Slow download. Unsure the source.

By siegristrm · 7 replies
Aug 20, 2011
  1. Hey, I know I'm supposed to provide a bunch of information, but there wasn't an actual forum (that I could see) for internet or performance issues. I'm unsure if I have a virus (I don't think I do), but I need to find out what is making my D/L speed slower than 30KB/s and usually around 10 KB/s. If you could tell me what to download (although it'll take forever) to give information necessary to figuring this out, I'll do it. I've worked with people on these forums before and they've always been truly helpful.

    An example of some of my issues are:

    1.) Loading a Youtube vid @ 360p, and not having a consistent stream. So, I pause it, let it load to full, and then come back to play it. However, when I play it, it stops and starts loading again (even though the grey "loaded" bar is filled).

    2.) I download software/updates/patches and it starts off fast at around 200+KB/s, then dramatically drops until it is idling around 10KB/s. Causing a 10 minute patch to be a 24 hour process.

    3.) Some games played online hang. This is most common for me in "League of Legends", but also when playing Civilization5 with my buddy online.

    4.) When clicking a link, I sometimes have to click it twice for it to actually load. Often one click just gives it the "Thinking" circle.

    I have attached my DXdiag to this for my PC setup. Currently, I'm in Japan, but we are running FiberOptic, at supposedly 100+Mb/s or so, but as you can tell, I'm not feeling it.

    Thank you for any help you can provide.

    Attached Files:

  2. Broni

    Broni Malware Annihilator Posts: 54,258   +383

    In this forum we can only check if your computer is clean.

    If you want us to do it....

    Please, complete all steps listed here:
    Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
    Attached logs won't be reviewed.

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
  3. siegristrm

    siegristrm TS Rookie Topic Starter Posts: 49

    Ok, thank you. I'm working on d/l the stuff now, but it's almost 6am and I have work early, so I'm going to reply tomorrow. Thank you for replying to me though :D
  4. Broni

    Broni Malware Annihilator Posts: 54,258   +383

    No problem :)
  5. siegristrm

    siegristrm TS Rookie Topic Starter Posts: 49

    Ok, took a while to d/l that GMER thing, but I have updated stuffs.


    Malwarebytes' Anti-Malware

    Database version: 7520

    Windows 6.1.7601 Service Pack 1
    Internet Explorer 8.0.7601.17514

    8/21/2011 3:17:59 AM
    mbam-log-2011-08-21 (03-17-59).txt

    Scan type: Quick scan
    Objects scanned: 188258
    Time elapsed: 6 minute(s), 17 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)




    DDS (Ver_2011-06-23.01) - NTFSAMD64
    Internet Explorer: 8.0.7601.17514
    Run by Robert at 1:04:00 on 2011-08-24
    Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1041.18.4094.2401 [GMT 9:00]
    AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    ============== Running Processes ===============
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Program Files (x86)\Uniblue\DriverScanner\dsmonitor.exe
    C:\Program Files (x86)\Windows Sidebar\sidebar.exe
    C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GetGoDM.exe
    C:\Program Files (x86)\AVG\AVG10\avgnsa.exe
    C:\Program Files (x86)\AVG\AVG10\avgemca.exe
    C:\Program Files (x86)\AVG\AVG10\avgtray.exe
    C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    C:\Program Files (x86)\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
    C:\Program Files (x86)\AVG\AVG10\avgcsrva.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\ 3\program\soffice.exe
    C:\Program Files (x86)\ 3\program\soffice.bin
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
    C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
    C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\\deploy\LoLLauncher.exe
    C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\\deploy\LolClient.exe
    ============== Pseudo HJT Report ===============
    mWinlogon: Userinit=userinit.exe
    BHO: GetGo URLCatch: {0315aa2c-10c7-4504-a1c4-f552aba8a095} - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\URLCatch.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB: GetGo Toolbar: {075bbe29-fec0-404a-a459-ff58713616fa} - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GGToolBand.dll
    uRun: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
    uRun: [GetGoDM] C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GetGoDM.exe /minimized:
    mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GGCatch.htm
    IE: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GGCatchAll.htm
    IE: &GetGo Toolbar Search - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
    IE: {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GetGoDM.exe
    IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://
    DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://
    TCP: DhcpNameServer =
    TCP: Interfaces\{A671DF3D-409A-4F35-8C90-786EC2F42134} : DhcpNameServer =
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    BHO-X64: GetGo URLCatch: {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\URLCatch.dll
    BHO-X64: GetGo URL Catcher (dont remove!) - No File
    BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    BHO-X64: AcroIEHelperStub - No File
    BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
    BHO-X64: IESiteBlocker.NavFilter - No File
    BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
    BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
    TB-X64: GetGo Toolbar: {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GGToolBand.dll
    mRun-x64: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
    IE-X64: {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files (x86)\GetGo Software\GetGo Download Manager\GetGoDM.exe
    ================= FIREFOX ===================
    FF - ProfilePath - C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\4nu23pvw.default\
    FF - prefs.js: browser.startup.homepage - hxxp://||
    FF - prefs.js: network.proxy.type - 0
    FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox4\components\avgssff4.dll
    FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox4\components\avgssff5.dll
    FF - component: C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\4nu23pvw.default\extensions\{1d09b5e5-973b-47d3-b9da-5579bda6eb62}\components\RadioWMPCoreGecko19.dll
    FF - component: C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\4nu23pvw.default\extensions\{1d09b5e5-973b-47d3-b9da-5579bda6eb62}\components\RadioWMPCoreGecko5.dll
    FF - component: C:\Users\Robert\AppData\Roaming\Mozilla\Firefox\Profiles\4nu23pvw.default\extensions\{1d09b5e5-973b-47d3-b9da-5579bda6eb62}\components\RadioWMPCoreGecko6.dll
    FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
    FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
    FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
    FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
    FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    ============= SERVICES / DRIVERS ===============
    R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
    R1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
    R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
    R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752]
    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
    R2 ezGOSvc;Easybits GO Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2009-7-14 20992]
    R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-6-23 2255464]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-8-3 379496]
    R3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
    R3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
    R3 LVRS64;Logicool RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs64.sys --> C:\Windows\system32\DRIVERS\lvrs64.sys [?]
    R3 LVUVC64;Logicool Qcam Pro 9000(UVC);C:\Windows\system32\DRIVERS\lvuvc64.sys --> C:\Windows\system32\DRIVERS\lvuvc64.sys [?]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S3 fssfltr;fssfltr;C:\Windows\system32\DRIVERS\fssfltr.sys --> C:\Windows\system32\DRIVERS\fssfltr.sys [?]
    S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2011-5-13 1492840]
    S3 LVPr2M64;Logicool LVPr2M64 Driver;C:\Windows\system32\DRIVERS\LVPr2M64.sys --> C:\Windows\system32\DRIVERS\LVPr2M64.sys [?]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
    S4 LVPrcS64;Process Monitor;C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe [2010-5-7 197976]
    S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
    =============== Created Last 30 ================
    2011-08-14 12:09:18 -------- d-----w- C:\Users\Robert\AppData\Local\Funcom
    2011-08-14 12:09:01 -------- d-----w- C:\ProgramData\media center programs
    2011-08-14 12:08:59 -------- d-----w- C:\Program Files (x86)\Funcom
    2011-08-14 11:31:19 -------- d-----w- C:\Downloads
    2011-08-10 02:35:58 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2011-08-10 02:35:58 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2011-08-10 02:35:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2011-08-09 15:17:38 142296 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
    2011-08-09 15:17:37 89048 ----a-w- C:\Program Files (x86)\Mozilla Firefox\libEGL.dll
    2011-08-09 15:17:37 781272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll
    2011-08-09 15:17:37 465880 ----a-w- C:\Program Files (x86)\Mozilla Firefox\libGLESv2.dll
    2011-08-09 15:17:37 2106216 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_43.dll
    2011-08-09 15:17:37 1998168 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_43.dll
    2011-08-09 15:17:37 1850328 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    2011-08-09 15:17:37 15832 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll
    2011-08-07 16:17:36 -------- d-----w- C:\Users\Robert\AppData\Local\Arktos
    2011-08-07 16:17:35 -------- d-----w- C:\Users\Robert\AppData\Local\CrashRpt
    2011-08-04 17:34:13 -------- d-----w- C:\Users\Robert\AppData\Roaming\GetGo Software
    2011-08-04 17:34:02 -------- d-----w- C:\Program Files (x86)\GetGo Software
    2011-08-04 17:31:17 74272 ----a-w- C:\Windows\System32\RtNicProp64.dll
    2011-08-04 17:31:17 539240 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
    2011-08-04 17:31:17 107552 ----a-w- C:\Windows\System32\RTNUninst64.dll
    2011-08-04 17:01:02 -------- d-----w- C:\ProgramData\Uniblue
    2011-08-04 17:01:00 -------- d-----w- C:\Users\Robert\AppData\Roaming\Uniblue
    2011-08-04 17:00:56 -------- d-----w- C:\Program Files (x86)\Uniblue
    2011-08-02 18:31:54 311912 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
    2011-07-27 07:45:21 -------- d-----w- C:\Users\Robert\riotsGamesLogs
    ==================== Find3M ====================
    2011-08-16 15:17:50 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-07-22 05:22:26 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
    2011-07-22 04:54:18 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
    2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
    2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
    2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
    2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
    2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
    2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
    2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
    2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
    2011-07-06 10:52:42 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    2011-07-06 10:52:42 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
    2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
    2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
    2011-06-21 06:20:53 1188864 ----a-w- C:\Windows\System32\wininet.dll
    2011-06-21 05:28:33 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
    2011-06-20 04:59:01 80256 ----a-w- C:\Windows\SysWow64\ezGOSvc.dll
    2011-06-20 04:59:01 663424 ----a-w- C:\Windows\SysWow64\ezGOSvcApp.exe
    2011-06-15 10:02:23 212992 ----a-w- C:\Windows\System32\odbctrac.dll
    2011-06-15 10:02:23 163840 ----a-w- C:\Windows\System32\odbccp32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccu32.dll
    2011-06-15 10:02:23 106496 ----a-w- C:\Windows\System32\odbccr32.dll
    2011-06-15 08:55:19 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
    2011-06-15 08:55:19 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
    2011-06-15 08:55:19 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
    2011-06-15 08:55:19 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
    2011-06-15 08:55:19 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
    2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
    2011-04-13 16:32:22 40445 ----a-w- C:\Program Files (x86)\uninstall.exe
    2011-04-02 10:02:10 79024 ----a-w- C:\Program Files (x86)\fraps64.dat
    2011-04-02 10:02:10 253104 ----a-w- C:\Program Files (x86)\fraps32.dll
    2011-04-02 10:02:10 201904 ----a-w- C:\Program Files (x86)\fraps64.dll
    2011-04-02 10:02:08 2550960 ----a-w- C:\Program Files (x86)\fraps.exe
    2011-04-02 10:00:10 163840 ----a-w- C:\Program Files (x86)\frapslcd.dll
    2011-01-18 08:53:32 2994688 ----a-w- C:\Program Files (x86)\openofficeorg33.msi
    2011-01-18 08:52:10 475016 ----a-w- C:\Program Files (x86)\setup.exe
    2009-07-14 01:39:53 398848 --sha-w- C:\Windows\Windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
    2009-07-14 01:14:45 396800 --sha-w- C:\Windows\Windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
    ============= FINISH: 1:04:46.64 ===============


    DDS (Ver_2011-06-23.01)
    Microsoft Windows 7 Ultimate
    Boot Device: \Device\HarddiskVolume1
    Install Date: 4/13/2011 2:02:10 AM
    System Uptime: 8/23/2011 11:09:01 PM (2 hours ago)
    Motherboard: Gigabyte Technology Co., Ltd. | | GA-MA78GPM-UD2H
    Processor: AMD Athlon(tm) 7850 Dual-Core Processor | Socket M2 | 2800/200mhz
    ==== Disk Partitions =========================
    A: is Removable
    C: is FIXED (NTFS) - 466 GiB total, 242.356 GiB free.
    D: is CDROM (UDF)
    E: is Removable
    ==== Disabled Device Manager Items =============
    ==== System Restore Points ===================
    RP82: 8/2/2011 4:53:04 PM - Scheduled Checkpoint
    RP83: 8/5/2011 2:30:53 AM - Installed Realtek Ethernet Controller Driver
    RP84: 8/6/2011 9:17:41 AM - Installed DirectX
    RP85: 8/6/2011 12:25:17 PM - Installed DirectX
    RP86: 8/6/2011 12:25:46 PM - Installed Microsoft Visual C++ 2005 Redistributable
    RP87: 8/7/2011 10:57:42 PM - Installed DirectX
    RP88: 8/10/2011 12:53:40 PM - Windows Update
    RP89: 8/17/2011 8:03:42 PM - Scheduled Checkpoint
    RP90: 8/19/2011 2:17:40 PM - Removed LogMeIn Hamachi
    RP91: 8/21/2011 6:25:32 AM - Installed NVIDIA 3D Vision Controller Driver
    ==== Installed Programs ======================
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader X (10.1.0)
    Age of Conan - Hyborian Adventures
    Alliance of Valiant Arms
    Champions Online: Free For All
    EasyBits GO
    EVEREST Home Edition v2.20
    Fable III
    Forsaken World
    Fraps (remove only)
    GetGo Download Manager
    Global Agenda
    GOM Player
    Java Auto Updater
    Java(TM) 6 Update 26
    Junk Mail filter update
    Logitech Vid HD
    Logitech Webcam Software
    LWS Facebook
    LWS Gallery
    LWS Help_main
    LWS Launcher
    LWS Motion Detection
    LWS Pictures And Video
    LWS Twitter
    LWS Video Mask Maker
    LWS Webcam Software
    LWS WLM Plugin
    LWS YouTube Plugin
    Malwarebytes' Anti-Malware version
    Mesh Runtime
    Messenger Companion
    Microsoft Games for Windows - LIVE Redistributable
    Microsoft Games for Windows Marketplace
    Microsoft Silverlight
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft XNA Framework Redistributable 3.1
    Mozilla Firefox 5.0.1 (x86 en-US)
    Mumble 1.2.3
    NVIDIA 3D Vision Controller Driver
    NVIDIA PhysX
    NVIDIA Stereoscopic 3D Driver
    Pando Media Booster
    Realtek Ethernet Controller Driver
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile Language Pack - ??? (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile Language Pack - ??? (KB2518870)
    Skype™ 5.3
    Spiral Knights
    Team Fortress 2
    Uniblue DriverScanner
    Visual Studio 2008 x64 Redistributables
    War Inc. Battlezone
    WinDirStat 1.1.2
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Installer
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Wise Disk Cleaner 5.93
    Wise Registry Cleaner 5.9.4
    WLAN 802.11g mini-PCI Module
    ==== Event Viewer Messages From Past Week ========
    8/22/2011 2:16:25 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
    8/20/2011 1:12:29 AM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
    8/20/2011 1:12:29 AM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535.
    ==== End Of File ===========================
  6. Broni

    Broni Malware Annihilator Posts: 54,258   +383

    I still need that GMER log.
  7. siegristrm

    siegristrm TS Rookie Topic Starter Posts: 49


    GMER -
    Rootkit scan 2011-08-25 00:52:53
    Windows 6.1.7601 Service Pack 1
    Running: jhok7f5n.exe

    ---- Files - GMER 1.0.15 ----

    File C:\Users\Robert\AppData\Local\Temp\fla9931.tmp 319098 bytes

    ---- EOF - GMER 1.0.15 ----

    Is it supposed to be this short?
  8. Broni

    Broni Malware Annihilator Posts: 54,258   +383

    Looks fine.

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan:

    On completion of the scan click "Save log", save it to your desktop and post in your next reply:

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.


    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
    Use AppRemover to uninstall it:
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.

    Make sure, you re-enable your security programs, when you're done with Combofix.


    If, for some reason, Combofix refuses to run, try one of the following:

    1. Run Combofix from Safe Mode.

    2. Delete Combofix file, download fresh one, but rename combofix.exe to yourname.exe BEFORE saving it to your desktop.
    Do NOT run it yet.

    Please download and run the below tool named Rkill (courtesy of which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...