Firefox Freezing, Suspect Virus [Closed] |
![]() ![]() |
Firefox Freezing, Suspect Virus [Closed] |
Jun 17 2009, 10:16 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows XP |
Hi Computer Gods,
Thank you in advance for your help! About days ago my Firefox stopped working correctly and started freezing after 10 minutes online. I have tried to run a virus scan with Kaspersky earlier this week but nothing was found. Then I followed the instructions from the Malware/Virus removal guide. Again, nothing was found. Tonight my Kaspersky quit working. I am trying to plan a wedding here and am beyond frustrated. I'm posting my logs from two days ago when I ran the scan. Please advise! Thanks again, Soon-to-be Bridezilla OTL logfile created on: 6/16/2009 12:45:29 AM - Run 1 OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Nikole\Downloads Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 91.54% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 220.58 Gb Total Space | 175.65 Gb Free Space | 79.63% Space Free | Partition Type: NTFS Drive D: | 9.77 Gb Total Space | 4.82 Gb Free Space | 49.37% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PC Current User Name: Nikole Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation) PRC - C:\Windows\System32\WLTRYSVC.EXE () PRC - C:\Windows\System32\bcmwltry.exe (Dell Inc.) PRC - C:\Windows\system32\aestsrv.exe (Andrea Electronics Corporation) PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation) PRC - C:\Windows\system32\STacSV.exe (IDT, Inc.) PRC - C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.) PRC - C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) PRC - C:\Windows\Explorer.EXE (Microsoft Corporation) PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.) PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.) PRC - C:\Windows\System32\igfxtray.exe (Intel Corporation) PRC - C:\Windows\System32\hkcmd.exe (Intel Corporation) PRC - C:\Windows\System32\igfxpers.exe (Intel Corporation) PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation) PRC - C:\Windows\System32\WLTRAY.EXE (Dell Inc.) PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.) PRC - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab) PRC - C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software ) PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) PRC - C:\Windows\system32\igfxsrvc.exe (Intel Corporation) PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.) PRC - C:\Program Files\DellTPad\HidFind.exe (Alps Electric Co., Ltd.) PRC - C:\Windows\system32\wbem\wmiprvse.exe (Microsoft Corporation) PRC - C:\Program Files\DellTPad\Apntex.exe (Alps Electric Co., Ltd.) PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Users\Nikole\Downloads\OTL.exe (OldTimer Tools) ========== Win32 Services (SafeList) ========== SRV - (AESTFilters [Auto | Running]) -- C:\Windows\system32\aestsrv.exe (Andrea Electronics Corporation) SRV - (AVP [Auto | Running]) -- C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe (Kaspersky Lab) SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (DockLoginService [Auto | Running]) -- C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation) SRV - (ehRecvr [On_Demand | Stopped]) -- C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation) SRV - (ehSched [On_Demand | Stopped]) -- C:\Windows\ehome\ehsched.exe (Microsoft Corporation) SRV - (ehstart [Auto | Stopped]) -- C:\Windows\ehome\ehstart.dll (Microsoft Corporation) SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) SRV - (GoogleDesktopManager-010708-104812 [On_Demand | Stopped]) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google) SRV - (GoToAssist [On_Demand | Stopped]) -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.) SRV - (IAANTMON [Auto | Running]) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (Intel Corporation) SRV - (idsvc [Unknown | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation) SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation) SRV - (STacSV [Auto | Running]) -- C:\Windows\system32\STacSV.exe (IDT, Inc.) SRV - (stllssvr [On_Demand | Stopped]) -- C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.) SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation) SRV - (wltrysvc [Auto | Running]) -- C:\Windows\System32\WLTRYSVC.EXE () SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation) SRV - (XAudioService [Auto | Running]) -- C:\Windows\system32\DRIVERS\xaudio.exe (Conexant Systems, Inc.) ========== Driver Services (SafeList) ========== DRV - (adp94xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.) DRV - (adpahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.) DRV - (adpu160m [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.) DRV - (adpu320 [Disabled | Stopped]) -- C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.) DRV - (aic78xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.) DRV - (aliide [Disabled | Stopped]) -- C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.) DRV - (ApfiltrService [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.) DRV - (arc [Disabled | Stopped]) -- C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.) DRV - (arcsas [Disabled | Stopped]) -- C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.) DRV - (BCM42RLY [On_Demand | Running]) -- C:\Windows\system32\drivers\BCM42RLY.sys (Broadcom Corporation) DRV - (BCM43XX [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\bcmwl6.sys (Broadcom Corporation) DRV - (BrFiltLo [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.) DRV - (BrFiltUp [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.) DRV - (Brserid [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.) DRV - (BrSerWdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.) DRV - (BrUsbMdm [Disabled | Stopped]) -- C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.) DRV - (BrUsbSer [On_Demand | Stopped]) -- C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.) DRV - (cmdide [Disabled | Stopped]) -- C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.) DRV - (e1express [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\e1e6032.sys (Intel Corporation) DRV - (E1G60 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\E1G60I32.sys (Intel Corporation) DRV - (elxstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\elxstor.sys (Emulex) DRV - (HpCISSs [Disabled | Stopped]) -- C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company) DRV - (HSF_DPV [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.) DRV - (HSXHWAZL [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HSXHWAZL.sys (Conexant Systems, Inc.) DRV - (iaStor [Boot | Running]) -- C:\Windows\system32\drivers\iastor.sys (Intel Corporation) DRV - (iaStorV [Disabled | Stopped]) -- C:\Windows\system32\drivers\iastorv.sys (Intel Corporation) DRV - (igfx [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\igdkmd32.sys (Intel Corporation) DRV - (iirsp [Disabled | Stopped]) -- C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH) DRV - (IntcHdmiAddService [On_Demand | Running]) -- C:\Windows\system32\drivers\IntcHdmi.sys (Intel® Corporation) DRV - (iteatapi [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.) DRV - (iteraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.) DRV - (kl1 [System | Running]) -- C:\Windows\system32\DRIVERS\kl1.sys (Kaspersky Lab) DRV - (klbg [Boot | Running]) -- C:\Windows\system32\drivers\klbg.sys (Kaspersky Lab) DRV - (KLFLTDEV [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\klfltdev.sys (Kaspersky Lab) DRV - (KLIF [System | Running]) -- C:\Windows\system32\DRIVERS\klif.sys (Kaspersky Lab) DRV - (KLIM6 [System | Running]) -- C:\Windows\system32\DRIVERS\klim6.sys (Kaspersky Lab) DRV - (LSI_FC [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic) DRV - (LSI_SAS [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic) DRV - (LSI_SCSI [Disabled | Stopped]) -- C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic) DRV - (mdmxsdk [Auto | Running]) -- C:\Windows\system32\DRIVERS\mdmxsdk.sys (Conexant) DRV - (megasas [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasas.sys (LSI Corporation) DRV - (MegaSR [Disabled | Stopped]) -- C:\Windows\system32\drivers\megasr.sys (LSI Corporation, Inc.) DRV - (Mraid35x [Disabled | Stopped]) -- C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation) DRV - (nfrd960 [Disabled | Stopped]) -- C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation) DRV - (ntrigdigi [Disabled | Stopped]) -- C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies) DRV - (nvraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation) DRV - (nvstor [Disabled | Stopped]) -- C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation) DRV - (OEM02Dev [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\OEM02Dev.sys (Creative Technology Ltd.) DRV - (OEM02Vfx [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\OEM02Vfx.sys (EyePower Games Pte. Ltd.) DRV - (PxHelp20 [Boot | Running]) -- C:\Windows\System32\Drivers\PxHelp20.sys (Sonic Solutions) DRV - (ql2300 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation) DRV - (ql40xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation) DRV - (R300 [On_Demand | Stopped]) -- C:\Windows\system32\DRIVERS\atikmdag.sys (ATI Technologies Inc.) DRV - (rimmptsk [Auto | Running]) -- C:\Windows\system32\DRIVERS\rimmptsk.sys (REDC) DRV - (rimsptsk [Auto | Running]) -- C:\Windows\system32\DRIVERS\rimsptsk.sys (REDC) DRV - (rismxdp [Auto | Running]) -- C:\Windows\system32\DRIVERS\rixdptsk.sys (REDC) DRV - (secdrv [Auto | Running]) -- C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) DRV - (SiSRaid4 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems) DRV - (STHDA [On_Demand | Running]) -- C:\Windows\system32\drivers\stwrt.sys (IDT, Inc.) DRV - (Symc8xx [Disabled | Stopped]) -- C:\Windows\system32\drivers\symc8xx.sys (LSI Logic) DRV - (Sym_hi [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_hi.sys (LSI Logic) DRV - (Sym_u3 [Disabled | Stopped]) -- C:\Windows\system32\drivers\sym_u3.sys (LSI Logic) DRV - (uliahci [Disabled | Stopped]) -- C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.) DRV - (UlSata [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.) DRV - (ulsata2 [Disabled | Stopped]) -- C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.) DRV - (viaide [Disabled | Stopped]) -- C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.) DRV - (vsmraid [Disabled | Stopped]) -- C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd) DRV - (winachsf [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.) DRV - (XAudio [Auto | Running]) -- C:\Windows\system32\DRIVERS\xaudio.sys (Conexant Systems, Inc.) DRV - (yukonwlh [On_Demand | Running]) -- C:\Windows\system32\DRIVERS\yk60x86.sys (Marvell) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data] IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&cl...amp;ibd=1080921 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "http://www.google.com/" FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0 FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11 FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/01 22:41:21 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/14 23:38:15 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/14 23:38:15 | 00,000,000 | ---D | M] FF - HKLM\software\mozilla\Thunderbird\Extensions\\{eea12ec4-729d-4703-bc37-106ce9879ce2}: C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY INTERNET SECURITY 2009\THBEXT [2009/04/14 22:34:17 | 00,000,000 | ---D | M] [2009/04/14 22:50:13 | 00,000,000 | ---D | M] -- C:\Users\Nikole\AppData\Roaming\mozilla\Extensions [2009/04/14 22:50:13 | 00,000,000 | ---D | M] -- C:\Users\Nikole\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} [2009/04/14 22:50:13 | 00,000,000 | ---D | M] -- C:\Users\Nikole\AppData\Roaming\mozilla\Firefox\Profiles\3imazx2c.default\extensions [2009/04/14 22:50:08 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions [2009/06/12 21:55:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [2009/06/12 21:55:47 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll [2009/06/12 21:55:47 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll [2009/05/07 20:43:01 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml [2009/05/07 20:43:01 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml [2009/05/07 20:43:01 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml [2009/05/07 20:43:01 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml [2009/05/07 20:43:01 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml [2009/05/07 20:43:01 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml [2009/05/07 20:43:01 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll (Kaspersky Lab) O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.) O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated) O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.) O4 - HKLM..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" (Kaspersky Lab) O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe (Dell Inc.) O4 - HKLM..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" ( ) O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google) O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe (Intel Corporation) O4 - HKLM..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" (Intel Corporation) O4 - HKLM..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe (Intel Corporation) O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.) O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" (CyberLink Corp.) O4 - HKLM..\Run: [Persistence] C:\Windows\system32\igfxpers.exe (Intel Corporation) O4 - HKLM..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide (Microsoft Corporation) O4 - Startup: C:\Users\Nikole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software ) O4 - Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17 O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm () O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.) O9 - Extra Button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll (Kaspersky Lab) O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [@%SystemRoot%\system32\nlasvc.dll,-1000] - C:\Windows\system32\NLAapi.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [@%SystemRoot%\system32\napinsp.dll,-1000] - C:\Windows\system32\napinsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [@%SystemRoot%\system32\pnrpnsp.dll,-1000] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [@%SystemRoot%\system32\pnrpnsp.dll,-1001] - C:\Windows\system32\pnrpnsp.dll (Microsoft Corporation) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_05) O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll (Kaspersky Lab) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll (Kaspersky Lab) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll (Kaspersky Lab) O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll (Kaspersky Lab) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.) O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\system32\igfxdev.dll (Intel Corporation) O20 - Winlogon\Notify\klogon: DllName - C:\Windows\system32\klogon.dll - C:\Windows\system32\klogon.dll (Kaspersky Lab) O31 - SafeBoot: AlternateShell - cmd.exe O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 17:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O34 - HKLM BootExecute: (autocheck) - File not found O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation) O34 - HKLM BootExecute: (*) - * [2009/06/15 23:10:06 | 00,000,000 | ---D | M] ========== Files/Folders - Created Within 30 Days ========== [2009/06/16 00:00:16 | 00,000,820 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2009/06/15 23:50:55 | 00,000,000 | ---D | C] -- C:\Users\Nikole\AppData\Roaming\Malwarebytes [2009/06/15 23:50:50 | 00,040,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2009/06/15 23:50:49 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2009/06/15 23:50:30 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2009/06/15 23:50:30 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/06/15 23:49:04 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT [2009/06/15 23:48:47 | 00,000,735 | ---- | C] () -- C:\Users\Nikole\Desktop\NTREGOPT.lnk [2009/06/15 23:48:46 | 00,000,716 | ---- | C] () -- C:\Users\Nikole\Desktop\ERUNT.lnk [2009/06/15 23:48:46 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT [2009/06/15 23:28:14 | 32,107,84768 | -HS- | C] () -- C:\hiberfil.sys [2009/06/15 23:23:57 | 00,000,000 | -HSD | C] -- C:\found.002 [2009/06/15 22:44:23 | 00,031,781 | ---- | C] () -- C:\Users\Nikole\Desktop\bookmarks.html [2009/06/14 23:48:32 | 00,000,000 | -HSD | C] -- C:\found.001 [2009/06/14 23:00:36 | 00,000,000 | -HSD | C] -- C:\found.000 [2009/06/11 22:56:01 | 00,001,500 | ---- | C] () -- C:\Users\Nikole\Desktop\index.html [2009/06/11 20:35:10 | 02,033,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys [2009/06/11 20:35:09 | 00,636,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\localspl.dll [2009/06/11 20:35:08 | 00,784,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rpcrt4.dll [2009/06/11 20:35:03 | 03,581,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.dll [2009/06/11 20:35:02 | 06,069,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieframe.dll [2009/06/11 20:35:02 | 01,166,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\urlmon.dll [2009/06/11 20:35:01 | 00,827,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wininet.dll [2009/06/11 20:35:01 | 00,389,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll [2009/06/11 20:35:01 | 00,270,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iertutil.dll [2009/06/11 20:35:00 | 00,458,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll [2009/06/11 20:35:00 | 00,389,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec [2009/06/11 20:35:00 | 00,230,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieaksie.dll [2009/06/11 20:35:00 | 00,102,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\occache.dll [2009/06/11 20:35:00 | 00,026,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe [2009/06/11 20:34:59 | 01,383,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb [2009/06/11 20:34:59 | 00,671,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll [2009/06/11 20:34:59 | 00,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieencode.dll [2009/06/11 20:34:59 | 00,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll [2009/06/05 00:13:09 | 00,010,752 | ---- | C] () -- C:\Users\Nikole\Documents\photographers.xlr [2009/06/04 23:40:09 | 00,618,340 | ---- | C] () -- C:\Users\Nikole\Desktop\hollandarts_rates.pdf [2009/06/04 23:39:37 | 02,081,880 | ---- | C] () -- C:\Users\Nikole\Desktop\hollandarts_extras.pdf [2009/06/04 23:38:27 | 00,200,163 | ---- | C] () -- C:\Users\Nikole\Desktop\garland_rates.pdf [2009/06/04 23:37:47 | 00,122,368 | ---- | C] () -- C:\Users\Nikole\Desktop\triano_rates.wps [2009/06/04 23:33:14 | 00,092,074 | ---- | C] () -- C:\Users\Nikole\Desktop\fariello_rates.pdf [2009/05/31 22:33:24 | 00,301,486 | ---- | C] () -- C:\Users\Nikole\Desktop\turtlepond.pdf [2008/09/21 07:26:25 | 01,953,696 | ---- | C] () -- C:\Windows\System32\igklg400.dll [2008/09/21 07:26:25 | 01,533,360 | ---- | C] () -- C:\Windows\System32\igklg450.dll [2008/09/21 07:26:25 | 00,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1409.dll [2008/09/21 07:26:25 | 00,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll [2008/09/21 07:26:25 | 00,004,608 | ---- | C] () -- C:\Windows\System32\HdmiCoin.dll [2008/09/21 07:26:21 | 00,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll [2008/09/21 04:51:41 | 00,055,808 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll [2006/11/02 08:35:32 | 00,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 06:25:44 | 00,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll [2006/11/02 06:23:31 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini [2006/11/02 06:23:31 | 00,000,144 | ---- | C] () -- C:\Windows\win.ini [2006/11/02 03:40:29 | 00,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini ========== Files - Modified Within 30 Days ========== [2009/06/16 00:41:10 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI [2009/06/16 00:41:10 | 00,595,684 | ---- | M] () -- C:\Windows\System32\perfh009.dat [2009/06/16 00:41:10 | 00,101,350 | ---- | M] () -- C:\Windows\System32\perfc009.dat [2009/06/16 00:33:57 | 00,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2009/06/16 00:33:57 | 00,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2009/06/16 00:33:55 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT [2009/06/16 00:33:53 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2009/06/16 00:33:50 | 32,107,84768 | -HS- | M] () -- C:\hiberfil.sys [2009/06/16 00:32:10 | 02,490,912 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.dat [2009/06/16 00:32:10 | 00,327,712 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox2.dat [2009/06/16 00:32:10 | 00,021,588 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox.idx [2009/06/16 00:32:10 | 00,002,200 | -HS- | M] () -- C:\Windows\System32\drivers\fidbox2.idx [2009/06/16 00:00:16 | 00,000,820 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2009/06/15 23:48:47 | 00,000,735 | ---- | M] () -- C:\Users\Nikole\Desktop\NTREGOPT.lnk [2009/06/15 23:48:46 | 00,000,716 | ---- | M] () -- C:\Users\Nikole\Desktop\ERUNT.lnk [2009/06/15 22:44:23 | 00,031,781 | ---- | M] () -- C:\Users\Nikole\Desktop\bookmarks.html [2009/06/12 21:06:13 | 00,271,432 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT [2009/06/11 23:13:28 | 00,001,500 | ---- | M] () -- C:\Users\Nikole\Desktop\index.html [2009/06/09 23:58:18 | 00,011,776 | ---- | M] () -- C:\Users\Nikole\Documents\budget_reflection.xlr [2009/06/09 23:58:18 | 00,001,326 | ---- | M] () -- C:\Users\Nikole\AppData\Roaming\wklnhst.dat [2009/06/05 00:52:07 | 00,010,752 | ---- | M] () -- C:\Users\Nikole\Documents\photographers.xlr [2009/06/04 23:40:09 | 00,618,340 | ---- | M] () -- C:\Users\Nikole\Desktop\hollandarts_rates.pdf [2009/06/04 23:39:37 | 02,081,880 | ---- | M] () -- C:\Users\Nikole\Desktop\hollandarts_extras.pdf [2009/06/04 23:38:27 | 00,200,163 | ---- | M] () -- C:\Users\Nikole\Desktop\garland_rates.pdf [2009/06/04 23:37:47 | 00,122,368 | ---- | M] () -- C:\Users\Nikole\Desktop\triano_rates.wps [2009/06/04 23:33:14 | 00,092,074 | ---- | M] () -- C:\Users\Nikole\Desktop\fariello_rates.pdf [2009/06/01 12:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mrt.exe [2009/05/31 22:33:24 | 00,301,486 | ---- | M] () -- C:\Users\Nikole\Desktop\turtlepond.pdf [2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys [2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2009/05/20 22:23:22 | 00,105,395 | ---- | M] () -- C:\Windows\System32\drivers\klin.dat [2009/05/20 22:23:22 | 00,094,643 | ---- | M] () -- C:\Windows\System32\drivers\klick.dat < End of report > OTL Extras logfile created on: 6/16/2009 12:45:29 AM - Run 1 OTL by OldTimer - Version 2.1.1.0 Folder = C:\Users\Nikole\Downloads Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation Internet Explorer (Version = 7.0.6001.18000) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 2.00 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 91.54% Memory free 4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 220.58 Gb Total Space | 175.65 Gb Free Space | 79.63% Space Free | Partition Type: NTFS Drive D: | 9.77 Gb Total Space | 4.82 Gb Free Space | 49.37% Space Free | Partition Type: NTFS E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: PC Current User Name: Nikole Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Output = Minimal File Age = 30 Days Company Name Whitelist: On ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation) .hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation) .html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) .url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] "DisableMonitoring" = 1 "" = [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 Reg Error: Unknown registry data type File not found [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile "EnableFirewall" = 0 "DisableNotifications" = 0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile "EnableFirewall" = 0 "DisableNotifications" = 0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile "EnableFirewall" = 0 "DisableNotifications" = 0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts\List ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications\List] ========== Vista Active Open Ports Exception List ========== ========== Vista Active Application Exception List ========== {5787CBE9-0AC0-48D9-92EB-763D69AD9512} = DIR=IN | APP=C:\PROGRAM FILES\DELL\MEDIADIRECT\KERNEL\DMP\CLBROWSERENGINE.EXE | {85AB9791-2830-4715-B25B-C9F12FC1D2CD} = DIR=IN | APP=C:\PROGRAM FILES\DELL\MEDIADIRECT\PCMSERVICE.EXE | {B076ECE7-4193-4BD4-A970-3C451CE33569} = DIR=IN | APP=C:\PROGRAM FILES\DELL\MEDIADIRECT\MEDIADIRECT.EXE | {B3A5E6EA-382C-49E0-A398-B48D74561F97} = DIR=IN | APP=C:\PROGRAM FILES\DELL\MEDIADIRECT\KERNEL\DMS\CLMSSERVICE.EXE | ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data "{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE "{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works "{1D5E29AD-39A9-4D0A-A8B6-46A6FCD8C995}" = Live! Cam Avatar v1.0 "{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools "{294EAADF-E50F-4DD8-AD8D-19587EA10512}" = Modem Diagnostic Tool "{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager "{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5 "{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting "{4B6AD248-D3BF-426A-8D64-847288154F13}" = QuickSet "{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector "{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3 "{669C7BD8-DAA2-49B6-966C-F1E2AAE6B17E}" = Cisco PEAP Module "{6B7B6D4D-8F9B-4CB3-8CA4-BCA9CC4C1A22}" = EDocs "{6D3963B0-E13B-4FC3-B0FF-506A304BB043}" = Cisco EAP-FAST Module "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio "{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide "{83770D14-21B9-44B3-8689-F7B523F94560}" = Cisco LEAP Module "{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}" = Kaspersky Internet Security 2009 "{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system "{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager "{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English) "{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup "{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad "{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0 "{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy "{B935C985-A17F-484B-8470-09E4FC27DC26}" = Dell-eBay "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center "{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect "{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE "{F6CB42B9-F033-4152-8813-FF11DA8E6A78}" = Dell Dock "Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Advanced Audio FX Engine" = Advanced Audio FX Engine "Advanced Video FX Engine" = Advanced Video FX Engine "Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card Utility "CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F" = Conexant HDA D330 MDC V.92 Modem "Creative OEM002" = Laptop Integrated Webcam Driver (1.04.01.1011) "Dell Webcam Center" = Dell Webcam Center "Dell Webcam Manager" = Dell Webcam Manager "ERUNT_is1" = ERUNT 1.1j "Google Desktop" = Google Desktop "GoToAssist" = GoToAssist 8.0.0.514 "InstallWIX_{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}" = Kaspersky Internet Security 2009 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11) ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 6/15/2009 11:02:59 PM | Computer Name = PC | Source = Windows Search Service | ID = 9000 Description = Error - 6/15/2009 11:03:00 PM | Computer Name = PC | Source = Windows Search Service | ID = 1006 Description = Error - 6/15/2009 11:03:42 PM | Computer Name = PC | Source = ESENT | ID = 489 Description = Windows (3124) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ". The open file operation will fail with error -1032 (0xfffffbf8). Error - 6/15/2009 11:03:42 PM | Computer Name = PC | Source = ESENT | ID = 455 Description = Windows (3124) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Error - 6/15/2009 11:03:52 PM | Computer Name = PC | Source = ESENT | ID = 489 Description = Windows (3124) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" for read only access failed with system error 5 (0x00000005): "Access is denied. ". The open file operation will fail with error -1032 (0xfffffbf8). Error - 6/15/2009 11:03:52 PM | Computer Name = PC | Source = ESENT | ID = 455 Description = Windows (3124) Windows: Error -1032 (0xfffffbf8) occurred while opening logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. Error - 6/15/2009 11:03:52 PM | Computer Name = PC | Source = Windows Search Service | ID = 9000 Description = Error - 6/15/2009 11:03:52 PM | Computer Name = PC | Source = Windows Search Service | ID = 1006 Description = Error - 6/15/2009 11:07:44 PM | Computer Name = PC | Source = EventSystem | ID = 4609 Description = Error - 6/15/2009 11:08:19 PM | Computer Name = PC | Source = WinMgmt | ID = 10 Description = [ Broadcom Wireless LAN Events ] Error - 3/23/2009 12:01:56 AM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 00:01:56, Mon, Mar 23, 09 Error - User "" does not have administrative privileges on this system Error - 3/23/2009 5:26:37 PM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 17:26:37, Mon, Mar 23, 09 Error - User "" does not have administrative privileges on this system Error - 3/27/2009 12:18:39 AM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 00:18:39, Fri, Mar 27, 09 Error - User "" does not have administrative privileges on this system Error - 3/29/2009 10:16:47 PM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 22:16:47, Sun, Mar 29, 09 Error - User "" does not have administrative privileges on this system Error - 4/1/2009 11:40:30 PM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 23:40:30, Wed, Apr 01, 09 Error - User "" does not have administrative privileges on this system Error - 4/5/2009 12:04:20 AM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 00:04:20, Sun, Apr 05, 09 Error - User "" does not have administrative privileges on this system Error - 4/8/2009 12:57:27 AM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 00:57:27, Wed, Apr 08, 09 Error - User "" does not have administrative privileges on this system Error - 4/14/2009 10:37:26 PM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 22:37:26, Tue, Apr 14, 09 Error - User "" does not have administrative privileges on this system Error - 4/15/2009 12:09:04 AM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 00:09:04, Wed, Apr 15, 09 Error - User "" does not have administrative privileges on this system Error - 5/6/2009 8:56:52 PM | Computer Name = PC | Source = WLAN-Tray | ID = 0 Description = 20:56:52, Wed, May 06, 09 Error - Unable to gain access to user store [ System Events ] Error - 5/27/2009 9:50:59 PM | Computer Name = PC | Source = HTTP | ID = 15016 Description = Error - 5/27/2009 9:51:26 PM | Computer Name = PC | Source = Service Control Manager | ID = 7000 Description = Error - 5/28/2009 8:32:52 PM | Computer Name = PC | Source = HTTP | ID = 15016 Description = Error - 5/28/2009 8:33:17 PM | Computer Name = PC | Source = Service Control Manager | ID = 7000 Description = Error - 5/30/2009 11:56:24 AM | Computer Name = PC | Source = HTTP | ID = 15016 Description = Error - 5/30/2009 11:56:54 AM | Computer Name = PC | Source = Service Control Manager | ID = 7000 Description = Error - 5/30/2009 4:46:16 PM | Computer Name = PC | Source = iaStor | ID = 262153 Description = The device, \Device\Ide\iaStor0, did not respond within the timeout period. Error - 5/31/2009 4:50:07 PM | Computer Name = PC | Source = HTTP | ID = 15016 Description = Error - 5/31/2009 4:50:35 PM | Computer Name = PC | Source = Service Control Manager | ID = 7000 Description = Error - 6/1/2009 7:13:43 PM | Computer Name = PC | Source = HTTP | ID = 15016 Description = < End of report > This post has been edited by wwwjunkie: Jun 17 2009, 10:25 PM |
|
|
Jun 26 2009, 11:38 AM
Post
#2
|
|
![]() GeekU Moderator Posts: 18,766 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Hi there and sorry for the delay I will need a fresh look at your system and what are your current symptoms
To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link. Download OTS to your Desktop
Please attach the log in your next post. To attach a file, do the following:
|
|
|
Jun 27 2009, 08:43 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows XP |
|
|
|
Jun 28 2009, 05:08 AM
Post
#4
|
|
![]() GeekU Moderator Posts: 18,766 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Nothing jumps out at me there but as your AV has stopped working I will need to look deeper
Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop. Link 1 Link 2 Link 3 ![]() ![]() -------------------------------------------------------------------- Double click on Combo-Fix.exe & follow the prompts.
|
|
|
Jun 28 2009, 04:12 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows XP |
Ok, here are the logs.
combolog_28jun09.txt ( 10.91K )
Number of downloads: 105
otl_28jun09.Txt ( 79.84K )
Number of downloads: 6ComboFix 09-06-26.02 - Nikole 06/28/2009 17:58.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3061.2097 [GMT -4:00] Running from: c:\users\Nikole\Desktop\Combo-Fix.exe AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 ))))))))))))))))))))))))))))))) . 2009-06-28 21:57 . 2009-06-28 21:57 -------- d-----w- C:\32788R22FWJFW.0.tmp 2009-06-28 21:35 . 2009-06-28 21:35 -------- d-sh--w- C:\found.009 2009-06-28 02:35 . 2009-06-28 02:35 -------- d-sh--w- C:\found.008 2009-06-26 04:02 . 2009-06-26 04:02 -------- d-sh--w- C:\found.007 2009-06-26 03:20 . 2009-06-26 03:20 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2009-06-26 03:20 . 2009-06-28 21:43 -------- d-----w- c:\users\Nikole\AppData\Roaming\SUPERAntiSpyware.com 2009-06-26 03:20 . 2009-06-28 21:43 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-06-26 02:42 . 2009-06-26 02:42 -------- d-----w- c:\windows\Sun 2009-06-18 07:52 . 2009-06-18 07:52 -------- d-sh--w- C:\found.005 2009-06-18 04:22 . 2009-06-18 04:22 -------- d-sh--w- C:\found.006 2009-06-17 03:37 . 2009-06-17 03:37 -------- d-sh--w- C:\found.004 2009-06-17 03:03 . 2009-06-17 03:03 -------- d-sh--w- C:\found.003 2009-06-16 05:19 . 2009-06-16 05:19 410984 ----a-w- c:\windows\system32\deploytk.dll 2009-06-16 05:18 . 2009-06-16 05:18 -------- d-----w- c:\programdata\McAfee 2009-06-16 03:50 . 2009-06-16 03:50 -------- d-----w- c:\users\Nikole\AppData\Roaming\Malwarebytes 2009-06-16 03:50 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-16 03:50 . 2009-06-16 03:50 -------- d-----w- c:\programdata\Malwarebytes 2009-06-16 03:50 . 2009-06-16 04:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-06-16 03:50 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-06-16 03:48 . 2009-06-16 03:48 -------- d-----w- c:\program files\ERUNT 2009-06-16 03:23 . 2009-06-16 03:23 -------- d-sh--w- C:\found.002 2009-06-15 03:48 . 2009-06-15 03:48 -------- d-sh--w- C:\found.001 2009-06-15 03:00 . 2009-06-15 03:00 -------- d-sh--w- C:\found.000 2009-06-12 00:34 . 2009-04-24 16:02 78336 ----a-w- c:\windows\system32\ieencode.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-28 21:58 . 2009-04-15 02:34 393248 --sha-w- c:\windows\system32\drivers\fidbox2.dat 2009-06-28 21:57 . 2009-04-15 02:34 2424 --sha-w- c:\windows\system32\drivers\fidbox2.idx 2009-06-28 21:56 . 2009-04-15 02:34 -------- d-----w- c:\programdata\Kaspersky Lab 2009-06-28 02:33 . 2009-04-15 02:34 2537504 --sha-w- c:\windows\system32\drivers\fidbox.dat 2009-06-28 02:33 . 2009-04-15 02:34 21952 --sha-w- c:\windows\system32\drivers\fidbox.idx 2009-06-26 04:32 . 2008-09-21 08:43 -------- d-----w- c:\program files\Java 2009-06-26 03:42 . 2009-03-22 00:14 6648 ----a-w- c:\users\Nikole\AppData\Local\d3d9caps.dat 2009-06-26 01:38 . 2009-01-21 01:28 1326 ----a-w- c:\users\Nikole\AppData\Roaming\wklnhst.dat 2009-06-18 04:41 . 2009-04-15 02:34 94643 ----a-w- c:\windows\system32\drivers\klick.dat 2009-06-18 04:41 . 2009-04-15 02:34 105395 ----a-w- c:\windows\system32\drivers\klin.dat 2009-06-15 03:38 . 2008-09-21 09:03 -------- d-----w- c:\program files\Microsoft Works 2009-06-15 03:38 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2009-04-24 16:05 . 2009-06-12 00:35 827904 ----a-w- c:\windows\system32\wininet.dll 2009-04-24 13:44 . 2009-06-12 00:35 26624 ----a-w- c:\windows\system32\ieUnatt.exe 2009-04-23 12:43 . 2009-06-12 00:35 784896 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-23 12:42 . 2009-06-12 00:35 636928 ----a-w- c:\windows\system32\localspl.dll 2009-04-21 11:55 . 2009-06-12 00:35 2033152 ----a-w- c:\windows\system32\win32k.sys 2009-04-15 02:46 . 2008-01-29 22:29 33808 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-04-15 02:46 . 2009-04-15 02:46 44808 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\fssync.dll 2009-04-15 02:46 . 2009-04-15 02:46 33808 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\klbg.sys 2009-04-15 02:46 . 2009-04-15 02:46 224272 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\Vista\klif.sys 2009-04-15 02:46 . 2009-04-15 02:46 206088 ----a-w- c:\programdata\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.454\avp.exe 2008-09-21 08:47 . 2008-09-21 08:47 76 --sh--r- c:\windows\CT4CET.bin 2008-09-21 11:19 . 2008-09-21 11:17 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-05-04 167936] "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-07-03 3563520] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-21 29744] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-15 206088] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-16 148888] c:\users\Nikole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-9-21 50688] QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2008-09-21 09:06 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\adialhk.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{B076ECE7-4193-4BD4-A970-3C451CE33569}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect "{85AB9791-2830-4715-B25B-C9F12FC1D2CD}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program "{5787CBE9-0AC0-48D9-92EB-763D69AD9512}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine "{B3A5E6EA-382C-49E0-A398-B48D74561F97}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [1/29/2008 6:29 PM 33808] R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [7/9/2008 6:28 PM 20496] R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [9/20/2008 11:30 PM 73728] R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [5/2/2008 3:09 PM 161048] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\System32\drivers\IntcHdmi.sys [9/21/2008 7:26 AM 111616] R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\System32\drivers\klfltdev.sys [3/13/2008 7:02 PM 26640] R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [9/21/2008 7:26 AM 235648] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [9/21/2008 7:26 AM 7424] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm FF - ProfilePath - c:\users\Nikole\AppData\Roaming\Mozilla\Firefox\Profiles\3imazx2c.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-28 18:02 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2009-06-28 18:04 ComboFix-quarantined-files.txt 2009-06-28 22:04 Pre-Run: 213,732,519,936 bytes free Post-Run: 213,676,707,840 bytes free Current=1 Default=1 Failed=0 LastKnownGood=9 Sets=1,2,3,4,5,6,7,8,9 150 |
|
|
Jun 28 2009, 04:16 PM
Post
#6
|
|
![]() GeekU Moderator Posts: 18,766 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Your AV is disabled - did you do that ?
If not can you re-install it and let me know the result |
|
|
Jun 28 2009, 10:01 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows XP |
Yes, I disabled it to run Combo Fix since it suggested Kaspersky could interfere with the scan. I turned it back on after running CF and OTL. Should I try to run another AV scan even though it wasn't detecting anything last week?
|
|
|
Jun 29 2009, 01:11 PM
Post
#8
|
|
![]() GeekU Moderator Posts: 18,766 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
No if you could let me know if you are still having problems with Firefox after this little run
Download TFC to your desktop
THEN Download and run Auslogics Disc Defragmenter |
|
|
Jun 29 2009, 09:28 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows XP |
I ran TFC. But I cannot run the Defragmenter. It gets to 14% and then my computer locks up. I've tried at least five times. Thoughts?
|
|
|
Jun 30 2009, 11:31 AM
Post
#10
|
|
![]() GeekU Moderator Posts: 18,766 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Lets check that there is nothing wrong with your disc
Manual steps to run Chkdsk from My Computer or Windows Explorer 1. Double-click My Computer, and then right-click the hard disk that you want to check. 2. Click Properties, and then click Tools. 3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed, 4. Use one of the following procedures: • To run Chkdsk in read-only mode, click Start. • To repair errors without scanning the volume for bad sectors, select the Automatically fix file system errors check box, and then click Start. • To repair errors, locate bad sectors, and recover readable information, select the Scan for and attempt recovery of bad sectors check box, and then click Start. Note If one or more of the files on the hard disk are open, you will receive the following message: The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer? Click Yes to schedule the disk check, and then restart your computer to start the disk check. |
|
|
Jul 1 2009, 08:45 PM
Post
#11
|
|
|
Member ![]() ![]() Posts: 13 OS: Windows XP |
Ok it took a couple of tries and a few hard powering downs, but I was finally able to run the disk check on both drives. Then I defragged them. It ran for a few minutes longer but then it froze again. Now it is back to freezing every 5-10 minutes. Do you think it's a virus or something wrong with the laptop itself?
This post has been edited by wwwjunkie: Jul 1 2009, 08:46 PM |
|
|
Jul 4 2009, 02:44 AM
Post
#12
|
|
![]() GeekU Moderator Posts: 18,766 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
I am sorry for the delay I have some severe internet problems I should be back on line by wednesday - sorry
|
|
|
Jul 7 2009, 03:05 PM
Post
#13
|
|
![]() GeekU Moderator Posts: 18,766 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Hi I am back again now, I would suspect that it is a hardware problem. Are you still experiencing the freezing ?
|
|
|
Jul 12 2009, 10:51 AM
Post
#14
|
|
![]() GeekU Moderator Posts: 18,766 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
14 / 1,978 | 22nd June 2005 - 07:06 PM sp0ke started - last by greyknight17 |
|||||
![]() |
2 / 217 | 28th July 2006 - 07:12 PM shambe started - last by greyknight17 |
|||||
![]() |
6 / 130 | 2nd November 2009 - 02:47 PM Test-Subject started - last by hammerman |
|||||
![]() |
10 / 69 | 4th November 2009 - 05:14 PM fastiriwn started - last by Rorschach112 |
|||||
|
Time is now: 8th November 2009 - 01:09 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising