This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Solved] Machine a lot slower than it used to be

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is the first of the files
VT Community Sign in ▼ My account ▼ Sign out Signing out… Languages ▼

VirusTotal's website has changed, we need new translations, do you feel like helping the community?
[removed]
Sign in to VT CommunitySafety ratings and user comments (disinfection, in-the-wild locations, reverse engineering reports, etc.) on malware and URLs, free and easy.
email
password
Keep me logged in
Sign in Signing in, please wait…
Login failed, please try again
Forgot your password? Create an account

Edit my profile
View my profile
Inbox

Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information…

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: UKCpInfo.sys
Submission date: 2011-01-24 06:30:00 (UTC)
Current status: queued queued analysing finished


Result: 0/ 43 (0.0%)
VT Community

not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.01.18.00 2011.01.17 -
AntiVir 7.11.1.220 2011.01.23 -
Antiy-AVL 2.0.3.7 2011.01.18 -
Avast 4.8.1351.0 2011.01.23 -
Avast5 5.0.677.0 2011.01.23 -
AVG 10.0.0.1190 2011.01.24 -
BitDefender 7.2 2011.01.24 -
CAT-QuickHeal 11.00 2011.01.24 -
ClamAV 0.96.4.0 2011.01.24 -
Commtouch 5.2.11.5 2011.01.24 -
Comodo 7484 2011.01.24 -
DrWeb 5.0.2.03300 2011.01.24 -
Emsisoft 5.1.0.1 2011.01.24 -
eSafe 7.0.17.0 2011.01.23 -
eTrust-Vet 36.1.8115 2011.01.21 -
F-Prot 4.6.2.117 2011.01.23 -
F-Secure 9.0.16160.0 2011.01.24 -
Fortinet 4.2.254.0 2011.01.24 -
GData 21 2011.01.24 -
Ikarus T3.1.1.97.0 2011.01.24 -
Jiangmin 13.0.900 2011.01.24 -
K7AntiVirus 9.77.3618 2011.01.22 -
Kaspersky 7.0.0.125 2011.01.24 -
McAfee 5.400.0.1158 2011.01.24 -
McAfee-GW-Edition 2010.1C 2011.01.23 -
Microsoft 1.6502 2011.01.24 -
NOD32 5811 2011.01.23 -
Norman 6.06.12 2011.01.23 -
nProtect 2011-01-18.01 2011.01.18 -
Panda 10.0.2.7 2011.01.23 -
PCTools 7.0.3.5 2011.01.23 -
Prevx 3.0 2011.01.24 -
Rising 23.41.05.03 2011.01.22 -
Sophos 4.61.0 2011.01.24 -
SUPERAntiSpyware 4.40.0.1006 2011.01.24 -
Symantec 20101.3.0.103 2011.01.24 -
TheHacker 6.7.0.1.119 2011.01.24 -
TrendMicro 9.120.0.1004 2011.01.24 -
TrendMicro-HouseCall 9.120.0.1004 2011.01.24 -
VBA32 3.12.14.3 2011.01.21 -
VIPRE 8176 2011.01.24 -
ViRobot 2011.1.24.4270 2011.01.24 -
VirusBuster 13.6.160.0 2011.01.23 -
Additional informationShow all
MD5 : 6587e2cddf436715873a92c045e53782
SHA1 : f8b9c526da675e5c22675fd8106dbb6bc579087d
SHA256: 5e3b8e761083032ddfab6f2671ca2799f87be888b9dd36b32c91c6ee14eae018
ssdeep: 3:L43VJJYGyQ:mjJY0
File size : 31 bytes
First seen: 2011-01-24 06:30:00
Last seen : 2011-01-24 06:30:00
TrID:
Unknown!
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned



VT Community

0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
VirusTotal Team
Add your comment… Remember that when you write comments as an anonymous user they receive the lowest possible reputation. So if you have not signed in yet don't forget to do so. How to markup your comments?

You can add basic styles to your comments using the following accepted bbcode tags:

text – bold
text – italics
text – underline
text – strikethrough
text
– preformatted text

You can also address comments to particular users using the "@" twitter-like mode. By prepending a "#" symbol to a word you can add custom tags to your comment, tags that can then be searched for.

Goodware Malware Spam attachment/link
P2P download Propagating via IM Network worm
Drive-by-download



Anonymous limit exceeded: anonymous users can only make one comment per file or URL, either sign in or register in order to continue making reviews on this item. Note that anonymous user discrimination is based on IP addresses, hence, it may be possible that another user behind your same proxy or NAT connection already made a review.

Preview commentEdit comment Post comment Posting comment…
Comment successfully posted







ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
VirusTotal © Hispasec Sistemas - Blog - Twitter - Contact: [removed]- Terms of Service & Privacy Policy
this is file 2 of STEP 1, I have not bothered to post the headings and the end details as they are the same as on the previous reply. Regards Les L0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: ctrldll.dll Submission date: 2011-01-24 06:38:17 (UTC) Current status: queued (#82) queued analysing finished Result: 0/ 43 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.01.18.00 2011.01.17 - AntiVir 7.11.1.220 2011.01.23 - Antiy-AVL 2.0.3.7 2011.01.18 - Avast 4.8.1351.0 2011.01.23 - Avast5 5.0.677.0 2011.01.23 - AVG 10.0.0.1190 2011.01.24 - BitDefender 7.2 2011.01.24 - CAT-QuickHeal 11.00 2011.01.24 - ClamAV 0.96.4.0 2011.01.24 - Commtouch 5.2.11.5 2011.01.24 - Comodo 7484 2011.01.24 - DrWeb 5.0.2.03300 2011.01.24 - Emsisoft 5.1.0.1 2011.01.24 - eSafe 7.0.17.0 2011.01.23 - eTrust-Vet 36.1.8115 2011.01.21 - F-Prot 4.6.2.117 2011.01.23 - F-Secure 9.0.16160.0 2011.01.24 - Fortinet 4.2.254.0 2011.01.24 - GData 21 2011.01.24 - Ikarus T3.1.1.97.0 2011.01.24 - Jiangmin 13.0.900 2011.01.24 - K7AntiVirus 9.77.3618 2011.01.22 - Kaspersky 7.0.0.125 2011.01.24 - McAfee 5.400.0.1158 2011.01.24 - McAfee-GW-Edition 2010.1C 2011.01.23 - Microsoft 1.6502 2011.01.24 - NOD32 5811 2011.01.23 - Norman 6.06.12 2011.01.23 - nProtect 2011-01-18.01 2011.01.18 - Panda 10.0.2.7 2011.01.23 - PCTools 7.0.3.5 2011.01.23 - Prevx 3.0 2011.01.24 - Rising 23.41.05.03 2011.01.22 - Sophos 4.61.0 2011.01.24 - SUPERAntiSpyware 4.40.0.1006 2011.01.24 - Symantec 20101.3.0.103 2011.01.24 - TheHacker 6.7.0.1.119 2011.01.24 - TrendMicro 9.120.0.1004 2011.01.24 - TrendMicro-HouseCall 9.120.0.1004 2011.01.24 - VBA32 3.12.14.3 2011.01.21 - VIPRE 8176 2011.01.24 - ViRobot 2011.1.24.4270 2011.01.24 - VirusBuster 13.6.160.0 2011.01.23 - Additional informationShow all MD5 : bcaa36cc4b4a62b2a8704d8ea669bc15 SHA1 : ba4cdc7471a97359b0a2599519618610abe56382 SHA256: b022df877599d5899d343a66e3958326969ad3a14046186016da5fcfa416a724
Here is the RootRepeal report Regards Les ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2011/01/24 06:51 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: E:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xB5998000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: E:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xBA628000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: E:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB4F27000 Size: 49152 File Visible: No Signed: - Status: -
Hi,

Please follow these steps:


Step 1 | Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    [2011/01/13 23:00:00 | 000,000,310 | —- | M] () – E:\WINDOWS\tasks\Regwork.job
    
    :Commands
    [purity]
    [EmptyFlash]
    [emptytemp]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • It will produce a log for you on reboot, please post that log in your next reply.

Step 2 | Please download Malwarebyte's Antimalware to your desktop: http://www.malwarebytes.org/mbam.php

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

Step 3 | Please go to http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan and then put the kettle on!
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place like your Desktop. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Copy and paste the report into your next.

[external image: Posted Image]

Hi, not sure that step1 worked as I had a blue box with red circle and an X within the circle. The box suggested that this was an OTL message, the message within the box Access violation at address 005CC7ED in module 'OTL.exe'. Read of address 00000000. I then pressed ok whithin the message box and closed down OTL. The screen then went to the picture I have on the screen with no programs or anything, then rebooted machine but no text of log. I will proceed no further until I hear otherwise from yourself. Regards Les
Hi,


We need to delete your current version of OTL (3.2.20.4) and get the latest one (3.2.20.5). Please follow these steps:


Step 1 | Clean up with OTL (this will delete your current version of OTL)

  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Step 2 | Download OTL from here: http://oldtimer.geekstogo.com/OTL.exe. Save it to your desktop and then run it. Check in the top of it's window that it's version 3.2.20.5 and then try again my last set of instructions.
Hi, sorry, I forgot to attach the log, follows. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. E:\WINDOWS\tasks\Regwork.job moved successfully. ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Default User ->Flash cache emptied: 56502 bytes User: Les ->Flash cache emptied: 65278 bytes User: LocalService User: NetworkService User: test ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Les ->Temp folder emptied: 16063462 bytes ->Temporary Internet Files folder emptied: 8578180 bytes ->Java cache emptied: 0 bytes ->Google Chrome cache emptied: 0 bytes ->Opera cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: test ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 521947 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 793102 bytes Total Files Cleaned = 25.00 mb Error starting restore point: System Restore is disabled. Error closing restore point: System Restore is disabled. OTL by OldTimer - Version 3.2.20.5 log created on 01252011_143400 Files\Folders moved on Reboot… E:\WINDOWS\temp\Perflib_Perfdata_69c.dat moved successfully. Registry entries deleted on Reboot…
Hi here is the log of step 2 Regards Les Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5594 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 25/01/2011 14:59:03 mbam-log-2011-01-25 (14-59-03).txt Scan type: Quick scan Objects scanned: 149918 Time elapsed: 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected)
Hi, went on to step 3 following RUN the program spent some time running updates, although I don't think these were really updates but download of the database, and then I get a message. Message from Web page 'Update has failed The program could not be started. Please close the winow of Kaspersky 7. 0 and start the program again from Kaspersky Lab. Regards Les
Hi,


Let's try ESET Online Scaner then.

Note: You can use either Internet Explorer or Mozilla FireFox for this scan.
Note: Be sure to add the ESET link I'll give you to your trusted sites.

  • Hold down Control then click on the following link to open a new window to http://www.eset.com/onlinescan/
  • Then click on: [external image: Posted Image]
  • Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
  • All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
HI, ESET seems to have worked ok, you mention not to touch mouse or keyboard, this is very difficult unless you swich off screen savers and such like, log is following Regards Les E:\Documents and Settings\Les\Application Data\49E675F611B159799C77249896186261\enemies-names.txt Win32/Adware.AntimalwareDoctor.AE.Gen application
Hi,

That's ok, thanks for the log.

Please download SystemLook from one of the links below and save it to your Desktop.

http://jpshortstuff.247fixes.com/SystemLook.exe
http://images.malwareremoval.com/jpshortstuff/SystemLook.exe

——————————————————————–
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    E:\Documents and Settings\Les\Application Data\49E675F611B159799C77249896186261 /s /md5

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi have done as requested and log follows, machine seems to vary quite a bit since I deleted the firewall and the Virus protection tool. Regards Les SystemLook 04.09.10 by jpshortstuff Log created at 09:43 on 27/01/2011 by Les Administrator - Elevation successful ========== dir ========== E:\Documents and Settings\Les\Application Data\49E675F611B159799C77249896186261 - Parameters: "/s /md5" —Files— enemies-names.txt –a—- 28842 bytes [21:48 14/07/2010] [21:48 14/07/2010] 8468629D8D2E984EB8E1D054B3DBB282 No folders found. -= EOF =-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI