This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

After the process, still freezing up [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi again and again… About a month ago went through the whole antimalware process with help on this site. My computer still freezes up every couple-three days. I always notice it as the mouse stops moving or disappears entirely. Ctrl-alt-del does not bring up the window. Waiting does not help. Can only shut down with the power button. Before we start the process anew, are there different reasons that a computer will freeze? Registry or something? Some other avenue of pursuit? Like to discuss the question. Thanks, denno
There can be any number of reasons why a computer can freeze up. It can be anything from conflicting programs, corrupt files, malware, failing hardware, lots of things. The only thing you can do is try and troubleshoot the possibilities to figure out what is going on. It can be very frustrating to figure out the root cause of these problems. Since it has been several weeks since you last worked with someone here regarding malware, we would prefer to have another look at your logs to ensure there is no malware on the machine again. If the logs are still good, then I would refer you over to the Windows forum where they can help you look at the other possibilities that might be causing the problem.




Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt and Attach.txt






Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Hiya and thanks BTW, the freezes never stopped after the last run-through. Did not stop and then recently start again. Here are scan results: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 10.2.1 Run by [removed] at 20:01:24 on 2012-03-13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1013.296 [GMT -4:00] . AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fppdis1.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\Fighters\Tray\FightersTray.exe C:\Program Files\Fighters\SPAMfighter\sfagent.exe C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin svchost.exe C:\Program Files\IDrive\IDriveE Service.exe C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\Fighters\SPAMfighter\sfus.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Fighters\FighterSuiteService.exe C:\Program Files\IDrive\IDriveETray.exe C:\Program Files\IDrive\IDriveEBackground.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\IDrive\IDrivePlugin.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Mozilla Firefox\firefox.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Plugin for Media Finder: {ad4df010-e2fd-43ce-864a-6bd1edc59ac2} - c:\documents and settings\denno\application data\media finder\extensions\IEPlugin32.dll BHO: Help the General-Search Project: {ca4520f3-ae13-4fb1-a513-58e23991c86d} - c:\docume~1\denno\applic~1\mediaf~1\extens~1\GENCRA~1.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [IDriveE Startup] "c:\program files\idrive\IDrvieEStartup.exe" Hide uRun: [InstallIQUpdater] "c:\program files\w3i\installiqupdater\InstallIQUpdater.exe" /silent /autorun uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Media Finder] "c:\program files\media finder\MF.exe" /opentotray mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [pdfFactory Pro Dispatcher v1] c:\windows\system32\spool\drivers\w32x86\2\fppdis1.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [EPSON Stylus Photo RX620 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9HA.EXE /P31 "EPSON Stylus Photo RX620 Series" /O5 "LPT1:" /M "Stylus Photo RX620" mRun: [EPSON Stylus Photo RX620 Series (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9HA.EXE /P40 "EPSON Stylus Photo RX620 Series (Copy 1)" /O6 "USB001" /M "Stylus Photo RX620" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe mRun: [CommonToolkitTray] c:\program files\fighters\tray\FightersTray.exe mRun: [sfagent] c:\program files\fighters\spamfighter\sfagent.exe mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime StartupFolder: c:\docume~1\denno\startm~1\programs\startup\idrive~1.lnk - c:\program files\idrive\IDriveEReg2ini.exe StartupFolder: c:\docume~1\denno\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\eventr~1.lnk - c:\program files\the print shop 23.1\Remind.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Download with &Media Finder - c:\program files\media finder\hook.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{CFF501FC-74FD-45DF-A444-135669F120CF} : DhcpNameServer = [removed] [removed] Notify: igfxcui - igfxdev.dll Notify: LMIinit - LMIinit.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\denno\application data\mozilla\firefox\profiles\bagfegyi.default\ FF - prefs.js: browser.search.selectedEngine - Bing FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z134&form=ZGAADF&install_date=20111124&q= FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\documents and settings\denno\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\oracle\javafx 2.0 runtime\bin\new_plugin\npjp2.dll FF - plugin: c:\windows\system32\npdeployJava1.dll FF - plugin: c:\windows\system32\npptools.dll FF - plugin: c:\windows\system32\npwmsdrm.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true . ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2012-2-4 64512] R2 IDriveE Service;IDriveE Service;c:\program files\idrive\IDriveE Service.exe [2011-6-18 157128] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-11-3 2152152] R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\logmein\x86\LMIGuardianSvc.exe [2011-7-6 374152] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2011-1-11 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2011-8-22 47640] R2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\fighters\spamfighter\sfus.exe [2011-12-20 215688] R2 Suite Service;Suite Service;c:\program files\fighters\FighterSuiteService.exe [2011-12-13 1324680] S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-11-3 15232] S4 LMIRfsClientNP;LMIRfsClientNP; [x] . =============== Created Last 30 ================ . 2012-03-02 21:17:04 ——– d—–w- c:\documents and settings\denno\application data\Media Finder 2012-03-01 01:40:27 ——– d—–w- c:\documents and settings\denno\local settings\application data\Google 2012-02-23 21:23:38 4448256 —-a-w- c:\windows\system32\GPhotos.scr 2012-02-16 06:14:53 3072 -c—-w- c:\windows\system32\dllcache\iacenc.dll 2012-02-16 06:14:53 3072 ——w- c:\windows\system32\iacenc.dll 2012-02-14 02:02:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll 2012-02-14 02:02:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll 2012-02-14 02:02:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll 2012-02-14 02:02:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll 2012-02-14 02:02:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll 2012-02-14 02:02:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll 2012-02-14 02:02:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll 2012-02-14 02:01:49 ——– d—–w- c:\documents and settings\denno\local settings\application data\Apple 2012-02-14 02:01:25 ——– d—–w- c:\documents and settings\denno\local settings\application data\Apple Computer . ==================== Find3M ==================== . 2012-02-27 14:47:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-08 04:12:11 87424 —-a-w- c:\windows\system32\LMIinit.dll 2012-02-08 04:12:11 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2012-02-08 04:12:11 52096 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2012-02-08 04:12:11 30592 —-a-w- c:\windows\system32\LMIport.dll 2012-02-06 04:05:18 141312 —-a-w- c:\windows\system32\javacpl.cpl 2012-02-04 04:12:10 16432 —-a-w- c:\windows\system32\lsdelete.exe 2012-02-03 09:22:18 1860096 —-a-w- c:\windows\system32\win32k.sys 2012-01-09 16:20:25 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2011-12-19 15:56:40 87424 —-a-w- c:\windows\system32\LMIinit.dll.000.bak 2011-12-19 08:13:37 832512 —-a-w- c:\windows\system32\wininet.dll 2011-12-19 08:13:37 1830912 ——w- c:\windows\system32\inetcpl.cpl 2011-12-19 08:13:36 78336 —-a-w- c:\windows\system32\ieencode.dll 2011-12-19 08:13:36 17408 —-a-w- c:\windows\system32\corpol.dll . ============= FINISH: 20:01:50.00 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 6/9/2011 12:56:50 PM System Uptime: 3/13/2012 4:35:46 PM (4 hours ago) . Motherboard: Dell Inc. | | 0CU409 Processor: Intel® Pentium® Dual CPU E2180 @ 2.00GHz | Socket 775 | 1995/200mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 298 GiB total, 257.485 GiB free. D: is CDROM (UDF) E: is FIXED (NTFS) - 233 GiB total, 194.427 GiB free. G: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP223: 12/14/2011 11:45:46 PM - System Checkpoint RP224: 12/15/2011 3:00:14 AM - Software Distribution Service 3.0 RP225: 12/16/2011 3:38:49 AM - System Checkpoint RP226: 12/17/2011 4:26:48 AM - System Checkpoint RP227: 12/18/2011 6:49:43 AM - System Checkpoint RP228: 12/19/2011 7:00:24 AM - System Checkpoint RP229: 12/19/2011 11:21:39 AM - Printer Driver LogMeIn Printer Driver Installed RP230: 12/20/2011 11:59:08 AM - System Checkpoint RP231: 12/21/2011 12:59:08 PM - System Checkpoint RP232: 12/29/2011 2:10:35 AM - System Checkpoint RP233: 12/30/2011 2:23:33 AM - System Checkpoint RP234: 12/31/2011 2:34:06 AM - System Checkpoint RP235: 1/1/2012 3:23:36 AM - System Checkpoint RP236: 1/2/2012 4:23:37 AM - System Checkpoint RP237: 1/3/2012 5:24:41 AM - System Checkpoint RP238: 1/4/2012 5:33:24 AM - System Checkpoint RP239: 1/5/2012 6:23:54 AM - System Checkpoint RP240: 1/5/2012 10:10:59 PM - Installed SPAMfighter. RP241: 1/6/2012 10:24:00 PM - System Checkpoint RP242: 1/7/2012 11:22:26 PM - System Checkpoint RP243: 1/8/2012 11:23:32 PM - System Checkpoint RP244: 1/9/2012 11:31:42 PM - System Checkpoint RP245: 1/10/2012 2:57:55 PM - Software Distribution Service 3.0 RP246: 1/11/2012 3:00:24 AM - Software Distribution Service 3.0 RP247: 1/12/2012 3:56:39 AM - System Checkpoint RP248: 1/13/2012 4:37:27 AM - System Checkpoint RP249: 1/14/2012 5:38:34 AM - System Checkpoint RP250: 1/15/2012 6:37:27 AM - System Checkpoint RP251: 1/16/2012 7:37:27 AM - System Checkpoint RP252: 1/17/2012 7:50:18 AM - System Checkpoint RP253: 1/18/2012 8:32:45 AM - System Checkpoint RP254: 1/19/2012 11:29:36 AM - System Checkpoint RP255: 1/20/2012 11:47:02 AM - System Checkpoint RP256: 1/21/2012 12:32:55 PM - System Checkpoint RP257: 1/22/2012 2:09:47 PM - System Checkpoint RP258: 1/23/2012 2:22:27 PM - System Checkpoint RP259: 1/24/2012 2:23:16 PM - System Checkpoint RP260: 1/25/2012 4:15:53 PM - System Checkpoint RP261: 1/26/2012 4:23:17 PM - System Checkpoint RP262: 1/27/2012 10:16:37 PM - System Checkpoint RP263: 1/28/2012 10:22:14 PM - System Checkpoint RP264: 1/29/2012 11:01:25 PM - System Checkpoint RP265: 1/30/2012 11:59:00 PM - System Checkpoint RP266: 1/31/2012 3:00:13 AM - Software Distribution Service 3.0 RP267: 2/1/2012 3:42:48 AM - System Checkpoint RP268: 2/2/2012 4:21:35 AM - System Checkpoint RP269: 2/3/2012 10:10:18 PM - Removed AVG 2012 RP270: 2/3/2012 10:11:38 PM - Removed AVG 2012 RP271: 2/3/2012 10:57:49 PM - Removed Ad-Aware RP272: 2/3/2012 11:00:36 PM - Installed Ad-Aware RP273: 2/3/2012 11:00:54 PM - Installed Ad-Aware RP274: 2/4/2012 11:28:10 PM - System Checkpoint RP275: 2/5/2012 11:05:14 PM - Installed Java™ 7 Update 2 RP276: 2/5/2012 11:05:38 PM - Installed JavaFX 2.0.2 RP277: 2/7/2012 12:37:55 AM - System Checkpoint RP278: 2/7/2012 10:25:25 AM - Removed Java™ 6 Update 26 RP279: 2/7/2012 11:13:00 PM - Printer Driver LogMeIn Printer Driver Installed RP280: 2/8/2012 11:15:38 PM - System Checkpoint RP281: 2/10/2012 12:15:39 AM - System Checkpoint RP282: 2/11/2012 1:16:45 AM - System Checkpoint RP283: 2/12/2012 2:16:43 AM - System Checkpoint RP284: 2/13/2012 3:15:39 AM - System Checkpoint RP285: 2/13/2012 9:02:19 PM - Installed QuickTime RP286: 2/14/2012 9:16:02 PM - System Checkpoint RP287: 2/15/2012 9:17:07 PM - System Checkpoint RP288: 2/16/2012 3:00:13 AM - Software Distribution Service 3.0 RP289: 2/17/2012 3:39:28 AM - System Checkpoint RP290: 2/18/2012 5:04:47 AM - System Checkpoint RP291: 2/19/2012 5:25:57 AM - System Checkpoint RP292: 2/20/2012 6:36:02 AM - System Checkpoint RP293: 2/21/2012 7:13:59 AM - System Checkpoint RP294: 2/22/2012 7:49:39 AM - System Checkpoint RP295: 2/23/2012 8:13:58 AM - System Checkpoint RP296: 2/24/2012 9:13:59 AM - System Checkpoint RP297: 2/25/2012 9:23:13 AM - System Checkpoint RP298: 2/26/2012 10:14:00 AM - System Checkpoint RP299: 2/27/2012 10:54:20 AM - System Checkpoint RP300: 2/28/2012 11:49:33 AM - System Checkpoint RP301: 2/29/2012 11:50:39 AM - System Checkpoint RP302: 2/29/2012 8:40:53 PM - Installed Windows XP – Software Updates KB952011. RP303: 3/1/2012 8:49:35 PM - System Checkpoint RP304: 3/2/2012 9:22:08 PM - System Checkpoint RP305: 3/3/2012 9:55:05 PM - System Checkpoint RP306: 3/4/2012 11:18:23 PM - System Checkpoint RP307: 3/6/2012 12:34:42 AM - System Checkpoint RP308: 3/7/2012 12:58:16 AM - System Checkpoint RP309: 3/8/2012 1:57:05 AM - System Checkpoint RP310: 3/9/2012 2:02:45 AM - System Checkpoint RP311: 3/10/2012 2:13:21 AM - System Checkpoint RP312: 3/11/2012 3:43:24 AM - System Checkpoint RP313: 3/12/2012 4:43:24 AM - System Checkpoint RP314: 3/13/2012 4:55:24 AM - System Checkpoint RP315: 3/13/2012 3:43:10 PM - Software Distribution Service 3.0 . ==== Installed Programs ====================== . 100% Free Chess 7.30 123 Free Solitaire 2011 v8.0 Ad-Aware Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Adobe Photoshop 7.0 Adobe Reader X (10.1.2) Apple Application Support Apple Software Update azzCardfile 4.1 Dell Resource CD Desktop Taipei version 2.2 EASEUS Data Recovery Wizard Free Edition 5.5.1 EPSON Printer Software EPSON Scan ESET Online Scanner v3 File Type Assistant FinalTorrent 2011 FinePrint pdfFactory Pro Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB2633952) IDrive version 3.4.1 July 27, 2011 InstaCodecs InstallIQ Updater Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections 12.1.12.0 Java Auto Updater Java™ 7 Update 2 JavaFX 2.0.2 LivePix 1.1 LogMeIn Macromedia Dreamweaver MX Macromedia Extension Manager MagicCute Data Recovery 2011.1 Malwarebytes Anti-Malware version 1.60.1.1000 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Web Publishing Wizard 1.52 Mozilla Firefox 10.0.2 (x86 en-US) Nero NetAssistant NetAssistant for Firefox NVIDIA Drivers OpenOffice.org 3.3 Picasa 3 QuickTime REALTEK GbE & FE Ethernet PCI NIC Driver Realtek High Definition Audio Driver Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 7 (KB2497640) Security Update for Windows Internet Explorer 7 (KB2530548) Security Update for Windows Internet Explorer 7 (KB2544521) Security Update for Windows Internet Explorer 7 (KB2559049) Security Update for Windows Internet Explorer 7 (KB2586448) Security Update for Windows Internet Explorer 7 (KB2618444) Security Update for Windows Internet Explorer 7 (KB2647516) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2618451) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2621440) Security Update for Windows XP (KB2624667) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2633171) Security Update for Windows XP (KB2639417) Security Update for Windows XP (KB2641653) Security Update for Windows XP (KB2646524) Security Update for Windows XP (KB2647518) Security Update for Windows XP (KB2660465) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB923789) Sothink FLV Player SPAMfighter svBuilder The Print Shop 23.1 Unity Web Player Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB2641690) WebFldrs XP Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 . ==== Event Viewer Messages From Past Week ======== . 3/8/2012 3:10:23 AM, error: Removable Storage Service [111] - RSM could not load media in drive Drive 0 of library Generic Storage Device USB Device. 3/10/2012 1:31:29 AM, error: Dhcp [1002] - The IP address lease 192.168.172.50 for the Network Card with network address 001D098C2B91 has been denied by the DHCP server 192.168.172.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== 20:06:10.0656 1540 TDSS rootkit removing tool [removed] Mar 9 2012 17:10:43 20:06:11.0046 1540 ============================================================ 20:06:11.0046 1540 Current date / time: 2012/03/13 20:06:11.0046 20:06:11.0046 1540 SystemInfo: 20:06:11.0046 1540 20:06:11.0046 1540 OS Version: 5.1.2600 ServicePack: 3.0 20:06:11.0046 1540 Product type: Workstation 20:06:11.0046 1540 ComputerName: SHERIFFJOHN 20:06:11.0046 1540 UserName: Denno 20:06:11.0046 1540 Windows directory: C:\WINDOWS 20:06:11.0046 1540 System windows directory: C:\WINDOWS 20:06:11.0046 1540 Processor architecture: Intel x86 20:06:11.0046 1540 Number of processors: 2 20:06:11.0046 1540 Page size: 0x1000 20:06:11.0046 1540 Boot type: Normal boot 20:06:11.0046 1540 ============================================================ 20:06:12.0187 1540 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 20:06:12.0218 1540 Drive \Device\Harddisk1\DR1 - Size: 0x3A35294400 (232.83 Gb), SectorSize: 0x200, Cylinders: 0x76BA, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 20:06:12.0218 1540 \Device\Harddisk0\DR0: 20:06:12.0218 1540 MBR used 20:06:12.0218 1540 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x254297C1 20:06:12.0218 1540 \Device\Harddisk1\DR1: 20:06:12.0218 1540 MBR used 20:06:12.0218 1540 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x17886, BlocksNum 0x1D189832 20:06:12.0328 1540 Initialize success 20:06:12.0328 1540 ============================================================ 20:06:30.0687 3184 ============================================================ 20:06:30.0687 3184 Scan started 20:06:30.0687 3184 Mode: Manual; 20:06:30.0687 3184 ============================================================ 20:06:30.0875 3184 Abiosdsk - ok 20:06:30.0890 3184 abp480n5 - ok 20:06:30.0937 3184 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 20:06:30.0937 3184 ACPI - ok 20:06:30.0968 3184 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 20:06:30.0968 3184 ACPIEC - ok 20:06:30.0968 3184 adpu160m - ok 20:06:31.0015 3184 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 20:06:31.0015 3184 aec - ok 20:06:31.0046 3184 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 20:06:31.0046 3184 AFD - ok 20:06:31.0062 3184 Aha154x - ok 20:06:31.0062 3184 aic78u2 - ok 20:06:31.0078 3184 aic78xx - ok 20:06:31.0078 3184 AliIde - ok 20:06:31.0093 3184 amsint - ok 20:06:31.0109 3184 asc - ok 20:06:31.0109 3184 asc3350p - ok 20:06:31.0109 3184 asc3550 - ok 20:06:31.0171 3184 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 20:06:31.0171 3184 AsyncMac - ok 20:06:31.0203 3184 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 20:06:31.0203 3184 atapi - ok 20:06:31.0203 3184 Atdisk - ok 20:06:31.0234 3184 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 20:06:31.0234 3184 Atmarpc - ok 20:06:31.0281 3184 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 20:06:31.0281 3184 audstub - ok 20:06:31.0312 3184 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 20:06:31.0312 3184 Beep - ok 20:06:31.0375 3184 catchme - ok 20:06:31.0421 3184 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 20:06:31.0421 3184 cbidf2k - ok 20:06:31.0421 3184 cd20xrnt - ok 20:06:31.0453 3184 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 20:06:31.0453 3184 Cdaudio - ok 20:06:31.0468 3184 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 20:06:31.0468 3184 Cdfs - ok 20:06:31.0484 3184 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 20:06:31.0500 3184 Cdrom - ok 20:06:31.0515 3184 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 20:06:31.0515 3184 cercsr6 - ok 20:06:31.0515 3184 Changer - ok 20:06:31.0531 3184 CmdIde - ok 20:06:31.0546 3184 Cpqarray - ok 20:06:31.0546 3184 dac2w2k - ok 20:06:31.0562 3184 dac960nt - ok 20:06:31.0578 3184 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 20:06:31.0578 3184 Disk - ok 20:06:31.0625 3184 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 20:06:31.0640 3184 dmboot - ok 20:06:31.0656 3184 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 20:06:31.0656 3184 dmio - ok 20:06:31.0687 3184 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 20:06:31.0687 3184 dmload - ok 20:06:31.0687 3184 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 20:06:31.0687 3184 DMusic - ok 20:06:31.0703 3184 dpti2o - ok 20:06:31.0718 3184 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 20:06:31.0718 3184 drmkaud - ok 20:06:31.0734 3184 e1express (34aaa3b298a852b3663e6e0d94d12945) C:\WINDOWS\system32\DRIVERS\e1e5132.sys 20:06:31.0734 3184 e1express - ok 20:06:31.0750 3184 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 20:06:31.0750 3184 Fastfat - ok 20:06:31.0781 3184 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 20:06:31.0781 3184 Fdc - ok 20:06:31.0781 3184 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 20:06:31.0781 3184 Fips - ok 20:06:31.0796 3184 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 20:06:31.0796 3184 Flpydisk - ok 20:06:31.0828 3184 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 20:06:31.0828 3184 FltMgr - ok 20:06:31.0828 3184 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 20:06:31.0828 3184 Fs_Rec - ok 20:06:31.0843 3184 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 20:06:31.0843 3184 Ftdisk - ok 20:06:31.0859 3184 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 20:06:31.0859 3184 Gpc - ok 20:06:31.0890 3184 hamachi (833051c6c6c42117191935f734cfbd97) C:\WINDOWS\system32\DRIVERS\hamachi.sys 20:06:31.0890 3184 hamachi - ok 20:06:31.0921 3184 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 20:06:31.0921 3184 HDAudBus - ok 20:06:31.0937 3184 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 20:06:31.0937 3184 hidusb - ok 20:06:31.0953 3184 hpn - ok 20:06:31.0984 3184 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 20:06:31.0984 3184 HTTP - ok 20:06:32.0000 3184 i2omgmt - ok 20:06:32.0000 3184 i2omp - ok 20:06:32.0125 3184 ialm (28423512370705aeda6a652fedb25468) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys 20:06:32.0218 3184 ialm - ok 20:06:32.0234 3184 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 20:06:32.0234 3184 Imapi - ok 20:06:32.0234 3184 ini910u - ok 20:06:32.0328 3184 IntcAzAudAddService (17bbbabb21f86b650b2626045a9d016c) C:\WINDOWS\system32\drivers\RtkHDAud.sys 20:06:32.0390 3184 IntcAzAudAddService - ok 20:06:32.0406 3184 IntelIde - ok 20:06:32.0421 3184 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 20:06:32.0421 3184 intelppm - ok 20:06:32.0453 3184 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 20:06:32.0453 3184 Ip6Fw - ok 20:06:32.0484 3184 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 20:06:32.0484 3184 IpFilterDriver - ok 20:06:32.0500 3184 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 20:06:32.0500 3184 IpInIp - ok 20:06:32.0500 3184 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 20:06:32.0500 3184 IpNat - ok 20:06:32.0515 3184 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 20:06:32.0515 3184 IPSec - ok 20:06:32.0515 3184 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 20:06:32.0515 3184 IRENUM - ok 20:06:32.0546 3184 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 20:06:32.0546 3184 isapnp - ok 20:06:32.0546 3184 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 20:06:32.0546 3184 Kbdclass - ok 20:06:32.0562 3184 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 20:06:32.0562 3184 kbdhid - ok 20:06:32.0593 3184 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 20:06:32.0593 3184 kmixer - ok 20:06:32.0625 3184 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 20:06:32.0625 3184 KSecDD - ok 20:06:32.0703 3184 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys 20:06:32.0703 3184 Lavasoft Kernexplorer - ok 20:06:32.0734 3184 Lbd (336abe8721cbc3110f1c6426da633417) C:\WINDOWS\system32\DRIVERS\Lbd.sys 20:06:32.0734 3184 Lbd - ok 20:06:32.0734 3184 lbrtfdc - ok 20:06:32.0765 3184 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys 20:06:32.0765 3184 LMIInfo - ok 20:06:32.0781 3184 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys 20:06:32.0781 3184 lmimirr - ok 20:06:32.0781 3184 LMIRfsClientNP - ok 20:06:32.0796 3184 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys 20:06:32.0796 3184 LMIRfsDriver - ok 20:06:32.0796 3184 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 20:06:32.0796 3184 mnmdd - ok 20:06:32.0812 3184 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 20:06:32.0812 3184 Modem - ok 20:06:32.0828 3184 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 20:06:32.0828 3184 Mouclass - ok 20:06:32.0843 3184 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 20:06:32.0843 3184 mouhid - ok 20:06:32.0859 3184 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 20:06:32.0859 3184 MountMgr - ok 20:06:32.0859 3184 mraid35x - ok 20:06:32.0875 3184 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 20:06:32.0875 3184 MRxDAV - ok 20:06:32.0921 3184 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 20:06:32.0921 3184 MRxSmb - ok 20:06:32.0921 3184 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 20:06:32.0937 3184 Msfs - ok 20:06:32.0953 3184 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 20:06:32.0953 3184 MSKSSRV - ok 20:06:32.0968 3184 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 20:06:32.0968 3184 MSPCLOCK - ok 20:06:32.0968 3184 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 20:06:32.0968 3184 MSPQM - ok 20:06:32.0984 3184 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 20:06:32.0984 3184 mssmbios - ok 20:06:33.0000 3184 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 20:06:33.0000 3184 Mup - ok 20:06:33.0031 3184 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 20:06:33.0031 3184 NDIS - ok 20:06:33.0046 3184 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 20:06:33.0046 3184 NdisTapi - ok 20:06:33.0062 3184 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 20:06:33.0062 3184 Ndisuio - ok 20:06:33.0062 3184 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 20:06:33.0062 3184 NdisWan - ok 20:06:33.0093 3184 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 20:06:33.0093 3184 NDProxy - ok 20:06:33.0109 3184 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 20:06:33.0109 3184 NetBIOS - ok 20:06:33.0125 3184 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 20:06:33.0125 3184 NetBT - ok 20:06:33.0140 3184 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 20:06:33.0140 3184 Npfs - ok 20:06:33.0171 3184 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 20:06:33.0171 3184 Ntfs - ok 20:06:33.0203 3184 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 20:06:33.0203 3184 Null - ok 20:06:33.0218 3184 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 20:06:33.0234 3184 NwlnkFlt - ok 20:06:33.0234 3184 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 20:06:33.0234 3184 NwlnkFwd - ok 20:06:33.0281 3184 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 20:06:33.0281 3184 Parport - ok 20:06:33.0281 3184 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 20:06:33.0281 3184 PartMgr - ok 20:06:33.0296 3184 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 20:06:33.0296 3184 ParVdm - ok 20:06:33.0312 3184 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 20:06:33.0312 3184 PCI - ok 20:06:33.0328 3184 PCIDump - ok 20:06:33.0328 3184 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 20:06:33.0328 3184 PCIIde - ok 20:06:33.0343 3184 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 20:06:33.0343 3184 Pcmcia - ok 20:06:33.0359 3184 PDCOMP - ok 20:06:33.0359 3184 PDFRAME - ok 20:06:33.0375 3184 PDRELI - ok 20:06:33.0375 3184 PDRFRAME - ok 20:06:33.0375 3184 perc2 - ok 20:06:33.0390 3184 perc2hib - ok 20:06:33.0406 3184 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 20:06:33.0406 3184 PptpMiniport - ok 20:06:33.0421 3184 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 20:06:33.0421 3184 PSched - ok 20:06:33.0437 3184 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 20:06:33.0437 3184 Ptilink - ok 20:06:33.0437 3184 ql1080 - ok 20:06:33.0453 3184 Ql10wnt - ok 20:06:33.0453 3184 ql12160 - ok 20:06:33.0468 3184 ql1240 - ok 20:06:33.0468 3184 ql1280 - ok 20:06:33.0500 3184 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 20:06:33.0500 3184 RasAcd - ok 20:06:33.0500 3184 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 20:06:33.0500 3184 Rasl2tp - ok 20:06:33.0515 3184 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 20:06:33.0515 3184 RasPppoe - ok 20:06:33.0515 3184 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 20:06:33.0515 3184 Raspti - ok 20:06:33.0531 3184 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 20:06:33.0531 3184 Rdbss - ok 20:06:33.0546 3184 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 20:06:33.0546 3184 RDPCDD - ok 20:06:33.0578 3184 RDPWD (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys 20:06:33.0578 3184 RDPWD - ok 20:06:33.0593 3184 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 20:06:33.0609 3184 redbook - ok 20:06:33.0640 3184 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 20:06:33.0656 3184 Secdrv - ok 20:06:33.0656 3184 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 20:06:33.0656 3184 Serial - ok 20:06:33.0687 3184 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys 20:06:33.0687 3184 Sfloppy - ok 20:06:33.0687 3184 Simbad - ok 20:06:33.0703 3184 Sparrow - ok 20:06:33.0734 3184 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 20:06:33.0734 3184 splitter - ok 20:06:33.0750 3184 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 20:06:33.0750 3184 sr - ok 20:06:33.0781 3184 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 20:06:33.0796 3184 Srv - ok 20:06:33.0796 3184 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 20:06:33.0796 3184 swenum - ok 20:06:33.0828 3184 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 20:06:33.0828 3184 swmidi - ok 20:06:33.0843 3184 symc810 - ok 20:06:33.0843 3184 symc8xx - ok 20:06:33.0859 3184 sym_hi - ok 20:06:33.0859 3184 sym_u3 - ok 20:06:33.0890 3184 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 20:06:33.0890 3184 sysaudio - ok 20:06:33.0921 3184 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 20:06:33.0937 3184 Tcpip - ok 20:06:33.0953 3184 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 20:06:33.0953 3184 TDPIPE - ok 20:06:33.0968 3184 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 20:06:33.0968 3184 TDTCP - ok 20:06:33.0968 3184 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 20:06:33.0968 3184 TermDD - ok 20:06:33.0984 3184 TosIde - ok 20:06:34.0000 3184 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 20:06:34.0000 3184 Udfs - ok 20:06:34.0000 3184 ultra - ok 20:06:34.0046 3184 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 20:06:34.0062 3184 Update - ok 20:06:34.0078 3184 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 20:06:34.0093 3184 usbccgp - ok 20:06:34.0093 3184 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 20:06:34.0093 3184 usbehci - ok 20:06:34.0109 3184 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 20:06:34.0109 3184 usbhub - ok 20:06:34.0125 3184 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 20:06:34.0125 3184 usbprint - ok 20:06:34.0140 3184 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 20:06:34.0140 3184 usbscan - ok 20:06:34.0171 3184 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 20:06:34.0171 3184 USBSTOR - ok 20:06:34.0171 3184 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20:06:34.0187 3184 usbuhci - ok 20:06:34.0187 3184 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 20:06:34.0187 3184 VgaSave - ok 20:06:34.0203 3184 ViaIde - ok 20:06:34.0203 3184 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 20:06:34.0203 3184 VolSnap - ok 20:06:34.0218 3184 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 20:06:34.0218 3184 Wanarp - ok 20:06:34.0234 3184 WDICA - ok 20:06:34.0250 3184 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 20:06:34.0250 3184 wdmaud - ok 20:06:34.0296 3184 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 20:06:34.0296 3184 WS2IFSL - ok 20:06:34.0328 3184 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 20:06:34.0328 3184 WudfPf - ok 20:06:34.0343 3184 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 20:06:34.0343 3184 WudfRd - ok 20:06:34.0375 3184 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 20:06:34.0531 3184 \Device\Harddisk0\DR0 - ok 20:06:34.0531 3184 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 20:06:34.0671 3184 \Device\Harddisk1\DR1 - ok 20:06:34.0671 3184 Boot (0x1200) (a8a140787998a5c70cf81abcf17345e9) \Device\Harddisk0\DR0\Partition0 20:06:34.0671 3184 \Device\Harddisk0\DR0\Partition0 - ok 20:06:34.0671 3184 Boot (0x1200) (40adc77757f6bb70d051223cb29a22cf) \Device\Harddisk1\DR1\Partition0 20:06:34.0671 3184 \Device\Harddisk1\DR1\Partition0 - ok 20:06:34.0671 3184 ============================================================ 20:06:34.0671 3184 Scan finished 20:06:34.0671 3184 ============================================================ 20:06:34.0687 3092 Detected object count: 0 20:06:34.0687 3092 Actual detected object count: 0
You have a couple of Browser helper object for Media Finder that I would remove it were me, but I doubt the are causing any of the issues you are experiencing. LIkewise you have the QUpdater installed which I personally would not want on my machine, but again, that is a personal preference, and I doubt it has anything to do with your issues of locking up.

Now on to some of the things that might be causing some of your problems. I do notice that you have Internet Explorer 7 on the machine. I realize from your previous postst that IE is not your default browser, but since IE 7 is very outdated, your system is probably constantly trying to update this and that is probably slowing your system down significantly and may be part of the cause of your lockups. I would suggest you go ahead and update this to IE 9 even if you don't intend to use it very often. This will eliminate one possibility that could be causing issues for you.

I also see that you are using Lavasoft Adwatch/AntiVirus as your AntiVirus solution. I know that you previously also had AVG on the system. AVG is certainly known to slow down systems, and removing it was probably a wise choice. However, Lavasoft is not a product well known for it's AntiVirus solution. While it may very well be a good product, it would not be one that I could personally endorse and tell you would be a good option. I might suggest you try Microsoft Security Essentials instead. I personally use this on my machines. It is lightweight and does not bog my system down at all. It updates with Windows updates and I've had no problems with any malware making it through. The choice is obviously yours. You should always use programs to you feel comfortable with when protecting your machine. Whichever you choose, you should only have one antivirus program installed on your machine at a time otherwise you will have conflicts.

At this point, your issues do not appear to be related to malware and I'd like to refer you to our Windows Forum for additional help. When posting there, please feel free to include a link to this post in case they need to see any information contained in the logs.
OK I don't mind getting rid of the things you mention, if you can tell me how. I am in the process of installing MSE now. Can't upgrade past IE 8, as I am using XP. Think I should do that? Otherwise, I will proceed to the other forum. Thanks, denno
Yes, IE 8 will be sufficient. It should stop IE from trying to update all the time.

As for getting rid of the items I mentioned, the fastest and easiest way is to probably download HijackThis (you can grab a copy from our preliminary posting page http://forums.whatthetech.com/index.php?showtopic=106388 it's tool #2 and post a log for me. (The instructions are all right there on how to run the tool.) I'll tell you which boxes to check and then we'll just run a quick fix and it should be that simple. HijackThis is an outdated tool for most things, but when it comes to something like this, believe it or not, it's one of the fastest ways to address browser helper objects :)
Thanks, Doris
Here's the logfile, and I will update to IE8

denno








Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:01:35 AM, on 3/14/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17108)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fppdis1.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Fighters\Tray\FightersTray.exe
C:\Program Files\Fighters\SPAMfighter\sfagent.exe
C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\IDrive\IDriveE Service.exe
C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Fighters\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fighters\FighterSuiteService.exe
C:\Program Files\IDrive\IDriveETray.exe
C:\Program Files\IDrive\IDriveEBackground.exe
C:\Program Files\IDrive\IDrivePlugin.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Denno\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEWebHook - {AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2} - C:\Documents and Settings\Denno\Application Data\Media Finder\Extensions\IEPlugin32.dll
O2 - BHO: Help the General-Search Project - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - C:\DOCUME~1\Denno\APPLIC~1\MEDIAF~1\EXTENS~1\GENCRA~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v1] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\fppdis1.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE /P31 "EPSON Stylus Photo RX620 Series" /O5 "LPT1:" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HA.EXE /P40 "EPSON Stylus Photo RX620 Series (Copy 1)" /O6 "USB001" /M "Stylus Photo RX620"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CommonToolkitTray] C:\Program Files\Fighters\Tray\FightersTray.exe
O4 - HKLM\..\Run: [sfagent] C:\Program Files\Fighters\SPAMfighter\sfagent.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [IDriveE Startup] "C:\Program Files\IDrive\IDrvieEStartup.exe" Hide
O4 - HKCU\..\Run: [InstallIQUpdater] "C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Media Finder] "C:\Program Files\Media Finder\MF.exe" /opentotray
O4 - Startup: IDrive Tray.lnk = C:\Program Files\IDrive\IDriveEReg2ini.exe
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\The Print Shop 23.1\Remind.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IDriveE Service - Pro Softnet Corporation - C:\Program Files\IDrive\IDriveE Service.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\Fighters\SPAMfighter\sfus.exe
O23 - Service: Suite Service - SPAMfighter ApS - C:\Program Files\Fighters\FighterSuiteService.exe

–
End of file - 7215 bytes
Sorry for the delay - it was a very busy day at work.



Run Hijack This
  • Double click on the icon on your desktop to launch Hijack This
  • Click on the Scan button
  • When the scan has finished, please put a check in the box next to the following item:

    O2 - BHO: IEWebHook - {AD4DF010-E2FD-43CE-864A-6BD1EDC59AC2} - C:\Documents and Settings\Denno\Application Data\Media Finder\Extensions\IEPlugin32.dll
    O2 - BHO: Help the General-Search Project - {CA4520F3-AE13-4FB1-A513-58E23991C86D} - C:\DOCUME~1\Denno\APPLIC~1\MEDIAF~1\EXTENS~1\GENCRA~1.DLL
    O4 - HKCU\..\Run: [InstallIQUpdater] "C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
    O8 - Extra context menu item: Download with &Media Finder - C:\Program Files\Media Finder\hook.html


  • Make sure all other windows, including your browser are closed, and then click on the Fix Checked button
If you are not prompted to do so, please reboot your computer after the fix has completed.


Have you noticed any improvements yet? Or has there not been enough time to really tell yet? Another thing you might want to do before you head over to the Windows forum is to make sure you have all your optional Windows updates installed. Many people have their critical updates set to install automatically, but don't realize there may be optional updates that they don't even know about. You can find these by visiting the Windows Update Site.

Visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them and immediately, reboot your computer, then revisit the site until there are no more critical or optional updates. These updates often build upon each other so it is important to continue to revisit the site after each installation until you are sure you have them all. I'd recommend doing this every few months to ensure you have all your optional updates installed.
OK, got rid of those items. I can't figure out any updates I need beyond the daily check for auto-updates. It's not telling me any such. I've begun a dialog at the other forum, going rather slowly. I have to figure out if I have a graphics card, and whether all the fans are working well. I'm only aware of two fans. They run quietly enough. I will see where that takes me. I won't know if the freezes have stopped until one happens, I suppose. Proving a negative, they say, is difficult. Thanks for your help so far. denno
I'll leave this thread open for a couple of days just in case you need any more help over here. Good luck in the Windows forum. Troubleshooting these things can be tough. I wish you luck!! Let me know if I can be of any further assistance. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI