Have been suspicious about a guest and his use of my computor for housing and employment research. So I set him up on Guest Account. Made no difference in the end.
The system has been very slugish. Often E-mail is slow to open mail, delete, etc or just freezes. It freezes in Internet Explorer (IE). I have run older AVG Free, found some stuff. Spybot has found nothing, although under TOOL and START UP, Spybot contininualy findy "RAIDY'S TROJAN", which I promply delete from same screen. Spybot said something about not to be confused with the lagit "Windows\System32\ctfmon.exe" name. Sometimes I am not able to open Tsk Mngr, my intensions being to close a frozen program to get to RUN Shutdown. Running AVG and Spybot and removing Raidy's Trojan all help, but it comes back.
I researched and decided I didn't need ctfmon.exe, whether it was lagit or not and tried to remove it all. Think I disabled WINDOWS version but... I installed WINPATROL and heard the bark every few minutes, CTF Loader wanted to load which I continually denied. I keep TSK MNGR open and handy and often find ctfmon.exe has started again. Seems when I stop it, thing get better, but not sure if lagit version is sucking what little resources are left or iligitimat version is sucking the life out.
I found while researching for a cure some of the sights I went to would lock-up, sights like AVG, and other lagitimat malware removal help sights. hmmm, And...I installed the latest AVG Free and soon the UPDATE came back with "General Error". After several days, I updated SpyBot and removed all of any AVG, past and present and attempted to down load fresh AVG Free, this time it failed on several attempts and (running eeeexxxttremely slowly) came back with "C\Doc Settings\Admin\Local Setting\Temp Internet File\couten.IE5\AZIU90EJ\avg_free-stb_all_2011_1153_cnet[1].exe. is not valid Windows 32 application."
I searched register and harddrive for thisinvalid file but found nothing, but did com across temp files, tempoary internet files, and history files that didn't look right, 1st, they weren't empty as I expected, and second, some held folders named with abritary letter/number combos, all capitol. I tried to delete I couldn't remove, they were listed as read only, which I was not allowed to change..."File is in use by a program or other person".
With smoke coming from my ears, I changed the "hide system files", and sure enough more unexplanable ghost or read only files that I don't recognise as system files, looks like I need help.
MS word freezes now and when I open local explorer, the File Tree comes up, kinda slow but... the paine to the right, it searches 5-10 seconds before it displays name-type-size, etc.
I thought I had things sorted out but for 1 pesky file in temporary internet file and 1 in history file. The computer was running extremely fast almost like normal!!!...then all hell broke loose and here I am...Please find the requested logs below and THANKS;
________________________________________________________________
HIJACKTHIS Log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:33:12 PM, on 11/14/2010
Platform: Windows XP SP3, v.3264 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe %System%\printer.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -
C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1
\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P
ddoctorv2
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common
Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -
expressboot
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\RunOnce: [AvgRemover] C:\Documents and Settings\Administrator\Local
Settings\Temporary Internet Files\Content.IE5\88NQWN7Z\avg_remover_stf_x86_2011_1165[1].exe
/run_number=2 /avgdir="C:\Program Files\AVG\AVG10\" /avgdatadir="C:\Documents and
Settings\All Users\Application Data\AVG10\"
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1
\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} -
C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2
\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1
\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-
A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) -
https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?
1227587037000
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?
1231478211718
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) -
http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%
20Files/AutoCAD%202000i/AcDcToday.ocx
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) -
http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred Control) - file:///C:/Program%
20Files/AutoCAD%202000i/InstFred.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%
20Files/AutoCAD%202000i/AcPreview.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program
Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} -
C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-
3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common
Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10
\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program
Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program
Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -
C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program
Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32
\LEXBCES.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices,
Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft,
Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. -
C:\WINDOWS\system32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 9350 bytes
____________________________________________________________
Uninstall List:
Acrobat.com
Actiontec Gateway
Adobe AIR
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Reader 9.3.4
Adobe Reader 9.4.0
AnswerWorks Runtime
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Print Creations
ArcSoft Print Creations - Album Page
ArcSoft Print Creations - Funhouse
ArcSoft Print Creations - Greeting Card
ArcSoft Print Creations - Photo Book
ArcSoft Print Creations - Photo Calendar
ArcSoft Print Creations - Scrapbook
ArcSoft Print Creations - Slimline Card
ATI AVIVO Codecs
ATI Catalyst Control Center
AutoCAD 2000i
AVG PC Tuneup 2011
Bonjour
Catalyst Control Center - Branding
CCleaner
CCScore
CDDRV_Installer
Comcast Desktop Software (v1.2.0.9)
Compaq Presario Monitor Driver Software 5.00
Defraggler
Desktop Doctor
DH Driver Cleaner Professional Edition
DynoSim Engine Simulation v.4.200208 ProTools
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSTOOLS
essvatgt
Google Earth
Google Update Helper
Google Updater
HiJackThis
HP Product Detection
Intel(R) Network Connections
Java(TM) 6 Update 11
Java(TM) SE Runtime Environment 6
KhalInstallWrapper
Kodak EasyShare software
KwikTrig 3.0.5
KwikTrig 3.0.5 (C:\Program Files\KwikTrig\)
Lexmark 510 Series
Logitech SetPoint
Logitech Updater
Meter View
Microsoft .NET Framework 2.0
Microsoft Combat Flight Simulator 3.1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
netbrdg
OfotoXMI
Olds Cutlass & 442 Ver 2.0 Screen Saver
ParetoLogic Data Recovery
ParetoLogic DriverCure
ParetoLogic Privacy Controls
PL-2303 USB-to-Serial
QuickTime
RegCure
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
SFR
SHASTA
skin0001
SKINXSDK
SoundMAX
Spelling Dictionaries Support For Adobe Reader 9
Spybot - Search & Destroy
staticcr
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Windows Internet Explorer 7 (KB928089)
V CAST Music with Rhapsody
VC 9.0 Runtime
VC 9.0 Runtime
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VPRINTOL
Windows Installer Clean Up
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinPatrol
WIRELESS
ZoneAlarm
_____________________________________________________
and ROOT RETREAVER Log
HKLM\SECURITY\Policy\Secrets\SAC* 3/25/2008 2:15 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 3/25/2008 2:15 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{5645C8C2-E277-11CF-8FDA-00AA00A14F93}\InprocServer32\ThreadingModel 1/26/2009 6:59 AM 5 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\LastChecked 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{2BF2CA35-CCAF-4E58-BAB7-4163BFA03B88}\RollCallDayStartSec 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{2BF2CA35-CCAF-4E58-BAB7-4163BFA03B88}\LastCheckSuccess 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\RollCallDayStartSec 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\LastCheckSuccess 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{74AF07D8-FB8F-4D51-8AC7-927721D56EBB}\LastCheckSuccess 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{74AF07D8-FB8F-4D51-8AC7-927721D56EBB}\RollCallDayStartSec 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\network\secure-S-1-5-18\sk 11/14/2010 12:25 AM 176 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 11/14/2010 1:13 AM 80 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\SchedulingAgent\LastTaskRun 11/14/2010 12:25 AM 16 bytes Data mismatch between Windows API and raw hive data.
___________________________________________________________
MACHINE INFO:
Windows Version: Microsoft Windows XP Professional
--------------------------------------------------------------------------------
*** Common Devices ***
--------------------------------------------------------------------------------
System Name: Evo D510 CMT
Processor Name: Intel(R) Pentium(R) 4 CPU 2.26GHz
BIOS Name: 686O2 v2.14
Video card Name: ATI Radeon HD 2400 Series
Default Printer: Lexmark 510 Series --------------------------------------------------------------------------------
*** Installed Programs ***
--------------------------------------------------------------------------------
Number of Installed Programs: 148
Number of Running Processes: 62
Internet Explorer Version: 7.0.5730.11
DirectX Version: DirectX 9.0c (4.09.0000.0904)
MS Office Version: 12.0.6545.5000
--------------------------------------------------------------------------------
*** CPU Properties ***
--------------------------------------------------------------------------------
Physical Processors: 1
Logical Processors: 1
Name: Intel(R) Pentium(R) 4 CPU 2.26GHz
Description: x86 Family 15 Model 2 Stepping 4
Manufacturer: GenuineIntel
Frequency: 2259 MHz
External Clock Frequency: 533 MHz
Processor ID: 3FEBFBFF - 00000F24
Code Name: Northwood
Revision: B0 --------------------------------------------------------------------------------
*** Cache Properties ***
--------------------------------------------------------------------------------
L1 Data Cache: 8 KB
L2 Cache: 512 KB
END
The system has been very slugish. Often E-mail is slow to open mail, delete, etc or just freezes. It freezes in Internet Explorer (IE). I have run older AVG Free, found some stuff. Spybot has found nothing, although under TOOL and START UP, Spybot contininualy findy "RAIDY'S TROJAN", which I promply delete from same screen. Spybot said something about not to be confused with the lagit "Windows\System32\ctfmon.exe" name. Sometimes I am not able to open Tsk Mngr, my intensions being to close a frozen program to get to RUN Shutdown. Running AVG and Spybot and removing Raidy's Trojan all help, but it comes back.
I researched and decided I didn't need ctfmon.exe, whether it was lagit or not and tried to remove it all. Think I disabled WINDOWS version but... I installed WINPATROL and heard the bark every few minutes, CTF Loader wanted to load which I continually denied. I keep TSK MNGR open and handy and often find ctfmon.exe has started again. Seems when I stop it, thing get better, but not sure if lagit version is sucking what little resources are left or iligitimat version is sucking the life out.
I found while researching for a cure some of the sights I went to would lock-up, sights like AVG, and other lagitimat malware removal help sights. hmmm, And...I installed the latest AVG Free and soon the UPDATE came back with "General Error". After several days, I updated SpyBot and removed all of any AVG, past and present and attempted to down load fresh AVG Free, this time it failed on several attempts and (running eeeexxxttremely slowly) came back with "C\Doc Settings\Admin\Local Setting\Temp Internet File\couten.IE5\AZIU90EJ\avg_free-stb_all_2011_1153_cnet[1].exe. is not valid Windows 32 application."
I searched register and harddrive for thisinvalid file but found nothing, but did com across temp files, tempoary internet files, and history files that didn't look right, 1st, they weren't empty as I expected, and second, some held folders named with abritary letter/number combos, all capitol. I tried to delete I couldn't remove, they were listed as read only, which I was not allowed to change..."File is in use by a program or other person".
With smoke coming from my ears, I changed the "hide system files", and sure enough more unexplanable ghost or read only files that I don't recognise as system files, looks like I need help.
MS word freezes now and when I open local explorer, the File Tree comes up, kinda slow but... the paine to the right, it searches 5-10 seconds before it displays name-type-size, etc.
I thought I had things sorted out but for 1 pesky file in temporary internet file and 1 in history file. The computer was running extremely fast almost like normal!!!...then all hell broke loose and here I am...Please find the requested logs below and THANKS;
________________________________________________________________
HIJACKTHIS Log
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:33:12 PM, on 11/14/2010
Platform: Windows XP SP3, v.3264 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe %System%\printer.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -
C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1
\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P
ddoctorv2
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common
Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -
expressboot
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\RunOnce: [AvgRemover] C:\Documents and Settings\Administrator\Local
Settings\Temporary Internet Files\Content.IE5\88NQWN7Z\avg_remover_stf_x86_2011_1165[1].exe
/run_number=2 /avgdir="C:\Program Files\AVG\AVG10\" /avgdatadir="C:\Documents and
Settings\All Users\Application Data\AVG10\"
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1
\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} -
C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2
\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1
\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-
A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) -
https://www-secure.symantec.com/techsup ... gctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?
1227587037000
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) -
http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?
1231478211718
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) -
http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%
20Files/AutoCAD%202000i/AcDcToday.ocx
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) -
http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred Control) - file:///C:/Program%
20Files/AutoCAD%202000i/InstFred.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) -
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%
20Files/AutoCAD%202000i/AcPreview.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program
Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} -
C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-
3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common
Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10
\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program
Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program
Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -
C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program
Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32
\LEXBCES.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices,
Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft,
Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. -
C:\WINDOWS\system32\UAService7.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 9350 bytes
____________________________________________________________
Uninstall List:
Acrobat.com
Actiontec Gateway
Adobe AIR
Adobe AIR
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Reader 9.3.4
Adobe Reader 9.4.0
AnswerWorks Runtime
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft Print Creations
ArcSoft Print Creations - Album Page
ArcSoft Print Creations - Funhouse
ArcSoft Print Creations - Greeting Card
ArcSoft Print Creations - Photo Book
ArcSoft Print Creations - Photo Calendar
ArcSoft Print Creations - Scrapbook
ArcSoft Print Creations - Slimline Card
ATI AVIVO Codecs
ATI Catalyst Control Center
AutoCAD 2000i
AVG PC Tuneup 2011
Bonjour
Catalyst Control Center - Branding
CCleaner
CCScore
CDDRV_Installer
Comcast Desktop Software (v1.2.0.9)
Compaq Presario Monitor Driver Software 5.00
Defraggler
Desktop Doctor
DH Driver Cleaner Professional Edition
DynoSim Engine Simulation v.4.200208 ProTools
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSTOOLS
essvatgt
Google Earth
Google Update Helper
Google Updater
HiJackThis
HP Product Detection
Intel(R) Network Connections
Java(TM) 6 Update 11
Java(TM) SE Runtime Environment 6
KhalInstallWrapper
Kodak EasyShare software
KwikTrig 3.0.5
KwikTrig 3.0.5 (C:\Program Files\KwikTrig\)
Lexmark 510 Series
Logitech SetPoint
Logitech Updater
Meter View
Microsoft .NET Framework 2.0
Microsoft Combat Flight Simulator 3.1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
netbrdg
OfotoXMI
Olds Cutlass & 442 Ver 2.0 Screen Saver
ParetoLogic Data Recovery
ParetoLogic DriverCure
ParetoLogic Privacy Controls
PL-2303 USB-to-Serial
QuickTime
RegCure
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
SFR
SHASTA
skin0001
SKINXSDK
SoundMAX
Spelling Dictionaries Support For Adobe Reader 9
Spybot - Search & Destroy
staticcr
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Windows Internet Explorer 7 (KB928089)
V CAST Music with Rhapsody
VC 9.0 Runtime
VC 9.0 Runtime
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VPRINTOL
Windows Installer Clean Up
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinPatrol
WIRELESS
ZoneAlarm
_____________________________________________________
and ROOT RETREAVER Log
HKLM\SECURITY\Policy\Secrets\SAC* 3/25/2008 2:15 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SECURITY\Policy\Secrets\SAI* 3/25/2008 2:15 PM 0 bytes Key name contains embedded nulls (*)
HKLM\SOFTWARE\Classes\CLSID\{5645C8C2-E277-11CF-8FDA-00AA00A14F93}\InprocServer32\ThreadingModel 1/26/2009 6:59 AM 5 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\LastChecked 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{2BF2CA35-CCAF-4E58-BAB7-4163BFA03B88}\RollCallDayStartSec 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{2BF2CA35-CCAF-4E58-BAB7-4163BFA03B88}\LastCheckSuccess 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\RollCallDayStartSec 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}\LastCheckSuccess 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{74AF07D8-FB8F-4D51-8AC7-927721D56EBB}\LastCheckSuccess 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\ClientState\{74AF07D8-FB8F-4D51-8AC7-927721D56EBB}\RollCallDayStartSec 11/13/2010 8:25 PM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Google\Update\network\secure-S-1-5-18\sk 11/14/2010 12:25 AM 176 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 11/14/2010 1:13 AM 80 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\SchedulingAgent\LastTaskRun 11/14/2010 12:25 AM 16 bytes Data mismatch between Windows API and raw hive data.
___________________________________________________________
MACHINE INFO:
Windows Version: Microsoft Windows XP Professional
--------------------------------------------------------------------------------
*** Common Devices ***
--------------------------------------------------------------------------------
System Name: Evo D510 CMT
Processor Name: Intel(R) Pentium(R) 4 CPU 2.26GHz
BIOS Name: 686O2 v2.14
Video card Name: ATI Radeon HD 2400 Series
Default Printer: Lexmark 510 Series --------------------------------------------------------------------------------
*** Installed Programs ***
--------------------------------------------------------------------------------
Number of Installed Programs: 148
Number of Running Processes: 62
Internet Explorer Version: 7.0.5730.11
DirectX Version: DirectX 9.0c (4.09.0000.0904)
MS Office Version: 12.0.6545.5000
--------------------------------------------------------------------------------
*** CPU Properties ***
--------------------------------------------------------------------------------
Physical Processors: 1
Logical Processors: 1
Name: Intel(R) Pentium(R) 4 CPU 2.26GHz
Description: x86 Family 15 Model 2 Stepping 4
Manufacturer: GenuineIntel
Frequency: 2259 MHz
External Clock Frequency: 533 MHz
Processor ID: 3FEBFBFF - 00000F24
Code Name: Northwood
Revision: B0 --------------------------------------------------------------------------------
*** Cache Properties ***
--------------------------------------------------------------------------------
L1 Data Cache: 8 KB
L2 Cache: 512 KB
END




(Selecting Uninstall application on close if you so wish)