This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC freezing up

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My PC is locking up a various times, never know when it's going to freeze up.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:57:03 PM, on 7/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PRISMSVC.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ReminderApp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Crump\Application Data\U3\00001862657376CC\LaunchPad.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe -H
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ReminderApp] C:\Program Files\ReminderApp.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] cmd.exe /c md "%USERPROFILE%\Local Settings\Temp" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_07] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_08] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_09] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_10] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_01] rundll32 advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Help\Tours" (User 'NETWORK SERVICE')
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: PRISMSVC - Conexant Systems, Inc. - C:\WINDOWS\system32\PRISMSVC.EXE
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 6218 bytes

Hello spidey,
Welcome to What the Tech.
My name is OCD, I will be helping you with your log today.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HijackThis log now, I will post back shortly with instructions.

Hello spidey,

  • You may want to print out these instructions for reference prior to proceeding.
  • This solution is specifically tailored for this particular problem, please do not attempt to use this solution on another computer.
  • If you have any questions, or are uncertain about any steps please ask 'before' proceeding.
- - - - - Next - - - - -

Please download ATF Cleaner by Atribune.
Download - http://www.nutnworks.com/downloads/ATF_Cleaner.exe
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

- - - - - Next - - - - -

Please download Malwarebytes' Anti-Malware from here or here

Double Click mbam-setup.exe to install the application.
  • Make sure a check mark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.< < Don't forget this!
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
    (The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.)
  • Copy and Paste the entire report in your next reply.
- - - - - Next - - - - -

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs) < < Important!
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
- - - - - Next - - - - -

Please download RootRepeal to your desktop
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
  • Click the Report tab at the bottom and then the Scan button.
  • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button, call it RepealScan and save the log to your desktop.
  • Reconnect to the internet.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • MBAM log
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse.
    Browse to where you saved the file, and click Open and the click UPLOAD.
  • RootRepeal log

Hi OCD, I've printed and downloaded the instructions………… with the computer freezing up as it does it will take me a while to get back to you so I wanted to let you know that it may take a few days. Thank y6ou for the help and I will get back to you as soon as I can get the information from the computer. Thanks again Spidey
Hi OCD………. Finally got al the scans ran, sorry it took so long. MBAM log Malwarebytes' Anti-Malware 1.39 Database version: 2421 Windows 5.1.2600 Service Pack 3 7/26/2009 6:29:19 PM mbam-log-2009-07-26 (18-29-19).txt Scan type: Quick Scan Objects scanned: 109332 Time elapsed: 12 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 12 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 8 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully. Files Infected: c:\program files\mywebsearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\PDFTronDLL.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. DDS.txt DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 18:32:54.43 on Sun 07/26/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.224.84 [GMT -5:00] AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE svchost.exe C:\WINDOWS\system32\PRISMSVR.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\PRISMSVC.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Unlocker\UnlockerAssistant.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\ReminderApp.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Dell Wireless\PRISMCFG.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Crump\Application Data\U3\00001862657376CC\LaunchPad.exe G:\Documents\computer cleaning\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=0i7fAuZHMpmLnaubZPnx6Q&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms} mWinlogon: SfcDisable=-99 (0xffffff9d) BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [UnlockerAssistant] c:\program files\unlocker\UnlockerAssistant.exe -H mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [] mRun: [ReminderApp] c:\program files\ReminderApp.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: PRISMAPI.DLL - PRISMAPI.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\crump\applic~1\mozilla\firefox\profiles\q76nujd9.default\ FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - component: c:\program files\mozilla firefox\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll FF - plugin: c:\documents and settings\crump\application data\mozilla\firefox\profiles\q76nujd9.default\extensions\{0c7e3f01-99e9-4095-9bdc-f84724960b57}\plugins\NPCpnMgr.dll FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2009-07-26 18:30 61,440 a——- c:\windows\system32\drivers\fontr.sys 2009-07-26 18:10 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-26 18:09 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-26 17:44 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-25 15:19 –d—– c:\docume~1\crump\applic~1\Malwarebytes 2009-07-25 15:16 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-24 10:58 –d—– c:\program files\Trend Micro 2009-07-24 10:38 –d—– c:\documents and settings\crump\.housecall6.6 2009-07-23 14:50 –d—– c:\docume~1\crump\applic~1\Printer Info Cache 2009-07-23 14:35 –d—– c:\windows\pss 2009-07-14 19:24 172,032 ——– c:\windows\system32\dllcache\scrrun.dll 2009-07-14 19:24 90,112 ——– c:\windows\system32\dllcache\wshext.dll 2009-07-14 19:24 512,000 ——– c:\windows\system32\dllcache\jscript.dll 2009-07-14 19:24 180,224 ——– c:\windows\system32\dllcache\scrobj.dll 2009-07-14 19:24 430,080 ——– c:\windows\system32\dllcache\vbscript.dll 2009-07-14 19:24 135,168 ——– c:\windows\system32\dllcache\cscript.exe 2009-07-14 19:24 155,648 ——– c:\windows\system32\dllcache\wscript.exe 2009-07-14 19:23 81,920 ——– c:\windows\system32\dllcache\fontsub.dll 2009-07-14 19:23 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-07-14 18:42 –d—– c:\windows\system32\wbem\snmp 2009-07-14 18:42 –d—– c:\windows\system32\xircom 2009-07-13 21:26 –d—– c:\windows\system32\scripting 2009-07-13 21:26 –d—– c:\windows\l2schemas 2009-07-13 21:26 –d—– c:\windows\system32\bits 2009-07-13 21:15 –d—– c:\windows\ServicePackFiles 2009-07-13 20:57 584 a——- c:\windows\imsins.BAK 2009-07-12 17:45 –d-h— C:\$AVG8.VAULT$ 2009-07-12 17:11 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-07-12 17:11 12,552 a——- c:\windows\system32\drivers\avgrkx86.sys 2009-07-12 17:11 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-07-12 17:10 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-07-12 17:10 –d—– c:\windows\system32\drivers\Avg 2009-07-12 17:09 –d—– c:\program files\AVG 2009-07-12 17:09 –d—– c:\docume~1\alluse~1\applic~1\avg8 2009-07-11 15:53 –d—– c:\docume~1\alluse~1\applic~1\Prism 2009-07-11 15:53 357,344 a—-r– c:\windows\system32\drivers\PRISMA02.sys 2009-07-11 15:53 49,152 a—-r– c:\windows\system32\CoPrism.dll 2009-07-11 15:52 61,529 a—-r– c:\windows\system32\PRISMSVC.exe 2009-07-11 15:52 450,649 a—-r– c:\windows\system32\PRISMAPI.dll 2009-07-11 15:52 385,113 a—-r– c:\windows\system32\PRISMSVR.exe 2009-07-11 15:52 49,152 a—-r– c:\windows\system32\StopSrvr.exe 2009-07-11 15:52 –d—– c:\program files\Dell Wireless 2009-07-11 15:52 20,747 a—-r– c:\windows\system32\drivers\AegisP.sys 2009-07-11 15:52 1,396,827 a—-r– c:\windows\system32\PRISME5.dll 2009-07-11 15:50 –d—– C:\Dell 2009-06-26 19:44 –d—– c:\program files\Text Effects 2009-06-26 19:42 –d—– c:\program files\common files\Nova Development 2009-06-26 19:42 –d—– c:\program files\Data 2009-06-26 19:42 –d—– c:\program files\Project 2009-06-26 19:42 –d—– c:\program files\WizardsUS 2009-06-26 19:42 –d—– c:\program files\Graphics ==================== Find3M ==================== 2009-07-13 21:36 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-06-16 19:31 19,900,192 a——- C:\AdbeRdr710_en_US.exe 2009-06-16 19:27 27,290,072 a——- C:\PDF_Suite_9.0.6.80.exe 2009-06-16 09:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 09:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 14:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 14:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-23 04:04 410,984 a——- c:\windows\system32\deploytk.dll 2009-05-21 13:46 268,288 ——– c:\windows\system32\dllcache\httpext.dll 2009-05-07 10:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 10:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-04-28 23:56 827,392 a——- c:\windows\system32\wininet.dll 2009-04-28 23:56 827,392 ——– c:\windows\system32\dllcache\wininet.dll 2009-04-28 23:56 233,472 ——– c:\windows\system32\dllcache\webcheck.dll 2009-04-28 23:56 1,159,680 ——– c:\windows\system32\dllcache\urlmon.dll 2009-04-28 23:56 671,232 ——– c:\windows\system32\dllcache\mstime.dll 2009-04-28 23:56 105,984 ——– c:\windows\system32\dllcache\url.dll 2009-04-28 23:56 102,912 ——– c:\windows\system32\dllcache\occache.dll 2009-04-28 23:56 44,544 ——– c:\windows\system32\dllcache\pngfilt.dll 2009-04-28 23:56 3,596,288 ——– c:\windows\system32\dllcache\mshtml.dll 2009-04-28 23:56 477,696 ——– c:\windows\system32\dllcache\mshtmled.dll 2009-04-28 23:56 193,024 ——– c:\windows\system32\dllcache\msrating.dll 2009-04-28 04:05 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-04-28 04:05 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2008-03-09 20:40 171 ac–h— c:\documents and settings\crump\hpothb07.dat 2006-11-13 16:42 4,183,248 a——- c:\program files\grtgcard.exe 2006-11-13 14:55 8,132,608 a——- c:\program files\enures.dll 2006-11-13 14:54 233,472 a——- c:\program files\SSCE5532.dll 2006-11-13 14:51 2,362,712 a——- c:\program files\GCFTutorial.chm 2006-11-10 17:44 98,015 a——- c:\program files\SearchIndex_Main.dat 2006-11-10 17:44 5,848 a——- c:\program files\SearchIndex_File.dat 2006-11-10 17:44 211 a——- c:\program files\SearchIndex_Super.dat 2006-11-09 13:21 437 a——- c:\program files\ReminderApp.exe.manifest 2006-11-09 11:33 1,446 a——- c:\program files\grtgcard.exe.manifest 2006-11-08 15:53 20,580,263 a——- c:\program files\grtgcard.pdf 2006-11-08 15:53 587,427 a——- c:\program files\gcfhelp.chm 2006-11-02 11:21 156,160 a——- c:\program files\ReminderApp.exe ============= FINISH: 18:34:22.71 =============== RootRepeal log ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/07/26 18:39 Program Version: Version 1.3.2.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF634D000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xFA3EC000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xF4F88000 Size: 49152 File Visible: No Signed: - Status: - ==EOF==

Attachments:

spidey,

Please run: Eset Online Scanner
(You will need Internet Explorer to run this scan)

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ESET log.txt
  • Tell me how your computer is running at the moment.

OCD, I've tried downloading the online scan tool multipe times last night and the computer keeps freezing up before it can load the program, but I will continue to try again this evening. The computer also seems to be running very slow. Again I just wanted to say thanks for the help, and I'll let you know as soon as I can get the scan completed. Spidey

spidey,

I've tried downloading the online scan tool multiple times last night and the computer keeps freezing up before it can load the program, but I will continue to try again this evening.


If you are still having difficulty with the ESET scanner, please try using this alternate online scan.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.



Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Kaspersky log
  • Any change is system performance?

OCD, I believe that I might have found one of the problems I have with this pc. That fan in the electric power box should runn all the time, correct? There's two other fans in the case but the one in the power box doesn't run at all. When I first start up the computer the first time for the day, it will runn about twenty minutes before freezing up, but the more I try to run it it seems to freeze up faster as in down to about eight minutes. So do you think the fan is one of the problems? I still haven't been able to run it long enough to have it run an online scan……. Spidey
Spidey,

I believe that I might have found one of the problems I have with this pc. That fan in the electric power box should run all the time, correct? There's two other fans in the case but the one in the power box doesn't run at all. When I first start up the computer the first time for the day, it will run about twenty minutes before freezing up, but the more I try to run it it seems to freeze up faster as in down to about eight minutes.
So do you think the fan is one of the problems?

Yes I do. It sounds like your computer is overheating because your power supply fan motor is not running consistently. I recommend you get the hardware issue resolved before we will be able to adequately address your malware issues. You should refrain from using this computer until you correct the problem so you don't damage any other components.

Since we were unable to complete the removal of malware from your computer, I highly recommend that after you fix your hardware issue you return here so we can complete the malware removal process.

Please let me know what course of action you plan on taking.
OCD, I will take out the old fan and get one to replace it with, and after I get it back uip and running I will reply back to here if that's okay….. Spidey

I will take out the old fan and get one to replace it with, and after I get it back uip and running I will reply back to here if that's okay…..

Spidey,

That sounds like a good idea. :thumbup:

OCD, Just to keep you up on what's happening…………… I've replaced the fan and it's working now but I still have the freezing up problem. The computer is running pretty slow so by the time I have the online scan downloading onto the computer it just freezes up. I will continue to try to run the online scan unless you've got another idea…… Spidey

spidey,

Let's bypass the online scan for the moment and see if we can find whats causing the problem.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    You may need two posts to fit them both in.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • OTL logs OTL.Txt and Extras.Txt
  • Tell me how your computer is running at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI