wbocock
Topic Starter
I'm trying to help a neighbor figure out why their PC is so slow on boot up and when trying to open applications, etc. I installed and ran Malwarebytes and Spybot, both cleaned up some stuff, but not that much. This is a WinXP/SP2 machine, has a 2 Ghz cpu and a gig of memory. I'm not sure if there is more malware that the above mentioned programs haven't found or if there is another problem. I'm including the DDS log and the attach file, I also have a Hijackthis log if needed.
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 15:38:33.81 on Mon 08/24/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.647 [GMT -4:00]
AV: avast! antivirus 4.8.1351 [VPS 090824-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
============== Running Processes ===============
C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINNT\system32\svchost.exe -k netsvcs
C:\WINNT\system32\svchost.exe -k WudfServiceGroup
C:\WINNT\Explorer.EXE
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\System32\svchost.exe -k imgsvc
C:\WINNT\system32\SK9910DM.EXE
C:\WINNT\GWMDMMSG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
C:\Program Files\NetZero\exec.exe
C:\WINNT\system32\wscntfy.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.verizon.net/central/vzc.portal
uSearch Page = hxxp://my.netzero.net/s/search?r=minisearch
uSearch Bar = hxxp://my.netzero.net/s/search?r=minisearch
mDefault_Search_URL = hxxp://my.netzero.net/s/search?r=minisearch
mSearch Page = hxxp://my.netzero.net/s/search?r=minisearch
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
mSearchAssistant = hxxp://my.netzero.net/s/search?r=minisearch
uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - c:\program files\netzero\SearchEnh1.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - c:\program files\netzero\Toolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\winnt\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe
uRun: [NetZero_uoltray] c:\program files\netzero\exec.exe regrun
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
mRun: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
mRun: [GWMDMMSG] GWMDMMSG.exe
mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe
mRun: [Keyboard Preload Check] c:\oemdrvrs\keyb\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
mRun: [GWMDMpi] c:\winnt\GWMDMpi.exe
mRun: [AdaptecDirectCD] "c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe"
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [HPDJ Taskbar Utility] c:\winnt\system32\spool\drivers\w32x86\3\hpztsb04.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRunOnce: [OOBEDDDemise] cmd /x /c erase c:\winnt\system32\oobe\msoobe.exe
StartupFolder: c:\documents and settings\owner\start menu\programs\startup\PowerReg Scheduler V3.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wincin~1.lnk - c:\program files\sandisk\common\bin\WinCinemaMgr.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\winnt\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll
DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: Yahoo! Spades - hxxp://download2.games.yahoo.com/games/clients/y/st3_x.cab
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://support.gateway.com/support/profiler/PCPitStop.CAB
DPF: {0F04992B-E661-4DB9-B223-903AB628225D} - file://c:\program files\gateway\do more\DoMoreRunExe.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
DPF: {511073AD-BE56-4D43-AE68-93390514385E} - hcp://system/TechTools.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1143324825062
DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} - hcp://system/RunExeActiveX.CAB
DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} - hcp://system/StartFirstControl.CAB
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37934.6622106481
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,13/mcgdmgr.cab
Notify: igfxcui - igfxsrvc.dll
AppInit_DLLs: c:\winnt\system32\guard32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\winnt\system32\drivers\aswSP.sys [2009-4-29 114768]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\winnt\system32\drivers\cmdguard.sys [2009-8-23 132040]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\winnt\system32\drivers\cmdhlp.sys [2009-8-23 25160]
R2 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2009-4-29 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-4-29 138680]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2009-8-23 707152]
R2 RioPNP;RioPNP;c:\winnt\system32\drivers\RioPnP.sys [2002-11-8 6736]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-4-29 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-4-29 352920]
S3 PCDRDRV;Pcdr Helper Driver;\??\c:\atf\qctest\pcdoc\pcdrdrv.sys –> c:\atf\qctest\pcdoc\PCDRDRV.sys [?]
=============== Created Last 30 ================
2009-08-24 15:08 –d—– C:\HJT
2009-08-23 19:00 179,792 a——- c:\winnt\system32\guard32.dll
2009-08-23 19:00 132,040 a——- c:\winnt\system32\drivers\cmdguard.sys
2009-08-23 19:00 25,160 a——- c:\winnt\system32\drivers\cmdhlp.sys
2009-08-23 14:34 91 a——- c:\winnt\wininit.ini
2009-08-23 12:42 –d—– c:\program files\Spybot - Search & Destroy
2009-08-23 12:42 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-08-23 12:41 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2009-08-23 12:41 19,096 a——- c:\winnt\system32\drivers\mbam.sys
2009-08-23 12:41 38,160 a——- c:\winnt\system32\drivers\mbamswissarmy.sys
2009-08-23 12:41 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-23 12:41 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-23 12:40 –d—– c:\program files\SpywareBlaster
2009-08-23 12:38 –d—– C:\tmp
2009-08-20 00:05 –d—– C:\36927068b1187e1437cd0153f00e96
2009-08-17 01:03 1,871,872 ——– c:\winnt\system32\dllcache\mstscax.dll
2009-08-17 01:03 128,512 ——– c:\winnt\system32\dllcache\dhtmled.ocx
2009-08-05 05:11 204,800 ——– c:\winnt\system32\dllcache\mswebdvd.dll
==================== Find3M ====================
2009-08-05 05:11 204,800 a——- c:\winnt\system32\mswebdvd.dll
2009-07-19 09:33 3,597,824 a——- c:\winnt\system32\dllcache\mshtml.dll
2009-07-19 09:32 6,067,200 ——– c:\winnt\system32\dllcache\ieframe.dll
2009-07-17 14:55 58,880 a——- c:\winnt\system32\atl.dll
2009-07-17 14:55 58,880 ——– c:\winnt\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 a——- c:\winnt\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a——- c:\winnt\system32\wmpdxm.dll
2009-07-13 23:43 286,208 a——- c:\winnt\system32\dllcache\wmpdxm.dll
2009-07-10 09:42 1,315,328 ——– c:\winnt\system32\dllcache\msoe.dll
2009-06-29 07:07 13,824 ——– c:\winnt\system32\dllcache\ieudinit.exe
2009-06-29 07:07 70,656 ——– c:\winnt\system32\dllcache\ie4uinit.exe
2009-06-29 04:35 634,632 ——– c:\winnt\system32\dllcache\iexplore.exe
2009-06-29 04:33 2,452,872 ——– c:\winnt\system32\dllcache\ieapfltr.dat
2009-06-29 04:33 161,792 a——- c:\winnt\system32\dllcache\ieakui.dll
2009-06-25 04:44 724,480 a——- c:\winnt\system32\lsasrv.dll
2009-06-25 04:44 298,496 a——- c:\winnt\system32\kerberos.dll
2009-06-25 04:44 168,448 a——- c:\winnt\system32\schannel.dll
2009-06-25 04:44 133,632 a——- c:\winnt\system32\msv1_0.dll
2009-06-25 04:44 59,392 a——- c:\winnt\system32\wdigest.dll
2009-06-25 04:44 56,320 a——- c:\winnt\system32\secur32.dll
2009-06-25 04:44 724,480 ——– c:\winnt\system32\dllcache\lsasrv.dll
2009-06-25 04:44 298,496 ——– c:\winnt\system32\dllcache\kerberos.dll
2009-06-25 04:44 168,448 ——– c:\winnt\system32\dllcache\schannel.dll
2009-06-25 04:44 133,632 ——– c:\winnt\system32\dllcache\msv1_0.dll
2009-06-25 04:44 59,392 ——– c:\winnt\system32\dllcache\wdigest.dll
2009-06-25 04:44 56,320 ——– c:\winnt\system32\dllcache\secur32.dll
2009-06-22 07:34 92,544 ——– c:\winnt\system32\dllcache\ksecdd.sys
2009-06-16 10:55 119,808 a——- c:\winnt\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\winnt\system32\fontsub.dll
2009-06-16 10:55 82,432 a——- c:\winnt\system32\dllcache\fontsub.dll
2009-06-16 10:55 119,808 ——– c:\winnt\system32\dllcache\t2embed.dll
2009-06-12 07:50 76,288 a——- c:\winnt\system32\telnet.exe
2009-06-12 07:50 76,288 ——– c:\winnt\system32\dllcache\telnet.exe
2009-06-10 10:21 84,992 a——- c:\winnt\system32\avifil32.dll
2009-06-10 10:21 84,992 ——– c:\winnt\system32\dllcache\avifil32.dll
2009-06-10 02:32 132,096 a——- c:\winnt\system32\wkssvc.dll
2009-06-10 02:32 132,096 ——– c:\winnt\system32\dllcache\wkssvc.dll
2009-06-09 11:06 1,871,872 a——- c:\winnt\system32\mstscax.dll
2009-06-03 15:27 1,290,752 a——- c:\winnt\system32\quartz.dll
2009-06-03 15:27 1,290,752 ——– c:\winnt\system32\dllcache\quartz.dll
2009-05-09 19:07 79,832 a——- c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
============= FINISH: 15:40:28.52 ===============