This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Another slooow computer problem . .. sorry

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi - have tried all the usual recommendations (deleting files, programs, restore points, etc), defragging, Malware Malbytes and avast virus scans are okay, but still running quite slow. It's an older Dell Dimension 2400 with XP, 718MB RAM, hard drive only half full. Not sure what else to change/delete, so thought it might be a virus - HJT log is posted below. Thanks again for any help!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:01:22 PM, on 8/13/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
E:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Documents and Settings\Owner\Application Data\HP SimpleSave Application\uUACTokenSvc.exe
C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [WinPatrol] E:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [DW6] "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1281570620921
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} (Image Uploader Control) - http://www.ritzpix.com/net/Uploader/LPUploader57.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: BackupService - ArcSoft, Inc. - C:\Documents and Settings\Owner\Application Data\HP SimpleSave Application\uUACTokenSvc.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

–
End of file - 6454 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt

Please attach the second file; Attach.txt.



Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that may have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one - make sure it is UNCHECKED)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi Doris - thanks for your help. Here are the DDS (one pasted, one attached as a zip) and Gmer (attached)results as you requested. Hope I did the attachments okay - let me know if not. Thanks again - Peter. . DDS (Ver_2011-06-23.01) - NTFSx86 Internet Explorer: 6.0.2900.5512 Run by [removed] at 17:19:16 on 2011-08-17 . ============== Running Processes =============== . . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [WinPatrol] e:\program files\billp studios\winpatrol\winpatrol.exe mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: learn-classic-rock-songs.com\www DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1281570620921 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} - hxxp://www.ritzpix.com/net/Uploader/LPUploader57.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{675A56C1-13C3-4418-A3DC-7E41E94DEF9A} : DhcpNameServer = [removed] [removed] Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll . ============= SERVICES / DRIVERS =============== . R? CrucialSMBusScan;CrucialSMBusScan R? gupdate;Google Update Service (gupdate) R? gupdatem;Google Update Service (gupdatem) S? aswFsBlk;aswFsBlk S? aswSnx;aswSnx S? aswSP;aswSP S? avast! Antivirus;avast! Antivirus S? BackupService;BackupService S? MBAMProtector;MBAMProtector S? MBAMService;MBAMService S? npf;NetGroup Packet Filter Driver S? rt2870;Linksys 802.11n USB Wireless LAN Card Driver S? WinDefend;Windows Defender . =============== Created Last 30 ================ . 2011-08-17 08:37:49 221184 —-a-w- c:\windows\system32\wmpns.dll 2011-08-17 08:00:31 ——– d—–w- c:\windows\system32\scripting 2011-08-17 08:00:27 ——– d—–w- c:\windows\l2schemas 2011-08-17 08:00:26 ——– d—–w- c:\windows\system32\en 2011-08-17 07:51:08 ——– d—–w- c:\windows\network diagnostic 2011-08-17 06:09:33 7152464 —-a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{ccef5eb6-88a2-4d57-b977-fe935fceb4c1}\mpengine.dll 2011-08-14 00:59:53 388096 —-a-r- c:\documents and settings\owner\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-08-14 00:54:58 ——– d—–w- c:\program files\Trend Micro 2011-08-13 17:07:19 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-07-31 05:23:21 ——– d—–w- c:\documents and settings\owner\application data\Malwarebytes 2011-07-31 05:22:08 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-31 05:22:06 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-07-31 05:22:03 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-07-31 05:22:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware . ==================== Find3M ==================== . 2011-07-04 11:43:53 40112 —-a-w- c:\windows\avastSS.scr 2011-05-24 23:14:10 222080 ——w- c:\windows\system32\MpSigStub.exe 2010-08-13 15:50:47 1712680 —-a-w- c:\program files\WindowsXP-KB952155-x86-ENU.exe 2010-08-12 03:49:08 7411096 —-a-w- c:\program files\R94481.EXE 2010-08-12 03:45:42 2795632 —-a-w- c:\program files\R47822.EXE 2010-08-12 00:19:23 278927592 —-a-w- c:\program files\XPSP2.exe 2010-01-26 15:11:08 444283 —-a-w- c:\program files\common files\WinPcapNmap.exe . ============= FINISH: 17:28:44.01 ===============

Attachments:

Please give me a little bit to analyze the logs. I'll be back to you just as quickly as I can.

While I do that, I do have one thing I would like to suggest. I would recommend going to your Control Panel > Add/Remove Programs and uninstall Yontoo. It is what we consider a PUA (potentially unwanted application).

Yontoo Layers or Drop Down Deals browser add-on - creates virtual layers that can be edited to create the appearance of having made changes to the underlying website. Has ads in the layers with no obvious warning on install.

The choice is yours, but if it were my machine, I would not want this program on there.

I'll be back to you shortly.
It looks like Avast may be interfering with the output in the logs. I'd like to have you boot into Safe Mode and then run just DDS again please.



Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would.



Run DDS by sUBs
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults here (you don't have to zip or attach any files this time.)
Okay - I got rid of the Yontoo thing - not sure where that came from. I re-ran the DDS in Safe Mode - here are the two logs. (I wonder if I didn't do it right the first time as I may not have turned off the right script blocking - I turned a different one off in avast, and the DDS scan only took a few minutes this time, as opposed to several minutes last time.) Hope this helps - thanks again, Peter . DDS (Ver_2011-06-23.01) - NTFSx86 MINIMAL Internet Explorer: 6.0.2900.5512 Run by [removed] at 2:11:13 on 2011-08-18 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.617 [GMT -4:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\Explorer.EXE . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [WinPatrol] e:\program files\billp studios\winpatrol\winpatrol.exe mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1281570620921 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} - hxxp://www.ritzpix.com/net/Uploader/LPUploader57.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{675A56C1-13C3-4418-A3DC-7E41E94DEF9A} : DhcpNameServer = [removed] [removed] Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll . ============= SERVICES / DRIVERS =============== . R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-8-13 441176] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-8-11 309848] S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-8-11 19544] S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-11 42184] S2 BackupService;BackupService;c:\documents and settings\owner\application data\hp simplesave application\uUACTokenSvc.exe [2010-12-13 83512] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-8-11 136176] S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-31 366640] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-1-26 50704] S3 CrucialSMBusScan;CrucialSMBusScan;\??\c:\docume~1\owner\locals~1\temp\crucialsmbusscan_xp32.sys –> c:\docume~1\owner\locals~1\temp\CrucialSMBusScan_XP32.sys [?] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-8-11 136176] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-7-31 22712] S3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2010-8-10 551680] . =============== Created Last 30 ================ . 2011-08-17 21:19:11 ——– d—–w- C:\## aswSnx private storage 2011-08-17 08:37:49 221184 —-a-w- c:\windows\system32\wmpns.dll 2011-08-17 08:00:31 ——– d—–w- c:\windows\system32\scripting 2011-08-17 08:00:27 ——– d—–w- c:\windows\l2schemas 2011-08-17 08:00:26 ——– d—–w- c:\windows\system32\en 2011-08-17 07:51:08 ——– d—–w- c:\windows\network diagnostic 2011-08-17 06:09:33 7152464 —-a-w- c:\documents and settings\all users\application data\microsoft\windows defender\definition updates\{ccef5eb6-88a2-4d57-b977-fe935fceb4c1}\mpengine.dll 2011-08-14 00:54:58 ——– d—–w- c:\program files\Trend Micro 2011-08-13 17:07:19 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-07-31 05:22:08 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-31 05:22:06 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-07-31 05:22:03 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-07-31 05:22:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware . ==================== Find3M ==================== . 2011-07-04 11:43:53 40112 —-a-w- c:\windows\avastSS.scr 2011-05-24 23:14:10 222080 ——w- c:\windows\system32\MpSigStub.exe 2010-08-13 15:50:47 1712680 —-a-w- c:\program files\WindowsXP-KB952155-x86-ENU.exe 2010-08-12 03:49:08 7411096 —-a-w- c:\program files\R94481.EXE 2010-08-12 03:45:42 2795632 —-a-w- c:\program files\R47822.EXE 2010-08-12 00:19:23 278927592 —-a-w- c:\program files\XPSP2.exe 2010-01-26 15:11:08 444283 —-a-w- c:\program files\common files\WinPcapNmap.exe . ============= FINISH: 2:12:48.51 =============== DDS Attach log: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-23.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 7/28/2010 7:19:37 PM System Uptime: 8/18/2011 2:08:27 AM (0 hours ago) . Motherboard: Dell Computer Corp. | | 0C2425 Processor: Intel® Celeron® CPU 2.40GHz | Microprocessor | 2392/400mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 34 GiB total, 17.368 GiB free. D: is CDROM () E: is FIXED (NTFS) - 37 GiB total, 10.339 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E968-E325-11CE-BFC1-08002BE10318} Description: Intel® 82845G/GL/GE/PE/GV Graphics Controller Device ID: PCI\VEN_8086&DEV_2562&SUBSYS_01601028&REV_01\3&172E68DD&0&10 Manufacturer: Intel Corporation Name: Intel® 82845G/GL/GE/PE/GV Graphics Controller PNP Device ID: PCI\VEN_8086&DEV_2562&SUBSYS_01601028&REV_01\3&172E68DD&0&10 Service: ialm . Class GUID: {4D36E968-E325-11CE-BFC1-08002BE10318} Description: Video Controller (VGA Compatible) Device ID: PCI\VEN_10DE&DEV_0312&SUBSYS_00000000&REV_A1\4&3B1CAF2B&0&20F0 Manufacturer: Name: Video Controller (VGA Compatible) PNP Device ID: PCI\VEN_10DE&DEV_0312&SUBSYS_00000000&REV_A1\4&3B1CAF2B&0&20F0 Service: . Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318} Description: Ethernet Controller Device ID: PCI\VEN_14E4&DEV_4401&SUBSYS_81271028&REV_01\4&3B1CAF2B&0&48F0 Manufacturer: Name: Ethernet Controller PNP Device ID: PCI\VEN_14E4&DEV_4401&SUBSYS_81271028&REV_01\4&3B1CAF2B&0&48F0 Service: . ==== System Restore Points =================== . RP422: 8/13/2011 8:23:34 AM - System Checkpoint RP423: 8/13/2011 8:59:49 PM - Installed HiJackThis RP424: 8/14/2011 3:54:05 AM - Software Distribution Service 3.0 RP425: 8/14/2011 3:54:45 AM - Software Distribution Service 3.0 RP426: 8/15/2011 10:31:44 AM - System Checkpoint RP427: 8/16/2011 7:47:10 AM - Software Distribution Service 3.0 RP428: 8/17/2011 2:09:10 AM - Software Distribution Service 3.0 RP429: 8/17/2011 3:01:21 AM - Software Distribution Service 3.0 RP430: 8/18/2011 1:50:06 AM - Removed HiJackThis . ==== Installed Programs ====================== . Adobe Flash Player 10 ActiveX Adobe Reader 9.4.5 AiO_Scan_CDA AiOSoftwareNPI avast! Free Antivirus BufferChm C6100 c6100_Help Coupon Printer for Windows CP_CalendarTemplates1 cp_OnlineProjectsConfig CP_Package_Basic1 CP_Panorama1Config cp_PosterPrintConfig CueTour CustomerResearchQFolder Destinations DeviceManagementQFolder DocProc DocProcQFolder DocumentViewer DocumentViewerQFolder Dragon NaturallySpeaking 7.0 eSupportQFolder Fax_CDA FullDPAppQFolder Google Chrome Google Earth Google Update Helper HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB981793) HP Customer Participation Program 7.0 HP Document Viewer 7.0 HP Imaging Device Functions 7.0 HP My Display HP Photosmart Premier Software 6.5 HP Photosmart, Officejet and Deskjet 7.0.A HP Software Update HP Solution Center 7.0 HPPhotoSmartExpress HPProductAssistant InstantShareDevices InstantShareDevicesMFC Intel® 537EP V9x DF PCI Modem Intel® Extreme Graphics Driver Java Auto Updater Java™ 6 Update 21 Malwarebytes' Anti-Malware version 1.51.1.1800 MarketResearch Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Corporation Microsoft LifeCam Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) MSXML4 Parser NewCopy_CDA NVIDIA Drivers OCR Software by I.R.I.S 7.0 OpenMG Limited Patch 4.7-07-14-05-01 OpenMG Secure Module 4.7.00 PanoStandAlone PhotoCardMaker 1.0.3 PhotoGallery ProductContextNPI Project64 1.6 RandMap Readme RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer RealUpgrade 1.1 Scan ScannerCopy SDK Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2509488) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft Office 2007 System (KB2541012) Security Update for Microsoft Office Excel 2007 (KB2541007) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB982381) Sibelius Scorch (ActiveX Only) Sibelius Scorch (Firefox, Opera, Netscape only) SkinsHP1 Skype Toolbars Skype™ 5.3 SlideShow SolutionCenter Sonic_PrimoSDK SonicStage 4.3 SoundMAX Status The Weather Channel Desktop 6 Toolbox TrayApp Unload Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office OneNote 2007 (KB980729) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VDownloader 3.5.864 Vizzed Retro Game Room WebFldrs XP WebReg Windows Defender Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Media Format 11 runtime Windows Presentation Foundation Windows XP Service Pack 3 WinPcap 4.1.1 Wondershare Photo Collage Studio 4.2.12.13 XML Paper Specification Shared Components Pack 1.0 . ==== Event Viewer Messages From Past Week ======== . 8/18/2011 2:10:32 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 8/18/2011 2:10:29 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswRdr aswSnx aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT OMCI RasAcd Rdbss Tcpip 8/18/2011 2:10:29 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning. 8/18/2011 2:10:29 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 8/18/2011 2:10:29 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 8/18/2011 2:09:55 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 8/18/2011 2:09:50 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 8/17/2011 5:51:58 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period. 8/17/2011 4:39:51 AM, error: Service Control Manager [7022] - The Windows Firewall/Internet Connection Sharing (ICS) service hung on starting. 8/14/2011 4:22:43 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service HP Port Resolver with arguments "-Service" in order to run the server: {5A5AA0AA-1DEB-4683-96B0-B43301E83971} 8/14/2011 3:56:09 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x800706be: Windows XP Service Pack 3 (KB936929). 8/14/2011 12:29:39 PM, error: Service Control Manager [7034] - The HP Port Resolver service terminated unexpectedly. It has done this 1 time(s). 8/13/2011 7:23:25 AM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.DebugCRT. Reference error message: The referenced assembly is not installed on your system. . 8/13/2011 7:23:25 AM, error: SideBySide [59] - Generate Activation Context failed for C:\Program Files\Real\RealPlayer\plugins\rmxrend.dll. Reference error message: The operation completed successfully. . 8/13/2011 7:23:25 AM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.DebugCRT could not be found and Last Error was The referenced assembly is not installed on your system. . ==== End Of File ===========================
Thanks for re-running that. It looks complete now.


I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Uncheck Remove found threats.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
Copy and paste that log as a reply to this topic.
Malwarebytes scan was okay, and it looks like eset found something. Here are the logs: Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7502 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 8/18/2011 7:27:23 PM mbam-log-2011-08-18 (19-27-23).txt Scan type: Quick scan Objects scanned: 176390 Time elapsed: 17 minute(s), 24 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESET: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=6.00.2900.5512 (xpsp.080413-2105) # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=c1542a9becb8964d88c03571f525e3db # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-08-19 03:01:13 # local_time=2011-08-18 11:01:13 (-0500, Eastern Daylight Time) # country="United States" # lang=9 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=770 16774141 100 100 0 89500288 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=154018 # found=9 # cleaned=0 # scan_time=10863 E:\Documents and Settings\Peter\Application Data\Microsoft\Internet Explorer\Quick Launch\eBay.lnk Win32/Adware.ADON application (unable to clean) 00000000000000000000000000000000 I E:\Documents and Settings\Peter\Local Settings\Application Data\Google\Chrome\User Data\Default\old_Cache_000\f_000ec4 HTML/ScrInject.B.Gen virus (unable to clean) 00000000000000000000000000000000 I E:\Documents and Settings\Peter\Local Settings\Application Data\Google\Chrome\User Data\Default\old_Cache_000\f_000ec6 HTML/ScrInject.B.Gen virus (unable to clean) 00000000000000000000000000000000 I E:\Documents and Settings\Peter\Local Settings\Application Data\Google\Chrome\User Data\Default\old_Cache_000\f_000ec8 HTML/ScrInject.B.Gen virus (unable to clean) 00000000000000000000000000000000 I E:\Documents and Settings\Peter\Local Settings\Temp\update.exe probably a variant of Win32/Injector.CPT trojan (unable to clean) 00000000000000000000000000000000 I E:\Documents and Settings\Peter\Start Menu\eBay.lnk Win32/Adware.ADON application (unable to clean) 00000000000000000000000000000000 I E:\Program Files\vdownloader1.0\vdownloader_setup.exe a variant of Win32/Adware.ADON application (unable to clean) 00000000000000000000000000000000 I E:\System Volume Information\_restore{5F2221FD-E1E8-4998-8BCE-92E742C03831}\RP423\A0340551.dll Win32/Toolbar.AskSBar application (unable to clean) 00000000000000000000000000000000 I E:\WINDOWS\SYSTEM32\install\explorer.exe probably a variant of Win32/Injector.CPT trojan (unable to clean) 00000000000000000000000000000000 I Thanks again, and looking forward to next step! Peter
Well, the good news is that the items found were on your E: drive not your C: drive. Your C: drive looks malware free. Are you actually running anything from the E: drive or are you using it as backup of your C: drive. From the file locations, it would appear it is a backup drive.
Didn't even notice that was on the E drive - which is just a back up for some files, pictures, etc - don't really use it much now. Should I still try to get rid of that Trojan thing. Most of those files on E are also saved on a separate HP Passport thing. Thanks, Peter
If it were me, I'd remove these (just delete the files): E:\Documents and Settings\Peter\Local Settings\Application Data\Google\Chrome\User Data\Default\old_Cache_000\f_000ec4 E:\Documents and Settings\Peter\Local Settings\Application Data\Google\Chrome\User Data\Default\old_Cache_000\f_000ec6 E:\Documents and Settings\Peter\Local Settings\Application Data\Google\Chrome\User Data\Default\old_Cache_000\f_000ec8 E:\Documents and Settings\Peter\Local Settings\Temp\update.exe E:\Program Files\vdownloader1.0\vdownloader_setup.exe E:\WINDOWS\SYSTEM32\install\explorer.exe This one is in a system restore point. I cannot tell from this information the date of this restore point or if it might be something you'd need. If you remove the file you may render the restore point useless. It's not going to hurt anything as long as you don't use the restore point. I'd probably leave it alone. E:\System Volume Information\_restore{5F2221FD-E1E8-4998-8BCE-92E742C03831}\RP423\A0340551.dll As for the E-bay quick launch links - the report shows "possible" items. I don't feel those are of any issue at all. I believe the slowness you are experiencing may be a result of the fairly low amount of RAM on the machine. You may want to post in the Windows forum to see if they have any other ideas for you.
I removed all the files in question. I'll look into getting a little more RAM, try cleaning things up a little more, or try posting in the Windows forum if it doesn't get any better soon. I guess you can close this as far as malware, etc - thanks again for your help! Peter

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI