It is currently Tue Sep 01, 2026 3:13 pm


PC GETTING SLOW LATELY...pls help...

All versions of Windows 7, 2008 and Vista including 32 bit and 64 bit

Moderator: icecube

Re: PC GETTING SLOW LATELY...pls help...

Postby edgondoy » Thu Jan 13, 2011 2:25 pm

Here it is & also i found a spyware of the name SPYWARE.BANKER during a quick scan with malwarebytes if you want the log i would gladly post it..
========
ComboFix 11-01-08.03 - Administrator 01/12/2011 21:34:28.8.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.715 [GMT -8:00]
Running from: c:\documents and settings\Administrator\Desktop\cbf.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\dqrkje.sys

c:\windows\regedit.exe . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ghbe


((((((((((((((((((((((((( Files Created from 2010-12-13 to 2011-01-13 )))))))))))))))))))))))))))))))
.

2011-01-09 03:27 . 2011-01-09 03:27 -------- dc-h--w- c:\windows\PIF
2011-01-09 03:04 . 2004-08-04 01:56 221184 -c--a-w- c:\windows\system32\wmpns.dll
2011-01-08 22:30 . 2011-01-08 22:47 -------- dc----w- c:\windows\system32\CatRoot_bak
2011-01-08 21:59 . 2009-04-02 07:02 604160 -c----w- c:\windows\system32\dllcache\wmspdmod.dll
2011-01-08 21:59 . 2009-10-21 05:50 75776 -c----w- c:\windows\system32\dllcache\strmfilt.dll
2011-01-08 21:59 . 2009-10-21 05:50 25088 -c----w- c:\windows\system32\dllcache\httpapi.dll
2011-01-08 21:59 . 2009-10-20 14:41 265728 -c----w- c:\windows\system32\dllcache\http.sys
2011-01-08 21:59 . 2010-02-24 12:48 457216 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-01-08 21:58 . 2009-10-12 13:54 112128 -c----w- c:\windows\system32\dllcache\rastls.dll
2011-01-08 21:58 . 2009-10-12 13:54 69632 -c----w- c:\windows\system32\dllcache\raschap.dll
2011-01-08 21:58 . 2008-07-07 20:06 253952 -c----w- c:\windows\system32\dllcache\es.dll
2011-01-08 21:57 . 2009-12-14 07:35 33280 -c----w- c:\windows\system32\dllcache\csrsrv.dll
2011-01-08 21:57 . 2009-06-10 06:26 134144 -c----w- c:\windows\system32\dllcache\wkssvc.dll
2011-01-08 21:56 . 2009-10-15 16:56 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-01-08 21:56 . 2009-10-15 16:56 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-01-08 21:56 . 2009-06-09 14:53 53248 -c----w- c:\windows\system32\dllcache\tsgqec.dll
2011-01-08 21:56 . 2009-06-09 14:53 290816 -c----w- c:\windows\system32\dllcache\rhttpaa.dll
2011-01-08 21:55 . 2009-06-09 14:53 2067968 -c----w- c:\windows\system32\dllcache\mstscax.dll
2011-01-08 21:55 . 2009-06-09 09:12 677888 -c----w- c:\windows\system32\dllcache\mstsc.exe
2011-01-08 21:55 . 2009-06-09 14:53 136192 -c----w- c:\windows\system32\dllcache\aaclient.dll
2011-01-08 21:55 . 2009-08-26 08:16 247326 -c----w- c:\windows\system32\dllcache\strmdll.dll
2011-01-08 21:53 . 2009-06-21 22:04 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2011-01-08 21:53 . 2009-05-07 15:44 344064 -c----w- c:\windows\system32\dllcache\localspl.dll
2011-01-08 21:52 . 2008-06-18 13:03 938496 -c----w- c:\windows\system32\dllcache\WMNetmgr.dll
2011-01-08 21:52 . 2008-06-18 09:09 100864 -c----w- c:\windows\system32\dllcache\logagent.exe
2011-01-08 21:50 . 2008-06-12 13:47 91648 -c----w- c:\windows\system32\dllcache\mtxoci.dll
2011-01-08 21:50 . 2008-06-12 13:47 66560 -c----w- c:\windows\system32\dllcache\mtxclu.dll
2011-01-08 21:50 . 2008-06-12 13:47 161792 -c----w- c:\windows\system32\dllcache\msdtcuiu.dll
2011-01-08 21:50 . 2008-06-12 13:47 956928 -c----w- c:\windows\system32\dllcache\msdtctm.dll
2011-01-08 21:50 . 2008-06-12 13:47 58880 -c----w- c:\windows\system32\dllcache\msdtclog.dll
2011-01-08 21:50 . 2008-06-12 13:47 428032 -c----w- c:\windows\system32\dllcache\msdtcprx.dll
2011-01-08 21:50 . 2009-09-04 20:45 58880 -c----w- c:\windows\system32\dllcache\msasn1.dll
2011-01-08 21:49 . 2009-07-17 18:55 58880 -c----w- c:\windows\system32\dllcache\atl.dll
2011-01-08 21:48 . 2008-05-08 12:14 203008 -c----w- c:\windows\system32\dllcache\rmcast.sys
2011-01-08 21:47 . 2010-05-02 07:09 1859968 -c----w- c:\windows\system32\dllcache\win32k.sys
2011-01-08 21:44 . 2008-07-03 13:16 8454656 -c----w- c:\windows\system32\dllcache\shell32.dll
2011-01-08 21:44 . 2009-10-13 10:45 270336 -c----w- c:\windows\system32\dllcache\oakley.dll
2011-01-08 21:43 . 2010-02-11 11:08 226880 -c----w- c:\windows\system32\dllcache\tcpip6.sys
2011-01-08 21:43 . 2008-06-20 10:44 360960 -c----w- c:\windows\system32\dllcache\tcpip.sys
2011-01-08 21:43 . 2008-06-20 17:36 245248 -c----w- c:\windows\system32\dllcache\mswsock.dll
2011-01-08 21:43 . 2008-06-20 17:36 147968 -c----w- c:\windows\system32\dllcache\dnsapi.dll
2011-01-08 21:43 . 2010-02-12 04:36 100864 -c----w- c:\windows\system32\dllcache\6to4svc.dll
2011-01-08 21:42 . 2010-01-29 14:45 1315840 -c----w- c:\windows\system32\dllcache\msoe.dll
2011-01-08 21:42 . 2010-01-29 14:45 683520 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2011-01-08 21:42 . 2009-04-15 15:26 583168 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2011-01-08 21:42 . 2010-04-06 12:52 2462720 -c----w- c:\windows\system32\dllcache\WMVCore.dll
2011-01-08 21:41 . 2010-02-05 18:14 1291776 -c----w- c:\windows\system32\dllcache\quartz.dll
2010-12-26 01:37 . 2009-12-24 07:05 177664 -c----w- c:\windows\system32\dllcache\wintrust.dll
2010-12-19 11:21 . 2008-06-20 10:44 138368 ----a-w- c:\windows\system32\drivers\afd.sys
2010-12-19 11:21 . 2008-06-20 10:44 138368 ----a-w- c:\windows\system32\dllcache\afd.sys
2010-12-19 11:20 . 2007-07-22 13:16 332928 ----a-w- c:\windows\system32\drivers\srv.sys
2010-12-19 11:18 . 2004-08-04 01:56 616960 ----a-w- c:\windows\system32\advapi32.dll
2010-12-19 11:18 . 2007-07-24 20:11 2059392 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-19 11:18 . 2007-07-22 13:15 2182144 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-19 11:18 . 2004-08-04 01:56 108032 ----a-w- c:\windows\system32\services.exe
2010-12-19 11:18 . 2004-08-04 01:56 708096 ----a-w- c:\windows\system32\ntdll.dll
2010-12-19 11:10 . 2010-02-11 11:08 226880 -c--a-w- c:\windows\system32\drivers\tcpip6.sys
2010-12-19 11:10 . 2008-06-20 10:44 360960 -c--a-w- c:\windows\system32\drivers\tcpip.sys
2010-12-19 02:05 . 2010-12-19 02:05 -------- dc----w- c:\windows\system32\KB905474
2010-12-17 04:10 . 2010-12-17 04:10 -------- d-----w- c:\windows\system32\wbem\snmp
2010-12-17 04:10 . 2010-12-17 04:10 -------- dc----w- c:\windows\system32\xircom
2010-12-17 04:10 . 2010-12-17 04:10 -------- dc----w- c:\windows\srchasst
2010-12-17 04:10 . 2010-12-17 04:10 -------- dc----w- c:\program files\microsoft frontpage
2010-12-16 06:32 . 2007-07-24 20:09 140288 -c--a-w- c:\windows\system32\sfc_os.dll
2010-12-16 03:59 . 2007-07-24 20:09 140288 -c--a-w- c:\windows\system32\dllcache\sfc_os.dll
2010-12-15 02:21 . 2010-12-15 02:21 -------- dc----w- c:\program files\Microsoft Works
2010-12-15 02:20 . 2010-12-15 02:20 -------- dc----w- c:\program files\MSBuild

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 02:09 . 2010-10-25 02:44 38224 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 02:08 . 2010-10-25 02:44 20952 -c--a-w- c:\windows\system32\drivers\mbam.sys
2010-12-04 02:59 . 2010-12-04 02:48 5310 -c--a-w- c:\windows\BricoPackFoldersDelete.cmd
2010-12-04 02:59 . 2010-12-04 02:59 46273 -c--a-w- c:\windows\BricoPackUninst.cmd
2010-11-01 01:47 . 2010-11-01 01:48 73728 -c--a-w- c:\windows\system32\javacpl.cpl
2010-11-01 01:47 . 2010-11-01 01:48 472808 -c--a-w- c:\windows\system32\deployJava1.dll
.

------- Sigcheck -------

[-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\drivers\atapi.sys

[-] 2004-08-04 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\drivers\asyncmac.sys


[-] 2004-08-03 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\drivers\kbdclass.sys

[-] 2004-08-04 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ndis.sys

[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys

[-] 2004-08-04 . 84885F9B82F4D55C6146EBF6065D75D2 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\lsass.exe

[-] 2004-08-04 . C6CE6EEC82F187615D1002BB3BB50ED4 . 108032 . . [5.1.2600.2180] . . c:\windows\system32\services.exe

[-] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe

[-] 2004-08-04 . 87CA7CE6469577F059297B9D6556D66D . 110080 . . [5.1.2600.2180] . . c:\windows\system32\imm32.dll

[-] 2004-08-04 . 74D66B3DE265E8789153414E75175F26 . 22016 . . [5.1.2600.2180] . . c:\windows\system32\lpk.dll

[-] 2004-08-04 . 1B5F6923ABB450692E9FE0672C897AED . 17408 . . [6.00.2900.2180] . . c:\windows\system32\powrprof.dll

[-] 2004-08-04 . 0F78E27F563F2AAF74B91A49E2ABF19A . 180224 . . [5.1.2600.2180] . . c:\windows\system32\scecli.dll

[-] 2004-08-04 . E8A12A12EA9088B4327D49EDCA3ADD3E . 5120 . . [5.1.2600.2180] . . c:\windows\system32\sfc.dll

[-] 2004-08-04 . 8F078AE4ED187AAABC0A305146DE6716 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\svchost.exe

[-] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\system32\userinit.exe

[-] 2004-08-04 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\system32\ws2_32.dll

[-] 2004-08-04 . 9BEACB911CA61E5881102188AB7FB431 . 19968 . . [5.1.2600.2180] . . c:\windows\system32\ws2help.dll

[-] 2007-07-22 . 1D23EB782291CB7D3ADB33C26EE9583B . 975360 . . [6.00.2900.3111] . . c:\windows\explorer.exe

[-] 2004-08-04 . 2EB58F9DCD6AB320B46744A4EA48B2D2 . 406528 . . [1.0420.2600.2180] . . c:\windows\system32\usp10.dll


[-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\xmlprov.dll

[-] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\eventlog.dll

[-] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

[-] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe


[-] 2004-08-04 . 92360854316611F6CC471612213C3D92 . 190976 . . [5.1.2600.2180] . . c:\windows\system32\schedsvc.dll

[-] 2001-08-23 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

[-] 2004-08-04 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ip6fw.sys

[-] 2007-07-22 13:18 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll

[-] 2004-08-04 . 55E148C01296696588EAFA425782C3E8 . 367616 . . [5.3.2600.2180] . . c:\windows\system32\dsound.dll

[-] 2004-08-04 . D67BDBBDA86CC9AEEBBAF3217C1717D8 . 1689088 . . [5.03.2600.2180] . . c:\windows\system32\d3d9.dll

[-] 2004-08-04 . 7ED462F353B3D915A418A689FA881F96 . 266240 . . [5.03.2600.2180] . . c:\windows\system32\ddraw.dll

[-] 2004-08-04 01:56 . B48D3193DD1474DCBCC32BF4779AC698 . 83456 . . [5.1.2600.2180] . . c:\windows\system32\olepro32.dll

[-] 2004-08-04 . 96492C721C6EA517E2BFD5381FEF55E3 . 39936 . . [5.1.2600.2180] . . c:\windows\system32\perfctrs.dll

[-] 2004-08-04 . D38408967BE738D0C1B47005BCE8CEEB . 18944 . . [5.1.2600.2180] . . c:\windows\system32\version.dll

c:\windows\System32\drivers\beep.sys ... is missing !!
c:\windows\System32\wscntfy.exe ... is missing !!
c:\windows\System32\regsvc.dll ... is missing !!
.
((((((((((((((((((((((((((((( SnapShot_2011-01-09_20.17.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-13 05:46 . 2011-01-13 05:46 16384 c:\windows\Temp\Perflib_Perfdata_77c.dat
+ 2007-07-22 13:18 . 2007-10-28 01:40 222720 c:\windows\system32\wmasf.dll
+ 2007-10-28 01:40 . 2007-10-28 01:40 222720 c:\windows\system32\dllcache\wmasf.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="g:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="g:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-23 112216]
"McAfeeUpdaterUI"="g:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 136768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [2009-03-08 128512]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Taskman"=""

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\g:\0autocheck autochk /r \??\g:\0autocheck autochk /r \??\g:\0autocheck autochk /r \??\G:\0autocheck autochk *

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"RemoveIT Pro v7Ent"=c:\program files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"g:\\Program\\Messenger\\YahooMessenger.exe"=
"g:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"g:\\Program Files\\Skype\\Phone\\Skype.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 12:32 128512 -c--a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2011-01-08 c:\windows\Tasks\1-Click Maintenance.job
- g:\program\TuneUp\OneClick.exe [2008-01-08 20:31]

2011-01-13 c:\windows\Tasks\User_Feed_Synchronization-{EF573F16-43C3-426D-83B3-8B8212819493}.job
- c:\windows\system32\msfeedssync.exe [2008-09-11 12:31]

2011-01-13 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-12-19 06:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyServer = 192.168.45.1:3128
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
Trusted Zone: hotmail.com\www
Trusted Zone: mcafeegsl.com\www
Trusted Zone: msn.com\www
Trusted Zone: tune-up.com\www
Trusted Zone: yahoo.com\us.mg2.mail
Trusted Zone: yahoo.com\www
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2l3t523o.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - g:\program files\lib\deploy\jqs\ff
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 1000000
FF - user.js: nglayout.initialpaint.delay - 600
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-12 21:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-602162358-2025429265-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,11,38,fb,56,db,14,42,95,6c,ce,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,30,c3,e3,18,f1,0c,4f,8f,ad,a3,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,11,38,fb,56,db,14,42,95,6c,ce,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1380)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
g:\program files\bin\jqs.exe
g:\program files\McAfee\Common Framework\FrameworkService.exe
g:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
g:\program files\McAfee\Common Framework\naPrdMgr.exe
g:\program files\McAfee\Common Framework\McTray.exe
.
**************************************************************************
.
Completion time: 2011-01-12 22:01:11 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-13 06:01
ComboFix2.txt 2011-01-10 07:38
ComboFix3.txt 2011-01-09 20:22
ComboFix4.txt 2011-01-09 03:00
ComboFix5.txt 2011-01-13 05:31

Pre-Run: 156,512,256 bytes free
Post-Run: 94,273,536 bytes free

- - End Of File - - 6C630AAB6A34B2B417DB0893D8D16710
edgondoy
Geek in Training
Geek in Training
 
Posts: 15
Joined: Mon Jan 03, 2011 3:38 pm

Thanks given:0
Thanks received:0
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby Gecko » Thu Jan 13, 2011 6:57 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby edgondoy » Sat Jan 15, 2011 2:53 pm

first i must state some factors that might affect other thing that might go on afterwards first everytime the pc reboots mcafee automatically opens so when combofix automatically force reboots the pc ..and afterwards beacause of that i have to manually diasble mcafee by using taks manager and ending the mcshield proccess..2nd i use notepad++ portable and 3rd just got this recently "Combofix has expired click "Yes" to run in reduced functionality mode and no "NO" to exit, I clicked yes. and lastly i disable everything when i run combofix the internet and mcafee(by using taskmanager ending the process mcshield.exe)
=============================
ComboFix 11-01-08.03 - Administrator 01/15/2011 21:23:42.9.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.660 [GMT -8:00]
Running from: c:\documents and settings\Administrator\Desktop\cbf.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
"c:\windows\Temp\Perflib_Perfdata_77c.dat"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\regedit.exe . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2010-12-16 to 2011-01-16 )))))))))))))))))))))))))))))))
.

2011-01-09 03:27 . 2011-01-09 03:27 -------- dc-h--w- c:\windows\PIF
2011-01-09 03:04 . 2004-08-04 01:56 221184 -c--a-w- c:\windows\system32\wmpns.dll
2011-01-08 22:30 . 2011-01-08 22:47 -------- dc----w- c:\windows\system32\CatRoot_bak
2011-01-08 21:59 . 2009-04-02 07:02 604160 -c----w- c:\windows\system32\dllcache\wmspdmod.dll
2011-01-08 21:59 . 2009-10-21 05:50 75776 -c----w- c:\windows\system32\dllcache\strmfilt.dll
2011-01-08 21:59 . 2009-10-21 05:50 25088 -c----w- c:\windows\system32\dllcache\httpapi.dll
2011-01-08 21:59 . 2009-10-20 14:41 265728 -c----w- c:\windows\system32\dllcache\http.sys
2011-01-08 21:59 . 2010-02-24 12:48 457216 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-01-08 21:58 . 2009-10-12 13:54 112128 -c----w- c:\windows\system32\dllcache\rastls.dll
2011-01-08 21:58 . 2009-10-12 13:54 69632 -c----w- c:\windows\system32\dllcache\raschap.dll
2011-01-08 21:58 . 2008-07-07 20:06 253952 -c----w- c:\windows\system32\dllcache\es.dll
2011-01-08 21:57 . 2009-12-14 07:35 33280 -c----w- c:\windows\system32\dllcache\csrsrv.dll
2011-01-08 21:57 . 2009-06-10 06:26 134144 -c----w- c:\windows\system32\dllcache\wkssvc.dll
2011-01-08 21:56 . 2009-10-15 16:56 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-01-08 21:56 . 2009-10-15 16:56 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-01-08 21:56 . 2009-06-09 14:53 53248 -c----w- c:\windows\system32\dllcache\tsgqec.dll
2011-01-08 21:56 . 2009-06-09 14:53 290816 -c----w- c:\windows\system32\dllcache\rhttpaa.dll
2011-01-08 21:55 . 2009-06-09 14:53 2067968 -c----w- c:\windows\system32\dllcache\mstscax.dll
2011-01-08 21:55 . 2009-06-09 09:12 677888 -c----w- c:\windows\system32\dllcache\mstsc.exe
2011-01-08 21:55 . 2009-06-09 14:53 136192 -c----w- c:\windows\system32\dllcache\aaclient.dll
2011-01-08 21:55 . 2009-08-26 08:16 247326 -c----w- c:\windows\system32\dllcache\strmdll.dll
2011-01-08 21:53 . 2009-06-21 22:04 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2011-01-08 21:53 . 2009-05-07 15:44 344064 -c----w- c:\windows\system32\dllcache\localspl.dll
2011-01-08 21:52 . 2008-06-18 13:03 938496 -c----w- c:\windows\system32\dllcache\WMNetmgr.dll
2011-01-08 21:52 . 2008-06-18 09:09 100864 -c----w- c:\windows\system32\dllcache\logagent.exe
2011-01-08 21:50 . 2008-06-12 13:47 91648 -c----w- c:\windows\system32\dllcache\mtxoci.dll
2011-01-08 21:50 . 2008-06-12 13:47 66560 -c----w- c:\windows\system32\dllcache\mtxclu.dll
2011-01-08 21:50 . 2008-06-12 13:47 161792 -c----w- c:\windows\system32\dllcache\msdtcuiu.dll
2011-01-08 21:50 . 2008-06-12 13:47 956928 -c----w- c:\windows\system32\dllcache\msdtctm.dll
2011-01-08 21:50 . 2008-06-12 13:47 58880 -c----w- c:\windows\system32\dllcache\msdtclog.dll
2011-01-08 21:50 . 2008-06-12 13:47 428032 -c----w- c:\windows\system32\dllcache\msdtcprx.dll
2011-01-08 21:50 . 2009-09-04 20:45 58880 -c----w- c:\windows\system32\dllcache\msasn1.dll
2011-01-08 21:49 . 2009-07-17 18:55 58880 -c----w- c:\windows\system32\dllcache\atl.dll
2011-01-08 21:48 . 2008-05-08 12:14 203008 -c----w- c:\windows\system32\dllcache\rmcast.sys
2011-01-08 21:47 . 2010-05-02 07:09 1859968 -c----w- c:\windows\system32\dllcache\win32k.sys
2011-01-08 21:44 . 2008-07-03 13:16 8454656 -c----w- c:\windows\system32\dllcache\shell32.dll
2011-01-08 21:44 . 2009-10-13 10:45 270336 -c----w- c:\windows\system32\dllcache\oakley.dll
2011-01-08 21:43 . 2010-02-11 11:08 226880 -c----w- c:\windows\system32\dllcache\tcpip6.sys
2011-01-08 21:43 . 2008-06-20 10:44 360960 -c----w- c:\windows\system32\dllcache\tcpip.sys
2011-01-08 21:43 . 2008-06-20 17:36 245248 -c----w- c:\windows\system32\dllcache\mswsock.dll
2011-01-08 21:43 . 2008-06-20 17:36 147968 -c----w- c:\windows\system32\dllcache\dnsapi.dll
2011-01-08 21:43 . 2010-02-12 04:36 100864 -c----w- c:\windows\system32\dllcache\6to4svc.dll
2011-01-08 21:42 . 2010-01-29 14:45 1315840 -c----w- c:\windows\system32\dllcache\msoe.dll
2011-01-08 21:42 . 2010-01-29 14:45 683520 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2011-01-08 21:42 . 2009-04-15 15:26 583168 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2011-01-08 21:42 . 2010-04-06 12:52 2462720 -c----w- c:\windows\system32\dllcache\WMVCore.dll
2011-01-08 21:41 . 2010-02-05 18:14 1291776 -c----w- c:\windows\system32\dllcache\quartz.dll
2010-12-26 01:37 . 2009-12-24 07:05 177664 -c----w- c:\windows\system32\dllcache\wintrust.dll
2010-12-19 11:21 . 2008-06-20 10:44 138368 ----a-w- c:\windows\system32\drivers\afd.sys
2010-12-19 11:21 . 2008-06-20 10:44 138368 ----a-w- c:\windows\system32\dllcache\afd.sys
2010-12-19 11:20 . 2007-07-22 13:16 332928 ----a-w- c:\windows\system32\drivers\srv.sys
2010-12-19 11:18 . 2004-08-04 01:56 616960 ----a-w- c:\windows\system32\advapi32.dll
2010-12-19 11:18 . 2007-07-24 20:11 2059392 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-19 11:18 . 2007-07-22 13:15 2182144 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-19 11:18 . 2004-08-04 01:56 108032 ----a-w- c:\windows\system32\services.exe
2010-12-19 11:18 . 2004-08-04 01:56 708096 ----a-w- c:\windows\system32\ntdll.dll
2010-12-19 11:10 . 2010-02-11 11:08 226880 -c--a-w- c:\windows\system32\drivers\tcpip6.sys
2010-12-19 11:10 . 2008-06-20 10:44 360960 -c--a-w- c:\windows\system32\drivers\tcpip.sys
2010-12-19 02:05 . 2010-12-19 02:05 -------- dc----w- c:\windows\system32\KB905474

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 02:09 . 2010-10-25 02:44 38224 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 02:08 . 2010-10-25 02:44 20952 -c--a-w- c:\windows\system32\drivers\mbam.sys
2010-12-04 02:59 . 2010-12-04 02:48 5310 -c--a-w- c:\windows\BricoPackFoldersDelete.cmd
2010-12-04 02:59 . 2010-12-04 02:59 46273 -c--a-w- c:\windows\BricoPackUninst.cmd
2010-12-04 02:59 . 2007-07-24 20:09 218624 -c--a-w- c:\windows\system32\uxtheme.dll
2010-12-01 17:22 . 2010-12-01 17:22 306432 -c--a-w- c:\windows\system32\TuneUpDefragService.exe
2010-11-01 01:47 . 2010-11-01 01:48 73728 -c--a-w- c:\windows\system32\javacpl.cpl
2010-11-01 01:47 . 2010-11-01 01:48 472808 -c--a-w- c:\windows\system32\deployJava1.dll
.

------- Sigcheck -------

[-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\drivers\atapi.sys

[-] 2004-08-04 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\drivers\asyncmac.sys


[-] 2004-08-03 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\drivers\kbdclass.sys

[-] 2004-08-04 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ndis.sys

[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys

[-] 2004-08-04 . 84885F9B82F4D55C6146EBF6065D75D2 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\lsass.exe

[-] 2004-08-04 . C6CE6EEC82F187615D1002BB3BB50ED4 . 108032 . . [5.1.2600.2180] . . c:\windows\system32\services.exe

[-] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe

[-] 2004-08-04 . 87CA7CE6469577F059297B9D6556D66D . 110080 . . [5.1.2600.2180] . . c:\windows\system32\imm32.dll

[-] 2004-08-04 . 74D66B3DE265E8789153414E75175F26 . 22016 . . [5.1.2600.2180] . . c:\windows\system32\lpk.dll

[-] 2004-08-04 . 1B5F6923ABB450692E9FE0672C897AED . 17408 . . [6.00.2900.2180] . . c:\windows\system32\powrprof.dll

[-] 2004-08-04 . 0F78E27F563F2AAF74B91A49E2ABF19A . 180224 . . [5.1.2600.2180] . . c:\windows\system32\scecli.dll

[-] 2004-08-04 . E8A12A12EA9088B4327D49EDCA3ADD3E . 5120 . . [5.1.2600.2180] . . c:\windows\system32\sfc.dll

[-] 2004-08-04 . 8F078AE4ED187AAABC0A305146DE6716 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\svchost.exe

[-] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\system32\userinit.exe

[-] 2004-08-04 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\system32\ws2_32.dll

[-] 2004-08-04 . 9BEACB911CA61E5881102188AB7FB431 . 19968 . . [5.1.2600.2180] . . c:\windows\system32\ws2help.dll

[-] 2007-07-22 . 1D23EB782291CB7D3ADB33C26EE9583B . 975360 . . [6.00.2900.3111] . . c:\windows\explorer.exe

[-] 2004-08-04 . 2EB58F9DCD6AB320B46744A4EA48B2D2 . 406528 . . [1.0420.2600.2180] . . c:\windows\system32\usp10.dll


[-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\xmlprov.dll

[-] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\eventlog.dll

[-] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

[-] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe


[-] 2004-08-04 . 92360854316611F6CC471612213C3D92 . 190976 . . [5.1.2600.2180] . . c:\windows\system32\schedsvc.dll

[-] 2001-08-23 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

[-] 2004-08-04 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ip6fw.sys

[-] 2007-07-22 13:18 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll

[-] 2004-08-04 . 55E148C01296696588EAFA425782C3E8 . 367616 . . [5.3.2600.2180] . . c:\windows\system32\dsound.dll

[-] 2004-08-04 . D67BDBBDA86CC9AEEBBAF3217C1717D8 . 1689088 . . [5.03.2600.2180] . . c:\windows\system32\d3d9.dll

[-] 2004-08-04 . 7ED462F353B3D915A418A689FA881F96 . 266240 . . [5.03.2600.2180] . . c:\windows\system32\ddraw.dll

[-] 2004-08-04 01:56 . B48D3193DD1474DCBCC32BF4779AC698 . 83456 . . [5.1.2600.2180] . . c:\windows\system32\olepro32.dll

[-] 2004-08-04 . 96492C721C6EA517E2BFD5381FEF55E3 . 39936 . . [5.1.2600.2180] . . c:\windows\system32\perfctrs.dll

[-] 2004-08-04 . D38408967BE738D0C1B47005BCE8CEEB . 18944 . . [5.1.2600.2180] . . c:\windows\system32\version.dll

c:\windows\System32\drivers\beep.sys ... is missing !!
c:\windows\System32\wscntfy.exe ... is missing !!
c:\windows\System32\regsvc.dll ... is missing !!
.
((((((((((((((((((((((((((((( SnapShot_2011-01-09_20.17.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-16 05:27 . 2011-01-16 05:27 16384 c:\windows\temp\Perflib_Perfdata_394.dat
+ 2007-07-22 13:18 . 2007-10-28 01:40 222720 c:\windows\system32\wmasf.dll
+ 2007-10-28 01:40 . 2007-10-28 01:40 222720 c:\windows\system32\dllcache\wmasf.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="g:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="g:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-23 112216]
"McAfeeUpdaterUI"="g:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 136768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-08 128512]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\g:\0autocheck autochk /r \??\g:\0autocheck autochk /r \??\g:\0autocheck autochk /r \??\G:\0autocheck autochk *

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"RemoveIT Pro v7Ent"=c:\program files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"g:\\Program\\Messenger\\YahooMessenger.exe"=
"g:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"g:\\Program Files\\Skype\\Phone\\Skype.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 12:32 128512 -c--a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2011-01-08 c:\windows\Tasks\1-Click Maintenance.job
- g:\program\TuneUp\OneClick.exe [2008-01-08 20:31]

2011-01-16 c:\windows\Tasks\User_Feed_Synchronization-{EF573F16-43C3-426D-83B3-8B8212819493}.job
- c:\windows\system32\msfeedssync.exe [2008-09-11 12:31]

2011-01-16 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-12-19 06:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyServer = 192.168.45.1:3128
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
Trusted Zone: hotmail.com\www
Trusted Zone: mcafeegsl.com\www
Trusted Zone: msn.com\www
Trusted Zone: tune-up.com\www
Trusted Zone: yahoo.com\us.mg2.mail
Trusted Zone: yahoo.com\www
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2l3t523o.default\
FF - prefs.js: browser.startup.homepage - http://www.yahoo.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - g:\program files\lib\deploy\jqs\ff
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 1000000
FF - user.js: nglayout.initialpaint.delay - 600
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-15 21:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-602162358-2025429265-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,11,38,fb,56,db,14,42,95,6c,ce,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,30,c3,e3,18,f1,0c,4f,8f,ad,a3,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,11,38,fb,56,db,14,42,95,6c,ce,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3956)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
g:\program files\bin\jqs.exe
g:\program files\McAfee\Common Framework\FrameworkService.exe
g:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
g:\program files\McAfee\Common Framework\McTray.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
g:\program files\McAfee\Common Framework\naPrdMgr.exe
.
**************************************************************************
.
Completion time: 2011-01-15 21:34:54 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-16 05:34
ComboFix2.txt 2011-01-13 06:01
ComboFix3.txt 2011-01-10 07:38
ComboFix4.txt 2011-01-09 20:22
ComboFix5.txt 2011-01-16 05:20

Pre-Run: 8,044,544 bytes free
Post-Run: 158,769,152 bytes free

- - End Of File - - F2F497FA4D2F29ABCEDABB8AA4A7955F
edgondoy
Geek in Training
Geek in Training
 
Posts: 15
Joined: Mon Jan 03, 2011 3:38 pm

Thanks given:0
Thanks received:0
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby Gecko » Sat Jan 15, 2011 10:55 pm

First delete your current version of Combofix (cbf) from your desktop and then from your recycle bin.
Then download a fresh version of combofix from to your desktop.
Now drag then drop the CFScript file still on your desktop onto ComboFix.exe again.

The script should replace your infected regedit with a backup from your service packs.
I have seen some reports of a false positive on the regedit.exe file
If it come back infected again I'll have you upload to http://virusscan.jotti.org/en for detection.

Post your latest Combofix log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby edgondoy » Sun Jan 16, 2011 6:21 am

Excellent news pc is strating fast like it normally did..though duing the combofix process it failed to make a backup beacuse of the laptop's low disk space, hope nothing signifacant was destroyed.. Heres the log..
=====================
ComboFix 11-01-14.01 - Administrator 01/16/2011 12:27:26.10.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.698 [GMT -8:00]
Running from: c:\documents and settings\Administrator\Desktop\cbf.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript

FILE ::
"c:\windows\Temp\Perflib_Perfdata_77c.dat"
.

((((((((((((((((((((((((( Files Created from 2010-12-16 to 2011-01-16 )))))))))))))))))))))))))))))))
.

2011-01-09 03:27 . 2011-01-09 03:27 -------- dc-h--w- c:\windows\PIF
2011-01-09 03:04 . 2004-08-04 01:56 221184 -c--a-w- c:\windows\system32\wmpns.dll
2011-01-08 22:30 . 2011-01-08 22:47 -------- dc----w- c:\windows\system32\CatRoot_bak
2011-01-08 21:59 . 2009-04-02 07:02 604160 -c----w- c:\windows\system32\dllcache\wmspdmod.dll
2011-01-08 21:59 . 2009-10-21 05:50 75776 -c----w- c:\windows\system32\dllcache\strmfilt.dll
2011-01-08 21:59 . 2009-10-21 05:50 25088 -c----w- c:\windows\system32\dllcache\httpapi.dll
2011-01-08 21:59 . 2009-10-20 14:41 265728 -c----w- c:\windows\system32\dllcache\http.sys
2011-01-08 21:59 . 2010-02-24 12:48 457216 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-01-08 21:58 . 2009-10-12 13:54 112128 -c----w- c:\windows\system32\dllcache\rastls.dll
2011-01-08 21:58 . 2009-10-12 13:54 69632 -c----w- c:\windows\system32\dllcache\raschap.dll
2011-01-08 21:58 . 2008-07-07 20:06 253952 -c----w- c:\windows\system32\dllcache\es.dll
2011-01-08 21:57 . 2009-12-14 07:35 33280 -c----w- c:\windows\system32\dllcache\csrsrv.dll
2011-01-08 21:57 . 2009-06-10 06:26 134144 -c----w- c:\windows\system32\dllcache\wkssvc.dll
2011-01-08 21:56 . 2009-10-15 16:56 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-01-08 21:56 . 2009-10-15 16:56 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-01-08 21:56 . 2009-06-09 14:53 53248 -c----w- c:\windows\system32\dllcache\tsgqec.dll
2011-01-08 21:56 . 2009-06-09 14:53 290816 -c----w- c:\windows\system32\dllcache\rhttpaa.dll
2011-01-08 21:55 . 2009-06-09 14:53 2067968 -c----w- c:\windows\system32\dllcache\mstscax.dll
2011-01-08 21:55 . 2009-06-09 09:12 677888 -c----w- c:\windows\system32\dllcache\mstsc.exe
2011-01-08 21:55 . 2009-06-09 14:53 136192 -c----w- c:\windows\system32\dllcache\aaclient.dll
2011-01-08 21:55 . 2009-08-26 08:16 247326 -c----w- c:\windows\system32\dllcache\strmdll.dll
2011-01-08 21:53 . 2009-06-21 22:04 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2011-01-08 21:53 . 2009-05-07 15:44 344064 -c----w- c:\windows\system32\dllcache\localspl.dll
2011-01-08 21:52 . 2008-06-18 13:03 938496 -c----w- c:\windows\system32\dllcache\WMNetmgr.dll
2011-01-08 21:52 . 2008-06-18 09:09 100864 -c----w- c:\windows\system32\dllcache\logagent.exe
2011-01-08 21:50 . 2008-06-12 13:47 91648 -c----w- c:\windows\system32\dllcache\mtxoci.dll
2011-01-08 21:50 . 2008-06-12 13:47 66560 -c----w- c:\windows\system32\dllcache\mtxclu.dll
2011-01-08 21:50 . 2008-06-12 13:47 161792 -c----w- c:\windows\system32\dllcache\msdtcuiu.dll
2011-01-08 21:50 . 2008-06-12 13:47 956928 -c----w- c:\windows\system32\dllcache\msdtctm.dll
2011-01-08 21:50 . 2008-06-12 13:47 58880 -c----w- c:\windows\system32\dllcache\msdtclog.dll
2011-01-08 21:50 . 2008-06-12 13:47 428032 -c----w- c:\windows\system32\dllcache\msdtcprx.dll
2011-01-08 21:50 . 2009-09-04 20:45 58880 -c----w- c:\windows\system32\dllcache\msasn1.dll
2011-01-08 21:49 . 2009-07-17 18:55 58880 -c----w- c:\windows\system32\dllcache\atl.dll
2011-01-08 21:48 . 2008-05-08 12:14 203008 -c----w- c:\windows\system32\dllcache\rmcast.sys
2011-01-08 21:47 . 2010-05-02 07:09 1859968 -c----w- c:\windows\system32\dllcache\win32k.sys
2011-01-08 21:44 . 2008-07-03 13:16 8454656 -c----w- c:\windows\system32\dllcache\shell32.dll
2011-01-08 21:44 . 2009-10-13 10:45 270336 -c----w- c:\windows\system32\dllcache\oakley.dll
2011-01-08 21:43 . 2010-02-11 11:08 226880 -c----w- c:\windows\system32\dllcache\tcpip6.sys
2011-01-08 21:43 . 2008-06-20 10:44 360960 -c----w- c:\windows\system32\dllcache\tcpip.sys
2011-01-08 21:43 . 2008-06-20 17:36 245248 -c----w- c:\windows\system32\dllcache\mswsock.dll
2011-01-08 21:43 . 2008-06-20 17:36 147968 -c----w- c:\windows\system32\dllcache\dnsapi.dll
2011-01-08 21:43 . 2010-02-12 04:36 100864 -c----w- c:\windows\system32\dllcache\6to4svc.dll
2011-01-08 21:42 . 2010-01-29 14:45 1315840 -c----w- c:\windows\system32\dllcache\msoe.dll
2011-01-08 21:42 . 2010-01-29 14:45 683520 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2011-01-08 21:42 . 2009-04-15 15:26 583168 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2011-01-08 21:42 . 2010-04-06 12:52 2462720 -c----w- c:\windows\system32\dllcache\WMVCore.dll
2011-01-08 21:41 . 2010-02-05 18:14 1291776 -c----w- c:\windows\system32\dllcache\quartz.dll
2010-12-26 01:37 . 2009-12-24 07:05 177664 -c----w- c:\windows\system32\dllcache\wintrust.dll
2010-12-19 11:21 . 2008-06-20 10:44 138368 ----a-w- c:\windows\system32\drivers\afd.sys
2010-12-19 11:21 . 2008-06-20 10:44 138368 ----a-w- c:\windows\system32\dllcache\afd.sys
2010-12-19 11:20 . 2007-07-22 13:16 332928 ----a-w- c:\windows\system32\drivers\srv.sys
2010-12-19 11:18 . 2004-08-04 01:56 616960 ----a-w- c:\windows\system32\advapi32.dll
2010-12-19 11:18 . 2007-07-24 20:11 2059392 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-12-19 11:18 . 2007-07-22 13:15 2182144 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-19 11:18 . 2004-08-04 01:56 108032 ----a-w- c:\windows\system32\services.exe
2010-12-19 11:18 . 2004-08-04 01:56 708096 ----a-w- c:\windows\system32\ntdll.dll
2010-12-19 11:10 . 2010-02-11 11:08 226880 -c--a-w- c:\windows\system32\drivers\tcpip6.sys
2010-12-19 11:10 . 2008-06-20 10:44 360960 -c--a-w- c:\windows\system32\drivers\tcpip.sys
2010-12-19 02:05 . 2010-12-19 02:05 -------- dc----w- c:\windows\system32\KB905474

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-21 02:09 . 2010-10-25 02:44 38224 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-21 02:08 . 2010-10-25 02:44 20952 -c--a-w- c:\windows\system32\drivers\mbam.sys
2010-12-04 02:59 . 2010-12-04 02:48 5310 -c--a-w- c:\windows\BricoPackFoldersDelete.cmd
2010-12-04 02:59 . 2010-12-04 02:59 46273 -c--a-w- c:\windows\BricoPackUninst.cmd
2010-12-04 02:59 . 2007-07-24 20:09 218624 -c--a-w- c:\windows\system32\uxtheme.dll
2010-12-01 17:22 . 2010-12-01 17:22 306432 -c--a-w- c:\windows\system32\TuneUpDefragService.exe
2010-11-01 01:47 . 2010-11-01 01:48 73728 -c--a-w- c:\windows\system32\javacpl.cpl
2010-11-01 01:47 . 2010-11-01 01:48 472808 -c--a-w- c:\windows\system32\deployJava1.dll
.

------- Sigcheck -------

[-] 2004-08-03 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\drivers\atapi.sys

[-] 2004-08-04 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\drivers\asyncmac.sys


[-] 2004-08-03 . EBDEE8A2EE5393890A1ACEE971C4C246 . 24576 . . [5.1.2600.2180] . . c:\windows\system32\drivers\kbdclass.sys

[-] 2004-08-04 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ndis.sys

[-] 2001-08-23 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys

[-] 2004-08-04 . 84885F9B82F4D55C6146EBF6065D75D2 . 13312 . . [5.1.2600.2180] . . c:\windows\system32\lsass.exe

[-] 2009-02-06 . 37561F8D4160D62DA86D24AE41FAE8DE . 110592 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\services.exe
[-] 2009-02-06 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\services.exe
[-] 2009-02-06 . 020CEAAEDC8EB655B6506B8C70D53BB6 . 110592 . . [5.1.2600.5755] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\services.exe
[-] 2009-02-06 . 4712531AB7A01B7EE059853CA17D39BD . 110592 . . [5.1.2600.3520] . . c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\services.exe
[-] 2004-08-04 . C6CE6EEC82F187615D1002BB3BB50ED4 . 108032 . . [5.1.2600.2180] . . c:\windows\system32\services.exe

[-] 2004-08-04 . 01C3346C241652F43AED8E2149881BFE . 502272 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe

[-] 2004-08-04 . 87CA7CE6469577F059297B9D6556D66D . 110080 . . [5.1.2600.2180] . . c:\windows\system32\imm32.dll

[-] 2004-08-04 . 74D66B3DE265E8789153414E75175F26 . 22016 . . [5.1.2600.2180] . . c:\windows\system32\lpk.dll

[-] 2004-08-04 . 1B5F6923ABB450692E9FE0672C897AED . 17408 . . [6.00.2900.2180] . . c:\windows\system32\powrprof.dll

[-] 2004-08-04 . 0F78E27F563F2AAF74B91A49E2ABF19A . 180224 . . [5.1.2600.2180] . . c:\windows\system32\scecli.dll

[-] 2004-08-04 . E8A12A12EA9088B4327D49EDCA3ADD3E . 5120 . . [5.1.2600.2180] . . c:\windows\system32\sfc.dll

[-] 2004-08-04 . 8F078AE4ED187AAABC0A305146DE6716 . 14336 . . [5.1.2600.2180] . . c:\windows\system32\svchost.exe

[-] 2004-08-04 . 39B1FFB03C2296323832ACBAE50D2AFF . 24576 . . [5.1.2600.2180] . . c:\windows\system32\userinit.exe

[-] 2004-08-04 . 2ED0B7F12A60F90092081C50FA0EC2B2 . 82944 . . [5.1.2600.2180] . . c:\windows\system32\ws2_32.dll

[-] 2004-08-04 . 9BEACB911CA61E5881102188AB7FB431 . 19968 . . [5.1.2600.2180] . . c:\windows\system32\ws2help.dll

[-] 2007-07-22 . 1D23EB782291CB7D3ADB33C26EE9583B . 975360 . . [6.00.2900.3111] . . c:\windows\explorer.exe

[-] 2004-08-04 . 2EB58F9DCD6AB320B46744A4EA48B2D2 . 406528 . . [1.0420.2600.2180] . . c:\windows\system32\usp10.dll


[-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\xmlprov.dll

[-] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\system32\eventlog.dll

[-] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

[-] 2004-08-04 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe


[-] 2004-08-04 . 92360854316611F6CC471612213C3D92 . 190976 . . [5.1.2600.2180] . . c:\windows\system32\schedsvc.dll

[-] 2001-08-23 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

[-] 2004-08-04 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ip6fw.sys

[-] 2007-07-22 13:18 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll

[-] 2004-08-04 . 55E148C01296696588EAFA425782C3E8 . 367616 . . [5.3.2600.2180] . . c:\windows\system32\dsound.dll

[-] 2004-08-04 . D67BDBBDA86CC9AEEBBAF3217C1717D8 . 1689088 . . [5.03.2600.2180] . . c:\windows\system32\d3d9.dll

[-] 2004-08-04 . 7ED462F353B3D915A418A689FA881F96 . 266240 . . [5.03.2600.2180] . . c:\windows\system32\ddraw.dll

[-] 2004-08-04 01:56 . B48D3193DD1474DCBCC32BF4779AC698 . 83456 . . [5.1.2600.2180] . . c:\windows\system32\olepro32.dll

[-] 2004-08-04 . 96492C721C6EA517E2BFD5381FEF55E3 . 39936 . . [5.1.2600.2180] . . c:\windows\system32\perfctrs.dll

[-] 2004-08-04 . D38408967BE738D0C1B47005BCE8CEEB . 18944 . . [5.1.2600.2180] . . c:\windows\system32\version.dll

c:\windows\System32\drivers\beep.sys ... is missing !!
c:\windows\System32\wscntfy.exe ... is missing !!
c:\windows\System32\regsvc.dll ... is missing !!
.
((((((((((((((((((((((((((((( SnapShot_2011-01-09_20.17.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-16 20:34 . 2011-01-16 20:34 16384 c:\windows\temp\Perflib_Perfdata_798.dat
+ 2007-07-22 13:18 . 2007-10-28 01:40 222720 c:\windows\system32\wmasf.dll
+ 2007-10-28 01:40 . 2007-10-28 01:40 222720 c:\windows\system32\dllcache\wmasf.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="g:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="g:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-02-23 112216]
"McAfeeUpdaterUI"="g:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 136768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-08 128512]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\g:\0autocheck autochk /r \??\g:\0autocheck autochk /r \??\g:\0autocheck autochk /r \??\G:\0autocheck autochk *

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"RemoveIT Pro v7Ent"=c:\program files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"g:\\Program\\Messenger\\YahooMessenger.exe"=
"g:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"g:\\Program Files\\Skype\\Phone\\Skype.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 12:32 128512 -c--a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2011-01-08 c:\windows\Tasks\1-Click Maintenance.job
- g:\program\TuneUp\OneClick.exe [2008-01-08 20:31]

2011-01-16 c:\windows\Tasks\User_Feed_Synchronization-{EF573F16-43C3-426D-83B3-8B8212819493}.job
- c:\windows\system32\msfeedssync.exe [2008-09-11 12:31]

2011-01-16 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-12-19 06:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyServer = 192.168.45.1:3128
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
Trusted Zone: hotmail.com\www
Trusted Zone: mcafeegsl.com\www
Trusted Zone: msn.com\www
Trusted Zone: tune-up.com\www
Trusted Zone: yahoo.com\us.mg2.mail
Trusted Zone: yahoo.com\www
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\2l3t523o.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - g:\program files\lib\deploy\jqs\ff
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 1000000
FF - user.js: nglayout.initialpaint.delay - 600
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-16 12:39
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-602162358-2025429265-1177238915-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,11,38,fb,56,db,14,42,95,6c,ce,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e8,30,c3,e3,18,f1,0c,4f,8f,ad,a3,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,cf,11,38,fb,56,db,14,42,95,6c,ce,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(876)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
g:\program files\bin\jqs.exe
g:\program files\McAfee\Common Framework\FrameworkService.exe
g:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
g:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
g:\program files\McAfee\Common Framework\McTray.exe
c:\windows\system32\cleanmgr.exe
.
**************************************************************************
.
Completion time: 2011-01-16 12:46:50 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-16 20:46
ComboFix2.txt 2011-01-16 05:34
ComboFix3.txt 2011-01-13 06:01
ComboFix4.txt 2011-01-10 07:38
ComboFix5.txt 2011-01-16 20:08

Pre-Run: 24,780,800 bytes free
Post-Run: 75,210,752 bytes free

- - End Of File - - A7CA740390F8BE4F2D1F2A909C78AD02
edgondoy
Geek in Training
Geek in Training
 
Posts: 15
Joined: Mon Jan 03, 2011 3:38 pm

Thanks given:0
Thanks received:0
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby Gecko » Mon Jan 17, 2011 1:12 pm

edgondoy,

Your log looks clean :)
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby edgondoy » Tue Jan 18, 2011 1:27 pm

are we done here? i feel like every other day it gets slowwer again...am I reapetedly getting attacked??or is it because of the low disk space?any tips to reduce the size of pagefile.sys(1.48gigabytes) :shock: ..and my masximum dsikspace in drive C:/ is 3.72 GBs.
edgondoy
Geek in Training
Geek in Training
 
Posts: 15
Joined: Mon Jan 03, 2011 3:38 pm

Thanks given:0
Thanks received:0
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby Gecko » Tue Jan 18, 2011 7:35 pm

edgondoy,

When you said that it was getting slower I went back and checked your OTL log.
I must have overlooked it the first time, "Windows XP Professional Edition Service Pack 2"
You need to update to service pack 3 without it you will just keep getting reinfected!


To set your pagefile.sys size:
Start > Control Panel > System > Advanced tab > Performance section Settings button >
Advanced tab > Virtual memeory section Change button > set to you liking but not too low maybe .5 gb

If after the update and changing the pagefile it's still slow post back and we'll take it from there.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby edgondoy » Wed Jan 19, 2011 2:07 pm

Thanks a lot man,you've been a really great help.. ill post a new thread if ever i get infected again provided of course this thread gets closed.. Again thanks!!
edgondoy
Geek in Training
Geek in Training
 
Posts: 15
Joined: Mon Jan 03, 2011 3:38 pm

Thanks given:0
Thanks received:0
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby edgondoy » Fri Jan 21, 2011 2:54 pm

I completely forgot arethese files important?
c:\windows\System32\drivers\beep.sys ... is missing !!
c:\windows\System32\wscntfy.exe ... is missing !!
c:\windows\System32\regsvc.dll ... is missing !!
edgondoy
Geek in Training
Geek in Training
 
Posts: 15
Joined: Mon Jan 03, 2011 3:38 pm

Thanks given:0
Thanks received:0
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby Gecko » Sat Jan 22, 2011 12:21 am

edgondoy,

Go to the Run box on the Start Menu and type in:
sfc /scannow (note the space between the c and the /)
Press enter

This should replace the missing files that were flagged as infected and are now missing.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: PC GETTING SLOW LATELY...pls help...

Postby edgondoy » Sat Jan 22, 2011 1:46 pm

dang..it didnt work because 1)WindowsFileProtection Stated the following "Files that are required for windows to run properly must be copied to the DLL Cache...Please Insert Windows XP Professional Service Pack 2 CD now. "
Is doing this my only option? i want to see my choices before doing this because I dont know how to put a cd on this laptop... :oops:
=====================================
also i forgot to state that a month ago I removed some windows updates in the add/remove programs tool in the control panel to save some space for drive C: .. afterwards it kept telling me about unrecognized versions and causing system instability... can this be repaired through other means other than reformatting???
edgondoy
Geek in Training
Geek in Training
 
Posts: 15
Joined: Mon Jan 03, 2011 3:38 pm

Thanks given:0
Thanks received:0
Top

Previous

Return to Windows 7, 2008 and Vista

Who is online

Users browsing this forum: No registered users and 1 guest

cron