Toshiba Satellite is VERY slow and unresponsive
-
re: Toshiba Satellite is VERY slow and unresponsive
I unchecked Devices but it still shut down, showing a blue screen saying Windows is shutting down to not harm your computer etc. I'm going on safe mode now.
-
-
I went on safe mode and I tried to run GMER there. It still shut down and restarted to normal mode, giving me the same message.
-
OK then...
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
- Please, never rename Combofix unless instructed.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
NOTE1. If Combofix asks you to install Recovery Console, please allow it.
NOTE 2. If Combofix asks you to update the program, always do so.
- Close any open browsers.
- WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
- Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
- Double click on combofix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the "C:\ComboFix.txt"
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
Make sure, you re-enable your security programs, when you're done with Combofix.
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
-
OK. I'm doing Combofix. I'll keep ya posted.
-
Ok
-
OK. Here is the Combofix log.
ComboFix 10-07-19.01 - Petrous Odisho Sir 07/19/2010 14:43:50.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2038.1088 [GMT -5:00]
Running from: c:\users\Petrous Odisho Sir\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Install.exe
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\About Hotbar.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Uninstall Instructions.lnk
c:\system volume information\SystemRestore
.
((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
.
2010-07-19 20:08 . 2010-07-19 20:10 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Local\temp
2010-07-19 20:08 . 2010-07-19 20:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-18 13:31 . 2010-07-18 13:31 -------- d-----w- c:\users\Petrous Odisho Sir\DoctorWeb
2010-07-17 22:06 . 2010-07-17 22:06 -------- d-----w- c:\windows\system32\EventProviders
2010-07-12 01:53 . 2010-07-17 23:36 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Local\Microsoft Games
2010-07-12 01:53 . 2010-07-17 23:31 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Local\Microsoft Games(1)
2010-07-12 01:53 . 2010-07-12 02:52 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Local\Microsoft Games(3)
2010-07-02 16:12 . 2010-07-02 16:12 -------- d-----w- c:\program files\4shared Desktop
2010-06-27 15:45 . 2010-06-27 15:45 -------- d-----w- c:\users\Petrous Odisho Sir\{c8ff50e5-da0a-44e3-942c-728c7e2a268e}
2010-06-27 15:45 . 2010-06-27 15:51 -------- d-----w- C:\AV_LOGS
2010-06-27 15:45 . 2010-06-27 15:45 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\Avnex
2010-06-27 15:45 . 2008-12-26 17:56 17792 ----a-w- c:\windows\system32\drivers\vcsvad.sys
2010-06-27 15:44 . 2010-07-02 13:16 -------- d-----w- c:\program files\AV Vcs 7.0 DIAMOND
2010-06-27 15:19 . 2010-06-27 15:19 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\NCH Swift Sound
2010-06-27 15:19 . 2010-06-27 15:19 -------- d-----w- c:\programdata\NCH Swift Sound
2010-06-27 15:18 . 2010-06-27 15:18 -------- d-----w- c:\program files\NCH Swift Sound
2010-06-26 13:37 . 2010-06-26 13:37 -------- d-----w- c:\program files\Microsoft.NET
2010-06-24 14:35 . 2010-04-14 17:47 293376 ----a-w- c:\windows\system32\psisdecd.dll
2010-06-24 14:35 . 2010-04-14 17:46 428544 ----a-w- c:\windows\system32\EncDec.dll
2010-06-24 14:34 . 2009-11-08 15:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-24 14:34 . 2009-11-08 15:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-24 14:34 . 2009-11-08 15:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-24 14:34 . 2009-11-08 15:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-24 14:34 . 2009-11-08 15:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 20:19 . 2010-04-16 16:05 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 20:19 . 2010-04-16 14:17 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-20 19:22 . 2010-06-20 19:22 -------- d-----w- c:\program files\LibUSB-Win32
2010-06-20 04:19 . 2009-07-07 23:53 28160 ----a-w- c:\windows\system32\drivers\libusb0.sys
2010-06-20 04:19 . 2007-03-20 16:33 43520 ----a-w- c:\windows\system32\libusb0.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2010-07-17 23:36 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-30 15:39 . 2010-06-19 00:50 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\FrostWire
2010-06-29 15:26 . 2010-03-04 15:20 1356 ----a-w- c:\users\Petrous Odisho Sir\AppData\Local\d3d9caps.dat
2010-06-19 11:29 . 2010-03-05 01:28 -------- d-----w- c:\program files\McAfee
2010-06-19 02:07 . 2010-04-03 15:31 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\Apple Computer
2010-06-19 00:50 . 2010-06-19 00:39 -------- d-----w- c:\program files\Java
2010-06-19 00:43 . 2010-06-19 00:43 -------- d-----w- c:\program files\Common Files\Java
2010-06-19 00:40 . 2010-06-19 00:42 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-19 00:24 . 2010-06-19 00:13 -------- d-----w- c:\programdata\HBLiteSA
2010-06-19 00:23 . 2010-06-19 00:22 -------- d-----w- c:\program files\Bonjour
2010-06-19 00:14 . 2010-06-19 00:12 -------- d-----w- c:\program files\Safari
2010-06-19 00:13 . 2010-06-19 00:13 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\HBLite
2010-06-19 00:13 . 2010-06-19 00:13 -------- d-----w- c:\program files\HBLite
2010-06-18 23:51 . 2010-06-18 23:51 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_ 00_00.Wdf
2010-05-26 16:16 . 2010-06-19 00:44 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:25 . 2010-06-19 00:44 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 19:14 . 2010-03-04 16:32 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 21:35 . 2010-05-18 21:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 21:35 . 2010-05-18 21:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-04 05:59 . 2010-06-19 00:43 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-19 00:43 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-19 00:43 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-19 00:43 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 13:53 . 2010-06-19 00:17 2036224 ----a-w- c:\windows\system32\win32k.sys
2010-04-23 13:55 . 2010-06-19 00:45 2048 ----a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2007-04-20 430080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.ex e" [2008-02-12 133656]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-02 202256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-04 135664]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30 319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-12-08 93320]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.1;c:\windows\system32\drivers\libusb0.sys [2009-07-07 28160]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
.
Contents of the 'Scheduled Tasks' folder
2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-04 14:49]
2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-04 14:49]
2010-03-05 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-03-05 18:22]
2010-03-05 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-03-05 18:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6 FF0C6D236BF8.dll/cmsidewiki.html
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://kingsisle.hs.llnwd.net/e1/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2010-07-19 15:10
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-07-19 15:19:02
ComboFix-quarantined-files.txt 2010-07-19 20:18
Pre-Run: 163,813,498,880 bytes free
Post-Run: 165,195,399,168 bytes free
- - End Of File - - 52D46523650E2466A8BE7417FBFB22B1
-
-
-

You have to be patient.
I'm just a volunteer and I'm not here 24/7.
Uninstall Combofix:
Go Start > Run [Vista users, go Start>"Start search"]
Type in:
Combofix /Uninstall
Note the space between the "Combofix" and the "/Uninstall"
Click OK (Vista users - press Enter).
Restart computer.
================================================== =========
Download OTL to your Desktop.
* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
* Under the Custom Scan box paste this in:
netsvcs
drivers32 /all
%SYSTEMDRIVE%\*.*
%systemroot%\system32\Spool\prtprocs\w32x86\*.dll
%systemroot%\system32\*.wt
%systemroot%\system32\*.ruy
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\system32\spool\prtprocs\w32x86\*.tmp
%systemroot%\*. /mp /s
/md5start
/md5stop
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\user32.dll /md5
%systemroot%\system32\ws2_32.dll /md5
%systemroot%\system32\ws2help.dll /md5
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
* Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
- When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.