This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer extremely slow

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Everything seemed fine until last week when my AVG antivirus found and cleaned an infection. I failed to note what it was. Since then, the system has been dog-slow. I've run an infinite number of scans on it and they either come up clean or find and remove something. Sometimes it will seem like it's back to normal for a few hours, then we're right back to the snail pace problem again. HJT log is attached. Other than slowness, I see no signs of infection. Thanks in advance for your help!
One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

However, if you do not have the resources to reinstall your computer and would like me to attempt to clean it, I will be happy to do so.
Should you have any questions, please feel free to ask.

Please let us know what you have decided to do in your next post.
I would like to clean it. I've been working quite a bit on it since uploading the first HJT log, will run another now and upload it as well. Can you tell me what Backdoor Trojan(s) was/were identified?

Thanks for your help.

New HJT log below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:02:56 PM, on 4/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\sol.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us5.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/โ€ฆ/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/โ€ฆ//www.yahoo.com
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: Javaโ„ข Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - S-1-5-18 Startup: AutoPlay.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: AutoPlay.exe (User 'Default user')
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: AutorunsDisabled
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Web-Based Email Tools - http://email.secureserver.net/Download.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecalโ€ฆivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedCโ€ฆbin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200305โ€ฆmeInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedCโ€ฆn/bin/cabsa.cab
O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O24 - Desktop Component AutorunsDisabled: (no name) - (no file)

โ€“
End of file - 7085 bytes
Hi again,

There were signs of RBOT there. Some seem to have disappeared compared to the log with the one in your topic starter.

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop. Post them back to your topic.
Here they are. Thanks! DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 9:12:26.23 on Sat 04/25/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13 ============== Pseudo HJT Report =============== uStart Page = hxxp://att.yahoo.com uDefault_Search_URL = hxxp://srch-us5.hpwis.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = 127.0.0.1;localhost uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com BHO: AutorunsDisabled - No File BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll BHO: Javaโ„ข Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll EB: hp toolkit: {8f4902b6-6c04-4ade-8052-aa58578a21bd} - c:\windows\system32\Shdocvw.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [nwiz] nwiz.exe /install mRun: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: mozilla.com\www Trusted Zone: yahoo.com DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5595/mcfscan.cab Handler: AutorunsDisabled\belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\0ftqyrqh.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2009-04-25 08:48 28,544 aโ€”โ€”- c:\windows\system32\drivers\pavboot.sys 2009-04-25 08:48 โ€“dโ€”โ€“ c:\program files\Panda Security 2009-04-25 07:42 โ€“dโ€”โ€“ c:\program files\Support Tools 2009-04-25 06:33 โ€“dโ€”โ€“ c:\windows\McAfee.com 2009-04-23 21:18 a-dshrโ€“ C:\cmdcons 2009-04-23 21:03 161,792 aโ€”โ€”- c:\windows\SWREG.exe 2009-04-23 21:03 98,816 aโ€”โ€”- c:\windows\sed.exe 2009-04-22 15:35 โ€“dโ€”โ€“ c:\program files\Trend Micro 2009-04-21 23:41 73,728 aโ€”โ€”- c:\windows\system32\javacpl.cpl 2009-04-21 20:00 โ€“dโ€”โ€“ c:\docume~1\owner\applic~1\Malwarebytes 2009-04-21 20:00 15,504 aโ€”โ€”- c:\windows\system32\drivers\mbam.sys 2009-04-21 20:00 38,496 aโ€”โ€”- c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-21 19:59 โ€“dโ€”โ€“ c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-04-21 19:59 โ€“dโ€”โ€“ c:\program files\Malwarebytes' Anti-Malware 2009-04-19 11:03 1,089,593 -cโ€”โ€” c:\windows\system32\dllcache\ntprint.cat 2009-04-16 22:15 โ€“dโ€”โ€“ c:\docume~1\owner\applic~1\Windows Search 2009-04-16 20:54 โ€“dโ€”โ€“ c:\windows\system32\XPSViewer 2009-04-16 20:51 89,088 -cโ€”โ€” c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-04-16 20:51 117,760 โ€”โ€”โ€“ c:\windows\system32\prntvpt.dll 2009-04-16 20:50 597,504 -cโ€”โ€” c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-04-16 20:50 575,488 -cโ€”โ€” c:\windows\system32\dllcache\xpsshhdr.dll 2009-04-16 20:50 575,488 โ€”โ€”โ€“ c:\windows\system32\xpsshhdr.dll 2009-04-16 20:50 1,676,288 -cโ€”โ€” c:\windows\system32\dllcache\xpssvcs.dll 2009-04-16 20:50 1,676,288 โ€”โ€”โ€“ c:\windows\system32\xpssvcs.dll 2009-04-16 20:50 โ€“dโ€”โ€“ C:\19be9c59a5f7e72e8d42 2009-04-16 20:48 โ€“dโ€”โ€“ c:\windows\SxsCaPendDel 2009-04-16 20:16 โ€“dโ€”โ€“ c:\docume~1\owner\applic~1\Windows Desktop Search 2009-04-16 20:13 โ€“dโ€”โ€“ c:\program files\Windows Desktop Search 2009-04-16 20:13 โ€“dโ€”โ€“ c:\windows\system32\GroupPolicy 2009-04-16 20:11 98,304 -cโ€”โ€” c:\windows\system32\dllcache\nlhtml.dll 2009-04-16 20:11 29,696 -cโ€”โ€” c:\windows\system32\dllcache\mimefilt.dll 2009-04-16 20:11 192,000 -cโ€”โ€” c:\windows\system32\dllcache\offfilt.dll 2009-04-16 20:02 284,160 -cโ€”โ€” c:\windows\system32\dllcache\pdh.dll 2009-04-16 20:02 401,408 -cโ€”โ€” c:\windows\system32\dllcache\rpcss.dll 2009-04-16 20:02 110,592 -cโ€”โ€” c:\windows\system32\dllcache\services.exe 2009-04-16 20:02 473,600 -cโ€”โ€” c:\windows\system32\dllcache\fastprox.dll 2009-04-16 20:02 227,840 -cโ€”โ€” c:\windows\system32\dllcache\wmiprvse.exe 2009-04-16 20:02 453,120 -cโ€”โ€” c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-16 20:02 729,088 -cโ€”โ€” c:\windows\system32\dllcache\lsasrv.dll 2009-04-16 20:02 617,472 -cโ€”โ€” c:\windows\system32\dllcache\advapi32.dll 2009-04-16 20:02 714,752 -cโ€”โ€” c:\windows\system32\dllcache\ntdll.dll 2009-04-16 20:00 2,560 โ€”โ€”โ€“ c:\windows\system32\xpsp4res.dll 2009-04-16 20:00 1,203,922 -cโ€”โ€” c:\windows\system32\dllcache\sysmain.sdb 2009-04-16 20:00 215,552 -cโ€”โ€” c:\windows\system32\dllcache\wordpad.exe 2009-04-16 18:39 52,224 -cโ€”โ€” c:\windows\system32\dllcache\msfeedsbs.dll 2009-04-16 18:39 459,264 -cโ€”โ€” c:\windows\system32\dllcache\msfeeds.dll 2009-04-16 18:39 991,232 -cโ€”โ€” c:\windows\system32\dllcache\ieframe.dll.mui 2009-04-16 18:39 268,288 -cโ€”โ€” c:\windows\system32\dllcache\iertutil.dll 2009-04-16 18:39 13,824 -cโ€”โ€” c:\windows\system32\dllcache\ieudinit.exe 2009-04-16 18:39 6,066,176 -cโ€”โ€” c:\windows\system32\dllcache\ieframe.dll 2009-04-16 18:39 2,455,488 -cโ€”โ€” c:\windows\system32\dllcache\ieapfltr.dat 2009-04-16 18:39 383,488 -cโ€”โ€” c:\windows\system32\dllcache\ieapfltr.dll 2009-04-16 18:39 63,488 -cโ€”โ€” c:\windows\system32\dllcache\icardie.dll 2009-04-16 16:05 โ€“dโ€”โ€“ c:\windows\system32\scripting 2009-04-16 16:04 โ€“dโ€”โ€“ c:\windows\l2schemas 2009-04-16 16:04 โ€“dโ€”โ€“ c:\windows\system32\en 2009-04-16 15:52 โ€“dโ€”โ€“ c:\windows\network diagnostic 2009-04-16 12:13 โ€“d-hโ€” C:\$AVG8.VAULT$ 2009-04-16 11:57 10,520 aโ€”โ€”- c:\windows\system32\avgrsstx.dll 2009-04-16 11:57 108,552 aโ€”โ€”- c:\windows\system32\drivers\avgtdix.sys 2009-04-16 11:57 325,640 aโ€”โ€”- c:\windows\system32\drivers\avgldx86.sys 2009-04-16 11:56 โ€“dโ€”โ€“ c:\windows\system32\drivers\Avg 2009-04-16 11:56 โ€“dโ€”โ€“ c:\program files\AVG 2009-04-16 11:56 โ€“dโ€”โ€“ c:\docume~1\alluse~1\applic~1\avg8 2009-04-15 08:45 102,664 aโ€”โ€”- c:\windows\system32\drivers\tmcomm.sys 2009-04-15 02:06 410,984 aโ€”โ€”- c:\windows\system32\deploytk.dll 2009-04-15 00:35 14,592 aโ€”โ€”- c:\windows\system32\drivers\kbdhid.sys ==================== Find3M ==================== 2009-04-16 16:14 80,975 aโ€”โ€”- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-04-16 16:11 49,152 aโ€”โ€”- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\bin\PCHI18N.dll 2009-04-16 16:10 155,907 aโ€”โ€”- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\bin\PCHButton.exe 2009-04-16 16:10 127,235 aโ€”โ€”- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\bin\ContentUpdater.exe 2009-04-16 16:10 122,880 aโ€”โ€”- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\bin\SearchCtrl.dll 2009-04-16 16:10 420,432 aโ€”โ€”- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\bin\pchplugin.zip 2009-04-16 16:10 77,824 aโ€”โ€”- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\bin\WinVerifyTrust.dll 2009-04-16 16:10 106,496 aโ€”โ€”- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\bin\PluginCtrl.dll 2009-04-16 16:10 731,136 aโ€”โ€”- c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\bin\motdeusr.zip 2009-04-15 00:54 40,560 aโ€”โ€”- c:\docume~1\owner\applic~1\wklnhst.dat 2009-03-25 06:29 130,432 aโ€”โ€”- c:\windows\system32\drivers\Rtnicxp.sys 2009-03-06 07:22 284,160 aโ€”โ€”- c:\windows\system32\pdh.dll 2009-03-03 12:18 73,728 aโ€”โ€”- c:\windows\system32\RtNicProp32.dll 2009-03-02 17:18 826,368 aโ€”โ€”- c:\windows\system32\wininet.dll 2009-02-20 11:09 78,336 โ€”โ€”โ€“ c:\windows\system32\ieencode.dll 2009-02-09 05:10 729,088 aโ€”โ€”- c:\windows\system32\lsasrv.dll 2009-02-09 05:10 714,752 aโ€”โ€”- c:\windows\system32\ntdll.dll 2009-02-09 05:10 617,472 aโ€”โ€”- c:\windows\system32\advapi32.dll 2009-02-09 05:10 401,408 aโ€”โ€”- c:\windows\system32\rpcss.dll 2009-02-09 04:13 1,846,784 aโ€”โ€”- c:\windows\system32\win32k.sys 2009-02-07 19:02 2,066,048 aโ€”โ€”- c:\windows\system32\ntkrnlpa.exe 2009-02-06 04:11 110,592 aโ€”โ€”- c:\windows\system32\services.exe 2009-02-06 04:08 2,189,056 aโ€”โ€”- c:\windows\system32\ntoskrnl.exe 2009-02-06 03:39 35,328 aโ€”โ€”- c:\windows\system32\sc.exe 2009-02-03 12:59 56,832 aโ€”โ€”- c:\windows\system32\secur32.dll 2007-09-13 07:15 68,456 acโ€”โ€” c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT 2001-08-18 05:00 94,784 -c-shโ€” c:\windows\twain.dll 2008-04-13 17:12 50,688 โ€”shโ€” c:\windows\twain_32.dll 2008-04-13 17:11 1,028,096 aโ€“shโ€” c:\windows\system32\mfc42.dll 2008-04-13 17:12 57,344 aโ€“shโ€” c:\windows\system32\msvcirt.dll 2008-04-13 17:12 413,696 aโ€“shโ€” c:\windows\system32\msvcp60.dll 2008-04-13 17:12 343,040 aโ€“shโ€” c:\windows\system32\msvcrt.dll 2008-04-13 17:12 551,936 โ€”shโ€” c:\windows\system32\oleaut32.dll 2008-04-13 17:12 84,992 aโ€“shโ€” c:\windows\system32\olepro32.dll 2008-04-13 17:12 11,776 โ€”shโ€” c:\windows\system32\regsvr32.exe ============= FINISH: 9:24:09.34 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-03-16.01) ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Reader 8.1.3 AiO_Scan AT&T Yahoo! Applications Audacity 1.2.4 AVG 8.5 Belarc Advisor 7.2 BroadJump Client Foundation Critical Update for Windows Media Player 11 (KB959772) HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB915800-v4) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) hp center hp deskjet 3820 series (Remove only) HP DLA HP Image Zone 4.2 hp instant support hp learning adventure HP Memories Disc HP Photo and Imaging 2.0 - All-in-One HP Photo and Imaging 2.0 - All-in-One Drivers HP Photo Printing Software HP PSC & OfficeJet 4.2 HP RecordNow Inactive HP Printer Drivers (Remove only) Intelยฎ 845G Chipset Graphics Driver Software InterVideo WinDVD Javaโ„ข 6 Update 13 LiveUpdate 1.7 (Symantec Corporation) LogMeIn Macromedia Shockwave Player Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Digital Image Library 9 - Blocker Microsoft Digital Image Standard 2006 Microsoft Digital Image Standard 2006 Editor Microsoft Digital Image Standard 2006 Library Microsoft Encarta Encyclopedia Standard 2006 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Location Finder Microsoft Money 2006 Microsoft National Language Support Downlevel APIs Microsoft Office Excel Viewer 2003 Microsoft Streets & Trips 2006 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Word 2002 Microsoft Works Microsoft Works and Money 2002 Setup Launcher Microsoft Works Suite 2006 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word Mozilla Firefox (3.0.9) MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) NVIDIA Windows 2000/XP Display Drivers Panda ActiveScan 2.0 PC-Doctor for Windows QFolder Quicken Financial Center QuickTime SBC Self Support Tool Scan Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB911565) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Spybot - Search & Destroy Tcl 8.0.5 for Windows Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VERITAS StorageGuard Viewpoint Media Player Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP WebIQ Technology Engine Windows Defender Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 11 Windows Search 4.0 Windows Support Tools Windows XP Hotfix - KB828028 Windows XP Service Pack 3 WinZip Works Suite OS Pack Works Upgrade Yahoo! Toolbar ==== End Of File ===========================
Hi

You seem to have run ComboFix without supervision there (not recommended!). Please post contents of c:\ComboFix.txt file so that I can see what was removed.
Yes, I did. Sorry. Was trying desperately to get the issue resolved in a timely manner. My friend, the computer's owner, has given up on the project. You can close this ticket. Thanks for your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI