This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer Freezing Up

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

free_spirit_etc,

Please double-click OTListIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:OTLI
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (Reg Error: Key error.)
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell - "" = AutoRun
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell - "" = AutoRun	G
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell\AutoRun - "" = Auto&Play	G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell - "" = AutoRun	G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell\AutoRun - "" = Auto&Play

  • Return to OTListIt2, right click in the "Custom Scans/Fixes" window (under the light blue bar) and choose Paste.
  • Click the red Run Fix button.
  • Click OK to show the fixlog in notepad.
  • Copy and paste the log in your next reply
  • Close OTListIt2
- - - - - Next - - - - -

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • OTListIt2 log
  • GMER.txt
  • Tell me how your computer is running at the moment.

Thanks! I am trying that. Am I supposed to include the ":OTLI" part when I run OTListIt2.exe? I am having trouble running that. It keeps going into Not Responding (though not freezing the system up). I tried it in Safe mode too. The odd thing was when I went back into normal mode, I had 125 temporary files on my desktop. I started a Scan with the gmer.exe. It did okay for about 30 minutes. But then the computer froze. So I will try it again. Besides that, I am not sure how my computer is running right now. I am not sure how to get the OTListIt2.exe to work. Thanks! Free

free_spirit_etc,

OTListIt2 needs to be run in Normal Mode

Am I supposed to include the ":OTLI"

Yes, include everything inside the code box, but NOT the word Code

:OTLI
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (Reg Error: Key error.)
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell - "" = AutoRun
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell - "" = AutoRun G
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell\AutoRun - "" = Auto&Play G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell - "" = AutoRun G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell\AutoRun - "" = Auto&Play


Hopefully, that has answered your questions. Please give the instructions another try.

Please double-click OTListIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).Copy the lines in the code box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:OTLI
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (Reg Error: Key error.)
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell - "" = AutoRun
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell - "" = AutoRun	G
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell\AutoRun - "" = Auto&Play	G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell - "" = AutoRun	G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell\AutoRun - "" = Auto&Play

  • Return to OTListIt2, right click in the "Custom Scans/Fixes" window (under the light blue bar) and choose Paste.
  • Click the red Run Fix button.
  • Click OK to show the fixlog in notepad.
  • Copy and paste the log in your next reply
  • Close OTListIt2
- - - - - Next - - - - -

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show All box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • OTListIt2 log
  • GMER.txt
  • Tell me how your computer is running at the moment.

My computer hasn't froze up. I worked on quite a few word documents last night with no problems.

I am still having trouble with OTListIt2 Not Responding.

I am using:

:OTLI
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (Reg Error: Key error.)
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell - "" = AutoRun
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell - "" = AutoRun G
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell\AutoRun - "" = Auto&Play G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell - "" = AutoRun G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell\AutoRun - "" = Auto&Play


Gamer Log

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-29 09:39:35
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF6C436B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF6C43574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF6C43A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF6C4314C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF6C4364E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF6C4308C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF6C430F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF6C4376E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF6C4372E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF6C438AE]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\SearchIndexer.exe[584] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00F21B19 C:\WINDOWS\system32\mssrch.dll (mssrch.lib/Microsoft Corporation)

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[844] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\.shtml\PersistentHandler@ {eec97550-47a9-11cf-b952-00aa0051fe20}
Reg HKLM\SOFTWARE\Classes\.wll\PersistentHandler@ {098f2470-bae0-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\CLSID\{B58C2440-A1A3-11d1-B024-006097C9A284}\LocalServer32@ C:\Program Files\Microsoft Office\Office\1033\MSOHELP.EXE
Reg HKLM\SOFTWARE\Classes\CLSID\{B58C2440-A1A3-11d1-B024-006097C9A284}\ProgID@ MsoHelpKeyDlg.1
Reg HKLM\SOFTWARE\Classes\CLSID\{B58C2440-A1A3-11d1-B024-006097C9A284}\VersionIndependentProgID@ MsoHelpKeyDlg
Reg HKLM\SOFTWARE\Classes\CLSID\{B58C2441-A1A3-11d1-B024-006097C9A284}\LocalServer32@ C:\Program Files\Microsoft Office\Office\1033\MSOHELP.EXE
Reg HKLM\SOFTWARE\Classes\CLSID\{B58C2441-A1A3-11d1-B024-006097C9A284}\ProgID@ MsoHelpAWDlg.1
Reg HKLM\SOFTWARE\Classes\CLSID\{B58C2441-A1A3-11d1-B024-006097C9A284}\VersionIndependentProgID@ MsoHelpAWDlg

—- EOF - GMER 1.0.15 —-

free_spirit_etc,

Let's remove the old version and download a new copy. We will be removing OTListIt2.exe and be replacing it with OTL.exe
(same program just new name format)

  • Double click on OTListIT2.exe to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.
- - - - - Next - - - - -
  • Download OTL to your desktop.
  • Please double-click OTL.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the code box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:OTL
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (Reg Error: Key error.)
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell - "" = AutoRun
O33 - MountPoints2\{64d7c457-c083-11dd-ac15-000fea17c644}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell - "" = AutoRun	G
O33 - MountPoints2\{6a67ac33-101d-11de-ac3c-000fea17c644}\Shell\AutoRun - "" = Auto&Play	G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell - "" = AutoRun	G
O33 - MountPoints2\{e12d0375-f38f-11dc-ab98-000fea17c644}\Shell\AutoRun - "" = Auto&Play

  • Return to OTL, right click in the "Custom Scans/Fixes" window (under the light blue bar) and choose Paste.
  • Click the red Run Fix button.
  • Click OK to show the fixlog in notepad.
  • Copy and paste the log in your next reply
  • Close OTL
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • OTL log
  • Tell me how your computer is running at the moment.

The CleanUp worked on the other one. But the new one is still going into Not Responding when I try to run the fix. It does move up where the: :OTL disappears. But it stops at: O3 - Toolbar: (no name) - {A057A204-BACC-4D26-CEC4-75A487FD6484} - (no file) And it shows two copies of it in the Windos Task Manager…both of them not responding. I tried it several times. Once I thought it was doing it.. but that time I forgot to paste the code in the box - so it just ran and then told me the process was completed - and gave me a one line file log. But it keeps going into not responding when I have the code pasted in the box. My computer is actually doing better at the moment. It froze up once - but that is GOOD compared to how it had been. I am also not getting all those temp files on the desktop. (It only did that once.) Free

free_spirit_etc,

Please download ComboFix from one of these locations:

Link 1
Link 2
Link 3

A guide can be found here

* IMPORTANT : Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
*Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. The log will be located here C:\ComboFix.txt (Provided 'C' is your root directory)
Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it at least 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ComboFix.txt
  • Tell me how your computer is running at the moment.

The Computer Froze up at the very end of ComboFix - when it was creating the log to pop up. But I think it finished scanning. ComboFix 09-05-30.03 - Semproni 05/30/2009 16:44:46.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.285 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1335 [VPS 090530-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\_000111_.tmp.dll . ((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-30 ))))))))))))))))))))))))))))))) . 2009-05-30 04:47:58 . 2009-05-30 04:47:58 0 d—–w C:\_OTL 2009-05-25 22:23:28 . 2009-05-25 22:23:28 152576 —-a-w C:\Documents and Settings\Semproni\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-05-22 07:57:45 . 2009-05-22 07:57:45 0 d—–w C:\Program Files\mypoints 2009-05-22 07:00:54 . 2009-02-05 20:06:20 51376 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys 2009-05-22 07:00:54 . 2009-02-05 20:06:10 23152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys 2009-05-22 07:00:53 . 2009-02-05 20:05:11 26944 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys 2009-05-22 07:00:52 . 2009-02-05 20:04:45 97480 —-a-w C:\WINDOWS\system32\AvastSS.scr 2009-05-22 07:00:51 . 2009-02-05 20:08:19 93296 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys 2009-05-22 07:00:51 . 2009-02-05 20:08:10 94032 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys 2009-05-22 07:00:51 . 2009-02-05 20:07:23 114768 —-a-w C:\WINDOWS\system32\drivers\aswSP.sys 2009-05-22 07:00:51 . 2009-02-05 20:07:12 20560 —-a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys 2009-05-22 07:00:32 . 2009-02-05 20:11:35 1256296 —-a-w C:\WINDOWS\system32\aswBoot.exe 2009-05-21 19:46:39 . 2009-05-21 19:46:39 430080 —-a-w C:\WINDOWS\system32\BSTIEPrintCtl1.dll 2009-05-21 19:46:39 . 2009-05-21 19:46:39 417792 —-a-w C:\NPcol305.dll 2009-05-18 04:23:51 . 2004-09-29 20:36:29 15360 —-a-w C:\WINDOWS\system32\drivers\NetMotCM.sys 2009-05-17 15:51:41 . 2009-05-17 15:51:41 0 d-sh–w C:\Documents and Settings\Semproni\IECompatCache 2009-05-16 20:37:54 . 2009-05-16 20:37:54 0 dc—-w C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81} 2009-05-15 09:52:33 . 2009-04-14 03:10:50 264704 ——w C:\Documents and Settings\Semproni\Application Data\OfficeUpdate12\oudetect.dll 2009-05-15 09:52:23 . 2009-05-15 09:52:33 0 d—–w C:\Documents and Settings\Semproni\Application Data\OfficeUpdate12 2009-05-15 09:42:11 . 2009-05-15 09:42:11 0 d-sh–w C:\Documents and Settings\Semproni\PrivacIE 2009-05-15 09:39:33 . 2009-05-15 09:39:33 0 d-sh–w C:\Documents and Settings\LocalService\IETldCache 2009-05-15 09:37:59 . 2009-05-15 09:37:59 0 d-sh–w C:\Documents and Settings\Semproni\IETldCache 2009-05-15 09:35:47 . 2009-05-15 09:35:47 0 d—–w C:\WINDOWS\ie8updates 2009-05-15 09:35:05 . 2009-04-25 05:30:39 102400 -c—-w C:\WINDOWS\system32\dllcache\iecompat.dll 2009-05-15 09:32:46 . 2009-05-15 09:34:59 0 dc-h–w C:\WINDOWS\ie8 2009-05-12 18:55:24 . 2009-05-12 18:55:24 0 d—–w C:\Documents and Settings\Semproni\Local Settings\Application Data\WMTools Downloaded Files 2009-05-12 09:33:59 . 2009-05-12 09:33:59 0 d—–w C:\Program Files\Common Files\Adobe AIR 2009-05-12 09:31:57 . 2009-05-12 14:04:41 0 d—–w C:\WINDOWS\SxsCaPendDel 2009-05-12 07:04:55 . 2009-05-12 07:04:55 20747 —-a-w C:\WINDOWS\system32\drivers\AegisP.sys 2009-05-12 07:04:50 . 2009-05-12 07:04:50 0 dc—-w C:\WINDOWS\system32\DRVSTORE 2009-05-12 07:04:50 . 2007-10-02 09:06:40 451968 —-a-w C:\WINDOWS\system32\drivers\rt73.sys 2009-05-12 07:04:49 . 2006-08-15 16:42:48 200704 —-a-w C:\WINDOWS\system32\UpdateDriver.exe 2009-05-12 07:04:45 . 2009-05-12 07:04:45 0 d–h–w C:\Program Files\InstallShield Installation Information 2009-05-12 07:04:37 . 2009-05-12 07:04:37 0 d—–w C:\Program Files\Belkin 2009-05-12 07:04:34 . 2009-05-12 07:04:34 0 d—–w C:\Documents and Settings\Semproni\Application Data\InstallShield 2009-05-12 03:15:05 . 2009-05-12 14:05:02 0 d—–w C:\Documents and Settings\All Users\Application Data\NOS 2009-05-12 03:15:03 . 2009-05-12 14:05:01 0 d—–w C:\Program Files\NOS . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-25 22:24:44 . 2009-04-28 23:13:25 410984 —-a-w C:\WINDOWS\system32\deploytk.dll 2009-05-23 23:39:46 . 2008-02-21 06:43:42 0 d—–w C:\Program Files\Spybot - Search & Destroy 2009-05-21 23:55:39 . 2008-11-09 02:29:44 0 d—a-w C:\Documents and Settings\All Users\Application Data\TEMP 2009-05-21 05:05:02 . 2009-05-24 04:15:38 162314 —-a-w C:\WINDOWS\pchealth\helpctr\Config\Cache\Personal_32_1033.dat 2009-05-17 03:52:26 . 2008-03-22 06:15:01 0 d—–w C:\Program Files\Coupons 2009-05-16 20:23:59 . 2008-06-12 08:29:06 0 d—–w C:\Program Files\Google 2009-05-16 15:44:21 . 2009-04-28 23:12:54 0 d—–w C:\Program Files\Java 2009-05-15 09:00:00 . 2008-11-09 02:29:39 0 d—–w C:\Program Files\SpywareBlaster 2009-05-12 09:36:35 . 2009-04-28 21:06:32 0 d—–w C:\Program Files\EsetOnlineScanner 2009-05-12 09:33:13 . 2008-02-22 23:08:39 0 d—–w C:\Program Files\Common Files\Adobe 2009-04-28 17:18:51 . 2009-04-28 17:18:51 0 d—–w C:\Program Files\E1704C 2009-04-28 17:17:29 . 2009-04-28 17:17:28 131829 —-a-w C:\Program Files\E1704C.zip 2009-04-26 15:34:50 . 2008-11-06 19:56:01 0 d—–w C:\Program Files\Malwarebytes' Anti-Malware 2009-04-26 15:34:36 . 2009-03-31 21:07:41 2967799 —-a-w C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-04-26 05:13:11 . 2009-03-14 22:39:21 0 d—–w C:\Program Files\OpenOffice.org 3 2009-04-26 00:30:15 . 2009-04-26 00:30:15 0 d—–w C:\Program Files\Trend Micro 2009-04-14 03:10:50 . 2009-04-14 03:10:50 524288 —-a-w C:\WINDOWS\opuc.dll 2009-04-06 20:32:54 . 2008-11-06 19:56:04 38496 —-a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2009-04-06 20:32:46 . 2008-11-06 19:56:06 15504 —-a-w C:\WINDOWS\system32\drivers\mbam.sys 2009-04-06 00:50:01 . 2008-02-22 09:14:41 0 d—–w C:\Documents and Settings\Semproni\Application Data\LimeWire 2009-04-02 17:33:44 . 2009-03-15 07:36:49 1 —-a-w C:\Documents and Settings\Semproni\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2009-03-15 22:51:42 . 2008-03-26 20:12:41 26032 —-a-w C:\Documents and Settings\Semproni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-03-14 22:35:43 . 2009-03-14 09:45:05 149353184 —-a-w C:\Program Files\OOo_3.0.1_Win32Intel_install_wJRE_en-US.exe 2009-03-08 09:34:58 . 2004-08-04 00:56:48 914944 —-a-w C:\WINDOWS\system32\wininet.dll 2009-03-08 09:34:30 . 2004-08-04 00:56:44 43008 —-a-w C:\WINDOWS\system32\licmgr10.dll 2009-03-08 09:33:40 . 2004-08-04 00:56:42 18944 —-a-w C:\WINDOWS\system32\corpol.dll 2009-03-08 09:33:06 . 2004-08-04 00:56:48 420352 —-a-w C:\WINDOWS\system32\vbscript.dll 2009-03-08 09:32:56 . 2004-08-04 00:56:42 72704 —-a-w C:\WINDOWS\system32\admparse.dll 2009-03-08 09:32:50 . 2004-08-04 00:56:44 71680 —-a-w C:\WINDOWS\system32\iesetup.dll 2009-03-08 09:31:38 . 2004-08-04 00:56:44 34816 —-a-w C:\WINDOWS\system32\imgutil.dll 2009-03-08 09:31:18 . 2004-08-04 00:56:16 48128 —-a-w C:\WINDOWS\system32\mshtmler.dll 2009-03-08 09:31:02 . 2004-08-04 00:56:54 45568 —-a-w C:\WINDOWS\system32\mshta.exe 2009-03-08 09:22:38 . 2004-08-17 00:49:06 156160 —-a-w C:\WINDOWS\system32\msls31.dll 2009-03-06 14:22:18 . 2004-08-04 00:56:46 284160 —-a-w C:\WINDOWS\system32\pdh.dll 2008-12-17 16:51:08 . 2008-12-17 16:50:40 7518240 —-a-w C:\Program Files\Firefox Setup 3.0.5.exe 2008-11-12 05:50:30 . 2008-11-12 05:50:26 449043 —-a-w C:\Program Files\RegSeeker.zip . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 00:12:16 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 00:12:27 169984] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 20:08:45 81000] "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-05-25 22:24:46 148888] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 21:39:22 294400] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^Semproni^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "WMPNetworkSvc"=3 (0x3) "Pml Driver HPZ12"=3 (0x3) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Lightning Download\\Lightning.exe"= R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [5/22/2009 2:00:51 AM 114768] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [5/22/2009 2:00:51 AM 20560] R3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\es1370mp.sys [2/26/2008 6:29:59 AM 37504] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-05-30 C:\WINDOWS\Tasks\User_Feed_Synchronization-{8EB98E4C-8F55-435E-9667-18FC8FE9E34B}.job - C:\WINDOWS\system32\msfeedssync.exe [2007-08-14 00:36:40 . 2009-03-08 09:31:54] 2009-05-18 C:\WINDOWS\Tasks\WinASORegistryOptimizerForSemproni.job - C:\Program Files\WinASO\Registry Optimizer 3.0\RegOpt.exe [2008-02-21 06:37:46 . 2007-02-12 23:55:32] . - - - - ORPHANS REMOVED - - - - SafeBoot-procexp90.Sys . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ FF - ProfilePath - C:\Documents and Settings\Semproni\Application Data\Mozilla\Firefox\Profiles\on0wtzl9.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - plugin: C:\Program Files\Mozilla Firefox\plugins\NPcol305.dll FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll .

free_spirit_etc,

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Folder::
C:\WINDOWS\SxsCaPendDel
C:\Documents and Settings\Semproni\Application Data\LimeWire


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ComboFix.txt log
  • Tell me if there is any change in the performance of your computer.

Hi, I ran the ComboFix twice because it froze up on the first run. I do think the computer is running much better. It does freeze up some, but not near as often…and mostly after I have been on it for awhile. Here is my log: ComboFix 09-05-31.02 - Semproni 05/31/2009 18:37:08.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.261 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Semproni\Desktop\CFScript.txt AV: avast! antivirus 4.8.1335 [VPS 090531-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . —- Previous Run ——- . C:\Documents and Settings\Semproni\Application Data\LimeWire C:\Documents and Settings\Semproni\Application Data\LimeWire\createtimes.cache C:\Documents and Settings\Semproni\Application Data\LimeWire\fileurns.bak C:\Documents and Settings\Semproni\Application Data\LimeWire\fileurns.cache C:\Documents and Settings\Semproni\Application Data\LimeWire\filters.props C:\Documents and Settings\Semproni\Application Data\LimeWire\gnutella.net C:\Documents and Settings\Semproni\Application Data\LimeWire\installation.props C:\Documents and Settings\Semproni\Application Data\LimeWire\library.dat C:\Documents and Settings\Semproni\Application Data\LimeWire\limewire.props C:\Documents and Settings\Semproni\Application Data\LimeWire\mojito.props C:\Documents and Settings\Semproni\Application Data\LimeWire\questions.props C:\Documents and Settings\Semproni\Application Data\LimeWire\responses.cache C:\Documents and Settings\Semproni\Application Data\LimeWire\simpp.xml C:\Documents and Settings\Semproni\Application Data\LimeWire\spam.dat C:\Documents and Settings\Semproni\Application Data\LimeWire\tables.props C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme.lwtp C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\01_star.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\02_star.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\03_star.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\04_star.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\05_star.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\chat.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\forward_dn.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\forward_up.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\kill.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\kill_on.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\logo.png C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\notsearching.png C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\pause_dn.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\pause_up.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\play_dn.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\play_up.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\question.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\rewind_up.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\searching.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\stop_dn.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\stop_up.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\theme.txt C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\version.txt C:\Documents and Settings\Semproni\Application Data\LimeWire\themes\windows_theme\warning.gif C:\Documents and Settings\Semproni\Application Data\LimeWire\ttrees.cache C:\Documents and Settings\Semproni\Application Data\LimeWire\ttroot.cache C:\Documents and Settings\Semproni\Application Data\LimeWire\version.xml C:\Documents and Settings\Semproni\Application Data\LimeWire\xml\data\audio.sxml C:\WINDOWS\SxsCaPendDel C:\WINDOWS\system32\_000111_.tmp.dll . ((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 ))))))))))))))))))))))))))))))) . 2009-05-30 04:47:58 . 2009-05-30 04:47:58 0 d—–w- C:\_OTL 2009-05-25 22:23:28 . 2009-05-25 22:23:28 152576 —-a-w- C:\Documents and Settings\Semproni\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-05-22 07:57:45 . 2009-05-22 07:57:45 0 d—–w- C:\Program Files\mypoints 2009-05-22 07:00:54 . 2009-02-05 20:06:20 51376 —-a-w- C:\WINDOWS\system32\drivers\aswTdi.sys 2009-05-22 07:00:54 . 2009-02-05 20:06:10 23152 —-a-w- C:\WINDOWS\system32\drivers\aswRdr.sys 2009-05-22 07:00:53 . 2009-02-05 20:05:11 26944 —-a-w- C:\WINDOWS\system32\drivers\aavmker4.sys 2009-05-22 07:00:52 . 2009-02-05 20:04:45 97480 —-a-w- C:\WINDOWS\system32\AvastSS.scr 2009-05-22 07:00:51 . 2009-02-05 20:08:19 93296 —-a-w- C:\WINDOWS\system32\drivers\aswmon.sys 2009-05-22 07:00:51 . 2009-02-05 20:08:10 94032 —-a-w- C:\WINDOWS\system32\drivers\aswmon2.sys 2009-05-22 07:00:51 . 2009-02-05 20:07:23 114768 —-a-w- C:\WINDOWS\system32\drivers\aswSP.sys 2009-05-22 07:00:51 . 2009-02-05 20:07:12 20560 —-a-w- C:\WINDOWS\system32\drivers\aswFsBlk.sys 2009-05-22 07:00:32 . 2009-02-05 20:11:35 1256296 —-a-w- C:\WINDOWS\system32\aswBoot.exe 2009-05-21 19:46:39 . 2009-05-21 19:46:39 430080 —-a-w- C:\WINDOWS\system32\BSTIEPrintCtl1.dll 2009-05-21 19:46:39 . 2009-05-21 19:46:39 417792 —-a-w- C:\NPcol305.dll 2009-05-21 04:41:04 . 2009-05-21 04:41:04 0 d—–w- C:\WINDOWS\system32\wbem\Repository 2009-05-18 04:23:51 . 2004-09-29 20:36:29 15360 —-a-w- C:\WINDOWS\system32\drivers\NetMotCM.sys 2009-05-17 15:51:41 . 2009-05-17 15:51:41 0 d-sh–w- C:\Documents and Settings\Semproni\IECompatCache 2009-05-16 20:37:54 . 2009-05-16 20:37:54 0 dc—-w- C:\Documents and Settings\All Users\Application Data\{92E7A367-8E12-4830-AA70-29C32E331A81} 2009-05-15 09:52:33 . 2009-04-14 03:10:50 264704 ——w- C:\Documents and Settings\Semproni\Application Data\OfficeUpdate12\oudetect.dll 2009-05-15 09:52:23 . 2009-05-15 09:52:33 0 d—–w- C:\Documents and Settings\Semproni\Application Data\OfficeUpdate12 2009-05-15 09:42:11 . 2009-05-15 09:42:11 0 d-sh–w- C:\Documents and Settings\Semproni\PrivacIE 2009-05-15 09:39:33 . 2009-05-15 09:39:33 0 d-sh–w- C:\Documents and Settings\LocalService\IETldCache 2009-05-15 09:37:59 . 2009-05-15 09:37:59 0 d-sh–w- C:\Documents and Settings\Semproni\IETldCache 2009-05-15 09:35:47 . 2009-05-15 09:35:47 0 d—–w- C:\WINDOWS\ie8updates 2009-05-15 09:35:05 . 2009-04-25 05:30:39 102400 -c—-w- C:\WINDOWS\system32\dllcache\iecompat.dll 2009-05-15 09:32:46 . 2009-05-15 09:34:59 0 dc-h–w- C:\WINDOWS\ie8 2009-05-12 18:55:24 . 2009-05-12 18:55:24 0 d—–w- C:\Documents and Settings\Semproni\Local Settings\Application Data\WMTools Downloaded Files 2009-05-12 09:33:59 . 2009-05-12 09:33:59 0 d—–w- C:\Program Files\Common Files\Adobe AIR 2009-05-12 07:04:55 . 2009-05-12 07:04:55 20747 —-a-w- C:\WINDOWS\system32\drivers\AegisP.sys 2009-05-12 07:04:50 . 2009-05-12 07:04:50 0 dc—-w- C:\WINDOWS\system32\DRVSTORE 2009-05-12 07:04:50 . 2007-10-02 09:06:40 451968 —-a-w- C:\WINDOWS\system32\drivers\rt73.sys 2009-05-12 07:04:49 . 2006-08-15 16:42:48 200704 —-a-w- C:\WINDOWS\system32\UpdateDriver.exe 2009-05-12 07:04:45 . 2009-05-12 07:04:45 0 d–h–w- C:\Program Files\InstallShield Installation Information 2009-05-12 07:04:37 . 2009-05-12 07:04:37 0 d—–w- C:\Program Files\Belkin 2009-05-12 07:04:34 . 2009-05-12 07:04:34 0 d—–w- C:\Documents and Settings\Semproni\Application Data\InstallShield 2009-05-12 03:15:05 . 2009-05-12 14:05:02 0 d—–w- C:\Documents and Settings\All Users\Application Data\NOS 2009-05-12 03:15:03 . 2009-05-12 14:05:01 0 d—–w- C:\Program Files\NOS . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-31 16:53:41 . 2008-03-22 06:15:01 0 d—–w- C:\Program Files\Coupons 2009-05-25 22:24:44 . 2009-04-28 23:13:25 410984 —-a-w- C:\WINDOWS\system32\deploytk.dll 2009-05-23 23:39:46 . 2008-02-21 06:43:42 0 d—–w- C:\Program Files\Spybot - Search & Destroy 2009-05-21 23:55:39 . 2008-11-09 02:29:44 0 d—a-w- C:\Documents and Settings\All Users\Application Data\TEMP 2009-05-21 05:05:02 . 2009-05-24 04:15:38 162314 —-a-w- C:\WINDOWS\pchealth\helpctr\Config\Cache\Personal_32_1033.dat 2009-05-16 20:23:59 . 2008-06-12 08:29:06 0 d—–w- C:\Program Files\Google 2009-05-16 15:44:21 . 2009-04-28 23:12:54 0 d—–w- C:\Program Files\Java 2009-05-15 09:00:00 . 2008-11-09 02:29:39 0 d—–w- C:\Program Files\SpywareBlaster 2009-05-12 09:36:35 . 2009-04-28 21:06:32 0 d—–w- C:\Program Files\EsetOnlineScanner 2009-05-12 09:33:13 . 2008-02-22 23:08:39 0 d—–w- C:\Program Files\Common Files\Adobe 2009-04-28 17:18:51 . 2009-04-28 17:18:51 0 d—–w- C:\Program Files\E1704C 2009-04-28 17:17:29 . 2009-04-28 17:17:28 131829 —-a-w- C:\Program Files\E1704C.zip 2009-04-26 15:34:50 . 2008-11-06 19:56:01 0 d—–w- C:\Program Files\Malwarebytes' Anti-Malware 2009-04-26 15:34:36 . 2009-03-31 21:07:41 2967799 —-a-w- C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-04-26 05:13:11 . 2009-03-14 22:39:21 0 d—–w- C:\Program Files\OpenOffice.org 3 2009-04-26 00:30:15 . 2009-04-26 00:30:15 0 d—–w- C:\Program Files\Trend Micro 2009-04-14 03:10:50 . 2009-04-14 03:10:50 524288 —-a-w- C:\WINDOWS\opuc.dll 2009-04-06 20:32:54 . 2008-11-06 19:56:04 38496 —-a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2009-04-06 20:32:46 . 2008-11-06 19:56:06 15504 —-a-w- C:\WINDOWS\system32\drivers\mbam.sys 2009-04-02 17:33:44 . 2009-03-15 07:36:49 1 —-a-w- C:\Documents and Settings\Semproni\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys 2009-03-15 22:51:42 . 2008-03-26 20:12:41 26032 —-a-w- C:\Documents and Settings\Semproni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-03-14 22:35:43 . 2009-03-14 09:45:05 149353184 —-a-w- C:\Program Files\OOo_3.0.1_Win32Intel_install_wJRE_en-US.exe 2009-03-08 09:34:58 . 2004-08-04 00:56:48 914944 —-a-w- C:\WINDOWS\system32\wininet.dll 2009-03-08 09:34:30 . 2004-08-04 00:56:44 43008 —-a-w- C:\WINDOWS\system32\licmgr10.dll 2009-03-08 09:33:40 . 2004-08-04 00:56:42 18944 —-a-w- C:\WINDOWS\system32\corpol.dll 2009-03-08 09:33:06 . 2004-08-04 00:56:48 420352 —-a-w- C:\WINDOWS\system32\vbscript.dll 2009-03-08 09:32:56 . 2004-08-04 00:56:42 72704 —-a-w- C:\WINDOWS\system32\admparse.dll 2009-03-08 09:32:50 . 2004-08-04 00:56:44 71680 —-a-w- C:\WINDOWS\system32\iesetup.dll 2009-03-08 09:31:38 . 2004-08-04 00:56:44 34816 —-a-w- C:\WINDOWS\system32\imgutil.dll 2009-03-08 09:31:18 . 2004-08-04 00:56:16 48128 —-a-w- C:\WINDOWS\system32\mshtmler.dll 2009-03-08 09:31:02 . 2004-08-04 00:56:54 45568 —-a-w- C:\WINDOWS\system32\mshta.exe 2009-03-08 09:22:38 . 2004-08-17 00:49:06 156160 —-a-w- C:\WINDOWS\system32\msls31.dll 2009-03-06 14:22:18 . 2004-08-04 00:56:46 284160 —-a-w- C:\WINDOWS\system32\pdh.dll 2008-12-17 16:51:08 . 2008-12-17 16:50:40 7518240 —-a-w- C:\Program Files\Firefox Setup 3.0.5.exe 2008-11-12 05:50:30 . 2008-11-12 05:50:26 449043 —-a-w- C:\Program Files\RegSeeker.zip . ((((((((((((((((((((((((((((( SnapShot@2009-05-30_21.47.10 ))))))))))))))))))))))))))))))))))))))))) . + 2009-05-31 23:32:38 . 2009-05-31 23:32:38 16384 C:\WINDOWS\Temp\Perflib_Perfdata_298.dat + 2009-05-31 23:32:28 . 2009-05-31 23:32:28 16384 C:\WINDOWS\Temp\Perflib_Perfdata_12c.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 00:12:16 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 00:12:27 169984] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 20:08:45 81000] "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-05-25 22:24:46 148888] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 21:39:22 294400] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk] [HKLM\~\startupfolder\C:^Documents and Settings^Semproni^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "WMPNetworkSvc"=3 (0x3) "Pml Driver HPZ12"=3 (0x3) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Lightning Download\\Lightning.exe"= R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [5/22/2009 2:00:51 AM 114768] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [5/22/2009 2:00:51 AM 20560] R3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\es1370mp.sys [2/26/2008 6:29:59 AM 37504] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-05-31 C:\WINDOWS\Tasks\User_Feed_Synchronization-{8EB98E4C-8F55-435E-9667-18FC8FE9E34B}.job - C:\WINDOWS\system32\msfeedssync.exe [2007-08-14 00:36:40 . 2009-03-08 09:31:54] 2009-05-18 C:\WINDOWS\Tasks\WinASORegistryOptimizerForSemproni.job - C:\Program Files\WinASO\Registry Optimizer 3.0\RegOpt.exe [2008-02-21 06:37:46 . 2007-02-12 23:55:32] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ FF - ProfilePath - C:\Documents and Settings\Semproni\Application Data\Mozilla\Firefox\Profiles\on0wtzl9.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - plugin: C:\Program Files\Mozilla Firefox\plugins\NPcol305.dll FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll .

free_spirit_etc,

We are still not getting a complete log when you run ComboFix. Please continue,

Please run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ESET log.txt
  • Again tell me how your computer is running at the moment. (ie. freezes)

My computer actually hasn't frozen today at all. Not sure why…. I ran the Eset Scanner yesterday. I couldn't find the Detail tab to click though. Ran it once, didn't find the Details tab - and the log isn't very long - so I thought maybe I did something wrong. Ran it again and it froze. Ran it the third time - and still didn't find the Details tab - but here is the log it showed: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=53251 # version=6 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=814eed94515d0e42a73e746f5c24fd5b # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-06-02 07:18:53 # local_time=2009-06-02 02:18:53 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=769 37 100 100 21731250000 # scanned=71845 # found=0 # cleaned=0 # scan_time=2114 esets_scanner_update returned -1 esets_gle=53251 esets_scanner_update returned -1 esets_gle=53251 # version=6 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=814eed94515d0e42a73e746f5c24fd5b # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-06-03 05:52:13 # local_time=2009-06-03 12:52:13 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=769 37 100 100 20012500000 # scanned=71696 # found=0 # cleaned=0 # scan_time=1885

free_spirit_etc,

With the intermittent freezing you have been encountering you may find it necessary to post in the Windows Help Forum
should this continue to occur. As this situation doesn't seem to be malware related.
http://forums.whatthetech.com/Microsoft_Windows_f119.html

If you do seek help in the Windows Help Forum please provide a link back to this thread for reference for the Tech helper.
http://forums.whatthetech.com/Computer_Fre…980#entry564980

===================================

Congratulations, your log is clean.

We need to remove some of the programs we used before we get to the "All Clean Speech"

  • Double click on OTL.exe to run it.
  • Select the CleanUp button.
  • When done, please close the program.
- - - - - Next - - - - -

Consider changing your Firewall to one that provides better protection than the Windows Firewall you are currently using.
Here are a few FREE ones:
  • Please download one (1) of the firewalls below, but do not install it just yet.
  • After you have downloaded the new firewall, disable the Windows firewall.
  • Then install the newly selected firewall.
Firewall:
- - - - - Next - - - - -

Here comes the "All Clean Speech":

Now that your log is clean, you need to set a new clean System Restore Point

Create a new Restore Point
  • Click on the Start button to open your Start Menu.
  • Click on the Control Panel menu option.
  • Click on the System and Maintenance menu option.
  • Click on the System menu option.
  • Click on System Protection in the left-hand task list.
  • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
  • Type in a title for the manual restore point and press the Create button.
  • Close the System window after you have been advised that the procedure has been successfully completed.
- - - - - Next - - - - -

Clear your existing system restore points except for the new clean restore point you just created:
  • Go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Next to System Restore click Clean up
  • This will remove all restore points except the new one you just created.
- - - - - Next - - - - -

Delete the Contents of the Temporary Internet Files Folder:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
  • Click OK
- - - - - Next - - - - -

Automatic Updates:

The easiest way to ensure you don't miss any of the critical Windows Updates is to set your computer up to receive Automatic Updates.
To set your computer up for Automatic Updates please do the following:
  • Click Start, and then click Control Panel.
  • Depending on which Control Panel view you use, Classic or Category, do one of the following:
  • Click System, and then click the Automatic Updates tab.
  • Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
  • Select Automatic and choose a frequency and time that's convenient for you to get the updates.
  • Click Apply, then OK
  • Close the Control Panel.
- - - - - Next - - - - -

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Simple and easy ways to keep your computer safe and secure on the Internet

Alternate Browsers - If you are currently using Internet Explorer you might want to consider changing over to Firefox.
Firefox is one of the most popular alternate browsers. - Mozilla Firefox

Update your AntiVirus Software - You are using Avast Anti - Virus as your anti virus software. It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - You are using Windows Firewall. I cannot stress how important it is that you keep the Firewall on your computer active at all times. Without a firewall your computer is susceptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that
aren't actually innocent at all. Using IE-SPYAD to help block unwanted sites and activities

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer always has the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Update all security programs regularly - Make sure you update all the programs regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.

Remember to have only one (1) Firewall and one (1) Anti-Virus program running at any one time.

I would also suggest you read "So how did I get infected in the first place"?: by Tony Klein

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI