This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow start-up

47 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Illukka, Here are the resul;ts of the scan. The relevant string appeared no less than 78 times in my registry! Is this very bad? REGEDIT4 ; RegSrch.vbs © Bill James ; Registry search results for string "4D36E96B-E325-11CE-BFC1-08002BE10318" 30-10-2005 14:52:18 ; NOTE: This file will be deleted when you close WordPad. ; You must manually save this file to a new location if you want to refer to it again later. ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\0000] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\0002] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers] "{4D36E96B-E325-11CE-BFC1-08002BE10318}"=hex(7):53,79,73,53,65,74,75,70,2e,44,\ [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*CPQA0D7] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0300] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0301] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0302] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0304] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0305] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0306] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0309] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp030a] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp030b] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0320] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0343] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0344] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\*pnp0345] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\hid_device_system_keyboard] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CriticalDeviceDatabase\PS2_KEYBOARD] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\Vid_1631&Pid_5002&MI_00\8&17221124&0&0000] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\Vid_1631&Pid_5002&MI_00\8&17221124&0&0000] "Driver"="{4D36E96B-E325-11CE-BFC1-08002BE10318}\\0000" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\Vid_1631&Pid_5002&MI_00\8&27c19b41&0&0000] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\HID\Vid_1631&Pid_5002&MI_00\8&27c19b41&0&0000] "Driver"="{4D36E96B-E325-11CE-BFC1-08002BE10318}\\0002" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\0000] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\0002] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CoDeviceInstallers] "{4D36E96B-E325-11CE-BFC1-08002BE10318}"=hex(7):53,79,73,53,65,74,75,70,2e,44,\ [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*CPQA0D7] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0300] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0301] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0302] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0304] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0305] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0306] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0309] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp030a] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp030b] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0320] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0343] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0344] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\*pnp0345] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\hid_device_system_keyboard] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CriticalDeviceDatabase\PS2_KEYBOARD] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\HID\Vid_1631&Pid_5002&MI_00\8&17221124&0&0000] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\HID\Vid_1631&Pid_5002&MI_00\8&17221124&0&0000] "Driver"="{4D36E96B-E325-11CE-BFC1-08002BE10318}\\0000" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\HID\Vid_1631&Pid_5002&MI_00\8&27c19b41&0&0000] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\HID\Vid_1631&Pid_5002&MI_00\8&27c19b41&0&0000] "Driver"="{4D36E96B-E325-11CE-BFC1-08002BE10318}\\0002" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\0000] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\0002] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CoDeviceInstallers] "{4D36E96B-E325-11CE-BFC1-08002BE10318}"=hex(7):53,79,73,53,65,74,75,70,2e,44,\ [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*CPQA0D7] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0300] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0301] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0302] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0304] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0305] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0306] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0309] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp030a] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp030b] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0320] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0343] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0344] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\*pnp0345] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\hid_device_system_keyboard] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase\PS2_KEYBOARD] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\HID\Vid_1631&Pid_5002&MI_00\8&17221124&0&0000] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\HID\Vid_1631&Pid_5002&MI_00\8&17221124&0&0000] "Driver"="{4D36E96B-E325-11CE-BFC1-08002BE10318}\\0000" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\HID\Vid_1631&Pid_5002&MI_00\8&27c19b41&0&0000] "ClassGUID"="{4D36E96B-E325-11CE-BFC1-08002BE10318}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\HID\Vid_1631&Pid_5002&MI_00\8&27c19b41&0&0000] "Driver"="{4D36E96B-E325-11CE-BFC1-08002BE10318}\\0002" Regards, JvdV
hi

the registry search proves without a doubt that there at least has been the keylogger.

now what is a keylogger.. it is an appliaction that monitors and captures all keystrokes on the computer its on, writes them to a logfile an sends it to an emails address using its own smtp engine etc
so what does this mean: someone has all of you details now; you passwords, your bank account number, your credit card number… everything. i really suggest formatting the harddrive an reinstalling the operation systems ( after backing up all important files )


also you need to change all online passwords, credit card deteails etc
i suggest contacting the police, your bank and your credit card company for possible fraudulent actions too


here some links to help you decide what to do:
http://www.dslreports.com/faq/10451
http://www.dslreports.com/faq/10063
http://www.microsoft.com/technet/community…gmt/sm0704.mspx
http://www.microsoft.com/technet/community…gmt/sm0504.mspx


i
Hi Illukka, How sure can we be about your conclusions? I checked my sons' PC and also on that computer I found 81 appearances of the string in question. You based your concern about this string on the following: HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\ "UpperFilters" = INFECTION WARNING! "msikbd2k" ["Netropa Corporation"] I realised yesterday where I had seen "Netropa" before, namely in my HJT log: O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe Can these two things have anything to do with eachother (and perhaps be not harmful after all)? If I were to format my hard disk and reinstall everything, what is the chance that I will copy the problem with my back-ups and bring it back to my system when I copy the back-ups back to my system? Other question: Do I also have to reformat my second hard disk, which only contains pictures, movies, word fiels and excel files? Please advise. Regards, JvdV
Hi Illukka, One more comment. I answered one of your earlier replies with "No, I have not installed a keylogger", but I investigated and analysed this a little bit further. With "Security Taks Manager" I traced MMKeybd.exe, which is Netropa's Hot Key program. This has been on my PC ever since I bought it in 2001 and it can indeed log keystrokes. Sorry for omitting this in my earlier reaction. The same may go for em_exec.exe, a Logitech event handler program, which also seems to be able to log keystrokes. Does all of this shed new light on your conclusions? Regards, JvdV
hmm that CLSID is a perfect match

lets still doublecheck, before formatting:

are any of the following files present on your computer:

C:\WINDOWS\System32\\drivers\wskrnlc.sys
C:\WINDOWS\System32\\acm-manual.chm
C:\WINDOWS\System32\\acmcc.exe
C:\WINDOWS\System32\\rbwinx1.dll
C:\WINDOWS\System32\\wskrnl.exe
C:\WINDOWS\System32\\wskrnlb.dll
C:\WINDOWS\System32\\wskrnlb.exe
C:\WINDOWS\System32\\wskrnlc.dll
C:\WINDOWS\System32\\wskrnlc.vxd
C:\WINDOWS\System32\\wskrnld.dll
C:\WINDOWS\System32\\wskrnle.dll


enable
'show all files' before searching them
Hi Illukka, No, none of these files is present on my computer. (By the way, I assume the double slash should have been a single slash in all the iles you mentioned.) What did you mean with "that CLSID is a perfect match" Regards, JvdV
the series of seemingly random chars :4D36E96B-E325-11CE-BFC1-08002BE10318 matches the one of the keylogger ok i believe you dont have it then :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI