something is wrong

Discussion in 'Malware Help (A Specialist Will Reply)' started by taunton, Jul 11, 2006.

  1. taunton

    taunton Private E-2

    computer very slow and i have 1g and 1/2 of Ram.

    startup takes forever, mouse will move somewhere else on the screen sometimes by itself

    my computer in the past had the trojan viruse and 1,017 worms, that Mcafee supposedly fixed but i have so many temp files that i cannot delete because it says they are being used by another program. All kind of stuff and i really try not to even get on my computer anymore because of all this irritation stuff and i have tried everything in my power to try and fix it

    I have even gotten a computer specialist to come to my house and all he did was reinstall windows


    Edit: deleted inline log for first steps guide to be run
     
    Last edited by a moderator: Jul 11, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    also note that you should also disable Spybot - Search & Destroy's TeaTimer as that can hinder any removal process.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis


    Are you experiencing any malware issues, popups, browser hijack etc?

    When the PC was re-installed, were all the drivers updated/installed, eg. Chipset Motherboard, Graphics Card, if your mouse has its own driver was that installed, some wireless and USB mice have specific drivers ( especially Logitech ) etc?

    Is it a desktop or laptop?

    Have you defragged since the new install?
     
  3. taunton

    taunton Private E-2

    I have done all of this that you are describing and some of the programs came up with some stuff and cleaned it and also i have 1g of ram i put in my computer but it acts like i only have 512mb. please hurry and respond
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    If you attach the logs requested in the guide you have mentioned you completed the steps from and we can see if their is anything else that could be causing this due to malware.

    I had 4 questions at the bottom you have not answered?
     
  5. taunton

    taunton Private E-2

    yes
    no
    desktop
    yes
     
  6. taunton

    taunton Private E-2

    Here is the log file please reply
     

    Attached Files:

  7. taunton

    taunton Private E-2

    here is my activescan online
     

    Attached Files:

  8. taunton

    taunton Private E-2

    somebody please reply and tell me something
    i would rather someone tell me they don't want to help, than to just not say anything
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why didn't you attach the Bitdefender log that was requested?

    You HJT log shows no malware. You can delee the below which Panda found:

    C:\Program Files\Common Files\Totem Shared <--- the whole folder
    C:\temp\salm.log
    Other than that you are clean based on the logs you have attached. Let's see if the below scans show us anything.

    Now run the below procedure and attach the runkeys.txt log.
    Now run the below procedure and attach the newfiles.txt log.
    Please download & run Blacklight Beta
    • Hit I accept. It will take you to download page.
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the Blacklight log file.
     
  10. taunton

    taunton Private E-2

    please read this and help
    do these programs take forever to scan because i still have runkeys
    and newfiles still running
    blacklight says there are no rootkits but spysweeper tells me i do?
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    GetRunKey.bat takes about 3 seconds.

    And ShowNew could be similar or slightly longer if you have a lot of new files to add to a list.

    Run them again and make sure you extracted ALL the files from the ZIP file and not just the .bat file.

    If they are not running, you could have problems with missing files in your OS. If you still don't get a long within a few seconds, do the below and then try to get the logs:

    Choose the file below appropriate for your Windows Version:

    For Windows XP Pro: download and run XPproFix
    For Windows XP Home: download and run XPHomeFix
     
  12. taunton

    taunton Private E-2

    here is all the information i think you may need
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of your logs are all pretty clean but I will give you a registry patch to run below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now reboot and look for the below files and delete them if found:
    C:\windows\system32\narrator.exe
    c:\windows\narrator.exe


    If your PC is still running slow, I would recommended looking elsewhere (like what you are running) because it does not appear to be malware. Start with McAfee!
     
    Last edited: Jul 14, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds