WiredWX Hobby Weather ToolsLog in

 


Laptop has become very slow. Please help

2 posters

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Wat next? I have posted the remaining part long back.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Hello.
I want to use Combofix again, too much Vundo here.

Please uninstall Mcafee again. Remember how to? Start > Control Panel > Add/remove programs.


  • Download combofix from here
    Link 1
    Link 2
  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See HERE for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    Laptop has become very slow. Please help - Page 2 Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes

    Laptop has become very slow. Please help - Page 2 Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Good Morning. I had to log off the comp yesterday since my husband wanted it.
I shall continue the steps now.

-Priya-

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Hello.
I still think this infection got through with that old Java installed. We'll update it with the programmers version later.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
ComboFix 09-03-25.04 - Saravanan 2009-03-26 11:32:24.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.395 [GMT -7:00]
Running from: c:\documents and settings\Saravanan\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\dolaribe.dll
c:\windows\system32\fivahofi.dll
c:\windows\system32\gthwsz.dll
c:\windows\system32\hohevopu.dll
c:\windows\system32\ivippe.dll
c:\windows\system32\kizomelo.dll
c:\windows\system32\kuzeduhu.dll
c:\windows\system32\moifwv.dll
c:\windows\system32\rohorite.dll
c:\windows\system32\uwibrn.dll
c:\windows\system32\vipukuna.dll
c:\windows\system32\vitayafi.dll
c:\windows\system32\wemupovi.dll
c:\windows\system32\yaravobe.dll
c:\windows\system32\ytnker.dll

.
((((((((((((((((((((((((( Files Created from 2009-02-26 to 2009-03-26 )))))))))))))))))))))))))))))))
.

2009-03-25 14:35 . 2009-03-25 14:36 d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-25 14:35 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-25 14:35 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-24 23:25 . 2009-03-24 23:25 d-------- c:\program files\TomTom International B.V
2009-03-24 23:10 . 2009-03-24 23:24 d-------- C:\018171eef7da986c1f61
2009-03-24 22:43 . 2009-03-24 22:43 0 --------- c:\windows\system32\dllcache\HFX1CC.tmp
2009-03-24 22:36 . 2009-03-24 22:38 d-------- c:\windows\system32\NtmsData
2009-03-24 13:49 . 2009-03-24 13:49 0 --------- c:\windows\system32\HFX4DD.tmp
2009-03-21 10:45 . 2009-03-21 10:45 d-------- c:\windows\system32\config\systemprofile\Application Data\SACore
2009-03-19 03:01 . 2009-03-19 03:03 1,374 --a------ c:\windows\imsins.BAK
2009-03-18 18:02 . 2009-03-18 18:03 d-------- c:\program files\McAfee.com
2009-03-18 17:34 . 2009-03-18 17:34 d-------- c:\documents and settings\Saravanan\Application Data\McAfee
2009-03-05 19:26 . 2009-03-17 22:50 d-------- c:\windows\system32\Nagasoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-26 18:40 --------- d-----w c:\program files\C4ebreg
2009-03-26 14:25 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2009-03-25 22:17 --------- d-----r c:\documents and settings\Saravanan\Application Data\yahoo!
2009-03-25 06:37 --------- d-----w c:\program files\TomTom HOME 2
2009-03-25 04:22 --------- d-----w c:\documents and settings\All Users\Application Data\yahoo!
2009-03-25 04:18 --------- d-----w c:\program files\Yahoo!
2009-03-19 01:09 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2009-03-19 01:07 --------- d-----w c:\program files\McAfee
2009-03-19 01:04 --------- d-----w c:\program files\Common Files\McAfee
2009-03-18 05:48 --------- d-----w c:\program files\Microsoft Works
2009-03-18 05:47 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-03-18 05:45 --------- d-----w c:\program files\IBM
2009-03-18 05:45 --------- d-----w c:\documents and settings\All Users\Application Data\ibm
2009-03-06 17:14 --------- d-----w c:\program files\TeamViewer
2009-02-14 04:07 --------- d-----w c:\documents and settings\All Users\Application Data\Norton
2009-02-14 03:47 --------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-02-10 20:58 --------- d-----w c:\documents and settings\Saravanan\Application Data\Malwarebytes
2009-02-10 20:58 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-10 19:43 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-02-10 19:34 --------- d-----w c:\program files\Lavasoft
2009-02-10 19:34 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-10 18:27 --------- d-----w c:\program files\Enigma Software Group
2009-02-10 18:11 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-10 05:48 --------- d-----w c:\documents and settings\All Users\Application Data\STOPzilla!
2009-02-10 01:25 --------- d-----w c:\documents and settings\All Users\Application Data\SITEguard
2009-02-10 01:21 --------- d-----w c:\program files\Common Files\iS3
2009-02-07 22:54 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-07 22:50 --------- d-----w c:\program files\Symantec Client Security
2009-02-07 22:50 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-02-07 22:43 --------- d-----w c:\documents and settings\All Users\Application Data\NortonInstaller
2009-01-26 21:21 --------- d-----w c:\documents and settings\Saravanan\Application Data\CoxFastConnect20
2009-01-26 21:03 --------- d-----w c:\program files\Common Files\Motorola
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\program files\IBM\Messages By IBM\ibmmessages.exe" [2004-08-06 442368]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-03-17 251240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-08 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-08 512000]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 897024]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-03-03 94208]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2004-11-24 212992]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-11 344064]
"UC_Start"="c:\program files\IBM\Updater\\ucstartup.exe" [2004-07-14 36864]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-09-02 127035]
"ibmmessages"="c:\program files\IBM\Messages By IBM\\ibmmessages.exe" [2004-08-06 442368]
"IBMPRC"="c:\ibmtools\UTILS\ibmprc.exe" [2004-12-16 90112]
"QCWLICON"="c:\program files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2005-03-18 86016]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-01-21 135168]
"ISSI EZUpdate Service"="c:\sdwork\issimsvc.exe" [2007-10-09 204800]
"ISAMTray"="c:\program files\C4ebreg\isamtray.exe" [2007-09-07 237568]
"C4EBReg"="c:\program files\C4ebreg\c4ebreg.exe" [2007-09-07 364544]
"stgclean"="c:\sdwork\w32main2.exe" [2006-12-13 260608]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-09-10 180269]
"SunJavaUpdateSched"="c:\jre1.5.0_04\bin\jusched.exe" [2005-06-02 36975]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"TpShocks"="TpShocks.exe" [2005-01-24 c:\windows\system32\TpShocks.exe]
"TP4EX"="tp4ex.exe" [2004-11-12 c:\windows\system32\TP4EX.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
2005-03-18 03:07 262144 c:\windows\system32\QConGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2004-08-12 20:11 24576 c:\windows\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.X264"= x264vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli pwdmon

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 20:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW6]
--a------ 2008-06-10 16:18 785520 c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-01 14:22 3739648 c:\program files\Google\Google Talk\googletalk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2005-09-10 03:39 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 01:01 110592 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-10-18 11:05 204288 c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\IBM\\Updater\\ucsmb.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\JustVoip.com\\JustVoip\\JustVoip.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-10 64160]
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2005-08-25 59776]
R0 TPDiskPM;TPDiskPM;c:\windows\system32\drivers\TPDiskPM.sys [2005-08-25 14208]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2005-08-25 11520]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2005-08-25 2432]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2005-08-25 4608]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [2005-08-25 4442]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [2004-12-16 63616]
R2 ISAMSvc;IBM Standard Asset Manager Service;c:\program files\C4ebreg\c4ebreg.exe [2007-09-07 364544]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-03-17 92008]
R3 TPInput;TPInput;c:\windows\system32\drivers\TPInput.sys [2005-08-25 6016]
S2 0133051238083630mcinstcleanup;McAfee Application Installer Cleanup (0133051238083630);c:\docume~1\SARAVA~1\LOCALS~1\Temp\013305~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\SARAVA~1\LOCALS~1\Temp\013305~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S3 artour;IBM Mobility Interface for Windows;c:\windows\system32\drivers\artndint.sys [2007-07-03 7760]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.sys [2005-08-25 12288]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - 0133051238083630MCINSTCLEANUP

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4ed7124-cfcc-11dd-b3a1-000e9bd9e91e}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder

2009-03-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
.
.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\IBM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} - hxxps://ra.qwest.com/sdccommon/download/tgctlins.cab
DPF: {84B93AC6-A7F2-4420-9FED-EE6735EA9C8D} - hxxp://www.bigad.com.au/player/vivid_ocx.jpeg
DPF: {9519B2A2-6592-4E41-8290-D0298459270C} - hxxp://w3.ibm.com/bluepages/scripts/lnwebassist.cab
DPF: {CB97291A-6603-466A-AA11-80C2EB74CB10} - hxxps://install.cox.net/CoxSelfInstall/CoxSelfInstallAx10.ocx
FF - ProfilePath - c:\documents and settings\Saravanan\Application Data\Mozilla\Firefox\Profiles\nvhb8pi6.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - about:blank
FF - plugin: c:\documents and settings\Saravanan\Application Data\Mozilla\Firefox\Profiles\nvhb8pi6.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\jre1.5.0_04\bin\NPJava11.dll
FF - plugin: c:\jre1.5.0_04\bin\NPJava12.dll
FF - plugin: c:\jre1.5.0_04\bin\NPJava13.dll
FF - plugin: c:\jre1.5.0_04\bin\NPJava14.dll
FF - plugin: c:\jre1.5.0_04\bin\NPJava32.dll
FF - plugin: c:\jre1.5.0_04\bin\NPJPI150_04.dll
FF - plugin: c:\jre1.5.0_04\bin\NPOJI610.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll

---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
.
.
------- File Associations -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-26 11:41:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(820)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\tphklock.dll

- - - - - - - > 'lsass.exe'(876)
c:\windows\system32\pwdmon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\ati2evxx.exe
c:\program files\IBM\Bluetooth Software\bin\btwdins.exe
c:\program files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\QCONSVC.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\TPHDEXLG.exe
c:\windows\system32\TpKmpSvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wscntfy.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\Logitech\QuickCam\LU\LULnchr.exe
c:\program files\Logitech\QuickCam\LU\LogitechUpdate.exe
.
**************************************************************************
.
Completion time: 2009-03-26 11:48:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-26 18:47:56
ComboFix2.txt 2009-03-18 22:46:56

Pre-Run: 27,716,276,224 bytes free
Post-Run: 28,514,729,984 bytes free

273 --- E O F --- 2009-03-19 10:08:37

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Hello.
Please install Mcafee again. Do you have Hijack This on this machine.

If you do, lets get an uninstall list.

  • Open HijackThis
  • Click "Open the Misc Tools section"
  • Click "Open Uninstall Manager"
  • Click "Save List..." (generates uninstall_list.txt)
  • Click Save, copy and paste the results in your next post.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Hi,

I dont think i have hijack this tool on my machine. Let me think
I guess we uninstalled that the last time you helped me with the other virus. I have installed McAfee again already. Smile...

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Please download the current version of HijackThis from HERE

  • Double click and run the installer.
  • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
  • After installing, you should get the user agreement, press accept and Hijack This will run.
  • Click "Open the Misc Tools section"
  • Click "Open Uninstall Manager"
  • Click "Save List..." (generates uninstall_list.txt)
  • Click Save, copy and paste the results in your next post.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
A page came up asking me whether i wanna scan.. i mean whether a system scan or etc etc.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Don't need a system scan. Is there a button that says "Open the Misc Tools section"?

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
ABC (remove only)
Access IBM
Access IBM Message Center
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.2
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
ATI HYDRAVISION
ClientTools
Compatibility Pack for the 2007 Office system
Critical Update for Windows Media Player 11 (KB959772)
CutePDF Writer 2.7
EditPlus 2
Google Talk (remove only)
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
IBM Access Connections
IBM Active Protection System
IBM Ayudame
IBM DLA
IBM Integrated 56K Modem
IBM Integrated Bluetooth IV Software
IBM RecordNow!
IBM Rescue and Recovery with Rapid Restore
IBM SATA Power Management Driver
IBM Themes
IBM ThinkPad Configuration
IBM ThinkPad EasyEject Utility
IBM ThinkPad Keyboard Customizer Utility
IBM ThinkPad Power Management Driver
IBM ThinkPad Power Manager
IBM ThinkPad Presentation Director
IBM ThinkPad UltraNav Driver
IBM ThinkPad UltraNav Wizard
IBM ThinkVantage Technologies Welcome Message
IBM TrackPoint Accessibility Features
IBM Update Connector
Intel(R) PROSet/Wireless Software
InterVideo WinDVD
InterVideo WinDVD Creator
J2SE Development Kit 5.0 Update 4
J2SE Runtime Environment 5.0 Update 4
Java 2 Runtime Environment, SE v1.4.2_13
JustVoip
Lenovo Battery Program
Logitech Desktop Messenger
Logitech QuickCam
Logitech QuickCam Driver Package
Lotus Notes 7.0
Malwarebytes' Anti-Malware
McAfee SecurityCenter
mCore
mDriver
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
mMHouse
Mozilla Firefox (3.0.7)
mPfMgr
mProSafe
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
mWlsSafe
mXML
RealPlayer
Remove Hidden Data Tool
Search Assistant - My Search
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Sonic Update Manager
TeamViewer 4
The Weather Channel Desktop 6
ThinkPad FullScreen Magnifier
ThinkPad Software Installer
TomTom HOME 2.6.1.1549
TomTom HOME Visual Studio Merge Modules
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VeohTV BETA
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Wallpapers
Western Australian Time Zone Update
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinZip
x264 Revision 564 x264.nl (remove only)
Yahoo! Browser Services

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Hello.
Lets update Java runtime + development kit.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

  • J2SE Development Kit 5.0 Update 4
  • J2SE Runtime Environment 5.0 Update 4
  • Java 2 Runtime Environment, SE v1.4.2_13


Updating Java:

  • Download the latest version of Java SE Runtime Environment (JRE) 6 Update 13.
  • Select the first option where it says "This release includes the highly anticipated...".
  • Click the "Download" button to the right.
  • In the Window that opens, select your platform and language, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe that you downloaded to install the newest version.
  • Now go back to the java page in the link above.
  • Select the SECOND option where it says This JDK includes the JRE and command-line development tools...
  • Again, click the "Download" button to the right.
  • In the Window that opens, select your platform and language, check the "agree" box, and click Continue.
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on jdk-6u13-windows-i586-p.exe that you downloaded to install the newest version.


You should now have installed the runtime update 13, and development kit update 13. Let me know once you've done that.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Hi,
Can this process be skipped ? I mean, as is told u earlier, my husband is a java programmer. Cant install without his permission. I shall do that later for sure.
Any other change needed ?
I can already feel the difference now!!Laptop so fast

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
Okay, update JUST the runtime, leave the development kit.
But tell him this:

Old versions have holes malware can abuse and I can't promise that not updating it will keep the malware out.

descriptionLaptop has become very slow. Please help - Page 2 EmptyRe: Laptop has become very slow. Please help

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum