System running slowly.

Discussion in 'Malware Help (A Specialist Will Reply)' started by malima, May 18, 2007.

  1. malima

    malima Private E-2

    I have followed the instructions in Basic maintenance and READ AND RUN ME FIRST. Here are my logs - thank you for your help!
     

    Attached Files:

  2. malima

    malima Private E-2

    ....
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download, install and run:
    CWShredder.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    O4 - HKLM\..\RunServices: [Microsoft Security Panagers] jnpejwvop.exe
    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
     
  4. malima

    malima Private E-2

    Thank you very much for taking the time!!

    CWShredder didn't find anything. Here are the logs:
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do a search for ---> IHSVC.EXE and if found, delete it!

    Run HJT and have it remove/fix this item:

    O4 - HKLM\..\Run: [Internet Help Svc] IHSVC.EXE

    Just exit HJT after fixing.

    Can you tell me what these are:
    Windows-pc-s›gning 3.01?
    Sikkerhedssoftware -----if you do know, remove the reg. key from the fix.
    EBJSecurity ----- if you do know, remove the reg. key from the fix

    Now.....because you have a haxdoor infection (stay off the web with this computer if possible), download and run Spyware Doctor ...it will not fix anything as it is a trial version, but it will give you a log...attach it to your next post.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT
    * Spyware Doctor log
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry ...bad day ...the reg. fix should read:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

     
  7. malima

    malima Private E-2

    Windows-pc-søgning = Windows Desktop Search - It appeared after I installed Office 2007.
    Sikkerhedssoftware = Safety software /Security software. I'm not sure exactly what it is, though.
    EBJSecurity - I don't know.

    Thanks, I'll follow your instructions and post the log files. I'm not particularly good at this, so I don't know what a haxdoor infection is... But I'll stay off the internet except for the necessary access to this forum.

    I've been using drivehq.com to synchronize some documents between this pc and my network drive at work (not since cleaning this pc), so I guess I should delete the files on drivehq and the network drive and clean the other pc before synchronizing again?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok....yes I would be concerned about the other computer.

    Please do a search and find all traces of the Security software and EBJSecurity.

    I'll get back with additional instructions.
     
  9. malima

    malima Private E-2

    I couldn't find the ihsvc.exe.

    I have attached the log from HJT.

    I'm not sure how to get the log from Spyware Doctor or how to copy the results into a text file, so I've attached a screenshot of the results...please let me know if there's some other way to do this.

    I just remember that EBJ is part of the software for my bank's web access. I think Sikkerhedssoftware is also related to that, since I found:

    ActiveX sikkerhedssoftware Control in C:/Windows/Downloaded Program Files.

    In the properties, there is mention of the bank's website.

    I deleted both from the fixME.reg.
     

    Attached Files:

  10. malima

    malima Private E-2

    ....
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Chas has informed me that the GetRunKeys is giving a false positive for the Haxdoor infection. So we will want you to download and run the latest version.
    Uninstall the old version as well as Spyware Doctor and Counterspy.

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Internet Help Svc] IHSVC.EXE

    Just exit HJT after fixing the item.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:

    * Delete on Reboot
    * then Click on the All Files button.*(or on the folders option)*
    * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\drivers\ikfile~1.sys
    C:\WINDOWS\system32\drivers\iksysflt.sys
    C:\WINDOWS\system32\drivers\iksyssec.sys
    C:\WINDOWS\system32\drivers\ikfile~2.sys

    * Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    * Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.

    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey --- the latest version!
    2. ShowNew
    3. HJT
     
  12. malima

    malima Private E-2

    I have uninstalled GetRunKey, Spyware Doctor and CounterSpy.

    I have installed Comodo Firewall instead of Windows Firewall, since I just read the advice on firewalls. I hope I haven't ruined the process by installing it at this point...

    I had some problems with unresponding programs when trying to shut down after unistalling the spyware tools and installing the firewall.

    I couldn't find this line in HijackThis:

    O4 - HKLM\..\Run: [Internet Help Svc] IHSVC.EXE

    So I didn't do anything further... I have attached the log from HJT.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run new scans with GetRun and ShowNew and attach them.....
     
  14. malima

    malima Private E-2

    Ok, here they are.

    There were two error messages when I ran GetRunKeys - the translation would possibly be something like "unable to find the registry key".
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean. You may uninstall any programs we had you download.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  16. malima

    malima Private E-2

    Thank you so much for the amazing help! My computer is now running smoothly again!
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem....safe surfing,
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds