System resources low low

Discussion in 'Malware Help (A Specialist Will Reply)' started by ragan, Nov 21, 2006.

  1. ragan

    ragan Private E-2

    Can anyone give me a little helphere? My ststem seem to always be running at 80-99% of system resources, even when I have almost all of my programs closed. I have run the "pre-post" clean up procedures. Attached are the results from my Active scan and HJlog. Should I upload all the others as well? Any assistance would be appreciated.
    Thasnks!

    Ragan
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and yes please all logs are needed :)
     
  3. ragan

    ragan Private E-2

    here are the others & Thanks!
     

    Attached Files:

  4. ragan

    ragan Private E-2

    Had to Zip this bdscan as it was too large.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are running an outdated version of SpywareBlaster. Let's fix that and also remove some old Sun Java versions.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2
    SpywareBlaster v3.4

    Now download, install, and update SpyWare Blaster

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
    O4 - HKLM\..\Run: [Spooler Subsystem] spoolsub.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
    O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact... - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Owner\Favorites\INSURANCE <--- the whole folder unless this is a Favorite that you created:
    C:\Documents and Settings\Ragan Jr\My Documents\graffiti fonts.exe
    C:\windows\system32\spoolsub.exe

    Now run Ccleaner.

    Now reboot in normal mode
    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. ragan

    ragan Private E-2

    Thanks again for your help, here are my results.

    When I ran HijackThis the only line that did not show up was:
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    I successfully chacked and fixed the others.


    I could not locate or remove the following: C:\Documents and Settings\Ragan Jr\My Documents\graffiti fonts.exe
    C:\windows\system32\spoolsub.exe

    (I think that I may have removed the Graffiti program earlier this week)


    I was not successful in running the REGEDIT4 -
    I'm pretty sure I followed your instructions correctly. I did not change the default "ANSI" format. I recieved errors saying "error opening, possible disk or file system error" and "Can not import...."

    I have attached the logs as requested.

    Thanks!
    Ragan
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All of the items (except msmsgs.exe) I asked you to fix with HijackThis are still in your log. Did you fix them. Did you attach the correct log?

    Uninstall Windows Defender and shutdown AOL Antispyware and then run the same fix again. Also download the registry patch again and retry it again.
     
  8. ragan

    ragan Private E-2

    Must have attached an old HJT log. Re ran the fix as instructed. Still not successful with the regedit. (was I supposed to include the "REGEDIT4" text in the notepad? I did)

    attached are the new logs

    Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Everything in the quote box is part of the patch.

    Download the attached fixWLK.zip file and extract the fixWLK.reg patch from it to your C:\ folder (this is the root folder of drive C ) Thus you should have C:\fixWLK.reg when finished.

    Now click Start, Run, and enter regedit and click OK. In the Registry Editor click File and select Import. Browse to the c:\fixWLK.reg file and open it. Tell me if you get an error message or a success message. If an error occurs, provide the exact word for word error message.


    Please run msconfig and select Normal Startup! Please leave it in this mode as requested in the READ ME.

    If the registry patch worked, give me a new log from GetRunKey.
     
  10. ragan

    ragan Private E-2

    Did you attach the fixWLK.zip file? I could not find it.
     
  11. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi I have attached the previous reg fixWLK file chas mentioned for you, unzip and run as directed earlier.
     
    Last edited: Feb 17, 2008
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks Halo! I was up way to late. :eek:
     
  13. ragan

    ragan Private E-2

    Thanks to both of you. I was successful with the regedit. Here is my new Getrunkey log.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  15. ragan

    ragan Private E-2

    Before we close this thread I have two questions, please.
    1) When I run Spybot I get this problem everytime: "Microsoft.WindowsSecurityCenter_disabled" I check fix it but it comes back.
    Is this a threat or a setting that I inadvertingly changed?

    2) I don't know much about Firewalls. How do I check to see if and what firewall or walls I am using? I seem to remember one from my ISP, I think my netgear router has one too.
     
  16. ragan

    ragan Private E-2

    Oh, I have Nortons Antivirus 2007 also. It has an inbound firewall too.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a problem. It is just telling you that he default setting where Windows is your security center has been changed. This has happened because you are using Norton for your security center.

    You Norton program is not just an inbound firewall. It should be bidirectional. If it is not bidirectional, it does not provide adequate protection.
     
  18. ragan

    ragan Private E-2

    chaslang,
    Thanks for your help, I think I'm good to go now. I appreciate your help!
    How do we close this thread?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds