This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Slowing Down Daily

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Running a Dell Optiplex 6X240 along with Zone Alarm Security Suite. Programs are slow to open and run.

Thanks in advance.

Dbm

OTL Extras logfile created on: 08/18/10 5:07:34 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Doug\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yy

767.00 Mb Total Physical Memory | 410.00 Mb Available Physical Memory | 53.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 3000 3000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.99 Gb Total Space | 96.32 Gb Free Space | 75.26% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 74.50 Gb Total Space | 34.17 Gb Free Space | 45.87% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 279.46 Gb Total Space | 222.08 Gb Free Space | 79.47% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: DOUGLAS
Current User Name: Doug
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = SafariHTML] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Safari\Safari.exe" -url "%1" File not found
https [open] – "C:\Program Files\Safari\Safari.exe" -url "%1" File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

OTL logfile created on: 08/18/10 5:07:34 PM - Run 1
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Doug\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yy

767.00 Mb Total Physical Memory | 410.00 Mb Available Physical Memory | 53.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 3000 3000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.99 Gb Total Space | 96.32 Gb Free Space | 75.26% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 74.50 Gb Total Space | 34.17 Gb Free Space | 45.87% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 279.46 Gb Total Space | 222.08 Gb Free Space | 79.47% Space Free | Partition Type: NTFS
I: Drive not present or media not loaded

Computer Name: DOUGLAS
Current User Name: Doug
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Doug\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Doug\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (RoxLiveShare9) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\rswin_3745.dll ()
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (RimUsb) – C:\WINDOWS\System32\Drivers\RimUsb.sys File not found
DRV - (portD) – C:\WINDOWS\System32\DRIVERS\portd2k.sys File not found
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (kl1) – C:\WINDOWS\System32\DRIVERS\kl1.sys (Kaspersky Lab)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (61883) – C:\WINDOWS\system32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\WINDOWS\system32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\WINDOWS\system32\drivers\msdv.sys (Microsoft Corporation)
DRV - (pfsvgae) – C:\Documents and Settings\Doug\Local Settings\Temp\pfsvgae.sys ()
DRV - (HCF_MSFT) – C:\WINDOWS\system32\drivers\HCF_MSFT.sys (Conexant)
DRV - (ac97intc) Intel® 82801 Audio Driver Install Service (WDM) – C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (EL90XBC) – C:\WINDOWS\system32\drivers\el90xbc5.sys (3Com Corporation)
DRV - (Winachcf) – C:\WINDOWS\system32\drivers\winachcf.sys (Conexant)
DRV - (BrPar) – C:\WINDOWS\System32\drivers\BrPar.sys (Brother Industries Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.charter.net/google/index.php?q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000001d Kernel Drivers (total 136): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EE000 \WINDOWS\system32\hal.dll 0xF7B6F000 \WINDOWS\system32\KDCOM.DLL 0xF7A7F000 \WINDOWS\system32\BOOTVID.dll 0xF7620000 ACPI.sys 0xF7B71000 \WINDOWS\System32\DRIVERS\WMILIB.SYS 0xF760F000 pci.sys 0xF766F000 isapnp.sys 0xF767F000 ohci1394.sys 0xF768F000 \WINDOWS\System32\DRIVERS\1394BUS.SYS 0xF7B73000 intelide.sys 0xF78EF000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS 0xF769F000 MountMgr.sys 0xF75F0000 ftdisk.sys 0xF7B75000 dmload.sys 0xF75CA000 dmio.sys 0xF78F7000 PartMgr.sys 0xF76AF000 VolSnap.sys 0xF75B2000 atapi.sys 0xF76BF000 disk.sys 0xF76CF000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS 0xF7592000 fltmgr.sys 0xF753C000 SYMDS.SYS 0xF752A000 sr.sys 0xF74FD000 SYMEFA.SYS 0xF76DF000 PxHelp20.sys 0xF74E6000 KSecDD.sys 0xF7459000 Ntfs.sys 0xF742C000 NDIS.sys 0xF76EF000 sbp2port.sys 0xF7412000 Mup.sys 0xF76FF000 agp440.sys 0xF771F000 \SystemRoot\System32\DRIVERS\nic1394.sys 0xF783F000 \SystemRoot\System32\DRIVERS\processr.sys 0xF65BB000 \SystemRoot\system32\DRIVERS\ati2mtag.sys 0xF65A7000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF64FC000 \SystemRoot\system32\DRIVERS\winachcf.sys 0xF7A07000 \SystemRoot\System32\Drivers\Modem.SYS 0xF7A0F000 \SystemRoot\System32\DRIVERS\usbohci.sys 0xF64D8000 \SystemRoot\System32\DRIVERS\USBPORT.SYS 0xF7A17000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF64C7000 \SystemRoot\System32\DRIVERS\el90xbc5.sys 0xF7A1F000 \SystemRoot\System32\DRIVERS\fdc.sys 0xF785F000 \SystemRoot\System32\DRIVERS\i8042prt.sys 0xF7A27000 \SystemRoot\System32\DRIVERS\kbdclass.sys 0xF7A2F000 \SystemRoot\System32\DRIVERS\mouclass.sys 0xF786F000 \SystemRoot\System32\DRIVERS\serial.sys 0xF7B43000 \SystemRoot\System32\DRIVERS\serenum.sys 0xF64B3000 \SystemRoot\System32\DRIVERS\parport.sys 0xF787F000 \SystemRoot\System32\Drivers\Imapi.SYS 0xF788F000 \SystemRoot\System32\DRIVERS\cdrom.sys 0xF789F000 \SystemRoot\System32\DRIVERS\redbook.sys 0xF6490000 \SystemRoot\System32\DRIVERS\ks.sys 0xF7A37000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0xF7A3F000 \SystemRoot\System32\DRIVERS\usbuhci.sys 0xF6478000 \SystemRoot\system32\drivers\ac97intc.sys 0xF6454000 \SystemRoot\system32\drivers\portcls.sys 0xF78AF000 \SystemRoot\system32\drivers\drmk.sys 0xF7D68000 \SystemRoot\System32\DRIVERS\audstub.sys 0xF78BF000 \SystemRoot\System32\DRIVERS\rasl2tp.sys 0xF7B4B000 \SystemRoot\System32\DRIVERS\ndistapi.sys 0xF643D000 \SystemRoot\System32\DRIVERS\ndiswan.sys 0xF78CF000 \SystemRoot\System32\DRIVERS\raspppoe.sys 0xF78DF000 \SystemRoot\System32\DRIVERS\raspptp.sys 0xF7A47000 \SystemRoot\System32\DRIVERS\TDI.SYS 0xF642C000 \SystemRoot\System32\DRIVERS\psched.sys 0xF772F000 \SystemRoot\System32\DRIVERS\msgpc.sys 0xF7A5F000 \SystemRoot\System32\DRIVERS\ptilink.sys 0xF7A67000 \SystemRoot\System32\DRIVERS\raspti.sys 0xF63A2000 \SystemRoot\System32\DRIVERS\rdpdr.sys 0xF6A01000 \SystemRoot\System32\DRIVERS\termdd.sys 0xF7BA3000 \SystemRoot\System32\DRIVERS\swenum.sys 0xF6344000 \SystemRoot\System32\DRIVERS\update.sys 0xF73DD000 \SystemRoot\System32\DRIVERS\mssmbios.sys 0xF69C1000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF775F000 \SystemRoot\System32\DRIVERS\usbhub.sys 0xF7BDF000 \SystemRoot\System32\DRIVERS\USBD.SYS 0xF791F000 \SystemRoot\System32\DRIVERS\flpydisk.sys 0xF7BE3000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7CD0000 \SystemRoot\System32\Drivers\Null.SYS 0xF7BE5000 \SystemRoot\System32\Drivers\Beep.SYS 0xF792F000 \SystemRoot\System32\drivers\vga.sys 0xF7BE7000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7BE9000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7937000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF793F000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7B33000 \SystemRoot\System32\DRIVERS\rasacd.sys 0xBA7CD000 \SystemRoot\System32\DRIVERS\ipsec.sys 0xBA774000 \SystemRoot\System32\DRIVERS\tcpip.sys 0xBA71D000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SYMTDI.SYS 0xBA6F7000 \SystemRoot\System32\DRIVERS\ipnat.sys 0xBA6D2000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xBA655000 \SystemRoot\System32\DRIVERS\netbt.sys 0xBA633000 \SystemRoot\System32\drivers\afd.sys 0xF781F000 \SystemRoot\System32\DRIVERS\netbios.sys 0xBA614000 \SystemRoot\system32\drivers\NIS\1107000.00C\Ironx86.SYS 0xF782F000 \SystemRoot\System32\DRIVERS\wanarp.sys 0xF62BF000 \SystemRoot\System32\DRIVERS\arp1394.sys 0xF62AF000 \SystemRoot\system32\drivers\NIS\1107000.00C\SRTSPX.SYS 0xBA5E9000 \SystemRoot\System32\DRIVERS\rdbss.sys 0xBA551000 \SystemRoot\System32\DRIVERS\mrxsmb.sys 0xF629F000 \SystemRoot\System32\Drivers\Fips.SYS 0xBA4F3000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xBA4D6000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xBA457000 \SystemRoot\system32\drivers\NIS\1107000.00C\ccHPx86.sys 0xBA3AB000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\BASHDefs\20100810.004\BHDrvx86.sys 0xF625F000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xBA393000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7C11000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF73CD000 \SystemRoot\System32\drivers\Dxapi.sys 0xF7987000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7CED000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\ati2dvag.dll 0xBF065000 \SystemRoot\System32\ati2cqag.dll 0xBF0FE000 \SystemRoot\System32\atikvmag.dll 0xBF182000 \SystemRoot\System32\atiok3x2.dll 0xBF1CD000 \SystemRoot\System32\ati3duag.dll 0xBF572000 \SystemRoot\System32\ativvaxx.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xB8253000 \SystemRoot\System32\DRIVERS\ndisuio.sys 0xB7F46000 \SystemRoot\system32\drivers\wdmaud.sys 0xB80B3000 \SystemRoot\system32\drivers\sysaudio.sys 0xB7EA3000 \SystemRoot\System32\DRIVERS\mrxdav.sys 0xF796F000 \SystemRoot\System32\drivers\BrPar.sys 0xF7B95000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xB7AD4000 \SystemRoot\System32\DRIVERS\srv.sys 0xB747B000 \SystemRoot\System32\Drivers\HTTP.sys 0xB7159000 \SystemRoot\System32\Drivers\NIS\1107000.00C\SRTSP.SYS 0xB7CE3000 \SystemRoot\System32\DRIVERS\asyncmac.sys 0xB6C84000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\IPSDefs\20100820.001\IDSxpx86.sys 0xB673F000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xB65F3000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\VirusDefs\20100822.007\NAVEX15.SYS 0xB65DF000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.6.0.32\Definitions\VirusDefs\20100822.007\NAVENG.SYS 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 42): 0 System Idle Process 4 System 496 C:\WINDOWS\system32\smss.exe 552 csrss.exe 588 C:\WINDOWS\system32\winlogon.exe 632 C:\WINDOWS\system32\services.exe 644 C:\WINDOWS\system32\lsass.exe 800 C:\WINDOWS\system32\ati2evxx.exe 820 C:\WINDOWS\system32\svchost.exe 876 svchost.exe 944 C:\WINDOWS\system32\svchost.exe 1016 C:\WINDOWS\system32\ati2evxx.exe 1124 svchost.exe 1220 svchost.exe 1324 C:\WINDOWS\system32\spoolsv.exe 1632 svchost.exe 1652 C:\WINDOWS\explorer.exe 1724 C:\WINDOWS\system32\svchost.exe 1792 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1900 C:\Program Files\Bonjour\mDNSResponder.exe 1928 C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe 168 C:\Program Files\Java\jre6\bin\jqs.exe 272 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 760 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe 936 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe 1144 C:\Program Files\HP\HP Software Update\hpwuschd2.exe 1152 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 1432 C:\Program Files\Common Files\Java\Java Update\jusched.exe 1440 C:\Program Files\iTunes\iTunesHelper.exe 1452 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe 1564 C:\WINDOWS\system32\HPZipm12.exe 1720 C:\WINDOWS\system32\svchost.exe 3012 alg.exe 3496 C:\Program Files\iPod\bin\iPodService.exe 3964 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe 1580 C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccsvchst.exe 868 C:\Program Files\Common Files\Real\Update_OB\realsched.exe 3172 C:\Program Files\Mozilla Firefox\firefox.exe 2716 C:\Documents and Settings\Doug\My Documents\Downloads\MBRCheck.exe 2696 1044 C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe 3020 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\E: –> \\.\PhysicalDrive1 at offset 0x00000000`01f60800 (NTFS) PhysicalDrive0 Model Number: ST3160812A, Rev: 3.AAJ PhysicalDrive1 Model Number: ST380021A, Rev: 3.10 Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A 74 GB \\.\PhysicalDrive1 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done! DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 14:37:35.40 on 08/22/10 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.141 [GMT -5:00] AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\Ati2evxx.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe -k Akamai C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe C:\Documents and Settings\Doug\My Documents\Downloads\dds.com ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.charter.net/google/index.php?q= uStart Page = hxxp://www.google.com/ uWindow Title = Powered by Charter Communications BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: : {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\17.7.0.12\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\17.7.0.12\IPSBHO.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\17.7.0.12\coIEPlg.dll TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [BrStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [] mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\docume~1\doug\startm~1\programs\startup\ding!.lnk - c:\program files\southwest airlines\ding\Ding.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {01016526-5E80-11D8-9E86-0007E96C65AE} - hxxps://install.charter.com/diskless/bin/ssctlsma.dll DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/d/c/8/dc8362b3-f410-4e7d-b672-209d6bd8fcea/OGAControl.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab DPF: {43E3F87D-DE7F-4087-BD4F-0DC854981158} - hxxp://download.microsoft.com/download/7/3/8/7384c441-3721-41ee-ae15-b678888f00dd/clearadj.CAB DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1171048235531 DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1181405173609 DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://doncesar.com/activex/AMC.cab DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://www.nick.com/common/groove/gx/GrooveAX27.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} - hxxp://63.241.168.238/ae/ecwplugins/ncs1.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} - hxxp://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} - hxxp://psdfs.pkwy.k12.mo.us/viewer/activeXViewer/activexviewer.cab DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\doug\applic~1\mozilla\firefox\profiles\b7541vtf.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.6.0.32\coffplgn\components\coFFPlgn.dll FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.6.0.32\ipsffplgn\components\IPSFFPl.dll FF - plugin: c:\documents and settings\doug\application data\mozilla\firefox\profiles\b7541vtf.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1107000.00c\symds.sys [2010-8-19 328752] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1107000.00c\symefa.sys [2010-8-19 173104] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.6.0.32\definitions\bashdefs\20100810.004\BHDrvx86.sys [2010-8-10 692272] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1107000.00c\cchpx86.sys [2010-8-19 501888] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1107000.00c\ironx86.sys [2010-8-19 116784] R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2001-8-18 14336] R2 NIS;Norton Internet Security;c:\program files\norton internet security\engine\17.7.0.12\ccsvchst.exe [2010-8-19 126392] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-8-19 102448] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.6.0.32\definitions\ipsdefs\20100820.001\IDSXpx86.sys [2010-8-20 331640] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.6.0.32\definitions\virusdefs\20100822.007\NAVENG.SYS [2010-8-22 85424] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_17.6.0.32\definitions\virusdefs\20100822.007\NAVEX15.SYS [2010-8-22 1362608] S2 gupdate1c9c10afa468d72;Google Update Service (gupdate1c9c10afa468d72);c:\program files\google\update\GoogleUpdate.exe [2009-4-19 133104] S2 portD;CMS PortIO Service;c:\windows\system32\drivers\portd2k.sys –> c:\windows\system32\drivers\portd2k.sys [?] S3 pfsvgae;pfsvgae;c:\docume~1\doug\locals~1\temp\pfsvgae.sys [2001-10-15 31744] =============== Created Last 30 ================ 2010-08-21 19:07:25 0 d—–w- c:\docume~1\doug\applic~1\Tific 2010-08-19 23:32:04 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF 2010-08-19 23:32:04 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2010-08-19 23:32:04 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL 2010-08-19 23:32:04 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2010-08-19 23:32:04 0 d—–w- c:\program files\Symantec 2010-08-19 23:32:04 0 d—–w- c:\program files\common files\Symantec Shared 2010-08-19 23:31:28 0 d—–w- c:\windows\system32\drivers\NIS 2010-08-19 23:31:24 0 d—–w- c:\program files\Norton Internet Security 2010-08-19 23:31:12 0 d—–w- c:\program files\NortonInstaller 2010-08-19 23:31:12 0 d—–w- c:\docume~1\alluse~1\applic~1\NortonInstaller 2010-08-19 23:29:21 0 d—–w- c:\docume~1\alluse~1\applic~1\Norton 2010-08-19 23:21:39 0 d—–w- c:\windows\Internet Logs 2010-08-18 21:30:09 0 d—–w- c:\program files\Trend Micro 2010-07-28 21:57:21 0 d—–w- c:\docume~1\doug\applic~1\CheckPoint 2010-07-28 21:56:39 0 d—–w- c:\program files\CheckPoint 2010-07-24 21:42:35 0 d—–w- c:\program files\iPod ==================== Find3M ==================== 2010-08-19 09:36:30 4212 —ha-w- c:\windows\system32\zllictbl.dat 2010-06-30 12:31:35 149504 —-a-w- c:\windows\system32\schannel.dll 2010-06-24 12:22:03 916480 —-a-w- c:\windows\system32\wininet.dll 2010-06-23 13:44:04 1851904 ——w- c:\windows\system32\win32k.sys 2010-06-17 14:03:00 80384 ——w- c:\windows\system32\iccvid.dll 2010-06-14 07:41:45 1172480 —-a-w- c:\windows\system32\msxml3.dll 2010-06-12 10:09:05 43520 ——w- c:\windows\system32\CmdLineExt03.dll 2008-10-02 23:58:14 65686384 -c—-w- c:\program files\Quicken_Home_Business_2009.exe 2008-05-07 18:51:17 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008050720080508\index.dat ============= FINISH: 14:39:08.43 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 02/09/07 11:21:59 AM System Uptime: 08/20/10 6:04:51 PM (44 hours ago) Motherboard: Dell Computer Corporation | | OptiPlex GX240 Processor: Intel® Pentium® 4 CPU 1.70GHz | Microprocessor | 1694/100mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 128 GiB total, 101.079 GiB free. D: is CDROM () E: is FIXED (NTFS) - 74 GiB total, 34.315 GiB free. ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP951: 08/04/10 1:39:20 PM - System Checkpoint RP952: 08/05/10 3:38:49 PM - System Checkpoint RP953: 08/06/10 6:16:27 PM - System Checkpoint RP954: 08/07/10 8:43:15 PM - System Checkpoint RP955: 08/08/10 8:46:32 PM - System Checkpoint RP956: 08/09/10 11:22:27 PM - System Checkpoint RP957: 08/11/10 2:12:46 PM - System Checkpoint RP958: 08/11/10 3:28:07 PM - Software Distribution Service 3.0 RP959: 08/12/10 4:07:46 PM - System Checkpoint RP960: 08/13/10 4:41:27 PM - System Checkpoint RP961: 08/14/10 5:05:21 PM - System Checkpoint RP962: 08/15/10 7:30:07 PM - System Checkpoint RP963: 08/16/10 8:11:39 PM - System Checkpoint RP964: 08/17/10 5:00:14 PM - Removed Safari RP965: 08/18/10 4:51:11 PM - OTL Restore Point RP966: 08/18/10 5:09:00 PM - OTL Restore Point RP967: 08/19/10 9:16:45 PM - System Checkpoint RP968: 08/20/10 9:49:46 PM - System Checkpoint RP969: 08/21/10 1:13:23 PM - After Norton Installation RP970: 08/22/10 2:10:57 PM - System Checkpoint ==== Installed Programs ====================== 3100_3200_3300_Help 3100_3200_3300trb 3300 3D Groove Playback Engine Acrobat.com Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3.3 Adobe Shockwave Player 11.5 AiO_Scan_CDA AiOSoftwareNPI AnswerWorks 5.0 English Runtime Apple Application Support Apple Mobile Device Support Apple Software Update Arithmemouse Times Tables Demo 1.12 Ascender Creativity Font Pack v.1.1.1 ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Control Panel ATI Display Driver AXIS Media Control Bonjour Brother HL-5370DW BufferChm Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center HydraVision Full Catalyst Control Center Localization All ccc-core-preinstall ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Combined Community Codec Pack 2008-09-21 16:18 Compatibility Pack for the 2007 Office system CP_AtenaShokunin1Config CP_CalendarTemplates1 CP_Package_Basic1 CP_Package_Variety1 CP_Package_Variety2 CP_Package_Variety3 CP_Panorama1Config Critical Update for Windows Media Player 11 (KB959772) CueTour CustomerResearchQFolder Destinations DeviceManagementQFolder DING! Diskeeper 2008 Home DocProc DocProcQFolder DocumentViewer DocumentViewerQFolder eSupportQFolder Fax_CDA FullDPAppQFolder Google Earth Google Update Helper HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Document Viewer 5.3 HP Extended Capabilities 5.3 HP Image Zone 5.3 HP Imaging Device Functions 5.3 HP Product Assistant HP Product Detection HP PSC & OfficeJet 5.3.A HP Solution Center & Imaging Support Tools 5.3 HP Update HPProductAssistant Image Web Server IE Plugins 2,0,0,104 InstantShareDevices iTunes Java Auto Updater Java™ 6 Update 20 LEGO Digital Designer LEGO Island LEGO Island 2 LEGO MINDSTORMS Edu NXT - English Language Pack LEGO MINDSTORMS Edu NXT Software v2.0 LEGO MINDSTORMS NXT Driver LEGO MINDSTORMS NXT Edu Migration Package LEGO Racers LEGO Racers 2 LEGO Star Wars II LEGO Universe MarketResearch Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Excel Viewer Microsoft Office Excel Viewer 2003 Microsoft Office Outlook 2003 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Word 2003 Microsoft Outlook Personal Folders Backup Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Windows XP Video Decoder Checkup Utility MobileMe Control Panel Mozilla Firefox (3.6.8) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Mummy Maze Deluxe 1.1 NewCopy_CDA Norton Internet Security OCR Software by I.R.I.S 7.0 OGA Notifier 2.0.0048.0 PanoStandAlone PhotoGallery ProductContextNPI Quicken 2010 QuickTime RandMap Readme RealPlayer Remote Printer Console RollerCoaster Tycoon 3 Platinum Scan ScannerCopy Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Shrek 2 Shrek 2 Team Action Shrek 2™: Team Action ™ Skins SkinsHP1 SolutionCenter Sonic_PrimoSDK SpongeBob Diner Dash SpongeBob SquarePants Employee of the Month Spybot - Search & Destroy 1.4 Stagecast Creator 2 Status The Polar Express Time Zone Data Update Tool for Microsoft Office Outlook TrayApp TweakNow RegCleaner Standard Unload Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB968220) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC 9.0 Runtime WebFldrs XP WebReg Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 ==== Event Viewer Messages From Past Week ======== 08/18/10 4:17:43 PM, error: Service Control Manager [7000] - The CMS PortIO Service service failed to start due to the following error: The system cannot find the file specified. ==== End Of File ===========================
Yes, I've run it. However the results are so long I can't seem to upload them to the site. Short of breaking it into multiple pieces do you have any suggestions? Thanks, Dbm
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=114068&view=findpost&p=677621

Collect::
c:\docume~1\Doug\LOCALS~1\Temp\pfsvgae.sys

Driver::
pfsvgae

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista/Win7 users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hi, I had to reboot the computer because it came to a complete stop. After that when I try to start the Kaspersky scan I get an error message indicated that Java needs to have an uninterrupted internet connection to run properly. Am writing this from work in the hopes you might have a work around or other suggestions. Thanks, Dbm
Hi

Try this scanner instead:


**Vista users - right click on the IE icon and run as administrator

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI