This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help pls system slow.

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My system is very slow loading programs and switching between programs and I havent a clue.Maybe someone can look at these files and help me.Thank you.I dont know where they went,I probably didnt do it right..Thanks anyway DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:16:07.90 on Thu 12/09/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_22 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2302.1881 [GMT -8:00] ============== Running Processes =============== C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\WINDOWS\Explorer.EXE C:\FRAPS\FRAPS.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Bigfoot Networks\Killer Driver\PortManager.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Raxco\PerfectDisk\PDAgent.exe C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\clayp\Desktop\dds.scr ============== Pseudo HJT Report =============== BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [Fraps] c:\fraps\FRAPS.EXE uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup uPolicies-explorer: NoWinKeys = 1 (0x1) uPolicies-explorer: NoSMMyDocs = 1 (0x1) uPolicies-explorer: NoFavoritesMenu = 1 (0x1) uPolicies-explorer: NoInstrumentation = 1 (0x1) IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe LSP: c:\windows\system32\iavlsp.dll LSP: %SYSTEMROOT%\system32\BfLLR.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1289789403296 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\windows defender\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\clayp\applic~1\mozilla\firefox\profiles\rk3y9nl8.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com?o=14652&l=dis FF - component: c:\documents and settings\clayp\application data\mozilla\firefox\profiles\rk3y9nl8.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc_fireftp.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\nos\bin\np_gp.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: browser.chrome.favicons - false FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 2250000 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 750000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 750000 FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 0 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2003-9-12 132899] R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2003-9-12 46810] R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-12-9 20328] R2 Killer Port Manager;Killer Port Manager;c:\program files\bigfoot networks\killer driver\PortManager.exe [2010-11-13 238080] R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2010-11-14 10448] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-11-14 363344] R2 uacFlt;Plantronics USB Audio Adapter EQ Filter Driver;c:\windows\system32\drivers\uacflt.sys [2010-11-14 21276] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 chdrvr01;CH Control Manager Driver 1;c:\windows\system32\drivers\chdrvr01.sys [2010-11-15 219072] R3 chdrvr02;CH Control Manager Driver 2;c:\windows\system32\drivers\chdrvr02.sys [2010-11-15 5120] R3 chdrvr03;CH Control Manager Driver 3;c:\windows\system32\drivers\chdrvr03.sys [2010-11-15 8704] R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2010-11-14 171096] R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2010-11-14 1324120] R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2010-11-14 72792] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-11-14 20952] R3 NetB834x;Killer NIC Gaming Adapter Service;c:\windows\system32\drivers\NetB834x.sys [2010-11-13 107680] R3 NetbEdge;Killer NIC NDIS-Edge Service;c:\windows\system32\drivers\NetBEdge.sys [2010-11-13 22048] R3 npusbio;npusbio;c:\windows\system32\drivers\npusbio.sys [2010-11-15 36384] R3 nvoclock;NVIDIA Enthusiasts Platform KDM;c:\windows\system32\drivers\nvoclock.sys [2009-9-15 38248] R3 SaiH2541;SaiH2541;c:\windows\system32\drivers\SaiH2541.sys [2007-5-1 132232] R3 STTub203;Thrustmaster HOTAS USB Bulk Out;c:\windows\system32\drivers\STTub203.sys [2010-11-15 40312] S3 Alpham1;Ideazon Fang USB Human Interface Device;c:\windows\system32\drivers\Alpham1.sys [2007-7-23 42624] S3 Alpham2;Ideazon Fang MM USB Human Interface Device;c:\windows\system32\drivers\Alpham2.sys [2007-3-20 18432] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-11-14 79360] S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2010-11-14 171096] S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2010-11-14 1324120] S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2010-11-14 72792] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2006-2-28 14336] =============== Created Last 30 ================ 2010-12-09 13:45 –d—– c:\program files\CCleaner 2010-12-09 05:16 –d—– c:\docume~1\clayp\applic~1\NVIDIA 2010-12-09 05:16 –d—– c:\program files\SystemRequirementsLab 2010-12-09 05:13 904,544 a——- C:\GPU-Z.0.4.9-[Guru3D.com].exe 2010-12-09 05:02 20,328 a——- c:\windows\system32\drivers\cpuz134_x32.sys 2010-12-09 05:02 –d—– c:\program files\CPUID 2010-12-04 19:39 –d—– c:\docume~1\clayp\applic~1\TeamViewer 2010-12-03 06:24 –d—– c:\program files\IObit 2010-12-02 07:53 472,808 a——- c:\windows\system32\deployJava1.dll 2010-12-02 07:53 73,728 a——- c:\windows\system32\javacpl.cpl 2010-11-30 11:19 237,320 a——- c:\windows\system32\PDBoot.exe 2010-11-29 16:11 1,908 a——- c:\windows\diagwrn.xml 2010-11-29 16:11 1,908 a——- c:\windows\diagerr.xml 2010-11-28 22:08 –d—– c:\windows\system32\LogFiles 2010-11-28 22:04 –d—– c:\program files\Super Fast Shutdown 2010-11-28 01:27 222,080 ——– c:\windows\system32\MpSigStub.exe 2010-11-26 18:02 –d—– c:\docume~1\alluse~1\applic~1\NVIDIA Corporation 2010-11-26 17:50 552 a——- c:\windows\system32\d3d8caps.dat 2010-11-26 17:42 –d—– c:\program files\Phyxion.net 2010-11-26 01:08 –d—– c:\windows\system32\scripting 2010-11-26 01:08 –d—– c:\windows\system32\en 2010-11-26 01:08 –d—– c:\windows\system32\bits 2010-11-26 01:08 –d—– c:\windows\l2schemas 2010-11-26 01:06 –d—– c:\windows\network diagnostic 2010-11-25 20:47 –d—– c:\docume~1\clayp\applic~1\ieSpell 2010-11-23 14:20 –d—– c:\docume~1\alluse~1\applic~1\Alwil Software 2010-11-23 12:30 –d—– c:\program files\common files\Steam 2010-11-23 12:30 –d—– c:\program files\Steam 2010-11-23 12:27 729,088 a——- c:\windows\iun6002.exe 2010-11-23 12:27 –d—– c:\program files\Novatix 2010-11-21 18:37 98,304 a——- c:\windows\system32CmdLineExt.dll 2010-11-21 10:10 –d—– c:\program files\ieSpell 2010-11-20 03:50 796,672 a——- c:\windows\GPInstall.exe 2010-11-20 00:43 118,784 a——- c:\windows\system32\iavlsp.dll 2010-11-20 00:34 74,703 a——- c:\windows\system32\mfc45.dll 2010-11-19 15:37 –d—– c:\docume~1\alluse~1\applic~1\IncrediMail 2010-11-19 15:37 –d—– c:\docume~1\alluse~1\applic~1\IM 2010-11-18 16:02 –d—– C:\Fraps 2010-11-17 19:26 –d—– c:\docume~1\alluse~1\applic~1\Saitek 2010-11-16 19:34 –d—– c:\program files\Ideazon 2010-11-16 08:23 22 a–sh— c:\windows\Sys3390 SettingsCollection.bin 2010-11-16 08:23 22 a–sh— c:\docume~1\clayp\applic~1\Sys6925.Config Collection.sys 2010-11-16 08:23 –d—– c:\program files\jv16 PowerTools 2010 2010-11-16 08:11 –d—– c:\program files\Fraps 2010-11-15 20:21 –d—– c:\docume~1\clayp\applic~1\Uniblue 2010-11-15 18:41 –d-h— c:\windows\system32\GroupPolicy 2010-11-15 18:36 0 a——- c:\windows\SYSTEM.INI 2010-11-15 16:58 –d—– c:\windows\system32\XPSViewer 2010-11-15 16:58 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2010-11-15 16:58 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2010-11-15 16:58 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2010-11-15 16:58 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2010-11-15 16:58 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2010-11-15 16:58 575,488 ——– c:\windows\system32\xpsshhdr.dll 2010-11-15 16:58 117,760 ——– c:\windows\system32\prntvpt.dll 2010-11-15 16:56 –d—– c:\program files\MSXML 6.0 2010-11-15 16:37 147,456 a——- c:\windows\system32\STTubeDevice203.dll 2010-11-15 16:37 45,056 a——- c:\windows\system32\HOTASCPL.dll 2010-11-15 16:37 40,312 a——- c:\windows\system32\drivers\STTub203.sys 2010-11-15 16:37 36,864 a——- c:\windows\system32\HOTASCougar.cpl 2010-11-15 16:37 –d—– c:\program files\HOTAS 2010-11-15 16:30 219,072 a——- c:\windows\system32\drivers\chdrvr01.sys 2010-11-15 16:30 86,776 a——- c:\windows\system32\CMCalBlk.dll 2010-11-15 16:30 8,704 a——- c:\windows\system32\drivers\chdrvr03.sys 2010-11-15 16:30 5,120 a——- c:\windows\system32\drivers\chdrvr02.sys 2010-11-15 16:30 –d—– c:\program files\CH Products 2010-11-15 16:13 –d—– c:\docume~1\clayp\applic~1\TS3Client 2010-11-15 16:10 –d—– c:\program files\TeamSpeak 3 Client 2010-11-15 15:54 36,384 a——- c:\windows\system32\drivers\npusbio.sys 2010-11-15 15:54 –d—– c:\program files\NaturalPoint 2010-11-15 15:32 4,236 a—-r– c:\windows\system32\SaiD2541.pr0 2010-11-15 15:09 –dsh— c:\documents and settings\clayp\PrivacIE 2010-11-15 15:06 –dsh— c:\documents and settings\clayp\IETldCache 2010-11-15 15:02 –d—– c:\windows\ie8updates 2010-11-15 15:02 11,076,096 -c—— c:\windows\system32\dllcache\ieframe.dll 2010-11-15 15:02 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll 2010-11-15 15:02 743,424 -c—— c:\windows\system32\dllcache\iedvtool.dll 2010-11-15 15:02 599,040 -c—— c:\windows\system32\dllcache\msfeeds.dll 2010-11-15 15:02 247,808 -c—— c:\windows\system32\dllcache\ieproxy.dll 2010-11-15 15:02 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll 2010-11-15 15:02 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2010-11-15 15:01 -cd-h— c:\windows\ie8 2010-11-15 14:59 –d—– c:\windows\ServicePackFiles 2010-11-15 14:50 273,024 ——– c:\windows\system32\drivers\bthport.sys 2010-11-15 14:48 –d—– c:\windows\system32\PreInstall 2010-11-15 09:02 280 a——- c:\windows\system32\PDBootState 2010-11-15 08:29 –d—– c:\program files\RegScrubXP 2010-11-14 20:04 –d—– c:\docume~1\clayp\applic~1\Malwarebytes 2010-11-14 20:04 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-11-14 20:04 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-11-14 20:04 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-11-14 20:04 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-11-14 19:13 –d—– c:\program files\Raxco 2010-11-14 18:54 –d—– c:\windows\system32\appmgmt 2010-11-14 18:50 21,728 a——- c:\windows\system32\wucltui.dll.mui 2010-11-14 18:50 17,632 a——- c:\windows\system32\wuaueng.dll.mui 2010-11-14 18:50 15,072 a——- c:\windows\system32\wuaucpl.cpl.mui 2010-11-14 18:50 15,064 a——- c:\windows\system32\wuapi.dll.mui 2010-11-14 18:50 –d—– c:\windows\system32\SoftwareDistribution 2010-11-14 18:49 –dsh— c:\documents and settings\clayp\UserData 2010-11-14 18:26 717 a——- C:\CPUID CPU-Z.lnk 2010-11-14 18:26 –d—– c:\docume~1\alluse~1\applic~1\IObit 2010-11-14 18:26 –d—– c:\docume~1\clayp\applic~1\IObit 2010-11-14 18:25 –d—– c:\docume~1\alluse~1\applic~1\FreeApp 2010-11-14 18:13 1,080 a——- c:\windows\system32\settingsbkup.sfm 2010-11-14 18:13 1,080 a——- c:\windows\system32\settings.sfm 2010-11-14 18:11 21,504 a——- c:\windows\system32\hidserv.dll 2010-11-14 18:11 60,032 a——- c:\windows\system32\drivers\usbaudio.sys 2010-11-14 18:08 32,128 a——- c:\windows\system32\drivers\usbccgp.sys 2010-11-14 18:07 81,920 a—-r– c:\windows\system32\equcof.dll 2010-11-14 18:07 45,056 a—-r– c:\windows\system32\uacb.dll 2010-11-14 18:07 21,276 a—-r– c:\windows\system32\drivers\uacflt.sys 2010-11-14 18:07 36,864 a——- c:\windows\system32\PersCtrl.cpl 2010-11-14 18:07 –d—– c:\program files\PerSono 2010-11-14 17:51 54,760 a——- c:\windows\system32\BMXStateBkp-{00000005-00000000-00000009-00001102-00000005-00291102}.rfx 2010-11-14 17:51 54,760 a——- c:\windows\system32\BMXState-{00000005-00000000-00000009-00001102-00000005-00291102}.rfx 2010-11-14 17:51 788 a——- c:\windows\system32\DVCState-{00000005-00000000-00000009-00001102-00000005-00291102}.rfx 2010-11-14 17:49 445,016 a——- c:\windows\system32\wrap_oal.dll 2010-11-14 17:49 109,144 a——- c:\windows\system32\OpenAL32.dll 2010-11-14 17:49 –d—– c:\program files\OpenAL 2010-11-14 17:49 146,048 a——- c:\windows\system32\drivers\portcls.sys 2010-11-14 17:49 129,536 a——- c:\windows\system32\ksproxy.ax 2010-11-14 17:49 60,160 a——- c:\windows\system32\drivers\drmk.sys 2010-11-14 17:49 4,096 a——- c:\windows\system32\ksuser.dll 2010-11-14 17:49 –d—– c:\windows\system32\Data 2010-11-14 17:49 –d—– c:\program files\common files\Creative Labs Shared 2010-11-14 17:48 –d—– c:\program files\Creative 2010-11-14 17:17 –d—– c:\windows\pss 2010-11-14 17:13 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2010-11-14 17:13 16,400 a——- c:\windows\system32\drivers\LNonPnP.sys 2010-11-14 17:13 16,928 ——– c:\windows\system32\spmsgXP_2k3.dll 2010-11-14 17:12 10,448 a——- c:\windows\system32\drivers\LBeepKE.sys 2010-11-14 17:12 –d—– c:\docume~1\clayp\applic~1\Logishrd 2010-11-14 10:25 –d—– c:\program files\common files\Innovative Solutions 2010-11-14 10:25 47,984 a——- c:\windows\system32\AdvUninstCPL.cpl 2010-11-14 10:25 –d—– c:\docume~1\alluse~1\applic~1\Innovative Solutions 2010-11-14 10:25 –d—– c:\program files\Innovative Solutions 2010-11-13 20:03 13,646 a——- c:\windows\system32\wpa.bak 2010-11-13 19:56 26,144 a——- c:\windows\system32\spupdsvc.exe 2010-11-13 19:56 135,168 a——- c:\windows\system32\directx.cpl 2010-11-13 19:56 266,360 a——- c:\windows\system32\TweakUI.exe 2010-11-13 19:56 –d—– c:\windows\RegisteredPackages 2010-11-13 19:41 –d—– c:\docume~1\clayp\applic~1\IsolatedStorage 2010-11-13 19:39 –d—– c:\docume~1\alluse~1\applic~1\PowerQuest 2010-11-13 19:37 –d—– c:\program files\PowerQuest 2010-11-13 19:37 –d—– c:\windows\system32\URTTemp 2010-11-13 17:40 9,623,680 ac—— c:\windows\system32\dllcache\nv4_mini.sys 2010-11-13 17:40 6,359,552 ac—— c:\windows\system32\dllcache\nv4_disp.dll 2010-11-13 17:40 9,623,680 a——- c:\windows\system32\drivers\nv4_mini.sys 2010-11-13 17:40 6,359,552 a——- c:\windows\system32\nv4_disp.dll 2010-11-13 17:40 –d—– c:\program files\NVIDIA Corporation 2010-11-13 17:39 664 a——- c:\windows\system32\d3d9caps.dat 2010-11-13 17:24 –d-h— c:\windows\msdownld.tmp 2010-11-13 17:24 –d—– c:\windows\Logs 2010-11-13 16:32 –d—– c:\windows\system32\ReinstallBackups 2010-11-13 16:31 200,216 a——- c:\windows\system32\bfLLR.dll 2010-11-13 16:31 112,640 a——- c:\windows\system32\instLLR.exe 2010-11-13 16:31 107,680 a——- c:\windows\system32\drivers\NetB834x.sys 2010-11-13 16:31 22,048 a——- c:\windows\system32\drivers\NetBEdge.sys 2010-11-13 16:31 –d—– c:\program files\Bigfoot Networks 2010-11-13 16:28 –d—– c:\documents and settings\clayp 2010-11-13 16:28 –ds—- c:\windows\system32\Microsoft 2010-11-13 16:26 76,288 ac—— c:\windows\system32\dllcache\uniime.dll 2010-11-13 16:25 57,856 ac—— c:\windows\system32\dllcache\esuimgd.dll 2010-11-13 16:24 –dsh— c:\documents and settings\all users\DRM 2010-11-13 16:24 488 a—hr– c:\windows\system32\WindowsLogon.manifest 2010-11-13 16:24 488 a—hr– c:\windows\system32\logonui.exe.manifest 2010-11-13 16:24 –ds—- c:\windows\Downloaded Program Files 2010-11-13 16:24 –d–r– c:\windows\Offline Web Pages 2010-11-13 16:24 749 a—hr– c:\windows\WindowsShell.Manifest 2010-11-13 16:24 749 a—hr– c:\windows\system32\wuaucpl.cpl.manifest 2010-11-13 16:24 749 a—hr– c:\windows\system32\sapi.cpl.manifest 2010-11-13 16:24 749 a—hr– c:\windows\system32\nwc.cpl.manifest 2010-11-13 16:24 749 a—hr– c:\windows\system32\ncpa.cpl.manifest 2010-11-13 16:24 749 a—hr– c:\windows\system32\cdplayer.exe.manifest 2010-11-13 16:24 –d-h— c:\program files\WindowsUpdate 2010-11-13 16:24 4,399,505 ac—— c:\windows\system32\dllcache\nls302en.lex 2010-11-13 16:22 –d—– c:\program files\common files\MSSoap 2010-11-13 16:21 –d—– c:\program files\Online Services 2010-11-13 16:21 –d—– c:\program files\Messenger 2010-11-13 16:21 –d—– c:\program files\MSN Gaming Zone 2010-11-13 16:19 –d—– c:\program files\Windows NT 2010-11-13 02:13 –d—– c:\program files\common files\ODBC 2010-11-13 02:13 –d—– c:\program files\common files\SpeechEngines 2010-11-13 02:12 –d–r– c:\documents and settings\all users\Documents ==================== Find3M ==================== 2010-11-29 14:56 240,816 a——- c:\windows\system32\nvdrsdb1.bin 2010-11-29 14:55 240,816 a——- c:\windows\system32\nvdrsdb0.bin 2010-11-13 20:01 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2010-11-13 16:21 21,640 a——- c:\windows\system32\emptyregdb.dat 2010-10-16 12:04 81,920 a——- c:\windows\system32\nvwddi.dll 2010-10-16 12:04 13,851,752 a——- c:\windows\system32\nvcpl.dll 2010-10-16 12:04 277,608 a——- c:\windows\system32\nvmccs.dll 2010-10-16 12:04 110,696 a——- c:\windows\system32\nvmctray.dll 2010-10-16 12:04 156,776 a——- c:\windows\system32\nvsvc32.exe 2010-10-16 12:04 145,000 a——- c:\windows\system32\nvcolor.exe 2010-10-16 10:55 14,532,608 a——- c:\windows\system32\nvoglnt.dll 2010-10-16 10:55 13,012,992 a——- c:\windows\system32\nvcompiler.dll 2010-10-16 10:55 4,882,432 a——- c:\windows\system32\nvcuda.dll 2010-10-16 10:55 2,932,840 a——- c:\windows\system32\nvcuvid.dll 2010-10-16 10:55 2,666,600 a——- c:\windows\system32\nvcuvenc.dll 2010-10-16 10:55 2,293,194 a——- c:\windows\system32\nvdata.bin 2010-10-16 10:55 1,462,272 a——- c:\windows\system32\nvapi.dll 2010-10-16 10:55 888,424 a——- c:\windows\system32\nvdispco32.dll 2010-10-16 10:55 813,672 a——- c:\windows\system32\nvgenco32.dll 2010-10-16 10:55 61,440 a——- c:\windows\system32\OpenCL.dll ============= FINISH: 17:16:17.62 ===============
Hi clayp,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Looks like you've done a lot of "adjusting" to your system… but I'm not really seeing anything I believe to be malware related.

Let's try this:

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tomk I just happened to think,what tells you I have malware.I check my system at least once a day with "Malwarebytes Pro"…Just asking… :D
It only cleaned up some mess. No malware.

Let's run a couple other tools:

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Please copy and paste the information into the thread… rather than attaching it.

Also please describe how your computer behaves at the moment.

It only cleaned up some mess. No malware.

Let's run a couple other tools:

Download TFC to your desktop

  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Please copy and paste the information into the thread… rather than attaching it.

Also please describe how your computer behaves at the moment.



Link for TFC no good,I already have and use the other program
Malwarebytes' Anti-Malware 1.50 www.malwarebytes.org Database version: 5302 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/12/2010 2:57:11 PM mbam-log-2010-12-12 (14-57-11).txt Scan type: Quick scan Objects scanned: 133866 Time elapsed: 1 minute(s), 12 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
I do not believe you have a malware problem. I suggest that you post in the Windows Forum for help from the techs. They may be able to help you tune things up a bit.

Meanwhile..

Time for some housekeeping
  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK.
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
That screen allows you to get to the recovery console if you should have a systems failure. The screen will close on it's own after a couple of seconds and your system will boot normally.

That screen allows you to get to the recovery console if you should have a systems failure. The screen will close on it's own after a couple of seconds and your system will boot normally.

Yes it does but it is very annoying….
2 seconds is very annoying? To me, two seconds isn't much of a trade off for the security of having the option available if there is a system crash… however… it's your computer. I can help you remove it if you are certain that this is what you wish.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI