This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My computer is so slow

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I did both scans for both the software. The eset scan took over an hour so I know how that went. The mbam scan didn't detect any threat but the eset scan detected 21 threats on my computer. Here is the mbam scan results: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5520 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/15/2011 3:28:34 PM mbam-log-2011-01-15 (15-28-33).txt Scan type: Quick scan Objects scanned: 148073 Time elapsed: 8 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I'll post the eset scan in the next post
Here is my eset scan results:

C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\1\7af69081-6f77b63e multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\10\1d57f04a-3d30a16d multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\11\16818dcb-28884920 multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\11\2e67514b-58ff6766 a variant of Java/TrojanDownloader.OpenStream.NAY trojan
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\16\49409950-409f0062 multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\19\30d181d3-6821b380 multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\33\3e20d921-1f92f0fb multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\34\ec2a1e2-7b0d1297 multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\39\52b785e7-3c0457af multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\46\5862e52e-22f6d545 multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\56\11e72f8-7fe67e1f multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\62\4e6f0cfe-1ad43b87 multiple threats
C:\Documents and Settings\Dad Teat\Application Data\Sun\Java\Deployment\cache\6.0\9\6d1909c9-4204d509 multiple threats
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\10\4c562fca-250a9a44 a variant of Java/TrojanDownloader.OpenStream.NAS trojan
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\13\7ad1bf4d-4937cb35 multiple threats
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\17\47b9e491-37490f1c a variant of Java/TrojanDownloader.OpenStream.NAS trojan
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\31\4ec704df-18329222 multiple threats
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\39\448e3767-2e561c0d multiple threats
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\50\170b44f2-4720ec62 multiple threats
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\58\2606caba-43c1e0c8 multiple threats
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\8\353109c8-41195153 multiple threats

These are all the threats that came up on there.

Hello Josh_N,
In a previous post you said that you were confused, what are you confused about?
Bill


I was confused basically about if I should keep the stuff we were working with like the mini scanner on my desktop or delete them. That's what.

Also, how is your pc running now? Is it any better?


It is getting a bit better. When I log on now it never goes blank.:) Plus the taskbar rarely freezes anymore.
I'm starting to think this is really helping. Maybe I should recommend this site to some of my friends
Way to go Josh_N, :popcorn: We're all most done..

To fix the problems EST found please do this…
Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Next
Please update your Adobe at http://get.adobe.com/reader/otherversions/ , this is the latest version.

Next
Rerun DDS and post a new DDS.txt

Please post how your PC is running and if you have any more issues.

Thanks
Bill
I downloaded TFC and when I used it, I didn't realize how stuff was hiding in my temp storage. :pullhair: I also did the DDS thing again and here are the results: DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 10:16:52.76 on Sun 01/16/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_23 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.223.112 [GMT -6:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\sistray.EXE C:\WINDOWS\system32\keyhook.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Documents and Settings\Josh\Desktop\Juogo\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SiSUSBRG] c:\windows\SiSUSBrg.exe mRun: [SiS Tray] c:\windows\system32\sistray.EXE mRun: [SiS Windows KeyHook] c:\windows\system32\keyhook.exe mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [SoundMan] SOUNDMAN.EXE mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1272494207687 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1272494194546 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\josh\applic~1\mozilla\firefox\profiles\r6r6dtbb.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.com FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2011-01-15 21:32:42 ——– d—–w- c:\program files\ESET 2011-01-15 20:28:35 ——– d—–w- c:\docume~1\josh\applic~1\Malwarebytes 2011-01-15 20:28:24 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-01-15 20:28:23 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2011-01-15 20:28:17 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-01-15 20:28:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-01-14 23:24:35 ——– d-sha-r- C:\cmdcons 2011-01-14 23:21:13 98816 —-a-w- c:\windows\sed.exe 2011-01-14 23:21:13 89088 —-a-w- c:\windows\MBR.exe 2011-01-14 23:21:13 256512 —-a-w- c:\windows\PEV.exe 2011-01-14 23:21:13 161792 —-a-w- c:\windows\SWREG.exe 2011-01-14 23:21:02 ——– d—–w- C:\ComboFix 2011-01-14 22:50:23 ——– d—–w- c:\windows\system32\XPSViewer 2011-01-14 22:49:25 89088 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2011-01-14 22:48:54 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2011-01-14 22:48:54 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2011-01-14 22:48:54 597504 ——w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2011-01-14 22:48:54 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll 2011-01-14 22:48:54 575488 ——w- c:\windows\system32\xpsshhdr.dll 2011-01-14 22:48:54 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll 2011-01-14 22:48:54 1676288 ——w- c:\windows\system32\xpssvcs.dll 2011-01-14 22:48:54 117760 ——w- c:\windows\system32\prntvpt.dll 2011-01-14 22:48:51 ——– d—–w- C:\04ffeb3a9dcd4b26e67712e824 2011-01-14 22:29:22 221184 —-a-w- c:\windows\system32\wmpns.dll 2011-01-10 00:37:30 ——– d—–w- c:\docume~1\josh\applic~1\LaxiusParty 2011-01-04 17:20:19 ——– d—–w- C:\found.002 2010-12-29 21:15:21 ——– d—–w- C:\found.001 2010-12-25 00:40:03 ——– d—–w- C:\found.000 ==================== Find3M ==================== 2010-11-18 18:12:44 81920 —-a-w- c:\windows\system32\isign32.dll 2010-11-13 00:53:06 472808 —-a-w- c:\windows\system32\deployJava1.dll 2010-11-12 22:34:10 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-11-09 14:52:35 249856 —-a-w- c:\windows\system32\odbc32.dll 2010-11-06 00:26:58 916480 —-a-w- c:\windows\system32\wininet.dll 2010-11-06 00:26:58 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-11-06 00:26:58 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2010-11-03 12:25:54 385024 —-a-w- c:\windows\system32\html.iec 2010-10-28 13:13:22 290048 —-a-w- c:\windows\system32\atmfd.dll 2010-10-26 13:25:00 1853312 —-a-w- c:\windows\system32\win32k.sys ============= FINISH: 10:17:53.87 =============== The other log is attached on this post.

Attachments:

Just a quick note, My PC is running better than it did before I came to you. You guys are a major help.:) I rarely get a error report message saying something doesn't respond anymore.
Hi Josh_N

I see —_ˆÙ•·˜^ƒyƒ‹ƒ\ƒi listed as an installed program between Adobe Reader X and BitTorrent in the Attach.txt. Would you look in Control Panel -> Add or Remove Programs and post the program listed between between Adobe Reader X and BitTorrent, please.

Thanks
Bill
Hello Josh_N :clap:

I saw 3 found folders in C: these inicate bad sectors from your hard drive. They may have been caused by the rootkit we removed or they may mean that your hd is starting to fail. If you more of them show up you may want to post in the Hardware forum for advice on how to handle the problem.

Now for some clean up….

To remove HJT R/click on HiJackThis.exe on the desltop and delete and the same for any saved HJT.log files

To remove DDS R/click on DDS.exe on the desktop and the same for any dds.txt and attach.txt files saved

To remove GMER R/click on GMER.exe on the desktop and the same for any GMER.txt

To remove TDSSkiller R/Click TDSSKiller on the desktop and delete, log files to delete are in c:\TDSS*.*

MalwareBytes You may keep this and use it periodically, be sure to update before running. If you don't want it any more you can remove it from control panel -> Add or Remove Programs.

TFC This is another keeper but if you do not want it just delete from your desktop.

:thumbup: Your logs are finally clean and the machine seems to be performing as it should. You know how much work and effort you've had to put into getting it back into working order, so hopefully you can impress upon the others who use this machine, to be more careful.

For the future safety of this machine and your data, try to ensure they sit down and read the following threads: (it won't take them very long)

Cracked/Illegal Software

Perils of P2P File Sharing

Think Prevention


If there aren't any more problems, we have some final housekeeping to tend to now. Please do not skip this step as it will implement important cleanup procedures, as well as reset your System Restore by flushing out previous restore points (which contain the infections) and create a new restore point for you.


Click Start > Run and copy/paste, or type the following bolded text into the Run box and click OK:

ComboFix /uninstall

——————————————————————–

To help protect your computer in the future I recommend that you follow these steps and look into the following free programs:

* Microsoft Windows Update - http://www.windowsupdate.com
Visit regularly. This will ensure your computer always has the latest security updates. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

* SpywareBlaster to help prevent spyware from installing in the first place. Install & update SpywareBlaster with the latest definitions. After you have updated, click the button - enable protection for all unprotected items.
o SpywareBlaster is a preventative program. It sets flags in the registry to prevent the running of a specific list of bad spyware related ActiveX controls. It will block any bad ActiveX from running in Internet Explorer and Firefox if it's listed in their database (which you should update frequently). To view their database and list of restricted sites, launch the program and click on each of the tabs on the main display page.

* WOT, Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
o Green to go
o Yellow for caution
o Red to stop
WOT has an addon available for both Firefox and IE.


* Scan here http://secunia.com/software_inspector/ for out of date & vulnerable common applications on your computer

* BACKING UP YOUR REGISTRY
ERUNT will create daily complete backups of your computer's Registry. Whilst System Restore does the same thing, a corrupt registry file may prevent Windows from booting & this effectively renders System Restore unavailable by simple means. With ERUNT, you're able to restore the damaged Registry.

Vista/Windows 7 users - see this link for proper setup of Erunt http://www.winhelponline.com/blog/ba…y-using-erunt/


NTREGOPT works by recreating each registry hive "from scratch", thus removing any slack space that may be left from previously modified or deleted keys. In other words, it compacts the Registry to a small size which allows Windows to load & perform faster.

Please respond back that you understand the above and agree with my recommendation of posting in the windows forum. Also, let me know if you have any questions. Once you've posted for the Tech Team, this thread will be closed.
Surf Safely :wavey:
RedCar92
Bill
What 3 folders indicate bad sectors and where are they located? What does hd mean? h drive? :huh: I'm keeping TFC just in case and I downloaded all the programs you have on your recent post. About your topics on cracked software and P2P file sharing, I downloaded cracked software and used a P2P download service without a problem. I don't if that was the cause of the hidden problems or what but my computer ran normally even with those. I also couldn't update my audio driver, so is it safe to now?:huh: I agree about posting in the windows forum? What's the link again? So if I have anymore problems I not going to post here anymore you're saying? Post back
I'm sorry :blush: I was not too clear nor specific about those 3 folders. They are
  • C:\found.002
  • C:\found.001
  • C:\found.000
They are hidden folders so you will have to do this in order to see them.,

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.

HD is hard drive, in your case, c:. Some times when a hard drive like c: starts to go bad, Windows cannot read the files without trying several times. Windows will sense this and run Disk Check to try and fix the problem. If bad sectors (spots) are found Window will create a folder called c:\Found.000 and put information in it. The next time it creates Found.002 and so on. Certain viruses can do the same thing. What I am saying is, if you see c:\found.003 in the near future it may mean that the Hard Drive may be going bad. Should this be the case, you should post the problem here. These are good techs and will be better able to help you than I.

Should you have a virus or spyware problem you may post it here any time but you should start a new topic.

I did not see any signs of Peer-to_Peer or cracked (illegal) software on your PC so what ever you were doing is probably OK.

You are safe to update your audio drivers. If you have trouble updating you may want to post here

If you have any more questions, please ask away. If I don't have the answer, I will find someone who does.

Regards
Bill

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI