Link to home
Start Free TrialLog in
Avatar of pazsint
pazsint

asked on

NEW WIN XP BUILD, HOW TO GET RID OF PERSISTENT SPYWARE?

I'M WORKING UP A FULL NEW GAMING BUILD WITH ALL NEW PARTS. SEVERAL PROBLEMS AND SYMPTOMS ARE UN-RESOLVED. YOUR HELP IS APPRECIATED.
I've installed a full new copy of win XP PRO w/SP1 , Pc-Ciillin 2005, and updated Spybot and SDpyblaster progRAMS. The Problems are:

l. AFTER AN INITIAL LOPGON FOR NET UPDATES WITH TRIAL NORTON AV, AS USUAL I THREW IT IN THE TRASH AND INSTALLED THE BEST PC-CILLIN. ALTHOUGH I GOT NO VIRUSES OR TROJANS, PC-CLLIN AS WELL AS SPYBOT FOUND A TON OF TRASH WARE THAT NORTON LET BY. I GOT RID OF MOST OF IT BUT THESE BUGGERS....
.....THERE IS A FULL 30 SECOND BLACKOUT ON BOOT BEFORE WINDOWS STARTS LOADING THAT WASN'T THERE INITIALLY AND I'VE NOT SEEN IN OTHER XP's. SEARCHING EVENT VIEWER I FOUND A NOTE THAT A DELAY OF 30000 MIILISECONDS OCCURED LOOKING FOR A THING CALLED 'ZESOFT' SERVICE..A NOT FOUND ERROR. I'VE SEARCHED FOR THIS BUGGER AND NONE OF THE SPYWARES OR MY AV FINDS IT . IS THIS WHAT MY 30 SECOND BOOT BLACKOUT IS FROM AND HOW DO I RID MYSELF OF 'ZESOFT'?

2.. WHEN I SCAN FOR SPYWARE WITH PC-CILLIN 2005 IT FINDS 5 PIECES REPEATEDLY FOR MANY MINUTES PERHAPS A THOUSAND INSTANCES THEN REPORTS AND INTERNAL ERROR AND SCAN COULD NOT BE COMPLETED. IF I TRY TO DELETE WHAT WAS FOUND, PROGRAM WILL FREEZE WITHOUT ANY DELETES. SPYBOT S&D DOES NOT FIND THESE 5 PIECES OF SPYWARE....BARBUDDY.A, SAHAGENT, HUNTBAR.A, WEBSEARCH.A., AND BHO_HUNTBAR.F
c...I also and can't fully expell the mcafee32 worm

3. ALTHOUGH THE MODEM IN USE IS A 56K V90 AND HAS BEEN USED WITHOUT ISSUE FOR DOWNLOADING WITH OTHER BUILDS OVER MY DIALOUT, THE PAGE ACCESS AND DOWNLOADING WITH THIS NEW XP MACHINE IS VERY SLOW. ALSO I'VE NOTICED THE REMOVAL OF SOME OF THE AUTODIALING WARE THAT NORTON LET IN, IMPROVED USABILILITY AT DESKTOP. BUT, LIKE RIGHT NOW I'M ALSO DOING A DOWNLOAD AND SOME OF WINDOWS APPS I TRY TO OPEN ARE SLOW, AND ITS EVEN MORE NOTICEABLE IF I OPEN ANOTHER BROWSER AND TRY TOO SURF... IT IS ETERNALLY SLOW. IS THIS BECAUSE OIF THE SPYWARE DOING THEIR TRASH AT SAME TIME I'M TRYING TO WORK ON NET?

Thanks for any and ALL help! Dan
Avatar of CodedK
CodedK
Flag of Greece image

Hi.

Do u have a usb device like Hard disk connected?
When windows starts there is a delay if u have such a device connected.

About Spyware problem :

-----------------------------------------------------------------------------------------------------
Online check (Big Database):
http://housecall.trendmicro.com
-----------------------------------------------------------------------------------------------------
AdAware ==> http://www.spychecker.com/program/adaware.html
SpyBot  ==> http://www.spychecker.com/program/spybot.html
SpySweeper ==> http://www.spychecker.com/program/spysweeper.html
SpywareBlaster ==> http://www.spychecker.com/program/spywareblaster.html
CoolWebShredder ==> http://www.spychecker.com/program/coolwebshredder.html
-----------------------------------------------------------------------------------------------------
Also have a look at Microsofts anti spyware tool :-
http://www.microsoft.com/athome/security/spyware/software/default.mspx
http://www.microsoft.com/security/malwareremove/default.mspx
and click on "Check My PC for infection"
-----------------------------------------------------------------------------------------------------
For removal infection go to
http://www.sarc.com/avcenter/tools.list.html
-----------------------------------------------------------------------------------------------------
HijackThis ==> http://www.merijn.org/files/hijackthis.zip
analysis ==> http://www.hijackthis.de
-----------------------------------------------------------------------------------------------------
Application (Management)

Download Codestuff Starter...
http://members.lycos.co.uk/codestuff/
 
For applications/malware that run on startup... coz they dont always hide at
currentversion\run where the average user will search...
Search on google for each exe running to identify whether they are legitimate.
-----------------------------------------------------------------------------------------------------
Hard-disk and registry cleaners:
CCleaner :   http://www.ccleaner.com
BeClean   :  http://boozet.xepher.net/beclean/download.htm
and Dustbuster  http://www.pcworld.com/downloads/file_description/0,fid,22384,00.asp
-----------------------------------------------------------------------------------------------------
A firewall like Zonealarm....
-----------------------------------------------------------------------------------------------------
Its good to be prepared but dont overdo it... :/
Installing many of these apps mentioned will slow down ur computer...
So choose the one that fit ur needs and install it :)

Hope this helps.. :)
USING HIJACK THIS:

Download HijackThis from:
http://www.gatesofdelirium.com/ee/tools/

With all browser windows closed - run HijackThis and
copy and paste the log file into the Analysis site here:
http://www.hijackthis.de/en

Click on the "Analyze" button and when the analysis is done -
Click on the "Save Analysis" button -
A page will be generated with your saved analysis -
Post a LINK to that page back here...

Please, do not post your log file here!!!

Here's the Experts-Exchange guidelines on posting HijackThis logs:
https://www.experts-exchange.com/questions/21149514/Instructions-regarding-the-handling-of-HIJACK-THIS-logs.html

Good luck!
Avatar of pazsint
pazsint

ASKER

Codeks...
 Thanks for all the info...as you say I don't like to overun software either. I use Hijack, Spybot, Spywareblaster. , as well as Pc-Cillin AV. Anyway I used the Hijack analyses, and only found one bad line that won't stay deleted...
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitedza32.exe

I've gone to SP 2 for XP now and cleaned everything up registry and unnecessarys and temp files...still have these issues:

1...Pc-Cillin still finds those 5 trashwares repeatetedly...I'm going to call them for tech help on this one.

2...that 30 second blackout is still there...no I don't keep any USB items plugged in during satrt up. I did find that ZESoft listed running in the services. Although I stop it, it reappears on next boot with same blackout period.

3...Also Now I find these XP apps don't work...Notepad, Help, and Sys Info.....why?
Hi!

Do as advised above -
Run HijackThis - run your log through the Analysis site -
Post a LINK to your log back here.
We'll take a look at it.

RF
TURN OFF SYSTEM RESTORE ;) Then run tools such as ad-aware or hijackthis only after system restore is off:
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
-rich
Avatar of pazsint

ASKER

Ross and Rich...Thanks
Yes I have system restore off in XP when using desktop cleaners. Hijack and analyses found only one bad line and removing it didn't take it all out. Here's is what I have learned, done, and removed in the meantime...
X-Clean found 10 more items including 8 lines of Websearch in registry.
Then X-Soft found 21 more entries ater that...at total of 38 offending lines, pieces files, etc were removed after I used after all the known best suggested trashware removers had their shot at it...what an eye opener...guys those 2 progs are all I'll use now!
 One catch is the X-Soft that apperas to be the best is a pay to remove software ..but it may well be worth iit. I was able with their list to take out a few more lines manually, and may yet get rid of the last 3 bugs in here, especiailly that 'ZeSoft' which only X-Soft out of ten progs I tried found.
the X-Soft link....
http://www.spywareguide.com/txt_onlinescan.html

By the way I haven't yet been able to get the XP progs working.... surely you guys would know what that is, please?
I would still advise you to run HijackThis and post a LINK to your log.

RF
:)

To tell u the truth i dont believe in spyware so much... :/
I dont believe that a person who knows his system well, would have serious spyware issues .. i think you know
your system... :)
So maybe its a hardware issue.

About those 5 files ... they may be in use.
Try to clean them in safe mode. Disable all services...

Try this and tell me

Good luck :)
Avatar of pazsint

ASKER

ROSS...Ok here is my HJ analyses link...
http://www.hijackthis.de/logfiles/1abfa0fd19dd0f6d6d9fcadd32fb02b4.html
The 2 WNC's are my AT&T dialout, the NV Tray is the nVidia VGA program, but the two Tcpip's at the end of the list I'm not sure of...what do you think?
Thanks!

TO CodedK: I have managed to get all but two items off...and those are found by Pc-Cillins spyware scan only...Huntbar.A and Websearch.A .  I called Pc-Cillin and they suggested using X-Cleaners micro prog and it did help. I know of some hardware issues but have been worlking them out on the side...the only thing possibly related in that vein is I still have this 30 full second delay after bios post while system blacks out and nothing happens before windows XP starts to load. Then again I reallly think something put a line in on me to have  the bugo start up before windows does, and I killed it but haven't found the annoying delay code..see?
Thanks too.
I read on a forum that some drivers can generate such problems.
Try the following:

Update Windows.... Search for hardware updates also.
Download Driver Genious
www.driver-soft.com

Do u have Nvidia?
More:
Update your Bios.
Defrag your harddrives.
:)
ASKER CERTIFIED SOLUTION
Avatar of pazsint
pazsint

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial