Computer Running VERY Slowly - HJT Log Included

C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP636\A0127935.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP620\A0121619.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. I also found that you can disable that feature in SpySweeper and it should have the same effect. · actions · 2004-Nov-30 11:04 pm · SpyPremium Memberjoin:2001-09-22NE

I was not able to use the ESET online scanner, well it scanned but would not remove because I needed to purchase the program, so I used Panda Active Scan.

Back to top #3 jamielaw jamielaw Malware Ass-Kicker! C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP579\A0116129.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. Run for your lives!" -Randy Quaid in Kingpin Send this topicPrint Pages: [1] Go Up « previous next » TrailerParkBoys.org» Off Topic» General Chat» Technical Support» Topic: Okay smart people, I

C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP566\A0097042.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. Reports: · Posted 6 years ago Top ispalten Posts: 6259 This post has been reported. Run for your lives!" -Randy Quaid in Kingpin JAG Posts: 670 Gender: Location: On the shores of Lake Erie Joined:Jul 2009 Re: Okay smart people, I need some help. O8 - Extra context menu item: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu

Contents of the 'Scheduled Tasks' folder "2008-04-24 11:21:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-07 23:28:50 Windows I was not able to use the ESET online scanner, well it scanned but would not remove because I needed to purchase the program, so I used Panda Active Scan. ABOUT About Us Contact Us Discussion Forum Advertising Privacy Policy GET ARTICLES BY EMAIL Enter your email address to get our daily newsletter. http://www.techsupportforum.com/forums/f284/computer-runs-extremely-slow-too-slow-to-function-hjt-log-included-246387.html Allow BOTH programs to remove whatever is found.

For example, if I click a link that brings up a download command box, I cannot click OK. I can't remember the exact feature in SpySweeper that was causing it, but it had to do with file explorer or something to that effect.I uninstalled it and everything went back Ask a Question See Latest Posts TechSpot Forums are dedicated to computer enthusiasts and power users. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b72a819f-fb91-416a-866f-ccf0ff222097} (Trojan.Vundo) -> Quarantined and deleted successfully.

Serves me right; I stopped messing with those muthers about a year ago because of a nasty virus but the kids were bored and driving me crazy; so a movie seemed http://www.howtogeek.com/forum/topic/computer-running-very-slowly-hijackthis-log-help C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP620\A0121614.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. Go to Mode, Advanced. Especially when running IE.

Terms of Use Privacy Policy Licensing Advertise International Editions: US / UK India News: Follow trailerparkboys.org on Twitter! check over here Amanda 0 jholland1964 650 8 Years Ago Judy, Thanks for your help so far! Also, I almost always use firefox (even though ie8 is installed). Perhaps a Mod will know which I mean.

C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP566\A0097048.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. Next run HiJackThis and place a check mark next to the following entries: O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll O1 - Hosts: www.downloadinga2.com O1 - Hosts: It looks … Computer acting a bit wierd, hijack this log included 4 replies Odd random sounds, like people talking. http://codecreview.com/computer-running/computer-running-very-slowly-hijack-this-log-included.html C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP579\A0116110.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.The program will launch and then begin downloading the latest definition files: Once the files have been downloaded click Logged Refuckulate the Carbonator Mitch Lahey Posts: 1615 Gender: Location: Catalina Island, CA Joined:Jan 2006 Re: Okay smart people, I need some help. Damage caused to Rental Home - Seeking Advice - Long Post! [OpenForum] by Candew309.

See if ANYTHING is using high CPU when this is happening. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ljjbrrjk (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\gdxfok.dll (Trojan.Vundo) -> Delete on reboot. Can also use the PROCESS TAB of TASK MANAGER too.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. Tap F8 before Windows loads. NOTE: Combofix prevents autorun of all CDs, floppies and USB devices to assist with malware removal & increase security. http://codecreview.com/computer-running/computer-running-slowly-and-freezing-after-running-firefox-and-steam-games.html HiJackThis log included! « Reply #2 on: Jul 29, 2010, 06:39 AM » the main problem is you're running XP Media Centre Edition.

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. and type "msconfig" and shut off non-essential start-up processes and services (Looks like you have a lot running). C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP582\A0116267.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 6:08:55 PM, on 1/26/2011 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16700) Boot mode: Normal Running processes: C:\Program Files (x86)\CyberLink\PowerDVD

Reports: · Posted 6 years ago Top Seasider Posts: 223 This post has been reported. Here it is:Logfile of HijackThis v1.99.1Scan saved at 2:12:21 PM, on 11/15/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.5730.0011)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\WLTRYSVC.EXEC:\WINDOWS\System32\bcmwltry.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeC:\Program Files\Cisco Systems\VPN Client\cvpnd.exeC:\WINDOWS\system32\Ati2evxx.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Network My Website!"The ultimate measure of a man is not where he stands in moments of comfort and convenience, but where he stands at times of challenge and controversy." - Martin Luther There is 256 mb ram. · actions · 2004-Nov-30 11:39 pm · Forums → Software and Operating Systems → Security« HJT Log - CWS_NS3 adware comes back • A Little

CAUTION! I can't use my laptop at this point and I can't even run my malware, spyware or virus programs because of how SLOW the computer has become. Unable to clean registry! C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP620\A0121620.dll (Adware.MyWeb.FunWeb) -> Quarantined and deleted successfully.

I am posting a Hijackthis log, I hope someone can see something on it. C:\System Volume Information\_restore{781B9E0A-A9F9-4D72-8CBE-54724B1293CB}\RP566\A0097056.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll O1 - Hosts: www.downloadinga2.com O1 - Hosts: downloadinga2.com O1 - Hosts: secure.extrabilling.com O1 - Hosts: updateyourprotection.com O1 - Hosts: www.updateyourprotection.com O1 Let me look through all this and will get back with you.

please, run the new scan while in normal mode · actions · 2004-Nov-30 12:28 am · littlezoeyjoin:2004-11-29 littlezoey Member 2004-Nov-30 9:34 pm Here is the updated version not in safe mode. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:16:33 AM, on 5/4/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Safe mode with network Mitch, what do you suggest instead of Avira? You should not have any open browsers or live internet connections when you are following the procedures below.

Members 878 posts OFFLINE Local time:12:34 PM Posted 25 November 2006 - 01:10 PM Hey Lov3 Sorry about the delay - the forums have been swamped with logs recently. Reports: · Posted 6 years ago Top ispalten Posts: 6259 This post has been reported. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.