This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Trojan Horse BHO.IZO

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello and thanks in advance for your help.

Today, AVG FREE detected the virus Trojan Horse BHO.IZO

in the following files:

"C:\System Volume Information\_restore{A7AC940B-0789-4D34-9930-4FB47791E0A9}\RP177\A0058946.dll
"C:\System Volume Information\_restore{A7AC940B-0789-4D34-9930-4FB47791E0A9}\RP177\A0058946.dll
"C:\System Volume Information\_restore{A7AC940B-0789-4D34-9930-4FB47791E0A9}\RP177\A0058948.dll

it was detected "on open" of process system root\system32\cidaemon.exe process ID 7624

Just like user "kuchi" said in his post, I can't find any info on this virus so I'm not sure what to do next. :scratch:

please help!?

as suggested to user "kuchi" by "jpshortstuff" I've downloaded DDS.exe and I'm including this log.

__________________________________________________________________________

DDS.txt

DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 17:32:15.12 on 19/06/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.376 [GMT -6:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\HDD Thermometer\HDD Thermometer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Michelle\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
mStart Page = about:blank
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {238D3403-0761-4B4D-851C-050A3A0AC40A} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [RSD_HDDThermo] c:\program files\hdd thermometer\HDD Thermometer.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\citrus~1.lnk - c:\program files\citrus alarm clock\Citrus Alarm Clock.exe
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll

============= SERVICES / DRIVERS ===============

R1 atitray;atitray;c:\program files\radeon omega drivers\v3.8.252\ati tray tools\atitray.sys [2005-11-13 12032]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-2 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-3-2 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-2 108552]
R1 GizmoDrv;Gizmo Virtual Drive Device Driver;c:\windows\system32\drivers\gizmodrv.sys [2008-1-24 16787]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-2 298776]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-2-21 1373480]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S1 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\windows\installer\MSI3B.tmp [2009-5-16 189696]
S3 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-3-9 425080]
S3 jswimd;jswimd Service;c:\windows\system32\drivers\jswimd.sys –> c:\windows\system32\drivers\jswimd.sys [?]
S3 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2008-7-21 193888]
S3 UCharger;Energizer Usb Charger Driver;c:\windows\system32\drivers\UCharger.sys [2007-5-15 13765]
S4 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-4 98304]
S4 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-4 118784]

=============== Created Last 30 ================

2009-06-10 00:41 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 00:41 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-06-10 00:41 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-06-10 00:41 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-06-07 21:10 –d—– C:\PerfLogs
2009-06-06 23:30 –d—– c:\windows\system32\custom matrices
2009-06-06 23:29 –d—– c:\windows\system32\QuickTime
2009-06-06 23:29 –d—– c:\windows\system32\C2MP
2009-06-05 04:35 –d—– c:\program files\ScreenPrint32 v3
2009-06-03 14:17 –d—– c:\program files\iPod
2009-06-03 14:16 –d—– c:\program files\iTunes
2009-05-28 10:51 3,554,816 a——- c:\windows\system32\ffdshow.ax
2009-05-28 10:41 4,472,538 a——- c:\windows\system32\libavcodec.dll
2009-05-27 19:56 –d—– c:\docume~1\michelle\applic~1\Flickr
2009-05-27 19:55 –d—– c:\program files\Flickr Uploadr
2009-05-26 17:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a——- c:\windows\system32\QuickTime.qts
2009-05-25 18:39 –d—– c:\documents and settings\michelle\.housecall6.6
2009-05-25 10:38 830,004 a——- c:\windows\system32\ff_x264.dll
2009-05-22 04:19 –d—– c:\docume~1\michelle\applic~1\MilkShape 3D 1.x.x
2009-05-21 07:27 210,944 a——- c:\windows\system32\Msvcrt10.dll
2009-05-21 07:27 152,848 a——- c:\windows\system32\Comdlg32.ocx
2009-05-21 07:27 –d—– c:\program files\Plugin Commander Light
2009-05-21 03:00 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2


==================== Find3M ====================


2009-06-05 04:35 73,216 a——- c:\windows\ST6UNST.EXE
2009-06-05 04:35 249,856 ——– c:\windows\Setup1.exe
2009-05-18 02:24 83,968 a——- c:\windows\system32\ac3config.exe
2009-05-17 17:37 557,469 a——- c:\windows\system32\libmplayer.dll
2009-05-17 05:28 410,984 a——- c:\windows\system32\deploytk.dll
2009-05-12 23:15 915,456 a——- c:\windows\system32\wininet.dll
2009-05-07 09:32 345,600 a——- c:\windows\system32\localspl.dll
2009-05-01 09:25 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-05-01 09:25 325,896 a——- c:\windows\system32\drivers\avgldx86.sys
2009-05-01 09:25 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-04-24 02:11 46,713,993 a——- c:\windows\system32\xa38872295.exe
2009-04-24 02:11 46,713,993 a——- c:\windows\system32\xa38863412.exe
2009-04-21 10:38 328,334 a——- c:\windows\system32\ff_kernelDeint.dll
2009-04-21 10:08 425,040 a——- c:\windows\system32\TomsMoComp_ff.dll
2009-04-21 09:54 146,098 a——- c:\windows\system32\libmpeg2_ff.dll
2009-04-21 09:52 828,029 a——- c:\windows\system32\xvidcore.dll
2009-04-17 06:26 1,847,168 a——- c:\windows\system32\win32k.sys
2009-04-15 08:51 585,216 a——- c:\windows\system32\rpcrt4.dll
2009-04-02 08:23 98,304 a——- c:\windows\system32\ff_wmv9.dll
2009-04-02 08:21 84,480 a——- c:\windows\system32\ff_vfw.dll
2008-02-19 02:02 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat
2007-03-21 13:31 272,109 a——- c:\program files\hdd_thermometer_v1.3.exe
2007-01-21 13:10 8 —shr– c:\windows\system32\A6EF669AEE.sys

============= FINISH: 17:33:28.44 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hi mad rian, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Are you experiencing any problems with your computer?

We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time is more than one is listed, into the "Suspicious files to scan" box on the top of the page:
  • Please ensure the scan is complete and the reults saved before submitting the next one

    c:\windows\system32\cidaemon.exe
    c:\windows\system32\xa38872295.exe
    c:\windows\system32\xa38863412.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please post back with the VirScan results.

Thanks
Hello, thanks for your prompt reply. I was able to get results for the file cidaemon.exe, but the other two files, xa38863412.exe and xa38872295.exe, were both too big for me to upload. Both files are 45, 620 KB.

Results for cidaemon.exe:

VirSCAN.org Scanned Report :
Scanned time : 2009/06/22 03:28:18 (MDT)
Scanner results: All Scanners reported not find malware!
File Name : cidaemon.exe
File Size : 8192 byte
File Type : PE32 executable for MS Windows (console) Intel 80386 32-bit
MD5 : 582304f6f1946fa5068cf143d729d7ed
SHA1 : 3908ac69a90bfc240fd52da26bfb722066ee650b
Online report : http://virscan.org/report/21ee9720a4f8c559…5ab396d59a.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090622152941 2009-06-22 2.37 -
AhnLab V3 2009.06.22.01 2009.06.22 2009-06-22 0.86 -
AntiVir 8.2.0.193 7.1.4.121 2009-06-22 0.16 -
Antiy 2.0.18 20090622.2564461 2009-06-22 0.12 -
Arcavir 2009 200906220749 2009-06-22 0.04 -
Authentium 5.1.1 200906212052 2009-06-21 1.08 -
AVAST! 4.7.4 090621-0 2009-06-21 0.00 -
AVG 8.5.286 270.12.85/2193 2009-06-22 3.75 -
BitDefender 7.81008.3440062 7.26125 2009-06-22 3.20 -
CA (VET) 9.0.0.143 31.6.6569 2009-06-20 5.57 -
ClamAV 0.95.1 9492 2009-06-21 0.01 -
Comodo 3.9 1391 2009-06-22 0.77 -
CP Secure 1.1.0.715 2009.06.21 2009-06-21 11.94 -
Dr.Web 4.44.0.9170 2009.06.22 2009-06-22 5.13 -
F-Prot 4.4.4.56 20090621 2009-06-21 1.13 -
F-Secure 5.51.6100 2009.06.22.03 2009-06-22 0.06 -
Fortinet 2.81-3.117 10.520 2009-06-21 0.20 -
GData 19.5984/19.372 20090622 2009-06-22 4.34 -
ViRobot 20090619 2009.06.19 2009-06-19 0.41 -
Ikarus T3.1.01.59 2009.06.22.72903 2009-06-22 3.51 -
JiangMin 11.0.706 2009.06.22 2009-06-22 2.05 -
Kaspersky 5.5.10 2009.06.22 2009-06-22 0.06 -
KingSoft 2009.2.5.15 2009.6.22.14 2009-06-22 0.54 -
McAfee 5.3.00 5653 2009-06-21 3.34 -
Microsoft 1.4803 2009.06.21 2009-06-21 4.88 -
mks_vir 2.01 2009.06.22 2009-06-22 3.16 -
Norman 6.01.09 6.01.00 2009-06-19 4.01 -
Panda 9.05.01 2009.06.21 2009-06-21 1.60 -
Trend Micro 8.700-1004 6.213.00 2009-06-22 0.02 -
Quick Heal 10.00 2009.06.22 2009-06-22 1.02 -
Rising 20.0 21.35.02.00 2009-06-22 1.07 -
Sophos 2.87.1 4.42 2009-06-22 2.57 -
Sunbelt 5201 5201 2009-06-21 0.91 -
Symantec 1.3.0.24 20090621.039 2009-06-21 0.05 -
nProtect 20090622.02 4386075 2009-06-22 6.27 -
The Hacker 6.3.4.3 v00350 2009-06-20 1.41 -
VBA32 3.12.10.7 20090621.1545 2009-06-21 2.45 -
VirusBuster 4.5.11.10 10.107.20/1648063 2009-06-21 2.02 -
P.S. Symptoms My system is running extremely slow as if some program is taking up all the memory, when my computer connects to the internet I get a warning that no firewall is turned on. the warning disappears after a second or two. I think some of my windows settings are getting reset to default settings, for example System Restore was turned on (I normally have it turned off). Also, my WIndows Event log and Application log are no longer recording new information. Also, in internet explorer, if I click on a new tab, it takes a really long time for that tab to open. Thanks again!
Hi mad rian,



Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop

Please post the Gmer log.

Thanks
GMER LOG:

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-23 00:42:31
Windows 5.1.2600 Service Pack 3


—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\Explorer.EXE[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [02302F20] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [02302C90] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [02302CF0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [02302CC0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

—- EOF - GMER 1.0.15 —-
Hi mad rian,

µTorrent
You have µTorrent, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall µTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • combofix log

How is the computer?

Thanks
Hello,

My computer is still running really, REALLY slow. Slow to startup, slow to open programs, even if I'm just opening an explorer window its slow to load up all the thumbnails and icons. Its been this way for weeks now. Another symptom I just remembered (i've just sort of gotten used to all these weird windows quirks, so much so that I don't even notice them anymore) When I open explorer, it no longer lists files and folders alphabetically, its like the files are sorted by reverse "Date File Created" or "Date Modified" or something….the folders aren't even grouped together, they're all mixed in with the files. Very strange.

ComboFix: getting combofix to run and make a log took a lot of work! I'm not sure if the details of that are useful to you, but I'm including them just in case, as well as the combofix log.

I downloaded the file from Link 1 and saved it to my desktop, using the tray icon I exited AVG Free, and then ran ComboFIx. A window popped up saying that AVG was still running, so I used Win. Task Manager and terminated 3 AVG processes that were still running. I hit OK on the ComboFix warning window, and another warning popped up saying that AVG was STILL running so I terminated combofix. I tried using the Win. Services console to disable the AVG watch dog service, ComboFix still complained. I tried removing AVG from the startup list and rebooting. Upon restart, 3 AVG processes still showed up in Win. Task Manager (even though AVG was not running) and ComboFix still wouldn't run. I tried uninstalling AVG, doing a repair install of AVG…both failed. I ended up going to the AVG forums and downloading a "remove AVG" utility and using that to get rid of AVG Free.

After that, I was finally able to run ComboFix, and it installed the Windows Recovery Console.


Is it possible that my AVG FREE was damaged by malware??

After ComboFix finished, I reinstalled AVG Free (the most recent version) and thats where I'm at. yeeshk!

ComboFix created 2 txt files, log.txt saved in a temp folder and ComboFix.txt, saved on C:\. They look similar. Not sure if you wanted me to post the log in this reply or attach the text file so……i'm posting log.txt and attaching ComboFix.txt (without word wrap)

thanks!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

COMBOFIX LOG

ComboFix 09-06-22.0E - 23/06/2009 16:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.529 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\M~\Application Data\.#
c:\documents and settings\M~\Application Data\.#\MBX@704@384170.###
c:\documents and settings\M~\Application Data\.#\MBX@704@3841A0.###
c:\documents and settings\M~\Application Data\.#\MBX@704@3841D0.###
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\SF.dll
c:\windows\system32\tmp.reg

.
((((((((((((((((((((((((( Files Created from 2009-05-23 to 2009-06-23 )))))))))))))))))))))))))))))))
.

2009-06-22 23:48 . 2009-06-22 23:48 ——– d—–w- c:\program files\Common Files\Corel
2009-06-22 23:48 . 2009-06-22 23:48 ——– d—–w- c:\program files\Common Files\Protexis
2009-06-22 23:48 . 2009-06-22 23:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Corel
2009-06-22 08:48 . 2009-06-22 23:51 88 –sh–r- c:\documents and settings\All Users\Application Data\A6EF669AEE.sys
2009-06-22 08:48 . 2009-06-22 23:51 2516 –sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-06-10 06:41 . 2009-04-30 21:22 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 06:41 . 2009-04-30 21:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 06:41 . 2009-04-30 21:22 1985024 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2009-06-10 06:41 . 2009-04-30 21:22 11064832 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2009-06-08 03:10 . 2009-06-08 07:47 ——– d—–w- C:\PerfLogs
2009-06-07 05:30 . 2009-06-07 05:30 ——– d—–w- c:\windows\system32\custom matrices
2009-06-07 05:29 . 2009-06-07 05:30 ——– d—–w- c:\windows\system32\C2MP
2009-06-07 05:29 . 2009-06-07 05:29 ——– d—–w- c:\windows\system32\QuickTime
2009-06-05 10:35 . 2009-06-05 10:36 ——– d—–w- c:\program files\ScreenPrint32 v3
2009-06-03 20:17 . 2009-06-03 20:17 ——– d—–w- c:\program files\iPod
2009-06-03 20:16 . 2009-06-03 20:17 ——– d—–w- c:\program files\iTunes
2009-06-03 20:02 . 2009-06-03 20:02 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-05-28 16:41 . 2009-05-28 16:41 4472538 —-a-w- c:\windows\system32\libavcodec.dll
2009-05-28 01:56 . 2009-05-28 01:56 ——– d—–w- c:\documents and settings\M~\Local Settings\Application Data\Flickr
2009-05-28 01:56 . 2009-05-28 01:56 ——– d—–w- c:\documents and settings\M~\Application Data\Flickr
2009-05-28 01:55 . 2009-06-12 20:52 ——– d—–w- c:\program files\Flickr Uploadr
2009-05-26 00:39 . 2009-05-26 00:39 ——– d—–w- c:\documents and settings\M~\.housecall6.6
2009-05-25 16:38 . 2009-05-25 16:38 830004 —-a-w- c:\windows\system32\ff_x264.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-23 22:34 . 2007-01-25 09:27 ——– d—–w- c:\program files\hiHO aWAaay
2009-06-23 22:31 . 2008-02-19 07:58 ——– d—–w- c:\documents and settings\M~\Application Data\Skype
2009-06-23 22:31 . 2008-02-19 08:02 ——– d—–w- c:\documents and settings\M~\Application Data\skypePM
2009-06-23 22:31 . 2007-03-21 19:31 ——– d—–w- c:\documents and settings\All Users\Application Data\HDD Thermometer
2009-06-23 22:31 . 2008-02-21 07:23 ——– d—–w- c:\documents and settings\M~\Application Data\WTablet
2009-06-23 22:29 . 2009-03-02 13:47 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-06-23 09:14 . 2009-03-23 16:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-22 23:46 . 2007-01-20 11:33 ——– d—–w- c:\program files\Corel
2009-06-22 08:48 . 2007-01-21 19:10 ——– d—–w- c:\documents and settings\M~\Application Data\Corel
2009-06-22 08:46 . 2007-03-15 09:03 ——– d—–w- c:\documents and settings\M~\Application Data\uTorrent
2009-06-16 20:34 . 2009-05-17 12:06 1 —-a-w- c:\documents and settings\M~\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-12 09:02 . 2007-01-28 07:30 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-12 08:49 . 2009-03-08 14:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-07 05:17 . 2007-01-22 04:28 ——– d—–w- c:\documents and settings\M~\Application Data\Apple Computer
2009-06-06 05:27 . 2009-02-19 09:46 ——– d—–w- c:\documents and settings\LocalService\Application Data\WTablet
2009-06-05 10:35 . 2007-06-13 07:00 249856 ——w- c:\windows\Setup1.exe
2009-06-05 10:35 . 2007-06-13 07:00 73216 —-a-w- c:\windows\ST6UNST.EXE
2009-06-03 20:17 . 2009-01-15 00:05 ——– d—–w- c:\program files\Common Files\Apple
2009-06-03 20:12 . 2009-01-15 00:06 ——– d—–w- c:\program files\QuickTime
2009-05-30 04:45 . 2009-05-16 14:43 ——– d—–w- c:\documents and settings\M~\Application Data\SolidDocuments
2009-05-30 00:57 . 2009-05-21 13:27 ——– d—–w- c:\program files\Plugin Commander Light
2009-05-22 10:23 . 2009-05-22 10:19 ——– d—–w- c:\documents and settings\M~\Application Data\MilkShape 3D 1.x.x
2009-05-21 10:16 . 2007-01-20 08:45 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-21 09:00 . 2009-05-21 09:00 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-05-20 05:04 . 2008-02-29 21:54 ——– d—–w- c:\program files\Common Files\Logishrd
2009-05-20 05:03 . 2008-02-29 21:54 ——– d—–w- c:\program files\Logitech
2009-05-20 04:51 . 2008-02-29 21:59 ——– d—–w- c:\documents and settings\All Users\Application Data\LogiShrd
2009-05-18 08:24 . 2009-05-18 08:24 83968 —-a-w- c:\windows\system32\ac3config.exe
2009-05-18 01:57 . 2008-04-06 04:33 31752 —-a-w- c:\documents and settings\M~\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-17 23:37 . 2009-05-17 23:37 557469 —-a-w- c:\windows\system32\libmplayer.dll
2009-05-17 18:17 . 2009-03-11 20:01 ——– d—–w- c:\program files\Google
2009-05-17 12:37 . 2009-05-17 11:32 ——– d—–w- c:\program files\OpenOffice.org 3
2009-05-17 11:41 . 2009-05-17 11:41 ——– d—–w- c:\documents and settings\M~\Application Data\OpenOffice.org
2009-05-17 11:33 . 2009-05-17 11:33 ——– d—–w- c:\program files\JRE
2009-05-17 11:28 . 2009-02-14 04:09 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-17 11:22 . 2007-01-24 23:36 ——– d—–w- c:\documents and settings\M~\Application Data\OpenOffice.org2
2009-05-16 14:39 . 2009-05-16 14:39 ——– d—–w- c:\program files\SolidDocuments
2009-05-16 14:38 . 2009-05-16 14:38 ——– d—–w- c:\documents and settings\All Users\Application Data\SolidDocuments
2009-05-16 13:07 . 2009-05-16 13:07 ——– d—–w- c:\program files\Common Files\DownloadManager
2009-05-13 05:15 . 2003-07-16 16:45 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 19:34 . 2009-05-07 19:33 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-07 15:32 . 2003-07-16 16:26 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-06 14:38 . 2009-05-06 14:23 ——– d—–w- c:\documents and settings\M~\Application Data\gtk-2.0
2009-04-25 02:08 . 2009-03-10 05:51 ——– d—–w- c:\program files\a-squared Free
2009-04-24 08:11 . 2009-04-24 08:11 46713993 —-a-w- c:\windows\system32\xa38872295.exe
2009-04-24 08:11 . 2009-04-24 08:11 46713993 —-a-w- c:\windows\system32\xa38863412.exe
2009-04-21 16:38 . 2009-04-21 16:38 328334 —-a-w- c:\windows\system32\ff_kernelDeint.dll
2009-04-21 16:08 . 2009-04-21 16:08 425040 —-a-w- c:\windows\system32\TomsMoComp_ff.dll
2009-04-21 15:54 . 2009-04-21 15:54 146098 —-a-w- c:\windows\system32\libmpeg2_ff.dll
2009-04-21 15:52 . 2009-04-21 15:52 828029 —-a-w- c:\windows\system32\xvidcore.dll
2009-04-17 12:26 . 2003-07-16 16:45 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2002-11-08 00:47 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-02 14:23 . 2009-04-02 14:23 98304 —-a-w- c:\windows\system32\ff_wmv9.dll
2009-04-02 14:21 . 2009-04-02 14:21 84480 —-a-w- c:\windows\system32\ff_vfw.dll
2007-03-21 19:31 . 2007-03-21 19:31 272109 —-a-w- c:\program files\hdd_thermometer_v1.3.exe
2007-01-21 19:10 . 2007-01-21 19:10 8 –sh–r- c:\windows\system32\A6EF669AEE.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RSD_HDDThermo"="c:\program files\HDD Thermometer\HDD Thermometer.exe" [2005-04-01 215040]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-02-07 21898024]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-12 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Citrus Alarm Clock.lnk - c:\program files\Citrus Alarm Clock\Citrus Alarm Clock.exe [2008-4-5 326656]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"PhotoshopElementsDeviceConnect"=2 (0x2)
"RasAuto"=3 (0x3)
"gusvc"=2 (0x2)
"AdobeActiveFileMonitor"=2 (0x2)
"Gizmo Central"=2 (0x2)
"aawservice"=3 (0x3)
"Maxtor Sync Service"=3 (0x3)
"LVCOMSer"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)
"JavaQuickStarterService"=3 (0x3)
"iPod Service"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"ACS"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 atitray;atitray;c:\program files\Radeon Omega Drivers\v3.8.252\ATI Tray Tools\atitray.sys [13/11/2005 5:43 PM 12032]
R1 GizmoDrv;Gizmo Virtual Drive Device Driver;c:\windows\system32\drivers\gizmodrv.sys [24/01/2008 4:30 AM 16787]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [21/02/2008 1:21 AM 1373480]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S1 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\windows\Installer\MSI3B.tmp [16/05/2009 9:07 AM 189696]
S3 jswimd;jswimd Service;c:\windows\system32\DRIVERS\jswimd.sys –> c:\windows\system32\DRIVERS\jswimd.sys [?]
S3 UCharger;Energizer Usb Charger Driver;c:\windows\system32\drivers\UCharger.sys [15/05/2007 8:43 AM 13765]
S4 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [04/10/2004 6:47 AM 98304]
S4 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [04/10/2004 5:40 AM 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-06-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-11 16:21]

2009-06-23 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-30 04:18]
.
- - - - ORPHANS REMOVED - - - -

Notify-avgrsstarter - avgrsstx.dll


.
——- Supplementary Scan ——-
.
mStart Page = about:blank
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-23 17:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SCPDFReadSpool]
"ImagePath"="c:\windows\Installer\MSI3B.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1214440339-920026266-854245398-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-06-23 17:11
ComboFix-quarantined-files.txt 2009-06-23 23:11

Pre-Run: 9,138,212,864 bytes free
Post-Run: 9,153,576,960 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptOut

207 — E O F — 2009-06-10 19:29

Attachments:

:scratch: one more thing! a new IE icon appeared on my desktop somewhere between running combofix and reinstalling AVG Free. Double clicking on it opens IE, right clicking on it and clicking properties opens up Internet Options. soo….its a shortcut but not a normal shortcut? it doesn't have the arrow icon overlay either. m
Hi mad rian,

a new IE icon appeared on my desktop somewhere between running combofix and reinstalling AVG Free. Double clicking on it opens IE, right clicking on it and clicking properties opens up Internet Options. soo….its a shortcut but not a normal shortcut? it doesn't have the arrow icon overlay either.

That's pretty much what it is. Somethings will have been reset to default so nothing to worry about.

When I open explorer, it no longer lists files and folders alphabetically, its like the files are sorted by reverse "Date File Created" or "Date Modified" or something….the folders aren't even grouped together,

Try this. Open Windows Explorer. In the right hand panel you will see various headings, Name, size, etc. Click on Type Is the display better now?



Let's see if we can find out about those files

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :file
    c:\windows\system32\A6EF669AEE.sys
    c:\windows\system32\xa38872295.exe
    c:\windows\system32\xa38863412.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Next

Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.


Next

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


And do a scan with this tool, it's quick.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Please post back with
  • SystemLook log
  • MBAM log
  • Both DDS logs

Thanks
Hello,

Since yesterdays scans, my system is running even slower!

For the DDS scan, you asked me to click yes when prompted for an optional scan….but there was no prompt!



SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 00:43 on 25/06/2009 by M~ (Administrator - Elevation successful)

========== file ==========

c:\windows\system32\A6EF669AEE.sys - File found and opened.
MD5: 0641A46F1E58529A42EAD4573A3A0861
Created at 19:10 on 21/01/2007
Modified at 19:10 on 21/01/2007
Size: 8 bytes
Attributes: -r-hs-
No version information available.

c:\windows\system32\xa38872295.exe - File found and opened.
MD5: 3A8402135BB15220721EA2023E7065D0
Created at 08:11 on 24/04/2009
Modified at 08:11 on 24/04/2009
Size: 46713993 bytes
Attributes: –a—
FileDescription: Wandering Willows 1.00 Installation
FileVersion: 1.00
CompanyName: Games
LegalCopyright: Games
Comments:

c:\windows\system32\xa38863412.exe - File found and opened.
MD5: 3A8402135BB15220721EA2023E7065D0
Created at 08:11 on 24/04/2009
Modified at 08:11 on 24/04/2009
Size: 46713993 bytes
Attributes: –a—
FileDescription: Wandering Willows 1.00 Installation
FileVersion: 1.00
CompanyName: Games
LegalCopyright: Games
Comments:

-=End Of File=-


Malwarebytes' Anti-Malware 1.38
Database version: 2332
Windows 5.1.2600 Service Pack 3

25/06/2009 1:09:25 AM
mbam-log-2009-06-25 (01-09-25).txt

Scan type: Quick Scan
Objects scanned: 91502
Time elapsed: 10 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 1:10:56.65 on 25/06/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.228 [GMT -6:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\M~\Desktop\dds.scr

============== Pseudo HJT Report ===============

mStart Page = about:blank
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {238D3403-0761-4B4D-851C-050A3A0AC40A} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [RSD_HDDThermo] c:\program files\hdd thermometer\HDD Thermometer.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\citrus~1.lnk - c:\program files\citrus alarm clock\Citrus Alarm Clock.exe
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll

============= SERVICES / DRIVERS ===============

R1 atitray;atitray;c:\program files\radeon omega drivers\v3.8.252\ati tray tools\atitray.sys [2005-11-13 12032]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-23 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-23 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-23 108552]
R1 GizmoDrv;Gizmo Virtual Drive Device Driver;c:\windows\system32\drivers\gizmodrv.sys [2008-1-24 16787]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-23 298776]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-2-21 1373480]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-6-25 38160]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S1 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\windows\installer\MSI3B.tmp [2009-5-16 189696]
S3 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-3-9 425080]
S3 jswimd;jswimd Service;c:\windows\system32\drivers\jswimd.sys –> c:\windows\system32\drivers\jswimd.sys [?]
S3 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2008-7-21 193888]
S3 UCharger;Energizer Usb Charger Driver;c:\windows\system32\drivers\UCharger.sys [2007-5-15 13765]
S4 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-4 98304]
S4 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-4 118784]

=============== Created Last 30 ================

2009-06-25 00:51 –d—– c:\docume~1\M~\applic~1\Malwarebytes
2009-06-25 00:51 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-25 00:51 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-25 00:51 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-06-25 00:51 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-23 17:18 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-06-23 17:18 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-06-23 17:18 327,688 a——- c:\windows\system32\drivers\avgldx86.sys
2009-06-23 17:18 –d—– c:\windows\system32\drivers\Avg
2009-06-23 17:09 -cd—– c:\windows\system32\dllcache\cache
2009-06-23 16:41 a-dshr– C:\cmdcons
2009-06-23 16:40 161,792 a——- c:\windows\SWREG.exe
2009-06-23 16:40 155,136 a——- c:\windows\PEV.exe
2009-06-23 16:40 98,816 a——- c:\windows\sed.exe
2009-06-22 17:48 –d—– c:\program files\common files\Corel
2009-06-22 17:48 –d—– c:\program files\common files\Protexis
2009-06-22 17:48 –d—– c:\docume~1\alluse~1\applic~1\Corel
2009-06-22 02:48 88 —shr– c:\docume~1\alluse~1\applic~1\A6EF669AEE.sys
2009-06-22 02:48 2,516 a–sh— c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-06-10 00:41 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 00:41 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-06-10 00:41 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-06-10 00:41 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-06-07 21:10 –d—– C:\PerfLogs
2009-06-06 23:30 –d—– c:\windows\system32\custom matrices
2009-06-06 23:29 –d—– c:\windows\system32\QuickTime
2009-06-06 23:29 –d—– c:\windows\system32\C2MP
2009-06-05 04:35 –d—– c:\program files\ScreenPrint32 v3
2009-06-03 14:17 –d—– c:\program files\iPod
2009-06-03 14:16 –d—– c:\program files\iTunes
2009-05-28 10:51 3,554,816 a——- c:\windows\system32\ffdshow.ax
2009-05-28 10:41 4,472,538 a——- c:\windows\system32\libavcodec.dll
2009-05-27 19:56 –d—– c:\docume~1\M~\applic~1\Flickr
2009-05-27 19:55 –d—– c:\program files\Flickr Uploadr
2009-05-26 17:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a——- c:\windows\system32\QuickTime.qts

==================== Find3M ====================

2009-06-05 04:35 73,216 a——- c:\windows\ST6UNST.EXE
2009-06-05 04:35 249,856 ——– c:\windows\Setup1.exe
2009-05-25 10:38 830,004 a——- c:\windows\system32\ff_x264.dll
2009-05-18 02:24 83,968 a——- c:\windows\system32\ac3config.exe
2009-05-17 17:37 557,469 a——- c:\windows\system32\libmplayer.dll
2009-05-17 05:28 410,984 a——- c:\windows\system32\deploytk.dll
2009-05-12 23:15 915,456 a——- c:\windows\system32\wininet.dll
2009-05-07 09:32 345,600 a——- c:\windows\system32\localspl.dll
2009-04-24 02:11 46,713,993 a——- c:\windows\system32\xa38872295.exe
2009-04-24 02:11 46,713,993 a——- c:\windows\system32\xa38863412.exe
2009-04-21 10:38 328,334 a——- c:\windows\system32\ff_kernelDeint.dll
2009-04-21 10:08 425,040 a——- c:\windows\system32\TomsMoComp_ff.dll
2009-04-21 09:54 146,098 a——- c:\windows\system32\libmpeg2_ff.dll
2009-04-21 09:52 828,029 a——- c:\windows\system32\xvidcore.dll
2009-04-17 06:26 1,847,168 a——- c:\windows\system32\win32k.sys
2009-04-15 08:51 585,216 a——- c:\windows\system32\rpcrt4.dll
2009-04-02 08:23 98,304 a——- c:\windows\system32\ff_wmv9.dll
2009-04-02 08:21 84,480 a——- c:\windows\system32\ff_vfw.dll
2008-02-19 02:02 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat
2007-03-21 13:31 272,109 a——- c:\program files\hdd_thermometer_v1.3.exe
2007-01-21 13:10 8 —shr– c:\windows\system32\A6EF669AEE.sys

============= FINISH: 1:12:09.90 ===============

📎Attach.txt
Hi mad rian,

Are your folders displaying correctly now?

I don't see any malware in the logs. The files seem to be related to a game Wandering Willows 1.00 Installation , Do you recognize it?

AVG can be a resource hog, did these slow downs start when you first starting using AVG?

You have a-squared Free Service installed as on demand scanner. MBAM is much better.

Lets uninstall GMER and have a look with something else.
  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as gmer_uninstall.bat
  • Change the Save as Type to All Files
  • and Save it in the folder where GMER.exe was saved
  • Once saved, double click on the gmer_uninstall.bat file. a MSDOS window will be displayed. That is normal.
Do Not copy the word CODE

@echo off
sc stop gmer
sc delete gmer
if exist %SystemRoot%\System32\drivers\gmer.sys del /f /q %SystemRoot%\System32\drivers\gmer.sys
if exist %SystemRoot%\gmer.dll del /f /q %SystemRoot%\gmer.dll
if exist %SystemRoot%\gmer.exe del /f /q %SystemRoot%\gmer.exe
if exist %SystemRoot%\gmer.ini del /f /q %SystemRoot%\gmer.ini
if exist %SystemRoot%\gmer_uninstall.cmd del /f /q %SystemRoot%\gmer_uninstall.cmd
if exist %SystemRoot%\gmer.bat del /f /q %SystemRoot%\gmer.bat
if exist %SystemRoot%\gmer.reg del /f /q %SystemRoot%\gmer.reg
if exist %SystemRoot%\gmer.log del /f /q %SystemRoot%\gmer.log
rd /s /q gmer
del /f /q gmer_uninstall.bat
exit

Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • Click Scan
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here



Thanks
Hello, The folder view in explorer was still messed up, but I fixed it another way.

Wandering Willows is a game I had installed (and thought I had uninstalled). Can I delete those two files now??

I've been using AVG for a few years now, so I don't think its the cause of the slowdown. My system's been slow for weeks….maybe even a couple of months now. Although……. i believe i installed an updated version a couple of months ago, and the version I just installed was another update. So maybe thats it??

Do you know of another reliable free or open-source anti-virus program that uses less resources??

Thanks, and here's the Rooter log:


Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully …
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 15 Model 2 Stepping 7, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Enabled
.
Internet Explorer 8.0.6001.18702
.
C:\ [Fixed-NTFS] .. ( Total:37 Go - Free:7 Go )
D:\ [CD_Rom]
.
Scan : 17:16.19
Path : C:\Documents and Settings\M~\Desktop\Rooter.exe
User : M~ ( Administrator -> YES )
.
———————-\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (652)
______ \??\C:\WINDOWS\system32\csrss.exe (704)
______ \??\C:\WINDOWS\system32\winlogon.exe (728)
______ C:\WINDOWS\system32\services.exe (776)
______ C:\WINDOWS\system32\lsass.exe (788)
______ C:\WINDOWS\system32\svchost.exe (948)
______ C:\WINDOWS\system32\svchost.exe (1052)
______ C:\WINDOWS\System32\svchost.exe (1164)
______ C:\WINDOWS\system32\svchost.exe (1200)
______ C:\WINDOWS\System32\svchost.exe (1284)
______ C:\WINDOWS\System32\wudfhost.exe (1440)
______ C:\WINDOWS\system32\svchost.exe (1508)
______ C:\WINDOWS\system32\spoolsv.exe (1776)
______ C:\WINDOWS\Explorer.EXE (1936)
______ C:\WINDOWS\system32\svchost.exe (200)
______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (248)
______ C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (392)
______ c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (424)
______ C:\WINDOWS\system32\svchost.exe (472)
______ C:\WINDOWS\system32\Wacom_Tablet.exe (1188)
______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (1424)
______ C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe (1420)
______ C:\WINDOWS\system32\Wacom_Tablet.exe (1492)
______ C:\PROGRA~1\AVG\AVG8\avgnsx.exe (1500)
______ C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (1944)
______ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (1996)
______ C:\PROGRA~1\AVG\AVG8\avgtray.exe (1028)
______ C:\Program Files\HDD Thermometer\HDD Thermometer.exe (1880)
______ C:\WINDOWS\system32\ctfmon.exe (372)
______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (692)
______ C:\WINDOWS\System32\alg.exe (2484)
______ C:\Program Files\Internet Explorer\iexplore.exe (3552)
______ C:\Program Files\Internet Explorer\iexplore.exe (3692)
______ C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (2900)
______ C:\Program Files\Internet Explorer\iexplore.exe (1484)
______ C:\Documents and Settings\M~\Desktop\Rooter.exe (3888)
.
———————-\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:39999504384)
.
———————-\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\Google Software Updater.job
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\WGASetup.job
.
———————-\\ Registry
.
.
———————-\\ Files & Folders
.
C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11\keygen.exe
C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11.0.016\keygen.exe
C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11.0.016 Final incl. key\keygen.exe
C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter v11 [2009] [CORE.Keygen] [ENG] [Arx]\Keygen\keygen.exe
==> Cracks & Keygens <==
.
———————-\\ Scan completed at 17:16.58
.
C:\Rooter$\Rooter_1.txt - (25/06/2009 | 17:16.58).c
Hi mad rian,


The folder view in explorer was still messed up, but I fixed it another way.

How? Just curious.

Yes we can remove those files.

Please read THIS

Keygens and cracks, I'm surprised you don't have more problems. These are a very good source of malware.

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Files
    C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11\keygen.exe
    C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11.0.016\keygen.exe
    C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11.0.016 Final incl. key\keygen.exe
    C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter v11 [2009] [CORE.Keygen] [ENG] [Arx]\Keygen\keygen.exe
    c:\windows\system32\xa38872295.exe
    c:\windows\system32\xa38863412.exe
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

I don't know about Avira firsthand but Avast is generally very light on resources.

Avast
Help and support can be found here Avast Forum
Antivir PersonalEditionClassic
Help and support can be found hereAvira Personal Support Forum

I suggest you download one of the above free antvirus programs. Then disconnect completly from the internet, pull the plug on the moden if necessary. Uninstall AVG and see how the computer is offline. Install your new AV and post back.

Please post back with the OTM log.

Thanks
hello,

file display fix: In explorer, while looking at a folder, I set up the view the way I wanted ("Details" mode, sorted by Name) then went to Tools>>Folder Options>>View and clicked "apply to all folders" . I'll still have to change the view in some folders, for example today I changed the view in Control Panel back to "Icons" mode, which I think is the default. Also, in Tools>>Folder Options>>View>>Advanced Settings I have the box "Remember each folders' view settings" checked so next time i open control panel, it should still display in Icons mode.

keygens, etc.: I've uninstalled the offending software and deleted all associated files, folders, keygens, executables, etc.

AV software: I've uninstalled AVG Free and installed Avira AntiVirus personal addition, I'll let you know next post how that affects system performance

OTM logs (I had to run it twice):

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
File/Folder C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11\keygen.exe not found.
File/Folder C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11.0.016\keygen.exe not found.
File/Folder C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11.0.016 Final incl. key\keygen.exe not found.
File/Folder C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter v11 [2009] [CORE.Keygen] [ENG] [Arx]\Keygen\keygen.exe not found.
c:\windows\system32\xa38872295.exe moved successfully.
c:\windows\system32\xa38863412.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: M~
->Temp folder emptied: 1781222 bytes
->Temporary Internet Files folder emptied: 23773753 bytes
->Java cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

%systemdrive% .tmp files removed: 0 bytes
C:\WINDOWS\msdownld.tmp folder deleted successfully.
%systemroot% .tmp files removed: 3437758 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 109080 bytes

RecycleBin emptied: 421963 bytes

Total Files Cleaned = 28.19 mb


OTM by OldTimer - Version 3.0.0.2 log created on 06262009_151350

Files moved on Reboot…

Registry entries deleted on Reboot…

-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-\|/-/|\-

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11\keygen.exe moved successfully.
C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11.0.016\keygen.exe moved successfully.
C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter 11.0.016 Final incl. key\keygen.exe moved successfully.
C:\DOCUME~1\M~\Desktop\torrents\done!\Corel Painter v11 [2009] [CORE.Keygen] [ENG] [Arx]\Keygen\keygen.exe moved successfully.
File/Folder c:\windows\system32\xa38872295.exe not found.
File/Folder c:\windows\system32\xa38863412.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: M~
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 1136305 bytes
->Java cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 109080 bytes

RecycleBin emptied: 8 bytes

Total Files Cleaned = 1.22 mb


OTM by OldTimer - Version 3.0.0.2 log created on 06262009_152308

Files moved on Reboot…

Registry entries deleted on Reboot…

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI