This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer is very slow and applications hang

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

My computer applications are all running very slowly, taking a very long time to launch, including IE and firefox. Have done a scanning with my Norton Antivirus with the latest updates but the results come back perfectly fine. Recently, some applications are not working.

Can you advise and assist please?

Thanks


OTL.TXT
OTL logfile created on: 3/6/2011 2:05:08 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:Documents and SettingsOwnerDesktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 466.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 37.24 Gb Total Space | 18.85 Gb Free Space | 50.62% Space Free | Partition Type: NTFS

Computer Name: EVELYN | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:Documents and SettingsOwnerDesktopOTL.exe (OldTimer Tools)
PRC - C:Program FilesNorton AntiVirusEngine18.5.0.125ccsvchst.exe (Symantec Corporation)
PRC - C:Program FilesFunshion OnlineFunshionFunshionService.exe (Funshion Online Technologies Ltd.)
PRC - C:Program FilesCommon FilesJavaJava Updatejucheck.exe (Sun Microsystems, Inc.)
PRC - C:Program FilesSamsungSamsung New PC StudioNPSAgent.exe (Samsung Electronics Co., Ltd.)
PRC - C:WINDOWSsystem32FsUsbExService.Exe (Teruten)
PRC - C:Program FilesLogitechQuickCamQuickcam.exe ()
PRC - C:Program FilesCommon FilesLogiShrdLQCVFXCOCIManager.exe ()
PRC - C:Program FilesCommon FilesLogiShrdLVMVFMLVPrcSrv.exe (Logitech Inc.)
PRC - C:WINDOWSexplorer.exe (Microsoft Corporation)
PRC - C:Program FilesCommon FilesAheadLibNMIndexStoreSvr.exe (Nero AG)
PRC - C:Program FilesCommon FilesAheadLibNMBgMonitor.exe (Nero AG)
PRC - C:Program FilesBelkinUSB F5D7050Wireless UtilityBelkinwcui.exe (Belkin Corporation)
PRC - C:Program FilesNETGEARWG111v2 Configuration UtilityRtlWake.exe ()


========== Modules (SafeList) ==========

MOD - C:Documents and SettingsOwnerDesktopOTL.exe (OldTimer Tools)
MOD - C:WINDOWSWinSxSx86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – File not found
SRV - (NAV) – C:Program FilesNorton AntiVirusEngine18.5.0.125ccSvcHst.exe (Symantec Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) – C:Program FilesMicrosoft OfficeOffice14GROOVE.EXE (Microsoft Corporation)
SRV - (FsUsbExService) – C:WINDOWSsystem32FsUsbExService.Exe (Teruten)
SRV - (LVPrcSrv) – C:Program FilesCommon FilesLogiShrdLVMVFMLVPrcSrv.exe (Logitech Inc.)
SRV - (ServiceLayer) – C:Program FilesPC Connectivity SolutionServiceLayer.exe (Nokia.)


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:Documents and SettingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NAV_18.1.0.37DefinitionsBASHDefs20110225.002BHDrvx86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:Documents and SettingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NAV_18.1.0.37DefinitionsVirusDefs20110305.002NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:Program FilesCommon FilesSymantec SharedEENGINEeeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:Program FilesCommon FilesSymantec SharedEENGINEEraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:Documents and SettingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NAV_18.1.0.37DefinitionsVirusDefs20110305.002NAVENG.SYS (Symantec Corporation)
DRV - (SymEvent) – C:WINDOWSsystem32driversSYMEVENT.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:WINDOWSSystem32DriversNAV1205000.07DSYMTDI.SYS (Symantec Corporation)
DRV - (SRTSP) – C:WINDOWSSystem32DriversNAV1205000.07DSRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:WINDOWSsystem32driversNAV1205000.07DSRTSPX.SYS (Symantec Corporation)
DRV - (SymEFA) – C:WINDOWSsystem32driversNAV1205000.07DSYMEFA.SYS (Symantec Corporation)
DRV - (SymIRON) – C:WINDOWSsystem32driversNAV1205000.07DIronx86.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:Documents and SettingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NAV_18.1.0.37DefinitionsIPSDefs20110303.001IDSXpx86.sys (Symantec Corporation)
DRV - (SymDS) – C:WINDOWSsystem32driversNAV1205000.07DSYMDS.SYS (Symantec Corporation)
DRV - (fssfltr) – C:WINDOWSsystem32driversfssfltr_tdi.sys (Microsoft Corporation)
DRV - (FsUsbExDisk) – C:WINDOWSsystem32FsUsbExDisk.Sys ()
DRV - (LVUSBSta) – C:WINDOWSsystem32driversLVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) – C:WINDOWSsystem32driverslvrs.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:WINDOWSsystem32driversLV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) – C:WINDOWSsystem32driverslv302af.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:WINDOWSsystem32driversLVPr2Mon.sys ()
DRV - (sscdmdm) – C:WINDOWSsystem32driverssscdmdm.sys (MCCI Corporation)
DRV - (sscdmdfl) – C:WINDOWSsystem32driverssscdmdfl.sys (MCCI Corporation)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:WINDOWSsystem32driverssscdbus.sys (MCCI Corporation)
DRV - (pccsmcfd) – C:WINDOWSsystem32driverspccsmcfd.sys (Nokia)
DRV - (RTLWUSB) – C:WINDOWSsystem32driverswg111v2.sys (NETGEAR Inc.)
DRV - (BLKWGU(Belkin)) Belkin Wireless G USB Network Adapter(Belkin) – C:WINDOWSsystem32driversBLKWGU.sys (Belkin Corporation)
DRV - (ZDPSp50) – C:WINDOWSsystem32driversZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (OMCI) – C:WINDOWSSYSTEM32DRIVERSOMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = %SystemRoot%system32blank.htm
IE - HKLMSOFTWAREMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.google.com/ie

IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Search Page = http://www.google.com
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.facebook.com/
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..network.proxy.type: 0

FF - HKLMsoftwaremozillaFirefoxextensions{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:Documents and SettingsAll UsersApplication DataNorton{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NAV_18.1.0.37IPSFFPlgn [2011/02/03 23:27:30 | 000,000,000 | —D | M]
FF - HKLMsoftwaremozillaMozilla Firefox 3.6.13extensionsComponents: C:Program FilesMozilla Firefoxcomponents [2011/02/12 17:14:43 | 000,000,000 | —D | M]
FF - HKLMsoftwaremozillaMozilla Firefox 3.6.13extensionsPlugins: C:Program FilesMozilla Firefoxplugins [2011/02/12 17:14:27 | 000,000,000 | —D | M]

[2011/02/12 17:15:00 | 000,000,000 | —D | M] (No name found) – C:Documents and SettingsOwnerApplication DataMozillaExtensions
[2011/03/05 14:09:03 | 000,000,000 | —D | M] (No name found) – C:Documents and SettingsOwnerApplication DataMozillaFirefoxProfiless8kbgyqa.defaultextensions
[2011/02/19 15:39:16 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:Documents and SettingsOwnerApplication DataMozillaFirefoxProfiless8kbgyqa.defaultextensions{20a82645-c095-46ed-80e3-08825760534b}
[2011/02/12 17:14:28 | 000,000,000 | —D | M] (No name found) – C:Program FilesMozilla Firefoxextensions
[2011/02/03 23:27:30 | 000,000,000 | —D | M] (Norton IPS) – C:DOCUMENTS AND SETTINGSALL USERSAPPLICATION DATANORTON{0C55C096-0F1D-4F28-AAA2-85EF591126E7}NAV_18.1.0.37IPSFFPLGN
[2009/02/07 19:42:13 | 000,000,000 | —D | M] (Java Quick Starter) – C:PROGRAM FILESJAVAJRE6LIBDEPLOYJQSFF

O1 HOSTS File: ([2003/07/17 04:29:34 | 000,000,734 | —- | M]) - C:WINDOWSsystem32driversetchosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:Program FilesNorton AntiVirusEngine18.5.0.125ipsipsbho.dll (Symantec Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.6.6209.1142swg.dll (Google Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:Program FilesMicrosoft OfficeOffice14URLREDIR.DLL (Microsoft Corporation)
O3 - HKCU..ToolbarShellBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU..ToolbarWebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..Run: [BCSSync] C:Program FilesMicrosoft OfficeOffice14BCSSync.exe (Microsoft Corporation)
O4 - HKLM..Run: [IMJPMIG8.1] C:WINDOWSIMEimjp8_1IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..Run: [LogitechQuickCamRibbon] C:Program FilesLogitechQuickCamQuickcam.exe ()
O4 - HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe (Nero AG)
O4 - HKLM..Run: [NPSStartup] File not found
O4 - HKLM..Run: [PHIME2002A] C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..Run: [PHIME2002ASync] C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE (Microsoft Corporation)
O4 - HKCU..Run: [AutoStartNPSAgent] C:Program FilesSamsungSamsung New PC StudioNPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:Program FilesCommon FilesAheadLibNMBgMonitor.exe (Nero AG)
O4 - HKCU..Run: [iKu] C:Program FilesYouKuiKuiKu.exe (优酷网)
O4 - Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupBelkin Wireless USB Utility.lnk = C:Program FilesBelkinUSB F5D7050Wireless UtilityBelkinwcui.exe (Belkin Corporation)
O4 - Startup: C:Documents and SettingsAll UsersStart MenuProgramsStartupWG111v2 Smart Wizard Wireless Setting.lnk = C:Program FilesNETGEARWG111v2 Configuration UtilityRtlWake.exe ()
O4 - Startup: C:Documents and SettingsOwnerStart MenuProgramsStartupFunshion.lnk = C:Program FilesFunshion OnlineFunshionFunshion.exe (Funshion Online Technologies Ltd.)
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: HonorAutoRunSetting = 1
O7 - HKCUSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:Program FilesMicrosoft OfficeOffice14EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:Program FilesMicrosoft OfficeOffice14ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:Program FilesMicrosoft OfficeOffice14ONBttnIELinkedNotes.dll (Microsoft Corporation)
O15 - HKCU..Trusted Domains: facebook.com ([www] http in Trusted sites)
O15 - HKCU..Trusted Domains: facebook.com ([www] https in Trusted sites)
O15 - HKCU..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {49EDFB5E-40A6-4364-937E-933611E372CE} http://gsm.gmarket.com.sg/ActiveX/egg_install_v24.cab (EggEditor 1.0 for GMarket)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1233999915903 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C945E31A-102E-4A0D-8854-D599D7AED5FA} http://gsm.gmarket.com.sg/GSM_new/ActiveX/vsflex8.cab (ComponentOne FlexGrid 8.0 (OLEDB))
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {EB26F8CC-42CE-4E81-9765-F50B0D8C7913} http://gsm.gmarket.com.sg/GMKT.SGGSM.Web/A…GGmarketGsm.cab (SGGmarketGsm Control)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 192.168.1.254
O20 - AppInit_DLLs: (C:PROGRA~1GoogleGOOGLE~1GOEC62~1.DLL) - C:Program FilesGoogleGoogle Desktop SearchGoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:WINDOWSexplorer.exe (Microsoft Corporation)
O20 - WinlogonNotifyigfxcui: DllName - igfxsrvc.dll - C:WINDOWSSystem32igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:Documents and SettingsOwnerLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O24 - Desktop BackupWallPaper: C:Documents and SettingsOwnerLocal SettingsApplication DataMicrosoftWallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:Program FilesMicrosoft OfficeOffice14GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/07 17:11:07 | 000,000,000 | —- | M] () - C:AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2{32b1dcce-f4fb-11dd-a6ec-cfd8140f5cc4}ShellAutoRuncommand - "" = E:wdsync.exe
O33 - MountPoints2{3998a256-155c-11e0-a8f4-001150b259dc}Shell - "" = AutoRun
O33 - MountPoints2{3998a256-155c-11e0-a8f4-001150b259dc}ShellAutoRun - "" = Auto&Play;
O33 - MountPoints2{3998a256-155c-11e0-a8f4-001150b259dc}ShellAutoRuncommand - "" = C:WINDOWSsystem32RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .RECYCLERS-5-3-42-2819952290-8240758988-879315005-3665jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2{3d03141f-2c28-11e0-a8ff-001150b259dc}Shell - "" = AutoRun
O33 - MountPoints2{3d03141f-2c28-11e0-a8ff-001150b259dc}ShellAutoRun - "" = Auto&Play;
O33 - MountPoints2{3d03141f-2c28-11e0-a8ff-001150b259dc}ShellAutoRuncommand - "" = C:WINDOWSsystem32RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .RECYCLERS-5-3-42-2819952290-8240758988-879315005-3665jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2{f777e304-12de-11de-a70b-001150b259dc}Shell - "" = AutoRun
O33 - MountPoints2{f777e304-12de-11de-a70b-001150b259dc}ShellAutoRun - "" = Auto&Play;
O33 - MountPoints2{f777e304-12de-11de-a70b-001150b259dc}ShellAutoRuncommand - "" = I:Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM..comfile [open] – "%1" %*
O35 - HKLM..exefile [open] – "%1" %*
O37 - HKLM…com [@ = comfile] – "%1" %*
O37 - HKLM…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: gijqdvgix - File not found

Drivers32: msacm.iac2 - C:WINDOWSSystem32iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:WINDOWSsystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:WINDOWSSystem32sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:WINDOWSSystem32tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:WINDOWSSystem32vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:WINDOWSSystem32vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:WINDOWSSystem32iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:WINDOWSSystem32lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv32 - C:WINDOWSSystem32ir32_32.dll ()
Drivers32: vidc.iv41 - C:WINDOWSSystem32ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:WINDOWSSystem32ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/06 14:03:27 | 000,581,120 | —- | C] (OldTimer Tools) – C:Documents and SettingsOwnerDesktopOTL.exe
[2011/03/06 13:38:49 | 000,000,000 | —D | C] – C:WINDOWSLastGood
[2011/03/05 16:44:23 | 000,000,000 | —D | C] – C:Documents and SettingsOwnerDesktopuss 040311
[2011/02/12 17:14:41 | 000,000,000 | —D | C] – C:Documents and SettingsOwnerLocal SettingsApplication DataMozilla
[2011/02/12 17:14:41 | 000,000,000 | —D | C] – C:Documents and SettingsOwnerApplication DataMozilla
[2011/02/12 17:14:29 | 000,000,000 | —D | C] – C:Documents and SettingsAll UsersStart MenuProgramsMozilla Firefox
[2011/02/12 17:14:25 | 000,000,000 | —D | C] – C:Program FilesMozilla Firefox
[8 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]
[3 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/06 14:03:37 | 000,581,120 | —- | M] (OldTimer Tools) – C:Documents and SettingsOwnerDesktopOTL.exe
[2011/03/06 13:39:02 | 000,000,886 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskMachineUA.job
[2011/03/06 13:36:54 | 000,002,834 | —- | M] () – C:Documents and SettingsOwnerfunshion.ini
[2011/03/06 13:34:48 | 000,000,882 | —- | M] () – C:WINDOWStasksGoogleUpdateTaskMachineCore.job
[2011/03/06 13:34:00 | 000,002,048 | –S- | M] () – C:WINDOWSbootstat.dat
[2011/03/05 15:51:34 | 000,000,069 | —- | M] () – C:WINDOWSNeroDigital.ini
[2011/03/05 15:41:16 | 000,139,264 | —- | M] () – C:WINDOWSSystem32TDCFileShlCtxt.dll
[2011/03/05 15:41:16 | 000,098,304 | —- | M] () – C:WINDOWSSystem32TDCFileIconDisplay.dll
[2011/03/05 13:55:21 | 000,002,206 | —- | M] () – C:WINDOWSSystem32wpa.dbl
[2011/02/28 12:07:09 | 000,000,162 | —- | M] () – C:Documents and SettingsOwnerdefault.pls
[2011/02/24 20:19:52 | 000,006,335 | —- | M] () – C:Documents and SettingsOwnerDesktopAudio1.nra
[2011/02/19 17:04:20 | 000,041,472 | —- | M] () – C:Documents and SettingsOwnerLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/19 16:50:13 | 000,000,151 | —- | M] () – C:WINDOWSPhotoSnapViewer.INI
[2011/02/12 17:14:45 | 000,000,000 | —- | M] () – C:WINDOWSnsreg.dat
[2011/02/12 17:14:30 | 000,001,620 | —- | M] () – C:Documents and SettingsOwnerApplication DataMicrosoftInternet ExplorerQuick LaunchMozilla Firefox.lnk
[2011/02/12 17:14:30 | 000,001,602 | —- | M] () – C:Documents and SettingsAll UsersDesktopMozilla Firefox.lnk
[2011/02/12 17:05:31 | 000,274,968 | —- | M] () – C:WINDOWSSystem32FNTCACHE.DAT
[2011/02/12 14:22:04 | 000,001,374 | —- | M] () – C:WINDOWSimsins.BAK
[8 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]
[3 C:WINDOWSSystem32*.tmp files -> C:WINDOWSSystem32*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/02/26 02:18:35 | 000,006,335 | —- | C] () – C:Documents and SettingsOwnerDesktopAudio1.nra
[2011/02/19 16:53:14 | 733,280,256 | —- | C] () – C:Documents and SettingsOwnerDesktoptimky-blackswan-dvdscr.avi
[2011/02/12 17:14:45 | 000,000,000 | —- | C] () – C:WINDOWSnsreg.dat
[2011/02/12 17:14:30 | 000,001,620 | —- | C] () – C:Documents and SettingsOwnerApplication DataMicrosoftInternet ExplorerQuick LaunchMozilla Firefox.lnk
[2011/02/12 17:14:30 | 000,001,602 | —- | C] () – C:Documents and SettingsAll UsersDesktopMozilla Firefox.lnk
[2010/07/02 19:32:02 | 000,110,592 | —- | C] () – C:WINDOWSSystem32FsUsbExDevice.Dll
[2010/07/02 19:32:01 | 000,036,608 | —- | C] () – C:WINDOWSSystem32FsUsbExDisk.Sys
[2010/07/02 19:30:41 | 000,002,528 | —- | C] () – C:Documents and SettingsOwnerApplication Data$_hpcst$.hpc
[2010/01/28 18:15:14 | 000,001,186 | —- | C] () – C:WINDOWSSystem32funshion.ini
[2009/10/19 17:38:38 | 000,000,056 | -H– | C] () – C:WINDOWSSystem32ezsidmv.dat
[2009/04/18 22:41:08 | 000,041,472 | —- | C] () – C:Documents and SettingsOwnerLocal SettingsApplication DataDCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/17 18:33:11 | 000,196,608 | —- | C] () – C:WINDOWSSystem32TDCOMG12_DLL.dll
[2009/03/17 18:33:11 | 000,139,264 | —- | C] () – C:WINDOWSSystem32TDCFileShlCtxt.dll
[2009/03/17 18:33:11 | 000,098,304 | —- | C] () – C:WINDOWSSystem32TDCFileIconDisplay.dll
[2009/03/01 00:14:10 | 000,000,151 | —- | C] () – C:WINDOWSPhotoSnapViewer.INI
[2009/02/26 23:04:18 | 000,000,069 | —- | C] () – C:WINDOWSNeroDigital.ini
[2009/02/08 00:57:39 | 000,004,161 | —- | C] () – C:WINDOWSODBCINST.INI
[2009/02/08 00:56:43 | 000,274,968 | —- | C] () – C:WINDOWSSystem32FNTCACHE.DAT
[2009/02/07 20:29:31 | 000,000,376 | —- | C] () – C:WINDOWSODBC.INI
[2009/02/07 19:58:36 | 000,081,110 | —- | C] () – C:WINDOWSSystem32lvcoinst.ini
[2009/02/07 18:00:29 | 000,004,569 | —- | C] () – C:WINDOWSSystem32secupd.dat
[2009/02/07 17:15:40 | 000,002,048 | –S- | C] () – C:WINDOWSbootstat.dat
[2009/02/07 17:09:01 | 000,021,640 | —- | C] () – C:WINDOWSSystem32emptyregdb.dat
[2008/12/16 21:58:54 | 000,025,624 | —- | C] () – C:WINDOWSSystem32driversLVPr2Mon.sys
[2008/12/16 21:50:56 | 000,013,584 | —- | C] () – C:WINDOWSSystem32driversiKeyLgFT.dll
[2007/10/25 17:26:10 | 000,005,632 | —- | C] () – C:WINDOWSSystem32driversStarOpen.sys
[2005/07/12 14:44:42 | 000,015,872 | —- | C] () – C:WINDOWSSystem32InsDrvZD64.DLL
[2004/03/23 16:38:00 | 000,028,672 | —- | C] () – C:WINDOWSSystem32InsDrvZD.dll
[2003/07/17 04:54:55 | 000,004,594 | —- | C] () – C:WINDOWSSystem32oembios.dat
[2003/07/17 04:54:54 | 013,107,200 | —- | C] () – C:WINDOWSSystem32oembios.bin
[2003/07/17 04:41:25 | 000,435,592 | —- | C] () – C:WINDOWSSystem32perfh009.dat
[2003/07/17 04:41:25 | 000,272,128 | —- | C] () – C:WINDOWSSystem32perfi009.dat
[2003/07/17 04:41:23 | 000,028,626 | —- | C] () – C:WINDOWSSystem32perfd009.dat
[2003/07/17 04:41:21 | 000,068,504 | —- | C] () – C:WINDOWSSystem32perfc009.dat
[2003/07/17 04:39:07 | 000,000,741 | —- | C] () – C:WINDOWSSystem32noise.dat
[2003/07/17 04:33:50 | 000,673,088 | —- | C] () – C:WINDOWSSystem32mlang.dat
[2003/07/17 04:33:39 | 000,046,258 | —- | C] () – C:WINDOWSSystem32mib.bin
[2003/07/17 04:27:41 | 000,218,003 | —- | C] () – C:WINDOWSSystem32dssec.dat
[2003/07/17 04:26:37 | 000,001,804 | —- | C] () – C:WINDOWSSystem32dcache.bin
[2003/03/14 12:24:00 | 000,024,576 | —- | C] () – C:WINDOWSSystem32ZyDelReg.exe

========== LOP Check ==========

[2010/02/28 21:10:24 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataNCH Swift Sound
[2010/07/02 19:44:04 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataPC Suite
[2010/10/23 22:48:09 | 000,000,000 | —D | M] – C:Documents and SettingsAll UsersApplication DataPCSettings
[2010/02/28 21:08:49 | 000,000,000 | —D | M] – C:Documents and SettingsOwnerApplication DataNCH Swift Sound
[2010/07/02 19:43:58 | 000,000,000 | —D | M] – C:Documents and SettingsOwnerApplication DataPC Suite
[2010/07/02 19:30:19 | 000,000,000 | —D | M] – C:Documents and SettingsOwnerApplication DataSamsung
[2010/02/28 21:09:58 | 000,000,282 | —- | M] () – C:WINDOWSTaskswavepadSevenDays.job
[2010/03/03 21:09:02 | 000,000,282 | —- | M] () – C:WINDOWSTaskswavepadShakeIcon.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%*.* >
[2009/02/07 17:11:07 | 000,000,000 | —- | M] () – C:AUTOEXEC.BAT
[2010/06/03 23:26:37 | 000,000,211 | RHS- | M] () – C:boot.ini
[2009/02/07 17:11:07 | 000,000,000 | —- | M] () – C:CONFIG.SYS
[2009/02/07 17:11:07 | 000,000,000 | RHS- | M] () – C:IO.SYS
[2010/02/23 21:53:22 | 000,014,182 | —- | M] () – C:MP4debug.log
[2009/02/07 17:11:07 | 000,000,000 | RHS- | M] () – C:MSDOS.SYS
[2009/02/07 18:09:34 | 000,047,564 | RHS- | M] () – C:NTDETECT.COM
[2010/12/09 20:44:33 | 000,250,048 | RHS- | M] () – C:ntldr
[2011/03/06 13:33:56 | 1610,612,736 | -HS- | M] () – C:pagefile.sys
[2009/02/26 23:03:02 | 000,000,389 | —- | M] () – C:Shortcut to The KMPlayer.lnk
[2009/02/07 20:18:37 | 000,000,268 | -H– | M] () – C:sqmdata00.sqm
[2009/02/07 20:32:52 | 000,000,268 | -H– | M] () – C:sqmdata01.sqm
[2009/02/07 20:35:14 | 000,000,268 | -H– | M] () – C:sqmdata02.sqm
[2009/04/18 01:19:01 | 000,000,268 | -H– | M] () – C:sqmdata03.sqm
[2009/02/07 20:18:37 | 000,000,244 | -H– | M] () – C:sqmnoopt00.sqm
[2009/02/07 20:32:52 | 000,000,244 | -H– | M] () – C:sqmnoopt01.sqm
[2009/02/07 20:35:14 | 000,000,244 | -H– | M] () – C:sqmnoopt02.sqm
[2009/04/18 01:19:01 | 000,000,244 | -H– | M] () – C:sqmnoopt03.sqm

< %systemroot%Fonts*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:WINDOWSFontsGlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:WINDOWSFontsGlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:WINDOWSFontsGlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:WINDOWSFontsGlobalUserInterface.CompositeFont

< %systemroot%Fonts*.dll >

< %systemroot%Fonts*.ini >
[2009/02/07 17:10:48 | 000,000,067 | -HS- | M] () – C:WINDOWSFontsdesktop.ini

< %systemroot%Fonts*.ini2 >

< %systemroot%Fonts*.exe >

< %systemroot%system32spoolprtprocsw32x86*.* >
[2008/07/06 20:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86mdippr.dll
[2008/07/06 18:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:WINDOWSsystem32spoolprtprocsw32x86printfilterpipelinesvc.exe

< %systemroot%REPAIR*.bak1 >

< %systemroot%REPAIR*.ini >

< %systemroot%system32*.jpg >

< %systemroot%*.jpg >

< %systemroot%*.png >

< %systemroot%*.scr >
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:WINDOWSWLXPGSS.SCR
[8 C:WINDOWS*.tmp files -> C:WINDOWS*.tmp -> ]

< %systemroot%*._sy >

< %APPDATA%AdobeUpdate*.* >

< %ALLUSERSPROFILE%Favorites*.* >

< %APPDATA%Microsoft*.* >
[2009/08/31 20:57:53 | 000,001,618 | -H– | M] () – C:Documents and SettingsOwnerApplication DataMicrosoftLastFlashConfig.WFC

< %PROGRAMFILES%*.* >

< %APPDATA%Update*.* >

< %systemroot%*. /mp /s >

< %systemroot%System32config*.sav >
[2009/02/08 00:56:03 | 000,094,208 | —- | M] () – C:WINDOWSsystem32configdefault.sav
[2009/02/08 00:56:03 | 000,602,112 | —- | M] () – C:WINDOWSsystem32configsoftware.sav
[2009/02/08 00:56:03 | 000,401,408 | —- | M] () – C:WINDOWSsystem32configsystem.sav

< %PROGRAMFILES%bak. /s >

< %systemroot%system32bak. /s >

< %ALLUSERSPROFILE%Start Menu*.lnk /x >
[2010/12/09 20:52:42 | 000,000,272 | -HS- | M] () – C:Documents and SettingsAll UsersStart Menudesktop.ini

< %systemroot%system32configsystemprofile*.dat /x >

< %systemroot%*.config >

< %systemroot%system32*.db >

< %PROGRAMFILES%Internet Explorer*.dat >

< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2009/02/07 18:20:07 | 000,000,177 | -HS- | M] () – C:Documents and SettingsOwnerApplication DataMicrosoftInternet ExplorerQuick Launchdesktop.ini
[2009/02/07 17:17:11 | 000,000,079 | —- | M] () – C:Documents and SettingsOwnerApplication DataMicrosoftInternet ExplorerQuick LaunchShow Desktop.scf

< %USERPROFILE%Desktop*.exe >
[2010/02/18 14:49:39 | 046,389,696 | —- | M] (Online Media Technologies Ltd. ) – C:Documents and SettingsOwnerDesktopAVSVideoConverter.exe
[2010/02/18 13:44:52 | 004,021,720 | —- | M] (Funshion Online Technologies Ltd.) – C:Documents and SettingsOwnerDesktopFunshionInstall2.1.0.16Beta.exe
[2009/03/12 18:37:45 | 004,430,568 | —- | M] () – C:Documents and SettingsOwnerDesktopiku_setup.exe
[2011/03/06 14:03:37 | 000,581,120 | —- | M] (OldTimer Tools) – C:Documents and SettingsOwnerDesktopOTL.exe

< %PROGRAMFILES%Common Files*.* >

< %systemroot%*.src >

< %systemroot%install*.* >

< %systemroot%system32DLL*.* >

< %systemroot%system32HelpFiles*.* >

< %systemroot%system32rundll*.* >

< %systemroot%winn32*.* >

< %systemroot%Java*.* >

< %systemroot%system32test*.* >

< %systemroot%system32Rundll32*.* >

< %systemroot%AppPatchCustom*.* >

< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >

< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstallLastSuccessTime: 2011-02-19 09:38:39

========== Files - Unicode (All) ==========
[2010/11/23 23:20:36 | 000,000,000 | —D | M](C:Documents and SettingsOwnerDesktop????7:?????????(?)) – C:Documents and SettingsOwnerDesktop哈利波特7:哈利波特与死亡圣器(上)
[2010/11/23 22:57:20 | 000,000,000 | —D | C](C:Documents and SettingsOwnerDesktop????7:?????????(?)) – C:Documents and SettingsOwnerDesktop哈利波特7:哈利波特与死亡圣器(上)

< End of report >

EXTRAS.TXT

OTL Extras logfile created on: 3/6/2011 2:05:08 PM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:Documents and SettingsOwnerDesktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 466.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 37.24 Gb Total Space | 18.85 Gb Free Space | 50.62% Space Free | Partition Type: NTFS

Computer Name: EVELYN | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:Program FilesMicrosoft OfficeOffice14msohtmed.exe" /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"4661:TCP" = 4661:TCP:*:Enabled:kkchdp

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileAuthorizedApplicationsList]
"C:Program FilesMSN Messengerlivecall.exe" = C:Program FilesMSN Messengerlivecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileAuthorizedApplicationsList]
"C:Program FilesMSN Messengerlivecall.exe" = C:Program FilesMSN Messengerlivecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:Program FilesSkypePlugin ManagerskypePM.exe" = C:Program FilesSkypePlugin ManagerskypePM.exe:*:Enabled:Skype Extras Manager
"C:Program FilesFunshion OnlineFunshionFunshionService.exe" = C:Program FilesFunshion OnlineFunshionFunshionService.exe:*:Enabled:FunshionService – (Funshion Online Technologies Ltd.)
"C:Program FilesSamsungSamsung New PC Studionpsasvr.exe" = C:Program FilesSamsungSamsung New PC Studionpsasvr.exe:*:Enabled:KTF MUSIC AoD Server – (PeeringPortal)
"C:Program FilesSamsungSamsung New PC Studionpsvsvr.exe" = C:Program FilesSamsungSamsung New PC Studionpsvsvr.exe:*:Enabled:KTF MUSIC VoD Server – (PeeringPortal)
"C:Program FilesFunshion OnlineFunshionFunshionUpgrade.exe" = C:Program FilesFunshion OnlineFunshionFunshionUpgrade.exe:*:Enabled:FunshionUpgrade – (Funshion Online Technologies Ltd.)
"C:Program FilesMicrosoft OfficeOffice14GROOVE.EXE" = C:Program FilesMicrosoft OfficeOffice14GROOVE.EXE:*:Enabled:Microsoft SharePoint Workspace – (Microsoft Corporation)
"C:Program FilesMicrosoft OfficeOffice14ONENOTE.EXE" = C:Program FilesMicrosoft OfficeOffice14ONENOTE.EXE:*:Enabled:Microsoft OneNote – (Microsoft Corporation)
"C:Program FilesMicrosoft OfficeOffice14OUTLOOK.EXE" = C:Program FilesMicrosoft OfficeOffice14OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook – (Microsoft Corporation)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 23
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{49EDFB5E-40A6-4364-937E-933611E372CE}" = EggEditor_gmarket
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{66EBD70F-A42C-475F-AEDF-277378151033}" = Nero 7 Essentials
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7E84FAC8-C518-40F9-9807-7455301D6D25}" = SamsungConnectivityCableDriver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-0010-0409-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (English) 14
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{937B232D-9776-471E-92BD-D424E514EF14}" = Logitech QuickCam
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A6359CCF-215D-43D9-8366-479D231F2A72}" = Belkin Wireless USB Utility
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC599724-5755-48C1-ABE7-ABB857652930}" = PC Connectivity Solution
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{D8CE69B0-9274-4b8c-BA49-0FF6A20A3C65}" = SAMSUNG SYMBIAN USB Download Driver
"{D92FF8EB-BD77-40AE-B68B-A6BFC6F8661D}" = Windows Live Family Safety
"{E0F252A6-DE85-4E93-A93B-DFC3537B3965}" = WG111v2 Configuration Utility
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F" = Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0)
"6194C28A8F62DD817EA1B918E6E46E806A21B452" = Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
"65B6FE5418CE28F4D72543FB2D964C3CEC83F161" = Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Funshion" = Funshion
"Google Desktop" = Google Desktop
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"iKu" = ÓÅ¿á i¿á
"InstallShield_{A6359CCF-215D-43D9-8366-479D231F2A72}" = Belkin Wireless USB Utility
"InstallShield_{AF7E85DC-317C-47F5-810E-B82EE093A612}" = Samsung New PC Studio USB Driver Installer
"InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}" = Samsung New PC Studio
"lvdrivers_11.90" = Logitech QuickCam Driver Package
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NAV" = Norton AntiVirus
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Prism" = Prism Video Converter
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile Modem Device" = Samsung Mobile Modem Device Software
"Samsung Mobile phone USB driver" = Samsung Mobile phone USB driver Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"SAMSUNG USB Mobile Device" = SAMSUNG USB Mobile Device Software
"Switch" = Switch Sound File Converter
"WavePad" = WavePad Sound Editor
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/20/2010 10:47:27 PM | Computer Name = EVELYN | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 14.0.8089.726, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/20/2010 10:48:28 PM | Computer Name = EVELYN | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 14.0.8089.726, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/20/2010 10:50:06 PM | Computer Name = EVELYN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/20/2010 10:50:12 PM | Computer Name = EVELYN | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 14.0.8089.726, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/20/2010 10:50:12 PM | Computer Name = EVELYN | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 14.0.8089.726, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 11/20/2010 10:50:36 PM | Computer Name = EVELYN | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.17055, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/25/2010 8:00:40 PM | Computer Name = EVELYN | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 14.0.8089.726, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 12/25/2010 8:00:46 PM | Computer Name = EVELYN | Source = Application Hang | ID = 1002
Description = Hanging application msnmsgr.exe, version 14.0.8089.726, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 1/30/2011 3:44:37 AM | Computer Name = EVELYN | Source = Application Error | ID = 1000
Description = Faulting application kmplayer.exe, version 2.9.3.1214, faulting module
ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.

Error - 2/4/2011 3:15:58 PM | Computer Name = EVELYN | Source = MSN Explorer Error Reporting | ID = 1000
Description =

[ System Events ]
Error - 2/3/2011 11:40:34 AM | Computer Name = EVELYN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 2/3/2011 11:40:39 AM | Computer Name = EVELYN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service wuauserv with
arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

Error - 3/5/2011 3:29:22 AM | Computer Name = EVELYN | Source = atapi | ID = 262153
Description = The device, DeviceIdeIdePort1, did not respond within the timeout
period.

Error - 3/5/2011 3:29:34 AM | Computer Name = EVELYN | Source = atapi | ID = 262153
Description = The device, DeviceIdeIdePort1, did not respond within the timeout
period.

Error - 3/5/2011 3:30:01 AM | Computer Name = EVELYN | Source = atapi | ID = 262153
Description = The device, DeviceIdeIdePort1, did not respond within the timeout
period.

Error - 3/5/2011 3:30:43 AM | Computer Name = EVELYN | Source = atapi | ID = 262153
Description = The device, DeviceIdeIdePort1, did not respond within the timeout
period.

Error - 3/5/2011 3:41:17 AM | Computer Name = EVELYN | Source = atapi | ID = 262153
Description = The device, DeviceIdeIdePort1, did not respond within the timeout
period.

Error - 3/5/2011 3:41:42 AM | Computer Name = EVELYN | Source = atapi | ID = 262153
Description = The device, DeviceIdeIdePort1, did not respond within the timeout
period.

Error - 3/5/2011 3:41:47 AM | Computer Name = EVELYN | Source = atapi | ID = 262153
Description = The device, DeviceIdeIdePort1, did not respond within the timeout
period.

Error - 3/5/2011 3:43:00 AM | Computer Name = EVELYN | Source = atapi | ID = 262153
Description = The device, DeviceIdeIdePort1, did not respond within the timeout
period.


< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, angelc

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
Hello there,

Recently, some applications are not working.

Can you tell me what applications are not working as intended?

===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Hi Conspire, Below are my findings:- 10 My Nero PhotoSnap Viewer Essentials used to be working but now it is no longer working but i can open my JPEG file using Window live Photo Gallery 2) My Mozilla Firefox, IE & microsoft applications take longer time to launch. 3) When i try double click gmer and i click run, a blue screen appear with error message saying A problem has been detected and windows has been shut down to prevent damage to your computer. BAD_POOL_HEADER Technical information: ***stop : 0x00000019 (0x00000020, 0x85A81420, 0x85A81C48, 0x1B050062) Thanks…
Hi,

Your Nero not working as in it crashed when opened? Did you try reinstalling before?

I need you to try and check only both "Sections" and "C:\" ; leaving all others unchecked.

If that fails, please try to run it in Safe Mode and again with the same settings as above.

Reboot your computer in Safe Mode
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Tutorial if you need it How to boot into Safemode
Ok, we will try different tools this time. Please perform this in normal mode.

Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.
    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
Hi Conspire, Below is the findings in the report. Thanks. RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #1 ============================================== >Drivers ============================================== 0xECFD3000 C:\WINDOWS\system32\DRIVERS\LV302V32.SYS 2682880 bytes (Logitech Inc., Logitech QuickCam Driver) 0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2192768 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2192768 bytes 0x804D7000 RAW 2192768 bytes 0x804D7000 WMIxWDM 2192768 bytes 0xBF800000 Win32k 1855488 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xED6B3000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110306.002\NAVEX15.SYS 1355776 bytes (Symantec Corporation, AV Engine) 0xED2ED000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110225.002\BHDrvx86.sys 815104 bytes (Symantec Corporation, BASH Driver) 0xBF05E000 C:\WINDOWS\System32\ialmdd5.DLL 765952 bytes (Intel Corporation, DirectDraw® Driver for Intel® Graphics Technology) 0xECF19000 C:\WINDOWS\system32\DRIVERS\lvrs.sys 761856 bytes (Logitech Inc., Logitech Kernel Audio Improvement Filter Driver) 0xF71D5000 C:\WINDOWS\System32\DRIVERS\ialmnt5.sys 684032 bytes (Intel Corporation, Intel Graphics Miniport Driver) 0xF73D3000 SYMEFA.SYS 671744 bytes 0xF7094000 C:\WINDOWS\system32\drivers\smwdm.sys 581632 bytes (Analog Devices, Inc., SoundMAX Integrated Digital Audio ) 0xF731C000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xED848000 C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SRTSP.SYS 544768 bytes (Symantec Corporation, Symantec AutoProtect) 0xED455000 C:\WINDOWS\System32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xEB773000 C:\WINDOWS\System32\DRIVERS\BLKWGU.sys 405504 bytes (Belkin Corporation, Belkin Wireless G USB Network Adapter Driver) 0xED3D1000 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 385024 bytes (Symantec Corporation, Symantec Eraser Control Driver) 0xF5D52000 C:\WINDOWS\System32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xED592000 C:\WINDOWS\System32\Drivers\NAV\1205000.07D\SYMTDI.SYS 364544 bytes (Symantec Corporation, Network Dispatch Driver) 0xED5EB000 C:\WINDOWS\System32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xED53A000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110303.001\IDSxpx86.sys 360448 bytes (Symantec Corporation, IDS Core Driver) 0xEC9E3000 C:\WINDOWS\System32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver) 0xF7489000 SYMDS.SYS 356352 bytes 0xBF119000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xEC1B7000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xF7548000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xECB2B000 C:\WINDOWS\System32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xF72EF000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xEB748000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xED4C5000 C:\WINDOWS\System32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xED512000 C:\WINDOWS\System32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xED42F000 C:\WINDOWS\System32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xED7FE000 C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 155648 bytes (Symantec Corporation, Symantec Event Library) 0xED824000 C:\WINDOWS\system32\drivers\NAV\1205000.07D\Ironx86.SYS 147456 bytes (Symantec Corporation, Iron Driver) 0xF7070000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xF7159000 C:\WINDOWS\System32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xF7122000 C:\WINDOWS\System32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xED4F0000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x806EF000 ACPI_HAL 131840 bytes 0x806EF000 C:\WINDOWS\system32\hal.dll 131840 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xF74E0000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xF7518000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xBF03F000 C:\WINDOWS\System32\ialmdev5.DLL 126976 bytes (Intel Corporation, Component GHAL Driver) 0xBF020000 C:\WINDOWS\System32\ialmdnt5.dll 126976 bytes (Intel Corporation, Controller Hub for Intel Graphics Driver) 0xED3B4000 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 118784 bytes (Symantec Corporation, Symantec Eraser Utility Driver) 0xF72D5000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xF7500000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xECE61000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xF73BC000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xF5DD9000 C:\WINDOWS\System32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xEC596000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xED69F000 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110306.002\NAVENG.SYS 81920 bytes (Symantec Corporation, AV Engine) 0xF7145000 C:\WINDOWS\System32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xF71C1000 C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xED644000 C:\WINDOWS\System32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xF73A9000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xF7477000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xECC98000 C:\WINDOWS\system32\DRIVERS\EAPPkt.sys 69632 bytes (Windows ® 2000 DDK provider, NDIS User mode I/O Driver) 0xF7537000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xF5DC8000 C:\WINDOWS\System32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xF7727000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xF76C7000 C:\WINDOWS\System32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xF76A7000 C:\WINDOWS\System32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xF76F7000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xF76D7000 C:\WINDOWS\System32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xEC91B000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xED95D000 C:\WINDOWS\system32\drivers\usbaudio.sys 61440 bytes (Microsoft Corporation, USB Audio Class Driver) 0xF77F7000 C:\WINDOWS\System32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xBF012000 C:\WINDOWS\System32\ialmrnt5.dll 57344 bytes (Intel Corporation, Controller Hub for Intel Graphics Driver) 0xF75D7000 C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xF7777000 C:\WINDOWS\System32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF75B7000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xECD89000 C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys 49152 bytes (Microsoft Corporation, Family Safety Filter Driver (TDI)) 0xF7797000 C:\WINDOWS\System32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF7647000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xF76B7000 C:\WINDOWS\System32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xF75A7000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xF7787000 C:\WINDOWS\System32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xF75F7000 C:\WINDOWS\system32\drivers\NAV\1205000.07D\SRTSPX.SYS 45056 bytes (Symantec Corporation, Symantec AutoProtect) 0xF7597000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xF77C7000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xF77B7000 C:\WINDOWS\System32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xF75C7000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xEC94B000 C:\WINDOWS\system32\FsUsbExDisk.SYS 36864 bytes 0xF7757000 C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xF7697000 C:\WINDOWS\System32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xF7767000 C:\WINDOWS\system32\drivers\LVUSBSta.sys 36864 bytes (Logitech Inc., USB Statistic Driver) 0xF77A7000 C:\WINDOWS\System32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xF7617000 C:\WINDOWS\System32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xEBC3F000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xF7657000 C:\WINDOWS\System32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xF7987000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xF799F000 C:\WINDOWS\System32\DRIVERS\usbccgp.sys 32768 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver) 0xF78CF000 C:\WINDOWS\System32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xF78D7000 C:\WINDOWS\System32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xF796F000 C:\WINDOWS\System32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xF7817000 C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xF7907000 C:\WINDOWS\System32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xF790F000 C:\WINDOWS\System32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xF78C7000 C:\WINDOWS\System32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xF7977000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xF792F000 C:\WINDOWS\System32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xF7997000 C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys 20480 bytes (-, -) 0xF797F000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xF781F000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xF78EF000 C:\WINDOWS\System32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xF78F7000 C:\WINDOWS\System32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xF78E7000 C:\WINDOWS\System32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xF7867000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xF7887000 C:\WINDOWS\System32\Drivers\ZDPSp50.sys 20480 bytes (Printing Communications Assoc., Inc. (PCAUSA), PCAUSA NDIS 5.0 SPR Protocol Driver) 0xED67B000 C:\WINDOWS\System32\DRIVERS\kbdhid.sys 16384 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xF729C000 C:\WINDOWS\System32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xECD99000 C:\WINDOWS\System32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xF5A11000 C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS 16384 bytes (Dell Computer Corporation, OMCI Device Driver) 0xF7A7F000 C:\WINDOWS\System32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xF79A7000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xF7A63000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xF59F1000 C:\WINDOWS\System32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xED69B000 C:\WINDOWS\System32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xF7A8B000 C:\WINDOWS\System32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xF7A77000 C:\WINDOWS\System32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xF7AE7000 C:\WINDOWS\system32\drivers\aeaudio.sys 8192 bytes (Andrea Electronics Corporation, Andrea Audio Stub Driver) 0xF7B53000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xF7AAF000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xF7B51000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xF7A97000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xF7A9B000 C:\WINDOWS\system32\DRIVERS\lv302af.sys 8192 bytes (Logitech Inc., Audio filter for Express Plus) 0xF7B55000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xF7ABD000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xF7B57000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xF7AFD000 C:\WINDOWS\System32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xF7B09000 C:\WINDOWS\System32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xF7A99000 C:\WINDOWS\System32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xF7BAB000 C:\WINDOWS\System32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xF7C2B000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xF7BD0000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xF7B5F000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ============================================== 0xED269600 Unknown thread object [ ETHREAD 0x86B5B870 ] , 600 bytes 0xED2682A0 Unknown thread object [ ETHREAD 0x86C3D678 ] , 600 bytes 0xED266D20 Unknown thread object [ ETHREAD 0x86B8A940 ] , 600 bytes !!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)
Hi,

Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


    **********************************************
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Conspire, When I try to run the Combofix.exe, it scanned till stage 50 and I saw the same blue screen again with error message saying A problem has been detected and windows has been shut down to prevent damage to your computer. BAD_POOL_HEADER I restarted my pc and try to run Combofix.exe again, same thing happen. Kindly advise. Thanks.
Let's see if we can rule out hardware problem.

Download BlueScreenView (in Zip file)
No installation required.
Unzip downloaded file and double click on BlueScreenView.exe file to run the program.
When scanning is done, go Edit>Select All.
Go File>Save Selected Items, and save the report as BSOD.txt.
Open BSOD.txt in Notepad, copy all content, and paste it into your next reply.
Hi Conspire, Here is my findings:- Thanks. ================================================== Dump File : Mini030911-02.dmp Crash Time : 3/9/2011 11:46:19 PM Bug Check String : BAD_POOL_HEADER Bug Check Code : 0x00000019 Parameter 1 : 0x00000020 Parameter 2 : 0x86ea2478 Parameter 3 : 0x86ea2890 Parameter 4 : 0x1a830035 Caused By Driver : Ntfs.sys Caused By Address : Ntfs.sys+800 File Description : NT File System Driver Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 5.1.2600.5512 (xpsp.080413-2111) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini030911-02.dmp Processors Count : 1 Major Version : 15 Minor Version : 2600 Dump File Size : 94,208 ================================================== ================================================== Dump File : Mini030911-01.dmp Crash Time : 3/9/2011 11:29:32 PM Bug Check String : BAD_POOL_HEADER Bug Check Code : 0x00000019 Parameter 1 : 0x00000020 Parameter 2 : 0x850f2000 Parameter 3 : 0x850f2418 Parameter 4 : 0x1a830000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+5c846 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini030911-01.dmp Processors Count : 1 Major Version : 15 Minor Version : 2600 Dump File Size : 94,208 ================================================== ================================================== Dump File : Mini030711-03.dmp Crash Time : 3/7/2011 11:28:07 PM Bug Check String : BAD_POOL_HEADER Bug Check Code : 0x00000019 Parameter 1 : 0x00000020 Parameter 2 : 0x85ae6000 Parameter 3 : 0x85ae6828 Parameter 4 : 0x1b050000 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+5c846 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini030711-03.dmp Processors Count : 1 Major Version : 15 Minor Version : 2600 Dump File Size : 94,208 ================================================== ================================================== Dump File : Mini030711-02.dmp Crash Time : 3/7/2011 8:14:23 PM Bug Check String : BAD_POOL_HEADER Bug Check Code : 0x00000019 Parameter 1 : 0x00000020 Parameter 2 : 0x85a81420 Parameter 3 : 0x85a81c48 Parameter 4 : 0x1b050062 Caused By Driver : win32k.sys Caused By Address : win32k.sys+20952 File Description : Multi-User Win32 Driver Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 5.1.2600.6064 (xpsp_sp3_gdr.101231-1614) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini030711-02.dmp Processors Count : 1 Major Version : 15 Minor Version : 2600 Dump File Size : 94,208 ================================================== ================================================== Dump File : Mini030711-01.dmp Crash Time : 3/7/2011 7:55:27 PM Bug Check String : DRIVER_CORRUPTED_EXPOOL Bug Check Code : 0x100000c5 Parameter 1 : 0x00000004 Parameter 2 : 0x00000002 Parameter 3 : 0x00000001 Parameter 4 : 0x8054bc34 Caused By Driver : ntoskrnl.exe Caused By Address : ntoskrnl.exe+74c34 File Description : NT Kernel & System Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 5.1.2600.6055 (xpsp_sp3_gdr.101209-1647) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini030711-01.dmp Processors Count : 1 Major Version : 15 Minor Version : 2600 Dump File Size : 94,208 ================================================== ================================================== Dump File : Mini111409-01.dmp Crash Time : 11/14/2009 11:32:10 PM Bug Check String : INVALID_WORK_QUEUE_ITEM Bug Check Code : 0x00000096 Parameter 1 : 0x85a3f123 Parameter 2 : 0x805616c0 Parameter 3 : 0x805616c0 Parameter 4 : 0xf72f0bf0 Caused By Driver : NDIS.sys Caused By Address : NDIS.sys+6bf0 File Description : NDIS 5.1 wrapper driver Product Name : Microsoft® Windows® Operating System Company : Microsoft Corporation File Version : 5.1.2600.5512 (xpsp.080413-0852) Processor : 32-bit Computer Name : Full Path : C:\WINDOWS\Minidump\Mini111409-01.dmp Processors Count : 1 Major Version : 15 Minor Version : 2600 Dump File Size : 90,112 ==================================================
Go to
Start and then to Run
Type in Chkdsk /r Note the space between k and /
Click Enter …It will probably ask if you want to do this on the next reboot…click Y
If the window doesn't shutdown on its own then reboot the system manually. On reboot the system will start the chkdsk operation
This one will take longer then chkdsk /f

Note… there are 5 stages…
It may appear to hang at a certain percent for a hour or more or even back up and go over the same area…this is normal…
DO NOT SHUT YOUR COMPUTER DOWN WHILE CHKDSK IS RUNNING OR YOU CAN HAVE SEVERE PROBLEMS
This can take several hours to complete.
When completed it will boot the system back into windows.

Run CF again and let me know if this fixes the problem
Hi Conspire, I ran the CHKDSK /R as advised and tghere is no problem When i tried to run combo fix again, the same error occured, and i saw the same blue screen again… can you advise? thanks
I'm thinking that this might be a case of non malware related.

A. If you have more than one RAM module installed, try starting/running computer with one RAM stick at a time.

NOTE Keep in mind, the manual check listed above is always superior to the software check, listed below. DO NOT proceed with memtest, if you can go with option A

B. If you have only one RAM stick installed…
…run memtest…

1. Download - Pre-Compiled Bootable ISO (.zip)
2. Unzip downloaded memtest86+-….iso.zip file.
3. Inside, you'll find memtest86+-….iso file.
4. Download, and install ImgBurn: http://www.imgburn.com/
5. Insert blank CD into your CD drive.
6. Open ImgBurn, and click on Write image file to disc
7. Click on Browse for a file… icon:

[external image: Posted Image]

8. Locate memtest86+-….iso file, and click Open button.
9. Click on ImgBurn green arrow to start burning bootable memtest86 CD:

[external image: Posted Image]

10. Once the CD is created, boot from it, and memtest will automatically start to run.

The running program will look something like this depending on the size and number of ram modules installed:


[external image: Posted Image]

It's recommended to run 5-6 passes. Each pass contains very same 8 tests.

This will show the progress of the test. It can take a while. Be patient, or leave it running overnight.

[external image: Posted Image]

The following image is the test results area:

[external image: Posted Image]

The most important item here is the “errors” line. If you see ANY errors, even one, most likely, you have bad RAM.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI