Slow computer and freeze – D-A
Thank, AVG has detect 27 malware in my system.
Daily I receive this type of error since 3 days: A problem has been detected and Windows has been shut down to prevent damage to your computer. Technical information: *** STOP: 0x0000000A (0XFFBDF000, OX0000002, OX0000001, OX804D9B08).
Here is my AVG log and Hijackthis log
———————————————————
AVG Anti-Spyware – Scan Report
———————————————————
+ Created at: 8:34:59 PM 10/18/2006
+ Scan result:
C:\WINDOWS\system32\mssvide.dll.tcf -> Adware.BHO : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Program Files\SurfAccuracy -> Adware.SurfAccuracy : Cleaned with backup (quarantined).
C:\Program Files\SurfAccuracy\SAcc.cfg -> Adware.SurfAccuracy : Cleaned with backup (quarantined).
C:\BITWARE\FAX\BFRXL.COD -> Adware.Systemdoctor : Cleaned with backup (quarantined).
D:\yas program\Trillian\ICQToolbar\version.txt -> Adware.Systemdoctor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C0EB0AC8-1411-42E0-BE44-B708820880B9}\RP135\A0075459.exe -> Backdoor.Rbot : Cleaned with backup (quarantined).
C:\Documents and Settings\yyyy\Cookies\yyyy@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\yyyy\Cookies\yyyy@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\yyyy\Cookies\yyyy@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\BAB\Cookies\bab@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\yyyy\Cookies\yyyy@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\yyyy\Cookies\yyyy@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.12:C:\Documents and Settings\yyyy\Application Data\Mozilla\Firefox\Profiles\12tl3hhd.default\coo kies.txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\yyyy\Cookies\yyyy@estat[1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\yyyy\Cookies\yyyy@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned.
C:\Documents and Settings\Yas\Cookies\yasvin@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned.
C:\Documents and Settings\Yas\Cookies\yasvin@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Yas\Cookies\yasvin@data4.perf.overture[2].txt -> TrackingCookie.Over
Logfile of HijackThis v1.99.1
Scan saved at 9:28:57 PM, on 10/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
C:\WINDOWS\PowerS.exe
D:\Avast4\aswUpdSv.exe
C:\WINDOWS\SOUNDMAN.EXE
D:\Avast4\ashServ.exe
D:\Avast4\ashDisp.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Internet Download Manager\IDMan.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\yas program\Ares\Ares.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Avast4\ashMaiSv.exe
D:\Avast4\ashWebSv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\AVG Anti-Spyware 7.5\guard.exe
D:\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://servihoo.com/
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = :
R3 – URLSearchHook: (no name) – {00A6FAF6-072E-44cf-8957-5838F569A31D} – (no file)
R3 – URLSearchHook: (no name) – {855F3B16-6D32-4fe6-8A56-BBB695989046} – (no file)
R3 – URLSearchHook: Yahoo! Toolbar – {EF99BD32-C1FB-11D2-892F-0090271D4F88} – C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 – BHO: IDM Helper – {0055C089-8582-441B-A0BF-17B458C2A3A8} – D:\Internet Download Manager\IDMIECC.dll
O2 – BHO: (no name) – {00A6FAF1-072E-44cf-8957-5838F569A31D} – (no file)
O2 – BHO: Yahoo! Toolbar Helper – {02478D38-C3F9-4EFB-9B51-7695ECA05670} – C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 – BHO: SpywareBlock Class – {0A87E45F-537A-40B4-B812-E2544C21A09F} – D:\YAS GAME\GhostSurf 2005\SCActiveBlock.dll
O2 – BHO: (no name) – {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} – (no file)
O2 – BHO: Yahoo! IE Services Button – {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} – C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 – BHO: SSVHelper Class – {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 – BHO: Windows Live Sign-in Helper – {9030D464-4C02-4ABF-8ECC-5164760863C6} – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 – BHO: Google Toolbar Helper – {AA58ED58-01DD-4d91-8333-CF10577473F7} – c:\program files\google\googletoolbar1.dll
O2 – BHO: gFlash Class – {F156768E-81EF-470C-9057-481BA8380DBA} – D:\YASPRO~1\FLASHGET\getflash.dll
O3 – Toolbar: Yahoo! Toolbar – {EF99BD32-C1FB-11D2-892F-0090271D4F88} – C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 – Toolbar: FlashGet Bar – {E0E899AB-F487-11D5-8D29-0050BA6940E3} – D:\YASPRO~1\FLASHGET\fgiebar.dll
O3 – Toolbar: &Google – {2318C2B1-4965-11d4-9B18-009027A5CD4F} – c:\program files\google\googletoolbar1.dll
O4 – HKLM\..\Run: [CnxDslTaskBar] “C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe” “ZTE Corporation\ZXDSL852″
O4 – HKLM\..\Run: [PowerS] C:\WINDOWS\PowerS.exe
O4 – HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 – HKLM\..\Run: [avast!] D:\Avast4\ashDisp.exe
O4 – HKLM\..\Run: [Zone Labs Client] “D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”
O4 – HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [IDMan] D:\Internet Download Manager\IDMan.exe /onboot
O4 – HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 – HKCU\..\Run: [ares] “D:\yas program\Ares\Ares.exe” -h
O4 – HKCU\..\Run: [Yahoo! Pager] “C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe” -quiet
O8 – Extra context menu item: &Clean Traces – D:\yas program\DAP\Privacy Package\dapcleanerie.htm
O8 – Extra context menu item: &Download with &DAP – D:\yas program\DAP\dapextie.htm
O8 – Extra context menu item: &Google Search – res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 – Extra context menu item: &ICQ Toolbar Search – res://D:\yas program\Trillian\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 – Extra context menu item: &Translate English Word – res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 – Extra context menu item: &Yahoo! Search – file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 – Extra context menu item: Backward Links – res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 – Extra context menu item: Download &all with DAP – D:\yas program\DAP\dapextie2.htm
O8 – Extra context menu item: Download All by FlashGet – D:\yas program\FlashGet\jc_all.htm
O8 – Extra context menu item: Download All Links with IDM – D:\Internet Download Manager\IEGetAll.htm
O8 – Extra context menu item: Download using FlashGet – D:\yas program\FlashGet\jc_link.htm
O8 – Extra context menu item: Download with IDM – D:\Internet Download Manager\IEExt.htm
O8 – Extra context menu item: E&xport to Microsoft Excel – res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 – Extra context menu item: Similar Pages – res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 – Extra context menu item: Translate Page into English – res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 – Extra context menu item: Yahoo! &Dictionary – file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 – Extra context menu item: Yahoo! &Maps – file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 – Extra context menu item: Yahoo! &SMS – file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 – Extra button: (no name) – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 – Extra ‘Tools’ menuitem: Sun Java Console – {08B0E5C0-4FCB-11CF-AAA5-00401C608501} – C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 – Extra button: Web Anti-Virus – {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 – Extra button: Yahoo! Services – {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} – C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 – Extra button: CADE – {605E5D27-BFA0-471F-87ED-98A2623D633C} – C:\Program Files\CADE\Web\new.htm
O9 – Extra button: Research – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 – Extra button: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – D:\yas program\Trillian\ICQLite\ICQLite.exe
O9 – Extra ‘Tools’ menuitem: ICQ Lite – {B863453A-26C3-4e1f-A54D-A2CD196348E9} – D:\yas program\Trillian\ICQLite\ICQLite.exe
O9 – Extra button: FlashGet – {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} – D:\YASPRO~1\FLASHGET\flashget.exe
O9 – Extra ‘Tools’ menuitem: &FlashGet – {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} – D:\YASPRO~1\FLASHGET\flashget.exe
O9 – Extra button: Yahoo! Messenger – {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} – C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 – Extra ‘Tools’ menuitem: Yahoo! Messenger – {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} – C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O9 – Extra ‘Tools’ menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:\Program Files\Messenger\msmsgs.exe
O16 – DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) – http://www.drivershq.com/DD_v4.CAB
O16 – DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) – http://go.microsoft.com/fwlink/?linkid=39204
O16 – DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) – https://signup.msn.com/pages/MsnInstC.cab
O16 – DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} – http://ak.imgfarm.com/images/nocache…up1.0.0.15.cab
O16 – DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) – http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 – DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) – http://us.chat1.yimg.com/us.yimg.com…45/yacscom.cab
O16 – DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) – C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 – DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) – http://www.cult3d.com/download/cult.cab
O16 – DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) – http://mp1.mplay.oberon-media.com/client/flashnet.cab
O16 – DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) – http://security.symantec.com/sscv6/S…/bin/cabsa.cab
O16 – DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) – http://update.microsoft.com/microsof…?1129009845078
O16 – DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) – http://www3.ca.com/securityadvisor/v…fo/webscan.cab
O16 – DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) – http://chat.yahoo.com/cab/yacsui.cab
O16 – DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) – http://www.crucial.com/controls/cpcScanner.cab
O16 – DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) – http://messenger.msn.com/download/Ms…Downloader.cab
O16 – DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) – http://www.windowsecurity.com/trojanscan/axscan.cab
O16 – DPF: {CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0_04) -
O16 – DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) – http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 – DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) – http://chat.msn.com/controls/msnchat45.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{820741F3-0DC6-46FE-A9C7-166A1F683B2C}: NameServer = 202.123.2.6 202.123.2.11
O18 – Protocol: livecall – {828030A1-22C1-4009-854F-8E305202313F} – C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 – Protocol: msnim – {828030A1-22C1-4009-854F-8E305202313F} – C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 – AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 – Winlogon Notify: klogon – C:\WINDOWS\system32\klogon.dll
O20 – Winlogon Notify: WgaLogon – C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 – SSODL: WPDShServiceObj – {AAA288BA-9A4C-45B0-95D7-94D524869DB5} – C:\WINDOWS\system32\WPDShServiceObj.dll
O23 – Service: avast! iAVS4 Control Service (aswUpdSv) – Unknown owner – D:\Avast4\aswUpdSv.exe
O23 – Service: avast! Antivirus – Unknown owner – D:\Avast4\ashServ.exe
O23 – Service: avast! Mail Scanner – Unknown owner – D:\Avast4\ashMaiSv.exe” /service (file missing)
O23 – Service: avast! Web Scanner – Unknown owner – D:\Avast4\ashWebSv.exe” /service (file missing)
O23 – Service: AVG Anti-Spyware Guard – Anti-Malware Development a.s. – D:\AVG Anti-Spyware 7.5\guard.exe
O23 – Service: Kaspersky Internet Security 6.0 (AVP) – Unknown owner – C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe” -r (file missing)
O23 – Service: iPodService – Apple Computer, Inc. – D:\yas program\iopod\iPod\bin\iPodService.exe
O23 – Service: TrueVector Internet Monitor (vsmon) – Zone Labs, LLC – C:\WINDOWS\system32\ZONELABS\vsmon.exe
Incoming search terms for the article:
Similar articles
- Computer becomes real slow, but not sure whats wrong
This few days my computer has become really laggy, but when I used Ad-aware and Spybot S&D they didn’t find anything. So please help me check and see if my logfile is clean, thanks in advance. here’s the logfile: Logfile of HijackThis v1.99.1 Scan saved at 11:23:33 PM, on 6/7/2005 Platform:
... - PC running SOOOOOO slow
Right new read out and I have deleted loads of stuff to free up C: space. Logfile of HijackThis v1.97.5 Scan saved at 20:45:15, on 18/03/2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\Executive Software\Diskeeper\DkService.exe C:\Program
... - PC running extremely slow [RESOLVED]
my PC is running very slow… but I cant seem to find out what is the main problem. Can anyone help me on this problem? Thank alot. Anyway, here is myhijack log: Logfile of HijackThis v1.99.1 Scan saved at 11:51:14 PM, on 12/2/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet
... - Computer slow + freezes
hello, Lately my computer was driving me crazy, it becomes very slow and freezes a lot to the point i have to shut it down and turn it back On. I did some clean up with AD AWARE SE and SPYBOT, but I still have the same issue. here is a scan with hijackthis that
... - Computer & Internet running slow
My system has been running slow and on the internet pages load slower and slower. Dell 2400 P4 2.2 512 ram 40g HD Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 6:18:14 PM, on 4/5/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe
...