So slow with hacker/dialer?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Wlfwo, Jul 30, 2006.

  1. Wlfwo

    Wlfwo Private E-2

    I finished up the read and run first page, I did have to run the panda and bitdefender after booting in normal mode. Panda found a threat which I still need to find and get rid of. Everything else found was low threat.

    So here are the logs, I do hope I did everything right.

    Thanks ever so much for helping.

    Nancy
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not show any major malware problems in your logs! Speed issues are frequently related to what you are running on your PC.

    You can have HJT fix the the below non-malware processes. They are not needed at startup and this will help a little with your speed problem:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    Also if you do not want all the HP settings (in the R1 and R0 lines), you should have HJT fix them and then Reset Web Settings from Internet Explorer.

    You can also delete the below file found by Panda:
    c:\windows\system32\unPPC.exe
     
  3. Wlfwo

    Wlfwo Private E-2

    Thanks ever so much! I am glad to know what panda found wasn't an actual threat. I thought my AVG and Zone Alarm had failed me. :eek: So now I am off to see what I can get rid of without the teens yelling "MOM!"
    Nancy
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Well if your copy of SpyCatcher is a paid subscription version, you can uninstall Windows Defender. This will help speed things up and you do not want two full realtime spyware blockers like this running anyway (similar to antivirus applications).

    By the way you do need to update to the current Sun Java version and uninstall all old versions. This is included in the below steps which you should follow anyway.


    How to Protect yourself from malware!
     
  5. Wlfwo

    Wlfwo Private E-2

    SpyCatcher was supposed to have been deleted, ages ago. Darn it! Thanks again. One more quick question: Why when I close anything do I lose everything on my desktop except the background? Any clues? This started when the computer started slowing down.
    Nancy
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Make sure it is uninstalled. If it already is then have HJT fix those two lines related to SpyCatcher and delete the folder if it still exists. You should also therefore keep Windows Defender since you need a realtime spyware blocking tool.

    Sounds like something is terminating your Windows shell (this is explorer.exe). Does it stay like this or does the Desktop come back in a short time? If it stays like that, press CTRL-SHIFT-ESC to bring up Task Manager. The click File, New Task (Run...) and enter explorer.exe and click OK. Does the Desktop come back?



    Let's do a couple quick scans to look for any other hidden problems!

    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
     
  7. Wlfwo

    Wlfwo Private E-2

    Spycatcher still had a folder up, it just had very little in it. I found it and deleted it. Will run a new HJT and make sure though.

    As for the desktop, yes it comes back in 5-30 secs, depending. I am also getting a heck of a lot of "not responding"

    The computer isn't that old, almost all of my resources are free (according to the computer) Thanks, I will run the new stuff and post those logs ASAP.
    Nancy
     
  8. Wlfwo

    Wlfwo Private E-2

    Ok, I ran both of those......now to find the files and upload them. Ok, I found something. I hope these are what you need if not, let me know and I will do it again. Thanks ever so much.
    Nancy
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing really bad showing in those logs but there are a few registry keys we can cleanup. I'll give you a patch further down to apply. But first I have a questions about what you use the below Netscape stuff for.
    O4 - HKLM\..\Run: [Netscape] C:\Program Files\Common Files\ISPCOMP\InstallService.exe
    O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Windows Explorer and delete all files and subfolders in the below two folders of your PC. Note: Windows may have a couple files in use in each of these folders and block their deletion. This is normal. Just work around those files and delete the others. Typically the ones in use are from the current date.


    C:\WINDOWS\Temp
    C:\Documents and Settings\HP_Administrator\Local Settings\TEMP



    Now reboot and let me know if there is any change at all in performance. Any remaining issues are likely due to all the stuff that is running from AOL and all the junk HP installed on their PC for you to have headaches from.
     
  10. Wlfwo

    Wlfwo Private E-2

    Netscape is my ISP, up until a few months ago I used AOL (was part of the host program) I still use AIM as my main mail therefore I have an AOL e-mail address.

    Ok, going to reboot now. Thanks again

    Nancy
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AIM is an instant messenger! What do you mean AOL email address? Are you paying two ISPs?

    Having AOL installed and running is a huge waste of system resources. I would dump it completely if you can.
     
  12. Wlfwo

    Wlfwo Private E-2

    AIM also has mail now. I left AOL at the end of June and kept my old screename and address. AOL forwards any e-mail sent to it to AIM.

    The only ISP I pay for is netscape.

    I thought I had dumped AOL, except for the AIM that is. I will look again. I do know it came loaded on the computer, so did about 6 others.

    It is running better, the desktop barely blinks when you close things out now. Thanks again. Off to try and get rid of AOL....again.
    Nancy
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not know that since I never use AOL and rarely have used AIM.


    I thought I had dumped AOL, except for the AIM that is. I will look again. I do know it came loaded on the computer, so did about 6 others.[/quote] It is still installed. See the below running which is direct from your HJT log. These are not needed AIM (unless for some reason you need all of this just to read their email but that would be totally crazy).
    Uninstall all of AOL using Add/Remove programs. Just don't uninstall AIM.
     
  14. Wlfwo

    Wlfwo Private E-2

    Ok, I think I got rid of all of it. Ran another HJT and am attaching the log.

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot has shown up again and also the spycatcher :confused: It does not show up in a search.

    Still doing a "blink" when I close a window. It's very fast now. So it's getting better. :D

    Thanks again,
    Nancy
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not according to your HJT log. I still see some AOL stuff. Let's do a few things to clean it up and also take care of the Realsched.exe again. Also let's clean up the junk from HP in you start and search pages.



    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to AOL Connectivity Service (if that is not found, look for the short name: aswUpdSv)... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above stop and disable for the following services:
    AOL TopSpeed Monitor

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    AOL ACS

    Now repeat the Delete NT Service steps for:
    AOL TopSpeedMonitor

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimtoday.aol.com/today/aimtoday.adp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1133970931\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - Startup: Protector.lnk = C:\Program Files\SpyCatcher\Protector.exe
    O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\SpyCatcher <--- the whole folder
    C:\Program Files\Common Files\AOL <--- the whole folder

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  16. Wlfwo

    Wlfwo Private E-2

    Ok, I did all that. The spycatcher folder wasn't there, at all. I even looked under tenbril, the name of the company.

    Here is the new log, lets hope this is a good one. :)

    Thanks so much!
    Nancy
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Much better but the below is still there:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    Did you forget to fix this? Did it come back? If it came back, exit WinPatrol, Windows Defender and ZoneAlarm before fixing (also close ALL browsers windows before fixing).

    How is everything running now?
     
  18. Wlfwo

    Wlfwo Private E-2

    It came back, I did fix it. I remember doing so. Other than a quick blink when I close anything it is doing much better!

    I have WinPatrol? I can't find it. I haven't gotten a not responding since early yesterday. : D I will get offline and close the other 2 and try to fix it again. Thanks ever so much!

    Nancy
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is in your HJT log:

    O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe

    Are you saying you do not have it installed? If not, then have HJT fix the above line.
     
  20. Wlfwo

    Wlfwo Private E-2

    I used to have it, had a little scotty dog as it's icon?

    OK, when you delete something (using the add/remove program) why does parts of it hang around? I either use the A/R or the uninstall if the program has one. So why do I still have bits and pieces?

    I will have HJT fix it too.
     
  21. Wlfwo

    Wlfwo Private E-2

    I dumped the WinPatrol for the spycatcher, which I then didn't like and dumped it for the BitDefender.

    I like things that work well without a lot of managing. I have teens, (not to mention the hubby) I can't hang over their shoulder ALL the time. So I need things that do better than average.

    If you know of anything that works better, although most of what I use I got from you guys here. Feel free to let me know.

    Did I mention you are all a great bunch of people? If not, I will mention it now. You guys are all terrific! A whole lot of people would be up the creek without a paddle without you all. And I am not shy about telling others about you guys.

    Should I attach another log to make sure we got everything?

    Thanks bunches!
    Nancy
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They all do different things. Especially Bitdefender. It is an antivirus program (which you do not have installed! You have AVG). You are not compairing apples to apples.

    Why thank you for the compliment? We all appreciate it.

    Yes! Let's see where things stand now.
     
  23. Wlfwo

    Wlfwo Private E-2

    Ok, now I am confused, I thought spycatcher, WinPatrol and BitDefender were all anti-spyware type programs and that AVG was virus protection. Where am I wrong at?

    Here is the log and I am off to check out the preventing malware thread again. I must have missed something.

    Thanks again!
    Nancy
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    WinPatrol and SpyCatcher both are in the antispyware family they just work and do slightly different things. Bitdefender is an mainly an antivirus program.


    You still have not updated your Sun Java version to the current version as mentioned in the How to protect thread. After getting the current version (5.0 update 7) uninstall all old versions.
     
  25. Wlfwo

    Wlfwo Private E-2

    Actually I did. They told me I had the newest version. I will try again. I was running Firefox and I have noticed somethings only seem to want IE. I will close FF and try with IE maybe that will help.
    Nancy
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your HJT log shows:


    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    That is one version out of date. The current would show jre1.5.0_07

    Look in Add/Remove programs too! Make sure you uninstall ALL older versions after updating. They do not uninstall while updating.
     
    Last edited: Aug 4, 2006
  27. Wlfwo

    Wlfwo Private E-2

    I went to the Java website, used the download now button, had to do a manual install, (seems Java doesn't like firefox) what I got was version 5.0 update 6, which my computer informs me I already have, so I tried to update it, Java then informed me I had the newest version. I will try again using IE and see what comes up.
     
  28. Wlfwo

    Wlfwo Private E-2

    Ok, went in IE and this is what I got:

    JAVA SOFTWARE for Your Computer


    We detected your Java environment as follows;
    Description Your Environment

    Java Runtime Vendor: Sun Microsystems Inc.
    Java Runtime Version 1.5.0_06




    CONGRATULATIONS, you have the Latest version of Java!

    So now what? They keep telling me I have the newest version.

    Thanks again
    Nancy
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  30. Wlfwo

    Wlfwo Private E-2

    Well, I would have.....except that is not where the malware sticky thread sent me. : ) Am off downloading that one now. Thanks again
    Nancy
     
  31. Wlfwo

    Wlfwo Private E-2

    Ok, I got it now. One question: Do I just remove the 5.0 update 6? or do I remove the 5.0 also? So far all I removed is the 5.0 update 6. Wasn't sure what to do with the 5.0 so left it, just in case.
    Thanks lots,
    Nancy
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All versions other than the current version should be uninstalled.
     
  33. Wlfwo

    Wlfwo Private E-2

    OK, I did that. All I have left is a slight flicker when you close a program. So hopefully this is the last log I will need to post. We will see.
    Thanks again
    Nancy
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  35. Wlfwo

    Wlfwo Private E-2

    Thank you! Thank you! Thank you! ^5
    Nancy
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're most welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds