cklenertz
Topic Starter
Hello,
I am having issues with my laptop. I'm on a home wireless network but I have the same challenges whether I'm plugged directly into the router or going wireless. My system is slow, it hangs frequently, I'm getting frequent pop-ups even though my blocker is on. I've run Spybot multiple times to no avail as well as CCleaner. In addition,
I'm having connectivity issues. Sometimes it works fine, sometimes not. I'm not sure if someone is using my system as a proxy or not. I have pasted the DDS logfile. I couldn't tell if I was supposed to copy and paste it or attach it. Let me know if you would prefer me to attach it next time.
Thanks,
Kevin
P.S. I appreciate any assessment and reply. I will be out of town until Monday 7/11. If I get a reply over the weekend I will not be able to respond until Monday but I thank you in advance for your time.
(DDS Logfile 7-6-2011)
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 23:05:15 on 2011-07-06
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2942.1445 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Users\Kevin\AppData\Local\Mozilla Firefox\firefox.exe
C:\Users\Kevin\AppData\Local\Mozilla Firefox\plugin-container.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\aestsrv.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Palm, Inc\novacom\x86\novacomd.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\System32\bcmwltry.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Users\Kevin\AppData\Local\Mozilla Firefox\plugin-container.exe
C:\Users\Kevin\AppData\Local\Mozilla Firefox\plugin-container.exe
C:\Users\Kevin\AppData\Local\Mozilla Firefox\plugin-container.exe
C:\Users\Kevin\AppData\Local\Mozilla Firefox\plugin-container.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [BootNaMir] c:\program files\wondershare\time freeze\BootSP.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{4CE1FCC5-D0DF-45C1-A735-4AF4FD7B3351} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{4CE1FCC5-D0DF-45C1-A735-4AF4FD7B3351}\659627573744963747279626574796F6E63456E6472716C6 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{4CE1FCC5-D0DF-45C1-A735-4AF4FD7B3351}\C456E6562747A70284F6D656A3023747169702F65747020757E6B6 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{4CE1FCC5-D0DF-45C1-A735-4AF4FD7B3351}\C456E6562747A70284F6D656A302B65656070297F60216373702F65747 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{4CE1FCC5-D0DF-45C1-A735-4AF4FD7B3351}\D4F62756970275966496D27657563747 : DhcpNameServer = [removed] [removed]
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\kevin\appdata\roaming\mozilla\firefox\profiles\bzft8pc7.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.wwdb.com/Login.aspx?ReturnUrl=/Home.aspx
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R?2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-5-17 42184]
R0 HKDirFlt;Wondershare HKDirFlt;c:\windows\system32\drivers\HKDirFlt.sys [2010-8-25 33896]
R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [2010-9-16 40560]
R0 MirDisk;Wondershare Time Freeze;c:\windows\system32\drivers\MirDisk.sys [2010-8-25 28648]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-5-17 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-5-17 307928]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2010-3-10 73728]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-5-17 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-5-17 53592]
R2 NovacomD;Palm Novacom;c:\program files\palm, inc\novacom\x86\novacomd.exe [2010-1-12 33792]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-5-2 1153368]
R3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2011-5-12 21744]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-13 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-2-28 183560]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-1-28 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-13 136176]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-3-17 15872]
S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-3-17 52224]
S3 USBTINSP;TI-Nspire™ Handheld or TI Network Bridge Device Driver;c:\windows\system32\drivers\tinspusb.sys [2010-3-29 122752]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-10 1343400]
.
=============== Created Last 30 ================
.
2011-07-07 05:59:26 7074640 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{0b203931-26f7-4ece-98c3-9795b4b497d2}\mpengine.dll
2011-06-29 00:32:06 293376 —-a-w- c:\windows\system32\umpnpmgr.dll
2011-06-29 00:31:42 1549312 —-a-w- c:\windows\system32\tquery.dll
2011-06-29 00:31:42 1401344 —-a-w- c:\windows\system32\mssrch.dll
2011-06-29 00:31:41 427520 —-a-w- c:\windows\system32\SearchIndexer.exe
2011-06-29 00:31:40 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe
2011-06-29 00:31:40 666624 —-a-w- c:\windows\system32\mssvp.dll
2011-06-29 00:31:40 337408 —-a-w- c:\windows\system32\mssph.dll
2011-06-29 00:31:40 197120 —-a-w- c:\windows\system32\mssphtb.dll
2011-06-29 00:31:40 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe
2011-06-29 00:31:39 59392 —-a-w- c:\windows\system32\msscntrs.dll
2011-06-15 05:36:56 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-06-15 05:36:56 141104 —-a-w- c:\program files\internet explorer\sqmapi.dll
2011-06-15 05:36:54 1797632 —-a-w- c:\windows\system32\jscript9.dll
2011-06-15 05:13:29 311808 —-a-w- c:\windows\system32\drivers\srv.sys
2011-06-15 05:13:29 310272 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-06-15 05:13:29 114688 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-15 05:13:23 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-15 05:13:22 338944 —-a-w- c:\windows\system32\drivers\afd.sys
2011-06-15 05:13:21 571904 —-a-w- c:\windows\system32\oleaut32.dll
2011-06-15 05:12:53 741376 —-a-w- c:\windows\system32\inetcomm.dll
2011-06-15 05:10:04 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-15 05:10:04 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-15 05:10:04 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.
==================== Find3M ====================
.
2011-05-25 02:14:10 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-05-13 16:49:04 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-10 12:10:59 40112 —-a-w- c:\windows\avastSS.scr
2011-05-10 12:10:55 199304 —-a-w- c:\windows\system32\asw3CB2.tmp
2011-05-10 12:03:54 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-10 11:59:44 53592 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-04-22 19:14:16 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-09 06:02:25 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02:25 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56:38 123904 —-a-w- c:\windows\system32\poqexec.exe
.
============= FINISH: 23:08:12.19 ===============