This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC slowing down

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, my PC seems like it is slowing down, i generally do not have a lot of programs running. I have noticed task manager > processes slowly filling with new processes hogging memory. I have downloaded DDS and ran it and here are the results - DDS.txt DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 0:11:25.50 on Fri 08/06/2010 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2721 [GMT 1:00] ============== Running Processes =============== svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe C:\WINDOWS.0\Explorer.EXE C:\Program Files\Unlocker\UnlockerAssistant.exe C:\WINDOWS.0\RTHDCPL.EXE C:\WINDOWS.0\SOUNDMAN.EXE C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\Documents and Settings\Administrator.EVEREST\Local Settings\Apps\2.0\MEV0PBVR.JHC\R1QLP74N.YTR\curs..tion_eee711038731a406_0004.0000_172b37d8269e5e48\CurseClient.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Administrator.EVEREST\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows.0\system32\dvmurl.dll mWinlogon: SfcDisable=-99 (0xffffff9d) BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll mRun: [UnlockerAssistant] c:\program files\unlocker\UnlockerAssistant.exe -H mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SoundMan] SOUNDMAN.EXE mRun: [AlcWzrd] ALCWZRD.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [GEST] = mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N StartupFolder: c:\documents and settings\administrator.everest\start menu\programs\startup\CurseClientStartup.ccip StartupFolder: c:\docume~1\admini~1.eve\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe uPolicies-explorer: NoResolveTrack = 1 (0x1) uPolicies-explorer: NoInstrumentation = 1 (0x1) mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) dPolicies-explorer: NoResolveTrack = 1 (0x1) dPolicies-explorer: NoInstrumentation = 1 (0x1) IE: &Winamp; Search - c:\documents and settings\all users.windows.0\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab TCP: {5E881150-D25F-4403-BEBB-944BCAAF32F8} = 156.154.70.22,156.154.71.22 Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs: c:\windows.0\system32\guard32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows.0\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1.eve\applic~1\mozilla\firefox\profiles\vd9zvte2.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\documents and settings\administrator.everest\application data\mozilla\firefox\profiles\vd9zvte2.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 cmderd;COMODO Internet Security Eradication Driver;c:\windows.0\system32\drivers\cmderd.sys [2010-6-1 15464] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows.0\system32\drivers\cmdGuard.sys [2010-6-4 229312] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows.0\system32\drivers\cmdhlp.sys [2010-6-1 25240] R2 Akamai;Akamai NetSession Interface;c:\windows.0\system32\svchost.exe -k Akamai [2008-4-14 14336] R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2010-6-1 1778480] R2 cpuz134;cpuz134;c:\windows.0\system32\drivers\cpuz134_x32.sys [2010-7-13 20328] R2 GEST Service;GEST Service for program management.;c:\program files\gigabyte\energysaver\GSvr.exe [2009-7-12 80392] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] =============== Created Last 30 ================ 2010-08-05 23:56 –d—– c:\documents and settings\administrator.everest\.netbeans 2010-08-05 23:56 –d—– c:\documents and settings\administrator.everest\.netbeans-registration 2010-08-05 23:54 –d—– c:\program files\glassfish-3.0.1 2010-08-05 23:39 –d—– c:\program files\NetBeans 6.9.1 2010-08-05 23:37 –d—– c:\documents and settings\administrator.everest\.nbi 2010-08-05 23:30 –d—– c:\windows.0\system32\NtmsData 2010-08-03 22:00 –d—– C:\MyJava 2010-08-03 21:51 –d—– c:\program files\Sun 2010-08-03 21:51 –d—– C:\jdk1.6.0_21 2010-08-03 21:38 –d—– C:\glassfishv3 2010-08-03 20:30 664 a——- c:\windows.0\system32\d3d9caps.dat 2010-08-03 19:34 –d—– c:\program files\DeepSilver 2010-08-02 23:46 –d-h— C:\VritualRoot 2010-08-02 23:46 –d—– c:\docume~1\alluse~1.0\applic~1\COMODO 2010-08-02 23:46 1,474,832 a——- c:\windows.0\system32\drivers\sfi.dat 2010-08-02 23:44 –d—– c:\program files\COMODO 2010-08-02 23:42 –d—– c:\docume~1\alluse~1.0\applic~1\Comodo Downloader 2010-07-26 16:49 –d—– c:\program files\Warhammer 40000 Dawn of War II - Chaos Rising 2010-07-26 16:35 1,892,184 a——- c:\windows.0\system32\D3DX9_42.dll 2010-07-26 16:35 453,456 a——- c:\windows.0\system32\d3dx10_42.dll 2010-07-22 18:17 –d—– c:\program files\SystemRequirementsLab 2010-07-22 18:16 423,656 a——- c:\windows.0\system32\deployJava1.dll 2010-07-22 18:16 73,728 a——- c:\windows.0\system32\javacpl.cpl 2010-07-21 11:28 –d—– c:\program files\Rosetta Stone 2010-07-21 11:28 –d—– c:\docume~1\alluse~1.0\applic~1\Rosetta Stone 2010-07-20 20:30 –d-h— c:\windows.0\PIF 2010-07-13 16:34 20,328 a——- c:\windows.0\system32\drivers\cpuz134_x32.sys 2010-07-13 16:34 –d—– c:\program files\CPUID 2010-07-09 03:45 –d—– c:\program files\Winamp Detect 2010-07-09 03:45 –d—– c:\program files\Winamp Toolbar 2010-07-09 03:45 –d—– c:\docume~1\alluse~1.0\applic~1\Winamp Toolbar ==================== Find3M ==================== 2010-08-05 12:30 16,608 a——- c:\windows.0\gdrv.sys 2010-07-07 03:27 5,069,312 a——- c:\windows.0\system32\drivers\ati2mtag.sys 2010-07-07 02:58 53,248 a——- c:\windows.0\system32\aticalrt.dll 2010-07-07 02:58 53,248 a——- c:\windows.0\system32\aticalcl.dll 2010-07-07 02:57 4,337,664 a——- c:\windows.0\system32\aticaldd.dll 2010-07-07 02:53 15,499,264 a——- c:\windows.0\system32\atioglxx.dll 2010-07-07 02:50 311,296 a——- c:\windows.0\system32\atiiiexx.dll 2010-07-07 02:48 446,464 a——- c:\windows.0\system32\ATIDEMGX.dll 2010-07-07 02:47 299,520 a——- c:\windows.0\system32\ati2dvag.dll 2010-07-07 02:41 3,869,952 a——- c:\windows.0\system32\ati3duag.dll 2010-07-07 02:33 208,896 a——- c:\windows.0\system32\atipdlxx.dll 2010-07-07 02:32 155,648 a——- c:\windows.0\system32\Oemdspif.dll 2010-07-07 02:32 26,112 a——- c:\windows.0\system32\Ati2mdxx.exe 2010-07-07 02:32 43,520 a——- c:\windows.0\system32\ati2edxx.dll 2010-07-07 02:32 159,744 a——- c:\windows.0\system32\ati2evxx.dll 2010-07-07 02:31 602,112 a——- c:\windows.0\system32\ati2evxx.exe 2010-07-07 02:29 53,248 a——- c:\windows.0\system32\ATIDDC.DLL 2010-07-07 02:29 143,360 a——- c:\windows.0\system32\atiapfxx.exe 2010-07-07 02:28 2,273,920 a——- c:\windows.0\system32\ativvaxx.dll 2010-07-07 02:27 887,724 a——- c:\windows.0\system32\ativva6x.dat 2010-07-07 02:25 573,440 a——- c:\windows.0\system32\atikvmag.dll 2010-07-07 02:24 393,216 a——- c:\windows.0\system32\atiok3x2.dll 2010-07-07 02:24 184,320 a——- c:\windows.0\system32\atiadlxx.dll 2010-07-07 02:23 17,408 a——- c:\windows.0\system32\atitvo32.dll 2010-07-07 02:19 704,512 a——- c:\windows.0\system32\ati2cqag.dll 2010-07-07 02:15 65,024 a——- c:\windows.0\system32\atimpc32.dll 2010-07-07 02:15 65,024 a——- c:\windows.0\system32\amdpcom32.dll 2010-07-07 02:15 53,248 a——- c:\windows.0\system32\drivers\ati2erec.dll 2010-07-05 10:21 279,712 a——- c:\windows.0\system32\drivers\atksgt.sys 2010-07-05 10:21 25,888 a——- c:\windows.0\system32\drivers\lirsgt.sys 2010-07-01 20:17 286,720 a——- c:\windows.0\iun503.exe 2010-06-01 19:00 278,288 a——- c:\windows.0\system32\guard32.dll 2010-05-11 21:42 205,156 a——- c:\windows.0\system32\atiicdxx.dat ============= FINISH: 0:13:10.89 =============== Any help much appreciated :)
Posted Image

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")



The issues with your computer that you list, doesn't appear to be related to Malware/Spyware/Virus but we can have a look.


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
[external image: Posted Image]
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI