Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stop making mediocre tutorials.The best tutorials are video! Camtasia Studio makes it easy to create engaging, buzz-building screen videos at any size, in any popular format. Download the free trial!
  #31  
Old March 25th, 2008, 08:50 AM
Porthos's Avatar
Porthos Porthos is offline
Malware Warrior /AV forum Mod
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Nov 2006
Location: San Antonio Tx
Posts: 1,033 Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 1 Week 1 Day 17 h 27 m 54 sec
Reputation Power: 363
Quote:
Originally Posted by mahroch
Hi, just want to tell you my impressions from usual working. I tried to install my bought AVG, but even if I was successfull I was not able to run resident shield, that's quite bad ...

As well the system is now super slow. Every small actions requires some 20 seconds of waiting ... open image, move in Outloook from one email to another, change tabs in IE/Mozilla ... everything is soooooo sloooooow, the LED of "HDD is working" is on all the time after the click ...

I don't know why and what to do ... :-( I could format and reinstall whole system, but after all that work we did on that I'd like to do it any other possible way ....

thanx

m.


You have a serious batch of infections. The unseen damage to the operating system and programs can not always be predicted.

You also have a serious amount of programs starting at startup that are NOT needed slowing your system down.
__________________
O'Neill: "So, we basically saved your whole planet, right?"
Chancellor: "Yes."
O'Neill: "Are you, therefore, indebted to us in any modest way?"
Chancellor: "I suppose that is the case."
O'Neill: "So how 'bout the blueprints to build one of those ion cannons?"
Chancellor: "You have been told our policy. That has not changed."

Reply With Quote
  #32  
Old March 25th, 2008, 02:18 PM
mahroch mahroch is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2008
Posts: 26 mahroch User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 37 m 21 sec
Reputation Power: 0
result

in other words it means that some damages cannot be fixed. As actual status of working speed is not satisfying only way is to reainstall whole system. Is that correct?

If it is so, I'll do it asap to have all the work back as soon as possible ...

thanx for help ...

m.

Reply With Quote
  #33  
Old March 25th, 2008, 02:27 PM
Porthos's Avatar
Porthos Porthos is offline
Malware Warrior /AV forum Mod
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Nov 2006
Location: San Antonio Tx
Posts: 1,033 Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 1 Week 1 Day 17 h 27 m 54 sec
Reputation Power: 363
Quote:
As actual status of working speed is not satisfying only way is to reainstall whole system. Is that correct?


Not always.

Lets look at what is running and installed

Download Deckard's System Scanner. HERE

1. Close all applications and windows.
2. Double-click on dss.exe to run it, and follow the prompts.
3. When the scan is complete, a text file will open - Main.txt
4. Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of Main.txt in your thread here.
5. A folder, C:\Deckard, will also open. In it will be another text file, Extra.txt.
6. Attach Extra.txt to your post.

Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.

What Deckard's System Scanner will do:

* create a new System Restore point in Windows XP and Vista.
* clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
* check some important areas of your system and produce a report for your analyst to review. Deckard's System Scanner automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.


When you get the two notepad documents, click somewhere inside the notepad document and hold CTRL/Control and press A then C. This will "select all" and "copy" the text.

Please post both of the logs.

Reply With Quote
  #34  
Old March 25th, 2008, 02:49 PM
mahroch mahroch is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2008
Posts: 26 mahroch User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 37 m 21 sec
Reputation Power: 0
main.txt

Deckard's System Scanner v20071014.68
Run by Maros on 2008-03-25 20;47;21
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Maros.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20;47;33, on 25.3.2008
Platform; Windows XP SP2 (WinNT 5.01.2600)
MSIE; Internet Explorer v7.00 (7.00.6000.16608)
Boot mode; Normal

Running processes;
C;\WINDOWS\System32\smss.exe
C;\WINDOWS\system32\winlogon.exe
C;\WINDOWS\system32\services.exe
C;\WINDOWS\system32\lsass.exe
C;\WINDOWS\system32\svchost.exe
C;\WINDOWS\System32\svchost.exe
C;\WINDOWS\system32\svchost.exe
C;\WINDOWS\System32\WLTRYSVC.EXE
C;\WINDOWS\System32\bcmwltry.exe
C;\WINDOWS\system32\spoolsv.exe
C;\WINDOWS\Explorer.EXE
C;\WINDOWS\system32\igfxsrvc.exe
C;\WINDOWS\system32\hkcmd.exe
C;\WINDOWS\system32\igfxpers.exe
C;\WINDOWS\stsystra.exe
C;\Program Files\Synaptics\SynTP\SynTPEnh.exe
C;\WINDOWS\system32\WLTRAY.exe
C;\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C;\Program Files\Dell\Media Experience\DMXLauncher.exe
C;\WINDOWS\system32\dla\tfswctrl.exe
C;\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C;\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C;\Program Files\iTunes\iTunesHelper.exe
C;\Program Files\Common Files\Real\Update_OB\realsched.exe
C;\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C;\WINDOWS\system32\ctfmon.exe
C;\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C;\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C;\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C;\WINDOWS\System32\svchost.exe
C;\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C;\WINDOWS\system32\svchost.exe
C;\WINDOWS\system32\svchost.exe
C;\Program Files\iPod\bin\iPodService.exe
C;\Program Files\MSN Messenger\usnsvc.exe
C;\Documents and Settings\Maros\Desktop\dss.exe
C;\PROGRA~1\HIJACK~1\Maros.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file;///C;/www/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http;//go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http;//go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http;//go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http;//go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http;//www1.euro.dell.com/content/default.aspx?c=sk&l=sk&s=gen
O2 - BHO; Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C;\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO; Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C;\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO; RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C;\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO; DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C;\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO; SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C;\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO; IE DOM Explorer - {CC7E636D-39AA-49b6-B511-65413DA137A1} - c;\Program Files\IE7\Adons\Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar; Developer Toolbar - {CC962137-2E78-4f94-975E-FC0C07DBD78F} - c;\Program Files\IE7\Adons\Developer Toolbar\IEDevToolbar.dll
O3 - Toolbar; Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C;\PROGRA~1\Zend\ZENDST~1\bin\ZENDIE~1.DLL
O4 - HKLM\..\Run; [igfxtray] C;\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run; [igfxhkcmd] C;\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run; [igfxpers] C;\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run; [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run; [SynTPEnh] C;\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run; [Dell QuickSet] C;\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run; [Broadcom Wireless Manager UI] C;\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run; [DVDLauncher] "C;\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run; [DMXLauncher] C;\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run; [ISUSPM Startup] "C;\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run; [ISUSScheduler] "C;\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run; [MpsOnn] C;\WINDOWS\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe
O4 - HKLM\..\Run; [dla] C;\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run; [ICQ Lite] "C;\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run; [SSBkgdUpdate] "C;\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run; [PaperPort PTD] C;\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run; [IndexSearch] C;\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run; [OpwareSE2] "C;\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run; [NeroFilterCheck] C;\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run; [QuickTime Task] "C;\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run; [iTunesHelper] "C;\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run; [ShaPlus Bandwidth Meter] "C;\Program Files\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter" /s
O4 - HKLM\..\Run; [Adobe Photo Downloader] "C;\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKLM\..\Run; [TkBellExe] "C;\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run; [SunJavaUpdateSched] "C;\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run; [AVG7_CC] C;\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run; [ctfmon.exe] C;\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run; [MsnMsgr] "C;\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run; [Switchboard] C;\Program Files\Switchboard\Switchboard.exe
O4 - HKCU\..\Run; [DU Meter] C;\WINDOWS\system32\DUMeter.exe
O4 - HKCU\..\Run; [Right Web Monitor Pro] C;\Program Files\Right Web Monitor Pro\webmonpro.exe
O4 - HKUS\S-1-5-19\..\Run; [AVG7_Run] C;\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run; [AVG7_Run] C;\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run; [CTFMON.EXE] C;\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run; [AVG7_Run] C;\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run; [CTFMON.EXE] C;\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup; Microsoft Office Outlook 2003.lnk = ?
O4 - Startup; Total Commander.lnk = C;\Program Files\totalcmd\TOTALCMD.EXE
O4 - Global Startup; Adobe Gamma Loader.lnk = C;\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item; &Clean Traces - C;\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item; &Download with &DAP - C;\Program Files\DAP\dapextie.htm
O8 - Extra context menu item; Download &all with DAP - C;\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item; Download &Flash Movies - C;\Program Files\Flash Hunter\save.htm
O8 - Extra context menu item; Zend Studio - Debug current page - res;//C;\Program Files\Zend\ZendStudioClient5\bin\ZendIEToolbar.dll/DebugCurrent.html
O8 - Extra context menu item; Zend Studio - Debug next page - res;//C;\Program Files\Zend\ZendStudioClient5\bin\ZendIEToolbar.dll/DebugNext.html
O9 - Extra button; iOpus iMacros - {0483894E-2422-45E0-8384-021AFF1AF3CD} - C;\Program Files\IE7\Adons\iMacros\imacros.dll (file missing)
O9 - Extra button; (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C;\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem; Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C;\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button; (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C;\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem; Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C;\WINDOWS\bdoscandel.exe
O9 - Extra button; Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C;\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button; Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C;\PROGRA~1\Zend\ZENDST~1\bin\ZENDIE~1.DLL
O9 - Extra 'Tools' menuitem; Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C;\PROGRA~1\Zend\ZENDST~1\bin\ZENDIE~1.DLL
O9 - Extra button; ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C;\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem; ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C;\Program Files\ICQLite\ICQLite.exe
O9 - Extra button; (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C;\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem; @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C;\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button; Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C;\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem; Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C;\Program Files\Messenger\msmsgs.exe
O9 - Extra button; Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C;\Program Files\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem; &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - C;\Program Files\Flash Hunter\save.htm (file missing) (HKCU)
O16 - DPF; {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http;//download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF; {9656B666-992F-4D74-8588-8CA69E97D90C} - http;//www.commonname.com/eng/oneclick/uninstbb.cab
O16 - DPF; {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http;//acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF; {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http;//fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service; Adobe LM Service - Adobe Systems - C;\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service; Apple Mobile Device - Apple, Inc. - C;\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service; AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C;\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service; AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C;\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service; Google Updater Service (gusvc) - Google - C;\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service; iPod Service - Apple Inc. - C;\Program Files\iPod\bin\iPodService.exe
O23 - Service; Macromedia Licensing Service - Unknown owner - C;\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service; NICCONFIGSVC - Dell Inc. - C;\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service; ServiceLayer - Nokia. - C;\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service; Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C;\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 11181 bytes

-- Files created between 2008-02-25 and 2008-03-25 -----------------------------

2008-03-25 09;38;45 0 d-------- C;\Documents and Settings\All Users\Application Data\Grisoft
2008-03-24 18;33;36 0 d-------- C;\MzCombo
2008-03-24 10;14;26 0 d-------- C;\WINDOWS\system32\ActiveScan
2008-03-24 09;22;34 0 d-------- C;\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-24 09;22;26 0 d-------- C;\Program Files\SUPERAntiSpyware
2008-03-24 09;22;25 0 d-------- C;\Documents and Settings\Maros\Application Data\SUPERAntiSpyware.com
2008-03-23 20;26;49 0 d-------- C;\WINDOWS\BDOSCAN8
2008-03-23 20;17;46 0 d-------- C;\Documents and Settings\Maros\Application Data\Malwarebytes
2008-03-23 20;17;22 0 d-------- C;\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-23 20;17;21 0 d-------- C;\Program Files\Malwarebytes' Anti-Malware
2008-03-23 09;07;17 68096 --a------ C;\WINDOWS\system32\zip.exe
2008-03-23 09;07;17 98816 --a------ C;\WINDOWS\system32\sed.exe
2008-03-23 09;07;17 80412 --a------ C;\WINDOWS\system32\grep.exe
2008-03-23 09;07;17 73728 --a------ C;\WINDOWS\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-03-22 15;10;34 0 d-------- C;\Program Files\Alwil Software
2008-03-14 09;53;58 0 d-------- C;\Program Files\Media Art
2008-03-14 08;45;55 0 d-------- C;\Documents and Settings\Maros\Application Data\AdobeAUM
2008-02-28 15;29;43 0 d-------- C;\Program Files\ProStockMaster_DB
2008-02-26 15;32;59 0 d-------- C;\Program Files\ProStockMaster
2008-02-26 10;03;33 0 d-------- C;\Program Files\Stock Photo Express
2008-02-26 09;29;59 0 d-------- C;\Program Files\onOne Software


-- Find3M Report ---------------------------------------------------------------

2008-03-25 10;50;07 0 d-------- C;\Program Files\Common Files\Wise Installation Wizard
2008-03-25 09;05;42 0 d-------- C;\Program Files\iTunes
2008-03-24 20;53;27 0 d--h----- C;\Program Files\InstallShield Installation Information
2008-03-24 20;50;14 0 d-------- C;\Program Files\Java
2008-03-24 11;43;31 0 d-------- C;\Program Files\MSN Messenger
2008-03-24 11;31;11 0 d-------- C;\Program Files\DAP
2008-03-23 09;15;00 0 d-------- C;\Program Files\Bandwidth Monitor
2008-03-22 13;50;12 0 d-------- C;\Program Files\CZDCplusplus
2008-03-22 13;01;52 0 d-------- C;\Documents and Settings\Maros\Application Data\AVG7
2008-03-22 11;29;32 0 d-------- C;\Program Files\eMule
2008-03-21 11;59;48 0 d-------- C;\Documents and Settings\Maros\Application Data\OpenOffice.org2
2008-03-20 10;33;09 0 d-------- C;\Documents and Settings\Maros\Application Data\Adobe
2008-03-20 07;56;02 0 d-------- C;\Documents and Settings\Maros\Application Data\Real
2008-03-14 17;28;59 9550 --ahs---- C;\WINDOWS\system32\KGyGaAvL.sys
2008-02-28 23;01;20 0 d-------- C;\Program Files\Mp3tag
2008-02-27 22;25;08 0 d-------- C;\Documents and Settings\Maros\Application Data\Skype
2008-02-22 11;30;38 0 d-------- C;\Program Files\AviSynth 2.5
2008-02-22 11;29;53 0 d-------- C;\Program Files\SuperDVD Video Editor
2008-02-21 22;06;12 0 d-------- C;\Documents and Settings\Maros\Application Data\HighAndes
2008-02-21 19;26;29 0 d-------- C;\Program Files\VideoThangTM
2008-02-16 15;47;46 0 d-------- C;\Program Files\totalcmd
2008-02-16 14;55;46 0 d-------- C;\Program Files\strong
2008-02-16 14;54;37 0 d-------- C;\Program Files\7-Zip
2008-02-14 22;30;50 0 d-------- C;\Program Files\FBOffline
2008-02-14 22;29;58 0 d-------- C;\Program Files\BSplayer
2008-02-14 22;29;58 0 d-------- C;\Documents and Settings\Maros\Application Data\BSplayer
2008-02-14 22;29;42 0 d-------- C;\Program Files\BrowserSizer
2008-02-14 15;45;58 0 d-------- C;\Program Files\Common Files
2008-02-14 15;45;58 0 d-------- C;\Program Files\Common Files\xing shared
2008-02-14 15;45;54 0 d-------- C;\Program Files\Real
2008-02-14 15;45;39 0 d-------- C;\Program Files\Common Files\Real
2008-02-12 15;18;56 0 d-------- C;\Program Files\NoiseNinja2
2008-02-11 20;22;51 1736 --a------ C;\WINDOWS\checkip.dat
2008-02-07 13;41;57 0 d-------- C;\Program Files\ElcomSoft
2008-02-07 13;41;21 1024 --a------ C;\WINDOWS\system32\pwdremover.dat
2008-02-01 12;52;52 0 d-------- C;\Documents and Settings\Maros\Application Data\ACD Systems
2008-02-01 12;50;57 0 d-------- C;\Program Files\Common Files\ACD Systems
2008-02-01 12;50;40 0 d-------- C;\Program Files\ACD Systems
2008-01-28 11;52;22 0 d-------- C;\Program Files\Mozilla Sunbird
2008-01-19 20;43;01 45096 --a------ C;\Documents and Settings\Maros\Application Data\NMM-MetaData.db
2008-01-18 16;12;25 200 --a------ C;\WINDOWS\mirrorqws.dat
2008-01-18 16;12;25 200 --a------ C;\Program Files\chargeqws
2008-01-15 10;57;03 73216 --a------ C;\WINDOWS\ST6UNST.EXE <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-01-09 15;01;48 53248 --a------ C;\WINDOWS\bdoscandel.exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C;\WINDOWS\system32\igfxtray.exe" [13.12.2005 16;44]
"igfxhkcmd"="C;\WINDOWS\system32\hkcmd.exe" [13.12.2005 16;41]
"igfxpers"="C;\WINDOWS\system32\igfxpers.exe" [13.12.2005 16;45]
"SigmatelSysTrayApp"="stsystra.exe" [24.03.2006 16;30 C;\WINDOWS\stsystra.exe]
"SynTPEnh"="C;\Program Files\Synaptics\SynTP\SynTPEnh.exe" [08.03.2006 11;48]
"Dell QuickSet"="C;\Program Files\Dell\QuickSet\Quickset.exe" [06.04.2006 14;58]
"Broadcom Wireless Manager UI"="C;\WINDOWS\system32\WLTRAY.exe" [19.12.2005 08;08]
"DVDLauncher"="C;\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [09.12.2005 20;29]
"DMXLauncher"="C;\Program Files\Dell\Media Experience\DMXLauncher.exe" [27.01.2005 01;02]
"ISUSPM Startup"="C;\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [11.08.2005 15;30]
"ISUSScheduler"="C;\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [11.08.2005 15;30]
"MpsOnn"="C;\WINDOWS\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe" [19.11.2001 19;14]
"dla"="C;\WINDOWS\system32\dla\tfswctrl.exe" [31.05.2005 04;33]
"ICQ Lite"="C;\Program Files\ICQLite\ICQLite.exe" [27.07.2006 19;12]
"SSBkgdUpdate"="C;\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [14.10.2003 09;22]
"PaperPort PTD"="C;\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [02.03.2004 08;29]
"IndexSearch"="C;\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [02.03.2004 08;42]
"OpwareSE2"="C;\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [08.05.2003 11;00]
"NeroFilterCheck"="C;\WINDOWS\system32\NeroCheck.exe" [09.07.2001 11;50]
"QuickTime Task"="C;\Program Files\QuickTime\QTTask.exe" [11.12.2007 10;56]
"iTunesHelper"="C;\Program Files\iTunes\iTunesHelper.exe" [11.12.2007 12;10]
"ShaPlus Bandwidth Meter"="C;\Program Files\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter /s" []
"Adobe Photo Downloader"="C;\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe" []
"TkBellExe"="C;\Program Files\Common Files\Real\Update_OB\realsched.exe" [14.02.2008 15;45]
"SunJavaUpdateSched"="C;\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22.02.2008 04;25]
"AVG7_CC"="C;\PROGRA~1\Grisoft\AVG7\avgcc.exe" [25.03.2008 09;38]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C;\WINDOWS\system32\ctfmon.exe" [04.08.2004 05;00]
"MsnMsgr"="C;\Program Files\MSN Messenger\MsnMsgr.exe" [19.01.2007 12;54]
"Switchboard"="C;\Program Files\Switchboard\Switchboard.exe" []
"DU Meter"="C;\WINDOWS\system32\DUMeter.exe" []
"Right Web Monitor Pro"="C;\Program Files\Right Web Monitor Pro\webmonpro.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Picasa Media Detector"=C;\Program Files\Picasa2\PicasaMediaDetector.exe
"Nokia.PCSync"="C;\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog

C;\Documents and Settings\Maros\Start Menu\Programs\Startup\
Microsoft Office Outlook 2003.lnk - C;\WINDOWS\Installer\{9011041B-6000-11D3-8CFE-0150048383C9}\outicon.exe [12.11.2007 11;05;50]
Total Commander.lnk - C;\Program Files\totalcmd\TOTALCMD.EXE [22.7.2006 15;10;05]

C;\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C;\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [7.10.2006 9;10;50]

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
Schedule


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{312c3853-188c-11db-8b0c-806d6172696f}]
AutoRun\command- D;\setup.exe




-- End of Deckard's System Scanner; finished at 2008-03-25 20;47;59 ------------

Reply With Quote
  #35  
Old March 25th, 2008, 02:52 PM
mahroch mahroch is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2008
Posts: 26 mahroch User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 37 m 21 sec
Reputation Power: 0
extra.txt is nt there

After running the dss.exe I get only main,txt, but no extra.txt.Did I do anything wrongly?

I wanted to tell you before, that I installed AVG and it is still not workig fully - I cannot run the resident shield and niether it is able to find out what date is the virus database from :-(

Reply With Quote
  #36  
Old March 25th, 2008, 04:14 PM
Porthos's Avatar
Porthos Porthos is offline
Malware Warrior /AV forum Mod
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Nov 2006
Location: San Antonio Tx
Posts: 1,033 Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 1 Week 1 Day 17 h 27 m 54 sec
Reputation Power: 363
Look in c\Deckard to find the extra text.

Reply With Quote
  #37  
Old March 26th, 2008, 05:08 PM
mahroch mahroch is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2008
Posts: 26 mahroch User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 37 m 21 sec
Reputation Power: 0
well ..

I looked there and there is only System Scanner folder and in there is main.txt. No extra.txt or anyting else.

I run it again, and the result is the same. No extra.txt nor anthyng else.

Any ideas?

m.

Reply With Quote
  #38  
Old March 26th, 2008, 05:25 PM
Porthos's Avatar
Porthos Porthos is offline
Malware Warrior /AV forum Mod
Dev Shed Beginner (1000 - 1499 posts)
 
Join Date: Nov 2006
Location: San Antonio Tx
Posts: 1,033 Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level)Porthos User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 1 Week 1 Day 17 h 27 m 54 sec
Reputation Power: 363
The following Bold Items can be disabled with MSconfig.



"igfxtray"="C;\WINDOWS\system32\igfxtray.exe" [13.12.2005 16;44]
"igfxhkcmd"="C;\WINDOWS\system32\hkcmd.exe" [13.12.2005 16;41]
"igfxpers"="C;\WINDOWS\system32\igfxpers.exe" [13.12.2005 16;45]
"SigmatelSysTrayApp"="stsystra.exe" [24.03.2006 16;30 C;\WINDOWS\stsystra.exe]
"SynTPEnh"="C;\Program Files\Synaptics\SynTP\SynTPEnh.exe" [08.03.2006 11;48]
"Dell QuickSet"="C;\Program Files\Dell\QuickSet\Quickset.exe" [06.04.2006 14;58]
"Broadcom Wireless Manager UI"="C;\WINDOWS\system32\WLTRAY.exe" [19.12.2005 08;08]
"DVDLauncher"="C;\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [09.12.2005 20;29]
"DMXLauncher"="C;\Program Files\Dell\Media Experience\DMXLauncher.exe" [27.01.2005 01;02]
"ISUSPM Startup"="C;\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [11.08.2005 15;30]
"ISUSScheduler"="C;\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [11.08.2005 15;30]
"MpsOnn"="C;\WINDOWS\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe" [19.11.2001 19;14]
"dla"="C;\WINDOWS\system32\dla\tfswctrl.exe" [31.05.2005 04;33]
"ICQ Lite"="C;\Program Files\ICQLite\ICQLite.exe" [27.07.2006 19;12]
"SSBkgdUpdate"="C;\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [14.10.2003 09;22]
"PaperPort PTD"="C;\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [02.03.2004 08;29]
"IndexSearch"="C;\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [02.03.2004 08;42]
"OpwareSE2"="C;\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [08.05.2003 11;00]
"NeroFilterCheck"="C;\WINDOWS\system32\NeroCheck.exe" [09.07.2001 11;50]
"QuickTime Task"="C;\Program Files\QuickTime\QTTask.exe" [11.12.2007 10;56]
"iTunesHelper"="C;\Program Files\iTunes\iTunesHelper.exe" [11.12.2007 12;10]

"ShaPlus Bandwidth Meter"="C;\Program Files\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter /s" []
"Adobe Photo Downloader"="C;\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe" []
"TkBellExe"="C;\Program Files\Common Files\Real\Update_OB\realsched.exe" [14.02.2008 15;45]
"SunJavaUpdateSched"="C;\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [22.02.2008 04;25]

"AVG7_CC"="C;\PROGRA~1\Grisoft\AVG7\avgcc.exe" [25.03.2008 09;38]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C;\WINDOWS\system32\ctfmon.exe" [04.08.2004 05;00]
"MsnMsgr"="C;\Program Files\MSN Messenger\MsnMsgr.exe" [19.01.2007 12;54]
"Switchboard"="C;\Program Files\Switchboard\Switchboard.exe" []
"DU Meter"="C;\WINDOWS\system32\DUMeter.exe" []
"Right Web Monitor Pro"="C;\Program Files\Right Web Monitor Pro\webmonpro.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Picasa Media Detector"=C;\Program Files\Picasa2\PicasaMediaDetector.exe
"Nokia.PCSync"="C;\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog



Then I would defrag the system.

Also how much RAM does this system have.

You can also adjust the power settings with the dell quickset program to high preformance so the processor does not clock down.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Help with not working antivirus/firewall/ ...


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

 Free IT White Papers!