This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

pc is slow loading

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good Morning, The problem is that your Master Boot Record could be infected and until I get that file analyzed we wont know for sure. All us forums work together and what I need to do is send that file off to be checked by helpers on another forum that specialize in the MBR All you have to do is save the dump file to your desktop Then right click it and select Send To > Compressed Zip Folder and it will be saved to your desktop Then go towards the bottom of this post and look for Manage Attachments , use the browse feature to find the new Zipped file you just created and attach it
It appears that it may not be infected , but there still looking. Are you at the moment experiencing any redirects to other websites ?


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 10-11-07.07 - Robbin 11/07/2010 18:39:56.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.171 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: EastLink Internet Security Services 9.12 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: EastLink Internet Security Services 9.12 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\program files\SoftPortal
c:\program files\SoftPortal\Soft\ATGE\ui.uim
c:\program files\SoftPortal\Soft\ATHtBt\ui.uim
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system32\Ijl11.dll
c:\windows\system32\spool\prtprocs\w32x86\TMPROCES.DLL
c:\windows\system32\SrchSTS.exe

—– BITS: Possible infected sites —–

hxxp://download.yimg.com
.
((((((((((((((((((((((((( Files Created from 2010-10-07 to 2010-11-07 )))))))))))))))))))))))))))))))
.

2010-11-03 16:20 . 2010-11-03 16:20 ——– d—–w- C:\_OTL
2010-10-29 19:38 . 2010-10-29 19:38 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Yahoo!
2010-10-29 17:25 . 2010-10-29 17:29 ——– dc-h–w- c:\windows\ie8
2010-10-29 17:12 . 2010-09-10 05:58 11080192 -cβ€”-w- c:\windows\system32\dllcache\ieframe.dll
2010-10-27 22:11 . 2010-10-29 16:19 ——– d—–w- c:\program files\Runtime Software
2010-10-14 16:44 . 2010-09-18 06:53 953856 -cβ€”-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-14 16:44 . 2010-09-18 06:53 974848 -cβ€”-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-14 16:43 . 2010-08-23 16:12 617472 -cβ€”-w- c:\windows\system32\dllcache\comctl32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-18 15:23 . 2003-03-31 12:00 974848 β€”-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2003-03-31 12:00 974848 β€”β€”w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2003-03-31 12:00 954368 β€”-a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2003-03-31 12:00 953856 β€”-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58 . 2003-03-31 12:00 916480 β€”-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58 . 2003-03-31 12:00 43520 β€”β€”w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58 . 2003-03-31 12:00 1469440 β€”β€”w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2003-03-31 12:00 285824 β€”-a-w- c:\windows\system32\atmfd.dll
2010-08-31 13:42 . 2003-03-31 12:00 1852800 β€”-a-w- c:\windows\system32\win32k.sys
2010-08-31 10:14 . 2009-03-28 12:48 41624 β€”-a-w- c:\windows\system32\drivers\fsbts.sys
2010-08-27 08:02 . 2003-03-31 12:00 119808 β€”-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:57 . 2003-03-31 12:00 99840 β€”-a-w- c:\windows\system32\srvsvc.dll
2010-08-26 13:39 . 2003-03-31 12:00 357248 β€”-a-w- c:\windows\system32\drivers\srv.sys
2010-08-26 12:52 . 2009-04-17 04:49 5120 β€”-a-w- c:\windows\system32\xpsp4res.dll
2010-08-23 16:12 . 2003-03-31 12:00 617472 β€”-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2003-03-31 12:00 58880 β€”-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:45 . 2004-01-01 18:14 590848 β€”-a-w- c:\windows\system32\rpcrt4.dll
2005-12-05 22:00 . 2005-12-05 22:00 74448 -cβ€”-w- c:\program files\DSETUP.dll
2005-12-05 22:00 . 2005-12-05 22:00 484560 -cβ€”-w- c:\program files\DXSETUP.exe
2005-12-05 22:00 . 2005-12-05 22:00 2247888 -cβ€”-w- c:\program files\dsetup32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"F-Secure TNB"="c:\program files\Eastlink Internet Security\FSGUI\TNBUtil.exe" [2009-11-18 1655208]
"F-Secure Manager"="c:\program files\Eastlink Internet Security\Common\FSM32.EXE" [2009-11-18 201128]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-12 282624]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSimpleStartMenu"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-04-03 16:50 1603152 β€”-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-05-14 16:01 644696 β€”-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116]
1998-11-30 22:04 497376 β€”-a-w- c:\windows\p_981116.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2007-01-23 19:44 101136 β€”-a-w- c:\windows\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-02-24 00:35 67128 β€”-a-w- c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-02-04 15:02 79400 β€”-a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PD0620 STISvc]
2005-05-10 17:03 36864 β€”-a-r- c:\windows\system32\P0620Pin.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-09-12 23:14 282624 β€”-a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 12:03 210472 β€”-a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-09-01 21:11 39408 β€”-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=

R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [3/28/2009 8:48 AM 41624]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [10/31/2007 8:30 PM 81864]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Eastlink Internet Security\HIPS\drivers\fshs.sys [3/28/2009 8:47 AM 69928]
R3 Esdpdx01;Esdpdx01;c:\windows\system32\drivers\ESDPDX01.SYS [7/2/2002 9:28 PM 58058]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Eastlink Internet Security\Anti-Virus\minifilter\fsgk.sys [10/31/2007 8:29 PM 124072]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Eastlink Internet Security\ORSP Client\fsorsp.exe [3/28/2009 8:47 AM 64016]
S2 gupdate1c9863e5073fc50;Google Update Service (gupdate1c9863e5073fc50);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2009 4:30 PM 133104]
S3 elomoufiltr;ELO TouchSystems-SRV2; [x]
S3 EloUsb;ELO TouchSystems-SRV; [x]
S3 VCR878;VCR878;c:\windows\system32\drivers\VCR878.sys [8/24/2002 12:44 PM 47244]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Eastlink Internet Security\Anti-Virus\win2k\fsfilter.sys [10/31/2007 8:29 PM 41640]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Eastlink Internet Security\Anti-Virus\win2k\fsrec.sys [10/31/2007 8:29 PM 27048]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 07:32 128512 β€”-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-10-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 17:21]

2010-11-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-26 23:15]

2010-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 20:30]

2010-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 20:30]

2010-11-07 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\EASTLI~1\ANTI-V~1\fsav.exe [2007-11-01 16:06]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = hxxp://www.myeastlink.ca/?region=NS
uInternet Settings,ProxyOverride =
LSP: c:\program files\Eastlink Internet Security\FSPS\program\FSLSP.DLL
Trusted Zone: facebook.com\www
Trusted Zone: yahoo.com\answers
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {9E515FE4-2A60-4D08-8E96-CF9A967BE49B} - hxxp://check.earthlinksecurity.com/SSMEarthLink.cab
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{282E8AE5-A8E3-412D-B40C-F5080832FFE0} - (no file)
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
MSConfigStartUp-FlashPlayerUpdate - c:\windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe
MSConfigStartUp-Lexmark 1200 Series - c:\program files\Lexmark 1200 Series\lxczbmgr.exe
MSConfigStartUp-PC Suite Tray - c:\program files\Nokia\Nokia PC Suite 6\PCSuite.exe
MSConfigStartUp-SmileboxTray - c:\documents and settings\Robbin\Application Data\Smilebox\SmileboxTray.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-07 18:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” LOCKED REGISTRY KEYS β€”β€”β€”β€”β€”β€”β€”

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”

- - - - - - - > 'winlogon.exe'(520)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(576)
c:\program files\Eastlink Internet Security\FSPS\program\FSLSP.DLL

- - - - - - - > 'explorer.exe'(1952)
c:\windows\system32\WININET.dll
c:\program files\Eastlink Internet Security\Spam Control\fsscoepl.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
β€”β€”β€”β€”β€”β€”β€”β€” Other Running Processes β€”β€”β€”β€”β€”β€”β€”β€”
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\brss01a.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Eastlink Internet Security\Anti-Virus\fsgk32st.exe
c:\program files\Eastlink Internet Security\Common\FSMA32.EXE
c:\program files\Eastlink Internet Security\Anti-Virus\FSGK32.EXE
c:\program files\Eastlink Internet Security\Common\FSHDLL32.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Eastlink Internet Security\FWES\Program\fsdfwd.exe
c:\program files\Eastlink Internet Security\Anti-Virus\fssm32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Eastlink Internet Security\Anti-Virus\fsav32.exe
c:\windows\System32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Completion time: 2010-11-07 19:05:38 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-07 23:05

Pre-Run: 22,363,295,744 bytes free
Post-Run: 22,369,992,704 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 26D55F52A18B051D09834E33FD52360

Thanks for the great instructions! I do not seem to be having problems with redirecting to other sites.
Well, CF removed a few bad things but if your MBR was infected it would have shown some info about it and it did not so I would say your ok. How is your system behaving now , you said no redirects , is there anything else going on to make you think your infected ?
:thumbup:

Malwarebytes <–This is the free version and yours to keep, keep it updated and run a scan now and then. The paid version has a protection modulale , but this is your choice.

TFC <–This also is free, run it now and then to clean out the clutter

Open OTL and click on the Cleanup feature and it will remove a lot of the programs we used along with all the backups

  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports



Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .



Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • WinPatrol Keep this fine program activated to block a lot of threats
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI