This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

was Occasionally slow intermittent freezing

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry about not getting back to you Conspire, a family illness meant i was away from home fopr a few days Please find combifix log below Regards ComboFix 12-06-21.03 - Paul 22/06/2012 15:54:11.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.3582.2404 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: ESET Smart Security 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE} SP: ESET Smart Security 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Paul\AppData\Roaming\chrtmp c:\windows\system32\ctl3d32.1 c:\windows\TEMP\logishrd\LVPrcInj01.dll . Infected copy of c:\windows\system32\userinit.exe was found and disinfected Restored copy from - c:\windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe . . ((((((((((((((((((((((((( Files Created from 2012-05-22 to 2012-06-22 ))))))))))))))))))))))))))))))) . . 2012-06-22 15:01 . 2012-06-22 15:01 ——– d—–w- c:\users\Default\AppData\Local\temp 2012-06-21 17:29 . 2009-09-03 09:37 16640 —-a-w- c:\windows\system32\drivers\WsAudio_DeviceS(1).sys 2012-06-21 17:29 . 2012-06-21 17:29 ——– d—–w- c:\program files\Aimersoft 2012-06-18 14:34 . 2012-06-18 14:34 ——– d—–w- c:\users\Paul\AppData\Roaming\AccurateRip 2012-06-18 14:34 . 2012-06-18 14:33 6908648 —-a-w- c:\windows\system32\SpoonUninstall.exe 2012-06-18 14:34 . 2012-06-18 14:34 ——– d—–w- c:\program files\Illustrate 2012-06-15 16:31 . 2012-06-15 16:31 ——– d—–w- c:\users\Paul\AppData\Local\Macromedia 2012-06-13 15:00 . 2012-04-20 05:05 524800 —-a-w- c:\program files\Internet Explorer\jsdbgui.dll 2012-06-13 15:00 . 2012-04-20 05:08 672856 —-a-w- c:\program files\Internet Explorer\iexplore.exe 2012-06-13 15:00 . 2012-04-20 05:05 860672 —-a-w- c:\program files\Internet Explorer\iedvtool.dll 2012-06-13 14:58 . 2012-05-15 01:12 2342400 —-a-w- c:\windows\system32\win32k.sys 2012-06-11 13:36 . 2012-06-11 14:18 ——– d—–w- c:\program files\ZAR 2012-06-06 17:10 . 2012-06-06 17:10 770384 —-a-w- c:\program files\Mozilla Firefox\msvcr100.dll 2012-06-06 17:10 . 2012-06-06 17:10 421200 —-a-w- c:\program files\Mozilla Firefox\msvcp100.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-15 16:22 . 2012-03-29 17:38 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-06-15 16:22 . 2011-08-22 10:04 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-04-18 02:06 . 2012-05-14 14:02 6734704 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DD024132-539A-4E69-94CA-E2B1AA3E4653}\mpengine.dll 2012-04-11 18:53 . 2012-04-11 18:53 146 —-a-w- c:\windows\DelMR.bat 2012-04-02 04:46 . 2012-05-13 11:36 3902320 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-04-02 04:46 . 2012-05-13 11:36 3958128 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-03-30 10:29 . 2012-05-13 11:36 1287024 —-a-w- c:\windows\system32\drivers\tcpip.sys 2012-06-17 14:19 . 2011-05-14 14:18 85472 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. . [-] 2010-08-15 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll [7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension] @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}" [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}] 2012-02-08 00:49 22376 —-a-w- c:\program files\Internet Download Manager\IDMShellExt.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TaskTray"="c:\program files\Creative\SBAudigy\Taskbar\CTLTray.exe" [2001-06-29 163840] "SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2011-01-12 405736] "IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2012-04-02 3478936] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-22 402432] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-03-24 2145000] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288] "Disc Detector"="c:\program files\Creative\ShareDLL\CtNotify.exe" [2001-04-02 191488] "UpdReg"="c:\windows\Updreg.exe" [2000-05-11 90112] "Jet Detection"="c:\program files\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2001-04-20 28672] "Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-01-31 38840] "LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304] "CTHelper"="CTHELPER.EXE" [2010-03-18 19456] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824] "HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2012-04-17 651264] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\acaptuser32.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" -osboot . R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-15 257224] R3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2010-03-18 99416] R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-01-17 79360] R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-09-08 79360] R3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2010-03-18 555096] R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\System32\drivers\CTERFXFX.SYS [2010-03-18 100952] R3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2010-03-18 100952] R3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2010-03-18 566360] R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2009-11-11 22384] R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040] R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2012-06-17 113120] R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-11-21 1343400] S0 tdrpman273;Acronis Try&Decide; and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [2011-01-25 752128] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-03-24 114984] S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2011-01-25 3246040] S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-03-24 133512] S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-03-24 810120] S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-03-24 41312] S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2012-02-08 91936] S2 OS Selector;Acronis OS Selector activator;c:\program files\Acronis\DiskDirector\OSS\reinstall_svc.exe [2010-05-25 2139400] S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-03-23 87040] S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2012-01-23 92592] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2011-01-25 167968] S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\System32\drivers\COMMONFX.SYS [2010-03-18 99416] S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\System32\drivers\CTAUDFX.SYS [2010-03-18 555096] S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\System32\drivers\CTSBLFX.SYS [2010-03-18 566360] S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2009-09-03 16640] . . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-06-22 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-29 16:22] . . ——- Supplementary Scan ——- . uInternet Settings,ProxyOverride = *.local IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = [removed] [removed] DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab FF - ProfilePath - c:\users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\6yadk2mh.default\ FF - prefs.js: browser.startup.homepage - hxxps://signin.ebay.co.uk/ws/eBayISAPI.dll?SignIn&UsingSSL;=1&pUserId;=&co;_partnerId=2&siteid;=3&ru;=http%3A%2F%2Fmy.ebay.co.uk%2Fws%2FeBayISAPI.dll%3FMyEbayBeta%26MyeBay%3D%26%26guest%3D1%26guest%3D1&pageType;=3984 . . ——- File Associations ——- . .scr=AutoCADScriptFile . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-4190755858-323130236-2043102344-1001_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):ea,85,10,2f,1d,2a,83,22,db,cb,6f,74,12,2a,f6,e3,ee,58,56,14,77, f2,ba,ef,5e,f4,f7,b7,82,e0,8a,b9,a6,df,9d,d9,f1,33,bc,d2,00,00,00,00,00,00,\ . [HKEY_USERS\S-1-5-21-4190755858-323130236-2043102344-1001_Classes\CLSID\{ff74d375-e605-4f40-9c9a-db1042b5cbbf}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "Model"=dword:0000009c "Therad"=dword:00000009 "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a, 1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\ESET\ESET Security\CurrentVersion\Info] @Denied: (2) (LocalSystem) @SACL= "AppDataDir"="c:\\ProgramData\\ESET\\ESET Smart Security\\" "DataDir"="ESET\\ESET Smart Security\\" "EditionName"="BUSINESS EDITION" "InstallDir"="c:\\Program Files\\ESET\\ESET Smart Security\\" "LanguageId"=dword:00000409 "PackageTag"=dword:6090e758 "ProductBase"=dword:00000001 "ProductCode"="{9516A4F3-A620-4C4B-B17C-750C6B87AF4B}" "ProductName"="ESET Smart Security" "ProductType"="essbe" "ProductVersion"="4.2.40.0" "UniqueId"="0017E4654C61C521" "ScannerBuild"=dword:00001a9b "ScannerVersionId"=dword:0000136c "ScannerVersion"="Locked/open ESET for status." . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'lsass.exe'(876) c:\windows\system32\relog_ap.DLL . - - - - - - - > 'Explorer.exe'(6368) c:\progra~1\SPYBOT~1\SDHelper.dll . ———————— Other Running Processes ———————— . c:\program files\Creative\Shared Files\CTAudSvc.exe c:\program files\Sandboxie\SbieSvc.exe c:\program files\Common Files\Acronis\Schedule2\schedul2.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\CTsvcCDA.EXE c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\windows\system32\taskhost.exe c:\windows\system32\conhost.exe c:\program files\Creative\ShareDLL\MediaDet.Exe c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe c:\program files\Microsoft IntelliPoint\dpupdchk.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2012-06-22 16:11:20 - machine was rebooted ComboFix-quarantined-files.txt 2012-06-22 15:11 . Pre-Run: 23,587,434,496 bytes free Post-Run: 23,343,771,648 bytes free . - - End Of File - - E1EFC7FAA2D5F85BC104DCFBA018770D
Hello, I Am Alander :)

Welcome to the Malware Removal forums.

I would be glad to take a look at your log and help you with solving any malware problems.

DDS logs can take a while to research so please be patient while I work on your log and I will post back here with any recommendations.

As I am still training, everything that I post to you, must be checked by an Admin or Moderator.

Thus, there may be a tiny bit of a delay between posts. While it shouldn't be too long, you can be assured you will get the best possible advice.

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download DDS by sUBs from one of the links below, save it to your Desktop (Note: It must be in this location).
  • Link 1
  • Link 2
Please disable any anti-malware program that will block scripts from running before running DDS.

  • Right-Click on dds.scr And select " Run as administrator "… and a command window will appear. This is normal.
  • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply
Hi Alander Thanks in advance Please find the requested logs below Regards . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_31 Run by [removed] at 14:10:01 on 2012-06-25 Microsoft Windows 7 Ultimate 6.1.7600.0.1252.44.1033.18.3582.2089 [GMT 1:00] . AV: ESET Smart Security 4.2 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5} SP: ESET Smart Security 4.2 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall *Enabled* {F3340042-195E-BB41-42D1-CDB495BB46DE} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Sandboxie\SbieSvc.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\CTsvcCDA.EXE C:\Program Files\ESET\ESET Smart Security\ekrn.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\ESET\ESET Smart Security\egui.exe C:\Program Files\Creative\ShareDLL\CTNotify.exe C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe C:\Windows\System32\CtHelper.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Creative\ShareDLL\MediaDet.Exe C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe C:\Program Files\Creative\SBAudigy\Taskbar\CTLTray.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\Program Files\Internet Download Manager\IEMonitor.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\svchost.exe -k SDRSVC C:\Windows\system32\WUDFHost.exe C:\Windows\explorer.exe C:\Windows\explorer.exe C:\Windows\explorer.exe C:\Windows\explorer.exe C:\Windows\explorer.exe C:\Program Files\Microsoft Office\Office12\WINWORD.EXE C:\Windows\helppane.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_262.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\explorer.exe C:\Windows\system32\taskhost.exe C:\Program Files\WinRAR\WinRAR.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyOverride = *.local BHO: IDM integration (IDMIEHlprObj Class): {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: Spybot-S&D; IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: CatcherBHO Class: {9b4df450-dcc7-4b07-935d-0cd757a64583} - c:\program files\moyea\youtube flv downloader\MoyeaCatcher.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll uRun: [TaskTray] c:\program files\creative\sbaudigy\taskbar\CTLTray.exe uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe" uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe" mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [Disc Detector] c:\program files\creative\sharedll\CtNotify.exe mRun: [UpdReg] c:\windows\Updreg.exe mRun: [Jet Detection] c:\program files\creative\sbaudigy\program\ADGJDet.exe mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 9.0\acrobat\Acrobat_sl.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide mRun: [CTHelper] CTHELPER.EXE mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [HTC Sync Loader] "c:\program files\htc\htc sync 3.0\htcUPCTLoader.exe" -startup uPolicies-explorer: = mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) mPolicies-system: EnableLinkedConnections = 1 (0x1) IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm IE: Download with IDM - c:\program files\internet download manager\IEExt.htm IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/ocx/15118/CTPID.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{4AB9D0AF-141E-4A15-855D-69E02CC12DB7} : DhcpNameServer = [removed] [removed] AppInit_DLLs: c:\windows\system32\acaptuser32.dll LSA: Authentication Packages = msv1_0 relog_ap . ================= FIREFOX =================== . FF - ProfilePath - c:\users\paul\appdata\roaming\mozilla\firefox\profiles\6yadk2mh.default\ FF - prefs.js: browser.startup.homepage - hxxps://signin.ebay.co.uk/ws/eBayISAPI.dll?SignIn&UsingSSL;=1&pUserId;=&co;_partnerId=2&siteid;=3&ru;=http%3A%2F%2Fmy.ebay.co.uk%2Fws%2FeBayISAPI.dll%3FMyEbayBeta%26MyeBay%3D%26%26guest%3D1%26guest%3D1&pageType;=3984 FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\users\paul\appdata\roaming\mozilla\firefox\profiles\6yadk2mh.default\extensions\[removed]\plugins\npLogitechDeviceDetection.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_262.dll . ============= SERVICES / DRIVERS =============== . R0 tdrpman273;Acronis Try&Decide; and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [2011-1-26 752128] R2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files\common files\acronis\cdp\afcdpsrv.exe [2011-1-26 3246040] R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2010-3-24 133512] R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2010-3-24 810120] R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2010-3-24 41312] R2 IDMWFP;IDMWFP;c:\windows\system32\drivers\idmwfp.sys [2012-3-16 91936] R2 OS Selector;Acronis OS Selector activator;c:\program files\acronis\diskdirector\oss\reinstall_svc.exe [2010-5-25 2139400] R2 PassThru Service;Internet Pass-Through Service;c:\program files\htc\internet pass-through\PassThruSvr.exe [2012-3-23 87040] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-1-5 1153368] R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2012-1-23 92592] R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2011-1-26 167968] R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416] R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096] R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360] R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2011-1-12 117892] R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2012-6-21 16640] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-29 250056] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2010-3-18 99416] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2011-1-17 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2011-9-8 79360] S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2010-3-18 555096] S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952] S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2010-3-18 100952] S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2010-3-18 566360] S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2009-10-26 25088] S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-23 23040] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-5-4 113120] S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-11-21 1343400] . =============== Created Last 30 ================ . 2012-06-25 13:02:18 ——– d—–w- c:\users\paul\appdata\local\Apps 2012-06-25 10:05:21 2422272 —-a-w- c:\windows\system32\wucltux.dll 2012-06-25 10:04:50 33792 —-a-w- c:\windows\system32\wuapp.exe 2012-06-25 10:04:50 171904 —-a-w- c:\windows\system32\wuwebv.dll 2012-06-22 15:09:28 ——– d-sh–w- C:\$RECYCLE.BIN 2012-06-22 14:51:59 98816 —-a-w- c:\windows\sed.exe 2012-06-22 14:51:59 518144 —-a-w- c:\windows\SWREG.exe 2012-06-22 14:51:59 256000 —-a-w- c:\windows\PEV.exe 2012-06-22 14:51:59 208896 —-a-w- c:\windows\MBR.exe 2012-06-21 17:29:21 16640 —-a-w- c:\windows\system32\drivers\WsAudio_DeviceS(1).sys 2012-06-21 17:29:04 ——– d—–w- c:\program files\Aimersoft 2012-06-18 14:34:08 6908648 —-a-w- c:\windows\system32\SpoonUninstall.exe 2012-06-18 14:34:08 ——– d—–w- c:\users\paul\appdata\roaming\AccurateRip 2012-06-18 14:34:00 ——– d—–w- c:\program files\Illustrate 2012-06-15 16:31:59 ——– d—–w- c:\users\paul\appdata\local\Macromedia 2012-06-13 15:00:04 524800 —-a-w- c:\program files\internet explorer\jsdbgui.dll 2012-06-13 15:00:01 672856 —-a-w- c:\program files\internet explorer\iexplore.exe 2012-06-13 15:00:00 860672 —-a-w- c:\program files\internet explorer\iedvtool.dll 2012-06-13 14:58:34 2342400 —-a-w- c:\windows\system32\win32k.sys 2012-06-11 13:36:04 ——– d—–w- c:\program files\ZAR 2012-06-06 17:10:21 770384 —-a-w- c:\program files\mozilla firefox\msvcr100.dll 2012-06-06 17:10:21 421200 —-a-w- c:\program files\mozilla firefox\msvcp100.dll . ==================== Find3M ==================== . 2012-06-23 10:56:06 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-06-23 10:56:06 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-05-15 03:08:48 981504 —-a-w- c:\windows\system32\wininet.dll 2012-04-28 03:19:47 177152 —-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 04:48:52 57856 —-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 04:48:52 129536 —-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 04:43:14 8192 —-a-w- c:\windows\system32\rdrmemptylst.exe 2012-04-20 05:05:47 44544 —-a-w- c:\windows\system32\licmgr10.dll 2012-04-20 03:58:07 386048 —-a-w- c:\windows\system32\html.iec 2012-04-20 03:24:18 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2012-04-11 18:53:38 146 —-a-w- c:\windows\DelMR.bat 2012-04-02 04:46:44 3958128 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-04-02 04:46:44 3902320 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-03-30 10:29:05 1287024 —-a-w- c:\windows\system32\drivers\tcpip.sys . ============= FINISH: 14:10:54.94 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 15/07/2010 00:44:40 System Uptime: 25/06/2012 11:00:59 (3 hours ago) . Motherboard: Dell Inc. | | 0HJ054 Processor: Intel® Pentium® D CPU 3.40GHz | Microprocessor | 2380/800mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 75 GiB total, 20.781 GiB free. D: is FIXED (NTFS) - 104 GiB total, 65.584 GiB free. E: is FIXED (NTFS) - 95 GiB total, 75.338 GiB free. F: is FIXED (NTFS) - 30 GiB total, 27.371 GiB free. G: is CDROM () H: is CDROM () I: is FIXED (NTFS) - 564 GiB total, 553.621 GiB free. J: is FIXED (NTFS) - 293 GiB total, 151.376 GiB free. K: is Removable O: is FIXED (NTFS) - 0 GiB total, 0.004 GiB free. Q: is FIXED (NTFS) - 170 GiB total, 69.787 GiB free. R: is FIXED (NTFS) - 170 GiB total, 103.486 GiB free. S: is FIXED (NTFS) - 159 GiB total, 108.123 GiB free. U: is FIXED (NTFS) - 200 GiB total, 110.624 GiB free. . ==== Disabled Device Manager Items ============= . Class GUID: Description: Device ID: PCI\VEN_1102&DEV;_7003&SUBSYS;_00401102&REV;_03\4&5855BE9&0&11F0 Manufacturer: Name: PNP Device ID: PCI\VEN_1102&DEV;_7003&SUBSYS;_00401102&REV;_03\4&5855BE9&0&11F0 Service: . ==== System Restore Points =================== . RP247: 22/06/2012 15:52:04 - ComboFix created restore point RP249: 23/06/2012 20:46:01 - AusLogics RegDefrag before defragmentation. RP248: 25/06/2012 11:04:17 - Windows Update . ==== Installed Programs ====================== . 2007 Microsoft Office Suite Service Pack 2 (SP2) Able2Extract 7.0 Acronis Disk Director Home Acronis True Image Home 2011 Adobe Acrobat 9 Pro Extended - English, Français, Deutsch Adobe Acrobat 9.4.2 - CPSID_83708 Adobe AIR Adobe Community Help Adobe Flash Player 11 ActiveX Adobe Flash Player 11 Plugin Adobe Photoshop CS5 Adobe Photoshop Lightroom 2.7 Adobe Reader 9.4.2 Aimersoft Media Converter(Build [removed]) Apple Application Support Apple Mobile Device Support Apple Software Update Audacity 1.3.13 (Unicode) AusLogics BoostSpeed AutoCAD 2010 - English AutoCAD 2010 Language Pack - English Avery Wizard 3.1 BayGenie eBay Auction Sniper Pro Edition [removed] Bonjour Canon RAW Codec CCleaner CDDRV_Installer Chinese Simplified Fonts Support For Adobe Reader 9 Creative ALchemy Creative Audio Console Creative Software AutoUpdate Creative WaveStudio 7 dBpoweramp Music Converter EAGLE 5.11.0 EAGLE PCB Power Tools 5.06 EPSON Scan FLV Player HTC BMP USB Driver HTC Driver Installer HTC Sync Img2CAD 7.0 Internet Download Manager iriver Music Manager iTunes Java Auto Updater Java™ 6 Update 31 JDownloader KhalInstallWrapper Logitech Vid HD Logitech Webcam Software Logitech Webcam Software Driver Package Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Camera Codec Pack Microsoft IntelliPoint 8.2 Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Outlook Connector Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Plus 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 Moyea YouTube FLV Downloader version: 3.1.2.26 Mozilla Firefox 13.0.1 (x86 en-GB) Mozilla Maintenance Service Mozilla Thunderbird 13.0.1 (x86 en-US) Mp3tag v2.49 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP3 Parser MSXML 4.0 SP3 Parser (KB973685) MyPhoneExplorer OpenAL PDF Settings CS5 Plus Pack for Acronis True Image Home 2011 PoiEdit QuickTime RealNetworks - Microsoft Visual C++ 2008 Runtime RealPlayer RealUpgrade 1.1 SAMSUNG Mobile Composite Device Software SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Drive Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung PC Studio 3 Sandboxie 3.52 Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Skype™ 5.5 Sony Ericsson Symbian 9 Drivers SopCast 3.5.0 Sound Blaster Audigy Spybot - Search & Destroy TomTom HOME 2.8.3.2499 TomTom HOME Visual Studio Merge Modules Tyre Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Veetle TV 0.9.18 WinPatrol WinRAR 4.11 (32-bit) Zero Assumption Recovery Version 9 . ==== Event Viewer Messages From Past Week ======== . 25/06/2012 11:51:27, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk3\DR3. 25/06/2012 11:03:51, Error: Microsoft-Windows-DistributedCOM [10001] - Unable to start a DCOM Server: {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83} as /. The error: "5" Happened while starting this command: C:\Windows\System32\slui.exe -Embedding 25/06/2012 11:01:17, Error: Ntfs [137] - The default transaction resource manager on volume O: encountered a non-retryable error and could not start. The data contains the error code. 24/06/2012 08:45:50, Error: Microsoft-Windows-BitLocker-Driver [24620] - Encrypted volume check: Volume information on cannot be read. 24/06/2012 08:44:29, Error: Service Control Manager [7038] - The WdiServiceHost service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The request is not supported. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). 24/06/2012 08:44:29, Error: Service Control Manager [7038] - The netprofm service was unable to log on as NT AUTHORITY\LocalService with the currently configured password due to the following error: The security account manager (SAM) or local security authority (LSA) server was in the wrong state to perform the security operation. To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC). 24/06/2012 08:44:29, Error: Service Control Manager [7001] - The WLAN AutoConfig service depends on the Extensible Authentication Protocol service which failed to start because of the following error: The dependency service or group failed to start. 24/06/2012 08:44:29, Error: Service Control Manager [7001] - The Extensible Authentication Protocol service depends on the CNG Key Isolation service which failed to start because of the following error: A system shutdown is in progress. 24/06/2012 08:44:29, Error: Service Control Manager [7000] - The Portable Device Enumerator Service service failed to start due to the following error: A system shutdown is in progress. 24/06/2012 08:44:29, Error: Service Control Manager [7000] - The Network List Service service failed to start due to the following error: The service did not start due to a logon failure. 24/06/2012 08:44:29, Error: Service Control Manager [7000] - The Diagnostic Service Host service failed to start due to the following error: The service did not start due to a logon failure. 24/06/2012 08:44:29, Error: Service Control Manager [7000] - The CNG Key Isolation service failed to start due to the following error: A system shutdown is in progress. 24/06/2012 08:44:29, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1069" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 23/06/2012 13:16:16, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2. 22/06/2012 16:04:25, Error: Ntfs [137] - The default transaction resource manager on volume K: encountered a non-retryable error and could not start. The data contains the error code. 22/06/2012 16:04:09, Error: Ntfs [137] - The default transaction resource manager on volume \Device\HarddiskVolume9 encountered a non-retryable error and could not start. The data contains the error code. 22/06/2012 16:03:49, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the SBSD Security Center Service service to connect. 22/06/2012 16:03:49, Error: Service Control Manager [7000] - The SBSD Security Center Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 22/06/2012 15:57:51, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 22/06/2012 15:51:38, Error: Service Control Manager [7034] - The Process Monitor service terminated unexpectedly. It has done this 1 time(s). 22/06/2012 15:48:05, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR4. 22/06/2012 15:44:45, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk2\DR3. 22/06/2012 13:00:06, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk9\DR9. 22/06/2012 12:43:24, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. 22/06/2012 12:43:24, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error %%-1073473535. 20/06/2012 15:12:51, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk9\DR10. . ==== End Of File ===========================
Hi Alander Just had a bit of a problem acessing my documents in :C/, error message was access denied, i checked to permissions and found deny to be ticked, i was unable to change this (logged on as admin) i disabled network connections and set to indivdual permissions (in avg) and restarted pc, when pc restarted I got the message installing windows updates, I had not dowloaded any updates, my pc is not set to dowload or instal automatically. upon restart I am able to acess mydocuments ran an eset scan, found the following C:\hiberfil.sys - error opening C:\pagefile.sys - error opening also getting repeat requests (via avg) for microsoft media player network sharing (which I am not allowing) Dont know if any of these mean anything, Regards
Hi :)

Is this machine used for any kind of business activities? I need to know to give the appropriate instructions

May I know how you have obtained the folllowing softwares?
Microsoft Office Professional Plus 2007
AutoCAD 2010
Adobe Acrobat 9 Pro

Step 1
Please download MGA Diagnostic Tool and save it to your Desktop.

  • Right click on MGADiag.exe and select Run As Administrator to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in the window.
  • Save this file and copy/paste it in your next reply.

Step 2
CKScanner
Please download CKScanner … Save it to your desktop.
This program should only be run once!
Make sure that CKScanner.exe is on the your desktop before running the application!

  • Double-click on the CKScanner.exe icon… then click the Search For Files button.
  • When the scan is finished (the cursor hourglass disappears) click the Save List To File button.
    A text file will be created on your desktop named "ckfiles.txt"
  • Click OK at the file saved message box. Double-click on the ckfiles.txt icon on your desktop.
  • Please copy/paste the contents of ckfiles.txt in your next reply.
Step 3.
Please include in your next reply:
  • Any problem executing the instructions?
  • MGA Diagnostic Tool Log
  • CKScanner Log
Thanks
3 Day Response
Hi…
It has been 2 days since my last post to you.
  • Do you still need help with this problem?
  • Do you need more time?
  • Are you having problems understanding or following my instructions?
Just let me know what's going on otherwise…
After 24 hrs., if you have not replied to this thread… it will be closed!

3 Day Response
Hi…
It has been 2 days since my last post to you.

  • Do you still need help with this problem?
  • Do you need more time?
  • Are you having problems understanding or following my instructions?
Just let me know what's going on otherwise…
After 24 hrs., if you have not replied to this thread… it will be closed!


No problem understanding anything you hav easked
However virtually accusing me of having stolen software on my is taking the REMOVED<–LDT

However virtually accusing me of having stolen software

No one is accusing you of that.

WTT doesn't normally provide support for business owned computers as we would have no idea if the company allows 3rd party help.
5 Day Response
Hi…
It has been 4 days since my last post to you.
  • Do you still need help with this problem?
  • Do you need more time?
Just let me know what's going on otherwise…
After 24 hrs., if you have not replied to this thread… it will be closed!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI