|
Answer» It may just be my computer, but in the last 5 or 6 months it seems like it is getting more and more bogged down and the constant processing / clicking noise is driving me crazy. Before I spent any money upgrading ram or anything, I would like to have my logs checked to make sure there isn't something else going on.
I have a Gateway E-4610S Desktop with 2GB Ram and a 80GB Hard Drive with less than 25% being used.
Here are my logs:
SUPERAntiSpyware Scan Log http://www.superantispyware.com
Generated 04/05/2012 at 00:45 AM
Application Version : 5.0.1146
Core Rules Database Version : 8418 Trace Rules Database Version: 6230
Scan type : Complete Scan Total Scan Time : 00:44:55
Operating System Information Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600) Administrator
Memory items scanned : 451 Memory threats detected : 0 Registry items scanned : 32725 Registry threats detected : 0 File items scanned : 113686 File threats detected : 80
Adware.Tracking Cookie ictv-ic-ec.indieclicktv.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\E4JWD5RD ] .serving-sys.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .atdmt.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .game-advertising-online.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] ad2.adfarm1.adition.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .adfarm1.adition.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .dmtracker.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .adbrite.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .statcounter.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] www.googleadservices.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .burstnet.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .www.burstnet.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .burstnet.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] www.burstnet.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .tribalfusion.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .doubleclick.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .apmebf.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .apmebf.com [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .fastclick.net [ C:\DOCUMENTS AND SETTINGS\AIDAN.MICHAEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\8E6N0U4M.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .dmtracker.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .usatoday1.112.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .truevalue.122.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .statcounter.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] wstat.wibiya.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .media2.legacy.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .media2.legacy.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .legolas-media.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .timeinc.122.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .msnportal.112.2o7.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .countingcrows.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .countingcrows.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] statse.webtrendslive.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ] .revsci.net [ C:\DOCUMENTS AND SETTINGS\MIKE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\UK3K73OZ.DEFAULT\COOKIES.SQLITE ]
Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org
Database version: v2012.04.05.05
Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Mike :: MICHAEL [administrator]
4/5/2012 9:10:13 AM mbam-log-2012-04-05 (09-10-13).txt
Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 236085 Time elapsed: 5 minute(s), 56 second(s)
Memory Processes Detected: 0 (No malicious items detected)
Memory Modules Detected: 0 (No malicious items detected)
Registry Keys Detected: 0 (No malicious items detected)
Registry Values Detected: 0 (No malicious items detected)
Registry Data Items Detected: 0 (No malicious items detected)
Folders Detected: 0 (No malicious items detected)
Files Detected: 0 (No malicious items detected)
(end)
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26 Run by Mike at 9:18:35 on 2012-04-05 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.998.387 [GMT -5:00] . AV: Kaspersky Anti-Virus *Enabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: COMODO Firewall *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Intel\AMT\LMS.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\NETGEAR\WG111v3\WG111v3.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\SearchProtocolHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official uInternet Settings,ProxyOverride = BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\ievkbd.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2011\avp.exe" mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRunOnce: [Malwarebytes Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky anti-virus 2011\klwtbbho.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259633329522 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{B7D8324C-E688-45B7-B0AF-BA9589464CC3} : DhcpNameServer = 192.168.1.254 Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: igfxcui - igfxdev.dll Notify: klogon - c:\windows\system32\klogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\mike\application data\mozilla\firefox\profiles\uk3k73oz.default\ FF - plugin: c:\documents and settings\mike\application data\mozilla\firefox\profiles\uk3k73oz.default\extensions\{195a3098-0bd5-4e90-ae22-ba1c540afd1e}\plugins\npGarmin.dll FF - plugin: c:\documents and settings\mike\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_228.dll . ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true . ============= SERVICES / DRIVERS =============== . R0 KL1;kl1;c:\windows\system32\drivers\kl1.sys [2010-6-9 132184] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2011-6-30 494968] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2011-6-30 31704] R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2010-6-9 11352] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2011-9-3 475736] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2010-6-29 116608] R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky anti-virus 2011\avp.exe [2010-11-2 365336] R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2011-6-30 1983232] R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2007-10-9 38144] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2010-5-7 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19472] R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [2007-12-28 287232] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-4 253600] . =============== Created Last 30 ================ . 2012-04-05 04:53:40418464----a-w-c:\windows\system32\FlashPlayerApp.exe 2012-03-22 19:56:32592824----a-w-c:\program files\mozilla firefox\gkmedias.dll 2012-03-22 19:56:3244472----a-w-c:\program files\mozilla firefox\mozglue.dll . ==================== Find3M ==================== . 2012-04-05 05:10:4570304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-11 21:13:4531704----a-w-c:\windows\system32\drivers\cmdhlp.sys 2012-03-11 21:13:44494968----a-w-c:\windows\system32\drivers\cmdGuard.sys 2012-03-11 21:13:4318056----a-w-c:\windows\system32\drivers\cmderd.sys 2012-03-11 21:13:1933984----a-w-c:\windows\system32\cmdcsr.dll 2012-03-11 21:13:18301224----a-w-c:\windows\system32\guard32.dll 2012-02-03 09:22:181860096----a-w-c:\windows\system32\win32k.sys 2012-01-11 19:06:473072------w-c:\windows\system32\iacenc.dll 2012-01-09 16:20:25139784----a-w-c:\windows\system32\drivers\rdpwd.sys . ============= FINISH: 9:20:16.57 ===============
. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 11/30/2009 10:00:06 PM System Uptime: 4/4/2012 11:51:14 PM (10 hours ago) . Motherboard: Intel Corporation | | DQ965MT Processor: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz | | 1864/266mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 73 GiB total, 54.859 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Intel(R) 82566DM Gigabit Network Connection Device ID: PCI\VEN_8086&DEV_104A&SUBSYS_0001107B&REV_02\3&61AAA01&0&C8 Manufacturer: Intel Name: Intel(R) 82566DM Gigabit Network Connection PNP Device ID: PCI\VEN_8086&DEV_104A&SUBSYS_0001107B&REV_02\3&61AAA01&0&C8 Service: e1express . ==== System Restore Points =================== . RP382: 1/6/2012 10:23:33 PM - System Checkpoint RP383: 1/7/2012 11:06:15 PM - System Checkpoint RP384: 1/8/2012 11:30:15 PM - System Checkpoint RP385: 1/10/2012 12:37:10 AM - System Checkpoint RP386: 1/11/2012 1:18:15 AM - System Checkpoint RP387: 1/11/2012 3:00:17 AM - Software Distribution Service 3.0 RP388: 1/12/2012 3:31:35 AM - System Checkpoint RP389: 1/13/2012 4:31:35 AM - System Checkpoint RP390: 1/14/2012 4:43:35 AM - System Checkpoint RP391: 1/15/2012 4:43:55 AM - System Checkpoint RP392: 1/16/2012 5:49:43 AM - System Checkpoint RP393: 1/17/2012 6:56:56 AM - System Checkpoint RP394: 1/18/2012 7:43:56 AM - System Checkpoint RP395: 1/19/2012 7:44:08 AM - System Checkpoint RP396: 1/20/2012 8:44:07 AM - System Checkpoint RP397: 1/21/2012 9:44:08 AM - System Checkpoint RP398: 1/22/2012 9:44:27 AM - System Checkpoint RP399: 1/23/2012 10:56:28 AM - System Checkpoint RP400: 1/24/2012 3:00:15 AM - Software Distribution Service 3.0 RP401: 1/25/2012 3:56:27 AM - System Checkpoint RP402: 1/26/2012 3:00:15 AM - Software Distribution Service 3.0 RP403: 1/27/2012 3:21:23 AM - System Checkpoint RP404: 1/28/2012 3:25:46 AM - System Checkpoint RP405: 1/29/2012 4:31:58 AM - System Checkpoint RP406: 1/30/2012 5:14:11 AM - System Checkpoint RP407: 1/31/2012 5:36:44 AM - System Checkpoint RP408: 2/1/2012 5:48:43 AM - System Checkpoint RP409: 2/2/2012 6:37:49 AM - System Checkpoint RP410: 2/3/2012 7:36:44 AM - System Checkpoint RP411: 2/4/2012 7:37:31 AM - System Checkpoint RP412: 2/4/2012 5:58:59 PM - Installed Ice Cream Tycoon RP413: 2/5/2012 11:54:07 PM - System Checkpoint RP414: 2/7/2012 12:37:03 AM - System Checkpoint RP415: 2/8/2012 12:49:03 AM - System Checkpoint RP416: 2/9/2012 1:49:03 AM - System Checkpoint RP417: 2/9/2012 8:07:35 AM - Installed H&R Block Premium + Efile + State 2011. RP418: 2/10/2012 8:42:56 AM - System Checkpoint RP419: 2/11/2012 9:08:34 AM - System Checkpoint RP420: 2/11/2012 10:51:10 AM - Installed H&R Block Missouri 2011. RP421: 2/12/2012 11:28:25 AM - System Checkpoint RP422: 2/15/2012 7:14:01 PM - System Checkpoint RP423: 2/15/2012 10:05:11 PM - Software Distribution Service 3.0 RP424: 2/16/2012 10:05:36 PM - System Checkpoint RP425: 2/17/2012 10:17:55 PM - System Checkpoint RP426: 2/18/2012 10:59:14 PM - System Checkpoint RP427: 2/19/2012 11:10:10 PM - System Checkpoint RP428: 2/20/2012 11:58:09 PM - System Checkpoint RP429: 2/22/2012 12:10:09 AM - System Checkpoint RP430: 2/23/2012 1:10:09 AM - System Checkpoint RP431: 2/24/2012 2:10:09 AM - System Checkpoint RP432: 2/25/2012 2:58:29 AM - System Checkpoint RP433: 2/26/2012 3:10:30 AM - System Checkpoint RP434: 2/27/2012 3:58:29 AM - System Checkpoint RP435: 2/28/2012 5:10:29 AM - System Checkpoint RP436: 2/29/2012 6:10:30 AM - System Checkpoint RP437: 3/1/2012 6:58:29 AM - System Checkpoint RP438: 3/2/2012 7:58:29 AM - System Checkpoint RP439: 3/3/2012 7:59:03 AM - System Checkpoint RP440: 3/4/2012 8:59:07 AM - System Checkpoint RP441: 3/5/2012 9:59:08 AM - System Checkpoint RP442: 3/6/2012 9:42:24 PM - System Checkpoint RP443: 3/7/2012 10:11:59 PM - System Checkpoint RP444: 3/8/2012 10:59:59 PM - System Checkpoint RP445: 3/10/2012 12:12:02 AM - System Checkpoint RP446: 3/11/2012 2:12:02 AM - System Checkpoint RP447: 3/12/2012 3:12:05 AM - System Checkpoint RP448: 3/13/2012 6:15:41 AM - System Checkpoint RP449: 3/14/2012 3:00:19 AM - Software Distribution Service 3.0 RP450: 3/15/2012 3:24:25 AM - System Checkpoint RP451: 3/16/2012 4:24:25 AM - System Checkpoint RP452: 3/17/2012 4:46:08 AM - System Checkpoint RP453: 3/18/2012 5:46:07 AM - System Checkpoint RP454: 3/19/2012 5:50:52 AM - System Checkpoint RP455: 3/20/2012 6:49:21 AM - System Checkpoint RP456: 3/21/2012 7:48:57 AM - System Checkpoint RP457: 3/22/2012 8:23:47 AM - System Checkpoint RP458: 3/23/2012 8:47:53 AM - System Checkpoint RP459: 3/24/2012 8:48:12 AM - System Checkpoint RP460: 3/25/2012 10:26:15 AM - System Checkpoint RP461: 3/26/2012 10:48:10 AM - System Checkpoint RP462: 3/27/2012 11:00:11 AM - System Checkpoint RP463: 3/28/2012 12:00:14 PM - System Checkpoint RP464: 3/29/2012 12:48:11 PM - System Checkpoint RP465: 3/30/2012 1:00:10 PM - System Checkpoint RP466: 3/31/2012 1:00:44 PM - System Checkpoint RP467: 4/1/2012 2:00:44 PM - System Checkpoint RP468: 4/2/2012 2:48:43 PM - System Checkpoint RP469: 4/3/2012 4:00:45 PM - System Checkpoint RP470: 4/4/2012 4:48:44 PM - System Checkpoint . ==== Installed Programs ====================== . Acrobat.com Adobe AIR Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Reader X (10.1.2) Adobe Shockwave Player 11.5 Apple Application Support Apple Software Update BeerSmith CCleaner COMODO Internet Security Epson Event Manager Epson FAX Utility Epson PC-FAX Driver EPSON Scan EPSON WorkForce 610 Series Printer Uninstall EPSON WorkForce 630 Series Printer Uninstall EpsonNet Print EpsonNet Setup EpsonNet Setup 3.3 GIMP 2.6.4 H&R Block Missouri 2011 H&R Block Premium + Efile + State 2011 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) Hotfix for Windows XP (KB915800-v4) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Ice Cream Tycoon Intel Audio Studio 2.0 Intel(R) Active Management Technology LMS Service and SOL Driver Intel(R) Management Engine Interface Intel(R) PRO Network Connections Drivers Java(TM) 6 Update 26 Kaspersky Anti-Virus 2011 Malwarebytes Anti-Malware version 1.60.1.1000 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office 2000 Premium Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mozilla Firefox 11.0 (x86 en-US) NETGEAR WG111v3 wireless USB 2.0 adapter NetZero For Cosmi OpenOffice.org 3.0 QuickTime Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2360131) Security Update for Windows Internet Explorer 8 (KB2416400) Security Update for Windows Internet Explorer 8 (KB2482017) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2647516) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Search 4 - KB963093 Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2183461) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360131) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2416400) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2641653) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2647518) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974455) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB976325) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982381) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) SigmaTel Audio Spelling Dictionaries Support For Adobe Reader 9 Spybot - Search & Destroy SpywareBlaster 4.4 Squeezebox Server 7.6.1 SUPERAntiSpyware Tux Paint 0.9.21c Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Windows (KB971513) Update for Windows Internet Explorer 8 (KB2447568) Update for Windows Internet Explorer 8 (KB976662) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB976749) Update for Windows XP (KB978207) Update for Windows XP (KB980182) WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows Search 4.0 Yahoo! BrowserPlus 2.9.8 . ==== Event Viewer Messages From Past Week ======== . 4/1/2012 12:04:04 AM, error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Type with the following error: Access is denied. . ==== End Of File ========================Hello and welcome to Computer HOPE Forum. My name is Dave. I will be helping you out with your particular problem on your computer.
1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine. 2. The fixes are specific to your problem and should only be used for this issue on this machine. 3. If you don't know or understand something, please don't hesitate to ask. 4. Please DO NOT run any other tools or scans while I am helping you. 5. It is important that you reply to this thread. Do not start a new topic. 6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe. 7. Absence of symptoms does not mean that everything is clear.
If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. ************************************************************************* Download Combofix from any of the links below, and save it to your DESKTOP.
Link 1 Link 2 Link 3
To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
- Close any open windows and double click ComboFix.exe to run it.
You will see the following image:
Click I Agree to start the program.
ComboFix will then extract the necessary files and you will see this:
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7
It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
If you did not have it installed, you will see the prompt below. Choose YES.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will CONTINUE it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Click on Yes, to continue scanning for malware.
When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.
Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.Thank you for taking a look. Here is the log from ComboFix.
ComboFix 12-04-07.02 - Mike 04/07/2012 7:24.16.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.998.323 [GMT -5:00] Running from: c:\documents and settings\Mike\Desktop\AV Tools\ComboFix.exe AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\TEMP . . ((((((((((((((((((((((((( Files Created from 2012-03-07 to 2012-04-07 ))))))))))))))))))))))))))))))) . . 2012-04-05 04:53 . 2012-04-05 05:10418464----a-w-c:\windows\system32\FlashPlayerApp.exe 2012-03-22 19:56 . 2012-03-22 19:56592824----a-w-c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-22 19:56 . 2012-03-22 19:5644472----a-w-c:\program files\Mozilla Firefox\mozglue.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-05 05:10 . 2011-07-02 01:4770304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-11 21:13 . 2011-06-30 14:3897760----a-w-c:\windows\system32\drivers\inspect.sys 2012-03-11 21:13 . 2011-06-30 14:3831704----a-w-c:\windows\system32\drivers\cmdhlp.sys 2012-03-11 21:13 . 2011-06-30 14:38494968----a-w-c:\windows\system32\drivers\cmdGuard.sys 2012-03-11 21:13 . 2011-06-30 14:3818056----a-w-c:\windows\system32\drivers\cmderd.sys 2012-03-11 21:13 . 2011-12-24 01:1333984----a-w-c:\windows\system32\cmdcsr.dll 2012-03-11 21:13 . 2011-06-30 14:37301224----a-w-c:\windows\system32\guard32.dll 2012-02-04 23:59 . 2012-02-04 23:5969632----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut5_75E8EDD2A1E346219D6D5DDBB46E7CDE.exe 2012-02-04 23:59 . 2012-02-04 23:5953248----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut4_E636F7D111FF4BB7A8037F8F16F3DE73.exe 2012-02-04 23:59 . 2012-02-04 23:5953248----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut1_E636F7D111FF4BB7A8037F8F16F3DE73.exe 2012-02-03 09:22 . 2009-09-21 20:291860096----a-w-c:\windows\system32\win32k.sys 2012-01-11 19:06 . 2012-02-16 02:123072------w-c:\windows\system32\iacenc.dll 2012-01-09 16:20 . 2009-09-21 20:40139784----a-w-c:\windows\system32\drivers\rdpwd.sys 2012-03-22 19:56 . 2011-09-01 23:5297208----a-w-c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-03 365336] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2004-10-15 65588] NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 2326528] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-10-12 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\guard32.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Squeezebox Server Tray Tool.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Squeezebox Server Tray Tool.lnk backup=c:\windows\pss\Squeezebox Server Tray Tool.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk] path=c:\documents and settings\Mike\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-03 07:37843712----a-w-c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2011-09-27 13:2259240----a-w-c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-08-21 12:0015360----a-w-c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager] 2009-12-03 15:12976320----a-w-c:\program files\Epson Software\Event Manager\EEventManager.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM] 2009-12-03 05:00847872----a-w-c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2006-10-29 15:1786016----a-r-c:\windows\system32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2006-10-29 15:1798304----a-r-c:\windows\system32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelAudioStudio] 2006-07-13 20:349134080----a-w-c:\program files\Intel Audio Studio\IntelAudioStudio.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2006-10-29 15:1781920----a-r-c:\windows\system32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-10-24 20:28421888----a-w-c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2011-04-08 17:59254696----a-w-c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"= "c:\\Program Files\\EpsonNet\\EpsonNet Setup\\tool09\\ENEasyApp.exe"= "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "9000:TCP"= 9000:TCP:Squeezebox Server 9000 tcp (UI) "9001:TCP"= 9001:TCP:Squeezebox Server 9001 tcp (UI) "9002:TCP"= 9002:TCP:Squeezebox Server 9002 tcp (UI) "9003:TCP"= 9003:TCP:Squeezebox Server 9003 tcp (UI) "9004:TCP"= 9004:TCP:Squeezebox Server 9004 tcp (UI) "9005:TCP"= 9005:TCP:Squeezebox Server 9005 tcp (UI) "9006:TCP"= 9006:TCP:Squeezebox Server 9006 tcp (UI) "9007:TCP"= 9007:TCP:Squeezebox Server 9007 tcp (UI) "9008:TCP"= 9008:TCP:Squeezebox Server 9008 tcp (UI) "9009:TCP"= 9009:TCP:Squeezebox Server 9009 tcp (UI) "9010:TCP"= 9010:TCP:Squeezebox Server 9010 tcp (UI) "9100:TCP"= 9100:TCP:Squeezebox Server 9100 tcp (UI) "8000:TCP"= 8000:TCP:Squeezebox Server 8000 tcp (UI) "10000:TCP"= 10000:TCP:Squeezebox Server 10000 tcp (UI) "9090:TCP"= 9090:TCP:Squeezebox Server 9090 tcp (UI) "3483:UDP"= 3483:UDP:Squeezebox Server 3483 udp "3483:TCP"= 3483:TCP:Squeezebox Server 3483 tcp . R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [6/30/2011 9:38 AM 494968] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [6/30/2011 9:38 AM 31704] R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [6/9/2010 4:43 PM 11352] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2/17/2010 1:25 PM 12880] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67664] R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [6/29/2010 12:48 PM 116608] R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [10/9/2007 4:13 PM 38144] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/7/2010 11:06 AM 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [11/2/2009 7:27 PM 19472] R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [12/28/2007 6:02 PM 287232] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/4/2012 11:53 PM 253600] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - ADOBEFLASHPLAYERUPDATESVC . Contents of the 'Scheduled Tasks' folder . 2012-04-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 05:10] . 2012-04-04 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official uInternet Settings,ProxyOverride = TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\uk3k73oz.default\ FF - user.js: yahoo.homepage.dontask - true . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-04-07 07:31 Windows 5.1.2600 Service Pack 3 NTFS . detected NTDLL code modification: ZwClose . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(868) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . - - - - - - - > 'explorer.exe'(304) c:\windows\system32\WININET.dll c:\program files\Windows Desktop Search\deskbar.dll c:\program files\Windows Desktop Search\en-us\dbres.dll.mui c:\program files\Windows Desktop Search\dbres.dll c:\program files\Windows Desktop Search\wordwheel.dll c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui c:\program files\Windows Desktop Search\msnlExtRes.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2012-04-07 07:33:09 ComboFix-quarantined-files.txt 2012-04-07 12:33 ComboFix2.txt 2011-07-06 22:16 ComboFix3.txt 2011-07-02 03:47 ComboFix4.txt 2011-04-08 03:38 . Pre-Run: 58,909,536,256 bytes free Post-Run: 58,930,921,472 bytes free . - - End Of File - - D10E599F924B7B5F6570E2E1C1F4E353 I seriously doubt that your computer is infected. I suspect that the noise you hear is some of the hardware going bad; either your harddrive or one of the fans. You could open the box and see if you can isolate the noise.
I'd like to scan your machine with ESET OnlineScan
•Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on to download the ESET Smart Installer. Save it to your desktop.
- Double click on the icon on your desktop.
•Check •Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Okay that's good news, and I seriously hope I'm not wasting your time. I explained my situation to a reliable source who said it sounded like a bug. I do sincerely appreciate your help.
Here is the ESET log. Thank you.
[emailprotected] as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=17e1e7d750000e45a6e1160e9aef7e3e # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-04-07 09:23:17 # local_time=2012-04-07 04:23:17 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 73272399 73272399 0 0 # compatibility_mode=768 16777215 100 0 52699339 52699339 0 0 # compatibility_mode=1024 16777215 100 0 45287938 45287938 0 0 # compatibility_mode=1280 16777175 100 0 18655359 18655359 0 0 # compatibility_mode=3073 16777213 80 71 1012073 9320834 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=71721 # found=0 # cleaned=0 # scan_time=2000 QuoteI explained my situation to a reliable source who said it sounded like a bug. I haven't seen an infection that would make noises on the computer. I can't see anything bad on your computer. You will have to open the box and try to see what is making the noise. Please let me know what you find.
|