Help!

Laptop sluggish- is it me or the computer?

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs RSS
Next:  Google Shuts Down Anti-Obama Sites  
Author Message
VegasAly



Joined: Jun 17, 2008
Posts: 12



PostPosted: Sun Jun 29, 2008 8:02 pm    Post subject: Laptop sluggish- is it me or the computer?

Continued from my previous post under General > Problem solvers... in a nut shell, my CPU usage seems to run constantly at 100.

http://help.lockergnome.com/general/Laptop-sluggish-computer-ftopict55317.html

The logs GreyKnight advised to run will be posted below...

I did disable the antivirus and antispyware programs in my Zone Alarm secuity suite so that they will not interfere with the software I just downloaded.

The malwarebytes and avg anti virus are still running but heres the superantispyware log -

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/29/2008 at 04:43 PM

Application Version : 4.15.1000

Core Rules Database Version : 3493
Trace Rules Database Version: 1484

Scan type : Complete Scan
Total Scan Time : 02:10:58

Memory items scanned : 524
Memory threats detected : 0
Registry items scanned : 6593
Registry threats detected : 0
File items scanned : 20091
File threats detected : 0

Adware.Tracking Cookie
.kontera.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.kontera.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
rotator.adjuggler.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.tribalfusion.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.doubleclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.questionmarket.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.atdmt.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
statse.webtrendslive.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.mediaplex.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.apmebf.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
www.googleadservices.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.2o7.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.ehg-accuweather.hitbox.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.hitbox.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.hitbox.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.bs.serving-sys.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.specificclick.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adopt.euroclick.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.adserver.adtechus.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
.advertising.com [ C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt ]
Back to top
VegasAly



Joined: Jun 17, 2008
Posts: 12



PostPosted: Sun Jun 29, 2008 8:10 pm    Post subject:

Malwarebytes' Anti-Malware 1.19
Database version: 904
Windows 5.1.2600 Service Pack 2

5:20:41 PM 6/29/2008
mbam-log-6-29-2008 (17-20-41).txt

Scan type: Full Scan (C:\|)
Objects scanned: 115176
Time elapsed: 2 hour(s), 55 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Back to top
VegasAly



Joined: Jun 17, 2008
Posts: 12



PostPosted: Sun Jun 29, 2008 10:03 pm    Post subject: AVG scan results

"Scan ""Scan whole computer"" was finished ."
"Infections found:";"0"
"Infected objects removed or healed";"0"
"Not removed or healed.";"0"
"Spyware found:";"0"
"Spyware removed:";"0"
"Not removed:";"0"
"Warnings count:";"32"
"Information count:";"0"
"Scan started:";"Sunday, June 29, 2008, 2: 23:29 PM"
"Total object scanned:";"714733"
"Time needed:";"4 hour(s) 43 minute(s) 46 second(s) "
"Errors encountered:";"0"

"Warnings"
"File";"Infection";"Result"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\tribalfusion.com.dcc03271";"Found Tracking cookie.Tribalfusion";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\doubleclick.net.bf396750";"Found Tracking cookie.Doubleclick";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\questionmarket.com.4dd5e426";"Found Tracking cookie.Questionmarket";"Potentiallydangerousobject"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\questionmarket.com.3eb5a9f1";"Found Tracking cookie.Questionmarket";"Potentiallydangerousobject"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\atdmt.com.b3e33b5f";"Found Tracking cookie.Atdmt";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\statse.webtrendslive.com.b4ca7df0";"Found Tracking cookie.Webtrendslive";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\mediaplex.com.f652b123";"Found Tracking cookie.Mediaplex";"Potentially dangerousobject"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\2o7.net.d4b64ade";"Found Tracking cookie.2o7";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\2o7.net.c8d658d3";"Found Tracking cookie.2o7";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\2o7.net.e27aabc7";"Found Tracking cookie.2o7";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\2o7.net.6b30dc5";"Found Tracking cookie.2o7";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\hitbox.com.bbf2a6e8";"Found Tracking cookie.Hitbox";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\hitbox.com.2b95f8a3";"Found Tracking cookie.Hitbox";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\serving-sys.com.4b416ef8";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\serving-sys.com.255d6f2f";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\serving-sys.com.606c3d3b";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\serving-sys.com.c9034af6";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\serving-sys.com.400f83f";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\serving-sys.com.6a1cf9e8";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\bs.serving-sys.com.5bf1f00f";"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\tacoda.net.e9f57f8";"Found Tracking cookie.Tacoda";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\tacoda.net.ed9c50d1";"Found Tracking cookie.Tacoda";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\tacoda.net.27341d57";"Found Tracking cookie.Tacoda";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\tacoda.net.5935e89";"Found Tracking cookie.Tacoda";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\tacoda.net.d323296e";"Found Tracking cookie.Tacoda";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\tacoda.net.c4fe2ebb";"Found Tracking cookie.Tacoda";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\adopt.euroclick.com.891542da";"Found Tracking cookie.Euroclick";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\adopt.euroclick.com.8b1bd7bc";"Found Tracking cookie.Euroclick";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\adopt.euroclick.com.17044b51";"Found Tracking cookie.Euroclick";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\adopt.euroclick.com.6d7740f7";"Found Tracking cookie.Euroclick";"Potentially dangerous object"
"C:\Documents and Settings\Aly\ApplicationData\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt:\advertising.com.525a5fb9";"Found Tracking cookie.Advertising";"Potentially dangerous object"
Back to top
VegasAly



Joined: Jun 17, 2008
Posts: 12



PostPosted: Sun Jun 29, 2008 10:42 pm    Post subject:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:53:18 PM, on 6/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\System32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\Program Files\Plaxo\3.11.0.27\PlaxoHelper_en.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\PayPal\PayPal Plug-In\RBroker.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\LIUtilities\WinTasks\wintasks.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Documents and Settings\Aly\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://r.office.microsoft.com/r/rlidOfficeUpdate?clid=1033
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.11.0.27\PlaxoHelper_en.exe -a -t
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/c...nt/muwe
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O20 - Winlogon Notify: RDM+ - C:\Program Files\RDM+\notify.dll (file missing)
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: RDM+ Local Service (RDMPLocalService) - Unknown owner - C:\Program Files\RDM+\rdmpserv.exe (file missing)
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 12815 bytes
Back to top
VegasAly



Joined: Jun 17, 2008
Posts: 12



PostPosted: Mon Jun 30, 2008 1:58 am    Post subject:

;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-06-29 23:08:13
PROTECTIONS: 2
MALWARE: 12
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AVG Anti-Virus 8.0 Yes Yes
ZoneAlarm Security Suite Antivirus 7.0.473.000 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.doubleclick.net/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.atdmt.com/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.fastclick.net/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.fastclick.net/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.tribalfusion.com/]
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.mediaplex.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[ad.yieldmanager.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.apmebf.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.serving-sys.com/]
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.bs.serving-sys.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.advertising.com/]
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[statse.webtrendslive.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.questionmarket.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Aly\Application Data\Mozilla\Firefox\Profiles\n4ykf2dz.default\cookies.txt[.questionmarket.com/]
;===================================================================================================================================================================================
SUSPECTS
Sent Location š
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description š
;===================================================================================================================================================================================
170904 HIGH MS07-043 š
;===================================================================================================================================================================================
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Mon Jun 30, 2008 8:09 pm    Post subject:

Not sure if this is malware related, but we can run some scans.

Let's try disabling a bunch of startup programs to see if there's any improvement. Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you checked the last one:

O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.11.0.27\PlaxoHelper_en.exe -a -t
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O20 - Winlogon Notify: RDM+ - C:\Program Files\RDM+\notify.dll (file missing)


You might also want to Google a bunch of those Thinkpad processes/services that you have running there. I'm sure that most are not required.

1. Download combofix at http://download.bleepingcomputer.com/sUBs/ComboFix.exe Save it to your Desktop before you run it.
2. Double-click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply.

Note:
Do not click on combofix's window while it's running. That may cause it to stall.
Back to top
AIM Address Yahoo Messenger
VegasAly



Joined: Jun 17, 2008
Posts: 12



PostPosted: Fri Jul 04, 2008 2:22 pm    Post subject:

I think I've seen a bit of an improvement on the sluggishness. I disabled the programs recommended and here is the log from the combo fix ...

ComboFix 08-07-04.1 - Aly 2008-07-04 11:16:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1483 [GMT -7:00]
Running from: C:\Documents and Settings\Aly\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-06-04 to 2008-07-04 )))))))))))))))))))))))))))))))
.

2008-07-02 10:17 . 2008-07-02 10:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-02 10:17 . 2008-07-02 10:17 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-02 10:16 . 2008-07-02 10:16 <DIR> d-------- C:\Documents and Settings\Aly\Application Data\Smith Micro
2008-06-29 19:40 . 2008-06-29 19:41 <DIR> d-------- C:\Program Files\Panda Security
2008-06-29 17:25 . 2008-06-29 17:25 <DIR> d-------- C:\Program Files\BillP Studios
2008-06-29 17:25 . 2008-06-29 17:25 <DIR> d-------- C:\Documents and Settings\Aly\Application Data\WinPatrol
2008-06-29 14:27 . 2008-06-29 14:27 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-29 14:27 . 2008-06-29 14:27 <DIR> d-------- C:\Documents and Settings\Aly\Application Data\SUPERAntiSpyware.com
2008-06-29 14:27 . 2008-06-29 14:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-29 14:24 . 2008-06-29 14:24 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-29 14:24 . 2008-06-29 14:24 <DIR> d-------- C:\Documents and Settings\Aly\Application Data\Malwarebytes
2008-06-29 14:24 . 2008-06-29 14:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-29 14:24 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-29 14:24 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-29 14:17 . 2008-07-04 10:53 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-29 14:17 . 2008-06-29 14:17 <DIR> d-------- C:\Program Files\AVG
2008-06-29 14:17 . 2008-06-29 14:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-29 14:17 . 2008-07-02 09:38 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-29 14:17 . 2008-07-02 09:40 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-29 14:17 . 2008-07-02 09:39 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-29 14:17 . 2008-07-02 09:39 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-27 10:29 . 2008-06-27 10:29 <DIR> d-------- C:\Program Files\Yahoo!
2008-06-27 10:29 . 2008-06-27 10:30 <DIR> d-------- C:\Program Files\CCleaner
2008-06-24 09:48 . 2008-06-24 10:17 <DIR> d-------- C:\Program Files\RDM+
2008-06-24 09:36 . 2008-06-24 09:36 <DIR> d-------- C:\Program Files\Verizon Wireless
2008-06-12 12:19 . 2008-06-12 12:21 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-06-10 22:57 . 2008-06-10 22:57 <DIR> d-------- C:\Program Files\PayPal
2008-06-10 22:57 . 2008-07-04 10:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WholeSecurity
2008-06-10 22:06 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 22:06 . 2008-06-13 06:10 272,128 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-06 07:23 . 2008-07-02 09:35 <DIR> d-------- C:\Program Files\Plaxo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-04 18:26 8,789,792 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-04 18:21 118,652 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-02 22:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\PCPitstop
2008-07-02 22:17 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-06-29 23:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-20 20:24 --------- d-----w C:\Documents and Settings\Aly\Application Data\LimeWire
2008-06-17 17:15 --------- d-----w C:\Program Files\CoffeeCup Software
2008-06-17 17:15 --------- d-----w C:\Documents and Settings\Aly\Application Data\CoreFTP
2008-06-14 03:53 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-14 03:53 --------- d-----w C:\Program Files\XVideoConverter
2008-06-12 19:11 --------- d-----w C:\Program Files\Windows Media Connect
2008-06-11 05:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-04 06:07 --------- d-----w C:\Program Files\EZ Grabber
2008-06-01 18:14 --------- d-----w C:\Program Files\Common Files\Research In Motion
2008-06-01 16:45 --------- d-----w C:\Program Files\PCPitstop
2008-05-30 17:17 --------- d-----w C:\Documents and Settings\Aly\Application Data\Ulead Systems
2008-05-30 17:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-05-30 16:18 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-05-30 16:15 --------- d-----w C:\Program Files\SmartSound Software
2008-05-30 16:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-05-30 15:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\QuickTime
2008-05-30 15:56 --------- d-----w C:\Program Files\Windows Media Components
2008-05-30 15:53 --------- d-----w C:\Program Files\Ulead Systems
2008-05-30 02:24 --------- d-----w C:\Program Files\Mydrv
2008-05-29 15:47 --------- d-----w C:\Program Files\LimeWire
2008-05-21 16:39 256 ----a-w C:\Documents and Settings\Aly\pool.bin
2008-05-17 16:28 --------- d-----w C:\Program Files\ThinkVantage Fingerprint Software
2008-05-17 07:22 --------- d-----w C:\Program Files\ThinkPad
2008-05-17 07:20 --------- d-----w C:\Program Files\InterVideo
2008-05-17 07:19 --------- d-----w C:\Program Files\Common Files\InterVideo
2008-05-17 07:04 --------- d-----w C:\Program Files\Common Files\Virtual Token
2008-05-17 07:04 --------- d-----w C:\Program Files\Common Files\ThinkVantage Fingerprint Software
2008-05-17 07:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\UIB
2008-05-17 06:59 --------- d-----w C:\Program Files\ThinkVantage
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360]
"amsg"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2005-08-01 22:36 475136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2007-12-05 16:14 122880]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-05 16:14 524288]
"EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2007-04-27 02:33 243248]
"TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 10:19 94208]
"LPManager"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe" [2008-01-11 02:21 144728]
"AMSG"="C:\Program Files\ThinkVantage\AMSG\Amsg.exe" [2005-08-01 22:36 475136]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-09-26 17:11 196696]
"ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2008-03-14 18:57 425984]
"ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2008-03-14 18:53 126976]
"PWRMGRTR"="C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-08-10 02:10 139264]
"BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-08-10 02:10 208896]
"TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2007-01-09 16:28 868352]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 14:48 479232]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2005-07-22 20:18 188416]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 10:34 487424]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-04-02 21:07 919016]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-02 09:40 1231128]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-04-25 10:31 333120]
"TpShocks"="TpShocks.exe" [2007-11-22 15:09 181536 C:\WINDOWS\system32\TpShocks.exe]
"TP4EX"="tp4ex.exe" [2005-10-17 01:11 65536 C:\WINDOWS\system32\TP4EX.exe]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-08-14 15:54 89600 C:\WINDOWS\system32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
2008-03-14 18:54 32768 C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 23:45 28672 C:\WINDOWS\system32\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 20:16 24576 C:\WINDOWS\system32\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-07-02 09:39]
R0 Shockprf;Shockprf;C:\WINDOWS\system32\DRIVERS\Apsx86.sys [2007-10-16 18:33]
R0 TPDIGIMN;TPDIGIMN;C:\WINDOWS\system32\DRIVERS\ApsHM86.sys [2007-10-16 18:32]
R1 ANC;ANC;C:\WINDOWS\system32\drivers\ANC.SYS [2008-01-21 20:34]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-02 09:38]
R1 hmonitor;hmonitor;C:\WINDOWS\system32\drivers\hmonitor.sys [2008-04-10 14:14]
R1 IBMTPCHK;IBMTPCHK;C:\WINDOWS\system32\Drivers\IBMBLDID.sys [2008-01-21 20:34]
R1 TPPWRIF;TPPWRIF;C:\WINDOWS\system32\drivers\Tppwrif.sys [2005-08-10 02:10]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-02 09:40]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-02 09:40]
R2 smihlp2;SMI Helper Driver (smihlp2);C:\Program Files\Common Files\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [2007-08-14 15:46]
R3 dfmirage;dfmirage;C:\WINDOWS\system32\DRIVERS\dfmirage.sys [2008-04-15 04:49]
R3 WSIMD;wsimd Service;C:\WINDOWS\system32\DRIVERS\wsimd.sys [2007-07-03 18:46]
S2 RDMPLocalService;RDM+ Local Service;"C:\Program Files\RDM+\rdmpserv.exe" []
S3 U6000ALL;U6000 TV Box(ALL);C:\WINDOWS\system32\DRIVERS\U6000ALL.sys [2007-07-13 01:56]

.
Contents of the 'Scheduled Tasks' folder
"2008-03-03 02:13:38 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-04 18:27:17 C:\WINDOWS\Tasks\PMTask.job"
- C:\PROGRA~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE
"2008-03-02 23:48:21 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2008-05-29 16:47:06 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-04-19 16:47:57 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
- - - - ORPHANS REMOVED - - - -

Notify-RDM+ - C:\Program Files\RDM+\notify.dll
Notify-NavLogon - (no file)


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-04 11:25:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tphklock.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\WINDOWS\system32\TPHDEXLG.exe
C:\WINDOWS\system32\TpKmpSvc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
.
**************************************************************************
.
Completion time: 2008-07-04 11:30:29 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-04 18:30:15

Pre-Run: 51,112,079,360 bytes free
Post-Run: 50,999,250,944 bytes free

220 --- E O F --- 2008-06-20 13:32:36
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Fri Jul 04, 2008 7:04 pm    Post subject:

When did you notice this slowdown issue? I rarely see a system that does belly up out of the blue. Did you install anything before this issue occurred?

I read your other post and you have installed other programs to try speeding things up. If they were not paid programs, please uninstall them as well as they didn't seem to help.

Is that the paid version of ZoneAlarm? Does it come with an antivirus program? It might interfere with AVG8 if it does...
Back to top
AIM Address Yahoo Messenger
VegasAly



Joined: Jun 17, 2008
Posts: 12



PostPosted: Sat Jul 05, 2008 12:20 pm    Post subject:

I'm not sure what I installed that may have caused this. I know I've had SpeedUpMyPC since before April, so it was happening then.

It is a paid version of Zone Alarm but I did disable the antivirus and antispyware in Zone Alarm so they wouldn/t interfere with the AVG and Super Antispyware.
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Sun Jul 06, 2008 8:42 pm    Post subject:

You might have to post back at the Windows board. The scans here are coming up clean. From what I see, you don't have anything harmful here except for some cookies (which are probably harmless).
Back to top
AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum