This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Running Slow

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been running slow. A few weeks ago I started getting error messages and clicks when I wasn't touching anything. I installed AVG Anti-Virus, and that has gone away, but it is still running very slow compared to before the error messages came. - Elisabeth DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 13:39:38.34 on Sun 06/13/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.494.45 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe svchost.exe svchost.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG9\avgnsx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Elisabeth\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.onepaper.com/stthomasvi/?N=A uSearch Page = hxxp://www.google.com uDefault_Page_URL = hxxp://www.dell4me.com/myway uSearch Bar = hxxp://bfc.myway.com/search/de_srchlft.html uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: N/A: {4d25f926-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\1.bin\deSrcAs.dll uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: : {4d25f921-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\1.bin\deSrcAs.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_1_0 uRun: [Google Update] "c:\documents and settings\elisabeth\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [] mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [type32] "c:\program files\microsoft intellitype pro\type32.exe" mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\point32.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k mRun: [ActivControl] c:\program files\activ software\activdriver\ActivControl2.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRunOnce: [NoIE4StubProcessing] c:\windows\system32\reg.exe delete "hklm\software\microsoft\active setup\Installed Components" /v "NoIE4StubProcessing" /f IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\elisab~1\applic~1\mozilla\firefox\profiles\egin5rgf.default\ FF - prefs.js: browser.startup.homepage - www.google.com.vi FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\documents and settings\elisabeth\local settings\application data\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-5-4 216200] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-5-4 29584] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-5-4 242896] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-5-4 308064] R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\system32\drivers\activhidsermini.sys [2009-5-5 55936] R3 prmvmouse;Promethean HID Mouse Service;c:\windows\system32\drivers\activmouse.sys [2010-3-12 5632] S2 spupdsvc;Windows Service Pack Installer update service;c:\windows\system32\spupdsvc.exe [2005-9-22 26144] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-5-4 369920] S3 hpoius07;USB to IEEE-1284.4 Translation Driver;c:\windows\system32\drivers\hpoius07.sys –> c:\windows\system32\drivers\hpoius07.sys [?] =============== Created Last 30 ================ ==================== Find3M ==================== 2010-06-03 06:51 242,896 a——- c:\windows\system32\drivers\avgtdix.sys 2010-05-06 06:41 916,480 ——– c:\windows\system32\dllcache\wininet.dll 2010-05-06 06:41 5,950,976 ——– c:\windows\system32\dllcache\mshtml.dll 2010-05-06 06:41 1,209,344 ——– c:\windows\system32\dllcache\urlmon.dll 2010-05-06 06:41 611,840 ——– c:\windows\system32\dllcache\mstime.dll 2010-05-06 06:41 206,848 ——– c:\windows\system32\dllcache\occache.dll 2010-05-06 06:41 599,040 ——– c:\windows\system32\dllcache\msfeeds.dll 2010-05-06 06:41 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll 2010-05-06 06:41 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll 2010-05-06 06:41 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll 2010-05-06 06:41 184,320 ——– c:\windows\system32\dllcache\iepeers.dll 2010-05-06 06:41 11,076,096 ——– c:\windows\system32\dllcache\ieframe.dll 2010-05-06 06:41 387,584 ——– c:\windows\system32\dllcache\iedkcs32.dll 2010-05-05 09:30 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe 2010-05-04 20:40 12,464 a——- c:\windows\system32\avgrsstx.dll 2010-05-04 20:40 216,200 a——- c:\windows\system32\drivers\avgldx86.sys 2010-05-04 08:39 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2010-05-02 01:22 1,851,264 a——- c:\windows\system32\win32k.sys 2010-05-02 01:22 1,851,264 ——– c:\windows\system32\dllcache\win32k.sys 2010-04-20 01:30 285,696 a——- c:\windows\system32\atmfd.dll 2010-04-20 01:30 285,696 ——– c:\windows\system32\dllcache\atmfd.dll 2010-04-16 07:43 634,656 ——– c:\windows\system32\dllcache\iexplore.exe 2010-04-16 07:43 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2010-04-12 17:29 411,368 a——- c:\windows\system32\deployJava1.dll 2010-04-06 04:52 2,462,720 ——– c:\windows\system32\dllcache\WMVCore.dll 2009-11-15 19:16 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009111520091116\index.dat ============= FINISH: 13:40:52.80 ===============

Attachments:

Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
My computer is running faster now. It opens files more quickly. Thank you. Below is my report from malware. I forgot to unclick system files to remove, but I don't think there were any. Thanks again! Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4203 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 6/16/2010 9:04:55 AM mbam-log-2010-06-16 (09-04-55).txt Scan type: Quick scan Objects scanned: 141463 Time elapsed: 12 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 1 Registry Data Items Infected: 2 Folders Infected: 4 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Generic.Bot.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywaysearchassistantde.auxiliary (Adware.MyWaySearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mywaysearchassistantde.auxiliary.1 (Adware.MyWaySearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{4d25f926-b9fe-4682-bf72-8ab8210d6d75} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 (Trojan.Agent) -> Quarantined and deleted successfully. Files Infected: C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\SYSTEM32\umdmgr.log (IRCBot.Trace) -> Quarantined and deleted successfully.
Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
My computer is running about the same as before - I havent had a chance to reboot it a few times.

Here are the results from Combofix:

ComboFix 10-06-15.04 - Elisabeth 06/16/2010 17:51:44.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.494.116 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\bszip.dll
c:\windows\xpsp1hfm.log

.
((((((((((((((((((((((((( Files Created from 2010-05-16 to 2010-06-16 )))))))))))))))))))))))))))))))
.

2010-06-16 14:02 . 2010-06-16 14:02 ——– d—–w- c:\documents and settings\All Users\Application Data\GoldWave
2010-06-16 14:02 . 2010-03-23 14:05 495104 —-a-w- c:\documents and settings\All Users\Application Data\GoldWave\lame_enc.dll
2010-06-16 12:41 . 2010-06-16 12:41 ——– d—–w- c:\documents and settings\Elisabeth\Application Data\Malwarebytes
2010-06-16 12:41 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-16 12:41 . 2010-06-16 12:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-16 12:41 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-16 12:41 . 2010-06-16 12:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-14 21:18 . 2010-06-14 21:18 ——– d—–w- c:\program files\GoldWave
2010-06-14 10:05 . 2010-06-14 10:05 ——– d-sh–w- c:\documents and settings\Elisabeth\PrivacIE
2010-06-14 00:13 . 2010-06-14 00:13 ——– d-sh–w- c:\documents and settings\Elisabeth\IETldCache
2010-06-13 13:28 . 2010-06-14 18:08 ——– d—–w- c:\windows\ie8updates
2010-06-13 13:20 . 2010-06-13 14:20 ——– dc-h–w- c:\windows\ie8
2010-06-13 13:15 . 2010-05-06 10:41 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2010-06-13 13:15 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-13 13:15 . 2010-05-06 10:41 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2010-06-13 12:40 . 2010-04-16 11:43 41984 ——w- c:\windows\system32\dllcache\iecompat.dll
2010-06-13 01:17 . 2010-06-14 23:19 ——– d—–w- c:\documents and settings\Elisabeth\Local Settings\Application Data\WMTools Downloaded Files
2010-06-06 01:13 . 2006-04-05 23:38 110592 —-a-w- c:\documents and settings\Devonte\Application Data\U3\temp\cleanup.exe
2010-06-06 01:09 . 2010-06-06 01:15 ——– d—–w- c:\documents and settings\Devonte\Application Data\U3
2010-06-03 10:51 . 2010-06-03 10:51 242896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-06-03 10:51 . 2010-06-03 10:51 29512 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-05-28 00:23 . 2010-05-28 00:23 503808 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50922c66-n\msvcp71.dll
2010-05-28 00:23 . 2010-05-28 00:23 499712 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50922c66-n\jmc.dll
2010-05-28 00:23 . 2010-05-28 00:23 348160 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50922c66-n\msvcr71.dll
2010-05-28 00:22 . 2010-05-28 00:22 61440 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-73130454-n\decora-sse.dll
2010-05-28 00:22 . 2010-05-28 00:22 12800 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-73130454-n\decora-d3d.dll
2010-05-25 22:30 . 2010-05-25 22:30 ——– d—–w- c:\documents and settings\Devonte\Local Settings\Application Data\AVG Security Toolbar
2010-05-22 22:18 . 2010-05-22 22:18 503808 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2ebe9103-n\msvcp71.dll
2010-05-22 22:18 . 2010-05-22 22:18 499712 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2ebe9103-n\jmc.dll
2010-05-22 22:18 . 2010-05-22 22:18 348160 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2ebe9103-n\msvcr71.dll
2010-05-22 22:17 . 2010-05-22 22:17 61440 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4fcb8a54-n\decora-sse.dll
2010-05-22 22:17 . 2010-05-22 22:17 12800 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4fcb8a54-n\decora-d3d.dll
2010-05-22 22:14 . 2010-05-22 22:14 ——– d—–w- c:\documents and settings\Devonte\Application Data\CyberLink
2010-05-22 22:13 . 2010-05-22 22:15 ——– d—–w- c:\documents and settings\Devonte\Local Settings\Application Data\PowerDVD

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-16 22:03 . 2007-08-06 21:22 ——– d—–w- c:\documents and settings\Elisabeth\Application Data\Skype
2010-06-16 21:20 . 2010-03-12 13:33 63488 —-a-w- c:\documents and settings\All Users\Application Data\Activ Software\ActivApplications\ActivFocusHook.dll
2010-06-16 21:00 . 2010-05-05 00:35 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-05-25 23:58 . 2010-05-02 22:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2010-05-25 23:58 . 2005-04-14 04:02 ——– d—–w- c:\program files\PokerRoom.com
2010-05-25 23:56 . 2007-08-07 19:00 ——– d—–w- c:\program files\Common Files\Logitech
2010-05-25 23:48 . 2005-03-21 17:55 ——– d—–w- c:\program files\Common Files\Real
2010-05-25 23:13 . 2006-11-01 13:03 ——– d—–w- c:\program files\Google
2010-05-25 23:04 . 2005-04-06 03:26 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-06 10:41 . 2004-08-04 11:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-05 00:36 . 2010-05-05 00:36 ——– d—–w- c:\program files\AVG
2010-05-04 04:32 . 2010-03-16 00:37 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-05-04 00:57 . 2010-05-04 00:57 503808 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-51a3f59d-n\msvcp71.dll
2010-05-04 00:57 . 2010-05-04 00:57 499712 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-51a3f59d-n\jmc.dll
2010-05-04 00:57 . 2010-05-04 00:57 348160 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-51a3f59d-n\msvcr71.dll
2010-05-04 00:56 . 2010-05-04 00:56 61440 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3a1274e8-n\decora-sse.dll
2010-05-04 00:56 . 2010-05-04 00:56 12800 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3a1274e8-n\decora-d3d.dll
2010-05-04 00:56 . 2005-03-21 17:42 ——– d—–w- c:\program files\Common Files\Java
2010-05-04 00:55 . 2005-03-21 17:42 ——– d—–w- c:\program files\Java
2010-05-02 23:34 . 2005-03-21 17:53 ——– d—–w- c:\program files\Common Files\AOL
2010-05-02 23:34 . 2005-03-21 17:53 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2010-05-02 22:44 . 2010-05-02 22:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-05-02 22:44 . 2010-05-02 22:44 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-05-02 22:30 . 2010-05-02 22:30 ——– d—–w- c:\documents and settings\Devonte\Application Data\Promethean
2010-05-02 16:31 . 2010-05-02 16:29 ——– d—–w- c:\program files\iTunes
2010-05-02 16:31 . 2010-05-02 16:29 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-02 16:30 . 2010-05-02 16:30 ——– d—–w- c:\program files\iPod
2010-05-02 16:30 . 2009-09-25 22:29 ——– d—–w- c:\program files\Common Files\Apple
2010-05-02 16:23 . 2009-09-25 22:31 ——– d—–w- c:\program files\QuickTime
2010-05-02 15:49 . 2010-05-02 15:49 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-02 05:22 . 2004-08-04 11:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 14:42 . 2010-04-29 14:42 ——– d—–w- c:\documents and settings\Devonte\Application Data\AdobeUM
2010-04-20 05:30 . 2004-08-04 11:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-12 21:29 . 2010-05-04 00:55 411368 —-a-w- c:\windows\system32\deployJava1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-16 68856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-07-02 23237416]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Google Update"="c:\documents and settings\Elisabeth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-07 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-25 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-25 118784]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 86016]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 196608]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ActivControl"="c:\program files\Activ Software\Activdriver\ActivControl2.exe" [2009-06-04 1084704]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\RosettaStoneLtdServices.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
""=

R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\SYSTEM32\DRIVERS\activhidsermini.sys [5/5/2009 5:25 PM 55936]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\SYSTEM32\DRIVERS\activmouse.sys [3/12/2010 9:32 AM 5632]
S3 hpoius07;USB to IEEE-1284.4 Translation Driver;c:\windows\system32\DRIVERS\hpoius07.sys –> c:\windows\system32\DRIVERS\hpoius07.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-06-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-433026666-2355460235-1667102857-1005Core.job
- c:\documents and settings\Elisabeth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-07 02:09]

2010-06-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-433026666-2355460235-1667102857-1005UA.job
- c:\documents and settings\Elisabeth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-07 02:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.onepaper.com/stthomasvi/?N=A
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Elisabeth\Application Data\Mozilla\Firefox\Profiles\egin5rgf.default\
FF - prefs.js: browser.startup.homepage - www.google.com.vi
FF - plugin: c:\documents and settings\Elisabeth\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9c.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-16 18:03
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1020)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2010-06-16 18:08:12
ComboFix-quarantined-files.txt 2010-06-16 22:08

Pre-Run: 40,625,811,456 bytes free
Post-Run: 40,634,617,856 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - E2044B0C5F989CC76A410E5F1029B955
Posted Today, 08:58 PM Is the Symantec / Nortons leftovers from before? I'm not sure what you're talking about. I may have had Symantec and Norton on before for the family member who had the computer before me - but they're inactive. I had to uninstall AVG (free version) to run Combofix, but I'm reinstalling it now.
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::

Folder::
c:\documents and settings\All Users\Application Data\Norton
c:\documents and settings\All Users\Application Data\Symantec
c:\documents and settings\All Users\Application Data\NortonInstaller
c:\program files\Viewpoint

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
My computer is running a bit sluggish now, but it seemed to run a bit faster when I rebooted it twice. I haven't had a chance to reboot since I did Combofix.

Here's the report.

ComboFix 10-06-16.03 - Elisabeth 06/17/2010 6:54.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.494.117 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Elisabeth\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Norton
c:\documents and settings\All Users\Application Data\Norton\symdata.xml
c:\documents and settings\All Users\Application Data\NortonInstaller
c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\05-02-2010-18h44m50s\Install.1.mft.7z
c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\05-02-2010-18h44m50s\NortonInstall-05-02-2010-18h44m50s.log
c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\05-25-2010-19h58m21s\Install.1.mft.7z
c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\05-25-2010-19h58m21s\NortonInstall-05-25-2010-19h58m21s.log
c:\documents and settings\All Users\Application Data\NortonInstaller\Logs\05-25-2010-19h59m02s\NortonInstall-05-25-2010-19h59m02s.log
c:\documents and settings\All Users\Application Data\Symantec
c:\documents and settings\All Users\Application Data\Symantec\symdata.xml
c:\program files\Viewpoint
c:\program files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\ComponentMgr.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLArt.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\Cursors.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\DataTracking.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\GifReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\LensFlares.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ObjectMovie.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ServiceComponent.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VectorView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPAudio.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPExtras.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\Components\ZoomView.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.xpt
c:\windows\system32\win.com

.
((((((((((((((((((((((((( Files Created from 2010-05-17 to 2010-06-17 )))))))))))))))))))))))))))))))
.

2010-06-17 02:13 . 2010-06-17 02:13 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-06-17 02:13 . 2010-06-17 02:54 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-17 02:13 . 2010-06-17 02:13 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-17 02:13 . 2010-06-17 02:54 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-06-17 02:13 . 2010-06-17 02:55 ——– d—–w- c:\windows\system32\drivers\Avg
2010-06-16 14:02 . 2010-06-16 14:02 ——– d—–w- c:\documents and settings\All Users\Application Data\GoldWave
2010-06-16 12:41 . 2010-06-16 12:41 ——– d—–w- c:\documents and settings\Elisabeth\Application Data\Malwarebytes
2010-06-16 12:41 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-16 12:41 . 2010-06-16 12:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-16 12:41 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-16 12:41 . 2010-06-16 12:41 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-14 21:18 . 2010-06-14 21:18 ——– d—–w- c:\program files\GoldWave
2010-06-14 10:05 . 2010-06-14 10:05 ——– d-sh–w- c:\documents and settings\Elisabeth\PrivacIE
2010-06-14 00:13 . 2010-06-14 00:13 ——– d-sh–w- c:\documents and settings\Elisabeth\IETldCache
2010-06-13 13:28 . 2010-06-14 18:08 ——– d—–w- c:\windows\ie8updates
2010-06-13 13:20 . 2010-06-13 14:20 ——– dc-h–w- c:\windows\ie8
2010-06-13 13:15 . 2010-05-06 10:41 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2010-06-13 13:15 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-13 13:15 . 2010-05-06 10:41 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2010-06-13 12:40 . 2010-04-16 11:43 41984 ——w- c:\windows\system32\dllcache\iecompat.dll
2010-06-13 01:17 . 2010-06-14 23:19 ——– d—–w- c:\documents and settings\Elisabeth\Local Settings\Application Data\WMTools Downloaded Files
2010-06-06 01:09 . 2010-06-06 01:15 ——– d—–w- c:\documents and settings\Devonte\Application Data\U3
2010-05-25 22:30 . 2010-05-25 22:30 ——– d—–w- c:\documents and settings\Devonte\Local Settings\Application Data\AVG Security Toolbar
2010-05-22 22:14 . 2010-05-22 22:14 ——– d—–w- c:\documents and settings\Devonte\Application Data\CyberLink
2010-05-22 22:13 . 2010-05-22 22:15 ——– d—–w- c:\documents and settings\Devonte\Local Settings\Application Data\PowerDVD

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-17 11:06 . 2007-08-06 21:22 ——– d—–w- c:\documents and settings\Elisabeth\Application Data\Skype
2010-06-17 10:19 . 2010-03-12 13:33 63488 —-a-w- c:\documents and settings\All Users\Application Data\Activ Software\ActivApplications\ActivFocusHook.dll
2010-06-17 02:57 . 2007-02-21 01:03 19 -c–a-w- c:\windows\popcinfo.dat
2010-06-17 02:55 . 2010-06-17 02:55 242896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-06-17 02:55 . 2010-06-17 02:55 29512 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-06-17 02:43 . 2005-04-06 03:27 ——– d—–w- c:\documents and settings\Elisabeth\Application Data\AdobeUM
2010-06-17 02:12 . 2010-05-05 00:35 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-05-28 00:23 . 2010-05-28 00:23 503808 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50922c66-n\msvcp71.dll
2010-05-28 00:23 . 2010-05-28 00:23 499712 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50922c66-n\jmc.dll
2010-05-28 00:23 . 2010-05-28 00:23 348160 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-50922c66-n\msvcr71.dll
2010-05-28 00:22 . 2010-05-28 00:22 61440 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-73130454-n\decora-sse.dll
2010-05-28 00:22 . 2010-05-28 00:22 12800 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-73130454-n\decora-d3d.dll
2010-05-25 23:58 . 2005-04-14 04:02 ——– d—–w- c:\program files\PokerRoom.com
2010-05-25 23:56 . 2007-08-07 19:00 ——– d—–w- c:\program files\Common Files\Logitech
2010-05-25 23:48 . 2005-03-21 17:55 ——– d—–w- c:\program files\Common Files\Real
2010-05-25 23:13 . 2006-11-01 13:03 ——– d—–w- c:\program files\Google
2010-05-25 23:04 . 2005-04-06 03:26 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-22 22:18 . 2010-05-22 22:18 503808 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2ebe9103-n\msvcp71.dll
2010-05-22 22:18 . 2010-05-22 22:18 499712 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2ebe9103-n\jmc.dll
2010-05-22 22:18 . 2010-05-22 22:18 348160 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2ebe9103-n\msvcr71.dll
2010-05-22 22:17 . 2010-05-22 22:17 61440 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4fcb8a54-n\decora-sse.dll
2010-05-22 22:17 . 2010-05-22 22:17 12800 —-a-w- c:\documents and settings\Devonte\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4fcb8a54-n\decora-d3d.dll
2010-05-06 10:41 . 2004-08-04 11:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-05 00:36 . 2010-05-05 00:36 ——– d—–w- c:\program files\AVG
2010-05-04 04:32 . 2010-03-16 00:37 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-05-04 00:57 . 2010-05-04 00:57 503808 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-51a3f59d-n\msvcp71.dll
2010-05-04 00:57 . 2010-05-04 00:57 499712 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-51a3f59d-n\jmc.dll
2010-05-04 00:57 . 2010-05-04 00:57 348160 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-51a3f59d-n\msvcr71.dll
2010-05-04 00:56 . 2010-05-04 00:56 61440 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3a1274e8-n\decora-sse.dll
2010-05-04 00:56 . 2010-05-04 00:56 12800 —-a-w- c:\documents and settings\Elisabeth\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3a1274e8-n\decora-d3d.dll
2010-05-04 00:56 . 2005-03-21 17:42 ——– d—–w- c:\program files\Common Files\Java
2010-05-04 00:55 . 2005-03-21 17:42 ——– d—–w- c:\program files\Java
2010-05-02 23:34 . 2005-03-21 17:53 ——– d—–w- c:\program files\Common Files\AOL
2010-05-02 23:34 . 2005-03-21 17:53 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2010-05-02 22:30 . 2010-05-02 22:30 ——– d—–w- c:\documents and settings\Devonte\Application Data\Promethean
2010-05-02 16:31 . 2010-05-02 16:29 ——– d—–w- c:\program files\iTunes
2010-05-02 16:31 . 2010-05-02 16:29 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-02 16:30 . 2010-05-02 16:30 ——– d—–w- c:\program files\iPod
2010-05-02 16:30 . 2009-09-25 22:29 ——– d—–w- c:\program files\Common Files\Apple
2010-05-02 16:23 . 2009-09-25 22:31 ——– d—–w- c:\program files\QuickTime
2010-05-02 15:49 . 2010-05-02 15:49 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-02 05:22 . 2004-08-04 11:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 14:42 . 2010-04-29 14:42 ——– d—–w- c:\documents and settings\Devonte\Application Data\AdobeUM
2010-04-20 05:30 . 2004-08-04 11:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-12 21:29 . 2010-05-04 00:55 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-03-23 14:05 . 2010-06-16 14:02 495104 —-a-w- c:\documents and settings\All Users\Application Data\GoldWave\lame_enc.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-06-16_22.03.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-17 10:17 . 2010-06-17 10:17 16384 c:\windows\Temp\Perflib_Perfdata_320.dat
+ 2010-06-17 02:43 . 2010-06-17 02:43 25214 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-7050000000A7}\ARPPRODUCTICON.exe
+ 2010-06-17 02:43 . 2010-06-17 02:43 388096 c:\windows\Installer\13772a3.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-16 68856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-07-02 23237416]
"Google Update"="c:\documents and settings\Elisabeth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-07 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-25 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-25 118784]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 86016]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 196608]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ActivControl"="c:\program files\Activ Software\Activdriver\ActivControl2.exe" [2009-06-04 1084704]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-17 2065248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-06-17 02:13 12464 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\RosettaStoneLtdServices.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
""=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [6/16/2010 10:13 PM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [6/16/2010 10:13 PM 242896]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [6/16/2010 10:13 PM 308064]
R3 ActivHidSerMini;Promethean Serial Board Driver;c:\windows\SYSTEM32\DRIVERS\activhidsermini.sys [5/5/2009 5:25 PM 55936]
R3 prmvmouse;Promethean HID Mouse Service;c:\windows\SYSTEM32\DRIVERS\activmouse.sys [3/12/2010 9:32 AM 5632]
S3 hpoius07;USB to IEEE-1284.4 Translation Driver;c:\windows\system32\DRIVERS\hpoius07.sys –> c:\windows\system32\DRIVERS\hpoius07.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-06-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-433026666-2355460235-1667102857-1005Core.job
- c:\documents and settings\Elisabeth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-07 02:09]

2010-06-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-433026666-2355460235-1667102857-1005UA.job
- c:\documents and settings\Elisabeth\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-07 02:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.onepaper.com/stthomasvi/?N=A
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Elisabeth\Application Data\Mozilla\Firefox\Profiles\egin5rgf.default\
FF - prefs.js: browser.startup.homepage - www.google.com.vi
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Elisabeth\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-ViewpointMediaPlayer - c:\program files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-17 07:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1036)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2010-06-17 07:13:34
ComboFix-quarantined-files.txt 2010-06-17 11:13
ComboFix2.txt 2010-06-16 22:08

Pre-Run: 40,245,813,248 bytes free
Post-Run: 40,220,909,568 bytes free

- - End Of File - - A881C110B0DDE837E117F6E0C6DA7303
The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

Reboot and let me know if it's running better.
Thank you so much. It is running faster now. A couple quick questions. 1. I see the Microsoft Recovery Console every time I boot now. When and how would I ever use it? 2. I still have the ATF cleaner file in my downloads folder. Is that something I should run periodically to clean my computer and keep it running smoothly? Could you ever run it too often? 3. I realize I know have Malwarebytes installed. How should I use this program in the future? Will it run scans automatically? Should I have it run scans for me? I also have the free version of AVG 9.0. Is it worth it to have both or do the do the same thing? Thanks again.
1. I see the Microsoft Recovery Console every time I boot now. When and how would I ever use it?
You would use that if you ever get a BSOD.

2. I still have the ATF cleaner file in my downloads folder. Is that something I should run periodically to clean my computer and keep it running smoothly? Could you ever run it too often?
I run ATF about once a week.

3. I realize I know have Malwarebytes installed. How should I use this program in the future? Will it run scans automatically? Should I have it run scans for me? I also have the free version of AVG 9.0. Is it worth it to have both or do the do the same thing?
I have the paid for version of MBAM so it is a full-time scanner. The free version you can run when ever you think you might have an infection.

AVG and MBAM are different. AVG is a Anti-Virus program while MBAM is a Anti-Spyware program.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI