Author Topic: Computer running slow  (Read 1824 times)

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Computer running slow
« Reply #20 on: August 11, 2008, 06:18:42 PM »
Can you do the following for me please
go to this link

http://www.virustotal.com/flash/index_en.html
Copy and paste the following bold line to the space next to  'Upload a File'

C:\:ntimaxp.gif

Then use the SEND FILE button
Let it finish scanning
Could you post back the results this scan back here please
Or better yet, just link to the results page

Did you right click the Avast icon by the clock and START On Access Protections?
« Last Edit: August 17, 2008, 12:10:39 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline joy

  • Jr. Member
  • **
  • Posts: 93
  • Karma: +0/-0
    • View Profile
    • http://
Computer running slow
« Reply #21 on: August 28, 2008, 11:08:12 AM »
Sorry for the delay,but I was on vacation....

Link to the scan logfile

http://www.virustotal.com/it/analisis/2c825ac2d8baec3e8e21d44058dd30ec

But, for any case, this is the result:

File _ntimaxp.gif ricevuto il 2008.08.28 18:24:35 (CET)
Stato corrente: Carico ... in coda attesa scansione finito NON TROVATO INTERROTTO


Risultato: 27/33 (81.82%)
Carico informazioni server...
Il tuo file è in coda in posizione: 1.
Tempo stimato inizio tra 37 e 53 secondi.
Non chiudere la finestra fino al termine della scansione.
Lo scanner che stava processando il tuo file si è fermato in questo momento, stiamo aspettando alcuni secondi per tentare di recuperare i tuoi risultati.
Se stai aspettando da più di cinque minuti devi rimandare il tuo file.
VirusTotal sta controllando il tuo file in questo momento,
i risultati saranno visualizzati mentre vengono generati.
 Formattato Stampa risultati  
Il tuo file è scaduto o non esiste.
Il servizio è fermo in questo momento, il tuo file sta aspettando di essere controllato (posizione: ) da un tempo indefinito.

Puoi aspettare la risposta sul web (ricarico automatico) o digitare il tuo indirizzo email nel riquadro qui sotto e premere "richiesta" così il sistema ti invierà una notifica al termine della scansione.
 Email:  
 

Antivirus Versione Ultimo aggiornamento Risultato
AhnLab-V3 2008.8.29.0 2008.08.28 Win-Trojan/Rkdice.124324
AntiVir 7.8.1.23 2008.08.28 TR/RKDice.A
Authentium 5.1.0.4 2008.08.28 W32/RKDice.A
Avast 4.8.1195.0 2008.08.28 Win32:RKDice
AVG 8.0.0.161 2008.08.28 Generic.YME
BitDefender 7.2 2008.08.28 Trojan.RKDice.A
CAT-QuickHeal 9.50 2008.08.26 Trojan.RKDice.a
ClamAV 0.93.1 2008.08.28 Trojan.RkDice-1
DrWeb 4.44.0.09170 2008.08.28 Win32.HLLW.SpyBot
eSafe 7.0.17.0 2008.08.27 -
eTrust-Vet 31.6.6054 2008.08.28 Win32/Stresid.AT
Ewido 4.0 2008.08.28 -
F-Prot 4.4.4.56 2008.08.28 W32/RKDice.A
F-Secure 7.60.13501.0 2008.08.28 Trojan.Win32.RKDice.a
Fortinet 3.14.0.0 2008.08.28 W32/RKDice.A!tr
GData 19 2008.08.28 Trojan.Win32.RKDice.a
Ikarus T3.1.1.34.0 2008.08.28 Trojan.Win32.RKDice.a
K7AntiVirus 7.10.428 2008.08.25 Trojan.Win32.RKDice.a
Kaspersky 7.0.0.125 2008.08.28 Trojan.Win32.RKDice.a
McAfee 5372 2008.08.28 -
Microsoft 1.3807 2008.08.25 Backdoor:Win32/Rkdice.A
NOD32v2 3396 2008.08.28 Win32/RKDice.A
Panda 9.0.0.4 2008.08.27 Trj/RKDice.A
PCTools 4.4.2.0 2008.08.28 Trojan.RKDice.A
Prevx1 V2 2008.08.28 Rootkit
Rising 20.59.31.00 2008.08.28 Trojan.RKDice.b
Sophos 4.33.0 2008.08.28 Troj/RKDice-Fam
Sunbelt 3.1.1582.1 2008.08.26 -
TheHacker 6.3.0.6.064 2008.08.27 Trojan/RKDice.a
TrendMicro 8.700.0.1004 2008.08.28 -
ViRobot 2008.8.28.1353 2008.08.28 -
VirusBuster 4.5.11.0 2008.08.28 Trojan.RKDice.A
Webwasher-Gateway 6.6.2 2008.08.28 Trojan.RKDice.A
Informazioni addizionali
File size: 124531 bytes
MD5...: de114af81889fb4ca2b97192ab068554
SHA1..: 3c431d647f7ed7e48de9e63d8cd035a1d4f7ebe1
SHA256: 4e2b3b6b777afdcd1b4ea7c9104678b099546458024daae12c6187b6213247b3
SHA512: 7db980b16e7be01ea2e95a177cd07e3145a0c4a3a0049fb3672664920abb8e11
d9dcbcdf16f05f1d54bbfe3ae17fb3afa77d596bd6e9ef45e02606bee414184f
PEiD..: -
TrID..: File type identification
Clipper DOS Executable (33.3%)
Generic Win/DOS Executable (33.0%)
DOS Executable Generic (33.0%)
VXD Driver (0.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x3ee83268
timedatestamp.....: 0x0 (Thu Jan 01 00:00:00 1970)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x154a3 0x15600 6.31 dcd0a63f7c3da347808fbdf171ee9433
.data 0x17000 0x3d12 0x3800 6.29 86d348928156335af3689f840ac766b4
.reloc 0x1b000 0x3048 0x3200 6.55 0196fdaa8682110c76516bf5c9b5e2e9

( 1 imports )
> KERNEL32.dll: RtlUnwind, GetModuleHandleA

( 3 exports )
upzpcnyjlhjtz, zqdedfmggplphcheiww, zttfydztmnqvwrgtulcjy
 
Prevx info: http://info.prevx.com/aboutprogramtext.asp...C0584003BD6CD4A


About Avast!...Yes, I did what you told me about starting on Access Protections

Thank you and Bye
Jo

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Computer running slow
« Reply #22 on: August 30, 2008, 11:37:47 AM »
Can you do the following please
Download [color=\"#FF0000\"]The Avenger.zip[/color] by Swandog46 to your Desktop.

    * Click on Avenger.zip to open the file
    * Extract avenger.exe to your desktop
LOG OFF any other users on the computer except for yourself

Copy ALL the text contained in [color=\"#0000FF\"]blue[/color] below to your Clipboard by highlighting it and pressing the (Ctrl+C) on your keyboard,
Make sure you include "Files to delete:"
=============================================================
[color=\"#0000FF\"]
Files to delete:
C:\:ntimaxp.gif
[/color]

==========================================================================

Now, start The Avenger program by clicking on its icon on your desktop
OK the prompt

    * Under "Input Script Here">>Paste the copied blue text from above
    * Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    * Press Execute >>Answer Yes to the Prompts
    * Allow the computer to Reboot
   
Avenger should now Reboot your computer

Back in Windows
Avenger should open a Notepad file with information
Please copy>Paste back here the whole contents
The same log can also be found at this location
C:\Avenger.txt

Can you also post a fresh hijackthis log and let me know how things are running
« Last Edit: August 30, 2008, 11:43:57 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here