1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active My PC is owrking TOO SLOW

Discussion in 'Malware and Virus Removal Archive' started by zeeshanhashmi, 2009/10/01.

  1. 2009/10/01
    zeeshanhashmi

    zeeshanhashmi Inactive Thread Starter

    Joined:
    2008/01/13
    Messages:
    77
    Likes Received:
    0
    [Active] My PC is owrking TOO SLOW

    Hi

    My computer is working too slow for the last couple of days. I am attaching the required DDS logs in my post below.

    Please also note that FIREFOX and CHROME (i do not use IE) sometimes become too slow and it seems that the computer is hanged, but its not hanged and start working after a moment but very slow.


    Thanks
    Zeeshan
     
  2. 2009/10/01
    zeeshanhashmi

    zeeshanhashmi Inactive Thread Starter

    Joined:
    2008/01/13
    Messages:
    77
    Likes Received:
    0
    DDS (Ver_09-09-29.01) - FAT32x86
    Run by Zeeshan Hashmi at 9:39:37.82 on Fri 10/02/2009
    Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1013.355 [GMT 5:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    SVCHOST.EXE
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    SVCHOST.EXE
    SVCHOST.EXE
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    D:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    D:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exe
    c:\program files\common files\mcafee\mna\mcnasvc.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\McAfee\MSK\MskSrver.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    D:\Program Files\MySQL\MySQL Server 5.1\bin\mysqld.exe
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
    C:\PROGRA~1\MICROS~3\rapimgr.exe
    D:\Program Files\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Zeeshan Hashmi\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = about:blank
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = *.local
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    uURLSearchHooks: H - No File
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
    BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
    TB: NuSphere ToolBar: {0f62d223-9206-4ea3-9ea8-d0f3c7c82aca} - c:\program files\nusphere\phped\NuSphereIEBar.dll
    TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
    EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
    uRun: [Google Update] "c:\documents and settings\zeeshan hashmi\local settings\application data\google\update\GoogleUpdate.exe" /c
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe "
    mRun: [iKeyWorks] c:\progra~1\a4tech\keyboard\Ikeymain.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [Acrobat Assistant 8.0] "d:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe "
    mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [SkyTel] SkyTel.EXE
    mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe "
    StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adobea~2.lnk - d:\program files\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe
    StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\micros~1.lnk - d:\program files\microsoft office\office11\ONENOTEM.EXE
    StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\monito~1.lnk - d:\program files\apache software foundation\apache2.2\bin\ApacheMonitor.exe
    IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZVfox000
    IE: Append to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert link target to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office11\EXCEL.EXE/3000
    IE: NuSphere PhpED :: Debug this page - c:\program files\nusphere\phped\NuSphereIEBar.dll/1000
    IE: Save YouTube Video as MP3
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
    IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office11\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {D4003189-95B1-4A2F-9A87-F2B03665960D} - hxxp://www.tvucricket.com/player/vjocx-en-black.cab
    Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: avgrsstarter - avgrsstx.dll
    Notify: igfxcui - igfxdev.dll
    SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digiwet.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\zeesha~1\applic~1\mozilla\firefox\profiles\dtdedgo9.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage -
    FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
    FF - plugin: c:\documents and settings\zeeshan hashmi\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
    FF - plugin: d:\program files\adobe\acrobat 8.0\acrobat\browser\nppdf32.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-9 335240]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-4-9 27784]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-9 108552]
    R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-11 214024]
    R2 Apache2.2;Apache2.2;d:\program files\apache software foundation\apache2.2\bin\httpd.exe [2008-12-10 24636]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-4-9 297752]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-2-6 92296]
    R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-1-11 359952]
    R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-1-11 144704]
    R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-1-11 606736]
    R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-1-11 79816]
    R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-1-11 35272]
    R3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-1-11 34248]
    R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-1-11 40552]
    S2 vvdsvc;VJVodClientServices;c:\windows\system32\svchost.exe -k vvdsvc [2004-8-3 14336]

    =============== Created Last 30 ================

    2009-09-15 21:29 <DIR> --d----- c:\program files\Iteral
    2009-09-12 00:09 <DIR> --d----- c:\windows\system32\Logs
    2009-09-11 12:57 <DIR> --d----- c:\docume~1\zeesha~1\applic~1\Trillian
    2009-09-08 18:44 <DIR> --d----- c:\program files\Microsoft
    2009-09-08 18:43 <DIR> --d----- c:\program files\Windows Live SkyDrive

    ==================== Find3M ====================

    2009-08-24 23:54 409,600 a------- c:\windows\system32\wrap_oal.dll
    2009-08-24 23:54 114,688 a------- c:\windows\system32\OpenAL32.dll
    2009-08-21 09:14 11,952 a------- c:\windows\system32\avgrsstx.dll
    2009-08-21 09:14 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll

    ============= FINISH: 9:43:34.46 ===============
     

  3. to hide this advert.

  4. 2009/10/01
    zeeshanhashmi

    zeeshanhashmi Inactive Thread Starter

    Joined:
    2008/01/13
    Messages:
    77
    Likes Received:
    0
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-09-29.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 1/11/2009 1:37:56 AM
    System Uptime: 10/2/2009 8:32:30 AM (1 hours ago)

    Motherboard: Intel Corporation | | D945GCCR
    Processor: Intel(R) Core(TM)2 CPU 4400 @ 2.00GHz | LGA 775 | 1995/200mhz

    ==== Disk Partitions =========================

    C: is FIXED (FAT32) - 37 GiB total, 3.378 GiB free.
    D: is FIXED (FAT32) - 37 GiB total, 33.779 GiB free.
    E: is FIXED (FAT32) - 37 GiB total, 35.499 GiB free.
    F: is FIXED (FAT32) - 37 GiB total, 30.632 GiB free.
    G: is CDROM ()
    H: is FIXED (FAT32) - 233 GiB total, 229.414 GiB free.

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: PCI Simple Communications Controller
    Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062011C1&REV_00\4&1E46F438&0&20F0
    Manufacturer:
    Name: PCI Simple Communications Controller
    PNP Device ID: PCI\VEN_11C1&DEV_0620&SUBSYS_062011C1&REV_00\4&1E46F438&0&20F0
    Service:

    ==== System Restore Points ===================

    RP202: 7/10/2009 10:32:06 AM - System Checkpoint
    RP203: 7/11/2009 1:35:58 PM - System Checkpoint
    RP204: 7/13/2009 6:59:35 PM - System Checkpoint
    RP205: 7/18/2009 6:33:03 AM - System Checkpoint
    RP206: 7/18/2009 1:34:06 PM - Avg8 Update
    RP207: 7/20/2009 10:13:06 AM - System Checkpoint
    RP208: 7/22/2009 6:31:04 PM - System Checkpoint
    RP209: 7/27/2009 10:03:07 AM - System Checkpoint
    RP210: 7/28/2009 6:08:15 PM - System Checkpoint
    RP211: 7/30/2009 8:55:58 AM - System Checkpoint
    RP212: 7/31/2009 11:56:41 AM - System Checkpoint
    RP213: 8/1/2009 2:58:25 PM - System Checkpoint
    RP214: 8/7/2009 6:34:36 PM - Removed Skypeâ„¢ 3.8
    RP215: 8/17/2009 8:05:38 AM - System Checkpoint
    RP216: 8/18/2009 9:06:54 AM - System Checkpoint
    RP217: 8/19/2009 10:11:39 AM - System Checkpoint
    RP218: 8/21/2009 9:12:35 AM - Avg8 Update
    RP219: 8/21/2009 9:14:28 AM - Avg8 Update
    RP220: 8/22/2009 11:18:10 AM - System Checkpoint
    RP221: 8/23/2009 7:57:48 PM - System Checkpoint
    RP222: 8/24/2009 8:14:40 PM - System Checkpoint
    RP223: 8/24/2009 11:53:32 PM - Installed DirectX
    RP224: 8/25/2009 2:39:48 PM - Installed DirectX
    RP225: 8/27/2009 7:13:07 AM - System Checkpoint
    RP226: 8/29/2009 9:37:28 AM - System Checkpoint
    RP227: 8/30/2009 11:13:28 AM - System Checkpoint
    RP228: 8/31/2009 11:40:07 AM - System Checkpoint
    RP229: 9/1/2009 7:36:19 AM - Installed Windows Media Format Runtime
    RP230: 9/2/2009 9:56:16 AM - System Checkpoint
    RP231: 9/3/2009 10:06:47 AM - System Checkpoint
    RP232: 9/4/2009 9:49:35 PM - System Checkpoint
    RP233: 9/5/2009 11:07:22 PM - System Checkpoint
    RP234: 9/7/2009 6:17:16 AM - System Checkpoint
    RP235: 9/8/2009 10:07:32 AM - System Checkpoint
    RP236: 9/8/2009 6:29:07 PM - Removed Windows Live Sign-in Assistant
    RP237: 9/8/2009 6:29:31 PM - Removed Windows Live Upload Tool
    RP238: 9/9/2009 7:57:18 PM - System Checkpoint
    RP239: 9/10/2009 8:15:41 PM - System Checkpoint
    RP240: 9/12/2009 12:01:59 AM - System Checkpoint
    RP241: 9/13/2009 7:31:25 AM - System Checkpoint
    RP242: 9/14/2009 7:56:47 PM - System Checkpoint
    RP243: 9/15/2009 9:29:58 PM - Installed WhiteBoardMeeting
    RP244: 9/17/2009 6:56:11 AM - System Checkpoint
    RP245: 9/18/2009 7:30:54 AM - System Checkpoint
    RP246: 9/19/2009 10:21:45 PM - System Checkpoint
    RP247: 9/21/2009 6:40:24 PM - System Checkpoint
    RP248: 9/22/2009 10:56:17 PM - System Checkpoint
    RP249: 9/24/2009 9:58:42 AM - System Checkpoint
    RP250: 9/27/2009 9:39:33 PM - System Checkpoint
    RP251: 9/29/2009 9:59:27 AM - System Checkpoint
    RP252: 9/30/2009 10:20:33 AM - System Checkpoint

    ==== Installed Programs ======================

    3D Shadow by Lokas Software
    A4Tech iKeyWorks 7.72
    AAC Decoder
    Acrobat.com
    Add or Remove Adobe Creative Suite 3 Design Premium
    Adobe Acrobat 8 Professional
    Adobe AIR
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe BridgeTalk Plugin CS3
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Color - Photoshop Specific
    Adobe Color Common Settings
    Adobe Color EU Extra Settings
    Adobe Color JA Extra Settings
    Adobe Color NA Recommended Settings
    Adobe Creative Suite 3 Design Premium
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe Dreamweaver CS3
    Adobe ExtendScript Toolkit 2
    Adobe Extension Manager CS3
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Fonts All
    Adobe Help Viewer CS3
    Adobe InDesign CS3
    Adobe InDesign CS3 Icon Handler
    Adobe Linguistics CS3
    Adobe MotionPicture Color Files
    Adobe PDF Library Files
    Adobe Photoshop CS3
    Adobe Reader 9.1
    Adobe Setup
    Adobe Shockwave Player 11.5
    Adobe SING CS3
    Adobe Stock Photos CS3
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Adobe WAS CS3
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS3
    AHV content for Acrobat and Flash
    Apache HTTP Server 2.2.11
    Apple Software Update
    Ask Toolbar
    AutoUpdate
    AVG 8.5
    CoffeeCup Web Form Builder - Trial
    Compatibility Pack for the 2007 Office system
    CSE HTML Validator Lite v6.52
    DivX Codec
    DivX Converter
    DivX Player
    DivX Plus DirectShow Filters
    DivX Version Checker
    DivX Web Player
    FileZilla Client 3.2.7.1
    Free Screen Recorder v2.9
    Free YouTube to Mp3 Converter version 3.1
    FSHED
    Google Chrome
    H.264 Decoder
    High Definition Audio Driver Package - KB888111
    Hotfix for Windows XP (KB909394)
    ImTOO FLV Converter
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) PRO Network Connections 11.2.0.69
    Java(TM) 6 Update 13
    Macromedia Dreamweaver MX
    Macromedia Extension Manager
    McAfee SecurityCenter
    Microsoft .NET Framework 2.0
    Microsoft ActiveSync
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office OneNote 2003
    Microsoft Office Professional Edition 2003
    Microsoft Silverlight
    Microsoft Visual C++ 2005 Redistributable
    MKV Splitter
    Morefunc
    Moyea FLV Player version 1.6.2.2
    Mozilla Embedded Browser version 2.0
    Mozilla Firefox (3.5.3)
    MSN
    MSVCRT
    MSXML 4.0 SP2 Parser and SDK
    MySQL Server 5.1
    MySQL Tools for 5.0
    NuSphere PhpED version 5.6
    OpenAL
    OpenOffice.org 3.1
    OpenPCLViewer WebStart
    Opera 9.64
    PDF Settings
    php-4.4.8 for NuSphere PhpED
    php-5.2.6 for NuSphere PhpED
    PHP 5.2.8
    Php Documentor version 1.4.2 for NuSphere PhpED
    phpDesigner version 6.2.3
    Polystyle 2.0zo (trial) for NuSphere PhpED
    QuickTime
    Realtek High Definition Audio Driver
    Riva FLV Encoder 2.0
    Security Update for Windows XP (KB958644)
    Segoe UI
    Skype web features
    Skypeâ„¢ 4.1
    Spyware Terminator
    Tennis Elbow 2005 1.0
    Trillian
    Uninstall 1.0.0.1
    Update for Windows XP (KB898461)
    VC80CRTRedist - 8.0.50727.762
    WebFldrs XP
    WhiteBoardMeeting
    Winamp
    Windows Installer 3.1 (KB893803)
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    Windows Media Format Runtime
    WinRAR archiver
    WinSCP 4.1.8
    XP Codec Pack
    Yahoo! Messenger
    Yahoo! Toolbar

    ==== Event Viewer Messages From Past Week ========

    9/30/2009 8:33:16 AM, error: Service Control Manager [7024] - The Apache2.2 service terminated with service-specific error 1 (0x1).
    9/29/2009 8:26:36 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the mcmscsvc service.
    9/27/2009 11:50:26 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    10/2/2009 12:23:19 AM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    10/2/2009 12:22:51 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    10/2/2009 12:22:17 AM, error: Service Control Manager [7034] - The Spyware Terminator Realtime Shield Service service terminated unexpectedly. It has done this 1 time(s).

    ==== End Of File ===========================
     
  5. 2009/10/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're running low on hard drive free space:
    C: is FIXED (FAT32) - 37 GiB total, 3.378 GiB free
    You need to start moving some stuff out of C drive. Windows needs at 15% of a free space to operate correctly.

    You're running TWO antivirus programs: AVG and McAfee.
    One of them has to go.
    Your choice of:
    - AVG Remover: http://www.avg.com/download-tools
    or...
    - McAfee Consumer Product Removal Tool: http://www.softpedia.com/get/Tweak/Uninstallers/McAfee-Consumer-Product-Removal-Tool.shtml

    When done.....

    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes ". If not, update the definitions before scanning by selecting "Check for Updates ". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Click Scan your Computer... button.
    * Click Scanning Preferences/Control Center... button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    - Close browsers before scanning.
    - Terminate memory threats before quarantining.

    * Click the Close button to leave the control center screen.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    - Click Preferences, then click the Statistics/Logs tab.
    - Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    - If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    - Please copy and paste the Scan Log results in your next reply.

    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 3. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    RESTART COMPUTER

    STEP 4. Download HijackThis:
    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackThis log.
    NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  6. 2009/10/01
    zeeshanhashmi

    zeeshanhashmi Inactive Thread Starter

    Joined:
    2008/01/13
    Messages:
    77
    Likes Received:
    0
    great thanks !

    I will update it and will get back to you.
    Can u please suggest a GOOD and FREE Antivirus ?
     
  7. 2009/10/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    AVG is free, but I don't recommend it since ver. 8.0

    I prefer...

    - Avira free antivirus: http://www.free-av.com/en/download/1/avira_antivir_personal__free_antivirus.html
    - Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html

    - free Comodo Internet Security (firewall + AV): http://www.personalfirewall.comodo.com/
    NOTE. During installation, Comodo will also allow you to install AV only, or firewall only, if you prefer to combine one Comodo product with some other product.

    If you decide to install Avast, or Avira, make sure, Windows firewall is turned on, or use Comodo firewall..
    If you decide to install Comodo Internet Security, or just Comodo firewall, make sure, Windows firewall is turned off.

    IMPORTANT! Make sure, you use only ONE antivirus, and ONE firewall.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.