Hello, my pc is running very slow since i installed bullguard.
Logfile of HijackThis v1.99.1
Scan saved at 4:55:04 PM, on 4/14/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BullGuard Software\BullGuard\BullGuard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\Program Files\PC fix\alternativ.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
https://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url=https://red.clientapps.yahoo.com/customize/ie/defaults/su/yie6/*https://www.yahoo.com]https://red.clientapps.yahoo.com/customize/ie/defaults/su/yie6/*https://www.yahoo.com[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [url=https://red.clientapps.yahoo.com/customize/ie/defaults/sb/yie6/*https://www.yahoo.com/search/ie.html]https://red.clientapps.yahoo.com/customize/ie/defaults/sb/yie6/*https://www.yahoo.com/search/ie.html[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [url=https://us.rd.yahoo.com/customize/ycomp/defaults/su/*https://www.yahoo.com]https://us.rd.yahoo.com/customize/ycomp/defaults/su/*https://www.yahoo.com[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: Web Assistant - {04DCB78C-AB45-83AD-A86A-6DFB90277939} - C:\Program Files\psquery\psquery.dll
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\System32\ipv6monk.dll
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\System32\ipv6mons.dll
O2 - BHO: (no name) - {8883081B-C5A7-4F04-8A65-BAEBE17B38DA} - C:\Program Files\Common Files\hope.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {B9697716-61E6-4FBC-89FD-EAC504D9EFE3} - C:\WINDOWS\System32\vtuvsqr.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3C9BC~3\Bar888.dll
O2 - BHO: (no name) - {E3BBA92A-FD8F-4DF7-8009-72BF6B78002E} - C:\WINDOWS\System32\gebyv.dll
O2 - BHO: 0 - {F4D249CB-342A-483C-9F90-F7A5B763E051} - C:\Program Files\Internet Explorer\laburu761.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3C9BC~3\Bar888.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [windows] C:\\windows_e57.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels32.exe
O4 - HKLM\..\Run: [bantool] C:\WINDOWS\system32\micro1\b9.exe
O4 - HKLM\..\Run: [ms03900107-56] C:\WINDOWS\ms03900107-56.exe
O4 - HKLM\..\Run: [BullGuard] "C:\Program Files\BullGuard Software\BullGuard\bullguard.exe" -boot
O4 - HKLM\..\Run: [win32087-5690010] C:\WINDOWS\win32087-5690010.exe
O4 - HKLM\..\Run: [win320707-569001] C:\WINDOWS\win320707-569001.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MBwtRifpT] ipschap(9).exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe"
O4 - HKCU\..\Run: [izwm] C:\Program Files\InetGet2\stub_109_4_0_4_0.exe
O4 - HKCU\..\Run: [1] "C:\WINDOWS\System32\1.exe"
O4 - HKCU\..\Run: [wukvgf] "C:\WINDOWS\System32\wukvgf.exe"
O4 - HKCU\..\Run: [wmds] "C:\WINDOWS\System32\wmds.exe"
O4 - HKCU\..\Run: [wvmgen] "C:\WINDOWS\System32\wvmgen.exe"
O4 - HKCU\..\Run: [waucu] "C:\WINDOWS\System32\waucu.exe"
O4 - HKCU\..\Run: [wekcf] "C:\WINDOWS\System32\wekcf.exe"
O4 - HKCU\..\Run: [wvvfy] "C:\WINDOWS\System32\wvvfy.exe"
O4 - HKCU\..\Run: [wrjtkh] "C:\WINDOWS\System32\wrjtkh.exe"
O4 - HKCU\..\Run: [wpavrgms] "C:\WINDOWS\System32\wpavrgms.exe"
O4 - HKCU\..\Run: [wpl] "C:\WINDOWS\System32\wpl.exe"
O4 - HKCU\..\Run: [wigw] "C:\WINDOWS\System32\wigw.exe"
O4 - HKCU\..\Run: [EARC] "C:\EARC.exe"
O4 - HKCU\..\Run: [FPLJ] "C:\FPLJ.exe"
O4 - HKCU\..\Run: [wysymcxj] "C:\WINDOWS\System32\wysymcxj.exe"
O4 - HKCU\..\Run: [walifehq] "C:\WINDOWS\System32\walifehq.exe"
O4 - HKCU\..\Run: [THDQ] "C:\THDQ.exe"
O4 - HKCU\..\Run: [MUJF] "C:\MUJF.exe"
O4 - HKCU\..\Run: [wsah] "C:\WINDOWS\System32\wsah.exe"
O4 - HKCU\..\Run: [LAKC] "C:\LAKC.exe"
O4 - HKCU\..\Run: [wljel] "C:\WINDOWS\System32\wljel.exe"
O4 - HKCU\..\Run: [wsnuxtyb] "C:\WINDOWS\System32\wsnuxtyb.exe"
O4 - HKCU\..\Run: [OHQB] "C:\OHQB.exe"
O4 - HKCU\..\Run: [NASR] "C:\NASR.exe"
O4 - HKCU\..\Run: [TKJQ] "C:\TKJQ.exe"
O4 - HKCU\..\Run: [FIREFOX] C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
O4 - HKCU\..\Run: [FKEH] "C:\FKEH.exe"
O4 - HKCU\..\Run: [PPLE] "C:\PPLE.exe"
O4 - HKCU\..\Run: [CBUJ] "C:\CBUJ.exe"
O4 - HKCU\..\Run: [JBNK] "C:\JBNK.exe"
O4 - HKCU\..\Run: [SKHM] "C:\SKHM.exe"
O4 - HKCU\..\Run: [OCSI] "C:\OCSI.exe"
O4 - HKCU\..\Run: [TATO] "C:\TATO.exe"
O4 - HKCU\..\Run: [RNDM] "C:\RNDM.exe"
O4 - HKCU\..\Run: [JBDP] "C:\JBDP.exe"
O4 - HKCU\..\Run: [JKGJ] "C:\JKGJ.exe"
O4 - HKCU\..\Run: [ORJM] "C:\ORJM.exe"
O4 - HKCU\..\Run: [GGHD] "C:\GGHD.exe"
O4 - HKCU\..\Run: [MMLP] "C:\MMLP.exe"
O4 - HKCU\..\Run: [UQOG] "C:\UQOG.exe"
O4 - HKCU\..\Run: [GTMK] "C:\GTMK.exe"
O4 - HKCU\..\Run: [BCII] "C:\BCII.exe"
O4 - HKCU\..\Run: [GMJN] "C:\GMJN.exe"
O4 - HKCU\..\Run: [AFBO] "C:\AFBO.exe"
O4 - HKCU\..\Run: [BJQT] "C:\BJQT.exe"
O4 - HKCU\..\Run: [SFDR] "C:\SFDR.exe"
O4 - HKCU\..\Run: [RERU] "C:\RERU.exe"
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard Software\BullGuard\bullguard.exe"
O4 - HKCU\..\Run: [PaSystem] "C:\Program Files\pasystem\pasystem.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [ttool] C:\WINDOWS\9129837.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Startup: desktop(2).ini
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\swinqodv.exe
O4 - Global Startup: desktop(2).ini
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\MESSEN~1\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\MESSEN~1\yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
https://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {26098EA2-C95D-48EA-89B4-63C5A63BD42F} -
https://www.pacimedia.com/install/pcs_0031.exe O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) -
https://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) -
https://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
https://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
https://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) -
https://www.miniclip.com/ricochet/ReflexiveWebGameLoader.cab O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) -
https://www.e-games.com.my/com/EGamesPlugin.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
https://software-dl.real.com/19bc180b6f07a1a92400/netzip/RdxIE601.cab O16 - DPF: {64696FB5-BA15-4920-B789-F35D3FC0A36A} -
https://www.icannnews.com/app/ST/ax.ocx O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
https://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_1.ocx O16 - DPF: {71CBDCD9-0830-4470-A890-35D364DA352C} -
https://scripts.downloadv3.com/binaries/P2EClient/EGAUTH_1047_EN_XP.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} -
https://download.shockwave.com/pub/otoy/OTOYAX.cab O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
https://chat.yahoo.com/cab/yacsui.cab O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} -
https://www.pacimedia.com/install/pcs_0009.exe O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) -
https://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O16 - DPF: {E427A57F-1A94-0BFC-6D7A-6DC214946AD4} - ms-its:mhtml:file://c:\\nosuch.mht!https://users.perfhost.com/~zone14/z/index.chm::/index.exe
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) -
https://chat.yahoo.com/cab/yvwrctl.cab O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) -
https://www5.incredimail.com/contents/setup/downloader_t5/imloader.cab O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} -
https://winfixer.com/pages/scanner/WFI.cab O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
https://cdn.digitalcity.com/_media/dalaillama/ampx.cab O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} -
https://download.overpro.com/WildApp.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{7869128A-938D-44CB-9434-8ECA8AA6D5C5}: NameServer = 85.255.115.45,85.255.112.215
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D6DFE76-485A-4517-A402-3ACB7682D70D}: NameServer = 85.255.115.45,85.255.112.215
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.45 85.255.112.215
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.45 85.255.112.215
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\n8l80i3ue8.dll (file missing)
O20 - Winlogon Notify: gebyv - C:\WINDOWS\System32\gebyv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vtuvsqr - C:\WINDOWS\SYSTEM32\vtuvsqr.dll
O20 - Winlogon Notify: WASHData - C:\WINDOWS\system32\surwvdrv(2).dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O20 - Winlogon Notify: winstart - winstart.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: appmgmts.exe - Unknown owner - C:\WINDOWS\System32\appmgmts.exe (file missing)
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard Software - C:\Program Files\BullGuard Software\BullGuard\BullGuardUpdate.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e mc-110-12-0000501 (file missing)
O23 - Service: comctl32(4).exe - Unknown owner - C:\WINDOWS\System32\comctl32(4).exe (file missing)
O23 - Service: cryptext.exe - Unknown owner - C:\WINDOWS\System32\cryptext.exe (file missing)
O23 - Service: dnsapi(3)(2).exe - Unknown owner - C:\WINDOWS\System32\dnsapi(3)(2).exe (file missing)
O23 - Service: dpnhupnp.exe - Unknown owner - C:\WINDOWS\System32\dpnhupnp.exe (file missing)
O23 - Service: dpus11.exe - Unknown owner - C:\WINDOWS\System32\dpus11.exe (file missing)
O23 - Service: dxmasf.exe - Unknown owner - C:\WINDOWS\System32\dxmasf.exe (file missing)
O23 - Service: ersvc(2).exe - Unknown owner - C:\WINDOWS\System32\ersvc(2).exe (file missing)
O23 - Service: ialmrnt5(6).exe - Unknown owner - C:\WINDOWS\System32\ialmrnt5(6).exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iilmdev5(5).exe - Unknown owner - C:\WINDOWS\System32\iilmdev5(5).exe (file missing)
O23 - Service: ir50_qcx.exe - Unknown owner - C:\WINDOWS\System32\ir50_qcx.exe (file missing)
O23 - Service: jgpl400.exe - Unknown owner - C:\WINDOWS\System32\jgpl400.exe (file missing)
O23 - Service: mcd32(2).exe - Unknown owner - C:\WINDOWS\System32\mcd32(2).exe (file missing)
O23 - Service: mqlogmgr.exe - Unknown owner - C:\WINDOWS\System32\mqlogmgr.exe (file missing)
O23 - Service: msieftp(3).exe - Unknown owner - C:\WINDOWS\System32\msieftp(3).exe (file missing)
O23 - Service: msstdfmt.exe - Unknown owner - C:\WINDOWS\System32\msstdfmt.exe (file missing)
O23 - Service: mswsock(2).exe - Unknown owner - C:\WINDOWS\System32\mswsock(2).exe (file missing)
O23 - Service: msxml2.exe - Unknown owner - C:\WINDOWS\System32\msxml2.exe (file missing)
O23 - Service: mtxoci.exe - Unknown owner - C:\WINDOWS\System32\mtxoci.exe (file missing)
O23 - Service: netlogon(9).exe - Unknown owner - C:\WINDOWS\System32\netlogon(9).exe (file missing)
O23 - Service: pdh.exe - Unknown owner - C:\WINDOWS\System32\pdh.exe (file missing)
O23 - Service: pid(2).exe - Unknown owner - C:\WINDOWS\System32\pid(2).exe (file missing)
O23 - Service: pmspl(2).exe - Unknown owner - C:\WINDOWS\System32\pmspl(2).exe (file missing)
O23 - Service: psapi(5)(2).exe - Unknown owner - C:\WINDOWS\System32\psapi(5)(2).exe (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: ssdpapi.exe - Unknown owner - C:\WINDOWS\System32\ssdpapi.exe (file missing)
O23 - Service: ssdpsrv(8).exe - Unknown owner - C:\WINDOWS\System32\ssdpsrv(8).exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: traffic(2).exe - Unknown owner - C:\WINDOWS\System32\traffic(2).exe (file missing)
O23 - Service: wintrust(3).exe - Unknown owner - C:\WINDOWS\System32\wintrust(3).exe (file missing)