This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] New Acer One netbook very sluggish - please help

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ac3r n3tb00k,

Glad to hear you were able to resolve the profile issue, please continue.

Combofix

Please download ComboFix from one of these locations:

Link 1
Link 2
Link 3

A guide can be found here

* IMPORTANT : Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
*Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. The log will be located here C:\ComboFix.txt (Provided 'C' is your root directory)
Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it at least 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ComboFix.txt
  • Tell me how your computer is running at the moment.

Hi OCD - Here is the log.txt file after running ComboFix: The machine seemed like it took longer to reboot than normal, but it seems to be running ok now…

ComboFix 09-05-31.02 - Carrie Ann 05/31/2009 18:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.659 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090530-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.

2009-05-30 03:53 . 2009-05-30 03:53 ——– d—–w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\Adobe
2009-05-30 03:53 . 2009-05-30 03:53 ——– d—–w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\Identities
2009-05-30 03:53 . 2009-05-30 03:53 ——– d—–w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\Google
2009-05-30 03:52 . 2009-05-30 03:52 ——– d—–w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\Mozilla
2009-05-30 03:35 . 2009-05-30 03:35 ——– d-sh–w- c:\documents and settings\Carrie Ann\IETldCache
2009-05-30 03:23 . 2009-05-30 03:23 ——– d-sh–w- c:\documents and settings\TEMP.CAD\IETldCache
2009-05-30 03:20 . 2009-05-30 03:20 ——– d—–w- c:\documents and settings\TEMP
2009-05-30 02:57 . 2009-05-30 02:57 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-05-29 02:18 . 2009-05-29 02:18 ——– d—–w- C:\_OTListIt
2009-05-24 05:15 . 2009-05-24 05:15 ——– d—–w- c:\windows\SHELLNEW
2009-05-24 00:12 . 2009-05-24 00:12 ——– d-sh–w- c:\documents and settings\Carrie\IETldCache
2009-05-24 00:09 . 2009-05-24 00:09 ——– d—–w- c:\windows\ie8updates
2009-05-24 00:08 . 2009-04-25 05:30 102400 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-05-24 00:06 . 2009-05-24 00:08 ——– dc-h–w- c:\windows\ie8
2009-05-23 04:32 . 2009-05-23 04:32 ——– d—–w- c:\program files\Trend Micro
2009-05-16 03:31 . 2009-05-16 03:31 2967799 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-16 00:19 . 2009-05-16 00:19 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-05-15 12:07 . 2007-10-23 14:27 110592 —-a-w- c:\documents and settings\Administrator\Application Data\U3\temp\cleanup.exe
2009-05-15 12:04 . 2008-05-02 15:41 3493888 —ha-w- c:\documents and settings\Administrator\Application Data\U3\temp\Launchpad Removal.exe
2009-05-15 12:04 . 2009-05-15 12:04 ——– d—–w- c:\documents and settings\Administrator\Application Data\U3
2009-05-15 02:20 . 2009-05-15 02:20 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-05-15 02:20 . 2009-04-06 20:32 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-15 02:20 . 2009-04-06 20:32 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-15 02:20 . 2009-05-16 03:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-15 02:20 . 2009-05-15 02:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-15 01:56 . 2008-04-14 05:10 57600 -c–a-w- c:\windows\system32\dllcache\redbook.sys
2009-05-15 01:56 . 2008-04-14 05:10 57600 —-a-w- c:\windows\system32\drivers\redbook.sys
2009-05-03 15:27 . 2008-04-14 20:00 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-03 15:22 . 2009-05-03 15:22 ——– d—–w- c:\program files\Windows Media Connect 2
2009-05-03 15:20 . 2009-05-03 15:21 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-05-03 15:20 . 2009-05-03 15:20 ——– d—–w- c:\windows\system32\LogFiles
2009-05-03 15:07 . 2009-05-03 15:09 ——– d—–w- C:\Music

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-30 03:42 . 2009-05-30 03:42 ——– d—–w- c:\documents and settings\Carrie Ann\Application Data\GetRightToGo
2009-05-30 03:42 . 2009-05-30 03:42 ——– d—–w- c:\documents and settings\Carrie Ann\Application Data\Malwarebytes
2009-05-30 03:42 . 2009-05-30 03:42 ——– d—–w- c:\documents and settings\Carrie Ann\Application Data\Template
2009-05-30 03:42 . 2009-05-30 03:42 ——– d—–w- c:\documents and settings\Carrie Ann\Application Data\U3
2009-05-24 05:16 . 2009-01-20 19:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-24 04:54 . 2009-01-20 19:28 ——– d—–w- c:\program files\eSobi
2009-05-23 01:57 . 2009-05-30 03:42 300 —-a-w- c:\documents and settings\Carrie Ann\Application Data\wklnhst.dat
2009-05-12 00:16 . 2009-01-20 18:45 ——– d—–w- c:\program files\Common Files\Adobe
2009-04-29 22:05 . 2009-01-20 18:10 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-29 05:07 . 2009-04-29 05:03 139554 —-a-w- c:\windows\hpoins21.dat
2009-04-29 05:07 . 2009-04-29 05:07 ——– d—–w- c:\program files\Common Files\HP
2009-04-29 05:07 . 2009-04-29 05:07 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2009-04-29 05:07 . 2009-04-29 05:07 ——– d—–w- c:\program files\Hewlett-Packard
2009-04-29 05:06 . 2009-04-29 05:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-04-29 05:04 . 2009-04-29 05:04 ——– d—–w- c:\program files\HP
2009-04-26 13:49 . 2009-05-30 03:35 60592 —-a-w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-20 14:12 . 2009-04-20 14:12 0 —-a-w- c:\windows\nsreg.dat
2009-04-06 12:48 . 2009-04-06 12:48 ——– d—–w- c:\program files\MSBuild
2009-04-06 12:48 . 2009-04-06 12:48 ——– d—–w- c:\program files\Reference Assemblies
2009-04-06 12:19 . 2009-01-20 19:05 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-04-06 12:19 . 2009-01-20 20:16 ——– d—–w- c:\program files\McAfee
2009-04-06 12:17 . 2009-01-20 19:22 ——– d—–w- c:\program files\Google
2009-04-06 12:16 . 2009-04-06 12:16 ——– d—–w- c:\program files\Alwil Software
2009-04-06 11:54 . 2009-04-06 11:54 ——– d—–w- c:\program files\Common Files\SNP2UVC
2009-04-06 11:54 . 2009-01-20 20:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-03-08 09:34 . 2008-10-16 20:38 914944 —-a-w- c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2007-08-14 02:44 43008 —-a-w- c:\windows\system32\licmgr10.dll
2009-03-08 09:33 . 2008-04-14 20:00 18944 —-a-w- c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2008-05-09 10:53 420352 —-a-w- c:\windows\system32\vbscript.dll
2009-03-08 09:32 . 2007-08-14 02:39 72704 —-a-w- c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2007-08-14 02:39 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-03-08 09:31 . 2007-08-14 02:36 34816 —-a-w- c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2007-08-14 02:01 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2007-08-14 02:32 45568 —-a-w- c:\windows\system32\mshta.exe
2009-03-08 09:22 . 2007-08-14 02:54 156160 —-a-w- c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2008-04-14 20:00 284160 —-a-w- c:\windows\system32\pdh.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-18 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2008-10-03 294544]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-09-04 425984]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-12-30 18082304]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-6-4 114688]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/6/2009 7:16 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/6/2009 7:16 AM 20560]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [7/8/2008 12:16 PM 96856]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\77.tmp –> c:\windows\system32\77.tmp [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-snp2uvc - c:\windows\vsnp2uvc.exe
SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://global.acer.com
FF - ProfilePath - c:\documents and settings\Carrie Ann\Application Data\Mozilla\Firefox\Profiles\cga6bqxj.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-31 18:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\77.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\igfxdev.dll

- - - - - - - > 'explorer.exe'(3416)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-31 18:21
ComboFix-quarantined-files.txt 2009-05-31 23:21

Pre-Run: 140,315,709,440 bytes free
Post-Run: 140,305,846,272 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

167 — E O F — 2009-05-14 18:23

ac3r n3tb00k,

Your ComboFix log came back clean, please continue.

I would like for you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ESET log.txt
  • New HijackThis log
  • Tell me how your computer is running at the moment.

Hello - here is the ESET log.txt: ESETSmartInstaller@High as downloader log: all ok # version=6 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=94bd709c0a2c684eb18b563de4309d1d # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-06-01 03:16:06 # local_time=2009-05-31 10:16:06 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=769 21 83 100 133657812500 # scanned=37911 # found=0 # cleaned=0 # scan_time=1566
And here is the new HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:23:40 PM, on 5/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Carbonite\CarbonitePreinstaller.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\igfxext.exe
C:\DOCUME~1\CARRIE~1\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled
O4 - HKLM\..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (file missing)
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe

–
End of file - 5545 bytes
It seems to be running normally I should add. The reboot time seemed normal and nothing seems laggy. Thanks for looking through all these logs OCD - am I infection free?

ac3r n3tb00k,

There is one file I am not sure about so I would like for you to submit it to be analyzed

Submit this File 77.tmp For Analysis

  • Please visit Jotti at http://virusscan.jotti.org/
  • Click on Browse… and navigate to the following file: c:\windows\system32\77.tmp
  • Click Open
  • Please post back the results of this scan.
If Jotti is too busy please try Virustotal at http://www.virustotal.com/

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Please post the results of the file analysis.

Hi OCD - 77.tmp is nowhere to be found on my computer. I just searched the whole c: drive and it did not find this file. I tried browsing to it on the Jotti website and couldn't find it so i thought maybe it was in a different location but the search i did came back empty… Any suggestions?

ac3r n3tb00k,

Enable the Viewing of Hidden files, please follow these steps:

  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
- - - - - Next - - - - -

Please try and locate the file again.

Submit this File 77.tmp For Analysis
  • Please visit Jotti at http://virusscan.jotti.org/
  • Click on Browse… and navigate to the following file: c:\windows\system32\77.tmp
  • Click Open
  • Please post back the results of this scan.
If Jotti is too busy please try Virustotal at http://www.virustotal.com/

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Please post the results of the file analysis.

Hi OCD - 77.tmp is still nowhere to be found - even after following those directions for enabling the viewing of hidden files. I also searched the C: drive and again nothing, I'm not sure what to do…. Everything does seem to be working good though. Ac3r

ac3r n3tb00k,

Congratulations, your computer is clean.

Earlier we talked about changing your Firewall to one that provides better protection than the Windows Firewall you are currently using.
Here are a few FREE ones:

  • Please download one (1) of the firewalls below, but do not install it just yet.
  • After you have downloaded the new firewall, disable the Windows firewall.
  • Then install the newly selected firewall.
Firewall:
- - - - - Next - - - - -

Here comes the "All Clean Speech":

Now that your log is clean, you need to set a new clean System Restore Point

Create a new Restore Point
  • Click on the Start button to open your Start Menu.
  • Click on the Control Panel menu option.
  • Click on the System and Maintenance menu option.
  • Click on the System menu option.
  • Click on System Protection in the left-hand task list.
  • Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
  • Type in a title for the manual restore point and press the Create button.
  • Close the System window after you have been advised that the procedure has been successfully completed.
- - - - - Next - - - - -

Clear your existing system restore points except for the new clean restore point you just created:
  • Go to Start > Run and type in cleanmgr
  • Select the More options tab
  • Next to System Restore click Clean up
  • This will remove all restore points except the new one you just created.
- - - - - Next - - - - -

Delete the Contents of the Temporary Internet Files Folder:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
  • Click OK
- - - - - Next - - - - -

Automatic Updates:

The easiest way to ensure you don't miss any of the critical Windows Updates is to set your computer up to receive Automatic Updates.
To set your computer up for Automatic Updates please do the following:
  • Click Start, and then click Control Panel.
  • Depending on which Control Panel view you use, Classic or Category, do one of the following:
  • Click System, and then click the Automatic Updates tab.
  • Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
  • Select Automatic and choose a frequency and time that's convenient for you to get the updates.
  • Click Apply, then OK
  • Close the Control Panel.
- - - - - Next - - - - -

Here are some tips to reduce the potential for spyware infection in the future:

Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Simple and easy ways to keep your computer safe and secure on the Internet

Alternate Browsers - If you are currently using Internet Explorer you might want to consider changing over to Firefox.
Firefox is one of the most popular alternate browsers. - Mozilla Firefox

Update your AntiVirus Software - You are using Avast as your anti virus software. It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall - You are using Windows Firewall (hopefully you have already made this change).I cannot stress how important it is that you keep the Firewall on your computer active at all times. Without a firewall your computer is susceptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that
aren't actually innocent at all. Using IE-SPYAD to help block unwanted sites and activities

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer always has the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Update all security programs regularly - Make sure you update all the programs regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.

Remember to have only one (1) Firewall and one (1) Anti-Virus program running at any one time.

I would also suggest you read "So how did I get infected in the first place"?: by Tony Klein

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI