What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Closed TopicStart new topic
> [Closed] PC BOGGED DOWN AND INTERNET ISSUES, VIRUS?
Jdobs
post Feb 18 2009, 03:20 PM
Post #1


New Member
*

Group: New Member
Posts: 1
Joined: 18-February 09
Member No.: 84,262
Operating System: Windows Vista



Hello, THanks in advance for any and all help.
THE ISSUE,
suddenly my pc has begun running very slow when im using more than one application. For example, i will move the mouse and 3 sec. later the mouse actually responds and moves. The other and main issue is the Internet Explorer. It will be working fine and all of the sudden it will slow down and then all together stop(green bar stays about a quater of the way loading) I checked with my ISP and the connection to the modem is good. I eliminated the router from the chain and problem still exist. Power cycling the modem and pc temporarily fixes the program but once i open a couple apps, boom my pc freaks out. I went through all the recommended steps on ur site before posting this. I have 2gigs of ram i have minimal startup programs selected, have a firewall(zonealarm) and use antivirus protection and plenty of harddrive space. Does vista just suck or does my hijackthis log file show any signs of the problem? I will include my hijack this log, SUPERanitspyware log and a rooter.exe log. THANKS THANKS and THANKS again. JEFF




Hijack this

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:53:30 PM, on 2/18/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: *.line6.net
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 6907 bytes






SUPERantispyware LOG


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/17/2009 at 11:18 PM

Application Version : 4.25.1012

Core Rules Database Version : 3764
Trace Rules Database Version: 1725

Scan type : Complete Scan
Total Scan Time : 00:55:06

Memory items scanned : 646
Memory threats detected : 0
Registry items scanned : 7207
Registry threats detected : 2
File items scanned : 26022
File threats detected : 22

Adware.MyWebSearch/FunWebProducts
HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs

Adware.Tracking Cookie
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@mediaplex[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@linuxquestions[2].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@at.atwola[2].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@atdmt[2].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@msnbc.112.2o7[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@tribalfusion[2].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@specificmedia[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@advertising[2].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@doubleclick[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@revsci[2].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@tacoda[2].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@adserver.adtechus[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@chitika[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@dynamic.media.adrevolver[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@ge.112.2o7[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@insightexpressai[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@kontera[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@track.wachoviadealer[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@rotator.adjuggler[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@socialmedia[1].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@specificclick[2].txt
C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies\Low\test@xiti[1].txt




ROOTER Log


Microsoft® Windows Vista™ Home Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : AMD Athlon™ 64 X2 Dual Core Processor 3600+ )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : test ( Administrator )
BOOT : Normal boot

Antivirus : AVG Anti-Virus Free 8.0 (Activated)
Firewall : ZoneAlarm Firewall 8.0.065.000 (Activated)

C:\ (Local Disk) - NTFS - Total:222 Go (Free:80 Go)
D:\ (Local Disk) - NTFS - Total:9 Go (Free:6 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (Local Disk) - FAT32 - Total:149 Go (Free:9 Go)

Tue 02/17/2009|23:30

----------------------\\ Search..

----------------------\\ Cracks & Keygens..

C:\PROGRA~2\Lavasoft\Ad-Aware\Quarantine\ZoneAlarm Internet Security Suite 7 1 254 Keygen.exe.bcc2f54e13759599faaa68f1a4f9bd1.aawqff


1 - "C:\Rooter$\Rooter_1.txt" - Tue 02/17/2009|23:31

----------------------\\ Scan completed at 23:31



Go to the top of the page
 
+Quote Post

Posts in this topic


Closed TopicStart new topic

 


RSS Time is now: 22nd March 2010 - 06:52 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy