Slow start-up
47 min read
Try this one: http://www.bleepingcomputer.com/forums/tutorial61.html
You keep mentioning NAV, have you thought to discuss it with Symantec? I will say I have never had any experience with NAV but I am told it is a huge resource user. I wish I could report that folks with NAV never get infected, but I can not. If we can't locate another software reason for the issue, before you start looking at a possible hardware failure, you may want to uninstall the product and try something like this free product which is not resource heavy:
http://free.grisoft.com/freeweb.php
In case I have not asked (I am working around 50 or so logs at any one time) I would like to make sure you do not have the SP2 firewall activated if you are running one in NAV, I am not sure that could cause your issues but it not a suggested proceedure.
If I remember correctly, Ken was also not able to locate a malware reason for your issues. Ken is a friend and I will discuss this with him if he ever stops watching the NY Yankee's play baseball.
Thanks…Phil
Hi Phil and Ken,
Thanks to both of you for your feedback and for your perseverance.
Apologies for not responding dunring 1½ week, but, as I indicated in my last reply, I was out of the country for over a week, so could not react.
I did everything Phil suggested and the results are as follows:
1. I ran Ewido in Safe Mode and the results are as follows:
———————————————————
ewido security suite - Scan rapport
———————————————————
+ Gemaakt op: 23:44:46, 22-10-2005
+ Rapport samenvatting: 90D96588
+ Scan resultaten:
C:\Documents and Settings\Joost\Cookies\[removed][1].txt -> Spyware.Cookie.Euroclick : Schoongemaakt met een backup
C:\Documents and Settings\Joost\Cookies\joost@burstnet[2].txt -> Spyware.Cookie.Burstnet : Schoongemaakt met een backup
C:\Documents and Settings\Joost\Cookies\[removed][2].txt -> Spyware.Cookie.Onestat : Schoongemaakt met een backup
::Einde rapport
2. I ran the Housecall scan and the results were was an infection with BKDR_NETPALS.A in C:\windows\system32\netpole.dll. What should I do about this?
3. I tried to run the Panda Software scan a couple of times, but it failed each time at the same spot, i.e. after some 250 files whilst processing the file C:\windows\explorer.exe. Does this point in any direction?
4. I ran the Kaspersky scan and it gave the following results:
——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Sunday, October 23, 2005 12:21:27
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 23/10/2005
Kaspersky Anti-Virus database records: 146347
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 79651
Number of viruses found: 3
Number of infected objects: 4
Number of suspicious objects: 0
Duration of the scan process: 3832 sec
Infected Object Name - Virus Name
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E4637A0.dll Infected: Trojan-Dropper.Win32.Mudrop.w
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\1E49619D.dll Infected: Trojan-Dropper.Win32.Mudrop.w
C:\WINDOWS\system32\netpal2.dll Infected: Backdoor.Win32.Adbreak.e
C:\WINDOWS\system32\sstep.dll Infected: Trojan-Dropper.Win32.Small.so
Scan process completed.
5. Next, I ran Silentrunners and the results of that process were as follows:
"Silent Runners.vbs", revision 41, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
———————————
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"PowerBar" = (empty string)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"EM_EXEC" = "C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE" ["Logitech Inc."]
"ACTIVBOARD" = "C:\Apps\ActivBoard\MMKeybd.exe" ["Netropa Corp."]
"Logitech Utility" = "Logi_MwX.Exe" ["Logitech Inc."]
"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
"Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer" ["Symantec Corporation"]
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\(Default) = "Norton Internet Security"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
{BDF3E430-B101-42AD-A544-FADC6B084872}\(Default) = "NAV Helper"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{950FF917-7A57-46BC-8017-59D9BF474000}" = "Shell Extension for CDRW"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Ahead\InCD\incdshx.dll" ["Ahead Software AG"]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{8BE13461-936F-11D1-A87D-444553540000}" = "Eraser Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Eraser\erasext.dll" ["-"]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: "]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
EasyCryptoMenu\(Default) = "{A0752120-6D75-D111-B5B1-0800095A2318}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\tsseCryp.dll" [null data]
Erasext\(Default) = "{8BE13461-936F-11D1-A87D-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Eraser\erasext.dll" ["-"]
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
EasyCryptoMenu\(Default) = "{A0752120-6D75-D111-B5B1-0800095A2318}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\tsseCryp.dll" [null data]
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
Erasext\(Default) = "{8BE13461-936F-11D1-A87D-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Eraser\erasext.dll" ["-"]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
Active Desktop and Wallpaper:
—————————–
Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Joost\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"
Startup items in "Joost" & "All Users" startup folders:
——————————————————-
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten
"Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
"Adobe Reader Snelle start" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]
Enabled Scheduled Tasks:
————————
"Herinnering voor registratie 1" -> launches: "C:\WINDOWS\System32\OOBE\oobebaln.exe /sys /r /n:1" [MS]
"Herinnering voor registratie 2" -> launches: "C:\WINDOWS\System32\OOBE\oobebaln.exe /sys /r /n:2" [MS]
"Herinnering voor registratie 3" -> launches: "C:\WINDOWS\System32\OOBE\oobebaln.exe /sys /r /n:3" [MS]
"Norton AntiVirus - Mijn computer scannen - Joost" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe /task:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]
"SyncBack Back-up Excel" -> launches: "C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe -m "Back-up Excel"" ["2BrightSparks"]
"SyncBack Back-up Word" -> launches: "C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe -m "Back-up Word"" ["2BrightSparks"]
Winsock2 Service Provider DLLs:
——————————-
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
————————————
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" = "Norton Internet Security"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\ = "Real.com" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Shdocvw.dll" [MS]
Dormant Explorer Bars in "View, Explorer Bar" menu
HKLM\Software\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\ = "Easy-WebPrint"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll" ["Sun Microsystems, Inc."]
{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\
"ButtonText" = "Real.com"
Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————
C-DillaCdaC11BA, C-DillaCdaC11BA, "C:\WINDOWS\system32\drivers\CDAC11BA.EXE" ["C-Dilla Ltd"]
ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"]
InCD Helper, InCDsrv, "C:\Program Files\Ahead\InCD\InCDsrv.exe" ["Ahead Software AG"]
ISSvc, ISSVC, ""C:\Program Files\Norton Internet Security\ISSVC.exe"" ["Symantec Corporation"]
Netropa NHK Server, nhksrv, "C:\Apps\ActivBoard\nhksrv.exe" [null data]
Norton AntiVirus Auto-Protect-service, navapsvc, ""C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"]
NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\System32\nvsvc32.exe" ["NVIDIA Corporation"]
Symantec Core LC, Symantec Core LC, "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" ["Symantec Corporation"]
Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
Symantec Network Drivers Service, SNDSrvc, ""C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"" ["Symantec Corporation"]
Symantec Network Proxy, ccProxy, ""C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"" ["Symantec Corporation"]
Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"]
Symantec SPBBCSvc, SPBBCSvc, ""C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"" ["Symantec Corporation"]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]
Keyboard Driver Filters:
————————
HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
"UpperFilters" = INFECTION WARNING! "msikbd2k" ["Netropa Corporation"]
Print Monitors:
—————
HKLM\System\CurrentControlSet\Control\Print\Monitors\
Canon BJ Language Monitor PIXMA iP3000\Driver = "CNMLM61.DLL" ["CANON INC."]
Canon BJ Language Monitor S100\Driver = "CNMLM3A.DLL" ["CANON INC."]
———-
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 113 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 29 seconds.
———- (total run time: 203 seconds)
6. As to your other questions, Phil:
If I try to remember when the speed slowed down, I can think of the following:
- SP2
- various Windows Updates (they are installed automaticaly)
- Azureus (i.e. a torrent program to download music and movies using torrents)
- Pinnacle Studio 9
- Office XP Suite (Word, Excel, Power Point, erc.)
- Google Earth
- Music Stream (a service provided by my Internet Service Provider to legally download music)
- Ewido Security Suite.
On each of these installations I had the impression my PC got slower. I tried if deinstalling e.g. Google Earth would make a difference, but it did not.
But despite the gradual increase in slowness, for a long time I got a desktop with all the icons appearing in one single moment upon start-up (i.e. after the Windows XP welcome screen), whereas since a month (or is it two months?) I first get the desktop background, then all the icons in white and after that, at a very slow pace, the icons fill up to their normal appearance one by one. This is an extremely slow process. At this moment one gets the impression that some (hidden?) process is using up all the memory of the PC.
7. Now as to Ken's questions:
Make and model of my PC: Packard bell, iMedia 3700
Bought in November 2001
Processor tpye and speed: AMD Athlon XP 1700+; cloclspeed 1,47 Ghz
Motherboard maker: Explorer
Amount of memory: 512 MB
Hard drive make and size: Make unknown (does ST340810A mean something to you?), size 40 GB (actually 37,2 GB available) of which 6,06 GB free.
I defragmented recently, but this did not yield any noticeable results.
A year ago, I added a Maxtor 160 GB hard disk, of which 109 GB is still free. At the same time I added 256 MB memory (i.e. I ugraded from 256 to 512) and I installed a DVD rewriter. But it all has worked fine and smooth (and fast!) for quite a while, so I don't think the source of the problem is there. Otherwise no new hardware installed other than a Canon Pixma inkjet printer a couple of months ago.
I look forward to your views with much interest.
Kind regards,
JvdV
1)These items:
C:\windows\system32\netpole.dll
C:\WINDOWS\system32\netpal2.dll
C:\WINDOWS\system32\sstep.dll
I would like to know more about these. Use the following free online scans, post the results.
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html
Once you have established they are bad, then use this tool to remove them:
http://forum.malwareremoval.com/viewtopic.php?t=320
You may not find them unless you enable hidden files:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html
2)
Not sure yet, considering and researching.I tried to run the Panda Software scan a couple of times, but it failed each time at the same spot, i.e. after some 250 files whilst processing the file C:\windows\explorer.exe. Does this point in any direction?
3)
Open NAV quarantine area and delete anything in there.I ran the Kaspersky scan and it gave the following results:
4) SilentRunners, nothing jumps out at me…This one is unusual, but there is no file to delete so I am not sure what it means. I am asking a Finish friend to take a look and will let you know when I hear from him if it means anything:
HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
"UpperFilters" = INFECTION WARNING! "msikbd2k" ["Netropa Corporation"]
5) Since I asked these questions and you were nice enough to answer them, I will try to respond.
SP2: There is no doubt you will experience a slowdown with the installation of SP2. Microsoft knew this would happen and tried to warn folks to make sure their computer was prepared for the installation:
http://www.microsoft.com/windowsxp/sp2/sp2_whattoknow.mspx
various Windows Updates (they are installed automaticaly) it happens here also, some folks have to remove some of these because they effect their computer so dramatically. I don't know how to advise you here. It would require something like removing them all and installing them one at a time to see if you can spot one update that slows you dramatically. You can also go into your update history and read about each of the downloads looking for a clue.
- Azureus (i.e. a torrent program to download music and movies using torrents)
- Pinnacle Studio 9
- Office XP Suite (Word, Excel, Power Point, erc.)
- Google Earth
- Music Stream (a service provided by my Internet Service Provider to legally download music)
We are getting way away from my area now, but a few thoughts off the record: First, and you probably did not, you should never install more than one program at a time, then allow time to see if the installation is going to have any negative impact on your configuration. At this point troubleshooting would require removing the programs one at a time looking for any significant change in overall performation. It is a tough way to troubleshoot.
Ewido Security Suite. Now there is no doubt during the trial period ewido uses a lot of resources. Once the trial period is over, if the program is not running it will do nothing to slow you down until you activate it to run a scan. If you do not use ewido, at this point you may want to uninstall it completely? Your call.
I may be wrong, and I have been wrong before, but you keep mentioning a "Hidden" process. I am beginning to believe it is the visable processes slowing you down and not something hidden.
Here is another program you can run that has just updated and now locates some new stuff. Be aware you will be adding a porgram and that is certainly not going to make your computer run faster.
You may give it a try if you wish:
Download SpySweeper Trial (on right side of page):
http://www.webroot.com/consumer/products/spysweeper
Install SpySweeper v4.5 (Double click: ssfsetup1_….)
Follow the prompts and do a Typical installation
Click: Install, make sure Run SpySweeper Now is checked, and click Finish.
Update the program definitions
Select: Sweep
It will take a while to scan the computer.
When the scan is done, remove whatever it finds.
Then, press the Results button
Select the Session Log tab
Select: Save to File
Save wherever is convenient
Copy/Paste the results in your response.
Post the SpySweeper Session log, and I would also like to see a new HijackThis log.
PCPitStop is offering a free scan that may give you some ideas, if you would like it try that here is the link:
http://www.pcpitstop.com/store/optimizescan.asp
I have lost track of what we have tried, if you have not run a diagnostic at PCPitStop, I suggest you do. They also have a forum there were they will help you understand the results of your tests.
http://www.pcpitstop.com/
Thanks…Phil
Adding this because of the additional post you made.
1) That is the way it should be set, one firewall at a time.
2) Humm, that is what you pay their technical support for and they just raised their rates. As we discussed before, NAV is very resource heavy. It may be that this security suite will slow down an older system like your and there may be nothing you can do about it. I would be interested in hearing what they say myself and it is not even my computer.
3) Yes…AVG by Grisoft does not contain a firewall, and the SP2 firewall would have to be activated.
just passed by as the guys asked me to take a peek
have you ever installed actmon keystroke logger ? or is it currently installed
http://www.actmon.com/
1. I misread my own handwriting. The file netpole.dll that was found by the Housecall scan should have read netpal2.dll, i.e. the same file as appeared in the results of the Kaspersky scan.
I performed the further analysis of netpal2.dll and sstep.dll and the results are as follows:
File: netpal2.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 4b1f35cd594a1229c58788b2e311d2a1
Packers detected: -
Scanner results
AntiVir Found nothing
ArcaVir Found Trojan.Adbreak.E
Avast Found nothing
AVG Antivirus Found BackDoor.Adbreak.F
BitDefender Found nothing
ClamAV Found Trojan.BHO-1
Dr.Web Found STPAGE.Trojan (probable variant)
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Backdoor.Win32.Adbreak.e
NOD32 Found a variant of Win32/Adware.NetPal application
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found nothing
—————————————————————————————————————————
File: sstep.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 494777b05f15b579984e02e38d594d84
Packers detected: UPX
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Trojan-Dropper.Win32.Small.so
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found Adware.ShopAtHome.6 (probable variant)
—————————————————————————————————————————
This is a report processed by VirusTotal on 10/23/2005 at 23:31:01 (CET) after scanning the file "netpal2.dll" file.
Antivirus Version Update Result
AntiVir 6.32.0.6 10.22.2005 no virus found
Avast 4.6.695.0 10.21.2005 no virus found
AVG 718 10.21.2005 BackDoor.Adbreak.F
Avira 6.32.0.6 10.22.2005 no virus found
BitDefender 7.2 10.22.2005 no virus found
CAT-QuickHeal 8.00 10.22.2005 no virus found
ClamAV devel-20050917 10.21.2005 no virus found
DrWeb 4.32b 10.23.2005 no virus found
eTrust-Iris 7.1.194.0 10.23.2005 no virus found
eTrust-Vet 11.9.1.0 10.21.2005 no virus found
Fortinet 2.48.0.0 10.22.2005 no virus found
F-Prot 3.16c 10.20.2005 no virus found
Ikarus 0.2.59.0 10.21.2005 no virus found
Kaspersky 4.0.2.24 10.23.2005 Backdoor.Win32.Adbreak.e
McAfee 4610 10.21.2005 potentially unwanted program Adware-NetPals
NOD32v2 1.1263 10.21.2005 a variant of Win32/Adware.NetPal
Norman 5.70.10 10.21.2005 no virus found
Panda 8.02.00 10.23.2005 Adware/NetPals
Sophos 3.98.0 10.23.2005 no virus found
Symantec 8.0 10.23.2005 no virus found
TheHacker 5.8.4.127 10.21.2005 Adware/NetPals
VBA32 3.10.4 10.23.2005 no virus found
————————————————————————————————————————–
This is a report processed by VirusTotal on 10/23/2005 at 23:34:37 (CET) after scanning the file "sstep.dll" file.
Antivirus Version Update Result
AntiVir 6.32.0.6 10.22.2005 no virus found
Avast 4.6.695.0 10.21.2005 no virus found
AVG 718 10.21.2005 no virus found
Avira 6.32.0.6 10.22.2005 no virus found
BitDefender 7.2 10.22.2005 no virus found
CAT-QuickHeal 8.00 10.22.2005 no virus found
ClamAV devel-20050917 10.21.2005 no virus found
DrWeb 4.32b 10.23.2005 no virus found
eTrust-Iris 7.1.194.0 10.23.2005 no virus found
eTrust-Vet 11.9.1.0 10.21.2005 no virus found
Fortinet 2.48.0.0 10.22.2005 no virus found
F-Prot 3.16c 10.20.2005 no virus found
Ikarus 0.2.59.0 10.21.2005 no virus found
Kaspersky 4.0.2.24 10.23.2005 Trojan-Dropper.Win32.Small.so
McAfee 4610 10.21.2005 Generic MultiDropper.f
NOD32v2 1.1263 10.21.2005 no virus found
Norman 5.70.10 10.21.2005 no virus found
Panda 8.02.00 10.23.2005 Adware/SideStep
Sophos 3.98.0 10.23.2005 no virus found
Symantec 8.0 10.23.2005 no virus found
TheHacker 5.8.4.127 10.21.2005 Adware/180Solutions
VBA32 3.10.4 10.23.2005 suspected of Adware.ShopAtHome.6
————————————————————————————————————————
Do these results confirm that both files are infected and should be deleted (or cleaned)? Please confirm. I am not sure how exactly the malware removal tool you mentioned works.
2. I cleaned the items in the NAV quarantaine section.
3. I did a run with Spy Sweeper and the log of that is as follows:
********
23:55: | Start of Session, zondag 23 oktober 2005 |
23:55: Spy Sweeper started
23:55: Sweep initiated using definitions version 560
23:55: Starting Memory Sweep
23:57: Memory Sweep Complete, Elapsed Time: 00:01:51
23:57: Starting Registry Sweep
23:57: Registry Sweep Complete, Elapsed Time:00:00:17
23:57: Starting Cookie Sweep
23:57: Cookie Sweep Complete, Elapsed Time: 00:00:00
23:57: Starting File Sweep
0:06: Found System Monitor: ufp 007 spy
0:06: unins000.exe (ID = 48061)
0:06: Found Adware: ignkeys
0:06: nlnupgradev4_5p13.exe (ID = 63471)
0:11: uninstall unidream photoplayer.lnk (ID = 48061)
0:11: File Sweep Complete, Elapsed Time: 00:13:34
0:11: Full Sweep has completed. Elapsed time 00:15:47
0:11: Traces Found: 3
0:12: Removal process initiated
0:12: Quarantining All Traces: ufp 007 spy
0:12: Quarantining All Traces: ignkeys
0:12: Removal process completed. Elapsed time 00:00:01
********
23:47: | Start of Session, zondag 23 oktober 2005 |
23:47: Spy Sweeper started
23:48: Your spyware definitions have been updated.
23:55: | End of Session, zondag 23 oktober 2005 |
How bad are the traces that have been found?
4. We already ran Pitstop before. I ran it again at it gave no special results other than some obsolete registry entries.
5. My HJT log currently looks like this:
Logfile of HijackThis v1.99.1
Scan saved at 0:32:33, on 24-10-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijack This\hijackthis versie 1.99.0.1\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer geleverd door CompuServe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\personal_investor_informer\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientIn…6/OCI/setup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://webdisk.planet.nl/webdisk/objects/u…geUploader3.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/74914…IPSUploader.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
6. Any further feedback you received on the items in my previous post?
7. What should I do with illukka's remark? Should I install a kystroke logger????
Kind regards,
JvdV
Killbox is a tool that will remove those files for you. This link includes a tutorial for it's use. This is a public link at a forum I know well, follow the instructions and you will have no problems:
http://forum.malwareremoval.com/viewtopic.php?t=320
Hard to tell, but we have them quarantined. after a week or so, empty the quarantine area. I can't think of a valid program that does not quarantine, except Spybot S&D and it calls it something else, Recovery. All quarantine areas should be cleaned out on a regular basis.How bad are the traces that have been found?
We may have run the diagnostic at PCPitStop but this link is to a tool which is a free trial version that just came to me today in my most recent copy of Langalist: http://www.pcpitstop.com/store/optimizescan.asp It is worth a try.We already ran Pitstop before. I ran it again at it gave no special results other than some obsolete registry entries.
Nope, any relevant information will be posted to you as I receive it.Any further feedback you received on the items in my previous post?
illukka is a good friend and a expert who I trust. He has only asked you a question here. He will give you only good advice and I suggest you supply any information he asks for if you can.What should I do with illukka's remark? Should I install a kystroke logger????
The question he asked again: To your knowledge
Logfile of HijackThis v1.99.1 Scan saved at 0:32:33, on 24-10-2005have you ever installed actmon keystroke logger ? or is it currently installed
http://www.actmon.com/
Did you install this service? Do you know why it is there? I would like to remove it if you know of no reason for it being there.
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
http://www.liutilities.com/products/wintas…brary/cdac11ba/
Do you know what product on your computer it may be associated with?
You can see more here: http://www.google.com/search?sourceid=navc…=CDAC11BA%2EEXE
Thanks
Hi Phil and Illukka,
1. I deleted the two fies with Killbox. No, NAV did not find these files.
2. I think I ran that same Pitstop programme before. In order to execute the suggested actions I apparently have to register and to buy the software. I did not do that.
3. To my knowledge I have never installed a keystroke logger. It sounds bad. Can we investigate this further and have it removed?
4. I have no clue what the file CDAC11BA.EXE might be associated with. I have fixed the entry in HJT. My log now looks like this:
Logfile of HijackThis v1.99.1
Scan saved at 17:13:48, on 24-10-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Hijack This\hijackthis versie 1.99.0.1\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planet.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer geleverd door CompuServe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\personal_investor_informer\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} - http://sib1.od2.com/common/Member/ClientIn…6/OCI/setup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://webdisk.planet.nl/webdisk/objects/u…geUploader3.cab
O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/74914…IPSUploader.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Regards,
JvdV
download registry search tools from here:
http://www.billsway.com/vbspage/
unzip the file to a folder on your desktop
Next, please reboot your computer in SafeMode by doing the following:
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.
then
double click on regrch.vbs, into the field "enter string to search" type or copy paste 4D36E96B-E325-11CE-BFC1-08002BE10318
and hit ok
save the result and after rebooting back to normal mode post it here
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI