View Single Post
Old 05-11-2007, 06:51 PM   #8 (permalink)
tetonbob
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,795
OS: 2000 Pro; XP Pro; XP Home


Re: An apple from the same tree

Hi John -

Kaspersky log says it took less than 4 hours,
Quote:
Duration of the scan process: 03:52:11
not sure why the difference in what it reports. Either seems like a long time for an 80GB drive.

What's F drive? Your USB drive?

There are some stray adware items left behind, but no serious risks that I can see, and nothing obvious to explain a slow system.

You may want to prevent AVG Anti-Spyware from running at Windows startup, and just call it into service when needed. This may help with system boot times. To do so, right click on the AVG A/S system tray icon, and uncheck Start with Windows. Also disable it's real time protection, as this will also use system resources, and will time out at the end of the trial period in 30 days. To do so:

Open AVG Anti-Spyware.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.

Hope that helps the boot time.

---------------------------------------------------------------------------------------------

Delete these:

C:\Deckard\System Scanner\backup
C:\Documents and Settings\Owner\My Documents\clipartfree.exe
C:\Documents and Settings\Owner\My Documents\wfallsawfree.exe
C:\WINDOWS\SYSTEM32\rk.exe


Delete contents of Norton Quarantine folder:

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine

---------------------------------------------------------------------------------------------

Next, let's use this tool as a diagnostic:
  1. Download combofix.exe to your desktop.
  2. Double click on combofix.exe & follow the prompts.
  3. When finished, it shall produce a log for you. Post that log in your next reply with a new HJT log
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline