This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet slow and typing delay

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi This is the log. Hope that helps. Thanks Eleanor Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5075 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18975 08/11/2010 20:20:35 mbam-log-2010-11-08 (20-20-35).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 335211 Time elapsed: 1 hour(s), 35 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\System Volume Information\SystemRestore\FRStaging\Users\elliebungo\AppData\Local\Xenocode\XSandbox\Browsealoud 6\6.00.0001\2009.12.01T12.04\Virtual\STUBEXE\7.1.280\@PROGRAMFILES@\Texthelp\Browsealoud\6.0\BAloud4.exe (Backdoor.Bifrose) -> Quarantined and deleted successfully. C:\System Volume Information\SystemRestore\FRStaging\Users\elliebungo\AppData\Roaming\VideoEgg\Loader\4665\npvideoegg-loader.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
The items that were found by Malwarebytes were located in a system restore point (SVI folder) and are not posing a direct active threat. They are in the SVI folder and can be cleared. I will provide you with instructions on how to do that shortly, but we still have one more scan we need to do first.


Please do a scan with Kaspersky Online Scanner
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
  • Text file [*.txt] Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.

This scan will likely take even longer than the Malwarebytes scan. You may want to set it up to run overnight when you won't need the computer.


Can you please let me know how the machine is running now.
Hi Doris The Kaspersky scan log is below: Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, November 10, 2010 02:39:09 Records in database: 4249365 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Objects scanned: 199053 Threats found: 3 Infected objects found: 4 Suspicious objects found: 0 Scan duration: 06:28:50 File name / Threat / Threats count C:\Users\elliebungo\AppData\Local\Google\Chrome\User Data\Default\old_Cache_000\f_000250 Infected: Exploit.JS.Pdfka.cus 2 C:\Users\elliebungo\AppData\Local\temp\jar_cache6280002628727426070.tmp Infected: Trojan-Downloader.Java.OpenConnection.bx 1 C:\Users\elliebungo\AppData\Local\temp\jar_cache6575934886221420342.tmp Infected: Exploit.Java.CVE-2009-3867.m 1 Selected area has been scanned. The computer isn't running any better really. Thanks Eleanor
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    :Files
    C:\Users\elliebungo\AppData\Local\Google\Chrome\User Data\Default\old_Cache_000\f_000250		
    C:\Users\elliebungo\AppData\Local\temp\jar_cache6280002628727426070.tmp 
    C:\Users\elliebungo\AppData\Local\temp\jar_cache6575934886221420342.tmp 
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log it generates.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
This program is for XP, Windows 2000, and Vista
  • Right-click ATF-Cleaner.exe to run the program and choose "run as administrator"
  • Under Main choose: Select All
  • Click the Empty Selected button.

(If you use FireFox or the Opera browser to keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.



I'd also like to address the uTorrent program that would not uninstall. I can see that you have RevoUninstaller on your machine. The version is a little out of date, but it will do just fine for what we want to do.
  • Double-click the RevoUninstaller icon to run it.
  • Once the screen has fully populated, please find uTorrent and double click it to select it for uninstallation.
  • When prompted to confirm deletion select Yes
  • When the Uninstall Mode screen appears, select Advanced and then click Next
  • RevoUninstaller will attempt to use the program's built in uninstaller, but if it fails to uninstall RevoUninstaller will continue on.
  • You should then see a screen showing RevoUninstaller has completed it's 4 steps. Click "Next" to scan for leftover files, folders and registry entries.
  • When that scan is finished you will need to click "Next" to continue to the results.
  • Be sure all the entries are selected and allow RevoUninstaller to remove them.
  • After completion, please reboot if you are not instructed to do so.

Please let me know how your system is running now.
Hi Doris This is the OTL log: All processes killed ========== OTL ========== ========== FILES ========== File\Folder C:\Users\elliebungo\AppData\Local\Google\Chrome\User Data\Default\old_Cache_000\f_000250 not found. File\Folder C:\Users\elliebungo\AppData\Local\temp\jar_cache6280002628727426070.tmp not found. File\Folder C:\Users\elliebungo\AppData\Local\temp\jar_cache6575934886221420342.tmp not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: elliebungo ->Temp folder emptied: 17544188 bytes ->Temporary Internet Files folder emptied: 50914990 bytes ->Java cache emptied: 161548 bytes ->FireFox cache emptied: 61612367 bytes ->Google Chrome cache emptied: 0 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 20843 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 87710 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 124.00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: elliebungo ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0.00 mb OTL by OldTimer - Version 3.2.16.0 log created on 11132010_210734 Files\Folders moved on Reboot… Registry entries deleted on Reboot… The PC is still running the same. Thanks Eleanor
If you ran DeFogger
To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.



Can you please tell me if you are using a modem and a router? If so, what is the make and model of the router?
Sorry for delay in replying. Have re-enabled the defogger and no error messages. Just using a router - it's Sky Netgear. I can't see a model number, but there's a number on it which is 272-10398-02. There's also a 'MAC' number and a serial number, SSID, network key and channel if you need any of that info. Thanks Eleanor
Let's reset your router and see if that improves your speed. (I checked and I believe the mode number of your router is DG834GT) 1. Open a web browser. Enter "192.168.0.1" and press "Enter." You should be prompted with a window asking for a username and password. If this does not work, use "192.168.1.1". 2. Enter the username and password that you selected when setting up the Netgear DG834GT for the first time. If you never changed the username and password, enter the username "admin" and the password "password." This brings you to the main internal control panel for the router. (Since yours is the Sky branded router, you might have to try the password as "sky" if you didn't change it when it was set up.) 3. Scroll down to the "Maintenance" heading on the left side of the screen and click the "Diagnostics" link. 4. Click the "Restart" button at the bottom of the window. The router turns off and reboots. Allow several seconds for the DG834GT to reboot fully before attempting to connect to it to browse the web. Note: If you are unable to access the control panel for the Netgear DG834GT because you do not have the password, reset it by unplugging it from the power outlet for 30 seconds, then plugging it back in. If after a reset your browsing speed is still slow, can you please do me a favor and look at the DNS setting for your router and tell me what it is. You should see it noted on the basic setup information page when you login to the router as directed above.
Hi, it's still going slow unfortunately. Under ASDL port the following is noted: MAC Address 00:1B:2F:93:19:3B IP Address [removed] Network Type PPPoA IP Subnet Mask 255.255.255.255 Gateway IP Address 87.87.251.228 90.207.238.97 Domain Name Server 90.207.238.99 Hope that's enough info. thanks Eleanor
Your logs appear to be malware free and you do not appear to be experiencing any malware related problems. I do not believe the internet slowness or typing delay is being caused by malware. You might want to post in the Browsers, Internet and Email forum for further assistance.

The following will implement some cleanup procedures as well as reset System Restore points:
  • Click Start > Run
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

Now to remove most of the tools that we have used in fixing your machine:
  • Run OTL.exe
  • This time, click on the CleanUp button.

If you notice any remaining tools or files you can delete them by right clicking and choosing delete.


Please follow these simple steps in order to keep your computer malware free and secure:

Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall

Your log doesn't appear to show a third-party software firewall installed - if you have one, and I've missed it, please ignore this. I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

If you are relying the firewall that comes with Windows, then you need to install one. While the Windows firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will. If you are using a wireless router that comes with a NAT hardware firewall, this also doesn't monitor outgoing connections.

Below are links to some free options:
Sunbelt Kerio OutPost
PC Tools Firewall Plus
Online Armor Free

After installing one of these, confirm your Windows Firewall is disabled by doing the following:
  • Click Start, click Run, type Firewall.cpl, and then click OK.
  • On the General tab, click Off (not recommended)
  • Click OK.

For a tutorial on Firewalls and a listing of some other available ones see the link below:
Understanding and Using Firewalls



Make your Internet Explorer more secure
This can be done by following these simple instructions:

1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.

1. Change the Download signed ActiveX controls to Prompt
2. Change theDownload unsigned ActiveX controls to Disable
3. Change the Initialise and script ActiveX controls not marked as safe to Disable
4. Change the Installation of desktop items to Prompt
5. Change the Launching programs and files in an IFRAME to Prompt
6. Change the Navigate sub-frames across different domains to Prompt
7. When all these settings have been made, click on the OK button.
8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.

You should update your version of the Adobe Flash to the newest version:
You should update your version of the Sun Java Platform (JRE) to the newest version:
  • Download and install the latest version of Java
  • Next, remove all older versions of the Sun Java Platform using the Control Panel's Add/Remove Program feature (as they may contain security vulnerabilities).
Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

The download and tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Run Malwarebytes Anti-Malware
Update and scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with SuperAntiSpyware.

Install SUPERAntiSpyware Home Edition (free edition)
You should also scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with Malwarebytes.

Perform an online virus scan
Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.

Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender: http://www.bitdefender.com/scan8/

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Follow this list and your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI