This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] slow after antivirus soft

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi i had anti virus soft and i couldnt use my computer so my nephew came down and helped he got it going but it is really slow now and when i turn it on it always says firewall disable for a min. or two then its on. long time to shut down and freezing a lot i am not that techey so take it easy on me thanks windows xp home sp3, ie 8. thanks. Posted as Jacee requested.

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:53:41.37 on Mon 04/05/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.255.85 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Frank\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page =
uStart Page = hxxp://my.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
uSearchAssistant =
mSearchAssistant =
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\frank\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
dRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NVMCTRAY.DLL,NvTaskbarInit
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255561002123
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194880429139
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
DPF: {8BE5651C-D60B-4B59-B5B2-F0EB93733D17} - hxxps://www36.verizon.com/CallAssistant/MyAccount/UnProtected/Voice%20Mail/VCAVMUtil.CAB
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_2/PhotoCenter_ActiveX_Control.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15111/CTPID.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-3-30 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-3-30 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-30 242696]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-9-15 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-9-15 66632]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-30 308064]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-3-30 369920]
S3 CA500AI;SPCA500A Still Image Capture, Sunplus Version 1.00;c:\windows\system32\drivers\bulkusb.sys –> c:\windows\system32\drivers\BULKUSB.sys [?]
S3 CA500AV;CaptureView VGA;c:\windows\system32\drivers\ca500av.sys –> c:\windows\system32\drivers\CA500AV.SYS [?]
S3 IPN2120;Instant Wireless-B PCI Adapter Driver;c:\windows\system32\drivers\LSIPNDS.sys [2003-7-10 96256]
S3 pctplsg;pctplsg;\??\c:\windows\system32\drivers\pctplsg.sys –> c:\windows\system32\drivers\pctplsg.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-9-15 12872]

=============== Created Last 30 ================

2010-04-05 10:06 –d-h— C:\$AVG
2010-04-05 09:48 –d—– c:\windows\ERUNT
2010-04-03 09:27 –d—– c:\windows\system32\wbem\Repository
2010-04-02 10:03 116,224 ac—— c:\windows\system32\dllcache\xrxwiadr.dll
2010-04-02 10:02 23,040 ac—— c:\windows\system32\dllcache\xrxwbtmp.dll
2010-04-02 10:02 18,944 ac—— c:\windows\system32\dllcache\xrxscnui.dll
2010-04-02 10:02 27,648 ac—— c:\windows\system32\dllcache\xrxftplt.exe
2010-04-02 10:02 4,608 ac—— c:\windows\system32\dllcache\xrxflnch.exe
2010-04-02 10:02 99,865 ac—— c:\windows\system32\dllcache\xlog.exe
2010-04-02 10:02 16,970 ac—— c:\windows\system32\dllcache\xem336n5.sys
2010-04-02 10:02 19,455 ac—— c:\windows\system32\dllcache\wvchntxx.sys
2010-04-02 10:02 12,063 ac—— c:\windows\system32\dllcache\wsiintxx.sys
2010-04-02 10:01 8,192 ac—— c:\windows\system32\dllcache\wshirda.dll
2010-04-02 10:01 8,832 ac—— c:\windows\system32\dllcache\wmiacpi.sys
2010-04-02 10:01 154,624 ac—— c:\windows\system32\dllcache\wlluc48.sys
2010-04-02 10:01 34,890 ac—— c:\windows\system32\dllcache\wlandrv2.sys
2010-04-02 10:00 771,581 ac—— c:\windows\system32\dllcache\winacisa.sys
2010-04-02 10:00 53,760 ac—— c:\windows\system32\dllcache\wiamsmud.dll
2010-04-02 10:00 87,040 ac—— c:\windows\system32\dllcache\wiafbdrv.dll
2010-04-02 10:00 701,386 ac—— c:\windows\system32\dllcache\wdhaalba.sys
2010-04-02 09:59 23,615 ac—— c:\windows\system32\dllcache\wch7xxnt.sys
2010-04-02 09:59 35,871 ac—— c:\windows\system32\dllcache\wbfirdma.sys
2010-04-02 09:59 33,599 ac—— c:\windows\system32\dllcache\watv04nt.sys
2010-04-02 09:59 19,551 ac—— c:\windows\system32\dllcache\watv02nt.sys
2010-04-02 09:59 29,311 ac—— c:\windows\system32\dllcache\watv01nt.sys
2010-04-02 09:59 11,775 ac—— c:\windows\system32\dllcache\wadv05nt.sys
2010-04-02 09:59 12,127 ac—— c:\windows\system32\dllcache\wadv02nt.sys
2010-04-02 09:59 12,415 ac—— c:\windows\system32\dllcache\wadv01nt.sys
2010-04-02 09:59 16,925 ac—— c:\windows\system32\dllcache\w940nd.sys
2010-04-02 09:59 19,016 ac—— c:\windows\system32\dllcache\w926nd.sys
2010-04-02 09:59 19,528 ac—— c:\windows\system32\dllcache\w840nd.sys
2010-04-02 09:58 64,605 ac—— c:\windows\system32\dllcache\vvoice.sys
2010-04-02 09:58 397,502 ac—— c:\windows\system32\dllcache\vpctcom.sys
2010-04-02 09:58 604,253 ac—— c:\windows\system32\dllcache\vmodem.sys
2010-04-02 09:58 249,402 ac—— c:\windows\system32\dllcache\vinwm.sys
2010-04-02 09:58 24,576 ac—— c:\windows\system32\dllcache\viairda.sys
2010-04-02 09:58 5,376 ac—— c:\windows\system32\dllcache\viaide.sys
2010-04-02 09:58 687,999 ac—— c:\windows\system32\dllcache\usrwdxjs.sys
2010-04-02 09:58 765,884 ac—— c:\windows\system32\dllcache\usrti.sys
2010-04-02 09:57 113,762 ac—— c:\windows\system32\dllcache\usrpda.sys
2010-04-02 09:57 7,556 ac—— c:\windows\system32\dllcache\usroslba.sys
2010-04-02 09:57 224,802 ac—— c:\windows\system32\dllcache\usr1807a.sys
2010-04-02 09:57 794,399 ac—— c:\windows\system32\dllcache\usr1806v.sys
2010-04-02 09:57 793,598 ac—— c:\windows\system32\dllcache\usr1806.sys
2010-04-02 09:57 794,654 ac—— c:\windows\system32\dllcache\usr1801.sys
2010-04-02 09:57 26,112 ac—— c:\windows\system32\dllcache\usbser.sys
2010-04-02 09:57 17,152 ac—— c:\windows\system32\dllcache\usbohci.sys
2010-04-02 09:57 32,384 ac—— c:\windows\system32\dllcache\usb101et.sys
2010-04-02 09:56 94,720 ac—— c:\windows\system32\dllcache\umaxud32.dll
2010-04-02 09:56 28,160 ac—— c:\windows\system32\dllcache\umaxu40.dll
2010-04-02 09:56 26,624 ac—— c:\windows\system32\dllcache\umaxu22.dll
2010-04-02 09:56 69,632 ac—— c:\windows\system32\dllcache\umaxu12.dll
2010-04-02 09:56 50,688 ac—— c:\windows\system32\dllcache\umaxscan.dll
2010-04-02 09:56 22,912 ac—— c:\windows\system32\dllcache\umaxpcls.sys
2010-04-02 09:56 50,176 ac—— c:\windows\system32\dllcache\umaxp60.dll
2010-04-02 09:56 47,616 ac—— c:\windows\system32\dllcache\umaxcam.dll
2010-04-02 09:56 211,968 ac—— c:\windows\system32\dllcache\um54scan.dll
2010-04-02 09:55 216,064 ac—— c:\windows\system32\dllcache\um34scan.dll
2010-04-02 09:55 36,736 ac—— c:\windows\system32\dllcache\ultra.sys
2010-04-02 09:55 11,520 ac—— c:\windows\system32\dllcache\twotrack.sys
2010-04-02 09:55 166,784 ac—— c:\windows\system32\dllcache\tridxpm.sys
2010-04-02 09:55 525,568 ac—— c:\windows\system32\dllcache\tridxp.dll
2010-04-02 09:55 159,232 ac—— c:\windows\system32\dllcache\tridkbm.sys
2010-04-02 09:55 440,576 ac—— c:\windows\system32\dllcache\tridkb.dll
2010-04-02 09:54 222,336 ac—— c:\windows\system32\dllcache\trid3dm.sys
2010-04-02 09:54 315,520 ac—— c:\windows\system32\dllcache\trid3d.dll
2010-04-02 09:54 34,375 ac—— c:\windows\system32\dllcache\tpro4.sys
2010-04-02 09:54 42,496 ac—— c:\windows\system32\dllcache\tp4res.dll
2010-04-02 09:54 82,944 ac—— c:\windows\system32\dllcache\tp4mon.exe
2010-04-02 09:54 31,744 ac—— c:\windows\system32\dllcache\tp4.dll
2010-04-02 09:54 4,992 ac—— c:\windows\system32\dllcache\toside.sys
2010-04-02 09:54 230,912 ac—— c:\windows\system32\dllcache\tosdvd03.sys
2010-04-02 09:54 241,664 ac—— c:\windows\system32\dllcache\tosdvd02.sys
2010-04-02 09:53 28,232 ac—— c:\windows\system32\dllcache\tos4mo.sys
2010-04-02 09:53 123,995 ac—— c:\windows\system32\dllcache\tjisdn.sys
2010-04-02 09:53 138,528 ac—— c:\windows\system32\dllcache\tgiulnt5.sys
2010-04-02 09:53 81,408 ac—— c:\windows\system32\dllcache\tgiul50.dll
2010-04-02 09:53 149,376 ac—— c:\windows\system32\dllcache\tffsport.sys
2010-04-02 09:53 17,129 ac—— c:\windows\system32\dllcache\tdkcd31.sys
2010-04-02 09:53 37,961 ac—— c:\windows\system32\dllcache\tdk100b.sys
2010-04-02 09:53 30,464 ac—— c:\windows\system32\dllcache\tbatm155.sys
2010-04-02 09:52 7,040 ac—— c:\windows\system32\dllcache\tandqic.sys
2010-04-02 09:52 36,640 ac—— c:\windows\system32\dllcache\t2r4mini.sys
2010-04-02 09:52 172,768 ac—— c:\windows\system32\dllcache\t2r4disp.dll
2010-04-02 09:52 32,640 ac—— c:\windows\system32\dllcache\symc8xx.sys
2010-04-02 09:52 16,256 ac—— c:\windows\system32\dllcache\symc810.sys
2010-04-02 09:52 30,688 ac—— c:\windows\system32\dllcache\sym_u3.sys
2010-04-02 09:52 28,384 ac—— c:\windows\system32\dllcache\sym_hi.sys
2010-04-02 09:52 94,293 ac—— c:\windows\system32\dllcache\sxports.dll
2010-04-02 09:52 103,936 ac—— c:\windows\system32\dllcache\sx.sys
2010-04-02 09:51 3,968 ac—— c:\windows\system32\dllcache\swusbflt.sys
2010-04-02 09:51 10,240 ac—— c:\windows\system32\dllcache\swpidflt.dll
2010-04-02 09:51 10,240 ac—— c:\windows\system32\dllcache\swpdflt2.dll
2010-04-02 09:51 53,760 ac—— c:\windows\system32\dllcache\sw_wheel.dll
2010-04-02 09:51 41,472 ac—— c:\windows\system32\dllcache\sw_effct.dll
2010-04-02 09:51 155,648 ac—— c:\windows\system32\dllcache\stlnprop.dll
2010-04-02 09:51 53,248 ac—— c:\windows\system32\dllcache\stlncoin.dll
2010-04-02 09:51 285,760 ac—— c:\windows\system32\dllcache\stlnata.sys
2010-04-02 09:51 16,896 ac—— c:\windows\system32\dllcache\stcusb.sys
2010-04-02 09:50 48,736 ac—— c:\windows\system32\dllcache\srwlnd5.sys
2010-04-02 09:50 99,328 ac—— c:\windows\system32\dllcache\srusd.dll
2010-04-02 09:50 24,660 ac—— c:\windows\system32\dllcache\spxupchk.dll
2010-04-02 09:50 61,824 ac—— c:\windows\system32\dllcache\speed.sys
2010-04-02 09:50 106,584 ac—— c:\windows\system32\dllcache\spdports.dll
2010-04-02 09:50 19,072 ac—— c:\windows\system32\dllcache\sparrow.sys
2010-04-02 09:50 7,552 ac—— c:\windows\system32\dllcache\sonypvu1.sys
2010-04-02 09:50 37,040 ac—— c:\windows\system32\dllcache\sonypi.sys
2010-04-02 09:49 114,688 ac—— c:\windows\system32\dllcache\sonypi.dll
2010-04-02 09:49 20,752 ac—— c:\windows\system32\dllcache\sonync.sys
2010-04-02 09:49 9,600 ac—— c:\windows\system32\dllcache\sonymc.sys
2010-04-02 09:49 7,552 ac—— c:\windows\system32\dllcache\sonyait.sys
2010-04-02 09:49 7,040 ac—— c:\windows\system32\dllcache\snyaitmc.sys
2010-04-02 09:49 58,368 ac—— c:\windows\system32\dllcache\smiminib.sys
2010-04-02 09:49 147,200 ac—— c:\windows\system32\dllcache\smidispb.dll
2010-04-02 09:49 25,034 ac—— c:\windows\system32\dllcache\smcpwr2n.sys
2010-04-02 09:49 35,913 ac—— c:\windows\system32\dllcache\smcirda.sys
2010-04-02 09:48 24,576 ac—— c:\windows\system32\dllcache\smc8000n.sys
2010-04-02 09:48 6,784 ac—— c:\windows\system32\dllcache\smbhc.sys
2010-04-02 09:48 6,912 ac—— c:\windows\system32\dllcache\smbclass.sys
2010-04-02 09:48 16,000 ac—— c:\windows\system32\dllcache\smbbatt.sys
2010-04-02 09:48 45,568 ac—— c:\windows\system32\dllcache\smb3w.dll
2010-04-02 09:48 33,792 ac—— c:\windows\system32\dllcache\smb0w.dll
2010-04-02 09:48 28,672 ac—— c:\windows\system32\dllcache\sma0w.dll
2010-04-02 09:48 28,160 ac—— c:\windows\system32\dllcache\sm91w.dll
2010-04-02 09:48 63,547 ac—— c:\windows\system32\dllcache\sla30nd5.sys
2010-04-02 09:48 91,294 ac—— c:\windows\system32\dllcache\skfpwin.sys
2010-04-02 09:47 94,698 ac—— c:\windows\system32\dllcache\sk98xwin.sys
2010-04-02 09:47 157,696 ac—— c:\windows\system32\dllcache\sisv256.dll
2010-04-02 09:47 50,432 ac—— c:\windows\system32\dllcache\sisv.sys
2010-04-02 09:47 32,768 ac—— c:\windows\system32\dllcache\sisnic.sys
2010-04-02 09:47 238,592 ac—— c:\windows\system32\dllcache\sisgrv.dll
2010-04-02 09:47 104,064 ac—— c:\windows\system32\dllcache\sisgrp.sys
2010-04-02 09:47 150,144 ac—— c:\windows\system32\dllcache\sis6306v.dll
2010-04-02 09:47 68,608 ac—— c:\windows\system32\dllcache\sis6306p.sys
2010-04-02 09:47 252,032 ac—— c:\windows\system32\dllcache\sis300iv.dll
2010-04-02 09:47 101,760 ac—— c:\windows\system32\dllcache\sis300ip.sys
2010-04-02 09:46 161,568 ac—— c:\windows\system32\dllcache\sgsmusb.sys
2010-04-02 09:46 18,400 ac—— c:\windows\system32\dllcache\sgsmld.sys
2010-04-02 09:46 98,080 ac—— c:\windows\system32\dllcache\sgiulnt5.sys
2010-04-02 09:46 386,560 ac—— c:\windows\system32\dllcache\sgiul50.dll
2010-04-02 09:46 36,480 ac—— c:\windows\system32\dllcache\sfmanm.sys
2010-04-02 09:46 6,784 ac—— c:\windows\system32\dllcache\serscan.sys
2010-04-02 09:46 17,664 ac—— c:\windows\system32\dllcache\sermouse.sys
2010-04-02 09:46 6,912 ac—— c:\windows\system32\dllcache\seaddsmc.sys
2010-04-02 09:46 11,520 ac—— c:\windows\system32\dllcache\scsiscan.sys
2010-04-02 09:46 11,648 ac—— c:\windows\system32\dllcache\scsiprnt.sys
2010-04-02 09:45 17,280 ac—— c:\windows\system32\dllcache\scr111.sys
2010-04-02 09:45 16,640 ac—— c:\windows\system32\dllcache\scmstcs.sys
2010-04-02 09:45 23,936 ac—— c:\windows\system32\dllcache\sccmusbm.sys
2010-04-02 09:45 23,936 ac—— c:\windows\system32\dllcache\sccmn50m.sys
2010-04-02 09:45 43,904 ac—— c:\windows\system32\dllcache\sbp2port.sys
2010-04-02 09:45 495,616 ac—— c:\windows\system32\dllcache\sblfx.dll
2010-04-02 09:45 75,392 ac—— c:\windows\system32\dllcache\s3savmxm.sys
2010-04-02 09:45 245,632 ac—— c:\windows\system32\dllcache\s3savmx.dll
2010-04-02 09:45 77,824 ac—— c:\windows\system32\dllcache\s3sav4m.sys
2010-04-02 09:45 198,400 ac—— c:\windows\system32\dllcache\s3sav4.dll
2010-04-02 09:44 61,504 ac—— c:\windows\system32\dllcache\s3sav3dm.sys
2010-04-02 09:44 179,264 ac—— c:\windows\system32\dllcache\s3sav3d.dll
2010-04-02 09:44 210,496 ac—— c:\windows\system32\dllcache\s3mvirge.dll
2010-04-02 09:44 62,496 ac—— c:\windows\system32\dllcache\s3mtrio.dll
2010-04-02 09:44 41,216 ac—— c:\windows\system32\dllcache\s3mt3d.sys
2010-04-02 09:44 182,272 ac—— c:\windows\system32\dllcache\s3mt3d.dll
2010-04-02 09:44 166,720 ac—— c:\windows\system32\dllcache\s3m.sys
2010-04-02 09:44 65,664 ac—— c:\windows\system32\dllcache\s3legacy.sys
2010-04-02 09:44 82,432 ac—— c:\windows\system32\dllcache\rwia450.dll
2010-04-02 09:44 79,872 ac—— c:\windows\system32\dllcache\rwia430.dll
2010-04-02 09:44 29,696 ac—— c:\windows\system32\dllcache\rw450ext.dll
2010-04-02 09:44 27,648 ac—— c:\windows\system32\dllcache\rw430ext.dll
2010-04-02 09:43 20,992 ac—— c:\windows\system32\dllcache\rtl8139.sys
2010-04-02 09:43 19,017 ac—— c:\windows\system32\dllcache\rtl8029.sys
2010-04-02 09:43 30,720 ac—— c:\windows\system32\dllcache\rthwcls.sys
2010-04-02 09:43 9,216 ac—— c:\windows\system32\dllcache\rsmgrstr.dll
2010-04-02 09:43 3,840 ac—— c:\windows\system32\dllcache\rpfun.sys
2010-04-02 09:43 79,104 ac—— c:\windows\system32\dllcache\rocket.sys
2010-04-02 09:43 37,563 ac—— c:\windows\system32\dllcache\rlnet5.sys
2010-04-02 09:43 86,097 ac—— c:\windows\system32\dllcache\reslog32.dll
2010-04-02 09:42 19,584 ac—— c:\windows\system32\dllcache\rasirda.sys
2010-04-02 09:42 714,762 ac—— c:\windows\system32\dllcache\r2mdmkxx.sys
2010-04-02 09:42 899,146 ac—— c:\windows\system32\dllcache\r2mdkxga.sys
2010-04-02 09:42 41,472 ac—— c:\windows\system32\dllcache\qvusd.dll
2010-04-02 09:42 3,328 ac—— c:\windows\system32\dllcache\qv2kux.sys
2010-04-02 09:42 49,024 ac—— c:\windows\system32\dllcache\ql1280.sys
2010-04-02 09:41 40,448 ac—— c:\windows\system32\dllcache\ql1240.sys
2010-04-02 09:41 45,312 ac—— c:\windows\system32\dllcache\ql12160.sys
2010-04-02 09:41 33,152 ac—— c:\windows\system32\dllcache\ql10wnt.sys
2010-04-02 09:41 40,320 ac—— c:\windows\system32\dllcache\ql1080.sys
2010-04-02 09:41 6,016 ac—— c:\windows\system32\dllcache\qic157.sys
2010-04-02 09:41 130,942 ac—— c:\windows\system32\dllcache\ptserlv.sys
2010-04-02 09:41 112,574 ac—— c:\windows\system32\dllcache\ptserlp.sys
2010-04-02 09:40 128,286 ac—— c:\windows\system32\dllcache\ptserli.sys
2010-04-02 09:40 159,232 ac—— c:\windows\system32\dllcache\ptpusd.dll
2010-04-02 09:40 5,632 ac—— c:\windows\system32\dllcache\ptpusb.dll
2010-04-02 09:40 33,280 ac—— c:\windows\system32\dllcache\psisrndr.ax
2010-04-02 09:40 35,328 ac—— c:\windows\system32\dllcache\psisload.dll
2010-04-02 09:40 363,520 ac—— c:\windows\system32\dllcache\psisdecd.dll
2010-04-02 09:40 16,128 ac—— c:\windows\system32\dllcache\pscr.sys
2010-04-02 09:40 17,664 ac—— c:\windows\system32\dllcache\ppa3.sys
2010-04-02 09:40 17,792 ac—— c:\windows\system32\dllcache\ppa.sys
2010-04-02 09:40 8,832 ac—— c:\windows\system32\dllcache\powerfil.sys
2010-04-02 09:40 7,168 ac—— c:\windows\system32\dllcache\pnrmc.sys
2010-04-02 09:40 121,344 ac—— c:\windows\system32\dllcache\phvfwext.dll
2010-04-02 09:38 29,769 ac—— c:\windows\system32\dllcache\pcntn5m.sys
2010-04-02 09:38 30,282 ac—— c:\windows\system32\dllcache\pcntn5hl.sys
2010-04-02 09:38 26,153 ac—— c:\windows\system32\dllcache\pcmlm56.sys
2010-04-02 09:38 3,328 ac—— c:\windows\system32\dllcache\pciide.sys
2010-04-02 09:38 29,502 ac—— c:\windows\system32\dllcache\pca200e.sys
2010-04-02 09:38 30,495 ac—— c:\windows\system32\dllcache\pc100nds.sys
2010-04-02 09:38 41,984 ac—— c:\windows\system32\dllcache\ovui2rc.dll
2010-04-02 09:38 44,544 ac—— c:\windows\system32\dllcache\ovui2.dll
2010-04-02 09:38 25,216 ac—— c:\windows\system32\dllcache\ovsound2.sys
2010-04-02 09:38 39,424 ac—— c:\windows\system32\dllcache\ovcoms.exe
2010-04-02 09:38 20,480 ac—— c:\windows\system32\dllcache\ovcomc.dll
2010-04-02 09:37 351,616 ac—— c:\windows\system32\dllcache\ovcodek2.sys
2010-04-02 09:37 116,736 ac—— c:\windows\system32\dllcache\ovcodec2.dll
2010-04-02 09:37 31,872 ac—— c:\windows\system32\dllcache\ovce.sys
2010-04-02 09:37 28,032 ac—— c:\windows\system32\dllcache\ovcd.sys
2010-04-02 09:37 48,000 ac—— c:\windows\system32\dllcache\ovcam2.sys
2010-04-02 09:37 25,088 ac—— c:\windows\system32\dllcache\ovca.sys
2010-04-02 09:37 54,186 ac—— c:\windows\system32\dllcache\otcsercb.sys
2010-04-02 09:37 43,689 ac—— c:\windows\system32\dllcache\otceth5.sys
2010-04-02 09:37 27,209 ac—— c:\windows\system32\dllcache\otc06x5.sys
2010-04-02 09:37 54,528 ac—— c:\windows\system32\dllcache\opl3sax.sys
2010-04-02 09:36 198,144 ac—— c:\windows\system32\dllcache\nv3.sys
2010-04-02 09:36 123,776 ac—— c:\windows\system32\dllcache\nv3.dll
2010-04-02 09:36 51,552 ac—— c:\windows\system32\dllcache\ntgrip.sys
2010-04-02 09:36 9,344 ac—— c:\windows\system32\dllcache\ntapm.sys
2010-04-02 09:36 7,552 ac—— c:\windows\system32\dllcache\nsmmc.sys
2010-04-02 09:36 28,672 ac—— c:\windows\system32\dllcache\nscirda.sys
2010-04-02 09:36 87,040 ac—— c:\windows\system32\dllcache\nm6wdm.sys
2010-04-02 09:36 126,080 ac—— c:\windows\system32\dllcache\nm5a2wdm.sys
2010-04-02 09:36 32,840 ac—— c:\windows\system32\dllcache\ngrpci.sys
2010-04-02 09:35 132,695 ac—— c:\windows\system32\dllcache\netwlan5.sys
2010-04-02 09:35 65,278 ac—— c:\windows\system32\dllcache\netflx3.sys
2010-04-02 09:35 39,264 ac—— c:\windows\system32\dllcache\neo20xx.sys
2010-04-02 09:35 60,480 ac—— c:\windows\system32\dllcache\neo20xx.dll
2010-04-02 09:35 15,872 ac—— c:\windows\system32\dllcache\ne2000.sys
2010-04-02 09:35 91,488 ac—— c:\windows\system32\dllcache\n9i3disp.dll
2010-04-02 09:35 27,936 ac—— c:\windows\system32\dllcache\n9i3d.sys
2010-04-02 09:35 33,088 ac—— c:\windows\system32\dllcache\n9i128v2.sys
2010-04-02 09:35 59,104 ac—— c:\windows\system32\dllcache\n9i128v2.dll
2010-04-02 09:35 13,664 ac—— c:\windows\system32\dllcache\n9i128.sys
2010-04-02 09:34 35,392 ac—— c:\windows\system32\dllcache\n9i128.dll
2010-04-02 09:34 128,000 ac—— c:\windows\system32\dllcache\n100325.sys
2010-04-02 09:34 52,255 ac—— c:\windows\system32\dllcache\n1000nt5.sys
2010-04-02 09:34 75,520 ac—— c:\windows\system32\dllcache\mxport.sys
2010-04-02 09:34 7,168 ac—— c:\windows\system32\dllcache\mxport.dll
2010-04-02 09:34 19,968 ac—— c:\windows\system32\dllcache\mxnic.sys
2010-04-02 09:34 19,968 ac—— c:\windows\system32\dllcache\mxicfg.dll
2010-04-02 09:34 21,888 ac—— c:\windows\system32\dllcache\mxcard.sys
2010-04-02 09:34 103,296 ac—— c:\windows\system32\dllcache\mtxvideo.sys
2010-04-02 09:34 49,024 ac—— c:\windows\system32\dllcache\mstape.sys
2010-04-02 09:33 12,416 ac—— c:\windows\system32\dllcache\msriffwv.sys
2010-04-02 09:33 22,016 ac—— c:\windows\system32\dllcache\msircomm.sys
2010-04-02 09:33 35,200 ac—— c:\windows\system32\dllcache\msgame.sys
2010-04-02 09:33 6,016 ac—— c:\windows\system32\dllcache\msfsio.sys
2010-04-02 09:33 56,832 ac—— c:\windows\system32\dllcache\msdvbnp.ax
2010-04-02 09:33 51,200 ac—— c:\windows\system32\dllcache\msdv.sys
2010-04-02 09:32 17,280 ac—— c:\windows\system32\dllcache\mraid35x.sys
2010-04-02 09:32 15,232 ac—— c:\windows\system32\dllcache\mpe.sys
2010-04-02 09:32 12,160 ac—— c:\windows\system32\dllcache\mouhid.sys
2010-04-02 09:32 16,128 ac—— c:\windows\system32\dllcache\modemcsa.sys
2010-04-02 09:32 6,528 ac—— c:\windows\system32\dllcache\miniqic.sys
2010-04-02 09:32 320,384 ac—— c:\windows\system32\dllcache\mgaum.sys
2010-04-02 09:32 235,648 ac—— c:\windows\system32\dllcache\mgaud.dll
2010-04-02 09:32 26,112 ac—— c:\windows\system32\dllcache\memstpci.sys
2010-04-02 09:32 47,616 ac—— c:\windows\system32\dllcache\memgrp.dll
2010-04-02 09:31 8,320 ac—— c:\windows\system32\dllcache\memcard.sys
2010-04-02 09:31 164,586 ac—— c:\windows\system32\dllcache\mdgndis5.sys
2010-04-02 09:31 7,424 ac—— c:\windows\system32\dllcache\mammoth.sys
2010-04-02 09:31 48,768 ac—— c:\windows\system32\dllcache\maestro.sys
2010-04-02 09:31 58,880 ac—— c:\windows\system32\dllcache\m3092dc.dll
2010-04-02 09:31 58,368 ac—— c:\windows\system32\dllcache\m3091dc.dll
2010-04-02 09:31 22,848 ac—— c:\windows\system32\dllcache\lwusbhid.sys
2010-04-02 09:31 20,864 ac—— c:\windows\system32\dllcache\lwadihid.sys
2010-04-02 09:31 797,500 ac—— c:\windows\system32\dllcache\ltsmt.sys
2010-04-02 09:29 37,376 ac—— c:\windows\system32\dllcache\kousd.dll
2010-04-02 09:29 253,952 ac—— c:\windows\system32\dllcache\kdsusd.dll
2010-04-02 09:29 48,640 ac—— c:\windows\system32\dllcache\kdsui.dll
2010-04-02 09:29 8,192 ac—— c:\windows\system32\dllcache\kbdkor.dll
2010-04-02 09:29 8,704 ac—— c:\windows\system32\dllcache\kbdjpn.dll
2010-04-02 09:29 14,592 ac—— c:\windows\system32\dllcache\kbdhid.sys
2010-04-02 09:27 13,056 ac—— c:\windows\system32\dllcache\inport.sys
2010-04-02 09:27 16,000 ac—— c:\windows\system32\dllcache\ini910u.sys
2010-04-02 09:26 372,824 ac—— c:\windows\system32\dllcache\iconf32.dll
2010-04-02 09:26 100,992 ac—— c:\windows\system32\dllcache\icam5usb.sys
2010-04-02 09:26 20,480 ac—— c:\windows\system32\dllcache\icam5ext.dll
2010-04-02 09:26 45,056 ac—— c:\windows\system32\dllcache\icam5com.dll
2010-04-02 09:26 154,496 ac—— c:\windows\system32\dllcache\icam4usb.sys
2010-04-02 09:26 61,952 ac—— c:\windows\system32\dllcache\icam4ext.dll
2010-04-02 09:26 91,136 ac—— c:\windows\system32\dllcache\icam4com.dll
2010-04-02 09:26 26,624 ac—— c:\windows\system32\dllcache\icam3ext.dll
2010-04-02 09:26 141,056 ac—— c:\windows\system32\dllcache\icam3.sys
2010-04-02 09:26 38,528 ac—— c:\windows\system32\dllcache\ibmvcap.sys
2010-04-02 09:25 109,085 ac—— c:\windows\system32\dllcache\ibmtrp.sys
2010-04-02 09:25 100,936 ac—— c:\windows\system32\dllcache\ibmtok.sys
2010-04-02 09:25 9,216 ac—— c:\windows\system32\dllcache\ibmsgnet.dll
2010-04-02 09:25 28,700 ac—— c:\windows\system32\dllcache\ibmexmp.sys
2010-04-02 09:25 161,020 ac—— c:\windows\system32\dllcache\i81xnt5.sys
2010-04-02 09:25 702,845 ac—— c:\windows\system32\dllcache\i81xdnt5.dll
2010-04-02 09:25 58,592 ac—— c:\windows\system32\dllcache\i740nt5.sys
2010-04-02 09:25 353,184 ac—— c:\windows\system32\dllcache\i740dnt5.dll
2010-04-02 09:25 18,560 ac—— c:\windows\system32\dllcache\i2omp.sys
2010-04-02 09:25 8,576 ac—— c:\windows\system32\dllcache\i2omgmt.sys
2010-04-02 09:23 19,456 ac—— c:\windows\system32\dllcache\hr1w.dll
2010-04-02 09:23 5,760 ac—— c:\windows\system32\dllcache\hpt4qic.sys
2010-04-02 09:23 13,312 ac—— c:\windows\system32\dllcache\hpsjmcro.dll
2010-04-02 09:23 324,608 ac—— c:\windows\system32\dllcache\hpojwia.dll
2010-04-02 09:23 25,952 ac—— c:\windows\system32\dllcache\hpn.sys
2010-04-02 09:23 32,768 ac—— c:\windows\system32\dllcache\hpgtmcro.dll
2010-04-02 09:23 68,608 ac—— c:\windows\system32\dllcache\hpgt53tk.dll
2010-04-02 09:23 165,888 ac—— c:\windows\system32\dllcache\hpgt53.dll
2010-04-02 09:23 31,232 ac—— c:\windows\system32\dllcache\hpgt42tk.dll
2010-04-02 09:23 93,696 ac—— c:\windows\system32\dllcache\hpgt42.dll
2010-04-02 09:23 126,976 ac—— c:\windows\system32\dllcache\hpgt34tk.dll
2010-04-02 09:23 101,376 ac—— c:\windows\system32\dllcache\hpgt34.dll
2010-04-02 09:23 48,128 ac—— c:\windows\system32\dllcache\hpgt33tk.dll
2010-04-02 09:21 1,733,120 ac—— c:\windows\system32\dllcache\g400d.dll
2010-04-02 09:21 320,384 ac—— c:\windows\system32\dllcache\g200m.sys
2010-04-02 09:21 470,144 ac—— c:\windows\system32\dllcache\g200d.dll
2010-04-02 09:21 454,912 ac—— c:\windows\system32\dllcache\fxusbase.sys
2010-04-02 09:21 92,160 ac—— c:\windows\system32\dllcache\fuusd.dll
2010-04-02 09:21 455,296 ac—— c:\windows\system32\dllcache\fusbbase.sys
2010-04-02 09:21 455,680 ac—— c:\windows\system32\dllcache\fus2base.sys
2010-04-02 09:21 442,240 ac—— c:\windows\system32\dllcache\fpnpbase.sys
2010-04-02 09:21 441,728 ac—— c:\windows\system32\dllcache\fpcmbase.sys
2010-04-02 09:21 444,416 ac—— c:\windows\system32\dllcache\fpcibase.sys
2010-04-02 09:20 34,173 ac—— c:\windows\system32\dllcache\forehe.sys
2010-04-02 09:20 71,680 ac—— c:\windows\system32\dllcache\fnfilter.dll
2010-04-02 09:20 27,165 ac—— c:\windows\system32\dllcache\fetnd5.sys
2010-04-02 09:20 22,090 ac—— c:\windows\system32\dllcache\fem556n5.sys
2010-04-02 09:20 24,618 ac—— c:\windows\system32\dllcache\fa410nd5.sys
2010-04-02 09:20 16,074 ac—— c:\windows\system32\dllcache\fa312nd5.sys
2010-04-02 09:20 11,850 ac—— c:\windows\system32\dllcache\f3ab18xj.sys
2010-04-02 09:18 72,192 ac—— c:\windows\system32\dllcache\es1969.sys
2010-04-02 09:17 70,174 ac—— c:\windows\system32\dllcache\el98xn5.sys
2010-04-02 09:16 334,208 ac—— c:\windows\system32\dllcache\ds1wdm.sys
2010-04-02 09:16 20,192 ac—— c:\windows\system32\dllcache\dpti2o.sys
2010-04-02 09:16 28,062 ac—— c:\windows\system32\dllcache\dp83820.sys
2010-04-02 09:16 23,808 ac—— c:\windows\system32\dllcache\dot4usb.sys
2010-04-02 09:16 8,704 ac—— c:\windows\system32\dllcache\dot4scan.sys
2010-04-02 09:16 12,928 ac—— c:\windows\system32\dllcache\dot4prt.sys
2010-04-02 09:16 206,976 ac—— c:\windows\system32\dllcache\dot4.sys
2010-04-02 09:14 229,462 ac—— c:\windows\system32\dllcache\digifwrk.dll
2010-04-02 09:13 14,720 ac—— c:\windows\system32\dllcache\dac960nt.sys
2010-04-02 09:12 21,533 ac—— c:\windows\system32\dllcache\cpqndis5.sys
2010-04-02 09:11 37,916 ac—— c:\windows\system32\dllcache\cb102.sys
2010-04-02 09:10 32,256 ac—— c:\windows\system32\dllcache\brmfrsmg.exe
2010-04-02 09:09 137,216 ac—— c:\windows\system32\dllcache\atidrae.dll
2010-04-02 09:05 101,888 ac—— c:\windows\system32\dllcache\adpu160m.sys
2010-04-02 09:04 66,048 ac—— c:\windows\system32\dllcache\s3legacy.dll
2010-03-30 14:16 –d—– c:\docume~1\frank\applic~1\AVG9
2010-03-30 11:50 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-03-30 11:50 216,200 a——- c:\windows\system32\drivers\avgldx86.sys
2010-03-30 11:49 –d—– c:\windows\system32\drivers\Avg
2010-03-30 11:49 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2010-03-30 11:48 242,696 a——- c:\windows\system32\drivers\avgtdix.sys
2010-03-30 11:48 –d—– c:\program files\AVG
2010-03-30 11:48 –d—– c:\docume~1\alluse~1\applic~1\avg9
2010-03-27 00:12 –d—– c:\windows\Profiles
2010-03-24 11:06 64,000 -c—— c:\windows\system32\dllcache\iecompat.dll
2010-03-24 11:05 247,808 -c—— c:\windows\system32\dllcache\ieproxy.dll
2010-03-24 11:05 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2010-03-23 08:50 –d—– c:\program files\SpywareBlaster
2010-03-21 11:57 594,432 -c—— c:\windows\system32\dllcache\msfeeds.dll
2010-03-21 11:57 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll
2010-03-21 11:57 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2010-03-21 11:57 59,904 ac—— c:\windows\system32\dllcache\icardie.dll
2010-03-21 11:57 13,824 -c—— c:\windows\system32\dllcache\ieudinit.exe
2010-03-21 11:57 445,952 ac—— c:\windows\system32\dllcache\ieapfltr.dll
2010-03-21 11:57 3,698,584 ac—— c:\windows\system32\dllcache\ieapfltr.dat
2010-03-21 11:57 1,241,088 ac—— c:\windows\system32\dllcache\ieframe.dll.mui
2010-03-21 11:57 11,070,976 -c—— c:\windows\system32\dllcache\ieframe.dll
2010-03-21 01:41 –d—– c:\docume~1\alluse~1\applic~1\Alwil Software
2010-03-20 23:54 –d—– c:\program files\Spybot - Search & Destroy
2010-03-20 23:54 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-20 23:00 –d—– c:\docume~1\frank\applic~1\Malwarebytes
2010-03-20 23:00 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-20 23:00 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-20 23:00 20,824 a——- c:\windows\system32\drivers\mbam.sys
2010-03-20 23:00 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-17 13:49 –d—– c:\docume~1\alluse~1\applic~1\Yahoo! Companion(3)
2010-03-11 14:52 54,156 a—h— c:\windows\QTFont.qfn
2010-03-11 14:52 1,409 a——- c:\windows\QTFont.for

==================== Find3M ====================

2010-04-05 08:15 0 a——- c:\windows\system32\drivers\lvuvc.hs
2010-04-05 08:15 0 a——- c:\windows\system32\drivers\logiflt.iad
2010-02-25 02:24 916,480 a——- c:\windows\system32\wininet.dll

============= FINISH: 10:54:33.84 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-05 11:39:45
Windows 5.1.2600 Service Pack 3
Running: kkm0kfcz.exe; Driver: C:\DOCUME~1\Frank\LOCALS~1\Temp\ugldrfog.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 10/14/2009 5:44:10 PM
System Uptime: 4/5/2010 8:06:51 AM (2 hours ago)

Motherboard: ASUSTeK Computer INC. | | WMT-LE
Processor: Intel® Pentium® 4 CPU 1500MHz | PGA 423 | 1495/100mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 75 GiB total, 30.6 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Instant Wireless-B PCI Adapter
Device ID: PCI\VEN_17FE&DEV_2120&SUBSYS_00201737&REV_00\4&11CD5334&0&50F0
Manufacturer: Linksys
Name: Instant Wireless-B PCI Adapter
PNP Device ID: PCI\VEN_17FE&DEV_2120&SUBSYS_00201737&REV_00\4&11CD5334&0&50F0
Service: IPN2120

==== System Restore Points ===================

RP1: 3/22/2010 6:41:09 PM - System Checkpoint
RP2: 3/22/2010 6:41:52 PM - Franks
RP3: 3/23/2010 9:45:41 AM - avast! Free Antivirus Setup
RP4: 3/23/2010 10:00:04 AM - Removed AVG Free 9.0
RP5: 3/23/2010 10:03:19 AM - Installed AVG Free 9.0
RP6: 3/24/2010 9:04:19 AM - Installed Windows NLSDownlevelMapping.
RP7: 3/24/2010 9:05:13 AM - Installed Windows IDNMitigationAPIs.
RP8: 3/24/2010 9:06:49 AM - Installed Windows Internet Explorer 7.
RP9: 3/24/2010 9:08:09 AM - Software Distribution Service 3.0
RP10: 3/24/2010 11:14:53 AM - Installed Windows Internet Explorer 8.
RP11: 3/24/2010 11:31:20 AM - Software Distribution Service 3.0
RP12: 3/24/2010 12:36:58 PM - Software Distribution Service 3.0
RP13: 3/25/2010 3:52:12 PM - System Checkpoint
RP14: 3/26/2010 4:06:28 PM - System Checkpoint
RP15: 3/27/2010 9:43:32 AM - Restore Operation
RP16: 3/28/2010 12:42:45 PM - System Checkpoint
RP17: 3/29/2010 1:18:44 PM - System Checkpoint
RP18: 3/30/2010 11:48:14 AM - Installed AVG Free 9.0
RP19: 3/30/2010 11:59:26 AM - Avg Update
RP20: 3/31/2010 8:52:44 AM - Software Distribution Service 3.0
RP21: 4/1/2010 11:56:36 AM - Avg Update
RP22: 4/1/2010 11:59:42 AM - Avg Update
RP23: 4/2/2010 5:58:11 PM - System Checkpoint
RP24: 4/3/2010 9:25:41 AM - Restore Operation
RP25: 4/5/2010 9:24:52 AM - Frank

==== Installed Programs ======================

Acrobat.com
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.1
ArcSoft PhotoImpression 5
Art of Wine Professional 3.0.0
AVG Free 9.0
CA Yahoo! Anti-Spy (remove only)
CCleaner
Creative Jukebox Driver
Creative MediaSource
Creative Zen Micro
Creative Zen Micro (PlaysForSure)
EPSON CX6000 Series User's Guide
EPSON Printer Software
EPSON Scan
EPSON Stylus CX6000 Scanner Driver Update
EPSON Web-To-Page
ERUNT 1.1j
FreeOcr V1
friendsareangels_3043706 Screen Saver
Garmin USB Drivers
Garmin WebUpdater
Glary Utilities 2.21.0.863
gonefishing_3043512 Screen Saver
Google Chrome
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
HP USB Disk Storage Format Tool
iISystem Wiper 2.4.1
Java™ 6 Update 3
Java™ 6 Update 5
Logitech Vid
Logitech Webcam Software
Logitech Webcam Software Driver Package
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 SR-1 Disc 2
Microsoft Office 2000 SR-1 Small Business
Microsoft Visual C Runtime
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
nature_3120380 Screen Saver
NVIDIA Windows 2000/XP Display Drivers
Picasa 3
QuickTime
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB954155)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
SpywareBlaster 4.2
SUPERAntiSpyware Free Edition
tropicalreef_3116236 Screen Saver
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows Internet Explorer 8 (KB980302)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
WebFldrs XP
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
Yahoo! Extras
Yahoo! Internet Mail
Yahoo! Search Protection
Yahoo! Software Update
Yahoo! Toolbar
Zen Micro Media Explorer

==== Event Viewer Messages From Past Week ========

4/3/2010 9:31:13 AM, error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
4/2/2010 9:27:46 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\inetwiz.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.
4/2/2010 9:27:45 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\inetwiz.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:27:18 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\iedw.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.
4/2/2010 9:27:17 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\iedw.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:27:09 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwutil.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.
4/2/2010 9:27:08 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwutil.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:27:05 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwrmind.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.
4/2/2010 9:27:03 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwrmind.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:27:00 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwhelp.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.
4/2/2010 9:26:58 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwhelp.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:26:57 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwdl.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.
4/2/2010 9:26:57 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwdl.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:26:55 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwconn2.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.
4/2/2010 9:26:54 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwconn2.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:26:53 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwconn1.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.
4/2/2010 9:26:52 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwconn1.exe has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:26:52 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwconn.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.5512.
4/2/2010 9:26:51 AM, information: Windows File Protection [64020] - Windows File Protection scan found that the system file c:\program files\internet explorer\connection wizard\icwconn.dll has a bad signature. This file was restored to the original version to maintain system stability. The file version of the system file is 0.0.0.1.
4/2/2010 9:02:33 AM, information: Windows File Protection [64016] - Windows File Protection file scan was started.
4/2/2010 10:03:10 AM, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully.
4/1/2010 12:02:01 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the avg9wd service.
4/1/2010 11:51:27 AM, error: Service Control Manager [7000] - The McciCMService service failed to start due to the following error: The system cannot find the file specified.
3/31/2010 8:06:56 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
3/31/2010 8:06:56 AM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/30/2010 11:00:29 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
3/30/2010 10:57:52 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
3/30/2010 10:56:48 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips IPSec MRxSmb NetBIOS NetBT Processor RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL
3/30/2010 10:37:51 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSP aswTdi Fips Processor SASDIFSV SASKUTIL
3/30/2010 1:49:16 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
3/30/2010 1:46:45 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
3/30/2010 1:46:45 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
3/30/2010 1:07:07 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT Processor RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL
3/30/2010 1:07:07 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
3/30/2010 1:07:07 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
3/30/2010 1:07:07 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
3/30/2010 1:07:07 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.

==== End Of File ===========================
Hi,

please run the following:

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi thanks for helping, i i am not thst couputer smart so please be patient with me thanks. GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-07 17:20:34
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Frank\LOCALS~1\Temp\ugldrfog.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Crwl39.gthr 392 bytes
File C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Crwl40.gthr 392 bytes

—- EOF - GMER 1.0.15 —-
hi,

no problem, anything you don't understand - just ask, I'll try and explain the best I can:

please do the following:

Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi heres my combo fix log thanks. ComboFix 10-04-06.05 - Frank 04/07/2010 23:03:52.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.255.20 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\cfg.dat

.
((((((((((((((((((((((((( Files Created from 2010-03-08 to 2010-04-08 )))))))))))))))))))))))))))))))
.

2010-04-03 18:11 . 2010-04-03 18:11 ——– d—–w- c:\documents and settings\Frank\Local Settings\Application Data\Temp
2010-04-03 18:09 . 2010-04-03 18:10 ——– d—–w- c:\documents and settings\Frank\Local Settings\Application Data\Deployment
2010-04-03 13:27 . 2010-04-03 13:27 ——– d—–w- c:\windows\system32\wbem\Repository
2010-04-02 14:03 . 2008-04-14 00:12 116224 -c–a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-04-02 14:02 . 2001-08-18 02:36 23040 -c–a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-04-02 14:02 . 2008-04-14 00:12 18944 -c–a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-04-02 14:02 . 2001-08-18 02:37 27648 -c–a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-04-02 14:02 . 2001-08-18 02:37 4608 -c–a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-04-02 14:02 . 2001-08-18 02:37 99865 -c–a-w- c:\windows\system32\dllcache\xlog.exe
2010-04-02 14:02 . 2001-08-17 16:11 16970 -c–a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-04-02 14:02 . 2004-08-04 02:29 19455 -c–a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-04-02 14:02 . 2004-08-04 02:29 12063 -c–a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-04-02 14:01 . 2008-04-14 00:12 8192 -c–a-w- c:\windows\system32\dllcache\wshirda.dll
2010-04-02 14:01 . 2008-04-13 18:36 8832 -c–a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-04-02 14:01 . 2004-08-04 02:31 154624 -c–a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-04-02 14:01 . 2001-08-17 16:12 34890 -c–a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-04-02 14:00 . 2001-08-17 17:28 771581 -c–a-w- c:\windows\system32\dllcache\winacisa.sys
2010-04-02 14:00 . 2001-08-18 02:36 53760 -c–a-w- c:\windows\system32\dllcache\wiamsmud.dll
2010-04-02 14:00 . 2001-08-18 02:36 87040 -c–a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-04-02 14:00 . 2001-08-17 17:28 701386 -c–a-w- c:\windows\system32\dllcache\wdhaalba.sys
2010-04-02 13:59 . 2004-08-04 02:29 23615 -c–a-w- c:\windows\system32\dllcache\wch7xxnt.sys
2010-04-02 13:59 . 2001-08-17 16:10 35871 -c–a-w- c:\windows\system32\dllcache\wbfirdma.sys
2010-04-02 13:59 . 2004-08-04 02:29 33599 -c–a-w- c:\windows\system32\dllcache\watv04nt.sys
2010-04-02 13:59 . 2004-08-04 02:29 19551 -c–a-w- c:\windows\system32\dllcache\watv02nt.sys
2010-04-02 13:59 . 2004-08-04 02:29 29311 -c–a-w- c:\windows\system32\dllcache\watv01nt.sys
2010-04-02 13:59 . 2004-08-04 02:29 11775 -c–a-w- c:\windows\system32\dllcache\wadv05nt.sys
2010-04-02 13:59 . 2004-08-04 02:29 12127 -c–a-w- c:\windows\system32\dllcache\wadv02nt.sys
2010-04-02 13:59 . 2004-08-04 02:29 12415 -c–a-w- c:\windows\system32\dllcache\wadv01nt.sys
2010-04-02 13:59 . 2001-08-17 16:13 16925 -c–a-w- c:\windows\system32\dllcache\w940nd.sys
2010-04-02 13:59 . 2001-08-17 16:13 19016 -c–a-w- c:\windows\system32\dllcache\w926nd.sys
2010-04-02 13:59 . 2001-08-17 16:13 19528 -c–a-w- c:\windows\system32\dllcache\w840nd.sys
2010-04-02 13:58 . 2001-08-17 17:28 64605 -c–a-w- c:\windows\system32\dllcache\vvoice.sys
2010-04-02 13:58 . 2001-08-17 17:28 397502 -c–a-w- c:\windows\system32\dllcache\vpctcom.sys
2010-04-02 13:58 . 2001-08-17 17:28 604253 -c–a-w- c:\windows\system32\dllcache\vmodem.sys
2010-04-02 13:58 . 2001-08-17 16:14 249402 -c–a-w- c:\windows\system32\dllcache\vinwm.sys
2010-04-02 13:58 . 2001-08-17 17:49 24576 -c–a-w- c:\windows\system32\dllcache\viairda.sys
2010-04-02 13:58 . 2008-04-13 18:40 5376 -c–a-w- c:\windows\system32\dllcache\viaide.sys
2010-04-02 13:58 . 2001-08-17 17:28 687999 -c–a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2010-04-02 13:58 . 2001-08-17 17:28 765884 -c–a-w- c:\windows\system32\dllcache\usrti.sys
2010-04-02 13:57 . 2001-08-17 17:28 113762 -c–a-w- c:\windows\system32\dllcache\usrpda.sys
2010-04-02 13:57 . 2001-08-17 17:28 7556 -c–a-w- c:\windows\system32\dllcache\usroslba.sys
2010-04-02 13:57 . 2001-08-17 17:28 224802 -c–a-w- c:\windows\system32\dllcache\usr1807a.sys
2010-04-02 13:57 . 2001-08-17 17:28 794399 -c–a-w- c:\windows\system32\dllcache\usr1806v.sys
2010-04-02 13:57 . 2001-08-17 17:28 793598 -c–a-w- c:\windows\system32\dllcache\usr1806.sys
2010-04-02 13:57 . 2001-08-17 17:28 794654 -c–a-w- c:\windows\system32\dllcache\usr1801.sys
2010-04-02 13:57 . 2008-04-13 18:45 26112 -c–a-w- c:\windows\system32\dllcache\usbser.sys
2010-04-02 13:57 . 2008-04-13 18:45 17152 -c–a-w- c:\windows\system32\dllcache\usbohci.sys
2010-04-02 13:57 . 2004-08-04 02:31 32384 -c–a-w- c:\windows\system32\dllcache\usb101et.sys
2010-04-02 13:56 . 2001-08-18 02:36 94720 -c–a-w- c:\windows\system32\dllcache\umaxud32.dll
2010-04-02 13:56 . 2001-08-18 02:36 28160 -c–a-w- c:\windows\system32\dllcache\umaxu40.dll
2010-04-02 13:56 . 2001-08-18 02:36 26624 -c–a-w- c:\windows\system32\dllcache\umaxu22.dll
2010-04-02 13:56 . 2001-08-18 02:36 69632 -c–a-w- c:\windows\system32\dllcache\umaxu12.dll
2010-04-02 13:56 . 2001-08-18 02:36 50688 -c–a-w- c:\windows\system32\dllcache\umaxscan.dll
2010-04-02 13:56 . 2001-08-17 17:58 22912 -c–a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-04-02 13:56 . 2001-08-18 02:36 50176 -c–a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-04-02 13:56 . 2001-08-18 02:36 47616 -c–a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-04-02 13:56 . 2001-08-18 02:36 211968 -c–a-w- c:\windows\system32\dllcache\um54scan.dll
2010-04-02 13:55 . 2001-08-18 02:36 216064 -c–a-w- c:\windows\system32\dllcache\um34scan.dll
2010-04-02 13:55 . 2001-08-17 17:52 36736 -c–a-w- c:\windows\system32\dllcache\ultra.sys
2010-04-02 13:55 . 2001-08-17 17:48 11520 -c–a-w- c:\windows\system32\dllcache\twotrack.sys
2010-04-02 13:55 . 2001-08-17 16:51 166784 -c–a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-04-02 13:55 . 2001-08-18 02:36 525568 -c–a-w- c:\windows\system32\dllcache\tridxp.dll
2010-04-02 13:55 . 2001-08-17 16:51 159232 -c–a-w- c:\windows\system32\dllcache\tridkbm.sys
2010-04-02 13:55 . 2001-08-17 18:56 440576 -c–a-w- c:\windows\system32\dllcache\tridkb.dll
2010-04-02 13:54 . 2001-08-17 16:51 222336 -c–a-w- c:\windows\system32\dllcache\trid3dm.sys
2010-04-02 13:54 . 2001-08-17 18:56 315520 -c–a-w- c:\windows\system32\dllcache\trid3d.dll
2010-04-02 13:54 . 2001-08-17 16:12 34375 -c–a-w- c:\windows\system32\dllcache\tpro4.sys
2010-04-02 13:54 . 2001-08-18 02:35 42496 -c–a-w- c:\windows\system32\dllcache\tp4res.dll
2010-04-02 13:54 . 2008-04-14 00:12 82944 -c–a-w- c:\windows\system32\dllcache\tp4mon.exe
2010-04-02 13:54 . 2001-08-18 02:36 31744 -c–a-w- c:\windows\system32\dllcache\tp4.dll
2010-04-02 13:54 . 2001-08-17 17:51 4992 -c–a-w- c:\windows\system32\dllcache\toside.sys
2010-04-02 13:54 . 2001-08-17 18:02 230912 -c–a-w- c:\windows\system32\dllcache\tosdvd03.sys
2010-04-02 13:54 . 2001-08-17 18:01 241664 -c–a-w- c:\windows\system32\dllcache\tosdvd02.sys
2010-04-02 13:53 . 2001-08-17 16:10 28232 -c–a-w- c:\windows\system32\dllcache\tos4mo.sys
2010-04-02 13:53 . 2001-08-17 16:14 123995 -c–a-w- c:\windows\system32\dllcache\tjisdn.sys
2010-04-02 13:53 . 2001-08-17 16:51 138528 -c–a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2010-04-02 13:53 . 2001-08-17 18:56 81408 -c–a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-04-02 13:53 . 2008-04-13 18:40 149376 -c–a-w- c:\windows\system32\dllcache\tffsport.sys
2010-04-02 13:53 . 2001-08-17 16:13 17129 -c–a-w- c:\windows\system32\dllcache\tdkcd31.sys
2010-04-02 13:53 . 2001-08-17 16:13 37961 -c–a-w- c:\windows\system32\dllcache\tdk100b.sys
2010-04-02 13:53 . 2001-08-17 17:49 30464 -c–a-w- c:\windows\system32\dllcache\tbatm155.sys
2010-04-02 13:52 . 2001-08-17 17:52 7040 -c–a-w- c:\windows\system32\dllcache\tandqic.sys
2010-04-02 13:52 . 2001-08-17 16:50 36640 -c–a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-04-02 13:52 . 2001-08-17 18:56 172768 -c–a-w- c:\windows\system32\dllcache\t2r4disp.dll
2010-04-02 13:52 . 2001-08-17 18:07 32640 -c–a-w- c:\windows\system32\dllcache\symc8xx.sys
2010-04-02 13:52 . 2001-08-17 18:07 16256 -c–a-w- c:\windows\system32\dllcache\symc810.sys
2010-04-02 13:52 . 2001-08-17 18:07 30688 -c–a-w- c:\windows\system32\dllcache\sym_u3.sys
2010-04-02 13:52 . 2001-08-17 18:07 28384 -c–a-w- c:\windows\system32\dllcache\sym_hi.sys
2010-04-02 13:52 . 2001-08-18 02:36 94293 -c–a-w- c:\windows\system32\dllcache\sxports.dll
2010-04-02 13:52 . 2001-08-17 17:50 103936 -c–a-w- c:\windows\system32\dllcache\sx.sys
2010-04-02 13:51 . 2001-08-17 18:02 3968 -c–a-w- c:\windows\system32\dllcache\swusbflt.sys
2010-04-02 13:51 . 2001-08-18 02:36 10240 -c–a-w- c:\windows\system32\dllcache\swpidflt.dll
2010-04-02 13:51 . 2001-08-18 02:36 10240 -c–a-w- c:\windows\system32\dllcache\swpdflt2.dll
2010-04-02 13:51 . 2001-08-18 02:36 53760 -c–a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-04-02 13:51 . 2001-08-18 02:36 41472 -c–a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-04-02 13:51 . 2001-08-18 02:36 155648 -c–a-w- c:\windows\system32\dllcache\stlnprop.dll
2010-04-02 13:51 . 2001-08-18 02:36 53248 -c–a-w- c:\windows\system32\dllcache\stlncoin.dll
2010-04-02 13:51 . 2001-08-17 16:18 285760 -c–a-w- c:\windows\system32\dllcache\stlnata.sys
2010-04-02 13:51 . 2001-08-17 17:51 16896 -c–a-w- c:\windows\system32\dllcache\stcusb.sys
2010-04-02 13:50 . 2001-08-17 16:11 48736 -c–a-w- c:\windows\system32\dllcache\srwlnd5.sys
2010-04-02 13:50 . 2001-08-18 02:36 99328 -c–a-w- c:\windows\system32\dllcache\srusd.dll
2010-04-02 13:50 . 2001-08-18 02:36 24660 -c–a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-04-02 13:50 . 2001-08-17 17:51 61824 -c–a-w- c:\windows\system32\dllcache\speed.sys
2010-04-02 13:50 . 2001-08-18 02:36 106584 -c–a-w- c:\windows\system32\dllcache\spdports.dll
2010-04-02 13:50 . 2001-08-17 18:07 19072 -c–a-w- c:\windows\system32\dllcache\sparrow.sys
2010-04-02 13:50 . 2001-08-17 17:56 7552 -c–a-w- c:\windows\system32\dllcache\sonypvu1.sys
2010-04-02 13:50 . 2001-08-17 16:51 37040 -c–a-w- c:\windows\system32\dllcache\sonypi.sys
2010-04-02 13:49 . 2001-08-18 02:36 114688 -c–a-w- c:\windows\system32\dllcache\sonypi.dll
2010-04-02 13:49 . 2001-08-17 16:51 20752 -c–a-w- c:\windows\system32\dllcache\sonync.sys
2010-04-02 13:49 . 2001-08-17 17:53 9600 -c–a-w- c:\windows\system32\dllcache\sonymc.sys
2010-04-02 13:49 . 2008-04-13 18:40 7552 -c–a-w- c:\windows\system32\dllcache\sonyait.sys
2010-04-02 13:49 . 2001-08-17 17:53 7040 -c–a-w- c:\windows\system32\dllcache\snyaitmc.sys
2010-04-02 13:49 . 2001-08-17 16:51 58368 -c–a-w- c:\windows\system32\dllcache\smiminib.sys
2010-04-02 13:49 . 2001-08-17 18:56 147200 -c–a-w- c:\windows\system32\dllcache\smidispb.dll
2010-04-02 13:49 . 2001-08-17 16:12 25034 -c–a-w- c:\windows\system32\dllcache\smcpwr2n.sys
2010-04-02 13:49 . 2001-08-17 16:10 35913 -c–a-w- c:\windows\system32\dllcache\smcirda.sys
2010-04-02 13:48 . 2001-08-17 16:12 24576 -c–a-w- c:\windows\system32\dllcache\smc8000n.sys
2010-04-02 13:48 . 2001-08-17 17:57 6784 -c–a-w- c:\windows\system32\dllcache\smbhc.sys
2010-04-02 13:48 . 2008-04-13 18:36 6912 -c–a-w- c:\windows\system32\dllcache\smbclass.sys
2010-04-02 13:48 . 2008-04-13 18:36 16000 -c–a-w- c:\windows\system32\dllcache\smbbatt.sys
2010-04-02 13:48 . 2001-08-18 02:36 45568 -c–a-w- c:\windows\system32\dllcache\smb3w.dll
2010-04-02 13:48 . 2001-08-18 02:36 33792 -c–a-w- c:\windows\system32\dllcache\smb0w.dll
2010-04-02 13:48 . 2001-08-18 02:36 28672 -c–a-w- c:\windows\system32\dllcache\sma0w.dll
2010-04-02 13:48 . 2001-08-18 02:36 28160 -c–a-w- c:\windows\system32\dllcache\sm91w.dll
2010-04-02 13:48 . 2004-08-04 02:31 63547 -c–a-w- c:\windows\system32\dllcache\sla30nd5.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-08 02:45 . 2007-10-03 02:34 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-08 01:49 . 2010-04-08 01:25 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-08 01:48 . 2010-04-08 01:48 5918776 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-08 01:43 . 2010-02-15 00:27 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-04-08 01:43 . 2010-02-15 00:26 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-04-06 14:21 . 2007-08-31 14:10 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-06 13:16 . 2010-04-06 13:09 ——– d—–w- c:\program files\PCPitstop
2010-04-06 13:10 . 2010-04-06 13:09 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-03-30 04:46 . 2010-04-08 01:25 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 04:45 . 2010-04-08 01:25 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-30 03:42 . 2009-01-23 14:04 ——– d—–w- c:\program files\Glary Utilities
2010-03-30 03:29 . 2008-02-15 00:26 ——– d—–w- c:\program files\CCleaner
2010-03-28 15:37 . 2009-08-13 18:02 117760 —-a-w- c:\documents and settings\Frank\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-03-27 13:44 . 2007-08-31 14:10 ——– d—–w- c:\program files\Common Files\InstallShield
2010-03-17 17:44 . 2007-08-29 17:05 ——– d—–w- c:\program files\Yahoo!
2010-03-13 20:27 . 2008-02-15 00:18 ——– d—–w- c:\program files\iISystem Wiper
2010-03-07 15:46 . 2010-03-04 17:36 ——– d—–w- c:\documents and settings\Frank\Application Data\IObit
2010-03-07 01:45 . 2007-08-29 17:05 ——– d–h–r- c:\documents and settings\All Users\Application Data\yahoo!
2010-03-07 01:36 . 2007-08-29 17:06 ——– d—–w- c:\documents and settings\Frank\Application Data\Yahoo!
2010-03-05 21:10 . 2007-11-04 12:53 ——– d—–w- c:\program files\Windows Media Connect 2
2010-03-04 17:36 . 2010-03-04 17:36 ——– d—–w- c:\program files\IObit
2010-02-25 06:24 . 2006-02-28 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-25 03:20 . 2008-07-26 16:32 ——– d—–w- c:\documents and settings\Frank\Application Data\Uniblue
2010-02-25 03:20 . 2010-02-25 02:58 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverScanner
2010-02-21 06:43 . 2007-09-28 17:23 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-02-21 03:43 . 2007-12-07 14:52 ——– d—–w- c:\program files\Java
2010-02-15 03:23 . 2010-02-15 00:16 ——– d—–w- c:\program files\Common Files\LogiShrd
2010-02-15 02:14 . 2010-02-15 02:14 ——– d—–w- c:\documents and settings\Frank\Application Data\Logitech
2010-02-15 01:55 . 2010-02-15 00:16 ——– d—–w- c:\documents and settings\All Users\Application Data\LogiShrd
2010-02-15 00:41 . 2010-02-15 00:16 ——– d—–w- c:\program files\Logitech
2010-02-09 03:43 . 2010-01-23 13:32 ——– d—–w- c:\program files\Creative
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-02-23 18:04 1664256 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-02-23 1664256]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2003-07-28 49152]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-12-07 16:29 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-30 15:50 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\F:\0autocheck autochk *

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Frank^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\documents and settings\Frank\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 20:57 948672 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 06:57 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-02 23:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 -c—-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-04-03 18:10 136176 —-atw- c:\documents and settings\Frank\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iIWiper]
2005-09-11 17:24 258048 —-a-w- c:\program files\iISystem Wiper\SystemWiper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-10-14 18:36 2793304 —-a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 –sha-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2003-07-28 18:19 4841472 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2003-07-28 18:19 323584 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-03-29 03:37 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
2009-02-03 13:15 111856 —-a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-02-22 08:25 144784 -c–a-w- c:\program files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-02-21 06:43 2012912 —-a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2009-02-03 13:15 111856 —-a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/30/2010 11:50 AM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/30/2010 11:48 AM 242696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [9/15/2009 11:42 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 66632]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/30/2010 11:48 AM 308064]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 12872]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [3/30/2010 11:49 AM 369920]
S3 CA500AI;SPCA500A Still Image Capture, Sunplus Version 1.00;c:\windows\system32\Drivers\BULKUSB.sys –> c:\windows\system32\Drivers\BULKUSB.sys [?]
S3 CA500AV;CaptureView VGA;c:\windows\system32\DRIVERS\CA500AV.SYS –> c:\windows\system32\DRIVERS\CA500AV.SYS [?]
S3 IPN2120;Instant Wireless-B PCI Adapter Driver;c:\windows\system32\drivers\LSIPNDS.sys [7/10/2003 11:09 AM 96256]
S3 pctplsg;pctplsg;\??\c:\windows\system32\drivers\pctplsg.sys –> c:\windows\system32\drivers\pctplsg.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-04-08 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-01-23 17:03]

2010-04-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1563985344-854245398-1004Core.job
- c:\documents and settings\Frank\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-03 18:10]

2010-04-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-1563985344-854245398-1004UA.job
- c:\documents and settings\Frank\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-04-03 18:10]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearchAssistant =
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
DPF: {8BE5651C-D60B-4B59-B5B2-F0EB93733D17} - hxxps://www36.verizon.com/CallAssistant/MyAccount/UnProtected/Voice%20Mail/VCAVMUtil.CAB
.
- - - - ORPHANS REMOVED - - - -

Toolbar-ITBar7Position - (no file)
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
MSConfigStartUp-VerizonServicepoint - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-07 23:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1844237615-1563985344-854245398-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(700)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2010-04-07 23:20:01
ComboFix-quarantined-files.txt 2010-04-08 03:19

Pre-Run: 32,805,363,712 bytes free
Post-Run: 32,793,006,080 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 834150A09BF45F0A301A97EC6FD0BF36
Hi,

Please do the following:



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
hi thanks again this is a log i found that my nephew did Malwarebytes' Anti-Malware 1.44 Database version: 3889 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 6.0.2900.5512 3/20/2010 11:50:34 PM mbam-log-2010-03-20 (23-50-34).txt Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|) Objects scanned: 180389 Time elapsed: 28 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job (Trojan.Downloader) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job (Trojan.Downloader) -> Quarantined and deleted successfully. and here is the log i just did Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3967 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 4/8/2010 12:28:45 AM mbam-log-2010-04-08 (00-28-45).txt Scan type: Quick scan Objects scanned: 107510 Time elapsed: 14 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) i will run the kaspersky on line scanner and post my log thanks.
Hi heres my Kaspersky report it took a very long time to get it going and to run. i used the link you provided, and i went to their website and it said , Coming soon: A new, improved version of the Kaspersky Online Scanner The current Kaspersky Online Scanner is unavailable - we apologize for the inconvenience. While you are waiting for the improved Online Scanner, why not try a free trial of Kaspersky Internet Security 2010, which has everything you need to keep your computer safe. Well here it is thanks ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, April 8, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, April 08, 2010 10:48:33 Records in database: 3922307 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 61265 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 08:43:46 No threats found. Scanned area is clean. Selected area has been scanned.
Hi

Please do the following:

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java Runtime Environment (JRE) 6 Update 19 The Java SE Runtime Environment (JRE) allows end-users to run Java applications.
  • Click the Download button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement
  • Click Continue The page will refresh.
  • Click on the link to download Windows Offline Installation and Save the file to your Desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start(or My Computer) > Control Panel and double-click on Add or Remove Programs and remove all older versions of Java.
  • Click (highlight) any item with Java Runtime Environment (JRE, J2SE, Java™ SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u19-windows-i586-p.exe to install the newest version.
  • After the install is complete, go back to your Control Panel(using Classic View) and click the Java icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button.
    • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
    • Trace and Log Files
  • Click OK on Delete Temporary Files Window. Note: This deletes ALL the Downloaded Applications and Applets from the CACHE
  • Click OK to leave the Temporary Files Window.
  • Click OK to leave the Java Control Panel.
  • Delete jre-6u19-windows-i586-p.exe from your desktop.


NEXT

Please advise how your computer is running now and if there are any outstanding issues.
Hi Thanks for your help it sems to be more responsive. is there anything else you see that i should do? i am ordering more ram . maby that will help :notworthy: :woot: also. thank you .
Just some housekeeping to do now:

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If any logs/tools remain on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.



    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
thanks for your help i will finish up later its getting late i will post later and let u know how everything went . thanks for takeing the time to help .
Hi my computer is a lot better but not like it was before but i can work with it thanks . one more thing if you can help when i start my computer the security warning for windows comes up and says no firewall is turned on it stays there for 10 to 30 seconds then goes away i chech the firewall and its on any idea it never use to do that. And one more thing i get a blue screen when windows is loading that says—————cannot determine file system of drive \??\ volume e9e93473\ 57cb\ 11dc\ -beef- oo - e0181e0c9a i looked for these on google but didnt find much. Thanks …
The firewall is being started after windows security center alert is started, that's why it is saying it is not turned on. I suggest posting a new topic in the Windows XP forum and having the expert techs there tweak your settings, as this isn't malware related. good luck

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI