This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

sound problems

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the attach log. UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 3/11/2008 4:34:14 AM System Uptime: 8/5/2010 7:00:51 AM (0 hours ago) Motherboard: Intel Corporation | | DG31PR Processor: Intel® Core™2 Duo CPU E6550 @ 2.33GHz | J3E1 | 2309/1333mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 109 GiB total, 52.459 GiB free. D: is CDROM () E: is CDROM (CDFS) ==== Disabled Device Manager Items ============= Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318} Description: Logitech PS/2 Port Mouse Device ID: ACPI\PNP0F12\4&2C575ACB&0 Manufacturer: Logitech Name: Logitech PS/2 Port Mouse PNP Device ID: ACPI\PNP0F12\4&2C575ACB&0 Service: i8042prt ==== System Restore Points =================== RP1: 8/2/2010 10:56:54 PM - System Checkpoint RP2: 8/2/2010 11:34:55 PM - Installed Windows 7 Upgrade Advisor RP3: 8/3/2010 12:29:13 AM - optimize RP4: 8/5/2010 7:23:41 AM - System Checkpoint ==== Installed Programs ====================== Ad-Aware Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.2.3 Apple Application Support Apple Mobile Device Support Apple Software Update Auslogics Disk Defrag AutoUpdate avast! Free Antivirus Azureus Bejeweled 2 Deluxe 1.1 Bonjour CCleaner (remove only) CEP - Color Enable Package Creative Audio Console Creative MediaSource Creative Software AutoUpdate Creative System Information Diablo II DivX DivX Converter DivX Player DivX Web Player DKP Profiler Dragon Age: Origins Dragon Age: Origins Character Creator Dungeon Siege Dungeon Siege 2 DVD Shrink 3.2 Game Booster Google Toolbar for Internet Explorer Google Update Helper Guild Wars High Definition Audio Driver Package - KB888111 HighMAT Extension to Microsoft Windows XP CD Writing Wizard HiJackThis HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® PRO Network Connections Drivers iTunes Java Auto Updater Java™ 6 Update 20 KeyScrambler Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft DirectX 9.0 SDK Update (October 2005) Microsoft IntelliPoint 7.1 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Excel Viewer 2003 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works 7.0 Mozilla Firefox (3.0.11) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK MSXML 6.0 Parser (KB933579) Nero Suite Neverwinter Nights 2 NVIDIA Display Control Panel NVIDIA Drivers NVIDIA nView Desktop Manager NVIDIA PhysX Octoshape add-in for Adobe Flash Player PC Pitstop Optimize3 3.0 PCI Audio Driver Pinnacle Hollywood FX 4.6 Pinnacle Hollywood FX Pack - ATI FX PowerDVD QuickTime RealPlayer REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Encoder (KB954156) Security Update for Windows Media Encoder (KB979332) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953155) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Sound Blaster Audigy 2 ZS Spybot - Search & Destroy Studio 8 System Requirements Lab TeamSpeak 2 RC2 The Sims 2 The Sims 2 Nightlife The Sims 2 Open For Business The Sims 2 University Ulead VideoStudio 5.0 DV Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971180) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB976749) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Ventrilo Client VideoLAN VLC media player 0.8.4a Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP Windows 7 Upgrade Advisor Windows Defender Windows Defender Signatures Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage v1.3.0254.0 Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Messenger Windows Live Sign-in Assistant Windows Media Connect Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Format Runtime Windows Media Player 10 Windows Media Player 11 Windows Media Player 9 Hotfix [See KB885492 for more information] Windows PowerShell™ 1.0 Windows XP Service Pack 3 WinRAR archiver XviD MPEG-4 Video Codec Yahoo! Toolbar ==== Event Viewer Messages From Past Week ======== 7/31/2010 7:34:05 AM, error: Service Control Manager [7031] - The Windows Defender service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service. 7/31/2010 6:47:21 AM, error: WMPNetworkSvc [14325] - Service 'WMPNetworkSvc' did not start correctly because QueryService encountered error '0x80004002'. In Windows Media Player, turn off media sharing, and then turn it back on. 7/30/2010 6:15:01 AM, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The specified module could not be found. 7/30/2010 6:15:01 AM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 7/29/2010 12:17:00 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the WZCSVC service. 7/29/2010 12:17:00 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the PlugPlay service. 7/29/2010 12:17:00 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service. 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The WMDM PMSP Service service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The Dragon Age: Origins - Content Updater service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The Creative Service for CDROM Access service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The Creative Audio Service service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:08:10 AM, error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 7/29/2010 12:08:10 AM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. ==== End Of File ===========================
i ran out of time before i had to go to work. ran it while i was at work and i couldn't come out of hibernation. i'll run it again and get you a log. Question–you did find 3 trojans. even though we removed them, could they of damage something or changed things to give me the problems i have?
That would be hard to know for certain. Can you please describe in as much detail as possible the outstanding issues, plus any error messages you might be receiving
here is the gmer log.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-05 17:59:13
Windows 5.1.2600 Service Pack 3
Running: jn2o6ncm.exe; Driver: C:\DOCUME~1\randy\LOCALS~1\Temp\pxldipoc.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB4278CD2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB4278B8E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xB4279142]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB427906C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB4278764]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB4278C68]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB42786A4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB4278708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB4278D88]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xB4279210]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB4278D48]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB4278EC8]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB4285B9C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB42859C0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB4285AFA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP B4285AFE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB38E 7 Bytes JMP B42859C4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC502 5 Bytes JMP B42815B4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2F86 5 Bytes JMP B4282F6C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP B4285BA0 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6BC43A0, 0x592C35, 0xE8000020]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- EOF - GMER 1.0.15 —-
here is the gmer log.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-05 17:59:13
Windows 5.1.2600 Service Pack 3
Running: jn2o6ncm.exe; Driver: C:\DOCUME~1\randy\LOCALS~1\Temp\pxldipoc.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB4278CD2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB4278B8E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xB4279142]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB427906C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB4278764]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB4278C68]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB42786A4]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB4278708]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB4278D88]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xB4279210]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB4278D48]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB4278EC8]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xB4285B9C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xB42859C0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xB4285AFA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

PAGE ntkrnlpa.exe!ZwLoadDriver 8058413A 7 Bytes JMP B4285AFE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!NtCreateSection 805AB38E 7 Bytes JMP B42859C4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC502 5 Bytes JMP B42815B4 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2F86 5 Bytes JMP B4282F6C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1134 7 Bytes JMP B4285BA0 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6BC43A0, 0x592C35, 0xE8000020]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- EOF - GMER 1.0.15 —-
ok, i'll try. but first, alittle about me. i'm not a computer tech guy. i don't understand alot of programs, so if i can't use it straight out of the box, there is a good chance i won't use it. i don't download music or movies or burn things on a cd. i play a video game once in awhile to pass the time away. the only thing i've done recently, like in the last couple months are these. fried my video card and had a computer store install it with updated drivers. downloaded iTunes for something until i saw it cost money so if i use that at all, it's for the internet radio it has. and now with these problems, since sound was one of them, i downloaded new sound card drivers. that's about all i can remember as far as what i've done with my computer. now the problems.

1. sound. i was playing diablo one night after i got the new video card. i got kicked to desktop and there was a window open telling me avast had new software for me to download. since it asked me to start but it hadn't started by itself, i thought i'd wait until i got done to install it. about 5 minutes later i lost ingame sound. as soon as that happened, the first thing that came to mind was this new video card was hot and fried my old sound card. but later found out that couldn't of happened cause the new card is like 3 slots away from my sound card. there is to much space inbetween them for it to of gotten hot. so i logged out of the game and thought i'd download this new avast program while i surfed the web for a new sound card. during the search, i found a link from microsoft and it was a guide for troubleshooting sound problems. when i went there i found out it was a program i could run to test my sound. i did that and when it got done it told me it had found the problem. it said my sound had been muted and asked me if it wanted me to let it fix it. i clicked yes, but by then the avast had finished and asked me to restart my computer. i clicked yes again. i got sound back so i wasn't worried. but then in diablo again i lost sound again. so i did a search and found a link and it talked about my drivers could be old and updating them could fix sound issues. i did that but i still have sound issues. about 99% of the time, restarting my computer will let me get sound back. sometimes i can go for days without losing sound but i remember one day i lost sound a few times. sometimes if i lose sound in diablo, i still have sound with iTunes. there have even been sometimes i get sound back but my headphones won't work. so everything with the sound issue has been to inconsistant for me to believe my sound card is going bad and how it could of been a virus. p.s. i never get a warning or error with the sound problem. it's like at anytime, someone turns a switch and i lose sound.

2. IE tab. the other problem i've noticed but wasn't to worried about at the time was the tab at the top of the browser window. every now and then but not always i might go to a web page, it looks like it's loading but just taking alittle longer than normal, then all of a sudden i notice a bubble coming from the tab. it doen't stay long so i have troubles reading the whole thing. and since it doesn't happen on every web page, i'm never ready to sit and read it. but it says something like IE had troubles loading the webpage and IE reset itself. i've never had this problem before but i've noticed it just recently. like in the last couple months. so that is why i thought the 2 problems could be related.

3. popup bar. and it wasn't until now that i've had trouble clicking on the bar that appears at the top of the screen when my browser stops popups and the webpage wants me to download or install something. i've gotten that bar before and never have had a problem. if i click on it now, it wants to load the screen but i get this msg in the new window that opens up.

Internet Explorer has closed this webpage to help protect your computer
A malfunctioning or malicious add-on has caused Internet Explorer to close this webpage.

and here is the link to pc pitstops overdrive program i finally got to run. http://www.pcpitstop.com/betapit/sec.asp?conid=23776138
it doesn't say much, but it also didn't find anything either for waht it can do.

but i can say that my computer isn't running good for the little i do with it. i used to play WoW so i needed my computer to be in top running order. running 25 man raids, loading web pages on the fly to read about things very quickly. i was one of the few that never really had any problems. well, that's about it. i hope you can understand what i wrote and i'm hoping you can find something you might of missed the first time around.
OK

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
hello catbyte, something i forgot to mention, not sure if it is important but when i went to pc pitstop and couldn't run their program, i made a post at their website forums. one of their techs commented on me running IE 7 and 8 and mentioned that could be causeimg my IE to act funny. i called a tech at my town and asked if IE had a fix button like a few programs do if you go to the add and remove programs under the control panel. he told me it doesn't, but if i remove IE8, it will go back to 7 on it's own and then it will want to update it's self. i did that thinking it would take care of itself. i'm not sure if any of this is important but i wanted to let you know.
here is the combofix log.

ComboFix 10-08-05.06 - randy 08/06/2010 6:22.4.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2045.1492 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2010-07-06 to 2010-08-06 )))))))))))))))))))))))))))))))
.

2010-08-03 05:04 . 2009-11-11 22:23 27744 —-a-w- c:\windows\system32\drivers\point32.sys
2010-08-03 05:04 . 2010-08-03 05:04 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-08-03 04:35 . 2010-08-03 04:35 ——– d—–w- c:\windows\Performance
2010-08-03 04:35 . 2010-08-03 04:35 ——– d—–w- c:\documents and settings\randy\Local Settings\Application Data\Microsoft Corporation
2010-08-03 04:34 . 2010-08-03 04:34 ——– d—–w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2010-08-03 00:00 . 2010-08-03 00:01 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-08-03 00:00 . 2010-08-03 00:00 ——– d—–w- c:\program files\PCPitstop
2010-08-01 02:27 . 2010-08-01 02:27 ——– d—–w- c:\program files\iPod
2010-08-01 02:27 . 2010-08-01 02:28 ——– d—–w- c:\program files\iTunes
2010-08-01 02:21 . 2010-08-01 02:21 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-31 12:05 . 2010-07-31 12:05 ——– d—–w- c:\documents and settings\randy\Application Data\Auslogics
2010-07-31 12:05 . 2010-07-31 12:05 ——– d—–w- c:\program files\Auslogics
2010-07-25 23:36 . 2010-07-25 23:36 388096 —-a-r- c:\documents and settings\randy\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-17 04:52 . 2010-07-17 04:52 ——– d—–w- c:\program files\Bonjour
2010-07-14 14:38 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-11 03:11 . 2010-08-01 04:48 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2010-07-11 02:54 . 2010-07-11 02:54 ——– d—–w- c:\documents and settings\randy\Application Data\Uniblue
2010-07-11 02:47 . 2010-07-11 02:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Creative
2010-07-11 02:45 . 2010-07-11 02:45 ——– d—–w- c:\program files\Common Files\Creative Labs Shared
2010-07-11 02:17 . 2010-07-11 02:17 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-10 02:47 . 2010-07-10 02:47 ——– d—–w- c:\documents and settings\randy\Application Data\ElevatedDiagnostics
2010-07-10 02:36 . 2010-06-28 20:57 38848 —-a-w- c:\windows\avastSS.scr
2010-07-10 02:35 . 2010-07-10 02:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-10 01:43 . 2010-07-10 01:43 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-06 03:38 . 2006-02-25 23:17 ——– d—–w- c:\program files\Diablo II
2010-08-03 16:26 . 2005-12-06 01:45 61160 -c–a-w- c:\documents and settings\randy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-03 00:00 . 2009-03-23 20:46 ——– d—–w- c:\program files\KeyScrambler
2010-08-01 04:49 . 2005-12-06 03:04 ——– d—–w- c:\program files\Google
2010-08-01 02:27 . 2010-05-13 00:16 ——– d—–w- c:\program files\Common Files\Apple
2010-07-11 02:47 . 2005-12-06 04:24 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-11 02:44 . 2007-08-08 17:42 109144 —-a-w- c:\windows\system32\OpenAL32.dll
2010-07-11 02:44 . 2005-12-08 17:12 445016 —-a-w- c:\windows\system32\wrap_oal.dll
2010-07-10 02:52 . 2005-12-06 03:06 ——– d—–w- c:\program files\Alwil Software
2010-06-28 20:57 . 2005-12-06 03:06 165032 —-a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2005-12-06 03:06 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2008-04-05 05:14 165456 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2005-12-06 03:06 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2005-12-06 03:06 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2005-12-06 03:06 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2008-04-05 05:14 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2005-12-06 03:06 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-25 23:51 . 2010-06-25 19:16 217180 —-a-w- c:\windows\system32\nvdrsdb0.bin
2010-06-25 23:51 . 2010-06-25 19:16 1 —-a-w- c:\windows\system32\nvdrssel.bin
2010-06-25 23:50 . 2010-06-25 19:16 217180 —-a-w- c:\windows\system32\nvdrsdb1.bin
2010-06-25 19:18 . 2010-06-25 19:16 ——– d—–w- c:\program files\NVIDIA Corporation
2010-06-25 19:17 . 2007-11-14 21:56 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-06-25 19:16 . 2010-06-25 19:16 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-06-21 02:00 . 2010-06-21 02:00 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-06-21 01:49 . 2009-07-06 22:43 ——– d—–w- c:\program files\IObit
2010-06-21 01:03 . 2005-12-08 23:41 ——– d—–w- c:\documents and settings\randy\Application Data\Azureus
2010-06-21 01:03 . 2005-12-08 23:40 ——– d—–w- c:\program files\Azureus
2010-06-21 01:03 . 2005-12-06 15:44 ——– d—–w- c:\program files\Microsoft Works
2010-06-21 01:02 . 2009-07-08 04:32 ——– d—–w- c:\documents and settings\randy\Application Data\IObit
2010-06-21 00:22 . 2008-04-30 17:27 ——– d—–w- c:\documents and settings\randy\Application Data\Move Networks
2010-06-15 02:15 . 2010-06-15 02:15 503808 —-a-w- c:\documents and settings\randy\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4dd1fe77-n\msvcp71.dll
2010-06-15 02:15 . 2010-06-15 02:15 499712 —-a-w- c:\documents and settings\randy\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4dd1fe77-n\jmc.dll
2010-06-15 02:15 . 2010-06-15 02:15 348160 —-a-w- c:\documents and settings\randy\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-4dd1fe77-n\msvcr71.dll
2010-06-15 02:15 . 2010-06-15 02:15 61440 —-a-w- c:\documents and settings\randy\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-36399cdf-n\decora-sse.dll
2010-06-15 02:15 . 2010-06-15 02:15 12800 —-a-w- c:\documents and settings\randy\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-36399cdf-n\decora-d3d.dll
2010-06-15 02:15 . 2010-01-29 03:41 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-06-14 14:31 . 2005-12-05 23:42 744448 —-a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-07 22:34 . 2010-06-07 22:34 81920 —-a-w- c:\windows\system32\nvwddi.dll
2010-06-07 22:34 . 2010-06-07 22:34 277608 —-a-w- c:\windows\system32\nvmccs.dll
2010-06-07 22:34 . 2010-06-07 22:34 13902440 —-a-w- c:\windows\system32\nvcpl.dll
2010-06-07 22:34 . 2010-06-07 22:34 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-06-07 22:34 . 2010-06-07 22:34 154728 —-a-w- c:\windows\system32\nvsvc32.exe
2010-05-28 17:58 . 2008-11-12 23:52 600680 —-a-w- c:\windows\system32\NVUNINST.EXE
2010-05-21 19:14 . 2009-10-04 07:39 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-18 21:35 . 2010-05-18 21:35 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 21:35 . 2010-05-18 21:35 107808 —-a-w- c:\windows\system32\dns-sd.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-03-09 524632]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-06-07 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-06-07 13902440]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"CTHelper"="CTHELPER.EXE" [2010-03-19 19456]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-11 1468256]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"KeyScrambler"="c:\program files\KeyScrambler\getting_started.html" [X]
"SetDefaultMIDI"="MIDIDEF.EXE" [2010-03-18 28672]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^randy^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
backup=c:\windows\pss\LimeWire On Startup.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^randy^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk]
backup=c:\windows\pss\Yahoo! Widget Engine.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-17 06:24 40368 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer]
2002-01-28 08:16 1228800 —-a-r- c:\windows\mixer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
2003-06-18 06:00 45056 -c–a-w- c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
2010-03-19 00:17 19456 —-a-w- c:\windows\system32\CtHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2003-09-17 15:43 57344 -c–a-w- c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
2006-08-11 19:56 18944 —-a-w- c:\windows\system32\CTXFIHLP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CtxfiReg]
2006-08-11 19:53 42496 —-a-w- c:\windows\system32\CTXFIREG.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-07-21 20:53 141608 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 17:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 02:53 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2009-07-10 01:34 214536 —-a-w- c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteCenter]
2003-10-08 21:35 139264 -c–a-w- c:\program files\Creative\MediaSource\RemoteControl\RcMan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
2002-12-03 23:06 45056 —-a-w- c:\program files\Creative\SB Drive Det\SBDrvDet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefaultMIDI]
2010-03-18 23:59 28672 —-a-w- c:\windows\system32\MIDIDEF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2006-07-21 08:14 86016 ——r- c:\windows\SoundMan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-05-23 14:00 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-07-10 01:34 198160 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 06:00 90112 —-a-w- c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 —-a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-19 02:05 204288 -c–a-w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege\\DungeonSiege.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\bin_ship\\DAOCharacterCreator.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6881:UDP"= 6881:UDP:azure
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/24/2009 10:36 PM 64160]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/5/2008 12:14 AM 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/5/2008 12:14 AM 17744]
R2 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [11/6/2009 6:57 PM 25832]
R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\pfmodnt.sys [3/18/2010 8:50 PM 15960]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [3/18/2010 8:39 PM 99416]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [3/18/2010 8:39 PM 555096]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [3/18/2010 8:39 PM 566360]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [3/23/2009 3:46 PM 115312]
S2 gupdate1ca00fe6b472bc0;Google Update Service (gupdate1ca00fe6b472bc0);c:\program files\Google\Update\GoogleUpdate.exe [7/9/2009 8:33 PM 133104]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 autorun;autorun;\??\c:\huadio.tmp –> c:\huadio.tmp [?]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [3/18/2010 8:39 PM 99416]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [7/10/2010 9:45 PM 79360]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [3/18/2010 8:39 PM 555096]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [3/18/2010 8:39 PM 100952]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [3/18/2010 8:39 PM 100952]
S3 ctgame;Game Port;c:\windows\system32\drivers\CTGAME.SYS [3/18/2010 8:40 PM 18904]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [3/18/2010 8:39 PM 566360]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 1029456]
S3 mapmem_dv;mapmem_dv;\??\c:\mapmem.tmp –> c:\mapmem.tmp [?]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [8/2/2010 7:00 PM 90352]
.
Contents of the 'Scheduled Tasks' folder

2010-08-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 04:37]

2010-08-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50]

2010-08-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-10 01:33]

2010-08-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-10 01:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://m.www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: aol.com\free
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\randy\Application Data\Mozilla\Firefox\Profiles\irv0rv16.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - IObit
FF - prefs.js: browser.startup.homepage - hxxp://m.www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://results.myway.com/GGmain.jhtml?id=YH&ptb=2A9B95B0-0089-486E-835B-1B502F5B189A&psa=&ind=2010071015&ptnrS=YH&si=&st=kwd&n=&searchfor=
FF - component: c:\documents and settings\randy\Application Data\Mozilla\Firefox\Profiles\irv0rv16.default\extensions\[removed]\components\KeyScramblerIE.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
HKCU-Run-SmartRAM - c:\program files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
AddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\randy\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-06 06:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\autorun]
"ImagePath"="\??\c:\huadio.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\mapmem_dv]
"ImagePath"="\??\c:\mapmem.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1715567821-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1715567821-1682526488-682003330-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:b2,e5,5b,f2,8c,bd,14,79,74,52,16,92,88,82,b0,b8,f8,18,88,d9,71,29,56,
ad,db,ba,82,ed,72,21,fe,7e,fc,1d,ff,b2,3d,87,7f,2b,1f,83,c2,d7,30,b1,8a,52,\
"??"=hex:e7,68,e5,df,53,bf,57,68,59,05,b8,ed,12,45,f6,75
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(336)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-06 06:29:08
ComboFix-quarantined-files.txt 2010-08-06 11:29

Pre-Run: 56,279,564,288 bytes free
Post-Run: 56,343,355,392 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 27DF8AE31949EAF0AFFA6090838021D9
Hi

I don't see any signs of malware in the logs, there are a couple of drivers with no files that we can delete, but that wouldn't cause your issues.

Please do the following:

On your keyboard, press the Windows logo key and the letter R to bring up the Run command box

Copy/paste the following bolded text into the Run box and click OK

sc delete autorun

Now repeat for the following:

sc delete mapmem_dv


Reboot the machine.


Your remaining issues appear to be hardware problems.

I suggest starting a new thread in our hardware forum outlining the issues as you did in your previous post.

Link back to this topic so they can see what we have done,

the tech's will be able to pinpoint the issues for you I'm sure.


Please delete the DDS and GMER logs from your desktop.

Press the Winkey + R to open a runbox, type in

ComboFix /uninstall to clean up combofix.


good luck

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI