Home > Hijack This > Hijack This Posted For PC Gone Slow

Hijack This Posted For PC Gone Slow

Is the computer running slow in general, or just when you are online? O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: {07cd6a65-5d16-073a-19e4-52f53fa40343} - {34304af3-5f25-4e91-a370-61d556a6dc70} - C:\Windows\system32\nqfipysh.dll - TROJAN O2 - BHO: (no name) - for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the It's very odd. navigate here

Uninstall all but Kaspersky, and get SUPERAntiSpyware (http://www.superantispyware.com/). Cohen Cohenl.com - ColoRanks - Host 4 Post Do not PM me for support!!! 0 OPDiscussion Starter wgclemente 8 Years Ago Still somewhat erratic. Infected -- Win32.Qhost !! --sha-w 974,848 2005-06-07 06:52:46 c:\winnt\Debug\system\svchost.exe ----a-w 7,952 1999-12-07 11:00:00 c:\winnt\system32\svchost.exe Entries: 2 (1) Directories: 0 Files: 2 Bytes: 982,800 Blocks: 1,920 ------- Sigcheck ------- 05-06-06 22:52 974848 Started by Mugen , Feb 04 2009 04:45 PM Page 1 of 2 1 2 Next This topic is locked 38 replies to this topic #1 Mugen Mugen Member Members 98 find more

scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wxsynas] "ImagePath"="c:\winnt\Wxsynas" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(172) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\winnt\system32\wzcdlg.dll c:\winnt\system32\WZCSAPI.DLL - No input is needed, the scan is running. scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Wed 21 Jan 2009 Search in the list for all previous installed versions of Java. (J2SE Runtime Environment…. ) It should have next icon next to it: http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif Select it and click Remove.

C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. Show Ignored Content As Seen On Welcome to Tech Support Guy! Please re-enable javascript to access full functionality. cab O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activ ex/hcImpl.cab O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGame s.cab O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish

Contents of the 'Scheduled Tasks' folder 2008-12-17 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57] 2008-12-23 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Bill.job - c:\program files\Norton Internet Security\Norton When finished, it shall produce a log for you, C:\ComboFix.txt. uStart Page = hxxp://www.google.com/ uDefault_Search_URL = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s LSP: %SystemRoot%\system32\msafd.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-06 15:37:35 Windows 5.0.2195 Service http://pressf1.pcworld.co.nz/showthread.php?76811-Hijack-this-Slow-computer File:: c:\winnt\system32\downer.exe c:\winnt\~DF196B.tmp c:\winnt\~DFE39C.tmp c:\winnt\~DFD234.tmp c:\winnt\~DFF21E.tmp c:\winnt\~DFAC21.tmp c:\winnt\~DF2CB7.tmp c:\winnt\~DF2CA6.tmp c:\winnt\~DF22C8.tmp c:\winnt\~DF80DC.tmp c:\winnt\~DFF401.tmp c:\winnt\~DF31FF.tmp c:\winnt\~DFCD98.tmp Driver::NetlogsWdiCenterHostNetwork Server ProtectionFolder:: C:\VundoFix Backupsc:\windows\wldqcmbz Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.

And using Nortons wont help, its a memory hog, and can slow a system down. Check out Good Gear Guide's broadband speed test -- PCWorld2011 -- Default Mobile Style Contact Us PC World Forums Archive Web Hosting Privacy Statement Top All times are GMT +13. Register Help Remember Me? Using Internet Explorer, visit http://www.kaspersky...apter=161739400Other available links Kaspersky Online Scanner or from here http://www.kaspersky.com/virusscanner Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select

Download SDFix or from Here and save it to your Desktop Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please https://www.daniweb.com/hardware-and-software/information-security/threads/163563/computer-running-very-slow-hijack-this-results at least some variant of it. Can anyone explain to me what Svchost is? The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt 2. - Run HJT again and post the log.

That may cause it to stall. check over here Please do not PM me for HJT help, we all benefit from posting on the open board.Want to help others? Edit: I forgot to add the log. Alternative to Windows Indexing Last Post 2 Weeks Ago I frequently find myself looking for files on my computer. 99.9% of the time I am looking for a file by name

Completion time: 2008-12-23 8:42:10 ComboFix-quarantined-files.txt 2008-12-23 13:42:05 Pre-Run: 48,228,397,056 bytes free Post-Run: 49,000,345,600 bytes free 130 --- E O F --- 2008-12-12 04:26:02 Hijack This log Logfile of Trend Micro HijackThis Please do not PM me for HJT help, we all benefit from posting on the open board.Want to help others? HiJack This Discussion in 'Virus & Other Malware Removal' started by AOK1974, Jan 24, 2004. http://pcialliance.org/hijack-this/hijack-this-log-aim-is-slow.html If you do not see the file extension, please refer to these instructions.

In your reply, post the logs (in this order): 1. - Malware Bytes Log 2. - Hijackthis Log Thanks, Cohen Cohenl.com - ColoRanks - Host 4 Post Do not PM me O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xporter vers Microsoft HOW TO: Enable or Disable Internet Connection Firewall in Windows XP VirtualMe, Jan 24, 2004 #3 This thread has been Locked and is not open to further replies.

Double click combofix.exe & follow the prompts.

However, it can also slow down the computer as the process typically uses a lot of CPU time. ComboFix will now run a scan on your system. So, I scanned with MS Security Essentials (my AV) = clear. Vista/Windows 7 users right-click and select Run As Administrator.When the program opens, click the Start Scan button.

Advertisement AOK1974 Thread Starter Joined: Sep 1, 2003 Messages: 102 Anybody see anything? windows-virus This article has been dead for over six months. Click on Disinfect # Please ignore the offer to buy the program. weblink Start a new discussion instead.

Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1130099718328 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Please re-enable javascript to access full functionality. Yes, my password is: Forgot your password? Back to top #18 Juliet Juliet Advanced Member Trusted Malware Techs 23,158 posts Gender:Female Posted 06 February 2009 - 09:55 PM If Kaspersky continues to give fits try this next scanner.

If not please perform the following steps below so we can have a look at the current condition of your machine. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged It found 6 entries in the registery and removed them. O23 - Service: Network Connections Logs (Netlogs) - Unknown owner - C:\WINNT\system32\perfs.exe (file missing)O23 - Service: Network Server Protected (Network Server Protection) - Unknown owner - C:\Documents and Settings\All Users\svchost.exe (file

Then, open CleanUp! I did a defrag, disk clean up, ran CC Cleaner, ran Spy Boot, Norton and Trend micro. Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy Click on this link Here to see a list of programs that should be disabled.

Anyway here's the logfile: Logfile of HijackThis v1.99.1 Scan saved at 7:19:38 a.m., on 17/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe Computer running slow. IPC error: 1450 Insufficient system resources exist to complete the requested service. Unable to clean registry!

I have run Ad-Aware and Spybot as well as keeping my AVG up to date and they don't show any issues. Loading... More information about ACR and LCIE can be found on the IEBlog and an explanation of multiple instances of iexplorer.exe is provided by DON, MS MVP IE here. Instructions on how to properly create a GMER log can be found here: How to create a GMER logThanks.DR Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs