This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Something Wrong .... So Slow

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Computer running so very slow for the last couple of weeks … keeps getting worse. I appreciate any help you can give …

Many thanks!



Logfile of HijackThis v1.99.1
Scan saved at 8:39:33 PM, on 6/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\wspan\swgw\FilterAgent.exe
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar6.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar6.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: QuickBooks Online Backup TaskBar Icon.LNK = C:\Program Files\QuickBooks Online Backup\OLSysTray.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Norton Personal Firewall.lnk = C:\Program Files\Norton Personal Firewall\nisfirst.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Worldspan Filter Agent.lnk = C:\wspan\swgw\FilterAgent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.worldspan.com
O15 - Trusted Zone: http://*.wspan.com
O16 - DPF: {03DF0933-6E10-4D32-9835-B9A815622831} (WSSystemInfo Class) - https://gopublic.wspan.com/secure/DLLs/WSSy…Information.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {7B72C3FC-34B5-4504-B4BE-EB38971A0888} (WSFileIO Class 3) - http://go.worldspan.com/Dlls/WSFileIO3.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://gopublic.wspan.com/Secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {F2C74EB6-1E7C-44A1-8EBA-CEDB52D47108} - https://gopublic.wspan.com/Secure/Dlls/WSClient.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Unknown owner - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Unknown owner - c:\Program Files\Norton Personal Firewall\NISUM.EXE (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (file missing)
Hi nursegirl and welcome to Tom Coyote! :)

Your log is clean. This may not be a malware problem, but we'll check.

Can you tell me more about the slowness? When does it happen?

In the meantime, please run this online scan…

Please do an online scan with Panda ActiveScan

- Once you are on the Panda site, click the Scan your PC button
- A new window will open…click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.

Post the contents of the Panda scan report.
I turned off my computer then restarted and running a bit better …. it seems after computer on for a while everything is slow, even my Outlook … for ex. to delete an email .. everything goes blank for about 5 seconds then it pops back up with that email gone …. a lot of times Internet Explorer just stops responding … initially yesterday when I tried to download the PandaScan (before I rebooted) it took 8 hours with nothing happening … After reboot I was able to download and run PandaScan, I will post the log for you to look at. Again, thanks for your help! Incident Status Location Adware:adware program Not disinfected c:\windows\system32\data.~ Adware:adware/portalscan Not disinfected c:\windows\system32\winupdt.008 Virus:vbs/psyme.gen Not disinfected Operating system Adware:adware/wintools Not disinfected Windows Registry Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Girl Friday LLC\Cookies\girl friday llc@atwola[2].txt Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Girl Friday LLC\Cookies\girl friday llc@burstnet[2].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Girl Friday LLC\Cookies\girl friday llc@cgi-bin[2].txt Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Girl Friday LLC\Cookies\girl friday llc@ct.360i[1].txt Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Girl Friday LLC\Cookies\girl friday llc@did-it[1].txt Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Girl Friday LLC\Cookies\girl friday llc@go[1].txt Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Girl Friday LLC\Cookies\girl friday llc@target[2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack [removed][1].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack [removed][2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack haynes@atwola[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack haynes@belnk[1].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack haynes@casalemedia[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack [removed][2].txt Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack haynes@go[1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack haynes@questionmarket[2].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack haynes@trafficmp[2].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack [removed][1].txt Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Jack Haynes\Cookies\jack [removed][2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Owner\Cookies\owner@go[1].txt Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Owner\Cookies\owner@target[2].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223120-261.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223120-405.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223120-490.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223120-586.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223120-652.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223120-722.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223120-763.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223121-106.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223121-200.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223121-206.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223121-413.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223121-500.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223121-551.dll Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\Owner\Desktop\backups\backup-20050221-223121-882.dll Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Shelby Haynes\Cookies\shelby haynes@go[1].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Shelby Haynes\Cookies\shelby [removed][1].txt Potentially unwanted tool:Application/HideWindow.A Not disinfected C:\hp\bin\FondleWindow.exe Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe Potentially unwanted tool:Application/KillApp.A Not disinfected C:\hp\bin\Terminator.exe Spyware:Spyware/ClearSearch Not disinfected C:\Program Files\6arxze0a\6arxze0a.dll Adware:Adware/Startpage.ACY Not disinfected C:\Program Files\Support.com\adelphia\scripts\IEconfig.vbs Adware:Adware/Beginto Not disinfected C:\RECYCLER\S-1-5-21-1584993097-548244230-269417757-500\Dc4.exe[reg6523.exe] Adware:Adware/ILookup Not disinfected C:\RECYCLER\S-1-5-21-1584993097-548244230-269417757-500\Dc4.exe[ic2_win.dll] Virus:Trj/Downloader.MDW Disinfected C:\RECYCLER\S-1-5-21-1584993097-548244230-269417757-500\Dc9.exe Spyware:Spyware/Apropos Not disinfected C:\WINDOWS\system32\Cache\BlazeVCM.exe[QuickBrowser.exe] Spyware:Spyware/Apropos Not disinfected C:\WINDOWS\system32\Cache\BlazeVCM.exe[QBAux.exe] Adware:Adware/Transponder Not disinfected C:\WINDOWS\system32\Cache\dr.exe Virus:Trj/Downloader.MDW Disinfected C:\WINDOWS\system32\Cache\pounder.exe
Hi nursegirl,

Please do the following…

1. Make sure you can view hidden files and folders:
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
2. Find and delete the following in RED:

c:\windows\system32\data.~
c:\windows\system32\winupdt.008
C:\Documents and Settings\Owner\Desktop\backups
C:\Program Files\6arxze0a
C:\Program Files\Support.com\adelphia\scripts\IEconfig.vbs
C:\WINDOWS\system32\Cache\BlazeVCM.exe

3. Download this file to your Desktop - combofix.exe
Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you. Post that log in your next reply, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
I was able to remove all but: c:\windows\system32\data.~ c:\windows\system32\winupdt.008 Could not find them …. my folder options were already set to your recommendations. Perhaps I am not looking in the right place … not to sound stupid but does the lower case "c" versus "C:" differentiate between the two? I will wait to run the other program until I hear back from you. Thanks!
Hi nursegirl,

For the above you could not remove, please run this tool:
  • Download OTMoveIt by OldTimer from here
  • Double click on OTMoveIt to start OTMoveIt
    [external image: Posted Image]
  • Untick the option to Unregister Dll's and Ocx's (1)
  • Select the contents of the below codebox, then press Ctrl+C to copy it to the clipboard
    c:\windows\system32\data.~
    c:\windows\system32\winupdt.008
  • In OTMoveIt Right click on the box labelled Paste List of Files/Folders to be Moved
  • Click Paste (2)
  • Click MoveIt! (3)
  • Copy and paste the contents of the results box (4) as a reply to this topic
Now run ComboFix, and post the two (ComboFix OTMoveIt) logs back here.
Hi Trogan_1000 -

Thank you for being so patient with me ….

Here is what I have -

c:\windows\system32\data.~ moved successfully.
c:\windows\system32\winupdt.008 moved successfully.

Created on 06/11/2007 21:27:52



ComboFix 07-06-11.3 - C:\Documents and Settings\Owner\Desktop\ComboFix.exe
"Owner" - 2007-06-11 21:45:56 - Service Pack 2 NTFS


((((((((((((((((((((((((( Files Created from 2007-05-12 to 2007-06-12 )))))))))))))))))))))))))))))))


2007-06-11 21:29 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-08 13:30 d——– C:\WINDOWS\system32\ActiveScan
2007-05-13 17:01 d——– C:\DOCUME~1\JACKHA~1\APPLIC~1\Apple Computer


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-08 23:26:38 ——– d—–w C:\Program Files\SpywareGuard
2007-06-08 23:26:35 ——– d—–w C:\Program Files\Spyware Doctor
2007-06-08 23:26:19 ——– d—–w C:\Program Files\QuickTime
2007-06-08 23:23:47 ——– d—–w C:\Program Files\Multimedia Card Reader
2007-06-08 23:22:14 ——– d—–w C:\Program Files\Messenger
2007-06-08 23:22:13 ——– d—–w C:\Program Files\Lexmark X1100 Series
2007-06-08 23:21:10 ——– d—–w C:\Program Files\iTunes
2007-06-08 23:08:32 ——– d—–w C:\Program Files\Google
2007-06-08 23:08:24 ——– d—–w C:\Program Files\Common Files\Symantec Shared
2007-05-04 23:35:52 ——– d—–w C:\Program Files\HP
2007-05-04 23:31:46 ——– d—–w C:\Program Files\Common Files\Real
2007-05-04 23:31:17 ——– d—–w C:\DOCUME~1\Owner\APPLIC~1\Real
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-15 14:37:53 ——– d—–w C:\Program Files\iPod
2007-04-15 14:32:58 ——– d—–w C:\Program Files\Apple Software Update
2007-03-17 13:43:01 292,864 —-a-w C:\WINDOWS\system32\winsrv.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{4A368E80-174F-4872-96B5-0B27DDD11DB2}=C:\Program Files\SpywareGuard\dlprotect.dll [2003-08-03 01:24]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]
{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}=C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll [2004-12-20 13:38]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar6.dll [2007-01-20 00:55]
{B56A7D7D-6927-48C8-A975-17DF180C71AC}=C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll [2005-01-21 15:32]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" []
"Sunkist2k"="C:\Program Files\Multimedia Card Reader\shwicon2k.exe" [2003-08-14 22:11]
"LTMSG"="LTMSG.exe" [2003-07-14 20:52 C:\WINDOWS\ltmsg.exe]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 06:43]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 23:02]
"ccRegVfy"="c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" []
"CamMonitor"="c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe" [2002-10-07 10:23]
"AutoTKit"="C:\hp\bin\AUTOTKIT.EXE" [2003-06-18 22:19]
"AcctMgr"="C:\Program Files\Norton Password Manager\AcctMgr.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2005-01-06 16:04]
"RecordNow!"="" []
"NVIEW"="nview.dll,nViewLoadHook" []
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-14 20:39]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS\oise.exe]
C:\WINDOWS\oise.exe


Contents of the 'Scheduled Tasks' folder
2007-06-07 14:47:05 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-11 04:00:00 C:\WINDOWS\tasks\Symantec Drmc.job
2007-06-11 22:10:19 C:\WINDOWS\tasks\Symantec NetDetect.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-11 21:49:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-06-11 21:50:03
C:\ComboFix-quarantined-files.txt … 2007-06-11 21:49

— E O F —


Logfile of HijackThis v1.99.1
Scan saved at 9:52:11 PM, on 6/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\wspan\swgw\FilterAgent.exe
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar6.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar6.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: QuickBooks Online Backup TaskBar Icon.LNK = C:\Program Files\QuickBooks Online Backup\OLSysTray.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Norton Personal Firewall.lnk = C:\Program Files\Norton Personal Firewall\nisfirst.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Worldspan Filter Agent.lnk = C:\wspan\swgw\FilterAgent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.worldspan.com
O15 - Trusted Zone: http://*.wspan.com
O16 - DPF: {03DF0933-6E10-4D32-9835-B9A815622831} (WSSystemInfo Class) - https://gopublic.wspan.com/secure/DLLs/WSSy…Information.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {7B72C3FC-34B5-4504-B4BE-EB38971A0888} (WSFileIO Class 3) - http://go.worldspan.com/Dlls/WSFileIO3.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://gopublic.wspan.com/Secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F2C74EB6-1E7C-44A1-8EBA-CEDB52D47108} - https://gopublic.wspan.com/Secure/Dlls/WSClient.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Unknown owner - c:\Program Files\Norton Personal Firewall\ccPxySvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Unknown owner - c:\Program Files\Norton Personal Firewall\NISUM.EXE (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SymWMI Service (SymWSC) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (file missing)



Don't know how all of this makes any sense to you …. good luck!
Hi nursegirl,

Not much showing in those log, but one suspicious file I'd liked scanned.
  • Go to VirusTotal
  • Copy and paste the following file path into the Search Box at the top of the page:
    • C:\WINDOWS\oise.exe
  • Click on the Send button
  • Save a copy of the results and post them in back here.
I also suggest uninstalling Party Poker as that is known to have malware within the game itself.
I don't know if we have done anything or not, but my computer is running so much better now from when we started. I uninstalled Party Poker and I just scanned file: oiseu.exe (I hope that is right because I couldn't find osie.exe)

Here are results:

STATUS: FINISHEDComplete scanning result of "oiseu.exe", received in VirusTotal at 06.12.2007, 19:30:10 (CET).

Antivirus Version Update Result
AhnLab-V3 2007.5.9.0 05.09.2007 no virus found
AntiVir 7.4.0.32 06.12.2007 no virus found
Authentium 4.93.8 06.12.2007 no virus found
Avast 4.7.997.0 06.12.2007 no virus found
AVG 7.5.0.467 05.08.2007 no virus found
BitDefender 7.2 06.12.2007 no virus found
CAT-QuickHeal 9.00 06.12.2007 no virus found
ClamAV devel-20070416 05.09.2007 no virus found
DrWeb 4.33 06.12.2007 no virus found
eSafe 7.0.15.0 05.08.2007 no virus found
eTrust-Vet 30.7.3713 06.12.2007 no virus found
FileAdvisor 1 06.12.2007 no virus found
Fortinet 2.85.0.0 06.12.2007 no virus found
F-Prot 4.3.2.48 05.08.2007 no virus found
F-Secure 6.70.13030.0 05.09.2007 no virus found
Ikarus T3.1.1.7 05.09.2007 no virus found
Kaspersky 4.0.2.24 06.12.2007 no virus found
McAfee 5051 06.12.2007 no virus found
Microsoft 1.2503 06.12.2007 Adware:Win32/QuickBrowser (threat-c)
NOD32v2 2325 06.12.2007 no virus found
Norman 5.80.02 06.12.2007 no virus found
Panda 9.0.0.4 06.12.2007 no virus found
Prevx1 V2 06.12.2007 Cptv.Windir.Malware
Sophos 4.18.0 06.12.2007 no virus found
Sunbelt 2.2.907.0 05.05.2007 QuickBrowser
Symantec 10 05.09.2007 no virus found
TheHacker [removed] 06.11.2007 no virus found
VBA32 [removed] 06.11.2007 no virus found
VirusBuster 4.3.23:9 06.12.2007 no virus found
Webwasher-Gateway 6.0.1 05.09.2007 no virus found


Aditional Information
File size: 2048 bytes
MD5: 57dfbefffe0982bab73ac72c6e0be293
SHA1: fddead7861154dd290b7f7c2bb159fff44037177
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PXC=24f6515189
Sunbelt info: QuickBrowser is an adware component that adds search windows.
Hi nursegirl

I don't know if we have done anything or not, but my computer is running so much better now from when we started.

Glad to hear it. If you remember earlier on you deleted some files and folders? They looked like the cause of problems.

Please use OTMoveIt, like you did previously, to delete the following file.

C:\WINDOWS\oise.exe

All the logs look clean now. If you don't have any problems or questions, can I mark this resolved?

You can delete OTMoveIt and ComboFix now.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI