This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer is VERY slow

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi All, My computer is VERY slow. It does not seem to be doing anything extremely obnoxious like redirecting or anything but it is simply unusable in this condition. I have attached a dds log below. Thank you in advance. . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 15:48:53.97 on Mon 12/03/2012 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.166 [GMT -6:00] . FW: Trend Micro OfficeScan Enterprise Client Firewall *Disabled* . ============== Running Processes =============== . C:\WINXP\system32\ibmpmsvc.exe C:\WINXP\system32\Ati2evxx.exe C:\WINXP\system32\svchost -k DcomLaunch svchost.exe C:\WINXP\System32\svchost.exe -k netsvcs C:\WINXP\system32\S24EvMon.exe svchost.exe svchost.exe C:\WINXP\system32\spoolsv.exe c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe C:\WINXP\System32\QCONSVC.EXE C:\WINXP\system32\RegSrvc.exe C:\WINXP\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe C:\WINXP\system32\TpKmpSVC.exe C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe C:\Program Files\ORL\VNC\WinVNC.exe C:\Program Files\Configuresoft\CSI Remote Client\CSIRemoteCSvc.exe C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe c:\program files\lenovo\system update\suservice.exe C:\WINXP\TEMP\ZBDF26.EXE C:\WINXP\system32\Ati2evxx.exe C:\WINXP\Explorer.EXE C:\WINXP\System32\svchost.exe -k HTTPFilter C:\WINXP\AGRSMMSG.exe C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe C:\WINXP\system32\taskswitch.exe C:\Program files\ThinkPad\ConnectUtilities\QCTRAY.EXE C:\Program files\ThinkPad\ConnectUtilities\QCWLICON.EXE C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe C:\WINXP\system32\RunDll32.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe C:\WINXP\system32\dla\tfswctrl.exe C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe C:\WINXP\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Microsoft Office Suites\Office12\ONENOTEM.EXE C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe C:\WINXP\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Documents and Settings\Administrator\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uWindow Title = Windows Internet Explorer provided by Chr. Hansen mDefault_Page_URL = hxxp://www.Chr-Hansen.com mStart Page = hxxp://www.Chr-Hansen.com uInternet Settings,ProxyOverride = ;;*.local mSearchAssistant = hxxp://www.google.com/ie_rsearch.html mCustomizeSearch = hxxp://www.google.com/ie_rsearch.html BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\winxp\system32\dla\tfswshx.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [ctfmon.exe] c:\winxp\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [IMJPMIG8.1] "c:\winxp\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [WinVNC] "c:\program files\orl\vnc\WinVNC.exe" -servicehelper mRun: [OfficeScanNT Monitor] "c:\program files\trend micro\officescan client\pccntmon.exe" -HideWindow mRun: [CoolSwitch] c:\winxp\system32\taskswitch.exe mRun: [QCTRAY] c:\program files\thinkpad\connectutilities\QCTRAY.EXE mRun: [QCWLICON] c:\program files\thinkpad\connectutilities\QCWLICON.EXE mRun: [TPHOTKEY] c:\progra~1\lenovo\pkgmgr\hotkey\TPHKMGR.exe mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor mRun: [BLOG] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe mRun: [NPDTray] c:\progra~1\thinkpad\utilit~1\NPDTray.exe mRun: [TP4EX] tp4ex.exe mRun: [imekrmig7.0] "c:\program files\common files\microsoft shared\ime\imkr7\IMEKRMIG.EXE" mRun: [IMSCMig] c:\progra~1\common~1\micros~1\ime\imsc40a\IMSCMIG.EXE /Preload mRun: [CJIMETIPSYNC] c:\program files\common files\microsoft shared\ime\imtc65\changjie\CINTLCFG.EXE /CJIMETIPSync mRun: [PHIMETIPSYNC] c:\program files\common files\microsoft shared\ime\imtc65\phonetic\TINTLCFG.EXE /PHIMETIPSync mRun: [IMJPMIG9.0] c:\progra~1\common~1\micros~1\ime\imjp9\IMJPMIG.EXE /Preload /Migration32 mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [dla] c:\winxp\system32\dla\tfswctrl.exe mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office suites\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\winxp\installer\{24c67b54-0718-445e-b663-3138d9246bd1}\Icon3E5562ED7.ico mPolicies-explorer: ForceClassicControlPanel = 1 (0x1) mPolicies-explorer: NoStrCmpLogical = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\mi0d1c~1\office12\EXCEL.EXE/3000 IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_01\bin\npjpi150_01.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi0d1c~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi0d1c~1\office12\REFIEBAR.DLL DPF: Microsoft XML Parser for Java - file://c:\winxp\java\classes\xmldso.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab Notify: AtiExtEvent - Ati2evxx.dll Notify: QConGina - QConGina.dll Notify: tpfnf2 - notifyf2.dll Notify: tphotkey - tphklock.dll . ============= SERVICES / DRIVERS =============== . R1 TPPWR;TPPWR;c:\winxp\system32\drivers\TPPWR.SYS [2008-12-22 16384] R2 CSIRemoteC;Configuresoft ECM Remote Client;c:\program files\configuresoft\csi remote client\CSIRemoteCSvc.exe [2006-4-25 102400] R2 OfcPfwSvc;OfficeScanNT Personal Firewall;c:\program files\trend micro\officescan client\OfcPfwSvc.exe [2006-8-9 233552] R2 TmFilter;Trend Micro Filter;c:\program files\trend micro\officescan client\tmxpflt.sys [2005-11-9 205328] R2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\officescan client\tmpreflt.sys [2005-11-9 36368] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-7 135664] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-7 135664] S3 QCNDISIF;QCNDISIF;c:\winxp\system32\drivers\qcndisif.sys [2008-12-22 12288] . =============== Created Last 30 ================ . 2012-12-02 20:01:27 ——– d—–w- c:\program files\iPod 2012-12-02 20:00:58 ——– d—–w- c:\program files\iTunes 2012-12-02 20:00:58 ——– d—–w- c:\docume~1\alluse~1\applic~1\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-12-02 19:49:01 ——– d—–w- c:\program files\Bonjour . ==================== Find3M ==================== . 2012-09-28 16:32:56 5989776 —-a-w- c:\winxp\system32\usbaaplrc.dll . ============= FINISH: 15:50:02.95 ===============
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!



Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing antying, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now


If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.
Ok…I downloaded the program and it seemed to be running fine…It loaded the Recovery Console and appeared to be scanning just fine. I walked away for the 10 minute scan. When I came back I had the blue screen of death. Now the machine will not boot…I get a read disk error at bootup. I will take the machine to work and have it rebuilt. Thanks anyway. Nate
We typically don't assist with machines used for business in these forums as your IT department should be the ones working on them. However, before you have the computer "rebuiilt" let's try booting into safe mode. A blue screen doesn't necessarily mean it's dead. (Unless you just want to have them rebuild it which is certainly your prerogative.)

Sometimes our tools do cause machines to crash. We do all that we can to prevent this, but each machine reacts differently to our tools. There is no way to predict ahead of time what will happen. Malware affects each machine differently.

I noticed the machine didn't appear to have XP service pack 3 which an IT department would most certainly want to install for security reasons. That is likely one of the reasons your machine appears to have a trojan on it. I would be happy to assist you in trying to get the machine up and running again, and if this is a personal machine, I would be more than happy to continue working with you to remove the trojan from your machine - the choice is yours. Either way, you can try the following to see if it will boot into safe mode so that you can attempt to shut it down normally and then reboot normally again.

Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account

    If you are able to successfully log in, then try shutting down normally and then reboot normally and see if that is successful
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would.
The machine is a personal machine and not used in any business. I am the IT Dept behind this machine (unfortunately). Fortunately, I can take it to work and they will rebuild it for me with a higher knowledge than my own. It will not boot in safe mode at all…Disk Read Error is all that will come up. Thanks for your help anyway. You guys do great work. I understand these things happen…no worries.
Disk read error could be a hardware thing too. :( I'll leave this topic open for a couple days before I close it out. However, reformatting the disc should clear out any malware that exists. Good luck!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI