This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Suddenly running slow [Closed]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi my names Ryan. My Laptop, running Windows Vista, is suddenly running slow in all areas (log-in, web browsing, opening programs…etc.) Looks like a virus to me. I'd appreciate any help or advice. Thanks.
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-

There are many reasons why a computer may run slowly and malware is just one of them. Let's give a look. :)
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs made by CKScanner, DDS and aswMBR. :)
CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11.QRAAUV —– EOF —– . DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by [removed] at 20:13:48 on 2012-03-19 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3963.1715 [GMT -4:00] . AV: Webroot SecureAnywhere *Enabled/Updated* {9C0666FC-6C7D-3E97-3C40-0C6B33FC7401} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Webroot SecureAnywhere *Enabled/Updated* {27678718-4A47-3119-06F0-3719487B3EBC} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\agr64svc.exe C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCameraSrv.exe C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\TOSHIBA\rselect\RSelSvc.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe C:\Program Files (x86)\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\system32\TODDSrv.exe C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe C:\Program Files\TOSHIBA\TECO\TecoService.exe C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\TOSHIBA\TECO\Teco.exe C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe C:\Windows\ehome\ehmsas.exe C:\Windows\ehome\ehsched.exe C:\Windows\ehome\ehRecvr.exe C:\Windows\system32\igfxext.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\splwow64.exe C:\Program Files (x86)\Webroot\WRSA.exe C:\Program Files (x86)\Webroot\WRSA.exe C:\Windows\system32\wuauclt.exe C:\Users\r.wroblewski\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\r.wroblewski\AppData\Local\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE C:\Users\r.wroblewski\Desktop\CKScanner.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB uDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO: Webroot Browser Helper Object: {e08861fe-8847-4b2a-8ec2-08edb20e4020} - C:\Program Files (x86)\Webroot\Security\install\products\WISE\toolbar\LPBar.dll TB: Webroot Toolbar: {d84a64a0-f2b2-4975-b264-3a3bce8d57d6} - C:\Program Files (x86)\Webroot\Security\install\products\WISE\toolbar\LPBar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [Google Update] "C:\Users\r.wroblewski\AppData\Local\Google\Update\GoogleUpdate.exe" /c uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe mRun: [TWebCamera] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun mRun: [NDSTray.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe" mRun: [cfFncEnabler.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe" mRun: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 mRun: [BSDAppUpdater] "C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe" mRun: [WRSVC] "C:\Program Files (x86)\Webroot\WRSA.exe" -ul mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{1F71F484-D97C-4FA5-BB70-F09638A5EDED} : DhcpNameServer = 192.168.1.1 BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO-X64: AcroIEHelperStub - No File BHO-X64: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO-X64: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll BHO-X64: Webroot Browser Helper Object: {e08861fe-8847-4b2a-8ec2-08edb20e4020} - C:\Program Files (x86)\Webroot\Security\install\products\WISE\toolbar\LPBar.dll BHO-X64: Webroot Browser Helper Object - No File TB-X64: Webroot Toolbar: {d84a64a0-f2b2-4975-b264-3a3bce8d57d6} - C:\Program Files (x86)\Webroot\Security\install\products\WISE\toolbar\LPBar.dll TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll mRun-x64: [TWebCamera] "%ProgramFiles(x86)%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun mRun-x64: [NDSTray.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe" mRun-x64: [cfFncEnabler.exe] "C:\Program Files (x86)\TOSHIBA\ConfigFree\cfFncEnabler.exe" mRun-x64: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 mRun-x64: [BSDAppUpdater] "C:\Program Files (x86)\Common Files\BSD\AppUpdater\BSDChecker.exe" mRun-x64: [WRSVC] "C:\Program Files (x86)\Webroot\WRSA.exe" -ul mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" . ============= SERVICES / DRIVERS =============== . R? clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64 R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86 R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64 R? gupdate;Google Update Service (gupdate) R? gupdatem;Google Update Service (gupdatem) R? PerfHost;Performance Counter DLL Host R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader R? RtsUIR;Realtek IR Driver R? USBAAPL64;Apple Mobile USB Driver R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0 S? camsvc;TOSHIBA Web Camera Service S? ConfigFree Gadget Service;ConfigFree Gadget Service S? ConfigFree Service;ConfigFree Service S? FontCache;Windows Font Cache Service S? FwLnk;FwLnk Driver S? PGEffect;Pangu effect driver S? RSELSVC;TOSHIBA Modem region select service S? rtl819xpn64;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver S? RtlProt;Realtke RtlProt WLAN Utility Protocol Driver S? TMachInfo;TMachInfo S? tos_sps64;TOSHIBA tos_sps64 Service S? TOSHIBA eco Utility Service;TOSHIBA eco Utility Service S? TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service S? TPCHSrv;TPCH Service S? TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver S? WRkrn;WRkrn S? WRSVC;WRSVC . =============== File Associations =============== . JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %* . =============== Created Last 30 ================ . 2012-03-18 14:43:08 69000 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B397DE39-5470-422D-8CEA-67850D7C8959}\offreg.dll 2012-03-18 03:08:03 ——– d—–w- C:\Users\r.wroblewski\AppData\Local\Temp 2012-03-17 02:02:22 8643640 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B397DE39-5470-422D-8CEA-67850D7C8959}\mpengine.dll 2012-03-13 21:09:46 708096 —-a-w- C:\Windows\System32\rdpencom.dll 2012-03-13 21:09:46 613376 —-a-w- C:\Windows\SysWow64\rdpencom.dll 2012-03-13 21:09:46 209920 —-a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-03-08 16:23:34 ——– d—–w- C:\Program Files\CCleaner . ==================== Find3M ==================== . 2012-03-16 14:39:48 98160 —-a-w- C:\Windows\System32\WRusr.dll 2012-03-16 14:39:48 146040 —-a-w- C:\Windows\SysWow64\WRusr.dll 2012-03-16 14:39:48 111592 —-a-w- C:\Windows\System32\drivers\WRkrn.sys 2012-02-23 14:18:36 279656 ——w- C:\Windows\System32\MpSigStub.exe 2012-02-14 16:49:43 327680 —-a-w- C:\Windows\System32\d3d10_1core.dll 2012-02-14 16:49:43 196096 —-a-w- C:\Windows\System32\d3d10_1.dll 2012-02-14 15:45:30 219648 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll 2012-02-14 15:45:30 160768 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2012-02-13 14:38:31 2002944 —-a-w- C:\Windows\System32\d3d10warp.dll 2012-02-13 14:12:08 1172480 —-a-w- C:\Windows\SysWow64\d3d10warp.dll 2012-02-13 14:06:48 834048 —-a-w- C:\Windows\System32\d2d1.dll 2012-02-13 14:03:11 1555968 —-a-w- C:\Windows\System32\DWrite.dll 2012-02-13 13:47:57 683008 —-a-w- C:\Windows\SysWow64\d2d1.dll 2012-02-13 13:44:40 1068544 —-a-w- C:\Windows\SysWow64\DWrite.dll 2012-02-02 15:34:25 2765824 —-a-w- C:\Windows\System32\win32k.sys 2012-01-03 14:25:21 404992 —-a-w- C:\Windows\System32\drivers\afd.sys . ============= FINISH: 20:22:06.68 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 6/6/2011 9:48:13 PM System Uptime: 3/18/2012 7:27:27 PM (25 hours ago) . Motherboard: TOSHIBA | | Portable PC Processor: Pentium® Dual-Core CPU T4300 @ 2.10GHz | CPU | 1200/800mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 287 GiB total, 156.637 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . ==== Installed Programs ====================== . Update for Microsoft Office 2007 (KB2508958) Acrobat.com Adobe AIR Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Reader 9.1 Amazon Links Apple Application Support Apple Software Update Compatibility Pack for the 2007 Office system Direct DiscRecorder DVD MovieFactory for TOSHIBA Google Chrome Google Toolbar for Internet Explorer Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Java™ 6 Update 11 LightScribe 1.4.124.1 MediaWidget 6.0 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Standard 2007 Microsoft Office Suite Activation Assistant Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Works MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Netzero Internet Access Installer Picasa 2 QuickBooks Financial Center QuickTime Realtek 8136 8168 8169 Ethernet Driver Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader Realtek WiFi Protected Setup Library Realtek WLAN Driver Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2553089) Security Update for 2007 Microsoft Office System (KB2553090) Security Update for 2007 Microsoft Office System (KB2584063) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Skype Launcher Spotify TOSHIBA Agreement Notification Utility Toshiba Application Installer TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA DVD PLAYER TOSHIBA eco Utility TOSHIBA Extended Tiles for Windows Mobility Center TOSHIBA Face Recognition TOSHIBA Hardware Setup TOSHIBA HDD/SSD Alert TOSHIBA Internal Modem Region Select Utility Toshiba Quality Application Toshiba Registration Toshiba Resources Page TOSHIBA Service Station TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA Supervisor Password TOSHIBA Value Added Package TOSHIBA Web Camera Application Update for 2007 Microsoft Office System (KB2284654) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2597970) 32-Bit Edition Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Outlook 2007 (KB2583910) Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) Webroot SecureAnywhere WildTangent Games . ==== Event Viewer Messages From Past Week ======== . 3/12/2012 3:19:11 PM, Error: Service Control Manager [7031] - The WRSVC service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. . ==== End Of File =========================== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-19 20:28:47 —————————– 20:28:47.395 OS Version: Windows x64 6.0.6002 Service Pack 2 20:28:47.395 Number of processors: 2 586 0x170A 20:28:47.411 ComputerName: RWROBLEWSKI-PC UserName: r.wroblewski 20:28:49.423 Initialize success 20:29:26.469 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 20:29:26.469 Disk 0 Vendor: TOSHIBA_ FG01 Size: 305245MB BusType: 3 20:29:26.500 Disk 0 MBR read successfully 20:29:26.500 Disk 0 MBR scan 20:29:26.516 Disk 0 Windows VISTA default MBR code 20:29:26.531 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 20:29:26.547 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 293456 MB offset 3074048 20:29:26.578 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 10288 MB offset 604071936 20:29:26.625 Disk 0 scanning C:\Windows\system32\drivers 20:29:36.813 Service scanning 20:30:06.346 Service WRkrn C:\Windows\System32\drivers\WRkrn.sys **LOCKED** 32 20:30:07.391 Modules scanning 20:30:07.391 Disk 0 trace - called modules: 20:30:07.453 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 20:30:07.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006585790] 20:30:07.469 3 CLASSPNP.SYS[fffffa60011d2c33] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004bd9050] 20:30:07.484 Scan finished successfully 20:30:40.106 Disk 0 MBR has been saved successfully to "C:\Users\r.wroblewski\Desktop\MBR.dat" 20:30:40.199 The log file has been saved successfully to "C:\Users\r.wroblewski\Desktop\aswMBR.txt" aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-19 20:28:47 —————————– 20:28:47.395 OS Version: Windows x64 6.0.6002 Service Pack 2 20:28:47.395 Number of processors: 2 586 0x170A 20:28:47.411 ComputerName: RWROBLEWSKI-PC UserName: r.wroblewski 20:28:49.423 Initialize success 20:29:26.469 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 20:29:26.469 Disk 0 Vendor: TOSHIBA_ FG01 Size: 305245MB BusType: 3 20:29:26.500 Disk 0 MBR read successfully 20:29:26.500 Disk 0 MBR scan 20:29:26.516 Disk 0 Windows VISTA default MBR code 20:29:26.531 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 20:29:26.547 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 293456 MB offset 3074048 20:29:26.578 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 10288 MB offset 604071936 20:29:26.625 Disk 0 scanning C:\Windows\system32\drivers 20:29:36.813 Service scanning 20:30:06.346 Service WRkrn C:\Windows\System32\drivers\WRkrn.sys **LOCKED** 32 20:30:07.391 Modules scanning 20:30:07.391 Disk 0 trace - called modules: 20:30:07.453 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 20:30:07.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006585790] 20:30:07.469 3 CLASSPNP.SYS[fffffa60011d2c33] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004bd9050] 20:30:07.484 Scan finished successfully 20:30:40.106 Disk 0 MBR has been saved successfully to "C:\Users\r.wroblewski\Desktop\MBR.dat" 20:30:40.199 The log file has been saved successfully to "C:\Users\r.wroblewski\Desktop\aswMBR.txt" 20:33:46.854 Disk 0 MBR has been saved successfully to "C:\Users\r.wroblewski\Desktop\MBR.dat" 20:33:46.963 The log file has been saved successfully to "C:\Users\r.wroblewski\Desktop\aswMBR.txt"
ListParts by Farbar Version: 12-03-2012 03 Ran by [removed] (administrator) on 19-03-2012 at 20:51:57 Windows Vista (X64) Running From: C:\Users\[removed]\Downloads Language: 0409 ************************************************************ ========================= Memory info ====================== Percentage of memory in use: 52% Total physical RAM: 3963.05 MB Available physical RAM: 1898.34 MB Total Pagefile: 8145.36 MB Available Pagefile: 5990.29 MB Total Virtual: 8192 MB Available Virtual: 8191.92 MB ======================= Partitions ========================= 1 Drive c: (TI100680V0E) (Fixed) (Total:286.58 GB) (Free:156.6 GB) NTFS ==>[Drive with boot components (obtanied from BCD)]
Hi,

I am not seeing anything jumping out at me. Please do the following…

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:
C:\Documents and Settings\\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
———-

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]
  • Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
———-

In your next reply please post the logs created by Malwarebytes and ESET online scanner.
Sorry I'm posting this again. Last thread got shut down yesterday because I let it sit for too long. Sorry for wasting anyone's time. Would Still appreciate help and I will be more diligent this time. Hi my names Ryan. My Laptop, running Windows Vista, is suddenly running slow in all areas (log-in, web browsing, opening programs…etc.) Looks like a virus to me. I'd appreciate any help or advice. Thanks.
Topic reopened….OP returned. Merged new topic with this one to continue with malware removal.
Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.03.19.06 Windows Vista Service Pack 2 x64 NTFS Internet Explorer 9.0.8112.16421 r.wroblewski :: RWROBLEWSKI-PC [administrator] 3/26/2012 4:08:45 PM mbam-log-2012-03-26 (16-08-45).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 191271 Time elapsed: 10 minute(s), 5 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI