This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Several blue screens (Vista)

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm on my girlfriend's computer, and it has been working well, mostly. Today, though , Vista has crashed on several occasions (Page break). System Restore helped to get past the initial log in screen. Going through the initial post and downloads, both GMER AND Defogger hasn't ran anything. GMER crashed the system, and Defogger disappeared? Anyway, here is what I have so far, in terms of logs… DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:27:12.09 on Fri 03/12/2010 Internet Explorer: 8.0.6001.18882 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2942.2067 [GMT -8:00] AV: Trend Micro Internet Security *On-access scanning disabled* (Outdated) {7D2296BC-32CC-4519-917E-52E652474AF5} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\Windows\system32\svchost.exe -k hpdevmgmt c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\SearchProtocolHost.exe C:\hp\support\hpsysdrv.exe C:\Windows\System32\rundll32.exe C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\FinePixViewer\QuickDCF2.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\PictureMover\Bin\PictureMover.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Cricket\QuickLink Mobile\QuickLink Mobile.exe C:\Program Files\Mozilla Firefox\firefox.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Owner\Downloads\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=bestbuy&pf=cndt uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=bestbuy&pf=cndt mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=bestbuy&pf=cndt mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN uRun: [OE] c:\program files\trend micro\internet security\tmas_oe\TMAS_OEMon.exe uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0" mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\cyberlink dvd suite deluxe" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe" mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" dRun: [OE] c:\program files\trend micro\internet security\tmas_oe\TMAS_OEMon.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\exifla~1.lnk - c:\program files\finepixviewer\QuickDCF2.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\pictur~1.lnk - c:\program files\picturemover\bin\PictureMover.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: {76DFA023-3954-4131-B737-504EFEE36294} = 172.28.221.53 172.28.221.54 ================= FIREFOX =================== FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\tuwr1b3q.default\ FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\drivers\tmlwf.sys [2008-7-29 145424] R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-7-29 50192] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2009-7-23 36368] R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\drivers\tmwfp.sys [2008-7-29 256528] R3 uts_bus;UTStarcom USB Composite Device driver (WDM);c:\windows\system32\drivers\uts_bus.sys [2010-2-27 84352] R3 uts_mdfl;UTStarcom USB Modem Filter;c:\windows\system32\drivers\uts_mdfl.sys [2010-2-27 14976] R3 uts_mdm;UTStarcom USB Modem Drivers;c:\windows\system32\drivers\uts_mdm.sys [2010-2-27 110848] R3 uts_serd;UTStarcom USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\uts_serd.sys [2010-2-27 90880] S2 Norton Internet Security;Norton Internet Security;"c:\program files\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 –> c:\program files\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?] S2 TmPfw;Trend Micro Personal Firewall;c:\program files\trend micro\internet security\TmPfw.exe [2009-1-28 497008] S2 TmProxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2009-1-28 677128] S3 PCD5SRVC{BD6912E3-AC9D80E8-05040000};PCD5SRVC{BD6912E3-AC9D80E8-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pc-doc~1\PCD5SRVC.pkms [2008-9-9 20640] S4 nvrd32;NVIDIA nForce RAID Driver;c:\windows\system32\drivers\nvrd32.sys [2008-11-13 133152] =============== Created Last 30 ================ 2010-03-12 18:26 351,763,970 a——- c:\windows\MEMORY.DMP 2010-03-06 19:54 –d—– c:\program files\PokerStars 2010-02-27 06:17 –d—– c:\programdata\Office Genuine Advantage 2010-02-27 04:18 897,624 a——- c:\windows\system32\drivers\tcpip.sys 2010-02-27 04:18 1,314,816 a——- c:\windows\system32\quartz.dll 2010-02-27 04:18 123,904 a——- c:\windows\system32\msvfw32.dll 2010-02-27 04:18 91,136 a——- c:\windows\system32\avifil32.dll 2010-02-27 04:18 82,944 a——- c:\windows\system32\mciavi32.dll 2010-02-27 04:18 65,024 a——- c:\windows\system32\avicap32.dll 2010-02-27 04:18 50,176 a——- c:\windows\system32\iyuv_32.dll 2010-02-27 04:18 31,744 a——- c:\windows\system32\msvidc32.dll 2010-02-27 04:18 22,528 a——- c:\windows\system32\msyuv.dll 2010-02-27 04:18 13,312 a——- c:\windows\system32\msrle32.dll 2010-02-27 04:18 11,776 a——- c:\windows\system32\tsbyuv.dll 2010-02-27 04:17 281,600 a——- c:\windows\system32\raschap.dll 2010-02-27 04:17 244,224 a——- c:\windows\system32\rastls.dll 2010-02-27 04:15 156,672 a——- c:\windows\system32\t2embed.dll 2010-02-27 04:15 72,704 a——- c:\windows\system32\fontsub.dll 2010-02-27 04:15 212,992 a——- c:\windows\system32\drivers\mrxsmb10.sys 2010-02-27 04:15 105,472 a——- c:\windows\system32\drivers\mrxsmb.sys 2010-02-27 04:03 –d—– c:\users\owner\appdata\roaming\Smith Micro 2010-02-27 04:01 110,848 a——- c:\windows\system32\drivers\uts_mdm.sys 2010-02-27 04:01 90,880 a——- c:\windows\system32\drivers\uts_serd.sys 2010-02-27 04:01 84,352 a——- c:\windows\system32\drivers\uts_bus.sys 2010-02-27 04:01 14,976 a——- c:\windows\system32\drivers\uts_mdfl.sys 2010-02-27 04:01 12,160 a——- c:\windows\system32\drivers\uts_whnt.sys 2010-02-27 04:01 12,160 a——- c:\windows\system32\drivers\uts_wh.sys 2010-02-27 04:01 12,160 a——- c:\windows\system32\drivers\uts_cmnt.sys 2010-02-27 04:01 12,160 a——- c:\windows\system32\drivers\uts_cm.sys 2010-02-27 04:01 –d—– c:\program files\UTStarcom 2010-02-27 04:01 –d—– c:\program files\Cricket 2010-02-27 02:08 24,064 a——- c:\windows\system32\nshhttp.dll 2010-02-27 02:08 411,136 a——- c:\windows\system32\drivers\http.sys 2010-02-27 02:08 31,232 a——- c:\windows\system32\httpapi.dll 2010-02-27 01:31 2,048 a——- c:\windows\system32\tzres.dll 2010-02-27 01:28 523,776 a——- c:\windows\system32\RMActivate_isv.exe 2010-02-27 01:28 511,488 a——- c:\windows\system32\RMActivate.exe 2010-02-27 01:28 472,576 a——- c:\windows\system32\secproc_isv.dll 2010-02-27 01:28 472,064 a——- c:\windows\system32\secproc.dll 2010-02-27 01:28 347,136 a——- c:\windows\system32\RMActivate_ssp.exe 2010-02-27 01:28 346,624 a——- c:\windows\system32\RMActivate_ssp_isv.exe 2010-02-27 01:28 329,216 a——- c:\windows\system32\msdrm.dll 2010-02-27 01:28 151,040 a——- c:\windows\system32\secproc_ssp_isv.dll 2010-02-27 01:28 151,040 a——- c:\windows\system32\secproc_ssp.dll 2010-02-27 01:20 301,568 a——- c:\windows\system32\drivers\srv.sys 2010-02-27 01:20 98,304 a——- c:\windows\system32\drivers\srvnet.sys ==================== Find3M ==================== 2010-03-09 03:47 914 a——- c:\users\owner\appdata\roaming\wklnhst.dat 2010-02-27 04:02 143,360 a——- c:\windows\inf\infstrng.dat 2010-02-27 04:02 86,016 a——- c:\windows\inf\infstor.dat 2010-02-27 04:02 51,200 a——- c:\windows\inf\infpub.dat 2010-01-01 22:38 916,480 a——- c:\windows\system32\wininet.dll 2010-01-01 22:32 109,056 a——- c:\windows\system32\iesysprep.dll 2010-01-01 22:32 71,680 a——- c:\windows\system32\iesetup.dll 2010-01-01 20:57 133,632 a——- c:\windows\system32\ieUnatt.exe 2008-11-13 02:22 665,600 a——- c:\windows\inf\drvindex.dat 2008-01-20 18:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 04:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 04:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 04:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 04:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 01:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 01:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 01:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 01:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2010-03-12 22:16 262,144 a–sh— c:\windows\serviceprofiles\localservice\ntuser.dat 2010-03-12 22:16 2,048 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\lastalive0.dat 2010-03-12 22:16 2,048 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\lastalive1.dat 2010-03-12 22:18 262,144 a–sh— c:\windows\serviceprofiles\networkservice\ntuser.dat 2009-10-24 16:46 245,760 a–sh— c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\ietldcache\index.dat 2008-11-13 02:24 8,192 a–sh— c:\windows\users\default\NTUSER.DAT ============= FINISH: 19:27:53.49 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 1/9/2009 11:59:44 AM System Uptime: 3/12/2010 7:15:29 PM (0 hours ago) Motherboard: ECS | | Iris8 Processor: AMD Athlon™ Dual Core Processor 4450e | Socket AM2 | 2300/201mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 222 GiB total, 155.066 GiB free. D: is FIXED (NTFS) - 11 GiB total, 1.544 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318} Description: Microsoft ISATAP Adapter Device ID: ROOT\*ISATAP\0000 Manufacturer: Microsoft Name: Microsoft ISATAP Adapter PNP Device ID: ROOT\*ISATAP\0000 Service: tunnel ==== System Restore Points =================== ==== Installed Programs ====================== Acrobat.com ActiveCheck component for HP Active Support Library Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader 9.1 BufferChm Compatibility Pack for the 2007 Office system CustomerResearchQFolder CyberLink DVD Suite Deluxe D1500 D1500_Help DeviceDiscovery DeviceManagementQFolder DJ_SF_03_D1500_ProductContext DJ_SF_03_D1500_Software DJ_SF_03_D1500_Software_Min ERUNT 1.1j eSupportQFolder FinePix Studio FinePixViewer Resource FinePixViewer Ver.5.5 Google Toolbar for Internet Explorer GPBaseService Hardware Diagnostic Tools Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Customer Experience Enhancements HP Customer Participation Program 10.0 HP Demo HP Deskjet D1500 Printer Driver Software 10.0 Rel .3 HP Imaging Device Functions 10.0 HP Photosmart Essential 2.5 HP Recovery Manager RSS HP Smart Web Printing HP Solution Center 10.0 HP Update HPAsset component for HP Active Support Library HPProductAssistant HPSSupply Java™ 6 Update 7 Juno Preloader LabelPrint LightScribe System Software 1.14.25.1 LightScribe Template Labeler Malwarebytes' Anti-Malware MarketResearch Microsoft .NET Framework 3.5 SP1 Microsoft Live Search Toolbar Microsoft Office Home and Student 60 day trial Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Works Mozilla Firefox (3.6) muvee Reveal My HP Games Norton Internet Security NVIDIA Drivers OGA Notifier 2.0.0048.0 PictureMover PokerStars Power2Go PowerDirector PSSWCORE Python 2.5.2 QuickLink Mobile Realtek High Definition Audio Driver Shop for HP Supplies SmartWebPrintingOC Soft Data Fax Modem with SmartCP SolutionCenter SPORE Creature Creator Trial Edition Status Toolbox TrayApp Trend Micro Internet Security UnloadSupport Update for Microsoft .NET Framework 3.5 SP1 (KB963707) UTStarcom USB Modem Software VideoToolkit01 WebReg Yahoo! Messenger Yahoo! Toolbar ==== End Of File =========================== Malwarebytes' Anti-Malware 1.44 Database version: 3862 Windows 6.0.6001 Service Pack 1 Internet Explorer 8.0.6001.18882 3/12/2010 9:04:32 PM mbam-log-2010-03-12 (21-04-32).txt Scan type: Quick Scan Objects scanned: 102806 Time elapsed: 3 minute(s), 49 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) As always, all help is appreciated.
Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I am checking over your log , I will post back shortly with instructions.
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 24 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________



You will need to right click and choose "Run as Administrator" to run the tools we will use.


Have you tried running GMER in safe mode?
To do this,
  • Restart your computer.
  • Keep on tapping f8 when windows starts to boot. Do this before you see the windows screen.
  • When a list of menu appears, scroll to Safe Mode Option using the arrow keys then press Enter.
  • Log in with an Administrator account.
  • Run GMER again by right-clicking and choosing "Run as Administrator".
If the abaove fails, do the following:

We Need to check for Rootkits with RootRepeal
Please download RootRepeal one of these locations and save it to your desktop
Here
Here
Here
  • Right click [external image: Posted Image] then choose "Run as Administrator" on your desktop to run the tool.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check just these boxes:
  • [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:, and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.
–Next–

Are you still using Norton Internet Security?

Try looking at your desktop for a file named "defogger_disable" then post the contents of the log.

To post in your next reply:
1. GMER / RootRepeal log.
2. About Norton.
3. Defogger_disable log.
GMER: will not run ANYWHERE. I don't believe Norton is installed on here. RootRepeal: I can download the client, but it freezes right before you indicate it should prompt me to choose the drive. Also, I've gotten a FOPS DeviceIOControl Error, and Vista WILL NOT shut down. I had to run a system restore back to when I created this thread…
Hi,

Please download mbr.exe from here to your desktop.

Open NOTEPAD and copy/paste the text in the quotebox below into it:

@echo off
mbr.exe -t
start mbr.log
del %0

Save this as fix.bat Choose to "Save type as - All Files"
It should look like this: [external image: Posted Image]
Place fix.bat next to mbr.exe & then right click then choose "Run as Administrator" to run it.

Post back to tell me what it says
Hi,

Let's try this:
Please download mbr.exe and save it to your root directory, usually C:\ <- (Important!).

  • Go to Start > Run and type: cmd.exe
  • press Ok.
  • At the command prompt type: c:\mbr.exe -t >>"C:\mbr.log"
  • press Enter.
  • A "DOS" box will open and quickly disappear. That is normal.
  • A log file named mbr.log will be created and saved to the root of the system drive (usually C:\).
  • Copy and paste the results of the mbr.log in your next reply.
Hi, It's been several days. Do you still need help on this? This thread will be closed if you don't respond within 24 hours.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI