This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

browsing problems

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok…I'm running windows xp professional, for some reason, a large number of my bookmarks (or even if I enter the site name manually) are either timing out or saying something about a dns error. This is going on with either ie or firefox. I've checked with mbam, avg antivirus, done a system restore to before the problem started. I've got other computers in the household but the primary one is the only one having this issue. Nothing really stands out in my eyes on the hijackthis logfile so I'm hoping somebody with a better eye can see what might be going on.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:35:24 AM, on 22/11/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\Net Nanny\nnsvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Net Nanny\nntray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
D:\utilities\NaturallySpeaking10\Program\natspeak.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft….k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft….k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft….k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft….k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NNTray] C:\Program Files\Net Nanny\nnstart.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "D:\utilities\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users.WINDOWS\Application Data\Nuance\NaturallySpeaking10\Ereg.ini
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\UTILIT~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\UTILIT~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft….k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi…b?1256943299296
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O18 - Protocol: intu-qt2008 - {05E53CE9-66C8-4A9E-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (file missing)
O18 - Protocol: intu-qt2009 - {03947252-2355-4E9B-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (file missing)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NNSvc - Net Nanny Software International, Inc. - C:\Program Files\Net Nanny\nnsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Audio Service (STacSV) - Unknown owner - c:\docume~1\zacr\locals~1\temp\cdm\{c173c3a9-7fe7-4717-af0b-a2c67dc36561}\STacSV.exe (file missing)

–
End of file - 8681 bytes
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

1) MBRCheck
Please download MBRCheck.exe to your desktop.

  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.

2) DDS
Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

3) GMER
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.

  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



4) What You Will Need To Post:
  • MBRCheck log
  • DDS logs
  • GMER log
ok….here are the logs…took a while because it doesn't help that my internet itself has been up and down like a yoyo over the last couple of days.

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000017c

Kernel Drivers (total 132):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E4000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F79000 ACPI.sys
0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xB9F68000 pci.sys
0xBA0A8000 isapnp.sys
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xBA0B8000 MountMgr.sys
0xB9F49000 ftdisk.sys
0xBA5AC000 dmload.sys
0xB9F23000 dmio.sys
0xBA330000 PartMgr.sys
0xBA0C8000 VolSnap.sys
0xB9F0B000 atapi.sys
0xBA0D8000 disk.sys
0xBA0E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xB9EEB000 fltMgr.sys
0xB9ED9000 sr.sys
0xB9EC2000 KSecDD.sys
0xB9EAF000 WudfPf.sys
0xB9E22000 Ntfs.sys
0xB9DF5000 NDIS.sys
0xBA0F8000 ohci1394.sys
0xBA108000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
0xB9DDB000 Mup.sys
0xBA118000 avgrkx86.sys
0xBA128000 AVGIDSxx.sys
0xBA148000 \SystemRoot\system32\DRIVERS\nic1394.sys
0xB95B6000 \SystemRoot\system32\DRIVERS\SMBios.sys
0xBA158000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xB942E000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
0xB941A000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xB93F2000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xBA428000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xB93CE000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xBA430000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xB93A7000 \SystemRoot\system32\DRIVERS\e100b325.sys
0xB9393000 \SystemRoot\system32\DRIVERS\parport.sys
0xBA168000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xBA438000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xBA178000 \SystemRoot\system32\DRIVERS\serial.sys
0xBA598000 \SystemRoot\system32\DRIVERS\serenum.sys
0xBA188000 \SystemRoot\system32\DRIVERS\imapi.sys
0xBA198000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xBA1A8000 \SystemRoot\system32\DRIVERS\redbook.sys
0xB9370000 \SystemRoot\system32\DRIVERS\ks.sys
0xBA440000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0xBA6B3000 \SystemRoot\system32\DRIVERS\audstub.sys
0xBA1B8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xBA5A0000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xB9359000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xBA1C8000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xBA1D8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xBA448000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xB9348000 \SystemRoot\system32\DRIVERS\psched.sys
0xBA1E8000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xBA450000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xBA458000 \SystemRoot\system32\DRIVERS\raspti.sys
0xB9318000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xBA1F8000 \SystemRoot\system32\DRIVERS\termdd.sys
0xBA460000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xB92FB000 \SystemRoot\system32\DRIVERS\mcdbus.sys
0xB92E3000 \SystemRoot\system32\DRIVERS\SCSIPORT.SYS
0xBA5E6000 \SystemRoot\system32\DRIVERS\swenum.sys
0xB9285000 \SystemRoot\system32\DRIVERS\update.sys
0xB9D8E000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xBA208000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA9114000 \SystemRoot\system32\drivers\sthda.sys
0xA90F0000 \SystemRoot\system32\drivers\portcls.sys
0xBA238000 \SystemRoot\system32\drivers\drmk.sys
0xBA248000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xBA5EC000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xBA5EE000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA723000 \SystemRoot\System32\Drivers\Null.SYS
0xBA5F0000 \SystemRoot\System32\Drivers\Beep.SYS
0xBA480000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xBA488000 \SystemRoot\System32\drivers\vga.sys
0xBA5F2000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xBA5F4000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xBA490000 \SystemRoot\System32\Drivers\Msfs.SYS
0xBA498000 \SystemRoot\System32\Drivers\Npfs.SYS
0xBA54C000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xA9095000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xA903C000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xA9002000 \SystemRoot\System32\Drivers\avgtdix.sys
0xA8F3C000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xBA268000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xBA4B0000 \SystemRoot\System32\Drivers\StMp3Rec.sys
0xBA278000 \SystemRoot\system32\DRIVERS\arp1394.sys
0xBA560000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xBA288000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xBA564000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xA8E8C000 \SystemRoot\system32\DRIVERS\netbt.sys
0xA8E6A000 \SystemRoot\System32\drivers\afd.sys
0xBA2A8000 \SystemRoot\system32\DRIVERS\netbios.sys
0xBA340000 \SystemRoot\System32\Drivers\SCDEmu.SYS
0xA8E3F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xBA7DF000 \SystemRoot\System32\Drivers\PQNTDrv.SYS
0xA80E7000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xBA2B8000 \SystemRoot\System32\Drivers\Fips.SYS
0xBA368000 \SystemRoot\System32\Drivers\avgmfx86.sys
0xA80A2000 \SystemRoot\System32\Drivers\avgldx86.sys
0xB95F6000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xA8062000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xBA640000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB9281000 \SystemRoot\System32\drivers\Dxapi.sys
0xBA3C0000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xBA72C000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF054000 \SystemRoot\System32\ati2cqag.dll
0xBF08E000 \SystemRoot\System32\atikvmag.dll
0xBF0C4000 \SystemRoot\System32\ati3duag.dll
0xBF32B000 \SystemRoot\System32\ativvaxx.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xA5E5E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA5D62000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys
0xB9606000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys
0xA5CA2000 \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys
0xA5A6D000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xBA654000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xA58FD000 \SystemRoot\system32\DRIVERS\srv.sys
0xBA618000 \??\C:\WINDOWS\system32\drivers\SIODRV.SYS
0xA5320000 \SystemRoot\system32\drivers\wdmaud.sys
0xA5575000 \SystemRoot\system32\drivers\sysaudio.sys
0xA4BF6000 \SystemRoot\System32\Drivers\HTTP.sys
0xA47C2000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 49):
0 System Idle Process
4 System
1312 C:\WINDOWS\system32\smss.exe
1632 csrss.exe
1708 C:\WINDOWS\system32\winlogon.exe
1768 C:\WINDOWS\system32\services.exe
1780 C:\WINDOWS\system32\lsass.exe
1992 C:\WINDOWS\system32\ati2evxx.exe
2008 C:\WINDOWS\system32\svchost.exe
228 svchost.exe
416 C:\WINDOWS\system32\svchost.exe
464 C:\WINDOWS\system32\svchost.exe
492 C:\Program Files\AVG\AVG9\avgchsvx.exe
500 C:\Program Files\AVG\AVG9\avgrsx.exe
620 C:\Program Files\AVG\AVG9\avgcsrvx.exe
796 svchost.exe
856 svchost.exe
1060 C:\WINDOWS\system32\spoolsv.exe
1112 C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
940 svchost.exe
972 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
1032 C:\Program Files\AVG\AVG9\avgwdsvc.exe
1352 C:\Program Files\Bonjour\mDNSResponder.exe
1440 C:\WINDOWS\system32\CTSVCCDA.EXE
1676 C:\Program Files\Java\jre6\bin\jqs.exe
384 C:\Program Files\Net Nanny\NNSvc.exe
1540 C:\WINDOWS\system32\IoctlSvc.exe
1864 C:\WINDOWS\system32\HPZipm12.exe
2232 C:\Program Files\AVG\AVG9\avgam.exe
2284 C:\Program Files\AVG\AVG9\avgnsx.exe
2764 C:\WINDOWS\system32\svchost.exe
2840 C:\WINDOWS\system32\searchindexer.exe
3796 alg.exe
2428 C:\Program Files\Net Nanny\nntray.exe
2732 C:\WINDOWS\system32\wscntfy.exe
4076 C:\WINDOWS\system32\ati2evxx.exe
1600 C:\WINDOWS\explorer.exe
1920 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
2864 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
2820 C:\PROGRA~1\AVG\AVG9\avgtray.exe
3864 C:\Program Files\AVG\AVG9\avgcsrvx.exe
700 C:\WINDOWS\system32\svchost.exe
3452 C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
3684 C:\Program Files\Mozilla Firefox\firefox.exe
3396 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
1644 C:\Program Files\Mozilla Firefox\plugin-container.exe
3580 C:\WINDOWS\system32\searchprotocolhost.exe
3884 searchfilterhost.exe
4020 C:\Documents and Settings\zacr\My Documents\Downloads\New Folder\MBRCheck.exe

\\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: –> \\.\PhysicalDrive1 at offset 0x00000000`007e0000 (NTFS)
\\.\E: –> \\.\PhysicalDrive2 at offset 0x00000000`00007e00 (NTFS)
\\.\I: –> \\.\PhysicalDrive3 at offset 0x00000001`384cf800 (NTFS)

PhysicalDrive0 Model Number: WDCWD600JB-00CRA1, Rev: 17.07W17
PhysicalDrive1 Model Number: WDCWD1600JD-22HBB0, Rev: 08.02D08
PhysicalDrive2 Model Number: HitachiHDS721616PLA380, Rev: P22OABEA
PhysicalDrive3 Model Number: ST9160821AS

Size Device Name MBR Status
——————————————–
55 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
149 GB \\.\PhysicalDrive1 Gateway MBR code detected
SHA1: 007DADCB3671462B53686F6996D328CFD544ABBD
149 GB \\.\PhysicalDrive2 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
149 GB \\.\PhysicalDrive3 Unknown MBR code
SHA1: 6A37CCD118436B688B51F6BD4C2B47A895EBDF7F


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!



DDS (Ver_10-11-26.01) - NTFSx86
Run by [removed] at 10:00:10.15 on 26/11/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2322 [GMT -7:00]

AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Net Nanny\nnsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Net Nanny\nntray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\zacr\My Documents\Downloads\New Folder\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [NNTray] c:\program files\net nanny\nnstart.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - d:\utilit~1\micros~1\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\utilit~1\micros~1\office11\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1256943299296
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} -
Handler: intu-qt2009 - {03947252-2355-4e9b-B446-8CCC75C43370} -
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\zacr\applic~1\mozilla\firefox\profiles\c5tway0f.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - plugin: c:\documents and settings\zacr\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\documents and settings\zacr\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npkanevapatch.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-8-4 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-8-4 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-8-4 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-8-4 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-8-4 243024]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-8-4 308136]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-8-4 5897808]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-8-4 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-8-4 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-8-4 26192]
S0 cerc6;cerc6; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-3 135664]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-10-26 517448]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2009-7-14 19720]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-3-29 137344]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-3-29 8320]

=============== Created Last 30 ================

2010-11-23 06:25:22 ——– d—–w- c:\docume~1\zacr\locals~1\applic~1\Scansoft
2010-11-22 04:16:28 ——– d—–w- c:\program files\SSBkgd Update Removal Tool
2010-11-21 21:14:15 ——– d—–w- c:\docume~1\zacr\applic~1\Nuance
2010-11-21 21:10:00 ——– d—–w- c:\docume~1\alluse~1.win\applic~1\Nuance
2010-11-21 16:38:11 ——– d—–w- c:\windows\system32\wbem\repository\FS
2010-11-21 16:38:11 ——– d—–w- c:\windows\system32\wbem\Repository
2010-11-08 05:10:51 ——– d—–w- c:\program files\MSN Messenger

==================== Find3M ====================

2010-09-18 18:23:26 974848 ——w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53:25 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53:25 954368 ——w- c:\windows\system32\mfc40.dll
2010-09-18 06:53:25 953856 ——w- c:\windows\system32\mfc40u.dll
2010-09-10 05:58:08 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:58:06 43520 ——w- c:\windows\system32\licmgr10.dll
2010-09-10 05:58:06 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51:14 285824 —-a-w- c:\windows\system32\atmfd.dll

============= FINISH: 10:01:26.28 ===============




UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-11-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 30/10/2009 3:08:36 PM
System Uptime: 26/11/2010 7:09:52 AM (3 hours ago)

Motherboard: Intel Corporation | | D945GTP
Processor: Intel® Pentium® 4 CPU 3.00GHz | LGA 775 | 3000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 56 GiB total, 21.681 GiB free.
D: is FIXED (NTFS) - 149 GiB total, 139.636 GiB free.
E: is FIXED (NTFS) - 149 GiB total, 58.489 GiB free.
F: is CDROM ()
G: is CDROM ()
I: is FIXED (NTFS) - 144 GiB total, 61.042 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: Nokia Windows Portable Device Driver
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: Nokia 6085
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd

==== System Restore Points ===================

RP79: 18/10/2010 7:52:22 PM - System Checkpoint
RP80: 20/10/2010 10:49:23 PM - System Checkpoint
RP81: 22/10/2010 6:49:26 AM - System Checkpoint
RP82: 23/10/2010 7:17:01 PM - System Checkpoint
RP83: 24/10/2010 8:30:17 AM - Install CloneDVD
RP84: 24/10/2010 8:50:10 AM - Remove CloneDVD
RP85: 25/10/2010 6:44:54 PM - System Checkpoint
RP86: 26/10/2010 9:06:06 AM - Avg Update
RP87: 26/10/2010 6:02:12 PM - Removed Intel® Desktop Utilities
RP88: 27/10/2010 10:49:17 AM - Configured Microsoft Flight Simulator X
RP89: 27/10/2010 12:15:51 PM - Removed QuickTax 2008.
RP90: 27/10/2010 12:53:49 PM - Removed QuickTax 2009.
RP91: 29/10/2010 10:53:58 PM - System Checkpoint
RP92: 30/10/2010 11:13:21 PM - System Checkpoint
RP93: 02/11/2010 7:15:27 PM - Installed TRS2006
RP94: 03/11/2010 9:30:45 PM - System Checkpoint
RP95: 05/11/2010 6:50:44 PM - System Checkpoint
RP96: 06/11/2010 11:16:51 PM - System Checkpoint
RP97: 07/11/2010 10:10:49 PM - Installed MSN Messenger 7.0
RP98: 08/11/2010 9:42:38 PM - Installed Norton PartitionMagic
RP99: 09/11/2010 9:19:30 AM - Avg Update
RP100: 09/11/2010 9:19:54 AM - Avg Update
RP101: 10/11/2010 8:23:24 PM - System Checkpoint
RP102: 10/11/2010 11:20:27 PM - Software Distribution Service 3.0
RP103: 12/11/2010 3:17:16 PM - System Checkpoint
RP104: 18/11/2010 8:11:25 AM - System Checkpoint
RP105: 19/11/2010 10:20:11 AM - System Checkpoint
RP106: 20/11/2010 11:35:31 PM - Restore Operation
RP107: 21/11/2010 3:00:21 AM - Software Distribution Service 3.0
RP108: 21/11/2010 4:58:05 AM - Avg Update
RP109: 21/11/2010 4:59:09 AM - Avg Update
RP110: 21/11/2010 9:09:00 AM - Restore Operation
RP111: 21/11/2010 9:30:36 AM - Restore Operation
RP112: 21/11/2010 2:05:35 PM - Installed Visual C++ Runtime for Dragon NaturallySpeaking.
RP113: 21/11/2010 2:09:36 PM - Installed Dragon NaturallySpeaking 10.
RP114: 23/11/2010 12:05:24 AM - System Checkpoint
RP115: 23/11/2010 8:55:58 PM - Removed Dragon NaturallySpeaking 10.
RP116: 24/11/2010 8:33:51 AM - Avg Update
RP117: 24/11/2010 8:34:31 AM - Avg Update
RP118: 25/11/2010 9:39:24 AM - System Checkpoint
RP119: 26/11/2010 9:44:05 AM - System Checkpoint

==== Installed Programs ======================

"Nero SoundTrax Help
Activision®
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2
Adobe Shockwave Player 11.5
AiO_Scan_CDA
AiOSoftwareNPI
Alberta Divorce Forms
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATI HYDRAVISION
ATI Problem Report Wizard
AVG 9.0
Bonjour
Cloudy with a Chance of Meatballs™
ClueFinders 3rd Grade Adventures
Dogz (remove only)
Driver Genius Professional Edition
Fax_CDA
Free Audio Converter version 1.2
gBurner
Ghostbusters ™: The Video Game
Google Chrome
Google Earth
Google Update Helper
HiJackThis
HijackThis 2.0.2
Hot Wheels® Stunt Track Driver 2 - GET'N DIRTY™
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Photosmart, Officejet and Deskjet 7.0.A
ImagXpress
Intel® Graphics Media Accelerator Driver
Intel® Network Connections [removed]
iTunes
Java Auto Updater
Java™ 6 Update 20
JumpStart 3rd Grade
Knight Rider
Knight Rider 2
LEGO Island 2
LEGO Star Wars II
LEGO® Batman™
LEGO® Harry Potter™: Years 1-4
LEGO® Indiana Jones™
LEGO® Indiana Jones™ 2
LEGO® Indiana Jones™ 2: The Adventure Continues
LEGO® Star Wars™: The Complete Saga
Lernout & Hauspie TruVoice American English TTS Engine
LucasArts' X-Wing
LucasArts' XvT: Flight School
Magic ISO Maker v5.4 (build 0239)
MagicDisc 2.7.106
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2416447)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Professional Edition 2003
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.7
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Web Publishing Wizard 1.52
Microsoft Windows Media Video 9 VCM
Microsoft WSE 3.0 Runtime
Microsoft XML Parser
Mozilla Firefox (3.6.12)
MSN
MSN Messenger 7.0
MSVC80_x86_v2
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nero 7 Ultra Edition
Nero BurningROM
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero CoverDesigner Help
Nero Disc Copy Gadget
Nero Disc Copy Gadget Help
Nero DiscSpeed
Nero DriveSpeed
Nero Express
Nero InfoTool
Nero Live
Nero Live Help
Nero PhotoSnap
Nero PhotoSnap Help
Nero Recode
Nero Recode Help
Nero Rescue Agent
Nero RescueAgent Help
Nero ShowTime
Nero StartSmart
Nero StartSmart Help
Nero Vision
Nero WaveEditor
Nero WaveEditor Help
NeroBurningROM
NeroExpress
neroxml
Net Nanny 5 (Remove Only)
NewCopy_CDA
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia Software Updater
Norton PartitionMagic
Norton PartitionMagic 8.0
OpenAL
PC Connectivity Solution
Photo Viewer V208G2
PowerISO
QFolder
QuickTime
Reader Rabbit 2nd Grade
Reader Rabbit Learn To Read With Phonics
Readme
Scan
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Shockwave
SoundTrax
Spelling Blaster Ages 6-9
SPIDERMAN 2 CRACKED
SpongeBob SquarePants Typing
Star Wars: Rogue Squadron™ 3D
Stunt Track Driver
System Requirements Lab for Intel
System47 Screen Saver
The Print Shop 22
Tonka Construction 2
TONKA Firefighter
TONKA Search & Rescue 2
Tonka Search and Rescue
Tonka® On the Job
Transformers™ - Revenge of the Fallen™
TRS2006
Unity Web Player
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB975364)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB898461)
Update for Windows XP (KB943729)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VCRedistSetup
Visual C++ Runtime for Dragon NaturallySpeaking
Vuze
WBFS Manager 4.0
WebFldrs XP
WebReg
Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4)
Windows Driver Package - Nokia Modem (10/05/2009 4.2)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows PowerShell™ 1.0
Windows Search 4.0
Yahoo! BrowserPlus 2.9.8
Yahoo! Messenger
ZEN V Series Media Explorer

==== End Of File ===========================



GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-11-26 13:09:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-c WDC_WD600JB-00CRA1 rev.17.07W17
Running: wz84mhtu.exe; Driver: C:\DOCUME~1\zacr\LOCALS~1\Temp\ufldapod.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA5D64670]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xA5D64720]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA5D647C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA5D64860]

—- Kernel code sections - GMER 1.0.15 —-

? C:\DOCUME~1\zacr\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 014E2690 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!send 71AB4C27 5 Bytes JMP 014E24E0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 014E47D0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 014E2850 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 014E49A0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 014E2A00 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1644] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 10405CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!sendto 71AB2F51 5 Bytes JMP 063D2690 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!send 71AB4C27 5 Bytes JMP 063D24E0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 063D47D0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 063D2850 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 063D49A0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[1920] ws2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 063D2A00 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\WINDOWS\system32\SearchIndexer.exe[2840] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!sendto 71AB2F51 5 Bytes JMP 06B02690 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!send 71AB4C27 5 Bytes JMP 06B024E0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 06B047D0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!WSASend 71AB68FA 5 Bytes JMP 06B02850 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 06B049A0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\ATI Technologies\ATI.ACE\cli.exe[3396] ws2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 06B02A00 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!sendto 71AB2F51 5 Bytes JMP 02832690 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!send 71AB4C27 5 Bytes JMP 028324E0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 028347D0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 02832850 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!WSARecvFrom 71ABF66A 5 Bytes JMP 028349A0 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3684] WS2_32.dll!WSASendTo 71AC0AAD 5 Bytes JMP 02832A00 C:\Program Files\Net Nanny\WSOCKHK.DLL (Net Nanny Winsock Hook Module/Net Nanny Software International, Inc.)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\Fastfat \Fat A45ADD20

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\games\LEGO\xae Indiana Jones\x2122 2\Audio\Audio.CFG 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\games\LEGO\xae Indiana Jones\x2122 2\Audio\_CutScenes\AkatorHub_Intro.ogg 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\games\LEGO\xae Indiana Jones\x2122 2\Audio\_Music\1_0_HUB_1Nepal_Qui.ogg 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls@E:\games\LEGO\xae Indiana Jones\x2122 2\Movies\PC\attract.bik 1

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\Temp\fbdf5c1b-2a49-4503-96da-05cc8f31fc36.tmp 0 bytes

—- EOF - GMER 1.0.15 —-
I'm not seeing anything there that could be causing the issue.

1) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

2) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

3) What You Will Need To Post:
  • MBAM log
  • ESET log
Ok….here's the mbam report….I had already had it on the system but had to reinstall because it was giving error codes and wouldn't run…even after being reinstalled it gave error codes but did run. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 5214 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 29/11/2010 5:07:02 PM mbam-log-2010-11-29 (17-07-02).txt Scan type: Quick scan Objects scanned: 186180 Time elapsed: 6 minute(s), 44 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=965e170b9ff59e44959393b08dfc5252 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-11-30 02:34:47 # local_time=2010-11-29 07:34:47 (-0700, Mountain Standard Time) # country="Canada" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 14793688 14793688 0 0 # compatibility_mode=1029 16777189 100 91 0 9216211 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=161316 # found=0 # cleaned=0 # scan_time=7263 ESETSmartInstaller@High as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=965e170b9ff59e44959393b08dfc5252 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-11-30 06:44:23 # local_time=2010-11-29 11:44:23 (-0700, Mountain Standard Time) # country="Canada" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 14807001 14807001 0 0 # compatibility_mode=1029 16777189 100 91 0 9229524 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=161354 # found=0 # cleaned=0 # scan_time=8927
I'm still not seeing anything in any of your logs. Are you still experiencing the same problems - and they're definitely only on this computer even though you have multiple computers using the same internet connection?
well, still having problems but at least the browsing problems are very intermittant….another odd symptom that I forgot to advise is that when either shutting down or restarting, I have to tell it to do that twice….the first time it seems to only refresh the desktop as if it had restarted and the second time it actually restarts.
If you don't object, I'd like you to try uninstalling NetNanny to see if it is causing the issues with the hooks it embeds in the browser.
unfortunately I have to leave netnanny in place…it's a bit of a legal requirement…I think though that it might have been less of a pc problem than an isp problem because my isp servers had been down for a couple of days last week and so far, since they've come back up, I've seemed to have less problems…not that it explains why only my primary pc seemed to be affected…I do thank you for the time looking over everything for me.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI