This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Boots properly Then freezes

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My 8 year old Dell boots properly but when I click on an icon or the start button it runs continuously with nothing executing and not allowing me to click on anything else. I thought it might be a hardware problem but it seems ok in the safe mode which is where I am now. In the safe mode I ran Anti-Malware and Ccleaner with no items detected. I have never had success with system restore and still have not.
Hi jack this follows, any assistance will be greatly appreciated.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:35:49 AM, on 8/11/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17098)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Administrator\My Documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [lxedmon.exe] "C:\Program Files\Lexmark S600 Series\lxedmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark S600 Series\ezprint.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\MESSEN~1\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\MESSEN~1\yhexbmes.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.com
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/17bfd7ea101c87…ip/RdxIE601.cab
O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} - http://www.imagestation.com/common/classes…ion=4,3,2,20802
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/downl…lscbase3401.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37440.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.samsphotoclub.com/upload/FujifilmUploadClient.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxedCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxedserv.exe
O23 - Service: lxed_device - - C:\WINDOWS\system32\lxedcoms.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

–
End of file - 8913 bytes
Hello and welcome to What The Tech.

I am currently assessing your situation and will be back with a fix for your problem as soon as possible.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this, click Options, then click Track this topic. Please select Immediate Email Notification for the topic subscription, then click Proceed.

Please be patient with me during this time.

Meanwhile, please make a reply to this topic to acknowledge that you have read this and is still with me to tackle the problem until the end. If I do not get any response within 3 days, this topic will be closed.
Hello tulio43 :),

Welcome to What The Tech. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.
  • Please observe and follow these Terms of Use and the rules in Are you Infected? Getting Started: How To Get Help.
  • Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
  • Please read the instructions carefully and follow them closely, in the order they are presented to you.
  • If you have any doubts or problems during the fix, please stop and ask.
  • All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
  • Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
  • Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
  • Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
  • If you do not reply within 3 days, this topic will be closed.
If you are agreeable to the above, then everything should go smoothly :) . We may begin.

——————–

Please download DDS from one of the links below and save it to your desktop.

Link 1
Link 2
Link 3

Please disable any script blocker before running DDS.

  • Double click on the dds file and a command window will appear. This is normal.
  • Shortly after, two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you to save and post the logs.
  • Save the logs to a convenient location such as your desktop.
  • Copy the contents of both logs and post them in your next reply.
——————–

Please download aswMBR and save it to your desktop. Click here.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily. They will interfere and may cause unexpected results.
  • If you need help to disable your protection programs see here and here.
  • Double click the aswMBR.exe file to run it.
  • Click on the Scan button to start. The program will launch a scan.
  • When done, you will see Scan finished successfully. Please click on Save log and save the file to your desktop.
  • Please post the contents of the log in your next reply.
——————–

Please post back:
1. the DDS logs (DDS.txt and Attach.txt)
2. aswMBR result
I completely agree with the items you enumerated and appreciate your efforts. The logs are as follows: . DDS (Ver_2011-06-23.01) - NTFSx86 NETWORK Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_20 Run by [removed] at 13:33:31 on 2011-08-13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.266 [GMT -4:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.dell4me.com/myway uSearch Page = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com uDefault_Page_URL = hxxp://www.dell4me.com/myway uSearch Bar = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mDefault_Page_URL = hxxp://www.yahoo.com mStart Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/stp/yie6/*http://www.yahoo.com mDefault_Search_URL = hxxp://www.google.com/ie mSearchAssistant = hxxp://www.google.com/ie BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll BHO: Lexmark Printable Web: {d2c5e510-be6d-42cc-9f61-e4f939078474} - c:\program files\lexmark printable web\bho.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - c:\program files\lexmark toolbar\toolband.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\messen~1\yhexbmes.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Sonic RecordNow!] uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [ezShieldProtector for Px] c:\windows\system32\ezSP_Px.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [lxedmon.exe] "c:\program files\lexmark s600 series\lxedmon.exe" mRun: [EzPrint] "c:\program files\lexmark s600 series\ezprint.exe" mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2499216C-4BA5-11D5-BD9C-000103C116D5} - {2499216C-4BA5-11D5-BD9C-000103C116D5} - c:\program files\yahoo!\common\ylogin.dll IE: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - {4C171D40-8277-11D5-AD55-00010333D0AD} - c:\progra~1\yahoo!\messen~1\yhexbmes.dll DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - hxxp://software-dl.real.com/17bfd7ea101c8762f222/netzip/RdxIE601.cab DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} - hxxp://www.imagestation.com/common/classes/batchdwnl.cab?version=4,3,2,20802 DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxps://scan.safety.live.com/resource/download/scanner/en-us/wlscbase3401.cab DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37440.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {A8683C98-5341-421B-B23C-8514C05354F1} - hxxp://www.samsphotoclub.com/upload/FujifilmUploadClient.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{BE5EA4A5-DAAD-42D5-B798-E22C9D17146C} : DhcpNameServer = 192.168.1.1 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - No File . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\hw7069i9.default\ FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPFxViewer.dll FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: c:\program files\nos\bin\np_gp.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin8.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll . ============= SERVICES / DRIVERS =============== . S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-6-26 441176] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-11 309848] S1 PROCEXP;PROCEXP;c:\windows\system32\drivers\PROCEXP.SYS [2004-9-22 10396] S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-11 19544] S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-11 42184] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-18 135664] S2 lxed_device;lxed_device;c:\windows\system32\lxedcoms.exe -service –> c:\windows\system32\lxedcoms.exe -service [?] S2 lxedCATSCustConnectService;lxedCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxedserv.exe [2010-4-17 98984] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-18 135664] S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\system32\svchost.exe -k nosGetPlusHelper [2002-8-29 14336] . =============== Created Last 30 ================ . 2011-08-09 20:56:53 ——– d—–w- c:\documents and settings\administrator\local settings\application data\Dell 2011-08-09 09:45:34 ——– d—–w- c:\documents and settings\administrator\local settings\application data\Mozilla 2011-08-09 00:47:07 ——– d—–w- c:\documents and settings\all users\application data\Spyware Terminator 2011-08-09 00:46:54 ——– d—–w- c:\program files\Spyware Terminator 2011-08-09 00:46:38 ——– d—–w- c:\documents and settings\all users\application data\OnlineArmor 2011-08-09 00:46:34 ——– d—–w- c:\program files\McAfee Security Scan 2011-08-09 00:46:34 ——– d—–w- c:\documents and settings\all users\application data\McAfee Security Scan 2011-08-09 00:46:06 ——– d—–w- C:\ProgramData 2011-08-09 00:46:06 ——– d—–w- c:\program files\123PDFConverter 2011-08-09 00:46:03 ——– d—–w- c:\program files\Tall Emu 2011-08-09 00:38:08 ——– d—–w- c:\documents and settings\administrator\application data\Malwarebytes 2011-07-30 13:06:54 ——– d—–w- c:\program files\Crawler 2011-07-30 13:06:37 142592 —-a-w- c:\windows\system32\drivers\sp_rsdrv2.sys . ==================== Find3M ==================== . 2011-07-06 23:52:42 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-07-06 23:52:42 22712 -c–a-w- c:\windows\system32\drivers\mbam.sys 2011-07-04 11:43:53 40112 —-a-w- c:\windows\avastSS.scr 2011-07-04 11:36:43 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2011-06-27 00:38:27 1100460 —-a-w- c:\documents and settings\all users\SPL5D.tmp 2011-06-24 09:22:33 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 13:34:27.32 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-06-23.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 4/1/2004 11:13:26 PM System Uptime: 8/11/2011 10:25:52 AM (51 hours ago) . Motherboard: Dell Computer Corp. | | 0F4491 Processor: Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/533mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 112 GiB total, 80.537 GiB free. D: is CDROM () E: is CDROM () G: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP2861: 7/31/2011 7:02:40 AM - Software Distribution Service 3.0 RP2862: 8/1/2011 6:13:32 AM - Software Distribution Service 3.0 RP2863: 8/2/2011 6:25:41 AM - Software Distribution Service 3.0 RP2864: 8/3/2011 5:52:31 AM - Software Distribution Service 3.0 RP2865: 8/4/2011 7:03:54 AM - Software Distribution Service 3.0 RP2866: 8/5/2011 1:26:37 PM - Software Distribution Service 3.0 RP2867: 8/8/2011 2:20:17 AM - System Checkpoint RP2868: 8/8/2011 3:00:19 AM - Software Distribution Service 3.0 RP2869: 8/8/2011 8:53:34 PM - Restore Operation RP2870: 8/8/2011 10:52:15 PM - Restore Operation RP2871: 8/8/2011 10:52:15 PM - Restore Operation RP2872: 8/9/2011 5:57:33 AM - Restore Operation . ==== Installed Programs ====================== . Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Lightroom Adobe Reader 7.0.9 Adobe SVG Viewer 3.0 Apple Application Support Apple Mobile Device Support Apple Software Update avast! Free Antivirus Bonjour CCleaner Dell Digital Jukebox Driver Dell Media Experience Dell Networking Guide Dell ResourceCD Dell Solution Center Dell Support DVDSentry FxFoto by Triscape Google Desktop Google Toolbar for Internet Explorer Google Update Helper Help and Support Customization Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2158563) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® Extreme Graphics 2 Driver Intel® PRO Network Adapters and Drivers Intel® PROSet Internet Explorer Default Page iTunes Jasc Paint Shop Pro 8 Java Auto Updater Java™ 6 Update 20 Lexmark Printable Web Lexmark S600 Series Lexmark Toolbar LG USB Modem driver Macromedia Shockwave Player Malwarebytes' Anti-Malware version 1.51.1.1800 Maxtor Manager Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2416447) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft National Language Support Downlevel APIs Microsoft Office XP Standard for Students and Teachers Microsoft Picture It! Photo Premium 9 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Word 2002 Microsoft Works Microsoft Works 2004 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word Mozilla Firefox 4.0 (x86 en-US) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6.0 Parser (KB933579) Music Visualizer Library 1.4.00 Net MD Simple Burner OpenMG Secure Module 4.5.01 OpenMG Secure Module 5.0.00 Picasa 3 QuickTime RealPlayer Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB2183461) Security Update for Windows Internet Explorer 7 (KB2360131) Security Update for Windows Internet Explorer 7 (KB2416400) Security Update for Windows Internet Explorer 7 (KB2482017) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2259922) Security Update for Windows XP (KB2279986) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2296199) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2436673) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479628) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485376) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981349) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981957) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Security Update for Windows XP (KB982802) Shutterfly Studio Sony Picture Utility Triscape FxFoto Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows XP (KB2141007) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Viewpoint Media Player Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage v1.3.0254.0 Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Live Safety scanner Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Login Yahoo! Messenger Yahoo! Messenger Explorer Bar . ==== Event Viewer Messages From Past Week ======== . 8/9/2011 7:55:29 AM, error: System Error [1003] - Error code 100000d1, parameter1 9931a79b, parameter2 00000007, parameter3 00000000, parameter4 f85a7021. 8/9/2011 6:39:57 AM, error: System Error [1003] - Error code 100000d1, parameter1 0000000c, parameter2 00000007, parameter3 00000001, parameter4 f84695f7. 8/9/2011 6:39:39 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Lbd 8/9/2011 6:32:01 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 8/9/2011 6:29:38 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 8/9/2011 6:04:49 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswRdr aswSnx aswSP aswTdi Fips intelppm IPSec Lbd MRxSmb NetBIOS NetBT PROCEXP RasAcd Rdbss Tcpip WS2IFSL 8/9/2011 6:04:49 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning. 8/9/2011 6:04:49 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 8/9/2011 6:04:49 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 8/9/2011 6:04:49 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 8/9/2011 6:04:49 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 8/9/2011 6:04:49 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 8/9/2011 5:17:44 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 8/9/2011 4:57:40 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 8/8/2011 11:29:36 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 8/8/2011 11:28:51 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSnx aswSP aswTdi Fips intelppm Lbd PROCEXP 8/8/2011 10:40:05 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Print Spooler service to connect. 8/8/2011 10:40:05 PM, error: Service Control Manager [7000] - The Print Spooler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 8/13/2011 7:10:02 AM, error: Dhcp [1002] - The IP address lease [removed] for the Network Card with network address 000CF1D812DA has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software Run date: 2011-08-13 13:43:38 —————————– 13:43:38.546 OS Version: Windows 5.1.2600 Service Pack 3 13:43:38.546 Number of processors: 1 586 0x209 13:43:38.546 ComputerName: STUDY UserName: 13:43:39.312 Initialize success 13:43:40.312 AVAST engine defs: 11080701 13:43:52.312 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 13:43:52.328 Disk 0 Vendor: ST3120026AS 8.05 Size: 114440MB BusType: 3 13:43:54.343 Disk 0 MBR read successfully 13:43:54.359 Disk 0 MBR scan 13:43:54.781 Disk 0 Windows XP default MBR code 13:43:54.796 Disk 0 scanning sectors +234372285 13:43:55.390 Disk 0 scanning C:\WINDOWS\system32\drivers 13:44:14.328 Service scanning 13:44:17.937 Modules scanning 13:44:20.968 Disk 0 trace - called modules: 13:44:21.015 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 13:44:21.031 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x833a1ab8] 13:44:21.046 3 CLASSPNP.SYS[f8678fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-17[0x83397d98] 13:44:22.593 AVAST engine scan C:\WINDOWS 13:44:30.078 AVAST engine scan C:\WINDOWS\system32 13:46:19.718 AVAST engine scan C:\WINDOWS\system32\drivers 13:46:40.656 AVAST engine scan C:\Documents and Settings\Administrator 13:47:01.140 AVAST engine scan C:\Documents and Settings\All Users 13:48:55.468 Scan finished successfully 13:50:01.515 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\MBR.dat" 13:50:01.531 The log file has been saved successfully to "C:\Documents and Settings\Administrator\Desktop\aswMBR.txt"
Hello tulio43 :),

What do you use the computer for? If you have important data, I suggest you make some backups.

These articles; System Backup for Windows XP, XP Backup, Windows 7 Backup and Restore, explain the whats and hows using the Windows built-in backup tool.

Some good and free alternative third party backup or imaging softwares that you can consider are Cobian Backup and Macrium Reflect. Tutorial for Cobian Backup can be found here and Macrium Reflect here.

For paid version, Acronis True Image Home is a good option.

To create a boot CD with alternative Operating System, you can try Puppy Linux or xPUD.

After you have done doing backup, please let me know so that we can continue.

You have Malwarebytes' Anti-Malware (MBAM) on your machine. I wish to take a look at the most recent log file. Open MBAM and click on the Logs tab. Open the file at the bottom of the list and post the contents back here. If there is no log or you have yet to run MBAM, please let me know.

——————–

Please post back:
1. what do you use the computer for
2. the previous MBAM report
Use the computer primarily for internet access(news, facebook, paying bills, etc.), Microsoft Money, and spreedsheetsfor such things as taxes, passwords and lists. Didn't have any luck with Cobian or Puppy Linux as I am running in safe mode, but I have a back-up from a couple weeks ago on a mini Maxtor drive and I probably have the original boot disk, so I am willing to proceed. Not much in the MBAM file but here it is: Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7324 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 7.0.5730.11 8/8/2011 11:53:52 PM mbam-log-2011-08-08 (23-53-52).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 276606 Time elapsed: 25 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello tulio43 :),

Check your hard disk for error
  • Go to Start > Run…. Copy and paste the following text into the white box:
    cmd /c chkdsk c: |find /v "percent" >> "%userprofile%\desktop\checkhd.txt"
  • Click OK. A command prompt window will appear for a while. Please wait until it closes.
  • Post the contents of checkhd.txt. It is found on your desktop.
——————–

Please perform a memtest and let me know the results.

Windows Memory Diagnostic Tool steps available here or here.

——————–

Do an online scan with ESET Online Scanner.
Please be patient as scanning will take quite some time. If you have problem running the scan, you might want to disable any real time protection that you have.
  • Click here to go to ESET Online Scanner page.
  • Click on Run ESET Online Scanner. A new window will open.
    For FireFox user, you will need to download and install esetsmartinstaller_enu.exe. Click on it and save the file to a convenient location. Double click on it to install and a new window will open.
  • After reading through the Terms of Use, check YES, I accept the Terms of Use and click Start to begin scan.
  • You will be prompted to install an ActiveX Control from ESET. Please install.
  • At the Computer scan settings section, uncheck (untick) Remove found threats. <– Important, do not remove anything yet.
  • Then, check Scan archives.
  • Now, click on Advanced settings and make sure all these are checked:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click on Scan to proceed.
  • When done, the scan result will be shown. Look for C:\Program Files\ESET\ESET Online Scanner\log.txt and open the file.
  • Post the contents in your reply.
If the contents of log.txt do not reflect what is shown in the result window, click on List of found threats, then Export to text file…, save a file and post that instead.

——————–

Please close all programs and do not run any others before and during the Rootkit Unhooker scan. Do not use the computer for anything else until after the scan is completed.

Please download Rootkit Unhooker and save it to your desktop. Click here.
  • Double click RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Ensure the following are checked (ticked):
    • Drivers
    • Stealth Code
    • Files
    • Code Hooks
  • Uncheck the rest, then click OK. An initial scan will be performed.
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK.
  • Wait until the scanner is done, then click on File at the pull down menu, followed by Save Report.
  • Save the report somewhere you can find it. Click Close to exit.
  • Copy the entire contents of the report and paste it in your next reply.
You may get a warning about parasite detection. Please click OK to continue.

——————–

Please post back:
1. chkdsk result
2. memtest result
3. ESET online scan report
4. Rootkit Unhooker log
Follows is the chkdsk result. In safe mode I cannot see a button to accept the windows mem diag tool license agreement and Rootkit Unhooker says it is not configured to run in safe mode. I will now run the eset scanner while awaiting your advice. The type of the file system is NTFS. WARNING! F parameter not specified. Running CHKDSK in read-only mode. CHKDSK is verifying files (stage 1 of 3)… CHKDSK is verifying indexes (stage 2 of 3)… CHKDSK is verifying security descriptors (stage 3 of 3)… CHKDSK is verifying Usn Journal… Usn Journal verification completed. 117154012 KB total disk space. 32504980 KB in 84885 files. 44440 KB in 11056 indexes. 0 KB in bad sectors. 331668 KB in use by the system. 65536 KB occupied by the log file. 84272924 KB available on disk. 4096 bytes in each allocation unit. 29288503 total allocation units on disk. 21068231 allocation units available on disk.
Follows are results from eset, two threats found. Just fyi, gotta leave, it's noon now will not be back till 7pm. Work Mon thru Wed until 6pm and going on a ten day vacation starting early Thursday 8/18 morning. C:\Program Files\Dell\DellSupportSilentInstall.EXE probably a variant of Win32/Adware.Agent.LCKGTSG application C:\SDFix\apps\Process.exe Win32/PrcView application
Hello tulio43 :),

Thanks for letting me know about your availability for the coming days. We skip Rootkit Unhooker and memtest for now. The findings from ESET should be harmless.

I probably have the original boot disk

Is this the Windows CD? Please look for it, we may need it.

Prior to the freezing issue, what programs have you installed or do you experience any unusual symptoms?

——————–

Please download MiniToolBox© by farbar and save it to your desktop. Click here.
  • Double click on MiniToolBox.exe to run it.
    Please check (tick) the following options:
    • List last 10 Event Viewer Errors
    • List Users, Partitions and Memory size.
  • Click on the GO button. A log will open.
  • Please post the contents of this log. It can also be found on the desktop as Result.txt.
——————–

Please close all programs and do not run any others before and during the GMER scan. Do not use the computer for anything else until after the scan is completed.

Please download GMER and save it to your desktop. Click here.
  • Please disable your real time protection of any Antivirus, Antispyware or Antimalware programs temporarily when running GMER. They may cause the computer to freeze.
  • If you need help to disable your protection programs see here and here.
  • Double click the .exe file. If asked to allow the gmer driver file with a sys extension to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan, click on No.
  • In the right panel, you will see several boxes that have been checked (ticked).
    • Uncheck IAT/EAT
    • Uncheck All other Drives/Partitions except C:\ (leave C:\ checked)
    • Uncheck Show All (don't miss this one)
  • Then click the Scan button and wait for it to finish.
  • Once done, click on the Save… button and save it as "Gmer.txt" at a convenient location. Post the contents of that report.
  • Enable back your security softwares as soon as you completed the GMER steps.
    Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries.
If you are having problems running GMER, retry with Devices unchecked as well. If you are still encountering difficulties, please try running GMER in Safe Mode. You can get into Safe Mode using the F8 key during the startup of your computer after a reboot.

——————–

Please post back:
1. the availability of Windows CD
2. the answers to my questions on programs and symptoms
3. MiniToolBx result
4. GMER log
Was hoping two items from ESET were the problem. I have two identical Reinstallation CD's - Microsoft Windows XP Home Edition and a homemade disk labeled Windows Recovery. The Minitoolbx result: MiniToolBox by Farbar Ran by [removed] (administrator) on 15-08-2011 at 07:13:26 Microsoft Windows XP Service Pack 3 (X86) *************************************************************************** ========================= Event log errors: =============================== Application errors: ================== Error: (08/08/2011 10:40:08 PM) (Source: Userenv) (User: SYSTEM)SYSTEM Description: Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off. Error: (08/08/2011 10:40:04 PM) (Source: Userenv) (User: Joan Kotula)Joan Kotula Description: Windows has backed up this user's profile. Windows will automatically try to use the backed up profile the next time this user logs on. Error: (08/08/2011 10:40:04 PM) (Source: Userenv) (User: SYSTEM)SYSTEM Description: Windows cannot load the locally stored profile. Possible causes of this error include insufficient security rights or a corrupt local profile. If this problem persists, contact your network administrator. DETAIL - The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format. Error: (08/08/2011 10:39:49 PM) (Source: Userenv) (User: SYSTEM)SYSTEM Description: Windows was unable to load the registry. This is often caused by insufficient memory or insufficient security rights. DETAIL - The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format. for C:\Documents and Settings\Joan Kotula\ntuser.dat Error: (08/08/2011 06:24:42 PM) (Source: Userenv) (User: Joan Kotula)Joan Kotula Description: Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off. Error: (08/08/2011 06:24:11 PM) (Source: Userenv) (User: Joan Kotula)Joan Kotula Description: Windows has backed up this user's profile. Windows will automatically try to use the backed up profile the next time this user logs on. Error: (08/08/2011 06:24:11 PM) (Source: Userenv) (User: Joan Kotula)Joan Kotula Description: Windows cannot load the locally stored profile. Possible causes of this error include insufficient security rights or a corrupt local profile. If this problem persists, contact your network administrator. DETAIL - The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format. Error: (08/08/2011 06:23:40 PM) (Source: Userenv) (User: SYSTEM)SYSTEM Description: Windows was unable to load the registry. This is often caused by insufficient memory or insufficient security rights. DETAIL - The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format. for C:\Documents and Settings\Joan Kotula\ntuser.dat Error: (08/07/2011 07:25:41 PM) (Source: Ci) (User: ) Description: Content index on c:\system volume information\catalog.wci could not be initialized. Error 3221225529. Error: (08/01/2011 09:09:03 AM) (Source: Ci) (User: ) Description: Content index on c:\system volume information\catalog.wci could not be initialized. Error 3221225477. System errors: ============= Error: (08/14/2011 01:41:13 PM) (Source: 0) (User: ) Description: 192.168.1.1005C:AC:4C:7C:FB:C3 Error: (08/14/2011 00:10:57 PM) (Source: DCOM) (User: Administrator) Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error: (08/14/2011 11:22:06 AM) (Source: 0) (User: ) Description: \Device\Harddisk0\D Error: (08/14/2011 11:22:02 AM) (Source: 0) (User: ) Description: \Device\Harddisk0\D Error: (08/14/2011 11:21:58 AM) (Source: 0) (User: ) Description: \Device\Harddisk0\D Error: (08/14/2011 11:21:55 AM) (Source: 0) (User: ) Description: \Device\Harddisk0\D Error: (08/14/2011 11:21:51 AM) (Source: 0) (User: ) Description: \Device\Harddisk0\D Error: (08/14/2011 11:21:47 AM) (Source: 0) (User: ) Description: \Device\Harddisk0\D Error: (08/14/2011 11:21:43 AM) (Source: 0) (User: ) Description: \Device\Harddisk0\D Error: (08/14/2011 11:21:40 AM) (Source: 0) (User: ) Description: \Device\Harddisk0\D Microsoft Office Sessions: ========================= Error: (08/08/2011 10:40:08 PM) (Source: Userenv)(User: SYSTEM)SYSTEM Description: Error: (08/08/2011 10:40:04 PM) (Source: Userenv)(User: Joan Kotula)Joan Kotula Description: Error: (08/08/2011 10:40:04 PM) (Source: Userenv)(User: SYSTEM)SYSTEM Description: The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format. Error: (08/08/2011 10:39:49 PM) (Source: Userenv)(User: SYSTEM)SYSTEM Description: The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format. C:\Documents and Settings\Joan Kotula\ntuser.dat Error: (08/08/2011 06:24:42 PM) (Source: Userenv)(User: Joan Kotula)Joan Kotula Description: Error: (08/08/2011 06:24:11 PM) (Source: Userenv)(User: Joan Kotula)Joan Kotula Description: Error: (08/08/2011 06:24:11 PM) (Source: Userenv)(User: Joan Kotula)Joan Kotula Description: The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format. Error: (08/08/2011 06:23:40 PM) (Source: Userenv)(User: SYSTEM)SYSTEM Description: The system has attempted to load or restore a file into the registry, but the specified file is not in a registry file format. C:\Documents and Settings\Joan Kotula\ntuser.dat Error: (08/07/2011 07:25:41 PM) (Source: Ci)(User: ) Description: c:\system volume information\catalog.wci3221225529 Error: (08/01/2011 09:09:03 AM) (Source: Ci)(User: ) Description: c:\system volume information\catalog.wci3221225477 ========================= Memory info: =================================== Percentage of memory in use: 55% Total physical RAM: 509.98 MB Available physical RAM: 226.69 MB Total Pagefile: 1247.83 MB Available Pagefile: 1017.75 MB Total Virtual: 2047.88 MB Available Virtual: 2004.52 MB ========================= Partitions: ===================================== 2 Drive c: () (Fixed) (Total:111.73 GB) (Free:80.25 GB) NTFS ========================= Users: ======================================== User accounts for \\STUDY Administrator ASPNET Guest HelpAssistant Joan Kotula Mark Kotula SUPPORT_388945a0 SUPPORT_3f151ab9 == End of log == I download GMER, dbl click "are you sure you want to launch cplcwoq.exe", I click OK. "Are you sure you want to run this software", I click run. A rootkit/malware screen appears, I uncheck IAT/EAT, there are no other drives/partitions, show all is already unchecked. There is no scan button, only ok or cancel, I click ok and it exits the application. It does not save to my desktop and everything I have been doing is in safe mode. I look at the program files per gmer and there is a lot there that I had long ago deleted. The only program changes that I recall making within the past several weeks are I eliminated Online Armour as it was preventing me from getting online after I had upgraded Firefox and I added Spyware terminator after I started having freezing problems (and Crawler came with it).
Hello tulio43 :),

There could be many possibilities for your problem, so we will need to go through them one by one to narrow down the issue. This may take a while.

Lets start with the most probable one, which is corrupted profile.

Please create a new user account according to the following article by Microsoft:
How to create and configure user accounts in Windows XP

Please reboot into Normal Mode with this new account and see if there are any problems. If you do not experience the freezing, then we have identified the cause.

If you need to copy data from your old profile:
How to copy data from a corrupted user profile to a new profile in Windows XP

Let me know how things go and we will continue from there.
I set up my new user name "jack and Jill", rebooted, and it is now freezing (you can hear the hard drive pulsating like a heartbeat every two seconds) when you want to select a user. After three to five minutes the Welcome screen with my selection of Jack and Jill came up and it appears locked there.
I reboot in safe mode and only Administrator and Jack and Jill are choices. It was previously Admin and Joan. In neither case did it have Mark (me) as a choice, where most of the programs are located.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI