slow IE startup -- is it edow.exe?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by toad, Aug 14, 2004.

  1. toad

    toad Private E-2

    Hi -- The tutorials on the site are very helpful. I've gone through all the steps listed to get rid of spyware: disabled system restore, cleaned up temp files, went into safe mode, scanned for viruses, used adaware and spybot, cws shredder, kill2me, and then hijack this. I used that site that diagnoses the hijack this logfile and got rid of anything annoying. Then I re-enabled system restore. Earlier today I got rid of that awful ads234 midadle thing manually, including it's reinstaller files.

    But STILL, when I initially open IE, it is very, very slow, about 30 second of nothing before anything happens. The only thing I see left is "edow.exe" sitting in c:

    How do I get rid of edow? An internet search shows me it's spyware, but nothing I did detected it.

    My computer is a Dell PC running XP, I honestly can't remember the processor speed, but I'll look it up if someone tells me I must =)

    thanks!
     
  2. toad

    toad Private E-2

    Oh, I forgot to mention, I also have 404searchsetup_ms54.exe sitting around, which nothing detects, but looks suspicious to me.

    thanks
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. toad

    toad Private E-2

    thanks chaslang, I did find that page, and I want to avoid touching my registry. If I knew how to "set a restore point," etc., I might try it...but...

    Let me make sure my hijackthis is the current version (forgot to do that), and then maybe I'll attach a log file.

    thanks,

    Ann
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want to fix the problem, there may not be anyway to repair it without touching the registry. Even using HijackThis does touch your registry. You could download and install Erunt a registry backup/restore tool and use it too. Get Erunt here: http://www.majorgeeks.com/download1267.html
     
  6. toad

    toad Private E-2

    Attached is my logfile for the hijack this scan done after I removed entries I thought were suspicious.

    thanks!
     

    Attached Files:

  7. toad

    toad Private E-2

    (going to get that registry tool -- thanks for the link!)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know anything about this TEKNUM stuff. I see some complaints about it being a problem but I do not know execactly what it is yet but is appears to be spyware. Read this:
    http://www.wilderssecurity.com/archive/index.php/t-13100.html

    Here is the line I'm talking about:

    O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup


    This next line bothers me too. It is okay to have HijackThis fix this. If you really need it, the application or website requiring it will just reinstall it when you go back there.
    O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - http://help.rr.com/Foundrysdccommon/download/tgctlar.cab
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here is some more info on TEKNUM from Tony Klein:

    The Teknum Systems folder is a hidden folder that sits in Program Files\Common Files, and comes with Handybits programs like EasyCrypto, VoiceMail, and EasyCrypto for one won't function without it.

    It checks for updates of the program at startup, and will even restore this value in your Run key if deleted.
    I dislike that kind of practice, but if you like the program it came with, you can choose to work around it:

    You can download updEnabler.exe on http://www.handybits.com/update_service.asp
    It will allow you to disable the update service.

    Your program will still require Update.exe to load at startup, but it won't want to access the net any more.

    In that case you should of course tell SpyBot to ignore Teknum.
    You can and should of course also have your firewall block it.

    Incidentally, Handybits will, after some prodding, provide a tool to remove the Teknum updater completely.
    This is it: htp://www.handybits.com/download/misc/hbCleanUp.exe

    Spywareinfo's Freeatlast said she still had to manually remove the Teknum registry entries first, then after running hbCleanUp & rebooting were they finally gone. Some removal tool... http://tsgstatus.com/images/smilies/rolleyes.gif
     
  10. toad

    toad Private E-2

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good find! Also read the info I posted below from Tony Klein!
     
  12. toad

    toad Private E-2

    Thanks for your help -- I'm going to go work with that information, learn to handle the registry, and let you know tomorrow how it went.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! Talk to you later tomorrow!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds