View Single Post
Old 11-12-2008, 10:49 PM   #1 (permalink)
seal123
Registered User
 
Join Date: Nov 2008
Posts: 29
OS: XP Pro SP2


Slow to respond to clicks, disconnects from dialup, lot of programs not responding

Hi Team
I know you are all extremely busy, so can I quickly say you guys and girls are so fantastic in the work and time you so generously give to help us poor saps who have not educated ourselves in the malware arena. Thank you so much.
My computer is very slow, not just on the net, but even responding to clicks to open programs or folders etc. I use a keyword search tool and other online tools and find I am constantly being disconnected on my dialup. A lot of programs I use end up not responding, and even use the task manager to shut them down takes forever. Recently when performing some normal tasks (can't remember exactly what) I got a message saying I had insufficient ram (I have one gig and wasnot using
any large programs at the time). Other computer users in the house said they have seen messages from AVG mentioning a Trojan and a Hack Tool. I hope this helps you help me.Thank you

Here is the DDS File

DDS (Version 1.0) - NTFSx86
Run by Deb at 15:15:26.07 on Thu 13/11/2008
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.667 [GMT 10:00]

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Deb\Desktop\Malware detection\dds.scr
C:\DOCUME~1\Deb\LOCALS~1\Temp\RarSFX1\CHIDE.exe

============== Psuedo HJT Report ===============

uStart Page = about:blank
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg8\avgssie.dll
BHO: {4A368E80-174F-4872-96B5-0B27DDD11DB2} - c:\program files\spywareguard\dlprotect.dll
BHO: {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - c:\program files\free download manager\iefdm2.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [MAAgent] c:\program files\markany\contentsafer\MAAgent.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [COMODO Internet Security] "c:\program files\comodo\firewall\cfp.exe" -h
dRunServices: [ssymsne] valuex.exe
StartupFolder: c:\docume~1\deb\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\deb\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
TrustedZone: www.linkshare.com
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office11\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent -Ati2evxx.dll
AppInit_DLLs: c:\windows\system32\guard32.dll,avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {81559C35-8464-49F7-BB0E-07A383BEF910} - c:\program files\spywareguard\spywareguard.dll
SEH: {88485281-8b4b-4f8d-9ede-82e29a064277} - c:\progra~1\markany\conten~1\MACSMA~1.DLL
LSA: Notification Packages = scecli scecli

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys
R2 ScFBPNT;CanoScan FBP Port Driver;\??\c:\windows\system32\drivers\ScFBPNT.SYS
S3 firewall;firewall;\??\c:\program files\foxie suite\firewall.sys
S3 JL2005;JL2005A Toy Camera;c:\windows\system32\drivers\toywdm.sys
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys
S4 mswmf32;mswmf32;

=============== Created Last 30 ================

2008-11-09 13:11 <DIR> --d----- c:\docume~1\deb\applic~1\Free Download Manager
2008-11-09 13:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\FreeDownloadManager.ORG
2008-11-09 13:10 <DIR> --d----- c:\program files\Free Download Manager
2008-11-07 11:50 54,156 a---h--- c:\windows\QTFont.qfn
2008-11-07 11:50 1,409 a------- c:\windows\QTFont.for
2008-10-29 11:24 <DIR> --d----- c:\program files\SEO Elite 4

==================== Find3M ====================

2008-11-13 13:22 <DIR> --d----- c:\program files\PopCap Games
2008-11-13 13:22 <DIR> --d----- c:\program files\Reply Email Automator Setup
2008-11-13 13:22 <DIR> --d----- c:\program files\Real Link Finder
2008-11-13 13:00 <DIR> --d----- c:\program files\LimeWire
2008-11-12 18:56 <DIR> --d----- c:\program files\Keyword Elite
2008-11-12 10:55 143,096 a------- c:\windows\system32\guard32.dll
2008-11-05 10:20 <DIR> --d----- c:\program files\SpywareGuard
2008-10-11 09:06 <DIR> --d----- c:\program files\FreeRIP3
2008-10-11 09:05 <DIR> --d----- c:\docume~1\alluse~1\applic~1\FreeRIP
2008-10-06 08:02 <DIR> --d----- c:\program files\Windows Media Connect 2
2008-10-05 21:22 <DIR> --d----- c:\docume~1\deb\applic~1\DataCast
2008-10-05 15:14 <DIR> --d----- c:\program files\Lame MP3 Codec
2008-10-05 15:14 65,024 a------- c:\windows\IFinst26.exe
2008-10-05 15:13 <DIR> --d----- c:\program files\XviD
2008-10-05 15:12 <DIR> --d----- c:\program files\MarkAny
2008-10-05 15:12 <DIR> --d----- c:\program files\Samsung
2008-10-02 21:35 <DIR> --d----- c:\program files\Windows NT
2008-10-02 21:34 <DIR> --d----- c:\program files\Messenger
2008-09-15 21:57 1,846,016 -------- c:\windows\system32\win32k.sys
2008-08-26 17:24 826,368 a------- c:\windows\system32\wininet.dll
2008-08-14 10:05 <DIR> --d----- c:\docume~1\deb\applic~1\eBookPro6
2008-07-11 15:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2008-07-10 14:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\comodo
2008-07-10 13:15 <DIR> --d----- c:\docume~1\deb\applic~1\Comodo
2008-06-18 12:00 <DIR> --d----- c:\docume~1\deb\applic~1\iolo
2008-06-18 12:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\iolo
2008-05-21 11:42 <DIR> --d----- c:\docume~1\deb\applic~1\Sony
2008-05-18 18:43 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Sony
2008-05-16 16:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2008-03-30 07:25 <DIR> --d----- c:\docume~1\deb\applic~1\rsvme
2008-01-08 18:32 <DIR> --d----- c:\docume~1\deb\applic~1\Bytescout SWF To Video Scout
2007-12-29 07:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Hagel Technologies
2007-12-24 06:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\MSScanAppDataDir
2007-12-17 17:43 <DIR> --d----- c:\docume~1\deb\applic~1\Good Keywords v2
2007-11-23 10:28 <DIR> --d----- c:\docume~1\deb\applic~1\Dcads Advanced Toolbar
2007-04-21 06:53 <DIR> --d----- c:\docume~1\deb\applic~1\SPAMfighter
2007-02-14 15:19 <DIR> --d--r-- c:\docume~1\deb\applic~1\Brother
2007-02-10 22:20 <DIR> --d----- c:\docume~1\deb\applic~1\SWEC_-_Stock_Wrap_Express
2006-11-18 07:49 <DIR> --d----- c:\docume~1\deb\applic~1\Secretmaker
2006-04-06 18:57 <DIR> --d----- c:\docume~1\deb\applic~1\funkitron
2006-02-25 18:23 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Ahead
2006-02-17 08:45 <DIR> --d----- c:\docume~1\deb\applic~1\Publish Providers
2006-02-17 08:45 <DIR> --d----- c:\docume~1\deb\applic~1\NetMedia Providers
2006-02-16 16:01 <DIR> --d----- c:\docume~1\deb\applic~1\MSN6
2006-02-16 15:30 <DIR> --d----- c:\docume~1\alluse~1\applic~1\MSN6

============= FINISH: 15:16:18.50 ===============
Attached Files
File Type: txt Gmer.txt (63.6 KB, 3 views)
File Type: txt Attach.txt (14.0 KB, 3 views)
seal123 is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here