system running slow

Discussion in 'Malware Help (A Specialist Will Reply)' started by rsbrowning, Jul 29, 2006.

  1. rsbrowning

    rsbrowning Private E-2

    my system is running slow - i have ran spybot and ad-aware - - i have also done a clean with ccleaner.

    i also noticed in ccleaner, there are some applications that do not show in windows control panel - add / remove programs. some of these i have no idea what they are. are you aware of any of these, and could they be part of the problem? Also, do you know how to copy the list of programs from ccleaner so that i can show you all of them?

    Here are a few that seem curious:
    BufferChm
    Common.msi
    CueTour
    CustomerResearchQFolder
    Deal Info
    Destinations
    DeviceFunctioQFolder
    DeviceManagementQFolder
    MailBox
    MDAC
    MSSoap
    Redistributed

    I have attached a report from AIDA - maybe it will help.
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (
    these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. rsbrowning

    rsbrowning Private E-2

    I have followed your instructions - - I have posted a hijackthis log and a panda log.

    I will wait for your response before I do anything (little nervous about panda report)
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Our instructions have changed since I posted. You are running HijackThis directly from the zip file. Which is exactly what we tell you not to do in the instructions. You did not run teh BitDefender Online Scan.

    [SIZE=+1]Welcome to MajorGeeks.com!

    [/SIZE] [SIZE=+1] Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments. [/SIZE][SIZE=+1]
    [/SIZE][SIZE=+1]
    [/SIZE] [SIZE=+1]- Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    [/SIZE]
    • [SIZE=+1]Make sure you check version numbers and get all updates.[/SIZE]
    [SIZE=+1]
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    [/SIZE][SIZE=+1]Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    [/SIZE][SIZE=+1]When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    [/SIZE]
    • [SIZE=+1]runkeys.txt - the log from GetRunKey.bat[/SIZE]
    • [SIZE=+1]newfiles.txt - the log from ShowNew.bat[/SIZE]
    • [SIZE=+1]CounterSpy - ONLY IF you were not able to run Windows Defender[/SIZE]
    • [SIZE=+1]Bitdefender - from step 6[/SIZE]
    • [SIZE=+1]Panda Scan - from step 6[/SIZE]
    • [SIZE=+1]HijackThis[/SIZE][SIZE=+1]
      [/SIZE]
     
  5. rsbrowning

    rsbrowning Private E-2

    I have followed the instructions and posted the files....
     

    Attached Files:

  6. rsbrowning

    rsbrowning Private E-2

    more logs.....

    I am haing proplems trying to upload bdscan.txt (I followed the instructions under Bitdefender).
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    What message are you getting when you try to attach the BitDefender log?
     
  8. rsbrowning

    rsbrowning Private E-2

    I try to attach it like the instructions indicate - however, after a few seconds I get a message the the upload was unsuccessful.
     
  9. rsbrowning

    rsbrowning Private E-2

    I followed the instructions - - I saved it as a text file (bdscan.txt). The file is rather large (2,234 KB) - could this possibly be the problem?

    It starts the download to Major Geeks - and the indicator slowly moves. But then I get a message that the file failed to download.

    Should I run it again - if so, do I need to run the other steps?
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Zip it, then attach the file.
     
  11. rsbrowning

    rsbrowning Private E-2

    Done - - I uploaded it as a .rar file.
     
  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    DId not attach. Upload as a ZIP file.
     
  13. rsbrowning

    rsbrowning Private E-2

    Here it is in Zip......
     

    Attached Files:

  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox
    - ExplorerXP

    << The installed version of Java on this compter is out-dated. Install Java Runtime Environment (JRE) 5.0 Update 7 available from http://java.sun.com/javase/downloads/index.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop. DO NOT run it as this time we will do that later in Safe Mode.
    Close Notepad.

    Confirm HijackThis default configuartion settings.
    1. Run Hijack This
    2. Click on the "None of the above, just start the program" button
    3. Under "Other stuff", click on the "Config..." button
    4. Make sure the following have check marks next to them:
    • Make backups before fixing
    • Confirm fixing & ignoring of items (safe mode)
    • Ignore non-standard but safe domains in IE (e.g. msn.com, microsoft.com)
    • Indclude list of running processes in logfiles
    • Show intro frame at startup
    5. Click on the "Back" Button

    Click the 'Scan' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files

    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  15. rsbrowning

    rsbrowning Private E-2

    I verified the HJT and ran a Scan - -

    Then I went to do this instruction that you gave me:

    5. Click on the "Back" Button

    Click the 'Scan' button. Place a checkmark in the box next to the following lines:
    Quote:
    R3 - Default URLSearchHook is missing
    O4 - HKCU\..\Run: [Ssrm] "C:\DOCUME~1\Rob\MYDOCU~1\SKS~1\chkdsk.exe" -vt tzt
    O4 - HKCU\..\Run: [Nfugfkql] C:\DOCUME~1\Rob\MYDOCU~1\FNTS~1\rundll32.exe
    O20 - AppInit_DLLs: C:\WINDOWS\system32\fast.dll

    NONE OF THESE ITEMS WERE THERE.

    I stopped at this point.
     
  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If the aren't there, then they aren't there; but continue with the fix. Removing the HijackThis lines are only a part of the fix.
     
  17. rsbrowning

    rsbrowning Private E-2

    OK - I followed the remainder of the steps as you advised me to. Onloy a few of the files / folders were there from the step re. ExplorerXP.

    Attached is a new copy of HJT
     

    Attached Files:

  18. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    << The installed version of Java on this compter is out-dated. Install Java Runtime Environment (JRE) 5.0 Update 8 available from http://java.sun.com/javase/downloads/index.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Reboot

    Post a fresh HijackThis log.
     
  19. rsbrowning

    rsbrowning Private E-2

    DONE - New HJT log posted.


    BTW - - can you give me instructions on deleting old version of Java - - I have tried to delete the file, but it woun't let me. I am simply truying to go into C:program Files and deleting the Java folder.

    I tried downloading the updated Java - The folder showed two subfolders - jre1.5.0_06 and jre1.5.0_08. I was able to delete the subfolder jre1.5.0_06. Is this going to work?
     

    Attached Files:

  20. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HijackThis log is clean.

    Delete all folders for all older versions in the Program FIles folder. The run regedit and do a search on java. Delete all registry entries for all older versions of java. Reboot.

    How is your computer running?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds