This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New hand-me-down computer running very slow [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys. My old laptop broke and I found myself in need of a computer before my quarter at UCSD begins. My wifes sister had one back at her old place. She is not very computer savvy and trusts a lot of sites/downloads. As a result the computer is running VERY slow. It will randomly freeze for a couple of seconds, and has a very slow shut down. Anyways, I hope you guys can help me out!!

- Arrik Montijo

Sorry forgot the logs.

Here is my OTL.txt

=================================================================

OTL logfile created on: 9/8/2013 11:32:51 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:Documents and Settingsjanell brownMy DocumentsDownloads
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 451.85 Mb Available Physical Memory | 44.21% Memory free
2.40 Gb Paging File | 1.94 Gb Available in Paging File | 80.72% Paging File free
Paging file location(s): C:pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 144.32 Gb Total Space | 77.06 Gb Free Space | 53.40% Space Free | Partition Type: NTFS

Computer Name: DF8RS5B1 | User Name: janell brown | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:Documents and Settingsjanell brownMy DocumentsDownloadsOTL.exe (OldTimer Tools)
PRC - C:Program FilesJavajre7binjqs.exe (Oracle Corporation)
PRC - C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.)
PRC - C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe (Malwarebytes Corporation)
PRC - C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe (Malwarebytes Corporation)
PRC - C:Program FilesMalwarebytes' Anti-Malwarembamscheduler.exe (Malwarebytes Corporation)
PRC - C:Program FilesLogitechLWSWebcam SoftwareLWS.exe (Logitech Inc.)
PRC - C:Program FilesMcAfee.comPersonal FirewallMpfService.exe (McAfee Corporation)
PRC - C:Program FilesMcAfeeSpamKillerMSKSrvr.exe (McAfee Inc.)
PRC - C:Program FilesCommon FilesInstallShieldUpdateServiceagent.exe (InstallShield Software Corporation)
PRC - C:Program FilesDell SupportDSAgnt.exe (Gteko Ltd.)
PRC - C:WINDOWSexplorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:Program FilesGoogleChromeApplication29.0.1547.66ppgooglenaclpluginchrome.dll ()
MOD - C:Program FilesGoogleChromeApplication29.0.1547.66pdf.dll ()
MOD - C:Program FilesGoogleChromeApplication29.0.1547.66ffmpegsumo.dll ()
MOD - C:WINDOWSsystem32sbe.dll ()
MOD - C:Program FilesLogitechLWSWebcam SoftwareImageFormatsQJpeg4.dll ()
MOD - C:Program FilesLogitechLWSWebcam SoftwareImageFormatsQGif4.dll ()
MOD - C:Program FilesLogitechLWSWebcam SoftwareQTXml4.dll ()
MOD - C:Program FilesLogitechLWSWebcam SoftwareQTGui4.dll ()
MOD - C:Program FilesLogitechLWSWebcam SoftwareQTCore4.dll ()
MOD - C:WINDOWSsystem32quartz.dll ()
MOD - C:WINDOWSsystem32devenum.dll ()
MOD - C:WINDOWSsystem32tsd32.dll ()
MOD - C:WINDOWSsystem32msdmo.dll ()


===========================================
===========================================
==========================================

Extras.txt

==============================================

OTL Extras logfile created on: 9/8/2013 11:32:51 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:Documents and Settingsjanell brownMy DocumentsDownloads
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 451.85 Mb Available Physical Memory | 44.21% Memory free
2.40 Gb Paging File | 1.94 Gb Available in Paging File | 80.72% Paging File free
Paging file location(s): C:pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:WINDOWS | %ProgramFiles% = C:Program Files
Drive C: | 144.32 Gb Total Space | 77.06 Gb Free Space | 53.40% Space Free | Partition Type: NTFS

Computer Name: DF8RS5B1 | User Name: janell brown | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINESOFTWAREClasses]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – C:Program FilesGoogleChromeApplicationchrome.exe (Google Inc.)

[HKEY_CURRENT_USERSOFTWAREClasses]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINESOFTWAREClassesshell[command]command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:Program FilesGoogleChromeApplicationchrome.exe" – "%1" (Google Inc.)
https [open] – "C:Program FilesGoogleChromeApplicationchrome.exe" – "%1" (Google Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%system32rundll32.exe %SystemRoot%system32shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoring]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringAhnlabAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringKasperskyAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringMcAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringPandaFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSophosAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringSymantecFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTinyFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendAntiVirus]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringTrendFirewall]

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterMonitoringZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSr]
"Start" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfile]

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileGloballyOpenPortsList]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyDomainProfileAuthorizedApplicationsList]
"%windir%system32sessmgr.exe" = %windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:Program FilesCommon FilesAOLACSAOLacsd.exe" = C:Program FilesCommon FilesAOLACSAOLacsd.exe:*:Enabled:AOL
"C:Program FilesCommon FilesAOLACSAOLDial.exe" = C:Program FilesCommon FilesAOLACSAOLDial.exe:*:Enabled:AOL
"C:Program FilesAmerica Online 9.0waol.exe" = C:Program FilesAmerica Online 9.0waol.exe:*:Enabled:America Online 9.0

[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessParametersFi
rewallPolicyStandardProfileAuthorizedApplicationsList]
"%windir%system32sessmgr.exe" = %windir%system32sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 – (Microsoft Corporation)
"C:Program FilesCommon FilesAOLACSAOLacsd.exe" = C:Program FilesCommon FilesAOLACSAOLacsd.exe:*:Enabled:AOL
"C:Program FilesCommon FilesAOLACSAOLDial.exe" = C:Program FilesCommon FilesAOLACSAOLDial.exe:*:Enabled:AOL
"C:Program FilesAmerica Online 9.0waol.exe" = C:Program FilesAmerica Online 9.0waol.exe:*:Enabled:America Online 9.0
"C:Program FilesMessengermsmsgs.exe" = C:Program FilesMessengermsmsgs.exe:*:Enabled:Windows Messenger – (Microsoft Corporation)
"C:Documents and Settingsjanell brownLocal SettingsApplication DataGoogleGoogle Talk Plugingoogletalkplugin.exe" = C:Documents and Settingsjanell brownLocal SettingsApplication DataGoogleGoogle Talk Plugingoogletalkplugin.exe:*:Enabled:Google Talk Plugin
"C:Program FilesSkypePhoneSkype.exe" = C:Program FilesSkypePhoneSkype.exe:*:Enabled:Skype – (Skype Technologies S.A.)
"C:Program FilesLogitechVid HDVid.exe" = C:Program FilesLogitechVid HDVid.exe:*:Enabled:Logitech Vid HD – (Logitech Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstall]
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{352310C3-E46B-42D3-8F32-54721FDD72D9}" = NetZeroInstallers
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{4667B940-BB01-428B-986E-A0CC46497BF7}" = ELIcon
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"{548EEA8E-8299-497F-8057-811D2D7097DC}" = Dell Support 3.1
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{5B6BE547-21E2-49CA-B2E2-6A5F470593B1}" = Sonic Activation Module
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{83F793B5-8BBF-42FD-A8A6-868CB3E2AAEA}" = Intel® PROSet for Wired Connections
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D58AFD19-6736-A938-154A-EABEA741D2CC}" = AMD Catalyst Install Manager
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATI Display Driver" = ATI Display Driver
"CCleaner" = CCleaner
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"FileHippo.com" = FileHippo.com Update Checker
"Google Chrome" = Google Chrome
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie8" = Windows Internet Explorer 8
"InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"Logitech Vid" = Logitech Vid HD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PROSet" = Intel® PRO Network Connections Drivers
"Windows Media Format Runtime" = Windows Media Format Runtime

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/7/2013 7:17:30 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/7/2013 7:17:33 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/8/2013 2:27:50 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/8/2013 2:27:53 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/8/2013 2:27:56 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/8/2013 2:27:57 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/8/2013 2:28:01 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/8/2013 2:28:03 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/8/2013 2:28:06 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

Error - 9/8/2013 2:28:09 PM | Computer Name = DF8RS5B1 | Source = MsiInstaller | ID = 11706
Description = Product: Sonic Activation Module – Error 1706. An installation package
for the product Sonic Activation Module cannot be found. Try the installation again
using a valid copy of the installation package 'Activate.MSI'.

[ System Events ]
Error - 9/7/2013 1:59:07 PM | Computer Name = DF8RS5B1 | Source = Service Control Manager | ID = 7000
Description = The McAfee SpamKiller Server service failed to start due to the following
error: %%1053

Error - 9/7/2013 2:01:10 PM | Computer Name = DF8RS5B1 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service MskService
with arguments "" in order to run the server: {5109B8D8-73AF-4C41-A70E-73707E1F908A}

Error - 9/7/2013 2:01:11 PM | Computer Name = DF8RS5B1 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the McAfee SpamKiller Server
service to connect.

Error - 9/7/2013 2:01:11 PM | Computer Name = DF8RS5B1 | Source = Service Control Manager | ID = 7000
Description = The McAfee SpamKiller Server service failed to start due to the following
error: %%1053

Error - 9/7/2013 6:30:43 PM | Computer Name = DF8RS5B1 | Source = DCOM | ID = 10010
Description = The server {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} did not register
with DCOM within the required timeout.

Error - 9/7/2013 6:31:59 PM | Computer Name = DF8RS5B1 | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493}.
The
error: "%2" Happened while starting this command: c:program filesmcafee.comagentmcagent.exe
-Embedding

Error - 9/7/2013 7:08:51 PM | Computer Name = DF8RS5B1 | Source = Service Control Manager | ID = 7000
Description = The McAfee WSC Integration service failed to start due to the following
error: %%2

Error - 9/7/2013 7:09:44 PM | Computer Name = DF8RS5B1 | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 9/7/2013 7:10:34 PM | Computer Name = DF8RS5B1 | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {C7E39D60-7A9F-42BF-ABB1-03DC0FA4F493}.
The
error: "%2" Happened while starting this command: c:program filesmcafee.comagentmcagent.exe
-Embedding

Error - 9/8/2013 2:27:14 PM | Computer Name = DF8RS5B1 | Source = Service Control Manager | ID = 7000
Description = The McAfee WSC Integration service failed to start due to the following
error: %%2


< End of report >

:welcome:

Hello,

my name is Jo and I will help you with your computer problems.


Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.


Please follow these guidelines:
  • Logs can take a while to research, so please be patient.
  • Read and follow the instructions in the sequence they are posted.
  • print or copy & save instructions.
  • Do not install / uninstall any applications, unless otherwise instructed.
  • Use only that tools you have been instructed to use.
  • Copy and Paste the log files inside your post, unless otherwise instructed.
  • Ask for clarification, if you have any questions.
  • Stay with this topic ‘til you get the “all clean” post.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.
I will return as soon as possible with more instructions.
Hello Montijoar, looks like you didn't copy the entire OTL.txt. Please attach the OTL.txt to your next reply, it can be found at C:\Documents and Settings\janell brown\My Documents\Downloads Thanks.
Thank you very much Jo, I appreciate your time.

Sorry about that!!!

Here it is!



OTL logfile created on: 9/8/2013 11:32:51 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\janell brown\My Documents\Downloads
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.07 Mb Total Physical Memory | 451.85 Mb Available Physical Memory | 44.21% Memory free
2.40 Gb Paging File | 1.94 Gb Available in Paging File | 80.72% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.32 Gb Total Space | 77.06 Gb Free Space | 53.40% Space Free | Partition Type: NTFS

Computer Name: DF8RS5B1 | User Name: janell brown | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\janell brown\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\McAfee.com\Personal Firewall\MpfService.exe (McAfee Corporation)
PRC - C:\Program Files\McAfee\SpamKiller\MSKSrvr.exe (McAfee Inc.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.66\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll ()
MOD - C:\Program Files\Google\Chrome\Application\29.0.1547.66\ffmpegsumo.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\tsd32.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()


========== Services (SafeList) ==========

SRV - (McDetect.exe) – c:\program files\mcafee.com\agent\mcdetect.exe File not found
SRV - (HidServ) – %SystemRoot%\System32\hidserv.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (MpfService) – C:\Program Files\McAfee.com\Personal Firewall\MpfService.exe (McAfee Corporation)
SRV - (MskService) – C:\Program Files\McAfee\SpamKiller\MSKSrvr.exe (McAfee Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) – system32\DRIVERS\wanatw4.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (HDAudBus) – system32\DRIVERS\HDAudBus.sys File not found
DRV - (Changer) – File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (LVUVC) – C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (CompFilter) – C:\WINDOWS\system32\drivers\lvbusflt.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (RTL8187B) – C:\WINDOWS\system32\drivers\wg111v3.sys (Realtek Semiconductor Corporation )
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (MPFIREWL) – C:\WINDOWS\system32\drivers\MpFirewall.sys (McAfee)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.facebook.com/home.php?ref=hp [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/dell?hl=en&cl…&channel=us
IE - HKCU\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo.com/search?fr=mcafee&p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_9_900_85.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - default_search_provider: McAfee (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?fr=mcafee&p={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.66\gcswf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Documents and Settings\janell brown\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.40.135.1_0\McChPlg.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Skype Toolbars (Enabled) = C:\Documents and Settings\janell brown\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8153_0\npSkypeChromePlugin.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Documents and Settings\janell brown\Application Data\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Documents and Settings\janell brown\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 6.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\janell brown\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Documents and Settings\janell brown\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Documents and Settings\janell brown\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Chrome In-App Payments service = C:\Documents and Settings\janell brown\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Gmail = C:\Documents and Settings\janell brown\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2004/08/10 03:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (McAfee Anti-Phishing Filter) - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\Program Files\McAfee\SpamKiller\McApfBHO.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (McAfee VirusScan) - {BA52B914-B692-46c4-B683-905236F6F655} - c:\Program Files\McAfee.com\VSO\mcvsshl.dll (McAfee, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\Program Files\McAfee\SpamKiller\McApfBHO.dll (McAfee, Inc.)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.43.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{744ADC0E-C410-423E-847C-742A3C6E669D}: DhcpNameServer = 192.168.43.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\janell brown\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\janell brown\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 02:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
Drivers32: wave5 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/09/08 11:29:14 | 000,000,000 | —D | C] – C:\Documents and Settings\janell brown\Local Settings\Application Data\Logitech® Webcam Software
[2013/09/08 11:28:12 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2013/09/07 20:02:26 | 000,000,000 | -HSD | C] – C:\Documents and Settings\janell brown\PrivacIE
[2013/09/07 17:05:03 | 000,000,000 | —D | C] – C:\Documents and Settings\janell brown\Local Settings\Application Data\Sun
[2013/09/07 17:02:28 | 000,000,000 | RH-D | C] – C:\Documents and Settings\janell brown\Recent
[2013/09/07 16:47:22 | 000,000,000 | —D | C] – C:\Program Files\ATI
[2013/09/07 16:42:35 | 000,000,000 | —D | C] – C:\AMD
[2013/09/07 16:08:49 | 000,000,000 | R–D | C] – C:\Documents and Settings\janell brown\My Documents\My Music
[2013/09/07 16:08:48 | 000,000,000 | -HSD | C] – C:\Documents and Settings\janell brown\IETldCache
[2013/09/07 16:04:45 | 000,000,000 | -H-D | C] – C:\WINDOWS\ie8
[2013/09/07 15:59:06 | 000,000,000 | —D | C] – C:\Program Files\FileHippo.com
[2013/09/07 15:56:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/09/07 15:55:19 | 000,867,240 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/09/07 15:55:19 | 000,263,592 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/09/07 15:55:19 | 000,144,896 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/09/07 15:55:14 | 000,175,016 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/09/07 15:55:14 | 000,175,016 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/09/07 15:55:14 | 000,094,632 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/09/07 15:54:53 | 000,000,000 | —D | C] – C:\Program Files\Java
[2013/09/07 00:25:49 | 000,000,000 | R–D | C] – C:\Documents and Settings\janell brown\Start Menu\Programs\Administrative Tools
[2013/09/06 23:58:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2013/09/06 23:58:20 | 000,000,000 | —D | C] – C:\Program Files\PCPitstop
[2013/09/06 23:53:05 | 000,692,616 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/06 23:53:04 | 000,071,048 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/06 22:35:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2013/09/06 22:35:15 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/09/06 20:21:38 | 000,000,000 | —D | C] – C:\Documents and Settings\janell brown\Application Data\Malwarebytes
[2013/09/06 20:21:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/09/06 20:21:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2013/09/06 20:21:11 | 000,022,856 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2013/09/06 20:21:11 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2013/09/06 20:20:05 | 000,000,000 | —D | C] – C:\Documents and Settings\janell brown\My Documents\Downloads
[2013/09/06 20:02:17 | 000,000,000 | —D | C] – C:\Program Files\CONEXANT
[2013/09/06 20:02:12 | 000,000,000 | —D | C] – C:\Documents and Settings\janell brown\My Documents\SightSpeed Recordings
[2013/09/06 20:01:06 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Recorded TV
[2013/09/06 17:49:04 | 000,000,000 | —D | C] – C:\Documents and Settings\janell brown\Application Data\Helios
[2013/09/06 17:47:03 | 000,000,000 | R–D | C] – C:\Documents and Settings\janell brown\My Documents\My Pictures
[2013/09/06 16:41:28 | 000,000,000 | —D | C] – C:\Documents and Settings\janell brown\Desktop\Arrik DROID
[2013/09/06 15:29:35 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/09/08 11:41:15 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/09/08 11:27:34 | 000,127,968 | —- | M] () – C:\WINDOWS\System32\Status.MPF
[2013/09/08 11:27:09 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/08 11:27:05 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/09/08 11:27:02 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2013/09/07 23:20:01 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/07 23:11:57 | 000,002,011 | —- | M] () – C:\Documents and Settings\janell brown\My Documents\road one.eml
[2013/09/07 23:11:23 | 000,001,833 | —- | M] () – C:\Documents and Settings\janell brown\My Documents\SPECIAL CIRCUMSTANCES.eml
[2013/09/07 22:30:35 | 000,438,737 | —- | M] () – C:\Documents and Settings\janell brown\My Documents\GODESS - Yahoo! Search Results.mht
[2013/09/07 17:22:24 | 000,001,261 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Logitech Webcam Software .lnk
[2013/09/07 16:08:57 | 000,000,815 | —- | M] () – C:\Documents and Settings\janell brown\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/09/07 16:01:55 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/09/07 16:01:55 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/09/07 15:59:07 | 000,001,632 | —- | M] () – C:\Documents and Settings\janell brown\Desktop\Update Checker.lnk
[2013/09/07 15:55:03 | 000,094,632 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/09/07 15:55:01 | 000,263,592 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/09/07 15:55:01 | 000,175,016 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/09/07 15:55:01 | 000,175,016 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/09/07 15:55:01 | 000,144,896 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/09/07 15:55:00 | 000,867,240 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npDeployJava1.dll
[2013/09/07 15:55:00 | 000,789,416 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/09/07 15:47:24 | 000,407,670 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2013/09/07 15:47:24 | 000,064,200 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2013/09/07 10:57:02 | 000,000,364 | —- | M] () – C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (DF8RS5B1-janell brown).job
[2013/09/06 22:35:33 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2013/09/06 20:21:28 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/06 20:00:55 | 000,135,664 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2013/09/06 15:43:24 | 000,000,000 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2013/09/06 15:43:24 | 000,000,000 | —- | M] () – C:\Documents and Settings\janell brown\Application Data\SingleFiles
[2013/09/06 15:43:24 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Services
[2013/09/06 15:43:23 | 000,000,000 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2013/09/06 15:43:23 | 000,000,000 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2013/09/06 15:43:23 | 000,000,000 | —- | M] () – C:\Documents and Settings\janell brown\Application Data\Scripts Menu
[2013/09/06 15:43:23 | 000,000,000 | —- | M] () – C:\Documents and Settings\All Users\Application Data\Screen Savers
[2013/09/06 15:40:17 | 000,000,045 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2013/09/06 15:26:55 | 000,000,002 | —- | M] () – C:\WINDOWS\msoffice.ini
[2013/09/06 15:20:36 | 000,003,558 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2013/09/06 15:20:35 | 000,000,088 | RHS- | M] () – C:\WINDOWS\System32\C771CB63FB.sys
[2013/09/06 15:14:49 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/09/07 23:11:57 | 000,002,011 | —- | C] () – C:\Documents and Settings\janell brown\My Documents\road one.eml
[2013/09/07 23:11:23 | 000,001,833 | —- | C] () – C:\Documents and Settings\janell brown\My Documents\SPECIAL CIRCUMSTANCES.eml
[2013/09/07 22:30:29 | 000,438,737 | —- | C] () – C:\Documents and Settings\janell brown\My Documents\GODESS - Yahoo! Search Results.mht
[2013/09/07 15:59:07 | 000,001,638 | —- | C] () – C:\Documents and Settings\janell brown\Start Menu\Programs\Update Checker.lnk
[2013/09/07 15:59:07 | 000,001,632 | —- | C] () – C:\Documents and Settings\janell brown\Desktop\Update Checker.lnk
[2013/09/06 23:53:20 | 000,000,830 | —- | C] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/09/06 22:35:33 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2013/09/06 20:21:28 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/06 15:43:24 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Services
[2013/09/06 15:43:23 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\Screen Savers
[2013/09/06 15:26:55 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2012/01/03 01:28:14 | 000,000,000 | —- | C] () – C:\WINDOWS\ViewNX2.INI
[2012/01/03 00:49:35 | 000,000,000 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2012/01/03 00:49:35 | 000,000,000 | —- | C] () – C:\Documents and Settings\janell brown\Application Data\SingleFiles
[2012/01/03 00:49:34 | 000,000,000 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2012/01/03 00:49:34 | 000,000,000 | —- | C] () – C:\Documents and Settings\janell brown\Application Data\Scripts Menu
[2012/01/03 00:49:33 | 000,000,000 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2011/10/13 12:32:43 | 000,061,678 | —- | C] () – C:\Documents and Settings\janell brown\Application Data\PFP120JPR.{PB
[2011/10/13 12:32:43 | 000,012,358 | —- | C] () – C:\Documents and Settings\janell brown\Application Data\PFP120JCM.{PB
[2011/07/24 21:48:55 | 000,003,584 | —- | C] () – C:\Documents and Settings\janell brown\Application Data\dvd.bmk
[2010/06/26 17:57:57 | 000,000,135 | —- | C] () – C:\Documents and Settings\janell brown\Local Settings\Application Data\fusioncache.dat

========== ZeroAccess Check ==========

[2005/08/16 02:39:16 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2006/09/23 13:12:50 | 001,497,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 03:01:53 | 000,473,088 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2004/08/10 03:00:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/01/03 00:49:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2012/01/03 20:36:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2013/09/07 00:10:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PCPitstop
[2012/01/03 00:49:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2013/09/06 17:49:04 | 000,000,000 | —D | M] – C:\Documents and Settings\janell brown\Application Data\Helios
[2011/09/14 20:38:46 | 000,000,000 | —D | M] – C:\Documents and Settings\janell brown\Application Data\Leadertech
[2011/09/14 23:08:15 | 000,000,000 | —D | M] – C:\Documents and Settings\janell brown\Application Data\MAGIX
[2012/01/03 01:47:00 | 000,000,000 | —D | M] – C:\Documents and Settings\janell brown\Application Data\Nikon
[2011/10/25 23:07:16 | 000,000,000 | —D | M] – C:\Documents and Settings\janell brown\Application Data\OpenOffice.org

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/13 17:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[2004/08/10 03:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\explorer.exe
[2004/08/10 03:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.SCF >
[2004/08/10 03:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2004/08/10 03:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/04/13 17:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\iexplore.exe
[2010/04/16 04:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINDOWS\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe
[2010/04/16 04:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINDOWS\ie8\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB982381-IE7\iexplore.exe
[2004/08/10 03:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINDOWS\ie7\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-2D97EBE6.PF >
[2013/09/07 22:35:47 | 000,124,856 | —- | M] () MD5=C06766F209E93C354BB5FBC7DA987404 – C:\WINDOWS\Prefetch\IEXPLORE.EXE-2D97EBE6.pf

< MD5 for: IEXPLORE.HLP >
[2004/08/10 03:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: SERVICES >
[2011/08/25 21:38:30 | 000,000,094 | –S- | M] () MD5=713F38DC6C1E73D06F1516873E1E8919 – C:\Documents and Settings\janell brown\Desktop\Arrik DROID\ALL PROGRAMS\cygwin\etc\services
[2004/08/10 03:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
[2013/09/06 15:43:24 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Documents and Settings\All Users\Application Data\Services

< MD5 for: SERVICES.EXE >
[2009/02/06 04:06:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/13 17:12:34 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\services.exe
[2009/02/06 03:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 03:22:21 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=4712531AB7A01B7EE059853CA17D39BD – C:\WINDOWS\system32\services.exe
[2009/02/06 04:11:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\$hf_mig$\KB956572\SP3GDR\services.exe
[2004/08/10 03:00:00 | 000,108,032 | —- | M] (Microsoft Corporation) MD5=C6CE6EEC82F187615D1002BB3BB50ED4 – C:\WINDOWS\$NtUninstallKB956572$\services.exe

< MD5 for: SERVICES.LNK >
[2005/08/16 02:43:10 | 000,001,506 | —- | M] () MD5=32C3F4CF3D6D83ED91BCDB7555C6D4A1 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2004/08/10 03:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc

< MD5 for: SERVICES.VIM >
[2010/08/19 04:23:33 | 000,001,811 | —- | M] () MD5=0216C0CAD51FAFA0506231D63150A78E – C:\Documents and Settings\janell brown\Desktop\Arrik DROID\ALL PROGRAMS\cygwin\usr\share\vim\vim73\syntax\services.vim
[2010/08/19 04:23:45 | 000,000,440 | —- | M] () MD5=9D401F5EFC34C1703DAC61B62B104530 – C:\Documents and Settings\janell brown\Desktop\Arrik DROID\ALL PROGRAMS\cygwin\usr\share\vim\vim73\ftplugin\services.vim

< MD5 for: WINLOGON.EXE >
[2004/08/10 03:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\dllcache\winlogon.exe
[2004/08/10 03:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\system32\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/13 17:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2005/08/16 02:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/26 17:57:40 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2005/08/16 02:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/06/15 18:18:18 | 000,006,969 | RH– | M] () – C:\dell.sdr
[2013/09/08 11:27:02 | 1071,796,224 | -HS- | M] () – C:\hiberfil.sys
[2011/09/14 16:36:36 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005/08/16 02:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2006/06/15 18:40:19 | 000,000,838 | -H– | M] () – C:\IPH.PH
[2010/06/28 21:23:47 | 000,000,485 | —- | M] () – C:\LOG19.log
[2005/08/16 02:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/10 03:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/10 03:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2013/09/08 11:26:55 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2006/06/15 18:40:26 | 000,000,087 | —- | M] () – C:\SystemInfo.ini

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2005/08/16 02:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2012/11/06 18:40:42 | 000,001,754 | -H– | M] () – C:\Documents and Settings\janell brown\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 206E-FE9E
Directory of C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices
09/07/2013 03:47 PM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Directory of C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote
09/07/2013 03:46 PM 2.0.0.0__b03f5f7f11d50a3a
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
2 Dir(s) 82,718,785,536 bytes free

< %systemroot%\System32\config\*.sav >
[2005/08/16 02:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2005/08/16 02:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2005/08/16 02:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005/08/16 02:43:10 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/06/26 17:58:07 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\janell brown\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005/08/16 02:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\janell brown\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-06 07:43:13

< End of report >
Hello Montijoar,

1. Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

2. Please download Malwarebytes Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page.
  • Caution: This is a beta version so please be sure to read the disclaimer and back up all your data before using.
  • Scan your system for malware
  • If malware is found, please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
If there is no malware found, please let me know as well.


3. Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on the Scan button.
  • AdwCleaner will begin…be patient as the scan may take some time to complete.
    The actual line should say "Pending. Please uncheck elements you do not want to remove" => scan is complete.
  • After the scan has finished, click on the Report button…a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it.
    If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
Results of screen317's Security Check version 0.99.73
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
BullGuard Antivirus
ECHO is off.
Antivirus out of date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
CCleaner
Java 7 Update 25
Adobe Flash Player 11.9.900.96
Adobe Reader XI
Google Chrome 29.0.1547.66
Google Chrome 29.0.1547.76
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 5%
````````````````````End of Log``````````````````````



—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 260292608

—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 269266944

—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 275640320

Downloaded database version: v2013.09.22.03
Downloaded database version: v2013.09.20.01
=======================================
Initializing…
———— Kernel report ————
09/23/2013 07:54:55
———— Loaded modules ———–
\WINDOWS\system32\ntkrnlpa.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\system32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
pciide.sys
\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
MountMgr.sys
ftdisk.sys
dmload.sys
dmio.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
KSecDD.sys
Ntfs.sys
NDIS.sys
Mup.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\HSFHWBS2.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\HSF_DP.sys
\SystemRoot\system32\DRIVERS\HSF_CNXT.sys
\SystemRoot\System32\Drivers\Modem.SYS
\SystemRoot\system32\DRIVERS\e100b325.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\redbook.sys
\SystemRoot\system32\DRIVERS\imapi.sys
\SystemRoot\system32\DRIVERS\afw.sys
\SystemRoot\system32\DRIVERS\afwcore.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\psched.sys
\SystemRoot\system32\DRIVERS\msgpc.sys
\SystemRoot\system32\DRIVERS\ptilink.sys
\SystemRoot\system32\DRIVERS\raspti.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\update.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\sthda.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\MODEMCSA.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\Drivers\i2omgmt.SYS
\SystemRoot\system32\drivers\BdSpy.sys
\SystemRoot\system32\DRIVERS\NSKernel.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\System32\Drivers\MpFirewall.sys
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\NSNetmon.sys
\SystemRoot\System32\drivers\ws2ifsl.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\wg111v3.sys
\SystemRoot\system32\DRIVERS\usbprint.sys
\SystemRoot\system32\DRIVERS\usbscan.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\??\C:\WINDOWS\system32\drivers\mbam.sys
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\AegisP.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\mrxdav.sys
\SystemRoot\system32\DRIVERS\Trufos.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\mdmxsdk.sys
\SystemRoot\System32\DRIVERS\ipfltdrv.sys
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
\WINDOWS\system32\ntdll.dll
———– End ———–
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk4\DR7
Upper Device Object: 0xffffffff86845ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000069\
Lower Device Object: 0xffffffff86c6f030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR6
Upper Device Object: 0xffffffff8682e498
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000068\
Lower Device Object: 0xffffffff86c438e0
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR5
Upper Device Object: 0xffffffff86815500
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000067\
Lower Device Object: 0xffffffff86c66ea0
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR4
Upper Device Object: 0xffffffff86829ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000066\
Lower Device Object: 0xffffffff86c64650
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff86f5fab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-17\
Lower Device Object: 0xffffffff86f61d98
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff86f5fab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86f60b70, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86f5fab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86f61d98, DeviceName: \Device\Ide\IdeDeviceP1T0L0-17\, DriverName: \Driver\atapi\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E686F016

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 96327

Partition 1 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 96390 Numsec = 302664600
Partition file system is NTFS
Partition is bootable

Partition 2 type is Other (0xdb)
Partition is NOT ACTIVE.
Partition starts at LBA: 302760990 Numsec = 9735390

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 160000000000 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-312480000-312500000)…
Done!
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff86829ab8, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86832020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86829ab8, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c64650, DeviceName: \Device\00000066\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xffffffff86815500, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86826020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86815500, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c66ea0, DeviceName: \Device\00000067\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xffffffff8682e498, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8682e270, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff8682e498, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c438e0, DeviceName: \Device\00000068\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffffff86845ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86818020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86845ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c6f030, DeviceName: \Device\00000069\, DriverName: \Driver\USBSTOR\
———— End ———-

****RIGHT WHEN THIS MALWAREBYTES SCAN ENDED WE GOT THE BLUE SCREEN AND HAD TO FORCE RESTART****




# AdwCleaner v3.004 - Report created 23/09/2013 at 12:26:51
# Updated 15/09/2013 by Xplode
# Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
# Username : janell brown - DF8RS5B1
# Running from : C:\Documents and Settings\janell brown\My Documents\Downloads\AdwCleaner.exe
# Option : Scan

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Found : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Key Found : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Key Found : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Key Found : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Key Found : HKLM\Software\Freeze.com
Key Found : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Found : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Key Found : HKLM\Software\Viewpoint

***** [ Browsers ] *****

-\\ Internet Explorer v8.0.6001.18702


-\\ Google Chrome v29.0.1547.76

[ File : C:\Documents and Settings\janell brown\Local Settings\Application Data\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [1599 octets] - [23/09/2013 12:26:51]

########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [1659 octets] ##########
Hi Montijoar,

BullGuard Antivirus

Antivirus out of date! (On Access scanning disabled!)

Can you enable and update it?


****RIGHT WHEN THIS MALWAREBYTES SCAN ENDED WE GOT THE BLUE SCREEN AND HAD TO FORCE RESTART****

Can you you scan with MBAR again, please?

————————————

Download ComboFix from the following location:
Link

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


————————————

How the computer is running now?
Hi, it has been several days since I sent my last set of instructions to help with your computer problem. Please let me know if you are having problems and still need help. Note: Threads will be closed if no response after 3 days.
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 260292608

—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 269266944

—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 275640320

Downloaded database version: v2013.09.22.03
Downloaded database version: v2013.09.20.01
=======================================
Initializing…
———— Kernel report ————
09/23/2013 07:54:55
———— Loaded modules ———–
\WINDOWS\system32\ntkrnlpa.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\system32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
pciide.sys
\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
MountMgr.sys
ftdisk.sys
dmload.sys
dmio.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
KSecDD.sys
Ntfs.sys
NDIS.sys
Mup.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\HSFHWBS2.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\HSF_DP.sys
\SystemRoot\system32\DRIVERS\HSF_CNXT.sys
\SystemRoot\System32\Drivers\Modem.SYS
\SystemRoot\system32\DRIVERS\e100b325.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\redbook.sys
\SystemRoot\system32\DRIVERS\imapi.sys
\SystemRoot\system32\DRIVERS\afw.sys
\SystemRoot\system32\DRIVERS\afwcore.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\psched.sys
\SystemRoot\system32\DRIVERS\msgpc.sys
\SystemRoot\system32\DRIVERS\ptilink.sys
\SystemRoot\system32\DRIVERS\raspti.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\update.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\sthda.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\MODEMCSA.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\Drivers\i2omgmt.SYS
\SystemRoot\system32\drivers\BdSpy.sys
\SystemRoot\system32\DRIVERS\NSKernel.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\System32\Drivers\MpFirewall.sys
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\NSNetmon.sys
\SystemRoot\System32\drivers\ws2ifsl.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\wg111v3.sys
\SystemRoot\system32\DRIVERS\usbprint.sys
\SystemRoot\system32\DRIVERS\usbscan.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\??\C:\WINDOWS\system32\drivers\mbam.sys
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\AegisP.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\mrxdav.sys
\SystemRoot\system32\DRIVERS\Trufos.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\mdmxsdk.sys
\SystemRoot\System32\DRIVERS\ipfltdrv.sys
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
\WINDOWS\system32\ntdll.dll
———– End ———–
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk4\DR7
Upper Device Object: 0xffffffff86845ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000069\
Lower Device Object: 0xffffffff86c6f030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR6
Upper Device Object: 0xffffffff8682e498
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000068\
Lower Device Object: 0xffffffff86c438e0
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR5
Upper Device Object: 0xffffffff86815500
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000067\
Lower Device Object: 0xffffffff86c66ea0
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR4
Upper Device Object: 0xffffffff86829ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000066\
Lower Device Object: 0xffffffff86c64650
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff86f5fab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-17\
Lower Device Object: 0xffffffff86f61d98
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff86f5fab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86f60b70, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86f5fab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86f61d98, DeviceName: \Device\Ide\IdeDeviceP1T0L0-17\, DriverName: \Driver\atapi\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E686F016

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 96327

Partition 1 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 96390 Numsec = 302664600
Partition file system is NTFS
Partition is bootable

Partition 2 type is Other (0xdb)
Partition is NOT ACTIVE.
Partition starts at LBA: 302760990 Numsec = 9735390

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 160000000000 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-312480000-312500000)…
Done!
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff86829ab8, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86832020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86829ab8, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c64650, DeviceName: \Device\00000066\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xffffffff86815500, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86826020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86815500, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c66ea0, DeviceName: \Device\00000067\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xffffffff8682e498, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8682e270, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff8682e498, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c438e0, DeviceName: \Device\00000068\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffffff86845ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86818020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86845ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86c6f030, DeviceName: \Device\00000069\, DriverName: \Driver\USBSTOR\
———— End ———-
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 383320064

—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 5.1.2600 Windows XP Service Pack 3 x86

Account is Administrative

Internet Explorer version: 8.0.6001.18702

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.793000 GHz
Memory total: 1071722496, free: 382242816

Downloaded database version: v2013.09.24.10
Downloaded database version: v2013.09.23.01
Initializing…
======================
———— Kernel report ————
09/25/2013 22:09:30
———— Loaded modules ———–
\WINDOWS\system32\ntkrnlpa.exe
\WINDOWS\system32\hal.dll
\WINDOWS\system32\KDCOM.DLL
\WINDOWS\system32\BOOTVID.dll
ACPI.sys
\WINDOWS\system32\DRIVERS\WMILIB.SYS
pci.sys
isapnp.sys
pciide.sys
\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
MountMgr.sys
ftdisk.sys
dmload.sys
dmio.sys
PartMgr.sys
VolSnap.sys
atapi.sys
disk.sys
\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
fltmgr.sys
sr.sys
KSecDD.sys
Ntfs.sys
NDIS.sys
Mup.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\ati2mtag.sys
\SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\HSFHWBS2.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\HSF_DP.sys
\SystemRoot\system32\DRIVERS\HSF_CNXT.sys
\SystemRoot\System32\Drivers\Modem.SYS
\SystemRoot\system32\DRIVERS\e100b325.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\redbook.sys
\SystemRoot\system32\DRIVERS\imapi.sys
\SystemRoot\system32\DRIVERS\afw.sys
\SystemRoot\system32\DRIVERS\afwcore.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\audstub.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\psched.sys
\SystemRoot\system32\DRIVERS\msgpc.sys
\SystemRoot\system32\DRIVERS\ptilink.sys
\SystemRoot\system32\DRIVERS\raspti.sys
\SystemRoot\system32\DRIVERS\rdpdr.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\DRIVERS\update.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\sthda.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\MODEMCSA.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\System32\Drivers\i2omgmt.SYS
\SystemRoot\system32\drivers\BdSpy.sys
\SystemRoot\system32\DRIVERS\NSKernel.sys
\SystemRoot\System32\Drivers\Fs_Rec.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\Drivers\mnmdd.SYS
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\rasacd.sys
\SystemRoot\system32\DRIVERS\ipsec.sys
\SystemRoot\system32\DRIVERS\tcpip.sys
\SystemRoot\System32\Drivers\MpFirewall.sys
\SystemRoot\system32\DRIVERS\ipnat.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\NSNetmon.sys
\SystemRoot\System32\drivers\ws2ifsl.sys
\SystemRoot\System32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\Drivers\Fips.SYS
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\system32\DRIVERS\wg111v3.sys
\SystemRoot\system32\DRIVERS\usbprint.sys
\SystemRoot\system32\DRIVERS\usbscan.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\Cdfs.SYS
\SystemRoot\System32\Drivers\dump_atapi.sys
\SystemRoot\System32\Drivers\dump_WMILIB.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\watchdog.sys
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\System32\drivers\dxgthk.sys
\SystemRoot\System32\ati2dvag.dll
\SystemRoot\System32\ati2cqag.dll
\SystemRoot\System32\atikvmag.dll
\SystemRoot\System32\ati3duag.dll
\SystemRoot\System32\ativvaxx.dll
\SystemRoot\System32\ATMFD.DLL
\??\C:\WINDOWS\system32\drivers\mbam.sys
\SystemRoot\system32\DRIVERS\AegisP.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\mrxdav.sys
\SystemRoot\system32\DRIVERS\Trufos.sys
\SystemRoot\system32\drivers\wdmaud.sys
\SystemRoot\system32\drivers\sysaudio.sys
\SystemRoot\System32\Drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\srv.sys
\SystemRoot\system32\DRIVERS\mdmxsdk.sys
\SystemRoot\System32\DRIVERS\ipfltdrv.sys
\SystemRoot\system32\DRIVERS\asyncmac.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
\WINDOWS\system32\ntdll.dll
———– End ———–
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk4\DR7
Upper Device Object: 0xffffffff86764ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000069\
Lower Device Object: 0xffffffff8681d810
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk3\DR6
Upper Device Object: 0xffffffff86760408
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000068\
Lower Device Object: 0xffffffff8679f030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk2\DR5
Upper Device Object: 0xffffffff86765ab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000067\
Lower Device Object: 0xffffffff86765870
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR4
Upper Device Object: 0xffffffff86775600
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\00000066\
Lower Device Object: 0xffffffff86794030
Lower Device Driver Name: \Driver\USBSTOR\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff86f6aab8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IdeDeviceP1T0L0-17\
Lower Device Object: 0xffffffff86f59d98
Lower Device Driver Name: \Driver\atapi\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff86f6aab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86f58b70, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86f6aab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86f59d98, DeviceName: \Device\Ide\IdeDeviceP1T0L0-17\, DriverName: \Driver\atapi\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E686F016

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 96327

Partition 1 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 96390 Numsec = 302664600
Partition file system is NTFS
Partition is bootable

Partition 2 type is Other (0xdb)
Partition is NOT ACTIVE.
Partition starts at LBA: 302760990 Numsec = 9735390

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 160000000000 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-312480000-312500000)…
Done!
Physical Sector Size: 0
Drive: 1, DevicePointer: 0xffffffff86775600, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8677d690, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86775600, DeviceName: \Device\Harddisk1\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86794030, DeviceName: \Device\00000066\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 2, DevicePointer: 0xffffffff86765ab8, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86765440, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86765ab8, DeviceName: \Device\Harddisk2\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff86765870, DeviceName: \Device\00000067\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xffffffff86760408, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff86765228, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86760408, DeviceName: \Device\Harddisk3\DR6\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8679f030, DeviceName: \Device\00000068\, DriverName: \Driver\USBSTOR\
———— End ———-
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xffffffff86764ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff8677d020, DeviceName: Unknown, DriverName: \Driver\PartMgr\
DevicePointer: 0xffffffff86764ab8, DeviceName: \Device\Harddisk4\DR7\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff8681d810, DeviceName: \Device\00000069\, DriverName: \Driver\USBSTOR\
———— End ———-
=======================================




**Combo fix had some kind of error when trying to download the recovery console

ComboFix 13-09-24.02 - janell brown 09/26/2013 7:33.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.223 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Services
.
.
((((((((((((((((((((((((( Files Created from 2013-08-26 to 2013-09-26 )))))))))))))))))))))))))))))))
.
.
2013-09-23 19:26 . 2013-09-23 19:28 ——– d—–w- C:\AdwCleaner
2013-09-23 14:54 . 2013-09-26 05:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2013-09-23 14:54 . 2013-09-26 05:09 105176 —-a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2013-09-23 14:52 . 2013-09-23 14:52 48728 —-a-w- c:\windows\system32\drivers\mbamchameleon.sys
2013-09-20 16:56 . 2013-09-20 16:56 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\BullGuard
2013-09-20 15:54 . 2009-02-27 10:42 31640 —-a-w- c:\windows\system32\msonpmon.dll
2013-09-20 15:54 . 2006-10-27 02:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2013-09-20 15:53 . 2013-09-22 19:06 ——– d—–w- c:\program files\Microsoft Works
2013-09-20 15:52 . 2013-09-20 15:52 ——– d—–w- c:\program files\Microsoft.NET
2013-09-20 15:50 . 2013-09-20 15:51 ——– d—–w- c:\windows\SHELLNEW
2013-09-20 15:50 . 2013-09-20 15:50 ——– d—–w- c:\documents and settings\janell brown\Local Settings\Application Data\Microsoft Help
2013-09-20 15:50 . 2013-09-26 01:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2013-09-20 15:49 . 2013-09-20 15:49 ——– d—–r- C:\MSOCache
2013-09-18 13:59 . 2013-09-18 13:59 ——– d–h–w- c:\documents and settings\LocalService\Application Data\GTek
2013-09-17 18:49 . 2010-11-17 01:11 267112 —-a-r- c:\windows\system32\hpinksts9311LM.dll
2013-09-17 18:49 . 2010-11-17 01:11 232296 —-a-r- c:\windows\system32\hpinksts9311.dll
2013-09-17 18:49 . 2010-11-17 01:11 213864 —-a-r- c:\windows\system32\hpinkcoi9311.dll
2013-09-17 18:34 . 2008-04-13 18:47 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2013-09-17 18:34 . 2008-04-13 18:47 25856 —-a-w- c:\windows\system32\dllcache\usbprint.sys
2013-09-12 04:10 . 2013-09-12 04:10 ——– d—–w- c:\program files\Microsoft Silverlight
2013-09-12 01:42 . 2013-09-12 01:42 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2013-09-09 02:05 . 2013-09-09 02:05 ——– d—–w- c:\program files\Common Files\Skype
2013-09-09 02:05 . 2013-09-09 02:05 ——– d—–r- c:\program files\Skype
2013-09-09 02:03 . 2013-09-09 02:03 ——– d—–w- c:\program files\Common Files\Java
2013-09-09 02:02 . 2013-09-09 02:02 144896 —-a-w- c:\windows\system32\javacpl.cpl
2013-09-09 02:02 . 2013-09-09 02:02 94632 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-09-09 02:02 . 2013-09-09 02:02 ——– d—–w- c:\program files\Java
2013-09-09 01:25 . 2013-09-09 02:10 ——– d—–w- c:\windows\SxsCaPendDel
2013-09-08 23:45 . 2010-09-18 06:53 954368 ——w- c:\windows\system32\dllcache\mfc40.dll
2013-09-08 23:45 . 2010-09-18 06:53 953856 ——w- c:\windows\system32\dllcache\mfc40u.dll
2013-09-08 23:44 . 2013-08-08 06:05 522240 ——w- c:\windows\system32\dllcache\jsdbgui.dll
2013-09-08 23:40 . 2010-08-23 16:12 617472 ——w- c:\windows\system32\dllcache\comctl32.dll
2013-09-08 23:38 . 2010-11-02 15:17 40960 ——w- c:\windows\system32\dllcache\ndproxy.sys
2013-09-08 23:37 . 2011-04-21 13:37 105472 ——w- c:\windows\system32\dllcache\mup.sys
2013-09-08 23:37 . 2013-02-12 00:32 12928 ——w- c:\windows\system32\dllcache\usb8023x.sys
2013-09-08 23:37 . 2013-02-12 00:32 12928 ——w- c:\windows\system32\dllcache\usb8023.sys
2013-09-08 23:36 . 2012-05-28 18:16 536576 ——w- c:\windows\system32\dllcache\msado15.dll
2013-09-08 23:35 . 2012-07-04 14:05 139784 ——w- c:\windows\system32\dllcache\rdpwd.sys
2013-09-08 23:34 . 2011-07-08 14:02 10496 ——w- c:\windows\system32\dllcache\ndistapi.sys
2013-09-08 23:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\iacenc.dll
2013-09-08 23:34 . 2012-01-11 19:06 3072 ——w- c:\windows\system32\dllcache\iacenc.dll
2013-09-08 23:33 . 2010-10-11 14:59 45568 ——w- c:\windows\system32\dllcache\wab.exe
2013-09-08 23:03 . 2012-06-02 22:19 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2013-09-08 21:55 . 2013-09-10 23:55 ——– d—–w- c:\windows\system32\MRT
2013-09-08 20:59 . 2013-08-08 06:05 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2013-09-08 20:59 . 2013-08-08 06:05 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2013-09-08 20:59 . 2013-08-08 06:05 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2013-09-08 20:51 . 2013-09-08 20:51 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2013-09-08 20:25 . 2013-09-08 20:25 ——– d—–w- c:\windows\system32\scripting
2013-09-08 20:25 . 2013-09-08 20:25 ——– d—–w- c:\windows\l2schemas
2013-09-08 20:25 . 2013-09-08 20:25 ——– d—–w- c:\windows\system32\en
2013-09-08 20:25 . 2013-09-08 20:25 ——– d—–w- c:\windows\system32\bits
2013-09-08 20:01 . 2013-09-08 20:01 ——– d—–w- c:\documents and settings\janell brown\Application Data\vlc
2013-09-08 19:53 . 2013-09-08 19:53 ——– d—–w- c:\program files\VideoLAN
2013-09-08 19:22 . 2013-09-08 19:22 ——– d—–w- c:\documents and settings\LocalService\Application Data\BullGuard
2013-09-08 19:22 . 2013-09-20 15:10 ——– d—–w- c:\documents and settings\janell brown\Application Data\BullGuard
2013-09-08 19:22 . 2013-09-26 14:40 ——– d—–w- c:\documents and settings\All Users\Application Data\BullGuard
2013-09-08 19:20 . 2013-09-08 19:20 ——– d—–w- c:\program files\Common Files\BullGuard Ltd
2013-09-08 19:20 . 2013-09-08 19:20 ——– d—–w- c:\program files\BullGuard Ltd
2013-09-08 18:29 . 2013-09-08 18:29 ——– d—–w- c:\documents and settings\janell brown\Local Settings\Application Data\Logitech® Webcam Software
2013-09-08 03:02 . 2013-09-08 03:02 ——– d-sh–w- c:\documents and settings\janell brown\PrivacIE
2013-09-08 00:05 . 2013-09-08 00:05 ——– d—–w- c:\documents and settings\janell brown\Local Settings\Application Data\Sun
2013-09-07 23:47 . 2013-09-07 23:47 ——– d—–w- c:\program files\ATI
2013-09-07 23:42 . 2013-09-07 23:42 ——– d—–w- C:\AMD
2013-09-07 23:08 . 2013-09-07 23:08 ——– d-sh–w- c:\documents and settings\janell brown\IETldCache
2013-09-07 23:04 . 2013-09-07 23:05 ——– dc-h–w- c:\windows\ie8
2013-09-07 22:59 . 2013-09-07 22:59 ——– d—–w- c:\program files\FileHippo.com
2013-09-07 22:55 . 2013-09-09 02:02 867240 —-a-w- c:\windows\system32\npDeployJava1.dll
2013-09-07 06:58 . 2013-09-07 07:10 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2013-09-07 06:58 . 2013-09-07 07:10 ——– d—–w- c:\program files\PCPitstop
2013-09-07 06:53 . 2013-09-26 01:42 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-07 06:53 . 2013-09-26 01:42 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-07 05:35 . 2013-09-07 05:35 ——– d—–w- c:\program files\CCleaner
2013-09-07 03:21 . 2013-09-07 03:21 ——– d—–w- c:\documents and settings\janell brown\Application Data\Malwarebytes
2013-09-07 03:21 . 2013-09-07 03:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-09-07 03:21 . 2013-09-07 03:21 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2013-09-07 03:21 . 2013-04-04 21:50 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2013-09-07 03:02 . 2013-09-07 03:02 ——– d—–w- c:\program files\CONEXANT
2013-09-07 00:49 . 2013-09-07 00:49 ——– d—–w- c:\documents and settings\janell brown\Application Data\Helios
2013-09-05 14:04 . 2013-09-05 14:04 209272 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-09 02:02 . 2011-10-26 05:19 789416 —-a-w- c:\windows\system32\deployJava1.dll
2013-09-08 19:29 . 2013-05-31 13:19 60256 —-a-w- c:\windows\system32\BGLsp.dll
2013-09-08 19:29 . 2013-05-31 13:19 113088 —-a-w- c:\windows\system32\BgGamingMonitor.dll
2013-08-09 01:56 . 2005-08-16 09:18 386560 —-a-w- c:\windows\system32\themeui.dll
2013-08-08 06:05 . 2005-08-16 09:18 920064 —-a-w- c:\windows\system32\wininet.dll
2013-08-08 06:05 . 2005-08-16 09:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2013-08-08 06:05 . 2005-08-16 09:18 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2013-08-08 06:05 . 2005-08-16 09:18 18944 —-a-w- c:\windows\system32\corpol.dll
2013-08-08 01:27 . 2005-08-16 09:18 1877760 —-a-w- c:\windows\system32\win32k.sys
2013-08-08 00:02 . 2005-08-16 09:18 385024 —-a-w- c:\windows\system32\html.iec
2013-08-05 13:30 . 2005-08-16 09:18 1289728 —-a-w- c:\windows\system32\ole32.dll
2013-08-01 00:20 . 2005-08-16 09:19 827392 —-a-w- c:\windows\system32\wmvdmod.dll
2013-07-10 10:37 . 2005-08-16 09:18 406016 —-a-w- c:\windows\system32\usp10.dll
2013-07-04 03:03 . 2005-08-16 09:18 2149888 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-07-04 02:08 . 2004-08-04 03:59 2028544 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2005-05-15 332800]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2012-11-23 307712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"BullGuard"="c:\program files\bullguard ltd\bullguard\BullGuard.exe" [2013-09-18 858976]
"BullGuardUpdate2"="c:\program files\bullguard ltd\bullguard\BullGuardUpdate2.exe" [2013-09-08 1879392]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2007-9-12 1527808]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsMain]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
2010-10-29 20:06 5915480 —-a-w- c:\program files\Logitech\Vid HD\Vid.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2011-11-11 21:08 205336 —-a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
2005-08-18 22:52 999424 —-a-w- c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]
2005-07-12 23:06 110592 —-a-w- c:\progra~1\McAfee\SPAMKI~1\MSKAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2005-07-13 00:05 1117184 —-a-w- c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
2005-08-12 03:02 53248 —-a-w- c:\program files\McAfee.com\VSO\oasclnt.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-07-13 20:33 17418928 —-a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
2005-08-10 17:49 163840 —-a-w- c:\progra~1\McAfee.com\VSO\mcvsshld.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
2005-07-08 23:18 151552 —-a-w- c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
R1 BdSpy;BdSpy;c:\windows\system32\drivers\BdSpy.sys [3/18/2013 6:24 AM 66160]
R1 NovaShieldFilterDriver;NovaShieldFilterDriver;c:\windows\system32\drivers\NSKernel.sys [6/26/2012 2:48 AM 789960]
R1 NovaShieldTDIDriver;NovaShieldTDIDriver;c:\windows\system32\drivers\NSNetmon.sys [6/26/2012 2:48 AM 19272]
R2 BsBackup;BullGuard backup service;c:\windows\System32\SvcHost.exe -k BullGuard_Backup [8/16/2005 2:18 AM 14336]
R2 BsBhvScan;BullGuard behavioural detection service;c:\program files\BullGuard Ltd\BullGuard\BullGuardBhvScanner.exe [5/20/2013 1:51 AM 376672]
R2 BsFileScan;BullGuard on-access service;c:\windows\System32\SvcHost.exe -k BullGuard [8/16/2005 2:18 AM 14336]
R2 BsFire;BullGuard firewall service;c:\windows\System32\SvcHost.exe -k BullGuard [8/16/2005 2:18 AM 14336]
R2 BsMailProxy;BullGuard e-mail monitoring service;c:\windows\System32\SvcHost.exe -k BullGuard_Proxy [8/16/2005 2:18 AM 14336]
R2 BsMain;BullGuard main service;c:\windows\System32\SvcHost.exe -k BullGuard_Main [8/16/2005 2:18 AM 14336]
R2 BsScanner;BullGuard scanning service;c:\program files\BullGuard Ltd\BullGuard\BullGuardScanner.exe [5/20/2013 1:51 AM 212320]
R2 BsUpdate;BullGuard update service;c:\program files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [9/18/2013 3:48 AM 287584]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [9/6/2013 8:21 PM 418376]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/6/2013 8:21 PM 701512]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [11/20/2012 6:11 AM 33888]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [11/20/2012 6:11 AM 284768]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/6/2013 8:21 PM 22856]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [4/23/2007 2:11 PM 224896]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [7/13/2012 1:28 PM 160944]
S3 CompFilter;UVCCompositeFilter;c:\windows\system32\drivers\lvbusflt.sys [11/9/2010 7:46 PM 20704]
S3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [9/23/2013 7:52 AM 48728]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [9/23/2013 7:54 AM 105176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard_Main REG_MULTI_SZ BsMain
BullGuard REG_MULTI_SZ BsFileScan BsFire
BullGuard_Proxy REG_MULTI_SZ BsMailProxy
BullGuard_Backup REG_MULTI_SZ BsBackup
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-09-21 19:27 1177552 —-a-w- c:\program files\Google\Chrome\Application\29.0.1547.76\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-07 01:42]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-14 19:11]
.
2013-09-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-14 19:11]
.
2013-09-07 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (DF8RS5B1-janell brown).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-06-16 23:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\BGLsp.dll
TCP: DhcpNameServer = 192.168.1.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-09-26 07:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_110_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_110_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1392)
c:\progra~1\BULLGU~1\BULLGU~1\BgAgent.dll
.
- - - - - - - > 'lsass.exe'(1468)
c:\progra~1\BULLGU~1\BULLGU~1\BgAgent.dll
c:\windows\system32\BGLsp.dll
.
Completion time: 2013-09-26 07:44:00
ComboFix-quarantined-files.txt 2013-09-26 14:43
.
Pre-Run: 73,147,408,384 bytes free
Post-Run: 73,109,745,664 bytes free
.
- - End Of File - - 18A7C8B933B0BC5EEABA9698252584C7
91722E6BC3A2B40FF00222DCA4A3DB3E




I still have a big problem with the computer. When it starts a box saying 'sonic activation module' needs a cd. I dont know what that is. when i cancel it repeatedly tries to loading/download something and pops up error messages that i need a cd. the comp randomly does after start up too.

sorry it took so long, working a lot.
Hi Montijoar,

BullGuard Antivirus:
Could you enable and update it?


Malwarebytes Anti-Rootkit scan:
Looks like you postet only the systemlog.txt and not the mbar-log-2013-xx-xx(xx-xx-xx).txt !


Check if you can uninstall "Sonic Activation Module"!
  • Please go to Start > Control Panel > Add Remove Programs.
  • Locate "Sonic Update Manager" and/or "Sonic Activation Module".
  • If it is there, uninstall it.
  • Reboot Your System
I took care of BullGuard I believe. Malwarebytes: First time I ran it: blue screen, second time: scan finished and when I pressed cleanup comp froze, third time: same as second, fourth time: blue screen sorry a mbar-log-2013-xx-xx(xx-xx-xx).txt wasn't in the folder, don't think i should keep trying? the scan didn't should 4 problems but I couldn't understand what they were. Sonic Encoders was listed in programs and I tried to uninstall it but got "The feature you are trying to use is on a network resource that is unavailable"
Hi Montijoar,

Malwarebytes: First time I ran it: blue screen, second time: scan finished and when I pressed cleanup comp froze, third time: same as second, fourth time: blue screen
sorry a mbar-log-2013-xx-xx(xx-xx-xx).txt wasn't in the folder, don't think i should keep trying? the scan didn't should 4 problems but I couldn't understand what they were.

We skip Malwarebytes.

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
    Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To > Compressed (zipped) file. Attach that zipped file in your next reply as well.

Sonic Encoders was listed in programs and I tried to uninstall it but got "The feature you are trying to use is on a network resource that is unavailable"

Download and install the Update Manager
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-09-29 10:09:33 —————————– 10:09:33.562 OS Version: Windows 5.1.2600 Service Pack 3 10:09:33.562 Number of processors: 2 586 0x409 10:09:33.562 ComputerName: DF8RS5B1 UserName: 10:09:44.765 Initialize success 10:11:13.531 AVAST engine download error: 0 10:11:24.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17 10:11:24.000 Disk 0 Vendor: ST3160812AS 3.ADH Size: 152587MB BusType: 3 10:11:24.328 Disk 0 MBR read successfully 10:11:24.328 Disk 0 MBR scan 10:11:24.328 Disk 0 unknown MBR code 10:11:24.343 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63 10:11:24.359 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 147785 MB offset 96390 10:11:24.390 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 4753 MB offset 302760990 10:11:24.406 Disk 0 scanning sectors +312496380 10:11:24.453 Disk 0 malicious Win32:MBRoot code @ sector 312496383 ! 10:11:24.453 Disk 0 PE file @ sector 312496405 ! 10:11:24.531 Disk 0 scanning C:\WINDOWS\system32\drivers 10:12:10.875 Service scanning 10:12:27.718 Modules scanning 10:12:42.921 Disk 0 trace - called modules: 10:12:42.937 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys 10:12:42.937 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86fd2ab8] 10:12:42.953 3 CLASSPNP.SYS[f7692fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-17[0x86fd4d98] 10:12:42.953 Scan finished successfully 10:12:58.156 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\janell brown\Desktop\MBR.dat" 10:12:58.156 The log file has been saved successfully to "C:\Documents and Settings\janell brown\Desktop\aswMBR.txt" sonic activation module kept popping up and saying I needed a CD while the update manager was starting up.
Hi Montijoar,

Re-run aswMBR.exe
  • Click Scan
  • On completion of the scan, click the FIX button,
  • There is a slight pause after clicking the 'Fix' button.
  • Wait for the tool to report 'Infection fixed successfully', now reboot the machine.
  • Rebooting the machine prematurely, before seeing this line will result in an incomplete fix.

    Note:After the 'Infection fixed successfully' message appears, the machine may became unresponsive. You may have to do a hard boot of your machine. That may be a side effect from the fix. All will be well after the reboot.
  • Save the log as before and post in your next reply.

"sonic activation module"
Try MS Fix it - Install_and_Uninstall
Hi, it has been several days since I sent my last set of instructions to help with your computer problem. Please let me know if you are having problems and still need help. Note: Threads will be closed if no response after 3 days.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI