This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tons of viruses, very very slow.

58 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix 11-08-24.04 - Painter 08/26/2011 4:48.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1278.685 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Painter\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Painter\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed]
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_TERMSERVICES
——-\Service_TermServices
.
.
((((((((((((((((((((((((( Files Created from 2011-07-26 to 2011-08-26 )))))))))))))))))))))))))))))))
.
.
2011-08-25 03:59 . 2011-08-25 03:58 476904 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-08-25 03:59 . 2011-08-25 03:57 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-08-24 10:39 . 2011-08-24 10:42 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-08-24 10:32 . 2010-09-18 06:53 954368 ——w- c:\windows\system32\dllcache\mfc40.dll
2011-08-24 10:32 . 2010-09-18 06:53 953856 ——w- c:\windows\system32\dllcache\mfc40u.dll
2011-08-24 10:31 . 2010-08-23 16:12 617472 ——w- c:\windows\system32\dllcache\comctl32.dll
2011-08-24 10:28 . 2010-11-02 15:17 40960 ——w- c:\windows\system32\dllcache\ndproxy.sys
2011-08-24 10:20 . 2011-07-08 14:02 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-24 10:20 . 2010-10-11 14:59 45568 ——w- c:\windows\system32\dllcache\wab.exe
2011-08-24 10:18 . 2011-06-24 14:10 139656 ——w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-24 10:18 . 2011-04-21 13:37 105472 ——w- c:\windows\system32\dllcache\mup.sys
2011-08-24 09:48 . 2011-08-24 09:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2011-08-24 09:48 . 2008-04-14 00:11 23552 —-a-w- c:\windows\system32\fxsmon.dll
2011-08-24 09:48 . 2008-04-14 00:11 23552 —-a-w- c:\windows\system32\dllcache\fxsmon.dll
2011-08-23 18:21 . 2011-08-23 18:21 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2011-08-23 10:09 . 2011-08-23 10:53 ——– d—–w- c:\windows\system32\scripting
2011-08-23 10:09 . 2011-08-23 10:09 ——– d—–w- c:\windows\l2schemas
2011-08-23 10:09 . 2011-08-23 10:51 ——– d—–w- c:\windows\system32\en
2011-08-23 10:09 . 2011-08-23 10:53 ——– d—–w- c:\windows\system32\bits
2011-08-23 09:52 . 2011-08-23 09:52 ——– d—–w- c:\windows\EHome
2011-08-23 09:47 . 2011-08-23 09:47 ——– d-sh–w- c:\documents and settings\Painter\IECompatCache
2011-08-23 09:47 . 2011-08-23 09:47 ——– d-sh–w- c:\documents and settings\Painter\PrivacIE
2011-08-23 09:46 . 2011-08-23 09:46 ——– d-sh–w- c:\documents and settings\Painter\IETldCache
2011-08-23 09:43 . 2011-08-23 09:43 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2011-08-23 09:40 . 2011-08-23 09:40 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2011-08-23 09:37 . 2011-06-23 18:36 602112 ——w- c:\windows\system32\dllcache\msfeeds.dll
2011-08-23 09:37 . 2011-06-23 18:36 55296 ——w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-08-23 09:37 . 2011-06-23 18:36 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2011-08-23 09:37 . 2011-06-23 18:36 1991680 ——w- c:\windows\system32\dllcache\iertutil.dll
2011-08-23 09:37 . 2011-06-23 18:36 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2011-08-23 09:37 . 2011-06-23 18:36 11081728 ——w- c:\windows\system32\dllcache\ieframe.dll
2011-08-23 09:37 . 2011-06-23 18:36 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2011-08-23 09:35 . 2011-08-23 09:37 ——– dc-h–w- c:\windows\ie8
2011-08-22 23:52 . 2011-08-22 23:52 ——– d—–w- c:\documents and settings\Painter\Local Settings\Application Data\AVG Security Toolbar
2011-08-22 21:56 . 2011-08-22 21:56 ——– d—–w- C:\malware
2011-08-22 21:39 . 2011-08-22 21:40 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-08-22 21:39 . 2011-08-22 21:39 ——– d—–w- C:\$AVG
2011-08-22 21:37 . 2011-08-22 21:37 ——– d—–w- c:\documents and settings\Painter\Application Data\AVG10
2011-08-22 21:35 . 2011-08-23 09:47 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2011-08-22 21:31 . 2011-08-26 09:41 ——– d—–w- c:\windows\system32\drivers\AVG
2011-08-22 21:31 . 2011-08-22 23:46 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG10
2011-08-22 21:30 . 2011-08-22 21:30 ——– d—–w- c:\program files\AVG
2011-08-22 21:16 . 2011-08-22 21:16 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2011-08-22 21:16 . 2011-08-22 21:30 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2011-08-22 03:27 . 2011-08-22 03:27 ——– d—–w- c:\documents and settings\Painter\Application Data\Malwarebytes
2011-08-22 03:18 . 2011-07-07 00:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-22 03:18 . 2011-08-22 03:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-08-22 03:18 . 2011-08-22 03:18 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-08-22 03:18 . 2011-07-07 00:52 22712 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 03:17 . 2001-08-17 18:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2011-08-22 03:17 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2011-08-22 00:38 . 2011-08-22 00:38 ——– d-s—w- c:\documents and settings\LocalService\UserData
2011-08-22 00:23 . 2011-08-22 00:23 ——– d-sh–w- c:\documents and settings\NetworkService\UserData
2011-08-21 23:31 . 2011-08-24 09:24 ——– d—–w- c:\documents and settings\Administrator
2011-08-20 17:00 . 2011-08-20 17:00 ——– d—–w- C:\3fbc396e7c181f3b61a46d0903cc1652
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-25 03:57 . 2008-01-01 16:18 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-07-15 13:29 . 2004-08-10 18:51 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2004-08-10 18:51 10496 —-a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2004-08-10 19:01 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2004-08-10 18:51 916480 —-a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2004-08-10 18:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2004-08-10 18:51 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-08-10 18:51 385024 —-a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2004-08-10 18:51 293376 —-a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02 . 2004-08-10 18:51 1858944 —-a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\malware —-
.
2011-08-22 21:56 . 2011-08-22 22:02 625664 —-a-w- c:\malware\dds.scr
2011-08-22 21:56 . 2011-08-22 22:04 1758 —-a-w- c:\malware\ott.txt
2011-08-22 21:56 . 2011-08-22 22:02 388608 —-a-w- c:\malware\HiJackThis.exe
2011-08-22 21:56 . 2011-08-22 22:00 580096 —-a-w- c:\malware\OTL.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-25_00.03.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-26 10:05 . 2011-08-26 10:05 16384 c:\windows\temp\Perflib_Perfdata_7a8.dat
+ 2004-08-10 18:51 . 2008-05-09 10:53 90112 c:\windows\system32\wshext.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 90112 c:\windows\system32\wshext.dll
+ 2007-01-29 08:58 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
- 2007-01-29 08:58 . 2010-04-21 13:28 46080 c:\windows\system32\tzchange.exe
+ 2004-08-10 18:51 . 2010-08-27 05:57 99840 c:\windows\system32\srvsvc.dll
+ 2004-08-10 18:51 . 2010-08-17 13:17 58880 c:\windows\system32\spoolsv.exe
+ 2004-08-10 18:51 . 2011-06-23 18:36 66560 c:\windows\system32\mshtmled.dll
- 2004-08-10 18:51 . 2009-03-08 09:31 66560 c:\windows\system32\mshtmled.dll
+ 2009-03-08 09:31 . 2011-06-23 18:36 55296 c:\windows\system32\msfeedsbs.dll
- 2009-03-08 09:31 . 2010-05-06 10:41 55296 c:\windows\system32\msfeedsbs.dll
- 2004-08-10 18:51 . 2010-05-06 10:41 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-10 18:51 . 2011-06-23 18:36 25600 c:\windows\system32\jsproxy.dll
- 2004-08-10 19:02 . 2008-04-14 00:11 81920 c:\windows\system32\isign32.dll
+ 2004-08-10 19:02 . 2010-11-18 18:12 81920 c:\windows\system32\isign32.dll
- 2004-08-10 18:51 . 2008-04-14 00:11 80384 c:\windows\system32\iccvid.dll
+ 2004-08-10 18:51 . 2010-06-17 14:03 80384 c:\windows\system32\iccvid.dll
+ 2004-08-10 18:51 . 2010-11-02 15:17 40960 c:\windows\system32\drivers\ndproxy.sys
+ 2004-08-10 18:50 . 2009-04-20 17:17 45568 c:\windows\system32\dnsrslvr.dll
- 2004-08-10 18:50 . 2008-04-14 00:11 45568 c:\windows\system32\dnsrslvr.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 90112 c:\windows\system32\dllcache\wshext.dll
+ 2010-08-27 05:57 . 2010-08-27 05:57 99840 c:\windows\system32\dllcache\srvsvc.dll
+ 2010-08-17 13:17 . 2010-08-17 13:17 58880 c:\windows\system32\dllcache\spoolsv.exe
- 2006-05-10 05:23 . 2009-03-08 09:31 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-05-10 05:23 . 2011-06-23 18:36 66560 c:\windows\system32\dllcache\mshtmled.dll
+ 2009-03-08 09:34 . 2011-06-23 18:36 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2006-05-10 05:22 . 2011-06-23 18:36 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2006-05-10 05:22 . 2010-05-06 10:41 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2010-11-18 18:12 . 2010-11-18 18:12 81920 c:\windows\system32\dllcache\isign32.dll
+ 2009-04-20 17:17 . 2009-04-20 17:17 45568 c:\windows\system32\dllcache\dnsrslvr.dll
+ 2009-12-14 07:08 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
- 2009-12-14 07:08 . 2009-12-14 07:08 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2004-08-10 18:50 . 2011-04-26 11:07 33280 c:\windows\system32\csrsrv.dll
- 2004-08-10 18:50 . 2009-12-14 07:08 33280 c:\windows\system32\csrsrv.dll
- 2010-04-01 16:42 . 2010-04-01 16:42 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2010-09-23 20:55 . 2010-09-23 20:55 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
- 2010-03-31 19:51 . 2010-03-31 19:51 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
- 2010-03-31 19:51 . 2010-03-31 19:51 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
- 2010-03-31 19:51 . 2010-03-31 19:51 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2010-09-23 08:17 . 2010-09-23 08:17 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
- 2010-03-31 20:32 . 2010-03-31 20:32 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2010-09-23 08:17 . 2010-09-23 08:17 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
- 2010-03-31 20:32 . 2010-03-31 20:32 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 12800 c:\windows\ie8updates\KB2559049-IE8\xpshims.dll
+ 2011-08-25 00:17 . 2009-03-08 09:31 66560 c:\windows\ie8updates\KB2559049-IE8\mshtmled.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 55296 c:\windows\ie8updates\KB2559049-IE8\msfeedsbs.dll
+ 2011-08-25 00:17 . 2009-03-08 09:34 43008 c:\windows\ie8updates\KB2559049-IE8\licmgr10.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 25600 c:\windows\ie8updates\KB2559049-IE8\jsproxy.dll
+ 2011-08-25 00:26 . 2011-08-25 00:26 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_c792f814\System.Drawing.Design.dll
+ 2011-08-25 00:26 . 2011-08-25 00:26 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_1fb307a2\CustomMarshalers.dll
- 2010-09-02 00:11 . 2010-09-02 00:11 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-08-25 00:25 . 2011-08-25 00:25 81920 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-08-28 20:29 . 2011-02-17 12:32 5120 c:\windows\system32\xpsp4res.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 155648 c:\windows\system32\wscript.exe
+ 2004-08-10 18:51 . 2008-05-08 11:24 155648 c:\windows\system32\wscript.exe
+ 2004-08-10 18:51 . 2011-03-04 06:37 420864 c:\windows\system32\vbscript.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 406016 c:\windows\system32\usp10.dll
+ 2004-08-10 18:51 . 2010-04-16 15:36 406016 c:\windows\system32\usp10.dll
- 2004-08-10 18:51 . 2009-03-08 09:34 105984 c:\windows\system32\url.dll
+ 2004-08-10 18:51 . 2011-06-23 18:36 105984 c:\windows\system32\url.dll
+ 2004-08-10 18:51 . 2010-08-27 08:02 119808 c:\windows\system32\t2embed.dll
- 2004-08-10 18:51 . 2009-10-15 16:28 119808 c:\windows\system32\t2embed.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 135168 c:\windows\system32\shsvcs.dll
+ 2004-08-10 18:51 . 2009-07-27 23:17 135168 c:\windows\system32\shsvcs.dll
+ 2004-08-10 18:51 . 2011-01-21 14:44 439296 c:\windows\system32\shimgvw.dll
+ 2004-08-10 18:51 . 2008-05-09 10:53 172032 c:\windows\system32\scrrun.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 172032 c:\windows\system32\scrrun.dll
+ 2004-08-10 18:51 . 2008-05-09 10:53 180224 c:\windows\system32\scrobj.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 180224 c:\windows\system32\scrobj.dll
+ 2004-08-10 18:51 . 2011-04-29 17:25 151552 c:\windows\system32\schannel.dll
+ 2004-08-10 18:51 . 2011-02-09 13:53 270848 c:\windows\system32\sbe.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 270848 c:\windows\system32\sbe.dll
+ 2004-08-10 18:51 . 2010-08-16 08:45 590848 c:\windows\system32\rpcrt4.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 551936 c:\windows\system32\oleaut32.dll
+ 2004-08-10 18:51 . 2010-12-20 17:32 551936 c:\windows\system32\oleaut32.dll
+ 2004-08-10 18:51 . 2010-11-09 14:52 249856 c:\windows\system32\odbc32.dll
- 2004-08-10 18:51 . 2008-04-14 00:12 249856 c:\windows\system32\odbc32.dll
- 2004-08-10 18:51 . 2010-05-06 10:41 206848 c:\windows\system32\occache.dll
+ 2004-08-10 18:51 . 2011-06-23 18:36 206848 c:\windows\system32\occache.dll
+ 2004-08-10 18:51 . 2010-12-09 15:15 718336 c:\windows\system32\ntdll.dll
- 2004-08-10 18:51 . 2008-06-20 17:46 245248 c:\windows\system32\mswsock.dll
+ 2004-08-10 18:51 . 2008-06-20 16:02 245248 c:\windows\system32\mswsock.dll
- 2004-08-10 19:01 . 2008-04-14 00:12 677888 c:\windows\system32\mstsc.exe
+ 2004-08-10 19:01 . 2011-01-27 11:57 677888 c:\windows\system32\mstsc.exe
- 2004-08-10 18:51 . 2010-05-06 10:41 611840 c:\windows\system32\mstime.dll
+ 2004-08-10 18:51 . 2011-06-23 18:36 611840 c:\windows\system32\mstime.dll
+ 2009-03-08 09:32 . 2011-06-23 18:36 602112 c:\windows\system32\msfeeds.dll
+ 2009-11-06 03:17 . 2009-11-06 03:17 297808 c:\windows\system32\mscoree.dll
+ 2006-10-19 02:47 . 2010-03-30 17:24 317440 c:\windows\system32\mp4sdecd.dll
- 2006-10-19 02:47 . 2006-10-19 02:47 317440 c:\windows\system32\MP4SDECD.dll
+ 2004-08-10 18:51 . 2011-02-08 13:33 974848 c:\windows\system32\mfc42u.dll
+ 2004-08-10 18:51 . 2011-02-08 13:33 978944 c:\windows\system32\mfc42.dll
+ 2004-08-10 18:51 . 2010-09-18 06:53 953856 c:\windows\system32\mfc40u.dll
+ 2004-08-10 18:51 . 2010-09-18 06:53 954368 c:\windows\system32\mfc40.dll
- 2004-08-10 18:51 . 2009-06-25 08:25 730112 c:\windows\system32\lsasrv.dll
+ 2004-08-10 18:51 . 2010-12-20 17:26 730112 c:\windows\system32\lsasrv.dll
+ 2004-08-10 18:51 . 2010-12-22 12:34 301568 c:\windows\system32\kerberos.dll
- 2004-08-10 18:51 . 2009-06-25 08:25 301568 c:\windows\system32\kerberos.dll
- 2004-08-10 18:51 . 2009-03-08 09:33 726528 c:\windows\system32\jscript.dll
+ 2004-08-10 18:51 . 2011-03-04 06:37 726528 c:\windows\system32\jscript.dll
+ 2011-08-25 03:59 . 2011-08-25 03:57 157472 c:\windows\system32\javaws.exe
+ 2011-08-25 03:59 . 2011-08-25 03:57 145184 c:\windows\system32\javaw.exe
+ 2011-08-25 03:59 . 2011-08-25 03:57 145184 c:\windows\system32\java.exe
+ 2004-08-10 19:02 . 2011-05-02 15:31 692736 c:\windows\system32\inetcomm.dll
- 2004-08-10 18:51 . 2010-05-06 10:41 184320 c:\windows\system32\iepeers.dll
+ 2004-08-10 18:51 . 2011-06-23 18:36 184320 c:\windows\system32\iepeers.dll
+ 2004-08-10 18:51 . 2011-06-23 18:36 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-10 18:51 . 2010-05-06 10:41 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-10 18:51 . 2011-06-23 12:05 173568 c:\windows\system32\ie4uinit.exe
- 2004-08-10 18:57 . 2011-08-23 18:20 412672 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-10 18:57 . 2011-08-25 01:04 412672 c:\windows\system32\FNTCACHE.DAT
- 2004-08-10 18:51 . 2008-04-14 00:11 186880 c:\windows\system32\encdec.dll
+ 2004-08-10 18:51 . 2011-02-09 13:53 186880 c:\windows\system32\encdec.dll
+ 2004-08-10 18:51 . 2011-02-17 13:18 357888 c:\windows\system32\drivers\srv.sys
+ 2004-08-10 18:51 . 2011-04-21 13:37 105472 c:\windows\system32\drivers\mup.sys
+ 2004-08-10 18:50 . 2011-02-16 13:22 138496 c:\windows\system32\drivers\afd.sys
- 2004-08-10 18:50 . 2008-08-14 10:04 138496 c:\windows\system32\drivers\afd.sys
+ 2004-08-10 18:50 . 2011-03-03 06:55 149504 c:\windows\system32\dnsapi.dll
+ 2008-05-08 11:24 . 2008-05-08 11:24 155648 c:\windows\system32\dllcache\wscript.exe
+ 2010-08-28 20:29 . 2010-07-12 12:55 218112 c:\windows\system32\dllcache\wordpad.exe
+ 2011-04-26 11:07 . 2011-06-20 17:44 293376 c:\windows\system32\dllcache\winsrv.dll
+ 2006-05-10 05:23 . 2011-06-23 18:36 916480 c:\windows\system32\dllcache\wininet.dll
- 2006-05-10 05:23 . 2010-05-06 10:41 916480 c:\windows\system32\dllcache\wininet.dll
+ 2006-09-18 14:15 . 2011-04-30 03:01 758784 c:\windows\system32\dllcache\vgx.dll
+ 2007-12-18 14:40 . 2011-03-04 06:37 420864 c:\windows\system32\dllcache\vbscript.dll
+ 2010-04-16 15:36 . 2010-04-16 15:36 406016 c:\windows\system32\dllcache\usp10.dll
+ 2009-03-08 09:34 . 2011-06-23 18:36 105984 c:\windows\system32\dllcache\url.dll
- 2009-03-08 09:34 . 2009-03-08 09:34 105984 c:\windows\system32\dllcache\url.dll
+ 2010-08-28 20:42 . 2010-08-27 08:02 119808 c:\windows\system32\dllcache\t2embed.dll
- 2010-08-28 20:42 . 2009-10-15 16:28 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-11-05 23:16 . 2011-02-17 13:18 357888 c:\windows\system32\dllcache\srv.sys
+ 2009-07-27 23:17 . 2009-07-27 23:17 135168 c:\windows\system32\dllcache\shsvcs.dll
+ 2011-01-21 14:44 . 2011-01-21 14:44 439296 c:\windows\system32\dllcache\shimgvw.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2008-05-09 10:53 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
+ 2008-12-05 06:54 . 2011-04-29 17:25 151552 c:\windows\system32\dllcache\schannel.dll
+ 2011-02-09 13:53 . 2011-02-09 13:53 270848 c:\windows\system32\dllcache\sbe.dll
+ 2009-04-15 14:51 . 2010-08-16 08:45 590848 c:\windows\system32\dllcache\rpcrt4.dll
+ 2010-12-20 17:32 . 2010-12-20 17:32 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 249856 c:\windows\system32\dllcache\odbc32.dll
- 2009-03-08 09:34 . 2010-05-06 10:41 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-03-08 09:34 . 2011-06-23 18:36 206848 c:\windows\system32\dllcache\occache.dll
+ 2010-08-28 20:42 . 2010-12-09 15:15 718336 c:\windows\system32\dllcache\ntdll.dll
+ 2008-06-20 17:46 . 2008-06-20 16:02 245248 c:\windows\system32\dllcache\mswsock.dll
- 2008-06-20 17:46 . 2008-06-20 17:46 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2006-05-10 05:23 . 2011-06-23 18:36 611840 c:\windows\system32\dllcache\mstime.dll
- 2006-05-10 05:23 . 2010-05-06 10:41 611840 c:\windows\system32\dllcache\mstime.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 102400 c:\windows\system32\dllcache\msjro.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 200704 c:\windows\system32\dllcache\msadox.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 536576 c:\windows\system32\dllcache\msado15.dll
+ 2010-11-09 14:52 . 2010-11-09 14:52 143360 c:\windows\system32\dllcache\msadco.dll
+ 2008-11-12 23:19 . 2011-07-15 13:29 456320 c:\windows\system32\dllcache\mrxsmb.sys
+ 2010-03-30 17:24 . 2010-03-30 17:24 317440 c:\windows\system32\dllcache\mp4sdecd.dll
+ 2006-10-14 08:13 . 2011-02-08 13:33 974848 c:\windows\system32\dllcache\mfc42u.dll
+ 2011-02-08 13:33 . 2011-02-08 13:33 978944 c:\windows\system32\dllcache\mfc42.dll
+ 2010-08-28 20:42 . 2010-12-20 17:26 730112 c:\windows\system32\dllcache\lsasrv.dll
- 2010-08-28 20:42 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2011-01-27 11:57 . 2011-01-27 11:57 677888 c:\windows\system32\dllcache\lhmstsc.exe
+ 2009-06-25 08:25 . 2010-12-22 12:34 301568 c:\windows\system32\dllcache\kerberos.dll
- 2009-06-25 08:25 . 2009-06-25 08:25 301568 c:\windows\system32\dllcache\kerberos.dll
- 2006-05-18 05:24 . 2009-03-08 09:33 726528 c:\windows\system32\dllcache\jscript.dll
+ 2006-05-18 05:24 . 2011-03-04 06:37 726528 c:\windows\system32\dllcache\jscript.dll
+ 2008-11-05 23:07 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2006-05-10 05:22 . 2010-05-06 10:41 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2006-05-10 05:22 . 2011-06-23 18:36 184320 c:\windows\system32\dllcache\iepeers.dll
- 2009-03-08 19:09 . 2010-05-06 10:41 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 19:09 . 2011-06-23 18:36 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 09:32 . 2011-06-23 12:05 173568 c:\windows\system32\dllcache\ie4uinit.exe
+ 2011-02-09 13:53 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
+ 2008-06-20 17:46 . 2011-03-03 06:55 149504 c:\windows\system32\dllcache\dnsapi.dll
+ 2008-05-07 09:07 . 2008-05-07 09:07 135168 c:\windows\system32\dllcache\cscript.exe
+ 2010-04-20 05:51 . 2011-02-15 12:56 290432 c:\windows\system32\dllcache\atmfd.dll
+ 2008-06-20 11:40 . 2011-02-16 13:22 138496 c:\windows\system32\dllcache\afd.sys
- 2008-06-20 11:40 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2004-08-10 18:50 . 2008-05-07 09:07 135168 c:\windows\system32\cscript.exe
- 2004-08-10 18:50 . 2008-04-14 00:11 617472 c:\windows\system32\comctl32.dll
+ 2004-08-10 18:50 . 2010-08-23 16:12 617472 c:\windows\system32\comctl32.dll
+ 2004-08-10 18:50 . 2011-02-15 12:56 290432 c:\windows\system32\atmfd.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-03-31 19:51 . 2010-03-31 19:51 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
- 2010-03-31 19:49 . 2010-03-31 19:49 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2010-09-23 07:25 . 2010-09-23 07:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2010-09-23 08:17 . 2010-09-23 08:17 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
- 2010-03-31 20:32 . 2010-03-31 20:32 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2011-08-25 03:59 . 2011-08-25 03:59 203776 c:\windows\Installer\9f3a12.msi
+ 2011-08-25 03:57 . 2011-08-25 03:57 901120 c:\windows\Installer\9f3a0d.msi
+ 2011-08-25 00:17 . 2010-05-06 10:41 916480 c:\windows\ie8updates\KB2559049-IE8\wininet.dll
+ 2011-08-25 00:17 . 2009-03-08 09:34 105984 c:\windows\ie8updates\KB2559049-IE8\url.dll
+ 2011-08-25 00:17 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2559049-IE8\spuninst\updspapi.dll
+ 2011-08-25 00:17 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2559049-IE8\spuninst\spuninst.exe
+ 2011-08-25 00:17 . 2010-05-06 10:41 206848 c:\windows\ie8updates\KB2559049-IE8\occache.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 611840 c:\windows\ie8updates\KB2559049-IE8\mstime.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 599040 c:\windows\ie8updates\KB2559049-IE8\msfeeds.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 247808 c:\windows\ie8updates\KB2559049-IE8\ieproxy.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 184320 c:\windows\ie8updates\KB2559049-IE8\iepeers.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 743424 c:\windows\ie8updates\KB2559049-IE8\iedvtool.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 387584 c:\windows\ie8updates\KB2559049-IE8\iedkcs32.dll
+ 2011-08-25 00:17 . 2010-05-05 13:30 173056 c:\windows\ie8updates\KB2559049-IE8\ie4uinit.exe
+ 2011-08-25 00:20 . 2009-03-08 09:33 759296 c:\windows\ie8updates\KB2544521-IE8\vgx.dll
+ 2011-08-25 00:20 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2544521-IE8\spuninst\updspapi.dll
+ 2011-08-25 00:20 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2544521-IE8\spuninst\spuninst.exe
+ 2011-08-25 00:22 . 2009-03-08 09:33 420352 c:\windows\ie8updates\KB2510531-IE8\vbscript.dll
+ 2011-08-25 00:22 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2510531-IE8\spuninst\updspapi.dll
+ 2011-08-25 00:22 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2510531-IE8\spuninst\spuninst.exe
+ 2011-08-25 00:22 . 2009-03-08 09:33 726528 c:\windows\ie8updates\KB2510531-IE8\jscript.dll
+ 2008-11-12 23:19 . 2011-07-15 13:29 456320 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2011-08-25 00:27 . 2011-08-25 00:27 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_66d56c7a\System.Drawing.dll
+ 2011-08-24 10:18 . 2010-10-23 00:51 1748992 c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\GdiPlus.dll
+ 2011-08-24 10:31 . 2010-08-23 16:12 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
+ 2004-08-10 18:51 . 2011-06-23 18:36 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-10 18:51 . 2011-01-21 14:44 8462336 c:\windows\system32\shell32.dll
+ 2004-08-10 18:51 . 2010-07-16 12:05 1288192 c:\windows\system32\ole32.dll
+ 2004-08-10 18:51 . 2010-12-09 13:38 2192768 c:\windows\system32\ntoskrnl.exe
+ 2004-08-04 04:59 . 2010-12-09 13:07 2069376 c:\windows\system32\ntkrnlpa.exe
+ 2004-08-10 18:51 . 2010-06-14 07:41 1172480 c:\windows\system32\msxml3.dll
- 2004-08-10 18:51 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll
+ 2004-08-10 19:01 . 2011-02-02 07:58 2067456 c:\windows\system32\mstscax.dll
+ 2004-08-10 18:51 . 2011-07-25 15:17 5969920 c:\windows\system32\mshtml.dll
+ 2007-03-15 23:19 . 2008-03-20 23:06 1480232 c:\windows\system32\LegitCheckControl.dll
+ 2009-03-08 09:32 . 2011-06-23 18:36 1991680 c:\windows\system32\iertutil.dll
+ 2008-11-05 23:15 . 2011-06-02 14:02 1858944 c:\windows\system32\dllcache\win32k.sys
+ 2006-05-10 05:23 . 2011-06-23 18:36 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2008-06-17 19:02 . 2011-01-21 14:44 8462336 c:\windows\system32\dllcache\shell32.dll
+ 2010-07-16 12:05 . 2010-07-16 12:05 1288192 c:\windows\system32\dllcache\ole32.dll
+ 2010-08-28 20:42 . 2010-12-09 13:38 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2010-08-28 20:42 . 2010-12-09 13:07 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-02-08 00:02 . 2010-12-09 13:07 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2010-08-28 20:42 . 2010-12-09 13:42 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-09-13 05:01 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
- 2006-09-13 05:01 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2010-08-28 20:30 . 2009-06-10 14:19 2066432 c:\windows\system32\dllcache\mstscax.dll
+ 2006-05-19 15:08 . 2011-07-25 15:17 5969920 c:\windows\system32\dllcache\mshtml.dll
- 2010-08-28 20:41 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2010-08-28 20:41 . 2010-06-18 13:36 3558912 c:\windows\system32\dllcache\moviemk.exe
+ 2011-02-02 07:58 . 2011-02-02 07:58 2067456 c:\windows\system32\dllcache\lhmstscx.dll
+ 2010-09-23 20:55 . 2010-09-23 20:55 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
- 2010-04-01 16:42 . 2010-04-01 16:42 1265664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2010-09-23 20:55 . 2010-09-23 20:55 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
- 2010-04-01 16:42 . 2010-04-01 16:42 1232896 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2010-09-23 07:26 . 2010-09-23 07:26 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
- 2010-03-31 19:50 . 2010-03-31 19:50 2514944 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2010-09-23 07:25 . 2010-09-23 07:25 2523136 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2010-09-23 20:55 . 2010-09-23 20:55 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
- 2010-04-01 16:42 . 2010-04-01 16:42 2142208 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 1209344 c:\windows\ie8updates\KB2559049-IE8\urlmon.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 5950976 c:\windows\ie8updates\KB2559049-IE8\mshtml.dll
+ 2011-08-25 00:17 . 2010-05-06 10:41 1985536 c:\windows\ie8updates\KB2559049-IE8\iertutil.dll
+ 2010-08-28 20:42 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2010-08-28 20:42 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-02-08 00:02 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2010-08-28 20:42 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2011-08-25 00:26 . 2011-08-25 00:26 1966080 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_5acd645d\System.dll
+ 2011-08-25 00:26 . 2011-08-25 00:26 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_3b158f3e\System.Xml.dll
+ 2011-08-25 00:26 . 2011-08-25 00:26 3018752 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_3d42538d\System.Windows.Forms.dll
+ 2011-08-25 00:27 . 2011-08-25 00:27 1470464 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_3558b1d4\System.Design.dll
+ 2011-08-25 00:27 . 2011-08-25 00:27 3391488 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_47e40684\mscorlib.dll
- 2010-09-02 00:11 . 2010-09-02 00:11 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-08-25 00:25 . 2011-08-25 00:25 1232896 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-08-25 00:25 . 2011-08-25 00:25 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2010-09-02 00:11 . 2010-09-02 00:11 1265664 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
- 2004-08-10 18:51 . 2009-07-14 04:43 10841088 c:\windows\system32\wmp.dll
+ 2004-08-10 18:51 . 2010-08-26 04:36 10841088 c:\windows\system32\wmp.dll
+ 2009-03-08 09:39 . 2011-06-23 18:36 11081728 c:\windows\system32\ieframe.dll
- 2004-08-10 18:51 . 2009-07-14 04:43 10841088 c:\windows\system32\dllcache\wmp.dll
+ 2004-08-10 18:51 . 2010-08-26 04:36 10841088 c:\windows\system32\dllcache\wmp.dll
+ 2010-09-24 19:08 . 2010-09-24 19:08 11430400 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M2416447\M2416447Uninstall.msp
+ 2010-09-24 12:08 . 2010-09-24 12:08 17518080 c:\windows\Installer\998bd3.msp
+ 2011-08-25 00:17 . 2010-05-06 10:41 11076096 c:\windows\ie8updates\KB2559049-IE8\ieframe.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-07-26 15:15 2532680 —-a-w- c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-07-26 2532680]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-16 454784]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-04-18 2334560]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2007-03-15 16:09 460784 —-a-w- c:\program files\DellSupport\DSAgnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 07:41 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-27 06:22 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KodakShareButtonApp]
2011-03-07 17:21 107008 —-a-w- c:\program files\Kodak\KODAK Share Button App\Listener.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhilipsDM]
2005-12-12 18:38 622592 —-a-w- c:\program files\Philips\Philips Device Manager\bin\DeviceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhilipsLime]
2005-09-08 22:10 159744 —-a-w- c:\program files\Philips\Philips Lime Service\bin\LimeAlive.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-15 02:42 1404928 —-a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-09-25 07:11 132496 —-a-w- c:\program files\Java\jre1.6.0_03\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-01-22 20:59 185896 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2/22/2011 8:13 AM 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [3/16/2011 4:03 PM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [1/7/2011 6:41 AM 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [4/5/2011 12:59 AM 297168]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 5:33 AM 269520]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [4/14/2011 9:28 PM 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2/10/2011 7:53 AM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2/10/2011 7:53 AM 27216]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [4/18/2011 5:39 PM 7398752]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [8/22/2011 4:35 PM 1025352]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/21/2011 10:18 PM 41272]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 7:49 AM 227232]
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
mWindow Title = Microsoft Internet Explorer provided by CenturyTel
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TCP: DhcpNameServer = 192.168.1.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
FF - ProfilePath - c:\documents and settings\Painter\Application Data\Mozilla\Firefox\Profiles\lqh4t2mc.default\
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG10\Firefox4
FF - Ext: AVG Security Toolbar em:version=7.007.026.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-26 05:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(2216)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\HPZipm12.exe
c:\program files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
c:\program files\AVG\AVG10\avgui.exe
.
**************************************************************************
.
Completion time: 2011-08-26 05:20:13 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-26 10:20
ComboFix2.txt 2011-08-25 00:16
.
Pre-Run: 7,760,420,864 bytes free
Post-Run: 7,750,418,432 bytes free
.
- - End Of File - - 2DDA3E50CA49637540F6F53999AEAA33


Yes, I created the folder myself to store all of the things that I needed to download.
Hello karamazov

Yes, I created the folder myself to store all of the things that I needed to download.

:thumbup:


  • Temporary File Cleaner


    • Download TFC to your desktop.
    • Close any open windows.
    • Double click the TFC icon to run the program.
    • TFC will close all open programs itself in order to run.
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish.
    • Once complete it should automatically reboot your machine.
    • If your machine does not reboot automatically, manually reboot to ensure a complete clean.
    • Note: After running TFC your machine may take slightly longer to boot the first time. This is normal.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please update your Java


    • Click on "Start", then on "Control Panel".
    • Go to "Add or Remove Programs" and uninstall any previous versions of Java that you find (Java 2 Runtime Environment, SE v1.4.2_03 and Java™ 6 Update 3).
    • Reboot your computer.
    • Next, download the latest version of Java by clicking here
    • Scroll down the page until you reach "Java Platform Standard Edition - Java SE 6 Update 27".
    • Beneath this and to the right, you will see a button marked "JRE Download ".
    • Click the "JRE Download " button.
    • Accept the license agreement.
    • You do not have to register if you do not want to (the registration step is optional).
    • Scroll down and click on the file called jre-6u27-windows-i586.exe located next to "Windows x86 Offline".
    • Save the file to your desktop, Do not select Run.
    • Double click on the saved file (jre-6u27-windows-i586.exe) to install the update.
    • Delete the downloaded installation file after completing the above procedure and reboot your system if not prompted to do so.

  • Please run the following scan


    • Note:Internet Explorer is preferred for this scan, although it will run with other browsers.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the MBAM log along with the ESET log in your next reply and let me know how the machine is running now.
Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7588 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 8/27/2011 2:12:47 PM mbam-log-2011-08-27 (14-12-47).txt Scan type: Quick scan Objects scanned: 197178 Time elapsed: 13 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\Painter\application data\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[removed] (Adware.GamesVance) -> Quarantined and deleted successfully. Files Infected: (No malicious items detected) C:\asquared\a2quarantine\575D4B93A6D666A7F580438A8C198C3D8E3C60C4.A2Q probably a variant of Win32/Agent.JGBBHSC trojan C:\i386\GTDownDE_87.ocx probably a variant of Win32/Adware.Agent.LCKGTSG application C:\WINDOWS\system32\drivers\etc\hosts.20110822-181603.backup Win32/Qhost trojan C:\WINDOWS\system32\drivers\etc\hosts.20110823-052050.backup Win32/Qhost trojan C:\WINDOWS\system32\drivers\etc\hosts.20110823-052912.backup Win32/Qhost trojan C:\WINDOWS\system32\drivers\etc\hosts.20110824-054531.backup Win32/Qhost trojan The computer seems to be running faster and much more reliable than before. It'll stay consistantly on the web. Still very slow but better.
Hello karamazov

Thank you for the logs.

The computer seems to be running faster and much more reliable than before. It'll stay consistantly on the web. Still very slow but better.

Glad to hear that things are getting better. Your speed issues may be related to the amount of RAM you have installed. We will try to address this is due course. ESET has made a number of detections - lets take care of those now:

  • Please download OTM


  • Please download OTM by OldTimer by clicking here.
  • Save the file (called OTM.exe) to your desktop.
  • Double click on the OTM.exe icon to run the program. (Note: If you are running on Vista/Windows 7, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


:Processes 
explorer.exe

:Files
C:\asquared\a2quarantine\575D4B93A6D666A7F580438A8C198C3D8E3C60C4.A2Q
C:\i386\GTDownDE_87.ocx
C:\WINDOWS\system32\drivers\etc\hosts.20110822-181603.backup
C:\WINDOWS\system32\drivers\etc\hosts.20110823-052050.backup
C:\WINDOWS\system32\drivers\etc\hosts.20110823-052912.backup
C:\WINDOWS\system32\drivers\etc\hosts.20110824-054531.backup

:Commands
[Purity]
[EmptyTemp]
[Emptyflash]
[Start Explorer]
[Reboot]




  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM.
  • Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File -> Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Please post the OTM log along with a new DDS log in your next reply.
All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== FILES ========== C:\asquared\a2quarantine\575D4B93A6D666A7F580438A8C198C3D8E3C60C4.A2Q moved successfully. C:\i386\GTDownDE_87.ocx moved successfully. C:\WINDOWS\system32\drivers\etc\hosts.20110822-181603.backup moved successfully. C:\WINDOWS\system32\drivers\etc\hosts.20110823-052050.backup moved successfully. C:\WINDOWS\system32\drivers\etc\hosts.20110823-052912.backup moved successfully. C:\WINDOWS\system32\drivers\etc\hosts.20110824-054531.backup moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Application Data User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 0 bytes User: mom ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Painter ->Temp folder emptied: 68445373 bytes ->Temporary Internet Files folder emptied: 3386596 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 39284031 bytes ->Flash cache emptied: 566 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 395 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 106.00 mb OTM by OldTimer - Version 3.1.18.0 log created on 08282011_151645 . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 15:26:38.73 on Sun 08/28/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_27 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1278.633 [GMT -5:00] . AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\AVG\AVG10\avgtray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Documents and Settings\Painter\Desktop\removal\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html mWindow Title = Microsoft Internet Explorer provided by CenturyTel uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = localhost;*.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\painter\applic~1\mozilla\firefox\profiles\lqh4t2mc.default\ FF - prefs.js: network.proxy.type - 0 FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll FF - component: c:\program files\avg\avg10\firefox4\components\avgssff5.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 297168] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-4-18 7398752] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-4-14 134480] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 27216] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-8-22 1025352] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-8-21 41272] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] . =============== Created Last 30 ================ . 2011-08-28 20:16:45 ——– d—–w- C:\_OTM 2011-08-27 21:46:02 ——– d—–w- c:\docume~1\painter\applic~1\StarBurn Japanese Edition 2011-08-27 21:45:28 721904 —-a-w- c:\windows\system32\drivers\sptd.sys 2011-08-27 19:36:47 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-08-27 19:34:01 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-08-27 19:33:53 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2011-08-27 19:33:53 785368 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-08-27 19:33:53 478168 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-08-27 19:33:53 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll 2011-08-27 19:33:53 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll 2011-08-27 19:33:53 1846232 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2011-08-27 19:33:53 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll 2011-08-27 10:52:13 ——– d—–w- c:\program files\ESET 2011-08-27 10:39:49 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-08-25 03:59:14 476904 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll 2011-08-25 03:59:14 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-08-24 21:12:45 ——– d-sha-r- C:\cmdcons 2011-08-24 21:09:33 98816 —-a-w- c:\windows\sed.exe 2011-08-24 21:09:33 518144 —-a-w- c:\windows\SWREG.exe 2011-08-24 21:09:33 256000 —-a-w- c:\windows\PEV.exe 2011-08-24 21:09:33 208896 —-a-w- c:\windows\MBR.exe 2011-08-24 10:39:22 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-08-24 10:32:15 954368 ——w- c:\windows\system32\dllcache\mfc40.dll 2011-08-24 10:32:14 953856 ——w- c:\windows\system32\dllcache\mfc40u.dll 2011-08-24 10:31:14 617472 ——w- c:\windows\system32\dllcache\comctl32.dll 2011-08-24 10:28:37 40960 ——w- c:\windows\system32\dllcache\ndproxy.sys 2011-08-24 10:20:36 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys 2011-08-24 10:20:06 45568 ——w- c:\windows\system32\dllcache\wab.exe 2011-08-24 10:18:55 139656 ——w- c:\windows\system32\dllcache\rdpwd.sys 2011-08-24 10:18:42 105472 ——w- c:\windows\system32\dllcache\mup.sys 2011-08-24 09:48:20 23552 —-a-w- c:\windows\system32\fxsmon.dll 2011-08-24 09:48:20 23552 —-a-w- c:\windows\system32\dllcache\fxsmon.dll 2011-08-23 10:09:19 ——– d—–w- c:\windows\system32\scripting 2011-08-23 10:09:18 ——– d—–w- c:\windows\l2schemas 2011-08-23 10:09:16 ——– d—–w- c:\windows\system32\en 2011-08-23 10:09:15 ——– d—–w- c:\windows\system32\bits 2011-08-23 09:57:50 ——– d—–w- c:\windows\network diagnostic 2011-08-23 09:52:24 ——– d—–w- c:\windows\EHome 2011-08-23 09:47:51 ——– d-sh–w- c:\documents and settings\painter\IECompatCache 2011-08-23 09:47:21 ——– d-sh–w- c:\documents and settings\painter\PrivacIE 2011-08-23 09:46:09 ——– d-sh–w- c:\documents and settings\painter\IETldCache 2011-08-23 09:38:21 ——– d—–w- c:\windows\ie8updates 2011-08-23 09:37:34 602112 ——w- c:\windows\system32\dllcache\msfeeds.dll 2011-08-23 09:37:34 55296 ——w- c:\windows\system32\dllcache\msfeedsbs.dll 2011-08-23 09:37:34 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll 2011-08-23 09:37:34 1991680 ——w- c:\windows\system32\dllcache\iertutil.dll 2011-08-23 09:37:34 12800 ——w- c:\windows\system32\dllcache\xpshims.dll 2011-08-23 09:37:34 11081728 ——w- c:\windows\system32\dllcache\ieframe.dll 2011-08-23 09:37:33 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll 2011-08-23 09:35:26 ——– dc-h–w- c:\windows\ie8 2011-08-22 23:59:20 ——– d—–w- c:\windows\pss 2011-08-22 23:52:49 ——– d—–w- c:\docume~1\painter\locals~1\applic~1\AVG Security Toolbar 2011-08-22 21:56:28 ——– d—–w- C:\malware 2011-08-22 21:39:01 ——– d—–w- C:\$AVG 2011-08-22 21:37:45 ——– d—–w- c:\docume~1\painter\applic~1\AVG10 2011-08-22 21:35:15 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar 2011-08-22 21:31:23 ——– d—–w- c:\windows\system32\drivers\AVG 2011-08-22 21:31:23 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG10 2011-08-22 21:30:07 ——– d—–w- c:\program files\AVG 2011-08-22 21:16:39 ——– d–h–w- c:\docume~1\alluse~1\applic~1\Common Files 2011-08-22 21:16:14 ——– d—–w- c:\docume~1\alluse~1\applic~1\MFAData 2011-08-22 03:27:51 ——– d—–w- c:\docume~1\painter\applic~1\Malwarebytes 2011-08-22 03:18:20 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-08-22 03:18:19 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2011-08-22 03:18:16 22712 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-08-22 03:18:16 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-08-22 03:17:30 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys 2011-08-22 03:17:11 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys 2011-08-20 17:00:46 ——– d—–w- C:\3fbc396e7c181f3b61a46d0903cc1652 . ==================== Find3M ==================== . 2011-06-23 18:36:30 916480 —-a-w- c:\windows\system32\wininet.dll 2011-06-23 18:36:30 43520 —-a-w- c:\windows\system32\licmgr10.dll 2011-06-23 18:36:30 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-06-23 12:05:13 385024 —-a-w- c:\windows\system32\html.iec 2011-06-20 17:44:52 293376 —-a-w- c:\windows\system32\winsrv.dll 2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 15:29:33.35 ===============
Hello karamazov

Your logs appear to be clean :)

We will take care of some installed foistware and then remove the tools we used to clean your machine. I will provide you with some additional programs that may address your system speed issues:

  • Foistware


    • I can see from your log that you have Viewpoint Media Player installed.
    • Viewpoint Media Player is considered as foistware rather than malware since it is installed without user's approval but doesn't spy or do anything "bad".
    • It is recommended that you remove Viewpoint products. However, this choice is up to you.
    • To remove these programs, click "Start" and then on "Control Panel" and then on "Add or Remove Programs".
    • Select Viewpoint Media Player and click on "Remove".

  • Please Uninstall Combofix


    • Click on "Start" and then on "Run".
    • Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.

  • Please perform the following cleanup procedure


    • Double click on the OTM.exe icon on your desktop to run the program.
    • Once OTM has opened, click on the "CleanUp!" button.
    • Follow any prompts that you receive.

  • Removal of Tools

    • You no longer need TDSSKiller, MGADiag or CKScanner. Please delete them from your machine.

  • Defragment your hard drive



  • StartupLight


    • You may wish to try StartupLite. Simply download this tool to your desktop and run it.
    • It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup.
    • This will result in fewer programs running when you boot your system, and should improve performance.
    • You can find it here: http://www.malwarebytes.org/startuplite.php


    More information can be found in the link below:

    http://www.bleepingcomputer.com/forums/ind…st&p=487112


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • You can download Firefox from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.
    • Please Note: IE9 is not configured to run on XP machines.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.
Thank you for your help, good sir :) I appreciate it. Ive followed all of the instructions with the exception of the auslogic defrag. It just wouldnt install
Hello karamazov

Ive followed all of the instructions with the exception of the auslogic defrag. It just wouldnt install

An alternative to Auslogics is Puran:

  • Puran Disk Defragmenter


  • Download and run Puran Disc Defragmenter.
  • The image provided below demonstrates how to perform a boot defrag and disk check:

[external image: Posted Image]

Thank you for your help

You are Very Welcome :)

Glad we could be of assistance

Best wishes
JonTom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI