A friend of a friend brought me a laptop that has been "running slow" for a couple of weeks now. I tried to run malwarebytes on it but it shuts down whenever I try to install it or for late matter whenever I try to go to this or any website dealing with getting it cleaned up.
Thanks for the help
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/31 11:33
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
——————-
Name: aujasnkj.sys
Image Path: C:\DOCUME~1\user\LOCALS~1\Temp\aujasnkj.sys
Address: 0xED289000 Size: 84352 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xEEC64000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7CF3000 Size: 8192 File Visible: No Signed: -
Status: -
Name: mchInjDrv.sys
Image Path: C:\WINDOWS\system32\Drivers\mchInjDrv.sys
Address: 0xF7F08000 Size: 2560 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xED7DC000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
——————-
#: 041 Function Name: NtCreateKey
Status: Hooked by "PCTCore.sys" at address 0xf76cd514
#: 047 Function Name: NtCreateProcess
Status: Hooked by "PCTCore.sys" at address 0xf76bc282
#: 048 Function Name: NtCreateProcessEx
Status: Hooked by "PCTCore.sys" at address 0xf76bc474
#: 063 Function Name: NtDeleteKey
Status: Hooked by "PCTCore.sys" at address 0xf76cdd00
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "PCTCore.sys" at address 0xf76cdfb8
#: 119 Function Name: NtOpenKey
Status: Hooked by "PCTCore.sys" at address 0xf76cc3fa
#: 192 Function Name: NtRenameKey
Status: Hooked by "PCTCore.sys" at address 0xf76ce422
#: 247 Function Name: NtSetValueKey
Status: Hooked by "PCTCore.sys" at address 0xf76cd7d8
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "PCTCore.sys" at address 0xf76bbf32
==EOF==
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 11:28:30.63 on 08/31/09
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.494.154 [GMT -4:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe
C:\WINDOWS\system32\lxdicoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AOL\1171387913\ee\AOLSoftware.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Cingular\Communication Manager\CingularCCM.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\RegistryPC\RegistryPC.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Cingular\Communication Manager\bmctl.exe
C:\WINDOWS\system32\wuauclt.exe
E:\dds.pif
C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: VINMaker: {6b3e26a3-c1e2-4125-8c8f-f1303f748c3a} - c:\windows\system32\kdpini.dll
BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - Google Toolbar Notifier BHO
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - Google Dictionary Compression sdch
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [RegistryPC] c:\program files\registrypc\RegistryPC.exe -boot
uRun: [DellSupport] "c:\program files\dell support\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SunJavaUpdateSched] c:\program files\java\j2re1.4.2_03\bin\jusched.exe
mRun: [RecoverFromReboot] c:\windows\temp\RecoverFromReboot.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [PrinTray] c:\windows\system32\spool\drivers\w32x86\3\printray.exe
mRun: [mmtask] c:\program files\musicmatch\musicmatch jukebox\mmtask.exe
mRun: [lxdimon.exe] "c:\program files\lexmark 3500-4500 series\lxdimon.exe"
mRun: [lxdiamon] "c:\program files\lexmark 3500-4500 series\lxdiamon.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe
mRun: [HP Software Update] c:\program files\hewlett-packard\hp software update\HPWuSchd2.exe
mRun: [HostManager] c:\program files\common files\aol\1171387913\ee\AOLSoftware.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [FaxCenterServer] "c:\program files\\lexmark fax solutions\fm3032.exe" /s
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [Cingular Communication Manager] c:\program files\cingular\communication manager\CingularCCM.exe -a
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
uPolicies-explorer: NoThumbnailCache = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
LSP: bmnet.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126026505890
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: cafadcfdabbdece - c:\windows\system32\cafadcfdabbdece.dll
Notify: igfxcui - igfxdev.dll
Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-6-5 130936]
R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [2009-7-31 99248]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-6-5 348752]
R2 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-6-5 1095560]
S3 ACGPRS;Sierra Wireless 3G Adapter;c:\windows\system32\drivers\acgprs.sys [2006-1-26 97280]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys –> c:\windows\system32\drivers\rootrepeal.sys [?]
=============== Created Last 30 ================
2009-08-28 15:13 39,936 a——- c:\windows\system32\02eb90b255815e9067361a3b549c9ff6.sys
2009-08-28 15:13 195,584 a——- c:\windows\system32\kdpini.dll
2009-08-28 10:34 –d—– c:\windows\system32\dllcache\cache
2009-08-28 10:00 a-dshr– C:\cmdcons
2009-08-28 09:54 229,376 a——- c:\windows\PEV.exe
2009-08-28 09:54 161,792 a——- c:\windows\SWREG.exe
2009-08-28 09:54 98,816 a——- c:\windows\sed.exe
2009-08-27 17:41 –d—– c:\docume~1\user\applic~1\Malwarebytes
2009-08-27 17:40 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-27 17:40 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-27 17:40 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-27 17:40 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-27 15:51 3,942,048 a——- C:\mbam-setup.exe
2009-08-27 08:50 –d—– c:\docume~1\user\applic~1\RegistryPC
2009-08-27 08:50 –d—– c:\program files\RegistryPC
2009-08-26 09:26 –d—– C:\TaxCut Business 2008
2009-08-26 08:41 1,089,601 ——– c:\windows\system32\dllcache\ntprint.cat
2009-08-25 11:04 –d—– c:\windows\system32\XPSViewer
2009-08-25 11:02 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-25 11:02 117,760 ——– c:\windows\system32\prntvpt.dll
2009-08-25 11:02 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-25 11:02 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-08-25 11:02 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-08-25 11:02 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-08-25 11:02 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-25 11:02 –d—– C:\d0c1720f1bcb8be2a9
2009-08-23 11:04 –d—– c:\program files\MSXML 6.0
2009-08-21 22:16 2,060,288 a——- c:\windows\system32\usbaaplrc.dll
2009-08-21 22:16 39,424 a——- c:\windows\system32\drivers\usbaapl.sys
2009-08-20 11:06 –d—– c:\program files\common files\ODBC
2009-08-20 11:02 –d—– c:\windows\ServicePackFiles
2009-08-19 12:41 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
2009-08-19 12:37 655,872 ——– c:\windows\system32\dllcache\mstscax.dll
2009-08-05 05:11 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll
==================== Find3M ====================
2009-08-13 11:45 280,064 ——– c:\windows\system32\cafadcfdabbdece.dll
2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll
2009-07-19 09:33 3,597,824 a——- c:\windows\system32\dllcache\cache\mshtml.dll
2009-07-19 09:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll
2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 14:55 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 10:08 286,720 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-13 10:08 5,537,792 ——– c:\windows\system32\dllcache\wmp.dll
2009-07-10 09:42 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-06-29 07:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-06-29 07:07 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-29 04:35 634,632 ——– c:\windows\system32\dllcache\iexplore.exe
2009-06-29 04:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat
2009-06-29 04:33 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-06-25 04:44 724,480 a——- c:\windows\system32\lsasrv.dll
2009-06-25 04:44 298,496 a——- c:\windows\system32\kerberos.dll
2009-06-25 04:44 168,448 a——- c:\windows\system32\schannel.dll
2009-06-25 04:44 133,632 a——- c:\windows\system32\msv1_0.dll
2009-06-25 04:44 59,392 a——- c:\windows\system32\wdigest.dll
2009-06-25 04:44 56,320 a——- c:\windows\system32\secur32.dll
2009-06-25 04:44 724,480 ——– c:\windows\system32\dllcache\lsasrv.dll
2009-06-25 04:44 298,496 ——– c:\windows\system32\dllcache\kerberos.dll
2009-06-25 04:44 168,448 ——– c:\windows\system32\dllcache\schannel.dll
2009-06-25 04:44 133,632 ——– c:\windows\system32\dllcache\msv1_0.dll
2009-06-25 04:44 59,392 ——– c:\windows\system32\dllcache\wdigest.dll
2009-06-25 04:44 56,320 ——– c:\windows\system32\dllcache\secur32.dll
2009-06-22 07:34 92,544 ——– c:\windows\system32\dllcache\ksecdd.sys
2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-16 10:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 10:55 82,432 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 07:50 76,288 ——– c:\windows\system32\dllcache\telnet.exe
2009-06-10 10:21 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 10:21 84,992 ——– c:\windows\system32\dllcache\avifil32.dll
2009-06-10 02:32 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 02:32 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 03:42 655,872 a——- c:\windows\system32\mstscax.dll
2009-06-03 15:27 1,290,752 a——- c:\windows\system32\quartz.dll
2009-06-03 15:27 1,290,752 ——– c:\windows\system32\dllcache\quartz.dll
2006-03-22 08:13 259,208 a——- c:\docume~1\user\applic~1\GDIPFONTCACHEV1.DAT
2006-03-14 01:44 6,531 a——- c:\program files\FORM1_NOTICE_FROM_LANDLORD_TO_TENANT.pdf
2005-11-12 22:39 6,841,856 a——- c:\program files\WIA390CANONDRIVERS.exe
2005-09-13 23:04 114,567 a——- c:\program files\le_cbt.exe
2005-08-04 18:44 42,518,640 a——- c:\program files\TaxCut2004CompleteHomeandBusinessD.exe
1998-08-15 22:05 750 a——- c:\program files\2000 Professional Tax System For Windows.LNK
============= FINISH: 11:29:47.04 ===============