This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Machine running slow, using a LOT of memory

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Howdie all,

Im running a reasonably old but up to date version of XP without too many troubles to date. Lately Im experiencing very slow performance and the occasion RAM issue. I use all the usual stuff like spybot resident / teatimer, avast onaccess scanner, and have recently been using bitdeffender as a friend mentioned it may solve my current problem. besides the fact that a bitdefender scan found some file that were downloaded yrs ago and decided they were malware (which I have since deleted) I cant find any other issues with those scans.

Heres my rootrepeal log -

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/06 16:42
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
——————-
Name: dump_diskdump.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_diskdump.sys
Address: 0xEF8FC000 Size: 16384 File Visible: No Signed: -
Status: -

Name: dump_SiSRaid.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_SiSRaid.sys
Address: 0xEFC6E000 Size: 45056 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEF339000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee1596b8

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee159574

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee159a52

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15914c

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15964e

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7ac90

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7ad7e

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15976e

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee15972e

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xee1598ae

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7abf4

#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xeea7aec4

==EOF==


Heres my DDS log -


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 16:38:59.79 on Sun 06/09/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.991.398 [GMT 10:00]

AV: avast! antivirus 4.8.1351 [VPS 090829-0] *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vsnp2std.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Burke\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.designotaku.com.au/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Click-to-Call BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - c:\program files\windows live\messenger\wlchtc.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 7\PcSync2.exe" /NoDialog
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [snp2std] c:\windows\vsnp2std.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [D-Link D-Link Wireless G DWA-510] c:\program files\d-link\d-link wireless g dwa-510\AirGCFG.exe
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2009\bdagent.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [UDC Integration]
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 6\PcSync2.exe" /NoDialog
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148271823671
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} - file://c:\program files\autocad 2002\InstBanr.ocx
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file://c:\program files\autocad 2002\InstFred.ocx
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file://c:\program files\autocad 2002\AcPreview.ocx
TCP: {8C08D7CA-A295-42E2-AC81-D19F86BF5447} = 192.231.203.132,192.231.203.3
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\chrisb~1\applic~1\mozilla\firefox\profiles\frtmtv5u.chrisnew\
FF - prefs.js: browser.startup.homepage - www.designotaku.com.au
FF - component: c:\documents and settings\chris burke\application data\mozilla\firefox\profiles\frtmtv5u.chrisnew\extensions\[removed]\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\chris burke\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\common-use signing interface\bin\npCsiPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-30 114768]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-10-30 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-10-30 138680]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [2003-7-17 18848]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-10-30 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-10-30 352920]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2009-4-15 146312]
R3 VMHybrid;VMHybrid service;c:\windows\system32\drivers\VMHybrid.sys [2008-9-1 1060224]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-8-23 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-8-23 8320]
S3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664]
S4 TwonkyMedia;TwonkyMedia;c:\program files\nokia\nokia home media server\media server\twonkymedia.exe -serviceversion 0 –> c:\program files\nokia\nokia home media server\media server\TwonkyMedia.exe -serviceversion 0 [?]

=============== Created Last 30 ================

2009-09-04 09:56 116,224 a——- c:\windows\system32\pdfcmnnt.dll
2009-09-04 09:56 23,552 a——- c:\windows\system32\MSMPIDE.DLL
2009-09-04 09:56 –d—– c:\program files\PDFCreator
2009-09-04 09:55 21,192 a——- c:\windows\system32\dopdfmn6.dll
2009-09-04 09:55 18,632 a——- c:\windows\system32\dopdfmi6.dll
2009-09-04 09:55 7,537 a——- c:\windows\system32\dopdf6.ctm
2009-09-04 09:54 –d—– c:\program files\Softland
2009-09-04 09:22 5,632 a——- c:\windows\system32\udcpm.dll
2009-09-04 09:22 –d–r– C:\UDC Output Files
2009-09-04 09:22 –d—– c:\program files\Universal Document Converter
2009-09-03 15:52 –d—– c:\program files\MSECache
2009-09-01 17:54 –d—– C:\mhnnzqvu.default
2009-08-27 22:36 722 a——- c:\windows\system32\BDUpdateV1.xml
2009-08-27 17:58 81,984 a——- c:\windows\system32\bdod.bin
2009-08-27 17:27 850 a——- c:\windows\system32\ProductTweaks.xml
2009-08-27 17:27 385 a——- c:\windows\system32\user_gensett.xml
2009-08-27 17:27 23,392 a——- c:\windows\system32\nscompat.tlb
2009-08-27 17:27 16,832 a——- c:\windows\system32\amcompat.tlb
2009-08-27 17:23 –d—– c:\docume~1\chrisb~1\applic~1\BitDefender
2009-08-27 17:23 –d—– c:\program files\BitDefender
2009-08-27 17:23 –d—– c:\docume~1\alluse~1\applic~1\BitDefender
2009-08-27 17:22 –d—– c:\program files\common files\BitDefender
2009-08-27 10:36 18,816 a——- c:\windows\system32\drivers\pccsmcfd.sys
2009-08-27 10:33 –d—– c:\docume~1\chrisb~1\applic~1\HouseCall 6.6
2009-08-27 10:30 27,784 a——- c:\windows\system32\drivers\point32.sys
2009-08-27 10:29 –d—– c:\program files\Microsoft IntelliPoint
2009-08-26 23:51 54,156 a—h— c:\windows\QTFont.qfn
2009-08-26 23:51 1,409 a——- c:\windows\QTFont.for
2009-08-26 23:49 4,463,988 a——- c:\windows\setupapi.log.4.old
2009-08-26 08:45 3,587,641 a——- c:\windows\setupapi.log.1.old
2009-08-23 22:42 –d—– c:\program files\Free-Buttons.org
2009-08-23 21:25 -cd-h— c:\docume~1\alluse~1\applic~1\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-08-23 20:58 8,320 a——- c:\windows\system32\drivers\nmwcdnsuc.sys
2009-08-23 20:58 136,704 a——- c:\windows\system32\drivers\nmwcdnsu.sys
2009-08-23 20:58 7,808 a——- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-08-23 20:58 22,016 a——- c:\windows\system32\drivers\ccdcmbo.sys
2009-08-23 20:58 7,808 a——- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-08-23 20:58 1,112,288 a——- c:\windows\system32\wdfcoinstaller01007.dll
2009-08-23 20:58 659,968 a——- c:\windows\system32\nmwcdcocls.dll
2009-08-23 20:58 17,664 a——- c:\windows\system32\drivers\ccdcmb.sys
2009-08-23 17:42 –d—– c:\documents and settings\chris burke\ErrorLogs
2009-08-20 22:58 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-19 18:08 299,008 a——- c:\windows\system32\Msdbrptr.dll
2009-08-19 18:08 203,576 a——- c:\windows\system32\Richtx32.ocx
2009-08-19 18:08 102,912 a——- c:\windows\system32\Vb6stkit.dll
2009-08-19 18:08 166,200 a——- c:\windows\system32\Msmask32.ocx
2009-08-19 18:08 –d—– c:\program files\TWC
2009-08-19 18:07 –d—– c:\program files\RKET
2009-08-19 18:05 –d—– c:\program files\FileNet
2009-08-19 18:04 –d—– C:\ProgramData
2009-08-19 18:04 –d—– C:\Informed
2009-08-17 11:57 –d—– c:\docume~1\alluse~1\applic~1\ALM
2009-08-17 11:56 –d—– c:\program files\Bonjour
2009-08-17 11:44 –d—– c:\program files\common files\Macrovision Shared
2009-08-16 09:08 69,075,917 a——- c:\windows\setupapi.log.0.old
2009-08-08 11:19 18,261,833 a——- c:\windows\setupapi.log.3.old
2009-08-08 10:37 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat

==================== Find3M ====================

2009-09-03 15:53 90,224 ac—— c:\docume~1\chrisb~1\applic~1\GDIPFONTCACHEV1.DAT
2009-08-27 17:57 146,312 a——- c:\windows\system32\drivers\bdfm.sys
2009-08-05 19:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-25 05:23 411,368 ac—— c:\windows\system32\deploytk.dll
2009-07-18 05:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-04 03:09 915,456 a——- c:\windows\system32\wininet.dll
2009-06-25 18:25 730,112 a——- c:\windows\system32\lsasrv.dll
2009-06-25 18:25 301,568 a——- c:\windows\system32\kerberos.dll
2009-06-25 18:25 147,456 a——- c:\windows\system32\schannel.dll
2009-06-25 18:25 136,192 a——- c:\windows\system32\msv1_0.dll
2009-06-25 18:25 56,832 a——- c:\windows\system32\secur32.dll
2009-06-25 18:25 54,272 a——- c:\windows\system32\wdigest.dll
2009-06-17 00:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-17 00:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-12 22:31 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 22:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-11 00:13 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 16:14 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll
2008-04-15 08:46 32 ac—— c:\docume~1\alluse~1\applic~1\ezsid.dat
2006-08-30 11:15 154,412,622 a——- c:\documents and settings\chris burke\PC Games - The Sims 2 (Full Version).zip

============= FINISH: 16:40:51.26 ===============

Attachments:

Hello and welcome to WTT.

I apologize for the delay in response.

If you still require assistance post a new set of DDS Logs and a description of any remaining problems or symptoms you may still have please.

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Then, please run RootRepeal:

Download and run RootRepeal CR

Please download RootRepeal to your desktop
Alternative Download Link 2
Alternative Download Link 3
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Unzip it to it's own folder
  • Close/Disable all other programs especially your security programs (anti-spyware, anti-virus, and firewall) Refer to this page, if you are unsure how.
  • Double-click on RootRepeal.exe to run it. If you are using Vista, please right-click and run as Administrator…
  • Click the Report tab at the bottom.
  • Now click the Scan button in the Report Tab. [external image: Posted Image]
  • A box will pop up, check the boxes beside ALL Seven options/scan area
    🖼Click to load external image (Posted Image)
  • Now click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button. [external image: Posted Image]
  • Save it as RepealScan and save it to your desktop
  • Reconnect to the internet.
  • Post the contents of that log in your reply please.

For your next reply I would like to see:
-The DDS logs
—DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Hey,

Here are the new logs -


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 23:33:41.57 on Tue 08/09/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.991.486 [GMT 10:00]

AV: avast! antivirus 4.8.1351 [VPS 090829-0] *On-access scanning enabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\vsnp2std.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Program Files\Nokia\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\Chris Burke\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris Burke\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.designotaku.com.au/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Click-to-Call BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - c:\program files\windows live\messenger\wlchtc.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Nokia.PCSync] "c:\program files\nokia\nokia pc suite 7\PcSync2.exe" /NoDialog
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [snp2std] c:\windows\vsnp2std.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [D-Link D-Link Wireless G DWA-510] c:\program files\d-link\d-link wireless g dwa-510\AirGCFG.exe
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2009\bdagent.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagea…en/preview.html
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148271823671
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} - file://c:\program files\autocad 2002\InstBanr.ocx
DPF: {C6637286-300D-11D4-AE0A-0010830243BD} - file://c:\program files\autocad 2002\InstFred.ocx
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD} - file://c:\program files\autocad 2002\AcPreview.ocx
TCP: {8C08D7CA-A295-42E2-AC81-D19F86BF5447} = 192.231.203.132,192.231.203.3
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\chrisb~1\applic~1\mozilla\firefox\profiles\frtmtv5u.chrisnew\
FF - prefs.js: browser.startup.homepage - www.designotaku.com.au
FF - component: c:\documents and settings\chris burke\application data\mozilla\firefox\profiles\frtmtv5u.chrisnew\extensions\[removed]\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\chris burke\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\common-use signing interface\bin\npCsiPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 200000
FF - user.js: content.notify.interval - 100000
FF - user.js: content.switch.threshold - 650000
FF - user.js: nglayout.initialpaint.delay - 300

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-30 114768]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-7-7 611664]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-10-30 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-10-30 138680]
R2 MLPTDR_N;MLPTDR_N;c:\windows\system32\MLPTDR_N.SYS [2003-7-17 18848]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-10-30 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-10-30 352920]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2009-4-15 146312]
R3 VMHybrid;VMHybrid service;c:\windows\system32\drivers\VMHybrid.sys [2008-9-1 1060224]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-8-23 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-8-23 8320]
S3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664]
S4 TwonkyMedia;TwonkyMedia;c:\program files\nokia\nokia home media server\media server\twonkymedia.exe -serviceversion 0 –> c:\program files\nokia\nokia home media server\media server\TwonkyMedia.exe -serviceversion 0 [?]

=============== Created Last 30 ================

2009-09-07 21:41 a-dshr– C:\cmdcons
2009-09-07 21:40 230,912 a——- c:\windows\PEV.exe
2009-09-07 21:40 161,792 a——- c:\windows\SWREG.exe
2009-09-07 21:40 98,816 a——- c:\windows\sed.exe
2009-09-04 09:56 116,224 a——- c:\windows\system32\pdfcmnnt.dll
2009-09-04 09:56 23,552 a——- c:\windows\system32\MSMPIDE.DLL
2009-09-04 09:56 –d—– c:\program files\PDFCreator
2009-09-04 09:55 21,192 a——- c:\windows\system32\dopdfmn6.dll
2009-09-04 09:55 18,632 a——- c:\windows\system32\dopdfmi6.dll
2009-09-04 09:55 7,537 a——- c:\windows\system32\dopdf6.ctm
2009-09-04 09:54 –d—– c:\program files\Softland
2009-09-04 09:22 5,632 a——- c:\windows\system32\udcpm.dll
2009-09-04 09:22 –d–r– C:\UDC Output Files
2009-09-04 09:22 –d—– c:\program files\Universal Document Converter
2009-09-03 15:52 –d—– c:\program files\MSECache
2009-09-01 17:54 –d—– C:\mhnnzqvu.default
2009-08-27 22:36 722 a——- c:\windows\system32\BDUpdateV1.xml
2009-08-27 17:58 81,984 a——- c:\windows\system32\bdod.bin
2009-08-27 17:27 850 a——- c:\windows\system32\ProductTweaks.xml
2009-08-27 17:27 385 a——- c:\windows\system32\user_gensett.xml
2009-08-27 17:27 23,392 a——- c:\windows\system32\nscompat.tlb
2009-08-27 17:27 16,832 a——- c:\windows\system32\amcompat.tlb
2009-08-27 17:23 –d—– c:\docume~1\chrisb~1\applic~1\BitDefender
2009-08-27 17:23 –d—– c:\program files\BitDefender
2009-08-27 17:23 –d—– c:\docume~1\alluse~1\applic~1\BitDefender
2009-08-27 17:22 –d—– c:\program files\common files\BitDefender
2009-08-27 10:36 18,816 a——- c:\windows\system32\drivers\pccsmcfd.sys
2009-08-27 10:33 –d—– c:\docume~1\chrisb~1\applic~1\HouseCall 6.6
2009-08-27 10:30 27,784 a——- c:\windows\system32\drivers\point32.sys
2009-08-27 10:29 –d—– c:\program files\Microsoft IntelliPoint
2009-08-26 23:51 54,156 a—h— c:\windows\QTFont.qfn
2009-08-26 23:51 1,409 a——- c:\windows\QTFont.for
2009-08-26 23:49 4,463,988 a——- c:\windows\setupapi.log.4.old
2009-08-26 08:45 3,587,641 a——- c:\windows\setupapi.log.1.old
2009-08-23 22:42 –d—– c:\program files\Free-Buttons.org
2009-08-23 21:25 -cd-h— c:\docume~1\alluse~1\applic~1\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-08-23 20:58 8,320 a——- c:\windows\system32\drivers\nmwcdnsuc.sys
2009-08-23 20:58 136,704 a——- c:\windows\system32\drivers\nmwcdnsu.sys
2009-08-23 20:58 7,808 a——- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-08-23 20:58 22,016 a——- c:\windows\system32\drivers\ccdcmbo.sys
2009-08-23 20:58 7,808 a——- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-08-23 20:58 1,112,288 a——- c:\windows\system32\wdfcoinstaller01007.dll
2009-08-23 20:58 659,968 a——- c:\windows\system32\nmwcdcocls.dll
2009-08-23 20:58 17,664 a——- c:\windows\system32\drivers\ccdcmb.sys
2009-08-23 17:42 –d—– c:\documents and settings\chris burke\ErrorLogs
2009-08-20 22:58 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-19 18:08 299,008 a——- c:\windows\system32\Msdbrptr.dll
2009-08-19 18:08 203,576 a——- c:\windows\system32\Richtx32.ocx
2009-08-19 18:08 102,912 a——- c:\windows\system32\Vb6stkit.dll
2009-08-19 18:08 166,200 a——- c:\windows\system32\Msmask32.ocx
2009-08-19 18:08 –d—– c:\program files\TWC
2009-08-19 18:07 –d—– c:\program files\RKET
2009-08-19 18:05 –d—– c:\program files\FileNet
2009-08-19 18:04 –d—– C:\ProgramData
2009-08-19 18:04 –d—– C:\Informed
2009-08-17 11:57 –d—– c:\docume~1\alluse~1\applic~1\ALM
2009-08-17 11:56 –d—– c:\program files\Bonjour
2009-08-17 11:44 –d—– c:\program files\common files\Macrovision Shared
2009-08-16 09:08 69,075,917 a——- c:\windows\setupapi.log.0.old

==================== Find3M ====================

2009-09-03 15:53 90,224 ac—— c:\docume~1\chrisb~1\applic~1\GDIPFONTCACHEV1.DAT
2009-08-27 17:57 146,312 a——- c:\windows\system32\drivers\bdfm.sys
2009-08-05 19:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-25 05:23 411,368 ac—— c:\windows\system32\deploytk.dll
2009-07-18 05:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-04 03:09 915,456 ——– c:\windows\system32\wininet.dll
2009-06-25 18:25 730,112 a——- c:\windows\system32\lsasrv.dll
2009-06-25 18:25 301,568 a——- c:\windows\system32\kerberos.dll
2009-06-25 18:25 147,456 a——- c:\windows\system32\schannel.dll
2009-06-25 18:25 136,192 a——- c:\windows\system32\msv1_0.dll
2009-06-25 18:25 56,832 a——- c:\windows\system32\secur32.dll
2009-06-25 18:25 54,272 a——- c:\windows\system32\wdigest.dll
2009-06-17 00:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-17 00:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-12 22:31 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 22:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-11 00:13 84,992 a——- c:\windows\system32\avifil32.dll
2008-04-15 08:46 32 ac—— c:\docume~1\alluse~1\applic~1\ezsid.dat
2006-08-30 11:15 154,412,622 a——- c:\documents and settings\chris burke\PC Games - The Sims 2 (Full Version).zip

============= FINISH: 23:35:19.90 ===============


and -


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 22/05/2006 12:21:46 PM
System Uptime: 9/08/2009 8:55:33 AM (735 hours ago)

Motherboard: Gigabyte Technology Co., Ltd. | | GA-8S661FXM-775
Processor: Intel® Pentium® 4 CPU 3.00GHz | Socket 775 | 3000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 186 GiB total, 27.427 GiB free.
D: is CDROM ()
E: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: SiS 900 PCI Fast Ethernet Adapter
Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_E0001458&REV_90\3&61AAA01&0&20
Manufacturer: SiS
Name: SiS 900 PCI Fast Ethernet Adapter
PNP Device ID: PCI\VEN_1039&DEV_0900&SUBSYS_E0001458&REV_90\3&61AAA01&0&20
Service: SISNIC

Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318}
Description: Motorola SM56 Speakerphone Modem
Device ID: PCI\VEN_1057&DEV_3052&SUBSYS_30201057&REV_04\3&61AAA01&0&58
Manufacturer: Motorola Inc
Name: Motorola SM56 Speakerphone Modem
PNP Device ID: PCI\VEN_1057&DEV_3052&SUBSYS_30201057&REV_04\3&61AAA01&0&58
Service: Modem

==== System Restore Points ===================

RP1030: 11/06/2009 11:50:42 AM - System Checkpoint
RP1031: 12/06/2009 11:51:38 AM - System Checkpoint
RP1032: 12/06/2009 10:44:36 PM - Software Distribution Service 3.0
RP1033: 15/06/2009 9:56:14 PM - System Checkpoint
RP1034: 16/06/2009 9:58:23 PM - System Checkpoint
RP1035: 18/06/2009 11:22:06 AM - System Checkpoint
RP1036: 19/06/2009 11:25:27 AM - System Checkpoint
RP1037: 21/06/2009 11:25:38 AM - System Checkpoint
RP1038: 22/06/2009 12:35:48 PM - System Checkpoint
RP1039: 23/06/2009 1:24:52 PM - System Checkpoint
RP1040: 24/06/2009 12:24:01 PM - Uniblue RegistryBooster 2009
RP1041: 24/06/2009 12:33:00 PM - Uniblue RegistryBooster 2009
RP1042: 24/06/2009 6:14:14 PM - Uniblue RegistryBooster 2009
RP1043: 24/06/2009 6:28:08 PM - Installed Uniblue DriverScanner v1.0
RP1044: 24/06/2009 6:34:56 PM - Installed Windows KB954550-v5.
RP1045: 24/06/2009 6:35:23 PM - Printer Driver Microsoft XPS Document Writer Installed
RP1046: 24/06/2009 6:49:08 PM - DriverScanner install: SiS 661FX
RP1047: 24/06/2009 6:50:13 PM - DriverScanner install: Microsoft USB Notebook/Mobile Optical Mouse (IntelliPoint)
RP1048: 24/06/2009 6:51:13 PM - DriverScanner install: SiS Accelerated Graphics Port
RP1049: 24/06/2009 6:56:49 PM - SpyEraser 24_06_2009_18_56_44
RP1050: 25/06/2009 9:40:27 AM - Printer Driver Microsoft XPS Document Writer Installed
RP1051: 26/06/2009 10:36:47 AM - System Checkpoint
RP1052: 27/06/2009 11:37:54 AM - System Checkpoint
RP1053: 29/06/2009 1:40:56 PM - System Checkpoint
RP1054: 30/06/2009 2:17:54 PM - System Checkpoint
RP1055: 1/07/2009 10:32:17 AM - Uniblue RegistryBooster 2009
RP1056: 1/07/2009 10:42:21 AM - Uniblue RegistryBooster 2009
RP1057: 2/07/2009 11:06:32 AM - System Checkpoint
RP1058: 3/07/2009 11:53:46 AM - System Checkpoint
RP1059: 5/07/2009 10:10:42 PM - System Checkpoint
RP1060: 6/07/2009 11:03:51 PM - System Checkpoint
RP1061: 9/07/2009 10:56:04 AM - System Checkpoint
RP1062: 10/07/2009 12:08:51 PM - System Checkpoint
RP1063: 11/07/2009 12:20:30 PM - System Checkpoint
RP1064: 12/07/2009 6:37:34 PM - System Checkpoint
RP1065: 13/07/2009 6:40:47 PM - System Checkpoint
RP1066: 14/07/2009 7:09:00 PM - System Checkpoint
RP1067: 15/07/2009 9:07:07 PM - System Checkpoint
RP1068: 15/07/2009 11:39:29 PM - Software Distribution Service 3.0
RP1069: 17/07/2009 10:33:56 AM - System Checkpoint
RP1070: 18/07/2009 1:24:03 PM - System Checkpoint
RP1071: 19/07/2009 1:27:27 PM - System Checkpoint
RP1072: 20/07/2009 4:58:40 PM - System Checkpoint
RP1073: 21/07/2009 5:58:44 PM - System Checkpoint
RP1074: 23/07/2009 5:51:55 PM - System Checkpoint
RP1075: 24/07/2009 6:10:01 PM - System Checkpoint
RP1076: 25/07/2009 8:44:02 PM - System Checkpoint
RP1077: 26/07/2009 9:18:36 PM - System Checkpoint
RP1078: 27/07/2009 9:55:37 PM - System Checkpoint
RP1079: 28/07/2009 10:51:17 PM - System Checkpoint
RP1080: 29/07/2009 10:55:30 PM - System Checkpoint
RP1081: 29/07/2009 11:58:19 PM - Installed Adobe Reader 9.1.
RP1082: 30/07/2009 12:44:32 AM - Installed Japanese Fonts Support For Adobe Reader 9.
RP1083: 30/07/2009 10:09:42 AM - Software Distribution Service 3.0
RP1084: 2/08/2009 12:13:58 PM - System Checkpoint
RP1085: 3/08/2009 1:32:10 PM - System Checkpoint
RP1086: 4/08/2009 2:20:26 PM - System Checkpoint
RP1087: 5/08/2009 7:39:00 AM - Installed Java™ 6 Update 15
RP1088: 6/08/2009 9:19:10 AM - System Checkpoint
RP1089: 6/08/2009 5:56:20 PM - Installed Java™ 6 Update 13
RP1090: 6/08/2009 5:57:37 PM - Installed OpenOffice.org 3.1
RP1091: 7/08/2009 8:43:20 AM - Software Distribution Service 3.0
RP1092: 8/08/2009 10:48:15 AM - Software Distribution Service 3.0
RP1093: 9/08/2009 1:11:19 PM - System Checkpoint
RP1094: 10/08/2009 2:07:32 PM - System Checkpoint
RP1095: 13/08/2009 9:16:26 AM - System Checkpoint
RP1096: 14/08/2009 12:01:28 AM - Software Distribution Service 3.0
RP1097: 15/08/2009 8:32:32 AM - System Checkpoint
RP1098: 16/08/2009 10:31:54 AM - System Checkpoint
RP1099: 16/08/2009 10:50:56 AM - Removed Adobe Acrobat 6.0 Professional
RP1100: 16/08/2009 10:55:52 PM - Software Distribution Service 3.0
RP1101: 17/08/2009 12:20:24 AM - Removed Adobe Photoshop
RP1102: 18/08/2009 1:01:06 AM - System Checkpoint
RP1103: 19/08/2009 9:27:05 AM - System Checkpoint
RP1104: 19/08/2009 6:05:48 PM - Installed FileNet Desktop eForms
RP1105: 20/08/2009 7:03:20 PM - System Checkpoint
RP1106: 20/08/2009 10:58:01 PM - Software Distribution Service 3.0
RP1107: 21/08/2009 11:16:47 PM - System Checkpoint
RP1108: 22/08/2009 2:39:23 PM - Uniblue RegistryBooster 2009
RP1109: 22/08/2009 3:15:12 PM - SpyEraser 22_08_2009_15_15_08
RP1110: 23/08/2009 7:23:38 PM - System Checkpoint
RP1111: 24/08/2009 8:07:30 PM - System Checkpoint
RP1112: 25/08/2009 8:12:58 PM - System Checkpoint
RP1113: 26/08/2009 8:49:02 PM - System Checkpoint
RP1114: 26/08/2009 11:40:18 PM - Software Distribution Service 3.0
RP1115: 27/08/2009 9:46:45 AM - Uniblue RegistryBooster 2009
RP1116: 27/08/2009 10:23:39 AM - DriverScanner install: SiS 661FX
RP1117: 27/08/2009 10:26:56 AM - DriverScanner install: Microsoft USB Basic Optical Mouse v2.0 (IntelliPoint)
RP1118: 27/08/2009 10:44:47 AM - Removed OpenOffice.org 3.1
RP1119: 27/08/2009 5:22:56 PM - Installed BitDefender Free Edition 2009
RP1120: 27/08/2009 10:37:03 PM - Software Distribution Service 3.0
RP1121: 30/08/2009 9:27:25 PM - System Checkpoint
RP1122: 31/08/2009 10:21:44 PM - System Checkpoint
RP1123: 31/08/2009 10:49:26 PM - Software Distribution Service 3.0
RP1124: 2/09/2009 8:04:47 AM - System Checkpoint
RP1125: 3/09/2009 8:48:29 AM - System Checkpoint
RP1126: 3/09/2009 3:52:23 PM - Installed Compatibility Pack for the 2007 Office system
RP1127: 4/09/2009 9:22:24 AM - Printer Driver Universal Document Converter Installed
RP1128: 4/09/2009 9:55:10 AM - Printer Driver doPDF 6 Printer Driver Installed
RP1129: 4/09/2009 9:56:36 AM - Printer Driver PDFCreator Installed
RP1130: 5/09/2009 6:30:08 PM - System Checkpoint
RP1131: 6/09/2009 6:50:45 PM - System Checkpoint
RP1132: 7/09/2009 6:55:25 PM - System Checkpoint
RP1133: 8/09/2009 8:36:57 PM - System Checkpoint

==== Installed Programs ======================

AAC Decoder
Ad-Aware
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color EU Recommended Settings
Adobe Color JA Extra Settings
Adobe Color NA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe Dreamweaver CS3
Adobe ExtendScript Toolkit 2
Adobe Extension Manager CS3
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Reader 9.1.3
Adobe Setup
Adobe Stock Photos CS3
Adobe SVG Viewer 3.0
Adobe Type Manager 4.1
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
ANIO Service
ANIWZCS2 Service
AnswerWorks Runtime
µTorrent
AusLogics Disk Defrag
AutoCAD 2002
AutoUpdate
avast! Antivirus
AVS DVD Player version 2.4
AVS Update Manager 1.0
AVS4YOU Software Navigator 1.3
BitDefender Free Edition 2009
Canon CanoScan Toolbox 4.1
CATSTORE520_DNN441_PA
CCleaner (remove only)
Choice Guard
Common-Use Signing Interface
Compatibility Pack for the 2007 Office system
ComproDTV 3
Core FTP LE 1.3c
Critical Update for Windows Media Player 11 (KB959772)
D-Link Wireless G DWA-510
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
doPDF 6.3 printer
e-Record 6
e-Record Tutorial
Elecard MPEG-2 Encoder Std
ERUNT 1.1j
FileNet Desktop eForms
Free-Buttons.org
Google Chrome
Google Earth
H.264 Decoder
Hijackthis 1.99.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HouseCall 6.6
Japanese Fonts Support For Adobe Reader 9
Java™ 6 Update 13
Java™ 6 Update 15
Java™ 6 Update 5
Java™ SE Runtime Environment 6 Update 1
Junk Mail filter update
KONICA MINOLTA PagePro 1300W
Macromedia Flash MX
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft IntelliPoint 6.3
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office XP Professional with FrontPage
Microsoft SQL Server Management Studio Express
Microsoft User-Mode Driver Framework Feature Pack 1.5
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
MKV Splitter
Motorola SM56 Speakerphone Modem
Mozilla Firefox (3.0.13)
Mozilla Thunderbird (2.0.0.23)
MSVC80_x86
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
Nero Suite
Nokia Connectivity Cable Driver
Nokia Download!
Nokia Home Media Server
Nokia Map Loader
Nokia MTP driver
Nokia Multimedia Factory
Nokia Ovi Application Installer
Nokia Ovi Application Installer 6.85.3011
Nokia Ovi Content Copier
Nokia Ovi Content Copier 6.85.3011
Nokia Ovi Music Manager
Nokia Ovi Music Manager 6.85.3008
Nokia Ovi One Touch Access
Nokia Ovi One Touch Access 6.85.3008
Nokia Ovi Suite
Nokia Ovi System Utilities
Nokia Ovi System Utilities 6.85.3018
Nokia PC Suite
Nokia Photos
Nokia Software Updater
PC Connectivity Solution
PDF Settings
PDFCreator
Picasa 2
QuickTime
RACE STUDIO 2
RealPlayer
Realtek AC'97 Audio
Record Keeping Evaluation Tool
Security Task Manager 1.7e
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Segoe UI
SiS 900 PCI Fast Ethernet Adapter Driver
SiS VGA Utilities
Skype Toolbar for Outlook
Skype™ 4.0
Songbird 1.0.0 (20081124)
Spybot - Search & Destroy
Tax Withheld Calculator
TwonkyMedia
Ulead Straight-to-Disc SDK
Uniblue DriverScanner 2009
Uniblue PowerSuite
Uniblue RegistryBooster 2009
Uniblue SpeedUpMyPC 2009
Uniblue SpyEraser
Uninstall 1.0.0.0
Universal Document Converter
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
USB2.0 PC Camera (SN9C201&202)
VC80CRTRedist - 8.0.50727.762
VideoMate E800 Driver
VideoMate T , M , P , S Series Driver
WDRACK
WebFldrs XP
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Player 10 Hotfix - KB894476
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
Your Small Business Tax Calendar

==== Event Viewer Messages From Past Week ========

7/09/2009 9:52:40 PM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Illegal operation attempted on a registry key that has been marked for deletion.
7/09/2009 9:44:41 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
7/09/2009 9:40:37 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
7/09/2009 9:40:36 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s).
7/09/2009 7:45:44 AM, error: ipnathlp [31012] - The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.
5/09/2009 5:03:27 PM, error: Dhcp [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 0022B070850A has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
3/09/2009 7:42:30 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
3/09/2009 7:42:11 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: szkg
3/09/2009 10:45:05 PM, error: ipnathlp [31008] - The DNS proxy agent was unable to read the local list of name-resolution servers from the registry. The data is the error code.
1/09/2009 7:01:41 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the ServiceLayer service to connect.
1/09/2009 7:01:41 AM, error: Service Control Manager [7000] - The ServiceLayer service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
1/09/2009 7:01:41 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service ServiceLayer with arguments "" in order to run the server: {ACF50018-41F8-476D-85FD-CD953DAE4A49}

==== End Of File ===========================


and -

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/08 23:37
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
——————-
Name: dump_diskdump.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_diskdump.sys
Address: 0xF4197000 Size: 16384 File Visible: No Signed: -
Status: -

Name: dump_SiSRaid.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_SiSRaid.sys
Address: 0xF6DAE000 Size: 45056 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF1516000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
——————-
Path: c:\documents and settings\chris burke\local settings\temp\etilqs_wq7xh0g2hj1vldmhfdjo
Status: Allocation size mismatch (API: 32768, Raw: 0)

SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf41b76b8

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf41b7574

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf41b7a52

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf41b714c

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf41b764e

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xf27fcc90

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xf27fcd7e

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf41b776e

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf41b772e

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf41b78ae

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xf27fcbf4

#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys" at address 0xf27fcec4

==EOF==


Hope you find something in that lot that helps me out :-)
Hi,

Same issue as before - no change - machine still running slow and crashing etc… seems to be running to many processes in my opinion.

Does this mean you have not found any issues in the above logs?


Hello.

Please give me an update of the following…

-Description of any remaining problems you may still have.


Thanks.

~Extremeboy

Hello.

Well, no infections I see active.

Let's do the following and see if it helps at all…

Download and Run StartupLite

This program will identify startup entries that are unnecessary to be started at bootup. This will help free some memory.
  • Download StartupLite.exe by MalwareBytes to your desktop.
  • Double click on StartUpLite.exe to run it. If you are using Windows Vista, right click the icon and select Run As Administrator.
  • A list of unecessary startup entries will be compiled.
  • Take a read at the description of each and for most of them you probably won't need it please make sure there is a checkmark next to Disable.
  • Leave all the items as Disabled and click Continue.
  • Restart your computer once it's done.

If that does not work, you can also try some of the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.

—

Please uninstall All older versions of Java EXCEPT Java 6 update 15.

Run ESET Online Scan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
You can refer to this animation by neomage if needed.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI