We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

HiJack this log

13

Comments

  • tranmererovers
    tranmererovers Posts: 2,313 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Have just updated avira and ran another full scan, with the following result...



    Avira AntiVir Personal
    Report file date: 03 May 2010 18:21

    Scanning for 2065862 virus strains and unwanted programs.

    The program is running as an unrestricted full version.
    Online services are available:

    Licensee : Avira AntiVir Personal - FREE Antivirus
    Serial number : 0000149996-ADJIE-0000001
    Platform : Windows XP
    Windows version : (Service Pack 3) [5.1.2600]
    Boot mode : Normally booted
    Username : SYSTEM
    Computer name : FSC391216061805

    Version information:
    BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00
    AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 12:37:38
    AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 12:57:04
    LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 18:33:04
    LUKERES.DLL : 10.0.0.1 12648 Bytes 2/10/2010 23:40:49
    VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 09:05:36
    VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 19:27:49
    VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 17:37:42
    VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 16:37:42
    VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 11:29:03
    VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 16:35:47
    VBASE006.VDF : 7.10.6.83 2048 Bytes 4/15/2010 16:35:47
    VBASE007.VDF : 7.10.6.84 2048 Bytes 4/15/2010 16:35:47
    VBASE008.VDF : 7.10.6.85 2048 Bytes 4/15/2010 16:35:47
    VBASE009.VDF : 7.10.6.86 2048 Bytes 4/15/2010 16:35:47
    VBASE010.VDF : 7.10.6.87 2048 Bytes 4/15/2010 16:35:48
    VBASE011.VDF : 7.10.6.88 2048 Bytes 4/15/2010 16:35:48
    VBASE012.VDF : 7.10.6.89 2048 Bytes 4/15/2010 16:35:48
    VBASE013.VDF : 7.10.6.90 2048 Bytes 4/15/2010 16:35:48
    VBASE014.VDF : 7.10.6.123 126464 Bytes 4/19/2010 16:35:49
    VBASE015.VDF : 7.10.6.152 123392 Bytes 4/21/2010 16:35:50
    VBASE016.VDF : 7.10.6.178 122880 Bytes 4/22/2010 16:35:50
    VBASE017.VDF : 7.10.6.206 120320 Bytes 4/26/2010 16:35:51
    VBASE018.VDF : 7.10.6.232 99328 Bytes 4/28/2010 16:35:51
    VBASE019.VDF : 7.10.7.2 155648 Bytes 4/30/2010 16:35:52
    VBASE020.VDF : 7.10.7.3 2048 Bytes 4/30/2010 16:35:52
    VBASE021.VDF : 7.10.7.4 2048 Bytes 4/30/2010 16:35:52
    VBASE022.VDF : 7.10.7.5 2048 Bytes 4/30/2010 16:35:53
    VBASE023.VDF : 7.10.7.6 2048 Bytes 4/30/2010 16:35:53
    VBASE024.VDF : 7.10.7.7 2048 Bytes 4/30/2010 16:35:53
    VBASE025.VDF : 7.10.7.8 2048 Bytes 4/30/2010 16:35:53
    VBASE026.VDF : 7.10.7.9 2048 Bytes 4/30/2010 16:35:53
    VBASE027.VDF : 7.10.7.10 2048 Bytes 4/30/2010 16:35:53
    VBASE028.VDF : 7.10.7.11 2048 Bytes 4/30/2010 16:35:53
    VBASE029.VDF : 7.10.7.12 2048 Bytes 4/30/2010 16:35:53
    VBASE030.VDF : 7.10.7.13 2048 Bytes 4/30/2010 16:35:54
    VBASE031.VDF : 7.10.7.21 87552 Bytes 5/3/2010 17:11:35
    Engineversion : 8.2.1.224
    AEVDF.DLL : 8.1.2.0 106868 Bytes 4/30/2010 16:36:07
    AESCRIPT.DLL : 8.1.3.27 1294714 Bytes 4/30/2010 16:36:07
    AESCN.DLL : 8.1.5.0 127347 Bytes 2/25/2010 18:38:41
    AESBX.DLL : 8.1.3.1 254324 Bytes 4/30/2010 16:36:07
    AERDL.DLL : 8.1.4.6 541043 Bytes 4/30/2010 16:36:05
    AEPACK.DLL : 8.2.1.1 426358 Bytes 3/19/2010 12:34:51
    AEOFFICE.DLL : 8.1.0.41 201083 Bytes 3/17/2010 11:09:46
    AEHEUR.DLL : 8.1.1.24 2613623 Bytes 4/30/2010 16:36:03
    AEHELP.DLL : 8.1.11.3 242039 Bytes 4/1/2010 16:05:25
    AEGEN.DLL : 8.1.3.7 373106 Bytes 4/30/2010 16:35:57
    AEEMU.DLL : 8.1.2.0 393588 Bytes 4/30/2010 16:35:56
    AECORE.DLL : 8.1.13.1 188790 Bytes 4/1/2010 16:05:25
    AEBB.DLL : 8.1.1.0 53618 Bytes 4/30/2010 16:35:55
    AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 12:03:38
    AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 12:03:35
    AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 16:47:40
    AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 12:35:46
    AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 12:39:51
    AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 12:22:13
    AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 09:53:30
    SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 12:57:58
    AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 15:38:56
    NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 14:41:00
    RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 13:10:20
    RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 14:14:29

    Configuration settings for the scan:
    Jobname.............................: Complete system scan
    Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
    Logging.............................: low
    Primary action......................: interactive
    Secondary action....................: ignore
    Scan master boot sector.............: on
    Scan boot sector....................: on
    Boot sectors........................: C:,
    Process scan........................: on
    Extended process scan...............: on
    Scan registry.......................: on
    Search for rootkits.................: on
    Integrity checking of system files..: off
    Scan all files......................: All files
    Scan archives.......................: on
    Recursion depth.....................: 20
    Smart extensions....................: on
    Macro heuristic.....................: on
    File heuristic......................: medium

    Start of the scan: 03 May 2010 18:21

    Starting search for hidden objects.
    HKEY_LOCAL_MACHINE\Software\Classes\.wid\bin
    [NOTE] The registry entry is invisible.

    The scan of running processes will be started
    Scan process 'msdtc.exe' - '40' Module(s) have been scanned
    Scan process 'dllhost.exe' - '61' Module(s) have been scanned
    Scan process 'dllhost.exe' - '45' Module(s) have been scanned
    Scan process 'vssvc.exe' - '48' Module(s) have been scanned
    Scan process 'avconfig.exe' - '51' Module(s) have been scanned
    Scan process 'avscan.exe' - '67' Module(s) have been scanned
    Scan process 'avcenter.exe' - '68' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '30' Module(s) have been scanned
    Scan process 'BTTray.exe' - '44' Module(s) have been scanned
    Scan process 'GoogleToolbarNotifier.exe' - '56' Module(s) have been scanned
    Scan process 'msnmsgr.exe' - '104' Module(s) have been scanned
    Scan process 'avgnt.exe' - '56' Module(s) have been scanned
    Scan process 'NokiaMServer.exe' - '28' Module(s) have been scanned
    Scan process 'OEdmn_6.exe' - '38' Module(s) have been scanned
    Scan process 'sm56hlpr.exe' - '33' Module(s) have been scanned
    Scan process 'jusched.exe' - '21' Module(s) have been scanned
    Scan process 'GrooveMonitor.exe' - '43' Module(s) have been scanned
    Scan process 'rundll32.exe' - '34' Module(s) have been scanned
    Scan process 'InCD.exe' - '27' Module(s) have been scanned
    Scan process 'VTtrayp.exe' - '26' Module(s) have been scanned
    Scan process 'VTTimer.exe' - '18' Module(s) have been scanned
    Scan process 'SOUNDMAN.EXE' - '25' Module(s) have been scanned
    Scan process 'Explorer.EXE' - '99' Module(s) have been scanned
    Scan process 'alg.exe' - '33' Module(s) have been scanned
    Scan process 'symlcsvc.exe' - '30' Module(s) have been scanned
    Scan process 'svchost.exe' - '39' Module(s) have been scanned
    Scan process 'SeaPort.exe' - '46' Module(s) have been scanned
    Scan process 'jqs.exe' - '33' Module(s) have been scanned
    Scan process 'IconixService.exe' - '31' Module(s) have been scanned
    Scan process 'avshadow.exe' - '26' Module(s) have been scanned
    Scan process 'btwdins.exe' - '26' Module(s) have been scanned
    Scan process 'svchost.exe' - '34' Module(s) have been scanned
    Scan process 'bgsvcgen.exe' - '11' Module(s) have been scanned
    Scan process 'avguard.exe' - '57' Module(s) have been scanned
    Scan process 'svchost.exe' - '34' Module(s) have been scanned
    Scan process 'sched.exe' - '44' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '65' Module(s) have been scanned
    Scan process 'svchost.exe' - '37' Module(s) have been scanned
    Scan process 'svchost.exe' - '32' Module(s) have been scanned
    Scan process 'svchost.exe' - '30' Module(s) have been scanned
    Scan process 'InCDsrv.exe' - '20' Module(s) have been scanned
    Scan process 'svchost.exe' - '167' Module(s) have been scanned
    Scan process 'svchost.exe' - '40' Module(s) have been scanned
    Scan process 'svchost.exe' - '53' Module(s) have been scanned
    Scan process 'lsass.exe' - '58' Module(s) have been scanned
    Scan process 'services.exe' - '27' Module(s) have been scanned
    Scan process 'winlogon.exe' - '71' Module(s) have been scanned
    Scan process 'csrss.exe' - '14' Module(s) have been scanned
    Scan process 'smss.exe' - '2' Module(s) have been scanned

    Starting master boot sector scan:
    Master boot sector HD0
    [INFO] No virus was found!

    Start scanning boot sectors:
    Boot sector 'C:\'
    [INFO] No virus was found!

    Starting to scan executable files (registry).
    The registry was scanned ( '1819' files ).


    Starting the file scan:

    Begin scan in 'C:\' <System>
    C:\System Volume Information\_restore{E2EBC557-D74B-4114-9489-BBBB8C50BDA0}\RP84\A0016813.exe
    [DETECTION] Is the TR/Spy.269312.7 Trojan

    Beginning disinfection:
    C:\System Volume Information\_restore{E2EBC557-D74B-4114-9489-BBBB8C50BDA0}\RP84\A0016813.exe
    [DETECTION] Is the TR/Spy.269312.7 Trojan
    [NOTE] The file was moved to the quarantine directory under the name '4483b8b8.qua'.


    End of the scan: 03 May 2010 19:54
    Used time: 1:27:59 Hour(s)

    The scan has been done completely.

    7403 Scanned directories
    315775 Files were scanned
    1 Viruses and/or unwanted programs were found
    0 Files were classified as suspicious
    0 files were deleted
    0 Viruses and unwanted programs were repaired
    1 Files were moved to quarantine
    0 Files were renamed
    0 Files cannot be scanned
    315774 Files not concerned
    8097 Archives were scanned
    0 Warnings
    1 Notes
    411981 Objects were scanned with rootkit scan
    1 Hidden objects were found
    It's easier to get forgiveness than to ask permission ;)
  • tranmererovers
    tranmererovers Posts: 2,313 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    closed wrote: »
    How much ram, what is the commit charge in task manager.

    Run this http://www.malwarebytes.org/startuplite.php

    uninstall spybot, remove all the file missing entries, and post a fresh log

    Have ran startuplite and removed the entries shown, the figures from task manager are

    Physical memory

    Total 194800
    Available 75108
    System cache 101984

    Commit Charge

    Total 277048
    Limit 478672
    Peak 383352

    Thanks :)
    It's easier to get forgiveness than to ask permission ;)
  • GunJack
    GunJack Posts: 11,897 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    if you're getting virtual memory warnings, open control panel - system-advanced - performance - virtual memory, and change it to system managed, then reboot. It's because you've got it set to custom size and it's too small...let windows do it for you ;)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • tranmererovers
    tranmererovers Posts: 2,313 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    GunJack wrote: »
    if you're getting virtual memory warnings, open control panel - system-advanced - performance - virtual memory, and change it to system managed, then reboot. It's because you've got it set to custom size and it's too small...let windows do it for you ;)

    Thanks GunJack, it is set to 'system managed' and the system gives a warning and then (I assume) tries to manage it but fails miserably and all seems to hang :(
    It's easier to get forgiveness than to ask permission ;)
  • closed
    closed Posts: 10,886 Forumite
    edited 3 May 2010 at 8:58PM
    were those figures posted after startuplite, and a reboot - it's swapping, to prevent that you need to cut down on what is running at startup. Presumably the last hjl was before startuplite?

    https://forums.moneysavingexpert.com/discussion/2436849
    !!
    > . !!!! ----> .
  • GunJack
    GunJack Posts: 11,897 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    closed wrote: »
    Presumably the last hjl was before startuplite?

    I'd assume so, looking at some of the carp running :(
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • tranmererovers
    tranmererovers Posts: 2,313 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    edited 4 May 2010 at 7:20AM
    closed wrote: »
    were those figures posted after startuplite, and a reboot - it's swapping, to prevent that you need to cut down on what is running at startup. Presumably the last hjl was before startuplite?

    https://forums.moneysavingexpert.com/discussion/2436849

    The figures were definately after startuplite had run but I can't be sure that I rebooted :o The last HJT was before startuplite.

    I've got to go out now, but when I get back I will repost the figures and run a new HJT. Thanks :beer:
    It's easier to get forgiveness than to ask permission ;)
  • tranmererovers
    tranmererovers Posts: 2,313 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Ok here are the figures after reboot, before doing anything else...

    Physical memory

    Total 194800
    Available 91244
    System cache 106608

    Commit Charge

    Total 276492
    Limit 472672
    Peak 415924

    Here is a new HJT log

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 14:20:17, on 04/05/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\WINDOWS\system32\bgsvcgen.exe
    C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    C:\Program Files\Common Files\Iconix\IconixService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\VTtrayp.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\Program Files\Iconix\OEAddOn\OEdmn_6.exe
    C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Belkin\Bluetooth Software\BTTray.exe
    C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P35 "EPSON Stylus DX3800 Series (Copy 1)" /O5 "LPT1:" /M "Stylus DX3800"
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [IconixOEAddOn] "C:\Program Files\Iconix\OEAddOn\OEdmn_6.exe"
    O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
    O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\OviPlayer.exe" /command:faststart
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O4 - Global Startup: BTTray.lnk = ?
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll
    O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files\Common Files\Iconix\IconixService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 10722 bytes

    Thanks in anticipation :beer:
    It's easier to get forgiveness than to ask permission ;)
  • closed
    closed Posts: 10,886 Forumite
    edited 4 May 2010 at 4:49PM
    Your peak commit after a reboot is more than twice your ram size, it should be less, trimming superfluous startup apps should bring it below installed ram.

    Disabling these should free up resources, but some will impact functionality which may or may not be important. Remove from control panel, add/remove programs if there is an uninstaller

    Backup before you start.

    See my previous link regarding ctfmon, further tweaking, and backups.

    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: IconixBHOClass Class - {761233B6-F228-49E4-8F6B-668499D4E55A} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll

    O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\s wg.dll
    O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [IconixOEAddOn] "C:\Program Files\Iconix\OEAddOn\OEdmn_6.exe"
    O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup
    O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\OviPlayer.exe" /command:faststart

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe"
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6 FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll

    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: (no name) - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll
    O9 - Extra 'Tools' menuitem: Email ID Preferences - {400A6CFA-E326-4d61-A90C-9AD75358DC5F} - C:\Program Files\Iconix\IEAddOn\IconixBHO_42.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01...l/MSNPUpld.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Iconix Update Service (IconixService) - Unknown owner - C:\Program Files\Common Files\Iconix\IconixService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    !!
    > . !!!! ----> .
  • tranmererovers
    tranmererovers Posts: 2,313 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Thanks Closed.

    Once I have the all clear that all the viruses etc are gone from the machine, (I'm hoping AliEnRIK will pop in and have a look at the combofix log and HJT logs :) ) I will return it to my friend and go through the installed applications in conjunction with your list and remove ones she doesn't use.

    I have had a look at your thread referenced above and also installed clearmem which I hope will help with performance.
    It's easier to get forgiveness than to ask permission ;)
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.3K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601.1K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.