WiredWX Hobby Weather ToolsLog in

 


Computer is freezing up and running slow

2 posters

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Please create a Windows Restore Point!
  • Download Quick Restore Maker v2 by UntameDKreationZ.
  • Save the download to your Desktop. Then, double-click it and Extract all.
  • To Extract, click the Next button repeatedly. Then, it will finish.
  • Double-click the Folder, and then double-click QuickRestoreMaker.exe.
  • It will create a Windows Restore Point. Click Exit when done.


==

Please copy and paste the following in to Notepad:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
"GlobalMaxTcpWindowSize"="256960"
"TcpWindowSize"="256960"
"DefaultTTL"="64"
"EnablePMTUDiscovery"="1"
"DisableTaskOffload"="0"

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPerServer"=dword:00000010
"MaxConnectionsPer1_0Server"=dword:00000010

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MaxConnectionsPerServer"=dword:00000010
"MaxConnectionsPer1_0Server"=dword:00000010

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RemoteComputer\NameSpace\{D6277990-4C6A-11CF-8D87-00AA0060F5BF}]

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters]
"SizReqBuf"="16384"

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\Parameters]
"MaxCmds"=dword:00000064
"MaxThreads"=dword:00000064
"MaxCollectionCount"="65535"

Then click File > Save as
File name: internetFIX.reg
Save as type: All Files
Location: Desktop

==

Once saved, Exit Notepad, and double-click on internetFIX.reg and confirm the prompts.

Then, restart your computer.

Let me know if this works or not to make the browsers work better.

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
My computer is still slow but not as slow as it was. Like when i go to start then click on my computer it still takes awhile to load up. It don't just load right up when i open it up That goes with every program. I still can't use Firefox Why? it opens up but want load up my homepage. I have to use Internet Explorer. It loads up but is slow and freezes up from time to time. I have hughes net satellite and it is suppose to be fast and is not. It takes awhile to load up internet. Is that cause my computer is slow? Why don't my programs open right up? It is faster then it was but they still don't open right up they have to load up and freeze up sometimes but not like it use to where i have to wait forever for it to unfreeze.

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Seems like you still have a rootkit.

Please download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.

  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-24 20:13:32
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JONATH~1\LOCALS~1\Temp\fwrcypoc.sys


---- System - GMER 1.0.15 ----

SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF729AE52]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF727BCDE]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF727BED0]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF729B640]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF729B8F4]
SSDT speh.sys ZwEnumerateKey [0xF7387CA2]
SSDT speh.sys ZwEnumerateValueKey [0xF7388030]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF7299B44]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies ) ZwOpenProcess [0xF77E8470]
SSDT speh.sys ZwQueryKey [0xF7388108]
SSDT speh.sys ZwQueryValueKey [0xF7387F88]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF729BD60]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF729B112]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies ) ZwTerminateProcess [0xF77E8520]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies ) ZwTerminateThread [0xF77E85C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies ) ZwWriteVirtualMemory [0xF77E8660]

INT 0x62 ? 8639DBF8
INT 0x73 ? 85FDABF8
INT 0x82 ? 8639DBF8

---- Kernel code sections - GMER 1.0.15 ----

? speh.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F68CD8AC 5 Bytes JMP 85FDA1D8
.text aslhv33q.SYS F6645384 1 Byte [20]
.text aslhv33q.SYS F6645384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text aslhv33q.SYS F66453AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text aslhv33q.SYS F66453C4 3 Bytes [00, 00, 00]
.text aslhv33q.SYS F66453C9 1 Byte [00]
.text ...

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Webroot\Washer\wwDisp.exe[208] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0008F305 C:\Program Files\Webroot\Washer\wwDisp.exe (Window Washer Client Executable/Webroot Software, Inc.)
.text C:\WINDOWS\Explorer.EXE[1180] SHELL32.dll!SHFileOperationW 7CA70924 5 Bytes JMP 021A1102 C:\Program Files\Unlocker\UnlockerHook.dll

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8639F2D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F739A93C] speh.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F739A990] speh.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F736B040] speh.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F736B13C] speh.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F736B0BE] speh.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F736B7FC] speh.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F736B6D2] speh.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F737AD92] speh.sys
IAT \SystemRoot\System32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 85FDA2D8
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlInitUnicodeString] 000000A5
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!swprintf] 000000E5
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeSetEvent] 000000F1
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 00000071
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 000000D8
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00000031
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmFreeMappingAddress] 00000015
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 00000004
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 000000C7
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmUnmapIoSpace] 00000023
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 000000C3
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IofCompleteRequest] 00000018
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 00000096
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IofCallDriver] 00000005
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0000009A
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 00000007
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoConnectInterrupt] 00000012
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoDetachDevice] 00000080
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeWaitForSingleObject] 000000E2
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeInitializeEvent] 000000EB
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeCancelTimer] 00000027
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 000000B2
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlInitAnsiString] 00000075
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 00000009
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoQueueWorkItem] 00000083
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmMapIoSpace] 0000002C
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0000001A
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoReportDetectedDevice] 0000001B
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoReportResourceForDetection] 0000006E
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 0000005A
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!NlsMbCodePageTag] 000000A0
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!PoRequestPowerIrp] 00000052
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 0000003B
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 000000D6
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!sprintf] 000000B3
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00000029
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ObfDereferenceObject] 000000E3
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 0000002F
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 00000084
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ZwClose] 00000053
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 000000D1
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 00000000
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 000000ED
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 00000020
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoCreateDevice] 000000FC
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 000000B1
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 0000005B
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 0000006A
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ZwOpenKey] 000000CB
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 000000BE
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoStartTimer] 00000039
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeInitializeTimer] 0000004A
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoInitializeTimer] 0000004C
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeInitializeDpc] 00000058
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeInitializeSpinLock] 000000CF
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoInitializeIrp] 000000D0
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ZwCreateKey] 000000EF
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 000000AA
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 000000FB
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ZwSetValueKey] 00000043
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeInsertQueueDpc] 0000004D
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000033
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoStartPacket] 00000085
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000045
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000F9
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoFreeMdl] 00000002
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmUnlockPages] 0000007F
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 00000050
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 0000003C
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 0000009F
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000A8
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeSynchronizeExecution] 00000051
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoStartNextPacket] 000000A3
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeBugCheckEx] 00000040
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 0000008F
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeSetTimer] 00000092
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!_allmul] 0000009D
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmProbeAndLockPages] 00000038
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!_except_handler3] 000000F5
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!PoSetPowerState] 000000BC
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000B6
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000DA
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlDeleteRegistryValue] 00000021
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!_aulldiv] 00000010
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!strstr] 000000FF
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!_strupr] 000000F3
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000D2
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CD
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!KeTickCount] 0000000C
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 00000013
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoDeleteDevice] 000000EC
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 0000005F
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000097
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoAllocateIrp] 00000044
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoAllocateMdl] 00000017
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 000000C4
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000A7
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000007E
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 0000003D
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!ExFreePoolWithTag] 00000064
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoFreeIrp] 0000005D
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!IoFreeWorkItem] 00000019
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!InitSafeBootMode] 00000073
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!RtlCompareMemory] 00000060
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!PoCallDriver] 00000081
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!memmove] 0000004F
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000DC
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\aslhv33q.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\MSVCRT.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9979] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe[1500] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9A27] C:\Program Files\Common Files\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 8639C1F8

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies )

Device \FileSystem\Fastfat \FatCdrom 85ACA500

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbohci \Device\USBPDO-0 85FD91F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{B55CF78A-CC5E-4CB4-BCA7-E07164A7A945} 85A5B500
Device \Driver\usbohci \Device\USBPDO-1 85FD91F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6322E818-AA14-4603-83D6-F456D22835CA} 85A5B500

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Ftdisk \Device\HarddiskVolume1 8640D1F8
Device \Driver\Cdrom \Device\CdRom0 85FAE1F8
Device \Driver\Cdrom \Device\CdRom1 85FAE1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F72C4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 [F72C4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F72C4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [F72C4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f [F72C4B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\Cdrom \Device\CdRom2 85FAE1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 85A5B500
Device \Driver\NetBT \Device\NetbiosSmb 85A5B500
Device \Driver\PCI_PNP4046 \Device\0000005b speh.sys

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\NetBT \Device\NetBT_Tcpip_{CB8F768E-CF4D-4E38-A96D-8B74D6A7078E} 85A5B500
Device \Driver\usbohci \Device\USBFDO-0 85FD91F8
Device \Driver\usbohci \Device\USBFDO-1 85FD91F8
Device \Driver\sptd \Device\220871546 speh.sys
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 85B0F500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 85B0F500
Device \Driver\Ftdisk \Device\FtControl 8640D1F8
Device \Driver\USBSTOR \Device\0000007e 859651F8
Device \Driver\USBSTOR \Device\0000007f 859651F8
Device \Driver\aslhv33q \Device\Scsi\aslhv33q1 85D2F1F8
Device \Driver\aslhv33q \Device\Scsi\aslhv33q1Port2Path0Target0Lun0 85D2F1F8
Device \FileSystem\Fastfat \Fat 85ACA500

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies )

Device \FileSystem\Cdfs \Cdfs 85AAD500

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x16 0x1C 0x31 0xF9 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x11 0xAD 0x40 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x4B 0xC6 0x4A 0x03 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x16 0x1C 0x31 0xF9 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x11 0xAD 0x40 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x4B 0xC6 0x4A 0x03 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x16 0x1C 0x31 0xF9 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x11 0xAD 0x40 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x4B 0xC6 0x4A 0x03 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x16 0x1C 0x31 0xF9 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x11 0xAD 0x40 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x4B 0xC6 0x4A 0x03 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x16 0x1C 0x31 0xF9 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x11 0xAD 0x40 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x4B 0xC6 0x4A 0x03 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x16 0x1C 0x31 0xF9 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x11 0xAD 0x40 ...
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x4B 0xC6 0x4A 0x03 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x16 0x1C 0x31 0xF9 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x1B 0x11 0xAD 0x40 ...
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x4B 0xC6 0x4A 0x03 ...

---- EOF - GMER 1.0.15 ----

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    Code:

    :filefind
    ntoskrnl.exe
    aslhv33q.SYS
    speh.sys
    atapi.sys


  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 20:54 on 25/01/2010 by Jonathan Murray (Administrator - Elevation successful)

========== filefind ==========

Searching for "ntoskrnl.exe"
C:\WINDOWS\$hf_mig$\KB840987\SP1QFE\ntoskrnl.exe --a--- 2051584 bytes [17:22 17/06/2004] [17:22 17/06/2004] F240DC474F8EDB2D95514D831DF069E5
C:\WINDOWS\$hf_mig$\KB914882\SP2QFE\ntoskrnl.exe --a--- 2180992 bytes [01:19 29/05/2008] [04:01 21/02/2006] DF4D09B676964646FA166A78C816B4C3
C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe --a--- 2182016 bytes [16:51 19/12/2006] [16:51 19/12/2006] CEF243F6DEFD20BE4ADDE26C7ECACB54
C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe --a--- 2182144 bytes [09:55 28/02/2007] [09:55 28/02/2007] 5A5C8DB4AA962C714C8371FBDF189FC9
C:\WINDOWS\$hf_mig$\KB956572\SP2QFE\ntoskrnl.exe --a--- 2186112 bytes [23:50 14/04/2009] [10:32 06/02/2009] 6A936E9D7BADAF3CAAEED1E1966EC1B0
C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\ntoskrnl.exe --a--- 2189056 bytes [23:50 14/04/2009] [11:08 06/02/2009] 7A95B10A73737EBF24139AAA63F5212B
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe --a--- 2189184 bytes [23:35 07/02/2009] [23:35 07/02/2009] EFE8EACE83EAAD5849A7A548FB75B584
C:\WINDOWS\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe --a--- 2185984 bytes [23:47 14/10/2008] [09:57 14/08/2008] CE69DBD54221F2D40E49FF6DB77C6507
C:\WINDOWS\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe --a--- 2189184 bytes [23:47 14/10/2008] [10:11 14/08/2008] EEAF32F8E15A24F62BECB1BD403BB5C5
C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe --a--- 2189184 bytes [20:11 14/08/2008] [20:11 14/08/2008] 31914172342BFF330063F343AC6958FE
C:\WINDOWS\$hf_mig$\KB971486\SP2QFE\ntoskrnl.exe --a--- 2185984 bytes [19:00 13/10/2009] [12:51 04/08/2009] 8DF112C341425F29DB4566B8D2A96A7F
C:\WINDOWS\$hf_mig$\KB971486\SP3GDR\ntoskrnl.exe --a--- 2189184 bytes [00:44 05/08/2009] [00:44 05/08/2009] 8415D9C7C050E7022AED8ABF281BE4A6
C:\WINDOWS\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe --a--- 2189312 bytes [19:00 13/10/2009] [13:56 04/08/2009] FDE779EA1A564EBFE16F4E0F82B61BAD
C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe -----c 2180352 bytes [05:41 05/11/2009] [14:00 04/08/2009] D6B537A639D623ED85B73AF3E3BE4B94
C:\WINDOWS\$NtUninstallKB840987$\ntoskrnl.exe --a--c 1879936 bytes [23:33 01/11/2004] [22:08 12/12/2002] DB499BE143D626FC8778BE7E18185EB3
C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe -----c 2179328 bytes [03:23 28/03/2007] [00:59 02/03/2005] 4D4CF2C14550A4B7718E94A6E581856E
C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe -----c 2180352 bytes [02:40 07/05/2007] [14:17 19/12/2006] 8F0DEAB1F81FB83F9C5995853CE48B9F
C:\WINDOWS\$NtUninstallKB956572$\ntoskrnl.exe -----c 2188928 bytes [06:13 05/11/2009] [19:27 13/04/2008] 0C89243C7C3EE199B96FCC16990E0679
C:\WINDOWS\$NtUninstallKB956572_0$\ntoskrnl.exe -----c 2180352 bytes [17:38 15/04/2009] [10:00 14/08/2008] 21C91DA9CB53AA8A37041BA9684A8458
C:\WINDOWS\$NtUninstallKB956841_0$\ntoskrnl.exe -----c 2180352 bytes [03:05 15/10/2008] [09:10 28/02/2007] 582A8DBAA58C3B1F176EB2817DAEE77C
C:\WINDOWS\$NtUninstallKB971486$\ntoskrnl.exe -----c 2189056 bytes [06:24 05/11/2009] [11:08 06/02/2009] 7A95B10A73737EBF24139AAA63F5212B
C:\WINDOWS\$NtUninstallKB971486_0$\ntoskrnl.exe -----c 2180480 bytes [03:07 14/10/2009] [17:24 06/02/2009] FACEBB0CA3154F77009CDFEE78A00BBB
C:\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe --a--c 1982208 bytes [14:31 16/10/2004] [06:24 18/08/2001] A29222D5281056E497408FCC9062F749
C:\WINDOWS\$xpsp1hfm$\Q811493\ntoskrnl.exe --a--c 1925760 bytes [14:30 16/10/2004] [12:57 24/04/2003] 97EC4AB4650DA6FC521CF16F8A6DDCB0
C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe ------ 2189184 bytes [23:50 14/04/2009] [00:44 05/08/2009] 8415D9C7C050E7022AED8ABF281BE4A6
C:\WINDOWS\ERDNT\cache\ntoskrnl.exe --a--- 2189184 bytes [21:59 13/01/2010] [00:44 05/08/2009] 8415D9C7C050E7022AED8ABF281BE4A6
C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe ------ 2188928 bytes [16:25 06/04/2006] [19:27 13/04/2008] 0C89243C7C3EE199B96FCC16990E0679
C:\WINDOWS\system32\dllcache\ntoskrnl.exe -----c 2189184 bytes [23:50 14/04/2009] [00:44 05/08/2009] 8415D9C7C050E7022AED8ABF281BE4A6
C:\WINDOWS\system32\ntoskrnl.exe ------ 2189184 bytes [12:00 08/11/2003] [00:44 05/08/2009] 8415D9C7C050E7022AED8ABF281BE4A6

Searching for "aslhv33q.SYS"
No files found.

Searching for "speh.sys"
No files found.

Searching for "atapi.sys"
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys -----c 95360 bytes [05:42 05/11/2009] [02:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\$NtUninstallQ306583$\atapi.sys --a--- 86656 bytes [22:30 23/03/2004] [21:51 17/08/2001] A64013E98426E1877CB653685C5C0009
C:\WINDOWS\ERDNT\cache\atapi.sys --a--- 96512 bytes [21:59 13/01/2010] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\ServicePackFiles\i386\atapi.sys ------ 96512 bytes [16:26 06/04/2006] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys ------ 96512 bytes [12:00 08/11/2003] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674

-=End Of File=-

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Please go HERE. Copy and paste the following file path in to the box.

C:\WINDOWS\system32\ntoskrnl.exe

Do the same for these two files:

C:\windows\system32\userinit.exe
C:\WINDOWS\system32\drivers\atapi.sys


Then click submit.

Please post the results (URL) to your next reply.

Note: re-scan the file. Do not get the past analysis.

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total
Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...
File ntoskrnl.exe received on 2010.01.27 02:13:04 (UTC)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/40 (0%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.01.27 -
AhnLab-V3 5.0.0.2 2010.01.26 -
AntiVir 7.9.1.150 2010.01.26 -
Antiy-AVL 2.0.3.7 2010.01.26 -
Authentium 5.2.0.5 2010.01.27 -
Avast 4.8.1351.0 2010.01.26 -
AVG 9.0.0.730 2010.01.26 -
BitDefender 7.2 2010.01.27 -
CAT-QuickHeal 10.00 2010.01.25 -
ClamAV 0.94.1 2010.01.26 -
Comodo 3719 2010.01.26 -
DrWeb 5.0.1.12222 2010.01.27 -
eSafe 7.0.17.0 2010.01.26 -
eTrust-Vet 35.2.7262 2010.01.26 -
F-Prot 4.5.1.85 2010.01.26 -
F-Secure 9.0.15370.0 2010.01.27 -
Fortinet 4.0.14.0 2010.01.26 -
GData 19 2010.01.27 -
Ikarus T3.1.1.80.0 2010.01.27 -
Jiangmin 13.0.900 2010.01.26 -
K7AntiVirus 7.10.957 2010.01.26 -
Kaspersky 7.0.0.125 2010.01.27 -
McAfee 5873 2010.01.26 -
McAfee+Artemis 5873 2010.01.26 -
McAfee-GW-Edition 6.8.5 2010.01.27 -
Microsoft 1.5406 2010.01.27 -
NOD32 4808 2010.01.26 -
Norman 6.04.03 2010.01.26 -
nProtect 2009.1.8.0 2010.01.26 -
Panda 10.0.2.2 2010.01.26 -
PCTools 7.0.3.5 2010.01.27 -
Rising 22.32.02.01 2010.01.27 -
Sophos 4.50.0 2010.01.27 -
Sunbelt 3.2.1858.2 2010.01.27 -
Symantec 20091.2.0.41 2010.01.27 -
TheHacker 6.5.0.9.165 2010.01.27 -
TrendMicro 9.120.0.1004 2010.01.26 -
VBA32 3.12.12.1 2010.01.26 -
ViRobot 2010.1.26.2156 2010.01.26 -
VirusBuster 5.0.21.0 2010.01.26 -
Additional information
File size: 2189184 bytes
MD5...: 8415d9c7c050e7022aed8abf281be4a6
SHA1..: e65c2d02a59e46a8f0ce546edcb1681d914723a0
SHA256: c24359d6adc63a86de17f2029dbc0562ae420aed44554c290784ffbc554a1e8e
ssdeep: 24576:UgWyem2gqH4DOHMs65BCtm6Zc9NcoVI9b4GiXY8ACc7XHgQCI+E9IoeAKp
r9q97c:jAm2Lq58MCo7n7qgt0K1TVv
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x22c0
timedatestamp.....: 0x45665e64 (Fri Nov 24 02:52:20 2006)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x52150 0x52200 0.24 98d68cb0e4b7d1e2e7334dfe531532a2
.rdata 0x54000 0x27a 0x400 3.59 6af562d60151e9a0168453115d732018
.data 0x55000 0xcb700 0xcb800 7.18 e77379261f640943c5bb3f9dd41cdde8
.rsrc 0x121000 0x2780 0x2800 4.44 0d5268eb0a7801ae414ece54d4a212bd

( 1 imports )
> KERNEL32.dll: GetCurrentProcess, GetTickCount, GetVersion, GetCurrentThreadId, GetModuleHandleA, GetCommandLineA, GetLastError, GetCurrentProcessId, GetCurrentThread, GetCommandLineW, HeapAlloc, GetProcessHeap, GetSystemDefaultLangID, GetACP, GetFileType, FindFirstFileA, HeapDestroy, GetOEMCP, WaitForSingleObject, GetCPInfo, CreateProcessW, SetFileAttributesA

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: NT Kernel _ System
original name: ntoskrnl.exe
internal name: ntoskrnl.exe
file version.: 5.1.2600.5857 (xpsp_sp3_gdr.090804-1435)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
trid..: OS/2 Executable (generic) (52.8%)
Win32 Executable Generic (32.0%)
Generic Win/DOS Executable (7.5%)
DOS Executable Generic (7.5%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file
VirusTotal ©️ Hispasec Sistemas - Blog - Contact: info@virustotal.com - Terms of Service & Privacy Policy


Srpski | Македонски | العربية | Suomi | ihMdI | | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virus Total
Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...
File userinit.exe received on 2010.01.27 02:18:19 (UTC)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/41 (0%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.01.27 -
AhnLab-V3 5.0.0.2 2010.01.26 -
AntiVir 7.9.1.150 2010.01.26 -
Antiy-AVL 2.0.3.7 2010.01.26 -
Authentium 5.2.0.5 2010.01.27 -
Avast 4.8.1351.0 2010.01.26 -
AVG 9.0.0.730 2010.01.26 -
BitDefender 7.2 2010.01.27 -
CAT-QuickHeal 10.00 2010.01.25 -
ClamAV 0.94.1 2010.01.26 -
Comodo 3719 2010.01.26 -
DrWeb 5.0.1.12222 2010.01.27 -
eSafe 7.0.17.0 2010.01.26 -
eTrust-Vet 35.2.7262 2010.01.26 -
F-Prot 4.5.1.85 2010.01.26 -
F-Secure 9.0.15370.0 2010.01.27 -
Fortinet 4.0.14.0 2010.01.26 -
GData 19 2010.01.27 -
Ikarus T3.1.1.80.0 2010.01.27 -
Jiangmin 13.0.900 2010.01.26 -
K7AntiVirus 7.10.957 2010.01.26 -
Kaspersky 7.0.0.125 2010.01.27 -
McAfee 5873 2010.01.26 -
McAfee+Artemis 5873 2010.01.26 -
McAfee-GW-Edition 6.8.5 2010.01.27 -
Microsoft 1.5406 2010.01.27 -
NOD32 4808 2010.01.26 -
Norman 6.04.03 2010.01.26 -
nProtect 2009.1.8.0 2010.01.26 -
Panda 10.0.2.2 2010.01.26 -
PCTools 7.0.3.5 2010.01.27 -
Prevx 3.0 2010.01.27 -
Rising 22.32.02.01 2010.01.27 -
Sophos 4.50.0 2010.01.27 -
Sunbelt 3.2.1858.2 2010.01.27 -
Symantec 20091.2.0.41 2010.01.27 -
TheHacker 6.5.0.9.165 2010.01.27 -
TrendMicro 9.120.0.1004 2010.01.26 -
VBA32 3.12.12.1 2010.01.26 -
ViRobot 2010.1.26.2156 2010.01.26 -
VirusBuster 5.0.21.0 2010.01.26 -
Additional information
File size: 26112 bytes
MD5...: a93aee1928a9d7ce3e16d24ec7380f89
SHA1..: 513f8bdf67a5a9e09803cfb61f590b39f2683853
SHA256: 944cd2135e171af338352568aa7fe1b8004733a4281395ad6723e0cf43d5f53f
ssdeep: 768:0RMJi8jDLIDSAaQFxfftjaLacmkLGKOq:0RMJbDMDSA7FxffJaLaSLG9q
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x54ad
timedatestamp.....: 0x480251a8 (Sun Apr 13 18:32:08 2008)
machinetype.......: 0x14c (I386)

( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x520e 0x5400 5.95 099b53205ad3f1c3b853a5310d08a9b1
.data 0x7000 0x14c 0x200 1.86 0bb948f267e82975313a03d8c0e8a1cf
.rsrc 0x8000 0xb50 0xc00 3.27 bac832e39f87c4f5f640e5d5c6a1c2fc

( 9 imports )
> USER32.dll: CreateWindowExW, DestroyWindow, RegisterClassExW, DefWindowProcW, LoadRemoteFonts, wsprintfW, GetSystemMetrics, GetKeyboardLayout, SystemParametersInfoW, GetDesktopWindow, LoadStringW, MessageBoxW, ExitWindowsEx, CharNextW
> ADVAPI32.dll: RegOpenKeyExA, ReportEventW, RegisterEventSourceW, DeregisterEventSource, OpenProcessToken, RegCreateKeyExW, RegSetValueExW, GetUserNameW, RegQueryValueExW, RegOpenKeyExW, RegQueryInfoKeyW, RegCloseKey, RegQueryValueExA
> CRYPT32.dll: CryptProtectData
> WINSPOOL.DRV: SpoolerInit
> ntdll.dll: RtlLengthSid, RtlCopySid, _itow, RtlFreeUnicodeString, DbgPrint, wcslen, wcscpy, wcscat, wcscmp, RtlInitUnicodeString, NtOpenKey, NtClose, _wcsicmp, memmove, RtlConvertSidToUnicodeString, NtQueryInformationToken
> NETAPI32.dll: DsGetDcNameW, NetApiBufferFree
> WLDAP32.dll: -, -, -, -, -, -
> msvcrt.dll: __setusermatherr, _initterm, __getmainargs, _acmdln, _adjust_fdiv, _XcptFilter, _exit, _c_exit, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, _cexit, exit
> KERNEL32.dll: CompareFileTime, LoadLibraryW, GetProcAddress, FreeLibrary, lstrcpyW, CreateProcessW, lstrlenW, GetVersionExW, LocalFree, LocalAlloc, GetEnvironmentVariableW, CloseHandle, lstrcatW, WaitForSingleObject, DelayLoadFailureHook, GetStartupInfoA, GetModuleHandleA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, LoadLibraryA, InterlockedCompareExchange, LocalReAlloc, GetSystemTime, lstrcmpW, GetCurrentThread, SetThreadPriority, ExpandEnvironmentStringsW, SearchPathW, GetLastError, CreateThread, GetFileAttributesExW, GetSystemDirectoryW, SetCurrentDirectoryW, FormatMessageW, lstrcmpiW, GetCurrentProcess, GetUserDefaultLangID, GetCurrentProcessId, SetEvent, OpenEventW, Sleep, SetEnvironmentVariableW

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: Userinit Logon Application
original name: USERINIT.EXE
internal name: userinit
file version.: 5.1.2600.5512 (xpsp.080413-2113)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

Scan another file
VirusTotal ©️ Hispasec Sistemas - Blog - Contact: info@virustotal.com - Terms of Service & Privacy Policy
_:

*
a:
Amazon
*
d:
Download Squad
*
f:
Facebook
*
g:
Digg
*
l:
Lifehacker
*
m:
Mashable
*
n:
NYTimes
*
r:
ReadWriteWeb
*
s:
MySpace
*
u:
YouTube
*
w:
Wikipedia
*
?:
VirusTotal - Free Online Virus and Malware Scan - Result

File atapi.sys received on 2010.01.27 02:21:02 (UTC)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 1/40 (2.5%)
Loading server information...
Your file is queued in position: ___.
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Compact
Print results Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:

Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.01.27 -
AhnLab-V3 5.0.0.2 2010.01.26 -
AntiVir 7.9.1.150 2010.01.26 -
Antiy-AVL 2.0.3.7 2010.01.26 -
Authentium 5.2.0.5 2010.01.27 -
Avast 4.8.1351.0 2010.01.26 -
AVG 9.0.0.730 2010.01.26 -
BitDefender 7.2 2010.01.27 -
CAT-QuickHeal 10.00 2010.01.25 -
ClamAV 0.94.1 2010.01.26 -
Comodo 3719 2010.01.26 -
DrWeb 5.0.1.12222 2010.01.27 -
eSafe 7.0.17.0 2010.01.26 Win32.Rootkit
eTrust-Vet 35.2.7262 2010.01.26 -
F-Prot 4.5.1.85 2010.01.26 -
F-Secure 9.0.15370.0 2010.01.27 -
Fortinet 4.0.14.0 2010.01.26 -
GData 19 2010.01.27 -
Ikarus T3.1.1.80.0 2010.01.27 -
Jiangmin 13.0.900 2010.01.26 -
K7AntiVirus 7.10.957 2010.01.26 -
Kaspersky 7.0.0.125 2010.01.27 -
McAfee 5873 2010.01.26 -
McAfee+Artemis 5873 2010.01.26 -
McAfee-GW-Edition 6.8.5 2010.01.27 -
Microsoft 1.5406 2010.01.27 -
NOD32 4808 2010.01.26 -
Norman 6.04.03 2010.01.26 -
nProtect 2009.1.8.0 2010.01.26 -
Panda 10.0.2.2 2010.01.26 -
PCTools 7.0.3.5 2010.01.27 -
Rising 22.32.02.01 2010.01.27 -
Sophos 4.50.0 2010.01.27 -
Sunbelt 3.2.1858.2 2010.01.27 -
Symantec 20091.2.0.41 2010.01.27 -
TheHacker 6.5.0.9.165 2010.01.27 -
TrendMicro 9.120.0.1004 2010.01.26 -
VBA32 3.12.12.1 2010.01.26 -
ViRobot 2010.1.26.2156 2010.01.26 -
VirusBuster 5.0.21.0 2010.01.26 -
Additional information
File size: 96512 bytes
MD5...: 9f3a2f5aa6875c72bf062c712cfa2674
SHA1..: a719156e8ad67456556a02c34e762944234e7a44
SHA256: b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9
ssdeep: 1536:MwXpkfV74F1D7yNEZIHRRJMohmus27G1j/XBoDQi7oaRMJfYHFktprll1Kb
DD0uu:MQ+N74vkEZIxMohjsimBoDTRMBwFktZu
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x159f7
timedatestamp.....: 0x4802539d (Sun Apr 13 18:40:29 2008)
machinetype.......: 0x14c (I386)

( 9 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x380 0x97ba 0x9800 6.45 0d7d81391f33c6450a81be1e3ac8c7b7
NONPAGE 0x9b80 0x18e8 0x1900 6.48 c74a833abd81cc5d037de168e055ad29
.rdata 0xb480 0xa64 0xa80 4.31 8523651899e28819a14bf9415af25708
.data 0xbf00 0xd94 0xe00 0.45 3575b51634ae7a56f55f1ee0a6213834
PAGESCAN 0xcd00 0x157f 0x1580 6.20 dc4c309c4db9576daa752fdd125fccf9
PAGE 0xe280 0x61da 0x6200 6.46 40b83d4d552384e58a03517a98eb4863
INIT 0x14480 0x22be 0x2300 6.47 906462abc478368424ea462d5868d2e3
.rsrc 0x16780 0x3e0 0x400 3.36 8fd2d82e745b289c28bc056d3a0d62ab
.reloc 0x16b80 0xd20 0xd80 6.39 ce2b0898cc0e40b618e5df9099f6be45

( 3 imports )
> ntoskrnl.exe: RtlInitUnicodeString, swprintf, KeSetEvent, IoCreateSymbolicLink, IoGetConfigurationInformation, IoDeleteSymbolicLink, MmFreeMappingAddress, IoFreeErrorLogEntry, IoDisconnectInterrupt, MmUnmapIoSpace, ObReferenceObjectByPointer, IofCompleteRequest, RtlCompareUnicodeString, IofCallDriver, MmAllocateMappingAddress, IoAllocateErrorLogEntry, IoConnectInterrupt, IoDetachDevice, KeWaitForSingleObject, KeInitializeEvent, KeCancelTimer, RtlAnsiStringToUnicodeString, RtlInitAnsiString, IoBuildDeviceIoControlRequest, IoQueueWorkItem, MmMapIoSpace, IoInvalidateDeviceRelations, IoReportDetectedDevice, IoReportResourceForDetection, RtlxAnsiStringToUnicodeSize, NlsMbCodePageTag, PoRequestPowerIrp, KeInsertByKeyDeviceQueue, PoRegisterDeviceForIdleDetection, sprintf, MmMapLockedPagesSpecifyCache, ObfDereferenceObject, IoGetAttachedDeviceReference, IoInvalidateDeviceState, ZwClose, ObReferenceObjectByHandle, ZwCreateDirectoryObject, IoBuildSynchronousFsdRequest, PoStartNextPowerIrp, IoCreateDevice, RtlCopyUnicodeString, IoAllocateDriverObjectExtension, RtlQueryRegistryValues, ZwOpenKey, RtlFreeUnicodeString, IoStartTimer, KeInitializeTimer, IoInitializeTimer, KeInitializeDpc, KeInitializeSpinLock, IoInitializeIrp, ZwCreateKey, RtlAppendUnicodeStringToString, RtlIntegerToUnicodeString, ZwSetValueKey, KeInsertQueueDpc, KefAcquireSpinLockAtDpcLevel, IoStartPacket, KefReleaseSpinLockFromDpcLevel, IoBuildAsynchronousFsdRequest, IoFreeMdl, MmUnlockPages, IoWriteErrorLogEntry, KeRemoveByKeyDeviceQueue, MmMapLockedPagesWithReservedMapping, MmUnmapReservedMapping, KeSynchronizeExecution, IoStartNextPacket, KeBugCheckEx, KeRemoveDeviceQueue, KeSetTimer, _allmul, MmProbeAndLockPages, _except_handler3, PoSetPowerState, IoOpenDeviceRegistryKey, RtlWriteRegistryValue, RtlDeleteRegistryValue, _aulldiv, strstr, _strupr, KeQuerySystemTime, IoWMIRegistrationControl, KeTickCount, IoAttachDeviceToDeviceStack, IoDeleteDevice, ExAllocatePoolWithTag, IoAllocateWorkItem, IoAllocateIrp, IoAllocateMdl, MmBuildMdlForNonPagedPool, MmLockPagableDataSection, IoGetDriverObjectExtension, MmUnlockPagableImageSection, ExFreePoolWithTag, IoFreeIrp, IoFreeWorkItem, InitSafeBootMode, RtlCompareMemory, PoCallDriver, memmove, MmHighestUserAddress
> HAL.dll: KfAcquireSpinLock, READ_PORT_UCHAR, KeGetCurrentIrql, KfRaiseIrql, KfLowerIrql, HalGetInterruptVector, HalTranslateBusAddress, KeStallExecutionProcessor, KfReleaseSpinLock, READ_PORT_BUFFER_USHORT, READ_PORT_USHORT, WRITE_PORT_BUFFER_USHORT, WRITE_PORT_UCHAR
> WMILIB.SYS: WmiSystemControl, WmiCompleteRequest

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: IDE/ATAPI Port Driver
original name: atapi.sys
internal name: atapi.sys
file version.: 5.1.2600.5512 (xpsp.080413-2108)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
packers (Kaspersky): PE_Patch

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Re-running ComboFix to remove infections:

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    FCopy::
    C:\WINDOWS\ServicePackFiles\i386\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys
  4. Save this as CFScript.txt, in the same location as ComboFix.exe

    Computer is freezing up and running slow - Page 2 2v3rg44

  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Every time I drag CFScript into Combofix it says some installation files are currupt please dowload a fresh copy and retry the installation. I downloaded a new copy of Combofix and I drag CFScript into it and it still says the same thing. Why?

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Try to rename the download as blackpudding.bat

then try again.

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
ComboFix 10-01-29.04 - Jonathan Murray 01/29/2010 19:20:02.2.1 - x86
Running from: C:\Documents and Settings\Jonathan Murray\Desktop\blackpudding.bat
Command switches used :: C:\Documents and Settings\Jonathan Murray\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
PEV Error: ProgramsFolder

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\SHELLLNK.TLB

.
--------------- FCopy ---------------

C:\WINDOWS\ServicePackFiles\i386\atapi.sys --> C:\WINDOWS\system32\drivers\atapi.sys
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-30 )))))))))))))))))))))))))))))))
.

2010-01-28 04:25:48 . 2010-01-29 22:41:10 -------- d-----w- C:\ComboFix
2010-01-22 04:28:45 . 2010-01-22 04:28:45 -------- d-----w- C:\Rooter$
2010-01-22 04:27:27 . 2010-01-22 04:27:40 173119 ----a-w- C:\Program Files\Rooter.exe
2010-01-21 04:56:28 . 2010-01-21 04:56:41 1956528 ----a-w- C:\Program Files\install_flash_player_ax.exe
2010-01-20 20:32:36 . 2010-01-20 20:32:36 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Local Settings\Application Data\Threat Expert
2010-01-20 03:55:20 . 2010-01-20 03:55:20 -------- d-----w- C:\WINDOWS\system32\wbem\Repository
2010-01-18 02:53:54 . 2010-01-18 02:54:10 595499 ----a-w- C:\Program Files\Autoruns.zip
2010-01-16 19:51:26 . 2010-01-20 03:53:25 -------- d-----w- C:\Program Files\hpHosts
2010-01-16 05:09:08 . 2010-01-16 05:09:16 800544 ----a-w- C:\Program Files\jre-6u17-windows-i586-iftw-rv.exe
2010-01-16 04:55:52 . 2010-01-16 04:59:17 27386256 ----a-w- C:\Program Files\AdbeRdr930_en_US.exe
2010-01-15 22:07:16 . 2010-01-15 22:07:17 843187 ----a-w- C:\Program Files\SecurityCheck.exe
2010-01-14 23:13:27 . 2010-01-14 23:13:47 2672312 ----a-w- C:\Program Files\esetsmartinstaller_enu.exe
2010-01-13 02:56:12 . 2009-11-21 15:51:04 471552 -c----w- C:\WINDOWS\system32\dllcache\aclayers.dll
2010-01-11 04:40:03 . 2009-11-10 15:26:26 767952 ----a-w- C:\WINDOWS\BDTSupport.dll
2010-01-11 04:40:02 . 2009-11-10 15:28:16 149456 ----a-w- C:\WINDOWS\SGDetectionTool.dll
2010-01-11 04:40:02 . 2009-11-10 15:28:10 165840 ----a-w- C:\WINDOWS\PCTBDRes.dll
2010-01-11 04:40:02 . 2009-11-10 15:28:10 1640400 ----a-w- C:\WINDOWS\PCTBDCore.dll
2010-01-11 04:40:02 . 2009-10-28 06:36:02 1152444 ----a-w- C:\WINDOWS\UDB.zip
2010-01-11 04:40:02 . 2008-11-26 17:08:42 131 ----a-w- C:\WINDOWS\IDB.zip
2010-01-11 04:04:27 . 2010-01-11 04:08:51 34628432 ----a-w- C:\Program Files\sdsetup.exe
2010-01-10 23:40:50 . 2010-01-10 23:40:50 -------- d-----w- C:\Documents and Settings\Administrator.JONATHAN\Application Data\SUPERAntiSpyware.com
2010-01-10 22:03:17 . 2010-01-29 22:36:54 0 ----a-w- C:\Documents and Settings\Jonathan Murray\Local Settings\Application Data\prvlcl.dat
2010-01-07 21:39:08 . 2010-01-07 23:30:14 -------- d-----w- C:\$AVG
2010-01-07 21:38:08 . 2010-01-07 21:38:08 12464 ----a-w- C:\WINDOWS\system32\avgrsstx.dll
2010-01-07 21:38:07 . 2010-01-29 00:37:48 -------- d-----w- C:\WINDOWS\system32\drivers\Avg
2010-01-07 21:36:12 . 2010-01-07 21:36:12 25608 ----a-w- C:\WINDOWS\system32\drivers\AVGIDSxx.sys
2010-01-07 21:36:11 . 2010-01-07 21:36:11 161800 ----a-w- C:\WINDOWS\system32\drivers\avgrkx86.sys
2010-01-07 21:36:10 . 2010-01-07 21:36:10 360584 ----a-w- C:\WINDOWS\system32\drivers\avgtdix.sys
2010-01-07 21:36:09 . 2010-01-07 21:36:09 333192 ----a-w- C:\WINDOWS\system32\drivers\avgldx86.sys
2010-01-07 21:36:07 . 2010-01-07 21:36:08 28424 ----a-w- C:\WINDOWS\system32\drivers\avgmfx86.sys
2010-01-07 21:34:35 . 2010-01-07 21:34:35 50968 ----a-w- C:\WINDOWS\system32\avgfwdx.dll
2010-01-07 21:34:35 . 2010-01-07 21:34:35 30104 ----a-w- C:\WINDOWS\system32\drivers\avgfwdx.sys
2010-01-07 21:34:30 . 2010-01-07 21:34:30 -------- d-----w- C:\Program Files\AVG
2010-01-07 21:34:19 . 2010-01-11 13:17:28 -------- d-----w- C:\Documents and Settings\All Users\Application Data\avg9
2010-01-07 18:43:16 . 2010-01-07 20:25:38 163713 ----a-w- C:\WINDOWS\system32\drivers\sfi.dat
2010-01-07 18:34:49 . 2010-01-07 20:27:19 -------- d-----w- C:\Program Files\COMODO
2010-01-07 18:28:31 . 2010-01-07 18:33:07 40603920 ----a-w- C:\Program Files\CIS_Setup_3.13.125662.579_XP_Vista_x32.exe
2010-01-07 18:00:35 . 2010-01-07 18:00:36 891248 ----a-w- C:\Program Files\avg_free_stb_all_9_40_cnet.exe
2010-01-05 22:45:26 . 2010-01-05 22:45:26 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-05 22:44:57 . 2010-01-05 22:45:02 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2010-01-05 22:44:57 . 2010-01-05 22:44:57 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Application Data\SUPERAntiSpyware.com
2010-01-05 22:44:20 . 2010-01-05 22:44:20 -------- d-----w- C:\Program Files\Common Files\Wise Installation Wizard
2010-01-05 22:42:55 . 2010-01-05 22:44:08 7451168 ----a-w- C:\Program Files\SUPERAntiSpywarePro.exe
2010-01-05 18:43:02 . 2010-01-05 18:43:02 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Application Data\Malwarebytes
2010-01-05 18:42:48 . 2010-01-07 21:07:14 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-01-05 18:42:45 . 2010-01-05 18:42:45 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-01-05 18:42:36 . 2010-01-07 21:07:04 19160 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2010-01-05 18:42:34 . 2010-01-11 22:26:27 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2010-01-05 18:40:58 . 2010-01-05 18:41:23 5061520 ----a-w- C:\Program Files\mbam-setup.exe
2010-01-02 02:55:35 . 2010-01-05 05:20:43 8086544 ----a-w- C:\Program Files\Firefox Setup 3.5.6.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-29 22:30:21 . 2008-05-16 01:32:00 -------- d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
2010-01-28 00:54:09 . 2010-01-28 19:45:48 82 ----a-w- C:\Program Files\CFScript.txt
2010-01-20 23:29:08 . 2009-10-11 22:11:31 411368 ----a-w- C:\WINDOWS\system32\deploytk.dll
2010-01-20 23:24:20 . 2010-01-16 05:11:35 152576 ----a-w- C:\Documents and Settings\Jonathan Murray\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-20 23:20:37 . 2010-01-16 05:09:29 79488 ----a-w- C:\Documents and Settings\Jonathan Murray\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-18 03:11:11 . 2004-03-25 03:00:15 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-16 05:12:27 . 2004-12-01 21:15:02 -------- d-----w- C:\Program Files\Java
2010-01-16 05:05:50 . 2004-03-24 01:01:29 -------- d-----w- C:\Program Files\Common Files\Adobe
2010-01-15 22:12:13 . 2010-01-09 19:44:53 1260800 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-01-15 22:12:11 . 2010-01-09 03:04:13 3777280 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-13 17:55:02 . 2008-05-16 23:20:31 -------- d-----w- C:\Program Files\Spyware Doctor
2010-01-13 05:24:18 . 2009-06-01 23:24:26 0 ----a-w- C:\qinfo.dat
2010-01-11 22:15:20 . 2010-01-11 22:15:20 5115824 ----a-w- C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-11 18:32:45 . 2005-01-08 16:28:23 -------- d-----w- C:\Program Files\Spybot - Search & Destroy
2010-01-11 18:21:51 . 2009-06-02 20:26:14 -------- d-----w- C:\Program Files\Spybot - Search & Destroy1
2010-01-10 23:41:29 . 2010-01-10 23:41:29 117760 ----a-w- C:\Documents and Settings\Administrator.JONATHAN\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-09 19:40:04 . 2010-01-09 03:04:04 3966744 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-09 03:03:11 . 2010-01-09 03:04:17 4043544 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-09 03:01:11 . 2010-01-09 03:04:16 2033432 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-09 02:56:27 . 2010-01-09 19:44:32 737560 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\axioo.dll
2010-01-09 02:56:22 . 2010-01-09 03:04:10 924952 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-01-09 02:50:53 . 2010-01-09 03:04:07 411928 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-07 21:36:13 . 2010-01-09 19:44:24 404760 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\fixcfg.exe
2010-01-05 22:50:36 . 2010-01-05 22:50:36 117760 ----a-w- C:\Documents and Settings\Jonathan Murray\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-05 05:49:31 . 2009-12-04 00:27:04 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Application Data\BitTorrent
2010-01-04 06:55:53 . 2009-08-31 05:12:07 -------- d-----w- C:\Program Files\WildGames
2010-01-04 06:29:30 . 2010-01-04 06:29:30 44024 ----a-w- C:\Program Files\bookmarks1-3-09.html
2009-12-31 05:26:06 . 2006-01-30 19:12:42 44240 ----a-w- C:\Documents and Settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-23 20:28:35 . 2008-12-14 01:25:42 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2009-12-23 20:20:14 . 2004-03-23 22:31:30 -------- d--h--w- C:\Program Files\InstallShield Installation Information
2009-12-23 19:55:38 . 2009-12-23 02:14:32 -------- d-----w- C:\Program Files\Unlocker
2009-12-23 19:32:22 . 2004-04-07 23:57:07 44240 ----a-w- C:\Documents and Settings\Jonathan Murray\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-23 15:22:31 . 2006-05-30 20:25:16 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Sonic
2009-12-23 15:19:34 . 2006-05-30 20:25:49 -------- d-----w- C:\Program Files\Common Files\Sonic Shared
2009-12-23 15:18:34 . 2006-05-30 20:22:29 -------- d-----w- C:\Program Files\Common Files\Roxio Shared
2009-12-23 15:18:13 . 2006-05-30 20:23:33 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Roxio
2009-12-22 19:17:21 . 2009-12-22 19:17:21 10134 ----a-r- C:\Documents and Settings\Jonathan Murray\Application Data\Microsoft\Installer\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}\ARPPRODUCTICON.exe
2009-12-22 05:21:05 . 2003-11-08 12:00:00 667136 ----a-w- C:\WINDOWS\system32\wininet.dll
2009-12-22 05:20:58 . 2009-02-17 01:22:32 81920 ------w- C:\WINDOWS\system32\ieencode.dll
2009-12-05 07:42:35 . 2009-12-05 07:41:54 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Application Data\Nero
2009-12-05 07:41:57 . 2009-12-05 07:41:57 -------- d-----w- C:\Documents and Settings\All Users\Application Data\LightScribe
2009-12-05 07:41:57 . 2007-04-04 16:59:58 -------- d-----w- C:\Program Files\Common Files\LightScribe
2009-12-05 07:39:38 . 2009-12-05 07:20:38 -------- d-----w- C:\Program Files\Common Files\Nero
2009-12-05 07:38:45 . 2007-04-04 16:55:58 -------- d-----w- C:\Program Files\Nero
2009-12-05 07:25:33 . 2007-04-04 16:55:58 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Nero
2009-12-05 06:33:38 . 2009-12-05 06:08:42 214167816 ----a-w- C:\Program Files\Nero-9.4.26.0_trial.exe
2009-12-04 23:36:03 . 2009-12-04 23:30:04 -------- d-----w- C:\Program Files\Cucusoft
2009-12-04 23:35:49 . 2009-12-04 23:35:40 2081039 ----a-w- C:\Program Files\dvd-author.exe
2009-12-04 23:29:21 . 2009-12-04 23:29:05 3119665 ----a-w- C:\Program Files\dvd-burner.exe
2009-12-04 23:26:39 . 2009-12-04 23:26:39 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Application Data\AnvSoft
2009-12-04 23:26:34 . 2009-12-04 23:26:34 -------- d-----w- C:\Program Files\AnvSoft
2009-12-04 23:26:02 . 2009-12-04 23:24:27 15672013 ----a-w- C:\Program Files\avc-free.exe
2009-12-04 23:23:11 . 2009-12-04 22:56:45 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Application Data\Vso
2009-12-04 23:23:09 . 2009-12-04 22:56:45 47360 ----a-w- C:\Documents and Settings\Jonathan Murray\Application Data\pcouffin.sys
2009-12-04 23:23:09 . 2009-12-04 22:56:45 47360 ----a-w- C:\Documents and Settings\Jonathan Murray\Application Data\pcouffin.sys
2009-12-04 22:56:45 . 2009-12-04 22:56:45 47360 ------w- C:\WINDOWS\system32\drivers\pcouffin.sys
2009-12-04 22:54:18 . 2009-12-04 22:52:35 18026336 ----a-w- C:\Program Files\vsoConvertXtoDVD4_setup.exe
2009-12-04 22:22:39 . 2009-12-04 22:11:43 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Application Data\DivX
2009-12-04 19:53:59 . 2009-12-04 19:52:13 -------- d-----w- C:\Program Files\DivX
2009-12-04 19:52:48 . 2009-12-04 19:52:14 -------- d-----w- C:\Program Files\Common Files\DivX Shared
2009-12-04 19:51:21 . 2009-12-04 19:49:15 23804080 ----a-w- C:\Program Files\DivXInstaller.exe
2009-12-04 19:14:36 . 2009-12-04 19:14:00 6104788 ----a-w- C:\Program Files\burnaware_free242.exe
2009-12-04 00:26:00 . 2009-12-04 00:25:53 -------- d-----w- C:\Program Files\BitTorrent
2009-12-04 00:14:29 . 2009-12-04 00:13:28 3066744 ----a-w- C:\Program Files\BitTorrent-6.3c.exe
2009-12-02 23:12:17 . 2009-12-02 23:12:06 8084968 ----a-w- C:\Program Files\Firefox Setup 3.5.5.exe
2009-12-02 00:03:46 . 2008-01-06 17:12:37 -------- d-----w- C:\Documents and Settings\Jonathan Murray\Application Data\LimeWire
2009-11-21 15:51:04 . 2003-11-08 12:00:00 471552 ----a-w- C:\WINDOWS\AppPatch\aclayers.dll
2009-11-14 00:47:32 . 2009-11-14 00:47:32 90112 ------w- C:\WINDOWS\system32\dpl100.dll
2009-11-14 00:47:28 . 2009-11-14 00:47:28 856064 ------w- C:\WINDOWS\system32\divx_xx0c.dll
2009-11-14 00:47:28 . 2009-11-14 00:47:28 856064 ------w- C:\WINDOWS\system32\divx_xx07.dll
2009-11-14 00:47:28 . 2009-11-14 00:47:28 847872 ------w- C:\WINDOWS\system32\divx_xx0a.dll
2009-11-14 00:47:28 . 2009-11-14 00:47:28 843776 ------w- C:\WINDOWS\system32\divx_xx16.dll
2009-11-14 00:47:28 . 2009-11-14 00:47:28 839680 ------w- C:\WINDOWS\system32\divx_xx11.dll
2009-11-14 00:47:28 . 2009-11-14 00:47:28 696320 ------w- C:\WINDOWS\system32\DivX.dll
2009-11-09 16:20:12 . 2009-06-02 04:10:32 207792 ----a-w- C:\WINDOWS\system32\drivers\PCTCore.sys
2009-11-05 06:03:07 . 2001-09-17 05:56:00 77607 ----a-w- C:\WINDOWS\PCHEALTH\HELPCTR\OfflineCache\index.dat
2009-10-07 20:01:34 . 2009-10-07 20:01:32 3340064 ----a-w- C:\Program Files\UnityWebPlayer.exe
2009-10-04 17:12:43 . 2009-10-04 17:11:46 12541248 ----a-w- C:\Program Files\RLCSetup.exe
2009-09-15 19:44:41 . 2009-09-15 19:42:01 25685128 ----a-w- C:\Program Files\wordview_en-us.exe
2009-09-15 19:26:52 . 2009-09-15 19:26:41 13824 ----a-r- C:\Program Files\TRU_Unicru_92908.doc
2009-09-12 20:16:28 . 2009-09-12 20:16:09 4122416 ----a-w- C:\Program Files\freeclip.exe
2009-09-11 23:10:58 . 2009-09-11 22:55:37 52736 ----a-w- C:\Program Files\oown_resume_template.doc
2009-09-04 19:49:38 . 2009-09-04 19:47:45 11729274 ----a-w- C:\Program Files\installeasyjob.exe
2009-09-02 19:29:27 . 2009-09-02 19:29:16 8050536 ----a-w- C:\Program Files\Firefox Setup 3.5.2.exe
2009-07-07 23:46:06 . 2009-07-07 23:45:58 359656 ----a-w- C:\Program Files\msicuu2.exe
2009-02-17 01:18:10 . 2009-02-16 04:28:41 16939888 ----a-w- C:\Program Files\IE8-WindowsXP-x86-ENU.exe
2008-11-23 17:56:59 . 2008-11-23 17:56:50 25740144 ----a-w- C:\Program Files\wmp11-windowsxp-x86-enu.exe
2008-09-06 03:18:00 . 2005-01-03 03:29:49 1505160 ----a-w- C:\Program Files\install_easyshare.exe
2008-07-04 00:24:37 . 2008-07-04 00:21:54 1445888 ----a-w- C:\Program Files\WinsockxpFix.exe
2008-05-31 02:17:18 . 2008-05-31 02:07:36 9723880 ----a-w- C:\Program Files\spybotsd152.exe
2008-05-29 00:21:48 . 2008-05-29 00:21:48 1244712 ----a-w- C:\Program Files\SetupOneCare.exe
2008-05-28 03:12:36 . 2008-05-28 03:12:30 7608344 ----a-w- C:\Program Files\spyhunterFULL.exe
2008-05-09 13:47:14 . 2008-05-09 13:47:14 1206366 ----a-w- C:\Program Files\wrar371.exe
2008-05-09 13:43:51 . 2008-05-09 13:43:39 244784 ----a-w- C:\Program Files\gnie_s_dvd4-iml2iso.rar
2008-05-09 03:44:36 . 2008-05-09 03:44:32 10121656 ----a-w- C:\Program Files\Alcohol120_trial_1.9.7.6221.exe
2008-05-09 03:28:46 . 2008-05-09 03:28:45 1385051 ----a-w- C:\Program Files\cddvdgen.zip
2008-05-09 03:12:54 . 2008-05-09 03:12:54 899414 ----a-w- C:\Program Files\SetupDVDDecrypter_3.5.4.0.exe
2008-04-06 17:28:37 . 2008-04-06 17:28:37 569777 ----a-w- C:\Program Files\DVD43_4-2-0_Setup.exe
2008-01-05 18:20:19 . 2008-01-05 18:20:19 3381280 ----a-w- C:\Program Files\LimeWireWin.exe
2006-06-18 00:07:59 . 2006-06-18 00:07:59 1522527 ----a-w- C:\Program Files\dvdrip32572.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 22:05:20 143360]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 16:46:18 217544]
"Window Washer"="C:\Program Files\Webroot\Washer\wwDisp.exe" [2007-09-05 20:43:14 1261384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 09:40:34 86960]
"HostManager"="C:\Program Files\Common Files\AOL\1155679928\ee\AOLSoftware.exe" [2006-09-26 00:52:48 50736]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 07:41:10 49152]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 19:10:42 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 02:55:32 54832]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 19:40:44 155648]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2009-10-26 07:33:41 15872]
"AVG9_TRAY"="C:\PROGRA~1\AVG\AVG9\avgtray.exe" [2010-01-09 19:41:13 2033432]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 06:57:28 35760]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 20:57:56 948672]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2010-01-20 23:29:12 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-04 02:59:28 44544]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
NETGEAR WG311v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe [2006-1-26 1486848]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 14:13:36 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21:42 548352 ----a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-07 21:38:08 12464 ----a-w- C:\WINDOWS\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
NvQTwk [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
2006-10-23 12:50:37 71216 ----a-r- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
2002-01-03 03:06:28 4608 ------w- C:\WINDOWS\system32\carpserv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
2008-03-01 19:49:50 826880 ----a-w- C:\Program Files\dvd43\DVD43_Tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2001-08-18 22:00:00 44032 ----a-w- C:\WINDOWS\ime\imkr6_1\imekrmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-04 05:31:59 208952 ----a-w- C:\WINDOWS\ime\imjp8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2009-11-18 17:47:14 1243088 ----a-w- C:\Program Files\Spyware Doctor\pctsTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
2000-07-13 20:00:00 311350 ----a-w- C:\Program Files\Microsoft Works\wkssb.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2000-07-13 20:00:00 28739 ----a-w- C:\Program Files\Microsoft Works\WkDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Smapp]
2001-10-12 23:45:06 69632 ----a-w- C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
2000-07-13 20:00:00 24576 ----a-w- C:\Program Files\Microsoft Works\wkfud.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MCVSRte"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 AVGIDSErHrxpx;AVG9IDSErHr;C:\WINDOWS\system32\drivers\AVGIDSxx.sys [01/07/2010 4:36:12 PM 25608]
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\drivers\avgrkx86.sys [01/07/2010 4:36:11 PM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\drivers\avgldx86.sys [01/07/2010 4:36:09 PM 333192]
R1 AvgTdiX;AVG Network Redirector;C:\WINDOWS\system32\drivers\avgtdix.sys [01/07/2010 4:36:10 PM 360584]
R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\drivers\avgfwdx.sys [01/07/2010 4:34:35 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [01/07/2010 4:36:04 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [01/07/2010 4:36:04 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [01/07/2010 4:36:03 PM 25736]
S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\drivers\avgfwdx.sys [01/07/2010 4:34:35 PM 30104]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ylmolrez

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 18:24:06 451872 ----a-w- C:\Program Files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-01-29 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 21:21:26 . 2008-04-21 21:21:26]

2010-01-21 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 21:21:26 . 2008-04-21 21:21:26]

2004-03-28 C:\WINDOWS\Tasks\Registration reminder 1.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2006-04-09 04:54:16 . 2008-04-14 00:12:31]

2004-03-23 C:\WINDOWS\Tasks\Registration reminder 2.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2006-04-09 04:54:16 . 2008-04-14 00:12:31]

2004-04-08 C:\WINDOWS\Tasks\Registration reminder 3.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2006-04-09 04:54:16 . 2008-04-14 00:12:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mWindow Title =
uInternet Settings,ProxyServer = 168.94.74.68:8080
IE: &AOL Toolbar Search
DPF: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
DPF: {2C8EEB84-6D60-11D4-BD64-0050048A82BF} - hxxp://tech-c.mhi.aol.com/netagent/objects/custappx2.CAB
FF - ProfilePath - C:\Documents and Settings\Jonathan Murray\Application Data\Mozilla\Firefox\Profiles\2tis2day.default\
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: C:\Program Files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
You did not post a full ComboFix log. Please go to C:\combofix.txt and get a full log.

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
I renamed Combofix to blackpudding.bat and dragged CFScript into and it worked. It gave me a log but I didn't find it at C:/Combofix.txt I found it in the folder blackpudding. So what do u want me to try and do?

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
Go ahead and post that log. That should be fine. Smile...

descriptionComputer is freezing up and running slow - Page 2 EmptyRe: Computer is freezing up and running slow

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum