This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very poor performance +

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This PC is going off my 18th floor balcony soon if I don't get it back to normal! No viruses, etc., come up in security program's results, so I have no idea what's going on. It's experiencing far too many crashes, and when it's not crashing, it's either freezing (alot) or running like carp**. Below is my DDS text results and I've attached the "Attach ZIP file" as it said to do on your "Are you infected" page. I hope I done it properly for you guys. Please advise if you get a chance. Thanx so much, Victoria DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 16:58:31.76 on Tue 06/15/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.639.107 [GMT -4:00] AV: Rogers Online Protection Anti-Virus *On-access scanning enabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755} FW: Rogers Online Protection Firewall *enabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22} ============== Running Processes =============== C:\WINDOWS\NEWEST\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\NEWEST\System32\svchost.exe -k netsvcs C:\WINDOWS\NEWEST\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Rogers Online Protection\Rogers Online Protection\Fws.exe svchost.exe C:\WINDOWS\NEWEST\system32\spoolsv.exe C:\WINDOWS\NEWEST\Explorer.EXE C:\WINDOWS\NEWEST\System32\svchost.exe -k HTTPFilter C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe C:\WINDOWS\NEWEST\system32\svchost.exe -k imgsvc C:\WINDOWS\NEWEST\System32\vssvc.exe C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Bin\SanaAgent.exe C:\WINDOWS\NEWEST\system32\LVComsX.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Bin\SanaMonitor.exe C:\Program Files\Rogers Online Protection\Rogers Online Protection\RPS.exe C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe C:\Program Files\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe C:\Program Files\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe C:\Program Files\Rogers Online Protection\Rogers Online Protection\PrtlAgt.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Documents and Settings\Vicky\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://facebook.com/ uSearch Page = hxxp://www.google.com uDefault_Search_URL = hxxp://www.google.com/ie uDefault_Page_URL = hxxp://ieaddons.com/en/students uSearch Bar = hxxp://www.google.com/ie uWindow Title = DONT HOG THE COMPUTER mDefault_Page_URL = hxxp://rogers.yahoo.com mDefault_Search_URL = hxxp://ca.red.clientapps.yahoo.com/customize/rogers/defaults/su/*http://www.yahoo.com mSearch Page = hxxp://ca.red.clientapps.yahoo.com/customize/rogers/defaults/sp/*http://www.yahoo.com mStart Page = hxxp://rogers.yahoo.com mWindow Title = DONT HOG THE COMPUTER mSearch Bar = hxxp://ca.red.clientapps.yahoo.com/customize/rogers/defaults/sb/*http://www.yahoo.com/search/ie.html uInternet Settings,ProxyOverride = localhost;*.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Download Guard for Internet Explorer: {20c1a7f0-528e-444f-bac5-5804a61cca7f} - c:\program files\lavasoft\download guard for internet explorer\DownloadGuardBHO.dll BHO: PopKill Class: {3c060ea2-e6a9-4e49-a530-d4657b8c449a} - c:\program files\rogers online protection\rogers online protection\pkR.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet explorer\iedvtool.dll EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll EB: {D86FA331-DF95-46C8-8978-4C00D084C9A1} - No File EB: {E360B15E-21A7-4FAB-944E-9DC4F092818E} - No File uRun: [Performance Center] c:\program files\ascentive\performance center\ApcMain.exe -m uRunOnce: [IndexCleaner] "c:\program files\rogers online protection\rogers online protection\IdxClnR.exe" mRun: [Rogers SHS] c:\program files\rogers\selfhealing\shs.exe mRun: [RogersServicepointAgent.exe] "c:\program files\rogers online protection\rogers servicepoint agent\RogersServicepointAgent.exe" /AUTORUN mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\newest\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp mRunOnce: [IndexCleaner] "c:\program files\rogers online protection\rogers online protection\IdxClnR.exe" uPolicies-explorer: NoFavoritesMenu = 1 (0x1) IE: Add to Google Photos Screensa&ver - c:\windows\newest\system32\GPhotos.scr/200 IE: Save Page As PDF … IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\newest\system32\WPDShServiceObj.dll SEH: WinFax PRO IShellExecuteHook: {a213b520-c6c2-11d0-af9d-008029e1027e} - c:\program files\symantec\winfax\WfxSeh32.Dll Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\vicky\applic~1\mozilla\firefox\profiles\u5d487yl.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://familywatchdog.us/ FF - prefs.js: keyword.URL - hxxp://mystart.incredimail.com/?loc=ff_address_bar_im2_test_v2&search= FF - component: c:\program files\microsoft\search enhancement pack\search helper\firefoxextension\searchhelperextension\components\SEPsearchhelperff.dll FF - plugin: c:\documents and settings\vicky\application data\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\documents and settings\vicky\application data\mozilla\firefox\profiles\u5d487yl.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\progra~1\meadco~1\npmeadax.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft\office live\npOLW.dll FF - plugin: c:\program files\rogers online protection\rogers servicepoint agent\nprpspa.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\newest\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\newest\system32\drivers\Lbd.sys [2010-4-17 64288] R1 KLIF;KLIF;c:\windows\newest\system32\drivers\klif.sys [2010-4-17 179984] R3 RadialpointSafeConnectDriver;RadialpointSafeConnectDriver;c:\program files\rogers online protection\rogers online protection\safeconnect\driver\platform_xp\SafeConnectDriver.sys [2008-11-14 161304] R3 RadialpointSafeConnectFilter;RadialpointSafeConnectFilter;c:\program files\rogers online protection\rogers online protection\safeconnect\driver\platform_xp\SafeConnectFilter.sys [2008-11-14 29720] R3 RadialpointSafeConnectShim;RadialpointSafeConnectShim;c:\program files\rogers online protection\rogers online protection\safeconnect\driver\platform_xp\SafeConnectShim.sys [2008-11-14 27376] S2 gupdate1ca640167659b5c;Google Update Service (gupdate1ca640167659b5c);c:\program files\google\update\GoogleUpdate.exe [2009-11-12 133104] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1285864] S3 NPF;NetGroup Packet Filter Driver;c:\windows\newest\system32\drivers\npf.sys [2005-8-2 32512] S3 TMPassthruMP;TMPassthruMP;c:\windows\newest\system32\drivers\tmpassthru.sys –> c:\windows\newest\system32\drivers\TMPassthru.sys [?] =============== Created Last 30 ================ 2010-06-15 17:32:36 10 —-a-w- c:\windows\newest\WININIT.INI 2010-06-15 17:03:57 73728 —-a-w- c:\windows\newest\system32\javacpl.cpl 2010-06-15 17:03:57 411368 —-a-w- c:\windows\newest\system32\deployJava1.dll 2010-06-15 16:34:57 0 d—–w- c:\windows\newest\system32\drivers\NSS 2010-06-15 16:34:57 0 d—–w- c:\program files\Norton Security Scan 2010-06-15 16:34:57 0 d—–w- c:\docume~1\alluse~1\applic~1\Symantec 2010-06-15 16:34:57 0 d—–w- c:\docume~1\alluse~1\applic~1\Norton 2010-06-15 16:34:52 0 d—–w- c:\program files\NortonInstaller 2010-06-15 16:34:52 0 d—–w- c:\docume~1\alluse~1\applic~1\NortonInstaller 2010-06-15 15:59:30 0 d—–w- c:\program files\Bonjour 2010-06-11 06:00:46 743424 -c—-w- c:\windows\newest\system32\dllcache\iedvtool.dll 2010-06-08 00:25:26 5632 —-a-w- c:\windows\newest\system32\ptpusb.dll 2010-06-08 00:25:21 15104 -c–a-w- c:\windows\newest\system32\dllcache\usbscan.sys 2010-06-08 00:25:21 15104 —-a-w- c:\windows\newest\system32\drivers\usbscan.sys 2010-06-08 00:25:14 159232 —-a-w- c:\windows\newest\system32\ptpusd.dll 2010-05-31 10:54:04 0 d—–w- c:\docume~1\vicky\applic~1\com.adobe.px.Uploader.4C35C4D325D350FE0114230CBADCA2DDD0AC8D25.1 2010-05-31 10:53:34 0 d—–w- c:\program files\Adobe Photoshop.com Uploader 2010-05-31 03:10:11 0 d—–w- c:\program files\Speccy 2010-05-31 03:10:02 0 d—–w- c:\program files\Defraggler 2010-05-29 23:47:36 161296 —-a-w- c:\windows\newest\system32\drivers\tmcomm.sys ==================== Find3M ==================== 2010-06-15 20:58:27 24541472 –sha-w- c:\windows\newest\system32\drivers\fidbox.dat 2010-06-11 23:44:59 52124 –sha-w- c:\windows\newest\system32\drivers\fidbox2.idx 2010-06-11 23:44:58 679456 –sha-w- c:\windows\newest\system32\drivers\fidbox2.dat 2010-06-11 23:44:58 291644 –sha-w- c:\windows\newest\system32\drivers\fidbox.idx 2010-05-10 06:08:41 95024 —-a-w- c:\windows\newest\system32\drivers\SBREDrv.sys 2010-05-10 06:08:35 15880 —-a-w- c:\windows\newest\system32\lsdelete.exe 2010-05-06 10:41:53 916480 —-a-w- c:\windows\newest\system32\wininet.dll 2010-05-02 05:22:50 1851264 —-a-w- c:\windows\newest\system32\win32k.sys 2010-04-29 18:47:18 3600384 -c–a-w- c:\windows\newest\system32\GPhotos.scr 2010-04-20 19:13:06 3168 -c–a-w- c:\docume~1\vicky\applic~1\wklnhst.dat 2010-04-20 05:30:08 285696 —-a-w- c:\windows\newest\system32\atmfd.dll 2010-04-08 17:20:02 91424 —-a-w- c:\windows\newest\system32\dnssd.dll 2010-04-08 17:20:02 107808 —-a-w- c:\windows\newest\system32\dns-sd.exe 2009-12-13 16:51:28 2147 -c–a-w- c:\program files\INSTALL.LOG 2009-08-31 17:22:26 32768 -csha-w- c:\windows\newest\system32\config\systemprofile\local settings\history\history.ie5\mshist012009082420090831\index.dat 2009-08-31 17:22:26 32768 -csha-w- c:\windows\newest\system32\config\systemprofile\local settings\history\history.ie5\mshist012009083120090901\index.dat ============= FINISH: 17:03:17.73 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hi,

Please do the following:


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI