This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hard drive space dissapearing, moving slowly

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all, My laptop here (Dell Latitude X300) is doing some odd things. For one thing it gets slow; when it starts up it's fine but after a while it gets bogged down and you can't use more than one application at a time without everything freezing and not responding. Secondly, the hard drive space is dissapearing, sometimes slowly other times rapidly. I had over 9 gigs free three days ago and now I'm down to 2.87; I haven't downloaded a thing. Lastly, the computer refuses to shut down properly. If it's not doing anything like playing music, it'll go to the standby screen where it will stay and freeze. I have since cleaned the registry and if i go directly to shut down it responds, but so far it hasn't gone to the standby screen since. I have no idea what to do, and I have a very bad feeling that my system has been compromised. I'm not that computer saavy, but I have my hijackthis log and an HDGraph. HDGraph is telling me that AVG8 is using something close to 10 gigs, which seems incredibly off to me, but again I don't really know. Any help would be greatly appreciated. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:45:06 PM, on 7/12/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file) O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file) O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file) O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe – End of file - 5422 bytes
Hi there,

Welcome to WTT.


OK firstly, I need you to print out each post I make so that you can refer to it while we fix your computer. I also need you to follow my instructions in the order that they are given. If however, you cannot carry out one of them, please continue on with the next and let me know what you were unsuccessful with.

Please ensure you have word wrap turned off in Notepad. To do this, open Notepad, choose Format, then ensure Word Wrap is Un-checked. (Word Wrap makes reading your logs difficult).

Next, I would like to make sure that you can view hidden files and folders;
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading SELECT Show hidden files and folders.
  • UNCHECK the Hide protected operating system files (recommended) option.
  • UNCHECK the Hide extensions for known file types option.
  • Click Yes to confirm.
  • Click OK.
Now there is nothing really showing in your log, so lets have a better look. Please uninstall uTorrent, and any other P2P programs before continuing. Malware can use these programs as a means of downloading additional malware without your knowing.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Download the This EXE file. Save it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click the randomly named EXE file. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • Click the Save… button, and save the log as GMER-1.log
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • Click on the Save… button again, and save it this time as "GMER-2.log"
If for some reason the program hangs during the second scan, post me the contents of the first log. If it doesn't hang, then just post me the contents of the second log.

Note: Use Notepad to open the logs so you can copy them in here.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Download DDS and save it to your desktop from here or here or here.

[external image: Posted Image]

Disable any script blocking software, and then double click dds.scr to run the tool.
  • When done, DDS will open two logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.
Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


So in your next reply, please include the following logs:
  • The contents of the GMER log
  • The contents of DDS.txt
  • Attach.txt as an attachment
Please make a separate post for each of the two logs.

Regards,
RatHat
Forgot to add for you to do this first, before running anything else:

Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.
Rathat

here are the logs you requested

GMER-2 Log

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-13 00:40:19
Windows 5.1.2600 Service Pack 2


—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe[388] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 00E02B80
.text C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe[388] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 00E02B3D
.text C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe[388] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 00E02B01
.text C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe[388] WS2_32.dll!send 71AB428A 5 Bytes JMP 00E02972
.text C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe[388] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 00E02A64
.text C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe[388] WS2_32.dll!recv 71AB615A 5 Bytes JMP 00E029AA
.text C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe[388] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 00E029E2
.text C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe[388] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00E02AE6
.text C:\WINDOWS\Explorer.EXE[592] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 01442B80
.text C:\WINDOWS\Explorer.EXE[592] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 01442B3D
.text C:\WINDOWS\Explorer.EXE[592] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 01442B01
.text C:\WINDOWS\Explorer.EXE[592] WS2_32.dll!send 71AB428A 5 Bytes JMP 01442972
.text C:\WINDOWS\Explorer.EXE[592] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 01442A64
.text C:\WINDOWS\Explorer.EXE[592] WS2_32.dll!recv 71AB615A 5 Bytes JMP 014429AA
.text C:\WINDOWS\Explorer.EXE[592] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 014429E2
.text C:\WINDOWS\Explorer.EXE[592] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 01442AE6
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1456] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 06332B80
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1456] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 06332B3D
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1456] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 06332B01
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1456] WS2_32.dll!send 71AB428A 5 Bytes JMP 06332972
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1456] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 06332A64
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1456] WS2_32.dll!recv 71AB615A 5 Bytes JMP 063329AA
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1456] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 063329E2
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1456] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 06332AE6
.text C:\Documents and Settings\—–\Desktop\8xgoiml5.exe[1560] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 01662B80
.text C:\Documents and Settings\—–\Desktop\8xgoiml5.exe[1560] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 01662B3D
.text C:\Documents and Settings\—–\Desktop\8xgoiml5.exe[1560] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 01662B01
.text C:\Documents and Settings\—–\Desktop\8xgoiml5.exe[1560] WS2_32.dll!send 71AB428A 5 Bytes JMP 01662972
.text C:\Documents and Settings\—–\Desktop\8xgoiml5.exe[1560] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 01662A64
.text C:\Documents and Settings\—–\Desktop\8xgoiml5.exe[1560] WS2_32.dll!recv 71AB615A 5 Bytes JMP 016629AA
.text C:\Documents and Settings\—–\Desktop\8xgoiml5.exe[1560] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 016629E2
.text C:\Documents and Settings\—–\Desktop\8xgoiml5.exe[1560] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 01662AE6
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1616] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 011A2B80
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1616] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 011A2B3D
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1616] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 011A2B01
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1616] WS2_32.dll!send 71AB428A 5 Bytes JMP 011A2972
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1616] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 011A2A64
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1616] WS2_32.dll!recv 71AB615A 5 Bytes JMP 011A29AA
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1616] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 011A29E2
.text C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe[1616] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 011A2AE6
.text C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe[1644] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 01082B80
.text C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe[1644] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 01082B3D
.text C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe[1644] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 01082B01
.text C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe[1644] WS2_32.dll!send 71AB428A 5 Bytes JMP 01082972
.text C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe[1644] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 01082A64
.text C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe[1644] WS2_32.dll!recv 71AB615A 5 Bytes JMP 010829AA
.text C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe[1644] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 010829E2
.text C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe[1644] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 01082AE6
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1668] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 011E2B80
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1668] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 011E2B3D
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1668] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 011E2B01
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1668] WS2_32.dll!send 71AB428A 5 Bytes JMP 011E2972
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1668] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 011E2A64
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1668] WS2_32.dll!recv 71AB615A 5 Bytes JMP 011E29AA
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1668] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 011E29E2
.text C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe[1668] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 011E2AE6
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[1912] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 01012B80
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[1912] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 01012B3D
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[1912] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 01012B01
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[1912] WS2_32.dll!send 71AB428A 5 Bytes JMP 01012972
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[1912] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 01012A64
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[1912] WS2_32.dll!recv 71AB615A 5 Bytes JMP 010129AA
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[1912] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 010129E2
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[1912] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 01012AE6
.text C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe[1960] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 014E2B80
.text C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe[1960] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 014E2B3D
.text C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe[1960] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 014E2B01
.text C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe[1960] WS2_32.dll!send 71AB428A 5 Bytes JMP 014E2972
.text C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe[1960] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 014E2A64
.text C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe[1960] WS2_32.dll!recv 71AB615A 5 Bytes JMP 014E29AA
.text C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe[1960] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 014E29E2
.text C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe[1960] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 014E2AE6
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1996] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 00EE2B80
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1996] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 00EE2B3D
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1996] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 00EE2B01
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1996] WS2_32.dll!send 71AB428A 5 Bytes JMP 00EE2972
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1996] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 00EE2A64
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1996] WS2_32.dll!recv 71AB615A 5 Bytes JMP 00EE29AA
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1996] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 00EE29E2
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1996] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00EE2AE6
.text C:\WINDOWS\System32\alg.exe[2260] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 00802B80
.text C:\WINDOWS\System32\alg.exe[2260] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 00802B3D
.text C:\WINDOWS\System32\alg.exe[2260] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 00802B01
.text C:\WINDOWS\System32\alg.exe[2260] WS2_32.dll!send 71AB428A 5 Bytes JMP 00802972
.text C:\WINDOWS\System32\alg.exe[2260] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 00802A64
.text C:\WINDOWS\System32\alg.exe[2260] WS2_32.dll!recv 71AB615A 5 Bytes JMP 008029AA
.text C:\WINDOWS\System32\alg.exe[2260] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 008029E2
.text C:\WINDOWS\System32\alg.exe[2260] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 00802AE6
.text C:\Program Files\Bonjour\mDNSResponder.exe[2568] WS2_32.dll!send 71AB428A 5 Bytes JMP 007C2972
.text C:\Program Files\Bonjour\mDNSResponder.exe[2568] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 007C2A64
.text C:\Program Files\Bonjour\mDNSResponder.exe[2568] WS2_32.dll!recv 71AB615A 5 Bytes JMP 007C29AA
.text C:\Program Files\Bonjour\mDNSResponder.exe[2568] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 007C29E2
.text C:\Program Files\Bonjour\mDNSResponder.exe[2568] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 007C2AE6
.text C:\Program Files\Bonjour\mDNSResponder.exe[2568] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 007C2B80
.text C:\Program Files\Bonjour\mDNSResponder.exe[2568] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 007C2B3D
.text C:\Program Files\Bonjour\mDNSResponder.exe[2568] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 007C2B01
.text C:\WINDOWS\system32\wuauclt.exe[2776] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 022A2B80
.text C:\WINDOWS\system32\wuauclt.exe[2776] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 022A2B3D
.text C:\WINDOWS\system32\wuauclt.exe[2776] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 022A2B01
.text C:\WINDOWS\system32\wuauclt.exe[2776] WS2_32.dll!send 71AB428A 5 Bytes JMP 022A2972
.text C:\WINDOWS\system32\wuauclt.exe[2776] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 022A2A64
.text C:\WINDOWS\system32\wuauclt.exe[2776] WS2_32.dll!recv 71AB615A 5 Bytes JMP 022A29AA
.text C:\WINDOWS\system32\wuauclt.exe[2776] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 022A29E2
.text C:\WINDOWS\system32\wuauclt.exe[2776] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 022A2AE6
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[3292] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 020E2B80
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[3292] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 020E2B3D
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[3292] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 020E2B01
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[3292] WS2_32.dll!send 71AB428A 5 Bytes JMP 020E2972
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[3292] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 020E2A64
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[3292] WS2_32.dll!recv 71AB615A 5 Bytes JMP 020E29AA
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[3292] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 020E29E2
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[3292] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 020E2AE6
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3360] WS2_32.dll!send 71AB428A 5 Bytes JMP 011C2972
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3360] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 011C2A64
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3360] WS2_32.dll!recv 71AB615A 5 Bytes JMP 011C29AA
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3360] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 011C29E2
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3360] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 011C2AE6
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3360] ADVAPI32.dll!CryptDestroyKey 77DEA064 7 Bytes JMP 011C2B80
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3360] ADVAPI32.dll!CryptDecrypt 77DEA2D1 7 Bytes JMP 011C2B3D
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[3360] ADVAPI32.dll!CryptEncrypt 77DF0900 7 Bytes JMP 011C2B01

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\ACPI \Device\00000041 871AD1C0

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\ACPI \Device\00000042 871AD1C0
Device \Driver\ACPI \Device\00000050 871AD1C0
Device \Driver\ACPI \Device\00000051 871AD1C0
Device \Driver\ACPI \Device\00000044 871AD1C0
Device \Driver\ACPI \Device\00000045 871AD1C0
Device \Driver\ACPI \Device\00000052 871AD1C0
Device \Driver\ACPI \Device\00000046 871AD1C0
Device \Driver\ACPI \Device\00000053 871AD1C0
Device \Driver\ACPI \Device\00000054 871AD1C0
Device \Driver\ACPI \Device\00000047 871AD1C0
Device \Driver\ACPI \Device\00000061 871AD1C0
Device \Driver\ACPI \Device\00000048 871AD1C0

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\ACPI \Device\00000049 871AD1C0
Device \Driver\ACPI \Device\00000058 871AD1C0
Device \Driver\ACPI \Device\00000059 871AD1C0
Device \Driver\ACPI \Device\00000066 871AD1C0
Device \Driver\ACPI \Device\00000068 871AD1C0
Device \Driver\ACPI \Device\00000069 871AD1C0
Device \Driver\ACPI \Device\00000084 871AD1C0
Device \Driver\ACPI \Device\0000004b 871AD1C0
Device \Driver\ACPI \Device\00000086 871AD1C0
Device \Driver\ACPI \Device\0000005a 871AD1C0
Device \Driver\ACPI \Device\0000005b 871AD1C0
Device \Driver\ACPI \Device\0000004e 871AD1C0
Device \Driver\ACPI \Device\00000088 871AD1C0
Device \Driver\ACPI \Device\0000005c 871AD1C0

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\ACPI \Device\0000005d 871AD1C0

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\ACPI \Device\0000006a 871AD1C0
Device \Driver\ACPI \Device\0000006b 871AD1C0
Device \Driver\ACPI \Device\0000006c 871AD1C0
Device \Driver\ACPI \Device\0000006e 871AD1C0
Device \Driver\ACPI \Device\0000008a 871AD1C0
Device \Driver\ACPI \Device\0000007f 871AD1C0

—- Threads - GMER 1.0.15 —-

Thread System [4:3736] 871E31A0
Thread System [4:3740] 871CDF9F
Thread System [4:3748] 87201517
Thread System [4:3760] 871D0C11

—- EOF - GMER 1.0.15 —-
DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 0:42:33.50 on Mon 07/13/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_07 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1142.706 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\—–\Desktop\dds.com ============== Pseudo HJT Report =============== uInternet Connection Wizard,ShellNext = iexplore uURLSearchHooks: N/A: {0a94b116-4504-4e26-ab05-e61e474aa38b} - c:\program files\askpbar\srchastt\1.bin\A9SRCHAS.DLL uURLSearchHooks: TorrentMan Toolbar: {7c5c0f58-e061-457d-9033-77307f5ed00c} - BHO: Ask Search Assistant BHO: {0a94b111-4504-4e26-ab05-e61e474aa38b} - c:\program files\askpbar\srchastt\1.bin\A9SRCHAS.DLL BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: {7c5c0f58-e061-457d-9033-77307f5ed00c} - TorrentMan Toolbar BHO: Ask Toolbar BHO: {f4d76f01-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: Ask Toolbar: {f4d76f09-7896-458a-890f-e1f05c46069f} - c:\program files\askpbar\bar\1.bin\ASKPBAR.DLL TB: TorrentMan Toolbar: {7c5c0f58-e061-457d-9033-77307f5ed00c} - uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\—–\applic~1\mozilla\firefox\profiles\rwqhkjhu.default\ FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\documents and settings\—–\application data\mozilla\firefox\profiles\rwqhkjhu.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll FF - plugin: c:\documents and settings\—–\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\final codecs\mozillaplugins\nppl3260.dll FF - plugin: c:\program files\final codecs\mozillaplugins\nprjplug.dll FF - plugin: c:\program files\final codecs\mozillaplugins\nprpjplug.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-7-1 327688] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-7-1 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-7-1 108552] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-3 906520] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-3 298776] =============== Created Last 30 ================ 2009-07-12 19:44 –d—– c:\program files\Trend Micro 2009-07-12 14:52 –d—– c:\program files\HDGraph 2009-07-12 14:49 –d—– c:\windows\system32\XPSViewer 2009-07-12 14:47 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-07-12 14:47 117,760 ——– c:\windows\system32\prntvpt.dll 2009-07-12 14:47 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-07-12 14:47 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-07-12 14:47 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-07-12 14:47 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-07-12 14:47 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-07-12 14:47 –d—– C:\9c183c561b141412568748eff5 2009-07-12 14:42 –d—– c:\program files\MSXML 6.0 2009-07-12 14:21 –d—– c:\program files\Eusing Free Registry Cleaner 2009-07-12 14:17 –d—– c:\program files\RegistryFix7 2009-07-08 19:55 –d—– c:\docume~1\—–\applic~1\Malwarebytes 2009-07-08 19:53 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-07-08 19:52 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-08 19:52 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-08 19:52 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-22 20:09 –d—– c:\windows\system32\appmgmt 2009-06-16 21:39 1,096 a——- C:\net_save.dna 2009-06-16 21:38 –d—– c:\program files\support.com 2009-06-16 21:38 –d—– c:\program files\common files\SupportSoft ==================== Find3M ==================== 2009-06-29 14:04 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-06-29 14:04 327,688 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-04 13:26 722 a——- c:\windows\fonts\RQF.pfm 2009-05-19 13:35 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-05-07 11:44 344,064 a——- c:\windows\system32\localspl.dll 2009-04-29 00:52 659,456 a——- c:\windows\system32\wininet.dll 2009-04-29 00:52 81,920 a——- c:\windows\system32\ieencode.dll 2009-04-17 05:58 1,846,656 a——- c:\windows\system32\win32k.sys 2009-04-15 11:11 584,192 a——- c:\windows\system32\rpcrt4.dll 2009-03-03 22:14 22,328 a——- c:\docume~1\—–\applic~1\PnkBstrK.sys ============= FINISH: 0:42:51.57 =============== 📎Attach.txt
Hi Allin,

I am not seeing anything bad here, except maybe this: TorrentMan Toolbar.

You do have a very small hard drive though for today's programs: 37 GiB total is not a lot.

Lets run one more double check to make sure you have no malware involved:

Please run an online scan with Kaspersky WebScanner.
Note: You must disable your Anti Virus program during the scan. If you are unsure of how to disable these programs, please refer to this page for details.
  • Click the Accept button to agree to the disclaimer.

    You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded and updated click on My Computer in the Scan settings
    • This will start the scan of your system.
    • The scan will take a while so be patient and let it run until it is complete.
    • Now click on the View scan report link:
  • Click the Save report as button
  • Under Save as type, choose Text file (*.txt)
  • Save the file to your desktop as Kaspersky.txt
  • Copy and paste that information in your next post.
Regards,
RatHat
Here are the results of the Kaspersky scan. I should also note that after running the other programs as you instructed me to do, the hard drive space opened up a bit more, almost up to 5 gigs, however has dropped down to 3.04, and it did start bogging down again right before I ran kaspersky. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Monday, July 13, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Monday, July 13, 2009 08:29:38 Records in database: 2464901 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 33650 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 01:02:38 File name / Threat name / Threats count C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.a 1 The selected area was scanned.
Well, there is no malware showing, only the Ask Toolbar which is rated as foistware.

Please uninstall the following program:

Ask Toolbar
Kaspersky Online Scanner

  • Go to Start then Settings, then Control Panel
  • Choose Add or Remove Programs
  • Remove the above
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Click Here to download OTC
Double-click OTC.exe to run it.
Click the Clean up button
Click Yes to the reboot.

Now delete any logs that you have left over on your desktop.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Keep ATF cleaner and run it every couple of days to clear out the temp folders and browser caches. These are what I think is taking up your space. In the long term though, I think you need to have a larger hard drive installed.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I will keep this log open for the next couple of days, so if you have any further problems post another reply here.

OK, all the best, and stay safe!

Best regards,
RatHat
RatHat Thanks for all you're help; so far everything seems to be running smoothly; my hard drive space though is still at 3.04 gigs, and although I haven't seen a drop all day, I would like to know if theres any way for me to reclaim the the 8+ gigs i'm missing. Any ideas? EDIT: Hard drive space is still dissapearing. My HDGraph shows that at least some of the lost memory has been sucked in by AVG8, which as far as i can tell is the only thing that really changed in the graph since I ran it two days ago.
That was the ticket. Uninstalling AVG freed up 13 gigs of memory; it's not slowing down anymore and the hard drive space isn't dropping. Problem solved, thank you for all your help RatHat
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI