gavexor
Topic Starter
My computer has been slowing down starting a month ago or so. So a couple of days ago I ran a virus scan. Within the next two days, various programs (such as Paint, Calculator, all the games, Microsoft Word and so on) has been removed from the start menu, but can still be found in the folders in My Computer. Since the scan didnt find anything, I havent had a clue what to do about this. Im no genius when it comes down to computers, but stuff just dont disappear without help.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/27 12:02
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\windows\System32\Drivers\dump_atapi.sys
Address: 0xBAD10000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\windows\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8A85000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal[1].sys
Image Path: C:\windows\system32\drivers\rootrepeal[1].sys
Address: 0xB8293000 Size: 49152 File Visible: No Signed: -
Status: -
==EOF==
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:58:21,97 on 2009-08-27
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.46.1053.18.511.130 [GMT 2:00]
AV: ESET NOD32 Antivirussystem 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
============== Running Processes ===============
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost -k DcomLaunch
svchost.exe
C:\windows\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program\NOD32\nod32kui.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program\Logitech\Video\LogiTray.exe
C:\Program\Macrogaming\SweetIM\SweetIM.exe
C:\Program\Java\jre6\bin\jusched.exe
C:\Program\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\Documents and Settings\Standard\Application Data\Techno Design IP\LiveSearch Notification.exe
C:\windows\system32\ctfmon.exe
C:\Program\Logitech\Video\FxSvr2.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\Program\NOD32\nod32krn.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\Program\Internet Explorer\iexplore.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Program\Internet Explorer\iexplore.exe
C:\Program\Java\jre6\bin\jucheck.exe
C:\windows\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Standard\Lokala inställningar\Temporary Internet Files\Content.IE5\DKWA97HC\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.se
uSearch Bar = hxxp://search.live.com/results.aspx?q={searchTerms}&mkt=sv-SE&FORM=MICVE5
mSearch Page = hxxp://www.google.se
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program\macrogaming\sweetimbarforie\toolbar.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program\acrobat reader\reader\activex\AcroIEHelper.ocx
BHO: SWEETIE Class: {1a0aadcd-3a72-4b5f-900f-e3bb5a838e2a} - c:\program\macrog~1\sweeti~1\toolbar.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program\askbardis\bar\bin\askBar.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program\java\jre6\bin\ssv.dll
BHO: Windows Live inloggningshjälpen: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program\delade filer\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} - c:\program\macrogaming\sweetimbarforie\toolbar.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program\askbardis\bar\bin\askBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program\google\google toolbar\GoogleToolbar_32.dll
uRun: [MsnMsgr] "c:\program\windows live\messenger\msnmsgr.exe" /background
uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\BackWeb-8876480.exe
uRun: [LogitechSoftwareUpdate] c:\program\logitech\video\ManifestEngine.exe boot
uRun: [SweetIM] c:\program\macrogaming\sweetim\SweetIM.exe
uRun: [Sony Ericsson PC Suite] "c:\program\sony ericsson\sony ericsson pc suite\SEPCSuite.exe" /systray /nologon
uRun: [LiveSearchNotification] "c:\documents and settings\standard\application data\techno design ip\LiveSearch Notification.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Software Informer] "c:\program\software informer\softinfo.exe" -autorun
uRun: [uTorrent] "c:\program\utorrent\uTorrent.exe"
uRun: [swg] "c:\program\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
mRun: [nod32kui] "c:\program\nod32\nod32kui.exe" /WAITSERVICE
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] c:\program\logitech\video\ISStart.exe
mRun: [LogitechVideoTray] c:\program\logitech\video\LogiTray.exe
mRun: [SweetIM] c:\program\macrogaming\sweetim\SweetIM.exe
mRun: [SunJavaUpdateSched] "c:\program\java\jre6\bin\jusched.exe"
mRun: [Windows Messanger Control Center] svchosl.exe
IE: E&xportera till Microsoft Excel - c:\program\micros~2\office11\EXCEL.EXE/3000
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program\partygaming\partypoker\RunApp.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program\windows live\writer\WriterBrowserExtension.dll
LSP: c:\windows\system32\imon.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\standard\applic~1\mozilla\firefox\profiles\i2zvzvzu.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.se
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
FF - plugin: c:\program\acrobat reader\reader\browser\nppdf32.dll
FF - plugin: c:\program\acrobat reader\reader\browser\nppdf32.dll
FF - plugin: c:\program\personal\bin\np_prsnl.dll
FF - plugin: c:\program\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");
c:\program\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".se");
c:\program\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");
============= SERVICES / DRIVERS ===============
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-12-17 15424]
R2 NOD32krn;NOD32 Kernel Service;c:\program\nod32\nod32krn.exe [2007-12-17 552064]
S2 ASKUpgrade;ASKUpgrade;c:\program\askbardis\bar\bin\ASKUpgrade.exe [2009-8-20 234888]
=============== Created Last 30 ================
2009-08-27 11:20 –d—– c:\program\Trend Micro
2009-08-27 11:16 –d—– c:\documents and settings\all users\Mallar
2009-08-27 11:00 –d—– c:\documents and settings\all users\Start-meny
2009-08-27 10:47 –d—– c:\docume~1\alluse~1\applic~1\Sony Ericsson
2009-08-20 18:15 –d—– c:\program\AskBarDis
2009-08-20 18:10 –d—– c:\program\uTorrent
2009-08-20 18:08 –d—– c:\docume~1\standard\applic~1\uTorrent
==================== Find3M ====================
2009-05-28 20:02 68,918 a——- c:\docume~1\standard\applic~1\mdbu.bin
============= FINISH: 11:58:39,75 ===============