[Resolved] Slow computer, firefox crashing, programmes hanging

  1. #1
    JBow is offline Newbie

    [Resolved] Slow computer, firefox crashing, programmes hanging

    Hi
    I have found you here via a google search about system idle seemingly hogging the CPU, and then suggestions to do a HIjackthis scan.
    I downloaded and ranHijckthis
    Then came here and on instruction downloaded and am now running Spybot - which looks like it will take a whle.
    I have started a new thread as advised in the announcement.

    The symptoms I have been experiencing are a slow, "congested" PC which is used much of the day, and left on all the time unless it really gets indigestion.
    Recently there has been rumblings of "work" going on behind teh scenes,
    Firefox has crashed most days this last week.
    I use Programmes like word / excel/ homesite/ an accounts prog /outlook express / firefox multi tabs - every day and often all together.
    Recently they have become very slow to open, transitiions between actions, hanging, getting a "not responding message and then clearing.
    I had to repair AVG as it was getting stuck in scans.

    Clearly something has given the system indigestion and I would appreciate help in finding out what.

    AVG is updated every day and scans every night
    Zone alarm is my firewall.

    The beast is a Dell dimension 8100 and is getting ancient but needs to carry on for some months yet before I can replace it.
    Its a busy machine but not used for gaming or downloading films, music or even iplayer !
    microsoft xp home edition version 2002 sp2
    intel pentium 4 cpu 1300 mhz
    1.28 ghz
    512mb ram
    virtual memort paging file size 768mb

    Do you want the hijackthis log from before running spybot or wait until the spyboot scan has run its course?
    My technical knowledge is weak on the ins and outs of systems, but hopefully will understand you well enough to do as I am told
    I do appreciate any help anyone can give me here.
    Its clearly a great well of knowledge and experience.

    -supplemental
    Spybot has now finished some 2 hours later and shows only expected cookies as "problems".
    Last edited by JBow; 26-07-2009 at 02:52 PM.


  2. #2
    broni is offline Senior Member
    Eventually, you should get more RAM.
    How big is your hard drive\free space?


    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***

    STEP 1. Download SUPERAntiSpyware Free for Home Users:
    SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: SUPERAntiSpyware.com - Database Definition Information.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Click Scan your Computer... button.
    * Click Scanning Preferences/Control Center... button.
    * Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    - Close browsers before scanning.
    - Terminate memory threats before quarantining.

    * Click the Close button to leave the control center screen.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    - Click Preferences, then click the Statistics/Logs tab.
    - Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    - If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    - Please copy and paste the Scan Log results in your next reply.

    * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    STEP 2. Download Malwarebytes' Anti-Malware: Malwarebytes.org to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    STEP 3. Download GMER: GMER - Rootkit Detector and Remover, by clicking on Download EXE button.
    Alternative downloads:
    - |MG| GMER 1.0.15.14972 Download
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    RESTART COMPUTER

    STEP 4. Download HijackThis:
    TrendSecure | Download TrendMicro HijackThis
    by clicking on Download HijackThis Installer
    Install, and run it.
    Post HijackThis log.
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

  3. #3
    JBow is offline Newbie
    Quote Originally Posted by broni View Post
    Eventually, you should get more RAM.
    How big is your hard drive\free space?
    My intent is that the beastie gets replaced in the autumn but its not a job for the middle of the summer season.

    The answer to the second query is
    C: 100G and FS 6.6G
    E: 49G and 23G

    would it help to move a couple of biggish folders from c to e for the moment.

    thank you for the rest of the instructions, I will do these and report back.
    I appreciate your time and expertise. and words of caution.

  4. #4
    broni is offline Senior Member
    Absloutely.
    Windows needs at least 15% of a free space, so you need AT LEAST 15GB free on C drive.

  5. #5
    JBow is offline Newbie
    Quote Originally Posted by broni View Post
    STEP 1. Download SUPERAntiSpyware Free for Home Users:

    - Please copy and paste the Scan Log results in your next reply.[/I]
    as I did not have a browser open I thought I could return to this programme to copy the log as I ticked save log, but when I came back to it there was no log.
    This scan did not create ANY results.
    Quote Originally Posted by broni View Post
    STEP 2. Download Malwarebytes' Anti-Malware:
    This scan has just completed, finding two problems, and the log file is as follows

    Malwarebytes' Anti-Malware 1.39
    Database version: 2510
    Windows 5.1.2600 Service Pack 2

    27/07/2009 15:42:51
    mbam-log-2009-07-27 (15-42-51).txt

    Scan type: Full Scan (C:\|E:\|)
    Objects scanned: 578373
    Time elapsed: 5 hour(s), 11 minute(s), 0 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\adsltaskbar (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Quote Originally Posted by broni View Post
    RESTART COMPUTER!

    STEP 3. Download GMER: GMER - Rootkit Detector and Remover,
    I am about to do this one.

  6. #6
    JBow is offline Newbie
    I am having a real problem with this GMER program

    I have downloaded it and then clicked on the exe file, it has given me a box with information but then it starts some work of its own checking files.
    After a couple of minutes the whole computer shuts down and then reboots.
    Its done it twice now, and I get a message that the system has recovered from a serious error.


    The system has recovered from a serious error.

    BCCode : f7 BCP1 : 00009390 BCP2 : 000056FA BCP3 : FFFFA905
    BCP4 : 00000000 OSVer : 5_1_2600 SP : 2_0 Product : 768_1

    C:\DOCUME~1\User\LOCALS~1\Temp\WER5a00.dir00\Mini0 72709-01.dmp
    C:\DOCUME~1\User\LOCALS~1\Temp\WER5a00.dir00\sysda ta.xml

    do I download a different copy or what?

  7. #7
    JBow is offline Newbie
    I tried it again, and it shut down within a couple of moments of opening the GMER window.

    I would really appreciate some help here.


  8. #8
    JBow is offline Newbie
    hijackthis log just done in case it helps
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:35:23, on 27/07/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\system32\bgsvcgen.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\system32\crypserv.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9 LE.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\program files\plustek\software\ulead photo explorer 8.0 se basic\Monitor.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\PayPal\Payment Wizard\Outlook Express\OEHook.exe
    C:\Program Files\Panasonic\VideoCam Suite 2\VideoCamSuiteAutoStart.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\OE-QuoteFix\oequotefix.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\ swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9 LE.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB001" /M "Stylus Photo R1800"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [Ulead AutoDetector] c:\program files\plustek\software\ulead photo explorer 8.0 se basic\Monitor.exe
    O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R1800 on ACER-FCAFBFA90D] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9 LE.EXE /P48 "Auto EPSON Stylus Photo R1800 on ACER-FCAFBFA90D" /O25 "\\ACER-FCAFBFA90D\Printer" /M "Stylus Photo R1800"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: PayPal Plug-In for Outlook Express.lnk = ?
    O4 - Global Startup: VideoCam Suite 2.0.lnk = ?
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - LizardTech - Press Room - Press Release
    O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
    O16 - DPF: {5F8A33E7-6A32-4EE0-887A-134C627CB052} (Easy Upload Tool Combo Control) - http://******loch.myphotoalbum.com/EasyUploadTool.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1135251813372
    O16 - DPF: {84818113-96C5-11D2-BE39-006008BF4DD5} (ViewDirector Object) - http://www.scotlandspeople.gov.uk/Vi...l/viewdw32.ocx
    O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
    O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) -
    O16 - DPF: {CA11EB7C-1C85-4577-8A49-9E28EFB30184} (UMediaPlayer Class) - http://www.umediaserver.net/bin/UMediaControl4.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
    O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
    O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Rapport Management Service (RapportMgmtService) - Unknown owner - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
    O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 8167 bytes

  9. #9
    broni is offline Senior Member
    I also re-read your initial post, where you say:
    system idle seemingly hogging the CPU
    System Idle Process actually show NOT used CPU cycles (the higher, the better).


    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

  10. #10
    JBow is offline Newbie
    Save 20% on AVG Internet Security 2012 Suite!
    thank you so much for your help, reassurance and time. It is much appreciated.

    The combofix log is

    ComboFix 09-07-27.02 - User 27/07/2009 23:03.1.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.328 [GMT 1:00]
    Running from: c:\documents and settings\User\Desktop\My Downloads\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\Installer\51452c8.msi
    c:\windows\system32\setup.ini

    .
    ((((((((((((((((((((((((( Files Created from 2009-06-27 to 2009-07-27 )))))))))))))))))))))))))))))))
    .

    2009-07-27 09:16 . 2009-07-27 09:16 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes
    2009-07-27 09:14 . 2009-07-13 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-07-27 09:14 . 2009-07-27 09:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-07-27 09:13 . 2009-07-13 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-07-27 09:13 . 2009-07-27 09:15 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-07-26 19:53 . 2009-07-26 19:53 117760 ----a-w- c:\documents and settings\Administrator.DELL.001\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\ UIREPAIR.DLL
    2009-07-26 19:52 . 2009-07-26 19:52 -------- d-----w- c:\documents and settings\Administrator.DELL.001\Application Data\SUPERAntiSpyware.com
    2009-07-26 19:42 . 2009-07-27 16:17 117760 ----a-w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\ UIREPAIR.DLL
    2009-07-26 19:40 . 2009-07-26 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2009-07-26 19:38 . 2009-07-26 19:38 -------- d-----w- c:\program files\SUPERAntiSpyware
    2009-07-26 19:38 . 2009-07-26 19:38 -------- d-----w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com
    2009-07-26 10:13 . 2009-07-26 10:14 -------- d-----w- c:\program files\Trend Micro
    2009-07-22 16:34 . 2009-07-22 16:34 -------- d-----w- c:\documents and settings\User\Application Data\AVG8
    2009-07-08 07:59 . 2009-07-04 12:16 2167576 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
    2009-06-28 10:03 . 2009-06-28 10:03 -------- d-----w- c:\documents and settings\User\Application Data\ChemTable Software
    2009-06-28 10:03 . 2009-06-28 10:03 -------- d-----w- c:\program files\Web Forum Reader
    2009-06-28 09:08 . 2009-06-28 09:08 -------- d-----w- c:\program files\SendTo FTP
    2009-06-28 09:08 . 1999-07-10 23:36 57344 ----a-w- c:\windows\system32\Gksui16.exe
    2009-06-28 07:38 . 2009-07-04 12:16 2054424 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2009-07-27 14:57 . 2007-04-19 15:14 4641194 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
    2009-07-27 06:04 . 2009-07-27 06:04 88785 ----a-w- c:\windows\Internet Logs\vsmon_2nd_2009_07_26_20_49_59_small.dmp.zip
    2009-07-26 19:50 . 2009-07-27 05:59 2131456 ----a-w- c:\windows\Internet Logs\xDB3.tmp
    2009-07-26 19:50 . 2009-07-27 05:59 2736640 ----a-w- c:\windows\Internet Logs\xDB2.tmp
    2009-07-26 19:36 . 2007-12-22 10:30 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2009-07-26 11:37 . 2008-11-14 10:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-07-26 11:13 . 2008-11-14 10:52 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-07-22 17:29 . 2009-03-17 08:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
    2009-07-04 12:16 . 2009-03-17 08:34 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-06-22 14:43 . 2006-08-19 09:46 -------- d-----w- c:\program files\OE-QuoteFix
    2009-06-21 10:51 . 2009-06-21 10:51 -------- d-----w- c:\program files\Tiddlywiki
    2009-06-19 21:40 . 2009-06-20 07:19 2096128 ----a-w- c:\windows\Internet Logs\xDB1.tmp
    2009-06-17 08:45 . 2007-01-02 09:40 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-06-16 14:55 . 2004-08-04 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
    2009-06-16 14:55 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
    2009-06-03 19:27 . 2004-08-04 12:00 1290752 ----a-w- c:\windows\system32\quartz.dll
    2009-05-26 17:50 . 2006-01-08 10:18 96200 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-05-07 15:44 . 2004-08-04 12:00 344064 ----a-w- c:\windows\system32\localspl.dll
    2009-05-04 07:50 . 2009-03-17 08:34 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-05-04 07:49 . 2009-03-17 08:34 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2009-04-29 04:31 . 2004-08-04 12:00 668160 ----a-w- c:\windows\system32\wininet.dll
    2009-04-29 04:31 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
    2007-07-01 12:12 . 2007-07-01 12:11 10091750 ----a-w- c:\program files\PAF5EnglishSetup.exe
    2007-06-24 17:09 . 2007-06-24 17:08 6910136 ------w- c:\program files\djvu_plugin.most.current.exe
    2006-04-15 18:47 . 2006-03-07 22:06 95782 ----a-w- c:\program files\sample.tif
    2006-02-11 08:00 . 2006-02-11 08:00 12284879 ----a-w- c:\program files\AVG7QT.DAT
    2009-01-20 06:03 . 2009-02-28 16:12 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2007-04-02 68856]
    "NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-04-14 1957888]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "EPSON Stylus Photo R1800"="c:\windows\System32\spool\DRIVERS\W32X86\3 \E_FATI9LE.EXE" [2004-09-08 98304]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.e xe" [2001-07-09 155648]
    "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
    "Ulead AutoDetector"="c:\program files\plustek\software\ulead photo explorer 8.0 se basic\Monitor.exe" [2003-11-18 45056]
    "Auto EPSON Stylus Photo R1800 on ACER-FCAFBFA90D"="c:\windows\System32\spool\DRIVERS\W32 X86\3\E_FATI9LE.EXE" [2004-09-08 98304]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
    "ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    PayPal Plug-In for Outlook Express.lnk - c:\program files\PayPal\Payment Wizard\Outlook Express\OEHook.exe [2007-1-9 102400]
    VideoCam Suite 2.0.lnk - c:\program files\Panasonic\VideoCam Suite 2\VideoCamSuiteAutoStart.exe [2009-3-31 181592]

    [hkey_local_machine\software\microsoft\windows\curr entversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2008-12-22 11:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-05-04 07:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "iPod Service"=3 (0x3)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [17/03/2009 09:34 335752]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [17/03/2009 09:34 108552]
    R1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\GhPciScan.sys [14/08/2002 16:11 5632]
    R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [25/02/2009 15:38 57320]
    R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [25/02/2009 15:38 238952]
    R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23/06/2009 11:01 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23/06/2009 11:01 72944]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [17/03/2009 09:33 298776]
    R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [26/05/2009 18:46 648424]
    R3 Bonifay;Bonifay;c:\windows\system32\drivers\Bonifa y.sys [16/06/2004 18:33 12032]
    R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23/06/2009 11:01 7408]
    R3 Stmatm;ATM/ADSL miniport;c:\windows\system32\drivers\stmatm.sys [12/04/2006 11:39 60255]
    S3 AF05BDA;AF9005 BDA Device;c:\windows\system32\drivers\AF05BDA.sys [08/02/2007 22:49 133504]
    S3 KMWDKUSB;KM-WDK USB;c:\windows\system32\drivers\KMWDKUSB.sys [22/12/2005 22:34 41667]
    S3 TaurusUsb;ADSL Modem USB Service;c:\windows\system32\drivers\torususb.sys [12/04/2006 11:39 653704]
    .
    Contents of the 'Scheduled Tasks' folder

    2008-11-14 c:\windows\Tasks\System Restore.job
    - c:\windows\system32\Restore\rstrui.exe [2005-12-22 12:00]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = about:blank
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uInternet Settings,ProxyOverride = 127.0.0.1
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    DPF: {5F8A33E7-6A32-4EE0-887A-134C627CB052} - hxxp://******loch.myphotoalbum.com/EasyUploadTool.cab
    DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446}
    DPF: {CA11EB7C-1C85-4577-8A49-9E28EFB30184} - hxxp://www.umediaserver.net/bin/UMediaControl4.cab
    FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\ubfdttiw.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.startup.homepage - hxxp://mail.google.com/mail/?auth=DQAAAJMAAABx-5cKGHJKaoIEbXU0FvLz6PiN7Ii2KRDWemUoMMtfa7i3i4LwZ4I xv_4YXZBKq-CgRFH1nqM3ZST7Vkd_KZCtpZQCknut1ngkUa2prvU0P4uJz8vY MV2guobDOPUY_eNS9tUKLADsDi6KZ2fQ7gM1RgU3vpTaV7FU-GivaB6NlPgwrMNOChF8CwEEPqRCVD1Yy-FAuqsnU0w7vQwzQqkm
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - plugin: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\ubfdttiw.default\ext ensions\loaderff@wiredred.com\plugins\NPLoaderFF.d ll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Java\j2re1.4.1_01\bin\NPJava11.dll
    FF - plugin: c:\program files\Java\j2re1.4.1_01\bin\NPJava12.dll
    FF - plugin: c:\program files\Java\j2re1.4.1_01\bin\NPJava13.dll
    FF - plugin: c:\program files\Java\j2re1.4.1_01\bin\NPJava32.dll
    FF - plugin: c:\program files\Java\j2re1.4.1_01\bin\NPJPI141_01.dll
    FF - plugin: c:\program files\Java\j2re1.4.1_01\bin\NPOJI610.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npdjvu.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npImgCtl.dll
    .

    ************************************************** ************************

    driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
    Rootkit scan 2009-07-27 23:14
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    ************************************************** ************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\KMWDK USB\KyoceraFS-1020D\7&29b86a02&0&KMWDKUSB]
    @Denied: (C D) (Everyone)
    "DeviceDesc"="Kyocera FS-1020D"
    "LocationInformation"="KMUSB001"
    "Capabilities"=dword:000000c0
    "ConfigFlags"=dword:00000000
    "HardwareID"=multi:"KMWDKUSB\\KyoceraFS-1020D43AD\00\00"
    "CompatibleIDs"=multi:"KyoceraFS-1020D43AD\00\00"
    "Class"="Printer"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(544)
    c:\program files\SUPERAntiSpyware\SASWINLO.dll
    .
    Completion time: 2009-07-27 23:20
    ComboFix-quarantined-files.txt 2009-07-27 22:20

    Pre-Run: 12,202,983,424 bytes free
    Post-Run: 12,284,772,352 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect

    185 --- E O F --- 2009-07-20 16:27


    the hijackthis log is

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:33:07, on 27/07/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\WINDOWS\system32\bgsvcgen.exe
    C:\WINDOWS\system32\crypserv.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9 LE.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\PayPal\Payment Wizard\Outlook Express\OEHook.exe
    C:\Program Files\Panasonic\VideoCam Suite 2\VideoCamSuiteAutoStart.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\ swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9 LE.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB001" /M "Stylus Photo R1800"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [Ulead AutoDetector] c:\program files\plustek\software\ulead photo explorer 8.0 se basic\Monitor.exe
    O4 - HKLM\..\Run: [Auto EPSON Stylus Photo R1800 on ACER-FCAFBFA90D] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9 LE.EXE /P48 "Auto EPSON Stylus Photo R1800 on ACER-FCAFBFA90D" /O25 "\\ACER-FCAFBFA90D\Printer" /M "Stylus Photo R1800"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: PayPal Plug-In for Outlook Express.lnk = ?
    O4 - Global Startup: VideoCam Suite 2.0.lnk = ?
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_01\bin\npjpi141_01.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - LizardTech - Press Room - Press Release
    O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.webshots.com/html/atx/wsaxcontrol.cab
    O16 - DPF: {5F8A33E7-6A32-4EE0-887A-134C627CB052} (Easy Upload Tool Combo Control) - http://******loch.myphotoalbum.com/EasyUploadTool.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1135251813372
    O16 - DPF: {84818113-96C5-11D2-BE39-006008BF4DD5} (ViewDirector Object) - http://www.scotlandspeople.gov.uk/Vi...l/viewdw32.ocx
    O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
    O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) -
    O16 - DPF: {CA11EB7C-1C85-4577-8A49-9E28EFB30184} (UMediaPlayer Class) - http://www.umediaserver.net/bin/UMediaControl4.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
    O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
    O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Rapport Management Service (RapportMgmtService) - Unknown owner - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
    O23 - Service: Sony SCSI Helper Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 8128 bytes

+ Reply to Thread
Page 1 of 2 1 2 LastLast