Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Is my computer infected? (sorry, type of infection unknown, if any)


  • This topic is locked This topic is locked
2 replies to this topic

#1 chuckk1

chuckk1

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:16 AM

Posted 10 February 2009 - 04:26 PM

My computer turned VERY slow. I have avast, zone alarm, ad aware, spyware blaster, spybot, windows livecare, advanced system care. I have tried disk clean up, defragging, disabling indexing, numerous tweaks and tips, etc. I have removed all unnecessary programs, used c cleaner, run chkdsk, etc. I have dusted and cleaned the processor, etc. You and HijackThis are my last hope. I appreciate any help you may have! Thank you very much! (ps I uninstalled AVG antivirus many months ago)


DDS (Ver_09-02-01.01) - NTFSx86
Run by dean at 15:28:57.04 on Tue 02/10/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_01
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.151 [GMT 1:00]

AV: AVG 7.5.524 *On-access scanning enabled* (Updated)
AV: avast! antivirus 4.8.1296 [VPS 090210-0] *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\dean\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\dean\Desktop\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
BHO: ZoneAlarm Spy Blocker BHO: {f0d4b231-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\zonealarmsb\bar\1.bin\SPYBLOCK.DLL
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\dean\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [preload] c:\windows\RUNXMLPL.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\itunes\iTunesHelper.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
Notify: igfxcui - igfxsrvc.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\dean\applic~1\mozilla\firefox\profiles\v89xxx2c.default\
FF - plugin: c:\documents and settings\dean\local settings\application data\google\update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\itunes\itunes\mozilla plugins\npitunes.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPZoneSB.dll

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-29 64160]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-24 111184]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2008-1-21 4224]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2008-1-21 10760]
R1 Hotkey;Hotkey;c:\windows\system32\drivers\HOTKEY.sys [2006-11-10 9867]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-7-22 353680]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-24 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-4-24 155160]
R2 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2008-1-21 4960]
R2 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2004-7-19 4096]
R2 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2005-4-7 78208]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 950096]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-4-24 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-4-24 352920]
S1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2008-1-21 821856]
S1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2008-1-21 27776]
S1 mailKmd;mailKmd; [x]
S1 Wbutton;Wbutton;c:\windows\system32\drivers\wbutton.sys --> c:\windows\system32\drivers\Wbutton.sys [?]
S2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe --> c:\progra~1\grisoft\avg7\avgamsvr.exe [?]
S2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe --> c:\progra~1\grisoft\avg7\avgupsvc.exe [?]
S2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe --> c:\progra~1\grisoft\avg7\avgemc.exe [?]
S3 POWERKEY;POWERKEY;c:\program files\launch manager\POWERKEY.SYS [2006-11-10 2343]
S3 SER120;OTI Serial port driver;c:\windows\system32\drivers\ser120.sys [2007-2-22 32782]

=============== Created Last 30 ================

2009-02-10 14:12 11,264 a------- c:\windows\system32\dllcache\1394vdbg.sys
2009-02-10 14:12 66,048 a------- c:\windows\system32\dllcache\s3legacy.dll
2009-02-10 14:08 25,992 a------- c:\windows\system32\pgdfgsvc.exe
2009-02-10 13:32 <DIR> --d----- c:\program files\Trend Micro
2009-02-07 01:59 <DIR> --d----- c:\windows\system32\XPSViewer
2009-02-07 01:57 597,504 -------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-07 01:57 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-02-07 01:57 575,488 -------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-07 01:57 117,760 -------- c:\windows\system32\prntvpt.dll
2009-02-07 01:57 89,088 -------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-02-07 01:57 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-02-07 01:57 1,676,288 -------- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-07 01:57 <DIR> --d----- C:\c021927ab2a3766934
2009-02-05 18:10 192,307 a------- C:\wubildr
2009-02-05 18:10 8,192 a------- C:\wubildr.mbr
2009-02-05 17:53 <DIR> --d----- C:\ubuntu
2009-02-05 14:51 163,840 a------- c:\windows\system32\igfxres.dll
2009-02-05 14:43 101,431 a------- c:\windows\system32\drivers\IdeChnDr.sys
2009-02-05 14:43 44,875 a------- c:\windows\system32\IPrtCnst.dll
2009-02-05 14:43 13,891 a------- c:\windows\system32\drivers\IdeBusDr.sys
2009-02-05 13:39 <DIR> --d----- c:\program files\winMd5Sum
2009-01-31 12:28 15,688 a------- c:\windows\system32\lsdelete.exe
2009-01-30 03:02 <DIR> --d----- C:\6330290e7730ad31e9e639ad
2009-01-30 03:02 <DIR> --d----- C:\789e706ff399fdf4b0
2009-01-29 17:50 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-01-29 17:39 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-29 17:38 <DIR> --d----- c:\program files\Lavasoft
2009-01-29 16:20 <DIR> --d----- c:\docume~1\dean\applic~1\IObit
2009-01-29 16:11 <DIR> --d----- c:\program files\Defraggler

==================== Find3M ====================

2009-01-07 14:22 360 a------- C:\drmHeader.bin
2008-12-11 11:57 333,952 -------- c:\windows\system32\dllcache\srv.sys
2008-12-05 13:10 4,212 ac--h--- c:\windows\system32\zllictbl.dat
2008-11-13 15:18 1,221,008 a------- c:\windows\system32\zpeng25.dll
2008-09-25 16:28 32,768 ac-sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092520080926\index.dat

============= FINISH: 15:30:11.15 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:12:16 AM

Posted 21 February 2009 - 10:30 PM

Hello chuckk1,

Posted Image

Sorry about the delay.:thumbup2: If you still need help, please post a new HijackThis log to make sure nothing has changed, and I'll be happy to look at it for you.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:12:16 AM

Posted 01 March 2009 - 06:05 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users