Infected Computer, Please help.

Thread Solved

Join Date: Sep 2009
Posts: 16
Reputation: dand122 is an unknown quantity at this point 
Solved Threads: 0
dand122 dand122 is offline Offline
Newbie Poster
 
0
  #21
Oct 5th, 2009
Originally Posted by BrianDSy View Post
KHALMNPR.EXE appears in the list of progams that are loaded at startup from the Registry. I can see it at the top of this page in your first message. This program is normally associated with Logitech mouse and hardware products, and allows various control and changes to these hardware devices. I can't see the whole registry entry at the top of the page, but it is there. Did you delete the program by hand, thinking that would uninstall it? The mouse software is still active then, waiting for you to reconnect the mouse. It will be listed as a Logitech program in the remove program list.

BHO stands for Browser Helper Object. It is an add-on for Internet Explorer. You can disable it by starting MSIE and clicking Tools/Add-Ons. Then look through the list of add-ons for the AVG toolbar. Disable that.
Also, you wrote above "I have a few other programs that I've tried to remove in Add/Remove Programs that say it can't find the file." That is a clear sign that the program was simply deleted from the Program Files, not uninstalled. This is the kind of thing you should never do, but Registry Mechanic may be able to fix it.
Also, according to the Hijack This log above, you are running it from a folder on the D: driver called "Program Files2". Please let us know if you have two different copies of WindowsXP installed on the same machine.
I was able to clear up the Logitech issue and so far the cursor is behaving.

Since I have a dual hard drive system and my C drive is getting pretty full, I've started saving programs to the D drive. I only have one copy of WindowsXP installed on my computer.
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,060
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 174
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei
 
0
  #22
Oct 6th, 2009
Originally Posted by dand122 View Post
So I've been able to do as suggested and I noticed an immediate improvement in the speed, but within a few hours it seemed to slow down again. Not as bad a before but still not as good as earlier.

Overall thank you for the help. Any other suggestions?
Since it slows again after a few hours then what you have to look at is what is running? How much RAM is installed? You said your "C" drive is getting full...how full?

One thing that will slow the computer is that AVG anti-virus program, it is just loaded with "stuff". I would recommend you choose another anti-virus program. Avira and Avast are both FREE, excellent and don't come with as much extra running files.
I, myself, prefer Avira and have used it several years but the choice is yours.
Do a new scan and post the log.
Last edited by jholland1964; Oct 6th, 2009 at 12:18 am.
Reply With Quote Quick reply to this message  
Join Date: Sep 2009
Posts: 16
Reputation: dand122 is an unknown quantity at this point 
Solved Threads: 0
dand122 dand122 is offline Offline
Newbie Poster
 
0
  #23
Oct 6th, 2009
Originally Posted by jacobaug09 View Post
Hello,

Most probably your system will be having registry problems.You

should Try out with a registry cleaner. It will cleaned up all temp

and unusual file and increase your computer speed. <SNIP>
I'm getting conflicting opinions about Registry Cleaners. Can they damage my files?
Are there any free ones available?
Reply With Quote Quick reply to this message  
Join Date: Sep 2009
Posts: 16
Reputation: dand122 is an unknown quantity at this point 
Solved Threads: 0
dand122 dand122 is offline Offline
Newbie Poster
 
0
  #24
Oct 6th, 2009
Originally Posted by jholland1964 View Post
Since it slows again after a few hours then what you have to look at is what is running? How much RAM is installed? You said your "C" drive is getting full...how full?

One thing that will slow the computer is that AVG anti-virus program, it is just loaded with "stuff". I would recommend you choose another anti-virus program. Avira and Avast are both FREE, excellent and don't come with as much extra running files.
I, myself, prefer Avira and have used it several years but the choice is yours.
Do a new scan and post the log.
My "C" drive is 95% full. I think I have 1 gig of RAM. Does that sound right? Where do I look to be sure?

I did get rid of AVG as you suggested and downloaded Avast.

I'll post a new scan shortly.

FYI, still having the cursor issue occasionally. If I'm running Outlook, a browser with 2+ windows open, and Powerpoint, then Powerpoint creeps along. It didn't used to.
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,060
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 174
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei
 
0
  #25
Oct 6th, 2009
Originally Posted by dand122 View Post
I'm getting conflicting opinions about Registry Cleaners. Can they damage my files?
Are there any free ones available?
Absolutely leave the Registry Cleaners alone. Learned this years ago from a fellow I learned much of what I know today and have followed his opinion on this which is the following:
. Were registry cleaning *really* able to improve performance, the developers of these utilities would support their marketing claims with some form of empirical evidence (performance prior to cleaning -vs- performance post cleaning). But have you ever seen such benchmarking? No, and that's because registry cleaning does *not* improve perforance. Think about it ... programs such as SpywareBlaster dump 1000's of entries into the registry without causing any performance hit. Similarly, the fact that registries tend to hold significantly more information than in years gone by (bigger hard disks = more programs installed/data stored = more registry entries) has not resulted in systems slowing to a crawl.

Using an automated cleaner to try to fix a problem is akin to using a shotgun to remove an appendix. The best way to deal with (possibly) registry-related issues is is to throughly research the problem and then use regedit to make any necessary changes and/or deletions (having first set a restore point or created a backup).
Now having your "C" 95% full will absolutely slow the computer, I am surprised it is actually running! You need to go through there and get some of that off of there. What all is it? Go through and decide what is needed and what is not. Burn pictures and music to disks and get it off entirely. Remove programs you never use. Clean Temp files and the like.
To find out how much RAM is on there Right Click My Computer and choose Properties. The first page that opens will give you that information right below where you see Computer:
1GB is an ok amount but more would be better. But key right now is cleaning out that "C" drive.
Reply With Quote Quick reply to this message  
Join Date: Sep 2009
Posts: 16
Reputation: dand122 is an unknown quantity at this point 
Solved Threads: 0
dand122 dand122 is offline Offline
Newbie Poster
 
0
  #26
Oct 6th, 2009
Originally Posted by jholland1964 View Post
Now having your "C" 95% full will absolutely slow the computer, I am surprised it is actually running! You need to go through there and get some of that off of there. What all is it? Go through and decide what is needed and what is not. Burn pictures and music to disks and get it off entirely. Remove programs you never use. Clean Temp files and the like.
To find out how much RAM is on there Right Click My Computer and choose Properties. The first page that opens will give you that information right below where you see Computer:
1GB is an ok amount but more would be better. But key right now is cleaning out that "C" drive.
It is 1GB of RAM. I've tried to go through get rid of programs I don't use as well as clean temp files and such. I've also been trying to utilize my "D" drive. Each drive is 95GB. I have a lot of music on my iTunes I think that is a big part of the problem. I tried moving the iTunes folder over to the "D" drive but it didn't recognize it when I did.
Reply With Quote Quick reply to this message  
Join Date: Sep 2009
Posts: 16
Reputation: dand122 is an unknown quantity at this point 
Solved Threads: 0
dand122 dand122 is offline Offline
Newbie Poster
 
0
  #27
Oct 6th, 2009
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:11:13 PM, on 10/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Internet Content Filter\SafeEyes.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Documents and Settings\Dan\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
D:\Program Files 2\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lds.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Safe &Eyes Toolbar - {430DDB4F-38CC-4E91-AF33-4157334EC937} - C:\Program Files\Internet Content Filter\setoolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [ICF] "C:\Program Files\Internet Content Filter\SafeEyes.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - S-1-5-18 Startup: AutoTBar.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: AutoTBar.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O10 - Unknown file in Winsock LSP: icf.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1170797693812
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 7458 bytes
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,060
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 174
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei
 
0
  #28
Oct 6th, 2009
You know to see what IS using all that space, you might try this program DiskPie I have used it before when cleaning out computers. It tells you exactly what IS taking up all the space on there. Read that PC Computer article about it and if you decide to use it then you can download the zip file right there at the top of page one. It does give a good picture of exactly what is hogging and that physical space on the drive.
Reply With Quote Quick reply to this message  
Join Date: Oct 2009
Posts: 1
Reputation: Hollyecho is an unknown quantity at this point 
Solved Threads: 1
Hollyecho Hollyecho is offline Offline
Newbie Poster

Get rid of norton.

 
0
  #29
Oct 8th, 2009
Two antivirus on the same computer (even if one is expired) do not play well together. (period!)

Go to:
http://service1.symantec.com/Support...05033108162039

and download the removal tool - Get rid of norton. Till norton has a smaller footprint, easier to manage, and plays well with wireless better, it is good just not to use it.

THEN - uninstall AVG (I will have you reinstall it after that part of your computer is clean)

THEN:
Open your RUN command, type msconfig
click on the startup tab (PAY ATTENTION - ONLY the startup tab, do not 'clean' anywhere else) UNCHECK EVERYTHING - yes, that is what I said - UNCHECK EVERYTHING. If windows needs it to operate it will "re-check" itself on reboot. - then reboot.

THEN:
After these three things are done, REINSTALL AVG or Avast (I kinda like avast better, for several various reasons I will not go into now) - Avast is also free to use. (reboot if you installed Avast - AVG you don't have to)

THEN :
Download and install C-Cleaner - update it, then USE IT !!! Keep using it till 0 bytes removed comes up, and then use its registry cleaner - keep running it till NO PROBLEMS Found comes up (i dont' have a book to tell you why, just that it works)

THEN:
Update (very important ALWAYS UPDATE FIRST) - and run Malwarebytes, if it finds things and needs to reboot - do so, then UPDATE and run malwarebytes again (till it finds nothing).

THEN:
Post if you are still having latency problems.


Hollyecho Montgomery
Microsoft Certified
A+
20 years experience field tech
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,060
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 174
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei
 
0
  #30
Oct 8th, 2009
Hollyecho, This thread was begun 8 days ago and now you are covering a LOT of OLD ground here advising the very same steps which have all ready been fully completed:

AVG has all ready been removed and replaced by Avast as noted HJT log in post #14. All the Norton stuff you noted have all ready been taken care of as noted by the poster in post #15.

Unnecessary start ups were listed in post #17 and recommendations on how to stop these were noted AND also taken care of as demonstrated by the latest HJT log.

Malwarebytes' was all ready updated run over 1 week ago and came up clean in post #3. Finally poster DID post he is continuing to have problems in post #22 2 days ago. He also posted his hard drive is 95% FULL and he only has 1GB of RAM. I gave him my recommendations yesterday and he has yet to post back.
Last edited by jholland1964; Oct 8th, 2009 at 11:23 am.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC