My laptop became slow couple of months ago. Backed up all useful data, formatted harddrive and reinstalled XP. Couple of days later it started to get slow again (after recovering data from backup hdd), but lately situation is very bad - after connecting to internet I cant do pretty much anything for half an hour or so, cause CPU is 100%, after that it is back to 30-60% most of the times. Probably some hidden applications are running in the background and sending data after connecting to the net. I have scanned with Avast antivirus, Malwarebytes and Spybot. None of them show any results, except spybot sometimes. I also use Zonealarm firewall and browse web in sandboxed browser. I think am doing pretty much everything to avoid viruses/malware, except some rare torrent downloads, but I always scan these files.
Probably my backup hdd has some badware on it, but this 100% CPU is something new. Would be great to get rid of all this bad from both my harddrives and would appreciate if you could give any hints how to avoid them later.
Thank You,
Matt
DDS (Ver_10-03-17.01) - NTFSx86
Run by Administrator at 18:24:51.34 on Thu 07/10/2010
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1917.1207 [GMT 10:00]
AV: avast! antivirus 4.8.1335 [VPS 101006-2] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Rjijhzyzxpopnfef\wumlmkcbca.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Rjijhzyzxpopnfef\wumlmkcbca.exe
C:\WINDOWS\BisonCam\BisonHK.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Optus Wireless Broadband\Optus Wireless Broadband.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Documents and Settings\Administrator\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\program files\flashget\jccatch.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dll
uRun: [Google Update] "c:\documents and settings\administrator\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Mobile Partner] "c:\program files\optus wireless broadband\Optus Wireless Broadband.exe"
uRun: [Mobile Partner] "c:\program files\optus wireless broadband\Optus Wireless Broadband.exe"
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Everything] "c:\program files\everything\Everything.exe" -startup
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [BisonHK] c:\windows\bisoncam\BisonHK.exe
mRun: [BisonHK] c:\windows\bisoncam\BisonHK.exe
IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm
IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2010-10-06 01:07:53 0 d-----w- c:\program files\etax2010
2010-10-03 12:34:08 307200 ----a-w- c:\windows\system32\TubeFinder.exe
2010-10-03 12:34:05 9728 ----a-w- c:\windows\system32\PCCLPFR.DLL
2010-10-03 12:34:05 84512 ----a-w- c:\windows\system32\PICCLP32.OCX
2010-10-03 12:34:05 364544 ----a-w- c:\windows\system32\PropertyGrid.ocx
2010-10-03 12:34:05 208500 ----a-w- c:\windows\system32\ReyXpBasics.tlb
2010-10-03 12:34:05 119568 ----a-w- c:\windows\system32\VB6FR.DLL
2010-10-03 12:34:05 101888 ----a-w- c:\windows\system32\VB6STKIT.DLL
2010-10-03 12:34:04 32768 ----a-w- c:\windows\system32\CMDLGFR.DLL
2010-10-03 12:34:04 24576 ----a-w- c:\windows\system32\ControlSubX.ocx
2010-10-03 12:34:04 152848 ----a-w- c:\windows\system32\COMDLG32.OCX
2010-10-03 12:34:04 141312 ----a-w- c:\windows\system32\MSCMCFR.DLL
2010-10-03 12:34:04 0 d-----w- c:\program files\Free FLV Converter
2010-10-03 12:34:04 0 d-----w- c:\docume~1\admini~1\applic~1\FreeFLVConverter
2010-10-03 11:36:15 0 d-----w- C:\Downloads
2010-10-03 11:30:54 0 d-----w- c:\program files\FlashGet
2010-09-30 08:07:56 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-09-30 08:07:56 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2010-09-30 08:07:56 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-09-30 08:07:56 8192 ----a-w- c:\windows\system32\kbdkor.dll
2010-09-30 08:07:56 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-09-30 08:07:56 6144 ----a-w- c:\windows\system32\kbd101c.dll
2010-09-30 08:07:56 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2010-09-30 08:07:56 5632 ----a-w- c:\windows\system32\kbd103.dll
2010-09-30 08:07:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-09-30 08:07:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2010-09-30 08:07:53 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2010-09-30 08:07:53 6144 ----a-w- c:\windows\system32\kbd106.dll
2010-09-26 11:46:04 0 d-----w- C:\temp
2010-09-26 11:45:07 0 d-----w- c:\windows\BisonC07
2010-09-26 11:45:02 5504 -c--a-w- c:\windows\system32\dllcache\mstee.sys
2010-09-26 11:45:02 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-09-26 11:37:39 81 ----a-r- c:\windows\OEM.ini
2010-09-26 11:37:38 0 d-----w- c:\windows\BisonCam
2010-09-26 11:36:11 0 d-----w- c:\documents and settings\administrator\.yawcam
2010-09-26 11:35:54 0 d-----w- c:\program files\Yawcam
2010-09-26 11:35:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-09-26 11:35:10 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-24 22:59:28 0 d-----w- c:\program files\VideoLAN
2010-09-18 11:54:25 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-09-18 11:41:30 0 d-----r- c:\program files\Skype
2010-09-17 11:50:29 0 d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes
2010-09-17 11:49:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-17 11:49:30 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-09-17 11:49:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-17 11:49:21 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-11 01:36:52 455 ----a-w- C:\boot_.ini
2010-09-11 01:14:54 0 d-----w- c:\program files\uTorrent
2010-09-11 01:14:49 0 d-----w- c:\docume~1\admini~1\applic~1\uTorrent
2010-09-10 14:25:19 24448 ----a-w- c:\windows\system32\drivers\ewdcsc.sys
2010-09-10 14:25:19 113280 ----a-w- c:\windows\system32\drivers\ewusbnet.sys
2010-09-10 14:25:19 102528 ----a-w- c:\windows\system32\drivers\ewusbmdm.sys
2010-09-10 14:25:19 100736 ----a-w- c:\windows\system32\drivers\ewusbdev.sys
2010-09-10 14:24:51 0 d-----w- c:\program files\Optus Wireless Broadband
2010-09-10 14:24:19 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-09-10 14:24:19 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
==================== Find3M ====================
2010-08-28 23:32:03 319488 ----a-w- c:\windows\HideWin.exe
2010-08-28 13:54:51 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-08-28 13:44:58 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-08-28 13:44:57 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-08-28 11:33:35 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-08-28 10:39:19 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-07-22 15:49:15 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57:20 5120 ----a-w- c:\windows\system32\xpsp4res.dll
============= FINISH: 18:37:14.67 ===============