This may be my ISP (dial-up NetZero) but i will be surfing just fine and fast and then my connection speed slows almost to a halt. I restart my computer and it usually fixes it.
I have Malwarebytes and SpyBot S&D and AVG PC Tuneup(full Version) and AVG AntiVirus and run all of them regularly.
All this started after Malwarebytes found 2 objects and removed them.
Also when i was running the GMER program it stopped and gave me a BSOD that said something about IRQ not equal or something. Here is the error codes it gave
0x0000000a (0xf70F6008, 0x00000005, 0x00000001, 0x806F78FE) I had to restart then i ran it again and this log is what i have attached.
I have attached the "attach.txt" and "ark.txt" as instructed. Below is the DDS.txt
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Keifer at 4:13:37.34 on Thu 04/21/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.647 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
svchost.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\qsacc\x1exec.exe
C:\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = https://my.screenname.aol.com/_cqr/login/login.psp?seamless=novl&locale=us&offerId=newmail-en-us-v2&siteState=ver%3A4%7Crt%3ASTANDARD%7Cat%3ASNS%7Cld%3Awebmail.aol.com%7Crp%3ALite%252fToday.aspx%7Cuv%3AAOL%7Clc%3Aen-us%7Cmt%3AANGELIA%7Csnt%3AScreenName%7Csid%3A5ea4925c-6301-4ca7-b1e9-c9ba3b223559&authLev=0&sitedomain=sns.webmail.aol.com&lang=en
uSearch Page = hxxp://my.netzero.net/s/search?r=minisearch
uSearch Bar = hxxp://my.netzero.net/s/search?r=minisearch
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} -
BHO: Pop-up Blocker: {52706ef7-d7a2-49ad-a615-e903858cf284} - c:\program files\netzero\qsacc\X1IEBHO.dll
TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - c:\program files\netzero\Toolbar.dll
uRun: [NetZero_uoltray] c:\program files\netzero\exec.exe regrun
uRun: [Free Download Manager] c:\program files\free download manager\fdm.exe -autorun
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
uPolicies-explorer: NoSMHelp = 01000000
uPolicies-explorer: NoActiveDesktop = 01000000
uPolicies-explorer: NoWinKeys = 01000000
uPolicies-explorer: NoSMMyDocs = 01000000
uPolicies-explorer: NoSMMyPictures = 01000000
uPolicies-explorer: NoNetworkConnections = 01000000
uPolicies-explorer: HideSCABattery = 1 (0x1)
uPolicies-explorer: RestrictRun = 0 (0x0)
mPolicies-explorer: RestrictRun = 0 (0x0)
mPolicies-system: DisableStatusMessages = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1299931607390
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Notify: freewat - freewat.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 0.0.0.0 mpa.one.microsoft.com genuine.microsoft.com sls.microsoft.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\keifer\applic~1\mozilla\firefox\profiles\vvwjw098.default\
FF - prefs.js: browser.startup.homepage - hxxps://my.screenname.aol.com/_cqr/login/login.psp?seamless=novl&locale=us&offerId=newmail-en-us-v2&siteState=ver%3A4%7Crt%3ASTANDARD%7Cat%3ASNS%7Cld%3Awebmail.aol.com%7Crp%3ALite%252fToday.aspx%7Cuv%3AAOL%7Clc%3Aen-us%7Cmt%3AANGELIA%7Csnt%3AScreenName%7Csid%3A5ea4925c-6301-4ca7-b1e9-c9ba3b223559&authLev=0&sitedomain=sns.webmail.aol.com&lang=en
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg10\Firefox4
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]
S0 cerc6;cerc6; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-04-21 03:00:13 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-04-21 03:00:13 -------- d-----w- c:\windows\system32\wbem\Repository
2011-04-21 02:55:37 -------- d-----w- c:\windows\system32\drivers\AVG
2011-04-21 02:55:37 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG10
2011-04-21 02:55:17 -------- d-----w- c:\docume~1\keifer\applic~1\AVG10
2011-04-21 02:48:42 -------- d-----w- C:\AVGTemp
2011-04-19 11:29:54 78096 ----a-r- c:\docume~1\keifer\applic~1\microsoft\installer\{fe74c184-4939-4ffa-b8c9-8e0cd6a6aa57}\ARPPRODUCTICON.exe
2011-04-19 11:28:34 -------- d-----w- c:\docume~1\keifer\locals~1\applic~1\{42FFD6CD-1797-4302-8C84-959BECBCDA13}
2011-04-19 11:19:52 -------- d-----w- c:\docume~1\alluse~1\applic~1\NetZero
2011-04-19 11:19:01 -------- d-----w- c:\program files\NetZero
2011-04-19 11:16:01 -------- d-----w- c:\program files\NetZero(2)(2)
2011-04-19 10:58:04 -------- d-----w- c:\docume~1\alluse~1\applic~1\NetZero(3)
2011-04-19 10:51:42 -------- d-----w- c:\program files\NetZero(2)
2011-04-19 10:51:40 -------- d-----w- c:\docume~1\alluse~1\applic~1\NetZero(2)
2011-04-19 10:36:50 -------- d-----w- c:\program files\NetZeroInstaller(2)
2011-04-19 09:54:02 -------- d-----w- c:\program files\XP Repair Pro 4.0
2011-04-19 04:01:24 -------- dc-h--w- c:\windows\ie8
2011-04-18 09:07:51 -------- d-----w- c:\program files\MSXML 4.0
2011-04-16 18:07:49 -------- d-----w- c:\program files\eBay
2011-04-16 18:07:49 -------- d-----w- c:\documents and settings\all users\eBay
2011-04-16 07:44:40 -------- d-----w- C:\AuctionSplash
2011-04-16 07:43:01 -------- d-----w- c:\docume~1\keifer\locals~1\applic~1\Deployment
2011-04-16 07:42:42 -------- d-----w- c:\program files\AuctionSplashSetup
2011-04-16 06:33:55 -------- d-----w- c:\docume~1\keifer\locals~1\applic~1\Sam Francke
2011-04-16 06:33:38 -------- d-----w- c:\program files\CSVed
2011-04-16 05:50:47 -------- d-----w- c:\docume~1\keifer\applic~1\GetRightToGo
2011-04-16 05:34:47 -------- d-----w- c:\docume~1\keifer\applic~1\OpenOffice.org
2011-04-16 05:29:26 -------- d-----w- c:\program files\OpenOffice.org 3
2011-04-16 05:28:26 472808 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll
2011-04-11 20:37:21 -------- d-----w- c:\program files\Cablenut
2011-04-11 06:49:31 -------- d-----w- c:\docume~1\keifer\applic~1\Systweak
2011-04-09 03:59:46 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-04-09 03:59:46 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-04-04 20:20:41 -------- d-----w- c:\docume~1\keifer\applic~1\Serif
2011-04-04 20:19:26 -------- d-----w- c:\program files\Serif
2011-04-04 15:56:01 -------- d-----w- c:\windows\system32\aliedit
2011-04-04 15:55:44 -------- d-----w- c:\program files\trademanager
2011-04-03 05:48:42 -------- d-----w- c:\program files\Rummy.com
2011-04-02 03:00:03 -------- d-----w- c:\docume~1\keifer\locals~1\applic~1\Mozilla
2011-03-30 17:47:48 49152 ----a-r- c:\windows\system32\inetwh32.dll
2011-03-30 17:47:48 1044480 ----a-r- c:\windows\system32\roboex32.dll
.
==================== Find3M ====================
.
2011-04-08 03:41:02 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2011-04-08 03:41:00 356352 ----a-w- c:\windows\system32\wpdsp.dll
2011-04-08 03:39:57 147456 ----a-w- c:\windows\system32\RtlCPAPI.dll
2011-04-08 03:38:45 18804736 ----a-w- c:\windows\system32\alsndmgr.cpl
2011-04-08 03:38:41 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-04-08 03:38:39 577536 ----a-w- c:\windows\soundman.exe
2011-04-08 03:36:59 49152 ----a-w- c:\windows\InstFunc.exe
2011-04-08 03:36:59 12288 ----a-w- c:\windows\InstFunc.dll
2011-04-08 03:32:40 315392 ----a-w- c:\windows\alcupd.exe
2011-04-08 03:32:40 217088 ----a-w- c:\windows\Alcrmv.exe
2011-04-08 03:23:30 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-03-16 08:23:59 21768 ----a-w- c:\documents and settings\keifer\s
2011-03-15 21:37:23 5376 ----a-w- c:\windows\system32\freewat.dll
2011-03-12 10:44:47 218624 ----a-w- c:\windows\system32\uxtheme.dll.tmp
2011-03-12 10:44:47 218624 ----a-w- c:\windows\system32\uxtheme.dll
2011-03-12 10:44:47 218624 ----a-w- c:\windows\system32\uxtheme(2).dll
2011-03-12 10:41:47 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-28 08:00:00 80896 ----a-w- c:\windows\system32\ff_vfw.dll
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2010-11-22 16:59:04 4177272 ----a-w- c:\program files\procexp.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Maxtor_6E040L0 rev.NAR61HA0 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x85FCDAB8]
3 CLASSPNP[0xF7719FD7] -> nt!IofCallDriver[0x804E37D5] -> \Device\00000055[0x85F332A0]
5 ACPI[0xF7690620] -> nt!IofCallDriver[0x804E37D5] -> \Device\Ide\IdeDeviceP0T0L0-4[0x85FCCD98]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
user != kernel MBR !!!
sectors 80293246 (+245): user != kernel
.
============= FINISH: 4:15:15.64 ===============
Attached File(s)
-
ark.txt (8.9K)
Number of downloads: 2 -
Attach.txt (4.77K)
Number of downloads: 0

Help
This topic is locked

Back to top



button.









