This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect Virus

57 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:pullhair: The laptop worked fine till yesterday. Now it boots up, sometime I get the McAfee screen sometimes not. I move the curser and then it beeps once and locks up. Could this be related to the recent virus or do I now have hardware issues?
That is unexpected behaviour.

nothing can be ruled out.

Lets get a fresh scan with DDS and GMER and get another look.


Uncheck the box beside files as well in the GMER scan:

I'll give you the download links and instructions again:



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I can't do anything, it's like not everything loads. If i click either button on the touchpad it beeps and locks up. Is this something that could be done in safe mode (if I can get there)?
Yes, do it in safemode did something happen priior to this behavior…when did you notice this first starting? There should have been a restore point made when we did the tool clean up…try restoring to that restore point, see if it makes any difference.
I was able to restore back to a point Sunday evening. The programs that you said to add are not here now, I will have to readd. I was working in my embroidery software when the system beeped and locked up the first time. I was able to reboot and continue working but after I shut it down it would not work correctly. Here are the logs from the scans as requested.

DDS


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 18:13:51.26 on Tue 02/09/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.304 [GMT -6:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\hasplms.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\test\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://groups.yahoo.com/group/DFWpaddlers/
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nwiz] nwiz.exe /installquiet /nodetect
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Cpqset] c:\program files\hewlett-packard\default settings\cpqset.exe
mRun: [RecGuard] c:\windows\sminst\RecGuard.exe
mRun: [Reminder] c:\windows\creator\Remind_XP.exe
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [McENUI] c:\progra~1\mcafee\mhn\McENUI.exe /hide
mRun: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] c:\program files\google\gmail notifier\gnotify.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\test\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.8.3/GarminAxControl.CAB
DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} - hxxp://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244681197328
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-1-16 214664]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run –> c:\windows\system32\hasplms.exe -run [?]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-4-3 93320]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-4-3 359952]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-4-3 144704]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-4-4 24652]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-4-3 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-4-3 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-4-3 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-4-3 40552]
S2 gupdate1ca204bad189b6c;Google Update Service (gupdate1ca204bad189b6c);c:\program files\google\update\GoogleUpdate.exe [2009-8-18 133104]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;c:\windows\system32\drivers\5U870CAP.sys [2006-6-6 61952]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-4-3 34248]
S3 rootrepeal2;rootrepeal2;\??\c:\windows\system32\drivers\rootrepeal2.sys –> c:\windows\system32\drivers\rootrepeal2.sys [?]
S3 rootrepeal3;rootrepeal3;\??\c:\windows\system32\drivers\rootrepeal3.sys –> c:\windows\system32\drivers\rootrepeal3.sys [?]
S3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\tmpassthru.sys –> c:\windows\system32\drivers\TMPassthru.sys [?]
S3 VsmRWDriver;VSM Reader/Writer Type A USB Driver service;c:\windows\system32\drivers\VsmRWDriver.sys [2009-11-7 7808]

=============== Created Last 30 ================

2010-02-09 18:17:20 0 d—–w- c:\documents and settings\test\.fontconfig
2010-02-09 18:09:40 0 d—–w- c:\windows\system32\wbem\Repository
2010-02-09 16:10:32 0 d-sh–w- C:\found.000
2010-02-07 20:52:10 0 d—–w- c:\program files\KeePass Password Safe
2010-02-07 20:34:57 0 d—–w- c:\program files\Crawler
2010-02-07 20:34:53 0 d—–w- c:\docume~1\test\applic~1\Spyware Terminator
2010-02-07 20:34:45 0 d—–w- c:\program files\Spyware Terminator
2010-02-07 20:34:45 0 d—–w- c:\docume~1\alluse~1\applic~1\Spyware Terminator
2010-02-07 05:56:58 0 d—–w- c:\program files\Sun
2010-02-07 05:56:31 73728 —-a-w- c:\windows\system32\javacpl.cpl
2010-02-07 05:56:31 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-07 05:25:51 0 d—–w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
2010-02-07 05:25:49 0 d—–w- c:\program files\McAfee Security Scan
2010-02-05 04:24:08 77312 —-a-w- c:\windows\MBR.exe
2010-02-05 04:24:08 261632 —-a-w- c:\windows\PEV.exe
2010-02-05 03:32:20 1089593 ——w- c:\windows\system32\dllcache\ntprint.cat
2010-02-04 04:20:00 101154 —-a-w- C:\handle.zip
2010-02-04 04:08:54 0 d—–w- c:\windows\system32\XPSViewer
2010-02-04 04:08:05 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-02-04 04:08:05 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-02-04 04:08:05 575488 ——w- c:\windows\system32\xpsshhdr.dll
2010-02-04 04:08:05 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-02-04 04:08:05 117760 ——w- c:\windows\system32\prntvpt.dll
2010-02-04 04:08:04 1676288 ——w- c:\windows\system32\xpssvcs.dll
2010-02-04 04:08:04 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2010-02-04 04:08:04 0 d—–w- C:\25ca33317abf00ac4eb404e5903d
2010-02-04 03:02:00 417136 —-a-w- c:\windows\handle.exe
2010-02-02 02:18:43 0 d—–w- c:\docume~1\test\applic~1\Malwarebytes
2010-02-02 02:18:33 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-02 02:18:31 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-02 02:18:28 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-02 02:18:27 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 00:58:31 0 —-a-w- c:\documents and settings\test\settings.dat
2010-01-30 02:01:17 0 d—–w- c:\documents and settings\test\log
2010-01-29 02:03:13 0 d—–w- c:\documents and settings\test\Calibre Library
2010-01-29 02:03:08 0 d—–w- c:\docume~1\test\applic~1\calibre
2010-01-29 02:00:41 0 d—–w- c:\program files\Calibre2
2010-01-29 01:02:38 0 d—–w- c:\program files\Spybot - Search & Destroy
2010-01-29 01:02:38 0 d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-01-27 04:34:08 0 d—–w- c:\program files\TrendMicro
2010-01-13 01:07:42 471552 ——w- c:\windows\system32\dllcache\aclayers.dll

==================== Find3M ====================

2009-12-31 15:33:06 70656 ——w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 15:33:06 13824 ——w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-18 13:05:43 634648 ——w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 13:04:09 161792 ——w- c:\windows\system32\dllcache\ieakui.dll
2009-11-25 02:24:19 56412 —ha-w- c:\windows\system32\mlfcache.dat
2009-06-11 01:32:14 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009061020090611\index.dat

============= FINISH: 18:15:17.09 ===============

Attach


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/31/2009 2:58:31 PM
System Uptime: 2/9/2010 5:44:59 PM (1 hours ago)

Motherboard: Quanta | | 30B9
Processor: AMD Turion™ 64 X2 Mobile Technology TL-50 | Socket S1 | 1607/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 81 GiB total, 46.802 GiB free.
D: is FIXED (FAT32) - 11 GiB total, 1.093 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E965-E325-11CE-BFC1-08002BE10318}
Description: CD-ROM Drive
Device ID: IDE\CDROMHL-DT-ST_DVDRAM_GSA-4084N_______________KQ09____\304B363242393232323120352020202020202020
Manufacturer: (Standard CD-ROM drives)
Name: HL-DT-ST DVDRAM GSA-4084N
PNP Device ID: IDE\CDROMHL-DT-ST_DVDRAM_GSA-4084N_______________KQ09____\304B363242393232323120352020202020202020
Service: cdrom

==== System Restore Points ===================

RP150: 11/10/2009 9:38:48 AM - System Checkpoint
RP151: 11/10/2009 10:00:18 PM - Software Distribution Service 3.0
RP152: 11/11/2009 1:29:56 PM - Software Distribution Service 3.0
RP153: 11/13/2009 8:45:48 PM - System Checkpoint
RP154: 11/14/2009 9:23:38 PM - System Checkpoint
RP155: 11/15/2009 9:31:13 PM - System Checkpoint
RP156: 11/17/2009 8:31:54 PM - System Checkpoint
RP157: 11/18/2009 9:31:51 PM - System Checkpoint
RP158: 11/20/2009 12:55:35 PM - System Checkpoint
RP159: 11/22/2009 8:21:05 PM - System Checkpoint
RP160: 11/24/2009 10:00:28 PM - Software Distribution Service 3.0
RP161: 11/25/2009 10:56:58 PM - System Checkpoint
RP162: 11/27/2009 12:56:27 PM - System Checkpoint
RP163: 11/29/2009 10:40:40 AM - System Checkpoint
RP164: 11/30/2009 5:57:27 PM - System Checkpoint
RP165: 12/1/2009 6:01:05 PM - System Checkpoint
RP166: 12/4/2009 12:14:21 PM - System Checkpoint
RP167: 12/5/2009 10:28:40 PM - System Checkpoint
RP168: 12/8/2009 8:52:17 PM - System Checkpoint
RP169: 12/8/2009 10:00:36 PM - Software Distribution Service 3.0
RP170: 12/10/2009 10:19:28 PM - System Checkpoint
RP171: 12/11/2009 11:10:15 PM - System Checkpoint
RP172: 12/13/2009 11:36:04 AM - System Checkpoint
RP173: 12/14/2009 9:39:47 PM - System Checkpoint
RP174: 12/15/2009 7:46:14 PM - Removed eBook Library by Sony.
RP175: 12/15/2009 7:46:33 PM - Installed Reader Library by Sony.
RP176: 12/16/2009 8:42:14 PM - System Checkpoint
RP177: 12/18/2009 8:49:46 PM - System Checkpoint
RP178: 12/18/2009 10:00:30 PM - Software Distribution Service 3.0
RP179: 12/20/2009 11:24:33 AM - System Checkpoint
RP180: 12/21/2009 8:06:18 PM - System Checkpoint
RP181: 12/23/2009 2:00:31 PM - System Checkpoint
RP182: 12/24/2009 3:06:06 PM - System Checkpoint
RP183: 12/25/2009 6:27:11 PM - System Checkpoint
RP184: 12/28/2009 11:40:21 PM - System Checkpoint
RP185: 12/30/2009 9:19:05 PM - System Checkpoint
RP186: 12/31/2009 10:31:28 PM - System Checkpoint
RP187: 1/1/2010 10:39:02 PM - System Checkpoint
RP188: 1/5/2010 3:37:22 PM - System Checkpoint
RP189: 1/6/2010 5:59:38 PM - System Checkpoint
RP190: 1/8/2010 3:29:32 PM - System Checkpoint
RP191: 1/9/2010 7:21:19 PM - System Checkpoint
RP192: 1/10/2010 7:31:57 PM - System Checkpoint
RP193: 1/12/2010 9:58:57 PM - System Checkpoint
RP194: 1/12/2010 10:00:29 PM - Software Distribution Service 3.0
RP195: 1/14/2010 8:50:03 PM - System Checkpoint
RP196: 1/15/2010 10:23:27 PM - System Checkpoint
RP197: 1/17/2010 11:34:12 AM - System Checkpoint
RP198: 1/19/2010 9:11:20 PM - System Checkpoint
RP199: 1/19/2010 9:46:00 PM - Software Distribution Service 3.0
RP200: 1/21/2010 6:56:02 PM - System Checkpoint
RP201: 1/21/2010 10:00:15 PM - Software Distribution Service 3.0
RP202: 1/22/2010 11:03:06 PM - System Checkpoint
RP203: 1/24/2010 1:47:01 PM - System Checkpoint
RP204: 1/25/2010 10:34:45 PM - Removed Reader Library by Sony.
RP205: 1/25/2010 10:45:45 PM - Installed Reader Library by Sony.
RP206: 1/25/2010 11:21:15 PM - Removed Reader Library by Sony.
RP207: 1/25/2010 11:30:43 PM - Installed Reader Library by Sony.
RP208: 1/25/2010 11:53:30 PM - Removed Reader Library by Sony.
RP209: 1/26/2010 12:03:21 AM - Installed Reader Library by Sony.
RP210: 1/26/2010 12:17:33 AM - Removed Reader Library by Sony.
RP211: 1/26/2010 12:25:26 AM - Installed Reader Library by Sony.
RP212: 1/26/2010 12:48:39 AM - Removed Reader Library by Sony.
RP213: 1/26/2010 12:54:27 AM - Installed Reader Library by Sony.
RP214: 1/26/2010 7:13:14 PM - Removed Reader Library by Sony.
RP215: 1/26/2010 7:14:24 PM - Removed Reader Library by Sony.
RP216: 1/26/2010 7:15:43 PM - Removed Quicken 2006
RP217: 1/26/2010 7:43:42 PM - Installed Reader Library by Sony.
RP218: 1/26/2010 10:21:28 PM - Removed PRS-500 USB driver.
RP219: 1/26/2010 10:32:41 PM - Installed Trend Micro RUBotted
RP220: 1/26/2010 10:34:08 PM - Installed HiJackThis
RP221: 1/28/2010 8:00:27 PM - Installed calibre
RP222: 1/28/2010 8:17:19 PM - Removed Reader Library by Sony.
RP223: 1/30/2010 1:31:37 AM - System Checkpoint
RP224: 1/31/2010 6:25:42 PM - System Checkpoint
RP225: 2/2/2010 6:59:14 PM - System Checkpoint
RP226: 2/2/2010 7:30:50 PM - Automatic Restore Point
RP227: 2/2/2010 7:31:15 PM - Automatic Restore Point
RP228: 2/3/2010 9:48:13 PM - OTL Restore Point
RP229: 2/3/2010 10:00:24 PM - Software Distribution Service 3.0
RP230: 2/4/2010 10:00:19 PM - Software Distribution Service 3.0
RP231: 2/6/2010 5:24:16 PM - System Checkpoint
RP232: 2/6/2010 5:39:59 PM - OTL Restore Point
RP233: 2/6/2010 5:43:03 PM - OTL Restore Point
RP234: 2/6/2010 5:59:18 PM - OTL Restore Point
RP235: 2/6/2010 11:37:16 PM - Removed J2SE Runtime Environment 5.0 Update 6
RP236: 2/6/2010 11:38:12 PM - Removed Java™ 6 Update 7
RP237: 2/6/2010 11:50:44 PM - Installed Java™ SE Development Kit 6 Update 18
RP238: 2/6/2010 11:55:42 PM - Installed Java™ 6 Update 18
RP239: 2/7/2010 2:11:58 PM - Removed Trend Micro RUBotted
RP240: 2/7/2010 2:13:28 PM - Removed HiJackThis
RP241: 2/7/2010 2:27:49 PM - Installed WOT for Internet Explorer
RP242: 2/7/2010 5:42:13 PM - Installed HP Help and Support
RP243: 2/9/2010 12:08:57 PM - Restore Operation

==== Installed Programs ======================


32-bit VSM Device Drivers
32-bit VSM Device Drivers 8.2
4D Embroidery Extra 8.1
4D Embroidery System 8.1 Update
7-Zip 9.07 beta
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AutoUpdate
Bonjour
BufferChm
calibre
Conexant HD Audio
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Customer Experience Enhancement
Destinations
DeviceManagementQFolder
DivX
Embroidery Machine Communication Software
EPSON Scan
EPSON WorkForce 500 Series Printer Uninstall
FullDPAppQFolder
Garmin POI Loader
Garmin USB Drivers
Google Chrome
Google Earth
Google Gmail Notifier
Google Update Helper
Google Updater
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Help and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Quick Launch Buttons 6.10 A2
HP QuickPlay 2.3
HP Update
HP User Guides 0032
HP Wireless Assistant 2.00 G2
HpSdpAppCoreApp
ieSpell
InstantShareDevices
iTunes
Java DB 10.5.3.0
Java™ 6 Update 18
Java™ SE Development Kit 6 Update 18
LightScribe 1.4.97.1
Macromedia Flash Player 8
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
McAfee Security Scan Plus
McAfee SecurityCenter
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Works
MobileMe Control Panel
Move Media Player
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 5.0
NetWaiting
NVIDIA Drivers
Office 2003 Trial Assistant
OpenOffice.org 3.0
OptionalContentQFolder
Otto
PhotoGallery
QuickTime
RandMap
Safari
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SkinsHP1
Soft Data Fax Modem with SmartCP
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
Sonic_PrimoSDK
SonicAC3Encoder
SonicMPEGEncoder
Spybot - Search & Destroy
Synaptics Pointing Device Driver
TourSetup
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Vongo
WebFldrs XP
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
Wireless Home Network Setup

==== Event Viewer Messages From Past Week ========

2/9/2010 12:08:45 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNASvc with arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
2/9/2010 12:08:17 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AmdK8 Cdrom Fips Imapi IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss redbook sp_rsdrv2 Tcpip
2/9/2010 12:08:17 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 12:08:17 PM, error: Service Control Manager [7001] - The Message Queuing Triggers service depends on the Message Queuing service which failed to start because of the following error: The dependency service or group failed to start.
2/9/2010 12:08:17 PM, error: Service Control Manager [7001] - The Message Queuing service depends on the Distributed Transaction Coordinator service which failed to start because of the following error: The dependency service or group failed to start.
2/9/2010 12:08:17 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 12:08:17 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 12:08:17 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 12:08:17 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 12:08:17 PM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/9/2010 12:07:09 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/9/2010 12:07:07 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2/9/2010 10:02:37 AM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
2/7/2010 9:11:56 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service COMSysApp with arguments "" in order to run the server: {ECABAFBC-7F19-11D2-978E-0000F8757E2A}
2/7/2010 9:07:53 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
2/7/2010 9:07:53 PM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/7/2010 9:07:53 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
2/7/2010 9:07:20 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
2/7/2010 9:07:20 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/7/2010 9:07:18 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the mcmscsvc service.
2/6/2010 6:59:46 PM, error: Service Control Manager [7031] - The McAfee SystemGuards service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/6/2010 6:59:45 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:44 PM, error: Service Control Manager [7034] - The Message Queuing Triggers service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:44 PM, error: Service Control Manager [7034] - The hpqwmiex service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:43 PM, error: Service Control Manager [7034] - The Viewpoint Manager Service service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:43 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:43 PM, error: Service Control Manager [7034] - The Message Queuing service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:42 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/6/2010 6:59:42 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/6/2010 6:59:42 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program.
2/6/2010 6:59:42 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/6/2010 6:59:41 PM, error: Service Control Manager [7034] - The McAfee SiteAdvisor Service service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:41 PM, error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:41 PM, error: Service Control Manager [7034] - The HASP License Manager service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:41 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 6:59:41 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/6/2010 6:59:41 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/6/2010 6:28:08 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference error message: The referenced assembly is not installed on your system. .
2/6/2010 6:28:08 PM, error: SideBySide [59] - Generate Activation Context failed for C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL. Reference error message: The operation completed successfully. .
2/6/2010 6:28:08 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last Error was The referenced assembly is not installed on your system.
2/6/2010 4:17:15 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service.
2/4/2010 9:24:14 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Cdrom Imapi redbook
2/4/2010 10:33:42 PM, error: PlugPlayManager [11] - The device Root\LEGACY_ROOTREPEAL\0000 disappeared from the system without first being prepared for removal.
2/4/2010 10:25:05 PM, error: WMPNetworkSvc [14344] - A new media server was not initialized because WMCreateDeviceRegistration() encountered error '0xc00d2711'. The Windows Media DRM components on your computer might be corrupted. Verify that protected files play correctly in Windows Media Player, and then restart the WMPNetworkSvc service.
2/4/2010 10:24:28 PM, error: Service Control Manager [7031] - The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
2/2/2010 5:33:58 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'GEARAspiWDM.sys' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.

==== End Of File ===========================


GMER

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-09 19:26:55
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\test\LOCALS~1\Temp\kgpyapod.sys


—- System - GMER 1.0.15 —-

SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwCreateKey [0x804D7FCE]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FCE] ZwCreateKey [0x804D7FCE]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwDeleteKey [0x804D7FD8]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FD8] ZwDeleteKey [0x804D7FD8]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwDeleteValueKey [0x804D7FC9]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FC9] ZwDeleteValueKey [0x804D7FC9]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwEnumerateKey [0x804D7FDD]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FDD] ZwEnumerateKey [0x804D7FDD]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwEnumerateValueKey [0x804D7FE2]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FE2] ZwEnumerateValueKey [0x804D7FE2]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwOpenKey [0x804D7FF1]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FF1] ZwOpenKey [0x804D7FF1]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwQueryKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FEC] ZwQueryKey [0x804D7FEC]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwQueryValueKey [0x804D7FE7]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FE7] ZwQueryValueKey [0x804D7FE7]
SSDT \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation) ZwSetValueKey [0x804D7FD3]
SSDT \WINDOWS\system32\ntkrnlpa.exe[unknown section] [804D7FD3] ZwSetValueKey [0x804D7FD3]

INT 0x03 \WINDOWS\system32\ntkrnlpa.exe[unknown section] 804D7FF6

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xECDEE78A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xECDEE738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xECDEE74C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xECDEE7CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xECDEE917]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xECDEE710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xECDEE724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xECDEE79E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xECDEE8B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xECDEE858]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xECDEE93F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xECDEE92B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xECDEE776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xECDEE762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xECDEE7F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xECDEE901]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xECDEE7E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xECDEE7B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device \Driver\Disk \Device\Harddisk0\DR0 aksfridge.sys (Ancillary Function Driver/Aladdin Knowledge Systems Ltd.)

AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Please navigate to the following folder: C:\4DEmbroidery\Drivers\VSMGenericDriver\Drivers32

locate this file: VsmRWDriver.sys


right click that file and select "copy"

Now navigate to the C:\WINDOWS\system32\drivers folder



locate the VsmRWDriver.sys file, right click it and choose "rename" > rename it to VsmRWDriver.sys.old

now right click in the space beside that file > choose "paste"

the VsmRWDriver.sys file you copied from drivers32 will now be in the system32/drivers folder.



Now I need you to upload that renamed file please:

Please open this page in your browser:

http://www.bleepingcomputer.com/submit-mal….php?channel=22

Fill in the link to topic field with a link to this topic

http://forums.whatthetech.com/Google_Redir…us_t109999.html

Copy/paste the following into the Browse to the file you want to submit field:

C:\WINDOWS\system32\drivers\VsmRWDriver.sys.old


Then press Send File, this will upload the file for analysis



Please reboot, then let me know if that makes any difference to how the computer is running
File uploaded as requested. Computer seems to be running fine. On Sunday I did notice a problem with the 4D Embroidery. Normally I could open the file organizer double click on one of the files and it would send it to Extra (which is used for editing and sending the design to the sewing machine) but I got and am still getting an error message, saying "Paint cannot read this file. this is not a valid bitmap file, or its format is not currently supported" Don't know if this has anything to do with the infection or not ,just thought i would throw it out there.
From your event log in the DDS report - this line

"2/9/2010 10:02:37 AM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:."

does indicate an issue with file system corruption.

Which would appear to be your embroidery program.

You might try uninstalling it completely, then reinstalling it.

or run chkdsk - see if that helps:


  • Click Start > Run… then type in CMD and click on OK.
  • At the Command Prompt C:\ > type the following: chkdsk c: /r and hit the Enter/Return key.
    Note: chkdsk c: /r presumes that the disk upon which you wish to run Error Checking is your C: Drive (most often)
  • When prompted with:

CHKDSK cannot run because the volume is in use by another process
Would you like to schedule this volume to be checked next time the system
restarts (Y/N)

  • Hit the Y key then at the Command Prompt C:\ >
  • Type in EXIT and and hit the Enter/Return key.
  • Now Reboot(Restart) your computer.
Note: Upon Reboot(Restart), CHKDSK will start and carry out the repairs required.

You should see a screen like this just after the Post(Power On Self Test) screen:

[external image: Posted Image]

Note: Do not touch either the keyboard or mouse, otherwise the CHKDSK will be canceled and you computer will continue to boot-up as normal.

Note: When CHKDSK has completed its scans, the machine will proceed to load and Boot to Windows, without need for you to take any action.


Let me know how that goes.
I uninstalled and reinstalled the embroidery software and ran the chkdsk (assume it did not find anything, I got up to let the dogs in and it was done, opening windows). I am still getting the error message in the embroidery organizer. I plan on going to the sewing center on Saturday to see if they have a clue.
there may be a file association issue if the extra's are trying to be opened with paint what file extensions are used with the embroidery program…see if we can correct the file associations
Hi

Try this:
  • Click on Start, then My Computer
  • Click on the Tools menu option and then choose Folder Options….
  • In the Folder Options window, click on the File Types tab.
  • Under Registered file types:, scroll down until you see the .hus file extension.
  • Click on the .hus file extension to highlight it:
  • Click the Change button in the Details for the file extension area near the bottom of the window.
  • The Open With dialog box should appear.
  • Scroll through the options in the Programs area and choose the application that you want to open the file extension with when you double-click on the particular kind of file on your computer - you should find your embroidery program listed here.
    Note: Chances are, the applications listed under Recommended Programs will contain the Embroidery program, but be sure to look at the applications under Other Programs as well if it doesn't show up immediately.
    Note: Click Browse… to search through your computer for the Embroidery program if it is not listed.
  • Once you find it - Click the OK button on the Open With window.
  • Click the Close button at the bottom of the Folder Options window.
  • From this point forward, when you double-click on any file with this particular file extension, the Embroidery Program will launch and load the particular file.

The Manufacturer of the software should be able to help you with this if that doesn't work.
So is everything running well now?


Are there any more issues?

Run this next program,

let's make sure there are no other file associations that aren't working properly.


Download SREng

  • Extract it to Desktop and double click SREngLdr.EXE to run it
  • Select System Repair from the left pane.
  • Click on File Association
  • Select all entries that have an Error status click [Repair]
  • Refer to this image for an example:

    [external image: Posted Image]
  • Close SREng now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI