This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

kinda slow computer, weird/sticky mouse [Solved]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi :) I've had a slow computer for a while, and now the mouse is "sticky" โ€ฆ dunno how to describe it, but it picks up everything it touches. Firefox and other things seem to crash an awful lot. too. Maybe it's nothing, but I'd really appreciate it if you guys could help me check it out. Thanks in advance!!
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!


Download and Run DDS by sUBs

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.com
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE



Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.9.2 Run by [removed] at 18:59:03 on 2012-12-27 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4044.1213 [GMT -5:00] . AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\windows\system32\lsm.exe C:\windows\system32\svchost.exe -k DcomLaunch C:\windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\windows\system32\svchost.exe -k netsvcs C:\windows\system32\svchost.exe -k LocalService C:\windows\system32\svchost.exe -k NetworkService C:\windows\System32\spoolsv.exe C:\windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\windows\system32\Dwm.exe C:\windows\Explorer.EXE C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\windows\system32\taskhost.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe C:\windows\system32\svchost.exe -k imgsvc C:\windows\system32\TODDSrv.exe C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\windows\System32\rundll32.exe c:\Program Files\Microsoft Security Client\NisSrv.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files (x86)\BitTorrent\BitTorrent.exe C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Windows\System32\StikyNot.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\Program Files (x86)\Free YouTube Downloader\YouTubeDownloader.exe C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_135.exe C:\windows\system32\taskeng.exe C:\windows\system32\SearchProtocolHost.exe C:\windows\system32\SearchFilterHost.exe C:\windows\system32\wbem\wmiprvse.exe C:\windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y uProxyOverride = ;*.local BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: Javaโ„ข Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll BHO: Javaโ„ข Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll uRun: [BitTorrent] "C:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED uRun: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background uRun: [AdobeBridge] mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Standby] "c:\Program Files (x86)\Common Files\Corel\Standby\Standby.exe" -START mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . TCP: NameServer = 192.168.254.254 192.168.254.254 TCP: Interfaces\{3CA6EBC8-F765-490A-AC8C-51A57724CEE7} : DHCPNameServer = 192.168.254.254 192.168.254.254 TCP: Interfaces\{C65F7F64-9738-44C6-9E9A-C651FDF10295} : DHCPNameServer = [removed] [removed] Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-BHO: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-BHO: TOSHIBA Media Controller Plug-in: {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll x64-TB: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" . INFO: x64-HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - x64-Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\9jna99sf.default\ FF - plugin: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll FF - plugin: C:\windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll FF - plugin: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll FF - plugin: C:\windows\SysWOW64\npDeployJava1.dll FF - plugin: C:\windows\SysWOW64\npmproxy.dll . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;C:\windows\System32\drivers\MpFilter.sys [2012-8-30 228768] R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\windows\System32\drivers\tos_sps64.sys [2009-6-24 482384] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\windows\System32\drivers\dtsoftbus01.sys [2012-2-15 283200] R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624] R2 NisDrv;Microsoft Network Inspection System;C:\windows\System32\drivers\NisDrvWFP.sys [2011-4-27 128456] R2 PCCUJobMgr;Common Client Job Manager Service;C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2011-11-30 126392] R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776] R2 UNS;Intelยฎ Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2011-11-30 2656280] R3 FwLnk;FwLnk Driver;C:\windows\System32\drivers\FwLnk.sys [2011-11-30 9216] R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;C:\windows\System32\drivers\L1C62x64.sys [2011-2-9 77424] R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-9-12 368896] R3 PGEffect;Pangu effect driver;C:\windows\System32\drivers\PGEffect.sys [2011-11-30 38096] R3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;C:\windows\System32\drivers\rtl8192ce.sys [2011-11-30 1109096] R3 Sftfs;Sftfs;C:\windows\System32\drivers\Sftfslh.sys [2011-10-1 764264] R3 Sftplay;Sftplay;C:\windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648] R3 Sftredir;Sftredir;C:\windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960] R3 Sftvol;Sftvol;C:\windows\System32\drivers\Sftvollh.sys [2011-10-1 22376] R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496] R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);C:\windows\System32\drivers\WsAudio_DeviceS(1).sys [2012-11-3 29288] R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);C:\windows\System32\drivers\WsAudio_DeviceS(2).sys [2012-11-3 29288] R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);C:\windows\System32\drivers\WsAudio_DeviceS(3).sys [2012-11-3 29288] R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);C:\windows\System32\drivers\WsAudio_DeviceS(4).sys [2012-11-3 29288] R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);C:\windows\System32\drivers\WsAudio_DeviceS(5).sys [2012-11-3 29288] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-11-9 160944] S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\windows\System32\drivers\RtsUStor.sys [2011-11-30 243712] S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TMachInfo;TMachInfo;C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-11-30 57216] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-6-9 138152] S3 TsUsbFlt;TsUsbFlt;C:\windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232] S3 WatAdminSvc;Windows Activation Technologies Service;C:\windows\System32\Wat\WatAdminSvc.exe [2012-1-11 1255736] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2012-12-27 22:54:55 9125352 โ€”-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{95F64275-06A5-47B9-B48C-0814289CAFEF}\mpengine.dll 2012-12-27 22:45:41 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{4CB360C1-0141-4681-B2A4-354C4BED3212} 2012-12-27 10:45:29 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{1623145A-9D3E-4231-9FC2-81E5F2DBF8F3} 2012-12-27 09:30:50 9125352 โ€”โ€”w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-12-26 22:45:09 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{788C6F85-9B7D-4A15-A979-DB0D01934107} 2012-12-24 14:42:13 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{C2D880B7-3184-4D84-902E-D49909856896} 2012-12-24 02:42:00 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{2A98E595-9D1A-4185-987D-684544426913} 2012-12-23 14:41:48 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{8E125124-106B-41A0-9B34-37088C07D84C} 2012-12-23 02:41:35 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{584D0C37-6670-4076-8957-5F28E33629EE} 2012-12-22 14:41:23 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{0245DC16-3D4A-481E-96C7-AB5F8A8F957B} 2012-12-22 02:41:11 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{FC620CEE-6A6C-493B-8651-22A4C48A2810} 2012-12-21 22:58:25 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\ElevatedDiagnostics 2012-12-21 14:40:46 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{6DA254DD-B312-45BD-B214-E0E7BCDB4CF1} 2012-12-21 08:02:35 34304 โ€”-a-w- C:\windows\SysWow64\atmlib.dll 2012-12-21 08:02:34 46080 โ€”-a-w- C:\windows\System32\atmlib.dll 2012-12-21 08:02:28 367616 โ€”-a-w- C:\windows\System32\atmfd.dll 2012-12-21 08:02:00 295424 โ€”-a-w- C:\windows\SysWow64\atmfd.dll 2012-12-21 02:40:33 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{3FFBF413-625C-4819-A431-0DD45D79ED5E} 2012-12-20 14:40:08 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{ACFC631C-7095-4571-B741-80EDE08A63ED} 2012-12-20 02:23:47 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{9845F1A9-BBE1-4B81-99D9-90F09C16C066} 2012-12-19 14:23:34 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{7B5AAF15-A1D2-4E47-B8D5-CB8DF5E67242} 2012-12-19 02:23:22 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{F7EFED31-35DE-4BA2-BA3B-2D30E48E32E3} 2012-12-18 14:23:08 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{930C5ABD-F79B-4521-A66F-2E33710B7291} 2012-12-18 01:02:08 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{58E678E1-6ADB-4A7C-8894-41A426A5FEA3} 2012-12-17 13:01:56 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{4CCD1AD8-ADE1-4F7A-BF35-BC02706796F3} 2012-12-17 01:01:43 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{10D3001A-DC93-47C4-89F3-5256C4C134FE} 2012-12-16 13:01:30 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{1F8E9058-5337-4471-A315-07A0DB7C4DE7} 2012-12-16 01:01:17 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{4F23DA79-AEBE-407C-9093-BE5E5F627C29} 2012-12-15 13:01:04 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{31AEC167-B680-4951-A8EC-C93418F8327F} 2012-12-15 01:00:51 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{7A253130-ECA7-4504-BAF8-AC21AB2FE996} 2012-12-14 13:00:39 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{5A5897B2-F588-46C9-A2B2-E5B554E9B7EF} 2012-12-14 01:00:26 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{0959B16A-C42D-4F00-9A7D-5A20551FE286} 2012-12-13 13:00:06 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{00CA4B55-68A6-416A-9F66-4B962F880A28} 2012-12-12 20:38:47 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{D383CBA9-818F-404D-9335-ACCF141D12C2} 2012-12-12 08:38:35 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{5F105890-D775-47C9-ACCB-C589F1D5718D} 2012-12-12 08:33:46 โ€”โ€”โ€“ d-shโ€“w- C:\found.000 2012-12-12 06:06:52 478208 โ€”-a-w- C:\windows\System32\dpnet.dll 2012-12-12 06:06:51 376832 โ€”-a-w- C:\windows\SysWow64\dpnet.dll 2012-12-02 13:37:36 95208 โ€”-a-w- C:\windows\SysWow64\WindowsAccessBridge-32.dll 2012-12-01 00:45:36 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{1136D736-DF31-4ABF-BD86-30A3B6918174} 2012-11-30 12:45:24 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{2C1112B9-E8C5-41D9-981C-2819C9E16C6B} 2012-11-30 00:45:11 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{52FF5593-FEFC-42EC-BC92-78997823CF82} 2012-11-28 17:44:32 โ€”โ€”โ€“ dโ€”โ€“w- C:\Users\Owner\AppData\Local\{86626681-10CC-44B7-B598-28DD149D0B39} 2012-11-28 08:50:22 972264 โ€”โ€”w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B39CB9B8-5FA6-4821-BA37-D334B854F2A0}\gapaengine.dll . ==================== Find3M ==================== . 2012-12-19 02:50:17 5642 โ€“sha-w- C:\ProgramData\KGyGaAvL.sys 2012-12-12 04:58:56 73656 โ€”-a-w- C:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-12-12 04:58:56 697272 โ€”-a-w- C:\windows\SysWow64\FlashPlayerApp.exe 2012-11-22 03:26:40 3149824 โ€”-a-w- C:\windows\System32\win32k.sys 2012-11-14 06:11:44 2312704 โ€”-a-w- C:\windows\System32\jscript9.dll 2012-11-14 06:04:11 1392128 โ€”-a-w- C:\windows\System32\wininet.dll 2012-11-14 06:02:49 1494528 โ€”-a-w- C:\windows\System32\inetcpl.cpl 2012-11-14 05:57:46 599040 โ€”-a-w- C:\windows\System32\vbscript.dll 2012-11-14 05:57:35 173056 โ€”-a-w- C:\windows\System32\ieUnatt.exe 2012-11-14 05:52:40 2382848 โ€”-a-w- C:\windows\System32\mshtml.tlb 2012-11-14 02:09:22 1800704 โ€”-a-w- C:\windows\SysWow64\jscript9.dll 2012-11-14 01:58:15 1427968 โ€”-a-w- C:\windows\SysWow64\inetcpl.cpl 2012-11-14 01:57:37 1129472 โ€”-a-w- C:\windows\SysWow64\wininet.dll 2012-11-14 01:49:25 142848 โ€”-a-w- C:\windows\SysWow64\ieUnatt.exe 2012-11-14 01:48:27 420864 โ€”-a-w- C:\windows\SysWow64\vbscript.dll 2012-11-14 01:44:42 2382848 โ€”-a-w- C:\windows\SysWow64\mshtml.tlb 2012-11-09 05:45:09 2048 โ€”-a-w- C:\windows\System32\tzres.dll 2012-11-09 04:42:49 2048 โ€”-a-w- C:\windows\SysWow64\tzres.dll 2012-10-16 08:38:37 135168 โ€”-a-w- C:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38:34 350208 โ€”-a-w- C:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39:52 561664 โ€”-a-w- C:\windows\apppatch\AcLayers.dll 2012-10-09 18:17:13 55296 โ€”-a-w- C:\windows\System32\dhcpcsvc6.dll 2012-10-09 18:17:13 226816 โ€”-a-w- C:\windows\System32\dhcpcore6.dll 2012-10-09 17:40:31 44032 โ€”-a-w- C:\windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40:31 193536 โ€”-a-w- C:\windows\SysWow64\dhcpcore6.dll 2012-10-04 17:46:16 362496 โ€”-a-w- C:\windows\System32\wow64win.dll 2012-10-04 17:46:15 243200 โ€”-a-w- C:\windows\System32\wow64.dll 2012-10-04 17:46:15 13312 โ€”-a-w- C:\windows\System32\wow64cpu.dll 2012-10-04 17:45:55 215040 โ€”-a-w- C:\windows\System32\winsrv.dll 2012-10-04 17:43:28 16384 โ€”-a-w- C:\windows\System32\ntvdm64.dll 2012-10-04 17:41:16 424960 โ€”-a-w- C:\windows\System32\KernelBase.dll 2012-10-04 16:47:41 5120 โ€”-a-w- C:\windows\SysWow64\wow32.dll 2012-10-04 16:47:41 274944 โ€”-a-w- C:\windows\SysWow64\KernelBase.dll 2012-10-04 15:21:55 338432 โ€”-a-w- C:\windows\System32\conhost.exe 2012-10-04 14:46:46 7680 โ€”-a-w- C:\windows\SysWow64\instnm.exe 2012-10-04 14:46:46 25600 โ€”-a-w- C:\windows\SysWow64\setup16.exe 2012-10-04 14:46:44 14336 โ€”-a-w- C:\windows\SysWow64\ntvdm64.dll 2012-10-04 14:46:43 2048 โ€”-a-w- C:\windows\SysWow64\user.exe 2012-10-04 14:41:50 6144 โ€”ha-w- C:\windows\SysWow64\api-ms-win-security-base-l1-1-0.dll 2012-10-04 14:41:50 4608 โ€”ha-w- C:\windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll 2012-10-04 14:41:50 3584 โ€”ha-w- C:\windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll 2012-10-04 14:41:50 3072 โ€”ha-w- C:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll 2012-10-03 17:56:54 1914248 โ€”-a-w- C:\windows\System32\drivers\tcpip.sys 2012-10-03 17:44:21 70656 โ€”-a-w- C:\windows\System32\nlaapi.dll 2012-10-03 17:44:21 303104 โ€”-a-w- C:\windows\System32\nlasvc.dll 2012-10-03 17:44:17 246272 โ€”-a-w- C:\windows\System32\netcorehc.dll 2012-10-03 17:44:17 18944 โ€”-a-w- C:\windows\System32\netevent.dll 2012-10-03 17:44:16 216576 โ€”-a-w- C:\windows\System32\ncsi.dll 2012-10-03 17:42:16 569344 โ€”-a-w- C:\windows\System32\iphlpsvc.dll 2012-10-03 16:42:24 18944 โ€”-a-w- C:\windows\SysWow64\netevent.dll 2012-10-03 16:42:24 175104 โ€”-a-w- C:\windows\SysWow64\netcorehc.dll 2012-10-03 16:42:23 156672 โ€”-a-w- C:\windows\SysWow64\ncsi.dll 2012-10-03 16:07:26 45568 โ€”-a-w- C:\windows\System32\drivers\tcpipreg.sys . ============= FINISH: 18:59:42.54 ===============
P2P - I see you have P2P software ( BitTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a may have contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Programs and Features.

If you choose to leave them on the machine, please refrain from using them while we are cleaning the machine to prevent further infection.


C: is FIXED (NTFS) - 283 GiB total, 8.407 GiB free.

Windows requires a minimum of 10% of your hard drive free (in your case 28.3GiB) to function properly. Having less than this free will cause the system to slow down and will cause the system to perform at less than it's optimal level. I would strongly suggest that you look at freeing up some of your system resources by moving some of your non-essential data/programs to other media, or deleting unused data or programs. The sluggishness that you are experiencing could definitely be a result of the low resources, especially if you have noticed your hard drive running (spinning and clicking) more than usual lately.


Although I'm not seeing anything alarming in your DDS log (which is a diagnostic tool to give us a look at your machine, not a tool that cleans infections) I definitely don't like the looks of the errors you have going on in the attach.txt file. No one tool shows us the full extent of everything that is going on with your machine. I would still like to go ahead and run a more powerful tool to look for possible infections.


Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. 1. Do not mouse-click anywhere on the screen while it is running. That may cause it to stall. In fact, I suggest you do not do anything else on the computer while Combofix is running as it can cause it to stall. It may appear at times that it isn't doing anything but it is. Just let it run. It may also reboot the machine as a part of what it is doing and that is not unusual. (If your computer requires a login then you WILL need to fill in the login/password for it to continue. If your computer does not have a login then it will continue on it's own..) Then, just sit tight until it finishes. Sometimes it takes 10 minutes, sometimes it takes an hour. Just be patient until the log pops up. If it takes more than an hour and doesn't appear to be doing anything, you can stop it and come back and let me know.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

If you have a problem launching programs after running Combofix, please do not panic! Simply reboot the computer and all should be fine.


Also, just so I know, can you tell me if this is a laptop or a desktop so I know what kind of mouse we are dealing with?
This is a laptop. Below is the ComboFix log. ComboFix 12-12-27.03 - Owner 12/27/2012 23:04:06.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4044.2671 [GMT -5:00] Running from: c:\users\[removed]\Downloads\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C} SP: Microsoft Security Essentials *Disabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\programdata\B0545EB164.sys . . ((((((((((((((((((((((((( Files Created from 2012-11-28 to 2012-12-28 ))))))))))))))))))))))))))))))) . . 2012-12-28 04:09 . 2012-12-28 04:09 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Public\AppData\Local\temp 2012-12-28 04:09 . 2012-12-28 04:09 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2012-12-27 22:54 . 2012-11-08 17:24 9125352 โ€”-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{95F64275-06A5-47B9-B48C-0814289CAFEF}\mpengine.dll 2012-12-27 09:30 . 2012-11-08 17:24 9125352 โ€”-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2012-12-21 22:58 . 2012-12-21 22:58 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Owner\AppData\Local\ElevatedDiagnostics 2012-12-21 08:02 . 2012-12-16 14:13 34304 โ€”-a-w- c:\windows\SysWow64\atmlib.dll 2012-12-21 08:02 . 2012-12-16 17:11 46080 โ€”-a-w- c:\windows\system32\atmlib.dll 2012-12-21 08:02 . 2012-12-16 14:45 367616 โ€”-a-w- c:\windows\system32\atmfd.dll 2012-12-21 08:02 . 2012-12-16 14:13 295424 โ€”-a-w- c:\windows\SysWow64\atmfd.dll 2012-12-12 08:33 . 2012-12-12 08:33 โ€”โ€”โ€“ dโ€”โ€“w- C:\found.000 2012-12-12 08:01 . 2012-11-14 06:32 10925568 โ€”-a-w- c:\windows\system32\ieframe.dll 2012-12-12 06:06 . 2012-11-02 05:59 478208 โ€”-a-w- c:\windows\system32\dpnet.dll 2012-12-12 06:06 . 2012-11-02 05:11 376832 โ€”-a-w- c:\windows\SysWow64\dpnet.dll 2012-12-10 17:55 . 2012-12-10 17:55 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\HP 2012-12-02 13:37 . 2012-09-25 04:16 95208 โ€”-a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2012-11-28 08:50 . 2012-11-28 08:43 972264 โ€”โ€”w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B39CB9B8-5FA6-4821-BA37-D334B854F2A0}\gapaengine.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-12-19 02:50 . 2012-01-29 07:33 5642 โ€“sha-w- c:\programdata\KGyGaAvL.sys 2012-12-12 08:05 . 2012-01-11 14:09 67413224 โ€”-a-w- c:\windows\system32\MRT.exe 2012-12-12 04:58 . 2012-04-03 05:09 697272 โ€”-a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2012-12-12 04:58 . 2011-10-31 02:34 73656 โ€”-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-10-16 08:38 . 2012-11-28 11:18 135168 โ€”-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2012-10-16 08:38 . 2012-11-28 11:18 350208 โ€”-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2012-10-16 07:39 . 2012-11-28 11:18 561664 โ€”-a-w- c:\windows\apppatch\AcLayers.dll 2012-10-09 18:17 . 2012-11-14 06:32 55296 โ€”-a-w- c:\windows\system32\dhcpcsvc6.dll 2012-10-09 18:17 . 2012-11-14 06:32 226816 โ€”-a-w- c:\windows\system32\dhcpcore6.dll 2012-10-09 17:40 . 2012-11-14 06:32 44032 โ€”-a-w- c:\windows\SysWow64\dhcpcsvc6.dll 2012-10-09 17:40 . 2012-11-14 06:32 193536 โ€”-a-w- c:\windows\SysWow64\dhcpcore6.dll 2012-10-04 16:40 . 2012-12-12 06:07 44032 โ€”-a-w- c:\windows\apppatch\acwow64.dll 2012-10-03 17:56 . 2012-11-14 06:32 1914248 โ€”-a-w- c:\windows\system32\drivers\tcpip.sys 2012-10-03 17:44 . 2012-11-14 06:32 70656 โ€”-a-w- c:\windows\system32\nlaapi.dll 2012-10-03 17:44 . 2012-11-14 06:32 303104 โ€”-a-w- c:\windows\system32\nlasvc.dll 2012-10-03 17:44 . 2012-11-14 06:32 246272 โ€”-a-w- c:\windows\system32\netcorehc.dll 2012-10-03 17:44 . 2012-11-14 06:32 18944 โ€”-a-w- c:\windows\system32\netevent.dll 2012-10-03 17:44 . 2012-11-14 06:32 216576 โ€”-a-w- c:\windows\system32\ncsi.dll 2012-10-03 17:42 . 2012-11-14 06:32 569344 โ€”-a-w- c:\windows\system32\iphlpsvc.dll 2012-10-03 16:42 . 2012-11-14 06:32 175104 โ€”-a-w- c:\windows\SysWow64\netcorehc.dll 2012-10-03 16:42 . 2012-11-14 06:32 18944 โ€”-a-w- c:\windows\SysWow64\netevent.dll 2012-10-03 16:42 . 2012-11-14 06:32 156672 โ€”-a-w- c:\windows\SysWow64\ncsi.dll 2012-10-03 16:07 . 2012-11-14 06:32 45568 โ€”-a-w- c:\windows\system32\drivers\tcpipreg.sys 2012-09-30 12:22 . 2012-06-12 16:47 972192 โ€”โ€”w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BitTorrent"="c:\program files (x86)\BitTorrent\BitTorrent.exe" [2012-10-21 1398680] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2012-01-24 3478336] "RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [BU] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008] "Standby"="c:\program files (x86)\Common Files\Corel\Standby\Standby.exe" [2009-12-17 105632] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NortonOnlineBackupReminder] 2011-06-22 22:26 3218864 โ€”-a-w- c:\program files (x86)\TOSHIBA\Toshiba Online Backup\Activation\TobuActivation.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaAppPlace] 2010-09-23 18:03 552960 โ€”-a-w- c:\program files (x86)\TOSHIBA\Toshiba App Place\ToshibaAppPlace.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToshibaServiceStation] 2011-07-12 01:16 1298816 โ€”-a-w- c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-11-09 160944] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-08-31 128456] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-09-13 368896] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-10-08 243712] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2011-07-12 57216] R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2011-06-10 138152] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-01-11 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184] S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [2009-06-24 482384] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-02-15 283200] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2012-01-04 822624] S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe [2011-07-19 126392] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-01 508776] S2 UNS;Intelยฎ Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intelยฎ Management Engine Components\UNS\UNS.exe [2011-02-01 2656280] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2009-07-07 9216] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [2011-02-09 77424] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [2011-02-09 38096] S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys [2011-01-05 1109096] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2011-10-01 764264] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2011-10-01 268648] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2011-10-01 25960] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2011-10-01 22376] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-01 219496] S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2010-12-24 29288] S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [2010-12-24 29288] S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [2010-12-24 29288] S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [2010-12-24 29288] S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [2010-12-24 29288] . . โ€” Other Services/Drivers In Memory โ€” . *NewlyCreated* - 06618746 *Deregistered* - 06618746 . Contents of the 'Scheduled Tasks' folder . 2012-12-28 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 04:58] . 2012-12-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 22:45] . 2012-12-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-11-30 22:45] . . โ€”โ€”โ€” X64 Entries โ€”โ€”โ€”โ€“ . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 1289704] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392] . โ€”โ€”- Supplementary Scan โ€”โ€”- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://start.toshiba.com/?cid=C001B2Y mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = ;*.local TCP: DhcpNameServer = 192.168.254.254 192.168.254.254 FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\9jna99sf.default\ . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKCU-Run-AdobeBridge - (no file) . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCCUJobMgr] "ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.13.11\diMaster.dll\" /prefetch:1" . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_135_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_135.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-12-27 23:12:05 ComboFix-quarantined-files.txt 2012-12-28 04:12 ComboFix2.txt 2012-05-05 21:26 . Pre-Run: 10,656,178,176 bytes free Post-Run: 17,812,344,832 bytes free . - - End Of File - - 9CDD1FC617A414AB35126C671B1FD7FA
Malwarebytes has a new version so please be sure to check for updates.

I see you have Malwarebytes already on your machine. Please run it by right-clicking and choosing Run as Administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.




This scan make take awhile depending on how many items are on the computer. You may want to run it at a time you won't be needing the machine. It should be run from IE and I'd recommend not doing anything else while it's running.


Go here to run an online scannner from ESET.
  • Note: For browsers other than Internet Explorer, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

If it doesn't find anything there will be no log to post.


I will address the mouse issues in my next post. Can you please also let me know how the machine is running in your next response?
I did the Malware and the eset scan and neither one showed anything malicious. I deleted some things and got it so there is 10% free and it all seems to be working better now. Including the mouse, I think.
Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2012.12.29.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Owner :: OWNER-PC [administrator] 12/29/2012 8:56:21 AM mbam-log-2012-12-29 (08-56-21).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 211018 Time elapsed: 4 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
I'm glad things seem to be working better with the additional free space. Your logs are looking good. We can do some tools clean up now. You'll want to try to keep that free space at 10% or more. You may want to invest in an external hard drive if you have some old data that you could archive and save that way to free up space for the future. External drives are fairly inexpensive these days. Things like photos or music are things that can be fairly easily moved to an external drive to free up space.

If you have any more mouse issues, I'd refer you to our Windows Forum for additional help. There may be some other hardware issues going on they could assist with. But for now, your machine appears to be malware free :)

============================

The following will implement some cleanup procedures as well as reset System Restore points:
  • Click the Windows Key + R to open the Run box.
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]

If there are any remaining tools or logs on your desktop you can right-click and delete them.

========================

Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Use and Update your AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall
I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

Use only one antivirus and one firewall on your machine
Having more than one anti-virus program and one firewall on your machine, even if only one is running, can cause conflicts and slowdowns in the performance of the machine.

If you need more information on free anti-virus or firewall options please let me know and I will give you some recommendations.

Make your Internet Explorer more secure
This can be done by following these simple instructions:
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.
5. Change the Download signed ActiveX controls to Prompt
6. Change the Download unsigned ActiveX controls to Disable
7. Change the Initialize and script ActiveX controls not marked as safe to Disable
8. Change the Installation of desktop items to Prompt
9. Change the Launching programs and files in an IFRAME to Prompt
10. Change the Navigate sub-frames across different domains to Prompt
11. When all these settings have been made, click on the OK button.
12. If it prompts you as to whether or not you want to save the settings, press the Yes button.
13. Next press the Apply button and then the OK to exit the Internet Properties page.

Keep your Java, Adobe Reader and Adobe Flash Up to Date
Older versions of these programs can contain security vulnerabilities. It is very important to keep them updated.

Update and Run Malwarebytes Anti-Malware
Scan your computer with this program on a regular basis just as you would an antivirus software making sure you update definitions each time you scan.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

I would suggest you read:
Tony Klein's excellent article: How I got Infected in the First Place
PC Safety and Securityโ€“What Do I Need?
How to Prevent Malware

Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI