Computer Hope

Software => Computer viruses and spyware => Topic started by: clljodoin on October 02, 2008, 05:59:06 AM

Title: Computer Extremely slow!!!!!
Post by: clljodoin on October 02, 2008, 05:59:06 AM
hey all!!!

so my computer has been gradually geting slower and slower. Now it is so bad that when i click firefox it takes 5-15 seconds for it to open. Also, my cpu usage jumps from 15% to 98%. So here are my logs, any info would be fantastic!!!



[Saving space - attachment deleted by admin]
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 02, 2008, 09:56:14 AM
Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
- O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
- O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Download OTMoveIt2 by OldTimer (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) and save it to your Desktop.

Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

1. Double-click OTMoveIt2.exe to run it.
2. Copy the lines in the codebox below.

Code: [Select]
[kill explorer]
C:\Program Files\AskSBar
EmptyTemp
[start explorer]

3. Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
4. Click the red Moveit! button.
5. Copy everything in the Results window (under the green bar) and paste it in your next reply.
6. Close OTMoveIt2

Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

----------

How is everything now?
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 02, 2008, 10:25:03 AM
hey hey!!!

So here is the log, ill reboot and see how things work!

Explorer killed successfully
Folder move failed. C:\Program Files\AskSBar\SrchAstt\1.bin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\AskSBar\SrchAstt scheduled to be moved on reboot.
Folder move failed. C:\Program Files\AskSBar\bar\1.bin scheduled to be moved on reboot.
Folder move failed. C:\Program Files\AskSBar\bar scheduled to be moved on reboot.
Folder move failed. C:\Program Files\AskSBar scheduled to be moved on reboot.
< EmptyTemp >
File delete failed. C:\Users\Chris\AppData\Local\Temp\etilqs_wTckIBk5Kk2NUqa3acPe scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~26405f33d3f.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\cch~26405f424a6.htp scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\MpCmdRun.log scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully
 
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10022008_122316
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 02, 2008, 10:45:54 AM
Umm, it hasnt changed, the cpu usage is at 80 now instead of 98 but it is still slow.

This is a laptop, is it possible its a processor overheating issue? I have hardware warranty i just want to rule out software issues

Thanks
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 02, 2008, 11:11:34 AM
Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link #2 (http://subs.geekstogo.com/ComboFix.exe)

**Note:  It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link (http://www.bleepingcomputer.com/forums/topic114351.html) to see a list of security programs that should be disabled and how to disable them.
 
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 04, 2008, 12:13:43 PM
so i tried to run combofix but it takes FOREVER. I had it open for 24 hrs and it was only at sage 16. Is there something I am doing wrong?
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 04, 2008, 12:29:54 PM
Try restarting the computer and running it again. It shouldn't take more than 20 - 25 minutes to finish.
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 04, 2008, 12:31:09 PM
okay ill try that and be back haha
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 04, 2008, 01:21:55 PM
So i tried to run combofix. This time it showed the little box with the ststus bar. Once that finished it never cam back with the prompt? Im very confused now
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 04, 2008, 02:22:59 PM
Also, it has been saying "it usually takes 10 minutes" for about an hr now
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 04, 2008, 04:04:05 PM
so 2 hrs, stage 6
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 04, 2008, 06:43:26 PM
Please print these instructions as they will be needed later when Internet access is not available.

Download SDFix by AndyManchesta (http://download.bleepingcomputer.com/andymanchesta/SDFix.exe) and save it to your desktop.

When using this tool, you must use the Administrator's account or an account with Administrative rights

Reboot your computer in Safe Mode (http://www.bleepingcomputer.com/tutorials/tutorial61.html) using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Open the SDFix folder and double click RunThis.bat to start the script.
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 04, 2008, 07:58:29 PM
when i try to run the batch file the dialog box closes the second it opens. any ideas?
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 04, 2008, 08:36:12 PM
Are you booting into Safe Mode before running it?
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 04, 2008, 08:43:38 PM
yes i am... do you think the fact that combofix took 6 hrs and didnt finish and this wont open are related?
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 04, 2008, 08:45:16 PM
Download DrWeb CureIt (http://freedrweb.com/) & save it to your desktop.

Scan with DrWeb-CureIt as follows:[/COLOR]
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 04, 2008, 09:10:03 PM
your the best EF!!! ill try that
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 04, 2008, 09:24:25 PM
DrWeb should run. Be sure to post the log.

Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 05, 2008, 11:32:43 AM
its running now, ill post it when its done
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 06, 2008, 02:49:20 PM
Process.exe;C:\$Recycle.Bin\S-1-5-21-3190090494-2590576837-2123475989-1000\$RC80WY3\apps;Tool.Prockill;;
psexec.cfexe;C:\ComboFix;Program.PsExec.171;;
6D952C06d01\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Chris\AppData\Local\Application Data\Mozilla\Firefox\Profiles\mcbr2ru4.default\Cache\6D952C06d01;Program.PsExec.171;;
6D952C06d01;C:\Documents and Settings\Chris\AppData\Local\Application Data\Mozilla\Firefox\Profiles\mcbr2ru4.default\Cache;Archive contains infected objects;Moved.;
8F2ABEC4d01\SDFix\apps\Process.exe;C:\Documents and Settings\Chris\AppData\Local\Application Data\Mozilla\Firefox\Profiles\mcbr2ru4.default\Cache\8F2ABEC4d01;Tool.Prockill;;
8F2ABEC4d01;C:\Documents and Settings\Chris\AppData\Local\Application Data\Mozilla\Firefox\Profiles\mcbr2ru4.default\Cache;Archive contains infected objects;Moved.;
Av-test.txt;C:\Documents and Settings\Chris\AppData\Local\Application Data\Temp;EICAR Test File (NOT a Virus!);Incurable.Moved.;
ComboFax.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Chris\Desktop\ComboFax.exe;Program.PsExec.171;;
ComboFax.exe;C:\Documents and Settings\Chris\Desktop;Archive contains infected objects;Moved.;
ComboFix.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Chris\Desktop\ComboFix.exe;Program.PsExec.171;;
ComboFix.exe;C:\Documents and Settings\Chris\Desktop;Archive contains infected objects;Moved.;
ComboFix01.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Chris\Desktop\ComboFix01.exe;Program.PsExec.171;;
ComboFix01.exe;C:\Documents and Settings\Chris\Desktop;Archive contains infected objects;Moved.;
SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Chris\Desktop\SDFix.exe;Tool.Prockill;;
SDFix.exe;C:\Documents and Settings\Chris\Desktop;Archive contains infected objects;Moved.;
6D952C06d01\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine\6D952C06d01;Program.PsExec.171;;
6D952C06d01;C:\Documents and Settings\Chris\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
8F2ABEC4d01\SDFix\apps\Process.exe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine\8F2ABEC4d01;Tool.Prockill;;
8F2ABEC4d01;C:\Documents and Settings\Chris\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
Av-test.txt;C:\Documents and Settings\Chris\DoctorWeb\Quarantine;EICAR Test File (NOT a Virus!);Incurable.Moved.;
ComboFax.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine\ComboFax.exe;Program.PsExec.171;;
ComboFax.exe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
ComboFix.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine\ComboFix.exe;Program.PsExec.171;;
ComboFix.exe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
ComboFix01.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine\ComboFix01.exe;Program.PsExec.171;;
ComboFix01.exe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine\SDFix.exe;Tool.Prockill;;
SDFix.exe;C:\Documents and Settings\Chris\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
Process.exe;C:\SDFix\apps;Tool.Prockill;;


So whatcha think of that? As you can see I saved Combofix a few times to try and get it to work haha
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 06, 2008, 02:54:23 PM
Run CCleaner.

What problems are you still having (if any)?
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 06, 2008, 03:49:48 PM
So there is pretty much no change. The CPU is still running at 100% whenever i run anyhting. For example it took 2 minutes to open CCleaner. What do you think?> Possibly a hardware issue? I added a Ccleaner log

[Saving space - attachment deleted by admin]
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 06, 2008, 03:57:21 PM
Try this.

Defrag the computer. There may be a lot of fragmented sections on the drive after cleaning the malware.

You can use the built in Windows Defrag or a faster FREE program. Defraggler (http://www.defraggler.com/) is very effective and easy to use. Be sure to clean out temp files and restart the computer just before using this.
Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 06, 2008, 04:18:56 PM
okay ill try that!! Thanks
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 06, 2008, 04:26:57 PM
After or before defragging also do the final steps. Just don't do them during the defrag.

Download OTCleanIt.exe (http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe) and save it to your Desktop.
.
----------

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html) or Windows Vista System Restore Guide  (http://www.bleepingcomputer.com/tutorials/tutorial143.html)
.
----------

Use the  Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.
.
----------

Go to Microsoft Windows Update (http://windowsupdate.microsoft.com/) and get all critical updates.

----------

Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

Concerned about Browser Security? Consider using Mozilla Firefox 3.0 (http://www.spreadfirefox.com/node&id=224248&t=324) with Adblock Plus (https://addons.mozilla.org/en-US/firefox/addon/1865) and NoScript (http://noscript.net/)

To prevent unknown applications from being installed on your computer install WinPatrol 2008 (http://www.winpatrol.com/winpatrol.html)
*  Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

I suggest using SiteAdvisor (http://www.siteadvisor.com/). SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

 SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html) - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
*  (http://www.bleepingcomputer.com/tutorials/tutorial49.html)Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/forums/tutorial49.html)
* If you don't know what ActiveX controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)

Check out  Keeping Yourself Safe On The Web (http://evilspages.blogspot.com/2008/05/keeping-yourself-safe-on-web.html) for tips and free tools to help keep you safe in the future.

Also see  Slow Computer? It May Not Be Malware (http://evilspages.blogspot.com/2008/05/slow-computer-it-may-not-be-malware.html) for free cleaning/maintenance tools to help keep your computer running smooth.

Title: Re: Computer Extremely slow!!!!!
Post by: clljodoin on October 07, 2008, 04:46:17 PM
Its runnign great! Thanks a lot
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 07, 2008, 04:47:52 PM
Your welcome.

Safe surfing....
Title: Re: Computer Extremely slow!!!!!
Post by: usman.sialkot on October 10, 2008, 05:00:04 AM
There may be a worm( a type of computer virus) that infected your computer.
For this probelm use norton anitvirus it will clean your pc instead deleting your infected files
Secondly defregment your hard disk and un install unnecessary software which you won't uze form controll panel> add and remove programs menu
Title: Re: Computer Extremely slow!!!!!
Post by: evilfantasy on October 10, 2008, 11:38:52 AM
There may be a worm( a type of computer virus) that infected your computer.
For this probelm use norton anitvirus it will clean your pc instead deleting your infected files
Secondly defregment your hard disk and un install unnecessary software which you won't uze form controll panel> add and remove programs menu

Do you not see that this issue is already fixed?

Please think before posting.

Also see here Would you like to learn to fight malware? (http://www.computerhope.com/forum/index.php/topic,57605.0.html)

Thread closed.