My computer has started to play up. Slow downloading webpages in IE8, stared to display the message at the top of each page 'to help protect your security ....... display content with security certificate errors'. I checked IE's download security options and so on. Google Chrome would not load, so I tried to remove using control panel, would not remove, tried to download and reinstall, no joy. Have run spybot and removed identified malware. Thought it was time to consult the experts. Here are the logs requested.
(noticed the infected messaged in the aswMBR log file. These have NOT been deleted)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.9.2
Run by sean at 21:00:19 on 2014-01-13
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1983.970 [GMT 0:00]
.
FW: ZoneAlarm Firewall *Disabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.9012.1008\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Spotify Web Helper] "c:\program files\spotify\data\SpotifyWebHelper.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Wireless Console 2] "c:\program files\wireless console 2\wcourier.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\sean\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/select/asusTek_sys_ctrl3.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} - hxxp://cam.thesandbar.com/activex/decoder/mpeg4_dec.cab
DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135} - hxxp://download.microsoft.com/download/3/B/E/3BE57995-8452-41F1-8297-DD75EF049853/VirtualEarth3D.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4D561B31-49A0-4E2C-8AFF-353468EC669B} - hxxp://www.greasypalm.co.uk/bho/update/GreasyPalm.cab
DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.tescophoto.com/wpp/tesco/app/ImageUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1350936625281
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1350936606734
DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://webcam1.ttu.ee/activex/AMC.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://webcam.salisbury.edu/activex/AxisCamControl.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://217.22.201.135/activex/AMC.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{A97A08D4-B39E-4E5F-A1D4-622F067B28E0} : DHCPNameServer = 192.168.1.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\31.0.1650.63\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 C2SCSI;C2SCSI;c:\windows\system32\drivers\c2scsi.sys [2009-5-28 230272]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2013-5-12 47640]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-7-28 27632]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\logmein\x86\rainfo.sys --> c:\program files\logmein\x86\RaInfo.sys [?]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2012-3-31 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-22 21248]
S3 massfilter_hs;ZTE HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2010-7-28 9728]
S3 zgwhsdiag;ZTE WCDMA Handset Diagnostic Port;c:\windows\system32\drivers\zgwhsdiag.sys [2010-7-28 106752]
S3 zgwhsmdm;ZTE WCDMA Handset USB Modem;c:\windows\system32\drivers\zgwhsmdm.sys [2010-7-28 106752]
S3 zgwhsnmea;WCDMA Handset NMEA Port;c:\windows\system32\drivers\zgwhsnmea.sys [2010-7-28 106752]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== File Associations ===============
.
ShellExec: FRONTPG.EXE: edit=c:\progra~1\micros~2\office\FRONTPG.EXE
.
=============== Created Last 30 ================
.
2014-01-12 21:18:13 -------- d-----w- c:\documents and settings\sean\local settings\application data\Spotify
2014-01-09 07:49:24 360448 ----a-w- c:\documents and settings\sean\application data\microsoft\installer\{6af75c96-2093-51f4-0412-501cb317a7f9}\reg.exe
2014-01-06 23:31:38 -------- d-----w- C:\dansMemoryStick
2014-01-06 19:23:36 4558848 -c--a-w- c:\windows\system32\GPhotos.scr
2014-01-05 23:11:25 -------- d-----w- c:\documents and settings\all users\application data\Avira
2014-01-03 22:07:07 -------- d-----w- C:\mumphoto
2014-01-03 22:06:23 -------- d-----w- c:\documents and settings\sean\mumphoto
2013-12-27 11:04:38 -------- d-----w- C:\Films
2013-12-19 19:23:02 -------- d-----w- c:\documents and settings\sean\application data\FinalTorrent
2013-12-19 19:15:49 -------- d-----w- c:\program files\FinalTorrent
2013-12-19 19:12:55 -------- d-----w- c:\documents and settings\sean\.android
2013-12-19 19:12:53 -------- d-----w- c:\documents and settings\sean\local settings\application data\cache
2013-12-19 19:12:45 -------- d-----w- c:\documents and settings\sean\local settings\application data\genienext
2013-12-19 19:12:44 -------- d-----w- c:\documents and settings\sean\local settings\application data\Mobogenie
2013-12-19 19:11:47 -------- d-----w- c:\program files\Mobogenie
2013-12-19 19:08:01 -------- d-----w- C:\tempd
.
==================== Find3M ====================
.
2003-08-27 14:19:18 36963 -c--a-r- c:\program files\common files\SM1updtr.dll
.
============= FINISH: 21:02:16.10 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-13 21:16:12
-----------------------------
21:16:12.968 OS Version: Windows 5.1.2600 Service Pack 3
21:16:12.968 Number of processors: 2 586 0xF0D
21:16:12.968 ComputerName: LAPTOP02 UserName: sean
21:16:15.765 Initialize success
21:21:58.000 AVAST engine defs: 14011300
21:29:06.109 The log file has been saved successfully to "C:\Documents and Settings\sean\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-13 21:16:12
-----------------------------
21:16:12.968 OS Version: Windows 5.1.2600 Service Pack 3
21:16:12.968 Number of processors: 2 586 0xF0D
21:16:12.968 ComputerName: LAPTOP02 UserName: sean
21:16:15.765 Initialize success
21:21:58.000 AVAST engine defs: 14011300
21:29:06.109 The log file has been saved successfully to "C:\Documents and Settings\sean\Desktop\aswMBR.txt"
21:30:03.859 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
21:30:03.875 Disk 0 Vendor: Hitachi_HTS541616J9SA00 SB4OC70P Size: 152627MB BusType: 3
21:30:04.062 Disk 0 MBR read successfully
21:30:04.062 Disk 0 MBR scan
21:30:04.109 Disk 0 Windows XP default MBR code
21:30:04.125 Disk 0 Partition 1 00 1B Hidd FAT32 MSDOS5.0 4000 MB offset 63
21:30:04.156 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 91573 MB offset 8193150
21:30:04.171 Disk 0 Partition - 00 0F Extended LBA 57051 MB offset 195735960
21:30:04.187 Disk 0 Partition 3 00 0B FAT32 MSWIN4.1 57051 MB offset 195736023
21:30:04.203 Disk 0 scanning sectors +312576705
21:30:04.390 Disk 0 scanning C:\WINDOWS\system32\drivers
21:30:25.484 Service scanning
21:30:56.937 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
21:31:04.578 Modules scanning
21:31:13.187 Disk 0 trace - called modules:
21:31:13.234 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spru.sys >>UNKNOWN [0x8a954938]<<
21:31:13.234 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a89dab8]
21:31:13.234 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000079[0x8a99d288]
21:31:13.234 5 ACPI.sys[b9e74620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a970030]
21:31:16.390 AVAST engine scan C:\WINDOWS
21:31:39.156 AVAST engine scan C:\WINDOWS\system32
21:44:15.625 AVAST engine scan C:\WINDOWS\system32\drivers
21:46:06.984 AVAST engine scan C:\Documents and Settings\sean
21:47:03.406 File: C:\Documents and Settings\sean\Application Data\Microsoft\Installer\{6AF75C96-2093-51F4-0412-501CB317A7F9}\reg.exe **INFECTED** Win32:Malware-gen
21:47:57.937 File: C:\Documents and Settings\sean\Application Data\Skype\caine_19\chatsync\77\locator.exe **INFECTED** Win32:Malware-gen
22:16:50.265 AVAST engine scan C:\Documents and Settings\All Users
22:25:45.203 Scan finished successfully
22:26:42.656 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\sean\Desktop\MBR.dat"
22:26:42.656 The log file has been saved successfully to "C:\Documents and Settings\sean\Desktop\aswMBR.txt"
Hi there. My comp is now taking ages to load windows, response times to carry out any activity. Anyone there to help me please ?
(noticed the infected messaged in the aswMBR log file. These have NOT been deleted)
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.9.2
Run by sean at 21:00:19 on 2014-01-13
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1983.970 [GMT 0:00]
.
FW: ZoneAlarm Firewall *Disabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - c:\program files\google\googletoolbarnotifier\5.7.9012.1008\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Spotify Web Helper] "c:\program files\spotify\data\SpotifyWebHelper.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Wireless Console 2] "c:\program files\wireless console 2\wcourier.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\sean\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDrives = dword:0
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://go.microsoft.com/fwlink/?linkid=58813
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/select/asusTek_sys_ctrl3.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {32C11E38-E587-4BE9-9ABB-D69158C21CE5} - hxxp://cam.thesandbar.com/activex/decoder/mpeg4_dec.cab
DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135} - hxxp://download.microsoft.com/download/3/B/E/3BE57995-8452-41F1-8297-DD75EF049853/VirtualEarth3D.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4D561B31-49A0-4E2C-8AFF-353468EC669B} - hxxp://www.greasypalm.co.uk/bho/update/GreasyPalm.cab
DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.tescophoto.com/wpp/tesco/app/ImageUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1350936625281
DPF: {6D2EF4B4-CB62-4C0B-85F3-B79C236D702C} - hxxp://www.facebook.com/controls/contactx.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1350936606734
DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://webcam1.ttu.ee/activex/AMC.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://webcam.salisbury.edu/activex/AxisCamControl.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://217.22.201.135/activex/AMC.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{A97A08D4-B39E-4E5F-A1D4-622F067B28E0} : DHCPNameServer = 192.168.1.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\31.0.1650.63\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 C2SCSI;C2SCSI;c:\windows\system32\drivers\c2scsi.sys [2009-5-28 230272]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2013-5-12 47640]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-7-28 27632]
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\logmein\x86\rainfo.sys --> c:\program files\logmein\x86\RaInfo.sys [?]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2012-3-31 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-22 21248]
S3 massfilter_hs;ZTE HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2010-7-28 9728]
S3 zgwhsdiag;ZTE WCDMA Handset Diagnostic Port;c:\windows\system32\drivers\zgwhsdiag.sys [2010-7-28 106752]
S3 zgwhsmdm;ZTE WCDMA Handset USB Modem;c:\windows\system32\drivers\zgwhsmdm.sys [2010-7-28 106752]
S3 zgwhsnmea;WCDMA Handset NMEA Port;c:\windows\system32\drivers\zgwhsnmea.sys [2010-7-28 106752]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
=============== File Associations ===============
.
ShellExec: FRONTPG.EXE: edit=c:\progra~1\micros~2\office\FRONTPG.EXE
.
=============== Created Last 30 ================
.
2014-01-12 21:18:13 -------- d-----w- c:\documents and settings\sean\local settings\application data\Spotify
2014-01-09 07:49:24 360448 ----a-w- c:\documents and settings\sean\application data\microsoft\installer\{6af75c96-2093-51f4-0412-501cb317a7f9}\reg.exe
2014-01-06 23:31:38 -------- d-----w- C:\dansMemoryStick
2014-01-06 19:23:36 4558848 -c--a-w- c:\windows\system32\GPhotos.scr
2014-01-05 23:11:25 -------- d-----w- c:\documents and settings\all users\application data\Avira
2014-01-03 22:07:07 -------- d-----w- C:\mumphoto
2014-01-03 22:06:23 -------- d-----w- c:\documents and settings\sean\mumphoto
2013-12-27 11:04:38 -------- d-----w- C:\Films
2013-12-19 19:23:02 -------- d-----w- c:\documents and settings\sean\application data\FinalTorrent
2013-12-19 19:15:49 -------- d-----w- c:\program files\FinalTorrent
2013-12-19 19:12:55 -------- d-----w- c:\documents and settings\sean\.android
2013-12-19 19:12:53 -------- d-----w- c:\documents and settings\sean\local settings\application data\cache
2013-12-19 19:12:45 -------- d-----w- c:\documents and settings\sean\local settings\application data\genienext
2013-12-19 19:12:44 -------- d-----w- c:\documents and settings\sean\local settings\application data\Mobogenie
2013-12-19 19:11:47 -------- d-----w- c:\program files\Mobogenie
2013-12-19 19:08:01 -------- d-----w- C:\tempd
.
==================== Find3M ====================
.
2003-08-27 14:19:18 36963 -c--a-r- c:\program files\common files\SM1updtr.dll
.
============= FINISH: 21:02:16.10 ===============
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-13 21:16:12
-----------------------------
21:16:12.968 OS Version: Windows 5.1.2600 Service Pack 3
21:16:12.968 Number of processors: 2 586 0xF0D
21:16:12.968 ComputerName: LAPTOP02 UserName: sean
21:16:15.765 Initialize success
21:21:58.000 AVAST engine defs: 14011300
21:29:06.109 The log file has been saved successfully to "C:\Documents and Settings\sean\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2014-01-13 21:16:12
-----------------------------
21:16:12.968 OS Version: Windows 5.1.2600 Service Pack 3
21:16:12.968 Number of processors: 2 586 0xF0D
21:16:12.968 ComputerName: LAPTOP02 UserName: sean
21:16:15.765 Initialize success
21:21:58.000 AVAST engine defs: 14011300
21:29:06.109 The log file has been saved successfully to "C:\Documents and Settings\sean\Desktop\aswMBR.txt"
21:30:03.859 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
21:30:03.875 Disk 0 Vendor: Hitachi_HTS541616J9SA00 SB4OC70P Size: 152627MB BusType: 3
21:30:04.062 Disk 0 MBR read successfully
21:30:04.062 Disk 0 MBR scan
21:30:04.109 Disk 0 Windows XP default MBR code
21:30:04.125 Disk 0 Partition 1 00 1B Hidd FAT32 MSDOS5.0 4000 MB offset 63
21:30:04.156 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 91573 MB offset 8193150
21:30:04.171 Disk 0 Partition - 00 0F Extended LBA 57051 MB offset 195735960
21:30:04.187 Disk 0 Partition 3 00 0B FAT32 MSWIN4.1 57051 MB offset 195736023
21:30:04.203 Disk 0 scanning sectors +312576705
21:30:04.390 Disk 0 scanning C:\WINDOWS\system32\drivers
21:30:25.484 Service scanning
21:30:56.937 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
21:31:04.578 Modules scanning
21:31:13.187 Disk 0 trace - called modules:
21:31:13.234 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spru.sys >>UNKNOWN [0x8a954938]<<
21:31:13.234 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a89dab8]
21:31:13.234 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000079[0x8a99d288]
21:31:13.234 5 ACPI.sys[b9e74620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a970030]
21:31:16.390 AVAST engine scan C:\WINDOWS
21:31:39.156 AVAST engine scan C:\WINDOWS\system32
21:44:15.625 AVAST engine scan C:\WINDOWS\system32\drivers
21:46:06.984 AVAST engine scan C:\Documents and Settings\sean
21:47:03.406 File: C:\Documents and Settings\sean\Application Data\Microsoft\Installer\{6AF75C96-2093-51F4-0412-501CB317A7F9}\reg.exe **INFECTED** Win32:Malware-gen
21:47:57.937 File: C:\Documents and Settings\sean\Application Data\Skype\caine_19\chatsync\77\locator.exe **INFECTED** Win32:Malware-gen
22:16:50.265 AVAST engine scan C:\Documents and Settings\All Users
22:25:45.203 Scan finished successfully
22:26:42.656 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\sean\Desktop\MBR.dat"
22:26:42.656 The log file has been saved successfully to "C:\Documents and Settings\sean\Desktop\aswMBR.txt"
Hi there. My comp is now taking ages to load windows, response times to carry out any activity. Anyone there to help me please ?
Last edited by a moderator: