WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionComputer running very slowly. EmptyComputer running very slowly.

more_horiz
Not sure if its a virus or what exactly is going on. Started happening after I ran a scan. No viruses were found during the scan. Here's the hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:05:38 PM, on 6/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Kathy Snyder\Desktop\Computer maintenance\hijackgpthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - S-1-5-18 Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229550027109
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} (F-Secure Online Scanner 4.0 Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: Charter High-Speed Security Suite (BackWeb Plug-in - 3528733) - Unknown owner - C:\PROGRA~1\CHARTE~1\backweb\3528733\Program\SERVIC~1.EXE (file missing)
O23 - Service: FSBWSYS - Unknown owner - C:\Program Files\Charter High-Speed Security Suite\backweb\3528733\program\fsbwsys.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6987 bytes

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Malwarebytes' Anti-Malware 1.38
Database version: 2369
Windows 5.1.2600 Service Pack 3

7/3/2009 3:23:35 PM
mbam-log-2009-07-03 (15-23-35).txt

Scan type: Quick Scan
Objects scanned: 124626
Time elapsed: 8 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
c:\documents and settings\Kathy Snyder\Application Data\Microsoft\dtsc (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
c:\documents and settings\kathy snyder\application data\microsoft\dtsc\s (Trojan.Agent) -> Quarantined and deleted successfully.

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Hello.
I want to see an uninstall log.

  • Open HijackThis.
  • When Hijack This opens, click "Open the Misc Tools section"
  • Then select "Open Uninstall Manager"
  • Click on "Save List..." (generates uninstall_list.txt)
  • Click Save, copy and paste the results in your next post.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Computer running very slowly. DXwU4
Computer running very slowly. VvYDg

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Here's the list:

16 Big Fish Games
4 Elements
7-Zip 4.43 beta
964plc32
Ad-Aware
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.1.0
Adobe Shockwave Player
Alice Greenfingers 2
Amelies Cafe
AnswerWorks Runtime
AOLIcon
Apple Mobile Device Support
Apple Software Update
Asamis Sushi Shop
Audacity 1.2.4
Big Fish Games Client
Bilbo - The Four Corners of the World
BitLord 1.1
Canon Camera Support Core Library
Canon Camera Window DS for ZoomBrowser EX
Canon Camera Window DVC for ZoomBrowser EX
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX
Conexant D850 56K V.9x DFVc Modem
Corel Applications
Costume Chaos
Critical Update for Windows Media Player 11 (KB959772)
Delicious Emilys Tea Garden
Dell CinePlayer
Dell Driver Reset Tool
Dell Game Console
Dell Support 3.1
Diner Dash Seasonal Snack Pack
DivX Codec
Dr Lynch Grave Secrets
ELIcon
Elizabeth Find MD - Diagnosis Mystery
Elsas Adventure
Escape Rosecliff Island
Fab Fashion
Farm Frenzy Pizza Party
Farm Mania
Fashion Solitaire
Fishdom
Fix-it-up - Kates Adventure
Google Earth
Gourmania
Green Valley Fun on the Farm
Haunted Night Screensaver
HijackThis 2.0.2
Holiday Express
Holiday Greeting ’92
Holiday Greeting ’93
Holiday Greeting ’94
Holiday Greeting ’96
Holiday Greeting ’97
Holly 2 Magic Land
Home Sweet Home 2 Kitchens and Baths
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Ice Cream Craze - Tycoon Takeover
Intel(R) Extreme Graphics 2 Driver
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet for Wired Connections
iTunes
Java(TM) 6 Update 11
Java(TM) 6 Update 7
Little Shop Of Treasures
Magic Match 1.18
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works 7.0
Miriel The Magical Merchant
Mozilla Firefox (3.0.7)
MSN
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
Mystery P I The New York Fortune
Nanny Mania 2
NetWaiting
OpenOffice.org 3.0
Pahelika - Secret Legends
Pet Shop Hop
Picasa 2
QuickTime
RealPlayer
Roll
Roxio DLA
Roxio MyDVD LE
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Sandlot Games Client Services
Sea Journey
Secure Game Player
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Shop-n-Spree
Sonic Activation Module
Sonic Update Manager
SoulSeek Client 156c
Spybot - Search & Destroy
The Haunted Woods Wallpaper
The Scruffs
The Wizards Pen
Tibet Quest
TOTO Holiday Greeting 2003 Screen Saver
tropicalreef_3116236 Screen Saver
Unwell Mel
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VC 9.0 Runtime
VC 9.0 Runtime
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 0.9.8a
WebCyberCoach 3.2 Dell
Webshots Desktop
Windows Imaging Component
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR archiver
Wonderburg
Yahoo! Browser Services
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
Ye Olde Sandwich Shoppe
Zenerchi
Zenerchi (remove only)
ZoneAlarm
ZoneAlarm Spy Blocker Toolbar


Just yesterday, I had more problems and so today I ran Malwarebytes again. What's happening now is that something keeps trying to open internet explorer without my asking it to. It tries to access site 192.168.2.1, which is my router settings. In addition, my homepage for internet explorer was changed, but after running malwarebytes again (with more problems found, listed below...) NOW Internet Explorer can't access any pages at all, even when I type a website in. Mozilla Firefox is working ok. Here's the new listing from Malwarebytes that I ran today:

Malwarebytes' Anti-Malware 1.39
Database version: 2427
Windows 5.1.2600 Service Pack 3

7/14/2009 8:51:51 PM
mbam-log-2009-07-14 (20-51-51).txt

Scan type: Quick Scan
Objects scanned: 120071
Time elapsed: 10 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-zix (Trojan.Lop) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ROAD ITCH AMOK PING (Trojan.Lop) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\Local Page (Hijack.Search) -> Bad: (http://www2.iesearch.com/) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://www2.iesearch.com/) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\kathy snyder\local settings\temporary internet files\Content.IE5\CECG58PH\INScript[1].dll (Adware.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\kathy snyder\local settings\temporary internet files\Content.IE5\YPGUU1V8\MINIME[1].0XE (Trojan.Swizzor) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Long slow road itch\Way Amok.exe (Trojan.Lop) -> Delete on reboot.

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Hello.
Okay, this is getting somewhat confusing now, please don't run tools without Me or Origin asking you to.

Lets deal with some of the slowness and remove a few things.

I see that you are running BitLord.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.

If Limewire is not removed, then I won't help you.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    BitLord 1.1
    Java(TM) 6 Update 11
    Java(TM) 6 Update 7
    Shop-n-Spree
    ZoneAlarm
    ZoneAlarm Spy Blocker Toolbar

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 2 (Fix + Hosts)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Computer running very slowly. DXwU4
Computer running very slowly. VvYDg

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
OK. Three questions/issues before I go further.

1. You say you won't help me unless I remove Limewire, but I don't have Limewire on my computer. (At least as far as I'm aware.)

2. When I went to Control Panel, Add/Remove Programs and tried to remove ShopnSpree , it said "invalid uninstall control file". It's a game I've had on the computer for awhile. I moved it from the C drive to the D drive, so that's why I think I'm getting that message. Should I just delete the whole folder directly out of my programs on the D drive?

3. I am aware about the Bitlord possible problems, so when I download anything, I always run a virus scan on any file I download BEFORE I open it. However, if you do think its necessary to remove at this point, I will do so.

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Limewire was a typo, he meant bitlord 😉

Yes you can do that

We recommend that torrent programs are removed since that's primarily how malware enters your system.

Please run the LOP S&D tool.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
I ran it but am unable to post the full log. I keep being told it's too long. I'll try posting it in sections and see if that works???
--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.53GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A01
USER : Kathy Snyder ( Administrator )
BOOT : Normal boot
Antivirus : BitDefender Antivirus 12.0 (Not Activated)
Firewall : BitDefender Firewall 12.0 (Not Activated)
C:\ (Local Disk) - NTFS - Total:108 Go (Free:78 Go)
D:\ (Local Disk) - NTFS - Total:37 Go (Free:23 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( Sat 07/18/2009|19:25 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ FIX

Deleted! - C:\WINDOWS\Tasks\B089DDFF93FE5313.job
Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch\Way Amok.dat
Deleted! - C:\DOCUME~1\KATHYS~1\APPLIC~1\spamid~1\antecastbolt.exe
Deleted! - C:\DOCUME~1\KATHYS~1\APPLIC~1\spamid~1\love comp tool.exe
Deleted! - C:\DOCUME~1\KATHYS~1\APPLIC~1\spamid~1\uhzoaejb.exe
Deleted! - C:\DOCUME~1\KATHYS~1\LOCALS~1\Temp\WinZix.zip
Deleted! - C:\DOCUME~1\KATHYS~1\LOCALS~1\Temp\bis123.exe
Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Long slow road itch
Deleted! - C:\DOCUME~1\KATHYS~1\APPLIC~1\spamid~1
Deleted! - C:\Program Files\spamid~1
-
[ Hosts file ] .. Restored!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

Deleted! - C:\Program Files\Viewpoint
Deleted! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing folders in APPLIC~1

[02/04/2009|04:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Adobe
[07/16/2006|06:28] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Gtek
[08/10/2004|11:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[12/14/2006|07:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Macromedia
[02/04/2009|04:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[02/04/2009|04:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Mozilla
[07/16/2006|06:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sun
[07/16/2006|06:29] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Symantec

[03/04/2009|05:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {83C91755-2546-441D-AC40-9A6B4B860800}
[05/14/2008|10:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[02/19/2009|09:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AdventureChronicles1
[02/28/2009|05:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Alawar Stargaze
[08/31/2006|09:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL
[07/14/2007|01:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[12/14/2006|12:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[07/05/2009|09:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ashtons. Family Resort
[04/13/2008|10:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Awem
[02/28/2009|08:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Big Fish Games Vancouver
[02/04/2009|11:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BigFishGamesCache
[02/01/2009|08:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BitDefender
[02/21/2009|08:56] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ blg
[04/28/2008|07:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Christmasville
[03/01/2008|04:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ EA
[03/17/2009|09:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ eGames
[04/20/2008|01:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Escape From Paradise
[10/15/2008|09:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FarmFrenzy2
[02/05/2009|06:27] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FarmFrenzy-PizzaParty
[12/03/2008|07:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Flood Light Games
[02/15/2008|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FloodLightGames
[09/17/2008|08:39] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ FreshGames
[02/08/2009|07:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ F-Secure
[12/14/2006|11:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ F-Secure(2)
[02/02/2009|02:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ fssg
[03/17/2009|08:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Fugazo
[06/29/2008|10:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Gameeel
[02/04/2009|06:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GameHouse
[04/09/2009|10:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GameXzone
[02/28/2008|06:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Go Go Gourmet
[03/11/2009|07:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Gogii
[12/19/2008|11:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Gold Casual Games
[05/01/2008|11:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Grey Alien Games
[07/16/2006|06:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GTek
[02/11/2009|06:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HipSoft
[07/16/2006|06:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[07/11/2009|07:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intenium
[04/16/2008|07:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ IronCode
[10/01/2008|08:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ JollyBear
[03/04/2009|05:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[07/02/2008|07:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MailFrontier
[07/03/2009|03:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[06/22/2009|05:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Mean Hamster
[09/08/2007|09:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[05/25/2009|03:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MumboJumbo
[05/25/2009|03:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MysteryChronicles
[04/05/2009|04:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ MythPeople
[02/04/2009|06:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NeoEdge Networks
[03/27/2009|09:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NevoSoft Games
[07/12/2009|05:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PlayFirst
[04/01/2009|02:50] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PlayPond
[03/18/2009|07:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PoBros
[09/08/2006|06:40] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ PopCap
[08/31/2006|06:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[11/12/2008|09:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Redrum
[04/05/2008|11:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Reflexive
[02/05/2009|12:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sandlot Games
[08/10/2004|11:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[02/05/2007|06:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SkillJam
[07/16/2006|06:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[03/27/2009|09:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sortasoft
[07/09/2008|08:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SpinTop Games
[04/17/2009|12:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[02/09/2009|08:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SugarGames
[08/29/2006|06:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[07/18/2009|10:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[07/14/2008|07:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TERMINAL Studio
[09/08/2006|06:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Trymedia
[05/01/2009|03:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WildWestQuest2
[09/02/2006|06:32] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[03/23/2007|08:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ yahoo!
[09/30/2007|05:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion
[04/13/2008|10:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Zylom

[07/16/2006|06:28] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Gtek
[12/14/2006|11:38] C:\DOCUME~1\CHRIST~1\APPLIC~1\ ispnews
[12/08/2006|10:23] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Macromedia
[12/14/2006|12:17] C:\DOCUME~1\CHRIST~1\APPLIC~1\ Microsoft

[12/09/2006|09:32] C:\DOCUME~1\CHRIST~1.DGD\APPLIC~1\ F-Secure
[07/16/2006|06:28] C:\DOCUME~1\CHRIST~1.DGD\APPLIC~1\ Gtek
[12/14/2006|11:34] C:\DOCUME~1\CHRIST~1.DGD\APPLIC~1\ ispnews
[12/09/2006|09:49] C:\DOCUME~1\CHRIST~1.DGD\APPLIC~1\ Macromedia
[12/14/2006|11:34] C:\DOCUME~1\CHRIST~1.DGD\APPLIC~1\ Microsoft

[07/16/2006|06:28] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Gtek
[08/10/2004|11:08] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[07/16/2006|06:24] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[07/16/2006|06:20] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Sun
[07/16/2006|06:29] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Symantec

[09/14/2008|09:43] C:\DOCUME~1\Guest\APPLIC~1\ Adobe
[02/13/2008|09:34] C:\DOCUME~1\Guest\APPLIC~1\ Apple Computer
[05/30/2008|10:35] C:\DOCUME~1\Guest\APPLIC~1\ F-Secure
[07/16/2006|06:28] C:\DOCUME~1\Guest\APPLIC~1\ Gtek
[08/10/2004|11:08] C:\DOCUME~1\Guest\APPLIC~1\ Identities
[04/26/2007|07:47] C:\DOCUME~1\Guest\APPLIC~1\ ispnews
[05/26/2007|10:19] C:\DOCUME~1\Guest\APPLIC~1\ Macromedia
[10/28/2008|08:00] C:\DOCUME~1\Guest\APPLIC~1\ Microsoft
[03/22/2009|11:53] C:\DOCUME~1\Guest\APPLIC~1\ Mozilla
[12/01/2008|01:55] C:\DOCUME~1\Guest\APPLIC~1\ OpenOffice.org
[07/16/2006|06:20] C:\DOCUME~1\Guest\APPLIC~1\ Sun
[07/16/2006|06:29] C:\DOCUME~1\Guest\APPLIC~1\ Symantec
[06/27/2008|09:50] C:\DOCUME~1\Guest\APPLIC~1\ Template
[02/13/2008|09:34] C:\DOCUME~1\Guest\APPLIC~1\ yahoo!

[05/31/2009|07:41] C:\DOCUME~1\KATHYS~1\APPLIC~1\ .#
[11/27/2006|08:23] C:\DOCUME~1\KATHYS~1\APPLIC~1\ 7Wonders
[03/11/2009|09:06] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Adobe
[05/14/2008|10:07] C:\DOCUME~1\KATHYS~1\APPLIC~1\ AdobeUM
[04/16/2008|07:56] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Age of Japan II
[06/19/2009|06:34] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Alawar
[04/15/2008|05:31] C:\DOCUME~1\KATHYS~1\APPLIC~1\ AmuletAdventure
[03/25/2009|02:07] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Anabel
[11/09/2006|09:56] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Apple Computer
[07/05/2009|09:44] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Ashtons. Family Resort
[02/12/2009|09:09] C:\DOCUME~1\KATHYS~1\APPLIC~1\ BeachPartyCraze
[07/03/2009|06:41] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Big Fish
[02/16/2008|04:41] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Big Fish Games
[02/07/2008|01:23] C:\DOCUME~1\KATHYS~1\APPLIC~1\

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
BitZipper
[02/21/2009|08:56] C:\DOCUME~1\KATHYS~1\APPLIC~1\ blg
[07/21/2008|07:13] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Blippy Games
[03/20/2009|07:43] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Boolat Games
[06/19/2009|09:48] C:\DOCUME~1\KATHYS~1\APPLIC~1\ BrandX Games
[02/03/2009|11:03] C:\DOCUME~1\KATHYS~1\APPLIC~1\ CatmoonGames
[08/29/2006|07:21] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Corel
[02/15/2009|07:04] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Dress Up Rush
[02/19/2009|11:04] C:\DOCUME~1\KATHYS~1\APPLIC~1\ dvdcss
[03/01/2008|04:24] C:\DOCUME~1\KATHYS~1\APPLIC~1\ EA
[03/17/2009|09:03] C:\DOCUME~1\KATHYS~1\APPLIC~1\ eGames
[03/25/2009|04:41] C:\DOCUME~1\KATHYS~1\APPLIC~1\ EleFun Games
[02/28/2009|05:14] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Fabulous Finds
[01/17/2009|08:25] C:\DOCUME~1\KATHYS~1\APPLIC~1\ FirstColony
[12/03/2008|07:32] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Flood Light Games
[02/15/2008|10:19] C:\DOCUME~1\KATHYS~1\APPLIC~1\ FloodLightGames
[08/04/2008|06:34] C:\DOCUME~1\KATHYS~1\APPLIC~1\ ForgottenRiddles
[04/13/2009|07:48] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Friday's games
[08/29/2006|06:57] C:\DOCUME~1\KATHYS~1\APPLIC~1\ F-Secure
[04/07/2008|06:37] C:\DOCUME~1\KATHYS~1\APPLIC~1\ funkitron
[06/24/2009|09:18] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Fuzzy Games
[09/30/2008|08:19] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Gaijin Ent
[03/25/2009|02:15] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Gamelab
[05/11/2008|06:21] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Genimo
[12/19/2008|11:38] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Gold Casual Games
[12/30/2006|03:19] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Google
[07/16/2006|06:28] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Gtek
[09/04/2006|06:33] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Help
[07/02/2009|09:28] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Home Sweet Home 2
[06/19/2009|09:08] C:\DOCUME~1\KATHYS~1\APPLIC~1\ HuruBeachParty
[08/10/2004|11:08] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Identities
[05/31/2009|09:00] C:\DOCUME~1\KATHYS~1\APPLIC~1\ IronCode
[04/05/2009|04:40] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Island
[08/29/2006|06:34] C:\DOCUME~1\KATHYS~1\APPLIC~1\ ispnews
[05/31/2009|08:47] C:\DOCUME~1\KATHYS~1\APPLIC~1\ ITTNord
[06/04/2008|09:33] C:\DOCUME~1\KATHYS~1\APPLIC~1\ iWin
[02/06/2009|09:35] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Jetsetter
[09/15/2006|07:01] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Lavasoft
[08/29/2006|07:41] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Leadertech
[01/26/2008|05:02] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Macromedia
[10/07/2008|09:31] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Magic Academy
[09/08/2006|09:47] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Magic Match
[07/03/2009|03:06] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Malwarebytes
[06/22/2009|05:37] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Mean Hamster
[09/10/2008|07:19] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Microsoft
[02/04/2009|05:25] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Mind Control Software
[01/12/2009|10:07] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Move Networks
[01/07/2009|11:02] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Mozilla
[11/09/2008|07:22] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Mushroom Age
[04/07/2009|08:37] C:\DOCUME~1\KATHYS~1\APPLIC~1\ My Games
[08/17/2008|04:39] C:\DOCUME~1\KATHYS~1\APPLIC~1\ MysteryStudio
[11/29/2008|07:04] C:\DOCUME~1\KATHYS~1\APPLIC~1\ OpenOffice.org
[02/25/2009|05:39] C:\DOCUME~1\KATHYS~1\APPLIC~1\ panoramik
[03/31/2009|08:10] C:\DOCUME~1\KATHYS~1\APPLIC~1\ PetShowCraze
[08/29/2006|06:40] C:\DOCUME~1\KATHYS~1\APPLIC~1\ PEX
[06/22/2009|05:19] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Pi Eye Games
[07/12/2009|05:25] C:\DOCUME~1\KATHYS~1\APPLIC~1\ PlayFirst
[01/06/2009|08:46] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Playrix Entertainment
[03/18/2009|07:01] C:\DOCUME~1\KATHYS~1\APPLIC~1\ PoBros
[05/11/2008|06:26] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Pogo Games
[02/01/2009|10:47] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Real
[09/04/2006|06:59] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Registry Booster
[06/04/2009|07:59] C:\DOCUME~1\KATHYS~1\APPLIC~1\ RobinsonCrusoe
[05/25/2009|08:15] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Sarah's Emergency Hospital
[05/11/2007|03:31] C:\DOCUME~1\KATHYS~1\APPLIC~1\ SecondLife
[11/03/2008|09:02] C:\DOCUME~1\KATHYS~1\APPLIC~1\ SecretIslandEng
[06/29/2009|06:57] C:\DOCUME~1\KATHYS~1\APPLIC~1\ SerpentOfIsis
[05/25/2009|09:19] C:\DOCUME~1\KATHYS~1\APPLIC~1\ ShinyTales
[08/29/2006|07:41] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Sonic
[03/27/2009|09:25] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Sortasoft
[07/05/2009|03:29] C:\DOCUME~1\KATHYS~1\APPLIC~1\ SpinTop Games
[07/16/2006|06:20] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Sun
[07/02/2008|06:57] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Super-Cow
[07/16/2006|06:29] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Symantec
[09/01/2006|05:02] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Template
[02/04/2009|11:12] C:\DOCUME~1\KATHYS~1\APPLIC~1\ TheScruffs
[06/24/2009|04:41] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Twintale Entertainment
[11/01/2008|01:09] C:\DOCUME~1\KATHYS~1\APPLIC~1\ ValuSoft
[07/06/2008|08:04] C:\DOCUME~1\KATHYS~1\APPLIC~1\ VeniceMysteryData
[03/05/2009|02:09] C:\DOCUME~1\KATHYS~1\APPLIC~1\ V-Games
[02/18/2009|07:03] C:\DOCUME~1\KATHYS~1\APPLIC~1\ ViquaSoft
[02/01/2009|12:10] C:\DOCUME~1\KATHYS~1\APPLIC~1\ vlc
[09/29/2006|07:49] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Webshots
[07/02/2008|08:29] C:\DOCUME~1\KATHYS~1\APPLIC~1\

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Wildfire
[02/15/2008|10:15] C:\DOCUME~1\KATHYS~1\APPLIC~1\ WinRAR
[05/27/2009|07:17] C:\DOCUME~1\KATHYS~1\APPLIC~1\ World-LooM
[09/30/2007|05:36] C:\DOCUME~1\KATHYS~1\APPLIC~1\ yahoo!
[07/08/2007|08:15] C:\DOCUME~1\KATHYS~1\APPLIC~1\ Yahoo! Messenger
[09/08/2006|05:38] C:\DOCUME~1\KATHYS~1\APPLIC~1\ yoclient
[03/01/2009|07:48] C:\DOCUME~1\KATHYS~1\APPLIC~1\ YoudaGames

[08/10/2004|10:57] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[08/10/2004|10:57] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft


--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[07/03/2009 10:16 AM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[07/18/2009 06:30 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 03:00 AM][-r-h-c---] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[03/26/2009|06:40] C:\Program Files\ 4 Elements
[09/15/2006|07:27] C:\Program Files\ 7-Zip
[01/17/2008|04:35] C:\Program Files\ Adobe
[05/25/2009|10:58] C:\Program Files\ Alice Greenfingers 2
[03/02/2009|12:29] C:\Program Files\ Alice's Magical Mahjong
[07/16/2006|06:11] C:\Program Files\ Analog Devices
[05/28/2008|08:06] C:\Program Files\ Apple Software Update
[06/04/2009|07:23] C:\Program Files\ Asamis Sushi Shop
[03/26/2009|08:36] C:\Program Files\ AskBarDis
[12/14/2006|12:15] C:\Program Files\ Audacity
[07/16/2006|06:32] C:\Program Files\ BAE
[02/15/2008|10:16] C:\Program Files\ BFG
[02/04/2009|11:09] C:\Program Files\ bfgclient
[06/26/2009|08:37] C:\Program Files\ Bilbo - The Four Corners of the World
[07/18/2009|10:38] C:\Program Files\ BitLord
[02/07/2008|03:39] C:\Program Files\ BitZipper
[03/31/2007|02:19] C:\Program Files\ Canon
[02/08/2009|07:50] C:\Program Files\ Charter High-Speed Security Suite
[07/16/2009|10:22] C:\Program Files\ Common Files
[08/10/2004|11:02] C:\Program Files\ ComPlus Applications
[07/16/2006|06:10] C:\Program Files\ CONEXANT
[09/01/2006|04:45] C:\Program Files\ Corel
[02/07/2008|02:41] C:\Program Files\ DAEMON Tools
[02/01/2009|07:43] C:\Program Files\ Dell
[08/29/2006|04:37] C:\Program Files\ Dell Support
[07/12/2009|05:24] C:\Program Files\ Diner Dash Seasonal Snack Pack
[01/12/2007|05:33] C:\Program Files\ directx
[02/01/2009|07:41] C:\Program Files\ DivX
[06/29/2009|05:55] C:\Program Files\ Elizabeth Find MD - Diagnosis Mystery
[06/22/2009|07:32] C:\Program Files\ Elsas Adventure
[07/05/2009|03:28] C:\Program Files\ Escape Rosecliff Island
[06/22/2009|08:38] C:\Program Files\ Fab Fashion
[10/15/2006|01:52] C:\Program Files\ FileSubmit
[01/06/2009|08:42] C:\Program Files\ Fishdom
[05/27/2009|05:36] C:\Program Files\ Fix-it-up - Kates Adventure
[11/04/2007|01:57] C:\Program Files\ Google
[07/06/2009|08:17] C:\Program Files\ Green Valley Fun on the Farm
[10/22/2006|04:11] C:\Program Files\ Haunted Night Screensaver
[07/02/2009|09:27] C:\Program Files\ Home Sweet Home 2 Kitchens and Baths
[07/03/2009|06:32] C:\Program Files\ Ice Cream Craze - Tycoon Takeover
[12/14/2006|12:16] C:\Program Files\ ImaginEngine
[07/02/2008|07:13] C:\Program Files\ InstallShield Installation Information
[07/16/2006|06:22] C:\Program Files\ Intel
[07/16/2006|06:23] C:\Program Files\ InterActual
[07/03/2009|05:09] C:\Program Files\ Internet Explorer
[07/25/2008|05:21] C:\Program Files\ iPod
[07/25/2008|05:22] C:\Program Files\ iTunes
[11/29/2008|07:02] C:\Program Files\ JRE
[03/04/2009|05:26] C:\Program Files\ Lavasoft
[05/30/2009|03:21] C:\Program Files\ Leeloos Talent Agency
[03/11/2009|09:38] C:\Program Files\ Little Shop Of Treasures
[07/14/2009|08:16] C:\Program Files\ Malwarebytes' Anti-Malware
[10/27/2008|02:18] C:\Program Files\ Messenger
[08/10/2004|11:04] C:\Program Files\ microsoft frontpage
[12/19/2008|12:51] C:\Program Files\ Microsoft Games
[09/04/2006|08:42] C:\Program Files\ Microsoft Office
[07/16/2006|06:25] C:\Program Files\ Microsoft Plus! Digital Media Edition
[07/16/2006|06:25] C:\Program Files\ Microsoft Plus! Photo Story 2 LE
[09/01/2006|03:58] C:\Program Files\ Microsoft Works
[04/05/2009|04:39] C:\Program Files\ Miriel The Magical Merchant
[09/24/2008|06:03] C:\Program Files\ Movie Maker
[07/18/2009|07:17] C:\Program Files\ Mozilla Firefox
[06/14/2007|08:33] C:\Program Files\ MSBuild
[12/11/2007|09:13] C:\Program Files\ MSN
[08/10/2004|11:01] C:\Program Files\ MSN Gaming Zone
[03/04/2009|09:27] C:\Program Files\ MSXML 4.0
[08/15/2007|09:34] C:\Program Files\ MSXML 6.0
[02/05/2009|05:58] C:\Program Files\ Mystery P I The New York Fortune
[03/05/2009|02:08] C:\Program Files\ Mythic Mahjong
[07/06/2009|08:06] C:\Program Files\ Nanny Mania 2
[09/24/2008|06:00] C:\Program Files\ NetMeeting
[07/16/2006|06:23] C:\Program Files\ NetWaiting
[08/10/2004|11:01] C:\Program Files\ Online Services
[11/29/2008|07:02] C:\Program Files\ OpenOffice.org 3
[09/24/2008|06:00] C:\Program Files\ Outlook Express
[05/31/2009|09:00] C:\Program Files\ Pahelika - Secret

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Legends
[02/02/2009|05:55] C:\Program Files\ Panda Security
[09/06/2006|01:29] C:\Program Files\ PhotoDeluxe 2.0
[11/04/2007|01:57] C:\Program Files\ Picasa2
[06/24/2009|09:48] C:\Program Files\ Pocahontas - Princess of Powhatan
[07/25/2008|05:19] C:\Program Files\ QuickTime
[07/16/2006|06:26] C:\Program Files\ Real
[06/14/2007|08:30] C:\Program Files\ Reference Assemblies
[11/10/2008|10:02] C:\Program Files\ ReflexiveArcade
[02/07/2008|12:18] C:\Program Files\ RegistryFix
[09/15/2006|06:46] C:\Program Files\ RegVac Registry Cleaner
[07/16/2009|07:01] C:\Program Files\ Roxio
[07/03/2009|06:34] C:\Program Files\ Sea Journey
[07/16/2006|06:32] C:\Program Files\ SearchAssist
[07/18/2009|10:39] C:\Program Files\ Shop-n-Spree
[02/05/2007|06:43] C:\Program Files\ SkillJam Technologies
[07/06/2009|05:39] C:\Program Files\ Soulseek
[05/08/2009|12:15] C:\Program Files\ Spybot - Search & Destroy
[09/24/2008|09:51] C:\Program Files\ TeaTimer (Spybot - Search & Destroy)
[03/05/2009|02:30] C:\Program Files\ The Wizards Pen
[04/09/2009|10:29] C:\Program Files\ Tibet Quest
[12/14/2006|12:16] C:\Program Files\ TryMedia
[12/10/2006|09:37] C:\Program Files\ TryMedia(2)
[08/10/2004|11:08] C:\Program Files\ Uninstall Information
[02/01/2009|12:09] C:\Program Files\ VideoLAN
[07/16/2006|06:28] C:\Program Files\ WebCyberCoach
[05/04/2007|07:16] C:\Program Files\ Webshots
[12/14/2006|12:15] C:\Program Files\ WexTech
[07/16/2006|06:30] C:\Program Files\ WildTangent
[02/09/2007|09:40] C:\Program Files\ Windows Media Connect 2
[09/24/2008|06:00] C:\Program Files\ Windows Media Player
[09/24/2008|06:00] C:\Program Files\ Windows NT
[08/10/2004|11:02] C:\Program Files\ WindowsUpdate
[02/15/2008|10:14] C:\Program Files\ WinRAR
[05/25/2009|05:30] C:\Program Files\ Wonderburg
[08/10/2004|11:04] C:\Program Files\ xerox
[03/23/2007|08:39] C:\Program Files\ Yahoo!
[02/05/2009|12:04] C:\Program Files\ Yahoo! Games
[06/22/2009|08:27] C:\Program Files\ Ye Olde Sandwich Shoppe
[02/08/2009|07:46] C:\Program Files\ Zone Labs

--------------------\\ Listing Folders in C:\Program Files\Common Files

[05/14/2008|10:08] C:\Program Files\Common Files\ Adobe
[08/31/2006|09:50] C:\Program Files\Common Files\ AOL
[05/27/2008|07:26] C:\Program Files\Common Files\ Apple
[02/01/2009|09:20] C:\Program Files\Common Files\ BitDefender
[07/16/2006|06:27] C:\Program Files\Common Files\ Borland Shared
[12/30/2006|03:18] C:\Program Files\Common Files\ InstallShield
[07/16/2006|06:20] C:\Program Files\Common Files\ Java
[12/14/2006|12:15] C:\Program Files\Common Files\ LHSPF
[03/27/2007|06:34] C:\Program Files\Common Files\ Microsoft Shared
[08/10/2004|11:02] C:\Program Files\Common Files\ MSSoap
[07/16/2006|06:26] C:\Program Files\Common Files\ Nullsoft
[08/10/2004|10:57] C:\Program Files\Common Files\ ODBC
[02/01/2009|10:45] C:\Program Files\Common Files\ Real
[07/16/2006|06:23] C:\Program Files\Common Files\ Roxio Shared
[12/14/2006|12:16] C:\Program Files\Common Files\ Sandlot Shared
[08/10/2004|11:02] C:\Program Files\Common Files\ Services
[07/16/2009|10:24] C:\Program Files\Common Files\ Sonic Shared
[08/10/2004|10:57] C:\Program Files\Common Files\ SpeechEngines
[03/17/2009|09:03] C:\Program Files\Common Files\ SWF Studio
[02/03/2009|08:59] C:\Program Files\Common Files\ Symantec Shared
[09/24/2008|06:00] C:\Program Files\Common Files\ System
[12/14/2006|12:15] C:\Program Files\Common Files\ WexTech Shared
[02/01/2009|10:46] C:\Program Files\Common Files\ xing shared

--------------------\\ Process

( 25 Processes )

... OK !

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

No Lop folder found !

--------------------\\ Searching within the Registry

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-18 19:28:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections

C:\WINDOWS\Party Down
==> BAGLE <==

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\KATHYS~1\Application Data\yoclient\rsrc\bundles\tiles\outdoors\structures\bundle\jettyedge_crack.raw


[F:1781][D:27]-> C:\DOCUME~1\KATHYS~1\LOCALS~1\Temp
[F:324][D:0]-> C:\DOCUME~1\KATHYS~1\Cookies
[F:4581][D:11]-> C:\DOCUME~1\KATHYS~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Sat 07/18/2009|19:30 - Option : [2]

--------------------\\ Scan completed at 19:30:45

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:

Computer running very slowly. CF_download_FF

Computer running very slowly. CF_download_rename

3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See HERE for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
ComboFix 09-07-19.02 - Kathy Snyder 07/19/2009 16:01.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.725 [GMT -7:00]
Running from: c:\documents and settings\Kathy Snyder\Desktop\Comb-Fix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kathy Snyder\Application Data\.#
c:\recycler\S-1-5-21-2859597797-327823571-1850385436-1007
c:\recycler\S-1-5-21-2859597797-327823571-1850385436-1008
c:\windows\Installer\16481e.msi
c:\windows\Installer\192be6.msi
c:\windows\Installer\563e7.msi
c:\windows\Installer\57694.msi
c:\windows\Installer\b8329.msi
c:\windows\system32\dbfb.dll

.
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.

2009-07-19 02:25 . 2009-07-19 02:30 -------- dc----w- C:\Lop SD
2009-07-18 17:39 . 2009-07-18 17:39 -------- d-----w- c:\program files\Shop-n-Spree
2009-07-13 00:24 . 2009-07-13 00:24 -------- d-----w- c:\program files\Diner Dash Seasonal Snack Pack
2009-07-13 00:24 . 2009-07-13 00:24 -------- d-----w- c:\windows\Diner Dash Seasonal Snack Pack
2009-07-13 00:19 . 2009-07-13 00:19 -------- d-----w- c:\windows\John and Marys Memories
2009-07-07 03:17 . 2009-07-07 03:17 -------- d-----w- c:\program files\Green Valley Fun on the Farm
2009-07-07 03:17 . 2009-07-07 03:17 -------- d-----w- c:\windows\Green Valley Fun on the Farm
2009-07-06 04:45 . 2009-07-06 04:45 -------- d-----w- c:\windows\Diner Dash Flo Through Time
2009-07-06 04:23 . 2009-07-06 04:44 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Ashtons. Family Resort
2009-07-06 04:23 . 2009-07-06 04:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Ashtons. Family Resort
2009-07-06 04:22 . 2009-07-06 04:22 -------- d-----w- c:\windows\Ashtons Family Resort
2009-07-05 22:28 . 2009-07-05 22:28 -------- d-----w- c:\program files\Escape Rosecliff Island
2009-07-05 22:28 . 2009-07-05 22:28 -------- d-----w- c:\windows\Escape Rosecliff Island
2009-07-04 01:41 . 2009-07-04 01:41 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Big Fish
2009-07-04 01:34 . 2009-07-04 01:34 -------- d-----w- c:\windows\Sea Journey
2009-07-04 01:34 . 2009-07-04 01:34 -------- d-----w- c:\program files\Sea Journey
2009-07-03 22:06 . 2009-07-03 22:06 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Malwarebytes
2009-07-03 22:05 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-03 22:05 . 2009-07-14 15:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-03 22:05 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-03 22:05 . 2009-07-03 22:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-03 04:28 . 2009-07-03 04:28 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Home Sweet Home 2
2009-07-03 04:27 . 2009-07-03 04:27 -------- d-----w- c:\program files\Home Sweet Home 2 Kitchens and Baths
2009-07-03 04:27 . 2009-07-03 04:27 -------- d-----w- c:\windows\Home Sweet Home 2 Kitchens and Baths
2009-06-30 01:57 . 2009-06-30 01:57 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\SerpentOfIsis
2009-06-30 00:56 . 2009-06-30 00:56 -------- d-----w- c:\windows\The Serpent of Isis
2009-06-30 00:55 . 2009-06-30 00:55 -------- d-----w- c:\windows\Elizabeth Find MD - Diagnosis Mystery
2009-06-30 00:55 . 2009-06-30 00:55 -------- d-----w- c:\program files\Elizabeth Find MD - Diagnosis Mystery
2009-06-25 04:48 . 2009-06-27 03:37 -------- d-----w- c:\program files\Bilbo - The Four Corners of the World
2009-06-25 04:48 . 2009-06-25 04:48 -------- d-----w- c:\windows\Bilbo - The Four Corners of the World
2009-06-24 23:41 . 2009-06-24 23:41 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Twintale Entertainment
2009-06-24 16:18 . 2009-06-24 16:18 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Fuzzy Games
2009-06-24 04:27 . 2009-06-25 04:48 -------- d-----w- c:\program files\Pocahontas - Princess of Powhatan
2009-06-24 04:27 . 2009-06-24 04:27 -------- d-----w- c:\windows\Pocahontas - Princess of Powhatan
2009-06-23 03:38 . 2009-06-23 03:38 -------- d-----w- c:\program files\Fab Fashion
2009-06-23 03:38 . 2009-06-23 03:38 -------- d-----w- c:\windows\Fab Fashion
2009-06-23 00:37 . 2009-06-23 00:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Mean Hamster
2009-06-23 00:37 . 2009-06-23 00:37 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Mean Hamster
2009-06-22 15:26 . 2009-06-22 15:27 -------- d-----w- c:\program files\Ye Olde Sandwich Shoppe
2009-06-22 15:26 . 2009-06-22 15:26 -------- d-----w- c:\windows\Ye Olde Sandwich Shoppe
2009-06-22 14:32 . 2009-06-22 14:32 -------- d-----w- c:\program files\Elsas Adventure
2009-06-22 14:32 . 2009-06-22 14:32 -------- d-----w- c:\windows\Elsas Adventure
2009-06-20 22:18 . 2009-06-20 22:18 -------- d-----w- c:\windows\Kitten Sanctuary
2009-06-20 04:07 . 2009-06-20 04:08 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\HuruBeachParty
2009-06-20 02:42 . 2009-06-20 02:42 -------- d-----w- c:\windows\Huru Beach Party
2009-06-20 01:34 . 2009-06-20 01:34 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Alawar

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 02:23 . 2009-07-19 02:23 0 ----a-w- c:\windows\system32\REN5E.tmp
2009-07-19 02:23 . 2009-07-19 02:23 0 ----a-w- c:\windows\system32\REN5D.tmp
2009-07-19 02:23 . 2009-07-19 02:23 0 ----a-w- c:\windows\system32\REN5C.tmp
2009-07-18 17:38 . 2008-01-18 03:08 -------- d-----w- c:\program files\BitLord
2009-07-18 17:19 . 2008-02-09 03:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-17 05:24 . 2006-07-16 13:23 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-07-17 02:01 . 2006-07-16 13:30 -------- d-----w- c:\program files\Roxio
2009-07-16 23:20 . 2006-08-30 02:40 45424 -c--a-w- c:\documents and settings\Kathy Snyder\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-16 02:33 . 2009-07-03 22:57 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-07-16 02:33 . 2009-07-03 22:57 1630560 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-07-16 02:33 . 2009-07-03 22:57 2353480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-07-16 01:53 . 2009-04-21 01:27 5369531 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-07-13 00:25 . 2007-01-01 05:09 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\PlayFirst
2009-07-13 00:25 . 2007-01-01 05:09 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-07-12 02:28 . 2009-03-02 03:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Intenium
2009-07-07 03:06 . 2009-03-11 16:09 -------- d-----w- c:\program files\Nanny Mania 2
2009-07-07 00:39 . 2006-08-29 23:43 -------- d-----w- c:\program files\Soulseek
2009-07-05 22:29 . 2008-11-20 04:15 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\SpinTop Games
2009-07-04 01:32 . 2009-05-25 23:03 -------- d-----w- c:\program files\Ice Cream Craze - Tycoon Takeover
2009-06-27 23:41 . 2009-06-27 23:41 121976 ----a-w- c:\windows\Internet Logs\vsmon_2nd_2009_06_27_14_36_52_small.dmp.zip
2009-06-23 00:19 . 2008-04-17 03:00 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Pi Eye Games
2009-06-19 16:48 . 2009-06-19 16:48 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\BrandX Games
2009-06-14 20:14 . 2008-08-06 20:21 34 -c--a-w- c:\documents and settings\Kathy Snyder\jagex_runescape_preferences.dat
2009-06-05 02:59 . 2009-03-01 23:54 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\RobinsonCrusoe
2009-06-05 02:23 . 2009-06-05 02:22 -------- d-----w- c:\program files\Asamis Sushi Shop
2009-06-01 04:00 . 2009-06-01 02:59 -------- d-----w- c:\program files\Pahelika - Secret Legends
2009-06-01 04:00 . 2009-06-01 04:00 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\IronCode
2009-06-01 03:47 . 2009-06-01 03:47 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\ITTNord
2009-05-30 22:21 . 2009-04-07 03:31 -------- d-----w- c:\program files\Leeloos Talent Agency
2009-05-28 02:17 . 2009-05-28 02:17 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\World-LooM
2009-05-28 00:36 . 2009-05-28 00:35 -------- d-----w- c:\program files\Fix-it-up - Kates Adventure
2009-05-26 04:19 . 2009-05-26 04:19 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\ShinyTales
2009-05-26 00:30 . 2009-05-26 00:30 -------- d-----w- c:\program files\Wonderburg
2009-05-25 22:31 . 2009-05-25 22:31 -------- d-----w- c:\documents and settings\All Users\Application Data\MysteryChronicles
2009-05-25 22:25 . 2009-05-25 22:25 -------- d-----w- c:\documents and settings\All Users\Application 12 16:40

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Data\MumboJumbo
2009-05-25 19:04 . 2009-05-25 19:04 520192 ----a-w- c:\windows\system32\tropicalreef_3116236.scr
2009-05-25 17:58 . 2009-05-21 03:41 -------- d-----w- c:\program files\Alice Greenfingers 2
2009-05-25 15:15 . 2009-05-25 15:15 -------- d-----w- c:\documents and settings\Kathy Snyder\Application Data\Sarah's Emergency Hospital
2009-05-08 01:01 . 2009-05-08 01:01 64160 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-05-07 15:32 . 2004-08-10 17:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-10 17:51 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2009-06-08 03:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-03-19 19:10 . 2009-01-08 06:02 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2007-02-06 01:43 . 2007-02-06 01:43 23552 -c--a-w- c:\program files\mozilla firefox\plugins\DrvMgt.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-17 01:22 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-10-17 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar1.dll" [2008-10-17 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]

c:\documents and settings\Kathy Snyder\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2006-9-29 45056]

c:\documents and settings\Guest\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Charter High-Speed Security Suite.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Charter High-Speed Security Suite.lnk
backup=c:\windows\pss\Charter High-Speed Security Suite.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL 9.LNK]
backup=c:\windows\pss\CorelCENTRAL 9.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL Alarms.LNK]
backup=c:\windows\pss\CorelCENTRAL Alarms.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Application Director 9.LNK]
backup=c:\windows\pss\Desktop Application Director 9.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Kathy Snyder^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Kathy Snyder\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Kathy Snyder^Start Menu^Programs^Startup^Webshots.lnk]
path=c:\documents and settings\Kathy Snyder\Start Menu\Programs\Startup\Webshots.lnk
backup=c:\windows\pss\Webshots.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\Kathy Snyder\\Desktop\\Soulseek.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/4/2009 5:31 PM 64160]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2/8/2009 7:48 PM 464264]
S2 BackWeb Plug-in - 3528733;Charter High-Speed Security Suite;c:\progra~1\CHARTE~1\backweb\3528733\Program\SERVIC~1.EXE --> c:\progra~1\CHARTE~1\backweb\3528733\Program\SERVIC~1.EXE [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 2:34 PM 1029456]
.
Contents of the 'Scheduled Tasks' folder

2009-07-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 00:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
FF - ProfilePath - c:\documents and settings\Kathy Snyder\Application Data\Mozilla\Firefox\Profiles\jsb5v8rb.default\
FF - prefs.js: browser.search.selectedEngine - FireSearch
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\npskilljamloader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npssp32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-19 16:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-07-19 16:09
ComboFix-quarantined-files.txt 2009-07-19 23:08

Pre-Run: 84,777,615,360 bytes free
Post-Run: 85,480,185,856 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

217 --- E O F --- 2007-12-

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Now open a new notepad file.
Input this into the notepad file:

Folder::
c:\program files\Shop-n-Spree
c:\program files\BitLord

File::
c:\windows\system32\REN5E.tmp
c:\windows\system32\REN5D.tmp
c:\windows\system32\REN5C.tmp

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=-

Driver::
ASKService



Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:
Computer running very slowly. Sfxdaw

This will open combofix again, agree to it's terms and allow it to run.
It may want to reboot after it's done. (It will warn you if it wants to)
Post the resulting log back here.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
ComboFix 09-07-20.04 - Kathy Snyder 07/20/2009 21:14:24.4.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.653 [GMT -7:00]
Running from: C:\Documents and Settings\Kathy Snyder\Desktop\Comb-Fix.exe
Command switches used :: C:\Documents and Settings\Kathy Snyder\Desktop\CFScript.txt
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

FILE ::
"c:\windows\system32\REN5C.tmp"
"c:\windows\system32\REN5D.tmp"
"c:\windows\system32\REN5E.tmp"
.

((((((((((((((((((((((((( Files Created from 2009-06-21 to 2009-07-21 )))))))))))))))))))))))))))))))
.

2009-07-20 23:25:25 . 2009-07-21 00:41:11 0 d-----w- C:\Documents and Settings\Kathy Snyder\DoctorWeb
2009-07-19 02:25:08 . 2009-07-19 02:30:45 0 dc----w- C:\Lop SD
2009-07-13 00:24:52 . 2009-07-13 00:24:58 0 d-----w- C:\Program Files\Diner Dash Seasonal Snack Pack
2009-07-13 00:24:52 . 2009-07-13 00:24:52 0 d-----w- C:\WINDOWS\Diner Dash Seasonal Snack Pack
2009-07-13 00:19:10 . 2009-07-13 00:19:10 0 d-----w- C:\WINDOWS\John and Marys Memories
2009-07-07 03:17:44 . 2009-07-07 03:17:55 0 d-----w- C:\Program Files\Green Valley Fun on the Farm
2009-07-07 03:17:44 . 2009-07-07 03:17:44 0 d-----w- C:\WINDOWS\Green Valley Fun on the Farm
2009-07-06 04:45:14 . 2009-07-06 04:45:14 0 d-----w- C:\WINDOWS\Diner Dash Flo Through Time
2009-07-06 04:23:51 . 2009-07-06 04:44:09 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Ashtons. Family Resort
2009-07-06 04:23:51 . 2009-07-06 04:23:52 0 d-----w- C:\Documents and Settings\All Users\Application Data\Ashtons. Family Resort
2009-07-06 04:22:58 . 2009-07-06 04:22:58 0 d-----w- C:\WINDOWS\Ashtons Family Resort
2009-07-05 22:28:42 . 2009-07-05 22:28:53 0 d-----w- C:\Program Files\Escape Rosecliff Island
2009-07-05 22:28:42 . 2009-07-05 22:28:43 0 d-----w- C:\WINDOWS\Escape Rosecliff Island
2009-07-04 01:41:47 . 2009-07-04 01:41:47 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Big Fish
2009-07-04 01:34:29 . 2009-07-04 01:34:29 0 d-----w- C:\WINDOWS\Sea Journey
2009-07-04 01:34:28 . 2009-07-04 01:34:29 0 d-----w- C:\Program Files\Sea Journey
2009-07-03 22:06:00 . 2009-07-03 22:06:00 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Malwarebytes
2009-07-03 22:05:53 . 2009-07-13 20:36:34 38160 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-07-03 22:05:52 . 2009-07-14 15:16:47 0 d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2009-07-03 22:05:52 . 2009-07-13 20:36:12 19096 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2009-07-03 22:05:52 . 2009-07-03 22:05:52 0 d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-07-03 04:28:04 . 2009-07-03 04:28:04 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Home Sweet Home 2
2009-07-03 04:27:09 . 2009-07-03 04:27:19 0 d-----w- C:\Program Files\Home Sweet Home 2 Kitchens and Baths
2009-07-03 04:27:09 . 2009-07-03 04:27:10 0 d-----w- C:\WINDOWS\Home Sweet Home 2 Kitchens and Baths
2009-06-30 01:57:30 . 2009-06-30 01:57:30 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\SerpentOfIsis
2009-06-30 00:56:02 . 2009-06-30 00:56:02 0 d-----w- C:\WINDOWS\The Serpent of Isis
2009-06-30 00:55:08 . 2009-06-30 00:55:08 0 d-----w- C:\WINDOWS\Elizabeth Find MD - Diagnosis Mystery
2009-06-30 00:55:07 . 2009-06-30 00:55:28 0 d-----w- C:\Program Files\Elizabeth Find MD - Diagnosis Mystery
2009-06-25 04:48:37 . 2009-06-27 03:37:31 0 d-----w- C:\Program Files\Bilbo - The Four Corners of the World
2009-06-25 04:48:37 . 2009-06-25 04:48:37 0 d-----w- C:\WINDOWS\Bilbo - The Four Corners of the World
2009-06-24 23:41:34 . 2009-06-24 23:41:34 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Twintale Entertainment
2009-06-24 16:18:52 . 2009-06-24 16:18:52 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Fuzzy Games
2009-06-24 04:27:56 . 2009-06-25 04:48:01 0 d-----w- C:\Program Files\Pocahontas - Princess of Powhatan
2009-06-24 04:27:56 . 2009-06-24 04:27:56 0 d-----w- C:\WINDOWS\Pocahontas - Princess of Powhatan
2009-06-23 03:38:23 . 2009-06-23 03:38:34 0 d-----w- C:\Program Files\Fab Fashion
2009-06-23 03:38:23 . 2009-06-23 03:38:23 0 d-----w- C:\WINDOWS\Fab Fashion
2009-06-23 00:37:11 . 2009-06-23 00:37:12 0 d-----w- C:\Documents and Settings\All Users\Application Data\Mean Hamster
2009-06-23 00:37:11 . 2009-06-23 00:37:11 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Mean Hamster
2009-06-22 15:26:49 . 2009-06-22 15:27:02 0 d-----w- C:\Program Files\Ye Olde Sandwich Shoppe
2009-06-22 15:26:49 . 2009-06-22 15:26:49 0 d-----w- C:\WINDOWS\Ye Olde Sandwich Shoppe
2009-06-22 14:32:12 . 2009-06-22 14:32:13 0 d-----w- C:\Program Files\Elsas Adventure
2009-06-22 14:32:12 . 2009-06-22 14:32:12 0 d-----w- C:\WINDOWS\Elsas Adventure

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-21 03:52:28 . 2006-12-14 19:16:09 0 d-----w- C:\Program Files\Common Files\Sandlot Shared
2009-07-20 16:32:07 . 2006-08-30 02:40:45 45424 -c--a-w- C:\Documents and Settings\Kathy Snyder\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-18 17:19:28 . 2008-02-09 03:32:09 0 d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
2009-07-17 05:24:39 . 2006-07-16 13:23:01 0 d-----w- C:\Program Files\Common Files\Sonic Shared
2009-07-17 02:01:10 . 2006-07-16 13:30:58 0 d-----w- C:\Program Files\Roxio
2009-07-16 02:33:13 . 2009-07-03 22:57:20 25440 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-07-16 02:33:13 . 2009-07-03 22:57:12 1630560 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-07-16 02:33:11 . 2009-07-03 22:57:07 2353480 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-07-16 01:53:40 . 2009-04-21 01:27:31 5369531 ----a-w- C:\WINDOWS\Internet Logs\tvDebug.Zip
2009-07-13 00:25:13 . 2007-01-01 05:09:41 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\PlayFirst
2009-07-13 00:25:13 . 2007-01-01 05:09:41 0 d-----w- C:\Documents and Settings\All Users\Application Data\PlayFirst
2009-07-12 02:28:06 . 2009-03-02 03:49:25 0 d-----w- C:\Documents and Settings\All Users\Application Data\Intenium
2009-07-07 03:06:32 . 2009-03-11 16:09:26 0 d-----w- C:\Program Files\Nanny Mania 2
2009-07-07 00:39:58 . 2006-08-29 23:43:48 0 d-----w- C:\Program Files\Soulseek
2009-07-05 22:29:11 . 2008-11-20 04:15:23 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\SpinTop Games
2009-07-04 01:32:37 . 2009-05-25 23:03:38 0 d-----w- C:\Program Files\Ice Cream Craze - Tycoon Takeover
2009-06-27 23:41:44 . 2009-06-27 23:41:42 121976 ----a-w- C:\WINDOWS\Internet Logs\vsmon_2nd_2009_06_27_14_36_52_small.dmp.zip
2009-06-23 00:19:05 . 2008-04-17 03:00:47 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Pi Eye Games
2009-06-20 04:08:16 . 2009-06-20 04:07:20 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\HuruBeachParty
2009-06-20 01:34:46 . 2009-06-20 01:34:46 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Alawar
2009-06-19 16:48:52 . 2009-06-19 16:48:52 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\BrandX Games
2009-06-14 20:14:44 . 2008-08-06 20:21:46 34 -c--a-w- C:\Documents and Settings\Kathy Snyder\jagex_runescape_preferences.dat
2009-06-05 02:59:57 . 2009-03-01 23:54:05 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\RobinsonCrusoe

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
2009-06-05 02:23:07 . 2009-06-05 02:22:54 0 d-----w- C:\Program Files\Asamis Sushi Shop
2009-06-01 04:00:41 . 2009-06-01 02:59:43 0 d-----w- C:\Program Files\Pahelika - Secret Legends
2009-06-01 04:00:37 . 2009-06-01 04:00:37 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\IronCode
2009-06-01 03:47:25 . 2009-06-01 03:47:25 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\ITTNord
2009-05-30 22:21:45 . 2009-04-07 03:31:38 0 d-----w- C:\Program Files\Leeloos Talent Agency
2009-05-28 02:17:22 . 2009-05-28 02:17:22 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\World-LooM
2009-05-28 00:36:07 . 2009-05-28 00:35:53 0 d-----w- C:\Program Files\Fix-it-up - Kates Adventure
2009-05-26 04:19:35 . 2009-05-26 04:19:35 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\ShinyTales
2009-05-26 00:30:35 . 2009-05-26 00:30:19 0 d-----w- C:\Program Files\Wonderburg
2009-05-25 22:31:24 . 2009-05-25 22:31:24 0 d-----w- C:\Documents and Settings\All Users\Application Data\MysteryChronicles
2009-05-25 22:25:10 . 2009-05-25 22:25:10 0 d-----w- C:\Documents and Settings\All Users\Application Data\MumboJumbo
2009-05-25 19:04:50 . 2009-05-25 19:04:50 520192 ----a-w- C:\WINDOWS\system32\tropicalreef_3116236.scr
2009-05-25 17:58:57 . 2009-05-21 03:41:16 0 d-----w- C:\Program Files\Alice Greenfingers 2
2009-05-25 15:15:31 . 2009-05-25 15:15:31 0 d-----w- C:\Documents and Settings\Kathy Snyder\Application Data\Sarah's Emergency Hospital
2009-05-08 01:01:22 . 2009-05-08 01:01:22 64160 -c--a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-05-07 15:32:35 . 2004-08-10 17:51:11 345600 ----a-w- C:\WINDOWS\system32\localspl.dll
2009-04-29 04:56:02 . 2004-08-10 17:51:29 827392 ----a-w- C:\WINDOWS\system32\wininet.dll
2009-04-29 04:55:56 . 2009-06-08 03:18:58 78336 ----a-w- C:\WINDOWS\system32\ieencode.dll
2009-03-19 19:10:11 . 2009-01-08 06:02:03 134648 ----a-w- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
2007-02-06 01:43:30 . 2007-02-06 01:43:30 23552 -c--a-w- C:\Program Files\mozilla firefox\plugins\DrvMgt.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-17 01:22:18 333192 ----a-w- C:\Program Files\AskBarDis\bar\bin\askBar1.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "C:\Program Files\AskBarDis\bar\bin\askBar1.dll" [2008-10-17 01:22:18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 00:12:16 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 21:50:42 221184]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - C:\WINDOWS\system32\narrator.exe [2008-04-14 00:12:29 53760]

C:\Documents and Settings\Kathy Snyder\Start Menu\Programs\Startup\
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2006-9-29 45056]

C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Charter High-Speed Security Suite.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Charter High-Speed Security Suite.lnk
backup=C:\WINDOWS\pss\Charter High-Speed Security Suite.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL 9.LNK]
backup=C:\WINDOWS\pss\CorelCENTRAL 9.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL Alarms.LNK]
backup=C:\WINDOWS\pss\CorelCENTRAL Alarms.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Application Director 9.LNK]
backup=C:\WINDOWS\pss\Desktop Application Director 9.LNKCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Kathy Snyder^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=C:\Documents and Settings\Kathy Snyder\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 3.0.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Kathy Snyder^Start Menu^Programs^Startup^Webshots.lnk]
path=C:\Documents and Settings\Kathy Snyder\Start Menu\Programs\Startup\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Documents and Settings\\Kathy Snyder\\Desktop\\Soulseek.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [3/4/2009 5:31:02 PM 64160]
S2 BackWeb Plug-in - 3528733;Charter High-Speed Security Suite;C:\PROGRA~1\CHARTE~1\backweb\3528733\Program\SERVIC~1.EXE --> C:\PROGRA~1\CHARTE~1\backweb\3528733\Program\SERVIC~1.EXE [?]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 2:34:37 PM 1029456]
.
Contents of the 'Scheduled Tasks' folder

2009-07-03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 20:15:18 . 2008-04-12 00:57:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
FF - ProfilePath - C:\Documents and Settings\Kathy Snyder\Application Data\Mozilla\Firefox\Profiles\jsb5v8rb.default\
FF - prefs.js: browser.search.selectedEngine - FireSearch
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npskilljamloader.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npssp32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Malwarebytes' Anti-Malware 1.39
Database version: 2475
Windows 5.1.2600 Service Pack 3

7/21/2009 2:41:01 PM
mbam-log-2009-07-21 (14-41-01).txt

Scan type: Quick Scan
Objects scanned: 111207
Time elapsed: 7 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
As I go through this process, I was wondering if these viruses can also affect ipods, routers and the cd drive on my computer? (All of mine have basically gone bonkers in the past month.)

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
If you saved anything on the Ipod it could be infected by an Autorun file, your router and cd drive should be fine.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
OK. Is my computer now considered virus free? And how do I check my ipod for the autorun file you mentioned?

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
bump

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Hello.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    Ask Toolbar

Please plug in your iPod to the machine.

Please download USBNoRisk to your Desktop and run it by double clicking the program's icon.

  1. Wait a couple of seconds for initial scan to finish.
  2. Connect all of your USB storage devices to the PC, one at a time, and keep each one connected at least for 10 seconds.
  3. If there are more USB storage devices to scan, please take a note about the order in which these were connected.
  4. After all the devices are scanned, right click in the Monitor tab, and choose "Save log". That will open the log in Notepad. Please copy and paste the log into this thread.
Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC, e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras, memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Computer running very slowly. DXwU4
Computer running very slowly. VvYDg

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
This is the scan on my ipod.

USBNoRisk 2.5 (26 July 2009) by bobby

Started at 8/2/2009 11:03:35 AM

Searching for connected USB Mass storage...
----------------------------------------
E: {8d715028-7f7f-11de-adbe-00167678b5c0}
========================================

Searching for other storage...
----------------------------------------
C: {412b707d-7e83-11de-9cd3-806d6172696f}
========================================

Scanning removable storage...
----------------------------------------

No blocked files found on E:
No Autorun.inf files found on E:
No mountpoint found for 8d715028-7f7f-11de-adbe-00167678b5c0
No Desktop.ini files found on E:
No mimics found on drive E:
----------------------------------------


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 412b707d-7e83-11de-9cd3-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

========================================
Initial scan finished!
========================================

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Ipod looks fine 😉

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
This is my jump drive

USBNoRisk 2.5 (26 July 2009) by bobby

Started at 8/2/2009 11:00:59 AM

Searching for connected USB Mass storage...
----------------------------------------
E: {a8ff2cce-7ee9-11de-adae-e844a6c1c992}
========================================

Searching for other storage...
----------------------------------------
C: {412b707d-7e83-11de-9cd3-806d6172696f}
========================================

Scanning removable storage...
----------------------------------------

No blocked files found on E:
No Autorun.inf files found on E:
Sanitized mountpoint for a8ff2cce-7ee9-11de-adae-e844a6c1c992
No Desktop.ini files found on E:
No mimics found on drive E:
----------------------------------------


Scanning fixed storage...
----------------------------------------

No blocked files found on C:
No Autorun.inf files found on C:
No mountpoint found for C:
No mountpoint found for 412b707d-7e83-11de-9cd3-806d6172696f
No Desktop.ini files found on C:
----------------------------------------

========================================
Initial scan finished!
========================================
========================================
Removed E:
========================================


New device connected at 8/2/2009 11:03:16 AM

Scanning for connected USB mass storage...
----------------------------------------
E: {8d715028-7f7f-11de-adbe-00167678b5c0}
Added E:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on E:
----------------------------------------
No Autorun.inf files found on E:
No mountpoint found for 8d715028-7f7f-11de-adbe-00167678b5c0
----------------------------------------

No Desktop.ini files found on E:
----------------------------------------

No mimics found on drive E:
========================================

========================================
Removed E:
========================================


New device connected at 8/2/2009 11:03:20 AM

Scanning for connected USB mass storage...
----------------------------------------
E: {8d715028-7f7f-11de-adbe-00167678b5c0}
Added E:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on E:
----------------------------------------
No Autorun.inf files found on E:
No mountpoint found for 8d715028-7f7f-11de-adbe-00167678b5c0
----------------------------------------

No Desktop.ini files found on E:
----------------------------------------

No mimics found on drive E:
========================================

========================================
Removed E:
========================================


New device connected at 8/2/2009 11:03:23 AM

Scanning for connected USB mass storage...
----------------------------------------
E: {8d715028-7f7f-11de-adbe-00167678b5c0}
Added E:
========================================

Scanning USB mass storage for files...
----------------------------------------
No blocked files found on E:
----------------------------------------
No Autorun.inf files found on E:
Sanitized mountpoint for 8d715028-7f7f-11de-adbe-00167678b5c0
----------------------------------------

No Desktop.ini files found on E:
----------------------------------------

No mimics found on drive E:
========================================

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Looks fine as well.

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Ok. I guess that's it then and my computer is up and working well. Thanks for your help!

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Glad we could help 😉

Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

Ad-Aware SE
A tutorial on using Ad-Aware to remove spyware from your computer may be found here.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.org/products/firefox/
I also recommand the following add-ons for Firefox, they will help keep you safe from malicious scripts or activeX exploits.
https://addons.mozilla.org/en-US/firefox/addon/722
https://addons.mozilla.org/en-US/firefox/addon/1865
https://addons.mozilla.org/en-US/firefox/addon/433

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

To help you keep your software updated, please considering using this free software program that will check for program updates.
Update Checker

5) Finally, consider maintaining a firewall. Some good free firewalls are Kerio, or
Outpost
A tutorial on understanding and using firewalls may be found here.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

If you would take a moment to fill out our feedback form, we would appreciate it.
The link can be found here.

Hopefully this should take care of your problems! Good luck. Big Grin

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Alright, I have downloaded all the files, as instructed. I also went to "How I got infected..." which sent me to the Jason Levine's browser security site and in doing so, I followed the directions to increase all my security settings as instructed.

However, now I can't get Trend Micro online scan to work anymore. It just keeps saying Trend Micro Housecall is opening, but nothing happens. I don't know how to fix this. I am using Mozilla Firefox browser.

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Maybe something is blocking it, which security tool do you have present?

............................................................................................

While my help is always free, please consider donating to keep this site alive: Donate

Computer running very slowly. 2wg6fte

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Zone Alarm is all I use at the moment.

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
Uninstall zonealarm, we don't recommend it.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Computer running very slowly. DXwU4
Computer running very slowly. VvYDg

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
OK. I uninstalled Zone Alarm. Installed Outpost instead. No change, though. When I run TrendMicro on Firefox, I get to Step 1 "preparing to update required resources" and then nothing more happens. When trying on Internet Explorer I get the message "an error occurred while trying to transfer data from the Internet" and then it freezes up Internet Explorer. I have restarted my computer and retried both browsers with the same result.

descriptionComputer running very slowly. EmptyRe: Computer running very slowly.

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum