This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer suddenly runs much slower, mouse freezes

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have WinXP Pro Ver 2002 SP3
Pentium 4 CPU 3.20GHz 3.19GHz, 0.99 of RAM

Hijackthis Notebook results:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:09:17 AM, on 11/24/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PROMon.exe
C:\WINDOWS\system32\NMSSvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: @C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Bing Bar] "C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} (SkillGam Control) - http://www.worldwinner.com/games/v47/skillgam/skillgam.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) - http://www.worldwinner.com/games/v50/tpir/tpir.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - http://www.worldwinner.com/games/v48/brickout/brickout.cab
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} (CPlayFirstTriJinxControl Object) - http://zone.msn.com/bingame/trix/default/T…nx.1.0.0.87.cab
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v50/pool/pool.cab
O16 - DPF: {3D3DBC64-0D21-4EA4-94EE-86D6D9B31C0C} (MoneyList Control) - http://www.worldwinner.com/games/v45/moneylist/moneylist.cab
O16 - DPF: {4AB16005-E995-4A60-89DE-8B8A3E6EB5B0} (TrivialPursuit Control) - http://www.worldwinner.com/games/v56/trivi…vialpursuit.cab
O16 - DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} (WWHearts Control) - http://www.worldwinner.com/games/v53/wwhearts/wwhearts.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v63/bjattack/bja.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1274911458296
O16 - DPF: {64CD313F-F079-4D93-959F-4D28B5519449} (Jeopardy Control) - http://www.worldwinner.com/games/v56/jeopardy/jeopardy.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinner.com/games/v41/freecell/freecell.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} (WorldWinner ActiveX Launcher Control) - http://www.worldwinner.com/games/launcher/….0/iewwload.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab
O16 - DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} (BejeweledTwist Control) - http://www.worldwinner.com/games/v51/bejew…eweledtwist.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v57/cubis/cubis.cab
O16 - DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} (Clue Control) - http://www.worldwinner.com/games/v68/clue/clue.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v41/hangman/hangman.cab
O16 - DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} (GrandSlamTrivia Control) - http://www.worldwinner.com/games/v46/grand…dslamtrivia.cab
O16 - DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} (Monopoly Control) - http://www.worldwinner.com/games/v46/monopoly/monopoly.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - http://www.worldwinner.com/games/v42/tilecity/tilecity.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinner.com/games/v45/royal/royal.cab
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - http://www.worldwinner.com/games/v52/dinerdash/dinerdash.cab
O16 - DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} (MysteryPI Control) - http://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinner.com/games/v43/paint/paint.cab
O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) - http://www.worldwinner.com/games/v44/golfsol/golfsol.cab
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinner.com/games/v54/wwspades/wwspades.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\system32\NMSSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 11428 bytes

I hope I did this correctly, Thanks.
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

1) MBRCheck
Please download MBRCheck.exe to your desktop.

  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

2) DDS
Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

3) GMER
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.

  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



4) What You Will Need To Post:
  • MBRCheck log
  • DDS logs
  • GMER log
Hey there Raktor! Thank you for your time with this. Here is the MBRCheck: MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000000c Kernel Drivers (total 130): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806FF000 \WINDOWS\system32\hal.dll 0xF7AD6000 \WINDOWS\system32\KDCOM.DLL 0xF79E6000 \WINDOWS\system32\BOOTVID.dll 0xF7587000 ACPI.sys 0xF7AD8000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7576000 pci.sys 0xF75D6000 isapnp.sys 0xF7B9E000 PCIIde.sys 0xF7856000 \WINDOWS\System32\Drivers\PCIIDEX.SYS 0xF7ADA000 intelide.sys 0xF75E6000 MountMgr.sys 0xF7557000 ftdisk.sys 0xF7ADC000 dmload.sys 0xF7531000 dmio.sys 0xF785E000 PartMgr.sys 0xF75F6000 VolSnap.sys 0xF7519000 atapi.sys 0xF7606000 disk.sys 0xF7616000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF74F9000 fltmgr.sys 0xF74A2000 SYMDS.SYS 0xF7490000 sr.sys 0xF7626000 Lbd.sys 0xF73E7000 SYMEFA.SYS 0xF7636000 PxHelp20.sys 0xF73D0000 KSecDD.sys 0xF7343000 Ntfs.sys 0xF7316000 NDIS.sys 0xF72FC000 Mup.sys 0xF698F000 \SystemRoot\system32\DRIVERS\ialmnt5.sys 0xF697B000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF694C000 \SystemRoot\system32\DRIVERS\b57xp32.sys 0xF7916000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF6928000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF791E000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF6892000 \SystemRoot\system32\drivers\smwdm.sys 0xF686E000 \SystemRoot\system32\drivers\portcls.sys 0xF7786000 \SystemRoot\system32\drivers\drmk.sys 0xF684B000 \SystemRoot\system32\drivers\ks.sys 0xF6833000 \SystemRoot\system32\drivers\aeaudio.sys 0xF7796000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF793E000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7946000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF681F000 \SystemRoot\system32\DRIVERS\parport.sys 0xF77A6000 \SystemRoot\system32\DRIVERS\serial.sys 0xF7ABE000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF7956000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF77B6000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF77C6000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF77D6000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF77E6000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF7ACA000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0xF7BF1000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF77F6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7AD2000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF6808000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF7806000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF7816000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF797E000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF67F7000 \SystemRoot\system32\DRIVERS\psched.sys 0xF7826000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF798E000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF799E000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF67C7000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF7836000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7B08000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF6769000 \SystemRoot\system32\DRIVERS\update.sys 0xF72B8000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7646000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF7676000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7B0E000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF7B1A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7C37000 \SystemRoot\System32\Drivers\Null.SYS 0xF7B1E000 \SystemRoot\System32\Drivers\Beep.SYS 0xF786E000 \SystemRoot\System32\drivers\vga.sys 0xF7B22000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7B28000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF78A6000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF78B6000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7A8E000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xAA69D000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xAA644000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xAA5EB000 \SystemRoot\system32\drivers\NAV\1201000.025\SYMTDI.SYS 0xAA5C5000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF7696000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xAA59F000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xAA547000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20101124.002\IDSxpx86.sys 0xAA51F000 \SystemRoot\system32\DRIVERS\netbt.sys 0xAA4FD000 \SystemRoot\System32\drivers\afd.sys 0xF76A6000 \SystemRoot\system32\DRIVERS\netbios.sys 0xAA4DA000 \SystemRoot\system32\drivers\NAV\1201000.025\Ironx86.SYS 0xF78DE000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF76D6000 \SystemRoot\system32\drivers\NAV\1201000.025\SRTSPX.SYS 0xAA4AF000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xF7AC2000 \SystemRoot\SYSTEM32\DRIVERS\OMCI.SYS 0xAA43F000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF76F6000 \SystemRoot\System32\Drivers\Fips.SYS 0xAA3E1000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xAA3C4000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xAA318000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20101104.001\BHDrvx86.sys 0xF7716000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xAA238000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7B38000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xAA700000 \SystemRoot\System32\drivers\Dxapi.sys 0xF795E000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7D1D000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF020000 \SystemRoot\System32\ialmdnt5.dll 0xBF012000 \SystemRoot\System32\ialmrnt5.dll 0xBF040000 \SystemRoot\System32\ialmdev5.DLL 0xBF070000 \SystemRoot\System32\ialmdd5.DLL 0xAA1D4000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA9E9B000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7AEA000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xA9D2B000 \SystemRoot\system32\DRIVERS\srv.sys 0xA993A000 \SystemRoot\System32\Drivers\NAV\1201000.025\SRTSP.SYS 0xA9798000 \??\C:\WINDOWS\system32\FsUsbExDisk.SYS 0xA95E3000 \SystemRoot\system32\drivers\wdmaud.sys 0xA9618000 \SystemRoot\system32\drivers\sysaudio.sys 0xA95A0000 \??\C:\WINDOWS\system32\drivers\NMSCFG.SYS 0xA9024000 \SystemRoot\System32\Drivers\HTTP.sys 0xA81DB000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xA831F000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xA909D000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xA801D000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20101126.003\NAVEX15.SYS 0xA8009000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20101126.003\NAVENG.SYS 0xA7EC0000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 47): 0 System Idle Process 4 SYSTEM 600 C:\WINDOWS\system32\smss.exe 656 csrss.exe 680 C:\WINDOWS\system32\winlogon.exe 724 C:\WINDOWS\system32\services.exe 736 C:\WINDOWS\system32\lsass.exe 912 C:\WINDOWS\system32\svchost.exe 980 svchost.exe 1076 C:\WINDOWS\system32\svchost.exe 1164 svchost.exe 1272 svchost.exe 1456 C:\WINDOWS\system32\spoolsv.exe 1588 svchost.exe 1644 C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe 1676 C:\WINDOWS\system32\FsUsbExService.Exe 1712 C:\Program Files\Java\jre6\bin\jqs.exe 1760 C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe 1948 C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe 2040 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 412 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 460 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 400 wmiprvse.exe 1040 alg.exe 1116 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE 3036 C:\WINDOWS\system32\NMSSvc.Exe 2276 C:\WINDOWS\system32\dllhost.exe 1788 msdtc.exe 3616 C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe 3080 C:\WINDOWS\explorer.exe 2692 C:\WINDOWS\system32\PROMon.exe 3164 C:\WINDOWS\system32\igfxtray.exe 3276 C:\WINDOWS\system32\hkcmd.exe 652 C:\WINDOWS\system32\igfxpers.exe 320 C:\Program Files\Analog Devices\SoundMAX\SMTray.exe 1924 C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe 3968 C:\Program Files\Common Files\Java\Java Update\jusched.exe 872 C:\Program Files\DivX\DivX Update\DivXUpdate.exe 3356 C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe 2852 C:\WINDOWS\system32\ctfmon.exe 4072 C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe 2752 C:\Program Files\Messenger\msmsgs.exe 3340 C:\WINDOWS\system32\wuauclt.exe 3620 C:\PROGRA~1\Yahoo!\Messenger\Ymsgr_tray.exe 832 C:\Program Files\Mozilla Firefox\firefox.exe 3944 C:\Program Files\Mozilla Firefox\plugin-container.exe 2152 C:\Documents and Settings\MJR_2\My Documents\Downloads\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: HitachiHDT721016SLA380, Rev: ST1OA3BB Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done! I will follow with the 2nd request next.
Here is the DDS. Ok, now you said to zip the Attatch one but I have to apologize for my lack of knowledge in what exactly what you mean by zip it. On the other hand, I know you need to see this information but im sure theres a reason you dont want me to copy & paste so Im wondering what I should do. Man, Im sorry for this. How embarrassing, lol. DDS: DDS (Ver_10-11-26.01) - NTFSx86 Run by [removed] at 11:21:32.07 on Fri 11/26/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.294 [GMT -8:00] AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe C:\WINDOWS\system32\FsUsbExService.Exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\WINDOWS\system32\NMSSvc.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\PROMon.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\MJR_2\My Documents\Downloads\dds.com ============== Pseudo HJT Report =============== uStart Page = about:blank uWindow Title = Internet Explorer, optimized for Bing and MSN uDefault_Page_URL = hxxp://www.msn.com BHO: Gamevance: {0ed403e8-470a-4a8a-85a4-d7688cfe39a3} - c:\program files\gamevance\gamevancelib32.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\18.1.0.37\IPSBHO.DLL BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Gamevance Text: {beac7dc8-e106-4c6a-931e-5a42e7362883} - c:\program files\gamevance\gvtl.dll BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: @c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [AutoStartNPSAgent] c:\program files\samsung\samsung new pc studio\NPSAgent.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [PROMon.exe] PROMon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Smapp] c:\program files\analog devices\soundmax\SMTray.exe mRun: [Bing Bar] "c:\program files\msn toolbar\platform\5.0.1449.0\mswinext.exe" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [NPSStartup] mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Norton Online Backup] c:\program files\symantec\norton online backup\NOBuClient.exe mRun: [Gamevance] c:\program files\gamevance\gamevance32.exe a IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: pureplay.com\www DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} - hxxp://www.worldwinner.com/games/v47/skillgam/skillgam.cab DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - hxxp://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab DPF: {1D082E71-DF20-4AAF-863B-596428C49874} - hxxp://www.worldwinner.com/games/v50/tpir/tpir.cab DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} - hxxp://www.worldwinner.com/games/v48/brickout/brickout.cab DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} - hxxp://zone.msn.com/bingame/trix/default/TriJinx.1.0.0.87.cab DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} - hxxp://www.worldwinner.com/games/v50/pool/pool.cab DPF: {3D3DBC64-0D21-4EA4-94EE-86D6D9B31C0C} - hxxp://www.worldwinner.com/games/v45/moneylist/moneylist.cab DPF: {4AB16005-E995-4A60-89DE-8B8A3E6EB5B0} - hxxp://www.worldwinner.com/games/v56/trivialpursuit/trivialpursuit.cab DPF: {555F1BBC-6EC2-474F-84AF-633EF097FF54} - hxxp://www.worldwinner.com/games/v53/wwhearts/wwhearts.cab DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} - hxxp://www.worldwinner.com/games/v63/bjattack/bja.cab DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} - hxxp://www.worldwinner.com/games/v49/blockwerx/blockwerx.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1274911458296 DPF: {64CD313F-F079-4D93-959F-4D28B5519449} - hxxp://www.worldwinner.com/games/v56/jeopardy/jeopardy.cab DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} - hxxp://www.worldwinner.com/games/v41/freecell/freecell.cab DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {8F6E7FB2-E56B-4F66-A4E1-9765D2565280} - hxxp://www.worldwinner.com/games/launcher/ie/v2.22.01.0/iewwload.cab DPF: {94299420-321F-4FF9-A247-62A23EBB640B} - hxxp://www.worldwinner.com/games/v46/wordmojo/wordmojo.cab DPF: {95A311CD-EC8E-452A-BCEC-B844EB616D03} - hxxp://www.worldwinner.com/games/v51/bejeweledtwist/bejeweledtwist.cab DPF: {97438FE9-D361-4279-BA82-98CC0877A717} - hxxp://www.worldwinner.com/games/v57/cubis/cubis.cab DPF: {A021A215-6CDC-44B4-8C16-90491CED9605} - hxxp://www.worldwinner.com/games/v68/clue/clue.cab DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} - hxxp://www.worldwinner.com/games/v41/hangman/hangman.cab DPF: {B6FA2311-5F85-47D3-B885-7055340FC740} - hxxp://www.worldwinner.com/games/v46/grandslam/grandslamtrivia.cab DPF: {BA35B9B8-DE9E-47C9-AFA7-3C77E3DDFD39} - hxxp://www.worldwinner.com/games/v46/monopoly/monopoly.cab DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} - hxxp://www.worldwinner.com/games/v42/tilecity/tilecity.cab DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} - hxxp://www.worldwinner.com/games/v45/royal/royal.cab DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} - hxxp://www.worldwinner.com/games/v52/dinerdash/dinerdash.cab DPF: {C82BB209-F528-46F9-96D5-69DEF7260916} - hxxp://www.worldwinner.com/games/v45/mysterypi/mysterypi.cab DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} - hxxp://www.worldwinner.com/games/v43/paint/paint.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} - hxxp://www.worldwinner.com/games/v44/golfsol/golfsol.cab DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} - hxxp://www.worldwinner.com/games/v54/wwspades/wwspades.cab Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\mjr_2\applic~1\mozilla\firefox\profiles\tlzdhnsi.default\ FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\ipsffplgn\components\IPSFFPl.dll FF - plugin: c:\documents and settings\mjr_2\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\msn toolbar\platform\5.0.1449.0\npwinext.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-11-25 64288] R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1201000.025\SymDS.sys [2010-10-15 339504] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1201000.025\SymEFA.sys [2010-10-15 666672] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\definitions\bashdefs\20101104.001\BHDrvx86.sys [2010-11-3 691248] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1201000.025\Ironx86.sys [2010-10-15 134704] R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\common files\magix services\database\bin\FABS.exe [2009-8-27 1253376] R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-7-11 238952] R2 NAV;Norton AntiVirus;c:\program files\norton antivirus\engine\18.1.0.37\ccSvcHst.exe [2010-10-15 126904] R2 NOBU;Norton Online Backup;c:\program files\symantec\norton online backup\NOBuAgent.exe [2010-6-8 2057560] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-28 102448] R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2010-7-11 36608] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\definitions\ipsdefs\20101124.002\IDSXpx86.sys [2010-10-19 341880] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\definitions\virusdefs\20101126.003\NAVENG.SYS [2010-11-26 86064] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_18.1.0.37\definitions\virusdefs\20101126.003\NAVEX15.SYS [2010-11-26 1371184] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-29 136176] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-9-22 1355928] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\common files\magix services\database\bin\fbserver.exe [2008-8-7 3276800] =============== Created Last 30 ================ 2010-11-26 14:16:24 ——– d—–w- c:\program files\Gamevance 2010-11-25 15:06:30 ——– d—–w- c:\program files\Windows Media Connect 2 2010-11-25 15:05:05 ——– d—–w- c:\windows\system32\LogFiles 2010-11-25 14:58:50 ——– d—–w- c:\windows\system32\NtmsData 2010-11-25 11:35:22 15880 —-a-w- c:\windows\system32\lsdelete.exe 2010-11-25 10:19:34 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys 2010-11-25 10:19:24 ——– d—–w- c:\docume~1\mjr_2\locals~1\applic~1\Sunbelt Software 2010-11-25 10:11:29 ——– dc-h–w- c:\docume~1\alluse~1\applic~1\{E961CE1B-C3EA-4882-9F67-F859B555D097} 2010-11-25 10:10:47 ——– d—–w- c:\program files\Lavasoft 2010-11-24 12:04:40 388096 —-a-r- c:\docume~1\mjr_2\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2010-11-24 11:35:51 ——– d—–w- c:\program files\Trend Micro 2010-11-21 22:05:33 ——– d—–w- c:\docume~1\mjr_2\applic~1\Tific 2010-11-21 22:05:18 ——– d—–w- c:\docume~1\mjr_2\locals~1\applic~1\Symantec 2010-11-21 22:04:01 ——– d—–w- c:\windows\system32\wbem\repository\FS 2010-11-21 22:04:01 ——– d—–w- c:\windows\system32\wbem\Repository 2010-11-20 22:41:05 ——– d—–w- c:\docume~1\mjr_2\applic~1\Malwarebytes 2010-11-20 22:40:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-11-20 22:40:53 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-11-20 22:40:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-11-20 22:40:53 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-11-12 12:40:16 ——– d—–w- c:\program files\PurePlay 2010-11-12 12:40:16 ——– d—–w- c:\docume~1\alluse~1\applic~1\PurePlay 2010-11-12 02:28:56 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys 2010-11-12 02:28:56 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2010-11-06 19:37:34 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2010-11-06 19:37:34 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2010-10-31 17:02:55 ——– d—–w- c:\program files\Veetle 2010-10-28 13:10:41 ——– d—–w- c:\docume~1\mjr_2\locals~1\applic~1\Apple 2010-10-28 13:10:00 ——– d—–w- c:\docume~1\mjr_2\locals~1\applic~1\Apple Computer ==================== Find3M ==================== 2010-10-15 11:10:24 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL 2010-09-18 19:23:26 974848 —-a-w- c:\windows\system32\mfc42u.dll 2010-09-18 06:53:25 974848 —-a-w- c:\windows\system32\mfc42.dll 2010-09-18 06:53:25 954368 —-a-w- c:\windows\system32\mfc40.dll 2010-09-18 06:53:25 953856 —-a-w- c:\windows\system32\mfc40u.dll 2010-09-15 11:50:37 472808 —-a-w- c:\windows\system32\deployJava1.dll 2010-09-15 09:29:49 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-09-10 05:58:08 916480 —-a-w- c:\windows\system32\wininet.dll 2010-09-10 05:58:06 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-09-10 05:58:06 1469440 ——w- c:\windows\system32\inetcpl.cpl 2010-09-08 18:17:46 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2010-09-08 18:17:46 69632 —-a-w- c:\windows\system32\QuickTime.qts 2010-09-01 11:51:14 285824 —-a-w- c:\windows\system32\atmfd.dll 2010-08-31 13:42:52 1852800 —-a-w- c:\windows\system32\win32k.sys ============= FINISH: 11:21:59.43 ===============
Here is the Attach: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-11-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/26/2010 1:37:01 PM System Uptime: 11/25/2010 7:22:07 AM (28 hours ago) Motherboard: Hewlett-Packard | | 0968h Processor: Intel® Pentium® 4 CPU 3.20GHz | XU1 PROCESSOR | 3194/800mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 149 GiB total, 136.19 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318} Description: PS/2 Compatible Mouse Device ID: ACPI\PNP0F13\4&1117367&0 Manufacturer: Microsoft Name: PS/2 Compatible Mouse PNP Device ID: ACPI\PNP0F13\4&1117367&0 Service: i8042prt ==== System Restore Points =================== RP206: 11/25/2010 10:51:59 AM - System Checkpoint ==== Installed Programs ====================== Ad-Aware Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.4.1 Adobe Shockwave Player 11.5 Apple Application Support Apple Software Update Bing Bar Bing Bar Platform Broadcom 440x 10/100 Integrated Controller Broadcom Management Programs Broadcom NetXtreme Ethernet Controller Coby Media Manager DivX Setup Firebird SQL Server - MAGIX Edition Gamevance Google Earth Google Update Helper HiJackThis HijackThis 2.0.2 Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB981793) Intel® Graphics Media Accelerator Driver Intel® PRO Intelligent Installer Java Auto Updater Java™ 6 Update 22 MAGIX Screenshare Malwarebytes' Anti-Malware Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Default Manager Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Mozilla Firefox (3.6.12) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Norton AntiVirus Norton Online Backup Norton Security Scan QuickTime REALTEK Gigabit and Fast Ethernet NIC Driver RTLSetup 2.50.503 SAMSUNG Android USB Modem Software SAMSUNG Mobile Composite Device Software Samsung Mobile Modem Device Software SAMSUNG Mobile Modem V2 Software Samsung Mobile phone USB driver Software SAMSUNG Mobile USB Download Driver Software SAMSUNG Mobile USB Driver SAMSUNG Mobile USB Modem 1.0 Software Samsung Mobile USB Modem Device Software SAMSUNG Mobile USB Modem Software Samsung New PC Studio SAMSUNG USB Driver for Mobile Phones SAMSUNG USB Mobile Device Software Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) SoundMAX Text-To-Speech-Runtime Unity Web Player Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows Internet Explorer 8 (KB982632) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC80CRTRedist - 8.0.50727.4053 Veetle TV 0.9.18 VirtualCom driver Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP Windows Driver Package - MobileTop (sshpmdm) Modem (01/26/2008 2.6.0.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Live ID Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Yahoo! Messenger ==== Event Viewer Messages From Past Week ======== 11/24/2010 1:18:08 AM, error: Service Control Manager [7031] - The Norton AntiVirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. ==== End Of File ===========================
Raktor, I have seem to run into a problem with the GMER part. It downloaded just fine but when I open it, there is only a choice of "Run" or "Cancel" and to get to the GMER screen I clicked on "Run". The problem Im having is that when I click run, right when the screen opens my computer reboots so, Im not able to get that info. I hope your familiar with what Im doing or not doing correctly. I'll wait to see what you have to say regarding this. Thanks again for your time.
GMER can get slightly tempromental at times. :)

Please reboot your computer in Safe Mode by doing the following:
  • Restart your computer.
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually.
  • Instead of Windows loading as normal, a menu with options should appear.
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

Try running GMER in safe mode.
Im thinking I didnt do it correctly because I couldnt find any way to copy/paste it and also this is all that came up from the scan, again, my sincere apologies for my ignorance. GMER: SSDT Lbd.Sys(Boot Driver/LavasoftAB) ZwCreateKey [OxF762687E] SSDT Lbd.Sys(Boot Driver/LavasoftAB) ZwSetValueKey [OxF762687E] ? SYMDS.SYS System can not find file specifi……………….. ? SYMEFA.SYS System can not find file specifi………………. .text C:/Program Files/Mozella Firefox/Firefox.exe [1234]nrdll.dll!LdrLoadDll DEVICE 7C9163C3 5 Bytes JMP0291003A This is all that was showing when finished. For some reason I dont think thats what you needed. If not please feel free to reply in caps, I would understand. :blush:
Download Combofix to your desktop from any of the links below.

Link 1
Link 2


==================================

Disable your antivirus program, then double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Well. Link 1 didnt do anything, Link 2 downloaded Combofix, however it first indicated that my computer didnt have a restore ???(forgot) but it installed one, rebooted. I ran it again, a blue screen popped up and it did an Auto scan. It next is showing "Complete Stage_1" then 2, 3 etc until it hit 50. Then it flashed "Deleting Files" and immediately rebooted. I logged back on and there was no log on desktop and I waited just in case it was going to continue but nothing. I then gave it another try and the same thing happened. I have to admit that Im getting worried that I doing more harm than good, PLEASE dont take that the wrong way because I know your doing what you can. I just hope your not getting frustrated with this and give up on me. I dont have no idea why i cant get a log of what you need. Shall I try to do this one in safe mode also? I'll wait for your reply.
You're fine, you're doing everything just right. :) What happens when you boot up in normal mode now? Do you see your desktop? What about Safe Mode? Do you see your desktop there?
Yes to both. Everything is still ok, its still just the dramatic loss in speed, ie: I was able to watch any streaming video flawlessly and one day just opening a web page now is slow and as far any video played, its buffering after a mere 5 seconds and every 5 seconds after that. What I would like to do is like a system recovery because I dont keep any important things on it, its mainly used for gaming, email and what not. Now, what I think happened was something came through the email because a friend of mine had one of those viruses that sends emails to your connects without you knowing it and I fell for it. Regarding the system recovery, my computer( the oldie that small businesses used, HP Pavilion 4 Compaq dc7100 CMT ) doesnt use a recovery disk, its said to use a spot on the hard drive that has that, however Im not able to find where I can do that. System Restore in Accessories only gives the option of restoring to a previous date in which Ive done but didnt help bring it back up to speed. And thanks for the reassurance.
Sorry, was waiting on advice from a colleague.

Delete the copy of Combofix from your desktop.

Download Combofix from any of the links below but rename it to iexplore.exe before saving it to your desktop.

Link 1
Link 2


==================================

Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI