jeff matthews
Topic Starter
I just bought a hard drive like bout a month ago so i hope its not having any issues but i get a script error when i try to write information from disks to my external hard drive. It started off doing it just gradually then over time it started doing it alot more frequently. I don't know if this has to do with corrupted data that im trying to write to the disk? Or my dvd rom drive is failing maybe. Another problem i have is the windows explorer will just shut down and restart each time, during some of these error codes. At first it started doing it with just the disks, now im having an issue with "my computer" not even loading right away, so im worried, if this might be a hard ware issue or a software issue with windows. Also i want to add that my Explorer.exe service is using between 24-25 CPU resources. Could this possible be a virus? But then why would it effect my hard drives? Is it possible to transfer a virus from a disk to an external hard drive? If so i could of probably transferred a virus because some of the dvds i was writing from are really old.
Here is the error code i get.
A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.
Script: https://js2.wlxrs.com/_D/F$Live.SiteCo…torage.FF.js:39
I also tried unplugging the internet and completely turning it off and then i tried to copy and write files, still i had an issue with the computer freezing, how ever this time there was no script code. But its kind of hard to tell at this point if its a virus related issue because the script code doesn't always pop up during problems.
Also just recently the problem progressively got worse. It is not allowing me to delete any files. It just stays there on idle with the transfer bar and says "recycling" for bout an hr and im only trying to delete 4gb of data. Then when i try to stop it, it freezes. and i have to log off and log back on again.
This really seems like a virus related issue to me.
I can't even empty my recycle bin. Or even move folders to other directories, good god its limiting everything i can do on my pc.
In any case, im going to post a few logs just to get the ball rolling faster. Since ive been here before many times i know the general procedures, so im going to run some tests and post the logs for you to check out. Since DDS script and Gmer won't work on my machine at this current point in time due to Windows explorer.exe failure issues, i had to reboot into safe mode. So im running both of these logs from safe mode.
GMER LOG SCAN
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2010-12-01 22:03:54
Windows 6.1.7600
—- System - GMER 1.0.15 —-
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1DAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A062D8
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1DF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1E1A8
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 81A7D599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81AA1F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1548] USER32.dll!TrackPopupMenu 76D14B3B 5 Bytes JMP 6D205CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[1656] ntdll.dll!LdrLoadDll 7776F625 5 Bytes JMP 003B13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\volmgr \Device\HarddiskVolume12 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume13 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004a halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume9 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume10 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume11 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Registry - GMER 1.0.15 —-
Reg HKCU\Software\Microsoft\Windows Live\Companion\[removed]@94e245c0ec83584d957b6f200c75bf1c\r\n 0x65 0x9D 0x2B 0xCF …
—- EOF - GMER 1.0.15 —-
DDS script LOG
DDS (Ver_10-11-27.01) - NTFSx86 NETWORK
Run by [removed] at 22:08:31.89 on Wed 12/01/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2551.1783 [GMT -8:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Users\Jeff\Desktop\Torrents\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [PlayNC Launcher]
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [cdloader] "c:\users\jeff\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [CrossLoop] "c:\users\jeff\appdata\local\crossloop\CrossLoopConnect.exe" -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server -nosac -noprompts -minimize
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [KeePass 2 PreLoad] "c:\program files\keepass password safe 2\KeePass.exe" –preload
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: []
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
StartupFolder: c:\users\jeff\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\users\jeff\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
================= FIREFOX ===================
FF - ProfilePath - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\wu8khyid.default\
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\wu8khyid.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Extension: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\wu8khyid.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
============= SERVICES / DRIVERS ===============
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2009-5-11 154664]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-1-8 316416]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-7-22 20968]
S2 CrossLoopService;CrossLoop Service;c:\users\jeff\appdata\local\crossloop\CrossLoopService.exe [2010-7-30 560848]
S2 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2010-3-25 490280]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-7-25 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-6-7 240232]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-7-10 12672]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
S3 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-7-18 86016]
S3 PS3 Media Server;PS3 Media Server;c:\program files\ps3 media server\win32\service\wrapper.exe [2010-1-12 217088]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-7-26 27192]
S3 uvnc_service;uvnc_service;c:\users\jeff\appdata\local\crossloop\winvnc.exe [2010-7-30 1587352]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-7-10 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
=============== Created Last 30 ================
2010-12-02 05:53:59 ——– d—–w- c:\windows\pss
2010-12-02 02:15:35 6273872 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{5e04361d-7e16-4bd8-aaad-39c858666aaf}\mpengine.dll
2010-11-30 07:09:59 ——– d—–w- c:\program files\AC3Filter
2010-11-30 06:45:24 ——– d—–w- C:\Release Unicode
2010-11-30 06:45:24 ——– d—–w- C:\Release
2010-11-30 06:39:04 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2010-11-30 06:39:02 ——– d—–w- c:\program files\ffdshow
2010-11-30 06:19:26 ——– d—–w- c:\program files\TVersity Codec Pack
2010-11-30 06:19:16 ——– d—–w- c:\progra~2\TVersity
2010-11-28 02:27:34 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-11-24 10:13:08 ——– d—–w- c:\users\jeff\.dvdcss
2010-11-23 21:29:31 7680 —-a-w- c:\program files\internet explorer\iecompat.dll
2010-11-19 04:17:45 ——– d—–w- c:\progra~2\PCPitstop
2010-11-16 06:26:07 ——– d—–w- c:\users\jeff\appdata\roaming\Windows Live Writer
2010-11-16 06:26:07 ——– d—–w- c:\users\jeff\appdata\local\Windows Live Writer
2010-11-12 22:34:39 29184 —-a-r- c:\users\jeff\appdata\roaming\microsoft\installer\{21ae04e8-ebf6-40db-9aa9-b7a80c5d057d}\Icon21AE04E8.exe
2010-11-12 22:34:24 ——– d—–w- c:\program files\mkv2vob
2010-11-12 22:33:55 ——– d—–w- c:\program files\common files\Wise Installation Wizard
2010-11-10 21:16:12 165376 —-a-w- c:\windows\system32\unrar.dll
2010-11-10 21:06:31 ——– d—–w- c:\program files\Free Offers from Freeze.com
2010-11-10 20:32:15 ——– d—–w- c:\program files\CoreAVC Pro
2010-11-10 07:37:28 ——– d—–w- c:\program files\AviSynth 2.5
2010-11-10 07:06:00 ——– d—–w- c:\users\jeff\appdata\roaming\PMS
2010-11-09 20:18:18 ——– d—–w- c:\users\jeff\fontconfig
2010-11-09 20:17:15 ——– d—–w- c:\program files\PS3 Media Server
2010-11-07 09:26:51 ——– d—–w- c:\program files\AllToAVI
2010-11-07 08:50:57 ——– d—–w- c:\program files\Red Kawa
2010-11-06 19:37:34 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2010-11-06 19:37:34 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2010-11-02 06:59:52 ——– d—–w- c:\progra~2\OrbNetworks
2010-11-02 06:59:43 ——– d—–w- c:\program files\Orb Networks
==================== Find3M ====================
2010-10-19 20:51:33 222080 ——w- c:\windows\system32\MpSigStub.exe
2010-09-23 07:47:28 49016 —-a-w- c:\windows\system32\sirenacm.dll
2010-09-23 07:32:56 301936 —-a-w- c:\windows\WLXPGSS.SCR
2010-09-21 21:03:14 208768 —-a-w- c:\windows\system32\LIVESSP.DLL
2010-09-15 12:50:37 472808 —-a-w- c:\windows\system32\deployJava1.dll
2010-09-08 04:30:04 978432 —-a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28:15 44544 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22:31 386048 —-a-w- c:\windows\system32\html.iec
2010-09-08 02:48:16 1638912 —-a-w- c:\windows\system32\mshtml.tlb
============= FINISH: 22:09:21.91 ===============
There ya go.
I also wanted to add that i ran maleware bytes and it didn't locate any issues.
Another thing, is that my streaming capabilities are low. I am not sure whats causing this, i know we did have a bad modem, but i just now replaced it so its impossible at this point in time that its a bad network connection. Also i checked other computer's on the network and they all work fine. Mine is the only one that seems to having poor streaming. Now i know there are troubleshooting steps to figure out how to speed up your streaming so if you can also go over that with me, that would be helpful, thanks!
Here is the error code i get.
A script on this page may be busy, or it may have stopped responding. You can stop the script now, or you can continue to see if the script will complete.
Script: https://js2.wlxrs.com/_D/F$Live.SiteCo…torage.FF.js:39
I also tried unplugging the internet and completely turning it off and then i tried to copy and write files, still i had an issue with the computer freezing, how ever this time there was no script code. But its kind of hard to tell at this point if its a virus related issue because the script code doesn't always pop up during problems.
Also just recently the problem progressively got worse. It is not allowing me to delete any files. It just stays there on idle with the transfer bar and says "recycling" for bout an hr and im only trying to delete 4gb of data. Then when i try to stop it, it freezes. and i have to log off and log back on again.
This really seems like a virus related issue to me.
I can't even empty my recycle bin. Or even move folders to other directories, good god its limiting everything i can do on my pc.
In any case, im going to post a few logs just to get the ball rolling faster. Since ive been here before many times i know the general procedures, so im going to run some tests and post the logs for you to check out. Since DDS script and Gmer won't work on my machine at this current point in time due to Windows explorer.exe failure issues, i had to reboot into safe mode. So im running both of these logs from safe mode.
GMER LOG SCAN
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2010-12-01 22:03:54
Windows 6.1.7600
—- System - GMER 1.0.15 —-
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1DAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A062D8
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1D6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1DF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 81A1E1A8
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 81A7D599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81AA1F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1548] USER32.dll!TrackPopupMenu 76D14B3B 5 Bytes JMP 6D205CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[1656] ntdll.dll!LdrLoadDll 7776F625 5 Bytes JMP 003B13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\volmgr \Device\HarddiskVolume12 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume13 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004a halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume9 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume10 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume11 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Registry - GMER 1.0.15 —-
Reg HKCU\Software\Microsoft\Windows Live\Companion\[removed]@94e245c0ec83584d957b6f200c75bf1c\r\n 0x65 0x9D 0x2B 0xCF …
—- EOF - GMER 1.0.15 —-
DDS script LOG
DDS (Ver_10-11-27.01) - NTFSx86 NETWORK
Run by [removed] at 22:08:31.89 on Wed 12/01/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2551.1783 [GMT -8:00]
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Users\Jeff\Desktop\Torrents\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [PlayNC Launcher]
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [cdloader] "c:\users\jeff\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [CrossLoop] "c:\users\jeff\appdata\local\crossloop\CrossLoopConnect.exe" -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server -nosac -noprompts -minimize
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [KeePass 2 PreLoad] "c:\program files\keepass password safe 2\KeePass.exe" –preload
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: []
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
StartupFolder: c:\users\jeff\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\users\jeff\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
================= FIREFOX ===================
FF - ProfilePath - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\wu8khyid.default\
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\wu8khyid.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Extension: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - c:\users\jeff\appdata\roaming\mozilla\firefox\profiles\wu8khyid.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
============= SERVICES / DRIVERS ===============
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2009-5-11 154664]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-1-8 316416]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-7-22 20968]
S2 CrossLoopService;CrossLoop Service;c:\users\jeff\appdata\local\crossloop\CrossLoopService.exe [2010-7-30 560848]
S2 NAUpdate;Nero Update;c:\program files\nero\update\NASvc.exe [2010-3-25 490280]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-7-25 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-6-7 240232]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-7-10 12672]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
S3 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-7-18 86016]
S3 PS3 Media Server;PS3 Media Server;c:\program files\ps3 media server\win32\service\wrapper.exe [2010-1-12 217088]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2010-7-26 27192]
S3 uvnc_service;uvnc_service;c:\users\jeff\appdata\local\crossloop\winvnc.exe [2010-7-30 1587352]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-7-10 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
=============== Created Last 30 ================
2010-12-02 05:53:59 ——– d—–w- c:\windows\pss
2010-12-02 02:15:35 6273872 —-a-w- c:\progra~2\microsoft\microsoft antimalware\definition updates\{5e04361d-7e16-4bd8-aaad-39c858666aaf}\mpengine.dll
2010-11-30 07:09:59 ——– d—–w- c:\program files\AC3Filter
2010-11-30 06:45:24 ——– d—–w- C:\Release Unicode
2010-11-30 06:45:24 ——– d—–w- C:\Release
2010-11-30 06:39:04 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2010-11-30 06:39:02 ——– d—–w- c:\program files\ffdshow
2010-11-30 06:19:26 ——– d—–w- c:\program files\TVersity Codec Pack
2010-11-30 06:19:16 ——– d—–w- c:\progra~2\TVersity
2010-11-28 02:27:34 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-11-24 10:13:08 ——– d—–w- c:\users\jeff\.dvdcss
2010-11-23 21:29:31 7680 —-a-w- c:\program files\internet explorer\iecompat.dll
2010-11-19 04:17:45 ——– d—–w- c:\progra~2\PCPitstop
2010-11-16 06:26:07 ——– d—–w- c:\users\jeff\appdata\roaming\Windows Live Writer
2010-11-16 06:26:07 ——– d—–w- c:\users\jeff\appdata\local\Windows Live Writer
2010-11-12 22:34:39 29184 —-a-r- c:\users\jeff\appdata\roaming\microsoft\installer\{21ae04e8-ebf6-40db-9aa9-b7a80c5d057d}\Icon21AE04E8.exe
2010-11-12 22:34:24 ——– d—–w- c:\program files\mkv2vob
2010-11-12 22:33:55 ——– d—–w- c:\program files\common files\Wise Installation Wizard
2010-11-10 21:16:12 165376 —-a-w- c:\windows\system32\unrar.dll
2010-11-10 21:06:31 ——– d—–w- c:\program files\Free Offers from Freeze.com
2010-11-10 20:32:15 ——– d—–w- c:\program files\CoreAVC Pro
2010-11-10 07:37:28 ——– d—–w- c:\program files\AviSynth 2.5
2010-11-10 07:06:00 ——– d—–w- c:\users\jeff\appdata\roaming\PMS
2010-11-09 20:18:18 ——– d—–w- c:\users\jeff\fontconfig
2010-11-09 20:17:15 ——– d—–w- c:\program files\PS3 Media Server
2010-11-07 09:26:51 ——– d—–w- c:\program files\AllToAVI
2010-11-07 08:50:57 ——– d—–w- c:\program files\Red Kawa
2010-11-06 19:37:34 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2010-11-06 19:37:34 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2010-11-02 06:59:52 ——– d—–w- c:\progra~2\OrbNetworks
2010-11-02 06:59:43 ——– d—–w- c:\program files\Orb Networks
==================== Find3M ====================
2010-10-19 20:51:33 222080 ——w- c:\windows\system32\MpSigStub.exe
2010-09-23 07:47:28 49016 —-a-w- c:\windows\system32\sirenacm.dll
2010-09-23 07:32:56 301936 —-a-w- c:\windows\WLXPGSS.SCR
2010-09-21 21:03:14 208768 —-a-w- c:\windows\system32\LIVESSP.DLL
2010-09-15 12:50:37 472808 —-a-w- c:\windows\system32\deployJava1.dll
2010-09-08 04:30:04 978432 —-a-w- c:\windows\system32\wininet.dll
2010-09-08 04:28:15 44544 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-08 03:22:31 386048 —-a-w- c:\windows\system32\html.iec
2010-09-08 02:48:16 1638912 —-a-w- c:\windows\system32\mshtml.tlb
============= FINISH: 22:09:21.91 ===============
There ya go.
I also wanted to add that i ran maleware bytes and it didn't locate any issues.
Another thing, is that my streaming capabilities are low. I am not sure whats causing this, i know we did have a bad modem, but i just now replaced it so its impossible at this point in time that its a bad network connection. Also i checked other computer's on the network and they all work fine. Mine is the only one that seems to having poor streaming. Now i know there are troubleshooting steps to figure out how to speed up your streaming so if you can also go over that with me, that would be helpful, thanks!