This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC Hangs on Shut Down, IE8 slow

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My computer has been hanging when shutting down, forcing me to manually shut the unit down. The computer also no longer likes to multi task. I use to be able to open multiple programs (IE, Outlook etc.) at the same time w/o hanging up the system. If I try this now everything freezes up & I have to go through task manager to close out the hung programs. Additionally, IE 8 is slower loading pages.

Thanks for any help you can provide.
Vista Home Basic SP2
Compaq Presario 32 bit=============

OTL logfile created on: 12/2/2011 4:16:26 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Mothership\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.58 Mb Total Physical Memory | 351.56 Mb Available Physical Memory | 39.30% Memory free
2.01 Gb Paging File | 1.32 Gb Available in Paging File | 65.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143.29 Gb Total Space | 79.38 Gb Free Space | 55.40% Space Free | Partition Type: NTFS
Drive D: | 5.76 Gb Total Space | 0.87 Gb Free Space | 15.16% Space Free | Partition Type: NTFS

Computer Name: MOTHERSHIP-PC | User Name: Mothership | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mothership\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccsvchst.exe (Symantec Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)

========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Program Files\HP\Digital Imaging\bin\crm\xmltok.dll ()
MOD - C:\Program Files\HP\Digital Imaging\bin\crm\xmlparse.dll ()

========== Win32 Services (SafeList) ==========

SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\BASHDefs\20111123.001\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (IDSVix86) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\IPSDefs\20111201.001\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20111202.003\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\Definitions\VirusDefs\20111202.003\NAVENG.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\Drivers\N360\0501000.01D\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\system32\drivers\N360\0501000.01D\SRTSPX.SYS (Symantec Corporation)
DRV - (SYMTDIv) – C:\Windows\System32\Drivers\N360\0501000.01D\SYMTDIV.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\Windows\system32\drivers\N360\0501000.01D\SYMEFA.SYS (Symantec Corporation)
DRV - (SymDS) – C:\Windows\system32\drivers\N360\0501000.01D\SYMDS.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\Windows\system32\drivers\N360\0501000.01D\Ironx86.SYS (Symantec Corporation)
DRV - (cpuz134) – C:\Program Files\CPUID\PC Wizard 2010\pcwiz_x32.sys (Windows ® Win 7 DDK provider)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\Windows\System32\drivers\HSX_DP.sys (Conexant Systems, Inc.)
DRV - (VSTHWBS2) – C:\Windows\System32\drivers\VSTBS23.SYS (Conexant Systems, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Mothership\AppData\Roaming\Move Networks\plugins\npqmp071706000001.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\IPSFFPlgn\ [2011/10/21 15:57:13 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.0.0.125\coFFPlgn_2011_7_3_6 [2011/12/02 15:54:34 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Mothership\AppData\Roaming\Move Networks [2011/06/23 15:27:45 | 000,000,000 | —D | M]


O1 HOSTS File: ([2006/09/18 15:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\ips\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\5.1.0.29\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC82540-80EE-4BBA-AED1-AE6EBF116D2F}: DhcpNameServer = 75.75.76.76 75.75.75.75
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Mothership\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Mothership\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/01 17:19:42 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Mothership\Desktop\OTL.exe
[2011/11/16 17:04:20 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/11/16 17:03:49 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/11/04 16:07:02 | 000,000,000 | —D | C] – C:\Program Files\Hewlett-Packard

========== Files - Modified Within 30 Days ==========

[2011/12/02 15:54:15 | 000,003,664 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/02 15:54:15 | 000,003,664 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/02 15:54:07 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/02 15:54:03 | 938,795,008 | -HS- | M] () – C:\hiberfil.sys
[2011/12/01 21:07:33 | 000,001,726 | -H– | M] () – C:\Users\Mothership\Documents\Default.rdp
[2011/12/01 18:07:01 | 000,000,428 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{11AA4C19-A7C2-4745-AAF1-2E35DA37E07D}.job
[2011/12/01 17:19:47 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Mothership\Desktop\OTL.exe
[2011/12/01 16:29:14 | 000,604,264 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/12/01 16:29:14 | 000,103,964 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/11/22 17:05:55 | 000,270,552 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/11/21 16:26:01 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/11/04 16:14:39 | 000,148,954 | —- | M] () – C:\Windows\hpoins19.dat
[2011/11/04 16:08:36 | 000,001,148 | —- | M] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2011/11/04 16:07:45 | 000,001,978 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk

========== Files Created - No Company Name ==========

[2011/11/04 16:09:00 | 000,000,855 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2011/11/04 16:08:36 | 000,001,148 | —- | C] () – C:\Users\Public\Desktop\HP Solution Center.lnk
[2011/11/04 16:07:45 | 000,001,978 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/11/04 15:58:53 | 000,148,954 | —- | C] () – C:\Windows\hpoins19.dat
[2011/11/04 15:55:53 | 000,026,952 | —- | C] () – C:\Windows\hpomdl19.dat
[2011/05/18 16:38:25 | 000,001,940 | —- | C] () – C:\Users\Mothership\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/07/11 18:15:49 | 000,011,264 | —- | C] () – C:\Users\Mothership\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/11 07:18:18 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2009/04/11 07:18:18 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/04/11 07:18:15 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2007/06/13 17:54:56 | 003,107,788 | —- | C] () – C:\Windows\System32\atiumdva.dat
[2007/02/20 19:39:10 | 000,144,773 | —- | C] () – C:\Windows\System32\atiicdxx.dat
[2006/11/02 06:53:49 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 06:44:53 | 000,270,552 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 04:33:01 | 000,604,264 | —- | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 04:33:01 | 000,287,440 | —- | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 04:33:01 | 000,103,964 | —- | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 04:33:01 | 000,030,674 | —- | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 04:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 04:23:21 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 02:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 02:19:00 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 01:25:31 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat

========== LOP Check ==========

[2011/05/08 16:37:19 | 000,000,000 | —D | M] – C:\Users\Mothership\AppData\Roaming\Image Zone Express
[2011/03/25 18:32:08 | 000,000,000 | —D | M] – C:\Users\Mothership\AppData\Roaming\Macroplant, LLC
[2010/07/18 20:25:17 | 000,000,000 | —D | M] – C:\Users\Mothership\AppData\Roaming\Printer Info Cache
[2011/12/01 21:08:22 | 000,032,648 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/12/01 18:07:01 | 000,000,428 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{11AA4C19-A7C2-4745-AAF1-2E35DA37E07D}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 07:18:47 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/07/11 20:11:25 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2008/02/09 15:51:36 | 000,008,056 | —- | M] () – C:\ComboFix.txt
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/12/02 15:54:03 | 938,795,008 | -HS- | M] () – C:\hiberfil.sys
[2011/12/02 15:54:02 | 1252,605,952 | -HS- | M] () – C:\pagefile.sys
[2008/09/21 08:45:26 | 000,000,477 | —- | M] () – C:\RHDSetup.log
[2008/09/21 08:49:37 | 000,000,000 | —- | M] () – C:\Trace.log
[2009/02/01 14:59:48 | 000,000,594 | —- | M] () – C:\updatedatfix.log
[2007/10/25 14:25:11 | 000,000,029 | —- | M] () – C:\wizard.txt
[2010/03/24 16:30:32 | 000,000,150 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/11/02 06:35:34 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:35:34 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:35:34 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/04/11 07:19:49 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/01/20 20:32:37 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/10/26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 20:57:01 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/04/11 08:02:52 | 021,975,040 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2009/04/11 08:02:36 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2009/04/11 08:02:53 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/11 19:43:16 | 000,000,221 | -HS- | M] () – C:\Users\Mothership\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/12/01 17:19:47 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Mothership\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-11-29 22:48:53

< >

< End of report >=============================================================================
===

OTL Extras logfile created on: 12/2/2011 4:16:26 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Mothership\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19154)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.58 Mb Total Physical Memory | 351.56 Mb Available Physical Memory | 39.30% Memory free
2.01 Gb Paging File | 1.32 Gb Available in Paging File | 65.70% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 143.29 Gb Total Space | 79.38 Gb Free Space | 55.40% Space Free | Partition Type: NTFS
Drive D: | 5.76 Gb Total Space | 0.87 Gb Free Space | 15.16% Space Free | Partition Type: NTFS

Computer Name: MOTHERSHIP-PC | User Name: Mothership | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{18D79616-B29C-4315-BCA6-FC790443C848}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{38DE07DF-C600-4A68-817C-61CD2424E6CB}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{7C02EB9D-BAE3-45EB-932A-860C0C2B6382}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 29
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.6
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1568757-E564-4cb5-8980-9333119A4384}" = F300
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"N360" = Norton Security Suite
"PC Wizard 2010_is1" = PC Wizard 2010.1.96

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Media Player" = Move Media Player

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/5/2011 12:42:02 PM | Computer Name = Mothership-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.19154, time stamp
0x4e8634f0, faulting module mshtml.dll, version 8.0.6001.19154, time stamp 0x4e864aec,
exception code 0xc0000005, fault offset 0x00067a38, process id 0xbc0, application
start time 0x01cc9bd67d1dacb1.

Error - 11/8/2011 10:48:05 PM | Computer Name = Mothership-PC | Source = EventSystem | ID = 4621
Description =

Error - 11/9/2011 10:55:32 PM | Computer Name = Mothership-PC | Source = EventSystem | ID = 4621
Description =

Error - 11/10/2011 11:43:04 PM | Computer Name = Mothership-PC | Source = EventSystem | ID = 4621
Description =

Error - 11/16/2011 7:08:23 PM | Computer Name = Mothership-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.19154, time stamp
0x4e8634f0, faulting module npctrl.dll, version 4.0.60831.0, time stamp 0x4e5d70da,
exception code 0xc0000005, fault offset 0x0001222b, process id 0xfd8, application
start time 0x01cca4b3439fe44b.

Error - 11/22/2011 7:03:20 PM | Computer Name = Mothership-PC | Source = EventSystem | ID = 4621
Description =

Error - 11/22/2011 10:57:10 PM | Computer Name = Mothership-PC | Source = EventSystem | ID = 4621
Description =

Error - 11/24/2011 6:57:01 AM | Computer Name = Mothership-PC | Source = EventSystem | ID = 4621
Description =

Error - 11/27/2011 6:43:11 PM | Computer Name = Mothership-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.19154, time stamp
0x4e8634f0, faulting module mshtml.dll, version 8.0.6001.19154, time stamp 0x4e864aec,
exception code 0xc0000005, fault offset 0x00067a38, process id 0x10dc, application
start time 0x01ccad53b68c3ffd.

Error - 12/1/2011 7:58:12 PM | Computer Name = Mothership-PC | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 8.0.6001.19154, time stamp
0x4e8634f0, faulting module mshtml.dll, version 8.0.6001.19154, time stamp 0x4e864aec,
exception code 0xc0000005, fault offset 0x00067a38, process id 0x15e4, application
start time 0x01ccb08405cc8dda.

[ System Events ]
Error - 3/13/2011 6:33:33 PM | Computer Name = Mothership-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 3/13/2011 8:03:39 PM | Computer Name = Mothership-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 3/13/2011 8:04:09 PM | Computer Name = Mothership-PC | Source = Service Control Manager | ID = 7011
Description =

Error - 3/13/2011 9:15:36 PM | Computer Name = Mothership-PC | Source = bowser | ID = 8003
Description =

Error - 3/14/2011 5:46:00 PM | Computer Name = Mothership-PC | Source = bowser | ID = 8003
Description =

Error - 3/14/2011 6:17:29 PM | Computer Name = Mothership-PC | Source = bowser | ID = 8003
Description =

Error - 3/14/2011 6:42:08 PM | Computer Name = Mothership-PC | Source = bowser | ID = 8003
Description =

Error - 3/14/2011 6:59:30 PM | Computer Name = Mothership-PC | Source = bowser | ID = 8003
Description =

Error - 3/14/2011 7:34:24 PM | Computer Name = Mothership-PC | Source = bowser | ID = 8003
Description =

Error - 3/16/2011 6:34:38 PM | Computer Name = Mothership-PC | Source = bowser | ID = 8003
Description =

< End of report >
Hello, I Am Alander :)

Welcome to the Malware Removal forums.

I would be glad to take a look at your log and help you with solving any malware problems.

OTL logs can take a while to research so please be patient while I work on your log and I will post back here with any recommendations.

As I am still training, everything that I post to you, must be checked by an Admin or Moderator.

Thus, there may be a tiny bit of a delay between posts. While it shouldn't be too long, you can be assured you will get the best possible advice.

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Hi :)

Is this machine use for business activities or used to connect to a school network, I need to know to give the appropriate instructions


Please download GMER Rootkit Scanner from Here.
  • Right click the .exe file and chose Run as Administrator. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All << (don't miss this one)
    See image below, Click the image to enlarge it
    [external image: Posted Image]

  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop, and post it in your next reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Note: Do not run any programs while Gmer is running.
Hi Alander,

This PC is shared in the household and is used for business activities via remote desktop into a business network, as well as everyday home use.

Below if the GMER log. I don't know if it ran correctly as it seems to be small in comparison to other scans.
======================================================================

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-09 17:11:12
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3160812AS rev.3.AHL
Running: Gmer z348mxk9.exe; Driver: C:\Users\MOTHER~1\AppData\Local\Temp\kxtcikoc.sys


—- System - GMER 1.0.15 —-

SSDT 85843490 ZwAlertResumeThread
SSDT 85843550 ZwAlertThread
SSDT 85843D20 ZwAllocateVirtualMemory
SSDT 85783868 ZwAlpcConnectPort
SSDT 8587B728 ZwAssignProcessToJobObject
SSDT 858431E0 ZwCreateMutant
SSDT 8587B1E8 ZwCreateSymbolicLinkObject
SSDT 854E7568 ZwCreateThread
SSDT 8587BAA0 ZwDebugActiveProcess
SSDT 85843EB0 ZwDuplicateObject
SSDT 85843B80 ZwFreeVirtualMemory
SSDT 858432D0 ZwImpersonateAnonymousToken
SSDT 858433B0 ZwImpersonateThread
SSDT 857D29F8 ZwLoadDriver
SSDT 85843AA0 ZwMapViewOfSection
SSDT 85843100 ZwOpenEvent
SSDT 854E7450 ZwOpenProcess
SSDT 85843DF0 ZwOpenProcessToken
SSDT 8587BF28 ZwOpenSection
SSDT 85843F80 ZwOpenThread
SSDT 8587B638 ZwProtectVirtualMemory
SSDT 85843610 ZwResumeThread
SSDT 85843850 ZwSetContextThread
SSDT 85843910 ZwSetInformationProcess
SSDT 8587BDE0 ZwSetSystemInformation
SSDT 8587B008 ZwSuspendProcess
SSDT 858436D0 ZwSuspendThread
SSDT 854E7648 ZwTerminateProcess
SSDT 85843790 ZwTerminateThread
SSDT 858439E0 ZwUnmapViewOfSection
SSDT 85843C50 ZwWriteVirtualMemory
SSDT 8587B2D8 ZwCreateThreadEx

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\RawIp SYMTDIV.SYS (Network Dispatch Driver/Symantec Corporation)

—- EOF - GMER 1.0.15 —-
Hi :)

This PC is shared in the household and is used for business activities via remote desktop into a business network, as well as everyday home use.


I am sorry to inform you that As per our Terms of Use:

We offer free computer help and tech support for home and personal use. We are not here to support others that work for profit, or to support/replace your company's IT department.

  • There may be restrictions and modifications installed on such machines that could be damaged or altered by the actions we take to remove Malware.

  • Any infection could jump terminals in a computer network.

  • There may also be legal issues regarding any loss of business data that I do not wish to deal with.

  • Some people who come here use their computers for work, and the computers may contain the patient records of a physician or the financial records of an accountant's clients or credit card and bank account information of their employer's customers.

  • There may be tremendous risks and legal liability for such users for not fully securing the computer. We will not know this unless we ask. We do not want to be accidentally putting those we help in vulnerable positions for law suits.

  • Business factors outweigh technical factors in making the reformat and reinstall decision. Sometimes friends give missing CDs or lack of expertise as a reason for not doing a reformat and reinstall.

  • The cost of replacing missing Windows XP and MS Office CDs and getting an Microsoft Certified Systems Engineer to come in for 3 hours to do the reinstall and apply all the critical updates, is trivial compared with the
    potential cost of a multi-million dollar lawsuit for breach of trust if confidential client or patient information is disclosed


  • And therefore I am unable to advise you further.
denisemn,
This doesn't appear to be a infection causing this.
I suggest you start a new topic in our Windows Forum.

Post this in your Topic.

My computer has been hanging when shutting down, forcing me to manually shut the unit down. The computer also no longer likes to multi task. I use to be able to open multiple programs (IE, Outlook etc.) at the same time w/o hanging up the system. If I try this now everything freezes up & I have to go through task manager to close out the hung programs. Additionally, IE 8 is slower loading pages.

Thanks for any help you can provide.
Vista Home Basic SP2
Compaq Presario 32 bit=============

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI