Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
[Active] PC & Browser very sluggish and freezes up.
Hello,
I realize i only have 512mb of memory but my computer is substantially slower than normal and when i open my browser it takes forever. I have ordered 2GB of memory which i desperately needed, but i believe i have something loaded on the pc that is bogging it down. Today i downloaded Malwarebytes and that seem to clean up a few things and the computer is performing a little better. Please take a look at the logs, thanks in advance for you time and support.
Logfile of random's system information tool 1.04 (written by random/random)
Run by John at 2008-12-11 15:21:44
Microsoft Windows XP Professional Service Pack 3
System drive D: has 2 GB (17%) free of 10 GB
Total RAM: 512 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:21:46 PM, on 12/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
D:\WINDOWS\tasks\AppleSoftwareUpdate.job
D:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
D:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
D:\WINDOWS\tasks\User_Feed_Synchronization-{83F4F7A1-000B-4D4D-A342-6C1D0F7FD3AE}.job
D:\WINDOWS\tasks\WorkCenter LOS Sync.job
D:\WINDOWS\tasks\WorkCenter Schedule Sync.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{2F85D76C-0569-466F-A488-493E6BD0E955}]
dsWebAllowBHO Class - C:\Program Files\Windows Desktop Search\dsWebAllow.dll [2006-03-26 265432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - d:\program files\google\googletoolbar4.dll [2007-01-19 2403392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-10-13 737776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 546672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - d:\program files\google\googletoolbar4.dll [2007-01-19 2403392]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 546672]
info.txt logfile of random's system information tool 1.04 2008-12-11 15:21:48
======Uninstall list======
-->MsiExec.exe /I{CFB6DF29-69D7-4191-894E-C695BABD55B8}
-->MsiExec.exe /X{2642BE09-1F9F-4E18-AAD4-0258B9BCE611}
-->MsiExec.exe /X{F3CA9611-CD42-4562-ADAB-A554CF8E17F1}
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 D:\WINDOWS\INF\PCHealth.inf
102 Dalmatians Activity Center-->D:\WINDOWS\IsUninst.exe -fC:\PROGRA~2\DISNEY~1\DISNEY~1\DeIsL1.isu
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7}
Adobe Flash Player 10 ActiveX-->D:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Adobe Shockwave Player-->D:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE D:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe® Photoshop® Album Starter Edition 3.0-->MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
Advanced SystemCare 3-->"C:\Program Files\Advanced SystemCare 3\unins000.exe"
Age of Mythology - The Titans Expansion-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTXP.EXE" /runtemp /addremove
Age of Mythology-->"C:\Program Files\Microsoft Games\Age of Mythology\UNINSTAL.EXE" /runtemp /addremove
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
AusLogics Disk Defrag-->"C:\Program Files\Auslogics\AusLogics Disk Defrag\unins000.exe"
avast! Antivirus-->C:\Program Files\AVAST Virus Protection\aswRunDll.exe "C:\Program Files\AVAST Virus Protection\Setup\setiface.dll",RunSetup
AXIS Media Control-->rundll32 "D:\Program Files\Axis Communications\AXIS Media Control\AxisMediaControl.dll",UninstallMe
Backyard Soccer 2004-->D:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{BEE7766E-C99F-4735-A42B-77924324F253}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Cole2k Media - Codec Pack (Advanced) 6.0.9-->D:\WINDOWS\system32\C2MP\Uninst.exe
Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Computrainer-->D:\WINDOWS\st6unst.exe -n "D:\Program Files\ST6UNST.LOG"
Coupon Printer for Windows-->"C:\Program Files\Coupons\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml"
Disney's Dinosaur Activity Center-->D:\WINDOWS\IsUninst.exe -fD:\PROGRA~1\DISNEY~1\DINOSA~1\DeIsL5.isu
Encompass-->MsiExec.exe /X{2D1421F3-0E2C-4989-A146-64090A48701F}
EPSON Printer Software-->D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
Eusing Free Registry Cleaner-->C:\PROGRA~2\EUSING~1\UNWISE.EXE C:\PROGRA~2\EUSING~1\INSTALL.LOG
Form Fill (Windows Live Toolbar)-->MsiExec.exe /X{0FADC5B1-E0E8-4DCA-A1BF-8B3B6496207A}
Google Toolbar for Internet Explorer-->regsvr32 /u /s "d:\program files\google\googletoolbar4.dll"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"D:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
hp officejet g series-->D:\WINDOWS\system32\hpocon09.exe /u 1197912028 /d "hp officejet g series"
Imaginext(TM) Battle Castle-->D:\Program Files\Common Files\Imaginext(TM)\Uninstall\CastleUn.exe
iTunes-->MsiExec.exe /I{5878FF02-3B8F-4309-B4E5-0D3DB6F2E8E6}
J2SE Runtime Environment 5.0 Update 11-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110}
Java 2 Runtime Environment Standard Edition v1.3.1_10-->RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{68249B6E-B714-11D7-88E8-0050DA21757E}\Setup.exe" -uninst
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
JumpStart Parent Resource Center-->D:\WINDOWS\IsUninst.exe -fc:\PROGRA~2\games\JUMPST~1\PRC\DeIsL1.isu
JumpStart Typing-->D:\Program Files\Common Files\Knowledge Adventure\Uninstall\JSTypeUn.EXE
Kid Pix Studio Deluxe-->D:\WINDOWS\TLCUninstall.exe -f "D:\Program Files\The Learning Company\Kid Pix Studio Deluxe\Uninstall.xml"
LimeWire 4.18.8-->"C:\Program Files 2\LimeWire\uninstall.exe"
Live Search Maps Add-In for Microsoft Office Outlook-->MsiExec.exe /I{EB9A4856-C28A-4BC2-9373-975A33BB9CD4}
Loan Analyzer Comparator-->MsiExec.exe /I{6E0DC0CF-B594-43DD-AF09-16409CD8BAE9}
LoanMagic v4-->C:\Program Files\Document Systems, Inc\LoanMagic\uninst.exe
Logitech QuickCam-->MsiExec.exe /I{466B21EE-2858-4845-B2B3-056FC544DAA3}
Logitech® Camera Driver-->"D:\Program Files\Common Files\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Map Button (Windows Live Toolbar)-->MsiExec.exe /X{59932D51-F260-4EF6-A784-4F69659F1A62}
MeridianLink Site Security Certificate-->C:\PROGRA~2\MERIDI~1\SITESE~1\UNWISE.EXE C:\PROGRA~2\MERIDI~1\SITESE~1\INSTALL.LOG
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"D:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "D:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninst all.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft ActiveSync-->MsiExec.exe /I{99052DB7-9592-4522-A558-5417BBAD48EE}
Microsoft Command & Control Engine-->RunDll32 advpack.dll,LaunchINFSection D:\WINDOWS\INF\mscnc.inf, Uninstall
Microsoft Data Access Components KB870669-->D:\WINDOWS\muninst.exe D:\WINDOWS\INF\KB870669.inf
Microsoft Internationalized Domain Names Mitigation APIs-->"D:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.ex e"
Microsoft National Language Support Downlevel APIs-->"D:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst. exe"
Microsoft Office Publisher 2003-->MsiExec.exe /I{91190409-6000-11D3-8CFE-0150048383C9}
Microsoft Office XP Professional-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0050048383C9}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Speech API 3.0-->RunDll32 advpack.dll,LaunchINFSection D:\WINDOWS\INF\spchapi.inf, Uninstall
Microsoft Speech Lexicon-->RunDll32 advpack.dll,LaunchINFSection D:\WINDOWS\INF\mslex.inf, Uninstall
Microsoft Visual J# .NET Redistributable Package 1.1-->MsiExec.exe /X{684FD900-B874-4A02-90E1-E65305D72B6B}
Microsoft Visual J# 2.0 Redistributable Package-->D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft Visual J# 2.0 Redistributable Package\install.exe
MSN Money Toolbar Add-in-->MsiExec.exe /I{8DD01BB5-720A-4161-9A59-8450597FA9AC}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML4 Parser-->MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13}
Natural Color-->RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{F51D9393-BB14-4566-99BF-D6ED63AEFCD7}\setup.exe"
NotePadSync-->C:\Program Files\InstallShield Installation Information\{14A19F58-528A-4ACC-8723-F6854B39CACC}\setup.exe -runfromtemp -l0x0009 -removeonly
NVIDIA Display Driver-->D:\WINDOWS\System32\nvudisp.exe Uninstall D:\WINDOWS\System32\nvdisp.nvu,NVIDIA Display Driver
NVIDIA WDM Drivers-->RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{B023185F-F1EF-4F97-B0BD-AE6D802226D1}\setup.exe"
OneCare Advisor (Windows Live Toolbar)-->MsiExec.exe /X{DF821FC5-C198-452B-A0D4-82433EFEAE9B}
Pdf995-->c:\pdf995\setup.exe uninstall
Photo Loader 2.3E-->RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{70B45586-B51E-4947-A258-A895596C5CED}\Setup.exe" -uninst
Photohands 1.0E-->RunDll32 D:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Program Files\InstallShield Installation Information\{544FB392-069D-4BA5-9DC7-FFD47230AEE5}\Setup.exe"
Popup Blocker (Windows Live Toolbar)-->MsiExec.exe /X{66034137-F1CE-4CEF-8180-46553C54DB18}
Pop-up Excel Calendar 1.2.2-->"C:\Program Files\OFFICE-KIT.COM\Pop-up Excel Calendar\unins000.exe"
QuickTime-->MsiExec.exe /I{55BF0E5F-EA8E-4C13-A8B4-9E4857F5A2DE}
Reader Rabbit's(R) Math Ages 6 - 9-->D:\Program Files\The Learning Company\Reader Rabbit's(R) Math Ages 6 - 9\uninstall.exe
Revo Uninstaller 1.75-->C:\Program Files\Revo Uninstaller\uninst.exe
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Windows Internet Explorer 7 (KB928090)-->"D:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)-->"D:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)-->"D:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)-->"D:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"D:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"D:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"D:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"D:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"D:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"D:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"D:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"D:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"D:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"D:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"D:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"D:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"D:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"D:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"D:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"D:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"D:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"D:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"D:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"D:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"D:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Smart Menus (Windows Live Toolbar)-->MsiExec.exe /X{1306C737-0AF4-46C7-B282-64E099304712}
SonicWALL SSL-VPN NetExtender-->D:\Program Files\SonicWALL\SSL-VPN\NetExtender\uninst.exe
Spybot - Search & Destroy 1.5.2.20-->"D:\WINDOWS\unins000.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
StatTrak for Baseball-->D:\WINDOWS\uninst.exe -f"c:\program files 2\DeIsL2.isu" -c"c:\program files 2\_ISREG32.DLL"
Tarzan Action Game-->D:\WINDOWS\IsUninst.exe -fC:\PROGRA~2\DISNEY~1\TARZAN~1\DeIsL1.isu
The Mystery of Veggie Island-->D:\WINDOWS\uninst.exe -fc:\PROGRA~2\games\VEGGIE~1\DeIsL1.isu
Toy Story 2-->D:\WINDOWS\IsUninst.exe -fC:\PROGRA~2\DISNEY~1\TOYSTO~1\DeIsL1.isu
Treasure Cove! CD-->D:\WINDOWS\IsUninst.exe -fc:\3133042c6699882c2c6a\Uninst\DeIsL1.isu
Treo 750 User Guide-->MsiExec.exe /X{9E4F351C-60AC-43DC-A38B-5C5F05B6B015}
U.B. Funkeys-->C:\Program Files\U.B. Funkeys\uninstall.exe
Uninstall TONKA Monster Trucks-->D:\WINDOWS\IsUninst.exe -f"c:\program files\games\Uninst.isu"
Update for Windows XP (KB955839)-->"D:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
WebEx-->D:\WINDOWS\DOWNLO~1\atcliun.exe
Windows Live Favorites for Windows Live Toolbar-->MsiExec.exe /X{786C4AD1-DCBA-49A6-B0EF-B317A344BD66}
Windows Live Outlook Toolbar (Windows Live Toolbar)-->MsiExec.exe /X{71CB529E-21A4-42AD-BF38-564F08988633}
Windows Live Toolbar Extension (Windows Live Toolbar)-->MsiExec.exe /X{D3F28364-8B10-45F1-8C2D-0037F4538BBB}
Windows Live Toolbar Feed Detector (Windows Live Toolbar)-->MsiExec.exe /X{328420FA-7638-4AB1-81DF-E0FECEFF24E3}
Windows Live Toolbar-->"C:\Program Files\Windows Live Toolbar\UnInstall.exe" {C6876FE6-A314-4628-B0D7-F3EE5E35C4B4}
Windows Live Toolbar-->MsiExec.exe /X{C6876FE6-A314-4628-B0D7-F3EE5E35C4B4}
Windows Media Format Runtime-->"D:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"D:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Mobile® Device Handbook-->C:\Program Files\Windows Mobile Device Handbook\Windows Mobile Device Handbook\Bin\DHUninstall.exe
Windows XP Service Pack 3-->"D:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
Yahoo! Install Manager-->D:\WINDOWS\system32\regsvr32 /u C:\PROGRA~2\Yahoo!\Common\YINSTH~1.DLL
Yahoo! Messenger-->D:\PROGRA~1\xerox\MESSEN~1\UNWISE.EXE /U D:\PROGRA~1\xerox\MESSEN~1\INSTALL.LOG
Hosts File Missing
John
Last edited by johnd1; 11th December 2008 at 23:29.
Reason: tpo :)
Didn't find the information you thought to find? Check out these Similar Threads
Please open MBAM and select the Logs tab.
Select a scan report then click View.
Post it's contents here.
If there is more than 1 recent log, post them all.
Download ComboFix by sUBs from here, saving the file to your desktop.
Please disable realtime protection applications as they sometimes interfere with the tool. Check this link for your applicable programs.
Close all open programs and windows
Double click ComboFix.exe and follow the prompts.
It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log in your next reply.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
**NOTE - I recommend you allow the Recovery Console to be downloaded and installed if or when prompted.
Hi Noah, here is the log you requested. I tried to turn off tea timer, i think i did it correctly. Thanks again for taking the time!!!
ComboFix 08-12-15.08 - John 2008-12-16 8:57:53.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.512.265 [GMT -8:00]
Running from: d:\documents and settings\John\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
.
Click Accept, when prompted to download and install the program files and database of malware definitions.
Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
Click View scan report at the bottom.
Click the Save Report As... button.
Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
**Note**
To optimize scanning time and produce a more sensible report for review:
Close any open programs.
Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.
Hi Noah, Yes it is performing much better since we ran the two removal applications noted above. The browser and the pc aren't freezing up anymore. The browser is still pretty slow to open when i click on the icon. Is this because i have the google toolbar with various icons (dictionary, mapquest, google maps, gmail) loading? I also noticed this
(Trusted Zone: *.frame.crazywinnings.com) in the above log...is this gone? does it have any impact on performance? Do you see any applications running at start up that i don't necessarily need? It seems like alot of stuff is loading but i don't know how or what to disable if anything.
Here is the Kaspersky Log. Thanks again Noah, much apprecaited!!
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, December 17, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, December 17, 2008 12:59:56
Records in database: 1468877
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan statistics:
Files scanned: 85673
Threat name: 7
Infected objects: 11
Suspicious objects: 0
Duration of the scan: 01:32:27
File name / Threat name / Threats count
C:\BACKUPS TO DISK\Backup personal settings and files 11.07.04.bkf Infected: Trojan.Java.ClassLoader.k 1
C:\BACKUPS TO DISK\Backup personal settings and files 11.07.04.bkf Infected: Trojan-Downloader.Java.OpenStream.c 1
C:\BACKUPS TO DISK\Backup personal settings and files 11.07.04.bkf Infected: not-a-virus:AdWare.Win32.BiSpy.f 2
C:\BACKUPS TO DISK\Backup personal settings and files 11.07.04.bkf Infected: not-a-virus:AdWare.Win32.BiSpy.m 2
C:\BACKUPS TO DISK\Backup personal settings and files 11.07.04.bkf Infected: not-a-virus:AdWare.Win32.HelpExpress 2
C:\BACKUPS TO DISK\Backup personal settings and files 11.07.04.bkf Infected: not-a-virus:AdWare.Win32.404Search.i 2
C:\BACKUPS TO DISK\Backup personal settings and files 11.07.04.bkf Infected: Exploit.HTML.Mht 1
Last edited by johnd1; 17th December 2008 at 18:24.
Reason: another typo ;).
Close all other open windows then click Fix Checked. Exit HijackThis when done.
You've got some infected files in the following backup.
C:\BACKUPS TO DISK\Backup personal settings and files 11.07.04.bkf
If that's something you can delete and create a new backup, I'd certainly recommend doing so.
Lets get ComboFix uninstalled. Click Start>Run and type ComboFix /u then hit Enter to uninstall ComboFix and remove the files it has quarantined. This action will also reset the System Restore points, removing any infected files there as well.
Verify the C:\Qoobox and C:\ComboFix folders were removed, as well as the C:\ComboFix.txt file.
You can delete any other logs that were created/saved too.
Delete RSIT.exe and the C:\rsit folder.
The Google toolbar may be a problem. Try disabling it to see if there's any improvement.