But not because I did not try.

    I tried to run the online virus scans while in safe mode, before posting, but when I am in safe mode my laptop does not load the PCMCIA controller in my machine, this is where my wireless card is located, so I can not access the internet.


    I removed the questionable items that you mentioned using HJT while in the safe mode, but as you can see most of them came back when I rebooted the machine in the normal mode.

    Please provide me with directions and I will attemp to follow them correctly.
    Thanks for your help on this!!!
    Almost_Done:cool:


    Why is it when I click on your links in your replys I receive this message instead of the linked page?
    "vBulletin Message
    No Thread specified. If you followed a valid link, please notify the webmaster"

    p.s. I am browsing with Mozilla
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and you still did not follow the directions in the READ ME. Look at the last couple sentences of the section on the onlines scanners again. I'll quote it here for you:
    You MUST do the online scans! Even if from normal boot mode. Do them before continuing with any other steps.

    Did you run Ad-Aware SE 1.05 with updated reference file and also the VX2 cleaner plugin?
     
    Last edited: Feb 20, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:
    regsvr32 /u C:\Windows\BTGrab.dll
    then click OK. If a dialog box confirming this action appears, click OK. If you get any error messages, just OK your way out and continue.

    Now repeat the above for these
    regsvr32 /u C:\Windows\ZServ.dll
    regsvr32 /u C:\Windows\Helper100.dll
    regsvr32 /u C:\Windows\dsktrf.dll
    regsvr32 /u C:\Windows\dsktrf1.dll

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\DMI\BIN\WIN32SL.EXE

    After killing all the above processes, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - (no file)
    O2 - BHO: (no name) - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - (no file)
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)
    O4 - HKLM\..\Run: [estrvqx] c:\windows\system\estrvqx.exe
    O16 - DPF: {5E6B281D-436A-11D3-80CB-0090276F843F} -
    O16 - DPF: {94349FB6-37A0-4385-BADA-1B48DE3CA833} -
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
    O16 - DPF: ppctlcab -
    O16 - DPF: Dialpad US Java Applet -

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete (if found):
    c:\windows\system\estrvqx.exe
    C:\Windows\BTGrab.dll
    C:\Windows\ZServ.dll
    C:\Windows\Helper100.dll
    C:\Windows\dsktrf.dll
    C:\Windows\dsktrf1.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again.

    Now empty your Recycle Bin

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.


    This next line is related to Dell. Read the info below and tell me do you need or use this? I'm sure this PC is way past waraantee.
    O4 - HKLM\..\RunServices: [Win32SL] C:\DMI\BIN\Win32sl.EXE -i

    win32sl.exe - Process Information
    Process File: win32sl or win32sl.exe

    Description:
    win32sl.exe is a process belonging to the Dell OpenManage Client Instrumentation software. It allows remote management application programs to access a client computer for maintainance purpose.


    Do you know what this next line with RW.EXE is? Is this for Remote Wonder related to an ATI Graphics card?
    O4 - HKLM\..\Run: [RunRw] "C:\PROGRAM FILES\RW\RW.EXE"
     
  7. Almost_Done

    Almost_Done Private E-2

    She reboots now with System Resources at 18%, and it still runs, although very slowly!!! :cool:

    Ran the following text at the run prompt: :mad:
    regsvr32 /u C:\Windows\BTGrab.dll
    regsvr32 /u C:\Windows\ZServ.dll
    regsvr32 /u C:\Windows\Helper100.dll
    regsvr32 /u C:\Windows\dsktrf.dll
    regsvr32 /u C:\Windows\dsktrf1.dll


    Using WinMe, restore is disabled and hidden files are enabled for viewing.

    Ran HijackThis and performed "Kill process" on:
    C:\DMI\BIN\WIN32SL.EXE

    Ran "Scan" and selected the following lines to "CLICK and FIX" , but they came right back:

    O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - (no file)
    O2 - BHO: (no name) - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - (no file)
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)
    O4 - HKLM\..\Run: [estrvqx] c:\windows\system\estrvqx.exe
    O16 - DPF: {5E6B281D-436A-11D3-80CB-0090276F843F} -
    O16 - DPF: {94349FB6-37A0-4385-BADA-1B48DE3CA833} -
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
    O16 - DPF: ppctlcab -
    O16 - DPF: Dialpad US Java Applet -



    Booted in safe mode and used Windows Explorer to delete:

    c:\windows\system\estrvqx.exe
    C:\Windows\ZServ.dll


    Emptied Recycle Bin.

    Rebooted in normal mode and a new HJT log is attached, in Log format.


    You are correct that my eight year old Dell laptop is way past waranty so I probably do not need the process listed below, are the bad guys using this for a back door nowadays?
    O4 - HKLM\..\RunServices: [Win32SL] C:\DMI\BIN\Win32sl.EXE -i

    Do I need it? How do I find out, delete it?
    Do you know what this next line with RW.EXE is? Is this for Remote Wonder related to an ATI Graphics card?
    O4 - HKLM\..\Run: [RunRw] "C:\PROGRAM FILES\RW\RW.EXE"


    Awaiting furhter instructions!
    Thanks! :)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please refer to this thread and make sure you have done all the steps in it or there equivalent. You need to get a firewall installed now.

    Make sure you are very careful what you give permission (in the firewall) to enter or leave your PC.
     
  9. Almost_Done

    Almost_Done Private E-2

    Since I have done the steps does that mean that all I need to do now is to get a firewall installed? :cool:
    Are these items that I am deleting returning due to the lack of a firewall?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! I forgot the link I wanted to post. Refer to this: How to Protect yourself from malware!

    A firewall is always needed an may help. I'm not sure what is bringing all of your stuff back immediately. When you say it came right back, do yo mean if you do another scan immediately after fixing the items that they are already back. That would sound like something is protecting your registry from changes.

    Please disable: Spybot - Search & Destroy\TeaTimer.exe

    And then make the changes again.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Earlier you asked the above! Only you can tell if you use the feature:

    http://www.ati.com/products/remotewonder/

    I'm assuming you have this ATI graphics card with that feature.
     
  12. Almost_Done

    Almost_Done Private E-2

    Do you mean that if If I install a firewall now my computer will be fixed??? :cool:


    Unaware if I needed this or not I deleted it:

    Originally Posted by Almost_Done
    Do I need it? How do I find out, delete it?
    Do you know what this next line with RW.EXE is? Is this for Remote Wonder related to an ATI Graphics card?
    O4 - HKLM\..\Run: [RunRw] "C:\PROGRAM FILES\RW\RW.EXE"



    Unaware if I needed this or not I deleted it:

    O4 - HKLM\..\Run: [RunRw] "C:\PROGRAM FILES\RW\RW.EXE


    I deleted the above items in the normal mode using HJT with a few browser windows open, fustrated and just trying to do something. First I did close teatimer and just about anything else that was running that I did not need to run the machine. Later I see where you amended your previous post to tell me to turn off teatimer because it may have been protecting my registry entries. After rebooting spybot, or what ever one of these many programs that monitors my registry changes asked me if I wanted to accept the deletions that I had made in my previous session, I clicked OK.
    Now system resources are at 81% when I reboot!!! Things run much faster for some reason.
    So now, how do I tell if I have some sneaky little bast&rd hiding on my machine someplace???



    Quote from chaslang:
    I'm not sure what is bringing all of your stuff back immediately. When you say it came right back, do yo mean if you do another scan immediately after fixing the items that they are already back. That would sound like something is protecting your registry from changes.


    You read my HJT log that I made directly after deleting the items in the safe mode, rebooted into normal mode, then I recorded the log before doing anything else.




    Ran "Scan" and selected the following lines to "CLICK and FIX" , but they came right back, What am I suppossed to do to get rid of these. Or am I supposed to keep them now? Are these good or bad?:

    O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - (no file)
    O2 - BHO: (no name) - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - (no file)
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)


    Thanks! :cool:
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a complete HJT log. I have seen multiple cases of problematic O2 BHO lines that will not go away even after using direct registry editing. Your problem may be another example of that..

    Please use quote boxes if you want to quote parts of previous messages. It makes it easier to read messages. Look at what I did in messages 10 & 11. I quoted your info and then added my text.


    Firewalls do not (well not in all cases) fix problems they are used to prevent the problems.
    If are running without a firewall, it is equivalent to having unsafe sex.
     
  14. Almost_Done

    Almost_Done Private E-2

    I have attached the HJT log that was made after a fresh boot in the normal mode. system resources down to 1%. very slow.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I requested that you disable the below
    C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE

    Please disable it and do not enable it anymore. Do you know how to do this? This does not mean kill the process. It means do not have it load anymore at startup.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still need the firewall!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To avoid wasting anymore time on this, just incase you do not know how to disable Spybot's Teatimer:

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    At this point reboot and then run HJT and select but do not click fix yet until ALL browser including this one have been shutdown:
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - (no file)
    O2 - BHO: (no name) - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - (no file)
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)
    O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)
    O16 - DPF: {5E6B281D-436A-11D3-80CB-0090276F843F} -
    O16 - DPF: {94349FB6-37A0-4385-BADA-1B48DE3CA833} -
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
    O16 - DPF: ppctlcab -
    O16 - DPF: Dialpad US Java Applet -

    Then get a new HJT log and post it.
     
  18. Almost_Done

    Almost_Done Private E-2

    System Resources are now at 82%, this number is normally much smaller. Does this mean that something is wrong with my computer now??? :confused:

    Disabled Spybot and Spybot's Teatimer, Before I removed it every page kinda looked like it was loading twice. A page would load up at a normal speed and then the entire page would flash as though it had just reloaded a second time, but very much faster.

    Rebooted and then ran HJT and selected and clicked to fix:
    O2 - BHO: (no name) - {017C20C1-F86F-11D8-9B25-000ACD002AE3} - (no file)
    O2 - BHO: (no name) - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - (no file)
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)
    O2 - BHO: (no name) - {00000000-C1EC-0345-6EC2-4D0300000000} - (no file)
    O16 - DPF: {5E6B281D-436A-11D3-80CB-0090276F843F} -
    O16 - DPF: {94349FB6-37A0-4385-BADA-1B48DE3CA833} -
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
    O16 - DPF: ppctlcab -
    O16 - DPF: Dialpad US Java Applet - So can you please tell me does this mean that the Spybot was the problem or are the hackers making Spybot the problem.


    Thank you for your help! :D
    HJT log attached
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why would you want system resources to be low? You want them as high as possible. The more that is running the lower they get. That's normal.

    Spybot is not the problem but Teatimer can be problematic on some PCs and waste resources. That's why I say in the stickies not to use it. Malware can cause interaction problems with many of the good tools (like Ad-Aware, Spybot, SpySweeper, MS Antispyware, SpywareBlaster....etc) making it necessary to sometimes uninstall them first inorder to properly fix a problem. Remember this programs try to block bad stuff but if bad stuff sneaks in and then we try to fix it, the good programs may see our fixes as bad stuff. Do you follow what I'm saying?

    You forgot the HJT log.
     
  20. Almost_Done

    Almost_Done Private E-2

    This time with attachment attached, maybe. :eek:
     

    Attached Files:

    Last edited by a moderator: Feb 23, 2005
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't quote when it is not necessary. It clutters up the thread making it hard to read.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  23. Almost_Done

    Almost_Done Private E-2

    I think that I understand what you are saying.
    I just notice that my HJT log did not post so I just reposted with that attachment.
    I understand that things start working better as the resouces increase, just jerking your chain some. ;)

    Thanks Again!
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds