1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved computer is running slow, possible infection?

Discussion in 'Malware and Virus Removal Archive' started by mva5493, 2007/08/11.

  1. 2007/08/15
    mva5493

    mva5493 Well-Known Member Thread Starter

    Joined:
    2007/01/29
    Messages:
    287
    Likes Received:
    0
    I have downloaded kb891711 as well as some other update from microsoft.
    C:\WINDOWS\Downlo~1\f3initialsetup1.0.0.8-2.inf I couldn't delete because I couldn't find it, I didn't make that clear before, sorry. The errors I got before have now stopped, except for the one that says ie encountered a problem and needed to close. That doesn't happen while using the program it just comes up when closing ie. When he got the errors before it would close the program while he was using it.

    Here is the fresh hjt log:
    Logfile of HijackThis v1.99.1
    Scan saved at 1:09:03 PM, on 8/15/07
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\PNPCHK.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\LVCOMS.EXE
    C:\WINDOWS\SYSTEM\PELMICED.EXE
    C:\PROGRAM FILES\USB DISK WIN98 DRIVER\RES.EXE
    C:\PROGRAM FILES\NETZERO\EXEC.EXE
    C:\MSOFFICE\OFFICE\MSOFFICE.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\NETZERO\EXEC.EXE
    C:\PROGRAM FILES\NETZERO\QSACC\X1EXEC.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gaiaonline.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.juno.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Juno Online Services, Inc.
    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\PROGRAM FILES\NETZERO\SEARCHENH1.DLL
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL
    O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\PROGRAM FILES\NETZERO\QSACC\X1IEBHO.DLL
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
    O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [PNPCHK] PNPCHK.EXE
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [SA] C:\PROGRAM FILES\LOGITECH\QUICKCAM\SA3.EXE
    O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
    O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
    O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE" -quiet
    O4 - HKCU\..\Run: [NetZero_uoltray] C:\PROGRAM FILES\NETZERO\EXEC.EXE regrun
    O4 - Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
    O4 - Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
    O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\MSOffice\Office\MSOFFICE.EXE
    O4 - User Startup: Microsoft Office Find Fast Indexer.lnk = C:\MSOffice\Office\FINDFAST.EXE
    O4 - User Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE
    O4 - User Startup: Microsoft Office Shortcut Bar.lnk = C:\MSOffice\Office\MSOFFICE.EXE
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O8 - Extra context menu item: Display All Images with Full Quality - res://C:\PROGRAM FILES\NETZERO\QSACC\appres.dll/228
    O8 - Extra context menu item: Display Image with Full Quality - res://C:\PROGRAM FILES\NETZERO\QSACC\appres.dll/227
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRAM FILES\YAHOO!\COMMON\YIESRVC.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O14 - IERESET.INF: START_PAGE_URL=http://my.juno.com
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
     
  2. 2007/08/15
    greenday5494

    greenday5494 Inactive

    Joined:
    2007/06/14
    Messages:
    118
    Likes Received:
    0
    bad post, ignore it please
     

  3. to hide this advert.

  4. 2007/08/15
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    That file should be gone now, but if you want to make sure, execute the following commands.

    attrib -r -h -s C:\WINDOWS\Downlo~1\f3initialsetup1.0.0.8-2.inf
    deltree C:\WINDOWS\Downlo~1\f3initialsetup1.0.0.8-2.inf


    If it's gone, it will say file not found. If it's present but hidden, the first command will unhide it, the second will ask you if you're sure. ;)

    How is the comp running now?

    Time to get some protection software on that machine. AV, Firewall, etc.

    Is there anything to click for more information on the IE errors? Post exact details of the error.
     
  5. 2007/08/15
    mva5493

    mva5493 Well-Known Member Thread Starter

    Joined:
    2007/01/29
    Messages:
    287
    Likes Received:
    0
    will try the attrib command to see if it is still there.
    the computer is not as slow as it was, the only error is the ie. There is not option to get any further information on the error. Just that ie needs to close. And it only comes up when I close ie myself. I have zone alarm and avg ready to go I just wanted to make sure all the errors were fixed before installing.
     
  6. 2007/08/15
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Check out the following link for the IE error.

    http://inetexplorer.mvps.org/archive/answers_10.htm#close

    Check the link there labled ERROR REPORTING TOOL as well.

    Additionally, you can try the following.

    Try registering Internet Explorer's DLL files. Close all IE windows. Go to Start->Run type in the following command and click OK. Make sure to leave a space between regsvr32 and the filename.

    regsvr32 Urlmon.dll

    When you receive the "DllRegisterServer in urlmon.dll succeeded" message, click OK.
    Then do each of the following.

    regsvr32 shdoc401.dll
    regsvr32 Oleaut32.dll
    regsvr32 Actxprxy.dll
    regsvr32 Mshtml.dll
    regsvr32 Shdocvw.dll


    Reboot.
     
  7. 2007/08/15
    mva5493

    mva5493 Well-Known Member Thread Starter

    Joined:
    2007/01/29
    Messages:
    287
    Likes Received:
    0
    will give it a shot in the morning, the computer is in my son's room and he is already in bed. I am the only night owl here, lol.
     
  8. 2007/08/16
    greenday5494

    greenday5494 Inactive

    Joined:
    2007/06/14
    Messages:
    118
    Likes Received:
    0
    just so ya kno (im not trying to be annoying here) but possibly to save you much headaches down the line, buy windows XP, because Mircosoft is not supporting Win98 one bit anymore. Im just saying, is all. With win98, you need to be in charge of ALL of your security. Goodluck. (sorry if i was being annoying!!)
     
  9. 2007/08/16
    mva5493

    mva5493 Well-Known Member Thread Starter

    Joined:
    2007/01/29
    Messages:
    287
    Likes Received:
    0
    I would upgrade to xp but the computer is an older machine and can't handle xp. So we will be upgrading when we upgrade the computer. Not annoying, thanks for the suggestion. It would be my suggestion to anyone still running that os as well.
    Valerie
     
  10. 2007/08/16
    mva5493

    mva5493 Well-Known Member Thread Starter

    Joined:
    2007/01/29
    Messages:
    287
    Likes Received:
    0
    avg is up and running. I decided to change browsers for now, I don't care for ie anyway (I use firefox mostly on this machine). So I installed it on my son's machine as well. No problems so far, I am installing the firewall now and don't expect any problems. So I think it is just about finished. thanks for the help again Dave! Maybe if I do this often enough I can figure it out on my own.;)
     
  11. 2007/08/16
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You're most welcome. Glad I could help. :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.