This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] very slow, unresponsive and freezes up laptop

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

almar,

Nothing wrong there.

Log looks good :D


You need to create a new Clean restore point:

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

You may be asked to choose drive. Choose C: At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

I would further suggest that you also read this tutorial on slow running computers
and Help! My computer is slow! by miekiemoes.

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
TomK I believe the computer still has some serious infection of some sort.this morning it took 45 minutes to get Internet explorer to connect, and then the keyboard keys are completely reconfigured to type the wrong letters, like you press the letter E and it registers as B and so forth and .I had to shut and start the computer three time to get it acting again.On the whole There was some improvement in functionality but it is still very slow and things like I have mentioned and if you remember the Chinese script that keep coming up with ComboFix instructions.It is just weird. That's why I have not set up a Restor Point at this stage . Please advise. Thanks
almar, Unfortunately, your symptoms sound bad… but I'm not finding anything. Let's keep rooting around and see if I can come up with something. Please update your Malwarebytes and run a full scan. Post the report here please.
Hi TomK here is the report of the scan.only one infecte item was found. Malwarebytes' Anti-Malware 1.42 Database version: 3382 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 12/17/2009 9:17:45 PM mbam-log-2009-12-17 (21-17-14).txt Scan type: Full Scan (C:\|) Objects scanned: 174853 Time elapsed: 3 hour(s), 51 minute(s), 17 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) -> No action taken.
almar,

Remove it. That will cause popups and slowness but not all of your problems.

Let's try Kaspersky online. It takes hours.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
TomK Kesprensky would not allow a scan even though I have disabled other Virus protectoion program on the computer.can not figure out what other reason might be for not allowing a scan.
This is the infected file foud when scaning with MBR yeserday. since I have closed the the program after scaning.How do I remove this file now.MBR is not runing again. I tried..: Files Infected: C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWeb.FunWeb) ps plse ignore this i did manage to remove it now.
almar,

Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

c:\windows\system32\userinit.exe<===this file

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

Please do the same for each of thes files:
c:\windows\system32\svchost.exe
c:\windows\explorer.exe
c:\windows\system32\ctfmon.exe
c:\windows\system32\spoolsv.exe
virusscan results userinit.exe File size: 24576 bytes Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5: 39b1ffb03c2296323832acbae50d2aff SHA1: e5aedcbe25a97c89101f1f3860ff846e94d70445 Scanners 2009-12-18 Found nothing 2009-12-19 Found nothing 2009-12-19 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing 2009-12-19 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing 2009-12-19 Found nothing 2009-12-19 Found nothing 2009-12-19 Found nothing 2009-12-17 Found nothing 2009-12-18 Found nothing 2009-12-18 Found nothing ……………………………… Status: Scan finished. 0 out of 21 scanners reported malware. Scan taken on: Thu 17 Dec 2009 14:01:28 (CET) Permalink ——————————————————————————– Additional info File size: 14336 bytes Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5: 8f078ae4ed187aaabc0a305146de6716 SHA1: da0ff4006859a7580aba81f486f692dead2014fe Scanners 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-16 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-15 Found nothing 2009-12-16 Found nothing 2009-12-16 Found nothing 2009-12-17 Found nothing ……………………………………………………….. Filename: Explorer.EXE Status: Scan finished. 0 out of 21 scanners reported malware. Scan taken on: Wed 11 Nov 2009 02:41:33 (CET) Permalink ——————————————————————————– Additional info File size: 1033216 bytes Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5: 97bd6515465659ff8f3b7be375b2ea87 SHA1: 972307a3ef93680afdd03603df20f2241047a934 Scanners 2009-11-10 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-10 Found nothing 2009-11-11 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing 2009-11-06 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing 2009-11-10 Found nothing …………………………………………………………………….. ……… Filename: ctfmon.exe Status: Scan finished. 0 out of 21 scanners reported malware. Scan taken on: Thu 17 Dec 2009 12:44:31 (CET) Permalink ——————————————————————————– Additional info File size: 15360 bytes Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5: 24232996a38c0b0cf151c2140ae29fc8 SHA1: b36d03b56a30187ffc6257459d632a4faac48af2 Scanners 2009-12-16 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-16 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-16 Found nothing 2009-12-17 Found nothing 2009-12-16 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-17 Found nothing 2009-12-15 Found nothing 2009-12-16 Found nothing 2009-12-16 Found nothing 2009-12-17 Found nothing …………………………………………………………………… Filename: spoolsv.exe Status: Scan finished. 0 out of 21 scanners reported malware. Scan taken on: Wed 11 Nov 2009 23:00:18 (CET) Permalink ——————————————————————————– Additional info File size: 57856 bytes Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5: da81ec57acd4cdc3d4c51cf3d409af9f SHA1: 7047ed8bd91f3e57972483feaa56e3499cd8c668 Scanners 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-10 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-06 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing 2009-11-11 Found nothing
DDS Report: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 23:06:56.73 on 12/18/2009 Fri Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Home Edition 5.1.2600.2.[removed].18.382.58 [GMT -5:00] AV: avast! antivirus 4.8.1356 [VPS 091218-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe C:\Program Files\Windows Defender\MSASCui.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Common Files\AOL\1151722181\ee\AOLSoftware.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\wanmpsvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trusteer\Rapport\bin\RapportService.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\conime.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Documents and Settings\g\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://my.yahoo.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo! \companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0 \activex\AcroIEHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6 \lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [HostManager] c:\program files\common files\aol\1151722181\ee\AOLSoftware.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0 \reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML IE: &Search IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - {4982D40A-C53B-4615-B15B-B5B5E98D167C} IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\g\applic~1\mozilla\firefox\profiles\mkw9dmh9.default\ FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/ FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-15 114768] R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2009-7-24 58728] R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2009-7-24 301928] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-15 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-11-15 138680] R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2009-7-24 918760] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2004-12-15 200192] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-11-15 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-11-15 352920] S3 brfilt;Brother MFC Filter Driver;c:\windows\system32\drivers\BrFilt.sys [2007-8-23 2944] S3 BrSerWDM;Brother Serial driver;c:\windows\system32\drivers\BrSerWdm.sys [2007-8-23 60416] S3 BrUsbMdm;Brother MFC USB Fax Only Modem;c:\windows\system32\drivers\BrUsbMdm.sys [2007-8-23 11008] S3 BrUsbScn;Brother MFC USB Scanner driver;c:\windows\system32\drivers\BrUsbScn.sys [2007-8-23 10368] S3 GoogleDesktopManager-093009-130223;Google Desktop Manager 5.9.909.30391;c:\program files\google\google desktop search\GoogleDesktop.exe [2006-8-26 30192] S3 ICAM3NT5;Intel USB Video Camera III;c:\windows\system32\drivers\Icam3.sys [2008-11-5 141056] S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys –> c:\windows\system32\drivers\rootrepeal.sys [?] =============== Created Last 30 ================ 2009-12-18 19:55 54,016 a——- c:\windows\system32\drivers\rhdrxwlx.sys 2009-12-18 15:56 73,728 a——- c:\windows\system32\javacpl.cpl 2009-12-18 15:56 411,368 a——- c:\windows\system32\deploytk.dll 2009-12-18 14:26 800,544 a——- C:\JavaSetup6u17-rv.exe 2009-12-14 15:41 –ds—- C:\ComboFix 2009-12-13 17:50 54,156 a—h— c:\windows\QTFont.qfn 2009-12-13 17:50 1,409 a——- c:\windows\QTFont.for 2009-12-12 19:13 244 a—h— C:\sqmnoopt05.sqm 2009-12-12 19:13 232 a—h— C:\sqmdata05.sqm 2009-12-12 19:13 244 a—h— C:\sqmnoopt04.sqm 2009-12-12 19:13 232 a—h— C:\sqmdata04.sqm 2009-12-12 16:15 244 a—h— C:\sqmnoopt03.sqm 2009-12-12 16:15 232 a—h— C:\sqmdata03.sqm 2009-12-11 11:39 –d—– c:\documents and settings\g\DoctorWeb 2009-12-09 23:38 –d—– C:\_OTL 2009-12-08 19:20 –d—– c:\docume~1\g\applic~1\Malwarebytes 2009-12-08 19:20 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-08 19:20 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-12-08 19:20 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-12-08 19:20 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-11-29 22:25 378 a——- C:\Shortcut to WINDOWS.lnk 2009-11-27 11:33 –d—– c:\program files\common files\Scanner 2009-11-24 16:52 –d—– c:\windows\pss ==================== Find3M ==================== 2009-12-08 21:55 4,016 a——- c:\docume~1\g\applic~1\wklnhst.dat 2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe 2009-10-27 06:06 18,432 a——- c:\windows\system32\dllcache\iedw.exe 2009-10-21 01:00 75,776 a——- c:\windows\system32\strmfilt.dll 2009-10-21 01:00 25,088 a——- c:\windows\system32\httpapi.dll 2009-10-21 01:00 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll 2009-10-21 01:00 25,088 ——– c:\windows\system32\dllcache\httpapi.dll 2009-10-20 09:58 263,552 a——- c:\windows\system32\drivers\http.sys 2009-10-20 09:58 263,552 ——– c:\windows\system32\dllcache\http.sys 2009-10-13 05:53 266,752 a——- c:\windows\system32\oakley.dll 2009-10-13 05:53 266,752 ——– c:\windows\system32\dllcache\oakley.dll 2009-10-12 08:54 112,128 a——- c:\windows\system32\rastls.dll 2009-10-12 08:54 69,632 a——- c:\windows\system32\raschap.dll 2009-10-12 08:54 112,128 ——– c:\windows\system32\dllcache\rastls.dll 2009-10-12 08:54 69,632 ——– c:\windows\system32\dllcache\raschap.dll 2009-09-25 00:56 473,600 a——- c:\windows\system32\dllcache\shlwapi.dll 2009-09-25 00:56 1,054,208 a——- c:\windows\system32\dllcache\danim.dll 2009-09-25 00:56 81,920 a——- c:\windows\system32\ieencode.dll 2009-09-25 00:56 81,920 ——– c:\windows\system32\dllcache\ieencode.dll 2004-02-12 11:54 470,528 a——- c:\program files\Manual DVD shrink 3.doc 2004-01-25 23:11 848,763 a——- c:\program files\dvdshrink314setup.exe ============= FINISH: 23:08:36.37 ===============

Attachments:

almar,

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6"=-
"4982D40A-C53B-4615-B15B-B5B5E98D167C"=-
"C4069E3A-68F1-403E-B40E-20066696354B"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"=-
"AOLDialer"=-
:Files
c:\program files\common files\aol
c:\program files\america online 9.0
c:\windows\system32\drivers\rhdrxwlx.sys
C:\ComboFix
C:\sqmnoopt05.sqm
C:\sqmdata05.sqm
C:\sqmnoopt04.sqm
C:\sqmdata04.sqm
C:\sqmnoopt03.sqm
C:\sqmdata03.sqm
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.

Then I would like you to go to Microsofts website and update your operating system to Windows SP3 (and install all of the updates).
TomK I am now using another computer for this note. After the OTL scan and fix ,i am now unable to connect to the internet .We must have taken out something vital for the connection doing the last OTL fix.Please check and advise.I cannot send you the last report because of that.
I can see from the OTL log that all AOL files been moved. 2 files have been deleted: HKEY_LOCAL_ MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\\Host Manager HKEY_LOCAL_ MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\\AOLDialer and all temp files emptied. Total files cleaned 230.80 mb I hope this can help. thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI