1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Vista - Slow, with very strange behaviour

Discussion in 'Malware and Virus Removal Archive' started by quirkymac, 2008/07/04.

  1. 2008/07/04
    quirkymac

    quirkymac Inactive Thread Starter

    Joined:
    2006/09/07
    Messages:
    196
    Likes Received:
    0
    The strange behaviour is when I try and change 'channels' ie using the tabs between running programs on my task bar. Can't do it with a left click and when I use right click it sometimes works but often has a think about things before not doing anything then I have to start again.

    Deckard's System Scanner v20071014.68
    Run by HomePC on 2008-07-04 19:05:29
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- Last 5 Restore Point(s) --
    8: 2008-07-04 08:47:39 UTC - RP261 - Scheduled Checkpoint
    7: 2008-07-03 14:00:01 UTC - RP260 - Scheduled Checkpoint
    6: 2008-07-02 02:05:24 UTC - RP259 - Windows Update
    5: 2008-07-01 14:40:52 UTC - RP258 - Scheduled Checkpoint
    4: 2008-06-30 21:39:47 UTC - RP257 - Installed Microsoft Visual C++ 2005 Redistributable


    -- First Restore Point --
    1: 2008-06-28 15:13:29 UTC - RP254 - Scheduled Checkpoint


    Backed up registry hives.
    Performed disk cleanup.

    System Drive C: has 2.01 GiB (less than 15%) free.


    -- HijackThis (run as HomePC.exe) ----------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:10:14 PM, on 4/07/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\SYSTEM32\WISPTIS.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
    C:\Program Files\Grisoft\AVG7\avgcc.exe
    C:\Windows\System32\CtHelper.exe
    C:\Windows\System32\Ctxfihlp.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
    C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
    C:\Program Files\Microsoft IntelliType Pro\itype.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\SYSTEM32\CTXFISPI.EXE
    C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Users\HomePC\Desktop\dss.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\HomePC.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
    O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll "
    O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
    O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
    O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe "
    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe "
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe "
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
    O4 - Startup: µTorrent.lnk = C:\Program Files\uTorrent\uTorrent.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} (Image Uploader Control) - http://photomax.lifepics.com/net/Uploader/LPUploader45.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www4.snapfish.co.nz/SnapfishActivia.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
    O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.bigwphotos.com.au/en/Photo/ImageUploader4.cab
    O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
    O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

    --
    End of file - 7932 bytes

    -- File Associations -----------------------------------------------------------

    All associations okay.


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R3 mcdbus (Driver for MagicISO SCSI Host Controller) - c:\windows\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller>
    R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>

    S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>


    -- Device Manager: Disabled ----------------------------------------------------

    No disabled devices found.


    -- Files created between 2008-06-04 and 2008-07-04 -----------------------------

    2008-07-04 19:09:54 0 d-------- C:\Program Files\Trend Micro
    2008-07-01 07:39:46 0 d-------- C:\Program Files\Flickr Uploadr
    2008-06-28 22:47:03 0 --a------ C:\Windows\nsreg.dat
    2008-06-22 06:15:48 0 d-a------ C:\Users\All Users\TEMP
    2008-06-15 07:48:37 0 d-------- C:\Program Files\Vstplugins
    2008-06-15 07:48:28 0 d-------- C:\Users\All Users\Sony
    2008-06-12 23:49:57 102400 --a------ C:\Windows\system32\Tony Hawk HelmetCam.scr <Not Verified; Prime Entertainment; Tony Hawk HelmetCam Screen Saver>
    2008-06-12 23:49:57 180224 --a------ C:\Windows\system32\ijl11.dll <Not Verified; Intel Corporation; Intel® JPEG Library>
    2008-06-12 23:49:56 139264 --a------ C:\Windows\system32\AVITrim.dll <Not Verified; Intel Corp.; AVITrim Control Module>
    2008-06-12 23:49:56 126976 --a------ C:\Windows\system32\AVIClean.dll <Not Verified; Intel Corp.; AVIClean DLL>
    2008-06-12 23:48:36 0 d-------- C:\Program Files\Digital Blue
    2008-06-08 07:37:28 0 d-------- C:\Users\All Users\FLEXnet
    2008-06-08 07:35:19 1025 --a------ C:\Windows\system32\sysprs7.dll
    2008-06-08 07:35:19 73 --a------ C:\Windows\system32\ssprs.dll
    2008-06-08 07:35:19 205 --a------ C:\Windows\system32\lsprst7.dll
    2008-06-08 07:35:19 1025 --a------ C:\Windows\system32\clauth2.dll
    2008-06-08 07:35:19 1025 --a------ C:\Windows\system32\clauth1.dll
    2008-06-08 06:59:43 96896 --a------ C:\Windows\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller>
    2008-06-08 06:59:42 0 d-------- C:\Program Files\MagicDisc
    2008-06-08 06:57:09 0 d-------- C:\Program Files\MagicISO
    2008-06-07 21:22:38 0 d-------- C:\Program Files\Haali
    2008-06-07 21:22:18 0 d-------- C:\Program Files\CoreCodec
    2008-06-07 21:13:05 0 d-------- C:\Users\All Users\Minnetonka Audio Software
    2008-06-07 20:58:11 0 d-------- C:\Program Files\WinAce


    -- Find3M Report ---------------------------------------------------------------

    2008-07-04 18:53:44 0 d-------- C:\Users\HomePC\AppData\Roaming\AVG7
    2008-07-04 18:50:57 0 d-------- C:\Users\HomePC\AppData\Roaming\uTorrent
    2008-07-04 18:09:23 12 --a------ C:\Windows\bthservsdp.dat
    2008-07-02 22:31:21 0 d-------- C:\Users\HomePC\AppData\Roaming\Adobe
    2008-07-01 07:41:57 0 d-------- C:\Users\HomePC\AppData\Roaming\Flickr
    2008-06-28 22:47:02 0 d-------- C:\Users\HomePC\AppData\Roaming\Mozilla
    2008-06-22 06:31:55 0 d-------- C:\Program Files\Sony Setup
    2008-06-22 06:15:46 0 d-------- C:\Users\HomePC\AppData\Roaming\Sony
    2008-06-22 06:13:22 0 d-------- C:\Program Files\Sony
    2008-06-15 07:59:34 0 d-------- C:\Users\HomePC\AppData\Roaming\Publish Providers
    2008-06-14 06:51:43 0 d-------- C:\Program Files\Steam
    2008-06-14 06:45:53 0 d-------- C:\Program Files\Common Files\Steam
    2008-06-12 23:49:17 0 d--h----- C:\Program Files\InstallShield Installation Information
    2008-06-12 23:48:29 0 d-------- C:\Program Files\Common Files\InstallShield
    2008-06-12 03:08:50 0 d-------- C:\Program Files\Windows Mail
    2008-06-10 08:11:42 0 d-------- C:\Program Files\DivX
    2008-05-31 09:22:48 802816 --a------ C:\Windows\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
    2008-05-31 09:22:48 823296 --a------ C:\Windows\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
    2008-05-31 09:22:48 823296 --a------ C:\Windows\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
    2008-05-31 09:22:46 815104 --a------ C:\Windows\system32\divx_xx0a.dll <Not Verified; DivX, Inc.; DivX®>
    2008-05-31 09:22:46 683520 --a------ C:\Windows\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
    2008-05-27 07:43:02 0 d-------- C:\Users\HomePC\AppData\Roaming\U3
    2008-05-23 08:22:18 3596288 --a------ C:\Windows\system32\qt-dx331.dll
    2008-05-23 08:19:46 196608 --a------ C:\Windows\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
    2008-05-23 08:19:46 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
    2008-05-23 08:18:54 12288 --a------ C:\Windows\system32\DivXWMPExtType.dll
    2008-05-20 19:15:38 0 d-------- C:\Program Files\uTorrent
    2008-05-11 21:10:09 0 d-------- C:\Program Files\Castle Creations
    2008-04-17 20:53:19 138056 --ah----- C:\Windows\system32\mlfcache.dat
    2008-04-09 17:45:07 737280 --a------ C:\Windows\iun6002.exe <Not Verified; Indigo Rose Corporation; Setup Factory 6.0 Runtime Module>


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender "= "C:\Program Files\Windows Defender\MSASCui.exe" [19/01/2008 05:38 PM]
    "RCSystem "= "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [22/11/2006 04:55 PM]
    "AudioDrvEmulator "= "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [22/11/2006 04:55 PM]
    "UpdReg "= "C:\Windows\UpdReg.EXE" [11/05/2000 12:00 AM]
    "Adobe Reader Speed Launcher "= "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [11/01/2008 09:16 PM]
    "!AVG Anti-Spyware "= "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 07:25 PM]
    "AVG7_CC "= "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [28/06/2008 08:23 AM]
    "CTXFIREG "= "CTxfiReg.exe" [25/10/2007 08:52 PM C:\Windows\System32\CTXFIREG.EXE]
    "CTHelper "= "CTHELPER.EXE" [05/03/2007 05:09 PM C:\Windows\System32\CtHelper.exe]
    "CTxfiHlp "= "CTXFIHLP.EXE" [05/03/2007 05:09 PM C:\Windows\System32\Ctxfihlp.exe]
    "NvSvc "= "C:\Windows\system32\nvsvc.dll" [11/12/2007 04:06 PM]
    "NvCplDaemon "= "C:\Windows\system32\NvCpl.dll" [11/12/2007 04:06 PM]
    "NvMediaCenter "= "C:\Windows\system32\NvMcTray.dll" [11/12/2007 04:06 PM]
    "QuickTime Task "= "C:\Program Files\QuickTime\QTTask.exe" [28/03/2008 10:37 PM]
    "TrueImageMonitor.exe "= "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [14/09/2007 02:52 AM]
    "AcronisTimounterMonitor "= "C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [14/09/2007 03:02 AM]
    "Acronis Scheduler2 Service "= "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [14/09/2007 02:55 AM]
    "itype "= "C:\Program Files\Microsoft IntelliType Pro\itype.exe" [22/11/2006 11:08 AM]
    "IntelliPoint "= "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [06/02/2007 09:52 AM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools "= "C:\Program Files\DAEMON Tools\daemon.exe" [12/11/2006 08:48 PM]
    "ehTray.exe "= "C:\Windows\ehome\ehTray.exe" [19/01/2008 05:33 PM]
    "WMPNSCFG "= "C:\Program Files\Windows Media Player\WMPNSCFG.exe" [19/01/2008 05:33 PM]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "DevconDefaultDB "=C:\Windows\system32\READREG /SILENT /FAIL=1
    "CtxfiReg "=CTXFIREG.exe /FAIL1

    C:\Users\HomePC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [6/8/2008 6:59:42 AM]
    æTorrent.lnk - C:\Program Files\uTorrent\uTorrent.exe [5/20/2008 7:15:38 PM]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2/10/2008 4:36:54 AM]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin "=2 (0x2)
    "EnableLUA "=0 (0x0)
    "EnableUIADesktopToggle "=0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
    avgwlntf.dll 10/02/2008 03:57 AM 9216 C:\Windows\System32\avgwlntf.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages "= msv1_0 relog_ap

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
    @= "Driver "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
    @= "Driver "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @= "Volume shadow copy "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
    @= "IEEE 1394 Bus host controllers "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
    @= "SBP2 IEEE 1394 Devices "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
    @= "SecurityDevices "

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc
    LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
    bthsvcs BthServ


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d1a55c0-c8be-11dc-a0eb-00508db538f6}]
    AutoRun\command- G:\setup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4118ce63-d688-11dc-9148-806e6f6e6963}]
    AutoRun\command- J:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4118db08-d688-11dc-9148-00508db538f6}]
    AutoRun\command- J:\AutoPlay.exe -auto


    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    C:\Windows\system32\unregmp2.exe /ShowWMP

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



    -- End of Deckard's System Scanner: finished at 2008-07-04 19:11:39 ------------
     
  2. 2008/07/04
    quirkymac

    quirkymac Inactive Thread Starter

    Joined:
    2006/09/07
    Messages:
    196
    Likes Received:
    0
    Kaspersky report
    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7 REPORT
    Saturday, July 5, 2008
    Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Friday, July 04, 2008 19:42:32
    Records in database: 913699
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    I:\
    L:\
    M:\
    N:\

    Scan statistics:
    Files scanned: 238339
    Threat name: 5
    Infected objects: 8
    Suspicious objects: 0
    Duration of the scan: 03:06:22


    File name / Threat name / Threats count
    C:\Program Files\DAEMON Tools\SetupDTSB.exe Infected: not-a-virus:AdTool.Win32.WhenU.a 1
    D:\found.000\dir0011.chk\Nero-7.7.5.1_eng_trial.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1
    D:\found.000\file0026.chk Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1
    E:\Programs and drivers\codecs\DivXPro503GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 1
    E:\Programs and drivers\install programs\vnc-4_1_1-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1
    E:\Programs and drivers\install programs\vnc-4_1_1-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1
    E:\Programs and drivers\utilities\vnc-4_1_1-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1
    E:\Programs and drivers\utilities\vnc-4_1_1-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1

    The selected area was scanned.
     

  3. to hide this advert.

  4. 2008/07/05
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    OK, I'm not the expert in these matters, I just "borrowed" a piece that Geri would post....

    *********
    About P2P software ( Limewire, BitTorrent uTorrent etc… ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here,
    here and here.

    I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

    Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at Windowsbbs Virus and Spyware removal.
     
    Arie,
    #3
  5. 2008/07/05
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Additionally,

    This could be a contributing factor. Windows needs room to 'breathe'. Can you free up some space?

    Have a look at the cpu usage on the Processes tab in Task Manager. Anything consuming cpu cycles when idle?

    You could have a shell extension in conflict too. ShellExView is a utility that can be used to enable/disable shell extensions. Might want to use it to rule out shell extensions as a source of the problem.
     
  6. 2008/07/09
    quirkymac

    quirkymac Inactive Thread Starter

    Joined:
    2006/09/07
    Messages:
    196
    Likes Received:
    0
    ShellExview results

    Thanks for the tips so far. Hadn't remembered that I had installed the P2P software, I will get rid of it now.

    Results of ShellExView.... the only strange ones I could see were
    Haali Matroska Thumbnail Extractor No Thumbnail No No No No No No C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll {327669A0-59A7-4be9-B99E-1C9F3A57611A} 30/03/2008 1:42:20 AM 7/06/2008 9:23:01 PM No .mka, .mkv, MatroskaVideo A 159,744
    Haali Column Provider No Column Handler No No No No No No C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll {0561EC90-CE54-4f0c-9C55-E226110A740C} 30/03/2008 1:42:20 AM 7/06/2008 9:23:01 PM No Folder A 159,744
    Haali Matroska Shell Property Page No System No No No No No No C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll {5574006C-28F5-4a65-A28C-74DE6BFBE0BB} 30/03/2008 1:42:20 AM 7/06/2008 9:23:01 PM No A 159,744
     
  7. 2008/07/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    You are not necessarily looking for a strange shell extension (the one you list belongs to Haali Media Splitter ..... you install that app?), but systematically disabling shell extensions to see if it has any effect on your current problem.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.