This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slower and slower.

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First off, I'm aware that any pc will get slower when time goes by.
That being said I'd like to say thank you very much for helping me with my computer.
I bought it about 6 months ago and everything has been running smooth, lately it has gotten slower though. I'm a gamer so FPS drop is something I recognize.
Programs (especially explorer and opera) tends to be very slow at startup, not particulary slow, just a huge spike often when I open them.
When I do a virus search it finds

I don't know if this is on topic or not, but very often when I turn on Opera and Counter Strike Source they won't load. They're on @ processes though, so I have to turn them off and on again (opera usually works at second try, css does absolutely not)

Here goes the HijackLog

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:55:21, on 31.03.2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe
D:\Programs\iTunes\iTunesHelper.exe
D:\Programs\Skype\Phone\Skype.exe
D:\Programs\HijackThis\Trend Micro\HiJackThis\HiJackThis.exe
D:\Programs\Opera\opera.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Programs\Java\bin\jp2ssv.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\IEToolbar.dll
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Programs\Adobe Reader\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: BitDefender Update Server v2 (Update Server) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: BitDefender Desktop Update Service (Updatesrv) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 6993 bytes
:welcome:

Hijackthis is not used much anymore, doesn't show the whole picture most times , we have moved on to other scanners.

Lets do a few things.

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility





Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Hey there and thanks for replying. Did not find anything with the malwarebytes but i'll attach it anyhow. I don't know if its supposed to be like this or not, the sentences seem to end before they're done as you can see.. So i've attached the dds.txt also.. And thanks again for any help =) DDS.txt : DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 15:55:31,26 on 02.04.2011 Internet Explorer: 8.0.7601.17514 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.47.1033.18.4095.2637 [GMT 2:00] . AV: BitDefender Antivirus *Enabled/Updated* {50909708-FF80-02AF- F814-B28405891E92} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44- DA132C1ACF46} SP: BitDefender Antispyware *Enabled/Updated* {EBF176EC-D9BA- 0D21-C2A4-89F67E0E542F} FW: BitDefender Firewall *Enabled* {68AB162D-B5EF-03F7-D34B- 1BB1FB5A59E9} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support \AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live \WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live \WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskhost.exe C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch64.exe C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static \MOM.exe D:\Programs\iTunes\iTunesHelper.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static \CCC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet D:\Programs\Opera\opera.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\DllHost.exe D:\Programs\Skype\Phone\Skype.exe C:\Windows\system32\msiexec.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files\BitDefender\BitDefender 2011\downloader.exe C:\Windows\system32\conhost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe D:\Install\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank mStart Page = about:blank uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596- fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe \Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc- 5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74- 9c25c1c588a9} - D:\Programs\Java\bin\jp2ssv.dll TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\IEToolbar.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun mRun: [BitDefender Antiphishing Helper] "C:\Program Files \BitDefender\BitDefender 2011\Antispam32\ieshow.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files \Java\Java Update\jusched.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies \ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [Adobe Reader Speed Launcher] "D:\Programs\Adobe Reader \Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM \1.0\AdobeARM.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime \QTTask.exe" -atboottime mRun: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe" mRunOnce: [Malwarebytes' Anti-Malware] D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows- i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows- i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows- i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C: \Program Files (x86)\Windows Live\Photo Gallery \AlbumDownloadProtocolHandler.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF- 8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll TB-X64: BitDefender Toolbar: {381FFDE8-2394-4F90-B10D- FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\IEToolbar.dll mRun-x64: [BitDefender Antiphishing Helper] "C:\Program Files \BitDefender\BitDefender 2011\ieshow.exe" mRun-x64: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe" . ============= SERVICES / DRIVERS =============== . R1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfndisf6.sys [2010-6-18 88144] R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\BitDefender \BitDefender Firewall\bdfwfpf.sys [2010-11-2 99408] R2 AMD External Events Utility;AMD External Events Utility;C: \Windows\System32\atiesrxx.exe [2010-9-29 203776] R2 Updatesrv;BitDefender Desktop Update Service;C:\Program Files \BitDefender\BitDefender 2011\updatesrv.exe [2011-4-1 53224] R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-10-27 8012288] R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-10-27 287232] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C: \Windows\System32\drivers\AtihdW76.sys [2010-7-15 116240] R3 BDFM;BDFM;C:\Windows\System32\drivers\bdfm.sys [2010-5-13 162896] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers \Rt64win7.sys [2010-6-23 344680] R3 SAlphamHid;SteelHIDSvc;C:\Windows\System32\drivers \SAlpham64.sys [2010-9-8 35200] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework \v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET \Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 Lycosa;Lycosa Keyboard;C:\Windows\System32\drivers\Lycosa.sys [2008-1-17 18816] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C: \Windows\System32\drivers\rdpvideominiport.sys [2011-2-26 20992] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-2-26 59392] S3 Update Server;BitDefender Update Server v2;C:\Program Files \Common Files\BitDefender\BitDefender Arrakis Server\bin \arrakis3.exe [2010-11-2 467248] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers \usbaapl64.sys [2010-12-14 51712] S4 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2010-6-28 692816] S4 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2010-6-28 1040976] . =============== Created Last 30 ================ . 2011-04-02 13:51:06 ——– d—–w- C:\Users \MANGOC~1\AppData\Roaming\Malwarebytes 2011-04-02 13:50:49 38224 —-a-w- C:\Windows \SysWow64\drivers\mbamswissarmy.sys 2011-04-02 13:50:48 ——– d—–w- C: \PROGRA~3\Malwarebytes 2011-04-02 13:50:46 24152 —-a-w- C:\Windows \System32\drivers\mbam.sys 2011-04-01 13:02:35 431176 —-a-w- C:\Windows \System32\drivers\bdfsfltr.sys 2011-04-01 13:02:30 101968 —-a-w- C:\Windows \System32\drivers\bdhv.sys 2011-03-27 02:43:47 ——– d—–w- C:\Users \MANGOC~1\AppData\Roaming\WinFF 2011-03-27 02:39:52 ——– d—–w- C: \PROGRA~3\DivX 2011-03-26 23:11:56 8424784 —-a-w- C: \PROGRA~3\Microsoft\Windows Defender\Definition Updates \{4F318B03-FE96-4C61-B999-2985B170AFF5}\mpengine.dll 2011-03-19 15:52:54 ——– d—–w- C:\Users \MANGOC~1\AppData\Local\Bitforge 2011-03-19 15:34:31 545 —-a-w- C:\Windows\UC.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows \RAR.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows \PKZIP.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows \PKUNZIP.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows \NOCLOSE.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows \LHA.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows \ARJ.PIF 2011-03-19 15:34:31 ——– d—–w- C:\Users \MANGOC~1\AppData\Roaming\GHISLER 2011-03-06 17:05:32 ——– d—–w- C:\Users \MANGOC~1\AppData\Roaming\TS3Client . ==================== Find3M ==================== . 2011-02-26 11:58:42 175616 —-a-w- C:\Windows \System32\msclmd.dll 2011-02-26 11:58:42 152576 —-a-w- C:\Windows \SysWow64\msclmd.dll 2011-02-19 12:05:15 1139200 —-a-w- C:\Windows \System32\FntCache.dll 2011-02-19 12:04:37 1544192 —-a-w- C:\Windows \System32\DWrite.dll 2011-02-19 12:04:17 902656 —-a-w- C:\Windows \System32\d2d1.dll 2011-02-19 06:30:51 1076736 —-a-w- C:\Windows \SysWow64\DWrite.dll 2011-02-19 06:30:50 739840 —-a-w- C:\Windows \SysWow64\d2d1.dll 2011-02-02 17:11:20 270720 ——w- C:\Windows \System32\MpSigStub.exe 2011-01-17 11:09:14 197120 —-a-w- C:\Windows \System32\d3d10_1.dll 2011-01-17 05:47:13 161792 —-a-w- C:\Windows \SysWow64\d3d10_1.dll 2011-01-07 12:17:52 475648 —-a-w- C:\Windows \System32\XpsGdiConverter.dll 2011-01-07 12:17:52 1465344 —-a-w- C:\Windows \System32\XpsPrint.dll 2011-01-07 12:14:11 46080 —-a-w- C:\Windows \System32\atmlib.dll 2011-01-07 09:51:01 1638912 —-a-w- C:\Windows \System32\mshtml.tlb 2011-01-07 09:20:44 366592 —-a-w- C:\Windows \System32\atmfd.dll 2011-01-07 07:46:34 870912 —-a-w- C:\Windows \SysWow64\XpsPrint.dll 2011-01-07 07:46:34 288256 —-a-w- C:\Windows \SysWow64\XpsGdiConverter.dll 2011-01-07 07:45:57 34304 —-a-w- C:\Windows \SysWow64\atmlib.dll 2011-01-07 06:01:22 1638912 —-a-w- C:\Windows \SysWow64\mshtml.tlb 2011-01-07 05:43:36 294400 —-a-w- C:\Windows \SysWow64\atmfd.dll 2011-01-05 10:34:00 612864 —-a-w- C:\Windows \System32\vbscript.dll 2011-01-05 06:56:24 3129344 —-a-w- C:\Windows \System32\win32k.sys 2011-01-05 05:55:55 428032 —-a-w- C:\Windows \SysWow64\vbscript.dll 2010-07-08 08:37:14 101544 —-a-w- C:\Program Files \Common Files\LinkInstaller.exe . ============= FINISH: 15:57:32,91 ===============
. DDS (Ver_11-03-05.01) - NTFS_AMD64 Run by [removed] at 15:55:31,26 on 02.04.2011 Internet Explorer: 8.0.7601.17514 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.47.1033.18.4095.2637 [GMT 2:00] . AV: BitDefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: BitDefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F} FW: BitDefender Firewall *Enabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files (x86)\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskhost.exe C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch64.exe C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe D:\Programs\iTunes\iTunesHelper.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet D:\Programs\Opera\opera.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\DllHost.exe D:\Programs\Skype\Phone\Skype.exe C:\Windows\system32\msiexec.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files\BitDefender\BitDefender 2011\downloader.exe C:\Windows\system32\conhost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe D:\Install\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank mStart Page = about:blank uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - D:\Programs\Java\bin\jp2ssv.dll TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\IEToolbar.dll uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun mRun: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe" mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [Adobe Reader Speed Launcher] "D:\Programs\Adobe Reader\Reader\Reader_sl.exe" mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe" mRunOnce: [Malwarebytes' Anti-Malware] D:\Programs\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll TB-X64: BitDefender Toolbar: {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\IEToolbar.dll mRun-x64: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe" mRun-x64: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe" . ============= SERVICES / DRIVERS =============== . R1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfndisf6.sys [2010-6-18 88144] R1 bdfwfpf;bdfwfpf;C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2010-11-2 99408] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2010-9-29 203776] R2 Updatesrv;BitDefender Desktop Update Service;C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe [2011-4-1 53224] R3 amdkmdag;amdkmdag;C:\Windows\System32\drivers\atikmdag.sys [2010-10-27 8012288] R3 amdkmdap;amdkmdap;C:\Windows\System32\drivers\atikmpag.sys [2010-10-27 287232] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2010-7-15 116240] R3 BDFM;BDFM;C:\Windows\System32\drivers\bdfm.sys [2010-5-13 162896] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2010-6-23 344680] R3 SAlphamHid;SteelHIDSvc;C:\Windows\System32\drivers\SAlpham64.sys [2010-9-8 35200] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S3 Lycosa;Lycosa Keyboard;C:\Windows\System32\drivers\Lycosa.sys [2008-1-17 18816] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2011-2-26 20992] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-2-26 59392] S3 Update Server;BitDefender Update Server v2;C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2010-11-2 467248] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-12-14 51712] S4 avc3;avc3;C:\Windows\System32\drivers\avc3.sys [2010-6-28 692816] S4 avckf;avckf;C:\Windows\System32\drivers\avckf.sys [2010-6-28 1040976] . =============== Created Last 30 ================ . 2011-04-02 13:51:06 ——– d—–w- C:\Users\MANGOC~1\AppData\Roaming\Malwarebytes 2011-04-02 13:50:49 38224 —-a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys 2011-04-02 13:50:48 ——– d—–w- C:\PROGRA~3\Malwarebytes 2011-04-02 13:50:46 24152 —-a-w- C:\Windows\System32\drivers\mbam.sys 2011-04-01 13:02:35 431176 —-a-w- C:\Windows\System32\drivers\bdfsfltr.sys 2011-04-01 13:02:30 101968 —-a-w- C:\Windows\System32\drivers\bdhv.sys 2011-03-27 02:43:47 ——– d—–w- C:\Users\MANGOC~1\AppData\Roaming\WinFF 2011-03-27 02:39:52 ——– d—–w- C:\PROGRA~3\DivX 2011-03-26 23:11:56 8424784 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{4F318B03-FE96-4C61-B999-2985B170AFF5}\mpengine.dll 2011-03-19 15:52:54 ——– d—–w- C:\Users\MANGOC~1\AppData\Local\Bitforge 2011-03-19 15:34:31 545 —-a-w- C:\Windows\UC.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows\RAR.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows\PKZIP.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows\PKUNZIP.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows\NOCLOSE.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows\LHA.PIF 2011-03-19 15:34:31 545 —-a-w- C:\Windows\ARJ.PIF 2011-03-19 15:34:31 ——– d—–w- C:\Users\MANGOC~1\AppData\Roaming\GHISLER 2011-03-06 17:05:32 ——– d—–w- C:\Users\MANGOC~1\AppData\Roaming\TS3Client . ==================== Find3M ==================== . 2011-02-26 11:58:42 175616 —-a-w- C:\Windows\System32\msclmd.dll 2011-02-26 11:58:42 152576 —-a-w- C:\Windows\SysWow64\msclmd.dll 2011-02-19 12:05:15 1139200 —-a-w- C:\Windows\System32\FntCache.dll 2011-02-19 12:04:37 1544192 —-a-w- C:\Windows\System32\DWrite.dll 2011-02-19 12:04:17 902656 —-a-w- C:\Windows\System32\d2d1.dll 2011-02-19 06:30:51 1076736 —-a-w- C:\Windows\SysWow64\DWrite.dll 2011-02-19 06:30:50 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll 2011-02-02 17:11:20 270720 ——w- C:\Windows\System32\MpSigStub.exe 2011-01-17 11:09:14 197120 —-a-w- C:\Windows\System32\d3d10_1.dll 2011-01-17 05:47:13 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2011-01-07 12:17:52 475648 —-a-w- C:\Windows\System32\XpsGdiConverter.dll 2011-01-07 12:17:52 1465344 —-a-w- C:\Windows\System32\XpsPrint.dll 2011-01-07 12:14:11 46080 —-a-w- C:\Windows\System32\atmlib.dll 2011-01-07 09:51:01 1638912 —-a-w- C:\Windows\System32\mshtml.tlb 2011-01-07 09:20:44 366592 —-a-w- C:\Windows\System32\atmfd.dll 2011-01-07 07:46:34 870912 —-a-w- C:\Windows\SysWow64\XpsPrint.dll 2011-01-07 07:46:34 288256 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2011-01-07 07:45:57 34304 —-a-w- C:\Windows\SysWow64\atmlib.dll 2011-01-07 06:01:22 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb 2011-01-07 05:43:36 294400 —-a-w- C:\Windows\SysWow64\atmfd.dll 2011-01-05 10:34:00 612864 —-a-w- C:\Windows\System32\vbscript.dll 2011-01-05 06:56:24 3129344 —-a-w- C:\Windows\System32\win32k.sys 2011-01-05 05:55:55 428032 —-a-w- C:\Windows\SysWow64\vbscript.dll 2010-07-08 08:37:14 101544 —-a-w- C:\Program Files\Common Files\LinkInstaller.exe . ============= FINISH: 15:57:32,91 ===============
Hi,

Log looks ok, lets dig a bit deeper

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
  • Double click GMER.exe.
    [external image: Posted Image]
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
      [external image: Posted Image]
      Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Please copy and paste the report into your Post.





OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI