Computer slowing down

Reply

Join Date: Jun 2005
Posts: 79
Reputation: hetixo is an unknown quantity at this point 
Solved Threads: 0
hetixo hetixo is offline Offline
Junior Poster in Training

Re: Computer slowing down

 
0
  #11
Jun 5th, 2007
can i just delete the .exe from the windows directory?
Reply With Quote Quick reply to this message  
Join Date: Jun 2005
Posts: 79
Reputation: hetixo is an unknown quantity at this point 
Solved Threads: 0
hetixo hetixo is offline Offline
Junior Poster in Training

Re: Computer slowing down

 
0
  #12
Jun 5th, 2007
right, i have located a file with a similar name, only this time ndnuninstall47.exe. No sign of the 36? Shall i delete that one?
Reply With Quote Quick reply to this message  
Join Date: Jun 2005
Posts: 79
Reputation: hetixo is an unknown quantity at this point 
Solved Threads: 0
hetixo hetixo is offline Offline
Junior Poster in Training

Re: Computer slowing down

 
0
  #13
Jun 5th, 2007
the 47 file has now disappeared from the windows directory. I will run combofix again.
Reply With Quote Quick reply to this message  
Join Date: Apr 2005
Posts: 16,329
Reputation: jbennet is a splendid one to behold jbennet is a splendid one to behold jbennet is a splendid one to behold jbennet is a splendid one to behold jbennet is a splendid one to behold jbennet is a splendid one to behold 
Solved Threads: 555
Moderator
Featured Poster
jbennet's Avatar
jbennet jbennet is offline Offline
Moderator

Re: Computer slowing down

 
0
  #14
Jun 5th, 2007
Post a new HJT log
http://cdn.battlefieldheroes.com/signatures/229198472/1Player profile at BattlefieldHeroes.com, Free Shooter Game
Reply With Quote Quick reply to this message  
Join Date: Jun 2005
Posts: 79
Reputation: hetixo is an unknown quantity at this point 
Solved Threads: 0
hetixo hetixo is offline Offline
Junior Poster in Training

Re: Computer slowing down

 
0
  #15
Jun 5th, 2007
ok

have run combofix again and again it has not produced a log report. However, a grey error box came up several times reading;

16Bit MS-Dos Subsystem

AutoScan

The NTVDM CPU has encountered an illegal instruction CS:0839 IP:5790 OP:63 69 66 69 65. Choose Close to terminate the application.

I chose close and files appeared on the Autoscan screen which i selected and have tried to paste here but it won't work.

Will post a new NJT log
Reply With Quote Quick reply to this message  
Join Date: Jun 2005
Posts: 79
Reputation: hetixo is an unknown quantity at this point 
Solved Threads: 0
hetixo hetixo is offline Offline
Junior Poster in Training

Re: Computer slowing down

 
0
  #16
Jun 5th, 2007
new HJT log is as follows. I notice that one of the o2 files that i fixed before is back;

Logfile of HijackThis v1.99.1
Scan saved at 16:07, on 2007-06-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\New Folder\imabunny.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,272
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 202
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: Computer slowing down

 
0
  #17
Jun 5th, 2007
You know, AVG AS should detect and remove New.net, or Newdotnet. Check my last post on page 1 of this thread to ensure you have correct AVG settings.
I know nothing about that error msg.... some incompatibility with windows, but.... heck, i've trialled that combofix version no probs. NT has created a virtual DOS machine to handle some part of the pgm that is in DOS, but has encountered some sort of error. Dunno.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum


Views: 1925 | Replies: 16
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2010 DaniWeb® LLC