We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide
Very Slow Email
Comments
-
You can stop now if you like
No ones forcing you to run anything...........:idea:0 -
only having a lafThe message you have entered is too short. Please lengthen your message to at least 10 characters.
Is the most annoying thing ever0 -
both scans? do you mean Cleaner and registryThe message you have entered is too short. Please lengthen your message to at least 10 characters.
Is the most annoying thing ever0 -
done the cobofix scan, do you need me to post the result?The message you have entered is too short. Please lengthen your message to at least 10 characters.
Is the most annoying thing ever0 -
Cleaner and registry ~ yeah
And please post the combofix log yes
:idea:0 -
ComboFix 09-02-26.02 - Ian 2009-02-27 19:59:24.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2037.1044 [GMT 0:00]
Running from: c:\users\Ian\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-01-27 to 2009-02-27 )))))))))))))))))))))))))))))))
.
2009-02-27 08:00 . 2009-02-27 08:00 <DIR> d
c:\users\All Users\SUPERAntiSpyware.com
2009-02-27 08:00 . 2009-02-27 08:00 <DIR> d
c:\programdata\SUPERAntiSpyware.com
2009-02-27 07:59 . 2009-02-27 07:59 <DIR> d
c:\users\Ian\AppData\Roaming\SUPERAntiSpyware.com
2009-02-27 07:59 . 2009-02-27 07:59 <DIR> d
c:\program files\SUPERAntiSpyware
2009-02-27 07:58 . 2009-02-27 07:58 <DIR> d
c:\program files\Common Files\Wise Installation Wizard
2009-02-26 20:02 . 2009-02-26 20:02 <DIR> d
c:\users\Ian\AppData\Roaming\GlarySoft
2009-02-26 19:48 . 2009-02-26 19:48 <DIR> d
c:\program files\Glary Utilities
2009-02-26 19:41 . 2009-02-26 19:41 <DIR> d
c:\program files\CCleaner
2009-02-26 16:57 . 2009-02-26 16:57 <DIR> d
c:\users\Ian\AppData\Roaming\Malwarebytes
2009-02-26 16:57 . 2009-02-26 16:57 <DIR> d
c:\users\All Users\Malwarebytes
2009-02-26 16:57 . 2009-02-26 16:57 <DIR> d
c:\programdata\Malwarebytes
2009-02-26 16:57 . 2009-02-26 16:57 <DIR> d
c:\program files\Malwarebytes' Anti-Malware
2009-02-26 16:57 . 2009-02-11 10:19 38,496 --a
c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-26 16:57 . 2009-02-11 10:19 15,504 --a
c:\windows\System32\drivers\mbam.sys
2009-02-26 09:03 . 2009-02-26 09:03 <DIR> d
c:\program files\Trend Micro
2009-02-21 08:56 . 2009-02-06 18:08 55,280 --a
c:\windows\System32\drivers\fssfltr.sys
2009-02-21 08:54 . 2009-02-21 08:54 <DIR> d
c:\program files\Microsoft SQL Server Compact Edition
2009-02-18 15:43 . 2009-02-23 21:48 <DIR> d
c:\users\All Users\Microsoft Help
2009-02-18 15:43 . 2009-02-23 21:48 <DIR> d
c:\programdata\Microsoft Help
2009-02-18 15:35 . 2009-02-18 16:02 <DIR> d
c:\users\Ian\AppData\Roaming\GetRightToGo
2009-02-18 15:20 . 2009-02-18 15:20 <DIR> d
c:\users\Ian\AppData\Roaming\ieSpell
2009-02-16 19:32 . 2009-02-16 19:32 <DIR> d
c:\users\All Users\WindowsSearch
2009-02-16 19:32 . 2009-02-16 19:32 <DIR> d
c:\programdata\WindowsSearch
2009-02-15 09:59 . 2008-12-05 04:32 428,544 --a
c:\windows\System32\EncDec.dll
2009-02-15 09:59 . 2008-12-05 04:32 293,376 --a
c:\windows\System32\psisdecd.dll
2009-02-15 09:59 . 2008-12-05 04:31 217,088 --a
c:\windows\System32\psisrndr.ax
2009-02-15 09:59 . 2008-12-05 04:31 177,664 --a
c:\windows\System32\mpg2splt.ax
2009-02-15 09:59 . 2008-12-05 04:31 80,896 --a
c:\windows\System32\MSNP.ax
2009-02-12 07:10 . 2009-01-15 03:36 1,383,424 --a
c:\windows\System32\mshtml.tlb
2009-02-12 07:10 . 2009-01-15 06:11 827,392 --a
c:\windows\System32\wininet.dll
2009-02-06 19:03 . 2009-02-06 19:03 307,576 --a
c:\windows\WLXPGSS.SCR
2009-02-06 18:52 . 2009-02-06 18:52 49,504 --a
c:\windows\System32\sirenacm.dll
2009-02-01 09:21 . 2009-02-26 07:55 <DIR> d
c:\users\IanKaty\Tracing
2009-02-01 09:15 . 2009-02-25 19:21 <DIR> d
c:\users\Ian\Tracing
2009-02-01 09:06 . 2006-11-29 13:06 3,426,072 --a
c:\windows\System32\d3dx9_32.dll
2009-02-01 09:03 . 2009-02-01 09:03 <DIR> d
c:\program files\Windows Live SkyDrive
2009-02-01 09:03 . 2009-02-01 09:08 <DIR> d
c:\program files\Microsoft
2009-02-01 08:47 . 2009-02-01 08:47 <DIR> d
c:\program files\Common Files\Windows Live
2009-01-30 13:19 . 2008-06-20 01:14 781,344 --a
c:\windows\System32\PresentationNative_v0300.dll
2009-01-30 13:19 . 2008-06-20 01:14 622,080 --a
c:\windows\System32\icardagt.exe
2009-01-30 13:19 . 2008-06-20 01:14 326,160 --a
c:\windows\System32\PresentationHost.exe
2009-01-30 13:19 . 2008-06-20 01:14 105,016 --a
c:\windows\System32\PresentationCFFRasterizerNative_v0300.dll
2009-01-30 13:19 . 2008-06-20 01:14 97,800 --a
c:\windows\System32\infocardapi.dll
2009-01-30 13:19 . 2008-06-20 01:14 43,544 --a
c:\windows\System32\PresentationHostProxy.dll
2009-01-30 13:19 . 2008-06-20 01:14 37,384 --a
c:\windows\System32\infocardcpl.cpl
2009-01-30 13:19 . 2008-06-20 01:14 11,264 --a
c:\windows\System32\icardres.dll
2009-01-30 13:10 . 2008-07-27 18:03 282,112 --a
c:\windows\System32\mscoree.dll
2009-01-30 13:10 . 2008-07-27 18:03 158,720 --a
c:\windows\System32\mscorier.dll
2009-01-30 13:10 . 2008-07-27 18:03 96,760 --a
c:\windows\System32\dfshim.dll
2009-01-30 13:10 . 2008-07-27 18:03 83,968 --a
c:\windows\System32\mscories.dll
2009-01-30 13:10 . 2008-07-27 18:03 41,984 --a
c:\windows\System32\netfxperf.dll
2009-01-27 21:30 . 2009-01-27 21:30 <DIR> d
c:\program files\Common Files\Adobe
2009-01-27 21:26 . 2009-01-27 21:26 <DIR> d
c:\program files\Common Files\Adobe AIR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 13:24
d
w c:\program files\Lx_cats
2009-02-26 09:01
d
w c:\users\Ian\AppData\Roaming\LimeWire
2009-02-26 07:18
d
w c:\program files\Microsoft Silverlight
2009-02-23 21:48
d
w c:\program files\Microsoft.NET
2009-02-21 08:56
d
w c:\program files\Windows Live
2009-02-13 07:57
d
w c:\program files\Windows Mail
2009-02-10 21:41
d
w c:\program files\ieSpell
2009-02-09 17:19
d
w c:\program files\Google
2009-01-30 17:42
d
w c:\program files\Microsoft SQL Server
2009-01-17 16:34 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2009-01-06 13:22
d
w c:\program files\Virtual Earth 3D
2009-01-06 13:12
d
w c:\program files\Microsoft Location Finder
2008-12-30 06:57 1,238 ----a-w c:\users\Ian\AppData\Roaming\wklnhst.dat
2008-12-24 07:43 410,984 ----a-w c:\windows\System32\deploytk.dll
2008-06-03 08:44 69,008 ----a-w c:\users\Ian\AppData\Roaming\GDIPFONTCACHEV1.DAT
2008-05-27 20:25 174 --sha-w c:\program files\desktop.ini
2008-05-12 15:11 0 ----a-w c:\users\iankaty\AppData\Roaming\wklnhst.dat
2008-04-09 07:05 76 --sh--r c:\windows\CT4CET.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-16 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-16 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-16 133656]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-24 136600]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
c:\users\IanKaty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Google.url [2009-02-22 217]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"!!5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Users^Ian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Google.url]
path=c:\users\Ian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google.url
backup=c:\windows\pss\Google.url.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\flockbox
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lphctuaj0e5fu
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a
2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DELL Webcam Manager]
2007-07-27 15:43 118784 c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
--a
2008-01-19 07:33 125952 c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_!!79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a
2008-02-28 16:07 1828136 c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdjamon]
--a
2007-03-06 02:40 20480 c:\program files\Lexmark 1400 Series\lxdjamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXDJCATS]
--a
2007-02-09 23:21 102400 c:\windows\System32\spool\drivers\w32x86\3\lxdjtime.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a
2009-02-06 18:51 3885408 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a
2008-02-18 15:29 2221352 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OEM02Mon.exe]
--a
2007-05-10 00:01 36864 c:\windows\OEM02Mon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a
2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a
2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a
2009-02-17 11:43 1830128 c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a
2008-11-27 20:44 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
--a
2008-09-26 13:50 206184 c:\program files\TomTom HOME 2\HOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"!!4D4000A2-1463-4129-AD7C-002D4649B91D}"= UDP:c:\program files\DNA\btdna.exe:DNA
"!!797B2607-3740-4635-9E5D-B5A6A416F6BE}"= TCP:c:\program files\DNA\btdna.exe:DNA
"!!13362407-1CAB-46CF-8131-E0F977D8CBD1}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{FAB6C4E7-4EE2-4B63-A74D-DF59236ABC05}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{DBD5EC8D-C269-41CD-9AD9-771860D6363C}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"!!192C5EA7-AE25-40D2-A780-413384AA72F7}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{E9558A26-8D07-4190-AE93-940B6338ED4B}"= UDP:c:\program files\Lexmark 1400 Series\App4R.exe:Lexmark Imaging Studio
"!!3700FD8D-9666-4578-B4C2-55275E1B94E7}"= TCP:c:\program files\Lexmark 1400 Series\App4R.exe:Lexmark Imaging Studio
"{D7C39BC4-44A0-467D-8492-039048C272CE}"= UDP:c:\windows\System32\lxdjcfg.exe:
"{A8BD8080-5006-4525-B8AC-4C01EB6E265D}"= TCP:c:\windows\System32\lxdjcfg.exe:
"!!8B16F2CC-B65B-4F76-AD9A-7ACED1135FB0}"= UDP:c:\windows\System32\lxdjcoms.exe:Lexmark Communications System
"{D15BA3BB-55FA-4520-A3BC-3D0D8475BDCA}"= TCP:c:\windows\System32\lxdjcoms.exe:Lexmark Communications System
"{A55241E4-93C1-4BF9-BE11-803CDED07342}"= UDP:c:\program files\Lexmark 1400 Series\lxdjamon.exe:Lexmark Device Monitor
"{AB947BA8-05D8-47F9-B35D-56BA7BF21716}"= TCP:c:\program files\Lexmark 1400 Series\lxdjamon.exe:Lexmark Device Monitor
"TCP Query User{06648985-3C8F-4212-9EBD-F8374CF2D4D1}c:\\users\\ian\\desktop\\documents\\limewire\\limewire.exe"= UDP:c:\users\ian\desktop\documents\limewire\limewire.exe:limewire.exe
"UDP Query User{922B16D5-A702-409D-986D-D9B923273E8C}c:\\users\\ian\\desktop\\documents\\limewire\\limewire.exe"= TCP:c:\users\ian\desktop\documents\limewire\limewire.exe:limewire.exe
"TCP Query User{2B7C84D1-6E7D-4092-9E25-87B2E5AF4FC0}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{105EE785-D4D3-48FE-9CE6-830190240756}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{F7B5B823-B981-4C85-9D73-393EF33ABFBE}c:\\users\\ian\\desktop\\documents\\limewire\\limewire.exe"= UDP:c:\users\ian\desktop\documents\limewire\limewire.exe:limewire.exe
"UDP Query User{15C9284F-29B7-4942-8995-34A57C969149}c:\\users\\ian\\desktop\\documents\\limewire\\limewire.exe"= TCP:c:\users\ian\desktop\documents\limewire\limewire.exe:limewire.exe
"!!50C69622-8A4B-4A7E-8241-9B9F79112A6E}"= UDP:c:\program files\Lexmark 1400 Series\Wireless\lxdjwpss.exe:
"!!52B7791F-0B42-4D1B-A887-EEC17FBEDE8F}"= TCP:c:\program files\Lexmark 1400 Series\Wireless\lxdjwpss.exe:
"TCP Query User{7479DBF8-5CD1-464E-BF4B-8CC6931C5C3A}c:\\program files\\nero\\nero8\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero8\nero home\nerohome.exe:Nero Home
"UDP Query User{2C9CB079-EA52-43E6-90E1-72AE63C4FB6B}c:\\program files\\nero\\nero8\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero8\nero home\nerohome.exe:Nero Home
"!!8253194E-1E73-4E6E-A257-D94CEFE21E4C}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdjpswx.exe:
"!!7EFE043F-0CB7-4FA7-8881-900C3510AB87}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdjpswx.exe:
"{B0513505-8497-4A68-B8E5-00571EA1CEDF}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.2
"!!70C73C6C-40B9-4E11-BC7D-FAEC2C53A0D5}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.2
"!!300300E0-1A6E-4770-890B-EA7A226483F9}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdjjswx.exe:
"!!5E437747-CB8C-4056-B370-BFC1C847ACCC}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdjjswx.exe:
"!!719505CF-9C0E-42A3-AA03-441635203DD0}"= UDP:990:LocalSubnet:LocalSubnet|IF=!!093BF425-B36D-48A1-8E88-8D85066D2FE2}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"!!57753921-5828-4280-A5C0-384F8DBC40B8}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdjpswx.exe:
"{CAFCEDAF-C741-42E9-8120-2B150DBDE5C2}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdjpswx.exe:
"!!70D0C099-3315-406D-941C-C5F6558336A2}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdjjswx.exe:
"!!0500A882-7D5D-44DF-AF65-1664E675A0DD}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdjjswx.exe:
"!!4915953E-C248-4415-A60B-A09C79584C9F}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"!!82ADA913-5898-466A-A959-46465A02AE2E}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdjtime.exe:
"!!91F7D7BC-0EEB-481E-9E6D-002F31E3A66D}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdjtime.exe:
"!!95EFF714-0765-4401-A07A-21395902F310}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxdjtime.exe:
"!!28DD7C5C-7078-4995-B10D-C78ABC822366}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxdjtime.exe:
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [2007-10-10 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [2008-04-08 7424]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [2009-02-21 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2009-02-27 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-12 17:10]
2009-02-27 c:\windows\Tasks\User_Feed_Synchronization-!!852ECD40-BA8F-435C-87B5-A9E53326306E}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 07:33]
2009-02-27 c:\windows\Tasks\User_Feed_Synchronization-{A13AFE64-1BC0-434A-BE16-FF6AF4B4C12A}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 07:33]
.
- - - - ORPHANS REMOVED - - - -
HKCU-RunOnce-Shockwave Updater - c:\windows\System32\Adobe\SHOCKW~1\SWHELP~2.EXE -Update -1103471 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET
MSConfigStartUp-lxdjmon - (no file)
.
Supplementary Scan
.
uStart Page = hxxp://www.google.co.uk/ig?hl=en&source=iglk
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - [URL]file://c:\program[/URL] files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - [URL]file://c:\program[/URL] files\ieSpell\wikipedia.HTM
LSP: c:\windows\system32\wpclsp.dll
DPF: !!05CDEE1D-D109-4992-B72B-6D4F5E2AB731} - hxxp://static.photobox.co.uk/sg/common/ImageUploader4.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-27 20:01:55
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
DLLs Loaded Under Running Processes
- - - - - - - > 'Explorer.exe'(1492)
c:\program files\Microsoft Office\Office10\msohev.dll
.
Completion time: 2009-02-27 20:04:09
ComboFix-quarantined-files.txt 2009-02-27 20:03:51
Pre-Run: 146,980,450,304 bytes free
Post-Run: 147,030,409,216 bytes free
238 --- E O F --- 2009-02-27 11:08:21The message you have entered is too short. Please lengthen your message to at least 10 characters.
Is the most annoying thing ever0 -
Well I dont claim to be an expert on these logs
But id say your good to go
Run Malwarebytes, SAS and your main AV alternating weekly though just to be safe:idea:0 -
ok mate cheers
which one shall i use instead of avgThe message you have entered is too short. Please lengthen your message to at least 10 characters.
Is the most annoying thing ever0 -
erm
What happened to avg?
It was on your first log but missing 'completely' off your last log!
if your sure its gone then use AVIRA ~
Download AVIRA ANTI VIRUS PERSONAL (Make sure you click 'DOWNLOAD LATEST VERSION')
http://www.filehippo.com/download_antivir/
:idea:0 -
I deleted it, everytime it was running the comp was way too slow and after all the programs you have gave me I dont think i'll need it????The message you have entered is too short. Please lengthen your message to at least 10 characters.
Is the most annoying thing ever0
This discussion has been closed.
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 354K Banking & Borrowing
- 254.3K Reduce Debt & Boost Income
- 455.3K Spending & Discounts
- 247.1K Work, Benefits & Business
- 603.7K Mortgages, Homes & Bills
- 178.3K Life & Family
- 261.2K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.7K Read-Only Boards