This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] PC has recently become cripplingly slow

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there
I'm new to the world of forums and I'm after some help as my PC has, over the last couple of days become INCREDIBLY slow on startup and also when on the internet.
When I've investigated the system with Windows task manager I've noticed that there are a couple of iexplore.exe files running which seem to use a lot of the memory.

I've run Hijack this and the log ile is below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:55:16, on 14/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\SolidWorks (2)\COSMOS\FloWorks\binCFW\StandAloneSlv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\documents and settings\steve brooks\local settings\application data\osygeqq.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.orange.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www1.euro.dell.com/content/default….;l=en&s=gen
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Virgin Net Broadband\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [osygeqq] "c:\documents and settings\steve brooks\local settings\application data\osygeqq.exe" osygeqq
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {1ED48504-8834-11D5-AC75-0008C73FD642} (ProductView Express) - file://C:\Program Files\proeWildfire 2.0\i486_nt\obj\pvx_install.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfipm.exe
O23 - Service: Backbone Service (BBDemon) - Dassault Systemes - C:\Program Files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Solver for COSMOSFloWorks 2006 - Unknown owner - C:\Program Files\SolidWorks (2)\COSMOS\FloWorks\binCFW\StandAloneSlv.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: Windows Log - Conexant Systems, Inc. - (no file)
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11601 bytes

I don't know what to do no. PLEASE help…
hello

Please download Navilog1 by IL-MAFIOSO:
http://pagesperso-orange.fr/il.mafioso/Navifix/Navilog1.exe
(*Alternate download location Here)

* Save it to your Desktop.
* Double-click on Navilog1.exe to install the program.
* When the installation is complete, the tool will start automatically.
* If it doesn't start automatically, please double-click on the Navilog1 shortcut on your Desktop to run it.
* Press E for English from the language Menu.
* Type 1 in the next Menu to select Search and press Enter.
* Wait for the Scan to finish (It may take a reasonable amount of time).
* Press any key as requested .
* A new document will be produced: fixnavi.txt.
* Please copy/paste the contents of this report in your next reply.

The report is also saved in the root of the directory, "%SystemDrive%\fixnavi.txt". (usually C:\fixnavi.txt)
Hi Rorschach112 Thanks very much for replying. I ran the Navilog1 program as you suggested and have attached the .txt file as requested. Whilst the scan was being carried out, the following messages appeared on my screen: Reg 32 LoadLibrary ("parametricobject.dll")failed-The specified module could not be found. Reg 32 LoadLibrary ("CSQuickTips.dll")failed-The specified module could not be found. Reg 32 LoadLibrary ("CFWVeiwerX.dll")failed-The specified module could not be found. Reg 32 Dll RegisterServer in vsflex7L.ocx succeeded Reg 32 LoadLibrary ("olch3x8.ocx")failed-The specified module could not be found. Reg 32 DllRegisterServer in CCXPButton.ocx succeeded Kind regards Steve

Attachments:

No need to attach the logs Steve

* Double-click on the Navilog1 shortcut icon from your Desktop to run it.
* Press E for English from the language Menu.
* Type 4 in the next Menu to select Manually cleaning Typing Adware Name and press Enter.
* The fix will require you to type the file name.
* Please type the following, exactly as it appears below in bold and then press Enter

osygeqq

* The fix will require you to type the file name again, please do so, and press Enter
* The tool will then advise you that it will restart your computer.
* Close all open windows and save personnal documents, if open, too.
* If your computer doesn't restart automatically, restart it manually.
* Choose your usual session.
* Wait for the *** Clean finished the … *** message (It may take a reasonable amount of time)
* A new document will be produced.
* Please copy/paste the contents of this report in your next reply.
* Your desktop will now appear.

Note : In the event you lose your desktop, press CTRL+ALT+Delete and run Explorer.exe as a new task.

The report is also saved in the root directory, %SystemDrive%\cleannavi.txt.. (usually C:\cleannavi.txt)
Hi Thanks for the reply I've just booted up my PC and tried to access Navilog1 to follow your instructions. Instead of it loading I get the following: LoadLibrary("parametricobject.dll")failed - The specified module could not be found. LoadLibrary("CSQuickTips.dll")failed - The specified module could not be found. LoadLibrary("CFWViewerX.dll")failed - The specified module could not be found. DllRegisterServer in vsflex7L.ocx succeeded. DllRegisterServer in olch2x8.ocx succeeded. LoadLibrary("olch3x8.ocx")failed - The specified module could not be found. DllRegisterServer in CCXPButton.ocx succeeded. Before the Navilog1 window disapears. This has happened a couple of times now and I've uninstalled Navilog1 and reinstalled it in the hope that this would cure the problem - to no avail. Any ideas whats going on? Regards Steve
do this then

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Hi

I've pasted the report below.

Thanks


ComboFix 09-01-13.04 - steve brooks 2009-01-15 23:02:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1502 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\steve brooks\Application Data\inst.exe
c:\documents and settings\steve brooks\Local Settings\Application Data\osygeqq.dat
c:\documents and settings\steve brooks\Local Settings\Application Data\osygeqq.exe
c:\documents and settings\steve brooks\Local Settings\Application Data\osygeqq_nav.dat
c:\documents and settings\steve brooks\Local Settings\Application Data\osygeqq_navps.dat
c:\program files\autorun.inf
c:\windows\system32\drivers\fad.sys
c:\windows\system32\Process.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_WINDOWS_LOG
——-\Service_Windows Log


((((((((((((((((((((((((( Files Created from 2008-12-15 to 2009-01-15 )))))))))))))))))))))))))))))))
.

2009-01-15 01:01 . 2009-01-15 17:25 d——– c:\program files\Navilog1
2009-01-14 21:45 . 2009-01-14 21:45 d——– c:\program files\Trend Micro
2009-01-14 21:04 . 2009-01-14 21:06 d——– c:\program files\ERUNT
2009-01-14 11:49 . 2008-12-07 11:20 d——– c:\program files\Crack + Read Me
2009-01-14 11:49 . 2007-07-17 10:19 2,891,656 –a—— c:\program files\XoftSpySE 4.33 Trial.exe
2009-01-14 09:19 . 2009-01-14 13:52 d——– c:\program files\XoftSpySE
2009-01-13 18:48 . 2008-04-13 18:45 26,112 –a—— c:\windows\system32\drivers\usbser.sys
2009-01-13 18:48 . 2008-04-13 18:45 26,112 –a—— c:\windows\system32\dllcache\usbser.sys
2009-01-11 20:55 . 2009-01-11 20:55 7,680 –ahs—- c:\windows\Thumbs.db
2009-01-10 23:59 . 2009-01-10 23:59 d——– c:\program files\AskTBar
2009-01-10 23:46 . 2009-01-10 23:46 d——– c:\documents and settings\steve brooks\Application Data\NeroDigital™
2009-01-07 13:41 . 2009-01-07 13:49 d——– c:\program files\proeWildfire 4.0
2009-01-06 17:50 . 2009-01-06 18:18 d——– c:\program files\Common Files\eDrawings2007
2009-01-06 14:05 . 2009-01-06 14:05 d——– C:\SolidWorks 2007
2009-01-05 21:32 . 2009-01-05 21:37 d——– c:\windows\system32\NtmsData
2009-01-05 21:05 . 2009-01-05 21:38 d——– c:\program files\SolidWorks 2007
2008-12-28 15:55 . 2008-12-28 15:55 d——– c:\windows\system32\scripting
2008-12-28 15:55 . 2008-12-28 15:55 d——– c:\windows\l2schemas
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\windows\system32\en
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\windows\system32\bits
2008-12-28 15:31 . 2008-12-28 15:31 d——– c:\windows\ServicePackFiles
2008-12-27 18:42 . 2008-12-27 18:42 410,984 –a—— c:\windows\system32\deploytk.dll
2008-12-25 11:41 . 2009-01-11 20:55 69 –a—— c:\windows\NeroDigital.ini
2008-12-24 12:32 . 2008-12-24 12:32 d——– c:\documents and settings\All Users\Application Data\Ahead
2008-12-24 10:41 . 2009-01-15 21:19 d——– c:\windows\system32\drivers\Avg
2008-12-24 10:41 . 2008-12-26 10:31 d——– c:\documents and settings\steve brooks\Application Data\AVGTOOLBAR
2008-12-24 10:41 . 2008-12-24 10:41 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-12-24 10:41 . 2008-12-24 10:41 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-12-23 22:52 . 2008-12-23 22:55 d——– c:\documents and settings\steve brooks\Application Data\Nero
2008-12-23 20:11 . 2009-01-11 11:07 d——– c:\program files\Nero
2008-12-23 20:10 . 2009-01-11 12:54 d——– c:\program files\Common Files\Nero
2008-12-23 20:10 . 2009-01-11 12:53 d——– c:\documents and settings\All Users\Application Data\Nero

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-15 22:21 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-01-15 09:25 ——— d—–w c:\documents and settings\steve brooks\Application Data\SolidWorks
2009-01-14 13:53 ——— d—–w c:\documents and settings\steve brooks\Application Data\uTorrent
2009-01-14 08:02 ——— d—–w c:\program files\Google
2009-01-13 19:01 ——— d—–w c:\program files\Nokia
2009-01-13 18:48 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-11 00:08 ——— d—–w c:\program files\Common Files\Ahead
2009-01-06 18:31 ——— d—–w c:\program files\Common Files\SolidWorks Shared
2009-01-06 18:20 ——— d—–w c:\program files\SolidWorks Installation Manager
2009-01-06 00:09 ——— d—–w c:\program files\eMule
2009-01-06 00:01 ——— d—–w c:\program files\LimeWire
2009-01-04 00:00 57,656 —-a-w c:\documents and settings\steve brooks\Application Data\GDIPFONTCACHEV1.DAT
2009-01-02 23:46 ——— d—–w c:\program files\Common Files\Autodesk Shared
2009-01-02 23:46 ——— d—–w c:\program files\Autodesk
2009-01-02 23:46 ——— d—–w c:\documents and settings\All Users\Application Data\Autodesk
2008-12-31 12:38 ——— d—–w c:\documents and settings\steve brooks\Application Data\ZoomBrowser EX
2008-12-28 17:26 ——— d—–w c:\program files\eMusic Download Manager
2008-12-28 12:12 ——— d—–w c:\documents and settings\All Users\Application Data\ZoomBrowser
2008-12-27 18:42 ——— d—–w c:\program files\Java
2008-12-26 11:20 ——— d—–w c:\program files\SolidWorks
2008-12-25 11:41 ——— d—–w c:\documents and settings\steve brooks\Application Data\Ahead
2008-12-15 23:16 ——— d—–w c:\program files\Ahead
2008-12-15 21:01 ——— d—–w c:\documents and settings\steve brooks\Application Data\Vso
2008-12-14 22:47 ——— d—–w c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-13 06:40 3,593,216 ——w c:\windows\system32\dllcache\mshtml.dll
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-11 10:57 333,952 ——w c:\windows\system32\dllcache\srv.sys
2008-11-28 16:38 ——— d—–w c:\program files\MSXML 6.0
2008-11-27 21:37 ——— d—–w c:\documents and settings\steve brooks\Application Data\EBookSys
2008-11-27 20:58 ——— d—–w c:\program files\iTunes
2008-11-27 20:58 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-27 20:57 ——— d—–w c:\program files\iPod
2008-11-27 20:57 ——— d—–w c:\program files\Common Files\Apple
2008-11-27 20:52 ——— d—–w c:\program files\QuickTime
2008-11-27 13:15 ——— d—–w c:\program files\ptc license
2008-11-26 03:26 ——— d—–w c:\documents and settings\steve brooks\Application Data\Ansys
2008-11-25 19:45 ——— d—–w c:\documents and settings\steve brooks\Application Data\Autodesk
2008-11-25 19:32 ——— d—–w c:\program files\AOEMView 2008
2008-11-25 19:31 ——— d—–w c:\program files\Microsoft WSE
2008-11-15 18:38 ——— d—–w c:\program files\PowerISO
2008-10-24 11:21 455,296 ——w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ——w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 14:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 14:13 202,776 —-a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 14:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 14:13 1,809,944 —-a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 14:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 14:12 561,688 —-a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 14:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 14:12 323,608 —-a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 14:09 92,696 —-a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 14:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 14:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 14:09 51,224 —-a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 14:09 43,544 —-a-w c:\windows\system32\wups2.dll
2008-10-16 14:08 34,328 —-a-w c:\windows\system32\wups.dll
2008-10-16 14:08 34,328 —-a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 14:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 13:11 70,656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824 ——w c:\windows\system32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408 ——w c:\windows\system32\dllcache\netapi32.dll
2008-10-15 07:06 633,632 ——w c:\windows\system32\dllcache\iexplore.exe
2008-10-15 07:04 161,792 ——w c:\windows\system32\dllcache\ieakui.dll
2008-08-07 22:09 47,360 —-a-w c:\documents and settings\steve brooks\Application Data\pcouffin.sys
2008-07-04 16:49 60,496,699 —-a-w c:\program files\Movie Magic Screenwriter.rar
2007-01-12 22:51 424 —-a-w c:\program files\Serial and Read Me.txt
2006-06-13 00:50 378,661 —-a-w c:\program files\winrar.zip
2006-05-17 20:32 638,125 —-a-w c:\program files\eMule.chm
2006-05-15 21:49 4,093,568 —-a-w c:\program files\LimeWireWin.exe
2006-05-04 16:23 4,677,596 —-a-w c:\program files\eMule0.47a-Installer.exe
2006-05-04 15:55 9,409,224 —-a-w c:\program files\Install_MSN_Messenger.exe
2006-05-04 15:25 10,035,280 —-a-w c:\program files\vsh_10021_home-use_enus.exe
2000-10-20 01:01 116,124 —-a-w c:\program files\SETUP.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-01-10 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-27 136600]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-12-15 839680]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-06 7118848]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-05-04 185896]
"SpeedTouch USB Diagnostics"="c:\program files\Virgin Net Broadband\Dragdiag.exe" [2004-01-26 866816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-24 1261336]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\steve brooks\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2006-03-13 233472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 15:08 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth Manager.lnk]
backup=c:\windows\pss\Bluetooth Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Push Client.LNK]
backup=c:\windows\pss\Push Client.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^steve brooks^Start Menu^Programs^Startup^Freecom Personal Media Suite.lnk]
backup=c:\windows\pss\Freecom Personal Media Suite.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wsqmaes

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-09-10 23:43 67488 c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
-ra—— 2005-10-07 05:13 176128 c:\program files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2005-07-06 23:52 7118848 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2005-07-06 23:52 1519616 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\pro_comm_msg.exe"=
"c:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\xtop.exe"=
"c:\\Program Files\\proeWildfire 2.0\\i486_nt\\nms\\nmsd.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\svchost.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Dassault Systemes\\B16\\intel_a\\code\\bin\\orbixd.exe"=
"c:\\Program Files\\Dassault Systemes\\B16\\intel_a\\code\\bin\\CNEXT.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-24 97928]
R1 LUMDriver;LUMDriver;c:\windows\system32\drivers\LUMDriver.sys [2003-07-11 14912]
R3 Bonifay;Bonifay;c:\windows\system32\drivers\Bonifay.sys [2006-11-28 12160]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-04-12 87936]
R4 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-10 124832]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-24 231704]
R4 BBDemon;Backbone Service;c:\program files\Dassault Systemes\B16\intel_a\code\bin\CATSysDemon.exe [2005-09-06 35840]
S3 Gonzales;Gonzales;c:\windows\system32\drivers\Gonzales.sys [2006-11-28 7040]
.
Contents of the 'Scheduled Tasks' folder

2008-12-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-01-15 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-06-03 12:19]

2008-09-11 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-06-03 12:19]

2009-01-15 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-07-13 08:43]

2009-01-14 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-07-13 08:43]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-osygeqq - c:\documents and settings\steve brooks\local settings\application data\osygeqq.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.orange.co.uk/
mStart Page = hxxp://www.orange.co.uk
uInternet Connection Wizard,ShellNext = hxxp://www1.euro.dell.com/content/default.aspx?c=uk&l=en&s=gen
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

O16 -: {1ED48504-8834-11D5-AC75-0008C73FD642} - file://c:\program files\proeWildfire 2.0\i486_nt\obj\pvx_install.exe
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-15 23:15:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1140)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2009-01-15 23:28:28
ComboFix-quarantined-files.txt 2009-01-15 23:28:08

Pre-Run: 3,645,685,760 bytes free
Post-Run: 3,622,232,064 bytes free

265 — E O F — 2009-01-15 01:42:30
Don't download cracks

Please download the OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wsqmaes]
    :Files
    c:\program files\Crack + Read Me
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
Hi Please see the log files below as requested: OT MoveIT log ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wsqmaes\\ not found. ========== FILES ========== c:\program files\Crack + Read Me moved successfully. ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_668.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01162009_181627 Files moved on Reboot… File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_668.dat not found! Rooter.exe log Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3 X86-based PC ( Uniprocessor Free : Intel® Pentium® M processor 1.73GHz ) BIOS : Default System BIOS USER : steve brooks ( Administrator ) BOOT : Normal boot Antivirus : AVG Anti-Virus Free 8.0 (Activated) C:\ (Local Disk) - NTFS - Total:55 Go (Free:3 Go) E:\ (CD or DVD) 16/01/2009|18:36 ———————-\\ Search.. ———————-\\ Rogues.. C:\PROGRA~1\AdwareAlert ———————-\\ Cracks & Keygens.. C:\DOCUME~1\STEVEB~1\Application Data\uTorrent\Adobe Photoshop Elements v6.0 (Full Version with Keygen).torrent C:\DOCUME~1\STEVEB~1\Desktop\inventor- pro-2008-keygen.exe C:\DOCUME~1\STEVEB~1\Desktop\license\keygen.bat C:\DOCUME~1\STEVEB~1\Recent\Pro Engineer Wildfire 4.0 C000 Win32 x86 WITH WORKING CRACK-iVAN.lnk 1 - "C:\Rooter$\Rooter_1.txt" - 16/01/2009|18:40 ———————-\\ Scan completed at 18:40 There is still a window Rooter.exe open stating"Cracks and Keygens.."
hello

Please download the OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\DOCUME~1\STEVEB~1\Application Data\uTorrent\Adobe Photoshop Elements v6.0 (Full Version with Keygen).torrent
    C:\DOCUME~1\STEVEB~1\Desktop\inventor- pro-2008-keygen.exe
    C:\DOCUME~1\STEVEB~1\Desktop\license\keygen.bat
    C:\DOCUME~1\STEVEB~1\Recent\Pro Engineer Wildfire 4.0 C000 Win32 x86 WITH WORKING CRACK-iVAN.lnk
    C:\PROGRA~1\AdwareAlert
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Do this as well please

Have a look for this file

C:\cleannavi.txt

Post that here if present



Then reboot into safe mode, and try run this step again

Please download Navilog1 by IL-MAFIOSO:
http://pagesperso-orange.fr/il.mafioso/Navifix/Navilog1.exe
(*Alternate download location Here)

* Save it to your Desktop.
* Double-click on Navilog1.exe to install the program.
* When the installation is complete, the tool will start automatically.
* If it doesn't start automatically, please double-click on the Navilog1 shortcut on your Desktop to run it.
* Press E for English from the language Menu.
* Type 1 in the next Menu to select Search and press Enter.
* Wait for the Scan to finish (It may take a reasonable amount of time).
* Press any key as requested .
* A new document will be produced: fixnavi.txt.
* Please copy/paste the contents of this report in your next reply.

The report is also saved in the root of the directory, "%SystemDrive%\fixnavi.txt". (usually C:\fixnavi.txt)
Hi

Please see the requested reports below

OTMoveIT3

Malwarebytes' Anti-Malware 1.33
Database version: 1659
Windows 5.1.2600 Service Pack 3

18/01/2009 10:34:48
mbam-log-2009-01-18 (10-34-43).txt

Scan type: Quick Scan
Objects scanned: 63745
Time elapsed: 28 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\AdwareAlert (Rogue.AdwareAlert) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\SETUP.EXE (Rogue.Installer) -> No action taken.

Cleanavi:

Navipromo Removal version 3.7.1 started on 15/01/2009 at 16:20:05.57

Fix running from C:\Program Files\navilog1
Actual User Account : "steve brooks"

Updated on 02.01.2009 at 19h00 by IL-MAFIOSO

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® M processor 1.73GHz )
BIOS : Default System BIOS
USER : steve brooks ( Administrator )
BOOT : Normal boot

Antivirus : AVG Anti-Virus Free 8.0 (Activated)


C:\ (Local Disk) - NTFS - Total:55 Go (Free:1 Go)
E:\ (CD or DVD)
I:\ (USB) - FAT32 - Total:28507 Mo (Free:7 Go)


Cleanning Stage done in normal mode and not on reboot
!! Results will not be optimised !!


Cleanning Stage done in normal mode and not on reboot
!! Results will not be optimised !!


Cleanning Stage done in normal mode and not on reboot
!! Results will not be optimised !!


Cleanning Stage done in normal mode and not on reboot
!! Results will not be optimised !!


Cleanning Stage done in normal mode and not on reboot
!! Results will not be optimised !!


Cleanning Stage done in normal mode and not on reboot
!! Results will not be optimised !!


*** Searching, making backups and deleting files ***

No Files entered !!


*** Deleting folders in "C:\WINDOWS" ***


*** Deleting folders in "C:\Program Files" ***


*** Deleting folders in "C:\Documents and Settings\All Users\startm~1\programs" ***


*** Deleting folders in "C:\Documents and Settings\All Users\startm~1" ***


*** Deleting folders in "c:\docume~1\alluse~1\applic~1" ***


*** Deleting folders in "C:\Documents and Settings\steve brooks\applic~1" ***


*** Deleting folders in "C:\DOCUME~1\ADMINI~1\applic~1" ***


*** Deleting folders in "C:\Documents and Settings\steve brooks\locals~1\applic~1" ***


*** Deleting folders in "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***


*** Deleting folders in "C:\Documents and Settings\steve brooks\startm~1\programs" ***


*** Deleting folders in "C:\DOCUME~1\ADMINI~1\startm~1\programs" ***



*** Deleting files ***


*** Deleting temporary files ***

Cleaning of C:\WINDOWS\Temp done !
Cleaning of C:\Documents and Settings\steve brooks\locals~1\Temp done !

*** Complementary Search ***
(Search specific files)

1)Deletion with backups new Instant Access files:

2)Heuristic search and deletion with backups :


* In "C:\WINDOWS\system32" *


* In "C:\Documents and Settings\steve brooks\locals~1\applic~1" *


* In "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *


*** Copy Registry to Safebackup folder ***

Backing up Registry done !

*** Cleaning Registry ***

Registry cleaned


*** Certificates ***

Egroup Certificate not found !
Electronic-Group Certificate deleted !
Montorgueil Certificate not found !
OOO-Favorit Certificate deleted !
Sunny-Day-Design-Ltd Certificate not found !

*** Search others known folders and files ***



*** Cleaning stage complete on 18/01/2009 at 12:12:34.95 ***

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI