0

hi all,
i am new to this computer and virus stuff, my internet has become terribly slow
and the system is getting stuck in few movements my friend said u have a virus in ur net
so, please help me which anti virus to download for free r i can fix manually with help of u guys and my kaspersky is not showing any thing
as i am new what i dont have any idea what to post like process or something else in my computer so that u guys can recognise virus, pardon me as iam new

2
Contributors
7
Replies
8
Views
8 Years
Discussion Span
Last Post by jholland1964
0

Hello and welcome to daniweb,
Begin by doing these three steps;

Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.

Next:
Please Run the ESET Online Scanner and attach the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is Un-checked at this time (we may have it clean what it finds at a later time), and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.

Finally, download HiJackThis
Do a Full system scan and save the log.
Copy/Paste all three logs back here and we can take a look.
Judy

0

hi,
firstly i thank u for ur reply my system has become very slow i would be very thankful for ur help this is log file of hijack this

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:29 AM, on 10/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{12B07E68-38FC-47B4-9DF5-460883A68817}: NameServer = 30.30.246.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{12B07E68-38FC-47B4-9DF5-460883A68817}: NameServer = 30.30.246.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{12B07E68-38FC-47B4-9DF5-460883A68817}: NameServer = 30.30.246.1
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: wampapache - Apache Software Foundation - D:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - D:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe

--
End of file - 5301 bytes

this is log file for eset online scanner
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3519 (20081013)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=6ed16033a5c25d4887321f4ab459f01e
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-10-14 02:39:36
# local_time=2008-10-14 07:39:36 (-0800, Pacific Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=76596
# found=2
# scan_time=482
E:\bsplayer223.953_clip.exe Win32/Adware.WhenU.SaveNow application (deleted) 00000000000000000000000000000000
E:\bsplayer223.953_clip.exe ¬ĽNSIS ¬ĽAdVantageSetup.exe Win32/Adware.WhenU.SaveNow application (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object) 00000000000000000000000000000000

this is log file for malvare
Malwarebytes' Anti-Malware 1.28
Database version: 1267
Windows 5.1.2600 Service Pack 2

10/14/2008 7:18:57 AM
mbam-log-2008-10-14 (07-18-57).txt

Scan type: Quick Scan
Objects scanned: 40416
Time elapsed: 1 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

0

Looks as if ESET scanner removed some adware but other than that nothing was found.
You do have some unnecessary auto starting programs which can and really should be run just manually when needed. Don't know if this would be the cause of your slow down on the system.
All of those InCD listings are not necessry to run at start up and therefore run all the time in the background.
These three were all running when you did your HiJackThis scan;
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
You also had two instances of Internet Explorer and one Firefox open and running when the scan was done.
How long has this slow down been happening? Have you done a general clean up of the computer lately? Empty temp files and internet temp files lately? Have you done a defrag?
Is the computer slow all the time or just when it is online? If it is only when it is online then this could be the fault of your ISP and not the computer.
How are you connected to the internet?

0

i have a ccleaner installed in my computer so, all the temp files will be deleted and the computer has became slow after the internet connection i have installed wamp and text editors software like stuff this may be the reason? and my cousine always installs some wiered stuff like games, style xp and many others
the system is getting slow down all the time
thank u

1

i have a ccleaner installed in my computer so, all the temp files will be deleted and the computer has became slow after the internet connection i have installed wamp and text editors software like stuff this may be the reason? and my cousine always installs some wiered stuff like games, style xp and many others
the system is getting slow down all the time
thank u

If the slow down began with the install of all those items then I think you can probably narrow it down to that.
If games and other items have also been added then you can probably add those to the cause also.
How big is the hard drive? How much space is remaining"
How much RAM do you have installed on the machine.
It may very well be just too much in too small a space but give me that info ok?

Votes + Comments
u helped me a lot thank u
0

thank u holland,
i have 160gb hard disk, 1 gb ram, recently i have formated my computer so,
i hardly used around 70gb but i partioned c drive with 30 gb space and my software like text editors,anti virus etc are there in c drive i use window xp sp2 os .does i have to remove all those program files and place it in another drive. and i left 6gb space in my hard disk which is free now and i want to install linux as another operating system
its really frustating when i sit near my computer its is very slow

0

Think you have to look at the numbers involved here. You said you have a 160GB hard drive and you recently reformatted, if I read it right you say

i hardly used around 70gb

which says really, unless I am wrong, that more than half the drive was full before you reformatted. You created a 30GB partition and everything you had installed is there. I am not certain why you put everything in that partition. If you have 30GB in that partition that means you have another partition with about 130GB that is not being used. But then you say you

i left 6gb space in my hard disk which is free now

...do you mean you actually have three partitions? One with 30GB, one with 6GB and then another with 124GB? Or do you mean that you have two partitions, one with 30GB and you are saving 6GB of that to install Linux and then you have the second partition with 130GB empty? Sorry if I sound confused, but I am.
Was the hard drive previously partitioned or was it just a 160GB unpartitioned drive?
If it was previously partitioned did you reformat the entire hard drive or just one partition?
I have to be totally honest I know virtually nothing about drive partitioning but it sounds to me like you partitioned the drive incorrectly or are using this partition incorrectly. From what you have said it sounds like the rest of this hard drive isn't being used at all. That you are doing everything from this one partition meaning the partition is very nearly full so naturally the computer would be very slow.
Maybe I am totally wrong here but it sounds to me like you created a 30GB partition and are working 100% from this partition, this would be like somebody with a 30GB hard drive ONLY on the computer and the drive is pretty much full. That computer would be slow as molasses.

Here are some articles explaining some of drive partitioning, maybe it will help some
What Is Disk Partitioning?

Can I make my C: partition bigger by taking space from D:?

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.