I had started a topic, but it was closed before I had a chance to read it. Please help me again, and I will be sure to be prompt on answering threads.
My computer is extremely slow and I need direction on how I can speed it up.
Hi
Nurse_Shagnasty and welcome to
WhatTheTech forums!
I'm
Sunyata and I will be helping you with your computer problems.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.
Please
read the following guidelines which
will help to make cleaning your machine
easier :
Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.The fixes I will give you are specific to your problem and should only be used for this issue on this machine. Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask! Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone. PLEASE DO NOT install/uninstall any programs unless asked to .PLEASE DO NOT run any malware scans other than those requested. Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed! I will reply back shortly with instructions
Note to Vista and Windows 7 users:
These tools MUST be run from the executable. (.exe) every time you run them These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator" )
Hello Nurse_Shagnasty
Please Download
DDS by sUBs to your desktop.
Your antivirus software might question the file. If it does, turn it off please
Double click DDS.scr to run it and wait for the scan to finish When finished DDS.txt will open A small while later, a prompt will open. Answer Yes DDS will continue scanning When done, Attach.txt will open Post DDS.txt and attach Attach.txt
Please
download aswMBR to your desktop.
[external image: Posted Image]
In your next reply please include:
DDS.txt Attach.txt aswMBR.log
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Run by [removed] at 10:54:10 on 2011-10-12
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.378 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SelectRebates\SelectRebates.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICKA.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Microsoft Office\Office12\GROOVE.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Shaughnessy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\DOCUME~1\SHAUGH~1\LOCALS~1\Temp\InteleViewer\CViewer\InteleViewer.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Shaughnessy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\McAfee Security Scan\2.0.181\McUICnt.exe
C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
C:\Documents and Settings\Shaughnessy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Documents and Settings\Shaughnessy\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: ShopAtHomeIEHelper Class: {e8daaa30-6caa-4b58-9603-8e54238219e2} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll
TB: ShopAtHome.com Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [EPSON Stylus Photo R280 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticka.exe /fu "c:\windows\temp\E_S3A0.tmp" /EF "HKCU"
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [Google Update] "c:\documents and settings\shaughnessy\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SelectRebates] c:\program files\selectrebates\SelectRebates.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [CanonSolutionMenuEx] c:\program files\canon\solution menu ex\CNSEMAIN.EXE /logon
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\shaugh~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\shaugh~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office12\GROOVE.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} - hxxp://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{211DDCF8-19A1-4967-ADF7-CFD46C7F76CA} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{5B909B18-AF26-4D58-A9D3-1D1B4B51A11B} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{7B2799DF-8D41-4C90-9803-A249DD386864} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{828293BA-C073-4BA2-BE77-1E6B5E049A12} : DhcpNameServer = [removed] [removed]
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\shaughnessy\application data\mozilla\firefox\profiles\a1h6040u.default\
FF - plugin: c:\documents and settings\shaughnessy\local settings\application data\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\documents and settings\shaughnessy\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\documents and settings\shaughnessy\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: ShopAtHome.com Intelligent Shopping Toolbar: [removed] - %profile%\extensions\[removed]
.
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 151216]
R1 MpKsl28269f12;MpKsl28269f12;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5468ecbe-e848-4217-8dfd-c1d6ed3ea489}\mpksl28269f12.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5468ecbe-e848-4217-8dfd-c1d6ed3ea489}\MpKsl28269f12.sys [?]
R1 MpKsl3e307e4b;MpKsl3e307e4b;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7e42141e-0473-461d-afca-75f4400d157c}\MpKsl3e307e4b.sys [2011-10-11 28752]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
R3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\system32\drivers\SMCWGU.sys [2009-7-12 408064]
S1 MpKsl0552c482;MpKsl0552c482;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c0c917a2-6ac7-4091-8ce1-eece708bb4f1}\mpksl0552c482.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c0c917a2-6ac7-4091-8ce1-eece708bb4f1}\MpKsl0552c482.sys [?]
S1 MpKsl28a32ed9;MpKsl28a32ed9;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a0b7b329-cee1-46cf-ac15-b5b305a748f4}\mpksl28a32ed9.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a0b7b329-cee1-46cf-ac15-b5b305a748f4}\MpKsl28a32ed9.sys [?]
S1 MpKsl53901d7e;MpKsl53901d7e;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8df664cc-b8a6-43ec-8f4f-16e65b39c85f}\mpksl53901d7e.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8df664cc-b8a6-43ec-8f4f-16e65b39c85f}\MpKsl53901d7e.sys [?]
S1 MpKsl59285386;MpKsl59285386;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{87dc5c6f-35e6-4709-a913-3d66a33a3536}\mpksl59285386.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{87dc5c6f-35e6-4709-a913-3d66a33a3536}\MpKsl59285386.sys [?]
S1 MpKsl941c3eb5;MpKsl941c3eb5;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0ff74d9c-ea9f-4162-a723-a04bc889e1ba}\mpksl941c3eb5.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{0ff74d9c-ea9f-4162-a723-a04bc889e1ba}\MpKsl941c3eb5.sys [?]
S1 MpKsl94821316;MpKsl94821316;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{07dbb2e3-252c-4938-91e1-56d69503b259}\mpksl94821316.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{07dbb2e3-252c-4938-91e1-56d69503b259}\MpKsl94821316.sys [?]
S1 MpKslbec7b65e;MpKslbec7b65e;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{447f94a0-3676-4059-b926-b7bf951d34b7}\mpkslbec7b65e.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{447f94a0-3676-4059-b926-b7bf951d34b7}\MpKslbec7b65e.sys [?]
S1 MpKslcd1b138e;MpKslcd1b138e;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e1b8696f-5deb-4d25-bddd-7be6d5a7ad95}\mpkslcd1b138e.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e1b8696f-5deb-4d25-bddd-7be6d5a7ad95}\MpKslcd1b138e.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-9-20 133104]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-9-20 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-8-23 41272]
.
=============== Created Last 30 ================
.
2011-10-12 01:58:33 28752 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7e42141e-0473-461d-afca-75f4400d157c}\MpKsl3e307e4b.sys
2011-10-12 01:58:04 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7e42141e-0473-461d-afca-75f4400d157c}\offreg.dll
2011-10-12 01:57:56 7269712 ——w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7e42141e-0473-461d-afca-75f4400d157c}\mpengine.dll
2011-10-10 04:13:39 ——– d—–w- C:\LEMMINGS
2011-09-26 23:39:34 ——– d—–w- c:\documents and settings\shaughnessy\application data\com.zoodles.3B7D4B2F97D0C2BDB13554D0687ECC70A3734EDD.1
2011-09-26 23:39:22 ——– d—–w- c:\program files\Zoodles
2011-09-21 23:59:53 ——– d—–w- c:\documents and settings\shaughnessy\application data\Unity
2011-09-21 23:51:44 ——– d—–w- c:\documents and settings\shaughnessy\local settings\application data\Unity
.
==================== Find3M ====================
.
2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-07-15 13:29:31 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.
============= FINISH: 10:55:17.78 ===============
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-12 11:04:09
—————————–
11:04:09.578 OS Version: Windows 5.1.2600 Service Pack 3
11:04:09.578 Number of processors: 2 586 0x404
11:04:09.578 ComputerName: COMPUTER UserName:
11:04:11.578 Initialize success
11:15:48.843 AVAST engine defs: 11101201
11:16:02.109 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
11:16:02.109 Disk 0 Vendor: WDC_WD600BB-53CAA1 17.07W17 Size: 57241MB BusType: 3
11:16:02.109 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
11:16:02.109 Disk 1 Vendor: QUANTUM_BIGFOOT_CY4320 A03.0500 Size: 4134MB BusType: 3
11:16:02.109 Disk 2 (boot) \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP1T0L0-18
11:16:02.109 Disk 2 Vendor: Maxtor_7L250S0 BACE1G10 Size: 238418MB BusType: 3
11:16:04.140 Disk 2 MBR read successfully
11:16:04.140 Disk 2 MBR scan
11:16:04.187 Disk 2 Windows XP default MBR code
11:16:04.187 Disk 2 scanning sectors +488263545
11:16:04.390 Disk 2 scanning C:\WINDOWS\system32\drivers
11:16:14.015 Service scanning
11:16:14.359 Service MpKsl3e307e4b C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E42141E-0473-461D-AFCA-75F4400D157C}\MpKsl3e307e4b.sys **LOCKED** 32
11:16:14.953 Modules scanning
11:16:28.390 Disk 2 trace - called modules:
11:16:28.406 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
11:16:28.421 1 nt!IofCallDriver -> \Device\Harddisk2\DR2[0x86756ab8]
11:16:28.421 3 CLASSPNP.SYS[f7652fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-18[0x8677fb00]
11:16:29.000 AVAST engine scan C:\WINDOWS
11:16:41.875 AVAST engine scan C:\WINDOWS\system32
11:18:27.859 AVAST engine scan C:\WINDOWS\system32\drivers
11:18:43.671 AVAST engine scan C:\Documents and Settings\Shaughnessy
11:22:11.093 Disk 2 MBR has been saved successfully to "C:\Documents and Settings\Shaughnessy\Desktop\MBR.dat"
11:22:11.093 The log file has been saved successfully to "C:\Documents and Settings\Shaughnessy\Desktop\aswMBR.txt"
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-10-12 11:04:09
—————————–
11:04:09.578 OS Version: Windows 5.1.2600 Service Pack 3
11:04:09.578 Number of processors: 2 586 0x404
11:04:09.578 ComputerName: COMPUTER UserName:
11:04:11.578 Initialize success
11:15:48.843 AVAST engine defs: 11101201
11:16:02.109 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
11:16:02.109 Disk 0 Vendor: WDC_WD600BB-53CAA1 17.07W17 Size: 57241MB BusType: 3
11:16:02.109 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c
11:16:02.109 Disk 1 Vendor: QUANTUM_BIGFOOT_CY4320 A03.0500 Size: 4134MB BusType: 3
11:16:02.109 Disk 2 (boot) \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP1T0L0-18
11:16:02.109 Disk 2 Vendor: Maxtor_7L250S0 BACE1G10 Size: 238418MB BusType: 3
11:16:04.140 Disk 2 MBR read successfully
11:16:04.140 Disk 2 MBR scan
11:16:04.187 Disk 2 Windows XP default MBR code
11:16:04.187 Disk 2 scanning sectors +488263545
11:16:04.390 Disk 2 scanning C:\WINDOWS\system32\drivers
11:16:14.015 Service scanning
11:16:14.359 Service MpKsl3e307e4b C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7E42141E-0473-461D-AFCA-75F4400D157C}\MpKsl3e307e4b.sys **LOCKED** 32
11:16:14.953 Modules scanning
11:16:28.390 Disk 2 trace - called modules:
11:16:28.406 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
11:16:28.421 1 nt!IofCallDriver -> \Device\Harddisk2\DR2[0x86756ab8]
11:16:28.421 3 CLASSPNP.SYS[f7652fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-18[0x8677fb00]
11:16:29.000 AVAST engine scan C:\WINDOWS
11:16:41.875 AVAST engine scan C:\WINDOWS\system32
11:18:27.859 AVAST engine scan C:\WINDOWS\system32\drivers
11:18:43.671 AVAST engine scan C:\Documents and Settings\Shaughnessy
11:22:11.093 Disk 2 MBR has been saved successfully to "C:\Documents and Settings\Shaughnessy\Desktop\MBR.dat"
11:22:11.093 The log file has been saved successfully to "C:\Documents and Settings\Shaughnessy\Desktop\aswMBR.txt"
11:35:04.250 AVAST engine scan C:\Documents and Settings\All Users
11:36:24.578 Scan finished successfully
11:37:17.593 Disk 2 MBR has been saved successfully to "C:\Documents and Settings\Shaughnessy\Desktop\MBR.dat"
11:37:17.640 The log file has been saved successfully to "C:\Documents and Settings\Shaughnessy\Desktop\aswMBR.txt"
Hello Nurse_Shagnasty
Did you intentionally install your shop-at-home-toolbar and rebates finder? Do you use them? They are known as Adware and many people find them undesirable. If you use them, that is fine. Otherwise you may wish to uninstall them.
You actually have many toolbars and browser helpers installed on your machine. Your machine will probably run faster and your internet browsing experience cleaner if you would minimise your browser add-ons.
First,
Please go to Start->Run on you computer and type in appwiz.cpl and press "Enter"
When the Add/Remove Programs wizard comes up, uninstall:
McAfee Security Scan Plus
It is Adware designed to sell you McAfee products.
Next,
Optionally uninstall any of the following you do not use or need:
Coupon Printer for Windows ShopAtHome.com Toolbar The Weather Channel Toolbar Yahoo! BrowserPlus 2.9.8
Next,
Reboot your computer
How is the computer running now? Are there any issues?
about to reboot, also having issues with the internet. I have a good connection, yet pages wont load. something about DNS server
Hi Nurse_Shagnasty
Make sure your DNS service is started:
Go to Start > Run and type Services.msc Scroll down and select DNS Client If you are given the option to Start service, then click that
If you are still having problems with page loading, please post the
exact error message you receive and the browser that displays it.
Hi Nurse_Shagnasty
Do you still need help with this?
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic