This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] internet explorer is dead computer keeps freeezing

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The last time my computer worked smoothly was a few weeks back. While surfing McAfee popped up saying there was an unexpected registry change that's been blocked. Shortly after that I started having all sorts of problems where the computer would freeze etc. Also my McAfee expired shortly after that and while trying to renew noticed that my internet explorer also no longer worked. One more thing that I'm not sure is related but I discovered when I reached the end of my rope and was trying to make copies of my files before re-formatting the hard drive is that I can't seem to get files to copy to a CD.

Anyway here is my HJT log and my MWB log. Thanks in advance you guys were a huge help years ago with my first computer problems.

MWB Log:

Malwarebytes' Anti-Malware 1.36
Database version: 2056
Windows 5.1.2600 Service Pack 3

4/28/2009 9:48:48 PM
mbam-log-2009-04-28 (21-48-48).txt

Scan type: Quick Scan
Objects scanned: 85495
Time elapsed: 3 minute(s), 29 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 4
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lowsec (Stolen.Data) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\SYSTEM32\lowsec\local.ds (Stolen.Data) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lowsec\user.ds (Stolen.Data) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lowsec\user.ds.lll (Stolen.Data) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\sdra64.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.


and here is my HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:54:14 PM, on 4/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.us/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5825 bytes
Hi and Welcome,

Please do the following:


STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.


Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
DDS.txt


DDS (Ver_09-03-16.01) - NTFSx86
Run by [removed] at 17:41:48.51 on Thu 05/07/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.611 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Donny\Desktop\dds.pif

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://bfc.myway.com/search/de_srchlft.html
uStart Page = hxxp://www.google.us/
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Dell Photo AIO Printer 922] "c:\program files\dell photo aio printer 922\dlbtbmgr.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
uPolicies-explorer: NoSMBalloonTip = 1 (0x1)
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\donny\applic~1\mozilla\firefox\profiles\3n4vk88f.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://start.mozilla.org/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll

—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-27 325640]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-4-27 27656]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-27 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-4-27 298264]

=============== Created Last 30 ================

2009-05-07 17:41 –d-h— c:\windows\PIF
2009-05-06 18:45 –d—– c:\windows\system32\KB905474
2009-04-28 21:47 –d—– c:\program files\Trend Micro
2009-04-28 21:44 –d—– c:\docume~1\donny\applic~1\Malwarebytes
2009-04-28 21:44 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-04-28 21:44 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-28 21:44 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-28 21:44 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-04-27 20:27 –d-h— C:\$AVG8.VAULT$
2009-04-27 18:31 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-04-27 18:31 10,520 a——- c:\windows\system32\avgrsstx.dll
2009-04-27 18:31 325,640 a——- c:\windows\system32\drivers\avgldx86.sys
2009-04-27 18:31 –d—– c:\windows\system32\drivers\Avg
2009-04-27 18:31 –d—– c:\program files\AVG
2009-04-27 18:31 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-04-24 15:47 –dsh— c:\documents and settings\donny\IETldCache
2009-04-24 15:46 –d—– c:\windows\ie8updates
2009-04-24 15:45 78,336 a——- c:\windows\system32\ieencode.dll
2009-04-24 15:44 105,984 ——– c:\windows\system32\dllcache\iecompat.dll
2009-04-15 22:42 –d—– c:\docume~1\alluse~1\applic~1\Citrix
2009-04-15 22:31 61,224 a——- c:\documents and settings\donny\GoToAssistDownloadHelper.exe
2009-04-15 22:21 –d—– c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-04-14 19:53 284,160 ——– c:\windows\system32\dllcache\pdh.dll
2009-04-14 19:53 401,408 ——– c:\windows\system32\dllcache\rpcss.dll
2009-04-14 19:53 473,600 ——– c:\windows\system32\dllcache\fastprox.dll
2009-04-14 19:53 227,840 ——– c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 19:53 110,592 ——– c:\windows\system32\dllcache\services.exe
2009-04-14 19:53 729,088 ——– c:\windows\system32\dllcache\lsasrv.dll
2009-04-14 19:53 453,120 ——– c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 19:53 714,752 ——– c:\windows\system32\dllcache\ntdll.dll
2009-04-14 19:53 617,472 ——– c:\windows\system32\dllcache\advapi32.dll
2009-04-14 19:52 1,203,922 ——– c:\windows\system32\dllcache\sysmain.sdb
2009-04-14 19:52 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-04-14 19:52 215,552 ——– c:\windows\system32\dllcache\wordpad.exe

==================== Find3M ====================

2009-03-21 09:06 989,696 ——– c:\windows\system32\dllcache\kernel32.dll
2009-03-06 09:22 284,160 a——- c:\windows\system32\pdh.dll
2009-03-02 18:04 1,499,136 ——– c:\windows\system32\dllcache\shdocvw.dll
2009-02-20 13:09 459,264 a——- c:\windows\system32\dllcache\msfeeds.dll
2009-02-20 13:09 268,288 a——- c:\windows\system32\dllcache\iertutil.dll
2009-02-20 13:09 52,224 a——- c:\windows\system32\dllcache\msfeedsbs.dll
2009-02-20 13:09 6,066,176 a——- c:\windows\system32\dllcache\ieframe.dll
2009-02-20 13:09 383,488 a——- c:\windows\system32\dllcache\ieapfltr.dll
2009-02-20 13:09 63,488 a——- c:\windows\system32\dllcache\icardie.dll
2009-02-20 05:20 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 03:11 3,068,416 a——- c:\windows\system32\dllcache\mshtml.dll
2009-02-20 03:10 666,112 a——- c:\windows\system32\wininet.dll
2009-02-20 03:10 666,112 a——- c:\windows\system32\dllcache\wininet.dll
2009-02-20 03:10 619,520 a——- c:\windows\system32\dllcache\urlmon.dll
2009-02-20 03:10 81,920 ——– c:\windows\system32\dllcache\ieencode.dll
2009-02-09 07:10 729,088 a——- c:\windows\system32\lsasrv.dll
2009-02-09 07:10 714,752 a——- c:\windows\system32\ntdll.dll
2009-02-09 07:10 617,472 a——- c:\windows\system32\advapi32.dll
2009-02-09 07:10 401,408 a——- c:\windows\system32\rpcss.dll
2009-02-09 06:13 1,846,784 a——- c:\windows\system32\win32k.sys
2009-02-09 06:13 1,846,784 a——- c:\windows\system32\win32k(2)(2).sys
2009-02-09 06:13 1,846,784 ——– c:\windows\system32\dllcache\win32k.sys
2009-02-07 19:02 2,066,048 ——– c:\windows\system32\dllcache\ntkrnlpa.exe

============= FINISH: 17:42:42.03 ===============

Attach.txt


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-03-16.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 1/16/2005 6:10:44 PM
System Uptime: 5/7/2009 5:23:17 PM (0 hours ago)

Motherboard: Dell Inc. | | 0U7077
Processor: Intel® Pentium® 4 CPU 3.20GHz | Microprocessor | 3192/800mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 145 GiB total, 104.946 GiB free.
D: is CDROM ()
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID:
Description: PCI Modem
Device ID: PCI\VEN_8086&DEV;_1080&SUBSYS;_10000028&REV;_04\4&10416D21&0&08F0
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_8086&DEV;_1080&SUBSYS;_10000028&REV;_04\4&10416D21&0&08F0
Service:

==== System Restore Points ===================

RP1: 9/8/2006 7:04:38 PM - System Checkpoint
RP2: 9/8/2006 7:13:51 PM - running good
RP3: 9/12/2006 5:25:52 PM - Software Distribution Service 2.0
RP4: 9/27/2006 6:11:07 PM - Software Distribution Service 2.0
RP5: 10/11/2006 8:08:31 PM - Software Distribution Service 2.0
RP6: 11/16/2006 3:00:17 AM - Software Distribution Service 2.0
RP7: 12/17/2006 3:00:20 AM - Software Distribution Service 2.0
RP8: 1/1/2007 9:24:45 PM - Installed iTunes
RP9: 1/1/2007 10:44:46 PM - Removed QuickTime
RP10: 1/14/2007 3:00:18 AM - Software Distribution Service 2.0
RP11: 2/15/2007 3:00:17 AM - Software Distribution Service 2.0
RP12: 2/25/2007 1:21:57 PM - Removed APC PowerChute Personal Edition
RP13: 3/14/2007 8:41:55 PM - Software Distribution Service 2.0
RP14: 4/3/2007 11:12:57 PM - Software Distribution Service 2.0
RP15: 4/11/2007 3:00:17 AM - Software Distribution Service 2.0
RP16: 4/11/2007 9:25:43 PM - Software Distribution Service 2.0
RP17: 8/22/2008 6:22:15 PM - Installed HPSU306Stub
RP18: 9/14/2008 11:04:41 PM - Software Distribution Service 3.0
RP19: 9/16/2008 10:22:23 PM - Software Distribution Service 3.0
RP20: 9/16/2008 11:13:26 PM - Software Distribution Service 3.0
RP21: 9/28/2008 6:25:07 PM - Software Distribution Service 3.0
RP22: 10/6/2008 8:05:20 PM - Software Distribution Service 3.0
RP23: 10/8/2008 10:43:37 PM - Software Distribution Service 3.0
RP24: 10/10/2008 12:06:09 AM - Software Distribution Service 3.0
RP25: 10/20/2008 5:44:47 PM - Software Distribution Service 3.0
RP26: 10/27/2008 7:34:13 PM - Software Distribution Service 3.0
RP27: 11/21/2008 5:25:05 PM - Software Distribution Service 3.0
RP28: 12/11/2008 6:03:52 PM - Software Distribution Service 3.0
RP29: 12/22/2008 2:58:23 PM - Software Distribution Service 3.0
RP30: 1/13/2009 6:45:43 PM - Software Distribution Service 3.0
RP31: 1/13/2009 10:12:36 PM - Installed Google Earth.
RP32: 2/11/2009 5:26:30 PM - Software Distribution Service 3.0
RP33: 2/22/2009 9:26:16 PM - Installed iTunes
RP34: 2/22/2009 10:19:44 PM - Removed QuickTime
RP35: 2/22/2009 10:37:18 PM - Removed iTunes
RP36: 2/22/2009 10:42:49 PM - Installed iTunes
RP37: 2/28/2009 3:00:15 AM - Software Distribution Service 3.0
RP38: 3/15/2009 9:01:02 PM - Software Distribution Service 3.0
RP39: 4/9/2009 7:55:07 AM - Restore Operation
RP40: 4/9/2009 8:28:29 AM - Software Distribution Service 3.0
RP41: 4/13/2009 9:10:16 PM - Restore Operation
RP42: 4/14/2009 10:22:49 PM - Software Distribution Service 3.0
RP43: 4/15/2009 9:52:48 PM - Installed Windows NLSDownlevelMapping.
RP44: 4/15/2009 9:53:20 PM - Installed Windows IDNMitigationAPIs.
RP45: 4/15/2009 9:53:37 PM - Installed Windows Internet Explorer 7.
RP46: 4/15/2009 10:08:25 PM - before IE remove
RP47: 4/15/2009 10:09:10 PM - Restore Operation
RP48: 4/15/2009 10:19:51 PM - Restore Operation
RP49: 4/24/2009 3:00:46 PM - Software Distribution Service 3.0
RP50: 4/24/2009 3:45:27 PM - Installed Windows Internet Explorer 8.
RP51: 4/24/2009 3:46:03 PM - Software Distribution Service 3.0
RP52: 4/24/2009 3:50:55 PM - Software Distribution Service 3.0
RP53: 4/27/2009 6:31:18 PM - Installed AVG Free 8.5
RP54: 4/27/2009 8:11:06 PM - Avg8 Update
RP55: 4/28/2009 8:36:20 AM - Avg8 Update
RP56: 4/28/2009 9:12:24 PM - Installed Microsoft Fix it 50027
RP57: 4/28/2009 10:43:11 PM - Software Distribution Service 3.0
RP58: 5/6/2009 6:44:35 PM - Software Distribution Service 3.0

==== Installed Programs ======================

Adobe Flash Player Plugin
Adobe Reader 7.0.8
Apple Mobile Device Support
Apple Software Update
AVG 8.5
Bonjour
Broadcom Advanced Control Suite 2
BufferChm
CameraDrivers
CameraUserGuides
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Networking Guide
Dell Photo AIO Printer 922
DeviceDiscovery
DeviceManagementQFolder
eSupportQFolder
FTDI USB Serial Converter Drivers
G5a922EN
Google Earth
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
HP Imaging Device Functions 9.0
HP Photosmart Cameras 9.0
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Solution Center 9.0
HP Update
hpicamDrvQFolder
HPProductAssistant
InstantShareDevicesMFC
Intel Application Accelerator
Intel® 537EP V9x DF PCI Modem
Internet Explorer Default Page
IrfanView (remove only)
iTunes
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment, SE v1.4.2_03
Java 2 Runtime Environment, SE v1.4.2_06
Learn2 Player (Uninstall Only)
Logitech MouseWare 9.77
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
McAfee Shredder
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Small Business Edition 2003
Microsoft Visual C++ 2005 Redistributable
Modem Event Monitor
Modem Helper
Modem On Hold
Mozilla Firefox (3.0.10)
My Way Search Assistant
NVIDIA Drivers
PanoStandAlone
Photo Click
PowerDVD 5.3
PSSWCORE
Qualxserve Service Agreement
QuickTime
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB963027)
SolutionCenter
Sonic DLA
Sonic MyDVD
Sonic RecordNow! Plus
Sonic Update Manager
Sound Blaster Live! 24-bit
Status
System Requirements Lab
TrayApp
UnloadSupport
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VideoToolkit01
WebFldrs XP
WebReg
Winamp (remove only)
Windows Genuine Advantage Notifications (KB905474)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
WinZip

==== End Of File ===========================


GMER.txt

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-07 18:50:50
Windows 5.1.2600 Service Pack 3


—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\wdfmgr.exe[336] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 008D2DFD
.text C:\WINDOWS\system32\wdfmgr.exe[336] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 008D2DBA
.text C:\WINDOWS\system32\wdfmgr.exe[336] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 008D2D7E
.text C:\WINDOWS\system32\wdfmgr.exe[336] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 008D2D63
.text C:\WINDOWS\system32\wdfmgr.exe[336] WS2_32.dll!send 71AB4C27 5 Bytes JMP 008D2BEF
.text C:\WINDOWS\system32\wdfmgr.exe[336] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 008D2CE1
.text C:\WINDOWS\system32\wdfmgr.exe[336] WS2_32.dll!recv 71AB676F 5 Bytes JMP 008D2C27
.text C:\WINDOWS\system32\wdfmgr.exe[336] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 008D2C5F
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1056] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 010F2D63
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1056] WS2_32.dll!send 71AB4C27 5 Bytes JMP 010F2BEF
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1056] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 010F2CE1
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1056] WS2_32.dll!recv 71AB676F 5 Bytes JMP 010F2C27
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1056] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 010F2C5F
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1056] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 010F2DFD
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1056] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 010F2DBA
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1056] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 010F2D7E
.text C:\Program Files\Bonjour\mDNSResponder.exe[1888] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00AA2D63
.text C:\Program Files\Bonjour\mDNSResponder.exe[1888] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00AA2BEF
.text C:\Program Files\Bonjour\mDNSResponder.exe[1888] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00AA2CE1
.text C:\Program Files\Bonjour\mDNSResponder.exe[1888] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00AA2C27
.text C:\Program Files\Bonjour\mDNSResponder.exe[1888] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00AA2C5F
.text C:\Program Files\Bonjour\mDNSResponder.exe[1888] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00AA2DFD
.text C:\Program Files\Bonjour\mDNSResponder.exe[1888] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00AA2DBA
.text C:\Program Files\Bonjour\mDNSResponder.exe[1888] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00AA2D7E
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2016] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01082DFD
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2016] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01082DBA
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2016] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01082D7E
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2016] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01082D63
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2016] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01082BEF
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2016] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01082CE1
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2016] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01082C27
.text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[2016] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01082C5F
.text C:\WINDOWS\Explorer.EXE[2276] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 017F2DFD
.text C:\WINDOWS\Explorer.EXE[2276] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 017F2DBA
.text C:\WINDOWS\Explorer.EXE[2276] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 017F2D7E
.text C:\WINDOWS\Explorer.EXE[2276] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 017F2D63
.text C:\WINDOWS\Explorer.EXE[2276] WS2_32.dll!send 71AB4C27 5 Bytes JMP 017F2BEF
.text C:\WINDOWS\Explorer.EXE[2276] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 017F2CE1
.text C:\WINDOWS\Explorer.EXE[2276] WS2_32.dll!recv 71AB676F 5 Bytes JMP 017F2C27
.text C:\WINDOWS\Explorer.EXE[2276] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 017F2C5F
.text C:\Program Files\iTunes\iTunesHelper.exe[3188] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 01FB2DFD
.text C:\Program Files\iTunes\iTunesHelper.exe[3188] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 01FB2DBA
.text C:\Program Files\iTunes\iTunesHelper.exe[3188] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 01FB2D7E
.text C:\Program Files\iTunes\iTunesHelper.exe[3188] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 01FB2D63
.text C:\Program Files\iTunes\iTunesHelper.exe[3188] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01FB2BEF
.text C:\Program Files\iTunes\iTunesHelper.exe[3188] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 01FB2CE1
.text C:\Program Files\iTunes\iTunesHelper.exe[3188] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01FB2C27
.text C:\Program Files\iTunes\iTunesHelper.exe[3188] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01FB2C5F
.text C:\Program Files\iPod\bin\iPodService.exe[3428] ADVAPI32.dll!CryptDestroyKey 77DE9EBC 7 Bytes JMP 00B92DFD
.text C:\Program Files\iPod\bin\iPodService.exe[3428] ADVAPI32.dll!CryptDecrypt 77DEA129 7 Bytes JMP 00B92DBA
.text C:\Program Files\iPod\bin\iPodService.exe[3428] ADVAPI32.dll!CryptEncrypt 77DEE360 7 Bytes JMP 00B92D7E
.text C:\Program Files\iPod\bin\iPodService.exe[3428] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00B92D63
.text C:\Program Files\iPod\bin\iPodService.exe[3428] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00B92BEF
.text C:\Program Files\iPod\bin\iPodService.exe[3428] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00B92CE1
.text C:\Program Files\iPod\bin\iPodService.exe[3428] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00B92C27
.text C:\Program Files\iPod\bin\iPodService.exe[3428] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00B92C5F

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\iaStor \Device\Ide\iaStor0 85FB6560
Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 85FB6560

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\Fastfat \Fat B8E2FD20

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Threads - GMER 1.0.15 —-

Thread System [4:692] 85FE7300
Thread System [4:696] 85FD39F6
Thread System [4:700] 86005387
Thread System [4:704] 85FD6971
Thread System [4:352] 85FE7300
Thread System [4:1444] 85FD39F6
Thread System [4:3036] 86005387
Thread System [4:960] 85FD6971
Thread System [4:3248] 85FE7300
Thread System [4:3872] 85FD39F6
Thread System [4:1756] 86005387
Thread System [4:536] 85FD6971

—- EOF - GMER 1.0.15 —-


At the moment my computer seems to be running well but I've had to restart probably 5x in the last day when it freezes up while surfing the net. Also my Firefox appears to have reverted back to its default modes without ever prompting or notifying me it was updating.
Hi,

Please do the following:

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 13)

NEXT


Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

Please download ATF Cleaner by Atribune.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
    • If you use Firefox browser
    • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.

NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include
  • MBAM Log
  • Kaspersky report
I cannot get all the way through a kaspersky scan without the computer freezing up but here is my mbam log: Malwarebytes' Anti-Malware 1.36 Database version: 2096 Windows 5.1.2600 Service Pack 3 5/8/2009 11:55:12 PM mbam-log-2009-05-08 (23-55-12).txt Scan type: Quick Scan Objects scanned: 87662 Time elapsed: 3 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,


Try this scan instead:

Please run the following online scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start.  The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button.  The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Almost made it through a full scan with the eset scanner and then the computer froze again. This time though I got a sustained warning tone from the computer itself. I also forgot to mention I've had two blue screen instances since I've started having this problem. I have photos of the blue screen but they are too large to attach so I've included them here. I'm running another eset scan right now if it finishes I'll post the results.

[external image: Posted Image]

[external image: Posted Image]
Hi,

This does not appear to be a malware issue…I think you are on the brink of a hardware failure.

let me clean up the tools we used for malware diagnosis, then you need to create a new topic in our hardware forum,

link to this topic so the tech gurus can see it's not malware related.

Please do the following:

Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program


next:

download erunt to back up your registry in case you haven't already done so.

Download ERUNT to your Desktop (right-click the link, select Save Link/Target As…, select your Desktop and press Save)
Right-click erunt.zip, choose Extract All… and follow the prompts to unzip the program.
Open the erunt folder on your Desktop and double-click ERUNT.exe to start the program
Click OK for all the prompts to back up your registry to the default location.

Note: if it becomes necessary to restore the registry, open the backup folder and start ERDNT.exe

make sure you make a back up of all your important files while you have the opportunity to do so.

Good luck.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI