This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible malware, need clarification [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My internet's been running significantly slower than it normally is. I am unable to load certain websites and it takes a long time to load when using Google Image Search. Download speed has also slowed down and sometimes the download just stops and then cancels. It happens on several websites so I know it wasn't the website's server that was the problem. I primarily use Firefox so I tried IE and I had the same problems. I found a solution on the internet that said that maybe I had a problem with the DNS settings and this is what I did using cmd: ipconfig /flushdns ipconfig /release ipconfig /renew ipconfig /registerdns netsh int ip reset reset.txt netsh winsock reset catalog Then I resetted the computer but no change. I full scanned my computer with avast, Spybot, CWShredder and Stinger but they found nothing. I also used CCleaner but nothing changed as well. The only other thing I haven't tried was calling my ISP and using HiJackThis so I thought I might try that first. Here's my log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 2:49:42 PM, on 12/31/2011 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Alwil Software\Avast5\avastUI.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\TUProgSt.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Vtune\TBPanel.exe C:\Program Files\BitTorrent\BitTorrent.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Samsung\Kies\KiesTrayAgent.exe C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\CircleDock0.9.2Alpha8.2\CircleDock.exe C:\Program Files\Mozilla Firefox 4.0 Beta 12\firefox.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox 4.0 Beta 12\plugin-container.exe C:\windows-kb890830-v3.5.exe d:\9b3c134dd61d352e9504655b\mrtstub.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\MRT.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8777;https=127.0.0.1:8777; O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Movie_Edit_Pro_14_PLUS_Download_version\TrayServer.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [TBPanel] C:\Program Files\Vtune\TBPanel.exe /A O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\BitTorrent.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [KiesHelper] C:\Program Files\Samsung\Kies\KiesHelper.exe /s O4 - HKCU\..\Run: [KiesTrayAgent] C:\Program Files\Samsung\Kies\KiesTrayAgent.exe O4 - HKCU\..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe O4 - Startup: Shortcut to CircleDock.lnk = C:\CircleDock0.9.2Alpha8.2\CircleDock.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - D:\Games\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe – End of file - 7122 bytes I'm not a computer expert but looking at the log file, it doesn't look like there's anything wrong with my computer. Just need clarification on this :D
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


Run Hijack This
  • Double click on the icon on your desktop to launch Hijack This
  • Click on the Scan button
  • When the scan has finished, please put a check in the box next to the following item:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:8777;https=127.0.0.1:8777;
  • Make sure all other windows, including your browser are closed, and then click on the Fix Checked button
If you are not prompted to do so, please reboot your computer after the fix has completed.





Download CKScanner© by askey127 and save to your desktop. Click here.
  • Double click on CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File. You will be prompted, click OK.
  • Post the contents of ckfiles.txt in your reply, it is located on your desktop.




P2P - I see you have P2P software ( BitTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.

If you choose to leave them on the machine, please refrain from using them while we are cleaning the machine to prevent further infection.



The fix in HijackThis is just a "quick fix" to hopefully give you a bit of immediate relief from the slowness. (It may not.) This is not really the tool we prefer to use to find malware these days. Let me know if this helped as well as posting the requested log and we'll go from there.
Hey there! Sorry I took a while to reply, I thought that after a few days after posting that people agreed with my guess that there was nothing wrong. Thank you for taking the time to reply, I realize now that you guys must be really busy. Anyway, I did as you asked with HiJackThis and uninstalled BitTorrent. Here's the result of the ckscanner: CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.MN.11.JNAPIE —– EOF —– Also the computer has started moving faster now, it's just a bit slow on startup because Tune Up Utilities said that the prefetch data was deleted. But after searching a bit, I discovered that Tune Up deletes the prefetch data for some reason. But that's just a speed issue right, nothing serious? Sorry again for taking so long
I was hoping that you'd get a little improvement from the fix in HijackThis, but I knew that wasn't going to be all that we needed to do. I was quite sure that we were going to need to so some more scans and some fixes from there.

And, to answer your question about the prefetch data - when prefetch data is deleted in XP, the first few reboots can often be slow. After a couple of reboots, there would be no reason that it should continue to be slow, as the prefetch data is rebuilt again

I would like to ask a very important question here though. I see that you are running XP SP2. Is there any reason that you have chosen not to update to Service Pack 3?

Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.



HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt
Oh sorry I should have mentioned earlier, I updated to SP3 a few days ago. Should I continue with the instructions? I had TDSSKiller and used it last January 2 and it found and deleted C:\WINDOWS\system32\Drivers\sptd.sys I ran it again January 7 and it found nothing. Oh and startup is getting faster like you said :D
Ok here you go :D DDS.txt . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 23:05:33 on 2012-01-12 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1983.1146 [GMT -8:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Alwil Software\Avast5\avastUI.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Vtune\TBPanel.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\System32\TUProgSt.exe C:\Program Files\Samsung\Kies\KiesTrayAgent.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe C:\CircleDock0.9.2Alpha8.2\CircleDock.exe C:\Program Files\Mozilla Firefox 4.0 Beta 12\firefox.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Mozilla Firefox 4.0 Beta 12\plugin-container.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com.ph/intl/en/ uSearch Page = uInternet Connection Wizard,ShellNext = hxxp://www.google.com.ph/intl/en/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll uRun: [TBPanel] c:\program files\vtune\TBPanel.exe /A uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [KiesHelper] c:\program files\samsung\kies\KiesHelper.exe /s uRun: [KiesTrayAgent] c:\program files\samsung\kies\KiesTrayAgent.exe uRun: [KiesPDLR] c:\program files\samsung\kies\external\firmwareupdate\KiesPDLR.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet StartupFolder: c:\docume~1\user\startm~1\programs\startup\rainme~1.lnk - c:\program files\rainmeter\Rainmeter.exe StartupFolder: c:\docume~1\user\startm~1\programs\startup\shortc~1.lnk - c:\circledock0.9.2alpha8.2\CircleDock.exe IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{146D3573-C13C-4EB5-A962-E6D6F8F70630} : DhcpNameServer = 192.168.1.1 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll LSA: Notification Packages = scecli scecli Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\k52tthno.default\ FF - prefs.js: network.proxy.type - 4 FF - plugin: c:\documents and settings\user\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox 4.0 beta 12\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox 4.0 beta 12\plugins\npwachk.dll . —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . ============= SERVICES / DRIVERS =============== . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-5-25 435032] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-12-28 314456] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-12-28 20568] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-12-28 44768] R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2012-1-8 2253120] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2010-12-18 119656] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-12-18 1684736] S3 cpuz134;cpuz134;\??\c:\docume~1\user\locals~1\temp\cpuz134\cpuz134_x32.sys –> c:\docume~1\user\locals~1\temp\cpuz134\cpuz134_x32.sys [?] S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\games\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832] S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\drivers\ssudbus.sys [2011-10-28 77624] S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-10-28 20032] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\magix\common\database\bin\fbserver.exe [2011-10-30 1527900] S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\drivers\ssudmdm.sys [2011-10-28 181432] S3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\drivers\ssudobex.sys [2011-10-28 181432] . =============== Created Last 30 ================ . 2012-01-13 06:57:10 607260 ——r- C:\dds.scr 2012-01-10 07:05:53 458240 —-a-w- C:\CKScanner.exe 2012-01-09 04:41:46 602432 —-a-w- c:\windows\system32\easyupdatusapiu.dll 2012-01-09 04:40:53 876136 —-a-w- c:\windows\system32\nvhdagenco3220102.dll 2012-01-09 04:40:49 919872 —-a-w- c:\windows\system32\nvdispco32.dll 2012-01-09 04:40:49 877376 —-a-w- c:\windows\system32\nvgenco32.dll 2012-01-08 19:48:57 229672 —-a-w- C:\CrucialScan.exe 2012-01-08 04:48:09 ——– d—–w- c:\documents and settings\all users\Uniblue 2012-01-04 05:52:30 ——– d—–w- c:\windows\SxsCaPendDel 2012-01-03 17:56:43 81920 -c—-w- c:\windows\system32\dllcache\fontsub.dll 2012-01-03 17:56:43 119808 -c—-w- c:\windows\system32\dllcache\t2embed.dll 2012-01-03 17:56:14 473600 -c—-w- c:\windows\system32\dllcache\fastprox.dll 2012-01-03 17:56:14 401408 -c—-w- c:\windows\system32\dllcache\rpcss.dll 2012-01-03 17:56:14 284160 -c—-w- c:\windows\system32\dllcache\pdh.dll 2012-01-03 17:56:14 227840 -c—-w- c:\windows\system32\dllcache\wmiprvse.exe 2012-01-03 17:56:14 110592 -c—-w- c:\windows\system32\dllcache\services.exe 2012-01-03 17:56:13 617472 -c—-w- c:\windows\system32\dllcache\advapi32.dll 2012-01-03 17:56:13 453120 -c—-w- c:\windows\system32\dllcache\wmiprvsd.dll 2012-01-03 17:54:48 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys 2012-01-03 17:48:58 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll 2012-01-03 17:45:03 456320 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys 2012-01-03 17:44:52 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll 2012-01-03 17:37:41 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys 2012-01-03 17:35:40 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys 2012-01-03 17:35:28 105472 -c—-w- c:\windows\system32\dllcache\mup.sys 2012-01-03 17:19:15 852480 -c—-w- c:\windows\system32\dllcache\vgx.dll 2012-01-03 17:18:58 718336 -c—-w- c:\windows\system32\dllcache\ntdll.dll 2012-01-03 17:18:11 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys 2012-01-03 17:17:56 45568 -c—-w- c:\windows\system32\dllcache\wab.exe 2012-01-03 17:17:48 590848 -c—-w- c:\windows\system32\dllcache\rpcrt4.dll 2012-01-03 17:17:36 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys 2012-01-03 17:16:56 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll 2012-01-03 17:16:10 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe 2012-01-03 17:13:00 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll 2012-01-03 17:12:03 218112 -c—-w- c:\windows\system32\dllcache\wordpad.exe 2012-01-02 23:23:15 1972528 —-a-w- C:\TDSSKiller.exe 2012-01-02 07:26:32 ——– d—–w- c:\program files\Defraggler 2012-01-01 17:29:10 ——– d—–w- c:\documents and settings\all users\application data\UAB 2012-01-01 17:28:50 ——– d—–w- c:\documents and settings\user\local settings\application data\PC_Drivers_Headquarters 2012-01-01 17:28:42 ——– d—–w- c:\documents and settings\all users\application data\PC Drivers HeadQuarters 2012-01-01 17:26:14 ——– d—–w- c:\program files\PC Drivers HeadQuarters 2011-12-31 22:39:10 15161664 —-a-w- C:\windows-kb890830-v4.3.exe 2011-12-31 22:30:28 388096 —-a-r- c:\documents and settings\user\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-12-31 22:30:28 ——– d—–w- c:\program files\Trend Micro 2011-12-31 20:19:00 14664 —-a-w- c:\windows\stinger.sys 2011-12-31 20:15:55 9031744 —-a-w- C:\stinger.exe 2011-12-31 20:13:23 532480 —-a-w- C:\cwshredder.exe 2011-12-27 01:52:19 ——– d—–w- c:\documents and settings\user\application data\To the Moon - Freebird Games 2011-12-27 01:42:31 ——– d—–w- C:\Downloads . ==================== Find3M ==================== . 2012-01-09 04:41:42 285176 —-a-w- c:\windows\system32\nvdrsdb0.bin 2012-01-09 04:41:42 1 —-a-w- c:\windows\system32\nvdrssel.bin 2012-01-09 04:41:40 285176 —-a-w- c:\windows\system32\nvdrsdb1.bin 2011-11-28 18:01:25 41184 —-a-w- c:\windows\avastSS.scr 2011-11-28 17:53:53 435032 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys 2011-11-01 20:35:20 81920 —-a-w- c:\windows\system32\ieencode.dll 2011-11-01 20:35:20 667136 —-a-w- c:\windows\system32\wininet.dll 2011-11-01 20:35:20 61952 —-a-w- c:\windows\system32\tdc.ocx 2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll 2011-11-01 15:02:49 369664 —-a-w- c:\windows\system32\html.iec 2011-10-30 22:36:54 80 –sh–r- c:\windows\ICMET20.BIN 2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll . ============= FINISH: 23:07:44.14 =============== Attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 12/18/2010 5:17:03 PM System Uptime: 1/12/2012 10:53:24 PM (1 hours ago) . Motherboard: PCCHIPS | | A15G Processor: AMD Athlon™ II X2 210e Processor | CPU 1 | 2611/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 146 GiB total, 100.172 GiB free. D: is FIXED (NTFS) - 319 GiB total, 205.999 GiB free. E: is CDROM () F: is CDROM () G: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP313: 12/13/2011 7:26:45 AM - Software Distribution Service 3.0 RP314: 12/13/2011 7:25:53 PM - Installed DirectX RP315: 12/14/2011 12:41:06 AM - Software Distribution Service 3.0 RP316: 12/16/2011 12:45:32 AM - Software Distribution Service 3.0 RP317: 12/17/2011 12:18:41 AM - Software Distribution Service 3.0 RP318: 12/17/2011 4:39:53 PM - Software Distribution Service 3.0 RP319: 12/18/2011 8:04:13 PM - System Checkpoint RP320: 12/19/2011 2:37:42 AM - Software Distribution Service 3.0 RP321: 12/19/2011 11:43:17 PM - Software Distribution Service 3.0 RP322: 12/20/2011 2:42:20 PM - Software Distribution Service 3.0 RP323: 12/21/2011 3:00:17 AM - Software Distribution Service 3.0 RP324: 12/21/2011 3:01:58 AM - Software Distribution Service 3.0 RP325: 12/21/2011 9:24:22 PM - Software Distribution Service 3.0 RP326: 12/22/2011 8:50:12 PM - Software Distribution Service 3.0 RP327: 12/23/2011 8:59:29 PM - System Checkpoint RP328: 12/24/2011 1:03:31 AM - Software Distribution Service 3.0 RP329: 12/24/2011 5:17:16 PM - Software Distribution Service 3.0 RP330: 12/25/2011 9:58:21 PM - System Checkpoint RP331: 12/26/2011 12:51:37 AM - Removed Fable III RP332: 12/26/2011 12:55:54 AM - Software Distribution Service 3.0 RP333: 12/26/2011 2:28:56 PM - Software Distribution Service 3.0 RP334: 12/26/2011 11:36:33 PM - Software Distribution Service 3.0 RP335: 12/28/2011 12:41:21 AM - Software Distribution Service 3.0 RP336: 12/28/2011 2:17:21 PM - Software Distribution Service 3.0 RP337: 12/29/2011 5:53:31 PM - Software Distribution Service 3.0 RP338: 12/30/2011 9:04:54 PM - System Checkpoint RP339: 12/31/2011 1:16:35 AM - Software Distribution Service 3.0 RP340: 12/31/2011 2:30:27 PM - Installed HiJackThis RP341: 12/31/2011 7:34:59 PM - Software Distribution Service 3.0 RP342: 1/1/2012 9:26:12 AM - Installed Driver Detective. RP343: 1/1/2012 4:17:57 PM - Software Distribution Service 3.0 RP344: 1/1/2012 7:33:16 PM - Removed Europa Universalis III Complete RP345: 1/2/2012 1:59:14 AM - Software Distribution Service 3.0 RP346: 1/2/2012 1:52:16 PM - Software Distribution Service 3.0 RP347: 1/2/2012 1:52:41 PM - Software Distribution Service 3.0 RP348: 1/3/2012 3:36:43 PM - System Checkpoint RP349: 1/3/2012 9:49:32 PM - Software Distribution Service 3.0 RP350: 1/4/2012 11:03:18 PM - Software Distribution Service 3.0 RP351: 1/9/2012 11:00:13 PM - System Checkpoint . ==== Installed Programs ====================== . Adobe Flash Player 10 Plugin Adobe Reader 9.4.7 Adobe Shockwave Player 11.5 Advertising Center Amnesia - The Dark Descent Apple Mobile Device Support Apple Software Update Assassin's Creed II Audacity 1.2.6 avast! Free Antivirus BlueJ 3.0.0 Bonjour CCleaner ClassicPro© v1.15 CodeBlocks DAEMON Tools Toolbar Defraggler DolbyFiles Dragon Age II Dragon Age: Origins Driver Detective Fable III Fallout Mod Manager 0.13.21 Fallout New Vegas Firebird SQL Server - MAGIX Edition GameHouse Games Collection: Super Rumble Cube GameHouse Games Collection: Super SpongeBob Collapse! GameHouse Games Collection: Super WHATword GameHouse Games Collection: Super Wild Wild Words GameHouse Games Collection: Tumblebugs GameHouse Games Collection: Wheel of Fortune High Definition Audio Driver Package - KB888111 High Speed Rail Project Beta v1 HiJackThis Hitman Blood Money Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB981793) iClone 2 SE for Magix ImagXpress iTunes Japanese Language Support Java Auto Updater Java DB 10.6.2.1 Java™ 6 Update 29 Java™ SE Development Kit 6 Update 24 JCreator LE 5.00 LAME v3.98.3 for Audacity MAGIX Screenshare 4.3.6.1987 (US) MAGIX Xtreme Photo Designer 6 [removed] (US) Mass Effect Mass Effect 2 Menu Templates - Starter Kit Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft AppLocale Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft Windows Application Compatibility Database Microsoft WinUsb 1.0 Microsoft WSE 3.0 Runtime MouseEventDemo Movie Templates - Starter Kit Mozilla Firefox (3.6.14) Mozilla Firefox 10.0 (x86 en-US) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) Nero 9 Essentials Nero BurnRights Nero BurnRights Help Nero ControlCenter Nero CoverDesigner Nero CoverDesigner Help Nero DiscSpeed Nero DiscSpeed Help Nero DriveSpeed Nero DriveSpeed Help Nero Express Help Nero InfoTool Nero InfoTool Help Nero Installer Nero Online Upgrade Nero ShowTime Nero StartSmart Nero StartSmart Help Nero Vision Nero Vision Help NeroExpress neroxml Network Addon Mod Version 29 Network Widening Mod Version 1.1.1 NVIDIA Control Panel 285.58 NVIDIA Display Control Panel NVIDIA Drivers NVIDIA Graphics Driver 285.58 NVIDIA HD Audio Driver [removed] NVIDIA Install Application NVIDIA nView 135.95 NVIDIA PhysX NVIDIA PhysX System Software 9.11.0621 NVIDIA Update 1.5.20 NVIDIA Update Components PowerISO QuickTime Rainmeter (remove only) Realtek High Definition Audio Driver Risen Samsung Kies SAMSUNG USB Driver for Mobile Phones Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2553089) Security Update for 2007 Microsoft Office System (KB2553090) Security Update for 2007 Microsoft Office System (KB2584063) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Extended (KB2416472) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition Security Update for Microsoft Office Access 2007 (KB979440) Security Update for Microsoft Office Groove 2007 (KB2552997) Security Update for Microsoft Office InfoPath 2007 (KB2510061) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2482017) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544521) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2618444) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982381) Security Update for Windows XP (KB982665) SimCity 4 Deluxe SpeedFan (remove only) SPORE™ SPORE™ Creepy & Cute Parts Pack SPORE™ Galactic Adventures Spybot - Search & Destroy Street Addon Mod Beta v3 System Requirements Lab CYRI The Sims™ 3 To the Moon TuneUp Utilities 2009 Ubisoft Game Launcher Unity Web Player Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office Outlook 2007 (KB2583910) Update for Outlook 2007 Junk Email Filter (KB2596560) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2541763) Update for Windows XP (KB2641690) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VLC media player 1.1.5 Vtune 7.13 WebFldrs XP Winamp Winamp Detector Plug-in Windows Genuine Advantage Notifications (KB905474) Windows Imaging Component Windows Media Format 11 runtime Windows Presentation Foundation Windows XP Service Pack 3 WinRAR archiver XML Paper Specification Shared Components Pack 1.0 Yahoo! Messenger . ==== Event Viewer Messages From Past Week ======== . 1/9/2012 10:16:44 PM, error: W32Time [34] - The time service has detected that the system time needs to be changed by -57719 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|192.168.1.2:123->65.55.21.21:123) is working properly. 1/7/2012 4:30:00 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service. 1/5/2012 8:18:55 PM, error: Service Control Manager [7000] - The Upload Manager service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process. 1/5/2012 8:17:35 PM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 001E9082CB6F has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File ===========================
Well, honestly, given that you had a proxy showing in your HijackThis log, I really expected to see some symptoms of malware in this log, but I'm not.

I do see in your error logs that it appears your date and time settings on the machine may be off. You may want to check those as it can cause some other system issues but that would not likely be the cause of your slowness.

Let's run a couple more malware scans and see if they turn up anything that isn't showing in these logs. Different scans look in different places and no one scan finds everything..


Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.





This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.

Please go to here to run the online scannner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked, and the option Scan unwanted applications is checked
  • Click on Advanced Settings and ensure these options are ticked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • If any threats were found, click the 'List of found threats' , then click Export to text file….
  • Save it to your desktop, then please copy and paste that log as a reply to this topic.



Also, can you tell me if you are using a router?
Here's the malwarebytes scan Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.14.02 Windows XP Service Pack 3 x86 NTFS Internet Explorer 6.0.2900.5512 user :: USER-5188DC22DE [administrator] 1/14/2012 10:03:47 PM mbam-log-2012-01-14 (22-03-47).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 201659 Time elapsed: 4 minute(s), 54 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) I haven't run the other scan yet, but I did use CHKDSK and everything seems fine now. Internet's working up to speed. Do you think it solved my problem?
It is quite possible that it fixed the problem. It's also possible it was just an ISP glitch that fixed itself too. I personally don't think you have anything to worry about at this point. I'll leave the thread open for a few days. If you want to run the other scan you can. If I don't hear back in a couple of days I'll go ahead and close out. I'll leave it up to you. I truly don't see any malware on the machine and if the performance is back up to speed, I don't see any reason to think that another scan is going to find anything different - but I will leave that choice up to you. I'm certainly here to look at the results if you would feel better running it. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI