This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Computer rarely starts properly, often crashes: Possible troj

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A file was downloaded that contained an .exe that has severly harmed my computer. I attempted to remove it via avast and ad-aware to no avail. For a few days it merly slowed the PC down and ran processes such as "c.exe" and "a.exe" in the background. I was able to end these with CCleaner.

But now when I start my computer it will only fully start-up in safe mode. System restore does not work as when it restarts, it simply stays at the loading screen. I am currently on my computer in normal mode, only as the result of a failed restart. Normal start-up does not work. Here is my HijackThis log. Thank you dearly.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:47 PM, on 12/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\msa.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.joystiq.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Program Files\Octoshape Streaming Services\Randy ******\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 5760 bytes


I edited out my full name with ******
Hi,

What happens when you try and boot into normal mode? Are there any error messages?

Please go into task manager and end process on the following:

C:\WINDOWS\msa.exe


The following scans can be done in safe mode if you cannot do them in normal mode.


Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
90% of the time when trying to boot in normal mode or "last working mode" I am stopped at the windows screen with the loading bar. The hard drive is silent and the load screen stays moving. The other 10% of the time I will see a quick blue screen error message that lasts for a second before auto restarting.

Here is DDS.txt

DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 21:44:05.58 on Fri 12/11/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1452 [GMT -6:00]

AV: avast! antivirus 4.8.1368 [VPS 091211-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Randy \Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.joystiq.com/
uInternet Settings,ProxyOverride = *.local
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Octoshape Streaming Services] "c:\program files\octoshape streaming services\randy \OctoshapeClient.exe" -inv:bootrun
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab
DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\randyk~1\applic~1\mozilla\firefox\profiles\jgl4ffsv.default\
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-20 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-20 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-5-19 138680]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-2-16 24652]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2003-10-22 344800]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-5-19 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-5-19 352920]
S3 kbeepm;kbeepm;\??\c:\docume~1\randyk~1\locals~1\temp\kbeepm.sys –> c:\docume~1\randyk~1\locals~1\temp\kbeepm.sys [?]
S3 XDva009;XDva009;\??\c:\windows\system32\xdva009.sys –> c:\windows\system32\XDva009.sys [?]
S3 XDva016;XDva016;\??\c:\windows\system32\xdva016.sys –> c:\windows\system32\XDva016.sys [?]
S3 XDva019;XDva019;\??\c:\windows\system32\xdva019.sys –> c:\windows\system32\XDva019.sys [?]
S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]

=============== Created Last 30 ================

2009-12-11 02:50:38 0 d—–w- c:\program files\Trend Micro
2009-12-10 20:18:38 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-09 22:43:18 70656 —-a-w- c:\windows\system32\yv12vfw.dll
2009-12-09 22:43:18 27648 —-a-w- c:\windows\system32\AVSredirect.dll
2009-12-09 22:43:17 70656 —-a-w- c:\windows\system32\i420vfw.dll
2009-12-09 22:37:02 0 d—–w- c:\program files\eRightSoft
2009-12-07 21:25:01 201216 —-a-w- c:\windows\msa.exe
2009-12-07 21:04:09 0 d—–w- c:\windows\Logs
2009-12-07 20:59:18 0 d—–w- c:\program files\Rockstar Games
2009-12-07 20:52:49 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-12-07 20:52:40 0 d—–w- c:\program files\DAEMON Tools Lite
2009-12-07 20:52:25 0 d—–w- c:\docume~1\randyk~1\applic~1\DAEMON Tools Lite
2009-12-07 20:52:13 0 d—–w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2009-12-02 20:41:58 1525 —-a-w- c:\documents and settings\randy \.recently-used.xbel
2009-12-02 20:41:27 0 d—–w- c:\documents and settings\randy \.thumbnails
2009-12-02 20:10:22 0 d—–w- c:\documents and settings\randy \.gimp-2.6
2009-12-02 20:09:48 0 d—–w- c:\program files\GIMP-2.0
2009-11-23 07:19:24 0 d—–w- c:\docume~1\randyk~1\applic~1\SumatraPDF
2009-11-23 07:19:21 0 d—–w- c:\program files\SumatraPDF
2009-11-14 16:35:31 0 d—–w- c:\docume~1\randyk~1\applic~1\MSNInstaller

==================== Find3M ====================

2009-12-10 16:20:06 98304 —-a-w- c:\windows\DUMP4c4b.tmp
2009-10-29 07:46:59 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46:52 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46:50 17408 ——w- c:\windows\system32\corpol.dll
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20:16 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll
2009-09-28 04:48:23 411368 —-a-w- c:\windows\system32\deploytk.dll
2006-05-03 09:06:54 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47:16 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30:52 216064 –sh–r- c:\windows\system32\nbDX.dll
2009-01-03 20:56:03 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009010320090104\index.dat

============= FINISH: 21:44:29.94 ===============


And Attatch.txt

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/12/2006 12:28:15 AM
System Uptime: 12/10/2009 8:37:50 PM (25 hours ago)

Motherboard: Unknow | | NF570_SLIT-A
Processor: Intel® Core™2 CPU 6400 @ 2.13GHz | Socket 775 | 2133/266mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 190 GiB total, 89.554 GiB free.
D: is CDROM ()
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: Microsoft UAA Bus Driver for High Definition Audio
Device ID: PCI\VEN_10DE&DEV;_026C&SUBSYS;_026C10DE&REV;_A2\3&2411E6FE&0&81
Manufacturer: Microsoft
Name: Microsoft UAA Bus Driver for High Definition Audio
PNP Device ID: PCI\VEN_10DE&DEV;_026C&SUBSYS;_026C10DE&REV;_A2\3&2411E6FE&0&81
Service: HDAudBus

==== System Restore Points ===================

RP803: 9/13/2009 5:56:38 PM - System Checkpoint
RP804: 9/14/2009 9:28:32 PM - System Checkpoint
RP805: 9/15/2009 10:33:18 PM - System Checkpoint
RP806: 9/16/2009 11:34:09 PM - System Checkpoint
RP807: 9/18/2009 10:33:31 AM - System Checkpoint
RP808: 9/19/2009 3:15:14 PM - System Checkpoint
RP809: 9/20/2009 3:52:07 PM - System Checkpoint
RP810: 9/21/2009 5:56:01 PM - System Checkpoint
RP811: 9/23/2009 10:14:13 AM - System Checkpoint
RP812: 9/24/2009 12:28:04 PM - System Checkpoint
RP813: 9/25/2009 2:28:55 PM - System Checkpoint
RP814: 9/26/2009 2:47:02 PM - System Checkpoint
RP815: 9/27/2009 3:25:55 PM - System Checkpoint
RP816: 9/27/2009 11:48:15 PM - Installed Java™ 6 Update 15
RP817: 9/29/2009 12:24:39 AM - System Checkpoint
RP818: 9/30/2009 1:16:55 AM - System Checkpoint
RP819: 10/1/2009 1:22:04 AM - System Checkpoint
RP820: 10/2/2009 1:53:30 AM - System Checkpoint
RP821: 10/3/2009 10:56:09 AM - System Checkpoint
RP822: 10/4/2009 4:30:01 PM - System Checkpoint
RP823: 10/5/2009 5:01:18 PM - System Checkpoint
RP824: 10/6/2009 8:57:31 PM - System Checkpoint
RP825: 10/8/2009 12:34:28 AM - System Checkpoint
RP826: 10/9/2009 1:15:39 AM - System Checkpoint
RP827: 10/10/2009 5:13:24 PM - System Checkpoint
RP828: 10/11/2009 3:00:16 AM - Software Distribution Service 3.0
RP829: 10/12/2009 3:47:31 AM - System Checkpoint
RP830: 10/13/2009 3:49:07 AM - System Checkpoint
RP831: 10/13/2009 6:19:39 PM - Software Distribution Service 3.0
RP832: 10/14/2009 7:08:33 PM - System Checkpoint
RP833: 10/15/2009 7:10:55 PM - System Checkpoint
RP834: 10/16/2009 7:58:56 PM - System Checkpoint
RP835: 10/18/2009 12:41:20 AM - System Checkpoint
RP836: 10/19/2009 12:51:23 AM - System Checkpoint
RP837: 10/20/2009 12:55:13 AM - System Checkpoint
RP838: 10/21/2009 1:52:18 AM - System Checkpoint
RP839: 10/21/2009 3:00:14 AM - Software Distribution Service 3.0
RP840: 10/22/2009 3:35:48 AM - System Checkpoint
RP841: 10/23/2009 3:47:10 AM - System Checkpoint
RP842: 10/25/2009 2:25:17 AM - System Checkpoint
RP843: 10/26/2009 11:05:37 AM - System Checkpoint
RP844: 10/27/2009 11:08:00 AM - System Checkpoint
RP845: 10/28/2009 11:32:55 AM - System Checkpoint
RP846: 10/29/2009 2:18:05 PM - System Checkpoint
RP847: 10/30/2009 2:29:47 PM - System Checkpoint
RP848: 10/31/2009 3:26:26 PM - System Checkpoint
RP849: 11/1/2009 5:25:44 PM - System Checkpoint
RP850: 11/3/2009 3:07:37 AM - System Checkpoint
RP851: 11/4/2009 4:02:23 AM - System Checkpoint
RP852: 11/5/2009 4:00:16 AM - Software Distribution Service 3.0
RP853: 11/6/2009 4:26:15 AM - System Checkpoint
RP854: 11/7/2009 5:07:01 AM - System Checkpoint
RP855: 11/8/2009 4:42:09 PM - System Checkpoint
RP856: 11/10/2009 4:34:45 AM - System Checkpoint
RP857: 11/11/2009 3:00:15 AM - Software Distribution Service 3.0
RP858: 11/12/2009 3:49:13 AM - System Checkpoint
RP859: 11/13/2009 4:10:20 AM - System Checkpoint
RP860: 11/14/2009 4:24:07 AM - System Checkpoint
RP861: 11/15/2009 4:34:45 AM - System Checkpoint
RP862: 11/16/2009 5:31:00 AM - System Checkpoint
RP863: 11/17/2009 5:43:01 AM - System Checkpoint
RP864: 11/18/2009 10:49:15 AM - System Checkpoint
RP865: 11/19/2009 11:09:44 AM - System Checkpoint
RP866: 11/20/2009 6:17:10 PM - System Checkpoint
RP867: 11/21/2009 6:55:22 PM - System Checkpoint
RP868: 11/22/2009 7:16:38 PM - System Checkpoint
RP869: 11/23/2009 1:23:12 AM - Removed Adobe Reader 6.0.1
RP870: 11/24/2009 2:25:48 AM - System Checkpoint
RP871: 11/25/2009 2:40:22 AM - System Checkpoint
RP872: 11/25/2009 12:27:43 PM - Software Distribution Service 3.0
RP873: 11/26/2009 4:00:55 PM - System Checkpoint
RP874: 11/27/2009 4:41:57 PM - System Checkpoint
RP875: 11/28/2009 8:34:59 PM - System Checkpoint
RP876: 11/29/2009 8:36:56 PM - Removed Project64 1.6
RP877: 12/1/2009 3:27:41 AM - System Checkpoint
RP878: 12/2/2009 5:57:12 AM - System Checkpoint
RP879: 12/3/2009 6:20:48 AM - System Checkpoint
RP880: 12/4/2009 6:21:56 AM - System Checkpoint
RP881: 12/5/2009 7:14:57 AM - System Checkpoint
RP882: 12/6/2009 7:26:57 AM - System Checkpoint
RP883: 12/7/2009 8:26:57 AM - System Checkpoint
RP884: 12/7/2009 2:52:48 PM - SPTD setup V1.62
RP885: 12/7/2009 3:04:21 PM - Installed DirectX
RP886: 12/8/2009 5:46:32 PM - System Checkpoint
RP887: 12/9/2009 3:00:16 AM - Software Distribution Service 3.0
RP888: 12/10/2009 10:49:23 AM - Restore Operation
RP889: 12/10/2009 10:59:56 AM - Restore Operation
RP890: 12/10/2009 11:05:49 AM - Restore Operation
RP891: 12/10/2009 11:56:48 AM - Uninstall Hitman: Contracts
RP892: 12/10/2009 12:02:34 PM - Configured AirPlus Xtreme G
RP893: 12/10/2009 2:10:46 PM - Restore Operation
RP894: 12/10/2009 8:26:46 PM - Restore Operation
RP895: 12/10/2009 8:40:06 PM - Restore Operation
RP896: 12/11/2009 8:30:33 PM - System Checkpoint

==== Installed Programs ======================

µTorrent
Ad-Aware SE Personal
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Shockwave Player
AGEIA PhysX v7.09.13
AIM 6
Apple Mobile Device Support
Apple Software Update
avast! Antivirus
AviSynth 2.5
BioShock
Bonjour
BrainBread v1.2
CCleaner (remove only)
Counter-Strike: Source
Creative Audio Console
Creative Media Toolbox
Creative MediaSource
Creative System Information
Critical Update for Windows Media Player 11 (KB959772)
Day of Defeat: Source
DivX Content Uploader
DivX Web Player
DNA
Doom 3
Grand Theft Auto 3
Grand Theft Auto: San Andreas
Grand Theft Auto: Vice City
Half-Life
Half-Life 2
HijackThis 2.0.2
Hitman Blood Money
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Indigo Prophecy
IrfanView (remove only)
iTunes
iTunes Alarm Clock 2.0
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 8
J2SE Runtime Environment 5.0 Update 9
Java™ 6 Update 15
Java™ 6 Update 7
Left 4 Dead
LightScribe [removed]
Logitech SetPoint
Manhunt
Max Payne
Max Payne 2: The Fall of Max Payne
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.5)
MSXML 6 Service Pack 2 (KB954459)
NVIDIA Drivers
OpenAL
OpenOffice.org 3.0
PC Wizard 2008.1.81
PeerGuardian 2.0
Penumbra Overture
Penumbra: Black Plague
Penumbra: Requiem
Psychonauts
QuickTime
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Sound Blaster X-Fi
Source SDK Base
Steam
SumatraPDF
SUPER © Version 2009.bld.36 (June 10, 2009)
System Requirements Lab
Team Fortress 2
TI Connect 1.6
Unreal Tournament 3 Demo
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
VLC media player 1.0.3
WebFldrs XP
Windows Defender
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
Zenmas Addon Pack

==== Event Viewer Messages From Past Week ========

12/9/2009 11:28:21 PM, error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s).
12/6/2009 7:03:48 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer LOLALAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB78-414. The master browser is stopping or an election is being forced.
12/6/2009 2:39:39 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer FREEMAN-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB78-414. The master browser is stopping or an election is being forced.
12/6/2009 10:17:03 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer CHIROPRACTIC-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB7. The master browser is stopping or an election is being forced.
12/5/2009 8:38:28 PM, error: NetBT [4321] - The name "WORKGROUP :1d" could not be registered on the Interface with IP address 192.168.2.4. The machine with the IP address 192.168.2.7 did not allow the name to be claimed by this machine.
12/10/2009 8:27:21 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL
12/10/2009 2:30:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
12/10/2009 2:20:27 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
12/10/2009 2:11:52 PM, error: System Error [1003] - Error code 10000050, parameter1 fffdf000, parameter2 00000001, parameter3 804dadf8, parameter4 00000000.
12/10/2009 2:10:38 PM, error: Service Control Manager [7000] - The ANIO Service service failed to start due to the following error: The system cannot find the file specified.
12/10/2009 10:24:49 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss sptd Tcpip WS2IFSL
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:46 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
12/10/2009 10:24:22 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/10/2009 10:23:49 AM, error: sptd [4] - Driver detected an internal error in its data structures for .
12/10/2009 10:23:49 AM, error: sfsync02 [12] -

==== End Of File ===========================

GMER.txt

GMER 1.0.15.15279 - http://www.gmer.net
Rootkit scan 2009-12-12 06:46:38
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\RANDYK~1\LOCALS~1\Temp\agtdykog.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB17D36B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB17D3574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB17D3A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB17D314C]
SSDT spja.sys ZwEnumerateKey [0xF74FCDA4]
SSDT spja.sys ZwEnumerateValueKey [0xF74FD132]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB17D364E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB17D308C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB17D30F0]
SSDT spja.sys ZwQueryKey [0xF74FD20A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB17D376E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB17D372E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB17D38AE]

INT 0x62 ? 8ACE2BF8
INT 0x73 ? 8AD50BF8
INT 0x82 ? 8ACE2BF8
INT 0x83 ? 8AD50BF8
INT 0xB4 ? 8AA5DBF8

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8AD4F1F8

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Fastfat \FatCdrom 88BB31F8

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\sptd \Device\4033101670 spja.sys
Device \Driver\usbohci \Device\USBPDO-0 8ABD41F8
Device \Driver\usbehci \Device\USBPDO-1 8AB231F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8AD511F8
Device \Driver\dmio \Device\DmControl\DmConfig 8AD511F8
Device \Driver\dmio \Device\DmControl\DmPnP 8AD511F8
Device \Driver\dmio \Device\DmControl\DmInfo 8AD511F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{7B9E8052-BB78-4140-AE2A-E5DAAC0831E7} 88B831F8
Device \Driver\PCI_PNP5420 \Device\00000054 spja.sys
Device \Driver\PCI_PNP5420 \Device\00000054 spja.sys

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Ftdisk \Device\HarddiskVolume1 8ACE31F8
Device \Driver\Cdrom \Device\CdRom0 8ABC81F8
Device \Driver\Cdrom \Device\CdRom1 8ABC81F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\NetBT \Device\NetBt_Wins_Export 88B831F8
Device \Driver\NetBT \Device\NetbiosSmb 88B831F8

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\NetBT \Device\NetBT_Tcpip_{49DCED48-698B-44FA-A7AD-65F6653F4D1E} 88B831F8
Device \Driver\usbohci \Device\USBFDO-0 8ABD41F8
Device \Driver\usbehci \Device\USBFDO-1 8AB231F8
Device \Driver\nvata \Device\NvAta0 8AD501F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 88B471F8
Device \Driver\nvata \Device\NvAta1 8AD501F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 88B471F8
Device \Driver\Ftdisk \Device\FtControl 8ACE31F8
Device \Driver\a9s5teur \Device\Scsi\a9s5teur1Port4Path0Target0Lun0 8A803500
Device \Driver\a9s5teur \Device\Scsi\a9s5teur1Port4Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\a9s5teur \Device\Scsi\a9s5teur1 8A803500
Device \Driver\a9s5teur \Device\Scsi\a9s5teur1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Fastfat \Fat 88BB31F8

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Cdfs \Cdfs 88B761F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x42 0xE7 0x93 0xD0 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCE 0x50 0xB3 0xE5 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0xC4 0xFF 0xC4 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x42 0xE7 0x93 0xD0 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCE 0x50 0xB3 0xE5 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0xC4 0xFF 0xC4 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x42 0xE7 0x93 0xD0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCE 0x50 0xB3 0xE5 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0xC4 0xFF 0xC4 …

—- EOF - GMER 1.0.15 —-


Thank you for your reply.
Hi,

You have CD Emulation drivers installed. They can sometimes interfere with our tools, so we need to disable them for the duration of the fix.

Please do the following:

Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.


NEXT


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Here is my combofix log.

ComboFix 09-12-11.05 - Randy Klosak 12/12/2009 17:16:34.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1519 [GMT -6:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091212-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\msa.exe
c:\windows\system32\AVSredirect.dll
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_SSHNAS


((((((((((((((((((((((((( Files Created from 2009-11-12 to 2009-12-12 )))))))))))))))))))))))))))))))
.

2009-12-11 02:50 . 2009-12-11 02:50 ——– d—–w- c:\program files\Trend Micro
2009-12-10 20:18 . 2009-12-10 21:44 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-09 22:43 . 2004-01-25 06:00 70656 —-a-w- c:\windows\system32\yv12vfw.dll
2009-12-09 22:43 . 2004-01-25 06:00 70656 —-a-w- c:\windows\system32\i420vfw.dll
2009-12-09 22:37 . 2008-03-16 12:30 216064 –sh–r- c:\windows\system32\nbDX.dll
2009-12-09 22:37 . 2007-02-21 10:47 31232 –sh–r- c:\windows\system32\msfDX.dll
2009-12-09 22:37 . 2006-05-03 09:06 163328 –sh–r- c:\windows\system32\flvDX.dll
2009-12-09 22:37 . 2009-12-09 22:37 ——– d—–w- c:\program files\eRightSoft
2009-12-07 21:04 . 2009-12-07 21:04 ——– d—–w- c:\windows\Logs
2009-12-07 20:59 . 2009-12-07 20:59 ——– d—–w- c:\program files\Rockstar Games
2009-12-07 20:52 . 2009-12-07 20:52 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-12-07 20:52 . 2009-12-07 20:56 ——– d—–w- c:\program files\DAEMON Tools Lite
2009-12-07 20:52 . 2009-12-07 20:58 ——– d—–w- c:\documents and settings\Randy \Application Data\DAEMON Tools Lite
2009-12-07 20:52 . 2009-12-07 20:52 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-12-02 20:41 . 2009-12-02 20:41 ——– d—–w- c:\documents and settings\Randy \Application Data\gtk-2.0
2009-12-02 20:41 . 2009-12-02 20:41 ——– d—–w- c:\documents and settings\Randy \.thumbnails
2009-12-02 20:10 . 2009-12-02 20:52 ——– d—–w- c:\documents and settings\Randy \.gimp-2.6
2009-12-02 20:09 . 2009-12-04 00:20 ——– d—–w- c:\program files\GIMP-2.0
2009-11-23 07:19 . 2009-11-23 07:21 ——– d—–w- c:\documents and settings\Randy \Application Data\SumatraPDF
2009-11-23 07:19 . 2009-11-23 07:19 ——– d—–w- c:\program files\SumatraPDF
2009-11-14 16:35 . 2009-11-14 16:35 ——– d—–w- c:\documents and settings\Randy \Application Data\MSNInstaller

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-12 23:22 . 2009-04-02 01:09 ——– d—–w- c:\program files\Steam
2009-12-12 23:19 . 2006-12-16 06:18 ——– d—–w- c:\documents and settings\Randy Klosak\Application Data\vlc
2009-12-11 02:37 . 2008-02-16 18:04 ——– d—–w- c:\program files\FrostWire
2009-12-11 02:34 . 2008-12-10 05:19 ——– d—–w- c:\documents and settings\Randy Klosak\Application Data\uTorrent
2009-12-10 21:42 . 2008-02-09 00:52 ——– d—–w- c:\documents and settings\Randy Klosak\Application Data\U3
2009-12-10 18:10 . 2007-06-14 22:07 ——– d—–w- c:\documents and settings\Randy Klosak\Application Data\IGN_DLM
2009-12-10 18:03 . 2006-12-14 04:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-10 16:20 . 2003-01-01 01:16 98304 —-a-w- c:\windows\DUMP4c4b.tmp
2009-12-09 02:36 . 2008-02-16 17:38 ——– d—–w- c:\program files\PeerGuardian2
2009-12-05 09:02 . 2008-12-04 05:59 1 —-a-w- c:\documents and settings\Randy Klosak\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-30 02:37 . 2008-12-17 01:29 ——– d—–w- c:\program files\Project64 1.6
2009-11-24 23:54 . 2007-05-19 23:04 1280480 —-a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2007-05-19 23:05 93424 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2007-05-19 23:05 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-09-21 03:54 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-09-21 03:54 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2007-05-19 23:05 48560 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2007-05-19 23:05 23120 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2007-05-19 23:05 27408 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2007-05-19 23:05 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-11-14 16:39 . 2006-12-25 07:45 ——– d—–w- c:\program files\Common Files\Ahead
2009-11-14 16:29 . 2008-01-27 20:25 ——– d—–w- c:\program files\KellySoftware
2009-10-29 07:46 . 2004-08-04 12:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2004-08-04 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2004-08-04 12:00 17408 ——w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2004-08-04 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-04 05:19 . 2006-12-16 01:43 21216 —-a-w- c:\documents and settings\Randy Klosak\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-28 04:48 . 2009-09-28 04:48 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-09-28 04:47 . 2009-09-28 04:47 152576 —-a-w- c:\documents and settings\Randy Klosak\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2006-05-03 09:06 . 2009-12-09 22:37 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2009-12-09 22:37 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-12-09 22:37 216064 –sh–r- c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-12-11 1217808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-05 49152]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-26 13680640]
"nwiz"="nwiz.exe" [2008-12-26 1657376]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-23 28160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-28 149280]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-26 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
2009-11-24 23:51 81000 —-a-w- c:\progra~1\ALWILS~1\Avast4\ashDisp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-03 00:23 102400 ——w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
2003-06-18 07:00 45056 ——w- c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
2006-12-12 16:46 19456 —-a-w- c:\windows\system32\CtHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
2006-12-12 16:46 20480 —-a-w- c:\windows\system32\Ctxfihlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-07-13 19:03 292128 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
2005-07-23 05:25 28160 —-a-w- c:\windows\KHALMNPR.Exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-12-26 06:08 13680640 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-12-26 06:08 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-12-26 06:08 1657376 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 22:18 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RCSystem]
2005-11-05 00:07 49152 ——w- c:\program files\Creative\Shared Files\Module Loader\DLLML.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2006-12-15 09:23 75520 —-a-w- c:\program files\Java\jre1.5.0_11\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 07:00 90112 ——w- c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VolPanel]
2005-10-14 17:01 122880 ——w- c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"PnkBstrB"=3 (0x3)
"PnkBstrA"=2 (0x2)
"LightScribeService"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"WinDefend"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\renegadenerf\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\renegadenerf\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\renegadenerf\\half-life\\hl.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\renegadenerf\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\max payne\\maxpayne.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\max payne 2 the fall of max payne\\maxpayne2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\manhunt\\manhunt.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\grand theft auto 3\\gta3.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\grand theft auto san andreas\\gta-sa.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\grand theft auto vice city\\gta-vc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Steam\\steamapps\\renegadenerf\\zombie panic! source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\penumbra black plague\\redist\\Penumbra.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\penumbra overture\\redist\\Penumbra.exe"=
"c:\\Program Files\\Steam\\steamapps\\renegadenerf\\source sdk base\\hl2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\psychonauts\\PsychoLauncher.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\penumbra black plague\\redist\\Requiem.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead 2 demo\\left4dead2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead 2\\left4dead2.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [9/20/2009 9:54 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/20/2009 9:54 PM 20560]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/16/2008 11:24 AM 24652]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [10/22/2003 3:27 PM 344800]
S3 kbeepm;kbeepm;\??\c:\docume~1\RANDYK~1\LOCALS~1\Temp\kbeepm.sys –> c:\docume~1\RANDYK~1\LOCALS~1\Temp\kbeepm.sys [?]
S3 XDva009;XDva009;\??\c:\windows\system32\XDva009.sys –> c:\windows\system32\XDva009.sys [?]
S3 XDva016;XDva016;\??\c:\windows\system32\XDva016.sys –> c:\windows\system32\XDva016.sys [?]
S3 XDva019;XDva019;\??\c:\windows\system32\XDva019.sys –> c:\windows\system32\XDva019.sys [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/7/2009 2:52 PM 691696]
S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.joystiq.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Randy Klosak\Application Data\Mozilla\Firefox\Profiles\jgl4ffsv.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Octoshape Streaming Services - c:\program files\Octoshape Streaming Services\Randy \OctoshapeClient.exe
MSConfigStartUp-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
MSConfigStartUp-DNA - c:\program files\BitTorrent_DNA\dna.exe
MSConfigStartUp-NeroFilterCheck - c:\windows\system32\NeroCheck.exe
MSConfigStartUp-ResChanger 2005 - c:\program files\ResChanger 2005\ResChanger2005.exe
AddRemove-DNA - c:\program files\BitTorrent_DNA\dna.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-12 17:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-507921405-2139871995-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:1b,f6,23,39,4d,41,c3,8e,1c,0e,9c,eb,51,b4,df,35,50,b1,dc,90,82,cd,46,
71,bd,cc,f6,95,28,4c,84,e5,5e,73,88,de,19,47,91,99,e3,30,69,af,85,64,3f,e7,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22

[HKEY_USERS\S-1-5-21-507921405-2139871995-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:9b,1f,ac,29,e2,71,e3,0e,72,60,11,32,0e,ab,88,fc,02,2d,13,c1,d4,
24,57,c4,83,7a,ed,fc,5e,8f,01,a2,b9,f8,e4,a9,4c,bc,28,1c,69,4f,51,0e,2a,7f,\
"rkeysecu"=hex:84,db,31,93,ec,52,fe,d2,7f,e8,8c,77,e6,f4,e5,30
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3496)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\SYSTEM32\CTXFISPI.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-12-12 17:30:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-12 23:30

Pre-Run: 96,133,709,824 bytes free
Post-Run: 96,150,319,104 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - DFDA736BA57A0D05662876E86DB5AC03


Again, thanks for the reply.
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Malwarebytes' Anti-Malware 1.42 Database version: 3350 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 12/12/2009 7:11:56 PM mbam-log-2009-12-12 (19-11-56).txt Scan type: Quick Scan Objects scanned: 99395 Time elapsed: 3 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, December 13, 2009 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, December 13, 2009 12:40:50 Records in database: 3366562 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ Scan statistics: Objects scanned: 127467 Threats found: 2 Infected objects found: 2 Suspicious objects found: 0 Scan duration: 01:43:48 File name / Threat / Threats count C:\Documents and Settings\Randy \Incomplete\T-5179105-my life game new cover version.mp3 Infected: Trojan-Downloader.WMA.GetCodec.s 1 C:\Qoobox\Quarantine\C\WINDOWS\msa.exe.vir Infected: Packed.Win32.Krap.ag 1 Selected area has been scanned.
Hi,

Re-enable the sptd drivers:

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.


NEXT

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "C:\Documents and Settings\Randy \Incomplete\T-5179105-my life game new cover version.mp3"



NEXT


Please post a fresh DDS and Attach.txt and advise how your computer is running now and if there are any outstanding issues.
DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 12:33:44.92 on Sun 12/13/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_15 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1606 [GMT -6:00] AV: avast! antivirus 4.8.1368 [VPS 091213-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\SYSTEM32\CTXFISPI.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Randy Klosak\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.joystiq.com/ uInternet Settings,ProxyOverride = *.local BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [Steam] "c:\program files\steam\steam.exe" -silent uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\randyk~1\applic~1\mozilla\firefox\profiles\jgl4ffsv.default\ FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-20 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-20 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-5-19 138680] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-2-16 24652] R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2003-10-22 344800] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-5-19 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-5-19 352920] S3 kbeepm;kbeepm;\??\c:\docume~1\randyk~1\locals~1\temp\kbeepm.sys –> c:\docume~1\randyk~1\locals~1\temp\kbeepm.sys [?] S3 XDva009;XDva009;\??\c:\windows\system32\xdva009.sys –> c:\windows\system32\XDva009.sys [?] S3 XDva016;XDva016;\??\c:\windows\system32\xdva016.sys –> c:\windows\system32\XDva016.sys [?] S3 XDva019;XDva019;\??\c:\windows\system32\xdva019.sys –> c:\windows\system32\XDva019.sys [?] S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] =============== Created Last 30 ================ 2009-12-13 01:07:08 0 d—–w- c:\docume~1\randyk~1\applic~1\Malwarebytes 2009-12-13 01:07:05 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-13 01:07:03 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-12-13 01:07:03 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-12-13 01:07:03 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-12-12 23:13:11 0 d-sha-r- C:\cmdcons 2009-12-12 23:10:21 98816 —-a-w- c:\windows\sed.exe 2009-12-12 23:10:21 77312 —-a-w- c:\windows\MBR.exe 2009-12-12 23:10:21 261632 —-a-w- c:\windows\PEV.exe 2009-12-12 23:10:21 161792 —-a-w- c:\windows\SWREG.exe 2009-12-12 23:04:55 20 —-a-w- c:\documents and settings\randy \defogger_reenable 2009-12-11 02:50:38 0 d—–w- c:\program files\Trend Micro 2009-12-10 20:18:38 664 —-a-w- c:\windows\system32\d3d9caps.dat 2009-12-09 22:43:18 70656 —-a-w- c:\windows\system32\yv12vfw.dll 2009-12-09 22:43:17 70656 —-a-w- c:\windows\system32\i420vfw.dll 2009-12-09 22:37:02 0 d—–w- c:\program files\eRightSoft 2009-12-07 21:04:09 0 d—–w- c:\windows\Logs 2009-12-07 20:59:18 0 d—–w- c:\program files\Rockstar Games 2009-12-07 20:52:49 691696 —-a-w- c:\windows\system32\drivers\sptd.sys 2009-12-07 20:52:40 0 d—–w- c:\program files\DAEMON Tools Lite 2009-12-07 20:52:25 0 d—–w- c:\docume~1\randyk~1\applic~1\DAEMON Tools Lite 2009-12-07 20:52:13 0 d—–w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite 2009-12-02 20:41:58 1525 —-a-w- c:\documents and settings\randy \.recently-used.xbel 2009-12-02 20:41:27 0 d—–w- c:\documents and settings\randy \.thumbnails 2009-12-02 20:10:22 0 d—–w- c:\documents and settings\randy \.gimp-2.6 2009-12-02 20:09:48 0 d—–w- c:\program files\GIMP-2.0 2009-11-23 07:19:24 0 d—–w- c:\docume~1\randyk~1\applic~1\SumatraPDF 2009-11-23 07:19:21 0 d—–w- c:\program files\SumatraPDF 2009-11-14 16:35:31 0 d—–w- c:\docume~1\randyk~1\applic~1\MSNInstaller ==================== Find3M ==================== 2009-12-10 16:20:06 98304 —-a-w- c:\windows\DUMP4c4b.tmp 2009-10-29 07:46:59 832512 ——w- c:\windows\system32\wininet.dll 2009-10-29 07:46:52 78336 —-a-w- c:\windows\system32\ieencode.dll 2009-10-29 07:46:50 17408 ——w- c:\windows\system32\corpol.dll 2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll 2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll 2009-10-20 16:20:16 265728 —-a-w- c:\windows\system32\drivers\http.sys 2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll 2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll 2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll 2009-09-28 04:48:23 411368 —-a-w- c:\windows\system32\deploytk.dll 2006-05-03 09:06:54 163328 –sh–r- c:\windows\system32\flvDX.dll 2007-02-21 10:47:16 31232 –sh–r- c:\windows\system32\msfDX.dll 2008-03-16 12:30:52 216064 –sh–r- c:\windows\system32\nbDX.dll 2009-01-03 20:56:03 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009010320090104\index.dat ============= FINISH: 12:34:17.25 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 12/12/2006 12:28:15 AM System Uptime: 12/13/2009 12:02:00 PM (0 hours ago) Motherboard: Unknow | | NF570_SLIT-A Processor: Intel® Core™2 CPU 6400 @ 2.13GHz | Socket 775 | 2133/266mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 190 GiB total, 89.428 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318} Description: Microsoft UAA Bus Driver for High Definition Audio Device ID: PCI\VEN_10DE&DEV;_026C&SUBSYS;_026C10DE&REV;_A2\3&2411E6FE&0&81 Manufacturer: Microsoft Name: Microsoft UAA Bus Driver for High Definition Audio PNP Device ID: PCI\VEN_10DE&DEV;_026C&SUBSYS;_026C10DE&REV;_A2\3&2411E6FE&0&81 Service: HDAudBus ==== System Restore Points =================== RP804: 9/14/2009 9:28:32 PM - System Checkpoint RP805: 9/15/2009 10:33:18 PM - System Checkpoint RP806: 9/16/2009 11:34:09 PM - System Checkpoint RP807: 9/18/2009 10:33:31 AM - System Checkpoint RP808: 9/19/2009 3:15:14 PM - System Checkpoint RP809: 9/20/2009 3:52:07 PM - System Checkpoint RP810: 9/21/2009 5:56:01 PM - System Checkpoint RP811: 9/23/2009 10:14:13 AM - System Checkpoint RP812: 9/24/2009 12:28:04 PM - System Checkpoint RP813: 9/25/2009 2:28:55 PM - System Checkpoint RP814: 9/26/2009 2:47:02 PM - System Checkpoint RP815: 9/27/2009 3:25:55 PM - System Checkpoint RP816: 9/27/2009 11:48:15 PM - Installed Java™ 6 Update 15 RP817: 9/29/2009 12:24:39 AM - System Checkpoint RP818: 9/30/2009 1:16:55 AM - System Checkpoint RP819: 10/1/2009 1:22:04 AM - System Checkpoint RP820: 10/2/2009 1:53:30 AM - System Checkpoint RP821: 10/3/2009 10:56:09 AM - System Checkpoint RP822: 10/4/2009 4:30:01 PM - System Checkpoint RP823: 10/5/2009 5:01:18 PM - System Checkpoint RP824: 10/6/2009 8:57:31 PM - System Checkpoint RP825: 10/8/2009 12:34:28 AM - System Checkpoint RP826: 10/9/2009 1:15:39 AM - System Checkpoint RP827: 10/10/2009 5:13:24 PM - System Checkpoint RP828: 10/11/2009 3:00:16 AM - Software Distribution Service 3.0 RP829: 10/12/2009 3:47:31 AM - System Checkpoint RP830: 10/13/2009 3:49:07 AM - System Checkpoint RP831: 10/13/2009 6:19:39 PM - Software Distribution Service 3.0 RP832: 10/14/2009 7:08:33 PM - System Checkpoint RP833: 10/15/2009 7:10:55 PM - System Checkpoint RP834: 10/16/2009 7:58:56 PM - System Checkpoint RP835: 10/18/2009 12:41:20 AM - System Checkpoint RP836: 10/19/2009 12:51:23 AM - System Checkpoint RP837: 10/20/2009 12:55:13 AM - System Checkpoint RP838: 10/21/2009 1:52:18 AM - System Checkpoint RP839: 10/21/2009 3:00:14 AM - Software Distribution Service 3.0 RP840: 10/22/2009 3:35:48 AM - System Checkpoint RP841: 10/23/2009 3:47:10 AM - System Checkpoint RP842: 10/25/2009 2:25:17 AM - System Checkpoint RP843: 10/26/2009 11:05:37 AM - System Checkpoint RP844: 10/27/2009 11:08:00 AM - System Checkpoint RP845: 10/28/2009 11:32:55 AM - System Checkpoint RP846: 10/29/2009 2:18:05 PM - System Checkpoint RP847: 10/30/2009 2:29:47 PM - System Checkpoint RP848: 10/31/2009 3:26:26 PM - System Checkpoint RP849: 11/1/2009 5:25:44 PM - System Checkpoint RP850: 11/3/2009 3:07:37 AM - System Checkpoint RP851: 11/4/2009 4:02:23 AM - System Checkpoint RP852: 11/5/2009 4:00:16 AM - Software Distribution Service 3.0 RP853: 11/6/2009 4:26:15 AM - System Checkpoint RP854: 11/7/2009 5:07:01 AM - System Checkpoint RP855: 11/8/2009 4:42:09 PM - System Checkpoint RP856: 11/10/2009 4:34:45 AM - System Checkpoint RP857: 11/11/2009 3:00:15 AM - Software Distribution Service 3.0 RP858: 11/12/2009 3:49:13 AM - System Checkpoint RP859: 11/13/2009 4:10:20 AM - System Checkpoint RP860: 11/14/2009 4:24:07 AM - System Checkpoint RP861: 11/15/2009 4:34:45 AM - System Checkpoint RP862: 11/16/2009 5:31:00 AM - System Checkpoint RP863: 11/17/2009 5:43:01 AM - System Checkpoint RP864: 11/18/2009 10:49:15 AM - System Checkpoint RP865: 11/19/2009 11:09:44 AM - System Checkpoint RP866: 11/20/2009 6:17:10 PM - System Checkpoint RP867: 11/21/2009 6:55:22 PM - System Checkpoint RP868: 11/22/2009 7:16:38 PM - System Checkpoint RP869: 11/23/2009 1:23:12 AM - Removed Adobe Reader 6.0.1 RP870: 11/24/2009 2:25:48 AM - System Checkpoint RP871: 11/25/2009 2:40:22 AM - System Checkpoint RP872: 11/25/2009 12:27:43 PM - Software Distribution Service 3.0 RP873: 11/26/2009 4:00:55 PM - System Checkpoint RP874: 11/27/2009 4:41:57 PM - System Checkpoint RP875: 11/28/2009 8:34:59 PM - System Checkpoint RP876: 11/29/2009 8:36:56 PM - Removed Project64 1.6 RP877: 12/1/2009 3:27:41 AM - System Checkpoint RP878: 12/2/2009 5:57:12 AM - System Checkpoint RP879: 12/3/2009 6:20:48 AM - System Checkpoint RP880: 12/4/2009 6:21:56 AM - System Checkpoint RP881: 12/5/2009 7:14:57 AM - System Checkpoint RP882: 12/6/2009 7:26:57 AM - System Checkpoint RP883: 12/7/2009 8:26:57 AM - System Checkpoint RP884: 12/7/2009 2:52:48 PM - SPTD setup V1.62 RP885: 12/7/2009 3:04:21 PM - Installed DirectX RP886: 12/8/2009 5:46:32 PM - System Checkpoint RP887: 12/9/2009 3:00:16 AM - Software Distribution Service 3.0 RP888: 12/10/2009 10:49:23 AM - Restore Operation RP889: 12/10/2009 10:59:56 AM - Restore Operation RP890: 12/10/2009 11:05:49 AM - Restore Operation RP891: 12/10/2009 11:56:48 AM - Uninstall Hitman: Contracts RP892: 12/10/2009 12:02:34 PM - Configured AirPlus Xtreme G RP893: 12/10/2009 2:10:46 PM - Restore Operation RP894: 12/10/2009 8:26:46 PM - Restore Operation RP895: 12/10/2009 8:40:06 PM - Restore Operation RP896: 12/11/2009 8:30:33 PM - System Checkpoint RP897: 12/12/2009 9:02:32 PM - System Checkpoint ==== Installed Programs ====================== µTorrent Ad-Aware SE Personal Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Shockwave Player AGEIA PhysX v7.09.13 AIM 6 Apple Mobile Device Support Apple Software Update avast! Antivirus AviSynth 2.5 BioShock Bonjour BrainBread v1.2 CCleaner (remove only) Counter-Strike: Source Creative Audio Console Creative Media Toolbox Creative MediaSource Creative System Information Critical Update for Windows Media Player 11 (KB959772) Day of Defeat: Source DivX Content Uploader DivX Web Player Doom 3 Grand Theft Auto 3 Grand Theft Auto: San Andreas Grand Theft Auto: Vice City Half-Life Half-Life 2 HijackThis 2.0.2 Hitman Blood Money Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Indigo Prophecy IrfanView (remove only) iTunes iTunes Alarm Clock 2.0 J2SE Runtime Environment 5.0 Update 11 J2SE Runtime Environment 5.0 Update 8 J2SE Runtime Environment 5.0 Update 9 Java™ 6 Update 15 Java™ 6 Update 7 Left 4 Dead LightScribe 1.4.89.1 Logitech SetPoint Malwarebytes' Anti-Malware Manhunt Max Payne Max Payne 2: The Fall of Max Payne Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Text-to-Speech Engine 4.0 (English) Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.5.5) MSXML 6 Service Pack 2 (KB954459) NVIDIA Drivers OpenAL OpenOffice.org 3.0 PC Wizard 2008.1.81 PeerGuardian 2.0 Penumbra Overture Penumbra: Black Plague Penumbra: Requiem Psychonauts QuickTime Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Sound Blaster X-Fi Source SDK Base Steam SumatraPDF SUPER © Version 2009.bld.36 (June 10, 2009) System Requirements Lab Team Fortress 2 TI Connect 1.6 Unreal Tournament 3 Demo Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Viewpoint Media Player VLC media player 1.0.3 WebFldrs XP Windows Defender Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 11 Windows Presentation Foundation Windows XP Service Pack 3 WinRAR archiver XML Paper Specification Shared Components Pack 1.0 Zenmas Addon Pack ==== Event Viewer Messages From Past Week ======== 12/9/2009 11:28:21 PM, error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s). 12/8/2009 12:54:22 AM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer LOLALAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB78-414. The master browser is stopping or an election is being forced. 12/8/2009 12:04:41 PM, error: NetBT [4321] - The name "WORKGROUP :1d" could not be registered on the Interface with IP address 192.168.2.4. The machine with the IP address 192.168.2.7 did not allow the name to be claimed by this machine. 12/7/2009 9:44:28 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer CHIROPRACTIC-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB7. The master browser is stopping or an election is being forced. 12/7/2009 3:49:20 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer FREEMAN-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB78-414. The master browser is stopping or an election is being forced. 12/10/2009 8:27:21 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL 12/10/2009 2:30:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 12/10/2009 2:20:27 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 12/10/2009 2:11:52 PM, error: System Error [1003] - Error code 10000050, parameter1 fffdf000, parameter2 00000001, parameter3 804dadf8, parameter4 00000000. 12/10/2009 2:10:38 PM, error: Service Control Manager [7000] - The ANIO Service service failed to start due to the following error: The system cannot find the file specified. 12/10/2009 10:24:49 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss sptd Tcpip WS2IFSL 12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 12/10/2009 10:24:46 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 12/10/2009 10:24:22 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 12/10/2009 10:23:49 AM, error: sptd [4] - Driver detected an internal error in its data structures for . 12/10/2009 10:23:49 AM, error: sfsync02 [12] - ==== End Of File =========================== The computer is now able to successfully restart normally without a hitch. I have not recieved any IE random pop-ups either. However, my speakers/sound card is not functioning properly still. Once the computer started acting up the speakers quit on me. This has happened before and was fixed with some meddeling so I'm not sure if it is directly related to my malware problems.
Hi,

Open Device Manager:

Go to Start > Run > type the following command into the run box:

devmgmt.msc

Open up the Sound, Video and game controllers tree and advise if there are any warnings

NEXT

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
When checked there were no warnings and still no sound. But now my computer doesn't even recognize that I have speakers plugged in. All physical connections are in working order.
Your Plug and Play service is probably turned off.

Please try the following:

set the startup type for Plug and Play to Automatic.
To do so, follow these steps:

1. Click Start, click Run, type services.msc and then click OK.

2. Double-click Plug and Play.
If you receive a Configuration Manager message, click OK.

3. In the Startup Type list, click Automatic, and then click OK.

4. Close Services.

5. Restart the computer.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI