This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] svchost.exe consumes 50% cpu all the time

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys,

I have a problem for the past few days - the computer is running slow. I can see in the task manager that a few minutes after computer start the svchost.exe takes 50% of the cpu all the time.

I followed the instructions in the 'Are you infected' post after scanning my pc with Kasterpsky online scan, Symantec online scan, Nod32 (which i have installed), Adware 1.1.0 and Spybot. All of them found some Trojans and Adware which were removed.

It seems that after running the MBAM the svchost does not start right away but it awakes eventually and takes 50% cpu as before.

Here are the logs of MBAM, GMER and DDS. Thanks in advance for the help :)

MBAM:
Malwarebytes' Anti-Malware 1.44
Database version: 3766
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/20/2010 10:06:35 AM
mbam-log-2010-02-20 (10-06-35).txt

Scan type: Quick Scan
Objects scanned: 118604
Time elapsed: 13 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cdbfb47b-58a8-4111-bf95-06178dce326d} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{cdbfb47b-58a8-4111-bf95-06178dce326d} (Adware.DoubleD) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\nadav\Start Menu\Programs\Startup\netuza32.exe (Worm.KoobFace) -> Delete on reboot.
C:\Documents and Settings\nadav\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.


GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-20 11:16:20
Windows 5.1.2600 Service Pack 3
Running: zpfhzxvr.exe; Driver: C:\DOCUME~1\nadav\LOCALS~1\Temp\pxtdqpod.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwClose [0xB790E7EE]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwCreateKey [0xB790E11C]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwDeleteKey [0xB790E8A8]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwDeleteValueKey [0xB790EADE]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwDuplicateObject [0xB790F622]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwEnumerateKey [0xB790EEBA]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwEnumerateValueKey [0xB790F244]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwFlushKey [0xB790E880]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwLoadKey [0xB790F4C0]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwOpenKey [0xB790DD90]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwQueryKey [0xB790EFA8]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwQueryValueKey [0xB790F366]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwRenameKey [0xB790F6AA]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwSetValueKey [0xB790ED1A]
SSDT \??\C:\WINDOWS\system32\drivers\fslx.sys (FSL System Driver/Altiris, Inc.) ZwUnloadKey [0xB790F544]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2CCC 80504568 4 Bytes CALL C9B6FCFD
.text ntkrnlpa.exe!ZwCallbackReturn + 2CD4 80504570 4 Bytes JMP 924AB790
.text ntkrnlpa.exe!ZwCallbackReturn + 2D0C 805045A8 4 Bytes CALL 4736FD3D
? nnahkv.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9FBB360, 0x32DEFD, 0xE8000020]

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\Explorer.EXE[2340] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C72F20] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[2340] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C72C90] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[2340] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00C72CF0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[2340] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C72CC0] C:\WINDOWS\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs amon.sys (Amon monitor/Eset )
AttachedDevice \FileSystem\Ntfs \Ntfs fslx.sys (FSL System Driver/Altiris, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs fslx.sys (FSL System Driver/Altiris, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\services.exe (*** hidden *** ) [AUTO] Eventlog <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\2A\S-1-5-21-1177238915-2147177821-725345543-1003\[_B_]LOCALAPPDATA[_E_]\Google\Chrome\Application\chrome.exe C:\fslrdr\2A\S-1-5-21-1177238915-2147177821-725345543-1003\[_B_]LOCALAPPDATA[_E_]\Google\Chrome\Application\chrome.exe:*:Disabled:Google Chrome
Reg HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\F\S-1-5-21-1177238915-2147177821-725345543-1003\[_B_]LOCALAPPDATA[_E_]\Google\Chrome\Application\chrome.exe C:\fslrdr\F\S-1-5-21-1177238915-2147177821-725345543-1003\[_B_]LOCALAPPDATA[_E_]\Google\Chrome\Application\chrome.exe:*:Disabled:Google Chrome
Reg HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\12\[_B_]PROGRAMFILES[_E_]\AIM6\aim6.exe C:\fslrdr\12\[_B_]PROGRAMFILES[_E_]\AIM6\aim6.exe:*:Disabled:AIM
Reg HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\41\[_B_]PROGRAMFILES[_E_]\ICQ6.5\ICQ.exe C:\fslrdr\41\[_B_]PROGRAMFILES[_E_]\ICQ6.5\ICQ.exe:*:Disabled:ICQ Library
Reg HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\42\[_B_]PROGRAMFILES[_E_]\ICQ6.5\ICQ.exe C:\fslrdr\42\[_B_]PROGRAMFILES[_E_]\ICQ6.5\ICQ.exe:*:Disabled:ICQ
Reg HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\A\[_B_]PROGRAMFILES[_E_]\RayV\RayV\RayV.exe C:\fslrdr\A\[_B_]PROGRAMFILES[_E_]\RayV\RayV\RayV.exe:*:Disabled:RayV
Reg HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\A\[_B_]PROGRAMFILES[_E_]\RayV\RayV\RayV.dll C:\fslrdr\A\[_B_]PROGRAMFILES[_E_]\RayV\RayV\RayV.dll:*:Enabled:RayV
Reg HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\2A\S-1-5-21-1177238915-2147177821-725345543-1003\[_B_]LOCALAPPDATA[_E_]\Google\Chrome\Application\chrome.exe C:\fslrdr\2A\S-1-5-21-1177238915-2147177821-725345543-1003\[_B_]LOCALAPPDATA[_E_]\Google\Chrome\Application\chrome.exe:*:Disabled:Google Chrome
Reg HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\F\S-1-5-21-1177238915-2147177821-725345543-1003\[_B_]LOCALAPPDATA[_E_]\Google\Chrome\Application\chrome.exe C:\fslrdr\F\S-1-5-21-1177238915-2147177821-725345543-1003\[_B_]LOCALAPPDATA[_E_]\Google\Chrome\Application\chrome.exe:*:Disabled:Google Chrome
Reg HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\12\[_B_]PROGRAMFILES[_E_]\AIM6\aim6.exe C:\fslrdr\12\[_B_]PROGRAMFILES[_E_]\AIM6\aim6.exe:*:Disabled:AIM
Reg HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\41\[_B_]PROGRAMFILES[_E_]\ICQ6.5\ICQ.exe C:\fslrdr\41\[_B_]PROGRAMFILES[_E_]\ICQ6.5\ICQ.exe:*:Disabled:ICQ Library
Reg HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\42\[_B_]PROGRAMFILES[_E_]\ICQ6.5\ICQ.exe C:\fslrdr\42\[_B_]PROGRAMFILES[_E_]\ICQ6.5\ICQ.exe:*:Disabled:ICQ
Reg HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\A\[_B_]PROGRAMFILES[_E_]\RayV\RayV\RayV.exe C:\fslrdr\A\[_B_]PROGRAMFILES[_E_]\RayV\RayV\RayV.exe:*:Disabled:RayV
Reg HKLM\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List@C:\fslrdr\A\[_B_]PROGRAMFILES[_E_]\RayV\RayV\RayV.dll C:\fslrdr\A\[_B_]PROGRAMFILES[_E_]\RayV\RayV\RayV.dll:*:Enabled:RayV
Reg HKLM\SOFTWARE\Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InProcServer32@ C:\WINDOWS\system32\msvbvm60.dll
Reg HKLM\SOFTWARE\Classes\Component Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}@409 NVPanel safely scriptable!
Reg HKLM\SOFTWARE\Classes\Component Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}@409 NVPanel safely initializable!
Reg HKLM\SOFTWARE\Classes\Interface\{BEF6E003-A874-101A-8BBA-00AA00300CAB}\TypeLib@ {00020430-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\JSEFile@ JScript Encoded Script File
Reg HKLM\SOFTWARE\Classes\TypeLib\{00020430-0000-0000-C000-000000000046}\2.0\0\win32@ C:\WINDOWS\System32\STDOLE2.TLB
Reg HKLM\SOFTWARE\Classes\TypeLib\{000204EF-0000-0000-C000-000000000046}\6.0\9\win32@ C:\WINDOWS\system32\msvbvm60.dll
Reg HKLM\SOFTWARE\Classes\TypeLib\{EA544A21-C82D-11D1-A3E4-00A0C90AEA82}\6.0\9\win32@ C:\WINDOWS\system32\msvbvm60.dll\3
Reg HKLM\SOFTWARE\Classes\VBEFile@ VBScript Encoded Script File
Reg HKCU\Software\Microsoft\Windows Live\Communications Clients\Shared\2234974920\Groups@ 0

—- EOF - GMER 1.0.15 —-


DDS:

DDS.txt


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 11:53:20.06 on Sat 02/20/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1255.972.1033.18.2030.1507 [GMT 2:00]

AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\WINDOWS\system32\FortiSSLVPNdaemon.exe
D:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\GlobespanVirata\Adsl\dslstat.exe
C:\Program Files\GlobespanVirata\Adsl\dslagent.exe
C:\WINDOWS\system32\rundll32.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\PROGRA~1\COMMON~1\Nokia\Services\SERVIC~1.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\nadav\Desktop\cleaning\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uDefault_Page_URL = hxxp://www.msn.com
mDefault_Page_URL = hxxp://www.msn.com
mStart Page = hxxp://www.msn.com
BHO: AGSearchHook Class: {0bc6e3fa-78ef-4886-842c-5a1258c4455a} - c:\program files\agi\common\agcutils.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - d:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\program files\spybot - search & destroy\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Babylon IE plugin: {9cfaccb6-2f3f-4177-94ea-0d2b72d384c1} - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: myBabylon English Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\mybabylon_english\tbmyB0.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: myBabylon English Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\program files\mybabylon_english\tbmyB0.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {D45171F3-7DA8-4D5A-8257-BCB94B9092AA} - No File
TB: {3CFB2C5F-D269-4D07-8066-24EA40379B94} - No File
EB: &Research;: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - d:\progra~1\micros~1\office12\REFIEBAR.DLL
uRun: [RealityPrompter] c:\program files\altiris\software virtualization agent\prompter.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Yahoo! Pager] "d:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Riya]
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [USBPhone] d:\program files\usbphone\USBPhone.exe
uRun: [RayV] c:\program files\rayv\rayv\RayV.exe /background
uRun: [SpybotSD TeaTimer] d:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [IntelAudioStudio] "c:\program files\intel audio studio\IntelAudioStudio.exe" TRAY
mRun: [atchk] "c:\program files\intel\amt\atchk.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [WinFoxV2] c:\windows\system32\WF2K.EXE Initial
mRun: [WinFast2KLoadDefault] rundll32.exe c:\windows\system32\wf2kcpl.dll,DllLoadDefaultSettings
mRun: [DSLSTATEXE] c:\program files\globespanvirata\adsl\dslstat.exe icon
mRun: [DSLAGENTEXE] c:\program files\globespanvirata\adsl\dslagent.exe
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Babylon Client] c:\program files\babylon\babylon-pro\Babylon.exe -AutoStart
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe"
mRun: [Nokia Tray Application] c:\program files\common files\nokia\ncltools\NclTray.exe
StartupFolder: c:\docume~1\nadav\startm~1\programs\startup\friend~1.lnk - c:\windows\system32\javaws.exe
StartupFolder: c:\docume~1\nadav\startm~1\programs\startup\onenot~1.lnk - d:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\nadav\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\fortem~1.lnk - d:\program files\lg soft india\fortemanager\bin\Monitor.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - d:\program files\logitec\setpoint\SetPoint.exe
IE: Translate this web page with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Action.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/ActionTU.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - d:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\windows\system32\imon.dll
Trusted Zone: pontis.com\vpn
DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188840169484
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} - hxxp://www.intel.com/design/motherbd/boardid/BoardID.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll

============= SERVICES / DRIVERS ===============

R1 FSLX;FSLX;c:\windows\system32\drivers\fslx.sys [2007-8-10 191360]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-8-14 15424]
R2 AGWinService;AG Windows Service;c:\program files\agi\common\win32\pythonservice.exe [2008-11-21 10240]
R2 FortiSslvpnDaemon;FortiClient SSL VPN;c:\windows\system32\FortiSSLVPNdaemon.exe [2009-9-17 703080]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-2 54752]
R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2007-8-14 549256]
R3 pppop;PPPoP WAN Adapter;c:\windows\system32\drivers\pppop.sys [2007-6-6 36384]
R4 WINFOXIO;WINFOXIO;c:\windows\system32\drivers\WINFOXIO.sys [2007-8-11 9600]
S2 gupdate1c9d7e424c72abc;Google Update Service (gupdate1c9d7e424c72abc);"c:\program files\google\update\googleupdate.exe" /svc –> c:\program files\google\update\GoogleUpdate.exe [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"d:\program files\lavasoft\ad-aware\aawservice.exe" –> d:\program files\lavasoft\ad-aware\AAWService.exe [?]
S2 UniFS;UniFS;d:\program files\unisonplay\unifsservice.exe –> d:\program files\unisonplay\UniFSService.exe [?]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 LGDDCDevice;LGDDCDevice;d:\program files\lg soft india\fortemanager\bin\i2cdriver.sys [2008-11-14 14336]

=============== Created Last 30 ================

2010-02-20 07:50:10 0 d—–w- c:\docume~1\nadav\applic~1\Malwarebytes
2010-02-20 07:50:03 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-20 07:50:01 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-20 07:49:59 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-18 16:43:38 0 dc—-w- c:\docume~1\alluse~1\applic~1\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-13 10:19:16 0 d–h–w- C:\c2call
2010-02-13 10:11:30 0 d—–w- c:\documents and settings\nadav\.junique
2010-02-13 08:29:38 16 —-a-w- c:\documents and settings\nadav\.javafx_ping_sent
2010-02-13 08:29:34 0 —-a-w- c:\documents and settings\nadav\.javafx_eula_accepted
2010-02-12 15:58:34 0 d—–w- C:\New Folder
2010-02-11 07:24:14 34688 -c–a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-02-11 07:24:14 34688 —-a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-02-11 07:24:07 8576 -c–a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-02-11 07:24:07 8576 —-a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-02-11 07:24:03 8192 -c–a-w- c:\windows\system32\dllcache\changer.sys
2010-02-11 07:24:03 8192 —-a-w- c:\windows\system32\drivers\changer.sys
2010-02-10 04:36:33 0 d—–w- c:\program files\Fortinet
2010-02-08 17:38:28 0 d—–w- c:\windows\USB 2.0 IrDA

==================== Find3M ====================

2010-02-20 09:22:46 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-02-20 09:22:40 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2009-12-31 16:50:03 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14:05 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26:15 2145280 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43:51 2023936 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-11-27 17:11:44 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:11:44 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 16:07:35 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07:35 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07:34 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07:34 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07:34 11264 —-a-w- c:\windows\system32\msrle32.dll

============= FINISH: 11:53:52.71 ===============


Attach.txt:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/12/2007 12:07:45 AM
System Uptime: 2/20/2010 11:22:25 AM (0 hours ago)

Motherboard: Intel Corporation | | DQ965GF
Processor: Intel® Core™2 CPU 6320 @ 1.86GHz | LGA 775 | 1864/266mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 15 GiB total, 0.965 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 7.677 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 274 GiB total, 22.62 GiB free.
G: is FIXED (NTFS) - 932 GiB total, 380.299 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E96E-E325-11CE-BFC1-08002BE10318}
Description: Plug and Play Monitor
Device ID: DISPLAY\GSM567E\5&3C3167C&0&11335587&01&00
Manufacturer: (Standard monitor types)
Name: Plug and Play Monitor
PNP Device ID: DISPLAY\GSM567E\5&3C3167C&0&11335587&01&00
Service:

==== System Restore Points ===================

RP978: 2/20/2010 4:27:04 AM - System Checkpoint
RP979: 2/20/2010 9:42:18 AM - Automatic Restore Point
RP980: 2/20/2010 9:44:33 AM - Automatic Restore Point

==== Installed Programs ======================

µTorrent
AAC Decoder
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
Advanced Disk Catalog
Altiris Software Virtualization Agent
Audio Converter
AutoUpdate
CDDRV_Installer
dBpowerAMP Monkeys Audio Codec
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
Dup Detector
eMule
ERUNT 1.1j
forteManager
FortiClient SSL VPN v4.0.2073
FriendCaller
GlobespanVirata DSL Modem
Google Chrome
Google Earth
Google Talk Plugin
Google Update Helper
Google Updater
H.264 Decoder
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Intel Audio Studio 2.0
Intel® Active Management Technology LMS Service and SOL Driver
Intel® Management Engine Interface
Intel® PRO Network Connections [removed]
IrfanView (remove only)
Java™ 6 Update 17
Junk Mail filter update
KhalInstallWrapper
Logitech Registration
Logitech SetPoint
Logitech Updater
Logitech Vid
Logitech Webcam Software
Logitech Webcam Software Driver Package
Lucid Dream Preparation
Lucid Dreaming Kit
Lucid Dreaming Screensaver
Malwarebytes' Anti-Malware
MediaMonkey 2.3
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
MKV Splitter
MSVCRT
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MV2Player (remove only)
MyExpatNet 0.9.1.14
Nero Suite
NOD32 antivirus system
NOD32 FiX v2.1
Nokia PC Suite 4.88
NSIS Example2
NVIDIA Drivers
oggcodecs 0.71.0946
orange time
Orban/Coding Technologies AAC/aacPlus Player Plugin™ 1.0
RadLight APE DirectShow filter (remove only)
Riya Uploader
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
Segoe UI
SigmaTel Audio
Skype web features
Skype™ 4.1
SoulSeek Client 156c
Spybot - Search & Destroy
TreeSize Professional 3.31
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Outlook 2007 Junk Email Filter (kb977719)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
USB 2.0 IrDA Bridge
VC80CRTRedist - 8.0.50727.4053
VideoLAN VLC media player 0.8.6f
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Webshots Desktop
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Player Firefox Plugin
Windows XP Service Pack 3
WinFast® Display Driver
WinFox Setup
WinRAR archiver
Yahoo! Messenger

==== Event Viewer Messages From Past Week ========

2/20/2010 10:32:38 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the JavaQuickStarterService service.
2/20/2010 10:10:57 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
2/18/2010 7:08:47 AM, error: Service Control Manager [7034] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s).
2/18/2010 6:55:27 AM, error: Service Control Manager [7000] - The UniFS service failed to start due to the following error: The system cannot find the file specified.
2/18/2010 6:55:27 AM, error: Service Control Manager [7000] - The Lavasoft Ad-Aware Service service failed to start due to the following error: The system cannot find the path specified.
2/16/2010 8:06:17 PM, error: Service Control Manager [7034] - The Terminal Services service terminated unexpectedly. It has done this 1 time(s).
2/16/2010 8:06:17 PM, error: Service Control Manager [7031] - The DCOM Server Process Launcher service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Reboot the machine.
2/15/2010 7:51:38 PM, error: Service Control Manager [7000] - The Google Update Service (gupdate1c9d7e424c72abc) service failed to start due to the following error: The system cannot find the path specified.
2/13/2010 2:20:37 PM, error: Dhcp [1002] - The IP address lease 10.9.0.26 for the Network Card with network address 00FF758F9000 has been denied by the DHCP server 10.9.0.45 (The DHCP Server sent a DHCPNACK message).

==== End Of File ===========================
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi, Thanks for the reply, but the problem was resolved. I was not sure at first but it seems that Malwarebytes' Anti-Malware removed the problem. It's not happening now - for a whole day. Thanks - I guess the 'Are you infected' post was enough :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI