Toshiba Satellite is VERY slow and unresponsive

  1. #21
    Toshiba is offline Junior Member

    re: Toshiba Satellite is VERY slow and unresponsive

    I unchecked Devices but it still shut down, showing a blue screen saying Windows is shutting down to not harm your computer etc. I'm going on safe mode now.


  2. #22
    broni is offline Senior Member
    OK. Keep me posted.

  3. #23
    Toshiba is offline Junior Member
    I went on safe mode and I tried to run GMER there. It still shut down and restarted to normal mode, giving me the same message.

  4. #24
    broni is offline Senior Member
    OK then...

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"

    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

  5. #25
    Toshiba is offline Junior Member
    OK. I'm doing Combofix. I'll keep ya posted.

  6. #26
    broni is offline Senior Member
    Ok

  7. #27
    Toshiba is offline Junior Member
    OK. Here is the Combofix log.

    ComboFix 10-07-19.01 - Petrous Odisho Sir 07/19/2010 14:43:50.1.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2038.1088 [GMT -5:00]
    Running from: c:\users\Petrous Odisho Sir\Desktop\ComboFix.exe
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Install.exe
    c:\program files\Search Toolbar
    c:\program files\Search Toolbar\icon.ico
    c:\program files\Search Toolbar\SearchToolbarUninstall.exe
    c:\program files\Search Toolbar\SearchToolbarUpdater.exe
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\About Hotbar.lnk
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Customer Support Center.lnk
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Hotbar\Hotbar Uninstall Instructions.lnk
    c:\system volume information\SystemRestore

    .
    ((((((((((((((((((((((((( Files Created from 2010-06-19 to 2010-07-19 )))))))))))))))))))))))))))))))
    .

    2010-07-19 20:08 . 2010-07-19 20:10 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Local\temp
    2010-07-19 20:08 . 2010-07-19 20:08 -------- d-----w- c:\users\Default\AppData\Local\temp
    2010-07-18 13:31 . 2010-07-18 13:31 -------- d-----w- c:\users\Petrous Odisho Sir\DoctorWeb
    2010-07-17 22:06 . 2010-07-17 22:06 -------- d-----w- c:\windows\system32\EventProviders
    2010-07-12 01:53 . 2010-07-17 23:36 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Local\Microsoft Games
    2010-07-12 01:53 . 2010-07-17 23:31 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Local\Microsoft Games(1)
    2010-07-12 01:53 . 2010-07-12 02:52 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Local\Microsoft Games(3)
    2010-07-02 16:12 . 2010-07-02 16:12 -------- d-----w- c:\program files\4shared Desktop
    2010-06-27 15:45 . 2010-06-27 15:45 -------- d-----w- c:\users\Petrous Odisho Sir\{c8ff50e5-da0a-44e3-942c-728c7e2a268e}
    2010-06-27 15:45 . 2010-06-27 15:51 -------- d-----w- C:\AV_LOGS
    2010-06-27 15:45 . 2010-06-27 15:45 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\Avnex
    2010-06-27 15:45 . 2008-12-26 17:56 17792 ----a-w- c:\windows\system32\drivers\vcsvad.sys
    2010-06-27 15:44 . 2010-07-02 13:16 -------- d-----w- c:\program files\AV Vcs 7.0 DIAMOND
    2010-06-27 15:19 . 2010-06-27 15:19 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\NCH Swift Sound
    2010-06-27 15:19 . 2010-06-27 15:19 -------- d-----w- c:\programdata\NCH Swift Sound
    2010-06-27 15:18 . 2010-06-27 15:18 -------- d-----w- c:\program files\NCH Swift Sound
    2010-06-26 13:37 . 2010-06-26 13:37 -------- d-----w- c:\program files\Microsoft.NET
    2010-06-24 14:35 . 2010-04-14 17:47 293376 ----a-w- c:\windows\system32\psisdecd.dll
    2010-06-24 14:35 . 2010-04-14 17:46 428544 ----a-w- c:\windows\system32\EncDec.dll
    2010-06-24 14:34 . 2009-11-08 15:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2010-06-24 14:34 . 2009-11-08 15:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
    2010-06-24 14:34 . 2009-11-08 15:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
    2010-06-24 14:34 . 2009-11-08 15:55 297808 ----a-w- c:\windows\system32\mscoree.dll
    2010-06-24 14:34 . 2009-11-08 15:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
    2010-06-23 20:19 . 2010-04-16 16:05 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
    2010-06-23 20:19 . 2010-04-16 14:17 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
    2010-06-20 19:22 . 2010-06-20 19:22 -------- d-----w- c:\program files\LibUSB-Win32
    2010-06-20 04:19 . 2009-07-07 23:53 28160 ----a-w- c:\windows\system32\drivers\libusb0.sys
    2010-06-20 04:19 . 2007-03-20 16:33 43520 ----a-w- c:\windows\system32\libusb0.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2010-07-17 23:36 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
    2010-06-30 15:39 . 2010-06-19 00:50 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\FrostWire
    2010-06-29 15:26 . 2010-03-04 15:20 1356 ----a-w- c:\users\Petrous Odisho Sir\AppData\Local\d3d9caps.dat
    2010-06-19 11:29 . 2010-03-05 01:28 -------- d-----w- c:\program files\McAfee
    2010-06-19 02:07 . 2010-04-03 15:31 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\Apple Computer
    2010-06-19 00:50 . 2010-06-19 00:39 -------- d-----w- c:\program files\Java
    2010-06-19 00:43 . 2010-06-19 00:43 -------- d-----w- c:\program files\Common Files\Java
    2010-06-19 00:40 . 2010-06-19 00:42 411368 ----a-w- c:\windows\system32\deployJava1.dll
    2010-06-19 00:24 . 2010-06-19 00:13 -------- d-----w- c:\programdata\HBLiteSA
    2010-06-19 00:23 . 2010-06-19 00:22 -------- d-----w- c:\program files\Bonjour
    2010-06-19 00:14 . 2010-06-19 00:12 -------- d-----w- c:\program files\Safari
    2010-06-19 00:13 . 2010-06-19 00:13 -------- d-----w- c:\users\Petrous Odisho Sir\AppData\Roaming\HBLite
    2010-06-19 00:13 . 2010-06-19 00:13 -------- d-----w- c:\program files\HBLite
    2010-06-18 23:51 . 2010-06-18 23:51 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_ 00_00.Wdf
    2010-05-26 16:16 . 2010-06-19 00:44 34304 ----a-w- c:\windows\system32\atmlib.dll
    2010-05-26 14:25 . 2010-06-19 00:44 289792 ----a-w- c:\windows\system32\atmfd.dll
    2010-05-21 19:14 . 2010-03-04 16:32 221568 ------w- c:\windows\system32\MpSigStub.exe
    2010-05-18 21:35 . 2010-05-18 21:35 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-05-18 21:35 . 2010-05-18 21:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
    2010-05-04 05:59 . 2010-06-19 00:43 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-05-04 05:55 . 2010-06-19 00:43 71680 ----a-w- c:\windows\system32\iesetup.dll
    2010-05-04 05:55 . 2010-06-19 00:43 109056 ----a-w- c:\windows\system32\iesysprep.dll
    2010-05-04 04:31 . 2010-06-19 00:43 133632 ----a-w- c:\windows\system32\ieUnatt.exe
    2010-05-01 13:53 . 2010-06-19 00:17 2036224 ----a-w- c:\windows\system32\win32k.sys
    2010-04-23 13:55 . 2010-06-19 00:45 2048 ----a-w- c:\windows\system32\tzres.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2007-04-20 430080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
    "Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
    "Persistence"="c:\windows\system32\igfxpers.ex e" [2008-02-12 133656]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]
    "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-02 202256]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
    Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\mcmscsvc]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\MCODS]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring"=dword:00000001

    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\ v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-04 135664]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30 319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-12-08 93320]
    S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.1;c:\windows\system32\drivers\libusb0.sys [2009-07-07 28160]
    S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]

    .
    Contents of the 'Scheduled Tasks' folder

    2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-04 14:49]

    2010-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-04 14:49]

    2010-03-05 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2010-03-05 18:22]

    2010-03-05 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2010-03-05 18:22]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uInternet Settings,ProxyOverride = *.local
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6 FF0C6D236BF8.dll/cmsidewiki.html
    DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://kingsisle.hs.llnwd.net/e1/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
    .
    - - - - ORPHANS REMOVED - - - -

    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    AddRemove-Search Toolbar - c:\program files\Search Toolbar\SearchToolbarUninstall.exe



    ************************************************** ************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
    Rootkit scan 2010-07-19 15:10
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    ************************************************** ************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Cl ass\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    Completion time: 2010-07-19 15:19:02
    ComboFix-quarantined-files.txt 2010-07-19 20:18

    Pre-Run: 163,813,498,880 bytes free
    Post-Run: 165,195,399,168 bytes free

    - - End Of File - - 52D46523650E2466A8BE7417FBFB22B1

  8. #28
    Toshiba is offline Junior Member
    Now what do I do?

  9. #29
    Toshiba is offline Junior Member
    Hmm

  10. #30
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    You have to be patient.
    I'm just a volunteer and I'm not here 24/7.

    Uninstall Combofix:
    Go Start > Run [Vista users, go Start>"Start search"]
    Type in:
    Combofix /Uninstall
    Note the space between the "Combofix" and the "/Uninstall"
    Click OK (Vista users - press Enter).
    Restart computer.

    ================================================== =========

    Download OTL to your Desktop.

    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * Under the Custom Scan box paste this in:



    netsvcs
    drivers32 /all
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\system32\*.wt
    %systemroot%\system32\*.ruy
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\system32\spool\prtprocs\w32x86\*.tmp
    %systemroot%\*. /mp /s
    /md5start
    /md5stop
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\user32.dll /md5
    %systemroot%\system32\ws2_32.dll /md5
    %systemroot%\system32\ws2help.dll /md5
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs



    * Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.

Closed Thread
Page 3 of 6 FirstFirst 1 2 3 4 5 6 LastLast