Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Help, computer really slow

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Help, computer really slow

Unread postby brandonbill2009 » January 3rd, 2008, 5:28 am

Need to know what to do, here is my HijackThis log, and all help is sooooo greatly appreciated!!!

Running processes:
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner.YOUR-84321C6B28\Desktop\HiJackThis.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O1 - Hosts: HP94093C HP0018FE94093C
O1 - Hosts: ad.doubleclick.net
O1 - Hosts: upgrade.bitdefender.com
O1 - Hosts: report.bitdefender.com
O1 - Hosts: ad.fastclick.net
O1 - Hosts: ads.fastclick.net
O1 - Hosts: atdmt.com
O1 - Hosts: awaps.net
O1 - Hosts: banner.fastclick.net
O1 - Hosts: banners.fastclick.net
O1 - Hosts: click.atdmt.com
O1 - Hosts: clicks.atdmt.com
O1 - Hosts: engine.awaps.net
O1 - Hosts: fastclick.net
O1 - Hosts: ftp.avp.ch
O1 - Hosts: ftp.kasperskylab.ru
O1 - Hosts: updates5.kaspersky-labs.com
O1 - Hosts: http://www.awaps.net
O1 - Hosts: http://www.viruslist.ru
O1 - Hosts: awaps.net
O1 - Hosts: fastclick.net
O1 - Hosts: kaspersky.ru
O1 - Hosts: akamai.net
O1 - Hosts: http://www.antivir.de
O1 - Hosts: antivir.de
O1 - Hosts: drweb.com
O1 - Hosts: http://www.drweb.com
O1 - Hosts: drweb.ru
O1 - Hosts: http://www.ravantivirus.com
O1 - Hosts: ravantivirus.com
O1 - Hosts: bitdefender.com
O1 - Hosts: http://www.bitdefender.com
O1 - Hosts: http://www.clamav.net
O1 - Hosts: clamav.net
O1 - Hosts: ftpav.ca.com
O1 - Hosts: upgrade.bitdefender.com
O1 - Hosts: http://www.bitdefender.ru
O1 - Hosts: bitdefender.ru
O1 - Hosts: open.by
O1 - Hosts: vba32.de
O1 - Hosts: http://www.open.by
O1 - Hosts: lavasoft.de
O1 - Hosts: lavasoft.com
O1 - Hosts: rs01.avast.com
O1 - Hosts: sm01.avast.com
O1 - Hosts: rs02.avast.com
O1 - Hosts: sm02.avast.com
O1 - Hosts: rs03.avast.com
O1 - Hosts: sm03.avast.com
O1 - Hosts: rs04.avast.com
O1 - Hosts: sm04.avast.com
O1 - Hosts: rs05.avast.com
O1 - Hosts: sm05.avast.com
O1 - Hosts: rs06.avast.com
O1 - Hosts: sm06.avast.com
O1 - Hosts: rs07.avast.com
O1 - Hosts: sm07.avast.com
O1 - Hosts: rs08.avast.com
O1 - Hosts: sm08.avast.com
O1 - Hosts: rs09.avast.com
O1 - Hosts: sm09.avast.com
O1 - Hosts: rs10.avast.com
O1 - Hosts: sm10.avast.com
O1 - Hosts: rs11.avast.com
O1 - Hosts: sm11.avast.com
O1 - Hosts: rs12.avast.com
O1 - Hosts: sm12.avast.com
O1 - Hosts: rs13.avast.com
O1 - Hosts: sm13.avast.com
O1 - Hosts: rs14.avast.com
O1 - Hosts: sm14.avast.com
O1 - Hosts: rs15.avast.com
O1 - Hosts: sm15.avast.com
O1 - Hosts: rs16.avast.com
O1 - Hosts: sm16.avast.com
O1 - Hosts: rs17.avast.com
O1 - Hosts: sm17.avast.com
O1 - Hosts: rs18.avast.com
O1 - Hosts: sm18.avast.com
O1 - Hosts: rs19.avast.com
O1 - Hosts: sm19.avast.com
O1 - Hosts: rs20.avast.com
O1 - Hosts: sm20.avast.com
O1 - Hosts: rs21.avast.com
O1 - Hosts: sm21.avast.com
O1 - Hosts: rs22.avast.com
O1 - Hosts: sm22.avast.com
O1 - Hosts: rs23.avast.com
O1 - Hosts: sm23.avast.com
O1 - Hosts: rs24.avast.com
O1 - Hosts: sm24.avast.com
O1 - Hosts: rs25.avast.com
O1 - Hosts: sm25.avast.com
O1 - Hosts: rs26.avast.com
O1 - Hosts: sm26.avast.com
O1 - Hosts: rs27.avast.com
O1 - Hosts: sm27.avast.com
O1 - Hosts: rs28.avast.com
O1 - Hosts: sm28.avast.com
O1 - Hosts: rs29.avast.com
O1 - Hosts: sm29.avast.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: (no name) - {84938242-5C5B-4A55-B6B9-A1507543B418} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [HPLJ Config] C:\Program Files\Hewlett-Packard\hp LaserJet 1010 Series\SetConfig.exe -c Network -p -pn "hp LaserJet 1010 Series Driver" -n 0 -l 1033 -sl 120000
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
O4 - HKLM\..\Run: [StopSignSsSsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll",VerifyStatus
O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
O4 - HKLM\..\Run: [Eac_Installer] C:\PROGRA~1\COMMON~1\EACCEL~1\INSTAL~1\eaccelsetup.exe -AskToResumeDL
O4 - HKLM\..\RunOnce: [StopSignSsSsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll",VerifyStatus /ro
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crl ... crlocx.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O21 - SSODL: eitheror - {2016a466-91a2-43c6-97d8-2fd380f065ef} - (no file)
O22 - SharedTaskScheduler: eitheror - {2016a466-91a2-43c6-97d8-2fd380f065ef} - (no file)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

End of file - 10971 bytes
Active Member
Posts: 1
Joined: January 3rd, 2008, 5:24 am
Register to Remove

Re: Help, computer really slow

Unread postby ndmmxiaomayi » January 3rd, 2008, 12:12 pm

Hi brandonbill2009. :)

Welcome to Malware Removal. The HijackThis log you've posted is not complete. Please post the full log. The log can be found on your desktop.
MRU Emeritus
MRU Emeritus
Posts: 9708
Joined: July 17th, 2006, 9:22 am

Re: Help, computer really slow

Unread postby ndmmxiaomayi » January 12th, 2008, 3:06 pm


Do you still need help?
MRU Emeritus
MRU Emeritus
Posts: 9708
Joined: July 17th, 2006, 9:22 am

Re: Help, computer really slow

Unread postby NonSuch » January 18th, 2008, 2:20 am

Due to lack of response this topic is now closed.

If you still need help open a new thread in the Malware Removal forum and wait for a new helper.

If you have been helped and wish to donate to help with the costs of this volunteer site, please read Donations For Malware Removal
User avatar
Posts: 27256
Joined: February 23rd, 2005, 7:08 am
Location: California
Register to Remove

  • Similar Topics
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!

Who is online

Users browsing this forum: No registered users and 23 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware