Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

slow computer and throwing the graphics drivers


  • This topic is locked This topic is locked
2 replies to this topic

#1 MakaronPL

MakaronPL

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:04:28 PM

Posted 04 March 2010 - 05:06 PM

slow computer and throwing the graphics drivers
i must often install graphics drivers and sometimes displays a bluescreen

Log
ComboFix 10-03-04.02 - DOM 2010-03-04 22:43:47.12.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.1023.581 [GMT 1:00]
Uruchomiony z: c:\documents and settings\DOM\Pulpit\ComboFix.exe

.

((((((((((((((((((((((((( Pliki utworzone od 2010-02-04 do 2010-03-04 )))))))))))))))))))))))))))))))
.

2010-02-23 11:03 . 2010-02-23 11:25 -------- d-----w- c:\program files\SuperTux
2010-02-23 10:07 . 2010-02-23 10:07 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-23 10:06 . 2010-02-23 10:06 -------- d-----w- c:\documents and settings\DOM\Ustawienia lokalne\Dane aplikacji\Adobe
2010-02-14 13:13 . 2010-02-14 13:13 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\Media Player Classic
2010-02-13 15:35 . 2010-02-13 16:00 -------- d-----w- c:\program files\Unlocker
2010-02-13 13:13 . 2002-01-21 04:00 545 ----a-w- c:\windows\UC.PIF
2010-02-13 13:13 . 2002-01-21 04:00 545 ----a-w- c:\windows\RAR.PIF
2010-02-13 13:13 . 2002-01-21 04:00 545 ----a-w- c:\windows\PKZIP.PIF
2010-02-13 13:13 . 2002-01-21 04:00 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-02-13 13:13 . 2002-01-21 04:00 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-02-13 13:13 . 2002-01-21 04:00 545 ----a-w- c:\windows\LHA.PIF
2010-02-13 13:13 . 2002-01-21 04:00 545 ----a-w- c:\windows\ARJ.PIF
2010-02-13 13:13 . 2010-02-13 15:07 -------- d-----w- C:\wincmd
2010-02-13 12:50 . 2006-10-22 11:22 208896 ----a-w- c:\windows\system32\nvudisp.exe
2010-02-13 12:50 . 2006-10-22 14:06 208896 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-02-12 22:35 . 2007-02-06 10:07 521128 ----a-w- C:\DPINST.exe
2010-02-12 22:35 . 2008-05-02 09:11 235131 ----a-w- C:\pmtimer.exe
2010-02-12 22:35 . 2008-05-02 09:11 282725 ----a-w- C:\DSPdsblr.exe
2010-02-12 22:35 . 2008-04-08 10:46 20992 ----a-w- C:\makePNF.exe
2010-02-12 22:35 . 2008-04-08 10:46 137728 ----a-w- C:\mute.exe
2010-02-12 22:35 . 2008-05-02 09:11 364721 ----a-w- C:\DPsFnshr.exe
2010-02-12 22:35 . 2008-04-08 10:46 55808 ----a-w- C:\devcon.exe
2010-02-12 20:09 . 2004-01-04 22:51 3180171 ----a-w- c:\windows\system\nv4_disp.dll
2010-02-12 19:09 . 2010-02-13 14:04 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\NVIDIA
2010-02-12 19:00 . 2010-02-12 19:00 -------- d-----w- c:\program files\S3
2010-02-12 18:59 . 2003-02-16 15:46 306688 ----a-w- c:\windows\IsUninst.exe
2010-02-12 18:59 . 2010-02-12 18:59 -------- d-----w- c:\documents and settings\DOM\WINDOWS
2010-02-12 18:50 . 2010-02-12 18:50 -------- d-----w- C:\NVIDIA

.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-04 20:08 . 2009-09-12 17:16 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\Winamp
2010-02-23 16:25 . 2009-09-14 14:33 -------- d-----w- c:\documents and settings\DOM\Dane aplikacji\Nowe Gadu-Gadu
2010-02-12 18:51 . 2010-01-08 15:30 -------- d-----w- c:\program files\Common Files\InstallShield
2010-02-08 09:06 . 2009-09-12 18:16 -------- d-----w- c:\program files\Gadu-Gadu
.

------- Sigcheck -------

[-] 2008-07-25 . 1F39C7BDBA4C5F3F01C4EABF7EDBF4B3 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

[-] 2008-07-25 . 8CD81261DA6BD4BCFBD857A25220A1FB . 689152 . . [5.82] . . c:\windows\system32\comctl32.dll

[-] 2008-07-25 . 5FB59F2506787A7E036B7C2EFF1CCE24 . 2190208 . . [5.1.2600.5512] . . c:\windows\system32\ntoskrnl.exe

[-] 2008-07-25 . 5F1CCDF37F28A88D0473B0C9EA1E0D58 . 487424 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

[-] 2008-07-25 . B49A80A502FD86B2F05BC7BBD723DDAB . 1528832 . . [6.00.2900.5512] . . c:\windows\explorer.exe


[-] 2008-07-25 . AD58E980CBCC1B8980D16D91408EB57A . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll

[-] 2008-07-25 . 0277E1A3E8B337555A45943808451981 . 40448 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe


[-] 2008-07-24 20:56 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll

c:\windows\System32\wscntfy.exe ... - brak elementu !!
c:\windows\System32\regsvc.dll ... - brak elementu !!
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domy›lne, prawid‚owe wpisy nie s… pokazane
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"Nowe Gadu-Gadu"="c:\program files\Nowe Gadu-Gadu\gg.exe" [2009-08-31 11391592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-04-23 124928]

c:\documents and settings\All Users\Menu Start\Programy\Autostart\
GlobeTrotter Connect.lnk - c:\program files\ERA\GlobeTrotter Connect\GlobeTrotter Connect.exe [2008-4-21 798720]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-09-15 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-09-15 20560]
R2 GtDetectSc;GtDetectSc;c:\program files\ERA\GlobeTrotter Connect\GtDetectSc.exe [2007-12-18 196704]
R3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\drivers\Gt51Ip.sys [2008-02-18 106624]
R3 GT72UBUS;GT 72 U BUS;c:\windows\system32\drivers\gt72ubus.sys [2008-02-08 59648]
.
Zawarto›‡ folderu 'Zaplanowane zadania'

2009-12-23 c:\windows\Tasks\FRU Task 2003-04-10 00:56ewlett-Packard2003-04-10 00:56p psc 1200 series272A572217594EBCF1CEE215E352B92AD073FDE4253730150.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 15:56]
.
.
------- Skan uzupe‚niaj…cy -------
.
uStart Page = hxxp://www.google.com/
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\DOM\Dane aplikacji\Mozilla\Firefox\Profiles\m28irxwi.default\
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - plugin: c:\documents and settings\DOM\Dane aplikacji\Nowe Gadu-Gadu\_userdata\npgg.1.dll
FF - plugin: c:\documents and settings\DOM\Dane aplikacji\Nowe Gadu-Gadu\_userdata\nppl3260.dll
FF - plugin: c:\documents and settings\DOM\Dane aplikacji\Nowe Gadu-Gadu\_userdata\nprpjplug.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-04 22:50
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesw ...

skanowanie ukrytych wpisw autostartu ...

skanowanie ukrytych plikw ...

skanowanie pomy›lnie uko„czone
ukryte pliki: 0

**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_USERS\S-1-5-21-1614895754-1060284298-515967899-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{47F11C9D-2E8B-8261-2613-AF834A8A5216}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abnjdmcoadofdeeemjacmnefcfemofblgb"=hex:69,61,6f,65,66,6b,64,67,64,6e,6e,61,
70,6e,6a,68,69,6f,00,00
"maakimmfmhicmcknofklhnjfdj"=hex:6f,61,6e,64,6f,62,62,67,62,6f,6f,69,70,6b,68,
62,69,68,6a,63,6c,70,63,67,65,61,66,6a,70,61,00,00
.
--------------------- Pliki DLL ‚adowane pod uruchomionymi procesami ---------------------

- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll

- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\scecli.dll
c:\windows\system32\SETUPAPI.dll

- - - - - - - > 'explorer.exe'(3688)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\LINKINFO.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\MSVCP60.dll
.
Czas uko„czenia: 2010-03-04 22:53:39
ComboFix-quarantined-files.txt 2010-03-04 21:53
ComboFix2.txt 2010-02-13 15:04
ComboFix3.txt 2010-01-15 21:27
ComboFix4.txt 2009-12-30 15:01
ComboFix5.txt 2010-03-04 21:42

Przed: 117186560 bajtw wolnych
Po: 142548992 bajtw wolnych

- - End Of File - - 486F5D6610E64A13038F68C62909D4D4



sorry for my English

Attached Files


Edited by Pandy, 04 March 2010 - 09:46 PM.
mod edit~ moved codebox tags


BC AdBot (Login to Remove)

 


#2 Blind Faith

Blind Faith

  • Malware Response Team
  • 4,101 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:06:28 PM

Posted 07 March 2010 - 03:37 PM

Hello and welcome to Bleeping Computer! welcome.gif

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

We also need a new log from the GMER anti-rootkit scanner. Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice

Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log





Elle
Can you hear it?It's all around!

Tomar ki man acch?
Yadi thak, tahal
Ki kshama kart paro
?



If I haven't replied in 48 hours, please feel free to send me a PM.



Posted Image

#3 thcbytes

thcbytes

  • Malware Response Team
  • 14,790 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:28 AM

Posted 12 March 2010 - 08:06 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Proud member - Unified Network of Instructors and Trained Eliminators
Posted Image

I do not accept personal donations for assistance provided. I would ask that you instead consider donating the greatest gift - Organ Donation. Your organs are of no use to you when your gone. You will save a life that would otherwise be lost!

http://donatelife.net/register-now/




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users