1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: slow internet

Discussion in 'Windows XP' started by bilerr, Apr 22, 2010.

Thread Status:
Not open for further replies.
Advertisement
  1. bilerr

    bilerr Thread Starter

    Joined:
    Apr 22, 2010
    Messages:
    6
    Hello,
    My computer run very slow, especially the internet. I ran AVg regularly and also Rgistry repair. it fixed some of it but still slow. Will apriciate any help. Thanks

    HijackThis logfile:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:54:49, on 22/04/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\3B Software\Common\Scheduler\wcomschd.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\AVG\AVG9\avgfws9.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
    C:\Program Files\AVG\AVG9\avgtray.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.il/search?sour...ם&ie=UTF-8&rlz=1T4ADBS_enIL331IL331&q=igoogle
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: (no name) - {54B02808-B60E-44CD-A72D-9865117E4E62} - (no file)
    O2 - BHO: AGFormHelperObj Class - {6620E618-1AB9-4EB2-ACA4-CBBE9066DBE6} - C:\Program Files\agat\AGForm\AGFormsHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O3 - Toolbar: AGForms - {ed2e7de7-07db-4941-a06d-f780b93ba730} - C:\Program Files\agat\AGForm\AGForms.dll
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Registry Repair Pro.lnk = C:\Program Files\3B Software\Registry Repair Pro\RegistryRepairPro.exe
    O4 - Startup: Scheduler.lnk = C:\Program Files\3B Software\Common\Scheduler\wcomschd.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
    O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    O23 - Service: שירות Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe

    --
    End of file - 9186 bytes
     
  2. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,949
    First Name:
    Frank
    Start HijackThis, but don't run a scan.

    Click on the "Open The Misc Tools Section" button.

    Click on the "Open Uninstall Manager" button.

    Click on the "Save List" button.

    Save the "uninstall_list.txt" file somewhere. It'll then open in Notepad.

    Return here to your thread, then copy-and-paste the entire file here.

    -----------------------------------------------------------------

    What's the brand name, model name, and model number of your computer?

    How much RAM does it have?

    Are you using a 56K dial-up connection or a high-speed connection?

    -----------------------------------------------------------------
     
  3. bilerr

    bilerr Thread Starter

    Joined:
    Apr 22, 2010
    Messages:
    6
    the uninstall_List:
    32 Bit HP CIO Components Installer
    Acrobat.com
    Ad-Aware
    Ad-Aware
    Adobe AIR
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.1.1
    Adobe Shockwave Player 11.5
    AVG 9.0
    CCleaner (remove only)
    E-GOV.IL Sign&Verify Software - AGForm toolbar
    First Steps
    Glary Registry Repair 3.2.0.828
    Glary Utilities 2.15.0.738
    Google Toolbar for Internet Explorer
    Google Toolbar for Internet Explorer
    Google Update Helper
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB926239)
    HP Customer Participation Program 8.0
    HP Deskjet All-In-One Software 8.0
    HP Imaging Device Functions 8.0
    HP Photosmart Essential
    HP Solution Center 8.0
    HP Update
    HPSSupply
    Let's Imagine
    lupa 2.1
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Office Professional Edition 2003
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6 Service Pack 2 (KB973686)
    My Home
    NCH Toolbox
    Nero 7 Essentials
    neroxml
    NVIDIA Drivers
    Photodex Presenter
    Picasa 2
    ProShow Gold
    Realtek High Definition Audio Driver
    Registry Repair Pro
    Skype web features
    Skype™ 4.1
    Spelling Dictionaries Support For Adobe Reader 9
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Internet Explorer 8
    Windows Media Encoder 9 Series
    Windows Media Encoder 9 Series
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player 11
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    עדכון אבטחה עבור Windows Internet Explorer 8 (KB971961)‎
    עדכון אבטחה עבור Windows Internet Explorer 8 (KB972260)‎
    עדכון אבטחה עבור Windows Media Encoder‏ (KB954156)
    עדכון אבטחה עבור Windows Media Player‏ (KB911564)
    עדכון אבטחה עבור Windows Media Player‏ (KB952069)
    עדכון אבטחה עבור Windows Media Player‏ (KB954155)
    עדכון אבטחה עבור Windows Media Player‏ (KB968816)
    עדכון אבטחה עבור Windows Media Player‏ (KB973540)
    עדכון אבטחה עבור Windows Media Player 11‏ (KB954154)
    עדכון אבטחה עבור Windows Media Player 6.4‏ (KB925398)
    עדכון אבטחה עבור Windows Media Player 9‏ (KB936782)
    עדכון אבטחה עבור Windows XP (KB890046)‎
    עדכון אבטחה עבור Windows XP (KB893756)‎
    עדכון אבטחה עבור Windows XP (KB896358)‎
    עדכון אבטחה עבור Windows XP (KB896423)‎
    עדכון אבטחה עבור Windows XP (KB896428)‎
    עדכון אבטחה עבור Windows XP (KB899587)‎
    עדכון אבטחה עבור Windows XP (KB899591)‎
    עדכון אבטחה עבור Windows XP (KB900725)‎
    עדכון אבטחה עבור Windows XP (KB901017)‎
    עדכון אבטחה עבור Windows XP (KB901214)‎
    עדכון אבטחה עבור Windows XP (KB902400)‎
    עדכון אבטחה עבור Windows XP (KB905414)‎
    עדכון אבטחה עבור Windows XP (KB905749)‎
    עדכון אבטחה עבור Windows XP (KB908519)‎
    עדכון אבטחה עבור Windows XP (KB911562)‎
    עדכון אבטחה עבור Windows XP (KB911927)‎
    עדכון אבטחה עבור Windows XP (KB913580)‎
    עדכון אבטחה עבור Windows XP (KB914388)‎
    עדכון אבטחה עבור Windows XP (KB914389)‎
    עדכון אבטחה עבור Windows XP (KB918118)‎
    עדכון אבטחה עבור Windows XP (KB918439)‎
    עדכון אבטחה עבור Windows XP (KB920213)‎
    עדכון אבטחה עבור Windows XP (KB920670)‎
    עדכון אבטחה עבור Windows XP (KB920683)‎
    עדכון אבטחה עבור Windows XP (KB920685)‎
    עדכון אבטחה עבור Windows XP (KB923191)‎
    עדכון אבטחה עבור Windows XP (KB923414)‎
    עדכון אבטחה עבור Windows XP (KB923561)‎
    עדכון אבטחה עבור Windows XP‏ (KB923689)
    עדכון אבטחה עבור Windows XP (KB923789)‎
    עדכון אבטחה עבור Windows XP (KB923980)‎
    עדכון אבטחה עבור Windows XP (KB924270)‎
    עדכון אבטחה עבור Windows XP (KB924496)‎
    עדכון אבטחה עבור Windows XP (KB924667)‎
    עדכון אבטחה עבור Windows XP (KB925902)‎
    עדכון אבטחה עבור Windows XP (KB926255)‎
    עדכון אבטחה עבור Windows XP (KB926436)‎
    עדכון אבטחה עבור Windows XP (KB927779)‎
    עדכון אבטחה עבור Windows XP (KB927802)‎
    עדכון אבטחה עבור Windows XP (KB928255)‎
    עדכון אבטחה עבור Windows XP (KB928843)‎
    עדכון אבטחה עבור Windows XP (KB929123)‎
    עדכון אבטחה עבור Windows XP (KB930178)‎
    עדכון אבטחה עבור Windows XP (KB931261)‎
    עדכון אבטחה עבור Windows XP (KB931784)‎
    עדכון אבטחה עבור Windows XP (KB932168)‎
    עדכון אבטחה עבור Windows XP (KB933729)‎
    עדכון אבטחה עבור Windows XP (KB935839)‎
    עדכון אבטחה עבור Windows XP (KB935840)‎
    עדכון אבטחה עבור Windows XP (KB936021)‎
    עדכון אבטחה עבור Windows XP (KB938127)‎
    עדכון אבטחה עבור Windows XP (KB938464)‎
    עדכון אבטחה עבור Windows XP (KB941202)‎
    עדכון אבטחה עבור Windows XP‏ (KB941569)
    עדכון אבטחה עבור Windows XP (KB941693)‎
    עדכון אבטחה עבור Windows XP (KB943055)‎
    עדכון אבטחה עבור Windows XP (KB943460)‎
    עדכון אבטחה עבור Windows XP (KB943485)‎
    עדכון אבטחה עבור Windows XP (KB944338)‎
    עדכון אבטחה עבור Windows XP (KB944653)‎
    עדכון אבטחה עבור Windows XP (KB945553)‎
    עדכון אבטחה עבור Windows XP (KB946026)‎
    עדכון אבטחה עבור Windows XP (KB946648)‎
    עדכון אבטחה עבור Windows XP (KB948590)‎
    עדכון אבטחה עבור Windows XP (KB950749)‎
    עדכון אבטחה עבור Windows XP (KB950759)‎
    עדכון אבטחה עבור Windows XP (KB950760)‎
    עדכון אבטחה עבור Windows XP (KB950762)‎
    עדכון אבטחה עבור Windows XP (KB950974)‎
    עדכון אבטחה עבור Windows XP (KB951066)‎
    עדכון אבטחה עבור Windows XP (KB951376-v2)‎
    עדכון אבטחה עבור Windows XP (KB951698)‎
    עדכון אבטחה עבור Windows XP (KB951748)‎
    עדכון אבטחה עבור Windows XP (KB952004)‎
    עדכון אבטחה עבור Windows XP (KB952954)‎
    עדכון אבטחה עבור Windows XP (KB953838)‎
    עדכון אבטחה עבור Windows XP (KB953839)‎
    עדכון אבטחה עבור Windows XP (KB954211)‎
    עדכון אבטחה עבור Windows XP (KB954600)‎
    עדכון אבטחה עבור Windows XP (KB955069)‎
    עדכון אבטחה עבור Windows XP (KB956390)‎
    עדכון אבטחה עבור Windows XP (KB956391)‎
    עדכון אבטחה עבור Windows XP (KB956572)‎
    עדכון אבטחה עבור Windows XP (KB956802)‎
    עדכון אבטחה עבור Windows XP (KB956803)‎
    עדכון אבטחה עבור Windows XP (KB956841)‎
    עדכון אבטחה עבור Windows XP (KB956844)‎
    עדכון אבטחה עבור Windows XP (KB957095)‎
    עדכון אבטחה עבור Windows XP (KB957097)‎
    עדכון אבטחה עבור Windows XP (KB958215)‎
    עדכון אבטחה עבור Windows XP (KB958470)‎
    עדכון אבטחה עבור Windows XP (KB958644)‎
    עדכון אבטחה עבור Windows XP (KB958687)‎
    עדכון אבטחה עבור Windows XP (KB958690)‎
    עדכון אבטחה עבור Windows XP (KB958869)‎
    עדכון אבטחה עבור Windows XP (KB959426)‎
    עדכון אבטחה עבור Windows XP (KB960225)‎
    עדכון אבטחה עבור Windows XP (KB960714)‎
    עדכון אבטחה עבור Windows XP (KB960715)‎
    עדכון אבטחה עבור Windows XP (KB960803)‎
    עדכון אבטחה עבור Windows XP (KB960859)‎
    עדכון אבטחה עבור Windows XP (KB961371)‎
    עדכון אבטחה עבור Windows XP (KB961373)‎
    עדכון אבטחה עבור Windows XP (KB961501)‎
    עדכון אבטחה עבור Windows XP (KB963027)‎
    עדכון אבטחה עבור Windows XP (KB968537)‎
    עדכון אבטחה עבור Windows XP (KB969059)‎
    עדכון אבטחה עבור Windows XP (KB969897)‎
    עדכון אבטחה עבור Windows XP (KB969898)‎
    עדכון אבטחה עבור Windows XP (KB969947)‎
    עדכון אבטחה עבור Windows XP (KB970238)‎
    עדכון אבטחה עבור Windows XP (KB971468)‎
    עדכון אבטחה עבור Windows XP (KB971557)‎
    עדכון אבטחה עבור Windows XP (KB971633)‎
    עדכון אבטחה עבור Windows XP (KB971657)‎
    עדכון אבטחה עבור Windows XP (KB972260)‎
    עדכון אבטחה עבור Windows XP (KB972270)‎
    עדכון אבטחה עבור Windows XP (KB973346)‎
    עדכון אבטחה עבור Windows XP (KB973354)‎
    עדכון אבטחה עבור Windows XP (KB973507)‎
    עדכון אבטחה עבור Windows XP (KB973869)‎
    עדכון אבטחה עבור Windows XP (KB973904)‎
    עדכון אבטחה עבור Windows XP (KB974112)‎
    עדכון אבטחה עבור Windows XP (KB974318)‎
    עדכון אבטחה עבור Windows XP (KB974392)‎
    עדכון אבטחה עבור Windows XP (KB974571)‎
    עדכון אבטחה עבור Windows XP (KB975025)‎
    עדכון אבטחה עבור Windows XP (KB975467)‎
    עדכון אבטחה עבור Windows XP (KB975560)‎
    עדכון אבטחה עבור Windows XP (KB975561)‎
    עדכון אבטחה עבור Windows XP (KB975713)‎
    עדכון אבטחה עבור Windows XP (KB977165-v2)‎
    עדכון אבטחה עבור Windows XP (KB977914)‎
    עדכון אבטחה עבור Windows XP (KB978037)‎
    עדכון אבטחה עבור Windows XP (KB978251)‎
    עדכון אבטחה עבור Windows XP (KB978262)‎
    עדכון אבטחה עבור Windows XP (KB978706)‎
    עדכון עבור Windows Internet Explorer 8 (KB973874)‎
    עדכון עבור Windows Internet Explorer 8 (KB976662)‎
    עדכון עבור Windows XP (KB894391)‎
    עדכון עבור Windows XP (KB898461)‎
    עדכון עבור Windows XP (KB900485)‎
    עדכון עבור Windows XP (KB908531)‎
    עדכון עבור Windows XP (KB910437)‎
    עדכון עבור Windows XP (KB911280)‎
    עדכון עבור Windows XP (KB916595)‎
    עדכון עבור Windows XP (KB920872)‎
    עדכון עבור Windows XP (KB922582)‎
    עדכון עבור Windows XP (KB925720)‎
    עדכון עבור Windows XP (KB930916)‎
    עדכון עבור Windows XP (KB932823-v3)‎
    עדכון עבור Windows XP (KB936357)‎
    עדכון עבור Windows XP (KB938828)‎
    עדכון עבור Windows XP (KB942763)‎
    עדכון עבור Windows XP (KB951072-v2)‎
    עדכון עבור Windows XP (KB955759)‎
    עדכון עבור Windows XP (KB955839)‎
    עדכון עבור Windows XP (KB967715)‎
    עדכון עבור Windows XP (KB968389)‎
    עדכון עבור Windows XP (KB973687)‎
    עדכון עבור Windows XP (KB973815)‎
    תיקון חם עבור Windows Media Player 11‏ (KB939683)
    תיקון חם עבור Windows XP (KB935448)‎
    תיקון חם עבור Windows XP (KB952287)‎
    תיקון חם עבור Windows XP (KB961118)‎
    תיקון חם עבור Windows XP (KB970653-v3)‎
    תיקון חם עבור Windows XP (KB979306)‎

    computer info:
    Windows XP SP2
    Intel Pentium Duel CPU E2180
    Ram 1.92gb
    ADSL connection - siemens SL2-141

    Thank you!
     
  4. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,949
    First Name:
    Frank
    Uninstall these programs because they're not needed or are dangerous to use.

    Acrobat.com

    Ad-Aware
    (Lavasoft)

    Adobe AIR

    CCleaner

    Glary Registry Repair

    Glary Utilities

    Registry Repair Pro


    It's unknown how much damage you've done to your computer by using those registry programs.

    -------------------------------------------------------------------

    Adobe Reader 9.1.1 needs to be updated to version 9.3. Start it and then click Help - Check For Updates. If the update feature doesn't work, you can get version 9.3 from here. It'll overwrite and replace the old version.

    If you actually use Skype 4.1, it needs to be updated to version 4.2.

    If you actually use Picasa 2, it needs to be updated to version 3.6.

    -------------------------------------------------------------------

    Download and install

    Malwarebytes Anti-Malware 1.45

    SUPERAntiSpyware 4.35.0.1002

    to replace Lavasoft Ad-Aware. They're more user-friendly and do a better job and are lighter on system resources.

    -------------------------------------------------------------------

    After you've done the above and have restarted your computer for the last time, submit a new HijackThis log here.

    ------------------------------------------------------------------
     
  5. bilerr

    bilerr Thread Starter

    Joined:
    Apr 22, 2010
    Messages:
    6
    Thank You.

    I did everything you said. here is the HijackThis log report:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:18:42, on 23/04/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\AVG\AVG9\avgfws9.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Picasa2\PicasaMediaDetector.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.il/search?sour...ם&ie=UTF-8&rlz=1T4ADBS_enIL331IL331&q=igoogle
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: (no name) - {54B02808-B60E-44CD-A72D-9865117E4E62} - (no file)
    O2 - BHO: AGFormHelperObj Class - {6620E618-1AB9-4EB2-ACA4-CBBE9066DBE6} - C:\Program Files\agat\AGForm\AGFormsHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O3 - Toolbar: AGForms - {ed2e7de7-07db-4941-a06d-f780b93ba730} - C:\Program Files\agat\AGForm\AGForms.dll
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Scheduler.lnk = C:\Program Files\3B Software\Common\Scheduler\wcomschd.exe
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
    O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    O23 - Service: שירות Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe

    --
    End of file - 8566 bytes

    ---

    also i run the maleware program u told me to download it found 2 infections:

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully

    I hope i did the right thing by Quarentined them.

    Thank you again for all you help!!!
     
  6. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,949
    First Name:
    Frank
    Here are complete instructions for the use of Malwarebytes Anti-Malware and SUPERAntiSpyware. I recommend doing this once or twice a month. Print off the instructions and use them until you get used to doing it on your own.

    Start Malwarebytes Anti-Malware.

    Click "Updates(tab) - Check for Updates".

    When the definition files have updated, click "OK".

    Click "Scanner(tab) - Perform quick scan - Scan".

    If infections are found during the scan, the number of infections will be highlighted in red.

    When the scan is finished, click "Show Results".

    Make sure that everything is selected, then click "Remove Selected".

    If you're prompted to restart to finish the removal process, click "Yes".

    Start Malwarebytes Anti-Malware again.

    Click "Logs"(tab).

    Highlight the scan log entry, then click "Open".

    When the scan log appears in Notepad, copy-and-paste it here.

    Start SUPERAntiSpyware.

    Click "Check for Updates".

    When the definition files have updated, click "Close".

    Click "Scan your Computer - Perform Quick Scan - Next".

    If infections or problems are found during the scan, a list will appear.

    When the scan is finished and the scan summary window appears, click "OK".

    Make sure that everything in the list is selected, then click "Next".

    If you're prompted to restart to finish the removal process, click "Yes".

    Start SUPERAntiSpyware again.

    Click "Preferences - Statistics/Logs"(tab).

    Highlight the scan log entry, then click "View Log".

    When the scan log appears in Notepad, copy-and-paste it here.

    ----------------------------------------------------------------
     
  7. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,949
    First Name:
    Frank
    Your computer has several programs that are auto-loading and running in the background. Some of them don't need to auto-load and run at all, and others can be manually started when needed.

    I'm going to give you instructions for trimming down that startup load. That should give your computer a little more speed and performance. Follow my instructions carefully and take your time.

    ---------------------------------------------------------------

    Click Start - Run, type in MSCONFIG and then click OK - Startup(tab).

    Remove the checkmark only from the entries that I've highlighted in bold text.
    (Note: .exe may be missing from the name)

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe

    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe

    O4 - HKLM\..\Run: NvCplDaemon RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: nwiz nwiz.exe /install

    O4 - HKLM\..\Run: NvMediaCenter RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: RTHDCPL RTHDCPL.EXE

    O4 - HKLM\..\Run: Alcmtr ALCMTR.EXE

    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

    O4 - HKLM\..\Run: Adobe Reader Speed Launcher "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe

    O4 - HKLM\..\Run: Adobe ARM "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: Picasa Media Detector C:\Program Files\Picasa2\PicasaMediaDetector.exe

    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

    O4 - HKCU\..\Run: Google Update "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

    O4 - HKCU\..\Run: SUPERAntiSpyware C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

    O4 - Startup: Scheduler.lnk = C:\Program Files\3B Software\Common\Scheduler\wcomschd.exe

    Also uncheck all entries that start with Nv

    After you're done, click Apply - OK - Exit Without Restart.

    Click Start - Run, type in SERVICES.MSC and then click OK.

    Expand the window so you can see the list more clearly.

    Double-click only on the entries that I've highlighted in bold text.
    (Note: You have to do one entry at a time)

    If "Startup Type" is set on Automatic, change it to Manual and then click Apply - OK.

    O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

    O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe

    O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe

    O23 - Service: Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe

    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe

    After you're done, close the window and then restart your computer.

    When the small System Configuration Utility window appears during restart, ignore the message.

    Put a checkmark in that window and then click OK to close it.

    Start HijackThis and then click "Do a system scan and save a log file".

    When the scan is finished and the log appears, copy-and-paste it here.

    ---------------------------------------------------------------
     
  8. bilerr

    bilerr Thread Starter

    Joined:
    Apr 22, 2010
    Messages:
    6
    Thanks!

    Here are all the info according your insractions:


    Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org
    גרסת מסד נתונים: 4024

    Scan from yesterday

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 8.0.6001.18702

    23/04/2010 12:22:03
    mbam-log-2010-04-23 (12-22-03).txt

    סוג הסריקה: סריקה מהירה
    סריקת אובייקטים: 104923
    הזמן שחלף: 8 דקות, 46 שניות

    תהליכי זיכרון נגועים: 0
    זכרונות מודלים נגועים: 0
    מפתחות רישום נגועים: 1
    ערכי רישום נגועים: 0
    פריטי נתוני רישום נגועים: 1
    תיקיות נגועות: 0
    קבצים נגועים: 0

    תהליכי זיכרון נגועים:
    (לא נמצאו פריטים זדוניים)

    זכרונות מודלים נגועים:
    (לא נמצאו פריטים זדוניים)

    מפתחות רישום נגועים: register key infected
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    ערכי רישום נגועים:
    (לא נמצאו פריטים זדוניים)

    פריטי נתוני רישום נגועים:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

    תיקיות נגועות:
    (לא נמצאו פריטים זדוניים)

    קבצים נגועים:
    (לא נמצאו פריטים זדוניים)

    Second and third scan – no infection: (the log is in Hebrew – sorry)
    Malwarebytes' Anti-Malware 1.45
    www.malwarebytes.org

    גרסת מסד נתונים: 4029

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 8.0.6001.18702

    24/04/2010 09:48:17
    mbam-log-2010-04-24 (09-48-17).txt

    סוג הסריקה: סריקה מהירה
    סריקת אובייקטים: 104170
    הזמן שחלף: 5 דקות, 37 שניות

    תהליכי זיכרון נגועים: 0
    זכרונות מודלים נגועים: 0
    מפתחות רישום נגועים: 0
    ערכי רישום נגועים: 0
    פריטי נתוני רישום נגועים: 0
    תיקיות נגועות: 0
    קבצים נגועים: 0

    תהליכי זיכרון נגועים:
    (לא נמצאו פריטים זדוניים)

    זכרונות מודלים נגועים:
    (לא נמצאו פריטים זדוניים)

    מפתחות רישום נגועים:
    (לא נמצאו פריטים זדוניים)

    ערכי רישום נגועים:
    (לא נמצאו פריטים זדוניים)

    פריטי נתוני רישום נגועים:
    (לא נמצאו פריטים זדוניים)

    תיקיות נגועות:
    (לא נמצאו פריטים זדוניים)

    קבצים נגועים:
    (לא נמצאו פריטים זדוניים)

    --------------------------------------

    SuperAntiSpyware scan results:

    First scan (Yesterday) –
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 04/23/2010 at 12:47 PM

    Application Version : 4.35.1002

    Core Rules Database Version : 4842
    Trace Rules Database Version: 2654

    Scan type : Quick Scan
    Total Scan Time : 00:15:21

    Memory items scanned : 521
    Memory threats detected : 0
    Registry items scanned : 459
    Registry threats detected : 0
    File items scanned : 4870
    File threats detected : 13

    Adware.Tracking Cookie
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt

    Todays scan:
    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 04/24/2010 at 10:20 AM

    Application Version : 4.35.1002

    Core Rules Database Version : 4846
    Trace Rules Database Version: 2658

    Scan type : Quick Scan
    Total Scan Time : 00:10:33

    Memory items scanned : 457
    Memory threats detected : 0
    Registry items scanned : 447
    Registry threats detected : 0
    File items scanned : 4822
    File threats detected : 2

    Adware.Tracking Cookie
    C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
    C:\Documents and Settings\Owner\Cookies\[email protected][2].txt

    ---------------------------------


    HijackThis log file:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:31:10, on 24/04/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\AVG\AVG9\avgfws9.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.il/search?sour...ם&ie=UTF-8&rlz=1T4ADBS_enIL331IL331&q=igoogle
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: (no name) - {54B02808-B60E-44CD-A72D-9865117E4E62} - (no file)
    O2 - BHO: AGFormHelperObj Class - {6620E618-1AB9-4EB2-ACA4-CBBE9066DBE6} - C:\Program Files\agat\AGForm\AGFormsHelper.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
    O3 - Toolbar: AGForms - {ed2e7de7-07db-4941-a06d-f780b93ba730} - C:\Program Files\agat\AGForm\AGForms.dll
    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
    O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
    O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
    O23 - Service: שירות Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe

    --
    End of file - 6946 bytes


    THANK YOU! the computer run smoother :)
     
  9. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,949
    First Name:
    Frank
    Thanks for making me aware about the Hebrew language. I was wondering what all the symbols in your log were.

    And thanks for making me aware that your computer is running smoother. (y)

    I guess we're done here, unless you have anything else that you need to address.

    ----------------------------------------------------------------
     
  10. bilerr

    bilerr Thread Starter

    Joined:
    Apr 22, 2010
    Messages:
    6
    Thank you for all your help!

    I will may turn to your help with my laptop soon.
    But for my mother computer I think we're done :) you really changed the way the computer work!

    Thanks again
     
  11. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    80,949
    First Name:
    Frank
    You're welcome. :) (y)

    If you decide you need help with your laptop, make sure to start a new thread for it.

    ---------------------------------------------------------------
     
  12. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/918540

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice