This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sluggish Browsing - intermittent issues

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Having sluggish response time when browsing. Also delays when opening programs / files. Here is DDS: Thanks in advance for help. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 16:42:00.92 on Mon 02/14/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2014.1098 [GMT -5:00] AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Norton Internet Security\AddOns\Norton AddOn Pack\Engine\3.8.0.5\ccProxy.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\WINDOWS\Explorer.EXE C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\Chris\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us mDefault_Page_URL = hxxp://www.yahoo.com/ mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage uInternet Settings,ProxyOverride = *.local BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.8.0.41\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.8.0.41\IPSBHO.DLL TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.8.0.41\coIEPlg.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot dRun: [ALUAlert] c:\program files\symantec\liveupdate\ALUNotify.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe Trusted Zone: taxactonline.com\www DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.support.gateway.com/support/profiler/PCPitStop.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - hxxp://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxp://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} - hxxp://merillat.view22.com/release_3_9_177/View22RTEv4.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} - hxxp://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://liasophia.webex.com/client/T26L/nbr/ieatgpc.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.8.0.41\CoIEPlg.dll Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\e4cotmtw.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p= FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll FF - plugin: c:\documents and settings\chris\application data\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\documents and settings\chris\application data\mozilla\firefox\profiles\e4cotmtw.default\extensions\[removed]\plugins\npLogitechDeviceDetection.dll FF - plugin: c:\progra~1\sonyon~1\npsoe.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\musicnotes\npmusicn.dll FF - plugin: c:\program files\musicnotes\NPSibelius.dll FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2007-1-30 3456] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1008000.029\SymEFA.sys [2010-1-27 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1008000.029\BHDrvx86.sys [2010-1-27 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1008000.029\cchpx86.sys [2010-1-27 482432] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20110211.002\IDSXpx86.sys [2011-2-11 341944] R2 ccProxy;Symantec Network Proxy;c:\program files\norton internet security\addons\norton addon pack\engine\3.8.0.5\ccProxy.exe [2010-2-18 186744] R2 Norton Internet Security;Norton Internet Security;c:\program files\norton internet security\engine\16.8.0.41\ccSvcHst.exe [2010-1-27 117640] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-12-25 102448] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20110214.002\NAVENG.SYS [2011-2-14 86008] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20110214.002\NAVEX15.SYS [2011-2-14 1360760] S2 navapsvc;Norton AntiVirus Auto Protect Service;"c:\program files\norton internet security\norton antivirus\navapsvc.exe" –> c:\program files\norton internet security\norton antivirus\navapsvc.exe [?] S3 dsiarhwprog;dsiarhwprog;c:\windows\system32\drivers\dsiarhwprog.sys [2010-12-30 29184] S3 EraserUtilDrvI10;EraserUtilDrvI10;\??\c:\program files\common files\symantec shared\eengine\eraserutildrvi10.sys –> c:\program files\common files\symantec shared\eengine\EraserUtilDrvI10.sys [?] S4 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 169312] S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-24 135664] =============== Created Last 30 ================ 2011-02-13 19:52 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2011-02-13 19:49 –d—– c:\docume~1\chris\applic~1\Malwarebytes 2011-02-13 19:49 20,952 a——- c:\windows\system32\drivers\mbam.sys 2011-02-13 19:49 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2011-02-13 19:49 34,296 a——- c:\windows\system32\drivers\mbamcatchme.sys 2011-02-13 19:49 –d—– c:\program files\Malwarebytes' Anti-Malware 2011-02-10 16:34 –d—– c:\windows\system32\drivers\NSS 2011-02-10 16:34 –d—– c:\program files\Norton Security Scan 2011-01-26 08:02 10,240 a——- c:\documents and settings\chris\fbchathistory.dat 2011-01-21 09:44 439,296 ——– c:\windows\system32\dllcache\shimgvw.dll ==================== Find3M ==================== 2011-01-21 09:44 439,296 a——- c:\windows\system32\shimgvw.dll 2011-01-21 09:44 8,462,336 ——– c:\windows\system32\dllcache\shell32.dll 2011-01-07 09:09 290,048 a——- c:\windows\system32\atmfd.dll 2011-01-07 09:09 290,048 ——– c:\windows\system32\dllcache\atmfd.dll 2010-12-31 08:10 1,854,976 a——- c:\windows\system32\win32k.sys 2010-12-31 08:10 1,854,976 ——– c:\windows\system32\dllcache\win32k.sys 2010-12-22 07:34 301,568 a——- c:\windows\system32\kerberos.dll 2010-12-22 07:34 301,568 ——– c:\windows\system32\dllcache\kerberos.dll 2010-12-21 05:29 11,080,704 ——– c:\windows\system32\dllcache\ieframe.dll 2010-12-20 12:26 730,112 a——- c:\windows\system32\lsasrv.dll 2010-12-20 12:26 730,112 ——– c:\windows\system32\dllcache\lsasrv.dll 2010-12-20 07:55 173,568 ——– c:\windows\system32\dllcache\ie4uinit.exe 2010-12-09 10:15 718,336 a——- c:\windows\system32\ntdll.dll 2010-12-09 10:15 718,336 ——– c:\windows\system32\dllcache\ntdll.dll 2010-12-09 09:30 33,280 a——- c:\windows\system32\csrsrv.dll 2010-12-09 09:30 33,280 ——– c:\windows\system32\dllcache\csrsrv.dll 2010-12-09 08:42 2,148,864 a——- c:\windows\system32\ntoskrnl.exe 2010-12-09 08:42 2,148,864 ——– c:\windows\system32\dllcache\ntkrnlmp.exe 2010-12-09 08:38 2,192,768 ——– c:\windows\system32\dllcache\ntoskrnl.exe 2010-12-09 08:07 2,027,008 a——- c:\windows\system32\ntkrnlpa.exe 2010-12-09 08:07 2,027,008 ——– c:\windows\system32\dllcache\ntkrpamp.exe 2010-12-09 08:07 2,069,376 ——– c:\windows\system32\dllcache\ntkrnlpa.exe 2010-12-01 20:54 27,024,112 a——- C:\PowerPointViewer.exe 2010-11-18 13:12 81,920 a——- c:\windows\system32\isign32.dll 2010-11-18 13:12 81,920 ——– c:\windows\system32\dllcache\isign32.dll 2008-10-04 07:39 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100420081005\index.dat ============= FINISH: 16:42:55.85 ===============

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, anirishfool1

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

—————————————————————————————————

It appears you didn't attach the second dds log, Attach.txt, to your initial post.

Go to Start > Run and copy/paste the following into the Run box and click OK:

%temp%\Attach.txt

A text file should open. Please attach that file to your next reply.

—————————————————————————————————

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
DDS Attach log
GMER log
Security check log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Ok. Sorry for my failure to follow directions. And thanks for the prompt response.

Here are the requested logs:

Attach:


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 2/1/2007 3:10:48 PM
System Uptime: 2/13/2011 8:11:35 PM (20 hours ago)

Motherboard: Dell Inc. | | 0MH651
Processor: Intel® Pentium® 4 CPU 3.00GHz | Microprocessor | 3000/800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 80.08 GiB free.
D: is CDROM ()
E: is FIXED (FAT32) - 931 GiB total, 644.597 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1106: 11/16/2010 7:13:12 PM - System Checkpoint
RP1107: 11/18/2010 12:37:55 AM - System Checkpoint
RP1108: 11/19/2010 7:57:34 AM - System Checkpoint
RP1109: 11/20/2010 11:20:49 AM - System Checkpoint
RP1110: 11/21/2010 4:46:19 PM - System Checkpoint
RP1111: 11/23/2010 6:04:59 PM - System Checkpoint
RP1112: 11/24/2010 9:03:06 PM - System Checkpoint
RP1113: 11/27/2010 8:23:50 PM - System Checkpoint
RP1114: 11/29/2010 12:39:58 AM - System Checkpoint
RP1115: 11/30/2010 8:50:35 AM - System Checkpoint
RP1116: 12/1/2010 9:24:13 PM - System Checkpoint
RP1117: 12/3/2010 4:39:57 AM - System Checkpoint
RP1118: 12/4/2010 12:06:44 PM - System Checkpoint
RP1119: 12/5/2010 4:40:06 PM - System Checkpoint
RP1120: 12/7/2010 4:57:32 PM - System Checkpoint
RP1121: 12/8/2010 5:38:01 PM - System Checkpoint
RP1122: 12/9/2010 8:02:55 PM - System Checkpoint
RP1123: 12/11/2010 7:00:58 AM - System Checkpoint
RP1124: 12/12/2010 7:24:56 AM - System Checkpoint
RP1125: 12/13/2010 4:02:52 PM - System Checkpoint
RP1126: 12/15/2010 7:28:05 AM - Software Distribution Service 3.0
RP1127: 12/16/2010 8:03:21 AM - System Checkpoint
RP1128: 12/17/2010 5:23:10 PM - System Checkpoint
RP1129: 12/19/2010 8:19:42 PM - System Checkpoint
RP1130: 12/21/2010 9:59:35 AM - System Checkpoint
RP1131: 12/23/2010 8:54:50 AM - System Checkpoint
RP1132: 12/24/2010 11:08:39 AM - System Checkpoint
RP1133: 12/25/2010 11:28:37 AM - System Checkpoint
RP1134: 12/26/2010 10:06:07 PM - System Checkpoint
RP1135: 12/28/2010 1:18:09 PM - System Checkpoint
RP1136: 12/29/2010 5:32:48 PM - System Checkpoint
RP1137: 12/30/2010 8:18:10 PM - Installed MSXML 4.0 SP2 Parser and SDK
RP1138: 12/30/2010 8:25:46 PM - Unsigned driver install
RP1139: 12/31/2010 10:01:04 PM - System Checkpoint
RP1140: 1/2/2011 4:01:12 AM - System Checkpoint
RP1141: 1/3/2011 1:37:57 PM - System Checkpoint
RP1142: 1/4/2011 2:12:52 PM - System Checkpoint
RP1143: 1/5/2011 5:30:27 PM - System Checkpoint
RP1144: 1/6/2011 3:00:25 AM - Software Distribution Service 3.0
RP1145: 1/7/2011 9:30:26 AM - System Checkpoint
RP1146: 1/8/2011 12:06:27 PM - System Checkpoint
RP1147: 1/9/2011 5:29:55 PM - System Checkpoint
RP1148: 1/11/2011 3:29:52 AM - System Checkpoint
RP1149: 1/12/2011 3:00:26 AM - Software Distribution Service 3.0
RP1150: 1/13/2011 3:25:17 AM - System Checkpoint
RP1151: 1/14/2011 8:58:11 AM - System Checkpoint
RP1152: 1/16/2011 10:31:31 PM - System Checkpoint
RP1153: 1/17/2011 11:54:39 PM - System Checkpoint
RP1154: 1/19/2011 12:43:46 AM - System Checkpoint
RP1155: 1/20/2011 1:07:46 AM - System Checkpoint
RP1156: 1/21/2011 1:31:45 AM - System Checkpoint
RP1157: 1/22/2011 1:39:25 AM - System Checkpoint
RP1158: 1/23/2011 9:13:56 AM - System Checkpoint
RP1159: 1/24/2011 4:31:03 PM - System Checkpoint
RP1160: 1/25/2011 4:39:06 PM - System Checkpoint
RP1161: 1/26/2011 4:58:53 PM - System Checkpoint
RP1162: 1/27/2011 5:39:14 PM - System Checkpoint
RP1163: 1/28/2011 7:10:43 PM - System Checkpoint
RP1164: 1/29/2011 7:52:11 PM - System Checkpoint
RP1165: 1/30/2011 8:04:39 PM - System Checkpoint
RP1166: 2/1/2011 6:51:29 AM - System Checkpoint
RP1167: 2/2/2011 12:41:37 PM - System Checkpoint
RP1168: 2/4/2011 8:00:24 AM - System Checkpoint
RP1169: 2/5/2011 5:14:45 PM - System Checkpoint
RP1170: 2/7/2011 10:29:14 AM - System Checkpoint
RP1171: 2/8/2011 3:09:20 PM - System Checkpoint
RP1172: 2/9/2011 8:58:11 AM - Software Distribution Service 3.0
RP1173: 2/10/2011 7:22:17 PM - System Checkpoint
RP1174: 2/12/2011 5:04:09 AM - System Checkpoint
RP1175: 2/13/2011 4:35:21 PM - System Checkpoint
RP1176: 2/13/2011 7:11:26 PM - Removed PhotoImpression
RP1177: 2/13/2011 7:14:18 PM - Removed Network Magic

==== Installed Programs ======================

1ClickImageExtractor
ABBYY PDF Transformer 1.0
Action Replay DSi Code Manager
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe PhotoDeluxe Home Edition 4.0
Adobe Photoshop Album 2.0 Starter Edition
Adobe Photoshop Elements 7.0
Adobe Photoshop.com Inspiration Browser
Adobe Premiere Elements 7.0
Adobe Premiere Elements 7.0 Templates
Adobe Reader 8.2.5
Adobe Shockwave Player 11.5
Age of Mythology
AiO_Scan
AIOMinimal
AiOSoftware
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft MediaConverter
ATI Catalyst Control Center
ATI Display Driver
Avery Easy Peel Label Sorter
Bing Maps 3D
Bonjour
Broadcom Management Programs
CCScore
CDDRV_Installer
Compatibility Pack for the 2007 Office system
Copy
CreativeProjects
Critical Update for Windows Media Player 11 (KB959772)
Director
DocProc
doPDF 7.1 printer
DV TS
erLT
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
Facebook Plug-In
Fax
FloorPlan 3D v6
Free Realms Installer
Garmin City Navigator North America NT 2009.11 Update
Garmin Communicator Plugin
Garmin USB Drivers
Garmin WebUpdater
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
GPL Ghostscript 8.64
High Definition Audio Driver Package - KB835221
HijackThis 1.99.1
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Image Zone 3.5
HP PSC & OfficeJet 3.5
HP Software Update
hpmdtab
HPSystemDiagnostics
InstantShare
IrfanView (remove only)
iTunes
Java Auto Updater
Java™ 6 Update 21
Java™ 6 Update 6
Java™ 6 Update 7
kgcbase
KhalInstallWrapper
Kodak EasyShare software
Korean Fonts Support For Adobe Reader 8
LEGO Digital Designer
Let's Ride Friends Forever
LiveUpdate (Symantec Corporation)
Logitech SetPoint
Logitech Updater
Malwarebytes' Anti-Malware
Memories Disc Creator 2.0
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Basic Edition 2003
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office XP Professional with FrontPage
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.6.13)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser
MSXML4 Parser
Musicnotes Software Suite 1.2
muvee autoProducer 4.1
Nero Suite
netbrdg
Norton AddOn Pack
Norton Internet Security
Norton Security Scan
Norton WMI Update
OfotoXMI
OpenOffice.org 3.0
overland
PhotoGallery
PhotoshopdotcomInspirationBrowser
PowerDVD 5.7
PrintScreen
Process Viewer
QFolder
QuickProjects
QuickTime
Readme
RealPlayer
Roller Coaster Factory 2
Scan
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
SFR
SHASTA
skin0001
SkinsHP1
SkinsHP2
SKINXSDK
SmartSound Quicktracks for Premiere Elements
SpywareBlaster 4.1
staticcr
Symantec Technical Support Web Controls
tooltips
TrayApp
Uniblue RegistryBooster 2
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Virtools 3D Life Player
VoiceOver Kit
VPRINTOL
WebFldrs XP
WebReg
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinPatrol 2008
WinRAR archiver
WinZip 12.0
WIRELESS

==== Event Viewer Messages From Past Week ========

2/8/2011 7:40:19 PM, error: Service Control Manager [7000] - The Norton AntiVirus Auto Protect Service service failed to start due to the following error: The system cannot find the path specified.
2/8/2011 12:38:15 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/8/2011 12:36:37 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BHDrvx86 ccHP eeCtrl Fips IDSxpx86 intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SRTSPX SYMTDI Tcpip
2/8/2011 12:36:37 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
2/8/2011 12:36:37 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/8/2011 12:36:37 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/8/2011 12:36:37 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/8/2011 12:36:37 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/8/2011 12:36:37 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

==== End Of File ===========================













Security Check:



Results of screen317's Security Check version 0.99.7
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Norton Internet Security
```````````````````````````````
Anti-malware/Other Utilities Check:

WinPatrol 2008 (Outdated! Latest version is WinPatrol 2009)
Out of date HijackThis installed!
Malwarebytes' Anti-Malware
HijackThis 1.99.1
Hijackthis 1.99.1
Java™ 6 Update 21
Java™ 6 Update 6
Java™ 6 Update 7
Out of date Java installed!
Adobe Flash Player 10.1.102.64
Adobe Reader 8.2.5
Korean Fonts Support For Adobe Reader 8
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.13)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Norton ccSvcHst.exe
WinPatrol winpatrol.exe
system32 WinPatrol.exe -?-
BillP Studios WinPatrol winpatrol.exe
``````````End of Log````````````








GMER:

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-17 07:46:05
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 ST3160812AS rev.3.ADJ
Running: wv67f4kt.exe; Driver: C:\DOCUME~1\Chris\LOCALS~1\Temp\uwlyapod.sys


—- System - GMER 1.0.15 —-

SSDT 8A5073F8 ZwAlertResumeThread
SSDT 8A4BF1B0 ZwAlertThread
SSDT 8A504518 ZwAllocateVirtualMemory
SSDT 8A4DFCC8 ZwAssignProcessToJobObject
SSDT 8A473728 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB6ED1130]
SSDT 899B5358 ZwCreateMutant
SSDT 8A478DA8 ZwCreateSymbolicLinkObject
SSDT 8A11F2F0 ZwCreateThread
SSDT 8A519CC0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB6ED13B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB6ED1910]
SSDT 8A479DB0 ZwDuplicateObject
SSDT 8A5E2BA0 ZwFreeVirtualMemory
SSDT 8A0290B8 ZwImpersonateAnonymousToken
SSDT 8A074528 ZwImpersonateThread
SSDT 8A2DD8B0 ZwLoadDriver
SSDT 8A0FCA70 ZwMapViewOfSection
SSDT 8A49CEC8 ZwOpenEvent
SSDT 89FCD8C0 ZwOpenProcess
SSDT 8A49DC98 ZwOpenProcessToken
SSDT 8A2EEC50 ZwOpenSection
SSDT 8A479F40 ZwOpenThread
SSDT 8A117D40 ZwProtectVirtualMemory
SSDT 8A508E70 ZwResumeThread
SSDT 8A5FAF48 ZwSetContextThread
SSDT 8A0DEDB8 ZwSetInformationProcess
SSDT 899D6778 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB6ED1B60]
SSDT 8A0E30B8 ZwSuspendProcess
SSDT 8A4BA570 ZwSuspendThread
SSDT 8A4DD798 ZwTerminateProcess
SSDT 8A12F890 ZwTerminateThread
SSDT 8A6F8B90 ZwUnmapViewOfSection
SSDT 8A5E3C08 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

? rkwxyr.sys The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xB7746A00]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\firefox.exe[4004] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 02D2003A

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
I don't see any signs of malware that impacts the PC's performance. Let's do another check up.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

===================================================

Re-run Malwarebytes' Anti-Malware
  • Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
    • Go to Update tab to update Malwarebytes' Anti-Malware
  • Then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • Look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

On your next reply please post :
MBAM log
ESET report


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
yes I will follow instructions soon. sorry for the wait. thanks for your patience. btw would it matter if one user is experiencing the sluggishness more than others?
If it's ridiculously sluggish then yes. But sometimes it can be a non malware related case that cause the sluggishness. If you have any other problems that you wish to describe, please do as I need more information to understand further what you are experiencing now.
I tried to update MBAM, but got this message in the attached jpg. I did the scan anyway: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5363 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/22/2011 4:52:28 PM mbam-log-2011-02-22 (16-52-28).txt Scan type: Quick scan Objects scanned: 226917 Time elapsed: 11 minute(s), 2 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Then I did the ESET (the Dell Laptop files are backed up on my external drive. I guess I should have excluded them - now I need to check the laptop!!!) ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=468f22a8538ec84386f822f4abae3171 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-02-23 05:42:54 # local_time=2011-02-23 12:42:54 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=3588 16777189 100 96 5204531 46565001 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=165995 # found=8 # cleaned=0 # scan_time=27090 C:\RECYCLER\S-1-5-21-1755230115-917001253-2734630794-1011\Dc19.exe a variant of Win32/Adware.Gamevance.AK application (unable to clean) 00000000000000000000000000000000 I E:\Dell Laptop Backup\DELLLAPTOP\Backup Set 2010-08-15 190008\Backup Files 2010-09-26 225423\Backup files 1.zip Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I E:\Dell Laptop Backup\DELLLAPTOP\Backup Set 2010-08-15 190008\Backup Files 2010-12-05 190009\Backup files 1.zip Java/TrojanDownloader.Agent.NCA trojan (unable to clean) 00000000000000000000000000000000 I E:\Dell Laptop Backup\DELLLAPTOP\Backup Set 2010-12-19 190009\Backup Files 2010-12-19 190009\Backup files 2.zip Java/TrojanDownloader.Agent.NCA trojan (unable to clean) 00000000000000000000000000000000 I E:\Dell Laptop Backup\DELLLAPTOP\Backup Set 2010-12-19 190009\Backup Files 2010-12-19 190009\Backup files 3.zip Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I E:\Dell Laptop Backup\DELLLAPTOP\Backup Set 2010-12-26 211334\Backup Files 2010-12-26 211334\Backup files 4.zip Java/TrojanDownloader.Agent.NCA trojan (unable to clean) 00000000000000000000000000000000 I E:\Dell Laptop Backup\DELLLAPTOP\Backup Set 2010-12-26 211334\Backup Files 2010-12-26 211334\Backup files 5.zip Win32/Adware.Toolbar.Dealio application (unable to clean) 00000000000000000000000000000000 I E:\Dell Laptop Backup\DELLLAPTOP\Backup Set 2010-12-26 211334\Backup Files 2011-01-02 205529\Backup files 1.zip multiple threats (unable to clean) 00000000000000000000000000000000 I Thanks again for your patience and responses

Attachments:

Apparently ESET also scanned my external hard drive, where I back up my laptop. Anything that is from E: is from a different machine that the orignal on this thread. Sorry for the confusion.
You want me to check on another computer right? I need you to open up another thread saying that I will take over it and the next morning I will respond to you. Meanwhile, please post OTL and GMER for that different machine. I'm going to close this one up to avoid confusion. Thank you
No, I have not requested the other machine checked. I was just explaining that several of the threats identified by ESET were from a backup file stored on an external drive, and were NOT from the machine in question in the original post.. I was trying not to confuse you about the location of the threats. I think the top threat on that list is from the original machine. If I decide to do a request for the laptop, I'll start a new thread. Sorry about the confusion. Does the original machine appear to be clear? Still sluggish when my wife is on the internet.
Your logs are clear, and I'm not entirely sure what you mean when you said it's sluggish browsing. Does it take up forever to load a webpage?
When she clicks on a link, it takes several seconds for the page to change. It is clear that the browser has responded - the "Loading" circle on firefox will start to go around. But sometimes there is no further action for several seconds. Eventually the screen goes to where she was intending, but it's enough that she has to walk away from this machine at times.
I need you to make a batch file.

Open a new Notepad session

  • Click the Start button, click Run
  • In the run box type notepad
  • Click OK
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
@Echo on
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0

In the notepad

Click File, Save as…, and set the Save in to your Desktop
In the filename box, type (including quotation marks) as the filename: "flush.bat"
Click Save


You should now have a file on your desktop with an icon like this [external image: Posted Image]

Double click on flush.bat & allow it to run. A small black screen may briefly flash on and off, that normal.

Tell me how is it running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI