Welcome Guest ( Login | Register )
        


Computer Running Slow Expand / Collapse
Author
Message
Posted 9/10/2009 7:09 PM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 7/24/2008 2:07 AM
Posts: 25, Visits: 27
My hijackthis log below: computer's running slow & searches keep redirecting me to other websites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:42, on 2009-09-10

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\ewido anti-malware\ewidoctrl.exe

C:\Program Files\Microsoft LifeCam\MSCamS32.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\wanmpsvc.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\svchost.exe

C:\DOCUME~1\Owner\LOCALS~1\Temp\install.exe

C:\DOCUME~1\Owner\LOCALS~1\Temp\system.exe

C:\DOCUME~1\Owner\LOCALS~1\Temp\mdm.exe

C:\DOCUME~1\Owner\LOCALS~1\Temp\smss.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\wuauclt.exe

C:\DOCUME~1\Owner\LOCALS~1\Temp\setup.exe

C:\Program Files\internet explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

O1 - Hosts: ::1 localhost

O1 - Hosts: 94.232.248.66 browser-security.microsoft.com

O1 - Hosts: 94.232.248.66 antivguardian.com

O1 - Hosts: 94.232.248.66 www.antivguardian.com

O2 - BHO: C:\WINDOWS\system32\tajf83ikdmf.dll - {BF56A325-23F2-42AD-F4E4-00AAC39CAA53} - C:\WINDOWS\system32\tajf83ikdmf.dll

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto

O4 - HKLM\..\Run: [Wkide] rundll32.exe "C:\WINDOWS\ibokemomop.dll",e

O4 - HKCU\..\Run: [AbacastDistributedOnDemand:11] C:\Documents and Settings\Owner\Local Settings\Application Data\AbacastDistributedOnDemand\Node\11\AbacastDistributedOnDemand.exe -r:11 -x:1

O4 - HKCU\..\Run: [Windows System Recover!] C:\DOCUME~1\Owner\LOCALS~1\Temp\setup.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [AntiSpyware Service] C:\WINDOWS\TEMP\k0qo9r2.exe (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [Windows System Recover!] C:\WINDOWS\TEMP\spoolsv.exe (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [NordBull] C:\WINDOWS\TEMP\cpv.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm

O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm

O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm

O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm

O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O20 - AppInit_DLLs: ,

O20 - Winlogon Notify: rgadtm - C:\WINDOWS\SYSTEM32\rgadtm.dll

O22 - SharedTaskScheduler: ghya673gidh87we9inkff - {BF56A325-23F2-42AD-F4E4-00AAC39CAA53} - C:\WINDOWS\system32\tajf83ikdmf.dll

O23 - Service: AntipyProex (AntipPro2009_100) - Unknown owner - C:\WINDOWS\svchasts.exe (file missing)

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--

End of file - 5584 bytes

  Post #253941
 
Posted 9/11/2009 3:37 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 32,820, Visits: 54,734
Welcome newuser76

**Important**
First of all for anyone else reading this topic other than this topic starter should read on.
Please note that some of the instructions given in this topic may be customized for this particular computer only,and could possibly cause problems if used on another computer with different issues.
If you require help with malware issues,if you're not a member of this forum,please click on "Register" at the top of the page Here and follow the instructions.
Then start a new topic of your own in the HijackThis Logs forum Here,thanks.

Ok newuser76,lets make a start:
First open Notepad,click on Format at the top and uncheck 'Word Wrap'.


Download TFC by OldTimer to your Desktop.
* Please double-click TFC.exe to run it,if you're running Windows Vista right click on TFC.exe and click on "Run as Administrator".
* It will close all programs when run, so make sure you have saved all your work before you begin.
* Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Let it run uninterrupted until it's finished.
* Once it's finished it should reboot your machine.If it doesn't,please manually restart the pc to ensure a complete cleanup.


Please read ALL of the following before making a start.

Then download ComboFix from HERE or HERE to your Desktop,by following the steps below.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

1.If you are using Firefox, make sure that your download settings are as follows:

* Click on Tools->Options->"Main" tab
* Set to "Always ask me where to Save the files".

2.During the download,rename Combofix to Combo-Fix as follows:





3.It is important you rename Combofix during the download, but not after.
4.Please do not rename Combofix to other names, but only to the one indicated.
5.Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
* Click Here to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

-----------------------------------------------------------

* Close any open browsers.
* WARNING: Combofix will disconnect your machine from the Internet as soon as it starts.
* Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
* If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

-----------------------------------------------------------

6.Double click on Combo-Fix.exe & follow the prompts,if you're running Windows Vista right click on Combo-Fix.exe and click on "Run as Administrator".
7.When finished, it will produce a report for you.
8.Please post the contents of "C:\Combo-Fix.txt" along with a new HijackThis log into your next reply.


**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

-----------------------------------------------------------

**VERY IMPORTANT**
* As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
* Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures**



Once the Microsoft Windows Recovery Console is installed using ComboFix,you should see the following message:



Post the following in your next reply please:
The contents of C:\ComboFix.txt
A new HijackThis log.



_______________________________________________________________


ASAP & UNITE member since 2006
Free Internet Security - WOT Web of Trust
Use OpenDNS

  Post #253944
 
Posted 9/19/2009 7:11 PM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 7/24/2008 2:07 AM
Posts: 25, Visits: 27
After I ran hijackthis all my desktops icons went away, mycomputer icon is unreadable and the only thing accessable is the task manager, I tried to run explorer.exe but it says 'Windows cannot access the specified device, path, or file. You may not have the appropriate permission to access the item' it doesnt give me internet access either and safe mode doesn't work, I only get a black screen.
  Post #254093
 
Posted 10/9/2009 11:32 AM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 7/24/2008 2:07 AM
Posts: 25, Visits: 27
Any help?? would be appreciated, thanx!
  Post #254375
 
Posted 10/9/2009 12:40 PM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 32,820, Visits: 54,734
Try this:
Download the Avira AntiVir Rescue System to your desktop.
* Place a blank CD in your cd/dvd burner and double-click on the downloaded file.
* The program will automatically burn the CD for you.
* Place the burned CD into the infected computer's cd/dvd rom drive and reboot.
* Once the program has loaded on screen,do the following:
* On the bottom left side of the screen there are 2 flags,click on the British flag to use the English language.
* Click on the Configuration button.
- Select Scan all files
- Select Try to repair infected files and Rename files,if they cannot be removed
- Select Scan for dialers
- Select Scan for spyware (SPR)

* Click on Virus scanner
* Click on Start scanner at the bottom of the screen

Currently the program does not support saving a report/log file.
Please take note/write down the list of items for Records, Suspect files,and Warnings then post them into your next reply.


_______________________________________________________________


ASAP & UNITE member since 2006
Free Internet Security - WOT Web of Trust
Use OpenDNS

  Post #254376
 
Posted 10/22/2009 11:45 AM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 7/24/2008 2:07 AM
Posts: 25, Visits: 27
When i reboot the computer with the cd in it, it doesnt give me the option with the flags, it prompts me to type something in after this:  root@RescueSystem:/#
  Post #254543
 
Posted 10/22/2009 12:31 PM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 32,820, Visits: 54,734
If you have the MS Windows XP installation disk,try doing a Repair Install,see if that will allow the pc to start up normally.
Configure your computer to start from the CD-ROM drive.
Boot into the Bios and set your CD-Rom drive as first boot device.
For more information about how to do this,refer to your computer's documentation or contact your computer manufacturer.
Then insert your Microsoft Windows XP Setup CD,and restart your computer.
When the 'Press any key to boot from CD' message is displayed on screen, press a key.
Press ENTER when you see the message to setup Windows XP now, and then press ENTER displayed on the 'Welcome to Setup' screen.
Do not choose the option to press R to use the Recovery Console.
In the Windows XP Licensing Agreement, press F8 to agree to the license agreement.
Make sure that your current installation of Windows XP is selected in the box, and then press R to repair Windows XP.
Follow the instructions on the screen to complete Setup.


If the above didn't help then you're going to have to format the drive and reinstall XP.
How to format your hard drive and install Windows XP from scratch:
http://bit.ly/WWSdD

If the operating system came pre-installed,info in the following links may be useful:

Restoring Your Computer´s Software to the Factory Settings [DELL]:
http://bit.ly/18DD7f

Acer System Recovery:
http://bit.ly/dT558

Sony Vaio Recovery:
http://bit.ly/se7sU

ThinkVantage® Rescue and Recovery [LENOVO]:
http://bit.ly/iSlLb


_______________________________________________________________


ASAP & UNITE member since 2006
Free Internet Security - WOT Web of Trust
Use OpenDNS

  Post #254544
 
Posted 11/20/2009 4:18 AM
New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 7/24/2008 2:07 AM
Posts: 25, Visits: 27
If i do the repair install will i lose any information I have on my hard drive? Also can I use any MS Windows XP installation disk or does it have to be the one my computer came with?? Thanx! 
  Post #255034
 
Posted 11/20/2009 5:54 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 32,820, Visits: 54,734
If i do the repair install will i lose any information I have on my hard drive?

No,you shouldn't do.

Also can I use any MS Windows XP installation disk or does it have to be the one my computer came with??

Use the MS Windows XP installation disk that came with your pc,if you haven't got it then try any MS Windows XP installation disk,just as long its the same edition/service pack you have installed on your pc.


_______________________________________________________________


ASAP & UNITE member since 2006
Free Internet Security - WOT Web of Trust
Use OpenDNS

  Post #255035
 
« Prev Topic | Next Topic »



All times are GMT -6:00, Time now is 5:00pm

Powered By InstantForum.NET v4.1.4 © 2010
Execution: 0.105. 7 queries. Compression Disabled.