90% of the time when trying to boot in normal mode or "last working mode" I am stopped at the windows screen with the loading bar. The hard drive is silent and the load screen stays moving. The other 10% of the time I will see a quick blue screen error message that lasts for a second before auto restarting.
Here is DDS.txt
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 21:44:05.58 on Fri 12/11/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1452 [GMT -6:00]
AV: avast! antivirus 4.8.1368 [VPS 091211-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Randy \Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.joystiq.com/
uInternet Settings,ProxyOverride = *.local
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Octoshape Streaming Services] "c:\program files\octoshape streaming services\randy \OctoshapeClient.exe" -inv:bootrun
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab
DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} - hxxp://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\randyk~1\applic~1\mozilla\firefox\profiles\jgl4ffsv.default\
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-20 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-20 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-5-19 138680]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-2-16 24652]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2003-10-22 344800]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-5-19 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-5-19 352920]
S3 kbeepm;kbeepm;\??\c:\docume~1\randyk~1\locals~1\temp\kbeepm.sys –> c:\docume~1\randyk~1\locals~1\temp\kbeepm.sys [?]
S3 XDva009;XDva009;\??\c:\windows\system32\xdva009.sys –> c:\windows\system32\XDva009.sys [?]
S3 XDva016;XDva016;\??\c:\windows\system32\xdva016.sys –> c:\windows\system32\XDva016.sys [?]
S3 XDva019;XDva019;\??\c:\windows\system32\xdva019.sys –> c:\windows\system32\XDva019.sys [?]
S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
=============== Created Last 30 ================
2009-12-11 02:50:38 0 d—–w- c:\program files\Trend Micro
2009-12-10 20:18:38 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-09 22:43:18 70656 —-a-w- c:\windows\system32\yv12vfw.dll
2009-12-09 22:43:18 27648 —-a-w- c:\windows\system32\AVSredirect.dll
2009-12-09 22:43:17 70656 —-a-w- c:\windows\system32\i420vfw.dll
2009-12-09 22:37:02 0 d—–w- c:\program files\eRightSoft
2009-12-07 21:25:01 201216 —-a-w- c:\windows\msa.exe
2009-12-07 21:04:09 0 d—–w- c:\windows\Logs
2009-12-07 20:59:18 0 d—–w- c:\program files\Rockstar Games
2009-12-07 20:52:49 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-12-07 20:52:40 0 d—–w- c:\program files\DAEMON Tools Lite
2009-12-07 20:52:25 0 d—–w- c:\docume~1\randyk~1\applic~1\DAEMON Tools Lite
2009-12-07 20:52:13 0 d—–w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2009-12-02 20:41:58 1525 —-a-w- c:\documents and settings\randy \.recently-used.xbel
2009-12-02 20:41:27 0 d—–w- c:\documents and settings\randy \.thumbnails
2009-12-02 20:10:22 0 d—–w- c:\documents and settings\randy \.gimp-2.6
2009-12-02 20:09:48 0 d—–w- c:\program files\GIMP-2.0
2009-11-23 07:19:24 0 d—–w- c:\docume~1\randyk~1\applic~1\SumatraPDF
2009-11-23 07:19:21 0 d—–w- c:\program files\SumatraPDF
2009-11-14 16:35:31 0 d—–w- c:\docume~1\randyk~1\applic~1\MSNInstaller
==================== Find3M ====================
2009-12-10 16:20:06 98304 —-a-w- c:\windows\DUMP4c4b.tmp
2009-10-29 07:46:59 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46:52 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46:50 17408 ——w- c:\windows\system32\corpol.dll
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20:16 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll
2009-09-28 04:48:23 411368 —-a-w- c:\windows\system32\deploytk.dll
2006-05-03 09:06:54 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47:16 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30:52 216064 –sh–r- c:\windows\system32\nbDX.dll
2009-01-03 20:56:03 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009010320090104\index.dat
============= FINISH: 21:44:29.94 ===============
And Attatch.txt
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/12/2006 12:28:15 AM
System Uptime: 12/10/2009 8:37:50 PM (25 hours ago)
Motherboard: Unknow | | NF570_SLIT-A
Processor: Intel® Core™2 CPU 6400 @ 2.13GHz | Socket 775 | 2133/266mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 190 GiB total, 89.554 GiB free.
D: is CDROM ()
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4D36E97D-E325-11CE-BFC1-08002BE10318}
Description: Microsoft UAA Bus Driver for High Definition Audio
Device ID: PCI\VEN_10DE&DEV;_026C&SUBSYS;_026C10DE&REV;_A2\3&2411E6FE&0&81
Manufacturer: Microsoft
Name: Microsoft UAA Bus Driver for High Definition Audio
PNP Device ID: PCI\VEN_10DE&DEV;_026C&SUBSYS;_026C10DE&REV;_A2\3&2411E6FE&0&81
Service: HDAudBus
==== System Restore Points ===================
RP803: 9/13/2009 5:56:38 PM - System Checkpoint
RP804: 9/14/2009 9:28:32 PM - System Checkpoint
RP805: 9/15/2009 10:33:18 PM - System Checkpoint
RP806: 9/16/2009 11:34:09 PM - System Checkpoint
RP807: 9/18/2009 10:33:31 AM - System Checkpoint
RP808: 9/19/2009 3:15:14 PM - System Checkpoint
RP809: 9/20/2009 3:52:07 PM - System Checkpoint
RP810: 9/21/2009 5:56:01 PM - System Checkpoint
RP811: 9/23/2009 10:14:13 AM - System Checkpoint
RP812: 9/24/2009 12:28:04 PM - System Checkpoint
RP813: 9/25/2009 2:28:55 PM - System Checkpoint
RP814: 9/26/2009 2:47:02 PM - System Checkpoint
RP815: 9/27/2009 3:25:55 PM - System Checkpoint
RP816: 9/27/2009 11:48:15 PM - Installed Java™ 6 Update 15
RP817: 9/29/2009 12:24:39 AM - System Checkpoint
RP818: 9/30/2009 1:16:55 AM - System Checkpoint
RP819: 10/1/2009 1:22:04 AM - System Checkpoint
RP820: 10/2/2009 1:53:30 AM - System Checkpoint
RP821: 10/3/2009 10:56:09 AM - System Checkpoint
RP822: 10/4/2009 4:30:01 PM - System Checkpoint
RP823: 10/5/2009 5:01:18 PM - System Checkpoint
RP824: 10/6/2009 8:57:31 PM - System Checkpoint
RP825: 10/8/2009 12:34:28 AM - System Checkpoint
RP826: 10/9/2009 1:15:39 AM - System Checkpoint
RP827: 10/10/2009 5:13:24 PM - System Checkpoint
RP828: 10/11/2009 3:00:16 AM - Software Distribution Service 3.0
RP829: 10/12/2009 3:47:31 AM - System Checkpoint
RP830: 10/13/2009 3:49:07 AM - System Checkpoint
RP831: 10/13/2009 6:19:39 PM - Software Distribution Service 3.0
RP832: 10/14/2009 7:08:33 PM - System Checkpoint
RP833: 10/15/2009 7:10:55 PM - System Checkpoint
RP834: 10/16/2009 7:58:56 PM - System Checkpoint
RP835: 10/18/2009 12:41:20 AM - System Checkpoint
RP836: 10/19/2009 12:51:23 AM - System Checkpoint
RP837: 10/20/2009 12:55:13 AM - System Checkpoint
RP838: 10/21/2009 1:52:18 AM - System Checkpoint
RP839: 10/21/2009 3:00:14 AM - Software Distribution Service 3.0
RP840: 10/22/2009 3:35:48 AM - System Checkpoint
RP841: 10/23/2009 3:47:10 AM - System Checkpoint
RP842: 10/25/2009 2:25:17 AM - System Checkpoint
RP843: 10/26/2009 11:05:37 AM - System Checkpoint
RP844: 10/27/2009 11:08:00 AM - System Checkpoint
RP845: 10/28/2009 11:32:55 AM - System Checkpoint
RP846: 10/29/2009 2:18:05 PM - System Checkpoint
RP847: 10/30/2009 2:29:47 PM - System Checkpoint
RP848: 10/31/2009 3:26:26 PM - System Checkpoint
RP849: 11/1/2009 5:25:44 PM - System Checkpoint
RP850: 11/3/2009 3:07:37 AM - System Checkpoint
RP851: 11/4/2009 4:02:23 AM - System Checkpoint
RP852: 11/5/2009 4:00:16 AM - Software Distribution Service 3.0
RP853: 11/6/2009 4:26:15 AM - System Checkpoint
RP854: 11/7/2009 5:07:01 AM - System Checkpoint
RP855: 11/8/2009 4:42:09 PM - System Checkpoint
RP856: 11/10/2009 4:34:45 AM - System Checkpoint
RP857: 11/11/2009 3:00:15 AM - Software Distribution Service 3.0
RP858: 11/12/2009 3:49:13 AM - System Checkpoint
RP859: 11/13/2009 4:10:20 AM - System Checkpoint
RP860: 11/14/2009 4:24:07 AM - System Checkpoint
RP861: 11/15/2009 4:34:45 AM - System Checkpoint
RP862: 11/16/2009 5:31:00 AM - System Checkpoint
RP863: 11/17/2009 5:43:01 AM - System Checkpoint
RP864: 11/18/2009 10:49:15 AM - System Checkpoint
RP865: 11/19/2009 11:09:44 AM - System Checkpoint
RP866: 11/20/2009 6:17:10 PM - System Checkpoint
RP867: 11/21/2009 6:55:22 PM - System Checkpoint
RP868: 11/22/2009 7:16:38 PM - System Checkpoint
RP869: 11/23/2009 1:23:12 AM - Removed Adobe Reader 6.0.1
RP870: 11/24/2009 2:25:48 AM - System Checkpoint
RP871: 11/25/2009 2:40:22 AM - System Checkpoint
RP872: 11/25/2009 12:27:43 PM - Software Distribution Service 3.0
RP873: 11/26/2009 4:00:55 PM - System Checkpoint
RP874: 11/27/2009 4:41:57 PM - System Checkpoint
RP875: 11/28/2009 8:34:59 PM - System Checkpoint
RP876: 11/29/2009 8:36:56 PM - Removed Project64 1.6
RP877: 12/1/2009 3:27:41 AM - System Checkpoint
RP878: 12/2/2009 5:57:12 AM - System Checkpoint
RP879: 12/3/2009 6:20:48 AM - System Checkpoint
RP880: 12/4/2009 6:21:56 AM - System Checkpoint
RP881: 12/5/2009 7:14:57 AM - System Checkpoint
RP882: 12/6/2009 7:26:57 AM - System Checkpoint
RP883: 12/7/2009 8:26:57 AM - System Checkpoint
RP884: 12/7/2009 2:52:48 PM - SPTD setup V1.62
RP885: 12/7/2009 3:04:21 PM - Installed DirectX
RP886: 12/8/2009 5:46:32 PM - System Checkpoint
RP887: 12/9/2009 3:00:16 AM - Software Distribution Service 3.0
RP888: 12/10/2009 10:49:23 AM - Restore Operation
RP889: 12/10/2009 10:59:56 AM - Restore Operation
RP890: 12/10/2009 11:05:49 AM - Restore Operation
RP891: 12/10/2009 11:56:48 AM - Uninstall Hitman: Contracts
RP892: 12/10/2009 12:02:34 PM - Configured AirPlus Xtreme G
RP893: 12/10/2009 2:10:46 PM - Restore Operation
RP894: 12/10/2009 8:26:46 PM - Restore Operation
RP895: 12/10/2009 8:40:06 PM - Restore Operation
RP896: 12/11/2009 8:30:33 PM - System Checkpoint
==== Installed Programs ======================
µTorrent
Ad-Aware SE Personal
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Shockwave Player
AGEIA PhysX v7.09.13
AIM 6
Apple Mobile Device Support
Apple Software Update
avast! Antivirus
AviSynth 2.5
BioShock
Bonjour
BrainBread v1.2
CCleaner (remove only)
Counter-Strike: Source
Creative Audio Console
Creative Media Toolbox
Creative MediaSource
Creative System Information
Critical Update for Windows Media Player 11 (KB959772)
Day of Defeat: Source
DivX Content Uploader
DivX Web Player
DNA
Doom 3
Grand Theft Auto 3
Grand Theft Auto: San Andreas
Grand Theft Auto: Vice City
Half-Life
Half-Life 2
HijackThis 2.0.2
Hitman Blood Money
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Indigo Prophecy
IrfanView (remove only)
iTunes
iTunes Alarm Clock 2.0
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 8
J2SE Runtime Environment 5.0 Update 9
Java™ 6 Update 15
Java™ 6 Update 7
Left 4 Dead
LightScribe [removed]
Logitech SetPoint
Manhunt
Max Payne
Max Payne 2: The Fall of Max Payne
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.5)
MSXML 6 Service Pack 2 (KB954459)
NVIDIA Drivers
OpenAL
OpenOffice.org 3.0
PC Wizard 2008.1.81
PeerGuardian 2.0
Penumbra Overture
Penumbra: Black Plague
Penumbra: Requiem
Psychonauts
QuickTime
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Sound Blaster X-Fi
Source SDK Base
Steam
SumatraPDF
SUPER © Version 2009.bld.36 (June 10, 2009)
System Requirements Lab
Team Fortress 2
TI Connect 1.6
Unreal Tournament 3 Demo
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Viewpoint Media Player
VLC media player 1.0.3
WebFldrs XP
Windows Defender
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
Zenmas Addon Pack
==== Event Viewer Messages From Past Week ========
12/9/2009 11:28:21 PM, error: Service Control Manager [7034] - The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s).
12/6/2009 7:03:48 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer LOLALAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB78-414. The master browser is stopping or an election is being forced.
12/6/2009 2:39:39 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer FREEMAN-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB78-414. The master browser is stopping or an election is being forced.
12/6/2009 10:17:03 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer CHIROPRACTIC-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{7B9E8052-BB7. The master browser is stopping or an election is being forced.
12/5/2009 8:38:28 PM, error: NetBT [4321] - The name "WORKGROUP :1d" could not be registered on the Interface with IP address 192.168.2.4. The machine with the IP address 192.168.2.7 did not allow the name to be claimed by this machine.
12/10/2009 8:27:21 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL
12/10/2009 2:30:39 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
12/10/2009 2:20:27 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
12/10/2009 2:11:52 PM, error: System Error [1003] - Error code 10000050, parameter1 fffdf000, parameter2 00000001, parameter3 804dadf8, parameter4 00000000.
12/10/2009 2:10:38 PM, error: Service Control Manager [7000] - The ANIO Service service failed to start due to the following error: The system cannot find the file specified.
12/10/2009 10:24:49 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss sptd Tcpip WS2IFSL
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:49 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2009 10:24:46 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
12/10/2009 10:24:22 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
12/10/2009 10:23:49 AM, error: sptd [4] - Driver detected an internal error in its data structures for .
12/10/2009 10:23:49 AM, error: sfsync02 [12] -
==== End Of File ===========================
GMER.txt
GMER 1.0.15.15279 -
http://www.gmer.net
Rootkit scan 2009-12-12 06:46:38
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\RANDYK~1\LOCALS~1\Temp\agtdykog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB17D36B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB17D3574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB17D3A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB17D314C]
SSDT spja.sys ZwEnumerateKey [0xF74FCDA4]
SSDT spja.sys ZwEnumerateValueKey [0xF74FD132]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB17D364E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB17D308C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB17D30F0]
SSDT spja.sys ZwQueryKey [0xF74FD20A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB17D376E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB17D372E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB17D38AE]
INT 0x62 ? 8ACE2BF8
INT 0x73 ? 8AD50BF8
INT 0x82 ? 8ACE2BF8
INT 0x83 ? 8AD50BF8
INT 0xB4 ? 8AA5DBF8
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs 8AD4F1F8
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Fastfat \FatCdrom 88BB31F8
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\sptd \Device\4033101670 spja.sys
Device \Driver\usbohci \Device\USBPDO-0 8ABD41F8
Device \Driver\usbehci \Device\USBPDO-1 8AB231F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8AD511F8
Device \Driver\dmio \Device\DmControl\DmConfig 8AD511F8
Device \Driver\dmio \Device\DmControl\DmPnP 8AD511F8
Device \Driver\dmio \Device\DmControl\DmInfo 8AD511F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{7B9E8052-BB78-4140-AE2A-E5DAAC0831E7} 88B831F8
Device \Driver\PCI_PNP5420 \Device\00000054 spja.sys
Device \Driver\PCI_PNP5420 \Device\00000054 spja.sys
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\Ftdisk \Device\HarddiskVolume1 8ACE31F8
Device \Driver\Cdrom \Device\CdRom0 8ABC81F8
Device \Driver\Cdrom \Device\CdRom1 8ABC81F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort0 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7978B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\NetBT \Device\NetBt_Wins_Export 88B831F8
Device \Driver\NetBT \Device\NetbiosSmb 88B831F8
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\NetBT \Device\NetBT_Tcpip_{49DCED48-698B-44FA-A7AD-65F6653F4D1E} 88B831F8
Device \Driver\usbohci \Device\USBFDO-0 8ABD41F8
Device \Driver\usbehci \Device\USBFDO-1 8AB231F8
Device \Driver\nvata \Device\NvAta0 8AD501F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 88B471F8
Device \Driver\nvata \Device\NvAta1 8AD501F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 88B471F8
Device \Driver\Ftdisk \Device\FtControl 8ACE31F8
Device \Driver\a9s5teur \Device\Scsi\a9s5teur1Port4Path0Target0Lun0 8A803500
Device \Driver\a9s5teur \Device\Scsi\a9s5teur1Port4Path0Target0Lun0 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\a9s5teur \Device\Scsi\a9s5teur1 8A803500
Device \Driver\a9s5teur \Device\Scsi\a9s5teur1 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Fastfat \Fat 88BB31F8
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Cdfs \Cdfs 88B761F8
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x42 0xE7 0x93 0xD0 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCE 0x50 0xB3 0xE5 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0xC4 0xFF 0xC4 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x42 0xE7 0x93 0xD0 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCE 0x50 0xB3 0xE5 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0xC4 0xFF 0xC4 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x42 0xE7 0x93 0xD0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCE 0x50 0xB3 0xE5 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3B 0xC4 0xFF 0xC4 …
—- EOF - GMER 1.0.15 —-
Thank you for your reply.