This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer suddenly runs much slower, mouse freezes

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok, I hope I did it. Here's what I got: ComboFix 10-11-29.05 - MJR_2 11/30/2010 5:54:06.3.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.381 [GMT -8:00] Running from: C:\Documents and Settings\[removed]\My Documents\Downloads\ComboFix.exe AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} . ((((((((((((((((((((((((( Files Created from 2010-10-28 to 2010-11-30 ))))))))))))))))))))))))))))))) . 2010-11-28 10:45:40 . 2010-11-28 10:45:38 98392 —-a-w- C:\WINDOWS\system32\drivers\SBREDrv.sys 2010-11-28 00:33:18 . 2010-11-28 00:34:29 ——– d—–w- C:\Documents and Settings\MJR_2\Application Data\Apple Computer 2010-11-25 15:28:16 . 2008-04-14 00:12:07 26624 —-a-w- C:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll 2010-11-25 15:06:30 . 2010-11-25 15:06:31 ——– d—–w- C:\Program Files\Windows Media Connect 2 2010-11-25 15:05:05 . 2010-11-25 15:05:42 ——– d—–w- C:\WINDOWS\system32\drivers\UMDF 2010-11-25 15:05:05 . 2010-11-25 15:05:05 ——– d—–w- C:\WINDOWS\system32\LogFiles 2010-11-25 14:58:50 . 2010-11-25 15:04:13 ——– d—–w- C:\WINDOWS\system32\NtmsData 2010-11-25 14:22:43 . 2010-11-26 13:18:58 ——– d—–w- C:\Documents and Settings\Guest 2010-11-25 11:35:22 . 2010-09-23 07:46:08 15880 —-a-w- C:\WINDOWS\system32\lsdelete.exe 2010-11-25 10:19:34 . 2010-09-23 07:46:08 64288 —-a-w- C:\WINDOWS\system32\drivers\Lbd.sys 2010-11-25 10:19:24 . 2010-11-25 10:19:24 ——– d—–w- C:\Documents and Settings\MJR_2\Local Settings\Application Data\Sunbelt Software 2010-11-25 10:11:29 . 2010-11-25 10:11:31 ——– dc-h–w- C:\Documents and Settings\All Users\Application Data\{E961CE1B-C3EA-4882-9F67-F859B555D097} 2010-11-25 10:10:47 . 2010-11-25 10:19:39 ——– d—–w- C:\Documents and Settings\All Users\Application Data\Lavasoft 2010-11-25 10:10:47 . 2010-11-25 10:10:47 ——– d—–w- C:\Program Files\Lavasoft 2010-11-24 12:04:40 . 2010-11-24 12:04:40 388096 —-a-r- C:\Documents and Settings\MJR_2\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2010-11-24 11:35:51 . 2010-11-24 11:35:51 ——– d—–w- C:\Program Files\Trend Micro 2010-11-23 06:52:37 . 2010-11-23 06:52:37 ——– d—–w- C:\Documents and Settings\MJR\Application Data\Tific 2010-11-23 06:52:34 . 2010-11-23 06:52:34 ——– d—–w- C:\Documents and Settings\MJR\Local Settings\Application Data\Symantec 2010-11-21 22:05:33 . 2010-11-21 22:05:33 ——– d—–w- C:\Documents and Settings\MJR_2\Application Data\Tific 2010-11-21 22:05:18 . 2010-11-21 22:05:18 ——– d—–w- C:\Documents and Settings\MJR_2\Local Settings\Application Data\Symantec 2010-11-21 22:04:01 . 2010-11-21 22:04:01 ——– d—–w- C:\WINDOWS\system32\wbem\Repository 2010-11-20 22:41:05 . 2010-11-20 22:41:05 ——– d—–w- C:\Documents and Settings\MJR_2\Application Data\Malwarebytes 2010-11-20 22:40:53 . 2010-11-27 02:25:38 ——– d—–w- C:\Program Files\Malwarebytes' Anti-Malware 2010-11-20 22:40:53 . 2010-11-20 22:40:53 ——– d—–w- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2010-11-12 12:40:16 . 2010-11-12 12:40:16 ——– d—–w- C:\Program Files\PurePlay 2010-11-12 12:40:16 . 2010-11-12 12:40:16 ——– d—–w- C:\Documents and Settings\All Users\Application Data\PurePlay 2010-11-12 05:19:05 . 2010-11-12 05:24:40 ——– d—–w- C:\Documents and Settings\MJR\Local Settings\Application Data\Adobe 2010-11-12 02:28:56 . 2008-04-13 19:45:40 32128 -c–a-w- C:\WINDOWS\system32\dllcache\usbccgp.sys 2010-11-12 02:28:56 . 2008-04-13 19:45:40 32128 —-a-w- C:\WINDOWS\system32\drivers\usbccgp.sys 2010-11-06 19:37:34 . 2010-11-06 19:37:34 103864 —-a-w- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll 2010-11-06 19:37:34 . 2010-11-06 19:37:34 103864 —-a-w- C:\Program Files\Internet Explorer\Plugins\nppdf32.dll 2010-10-31 17:02:55 . 2010-10-31 17:03:00 ——– d—–w- C:\Program Files\Veetle . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-10-15 11:10:24 . 2010-05-26 22:36:08 60808 —-a-w- C:\WINDOWS\system32\S32EVNT1.DLL 2010-10-15 11:10:24 . 2010-05-26 22:36:08 126512 —-a-w- C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2010-09-18 19:23:26 . 2006-02-28 12:00:00 974848 —-a-w- C:\WINDOWS\system32\mfc42u.dll 2010-09-18 06:53:25 . 2006-02-28 12:00:00 974848 —-a-w- C:\WINDOWS\system32\mfc42.dll 2010-09-18 06:53:25 . 2006-02-28 12:00:00 954368 —-a-w- C:\WINDOWS\system32\mfc40.dll 2010-09-18 06:53:25 . 2006-02-28 12:00:00 953856 —-a-w- C:\WINDOWS\system32\mfc40u.dll 2010-09-15 11:50:37 . 2010-05-29 03:34:58 472808 —-a-w- C:\WINDOWS\system32\deployJava1.dll 2010-09-15 09:29:49 . 2010-05-29 03:34:58 73728 —-a-w- C:\WINDOWS\system32\javacpl.cpl 2010-09-10 05:58:08 . 2006-02-28 12:00:00 916480 —-a-w- C:\WINDOWS\system32\wininet.dll 2010-09-10 05:58:06 . 2006-02-28 12:00:00 43520 —-a-w- C:\WINDOWS\system32\licmgr10.dll 2010-09-10 05:58:06 . 2006-02-28 12:00:00 1469440 ——w- C:\WINDOWS\system32\inetcpl.cpl 2010-09-08 18:17:46 . 2010-09-08 18:17:46 94208 —-a-w- C:\WINDOWS\system32\QuickTimeVR.qtx 2010-09-08 18:17:46 . 2010-09-08 18:17:46 69632 —-a-w- C:\WINDOWS\system32\QuickTime.qts . ——- Sigcheck ——- [7] 2008-06-20 11:59:02 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys [7] 2008-06-20 11:51:12 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys [7] 2008-06-20 11:51:12 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\system32\dllcache\tcpip.sys [-] 2008-06-20 11:51:12 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\system32\drivers\tcpip.sys [7] 2008-06-20 10:45:13 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)] . . C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys [7] 2008-06-20 10:44:42 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394 (xpsp_sp2_qfe.080620-1259)] . . C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys [7] 2008-04-13 19:20:16 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys [7] 2008-04-13 19:20:16 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\tcpip.sys [7] 2006-02-28 12:00:00 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] . . C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-11-07 01:28:22 116056] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PROMon.exe"="PROMon.exe" [2002-04-19 01:32:36 73728] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-05 06:22:32 94208] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-05 06:19:18 77824] "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-05 06:23:14 114688] "Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 16:08:58 143360] "Bing Bar"="C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 23:39:38 243544] "Microsoft Default Manager"="C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-12 00:43:04 288088] "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 18:44:46 248552] "DivXUpdate"="C:\Program Files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 06:39:18 1164584] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 11:47:04 35760] "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 06:07:44 932288] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2010-09-08 18:17:42 421888] "Norton Online Backup"="C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-08 19:25:10 968536] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"= "C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"= "C:\\Program Files\\Symantec\\Norton Online Backup\\NOBuClient.exe"= R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [11/25/2010 2:19:34 AM 64288] R0 SymDS;Symantec Data Store;C:\WINDOWS\system32\drivers\NAV\1201000.025\SymDS.sys [10/15/2010 3:10:14 AM 339504] R0 SymEFA;Symantec Extended File Attributes;C:\WINDOWS\system32\drivers\NAV\1201000.025\SymEFA.sys [10/15/2010 3:10:14 AM 666672] R1 BHDrvx86;BHDrvx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20101104.001\BHDrvx86.sys [11/3/2010 4:07:06 PM 691248] R1 SymIRON;Symantec Iron Driver;C:\WINDOWS\system32\drivers\NAV\1201000.025\Ironx86.sys [10/15/2010 3:10:14 AM 134704] R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [8/27/2009 4:09:10 PM 1253376] R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [7/11/2010 7:02:54 PM 238952] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [9/22/2010 11:46:07 PM 1375992] R2 NAV;Norton AntiVirus;C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe [10/15/2010 3:10:05 AM 126904] R2 NOBU;Norton Online Backup;C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [6/8/2010 11:20:16 AM 2057560] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/26/2010 11:01:50 PM 102448] R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [7/11/2010 7:02:54 PM 36608] R3 IDSxpx86;IDSxpx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20101129.001\IDSXpx86.sys [10/19/2010 12:36:22 PM 341880] R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys [9/22/2010 11:46:08 PM 15264] S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [5/29/2010 9:55:30 AM 136176] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [8/7/2008 10:10:02 AM 3276800] — Other Services/Drivers In Memory — *NewlyCreated* - FSUSBEXDISK *NewlyCreated* - NMSCFG . Contents of the 'Scheduled Tasks' folder 2010-11-28 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job - C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-09-23 07:46:07 . 2010-11-28 10:44:51] 2010-11-30 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-29 17:55:30 . 2010-05-29 17:55:26] 2010-11-30 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-29 17:55:30 . 2010-05-29 17:55:26] 2010-11-30 C:\WINDOWS\Tasks\Norton Security Scan for MJR.job - C:\Program Files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-05 12:26:53 . 2010-08-24 17:06:50] 2010-11-29 C:\WINDOWS\Tasks\Norton Security Scan for MJR_2.job - C:\Program Files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-05 12:26:53 . 2010-08-24 17:06:50] . . ——- Supplementary Scan ——- . uStart Page = about:blank Trusted Zone: pureplay.com\www FF - ProfilePath - C:\Documents and Settings\MJR_2\Application Data\Mozilla\Firefox\Profiles\tlzdhnsi.default\ FF - component: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\components\IPSFFPl.dll FF - plugin: C:\Documents and Settings\MJR_2\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll FF - plugin: C:\Program Files\Veetle\Player\npvlc.dll FF - plugin: C:\Program Files\Veetle\plugins\npVeetle.dll FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Extension: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Documents and Settings\MJR_2\Application Data\Mozilla\Firefox\Profiles\tlzdhnsi.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} FF - Extension: vShare Plugin: vshare@toolbar - C:\Documents and Settings\MJR_2\Application Data\Mozilla\Firefox\Profiles\tlzdhnsi.default\extensions\vshare@toolbar FF - Extension: Java Quick Starter: [removed] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff FF - Extension: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn . - - - - ORPHANS REMOVED - - - - HKLM-Run-NPSStartup - (no file) HKLM-Run-Gamevance - C:\Program Files\Gamevance\gamevance32.exe AddRemove-Adobe Flash Player Plugin - C:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_Plugin.exe AddRemove-Gamevance - C:\Program Files\Gamevance\gvun.exe AddRemove-01_Simmental - C:\Program Files\Samsung\USB Drivers\01_Simmental\Uninstall.exe AddRemove-02_Siberian - C:\Program Files\Samsung\USB Drivers\02_Siberian\Uninstall.exe AddRemove-03_Swallowtail - C:\Program Files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe AddRemove-04_semseyite - C:\Program Files\Samsung\USB Drivers\04_semseyite\Uninstall.exe AddRemove-05_Sloan - C:\Program Files\Samsung\USB Drivers\05_Sloan\Uninstall.exe AddRemove-06_Spencer - C:\Program Files\Samsung\USB Drivers\06_Spencer\Uninstall.exe AddRemove-07_Schorl - C:\Program Files\Samsung\USB Drivers\07_Schorl\Uninstall.exe AddRemove-08_EMPChipset - C:\Program Files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe AddRemove-09_Hsp - C:\Program Files\Samsung\USB Drivers\09_Hsp\Uninstall.exe AddRemove-11_HSP_Plus_Default - C:\Program Files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe AddRemove-16_Shrewsbury - C:\Program Files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe AddRemove-17_EMP_Chipset2 - C:\Program Files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe AddRemove-18_Zinia_Serial_Driver - C:\Program Files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe AddRemove-19_VIA_driver - C:\Program Files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe AddRemove-20_NXP_Driver - C:\Program Files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe AddRemove-21_Searsburg - C:\Program Files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe AddRemove-22_WiBro_WiMAX - C:\Program Files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
Ok, in the Combofix file there are 8 text documents titled: Combofix (this one i already posted), Osid, Resident, mbr, pend, version, mbr and the last is RegLocks. The only one of them that really has something in it is RegLocks. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@C:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="C:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" Im gona try in safe mode.
I found this file WAY far from other C-fix folders. It was actually in a folder labled for something else. This is a text document titled "Combofix-quarantined-files-Notepad". Here's whats in that: 2010-11-30 14:01:52 . 2010-11-30 14:01:52 924 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-22_WiBro_WiMAX.reg.dat 2010-11-30 14:01:52 . 2010-11-30 14:01:52 912 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-21_Searsburg.reg.dat 2010-11-30 14:01:52 . 2010-11-30 14:01:52 916 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-20_NXP_Driver.reg.dat 2010-11-30 14:01:52 . 2010-11-30 14:01:52 916 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-19_VIA_driver.reg.dat 2010-11-30 14:01:52 . 2010-11-30 14:01:52 948 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-18_Zinia_Serial_Driver.reg.dat 2010-11-30 14:01:52 . 2010-11-30 14:01:52 924 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-17_EMP_Chipset2.reg.dat 2010-11-30 14:01:52 . 2010-11-30 14:01:52 912 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-16_Shrewsbury.reg.dat 2010-11-30 14:01:52 . 2010-11-30 14:01:52 936 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-11_HSP_Plus_Default.reg.dat 2010-11-30 14:01:52 . 2010-11-30 14:01:52 884 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-09_Hsp.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 916 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-08_EMPChipset.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 896 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-07_Schorl.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 904 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-06_Spencer.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 892 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-05_Sloan.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 908 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-04_semseyite.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 920 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-03_Swallowtail.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 908 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-02_Siberian.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 908 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-01_Simmental.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 540 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-Gamevance.reg.dat 2010-11-30 14:01:51 . 2010-11-30 14:01:51 1,568 —-a-w- C:\Qoobox\Quarantine\Registry_backups\AddRemove-Adobe Flash Player Plugin.reg.dat 2010-11-30 14:01:27 . 2010-11-30 14:01:27 143 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-Gamevance.reg.dat 2010-11-30 14:01:26 . 2010-11-30 14:01:26 97 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-NPSStartup.reg.dat 2010-11-27 14:08:44 . 2010-12-02 09:53:06 4,935 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2010-11-27 13:56:39 . 2010-12-02 09:48:54 459 —-a-w- C:\Qoobox\Quarantine\catchme.log

Extract the file and run it.

Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)

Please then boot into Safe Mode by tapping F8 whilst booting, and run Combofix again.

Please post the content of the TDSSKiller log, and the Combofix log
Ok Raktor, I have a whole new scenario, that's if your interested. I ended up taking it to get restored. Now what I don't understand is that the system has been wiped completely clean but I STILL don't have the speed I had about a month ago. Do you still want to continue with this? I hope so.
If you're still encountering the same issue after restoring, it indicates a possible problem with the hardware inside the machine itself instead - rather than malware.

Please post in our Microsoft Windows forum instead, and they'll help you out, since this doesn't appear to be a malware related issue. Tell them that everything in here showed no real sign of bugs.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI