system 32 folder

Discussion in 'Malware Help (A Specialist Will Reply)' started by sleepygamer213, May 6, 2005.

  1. sleepygamer213

    sleepygamer213 First Sergeant

    Why does my system 32 folder display right after my computer boots up? My comp has been running a little slow lately... Is it possible i got a virus from another computer on my network?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No the system32 folder issue is not due to malware. See this: http://support.microsoft.com/?kbid=170086

    As far as you PC running slow....what is slow? Do you mean your PC in general seems slow or do you mean you internet connection speed seems slow?

    If you believe you have some malware issues, complete the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. sleepygamer213

    sleepygamer213 First Sergeant

    By slow i mean my comp is running slow AND my internet is running slow... I got rid of all the viruses and spyware on my comp, i think...

    I ran:
    Avast! Latest Virus Definitions, eliminated all viruses
    AVG 7.0, Latest Definitions, didnt detect any viruses
    Microsoft Anti-Spyware, Latest Definitions, eliminated 2 malware
    Lavasoft Personal, Latest Definitions, eliminated a few tracking cookies
    Registry Mechinic, didnt find anything wrong with registry
    Hijack This!, Coundnt find anything i know of wrong, so heres the logfile anyway....

    Comp Specs;
    CPU: AMD Athlon XP 2600+ @1.9 GHz
    512MB RAM
    Mobo: ASUS A7N8X-X
    Internet: Comcast Digital Cable, used to run at 3.5mb/s, now at .2mb/s
    400 watt PSU
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running multiple antivirus applications (Avast and AVG) is not a good idea and it will have a negative effect on PC performance. Howver it may not be the reason behind your problem. You must uninstall one of them.

    I do not see any other visible signs of problems! You should run all the steps in the READ ME FIRST sticky thead as requested (you have not run them) and possibly run the Alternative scans too. They may find something.

    How much hard disk space is free? Have you done a defrag recently?

    If your internet connection is that slow all the time, you may want to ask your cable provider why the connection is so much slower than it used to be. If many people have subscribe to the service, they may need to increase bandwidth to your area.
     
  5. sleepygamer213

    sleepygamer213 First Sergeant

    Im in the middle of doing the steps now... which would you recommend out of AVG and Avast! ?... Im asking you because you seem to be the one to ask lol
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They are both good! I would suggest keeping Avast!
     
  7. sleepygamer213

    sleepygamer213 First Sergeant

    I was leaning towards Avast! since lately it has been detecting things that AVG hasn't....

    The two free online scans both found viruses, one couldn't be cleaned and the other was the symantec which just looks for them.... I think they were mainly Trojans...
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be much more useful if you told me exactly what they found. The virus/trojan names and what the file name and path is.

    Also as I said before, scroll down to the Alternative Scans section of the READ ME FIRST and run those other scans.
     
  9. sleepygamer213

    sleepygamer213 First Sergeant

    Heres the Hijackthis log from the otehr computer on my network, i deleted everything that i reconginzed was bad but wasnt sure about some stuff that wasnt recognized...
     

    Attached Files:

  10. sleepygamer213

    sleepygamer213 First Sergeant

    Bitdefender found this....

    D:\Program Files\AIM\Sysfiles\WxBug.EXE=>wise0008
    Detected with: Adware.Wheaterbug.A

    D:\Program Files\AIM\Sysfiles\WxBug.EXE=>wise0008
    Disinfection failed

    D:\Program Files\AIM\Sysfiles\WxBug.EXE=>wise0008
    Deleted

    D:\Program Files\AIM\Sysfiles\WxBug.EXE
    Update failed

    A squared got rid of Trojan.win32.Stervic.c and Trojan.Win32.Agentdb.dll

    Ill repost what Norton Found (one file)
     
  11. sleepygamer213

    sleepygamer213 First Sergeant

    The File symantec found was:

    C:\WINDOWS\system32\get.exe is infected with Download.Trojan

    Also can my computer get viruses from other computers in my network?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be better if you allowed us to tell you what to remove. If you just fix lines that HJT shows you that is not always the same thing as fixing the root problem. Files and folder may need to be deleted. Also sometimes an uninstall of a program rather than a fix with HJT is the proper method.

    Yes PCs on a network can infect each other.

    Download LSP - Fix

    Now run LSP-Fix.

    Check the Box labeled "I know what I'm doing" and then click on the flsmngr.dll file (in the “Keep” section) to select it.

    Then, Select the >> button to move flsmngr.dll into the Remove section.

    Now, click the Finish Button. When the Repair Summary box appears, click OK.
    If it is already in the Remove section, just click Finish.

    You do not have the proper version of HJT on this PC. You have:HijackThis v1.99.0
    You forgot to exit you browser sessions: C:\Program Files\Internet Explorer\iexplore.exe
    And you do not have HJT installed properly: C:\Documents and Settings\Mark\Desktop\hijackthis\HijackThis.exe

    Fix the above before continuing.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
    O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
    O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
    O4 - HKLM\..\Run: [FlnCPY] "C:\Program Files\Common Files\Java\flncpy.exe"
    O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\windows\System32\spoolsrv32.exe
    O4 - HKCU\..\Run: [suachjo] c:\windows\beeyxqs.exe
    O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\windows\System32\spoolsrv32.exe


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\windows\System32\spoolsrv32.exe
    c:\windows\beeyxqs.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds