Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

coolwebsearch


  • This topic is locked This topic is locked
22 replies to this topic

#1 jbander

jbander

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 20 April 2010 - 04:38 PM

Window Explorer freezes and it wont shut down for 1 or 2 minutes and the cpu usage go's to 100%

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:33:25 PM, on 4/20/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startribune.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6087.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1269106466671
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{689E37A2-85C8-42D1-874A-99D3D69956FE}: NameServer = 208.38.65.37,208.38.65.35
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

--
End of file - 4620 bytes


BC AdBot (Login to Remove)

 


#2 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:03:55 AM

Posted 25 April 2010 - 06:47 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below I will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE


And

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.


Then

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.
Posted Image
m0le is a proud member of UNITE

#3 jbander

jbander
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 26 April 2010 - 12:59 AM

QUOTE(jbander @ Apr 20 2010, 04:38 PM) View Post
Window Explorer freezes and it wont shut down for 1 or 2 minutes and the cpu usage go's to 100%

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:33:25 PM, on 4/20/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startribune.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6087.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1269106466671
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{689E37A2-85C8-42D1-874A-99D3D69956FE}: NameServer = 208.38.65.37,208.38.65.35
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

--
End of file - 4620 bytes



#4 jbander

jbander
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 26 April 2010 - 11:36 AM

QUOTE(jbander @ Apr 26 2010, 12:59 AM) View Post
QUOTE(jbander @ Apr 20 2010, 04:38 PM) View Post
Window Explorer freezes and it wont shut down for 1 or 2 minutes and the cpu usage go's to 100%

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:33:25 PM, on 4/20/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startribune.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6087.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1269106466671
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{689E37A2-85C8-42D1-874A-99D3D69956FE}: NameServer = 208.38.65.37,208.38.65.35
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

--
End of file - 4620 bytes



DDS (Ver_10-03-17.01) - NTFSx86
Run by Jon Anderson at 0:46:14.42 on Mon 04/26/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.190.21 [GMT -5:00]

AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Jon Anderson\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.startribune.com/
uSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [VTTimer] VTTimer.exe
mRun: [VTTrayp] VTtrayp.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [EPSON Stylus Photo R340 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1269106466671
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {689E37A2-85C8-42D1-874A-99D3D69956FE} = 208.38.65.37,208.38.65.35

============= SERVICES / DRIVERS ===============

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-16 162768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-16 19024]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-16 40384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-16 135664]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-16 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-16 40384]

=============== Created Last 30 ================

2010-04-22 06:33:17 0 d-----w- c:\windows\system32\NtmsData
2010-04-20 21:32:00 0 d-----w- c:\program files\Trend Micro
2010-04-20 04:53:01 0 d-----w- c:\program files\TrendMicro
2010-04-18 22:45:50 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-04-12 05:40:45 2 ----a-w- c:\windows\msoffice.ini
2010-04-12 00:18:10 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-04-12 00:17:54 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-04-12 00:17:41 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-12 00:17:41 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys

==================== Find3M ====================

2010-03-20 07:18:00 39424 ----a-w- c:\windows\zipinst.exe
2010-03-16 20:37:54 8552 ----a-w- c:\windows\system32\drivers\asctrm.sys
2010-02-25 06:24:37 916480 ----a-w- c:\windows\system32\wininet.dll

============= FINISH: 0:46:37.51 ===============

Attached Files



#5 jbander

jbander
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 26 April 2010 - 12:17 PM

QUOTE(jbander @ Apr 26 2010, 11:36 AM) View Post
QUOTE(jbander @ Apr 26 2010, 12:59 AM) View Post
QUOTE(jbander @ Apr 20 2010, 04:38 PM) View Post
Window Explorer freezes and it wont shut down for 1 or 2 minutes and the cpu usage go's to 100%

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:33:25 PM, on 4/20/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startribune.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [EPSON Stylus Photo R340 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6087.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1269106466671
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{689E37A2-85C8-42D1-874A-99D3D69956FE}: NameServer = 208.38.65.37,208.38.65.35
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

--
End of file - 4620 bytes



DDS (Ver_10-03-17.01) - NTFSx86
Run by Jon Anderson at 0:46:14.42 on Mon 04/26/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.190.21 [GMT -5:00]

AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Jon Anderson\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.startribune.com/
uSearch Page = hxxp://www.google.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [VTTimer] VTTimer.exe
mRun: [VTTrayp] VTtrayp.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [EPSON Stylus Photo R340 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIAJA.EXE /P30 "EPSON Stylus Photo R340 Series" /O6 "USB002" /M "Stylus Photo R340"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1269106466671
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {689E37A2-85C8-42D1-874A-99D3D69956FE} = 208.38.65.37,208.38.65.35

============= SERVICES / DRIVERS ===============

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-16 162768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-16 19024]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-16 40384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-16 135664]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-16 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-16 40384]

=============== Created Last 30 ================

2010-04-22 06:33:17 0 d-----w- c:\windows\system32\NtmsData
2010-04-20 21:32:00 0 d-----w- c:\program files\Trend Micro
2010-04-20 04:53:01 0 d-----w- c:\program files\TrendMicro
2010-04-18 22:45:50 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-04-12 05:40:45 2 ----a-w- c:\windows\msoffice.ini
2010-04-12 00:18:10 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-04-12 00:17:54 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-04-12 00:17:41 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2010-04-12 00:17:41 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys

==================== Find3M ====================

2010-03-20 07:18:00 39424 ----a-w- c:\windows\zipinst.exe
2010-03-16 20:37:54 8552 ----a-w- c:\windows\system32\drivers\asctrm.sys
2010-02-25 06:24:37 916480 ----a-w- c:\windows\system32\wininet.dll

============= FINISH: 0:46:37.51 ===============

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-26 12:09:04
Windows 5.1.2600 Service Pack 2
Running: 5vq04cqg.exe; Driver: C:\DOCUME~1\JONAND~1\LOCALS~1\Temp\kwryqkob.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF8FCBC08]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF8FCBAC4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xF8FCC078]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF8FCBFA2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF8FCB69A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF8FCBB9E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF8FCB5DA]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF8FCB63E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF8FCBCBE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xF8FCC146]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF8FCBC7E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF8FCBDFE]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xF8FD850A]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xF8FD832E]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xF8FD8468]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

PAGE ntkrnlpa.exe!ZwLoadDriver 80578664 7 Bytes JMP F8FD846C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 8059F568 7 Bytes JMP F8FD8332 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805B0A74 5 Bytes JMP F8FD44AA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805B7762 5 Bytes JMP F8FD597E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805C5F66 7 Bytes JMP F8FD850E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xFA492900]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2EDAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E4671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E46DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E4542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E45A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E47A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2748] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E4606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!UnhookWindowsHookEx 7E41F21E 5 Bytes JMP 3E25466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!CallNextHookEx 7E41F85B 5 Bytes JMP 3E2DD101 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2EDAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!SetWindowsHookExW 7E42DDB5 5 Bytes JMP 3E2E9A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E4671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E46DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E4542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E45A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E47A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E4606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 3E2EDB20 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] ole32.dll!OleLoadFromStream 7752A257 5 Bytes JMP 3E3E4AA7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[584] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00370002
IAT C:\WINDOWS\system32\services.exe[584] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00370000
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Fastfat \FatCdrom aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

---- Disk sectors - GMER 1.0.15 ----

Disk \Device\Harddisk0\DR0 sector 60: copy of MBR

---- EOF - GMER 1.0.15 ----


#6 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:03:55 AM

Posted 26 April 2010 - 12:37 PM

When you reply please use Add Reply and not Quote.

No signs on the log of any problems.


Please run MBAM, this will find any CoolWebSearch still around

Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application or, if you are using Vista, right-click and select Run As Administrator on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Full Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes, they may alert you after scanning with MBAM. Please permit the program to allow the changes.

Posted Image
m0le is a proud member of UNITE

#7 jbander

jbander
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 26 April 2010 - 06:45 PM

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 4040

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

4/26/2010 6:40:23 PM
mbam-log-2010-04-26 (18-40-23).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 138204
Time elapsed: 24 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


#8 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:03:55 AM

Posted 26 April 2010 - 06:50 PM

It's looking good for no infections.


Please run Superantispyware next

Download and scan with SUPERAntiSpyware Free for Home Users
  • Double-click SUPERAntiSpyware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked (leave all others unchecked):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the control center screen.
  • Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
  • On the left, make sure you check C:\Fixed Drive.
  • On the right, under "Complete Scan", choose Perform Complete Scan.
  • Click "Next" to start the scan. Please be patient while it scans your computer.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes".
  • To retrieve the removal information after reboot, launch SUPERAntispyware again.
    • Click Preferences, then click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    • Please copy and paste the Scan Log results in your next reply.
  • Click Close to exit the program.


If that's okay then we can see where we go from there. The symptoms are freezing Explorer and 100% CPU, is that everything?
Posted Image
m0le is a proud member of UNITE

#9 jbander

jbander
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 27 April 2010 - 12:50 PM

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/27/2010 at 12:33 PM

Application Version : 4.35.1002

Core Rules Database Version : 4856
Trace Rules Database Version: 2668

Scan type : Complete Scan
Total Scan Time : 00:23:09

Memory items scanned : 401
Memory threats detected : 0
Registry items scanned : 3236
Registry threats detected : 0
File items scanned : 13484
File threats detected : 145

Adware.Tracking Cookie
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@yieldmanager[3].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@questionmarket[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@server.iad.liveperson[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www.googleadservices[3].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.bleepingcomputer[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.pointroll[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@nextag[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ru4[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www.burstnet[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@adserver.duetads[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@bs.serving-sys[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@zedo[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@collective-media[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www.googleadservices[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@pointroll[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@fastclick[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@bluestreak[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ad.yieldmanager[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@imrworldwide[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@a1.interclick[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@mediaplex[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@mediaforge[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@zipzoomfly.122.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@findarticles[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@adxpose[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@cbsdigitalmedia.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@landing.hitfarm[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@media6degrees[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ad.thehill[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www.googleadservices[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@chitika[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@adserver.adtechus[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@content.yieldmanager[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@adbrite[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@tacoda[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@lucidmedia[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@associatedcontent.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@adecn[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@valueclick[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@interclick[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@advertising[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@eas.apm.emediate[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@doubleclick[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@lockedonmedia[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@revsci[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@pro-market[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@overture[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@2o7[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.associatedcontent[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@cdn4.specificclick[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@banners.thestranger[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@server.iad.liveperson[4].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@statse.webtrendslive[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@yieldmanager[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@247realmedia[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@s.clickability[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@realmedia[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ext-us.bestofmedia[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@e-2dj6wjkoslcpkbp.stats.esomniture[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@counter.surfcounters[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@e-2dj6wjlokmdpkdp.stats.esomniture[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ehg-morningstar.hitbox[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@content.yieldmanager[3].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@web-stat[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@specificmedia[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@atdmt[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@at.atwola[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@statcounter[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.undertone[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@sales.liveperson[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@serving-sys[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@trafficmp[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@shopping.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ad.wsod[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@tribalfusion[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.bridgetrack[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@dmtracker[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@smartadserver[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@counter.hitslink[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@apmebf[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@msnbc.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@buydig.122.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.addynamix[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@kanoodle[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@specificclick[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@network.realmedia[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@burstnet[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@xiti[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@finditcheaperusa[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@invitemedia[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@insightexpressai[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@e-2dj6wjlyclcjiap.stats.esomniture[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@brookingsinstitution.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@dealtime[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@stat.dealtime[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@kontera[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@server.iad.liveperson[6].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@highbeam.122.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@thefind[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@paypal.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@classmates.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ad.blockshopper[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@s1.shinystat[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@walmart.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@qnsr[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@sales.liveperson[5].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www.burstbeacon[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@media.legacy[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@msnportal.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@sales.liveperson[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@tradedoubler[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@hitbox[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@bizrate[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@in.getclicky[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@adserver.aol[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www.discountdownloadsoftware[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@legolas-media[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@sales.liveperson[3].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@oasn04.247realmedia[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@media.adfrontiers[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.cnn[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@casalemedia[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@linksynergy[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@tracking.foxnews[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@server.iad.liveperson[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@iserve.imediastreams[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@burstbeacon[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@eyewonder[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ehg-verizon.hitbox[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www.googleadservices[4].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www1.addfreestats[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.pricescan[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@shinystat[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@csi-tracking[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@stats.gamestop[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@stats.gamestop[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads.pcper[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@server.iad.liveperson[5].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@data.coremetrics[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ehg-techtarget.hitbox[2].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ads1.madmariner[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@www.googleadservices[6].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@hearstmagazines.112.2o7[1].txt
C:\Documents and Settings\Jon Anderson\Cookies\jon_anderson@ihatethemedia[2].txt


#10 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:03:55 AM

Posted 27 April 2010 - 04:10 PM

Clean, apart from the usual tracking cookies list. smile.gif


Can you answer this question from my last post:

QUOTE
The symptoms are freezing Explorer and 100% CPU, is that everything?



Posted Image
m0le is a proud member of UNITE

#11 jbander

jbander
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 28 April 2010 - 12:54 AM

First I want to tell you how much I appreciate what you are doing for me . What you are doing is very important to the people that are having problems with their computer. Nothing is more frustrating then these dam computer. I love them and hate them. Anyway thank you. To answer your last question, My error message that I'm getting in my event viewer is 1002 application hang. But I sense that that isn't telling us much. It has been freezing up and I can't shut it down (it takes 1-3 minutes for it to close after i x it to close it.) I usually have been using the task manager to close it (Explorer) down. I can't tell you if it freezes any other program because I spend all my time on the Internet. This is kind of bad news but it might be important. It seems to have gotten worse since we have been adding all the testing program we have loaded to find the problem. Although i have put the testing program in the trash other then the last two you sent me. I just reloaded the recovery disk to my computer about 6 weeks ago so it fresh now. and I operate using avast for virus protection.

Thank you

Jon

#12 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:03:55 AM

Posted 28 April 2010 - 07:41 PM

If the Explorer program is damaged then anything we add to the load will make it worse.


We will now try and repair these files

We are going to run chkdsk which will verify and repair the file system

Step One: Click Start, select Run

Step Two: In the box, type cmd

Step Three: Click Ok

Step Four: Run the chkdsk utility by typing in the following command:

chkdsk c: /f /r

NOTE: The /f command automatically fixes any errors encountered, the /r command locates bad sectors and recovers readable information.

Step Five: A reboot is normally required for the chkdsk program to lock the disk and run correctly (this is typical on machines that have only one volume), so simply restart the computer and chkdsk will run automatically. When it's finished, (This process can take quite a while depending on the size of your disk, etc.), it will boot back to normal Windows.

On Rebooting the PC you will see the disk being checked.

This process will take, on average, about an hour.


Now we should attempt to update your XP to service pack 3

Your Microsoft Windows installation is out of date. Using unpatched Windows systems on the Internet are a security risk to everyone. When there are insecure computers connected to the Internet, malware spreads faster and more extensively, distributed denial-of-service attacks are easier to launch, and spammers have more platforms from which to send e-mail. Whenever a security problem in its software is found, Microsoft will usually create a patch for it. After the patch is installed, attackers can't use the vulnerability to install malicious software on your computer. Keeping up-to-date with all these security patches will help prevent malware from reinfecting your machine. If you are not sure how to do this, see How to use Microsoft Update.

For additional information, be sure to read "Windows Xp Service Pack 3 (sp3) Information".

Then go here to check for & install updates to Microsoft applications.
Note: The update process uses ActiveX, so you will need to use Internet Explorer for it, and allow the ActiveX control that it wants to install.

Please reboot and repeat the update process until there are no more updates to install.

Let me know how this stage goes. thumbup2.gif
Posted Image
m0le is a proud member of UNITE

#13 jbander

jbander
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 30 April 2010 - 07:40 PM

I ran checkdisk and that completed by itself I presume every thing that was the matter was fixed. But Now I have this problem I just can't get myself to load service pack 3 ,all I ever heard about it is that it doesn't load successfully very often. I just loaded 5 pages of common error messages when trying to load servpac 3 > with most of the error messages you have to go online again to read more about the error message to fix it, and if you get the error message you have no way to fix it because you can't use explorer....My computer is getting everyday, really slow today

#14 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:03:55 AM

Posted 01 May 2010 - 03:18 AM

Microsoft have a checklist for things that could be stopping the update to SP3

Please read through this and action everything it says.


For the CPU problem:

Please downloadProcess Explorer

Please open Process Explorer.

Select the process(es) that is/are using the high CPU.

Right click it and select Properties, then the Services tab.

Under Services Registered in Process, you will find the Service and Display name.

Please take note of what these are and include them in your next reply.
Posted Image
m0le is a proud member of UNITE

#15 jbander

jbander
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:10:55 PM

Posted 02 May 2010 - 12:32 AM

Downloaded process explore, opened it, selected system idle process because it was using 100 % of the cpu. Right clicked it chose properties. But there was no service tab and going to the instructions it says.....This tab is present only for processes that are executing Win32 services, and lists the services running within the process. Process Explorer shows a service's name and display name, and on Windows 2000 and higher, if available, the service's description. The permissions button opens a permissions editor that shows the access permissions assigned to the service.... Any suggestions? I also downloaded and added sp3, no problems.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users