It is currently Tue Sep 01, 2026 12:14 pm


everything is slow

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

everything is slow

Postby PearlJamaholic » Sun Feb 22, 2009 10:04 pm

i have like 6 things listed in the system config utility for startup, but during start up everything is so slow. i ran avg, spy-bot and malware bytes and everything is good. i dont know what the problem is. i dont know if its connected but EAC doesnt even see any of the drives. and i dont know why but my auto-monitor turn off doesnt work either. after the time hits the screen flickers (goes off for a split second). something is weird and different than normal but i dont know what's causing it.

Logfile of HijackThis v1.99.1
Scan saved at 3:57:21 PM, on 2/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Logitech\Setpoint\SetPoint.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Downloads\Program Downloads(old)\Spyware\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Logitech] C:\Program Files\Logitech\Setpoint\SetPoint.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 6829287345
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/ ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/ ... /CTPID.cab
O18 - Protocol: bw+0 - {EF8AD6F3-5C68-49D5-A025-0B6F6C04A550} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {EF8AD6F3-5C68-49D5-A025-0B6F6C04A550} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
PearlJamaholic
Senior Geek
Senior Geek
 
Posts: 112
Joined: Tue Jul 06, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Re: everything is slow

Postby Gecko » Mon Feb 23, 2009 12:35 pm

Your HJT logs is clean, so lets try Combofix.

Please download to your desktop.

Double click combofix.exe and follow the prompts.

Do not exit Combofix while it is running you my loose all your personal settings!
Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.

When it's done running it will produce a log for you. Please post that log in your next reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: everything is slow

Postby PearlJamaholic » Tue Feb 24, 2009 4:08 am

ComboFix 09-02-21.01 - William 2009-02-23 22:02:11.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1357 [GMT -5:00]
Running from: c:\documents and settings\William\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-01-24 to 2009-02-24 )))))))))))))))))))))))))))))))
.

2009-02-22 00:33 . 2009-02-22 00:33 <DIR> d-------- c:\program files\TagScanner
2009-02-19 15:11 . 2009-02-19 15:11 <DIR> d-------- c:\program files\Sony Setup
2009-02-19 15:11 . 2009-02-19 15:11 <DIR> d-------- c:\program files\Sony
2009-02-19 04:03 . 2009-02-19 04:03 33,846 --a------ c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.bmp
2009-02-19 04:03 . 2009-02-19 04:03 2,989 --a------ c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2009-02-17 00:35 . 2009-02-17 00:35 <DIR> d-------- c:\documents and settings\William\WINDOWS
2009-02-13 18:47 . 2004-12-07 11:33 0 --a------ c:\windows\.mh
2009-02-13 18:25 . 2009-02-13 18:25 <DIR> d-------- c:\program files\Smithville
2009-02-11 15:18 . 2009-02-11 15:18 <DIR> d-------- c:\program files\Hero Editor
2009-02-11 15:18 . 2009-02-11 15:18 249,856 --------- c:\windows\Setup1.exe
2009-02-11 15:18 . 2009-02-11 15:18 73,216 --a------ c:\windows\ST6UNST.EXE
2009-02-09 01:40 . 2009-02-09 01:40 <DIR> d-------- c:\program files\ATMA V
2009-02-08 16:54 . 2009-02-08 16:54 94,208 --a------ c:\windows\DIIUnin.exe
2009-02-08 16:54 . 2009-02-08 17:06 35,750 --a------ c:\windows\DIIUnin.dat
2009-02-08 16:54 . 2009-02-08 16:54 2,829 --a------ c:\windows\DIIUnin.pif
2009-02-08 16:38 . 2009-02-23 16:00 <DIR> d-------- c:\program files\Diablo II
2009-02-08 16:35 . 2009-02-08 17:05 21,840 --a----t- c:\windows\system32\SIntfNT.dll
2009-02-08 16:35 . 2009-02-08 17:05 17,212 --a----t- c:\windows\system32\SIntf32.dll
2009-02-08 16:35 . 2009-02-08 17:05 12,067 --a----t- c:\windows\system32\SIntf16.dll
2009-02-07 22:31 . 2009-02-07 22:31 <DIR> d-------- c:\program files\7-Zip
2009-02-07 21:48 . 2009-02-07 21:48 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2009-02-04 17:11 . 2009-02-04 17:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Blizzard
2009-01-31 14:39 . 2009-01-31 14:39 <DIR> d-------- c:\windows\system32\XPSViewer
2009-01-31 14:39 . 2009-01-31 14:39 <DIR> d-------- c:\program files\MSBuild
2009-01-31 14:38 . 2009-01-31 22:42 <DIR> d-------- c:\windows\SxsCaPendDel
2009-01-31 14:38 . 2009-01-31 14:38 <DIR> d-------- c:\program files\Reference Assemblies
2009-01-31 14:38 . 2008-07-06 07:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-01-31 14:38 . 2008-07-06 07:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-01-31 14:38 . 2008-07-06 05:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-01-31 14:38 . 2008-07-06 07:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-01-31 14:38 . 2008-07-06 07:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-01-31 14:38 . 2008-07-06 07:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-01-31 14:38 . 2008-07-06 07:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-01-29 21:46 . 2009-01-29 21:48 <DIR> d-------- c:\documents and settings\William\Application Data\vlc
2009-01-29 21:45 . 2009-01-29 21:45 <DIR> d-------- c:\program files\VideoLAN
2009-01-28 19:12 . 2009-01-28 19:12 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-01-28 11:17 . 2009-01-28 11:17 <DIR> d-------- c:\documents and settings\William\usrusmt2.tmp
2009-01-28 10:32 . 2009-02-17 03:29 <DIR> d-------- c:\program files\Wise Registry Cleaner 3
2009-01-28 10:30 . 2009-01-28 10:40 <DIR> d-------- c:\program files\Wise Disk Cleaner
2009-01-28 10:29 . 2009-01-28 10:29 <DIR> d-------- c:\documents and settings\William\Application Data\GlarySoft
2009-01-28 10:16 . 2009-01-28 10:16 <DIR> d-------- c:\documents and settings\William\Application Data\Auslogics
2009-01-28 09:41 . 2009-01-28 10:03 <DIR> d-------- c:\documents and settings\William\Application Data\IObit

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-23 20:46 --------- d-----w c:\documents and settings\William\Application Data\BitTorrent
2009-02-21 07:43 --------- d-----w c:\program files\DC++
2009-02-20 23:13 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-19 09:02 515,760 ----a-w c:\windows\system32\SpoonUninstall.exe
2009-02-18 09:01 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-11 03:05 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-05 03:15 --------- d-----w c:\program files\World of Warcraft
2009-02-04 21:22 --------- d-----w c:\program files\Cthulhu Deck Builder
2009-01-29 00:12 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-29 00:09 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-01-28 16:17 --------- d-----w c:\documents and settings\All Users\Application Data\QuickTime
2009-01-28 15:40 --------- d-----w c:\program files\YouTube Downloader
2009-01-28 01:37 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-23 10:24 --------- d-----w c:\program files\Common Files\Logitech
2009-01-20 08:48 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-01-14 21:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 21:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-14 19:50 --------- d-----w c:\program files\Java
2009-01-12 10:50 --------- d-----w c:\program files\Windows Live Safety Center
2009-01-08 22:59 --------- d-----w c:\documents and settings\William\Application Data\dvdcss
2009-01-01 01:42 --------- d-----w c:\program files\MySurvey Messenger
2008-12-25 08:55 45,056 ----a-w c:\windows\system32\WNASPI32.DLL
2008-12-25 08:55 16,512 ----a-w c:\windows\system32\drivers\ASPI32.SYS
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2008-05-08 18:13 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050820080509\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Logitech"="c:\program files\Logitech\Setpoint\SetPoint.exe" [2008-05-02 805392]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-28 1601304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-28 19:12 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2008-03-29 20:32 32768 c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LBTServ"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"aawservice"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Downloads\\LackeyCCGBetaWin\\LackeyCCG\\LackeyCCG.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\MidTen Media\\Comic Collector Live\\CCL.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-31 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-28 298264]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2008-03-29 3712]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-09-15 13352]
.
Contents of the 'Scheduled Tasks' folder

2009-02-24 c:\windows\Tasks\User_Feed_Synchronization-{83F13654-49EE-4986-9C5C-3B89CA27E826}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:36]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/ ... TSUEng.cab
FF - ProfilePath - c:\documents and settings\William\Application Data\Mozilla\Firefox\Profiles\hdh7b6ak.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\William\Application Data\Mozilla\Firefox\Profiles\hdh7b6ak.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-23 22:03:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(676)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-02-23 22:06:10
ComboFix-quarantined-files.txt 2009-02-24 03:06:07

Pre-Run: 125,121,597,440 bytes free
Post-Run: 125,187,960,832 bytes free

170 --- E O F --- 2009-02-11 03:08:42
PearlJamaholic
Senior Geek
Senior Geek
 
Posts: 112
Joined: Tue Jul 06, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Re: everything is slow

Postby Gecko » Tue Feb 24, 2009 12:58 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: everything is slow

Postby PearlJamaholic » Wed Feb 25, 2009 7:13 am

so what are the mh and setup1 things? im guessing they are bad.




ComboFix 09-02-24.02 - William 2009-02-25 1:07:08.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1479 [GMT -5:00]
Running from: c:\documents and settings\William\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\William\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\documents and settings\William\usrusmt2.tmp
c:\windows\.mh
c:\windows\Setup1.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\.mh
c:\windows\Setup1.exe

.
((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.

2009-02-22 00:33 . 2009-02-22 00:33 <DIR> d-------- c:\program files\TagScanner
2009-02-19 15:11 . 2009-02-19 15:11 <DIR> d-------- c:\program files\Sony Setup
2009-02-19 15:11 . 2009-02-19 15:11 <DIR> d-------- c:\program files\Sony
2009-02-19 04:03 . 2009-02-19 04:03 33,846 --a------ c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.bmp
2009-02-19 04:03 . 2009-02-19 04:03 2,989 --a------ c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2009-02-17 00:35 . 2009-02-17 00:35 <DIR> d-------- c:\documents and settings\William\WINDOWS
2009-02-13 18:25 . 2009-02-13 18:25 <DIR> d-------- c:\program files\Smithville
2009-02-11 15:18 . 2009-02-11 15:18 <DIR> d-------- c:\program files\Hero Editor
2009-02-11 15:18 . 2009-02-11 15:18 73,216 --a------ c:\windows\ST6UNST.EXE
2009-02-09 01:40 . 2009-02-09 01:40 <DIR> d-------- c:\program files\ATMA V
2009-02-08 16:54 . 2009-02-08 16:54 94,208 --a------ c:\windows\DIIUnin.exe
2009-02-08 16:54 . 2009-02-08 17:06 35,750 --a------ c:\windows\DIIUnin.dat
2009-02-08 16:54 . 2009-02-08 16:54 2,829 --a------ c:\windows\DIIUnin.pif
2009-02-08 16:38 . 2009-02-23 16:00 <DIR> d-------- c:\program files\Diablo II
2009-02-08 16:35 . 2009-02-08 17:05 21,840 --a----t- c:\windows\system32\SIntfNT.dll
2009-02-08 16:35 . 2009-02-08 17:05 17,212 --a----t- c:\windows\system32\SIntf32.dll
2009-02-08 16:35 . 2009-02-08 17:05 12,067 --a----t- c:\windows\system32\SIntf16.dll
2009-02-07 22:31 . 2009-02-07 22:31 <DIR> d-------- c:\program files\7-Zip
2009-02-07 21:48 . 2009-02-07 21:48 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2009-02-04 17:11 . 2009-02-04 17:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Blizzard
2009-01-31 14:39 . 2009-01-31 14:39 <DIR> d-------- c:\windows\system32\XPSViewer
2009-01-31 14:39 . 2009-01-31 14:39 <DIR> d-------- c:\program files\MSBuild
2009-01-31 14:38 . 2009-01-31 22:42 <DIR> d-------- c:\windows\SxsCaPendDel
2009-01-31 14:38 . 2009-01-31 14:38 <DIR> d-------- c:\program files\Reference Assemblies
2009-01-31 14:38 . 2008-07-06 07:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-01-31 14:38 . 2008-07-06 07:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-01-31 14:38 . 2008-07-06 05:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-01-31 14:38 . 2008-07-06 07:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-01-31 14:38 . 2008-07-06 07:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-01-31 14:38 . 2008-07-06 07:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-01-31 14:38 . 2008-07-06 07:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-01-29 21:46 . 2009-01-29 21:48 <DIR> d-------- c:\documents and settings\William\Application Data\vlc
2009-01-29 21:45 . 2009-01-29 21:45 <DIR> d-------- c:\program files\VideoLAN
2009-01-28 19:12 . 2009-01-28 19:12 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-01-28 11:17 . 2009-01-28 11:17 <DIR> d-------- c:\documents and settings\William\usrusmt2.tmp
2009-01-28 10:32 . 2009-02-17 03:29 <DIR> d-------- c:\program files\Wise Registry Cleaner 3
2009-01-28 10:30 . 2009-01-28 10:40 <DIR> d-------- c:\program files\Wise Disk Cleaner
2009-01-28 10:29 . 2009-01-28 10:29 <DIR> d-------- c:\documents and settings\William\Application Data\GlarySoft
2009-01-28 10:16 . 2009-01-28 10:16 <DIR> d-------- c:\documents and settings\William\Application Data\Auslogics
2009-01-28 09:41 . 2009-01-28 10:03 <DIR> d-------- c:\documents and settings\William\Application Data\IObit

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 21:32 --------- d-----w c:\program files\Exact Audio Copy
2009-02-23 20:46 --------- d-----w c:\documents and settings\William\Application Data\BitTorrent
2009-02-21 07:43 --------- d-----w c:\program files\DC++
2009-02-20 23:13 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-19 09:02 515,760 ----a-w c:\windows\system32\SpoonUninstall.exe
2009-02-18 09:01 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-11 03:05 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-05 03:15 --------- d-----w c:\program files\World of Warcraft
2009-02-04 21:22 --------- d-----w c:\program files\Cthulhu Deck Builder
2009-01-29 00:12 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-29 00:09 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-01-28 16:17 --------- d-----w c:\documents and settings\All Users\Application Data\QuickTime
2009-01-28 15:40 --------- d-----w c:\program files\YouTube Downloader
2009-01-28 01:37 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-23 10:24 --------- d-----w c:\program files\Common Files\Logitech
2009-01-20 08:48 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2009-01-14 21:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 21:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-14 19:50 --------- d-----w c:\program files\Java
2009-01-12 10:50 --------- d-----w c:\program files\Windows Live Safety Center
2009-01-08 22:59 --------- d-----w c:\documents and settings\William\Application Data\dvdcss
2009-01-01 01:42 --------- d-----w c:\program files\MySurvey Messenger
2008-12-25 08:55 45,056 ----a-w c:\windows\system32\WNASPI32.DLL
2008-12-25 08:55 16,512 ----a-w c:\windows\system32\drivers\ASPI32.SYS
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
2008-05-08 18:13 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050820080509\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-02-23_22.04.58.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-24 21:29:57 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_740.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Logitech"="c:\program files\Logitech\Setpoint\SetPoint.exe" [2008-05-02 805392]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-28 1601304]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-28 19:12 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2008-03-29 20:32 32768 c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LBTServ"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"aawservice"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Downloads\\LackeyCCGBetaWin\\LackeyCCG\\LackeyCCG.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\MidTen Media\\Comic Collector Live\\CCL.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-31 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-28 298264]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2008-03-29 3712]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-09-15 13352]

--- Other Services/Drivers In Memory ---

*Deregistered* - PROCEXP111
.
Contents of the 'Scheduled Tasks' folder

2009-02-25 c:\windows\Tasks\User_Feed_Synchronization-{83F13654-49EE-4986-9C5C-3B89CA27E826}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:36]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/ ... TSUEng.cab
FF - ProfilePath - c:\documents and settings\William\Application Data\Mozilla\Firefox\Profiles\hdh7b6ak.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\William\Application Data\Mozilla\Firefox\Profiles\hdh7b6ak.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-25 01:08:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(672)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-02-25 1:10:14
ComboFix-quarantined-files.txt 2009-02-25 06:10:09
ComboFix2.txt 2009-02-24 03:06:12

Pre-Run: 123,694,055,424 bytes free
Post-Run: 123,723,771,904 bytes free

185 --- E O F --- 2009-02-11 03:08:42


Logfile of HijackThis v1.99.1
Scan saved at 1:11:55 AM, on 2/25/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Logitech\Setpoint\SetPoint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
D:\Program Downloads\ProcessExplorer\procexp.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Downloads\Program Downloads(old)\Spyware\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Logitech] C:\Program Files\Logitech\Setpoint\SetPoint.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windows ... 6829287345
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/ ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/ ... /CTPID.cab
O18 - Protocol: bw+0 - {EF8AD6F3-5C68-49D5-A025-0B6F6C04A550} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: offline-8876480 - {EF8AD6F3-5C68-49D5-A025-0B6F6C04A550} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
PearlJamaholic
Senior Geek
Senior Geek
 
Posts: 112
Joined: Tue Jul 06, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Re: everything is slow

Postby Gecko » Wed Feb 25, 2009 12:26 pm

PearlJamaholic,

Those two files were the malware and a trojan.

Your logs look clean, how's it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: everything is slow

Postby PearlJamaholic » Wed Feb 25, 2009 7:07 pm

seems good, i restarted it this morning and it seemed alright. it didnt take forever for everything to load. thanks. i guess avg and spybot cant find everything......
PearlJamaholic
Senior Geek
Senior Geek
 
Posts: 112
Joined: Tue Jul 06, 2004 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron