Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Internet Pages Loading REALLY Slow After Trojan  (Read 6496 times)

0 Members and 1 Guest are viewing this topic.

fullbug

    Topic Starter


    Apprentice
  • Thanked: 1
    Internet Pages Loading REALLY Slow After Trojan
    « on: June 18, 2008, 06:06:07 AM »
    Hi, I'm on a Windows XP Home, Toshiba Laptop, SP2, and yesterday I downloaded a file that was, unknown to me, loaded with trojans....

    I used SuperAntiSpyware and MalwareBytes to remove them, and those scans now come clean....
    However, now my internet pages, no matter what browser I'm using, load REALLY slow, for example to get this page to load took about 2-3 minutes, where as before it would be pretty much instant, as you can imagine this is very frustrating....

    I have ran CCleaner as well, and right now am running Auslogics Disk Defrag, but nothing is helping, any suggestions would be great, thanx....

    Carbon Dudeoxide

    • Global Moderator

    • Mastermind
    • Thanked: 169
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Experience: Guru
    • OS: Mac OS
    Re: Internet Pages Loading REALLY Slow After Trojan
    « Reply #1 on: June 18, 2008, 06:15:16 AM »
    Quote
    I used SuperAntiSpyware and MalwareBytes to remove them, and those scans now come clean....
    Can't be too careful. I suggest starting here:

    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    Post the logs here and our malware specialists will make sure you have a clean bill of health.  ;)

    fullbug

      Topic Starter


      Apprentice
    • Thanked: 1
      Re: Internet Pages Loading REALLY Slow After Trojan
      « Reply #2 on: June 18, 2008, 06:18:14 AM »
      Here is my hijackthis file if it helps....

      Logfile of HijackThis v1.99.1
      Scan saved at 8:10:48 AM, on 18/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Online Armor\oasrv.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Advanced WindowsCare 3 Beta\awcservice.exe
      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      C:\WINDOWS\system32\DVDRAMSV.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Spyware Terminator\sp_rsser.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\ltmoh\Ltmoh.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
      C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
      C:\Program Files\Canon\CAL\CALMAIN.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Program Files\Ahead\InCD\InCD.exe
      C:\Program Files\ClipX\clipx.exe
      C:\Program Files\WinPatrol\winpatrol.exe
      C:\Program Files\Synaptics\SynTP\Toshiba.exe
      C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
      C:\Program Files\Online Armor\oaui.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
      C:\Program Files\Eraser\eraser.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\system32\RAMASST.exe
      C:\Program Files\Starter\Starter.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\T-Clock\lang\tclock.exe
      C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
      C:\PROGRAM FILES\NOTESHOLDER\NOTESHOLDER.EXE
      C:\PROGRAM FILES\RAINLENDAR2\RAINLENDAR2.EXE
      C:\Program Files\uTorrent\uTorrent.exe
      C:\Program Files\Avant Browser\avant.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Disc Defrag\AusLogics Disk Defrag\diskdefrag.exe
      C:\Program Files\HighJack This\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shoptoshiba.ca/welcome
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
      O4 - HKLM\..\Run: [ClipX] C:\Program Files\ClipX\clipx.exe
      O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe -expressboot
      O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
      O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
      O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
      O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
      O4 - Startup: KillProcess.lnk = C:\Program Files\KillProcess\KillProcess.exe
      O4 - Startup: Starter.lnk = ?
      O4 - Startup: T-Clock.lnk = C:\Program Files\T-Clock\lang\tclock.exe
      O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Evernote - res://C:\Program Files\Evernote\Evernote3\enbar.dll/2000
      O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
      O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Broken Internet access because of LSP provider 'avsda.dll' missing
      O11 - Options group: [INTERNATIONAL] International*
      O15 - Trusted Zone: http://www1.skillground.com
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
      O16 - DPF: {0F733F27-5BBB-4D03-8D6B-19E2143880BF} (SkillGround Game Manager) - http://www1.skillground.com/cab1830/SkillGround.cab
      O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
      O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
      O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
      O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
      O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
      O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Advanced WindowsCare Boost Service (AwcService) - IObit - C:\Program Files\Advanced WindowsCare 3 Beta\awcservice.exe
      O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
      O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
      O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
      O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
      O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Online Armor\oasrv.exe
      O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
      O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe

      fullbug

        Topic Starter


        Apprentice
      • Thanked: 1
        Re: Internet Pages Loading REALLY Slow After Trojan
        « Reply #3 on: June 18, 2008, 06:37:44 AM »
        I will have to run SAS and Malwarebytes again, as I didnt save the logs, will post them when its done....

        fullbug

          Topic Starter


          Apprentice
        • Thanked: 1
          Re: Internet Pages Loading REALLY Slow After Trojan
          « Reply #4 on: June 18, 2008, 11:11:11 AM »
          Here is my SAS log, will post the MalwareBytes one when its finished....
          Ever after 3 scans so far,SAS still found a trojan....

          SUPERAntiSpyware Scan Log
          http://www.superantispyware.com

          Generated 06/18/2008 at 12:49 PM

          Application Version : 4.1.1046

          Core Rules Database Version : 3482
          Trace Rules Database Version: 1450

          Scan type       : Complete Scan
          Total Scan Time : 02:21:42

          Memory items scanned      : 497
          Memory threats detected   : 0
          Registry items scanned    : 5341
          Registry threats detected : 0
          File items scanned        : 201721
          File threats detected     : 32

          Adware.Tracking Cookie
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\sean@mediaplex[3].txt
             C:\Documents and Settings\Sean\Cookies\sean@advertising[3].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][3].txt
             C:\Documents and Settings\Sean\Cookies\sean@tacoda[1].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\sean@collective-media[2].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\sean@atwola[2].txt
             C:\Documents and Settings\Sean\Cookies\sean@xiti[2].txt
             C:\Documents and Settings\Sean\Cookies\sean@2o7[2].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][2].txt
             C:\Documents and Settings\Sean\Cookies\sean@interclick[1].txt
             C:\Documents and Settings\Sean\Cookies\sean@revsci[2].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][3].txt
             C:\Documents and Settings\Sean\Cookies\sean@hitbox[1].txt
             C:\Documents and Settings\Sean\Cookies\sean@2o7[1].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\sean@adinterax[2].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][2].txt
             C:\Documents and Settings\Sean\Cookies\sean@adultfriendfinder[2].txt
             C:\Documents and Settings\Sean\Cookies\sean@advertising[2].txt
             C:\Documents and Settings\Sean\Cookies\sean@mediaplex[2].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][1].txt
             C:\Documents and Settings\Sean\Cookies\[email protected][2].txt
             C:\Documents and Settings\Sean\Cookies\sean@xiti[1].txt
             

          Trojan.Vundo-Variant/Small-GEN
             C:\WINDOWS\SYSTEM32\HGGYVWPQ.DLL

          fullbug

            Topic Starter


            Apprentice
          • Thanked: 1
            Re: Internet Pages Loading REALLY Slow After Trojan
            « Reply #5 on: June 18, 2008, 11:24:46 AM »
            Malwarebytes' Anti-Malware 1.17
            Database version: 867

            1:23:21 PM 18/06/2008
            mbam-log-6-18-2008 (13-23-21).txt

            Scan type: Quick Scan
            Objects scanned: 45877
            Time elapsed: 6 minute(s), 8 second(s)

            Memory Processes Infected: 0
            Memory Modules Infected: 0
            Registry Keys Infected: 1
            Registry Values Infected: 0
            Registry Data Items Infected: 0
            Folders Infected: 0
            Files Infected: 0

            Memory Processes Infected:
            (No malicious items detected)

            Memory Modules Infected:
            (No malicious items detected)

            Registry Keys Infected:
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

            Registry Values Infected:
            (No malicious items detected)

            Registry Data Items Infected:
            (No malicious items detected)

            Folders Infected:
            (No malicious items detected)

            Files Infected:
            (No malicious items detected)

            fullbug

              Topic Starter


              Apprentice
            • Thanked: 1
              Re: Internet Pages Loading REALLY Slow After Trojan
              « Reply #6 on: June 18, 2008, 11:28:19 AM »
              Here is the hijackthis log after the scans....


              Logfile of HijackThis v1.99.1
              Scan saved at 1:26:08 PM, on 18/06/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
              C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Online Armor\oasrv.exe
              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\Program Files\Advanced WindowsCare 3 Beta\awcservice.exe
              C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
              C:\WINDOWS\system32\DVDRAMSV.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
              C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
              C:\Program Files\Spyware Terminator\sp_rsser.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
              C:\Program Files\Canon\CAL\CALMAIN.exe
              C:\WINDOWS\AGRSMMSG.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\ltmoh\Ltmoh.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
              C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\WINDOWS\system32\igfxpers.exe
              C:\Program Files\Ahead\InCD\InCD.exe
              C:\Program Files\ClipX\clipx.exe
              C:\Program Files\WinPatrol\winpatrol.exe
              C:\Program Files\Synaptics\SynTP\Toshiba.exe
              C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\Online Armor\oaui.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
              C:\Program Files\Eraser\eraser.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\RAMASST.exe
              C:\Program Files\Starter\Starter.exe
              C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
              C:\Program Files\T-Clock\lang\tclock.exe
              C:\PROGRAM FILES\NOTESHOLDER\NOTESHOLDER.EXE
              C:\PROGRAM FILES\RAINLENDAR2\RAINLENDAR2.EXE
              C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\Program Files\Avant Browser\avant.exe
              C:\WINDOWS\explorer.exe
              C:\Program Files\HighJack This\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shoptoshiba.ca/welcome
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
              O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
              O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
              O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
              O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
              O4 - HKLM\..\Run: [ClipX] C:\Program Files\ClipX\clipx.exe
              O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe -expressboot
              O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
              O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe"
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
              O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
              O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
              O4 - Startup: KillProcess.lnk = C:\Program Files\KillProcess\KillProcess.exe
              O4 - Startup: Starter.lnk = ?
              O4 - Startup: T-Clock.lnk = C:\Program Files\T-Clock\lang\tclock.exe
              O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: Add to Evernote - res://C:\Program Files\Evernote\Evernote3\enbar.dll/2000
              O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
              O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
              O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O10 - Broken Internet access because of LSP provider 'avsda.dll' missing
              O11 - Options group: [INTERNATIONAL] International*
              O15 - Trusted Zone: http://www1.skillground.com
              O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
              O16 - DPF: {0F733F27-5BBB-4D03-8D6B-19E2143880BF} (SkillGround Game Manager) - http://www1.skillground.com/cab1830/SkillGround.cab
              O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
              O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
              O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
              O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
              O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
              O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: Advanced WindowsCare Boost Service (AwcService) - IObit - C:\Program Files\Advanced WindowsCare 3 Beta\awcservice.exe
              O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
              O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
              O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
              O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
              O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
              O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
              O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
              O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
              O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Online Armor\oasrv.exe
              O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
              O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe



              fullbug

                Topic Starter


                Apprentice
              • Thanked: 1
                Re: Internet Pages Loading REALLY Slow After Trojan
                « Reply #7 on: June 18, 2008, 11:31:20 AM »
                Another thing, this window keeps popping up from Scotty the watchdog....

                [recovering disk space -- attachment deleted by admin]

                fullbug

                  Topic Starter


                  Apprentice
                • Thanked: 1
                  Re: Internet Pages Loading REALLY Slow After Trojan
                  « Reply #8 on: June 18, 2008, 02:45:53 PM »
                  Even after running all those, my AntiVir is still reporting the same trojan, I also ran Trojan Remover....

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: Internet Pages Loading REALLY Slow After Trojan
                  « Reply #9 on: June 18, 2008, 09:13:44 PM »
                  This is outdated HJT version...

                  Download HijackThis:
                  http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
                  Click on Download HijackThis Installer
                  Post HijackTHis log.

                  fullbug

                    Topic Starter


                    Apprentice
                  • Thanked: 1
                    Re: Internet Pages Loading REALLY Slow After Trojan
                    « Reply #10 on: June 19, 2008, 06:41:03 AM »
                    OK.....

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 8:39:42 AM, on 19/06/2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Online Armor\oasrv.exe
                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\Program Files\Advanced WindowsCare 3 Beta\awcservice.exe
                    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                    C:\WINDOWS\system32\DVDRAMSV.exe
                    C:\WINDOWS\system32\HPZipm12.exe
                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
                    C:\Program Files\Spyware Terminator\sp_rsser.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
                    C:\Program Files\ThreatFire\TFService.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
                    C:\Program Files\Canon\CAL\CALMAIN.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\AGRSMMSG.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\ltmoh\Ltmoh.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\Program Files\Synaptics\SynTP\Toshiba.exe
                    C:\Program Files\Ahead\InCD\InCD.exe
                    C:\Program Files\ClipX\clipx.exe
                    C:\Program Files\WinPatrol\winpatrol.exe
                    C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe
                    C:\Program Files\Online Armor\oaui.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
                    C:\Program Files\ThreatFire\TFTray.exe
                    C:\Program Files\Eraser\eraser.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\RAMASST.exe
                    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
                    C:\Program Files\Starter\Starter.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\T-Clock\lang\tclock.exe
                    C:\PROGRAM FILES\NOTESHOLDER\NOTESHOLDER.EXE
                    C:\PROGRAM FILES\RAINLENDAR2\RAINLENDAR2.EXE
                    C:\Program Files\Avant Browser\avant.exe
                    C:\WINDOWS\explorer.exe
                    C:\Program Files\HighJack This\HijackThis.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://shoptoshiba.ca/welcome
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                    O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
                    O4 - HKLM\..\Run: [ClipX] C:\Program Files\ClipX\clipx.exe
                    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe -expressboot
                    O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRA~1\SPYWAR~1\SpywareTerminatorShield.exe"
                    O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Online Armor\oaui.exe"
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
                    O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
                    O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - .DEFAULT User Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user')
                    O4 - Startup: KillProcess.lnk = C:\Program Files\KillProcess\KillProcess.exe
                    O4 - Startup: Starter.lnk = ?
                    O4 - Startup: T-Clock.lnk = C:\Program Files\T-Clock\lang\tclock.exe
                    O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                    O8 - Extra context menu item: Add to Evernote - res://C:\Program Files\Evernote\Evernote3\enbar.dll/2000
                    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
                    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                    O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
                    O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O15 - Trusted Zone: http://www1.skillground.com
                    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                    O16 - DPF: {0F733F27-5BBB-4D03-8D6B-19E2143880BF} (SkillGround Game Manager) - http://www1.skillground.com/cab1830/SkillGround.cab
                    O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
                    O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
                    O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
                    O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
                    O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
                    O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: Advanced WindowsCare Boost Service (AwcService) - IObit - C:\Program Files\Advanced WindowsCare 3 Beta\awcservice.exe
                    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                    O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
                    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
                    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
                    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
                    O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Online Armor\oasrv.exe
                    O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
                    O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
                    O24 - Desktop Component 0: (no name) - (no file)

                    --
                    End of file - 12219 bytes

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: Internet Pages Loading REALLY Slow After Trojan
                    « Reply #11 on: June 19, 2008, 11:28:24 AM »
                    I see nothing malicious, but I may have couple of suggestions.
                    You may be running too many protection programs...
                    Advanced Windows care is in beta stage. I'd uninstall it.
                    Then, you have Spyware Terminator with Clam service running, and also ThreatFire. I'd get rid of Spyware Terminator.

                    fullbug

                      Topic Starter


                      Apprentice
                    • Thanked: 1
                      Re: Internet Pages Loading REALLY Slow After Trojan
                      « Reply #12 on: June 19, 2008, 08:06:19 PM »
                      I see nothing malicious, but I may have couple of suggestions.
                      You may be running too many protection programs...
                      Advanced Windows care is in beta stage. I'd uninstall it.
                      Then, you have Spyware Terminator with Clam service running, and also ThreatFire. I'd get rid of Spyware Terminator.
                      Noted....
                      Since my last SAS run, things seem better, although the Scotty warning wont stop, no matter what choice I pick, I just ended up turning it off....
                      Will get rid of ST, thanx as always Broni.... 8)

                      Broni


                        Mastermind
                      • Kraków my love :)
                      • Thanked: 614
                        • Computer Help Forum
                      • Computer: Specs
                      • Experience: Experienced
                      • OS: Windows 8
                      Re: Internet Pages Loading REALLY Slow After Trojan
                      « Reply #13 on: June 19, 2008, 08:58:08 PM »
                      Good.
                      BTW, you may accept that change, WinPatrol is asking about. Nothing dangerous there.