This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] very slow, unresponsive and freezes up laptop

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

exeHelper by Raktor Build 20091204 Run at 14:16:47 on 12/12/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished–
Hi TomK I have tried ComboFox ,again I get all boxes in chinese.I have now got it installed on the desktop and it has taken over the c: directory .I am worried to answer the wrong prompts since I don't understand chinese.I do not know why this is happening on his computer.perhaps we should remove any chinese programs installed on this computer.I don'tsee any though.Right now I want to remove ComboFox from the computer but worried to do so might remove crucial programs with it since C; has become its sudirectory.Pls help.
almar,

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
This should remove ComboFix.

Other than the Chinese when trying to run ComboFix, how is the computer running now?
Hi TomK The computer is a bit better than before, but still freezes up sometimes and takes up unnecessory time to start up any application.on the whole it looks like it was on the way to recovery.I still would like to know how we're getting the chinese text with the Combofix instructions.You think we can use another simimlar virus scan program instead?.Could you tell from the previous scans done that I have a chinese script program installed on the computer which needs to be uninstalled ? many thanks for your help. I did try the Combofix/uninstall but it could not find an uninstall file to uninstall it. could i just deleted?
almar, I'm not sure why the chinese when your computer is set for english. :wacko: It currently doesn't matter as far as ComboFix is concerned because it has been pulled from use for something that shouldn't relate to your machine at all. Do you connect through AOL?
No I do not use AOL, I used to4 years ago but I still have it installed on the computer.Are there issues concerning AOL? Can I simply delete Combofix files from the computer? What is the best free virus protection program to install nowadys, in your opinion ,?
almar,

AOL is a rescource hog. If you don't use it, I'd uninstall anything related to AOL using add or remove programs in your control panel.

Can I simply delete Combofix files from the computer?

You shouldn't. You should run the uninstall routine as suggested in post #33.

What is the best free virus protection program to install nowadys, in your opinion ,?

I have Avira on one and AVast on another. I find them both acceptable.
Its funny but the only time I am getting the chinese instructions is when trying to install Combofix ,not on the others.Perhaps that's one of the reasons it was pulled from use!. Do you still use HiJackthis for yr scans? is it any good? I have no idea why NotePad has entirely disappeared from the list of softwares within Accessories.How do I get it back?
almar,

Download, unzip and run this program. It restores missing shortcuts in the accessories group: http://www.winxptutor.com/download/accrestore.zip

ComboFix being pulled had to do with a specific infection targeting it. You had no signs of that infection.

HijackThis is not used very often anymore because it has become quite outdated and doesn't show adequate information for us to clean most systems anymore.

Let me know how you do with notepad being restored, and then please post me new DDS logs.
TomK Good got Notpad back :D :D here is the DDS report: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:44:03.28 on 12/14/2009 Mon Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.[removed].18.382.37 [GMT -5:00] AV: avast! antivirus 4.8.1356 [VPS 091214-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== ============== Pseudo HJT Report =============== uStart Page = hxxp://my.yahoo.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo;! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9e.exe mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [HostManager] c:\program files\common files\aol\1151722181\ee\AOLSoftware.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe IE: &AOL; Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML IE: &Search; IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - {4982D40A-C53B-4615-B15B-B5B5E98D167C} IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\g\applic~1\mozilla\firefox\profiles\mkw9dmh9.default\ FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2009-12-14 15:41 –ds—- C:\ComboFix 2009-12-13 17:50 54,156 a—h— c:\windows\QTFont.qfn 2009-12-13 17:50 1,409 a——- c:\windows\QTFont.for 2009-12-12 19:13 244 a—h— C:\sqmnoopt05.sqm 2009-12-12 19:13 232 a—h— C:\sqmdata05.sqm 2009-12-12 19:13 244 a—h— C:\sqmnoopt04.sqm 2009-12-12 19:13 232 a—h— C:\sqmdata04.sqm 2009-12-12 16:15 244 a—h— C:\sqmnoopt03.sqm 2009-12-12 16:15 232 a—h— C:\sqmdata03.sqm 2009-12-11 11:39 –d—– c:\documents and settings\g\DoctorWeb 2009-12-09 23:38 –d—– C:\_OTL 2009-12-08 19:20 –d—– c:\docume~1\g\applic~1\Malwarebytes 2009-12-08 19:20 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-08 19:20 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-12-08 19:20 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-12-08 19:20 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-11-29 22:25 378 a——- C:\Shortcut to WINDOWS.lnk 2009-11-27 11:33 –d—– c:\program files\common files\Scanner 2009-11-24 16:52 –d—– c:\windows\pss ==================== Find3M ==================== 2009-12-08 21:55 4,016 a——- c:\docume~1\g\applic~1\wklnhst.dat 2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe 2009-10-27 06:06 18,432 a——- c:\windows\system32\dllcache\iedw.exe 2009-10-21 01:00 75,776 a——- c:\windows\system32\strmfilt.dll 2009-10-21 01:00 25,088 a——- c:\windows\system32\httpapi.dll 2009-10-21 01:00 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll 2009-10-21 01:00 25,088 ——– c:\windows\system32\dllcache\httpapi.dll 2009-10-20 09:58 263,552 a——- c:\windows\system32\drivers\http.sys 2009-10-20 09:58 263,552 ——– c:\windows\system32\dllcache\http.sys 2009-10-13 05:53 266,752 a——- c:\windows\system32\oakley.dll 2009-10-13 05:53 266,752 ——– c:\windows\system32\dllcache\oakley.dll 2009-10-12 08:54 112,128 a——- c:\windows\system32\rastls.dll 2009-10-12 08:54 69,632 a——- c:\windows\system32\raschap.dll 2009-10-12 08:54 112,128 ——– c:\windows\system32\dllcache\rastls.dll 2009-10-12 08:54 69,632 ——– c:\windows\system32\dllcache\raschap.dll 2009-09-25 00:56 473,600 a——- c:\windows\system32\dllcache\shlwapi.dll 2009-09-25 00:56 1,054,208 a——- c:\windows\system32\dllcache\danim.dll 2009-09-25 00:56 81,920 a——- c:\windows\system32\ieencode.dll 2009-09-25 00:56 81,920 ——– c:\windows\system32\dllcache\ieencode.dll 2004-02-12 11:54 470,528 a——- c:\program files\Manual DVD shrink 3.doc 2004-01-25 23:11 848,763 a——- c:\program files\dvdshrink314setup.exe ============= FINISH: 19:48:17.54 =============== also see file Attach2 attached

Attachments:

almar,

My mistake. Please put the following in the Run box.
"%userprofile%\desktop\mbr.exe" -t

A file will appear on your desktop called mbr.log
his is the mbr file
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
kernel: MBR read successfully
user & kernel MBR OK

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI