Can someone look at this Combofix log?  Machine still very slow

Posted on 2009-06-29
Last Modified: 2013-11-22
I have a Windows Vista laptop I'm trying to help with.  It's running VERY slow lately.  Granted the laptop only has 768 MB of ram and it's running Vista, but it still was quicker than this up until recently.  The user never had an issue with basic tasks, now lately opening My Computer can cause it to hang at times.  

I've run Combofix and it removed a lot, but it also mentioned some files it "coudl not find.'  Would someone mind looking over the log and see if a script is needed?

Question by:Jsmply
LVL 27

Accepted Solution

David-Howard earned 200 total points
ID: 24741087
First off I would remove the Mywebsearch toolbar.
Directions on the removal as well as using HiJackThis can be found here.
On next boot, right click any open area on your task bar and select Task Manager. Click the Performance tab. If your systems performance (CPU usage) is high, then click the Processes tab. From there you can get an idea of which program is using the most memory.
You  might also try running Malwarebytes.
It's free and you can get it free from
There is also a trusted and free utility that shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys. This is handy if you are receiving rundll errors or pop ups when you log on.
AutoRuns for Windows
If after running any of the suites above you find that your internet connection fails (is broken) please perform the following steps.
Restart your computer and test your internet connection.
If it does not work, then click Start ->Settings and Control Panel.
Select Network connections. Locate your connection and right click on it.
In the menu click the Repair option. When the repair proccess has finished, your connection should be working again. Reboot to test.
If you have any questions concerning a file on your system that may be a threat you can use this site for testing. 

Author Comment

ID: 24741366
Okay, I finished Malwarebytes, it found a lot of stuff, most of it being the MyWebsearch toolbar so I guess Combofix didn't get it all.  Here is the MBAM log after it ran.

Does this look like it got it all?  I also see things such as Trojan-Vundo, etc.  Do I need a custom script for Combofix or is MBAM able to remove this?
LVL 15

Assisted Solution

xmachine earned 150 total points
ID: 24743611
1) Download & run CCleaner to clean your system (including registry) from junk files/registry keys


3) Download & run GMER (rootkit scanner) from (

Start GMER, select all options on the right side, after scanning is finished, click on save. Attach the log file here

4) Download reglooks.exe to your Desktop. Doubleclick on it to run it and when it has finished scanning, a log named result.txt will open in Notepad. Copy the log and post it in this thread.

5) Download & run injecteddll


select all items, then click on the save button to export a log file, attach it here as well
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Assisted Solution

GIMLI earned 150 total points
ID: 24745304
did you try to disk cleanup & disk defragmenter?

or you can follow the instruction on this link
LVL 27

Expert Comment

ID: 24745647
Combofix should have removed Vundo. However, in some instances you need to rename Combofix BEFORE you download it to your system. If not, and you are infected Combofix may not run properly. You may also need to run your antimalware applications in Safe Mode (If all else fails).
To enter Safe Mode, reboot and select F8 at startup, log on as usual and then run your scans.
Symantec states to disable System Restore for the Vundo infection. This also allows proper detection and removal.
Directions can be found here:
Symantec also offers a free Vundo removal tool.


Author Closing Comment

ID: 31598137

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Virus softwares 11 100
vMware vShield Endpoint 6.0 4 110
Is there a removal tool and a decryption tool for Osiris ransomware 6 267
Total AV worth it? 4 342
Most PC repair technicians (if not all) always start their cleanup process by emptying the temp folders before running any removal tools. It makes sense because temp folders are common places for malware installers to lurk and removing all the junk …
Sub-Titled: “My Way” (with apologies to Francis Albert Sinatra) Let me start by stating emphatically that I am one of those Experts who prefer doing things “My Way”. It’s kind of a no-brainer. “The following procedure works for me, so here is …
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question