View Single Post
  #5 (permalink)  
Old 11-02-2006, 08:33 PM
shorty1_wt shorty1_wt is offline
Newbie
D-A-L Newbie
 
Join Date: Feb 2006
Posts: 9
shorty1_wt Is a beginner here at D-A-L
Re: computer lagging badly

here's the log files you requested
thanks again for all your help.
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 1:17:22 PM, 2/11/2006
+ Report-Checksum: BC9F3915

+ Scan result:

:mozilla.26:C:\Documents and Settings\Janice\Application Data\Mozilla\Firefox\Profiles\835r8pn9.default\coo kies.txt -> TrackingCookie.Atdmt : Ignored
:mozilla.64:C:\Documents and Settings\Janice\Application Data\Mozilla\Firefox\Profiles\835r8pn9.default\coo kies.txt -> TrackingCookie.Overture : Ignored
:mozilla.65:C:\Documents and Settings\Janice\Application Data\Mozilla\Firefox\Profiles\835r8pn9.default\coo kies.txt -> TrackingCookie.Overture : Ignored
:mozilla.74:C:\Documents and Settings\Janice\Application Data\Mozilla\Firefox\Profiles\835r8pn9.default\coo kies.txt -> TrackingCookie.Questionmarket : Ignored
:mozilla.83:C:\Documents and Settings\Janice\Application Data\Mozilla\Firefox\Profiles\835r8pn9.default\coo kies.txt -> TrackingCookie.2o7 : Ignored
:mozilla.80:C:\Documents and Settings\Janice\Application Data\Mozilla\Firefox\Profiles\835r8pn9.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\System Volume Information\_restore{8A67BDEA-BD1B-49A3-921E-2B8A035D62F0}\RP295\A0029827.scr -> Downloader.Agent.a : Cleaned with backup
C:\System Volume Information\_restore{8A67BDEA-BD1B-49A3-921E-2B8A035D62F0}\RP295\A0029828.dll -> Downloader.Lemmy.q : Cleaned with backup
C:\System Volume Information\_restore{8A67BDEA-BD1B-49A3-921E-2B8A035D62F0}\RP295\A0029829.exe -> Downloader.IstBar.cl : Cleaned with backup
C:\System Volume Information\_restore{8A67BDEA-BD1B-49A3-921E-2B8A035D62F0}\RP295\A0029830.dll -> Downloader.Lemmy.q : Cleaned with backup
C:\System Volume Information\_restore{8A67BDEA-BD1B-49A3-921E-2B8A035D62F0}\RP295\A0029831.exe -> Downloader.IstBar.cl : Cleaned with backup
C:\System Volume Information\_restore{8A67BDEA-BD1B-49A3-921E-2B8A035D62F0}\RP295\A0029832.exe -> Hijacker.VB.bt : Cleaned with backup
C:\System Volume Information\_restore{8A67BDEA-BD1B-49A3-921E-2B8A035D62F0}\RP295\A0029833.dll -> Adware.Webdir : Cleaned with backup
C:\William's Stuff\WILLIAMDISK (E)\zip and install\miclockers.zip/yaheek.dll -> Not-A-Virus.Monitor.Win32.Dafunk : Cleaned with backup


::Report End

Logfile of HijackThis v1.99.1
Scan saved at 1:26:59 PM, on 2/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: RefresherBand Class - {B24BA06E-FB7B-4757-95C2-DC01125F750E} - C:\PROGRA~1\YREFRE~1\YREFRE~1.DLL
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 9.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - Startup: MyWebSearch Email Plugin.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://jcs.chat.dcn.yahoo.com/v45/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
Reply With Quote