Baron2551
08-16-2009, 04:30 PM
Hello,
This pc is about 5 years old. It takes extremely long just to open up the browser. I have been reading threads on here and have logs for your viewing.
I ran the combo and malware. I have defragged in the last week. I ran Avast yesterday. I also ran Spyware x Terminator. I also ran CCleanup.
Please inform me on what needs to be corrected. I have noticed that when I went to MSCONFIG startup that there is a long list. Can MicroSoft Office be deleted from that so it doesn't run at startup? Plus, all the camera stuff.
Thanks!
ComboFix 09-08-10.06 - Owner 08/16/2009 13:50.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.247.100 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090815-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\Installer\115bc5.msi
c:\windows\Installer\128cb.msi
c:\windows\Installer\5d6ef895.msi
c:\windows\system32\iAlmcoin.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-07-16 to 2009-08-16 )))))))))))))))))))))))))))))))
.
2009-08-16 18:36 . 2009-08-16 18:36 -------- d-----w- c:\windows\LastGood
2009-08-13 05:03 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-30 20:09 . 2009-07-30 20:10 -------- d-----w- c:\windows\system32\NtmsData
2009-07-30 18:26 . 2009-07-30 18:26 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-07-30 18:25 . 2009-07-13 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-30 18:25 . 2009-07-30 18:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-30 18:25 . 2009-07-13 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-30 18:25 . 2009-07-30 18:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-23 00:51 . 2009-07-23 00:52 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Plaxo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-08-15 23:50 . 2006-07-07 00:09 -------- d-----w- c:\program files\Plaxo
2009-08-15 23:10 . 2003-08-23 14:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-05 09:01 . 2002-12-12 14:14 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-30 20:33 . 2003-08-23 14:12 28880 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-30 20:26 . 2003-08-23 14:23 28276 ----a-w- c:\windows\system32\drivers\MxlW2k.sys
2009-07-30 20:25 . 2005-12-21 02:46 -------- d-----w- c:\program files\QuickTime
2009-07-30 20:19 . 2003-08-29 03:19 -------- d-----w- c:\documents and settings\Owner\Application Data\interMute
2009-07-30 20:18 . 2003-08-24 03:34 -------- d-----w- c:\program files\BackWeb
2009-07-30 20:14 . 2007-01-03 22:38 -------- d-----w- c:\program files\Common Files\Nikon
2009-07-30 20:06 . 2005-05-06 00:35 -------- d-----w- c:\program files\Common Files\Caere
2009-07-17 19:01 . 2003-08-25 21:25 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2003-08-23 13:22 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 21:07 . 2009-07-08 21:07 -------- d-----w- c:\program files\Alwil Software
2009-07-08 20:44 . 2009-07-08 20:44 -------- d-----w- c:\program files\CCleaner
2009-07-08 20:40 . 2003-08-29 03:15 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-07 20:52 . 2004-07-27 01:50 -------- d-----w- c:\program files\SymNetDrv
2009-07-07 18:48 . 2009-07-07 18:48 -------- d-----w- c:\program files\AVG
2009-07-07 18:27 . 2003-08-29 03:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-29 16:12 . 2006-06-23 15:33 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2003-08-25 21:25 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2003-08-25 21:25 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2003-08-25 20:34 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2003-08-23 12:42 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2003-08-25 20:32 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2003-08-25 21:25 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2003-08-25 20:34 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2005-08-30 13:14 1291264 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"PlaxoUpdate"="c:\program files\Plaxo\3.22.0.7\PlaxoHelper_en.exe" [2009-07-10 378951]
"PlaxoSysTray"="c:\program files\Plaxo\3.22.0.7\PlaxoSysTray.exe" [2009-07-10 20480]
"NVIEW"="nview.dll" - c:\windows\system32\nview.dll [2003-05-03 835654]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"AutoTKit"="c:\hp\bin\AUTOTKIT.EXE" [2003-06-19 53248]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-03 4640768]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2003-02-25 53248]
"PPMemCheck"="c:\progra~1\STOMPS~1\SPYWAR~1\PPMemCheck.exe" [2004-04-02 148480]
"Spyware X-terminator Control Center"="c:\progra~1\STOMPS~1\SPYWAR~1\PPControl.exe" [2004-03-31 61440]
"CookiePatrol"="c:\progra~1\STOMPS~1\SPYWAR~1\CookiePatrol.exe" [2004-04-02 69632]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-02-05 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 36975]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-05-03 323584]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2004-07-19 263320]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"SRUUninstall"="c:\windows\System32\msiexec.exe" [2008-04-14 78848]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2002-6-20 24651]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 10:50 40960 ----a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R3 epstw2k;SCM Parallel Port SCSI Driver;c:\windows\system32\DRIVERS\epstw2k.sys [2001-08-17 114944]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\DRIVERS\scsiscan.sys [2008-04-13 11520]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswF sBlk.sys [2009-02-05 20560]
.
This pc is about 5 years old. It takes extremely long just to open up the browser. I have been reading threads on here and have logs for your viewing.
I ran the combo and malware. I have defragged in the last week. I ran Avast yesterday. I also ran Spyware x Terminator. I also ran CCleanup.
Please inform me on what needs to be corrected. I have noticed that when I went to MSCONFIG startup that there is a long list. Can MicroSoft Office be deleted from that so it doesn't run at startup? Plus, all the camera stuff.
Thanks!
ComboFix 09-08-10.06 - Owner 08/16/2009 13:50.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.247.100 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090815-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\Installer\115bc5.msi
c:\windows\Installer\128cb.msi
c:\windows\Installer\5d6ef895.msi
c:\windows\system32\iAlmcoin.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-07-16 to 2009-08-16 )))))))))))))))))))))))))))))))
.
2009-08-16 18:36 . 2009-08-16 18:36 -------- d-----w- c:\windows\LastGood
2009-08-13 05:03 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-30 20:09 . 2009-07-30 20:10 -------- d-----w- c:\windows\system32\NtmsData
2009-07-30 18:26 . 2009-07-30 18:26 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-07-30 18:25 . 2009-07-13 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-30 18:25 . 2009-07-30 18:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-30 18:25 . 2009-07-13 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-30 18:25 . 2009-07-30 18:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-23 00:51 . 2009-07-23 00:52 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Plaxo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-08-15 23:50 . 2006-07-07 00:09 -------- d-----w- c:\program files\Plaxo
2009-08-15 23:10 . 2003-08-23 14:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-05 09:01 . 2002-12-12 14:14 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-30 20:33 . 2003-08-23 14:12 28880 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-30 20:26 . 2003-08-23 14:23 28276 ----a-w- c:\windows\system32\drivers\MxlW2k.sys
2009-07-30 20:25 . 2005-12-21 02:46 -------- d-----w- c:\program files\QuickTime
2009-07-30 20:19 . 2003-08-29 03:19 -------- d-----w- c:\documents and settings\Owner\Application Data\interMute
2009-07-30 20:18 . 2003-08-24 03:34 -------- d-----w- c:\program files\BackWeb
2009-07-30 20:14 . 2007-01-03 22:38 -------- d-----w- c:\program files\Common Files\Nikon
2009-07-30 20:06 . 2005-05-06 00:35 -------- d-----w- c:\program files\Common Files\Caere
2009-07-17 19:01 . 2003-08-25 21:25 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2003-08-23 13:22 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 21:07 . 2009-07-08 21:07 -------- d-----w- c:\program files\Alwil Software
2009-07-08 20:44 . 2009-07-08 20:44 -------- d-----w- c:\program files\CCleaner
2009-07-08 20:40 . 2003-08-29 03:15 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-07 20:52 . 2004-07-27 01:50 -------- d-----w- c:\program files\SymNetDrv
2009-07-07 18:48 . 2009-07-07 18:48 -------- d-----w- c:\program files\AVG
2009-07-07 18:27 . 2003-08-29 03:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-29 16:12 . 2006-06-23 15:33 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2003-08-25 21:25 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-16 14:36 . 2003-08-25 21:25 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2003-08-25 20:34 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2003-08-23 12:42 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2003-08-25 20:32 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2003-08-25 21:25 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2003-08-25 20:34 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2005-08-30 13:14 1291264 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"PlaxoUpdate"="c:\program files\Plaxo\3.22.0.7\PlaxoHelper_en.exe" [2009-07-10 378951]
"PlaxoSysTray"="c:\program files\Plaxo\3.22.0.7\PlaxoSysTray.exe" [2009-07-10 20480]
"NVIEW"="nview.dll" - c:\windows\system32\nview.dll [2003-05-03 835654]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"AutoTKit"="c:\hp\bin\AUTOTKIT.EXE" [2003-06-19 53248]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-03 4640768]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2003-02-25 53248]
"PPMemCheck"="c:\progra~1\STOMPS~1\SPYWAR~1\PPMemCheck.exe" [2004-04-02 148480]
"Spyware X-terminator Control Center"="c:\progra~1\STOMPS~1\SPYWAR~1\PPControl.exe" [2004-03-31 61440]
"CookiePatrol"="c:\progra~1\STOMPS~1\SPYWAR~1\CookiePatrol.exe" [2004-04-02 69632]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-02-05 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 36975]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-05-03 323584]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2004-07-19 263320]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"SRUUninstall"="c:\windows\System32\msiexec.exe" [2008-04-14 78848]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
wkcalrem.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2002-6-20 24651]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 10:50 40960 ----a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R3 epstw2k;SCM Parallel Port SCSI Driver;c:\windows\system32\DRIVERS\epstw2k.sys [2001-08-17 114944]
R3 scsiscan;SCSI Scanner Driver;c:\windows\system32\DRIVERS\scsiscan.sys [2008-04-13 11520]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswF sBlk.sys [2009-02-05 20560]
.