I Hope I did this correct. I have a Dell XPS 420 stock except for an internal modem I put in about 2 months ago. It is running 4 gig memory and I have ran Trand micro pc cillin since purchase I have never had any virus problems or spyware reported. I do use SpySweeper to check for malware and spies, not viruses. I stay up to date on my windows updates. The problems I am having are that the system takes about 3 to 5 minutes to shut down, system locks 2 or more times per day and there is no way to shut it down because everything is inactive. The only way to restart is to push the button and then restart it. Spybot takes about 15 minutes to start sometimes longer and I do use the 1.5 version. If I run a backup to external drive I can expect a shadow copy of 150 gig to take about 8 hours on a Maxtor 7200rpm external drive. Disk defrag takes 6 to 8 if I tell it to do both drives being 1 internal and 1 external. I am using Vista Ultimate 32 bit.
I hope I did things right as instructions go for the HJT log and please someone look over and see if I have done something wrong. Thanks William
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:00:52 PM, on 6/7/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal
Welcome to the DCF forums. My name is SpotCheckBilly (SCB for short) and if you still need assistance I'll be happy to help you out.
===Very Important===
The instructions in this thread have been specifically designed for THIS USER'S MACHINE ONLY . You should not use these instructions to clean your machine. Doing so could cause irreparable damage to your machine. If you need assistance, please start your own thread.
=================
A couple of important things to keep in mind during our fix.
Please >>DO NOT<< run any scans/tools or other fixes unless I ask you to.
If you are running P2P filesharing program(s). My recommendation is you uninstall it/them.
If you are running any cracked/pirated software, REMOVE it before proceeding. Many helpers -- myself included -- will not assist you if you are using such software.
Remember, we are in this process together. We must cooperate with each other or the fix will surely fail.
If there is something you don't understand or or are unsure of -- Please Do not skip it. Instead, take a moment to ask. With some infections skipping a step can be disastrous.
That being said, let's get started. :)
There doesn't appear to be a lot going on in your log that might be malware related. Let's take care of a couple of minor things, then we can dig a little deeper. You have two "active" anti-malware modules running --Spybot Search & Destroy's Tea Timer and Windows Defender. These programs seldom get along together and often will result in conflicts as well as reduced overall system security. Since Vista Comes with Windows Defender already installed I would recommend that you disable Tea Timer. You can certainly keep Spybot S&D as an "on demand" scanner if you like. Same thing goes for SpySweeper.
We need to disable Spybot S&D "Tea Timer" as it may interfere with the fix. Please do the following:
1. Run Spybot-S&D 2. Go to the
Mode menu, and make sure "
Advanced Mode" is selected
3. On the left hand side, choose
Tools ->
Resident 4.
Uncheck "
Resident TeaTimer" and
OK any prompts<---
Note: DO NOT reenable after we are finished.
Please disable
Windows Defender Real Time Protection as it may interfere with the fix. To disable Windows Defender:
Open Windows Defender
Click Tools
Click General Settings
Scroll down to Real Time Protection Options
Uncheck Turn on Real Time Protection (recommended)
Close Windows Defender
Once your log is clean you can re-enable Windows Defender Real Time Protection.
Run
HiJackThis and click "
Do a system scan only", then check(tick) the following, if present:
O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
O15 - Trusted Zone: http://us.creative.com O15 - Trusted Zone: http://ups.surveyrouter.com O15 - Trusted Zone: http://help.wildblue.net O15 - Trusted Zone: http://myaccount.wildblue.net <---
Note: it's never a good idea to put
any sites into the Trusted Zone. This is a well-known point of entry for malware.
With all windows closed except
HiJackThis, click "
Fix checked".<---
Note:
Post back a fresh
HijackThis log and let me know if your symptoms have improved. If you're having any other symptoms, please let me know about those as well. :) -- SCB
SpotCheck Billy thanks for yout time and I'm sorry about delay but was out of town when reply came in. I am really greatful for your help and I am sorry if I didn't reply to you derectly but wife pushing me. Let me know what else I may need to do I am still having eratic lockups and slow shutdowns but startup is improving, I guess I need to shut down some services but unsure of which. Thank you
SORRY THIS IS NOT WHAT YOU WANTED. I WILL GET THIS CORRECTED ASAP
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:00:52 PM, on 6/7/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Message Edited by Do_Not Know on 06-18-2008 11:06 PM
The post on 6-18-08 from Do_Not Know has not been fixed. It is the same as the first one sent in. Please ignore this and I hope to upload the correct one soon. I am very sorry for wasting anyone's time and I will try my best not to do this again in such a hurry and most of all I would like to apologize to SCB please forgive me.
Message Edited by Do_Not Know on 06-18-2008 11:09 PM
The reason we Do_Not Grow is because WE Do_Not Know.
If you can answer our post it really helps us most.
SCB I hope this is what you need. System seems to start much faster now but the biggest problem I see is that I still have the occasional freezes where all you can do is shutdown with power button and also after I tell it to shutdown and the shutdown screen is present it takes about 3 to 5 minutes to turn itself off. You have been a big help and if you can offer any more help I would appreciate this. And this has nothing to do with my problem but do you know what the largest processor I can put in this XPS 420? And too it says it has 4 gb ram but was curious what it can support on Vista Ultimate 32 bit. I believe if I put the 64 bit on it can hold more. I only have 4 slots and they are all full with 1G 800 chips. Anyway thanks again and I really am sorry if I caused any problems or posted in wrong forum about the other questions.
William
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:00:14 AM, on 6/19/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal
No need to apologize for anything. We all have priorities and do things in the best order that we can. I, too, have a wife and I know exactly what you mean. :)
OK, let's clear out some other stuff.
Please disable Windows Defender Real Time Protection as it may interfere with the fix. To disable Windows Defender:
Open Windows Defender
Click Tools
Click General Settings
Scroll down to Real Time Protection Options
Uncheck Turn on Real Time Protection (recommended)
Close Windows Defender
Once your log is clean you can re-enable Windows Defender Real Time Protection.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit von the Main menu to close the program.
Next, go to Start->Run and type "Services.msc" (without quotes) then hit Ok
1. Scroll down and find the service called WebrootSpySweeperService. 2. Right-click=> Stop. 3. Right click=>Properties area 4. Under the General Tab, in the "Startup Type" drop-down box select Disabled. 5. Hit Apply=>Ok and close any open windows.
Run HiJackThis and click "Do a system scan only", then check(tick) the following, if present:
R3 - URLSearchHook: Gadgetbar Toolbar - {ad8088d4-219c-40db-b16a-5e53261bed3d} - C:\Program Files\Gadgetbar\tbGad1.dll <---Note: This has been associated with adware/spyware. Uninstall via Start=>Control Panel=>Add/Remove Programs, first.
The following are OPTIONAL. The following start up items are either well known resource hogs, can be launched manually when needed, or both. "Fixing" them with HijackThis may improve overall system performance.
With all windows closed except HiJackThis, click "Fix checked".
From "Safe Mode", (Reboot if necessary.) locate and delete the following item(s), if present. Make sure you're able to view system and hidden files/ folders:
To show hidden files :
1. Click Start=>Control Panel=>Folder Options=>View tab. 2. Select "Show hidden files and folders" 3. Clear the check mark in "Hide protected operating system files"=>Yes to confirm. 4. Click Apply=>OK. 5. Close Control Panel.
folders...
C:\Program Files\Gadgetbar
Note that some of these file(s) may not be present.
As far as the hardware upgrades go, DCF has boards dedicated to just such things. Since they are Dell boards, they specialize in Dell computers. Post your questions at General Hardware or Upgrade Hardware.
For lots of good information regarding what services/processes you need to have running -- depending on how you use your machine -- please visit Black viper's web site.
Finally, I would like you to download and run a scan with Malwarebytes Anti-Malware. This is an excellent on-demand scanner which is updated almost daily and is also free.
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform Full Scan
Click Scan.
When the scan is complete, click OK, then Show Results to view the results. If Malware is found...
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad.
Please save it to your desktop.
NOTE: Logs can be retrieved at a later date from the Malwarebytes' Anti-Malware main screen:
Launch Malwarebytes' Anti-Malware.
Click the Logs tab.
Double-click log-mm.dd.yyyy.txt.
If any malware is found, please post back the log file created.
This is a lot of information to cover, so don't feel that you have to rush to get it done. I am subscribed to this thread and will be notified by e-mail when you reply. :) -- SCB
Well SCB looks like I have HiJack this where we wanted it. I could not close the service WEBROOT Spy Sweeper Engine inside of Windows at the service itself because all instances of stop or any other thing where shaded out. When I went into safe mode to delete program files \GagetBar I went over to services and was able to disable WebrootSpySweeper and after I restarted in Windows I went and checked and sure nuff it was disabled. Anyway I left a few of the 04 HKLM programs running cause I didn't know what a few updated but you said they where optinal if needed. I got rid of 3 and kept 3. As for Malwarebytes it does show one infection and I have not yet removed selected but I will and just wanted to show you the log so far.
Thank you for your time and help will post back final log of MalwareByte's
The reason we Do_Not Grow is because WE Do_Not Know. If you can answer our post it really helps us most.
Malwarebytes' Anti-Malware 1.18 Database version: 884 10:52:26 PM 6/23/2008 mbam-log-6-23-2008 (22-52-26).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 194806 Time elapsed: 43 minute(s), 9 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected
SCB-I have to say that having people like you that are willing to put up there time and with our frustration must be hard for you. But I can tell from what you do that you are awarded in a differnet way or else you wouldn't put up with us. I can't express in words for the help you have given me and I'm sure many others. It's people like you that continue to make computing fun for the inexperienced one. Thank so much for your time and effort and I can't say thank you enough. William
...... The reason we Do_Not Grow is because WE Do_Not Know.......
How very true. My theory is that working through a situation such as this will always make us grow. Those of us who help here do so for many reasons -- the main one being simply a desire to help. We also pretty much all love the challenge you can well imagine that keeping up with anything related to computers is a challenge. Things change daily and sometimes more than once a day. Keeps us on our toes and our minds sharp. :D
OK, please go ahead and let Malwarebytes Anti-Malware fix the problem it found (Normal Mode, Quick Scan, please). Post back a fresh HijackThis log and let me know how things are running, please. :) -- SCB
SCB-Things seem to be running fine except still over 3minutes to shutdown. I will check on the other site you recommended for stopping some services. Here is the log file from HiJack this and once again thanks for being here.
Part of your most recent HJT log is missing. Please rescan and when Notepad opens with the scan results, please do the following:
Return to This thread.
Switch to the Notepad window.
Hit Ctrl+a to select all of the contents.
Hit Ctrl+c to copy the entire contents.
switch back to this Reply window.
Hit Ctrl+v toPaste the entire contents into the message box.
This will ensure that the entire contents gets posted. And I can check through it to see if there's anything else we can do. Incidentally, if I don't de-fragment my hard drive often, a three-minute shutdown time is not unusual. It also depends on what programs need to shut down before Windows can shut down. :) -- SCB
SpotCheckBilly
932 Posts
562
0
Posted June 16th, 2008 20:00
Welcome to the DCF forums. My name is SpotCheckBilly (SCB for short) and if you still need assistance I'll be happy to help you out.
The instructions in this thread have been specifically designed for THIS USER'S MACHINE ONLY . You should not use these instructions to clean your machine. Doing so could cause irreparable damage to your machine. If you need assistance, please start your own thread.
A couple of important things to keep in mind during our fix.
Remember, we are in this process together. We must cooperate with each other or the fix will surely fail.
If there is something you don't understand or or are unsure of -- Please Do not skip it. Instead, take a moment to ask. With some infections skipping a step can be disastrous.
That being said, let's get started. :)
There doesn't appear to be a lot going on in your log that might be malware related. Let's take care of a couple of minor things, then we can dig a little deeper. You have two "active" anti-malware modules running --Spybot Search & Destroy's Tea Timer and Windows Defender. These programs seldom get along together and often will result in conflicts as well as reduced overall system security. Since Vista Comes with Windows Defender already installed I would recommend that you disable Tea Timer. You can certainly keep Spybot S&D as an "on demand" scanner if you like. Same thing goes for SpySweeper.
We need to disable Spybot S&D "Tea Timer" as it may interfere with the fix. Please do the following:
1. Run Spybot-S&D
2. Go to the Mode menu, and make sure " Advanced Mode" is selected
3. On the left hand side, choose Tools -> Resident
4. Uncheck " Resident TeaTimer" and OK any prompts<--- Note: DO NOT reenable after we are finished.
Please disable Windows Defender Real Time Protection as it may interfere with the fix. To disable Windows Defender:
- Open Windows Defender
- Click Tools
- Click General Settings
- Scroll down to Real Time Protection Options
- Uncheck Turn on Real Time Protection (recommended)
- Close Windows Defender
Once your log is clean you can re-enable Windows Defender Real Time Protection.Run HiJackThis and click " Do a system scan only", then check(tick) the following, if present:
O2 - BHO: (no name) - {465E08E7-F005-4389-980F-1D8764B3486C} - (no file)
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [RunSpySweeperScheduleAtStartup] "C:\Windows\system32\msfeedssync.exe" /ScheduleSweep=User_Feed_Synchronization-{25C76518-A9DD-4ECF-A63A-35EC942EDA64}
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O15 - Trusted Zone: http://us.creative.com
O15 - Trusted Zone: http://ups.surveyrouter.com
O15 - Trusted Zone: http://help.wildblue.net
O15 - Trusted Zone: http://myaccount.wildblue.net <--- Note: it's never a good idea to put any sites into the Trusted Zone. This is a well-known point of entry for malware.
With all windows closed except HiJackThis, click " Fix checked".<--- Note:
Post back a fresh HijackThis log and let me know if your symptoms have improved. If you're having any other symptoms, please let me know about those as well. :) -- SCB