SLOW loading apps - have done run,read me first steps

Discussion in 'Malware Help (A Specialist Will Reply)' started by Beatlehead, Jul 6, 2006.

  1. Beatlehead

    Beatlehead Private E-2

    I originally posted this in "software" because all my software was running slow - but I guess that wasn't the right thread! Oops!!!! ;)
    I'm reposting here - hoping for some assistances.
    Thank you!!!

    SLOW loading apps, have tried AV's, antispyware, your steps, still slow
    Hello!!!! So glad to have found this forum.

    All my apps have been loading extremely slowly - several minutes, including FireFox, IE, Outlook Express, Quicken, Bitdefender, pretty much all of them. Clicking on Start/Programs is also a long wait to just see the program list... It's getting really frustrating. Windows itself doesn't take that long to come up, comparatively, but it's still kinda slow.

    My specs. HP Pavilion ze5400, 2.65 GHz Pentium 4, 960 MB RAM, 80 GB HD (36 Free), Windows XP Home SP2 (purchased 12/03)
    Defragged my hard drive last week.

    I tried contacting HP for help, but they were pretty quick to advise me to use my Windows Recovery CD to repair my OS. (They had given be the list of to do's, like check for viruses and spyware, which I did.) I was also getting fairly frequent blue screen errors which seemed to be caused by a device. I completely removed the 2 devices that I had added (with their drivers): Creative Soundblaster Live and WinTV by Haupaugge. Haven't had one of those since for a couple days - hopefully that is fixed. I'd rather try to clean my laptop up to see if that helps before reinstall/repair of Windows XP (Home SP2).

    I followed the RUN AND READ ME FIRST sticky - but before that I had run Bitdefender 9, and Spybot which identified JS.Blackworm.A, Win32.Netsky.C@mm, adware.bho.sidestep.A.1, adware.sidestep.F. First two cleaned, but can't seem to get rid of SideStep. Bitdefender also ID'd Trojan.Patched.B (DLMCleaner.exe), but isn't that a part of Adobe Reader? I couldn't download a couple pdfs after that was in quarantine. I emptied quarantine before proceding.

    The Major Geek steps:
    In Safe Mode Ran:
    CCleaner
    Windows Malicious Software Removal
    Ad Aware
    Spybot S&D (w/ immunize)- found and fixed SideStep BHO
    Windows Defender

    Reconnected to internet in safe mode:
    Bitdefender - found DLMCleaner.exe again, called Trojan.Patched.B = allowed to clean
    Panda Active Scan

    Computer still slow:
    Tried alternative scans:
    SpySweeper - could not install - error: C:\Windows\libeay32.dll = in use by other process
    Ewido AntiSpyware and TrojanScan - stopped after about 8 hours, getting more frustrated....

    I tried to attach my logs here, but it wouldn't let me. They are attached to my original post in the "software" forum. Bitdefender and Panda logs as well as a HJT log.

    Anyone want to try to tackle this with me???? I'd be very appreciative!!!

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have the trial versions of Spy Sweeper and Ewido installed, uninstall them now!

    You need to attach the logs from step 6 of the READ & RUN ME and then attach the requested HijackThis log from step 7.
     
  3. Beatlehead

    Beatlehead Private E-2

    Thanks for the reply! I uninstalled Ewido. I was unable to install SpySweeper - I got an error: C:\Windows\libeay32.dll - in use by other process

    I added a "1" to the attachment names - I couldn't upload the same files as I attached to my post in the other forum. (Not sure if I uploaded correctly - I hope they are there.)
     
  4. Beatlehead

    Beatlehead Private E-2

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have uninstalled Ewido, you should be able to attach a new HJT log because your log would be different. So attach a new HJT log AFTER you follow the directions in step 7 of the READ & RUN ME to install it properly. You currently are running it exactly how we request that you not run it.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you still use the below?
    O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
    O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
     
  7. Beatlehead

    Beatlehead Private E-2

    Well I just closed Bitdefender because I was getting strange messages about a bitdefender file and my apps are loading much much faster!!!
    So now I wonder if I should uninstall Bitdefender completely. Its on my husband's computer and hasn't caused problems.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't get side tracked. Answer my question? You do have another malware problem that needs to be fixed. But if you do not answer my question and attach a new HJT log, I cannot help you.
     
  9. Beatlehead

    Beatlehead Private E-2

    As I wrote above, I tried to attach my logs, but the site won't let me because I have attached them in my original thread. (I got the message that I had already attached these files in another thread and they wouldn't upload.) I don't know what else to do. Maybe I can add something to the files so that the site doesn't think they are the same, but I really tried to attach these files. I will try again, but can't you go to the other thread to see them quite easily?
    I do appreciate your help though. I'll try once more.
     
  10. Beatlehead

    Beatlehead Private E-2

    It looks like this finally worked. I added some dots on the first lines of activescan3.txt and hijackthis3.log . I added "extra text" to the bottom of bdscan3.txt to try not to screw up the html code. The upload application was recognizing them as identical before even though I changed their names.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See message number 5!!! Please follow directions!

    And you still did not answer my question from number 6. You need to only do what I ask you to do. I did not need you to repost the online scanners logs. I only needed a new HJT log which should have uploaded just fine since you said you uninstalled Ewido. That alone would make your log different. The log you just posted is the same old log. I requested A NEW LOG!
     
  12. Beatlehead

    Beatlehead Private E-2

    I am very sorry - but I really am trying to follow your directions. When I wrote #7 I did not see your # 5 and 6. Maybe I missed it but we could have been posting at the same time and it didn't appear yet. So my apologies. Since I hadn't seen them before - I didn't scroll up to check if anything new had popped up before my post.

    I wasn't running HJT in a temp folder or desktop so I thought it was okay. I re-extracted to the C:\program files\hjt as directed - is that what you meant?

    Regarding your #6 - I am not using either of these. I uninstalled FedEx Kinko's.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but we also say do not put it under C:\Documents and Settings\


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
    O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\system32\mstask.exe
    O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k42037/sb02b.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\SpyCatcher 2006 <-- the folder is found
    C:\WINDOWS\system32\mstask.exe <--- only delete mstask.exe if found. Don't delete mstask.dll

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  14. Beatlehead

    Beatlehead Private E-2

    Yes - duh - sorry. :eek: I always use the shortcut to My Documents and forget that it is really under Documents and Settings.

    Done

    These were not present

    Done

    Much, much better. :D Apps are taking more like 15 seconds to load (compared to 5-10 minutes before). (I tested 4 apps - Outlook Express, Firefox, Quicken 2005, Palm Desktop).
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you know that you still have a Service from Symantec Security Center running?

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    Do you actually still have something from Symantec installed even though you are using Antivir?

    This is your only remaining issue but obviously it is not malware.
     
  16. Beatlehead

    Beatlehead Private E-2

    No - not using Symantec intentionally. It must be a left over?
     
  17. Beatlehead

    Beatlehead Private E-2

    I found "Norton WMI Update" in my Add/Remove Programs
    Should I remove it?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but that will probably not remove the Service. Use the below to remove the service.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to SymWMI Service ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SymWSC

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.


    After reboot, just verify for yourself that the O23 line for Symantec is gone.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  19. Beatlehead

    Beatlehead Private E-2

    It's gone. I'll do the system restore and malware protection steps now.

    I can't thank you enough for your help. You're doing a great service.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds