Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Is Spyware, etc. causing system degradation?

[Fixed] Hijackthis! Logs - [Fixed] Is Spyware, etc. causing system degradation? posted in the Security & Safety forums; I have a Dell 8300 desktop with XP Professional SP2. The computer is always running in "overdrive" -- you can hear the CPU running high and when I check the ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-04-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 23
reillytj - See this Members User comments on their Profile page
Default [Fixed] Is Spyware, etc. causing system degradation?

I have a Dell 8300 desktop with XP Professional SP2. The computer is always running in "overdrive" -- you can hear the CPU running high and when I check the CPU usage, Explorer.exe is grabbing 50%. The PC sounds like it would if a program was doing something intensive but I have no idea what is happening. Recently another related issue has arisen. If I try to boot into Safe Mode, the dialog box that asks if you are okay with running Safe mode comes up but before I can click OK/Yes, the dialog disappears, I get no desktop (explorer.exe is not an active process). Something is amiss and I need urgent help. Here is the Hijackthis log from today.
Please help and feel free to email me directly with any tips, etc.
Tim Reilly

email: Edit: Sorry Tim, not a good idea to post your email here, we answer all posts in the forum. LGW
Attached Files
File Type: txt HJT log.txt (13.2 KB, 1 views)



Last edited by ladygreenwitch; 01-04-2006 at 05:06 PM.
  #2  
Old 01-04-2006
ladygreenwitch's Avatar
Administrator
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,690
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hi Reilly,

Welcome to PCHF. We have a wonderful group of techs here, and I am sure that we will be able to help you determine what's causing your problems.

In the future, please only post logs as attachments. I will fix your post for you.

Please follow the instructions for PreWork in my signature, making SURE to unzip HijackThis into its own folder before running it.

Look forward to your reply,

TTFN

LGW


  #3  
Old 01-04-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Reillytj , welcome to PCHF.



When in safemode , see if you can start explorer and apps like this:

task manager/file/new task (run)/explorer.exe
task manager/file/new task (run)/hijackthis.exe
task manager/file/new task (run)/ect

If not , then do the fix in normal mode.

Please download Process Explorer by Systernals from HERE.

Also download KillBox by Option^Explicit from HERE.

And download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original Hosts file.

Then boot up in SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.

Unzip Process Explorer and double click on procexp.exe
In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.
Once you see this screen click on each instance of reg.dll once and then click the kill button.
After you have killed all of the reg.dll's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of reg.dll then click the kill button.
Once you have done that click OK again.

Next run HijackThis and place a check beside each of the following:

O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\reg.dll
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.sidestep.com/get/k00719/sb02a.cab
O20 - Winlogon Notify: reg - C:\WINDOWS\reg.dll
Now click fix checked and close HijackThis.


Please copy the text in the quote below, and paste it into a blank notepad window.

Save it as vundo.reg and in the "save as" type box choose "all files".
Once you have saved it double click it and allow it to merge with the registry.

Code:
REGEDIT4 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}] 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] 
[-HKEY_CLASSES_ROOT\CLSID\{581F22DA-7202-4F21-AEF3-114787156016}] 
[-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}] 
[-HKEY_CLASSES_ROOT\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}] 
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents] 
[-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1] 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents] 
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1]

Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\reg.dll

Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)

After your computer has rebooted run Hijackthis again and attach the new Hijackthis to a post , log instead of copying it to a post please.

Also do you know that Cisco Systems VPN Client is running on youre pc?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 01-04-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 23
reillytj - See this Members User comments on their Profile page
Default

Joe,

Thanks for the instructions. I will try them ASAP. I have one question. You say to try executing the explorer.exe, Hijackthis, and ect in safe mode from the task manager. Then you say, "If not , then do the fix in normal mode.". Do you mean to apply all of the instructions following that in normal Windows mode instead of in safe mode? Or, keep trying to execute them in Safe Mode? Just want to be sure before I start. One aside. I booted up into a command prompt last week and tried to delete the C:\Windows\reg.dll file but the delete failed because the file was in use from other processes. I look forward to killing it from these processes and then deleting it. Let me know about my question above. Again, many thanks.

Tim


  #5  
Old 01-04-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

If you can follow the fix instructions in safemode by starting explorer , or running the tools the way i mentioned then please do so , but if you cant , then you can do it in normal windows mode.


And after you followed my instructions the reg.dll wil be gone.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 01-11-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 23
reillytj - See this Members User comments on their Profile page
Default

Joe,

I have followed your instructions and explorer.exe is clean (no more reg.dll). Explorer.exe has not grabbed 50% of the CPU since last night so I thank you for your help. Where does reg.dll come from? Here is the attached Hijackthis log for your review.

Tim
Attached Files
File Type: txt hijackthis after reg.dll 1-10-2006.txt (12.3 KB, 1 views)


  #7  
Old 01-12-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Its gone indeed. Youre hjt log is clean.


Where it comes from , good question. You have a AV , anti spyware , a firewall and windows is updated. So the most commen ways are blocked on youre pc.

But it is known to be installed by visiting a Web site link contained in a spammed email , although it could also be installed by an other app , or youve clicked on the wrong popup ect.


But you are rid of it. :cool:


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 06:28 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Credit Counseling
Credit Advisors has been helping people with Credit Counseling for over 40 years.

Debt Consolidation
Get out of debt fast with a debt conoslidation loan.

News
News and events from The Mirror.