MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: Computer slow and popups have resumed
December 08, 2019, 06:34:19 AM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
December 08, 2019, 06:34:19 AM

Login with username, password and session length
 Featured Sites:
News
New  Got pics of your modded PC or want to show off your cool desktop, visit our new Show & Tell forum!
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: Computer slow and popups have resumed  (Read 1138 times)
Qlingk
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Female
Posts: 13


Bookmark and Share

View Profile
« on: October 26, 2005, 11:27:25 PM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version:  WP
Problem Application Name & Version:  All, especially IE
Problem Hardware Make & Model:  HP Pavillion 505n
Error Messages:  None


Here's my log.  I'm writing on behalf of my husband who went to naughty sites and slowed the computer down.  Please tell me what to clean up (and I have all of the other programs--Ewido, Cleanup, etc.  I just don't want to clean out anything that should stay.  Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 7:21:11 PM, on 10/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\winxp32.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\atlbl.exe
C:\Documents and Settings\Owner\My Documents\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {03517127-00C0-4EA8-8A0D-A0DA652FE0AB} - C:\WINDOWS\iekl32.dll
O2 - BHO: Class - {0B01F3E9-B4C0-2C24-AA3E-F733655C3C34} - C:\WINDOWS\atlea32.dll
O2 - BHO: Class - {1EDD53C7-E5D0-7FC7-55FE-8C72FF985424} - C:\WINDOWS\system32\sdkcq.dll
O2 - BHO: Class - {388C2CE8-D451-ED6C-8451-CE75E8028210} - C:\WINDOWS\sdkqm32.dll
O2 - BHO: Class - {3EAAB545-5DA5-D593-1DC7-5C6B1EC765D8} - C:\WINDOWS\system32\sdkao.dll
O2 - BHO: Class - {3F821BB6-B7DE-4279-1176-BFC66AFDF827} - C:\WINDOWS\mfcbu.dll
O2 - BHO: Class - {52E3BD52-DF68-05E9-73D4-FEDA8DF83C3B} - C:\WINDOWS\winao.dll
O2 - BHO: Class - {5FD30CE7-0DCC-51E7-8545-3F1D6198A4F5} - C:\WINDOWS\system32\iegh32.dll
O2 - BHO: Class - {7A988D06-D68D-D011-5F0D-3C5AC44C5927} - C:\WINDOWS\system32\netyh.dll
O2 - BHO: Class - {7E397AF9-83B5-CF28-F260-4576822567B8} - C:\WINDOWS\system32\appmw.dll
O2 - BHO: Class - {7FBC1A44-1179-6601-4CA4-F9E5BA9627AC} - C:\WINDOWS\system32\atlhv.dll
O2 - BHO: Class - {81A4261C-171F-77DC-FD21-B540588D285C} - C:\WINDOWS\system32\ieqv32.dll
O2 - BHO: Class - {85F30D49-60FD-6D87-DB29-3C75DD93BD56} - C:\WINDOWS\apigs32.dll
O2 - BHO: Class - {97CFEC37-F4BD-D7AD-DE93-8818A2F7F992} - C:\WINDOWS\sysyi.dll
O2 - BHO: Class - {A81C69CD-6D37-624F-72D7-17655E58CA0C} - C:\WINDOWS\system32\javaqz.dll
O2 - BHO: Class - {B32D2588-F2B7-0679-4EC0-427E7F172FD3} - C:\WINDOWS\system32\appmb32.dll
O2 - BHO: Class - {D30F1D3E-9A80-B7B8-660D-9D89FEB47648} - C:\WINDOWS\system32\msyp32.dll
O2 - BHO: Class - {F22ABCC8-DA46-6EFF-B0D2-2B1D0647AB7A} - C:\WINDOWS\d3qu.dll
O2 - BHO: Class - {FF22754C-BE20-6A0D-3A0A-B818CBA44118} - C:\WINDOWS\system32\d3gc.dll
O2 - BHO: Class - {FF6D6BE4-0644-EFEF-B7B9-4B57D7A01483} - C:\WINDOWS\apifa.dll
O4 - HKLM\..\Run: [winxp32.exe] C:\WINDOWS\winxp32.exe
O12 - Plugin for 4
Logged

~RDW~
You're only immortal for a limited time.
Pancake
Global Moderator
Hero Member
*****

Karma: +78/-0
Offline Offline

Gender: Male
Posts: 3915


Bookmark and Share

View Profile
« Reply #1 on: October 27, 2005, 02:32:28 AM »

Hi and Welcome
Looks like a major clean out to be done.


It may help you if you print out or copy this page for easy reference.. Make sure to work through the fixes in the exact order its listed. Please Keep your browser and all open programs closed (except firewalls and antivirus) when you are carrying out the fixes



Download any of the required programs before attempting to start any of the fixes.



SHOW HIDDEN FILES AND FOLDERS.
To show hidden files instructions (WinXP)
Doubleclick My Computer | Tools | Folder Options | View tab
Select Show Hidden Files and Folders
Uncheck Hide extensions for known file types
Uncheck Hide protected operating system files (Recommended)
Select Apply to All Folders | Yes | Apply | OK
------------------------------------------------------------------

Files highlighted in BLACK  will need to be removed from your hard drive.

  -----------------------------------------------------------------------

Download and run AboutBuster,Ewido & CWShredder (check for updates) for a preliminary cleanup first.Some files below may not be present after running the above programs.Full instructions below.



----------------------------------------------------------------------

How to setup  AboutBuster version 5

Download AboutBuster

Then unzip all files from the zip folder to a folder or your desktop. Start it and press the OK button. Then hit the update button and a new screen will appear. On that screen press the Check for Updates button..

To scan your machine, press the Start button and then press OK. The program should start scanning. When it is done, press the exit button and reboot. Once rebooted run About:Buster one more time.

This program is updated often so you should always use the built in update feature before you scan with it.


------------------------------------------------------------------------
How to install and run CWShredder

Download CWShredder
Choose the stand alone version. This is free.
Save cwshredder.exe into its own directory, NOT in a TEMPorary folder or on the DESKTOP.
I recommend, c:/program files/CWShredder/
Close all browsers
Unzip into same directory
Doubleclick CWSInstall.exe
Click <Check for updates> and let it install all updates
Click <Fix>
Click <Next>
Close CWShredder//

----------------------------------------------------------------------

Please download Ewido Security Suite and do a scan when you first get into Safe Mode.

 Install Ewido Security Suite.
 When installing, under 'Additional Options' uncheck: "Install background guard" and  "Install scan via context menu"

To open the main screen double click the icon on the desktop.
 
 You will get a warning 'Database could not be found!'.(only if no updated have first been installed) Click OK.

 Update to the latest definition files.On the left of the main screen click Update.Then click on Start Update.Let it complete the updates.

Now Click on Scanner and Click on Complete System Scan and the scan will start.

During some scans  it may find cases of false positives so you will need to step through the process of cleaning files one-by-one.

If a file is detected you KNOW to be legitimate, select None as the action. Do NOT select 'Perform action on all infections'
 
If you are unsure of any entry found play safe and select None as the action.
Press the button marked Save Report

Save the report .txt file to your desktop or somewhere you can find it.Post it back with your next HJT log.


------------------------------------------------------------------------------

Please start by putting your computer in SAFE MODE.  During reboot, tap the F8 key. Select Safe Mode and then run HJT.
--------------------------------------------------------------





Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click End Process for each one if they are still listed.

winxp32.exe
atlbl.exe

-----------------------------------------------------------------


Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\rvejf.dll/sp.html#14044
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {03517127-00C0-4EA8-8A0D-A0DA652FE0AB} - C:\WINDOWS\iekl32.dll
O2 - BHO: Class - {0B01F3E9-B4C0-2C24-AA3E-F733655C3C34} - C:\WINDOWS\atlea32.dll
O2 - BHO: Class - {1EDD53C7-E5D0-7FC7-55FE-8C72FF985424} - C:\WINDOWS\system32\sdkcq.dll
O2 - BHO: Class - {388C2CE8-D451-ED6C-8451-CE75E8028210} - C:\WINDOWS\sdkqm32.dll
O2 - BHO: Class - {3EAAB545-5DA5-D593-1DC7-5C6B1EC765D8} - C:\WINDOWS\system32\sdkao.dll
O2 - BHO: Class - {3F821BB6-B7DE-4279-1176-BFC66AFDF827} - C:\WINDOWS\mfcbu.dll
O2 - BHO: Class - {52E3BD52-DF68-05E9-73D4-FEDA8DF83C3B} - C:\WINDOWS\winao.dll
O2 - BHO: Class - {5FD30CE7-0DCC-51E7-8545-3F1D6198A4F5} - C:\WINDOWS\system32\iegh32.dll
O2 - BHO: Class - {7A988D06-D68D-D011-5F0D-3C5AC44C5927} - C:\WINDOWS\system32\netyh.dll
O2 - BHO: Class - {7E397AF9-83B5-CF28-F260-4576822567B8} - C:\WINDOWS\system32\appmw.dll
O2 - BHO: Class - {7FBC1A44-1179-6601-4CA4-F9E5BA9627AC} - C:\WINDOWS\system32\atlhv.dll
O2 - BHO: Class - {81A4261C-171F-77DC-FD21-B540588D285C} - C:\WINDOWS\system32\ieqv32.dll
O2 - BHO: Class - {85F30D49-60FD-6D87-DB29-3C75DD93BD56} - C:\WINDOWS\apigs32.dll
O2 - BHO: Class - {97CFEC37-F4BD-D7AD-DE93-8818A2F7F992} - C:\WINDOWS\sysyi.dll
O2 - BHO: Class - {A81C69CD-6D37-624F-72D7-17655E58CA0C} - C:\WINDOWS\system32\javaqz.dll
O2 - BHO: Class - {B32D2588-F2B7-0679-4EC0-427E7F172FD3} - C:\WINDOWS\system32\appmb32.dll
O2 - BHO: Class - {D30F1D3E-9A80-B7B8-660D-9D89FEB47648} - C:\WINDOWS\system32\msyp32.dll
O2 - BHO: Class - {F22ABCC8-DA46-6EFF-B0D2-2B1D0647AB7A} - C:\WINDOWS\d3qu.dll
O2 - BHO: Class - {FF22754C-BE20-6A0D-3A0A-B818CBA44118} - C:\WINDOWS\system32\d3gc.dll
O2 - BHO: Class - {FF6D6BE4-0644-EFEF-B7B9-4B57D7A01483} - C:\WINDOWS\apifa.dll
O4 - HKLM\..\Run: [winxp32.exe] C:\WINDOWS\winxp32.exe
O23 - Service: Network Security Service ( 11F
« Last Edit: October 27, 2005, 02:35:32 AM by Pancake » Logged

An Australian Member of

EDDY
Qlingk
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Female
Posts: 13


Bookmark and Share

View Profile
« Reply #2 on: October 27, 2005, 01:23:26 PM »

Here's what I got...

Logfile of HijackThis v1.99.1
Scan saved at 9:20:44 AM, on 10/27/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Owner\My Documents\Hijackthis\HijackThis.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O12 - Plugin for 4
Logged

~RDW~
You're only immortal for a limited time.
Pancake
Global Moderator
Hero Member
*****

Karma: +78/-0
Offline Offline

Gender: Male
Posts: 3915


Bookmark and Share

View Profile
« Reply #3 on: October 27, 2005, 11:57:58 PM »

Thats all looking fine.Your log is now clean.

Please use this as   Your Guide to Spyware Prevention and use the tools provided.
Logged

An Australian Member of

EDDY
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page April 11, 2017, 01:13:23 AM