Computer running extremely slow-possible virus?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jackie2006, Feb 15, 2006.

  1. jackie2006

    jackie2006 Private E-2

    Hi-I've been having a problem with my computer running extremely slow for a few days now. (I'm using Windows 2000) It seems to freeze when I attempt to open any programs or files, or even log off or shut down, and then will respond about 10 minutes later. I have Symantec Anti-virus version 10 installed, and ran a scan but nothing came up. I also have Microsoft Anti-spyware installed, but it did not find anything either.

    I followed the steps listed in the Run and Readme first post-with the exception of Microsoft Windows Defender Beta 2. I was able to download the program, but not able to install. I even tried downloading from the Microsoft website, but was unable to install.

    Anyway, it appears that the Panda online scan and BitDefender scans found viruses, but I'm unsure of what to do next. Attached are the log files. I would really appreciate some help with this problem, as I'm pretty much unable to use the computer as it is. Thank you!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to MGs!

    You need to follow the directions exactly as written in step 6 to attach your Bitdefender log. All you posted was a log summary that shows a virus but does not indicate where it is or if it was fixed.

    Goto Add/Remove programs and uninstall this junk: SpySpotter
    It has long been on the rogue list at: http://www.spywarewarrior.com/rogue_anti-spyware.htm

    You can also delete the below files:
    C:\WINNT\SYSTEM32\INNERADINSTALL.LOG
    C:\WINNT\Downloaded Program Files\HDPlugin1019.inf <--- you can only see this from the command prompt.
    C:\WINNT\mwsvm.bin

    Also have HijackThis fix the below lines:

    O16 - DPF: {25D9AA40-ED39-11D2-A038-009027078284} (UrlDownloader Class) - https://www2.advisorservices.com/AdvisorWeb/File/urldownloader.cab
    O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://hgtv1.view22.com/app/view22rte.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://adventsoftware.webex.com/client/v_mywebex-t20/event/ieatgpc.cab

    See if the above helps, but your problem with a slow PC may not be malware.
     
    Last edited: Feb 15, 2006
  3. jackie2006

    jackie2006 Private E-2

    Ok, I re-ran Bitdefender and got the attached log. I did follow the instructions, but got the same summary log. This time, it does not indicate that any virus was found. I believe I received an email with that virus in an attachment, however Symantec caught the virus before I could open the email and quarantined it. Is it possible that the virus was detected in the quarantine folder?

    I was able to remove Spyspotter, along with the following files-
    C:\WINNT\SYSTEM32\INNERADINSTALL.LOG
    C:\WINNT\mwsvm.bin
    but I was unsure of how to remove this file: "C:\WINNT\Downloaded Program Files\HDPlugin1019.inf" You said it can only be seen from the command prompt, but I wasn't sure how to do that.

    I also removed the objects with Hijack this that you recommended, and attached a new Hijack this log. The computer is still running very slowly when I boot in normal mode. Is there anything else that could be causing this?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you did not follow the directions. If you did, your attachment would be an html file save as a .txt file. But I don't need it now since no viruses are found anymore.

    Additional steps to delete HDPlugin1019.inf:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a command prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINNT\Downloaded Program Files\
    attrib -r -h -s HDPlugin1019.inf
    del HDPlugin1019.inf
    exit


    Please only attach HJT logs from normal boot mode unless otherwise specified. Safe mode logs are not always of that much use. Before attaching a new HJT log, run the below and attach the request log from Ewido. Then attach you HJT log from normal boot mode.

    Running Ewido Anti-Malware
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds