weird stuff...requesting help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bairdo, Oct 5, 2006.

  1. Bairdo

    Bairdo Private E-2

    Hello, can someone help me out? My in-laws gave me their computer to look at because it was doing weird stuff, going extremely slow, etc. Also the USB ports stopped working (not sure if it is related). I read the "read-me first" thread and followed the instructions. Here are my attachments. I appreciate any and all help.

    Bairdo
     

    Attached Files:

  2. Bairdo

    Bairdo Private E-2

    Here are the other required files. thanks again.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Slow PCs are not necessarily malware problems. Especially when I see things like AOL and McAfee installed. They are resource hogs!

    You did not follow the directions in step 0 of the READ ME. The below should be uninstalled:
    Viewpoint Toolbar

    I also recommend uninstalling WeatherBug unless it is an absolute necessity. It will slow things down and it is consider by many people to fit into the malware family due to the adware from it and it several hundred entries into the registry which also affects performance.

    You also did not follow all the directions in step 7 of the READ ME. I see MSconfig running to control startups. You must not do this. The PC must be in Normal Startup mode. Fix this now but do not attach a new log yet. Wait until after working thru my procedure below.


    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    Java 2 Runtime Environment Standard Edition v1.3.1
    Java 2 Runtime Environment Standard Edition v1.3.1_02

    Do you use CompuServe in addition to AOL? If not then uninstall the CompuServe software.


    Note that in the log from ShowNew the uninstall programs list shows that eTrust EZ Armor and EZ Firewall are installed. EZ Armor will conflict with the McAfee Security Center that is installed and combined that will slow the PC down. This is part of why step 3 of the READ ME instructs you to only have one antivirus application.
    • Is eTrust really still installed?
    • Does the McAfee Software being used also have a firewall? If so, you then have two firewall which is also a bad idea.
    Make sure you answer these questions!


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    These next three are not malware but are not need to load at startup and waste system resources.
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    BigFix (also not malware) is a huge waster of system resources and can slow a PC down a ton. I really recommend uninstalling it but you may like to use it. If that is that case, just have HJT fix the below line which will stop it from loading at startup. Then you can just run the program manually when you need it (which may be never).
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe

    EasyShare is also a big waste of resources. Why not stop it from loading at startup by fixing the below line too. You can also run this manually when needed.
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe

    After clicking Fix, exit HJT.

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    After reboot, find and delete the below files:
    C:\Documents and Settings\Sarah\Local Settings\Temp\p2psetup.exe
    C:\WINDOWS\system32\P2P Networking v124.cpl

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\temp
    C:\Documents and Settings\Brenda\Local Settings\Temp

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Oct 6, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds