Author Topic: slllllloooooooooowwwwwww help  (Read 621 times)

0 Members and 1 Guest are viewing this topic.

Offline debralcola

  • Newbie
  • *
  • Posts: 31
slllllloooooooooowwwwwww help
« on: February 03, 2012, 12:37:51 AM »
My computer is just so slow last couple of months. I am trying to clean it up and help it not be so sluggish. When I want to get on the internet it just says not responding and takes about 2 - 3 minutes to load.
I could not get the RSIT to give me two reports, it would only do the log. I tried 3 times...? :sos:


 Results of screen317's Security Check version 0.99.30 
 Windows 7 Service Pack 1 x86   
 Internet Explorer 9 
``````````````````````````````
Antivirus/Firewall Check:

 Windows Firewall Enabled! 
 Avira AntiVir Personal - Free Antivirus
 WMI entry may not exist for antivirus; attempting automatic update.
 Avira successfully updated!
```````````````````````````````
Anti-malware/Other Utilities Check:

 Java(TM) 6 Update 29 
 Java version out of date!
 Adobe Flash Player    11.1.102.55 
 Adobe Reader 9 Adobe Reader out of date!
 Mozilla Firefox 8.0.1 Firefox out of Date! 
````````````````````````````````
Process Check: 
objlist.exe by Laurent

 WinPatrol winpatrol.exe
 Avira Antivir avgnt.exe
 Avira Antivir avguard.exe
 BillP Studios WinPatrol WinPatrol.exe 
``````````End of Log````````````

Logfile of random's system information tool 1.09 (written by random/random)
Run by Debra Lopez at 2012-02-02 20:01:58
Microsoft Windows 7 Home Premium  Service Pack 1
System drive C: has 7 GB (18%) free of 37 GB
Total RAM: 512 MB (10% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:02:43 PM, on 2/2/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Debra Lopez\Downloads\RSIT.exe
C:\Program Files\trend micro\Debra Lopez.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=BNHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Yontoo Layer (Drop Down Deals)s - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Runtime (Drop Down Deals)\YontooIEClient.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Click to call with Skype - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{718EA244-D67D-44BD-9AA7-9193438B00B0}: NameServer = 192.168.0.1 0.0.0.0
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: Advanced SystemCare Service (AdvancedSystemCareService) - IObit - C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbl_device -   - C:\Windows\system32\lxblcoms.exe
O23 - Service: lxdpCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdpserv.exe
O23 - Service: lxdp_device -   - C:\Windows\system32\lxdpcoms.exe
O23 - Service: SmartLinkService (SLService) -   - C:\Windows\SYSTEM32\slserv.exe

--
End of file - 7308 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Debra Lopez\AppData\Roaming\Mozilla\Firefox\Profiles\ojjfhca9.default

prefs.js - "browser.startup.homepage" -  "http://www.bing.com/|http://www.google.com/webhp?hl=en"
prefs.js - "extensions.enabledItems" -  "searchtoolbar@zugo.com:1.2, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.16"
prefs.js - "keyword.URL" -  "http://www.bing.com/search?pc=Z039&form=ZGAADF&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 10.1 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin]
"Description"=This plugin detects and launches Pando Media Booster
"Path"=C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll

C:\Program Files\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
{972ce4c6-7e08-4474-a285-3208198ce6fd}
{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}

C:\Program Files\Mozilla Firefox\components\
binary.manifest
browsercomps.dll
nsIQTScriptablePlugin.xpt

C:\Program Files\Mozilla Firefox\plugins\
npdeployJava1.dll
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class

C:\Program Files\Mozilla Firefox\searchplugins\
amazondotcom.xml
bing.xml
eBay.xml
google.xml
twitter.xml
wikipedia.xml
yahoo.xml

C:\Users\Debra Lopez\AppData\Roaming\Mozilla\Firefox\Profiles\ojjfhca9.default\extensions\
coralietab@mozdev.org
plugin@yontoo.com

C:\Users\Debra Lopez\AppData\Roaming\Mozilla\Firefox\Profiles\ojjfhca9.default\searchplugins\
bing-zugo.xml

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-09-22 61888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-09-22 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28 441216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D425283-D487-4337-BAB6-AB8354A81457}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9FDDE16B-836F-4806-AB1F-1455CBEFF289}]
Windows Live Messenger Companion Helper - C:\Program Files\Windows Live\Companion\companioncore.dll [2011-05-13 393600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-01-14 342128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Browser Helper - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-07-11 3821568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-10-18 42272]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
Yontoo Layers (Drop Down Deals) - C:\Program Files\Yontoo Layers Runtime (Drop Down Deals)\YontooIEClient.dll [2011-08-11 196384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9D425283-D487-4337-BAB6-AB8354A81457}
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2012-01-14 342128]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2011-01-10 281768]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2011-05-15 325512]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-06-09 254696]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2011-10-24 421888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 4"=C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe [2011-08-09 417112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
C:\Windows\system32\Ati2mdxx.exe [2005-01-19 25088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath]
C:\Windows\VM_STI.EXE [2003-01-21 40960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
C:\Program Files\Lexmark Z2300 Series\ezprint.exe [2008-03-27 107176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2011-10-09 421736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdpmon.exe]
C:\Program Files\Lexmark Z2300 Series\lxdpmon.exe [2008-03-27 656040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\Windows\system32\\NeroCheck.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2011-10-24 421888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HotKeyDetect.lnk]
C:\Windows\HOTKEY~1.EXE [2006-05-24 163935]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SnapDetect.lnk]
C:\Windows\SNAPDE~1.EXE [2005-12-13 168021]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\Windows\system32\Ati2evxx.dll [2005-01-19 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\system32\webcheck.dll [2011-04-10 203776]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rootrepeal.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=serwvdrv.dll
"msacm.msaudio1"=msaud32.acm
"msacm.sl_anet"=sl_anet.acm
"wave2"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"wave3"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"msacm.siren"=sirenacm.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2012-01-28 08:50:55 ----A---- C:\Windows\system32\schannel.dll
2012-01-28 08:50:54 ----A---- C:\Windows\system32\lsasrv.dll
2012-01-28 08:50:54 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2012-01-28 08:50:54 ----A---- C:\Windows\system32\drivers\cng.sys
2012-01-28 08:50:52 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2012-01-28 08:50:50 ----A---- C:\Windows\system32\lsass.exe
2012-01-28 08:50:49 ----A---- C:\Windows\system32\webio.dll
2012-01-28 08:50:45 ----A---- C:\Windows\system32\sspicli.dll
2012-01-28 08:50:43 ----A---- C:\Windows\system32\secur32.dll
2012-01-28 08:50:42 ----A---- C:\Windows\system32\sspisrv.dll
2012-01-12 22:13:52 ----A---- C:\Windows\system32\ntdll.dll
2012-01-12 22:13:50 ----A---- C:\Windows\system32\packager.dll
2012-01-12 22:13:46 ----A---- C:\Windows\system32\quartz.dll
2012-01-12 22:13:45 ----A---- C:\Windows\system32\qdvd.dll

======List of files/folders modified in the last 1 month======

2012-02-02 20:02:31 ----D---- C:\Program Files\trend micro
2012-02-02 19:59:25 ----D---- C:\Windows\Prefetch
2012-02-02 19:31:38 ----D---- C:\Windows\system32\config
2012-02-02 19:07:47 ----D---- C:\Windows\Temp
2012-02-01 22:48:40 ----D---- C:\Windows\system32\DriverStore
2012-02-01 21:56:15 ----SHD---- C:\Windows\Installer
2012-01-29 15:48:12 ----D---- C:\Windows\System32
2012-01-29 15:48:12 ----D---- C:\Windows\inf
2012-01-29 15:48:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2012-01-29 08:01:02 ----D---- C:\Windows\winsxs
2012-01-29 07:55:13 ----D---- C:\Windows\system32\drivers
2012-01-29 07:32:55 ----SHD---- C:\System Volume Information
2012-01-28 08:18:23 ----D---- C:\Windows\system32\catroot2
2012-01-27 22:08:21 ----D---- C:\Windows\system32\catroot
2012-01-14 18:36:24 ----A---- C:\Windows\win.ini
2012-01-14 17:58:45 ----D---- C:\Windows\debug
2012-01-14 17:58:29 ----A---- C:\Windows\system32\MRT.exe
2012-01-14 17:57:41 ----D---- C:\Windows\ehome
2012-01-10 22:23:22 ----D---- C:\Windows\Microsoft.NET
2012-01-10 22:22:05 ----RSD---- C:\Windows\assembly
2012-01-04 21:23:22 ----D---- C:\Windows
2012-01-03 23:21:19 ----D---- C:\Windows\Minidump

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R0 RecAgent;RecAgent; C:\Windows\system32\DRIVERS\RecAgent.sys [2003-10-28 14160]
R0 SmartDefragDriver;SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [2010-11-26 15672]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2011-07-10 138192]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2011-07-10 66616]
R2 irda;IrDA Protocol; C:\Windows\system32\DRIVERS\irda.sys [2009-07-13 96768]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\Windows\system32\drivers\RTKVAC.SYS [2009-06-19 4172832]
R3 ati2mtag;ati2mtag; C:\Windows\system32\DRIVERS\ati2mtag.sys [2005-01-19 965632]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\Windows\system32\drivers\MODEMCSA.sys [2009-07-13 18432]
R3 Mtlmnt5;Mtlmnt5; C:\Windows\system32\DRIVERS\Mtlmnt5.sys [2003-10-28 226288]
R3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista; C:\Windows\system32\DRIVERS\NETw2v32.sys [2007-03-06 2595840]
R3 NSCIRDA;NSC Infrared Device Driver; C:\Windows\system32\DRIVERS\nscirda.sys [2008-01-19 30720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2010-08-12 27632]
R3 Slntamr;SmartLink AMR_PCI Driver; C:\Windows\system32\DRIVERS\slntamr.sys [2003-11-08 566256]
R3 SlWdmSup;SlWdmSup; C:\Windows\system32\DRIVERS\SlWdmSup.sys [2003-10-28 15712]
R3 tiumfwl;tiumfwl; C:\Windows\system32\drivers\tiumfwl.sys [2003-02-18 42092]
R3 ZTEusbwwan;ZTE MBN Miniport; C:\Windows\system32\DRIVERS\ZTEusbwwan.sys [2011-04-09 193536]
S2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-13 8704]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-13 70720]
S3 ALCXSENS;Service for WDM 3D Audio Driver; C:\Windows\system32\drivers\ALCXSENS.SYS [2003-12-11 391424]
S3 amdagp;AMD AGP Bus Filter Driver; C:\Windows\system32\drivers\amdagp.sys [2009-07-13 53312]
S3 ARCSOFTVIRTUALCAPTURE;Magic-i Virtual Driver; C:\Windows\system32\DRIVERS\ArcSoftVirtualCapture.sys [2006-12-07 15104]
S3 avshws;Senstic PocketCam; C:\Windows\system32\DRIVERS\camsource.sys [2010-07-05 29000]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 catchme;catchme; C:\Windows\system32\drivers\catchme.sys []
S3 cpuz132;cpuz132; C:\Windows\system32\drivers\cpuz132.sys []
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2011-05-13 39272]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2010-08-12 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2010-08-12 25512]
S3 KMWDFILTERx86;HIDServiceDesc; C:\Windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 25088]
S3 Mtlstrm;Mtlstrm; C:\Windows\system32\DRIVERS\Mtlstrm.sys [2003-11-03 1299976]
S3 NtMtlFax;NtMtlFax; C:\Windows\system32\DRIVERS\NtMtlFax.sys [2003-10-28 180368]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-13 12368]
S3 PCTINDIS4;PCTINDIS4 NDIS Protocol Driver; \??\C:\Windows\system32\PCTINDIS4.SYS []
S3 PocketAudio;Senstic PocketAudio (WDM); C:\Windows\system32\drivers\senaudio.sys [2010-03-02 31304]
S3 sisagp;SIS AGP Bus Filter; C:\Windows\system32\drivers\sisagp.sys [2009-07-13 52304]
S3 SlNtHal;SlNtHal; C:\Windows\system32\DRIVERS\Slnthal.sys [2003-10-28 87656]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM); C:\Windows\system32\DRIVERS\sscebus.sys [2010-04-26 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter; C:\Windows\system32\DRIVERS\sscemdfl.sys [2010-04-26 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers; C:\Windows\system32\DRIVERS\sscemdm.sys [2010-04-26 123648]
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 52224]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2011-05-10 42496]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-13 35840]
S3 viaagp;VIA AGP Bus Filter; C:\Windows\system32\drivers\viaagp.sys [2009-07-13 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-13 52736]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 ZSMC301b;CMM PC Camera; C:\Windows\System32\Drivers\usbVM31b.sys [2003-11-27 90541]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdvancedSystemCareService;Advanced SystemCare Service; C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2011-07-10 269480]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-10-09 55144]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 390504]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2010-07-04 238952]
R2 Irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2009-07-13 20992]
R2 lxbl_device;lxbl_device; C:\Windows\system32\lxblcoms.exe [2007-04-20 537520]
R2 lxdp_device;lxdp_device; C:\Windows\system32\lxdpcoms.exe [2008-02-27 594600]
R2 SLService;SmartLinkService; C:\Windows\system32\slserv.exe [2003-10-28 45056]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\Windows\system32\Ati2evxx.exe [2005-01-19 344064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-30 135664]
S2 lxdpCATSCustConnectService;lxdpCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdpserv.exe [2009-04-28 94208]
S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe []
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2011-05-13 1492840]
S3 gupdatem;Google Update Service (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2010-09-30 135664]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-02-13 182768]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-10-09 821608]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-06-03 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service; C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]

-----------------EOF-----------------

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421  BrowserJavaVersion: 1.6.0_29
Run by Debra Lopez at 20:24:50 on 2012-02-02
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.512.76 [GMT -5:00]
.
AV: AntiVir Desktop *Enabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AntiVir Desktop *Enabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\FsUsbExService.Exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\lxblcoms.exe
C:\Windows\system32\lxdpcoms.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bing.com/?pc=BNHP
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Yontoo Layers (Drop Down Deals): {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers runtime (drop down deals)\YontooIEClient.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Advanced SystemCare 4] c:\program files\iobit\advanced systemcare 4\ASCTray.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{718EA244-D67D-44BD-9AA7-9193438B00B0} : NameServer = 192.168.0.1 0.0.0.0
TCP: Interfaces\{95244D9F-27B5-4C9B-83A4-0023D3BEED47} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{95244D9F-27B5-4C9B-83A4-0023D3BEED47}\155716C6964797 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{95244D9F-27B5-4C9B-83A4-0023D3BEED47}\34C434D27523 : DhcpNameServer = 64.89.74.2 64.89.70.2 192.168.2.1 64.89.74.2 64.89.70.2 64.89.74.2 192.168.5.1 64.89.74.2 64.89.70.2 192.168.2.1 64.89.74.2 64.89.70.2 64.89.74.2
TCP: Interfaces\{95244D9F-27B5-4C9B-83A4-0023D3BEED47}\6425F474F505F4E444 : DhcpNameServer = 192.168.0.1 192.168.1.254
TCP: Interfaces\{95244D9F-27B5-4C9B-83A4-0023D3BEED47}\6427565602D43644F6E616C6467237027596D26496 : DhcpNameServer = 192.168.1.1 64.134.255.2 64.134.255.10
TCP: Interfaces\{95244D9F-27B5-4C9B-83A4-0023D3BEED47}\65562796A7F6E602143433030293932313 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{95244D9F-27B5-4C9B-83A4-0023D3BEED47}\75169707F62747F5143636563737 : DhcpNameServer = 192.168.5.1 64.134.255.2 64.134.255.10
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: AtiExtEvent - Ati2evxx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\debra lopez\appdata\roaming\mozilla\firefox\profiles\ojjfhca9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/|http://www.google.com/webhp?hl=en
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z039&form=ZGAADF&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\users\debra lopez\appdata\roaming\mozilla\firefox\profiles\ojjfhca9.default\extensions\coralietab@mozdev.org\plugins\npCoralIETab.dll
.
---- FIREFOX POLICIES ----
.
FF - user.js: extentions.y2layers.installId - d07b98e1-5870-4736-93f1-af50c836625d
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock,BuzzdockTease,DropDownDeals,
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-9-29 15672]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-9-29 328536]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-2-15 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-2-15 269480]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-2-15 66616]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2011-6-26 238952]
R2 lxbl_device;lxbl_device;c:\windows\system32\lxblcoms.exe -service --> c:\windows\system32\lxblcoms.exe -service [?]
R2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe -service --> c:\windows\system32\lxdpcoms.exe -service [?]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2011-6-26 36608]
R3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2007-3-6 2595840]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-8-12 27632]
R3 ZTEusbwwan;ZTE MBN Miniport;c:\windows\system32\drivers\ZTEusbwwan.sys [2011-4-9 193536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-9-30 135664]
S2 lxdpCATSCustConnectService;lxdpCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdpserv.exe [2008-2-27 94208]
S3 avshws;Senstic PocketCam;c:\windows\system32\drivers\camsource.sys [2010-7-5 29000]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2011-9-30 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2011-5-13 1492840]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2010-8-12 13224]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-9-30 135664]
S3 KMWDFILTERx86;HIDServiceDesc;c:\windows\system32\drivers\KMWDFILTER.sys [2009-4-29 25088]
S3 PocketAudio;Senstic PocketAudio (WDM);c:\windows\system32\drivers\senaudio.sys [2010-3-2 31304]
S3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\drivers\sscebus.sys [2011-6-26 98560]
S3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\drivers\sscemdfl.sys [2011-6-26 14848]
S3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\drivers\sscemdm.sys [2011-6-26 123648]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-4 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-3 1343400]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2012-01-28 13:50:55   224768   ----a-w-   c:\windows\system32\schannel.dll
2012-01-28 13:50:54   369352   ----a-w-   c:\windows\system32\drivers\cng.sys
2012-01-28 13:50:54   134000   ----a-w-   c:\windows\system32\drivers\ksecpkg.sys
2012-01-28 13:50:54   1038848   ----a-w-   c:\windows\system32\lsasrv.dll
2012-01-28 13:50:52   67440   ----a-w-   c:\windows\system32\drivers\ksecdd.sys
2012-01-28 13:50:50   22528   ----a-w-   c:\windows\system32\lsass.exe
2012-01-28 13:50:49   314880   ----a-w-   c:\windows\system32\webio.dll
2012-01-28 13:50:45   100352   ----a-w-   c:\windows\system32\sspicli.dll
2012-01-28 13:50:43   22016   ----a-w-   c:\windows\system32\secur32.dll
2012-01-28 13:50:42   15872   ----a-w-   c:\windows\system32\sspisrv.dll
2012-01-13 03:13:52   1288472   ----a-w-   c:\windows\system32\ntdll.dll
2012-01-13 03:13:50   67072   ----a-w-   c:\windows\system32\packager.dll
2012-01-13 03:13:46   1328128   ----a-w-   c:\windows\system32\quartz.dll
2012-01-13 03:13:45   514560   ----a-w-   c:\windows\system32\qdvd.dll
2012-01-07 01:29:25   6823496   ----a-w-   c:\programdata\microsoft\windows defender\definition updates\{0d069fb5-d6c9-41c3-807e-344b00f27074}\mpengine.dll
.
==================== Find3M  ====================
.
2011-11-24 18:03:30   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 04:25:27   2342912   ----a-w-   c:\windows\system32\win32k.sys
2011-11-15 19:29:56   222080   ------w-   c:\windows\system32\MpSigStub.exe
2011-11-05 04:26:03   2048   ----a-w-   c:\windows\system32\tzres.dll
2011-06-26 06:05:19   166909440   ----a-w-   c:\program files\Samsung New PC Studio.msi
.
============= FINISH: 20:26:44.75 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 6/2/2010 8:02:15 PM
System Uptime: 2/2/2012 7:06:09 PM (1 hours ago)
.
Motherboard: KAPOK        |  | Intel 852/855GM
Processor: Intel(R) Pentium(R) M processor 1.80GHz | uPGA2 | 1799/1800mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 36 GiB total, 6.421 GiB free.
D: is CDROM (CDFS)
E: is CDROM (CDFS)
F: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description: T-Mobile Technologies MSM
Device ID: USB\VID_19D2&PID_0158&MI_00\6&7998D40&0&0000
Manufacturer:
Name: T-Mobile Technologies MSM
PNP Device ID: USB\VID_19D2&PID_0158&MI_00\6&7998D40&0&0000
Service:
.
Class GUID:
Description: T-Mobile Technologies MSM
Device ID: USB\VID_19D2&PID_0158&MI_01\6&7998D40&0&0001
Manufacturer:
Name: T-Mobile Technologies MSM
PNP Device ID: USB\VID_19D2&PID_0158&MI_01\6&7998D40&0&0001
Service:
.
Class GUID:
Description: T-Mobile Technologies MSM
Device ID: USB\VID_19D2&PID_0158&MI_02\6&7998D40&0&0002
Manufacturer:
Name: T-Mobile Technologies MSM
PNP Device ID: USB\VID_19D2&PID_0158&MI_02\6&7998D40&0&0002
Service:
.
Class GUID: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Description: CMM PC Camera
Device ID: USB\VID_0AC8&PID_301B\5&1C09B15C&0&2
Manufacturer: VM
Name: CMM PC Camera
PNP Device ID: USB\VID_0AC8&PID_301B\5&1C09B15C&0&2
Service: ZSMC301b
.
==== System Restore Points ===================
.
RP406: 1/29/2012 7:31:36 AM - Windows Update
.
==== Installed Programs ======================
.
Acrobat.com
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.4.5
Adobe Shockwave Player 11.6
Advanced SystemCare 4
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Display Driver
Avira AntiVir Personal - Free Antivirus
Bonjour
Click to Call with Skype
Compatibility Pack for the 2007 Office system
D3DX10
Driver Manager
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Internet TV for Windows Media Center
IrfanView (remove only)
iTunes
Java Auto Updater
Java(TM) 6 Update 29
Junk Mail filter update
Lexmark Z2300 Series
Lexmark Z700-P700 Series
MAGIX Slideshow Maker 2
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2000 Premium
Microsoft Office File Validation Add-In
Microsoft Office Outlook Connector
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 8.0.1 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Netflix in Windows Media Center
OGA Notifier 2.0.0048.0
OverDrive Media Console
Pando Media Booster
PhotoScape
QuickTime
Realtek AC'97 Audio
Samsung New PC Studio
SAMSUNG USB Driver for Mobile Phones
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Skype™ 5.5
Smart Defrag 2
swMSM
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
USB2.0 UVC Camera
Widevine Media Transformer Plugin 5.0.0
Windows 7 Upgrade Advisor
Windows Driver Package - eMPIA Technology Inc, (emAudio) MEDIA  (04/27/2007 5.7.0427.0)
Windows Driver Package - Orion Technology (DCamUSBET) Image  (05/10/2007 2.7.0510.1)
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Media Center Add-in for Flash
Windows Media Center Add-in for Silverlight
WinPatrol
Yontoo Layers Runtime (Drop Down Deals) 1.10.01
.
==== Event Viewer Messages From Past Week ========
.
2/2/2012 8:02:53 PM, Error: Service Control Manager [7016]  - The SmartLinkService service has reported an invalid current state 0.
2/2/2012 7:09:19 PM, Error: Service Control Manager [7000]  - The IPsec Policy Agent service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
2/2/2012 7:09:15 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the IPsec Policy Agent service to connect.
2/2/2012 7:07:25 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the lxdpCATSCustConnectService service to connect.
2/2/2012 7:07:25 PM, Error: Service Control Manager [7000]  - The lxdpCATSCustConnectService service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
2/2/2012 7:06:16 PM, Error: Microsoft-Windows-Kernel-Processor-Power [6]  - Some processor performance power management features have been disabled due to a known firmware problem. Check with the computer manufacturer for updated firmware.
1/31/2012 5:52:42 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1053" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69}
1/31/2012 5:52:40 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect.
1/31/2012 5:52:40 AM, Error: Service Control Manager [7000]  - The Google Update Service (gupdate) service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
1/31/2012 3:59:59 PM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
1/29/2012 3:50:55 PM, Error: Disk [11]  - The driver detected a controller error on \Device\Harddisk1\DR3.
1/29/2012 3:46:43 PM, Error: Disk [11]  - The driver detected a controller error on \Device\Harddisk1\DR2.
1/28/2012 8:29:16 AM, Error: NetBT [4307]  - Initialization failed because the transport refused to open initial addresses.
1/28/2012 8:22:15 AM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.
1/28/2012 8:21:05 AM, Error: Microsoft-Windows-DistributedCOM [10005]  - DCOM got error "1053" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
1/28/2012 8:20:40 AM, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the BITS service.
1/28/2012 8:20:40 AM, Error: Service Control Manager [7000]  - The Background Intelligent Transfer Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
1/28/2012 8:19:39 AM, Error: Service Control Manager [7022]  - The Internet Connection Sharing (ICS) service hung on starting.
1/27/2012 10:06:02 PM, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Peer Networking Identity Manager service to connect.
1/27/2012 10:06:02 PM, Error: Service Control Manager [7001]  - The Peer Networking Grouping service depends on the Peer Networking Identity Manager service which failed to start because of the following error:  The service did not respond to the start or control request in a timely fashion.
1/27/2012 10:06:02 PM, Error: Service Control Manager [7001]  - The Peer Name Resolution Protocol service depends on the Peer Networking Identity Manager service which failed to start because of the following error:  The service did not respond to the start or control request in a timely fashion.
1/27/2012 10:06:02 PM, Error: Service Control Manager [7000]  - The Peer Networking Identity Manager service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
 

Thanks to everyone for your help. :dance:

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: slllllloooooooooowwwwwww help
« Reply #1 on: February 03, 2012, 06:35:58 PM »
Hi, Debra.

The first thing that jumps out is that you are now running a program I do NOT recommend.  Registry cleaners do more damage than good, particularly one with a reputation for stealing other vendor's code!

About Registry Cleaners:

Windows is a closed source system. Developers of registry cleaners do not have the core code of Windows 7 and are not working on definitive information, but rather they are going on past knowledge and experience. Automatic cleaners will usually have to do some guesswork.

Modifying registry keys incorrectly can cause Windows instability, or make Windows unbootable. No registry cleaner is completely safe and the potential is ever present to cause more problems than they claim to fix.

Registry cleaners cannot distinguish between good and bad. If you run a registry cleaner, it will delete all those keys which are obsolete and sitting idle; but in reality, those keys may well be needed by some programs or windows at a later time.

Windows 7 is much more efficient at managing the registry than previous Windows versions.  If you run CCleaner or any other registry cleaner and do not know precisely what you are doing, you will have problems down the road. There are no gains to be had from using a registry cleaner and the risk is great.  The few keys will not make 1 millisecond's difference in performance, although incorrectly removed keys will certainly make a mess!

Forget all the "wisdom" you learned about XP. Windows 7 is not XP and does not manage the registry the same as XP.

From Microsoft at Increase PC speed: Optimize your computer, help your PC run faster:

Quote
Note: This article does not address or recommend tinkering with the registry files. Such activities can be detrimental to your computer and should only be attempted by properly trained professionals.

Also see Are registry cleaners necessary?

Should you at any time tinker with the registry, first create a backup.  See Back up the registry

About IObit:

Based on IOBit's past practices, I wouldn't run it on my computer.  See the following for additional information:
-- IOBit Steals Malwarebytes' Intellectual Property
-- IOBit’s Denial of Theft Unconvincing
-- IOBit Theft Conclusion

I strongly encourage you to uninstall the IObit program, Advanced SystemCare 4.  Before doing so, however, if IObit created a backup prior to running, you may end up solving errors by restoring that backup.

Outdated Programs:
Next. the following programs are out of date and have each had critical security vulnerabilities addressed in the updates:
  • The current updated version of Java(TM) 6 Update 30.  Be careful to UNcheck any offered toolbars or unneeded programs:  http://java.com/en/download/inc/windows_new_xpi.jsp
  • The current version of Adobe Reader is 10.1.2.  UNcheck the McAfee Security Scan Plus scan!  http://get.adobe.com/reader/
  • Mozilla Firefox 10 has been released.  To get the current version, select Help, About Firefox, Check for Updates.

After you have completed the above, please follow these instructions carefully.[/b]

Download ComboFix from one of the following locations:

Link 1
Link 2

!!! IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your antivirus and anti-malware security applications. If not disabled, these programs will likely interfere with cleanup process. This can usually be accomplished by a right-click on the icon in the System Tray. 

Note:  If you are unsure how to disable your security software, see the instructions in this topic at Tech Support Forum:  How to disable your security applications.

Now, please run ComboFix:
  • Note:  If infections are found, ComboFix will automatically reboot the machine to complete the removal process.  Please ensure all opened windows are closed before proceeding.
  • Double-click ComboFix.exe on your desktop and follow the prompts.
  • As part of the process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it is strongly recommended to have this pre-installed on your machine before doing any malware removal. The Recovery Console will allow you to start up the computer in a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    Please note: If the Microsoft Windows Recovery Console is already installed on the computer, ComboFix will continue the malware removal procedures.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console.
  • When prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

  • After the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

  • Click "Yes" to continue scanning for malware.
  • When finished, a log will be produced. Please include the C:\ComboFix.txt in your next reply.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline debralcola

  • Newbie
  • *
  • Posts: 31
Re: slllllloooooooooowwwwwww help
« Reply #2 on: February 06, 2012, 02:56:18 AM »
ok, so I took all the "junk" off, but when I did, I kept getting the bsod(blue screen) and something about ati3daung... I think that was why I had put iobit etc. on there. Anyway, I couldn't get firefox 10 to install??? But finally got the others. Here goes combofix.

ComboFix 12-02-05.02 - Debra Lopez 02/05/2012  22:24:31.4.1 - x86
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.512.187 [GMT -5:00]
Running from: c:\users\Debra Lopez\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((   Files Created from 2012-01-06 to 2012-02-06  )))))))))))))))))))))))))))))))
.
.
2012-02-06 03:36 . 2012-02-06 03:36   --------   d-----w-   c:\users\Public\AppData\Local\temp
2012-02-06 03:36 . 2012-02-06 03:36   --------   d-----w-   c:\users\Default\AppData\Local\temp
2012-02-06 03:36 . 2012-02-06 03:36   --------   d-----w-   c:\users\Chaddock\AppData\Local\temp
2012-02-05 21:22 . 2012-02-06 03:36   --------   d-----w-   c:\users\Debra Lopez\AppData\Local\temp
2012-02-05 03:32 . 2012-02-05 03:32   --------   d-----w-   c:\users\Chaddock\AppData\Local\Mozilla
2012-02-04 15:01 . 2011-11-10 10:54   476904   ----a-w-   c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2012-01-28 13:50 . 2011-11-17 05:34   224768   ----a-w-   c:\windows\system32\schannel.dll
2012-01-28 13:50 . 2011-11-17 05:41   134000   ----a-w-   c:\windows\system32\drivers\ksecpkg.sys
2012-01-28 13:50 . 2011-11-17 05:39   369352   ----a-w-   c:\windows\system32\drivers\cng.sys
2012-01-28 13:50 . 2011-11-17 05:32   1038848   ----a-w-   c:\windows\system32\lsasrv.dll
2012-01-28 13:50 . 2011-11-17 05:41   67440   ----a-w-   c:\windows\system32\drivers\ksecdd.sys
2012-01-28 13:50 . 2011-11-17 05:29   22528   ----a-w-   c:\windows\system32\lsass.exe
2012-01-28 13:50 . 2011-11-17 05:35   314880   ----a-w-   c:\windows\system32\webio.dll
2012-01-28 13:50 . 2011-11-17 05:34   100352   ----a-w-   c:\windows\system32\sspicli.dll
2012-01-28 13:50 . 2011-11-17 05:34   22016   ----a-w-   c:\windows\system32\secur32.dll
2012-01-28 13:50 . 2011-11-17 05:34   15872   ----a-w-   c:\windows\system32\sspisrv.dll
2012-01-13 03:13 . 2011-11-17 05:38   1288472   ----a-w-   c:\windows\system32\ntdll.dll
2012-01-13 03:13 . 2011-11-19 14:01   67072   ----a-w-   c:\windows\system32\packager.dll
2012-01-13 03:13 . 2011-10-26 04:32   1328128   ----a-w-   c:\windows\system32\quartz.dll
2012-01-13 03:13 . 2011-10-26 04:32   514560   ----a-w-   c:\windows\system32\qdvd.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 18:03 . 2011-06-22 15:04   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 04:25 . 2011-12-17 18:27   2342912   ----a-w-   c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2012-01-07 01:29   6823496   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{0D069FB5-D6C9-41C3-807E-344B00F27074}\mpengine.dll
2011-11-15 19:29 . 2010-06-03 02:43   222080   ------w-   c:\windows\system32\MpSigStub.exe
2011-11-10 10:54 . 2010-06-26 11:39   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-06-26 06:05 . 2011-06-26 06:06   166909440   ----a-w-   c:\program files\Samsung New PC Studio.msi
2011-11-23 11:48 . 2011-05-10 23:07   134104   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-08-11 22:17   196384   ----a-w-   c:\program files\Yontoo Layers Runtime (Drop Down Deals)\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages   REG_MULTI_SZ      kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HotKeyDetect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HotKeyDetect.lnk
backup=c:\windows\pss\HotKeyDetect.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SnapDetect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SnapDetect.lnk
backup=c:\windows\pss\SnapDetect.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
2005-01-20 03:21   25088   ----a-w-   c:\windows\System32\Ati2mdxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath]
2003-01-21 20:19   40960   ----a-w-   c:\windows\VM_STI.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
2008-03-27 15:15   107176   ----a-w-   c:\program files\Lexmark Z2300 Series\ezprint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 22:06   421736   ----a-w-   c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdpmon.exe]
2008-03-27 15:15   656040   ----a-w-   c:\program files\Lexmark Z2300 Series\lxdpmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 18:28   421888   ----a-w-   c:\program files\QuickTime\QTTask.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-30 135664]
R2 lxdpCATSCustConnectService;lxdpCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdpserv.exe [2009-04-28 94208]
R3 avshws;Senstic PocketCam;c:\windows\system32\DRIVERS\camsource.sys [2010-07-06 29000]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-08-12 13224]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-30 135664]
R3 KMWDFILTERx86;HIDServiceDesc;c:\windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 25088]
R3 PCTINDIS4;PCTINDIS4 NDIS Protocol Driver;c:\windows\system32\PCTINDIS4.SYS

R3 PocketAudio;Senstic PocketAudio (WDM);c:\windows\system32\drivers\senaudio.sys [2010-03-03 31304]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-03 1343400]
R3 ZTEusbwwan;ZTE MBN Miniport;c:\windows\system32\DRIVERS\ZTEusbwwan.sys [2011-04-09 193536]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952]
S2 lxbl_device;lxbl_device;c:\windows\system32\lxblcoms.exe [2007-04-20 537520]
S2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe [2008-02-27 594600]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2007-03-07 2595840]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2010-08-12 27632]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - FSUSBEXDISK
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-30 14:04]
.
2012-02-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-30 14:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/?pc=BNHP
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{718EA244-D67D-44BD-9AA7-9193438B00B0}: NameServer = 192.168.0.1 0.0.0.0
FF - ProfilePath - c:\users\Debra Lopez\AppData\Roaming\Mozilla\Firefox\Profiles\ojjfhca9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/|http://www.google.com/webhp?hl=en
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z039&form=ZGAADF&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: extentions.y2layers.installId - d07b98e1-5870-4736-93f1-af50c836625d
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock,BuzzdockTease,DropDownDeals,
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-05  22:41:10
ComboFix-quarantined-files.txt  2012-02-06 03:41
ComboFix2.txt  2012-02-05 21:22
ComboFix3.txt  2011-02-09 00:35
.
Pre-Run: 7,582,056,448 bytes free
Post-Run: 7,530,237,952 bytes free
.
- - End Of File - - 1F8B9A35ED1761ECFD788B6AC8150864

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: slllllloooooooooowwwwwww help
« Reply #3 on: February 06, 2012, 02:37:59 PM »
Hi, Debra.

I need to see the previous run of ComboFix.  Hold down the Windows Key and the "R" key.  A run box will appear.  Copy and paste the following:  C:\Qoobox\ComboFix2.txt then click OK

Notepad will open with a log.  Post the contents of that log in your next reply.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline debralcola

  • Newbie
  • *
  • Posts: 31
Re: slllllloooooooooowwwwwww help
« Reply #4 on: February 08, 2012, 02:03:43 AM »
ComboFix 12-02-05.02 - Debra Lopez 02/05/2012  16:03:18.3.1 - x86
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.512.121 [GMT -5:00]
Running from: c:\users\Debra Lopez\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\programdata\SPL7D2B.tmp
c:\programdata\Tarma Installer
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\programdata\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\users\Debra Lopez\AppData\Roaming\.#
c:\users\Debra Lopez\AppData\Roaming\.#\MBX@42C@14B2790.###
c:\users\Debra Lopez\AppData\Roaming\.#\MBX@42C@14B27C0.###
c:\users\Debra Lopez\AppData\Roaming\.#\MBX@938@14C2790.###
c:\users\Debra Lopez\AppData\Roaming\.#\MBX@938@14C27C0.###
c:\windows\security\Database\tmp.edb
c:\windows\system32\REN3D2D.tmp
c:\windows\system32\SET4B1C.tmp
c:\windows\system32\SET5CDC.tmp
.
.
(((((((((((((((((((((((((   Files Created from 2012-01-05 to 2012-02-05  )))))))))))))))))))))))))))))))
.
.
2012-02-05 21:16 . 2012-02-05 21:17   --------   d-----w-   c:\users\Debra Lopez\AppData\Local\temp
2012-02-05 21:16 . 2012-02-05 21:16   --------   d-----w-   c:\users\Public\AppData\Local\temp
2012-02-05 21:16 . 2012-02-05 21:16   --------   d-----w-   c:\users\Default\AppData\Local\temp
2012-02-05 03:32 . 2012-02-05 03:32   --------   d-----w-   c:\users\Chaddock\AppData\Local\Mozilla
2012-02-04 15:01 . 2011-11-10 10:54   476904   ----a-w-   c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2012-01-28 13:50 . 2011-11-17 05:34   224768   ----a-w-   c:\windows\system32\schannel.dll
2012-01-28 13:50 . 2011-11-17 05:41   134000   ----a-w-   c:\windows\system32\drivers\ksecpkg.sys
2012-01-28 13:50 . 2011-11-17 05:39   369352   ----a-w-   c:\windows\system32\drivers\cng.sys
2012-01-28 13:50 . 2011-11-17 05:32   1038848   ----a-w-   c:\windows\system32\lsasrv.dll
2012-01-28 13:50 . 2011-11-17 05:41   67440   ----a-w-   c:\windows\system32\drivers\ksecdd.sys
2012-01-28 13:50 . 2011-11-17 05:29   22528   ----a-w-   c:\windows\system32\lsass.exe
2012-01-28 13:50 . 2011-11-17 05:35   314880   ----a-w-   c:\windows\system32\webio.dll
2012-01-28 13:50 . 2011-11-17 05:34   100352   ----a-w-   c:\windows\system32\sspicli.dll
2012-01-28 13:50 . 2011-11-17 05:34   22016   ----a-w-   c:\windows\system32\secur32.dll
2012-01-28 13:50 . 2011-11-17 05:34   15872   ----a-w-   c:\windows\system32\sspisrv.dll
2012-01-13 03:13 . 2011-11-17 05:38   1288472   ----a-w-   c:\windows\system32\ntdll.dll
2012-01-13 03:13 . 2011-11-19 14:01   67072   ----a-w-   c:\windows\system32\packager.dll
2012-01-13 03:13 . 2011-10-26 04:32   1328128   ----a-w-   c:\windows\system32\quartz.dll
2012-01-13 03:13 . 2011-10-26 04:32   514560   ----a-w-   c:\windows\system32\qdvd.dll
2012-01-07 01:29 . 2011-11-21 10:47   6823496   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{0D069FB5-D6C9-41C3-807E-344B00F27074}\mpengine.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 18:03 . 2011-06-22 15:04   414368   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 04:25 . 2011-12-17 18:27   2342912   ----a-w-   c:\windows\system32\win32k.sys
2011-11-15 19:29 . 2010-06-03 02:43   222080   ------w-   c:\windows\system32\MpSigStub.exe
2011-11-10 10:54 . 2010-06-26 11:39   472808   ----a-w-   c:\windows\system32\deployJava1.dll
2011-06-26 06:05 . 2011-06-26 06:06   166909440   ----a-w-   c:\program files\Samsung New PC Studio.msi
2011-11-23 11:48 . 2011-05-10 23:07   134104   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-08-11 22:17   196384   ----a-w-   c:\program files\Yontoo Layers Runtime (Drop Down Deals)\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages   REG_MULTI_SZ      kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HotKeyDetect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HotKeyDetect.lnk
backup=c:\windows\pss\HotKeyDetect.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SnapDetect.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SnapDetect.lnk
backup=c:\windows\pss\SnapDetect.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
2005-01-20 03:21   25088   ----a-w-   c:\windows\System32\Ati2mdxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath]
2003-01-21 20:19   40960   ----a-w-   c:\windows\VM_STI.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
2008-03-27 15:15   107176   ----a-w-   c:\program files\Lexmark Z2300 Series\ezprint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 22:06   421736   ----a-w-   c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdpmon.exe]
2008-03-27 15:15   656040   ----a-w-   c:\program files\Lexmark Z2300 Series\lxdpmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 18:28   421888   ----a-w-   c:\program files\QuickTime\QTTask.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-30 135664]
R2 lxdpCATSCustConnectService;lxdpCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdpserv.exe [2009-04-28 94208]
R3 avshws;Senstic PocketCam;c:\windows\system32\DRIVERS\camsource.sys [2010-07-06 29000]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-08-12 13224]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-30 135664]
R3 KMWDFILTERx86;HIDServiceDesc;c:\windows\system32\DRIVERS\KMWDFILTER.sys [2009-04-29 25088]
R3 PCTINDIS4;PCTINDIS4 NDIS Protocol Driver;c:\windows\system32\PCTINDIS4.SYS

R3 PocketAudio;Senstic PocketAudio (WDM);c:\windows\system32\drivers\senaudio.sys [2010-03-03 31304]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [2010-04-27 98560]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [2010-04-27 14848]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [2010-04-27 123648]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-03 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-04-27 136360]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2010-07-04 238952]
S2 lxbl_device;lxbl_device;c:\windows\system32\lxblcoms.exe [2007-04-20 537520]
S2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe [2008-02-27 594600]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2010-06-14 36608]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2007-03-07 2595840]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2010-08-12 27632]
S3 ZTEusbwwan;ZTE MBN Miniport;c:\windows\system32\DRIVERS\ZTEusbwwan.sys [2011-04-09 193536]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - FSUSBEXDISK
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-30 14:04]
.
2012-02-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-30 14:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/?pc=BNHP
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{718EA244-D67D-44BD-9AA7-9193438B00B0}: NameServer = 192.168.0.1 0.0.0.0
FF - ProfilePath - c:\users\Debra Lopez\AppData\Roaming\Mozilla\Firefox\Profiles\ojjfhca9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/|http://www.google.com/webhp?hl=en
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z039&form=ZGAADF&q=
FF - prefs.js: network.proxy.type - 0
FF - user.js: extentions.y2layers.installId - d07b98e1-5870-4736-93f1-af50c836625d
FF - user.js: extentions.y2layers.defaultEnableAppsList - Buzzdock,Buzzdock,BuzzdockTease,DropDownDeals,
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-NPSStartup - (no file)
MSConfigStartUp-NeroCheck - c:\windows\system32\\NeroCheck.exe
AddRemove-{889DF117-14D1-44EE-9F31-C5FB5D47F68B} - c:\progra~2\TARMAI~1\{889DF~1\Setup.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-05  16:22:17
ComboFix-quarantined-files.txt  2012-02-05 21:22
ComboFix2.txt  2011-02-09 00:35
.
Pre-Run: 6,986,149,888 bytes free
Post-Run: 6,793,728,000 bytes free
.
- - End Of File - - 0828BCE7D8485742FE21A5F68770EC7F

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: slllllloooooooooowwwwwww help
« Reply #5 on: February 09, 2012, 02:08:19 AM »
Hi, Debra. 

Sorry for the delay in responding. 

IObit would not be able to help with ati3daung.dll as that is for the ATI video driver.  I see you have ATI - Software Uninstall Utility and
ATI Display Driver installed.  Did you recently update any ATI drivers? 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline debralcola

  • Newbie
  • *
  • Posts: 31
Re: slllllloooooooooowwwwwww help
« Reply #6 on: February 09, 2012, 03:07:20 AM »
Let me not show my ignorance..... I am not aware of updating drivers.


Deb  :grin:

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: slllllloooooooooowwwwwww help
« Reply #7 on: February 10, 2012, 02:44:44 PM »
That's ok, Debra.  Let's see what we can find out about your video card. 

Click Start > Control Panel > Device Manager.  Expand Display adapters.
Double-click the device shown (likely with an ATI name).

Please reply with the exact name of the adapter.  In addition, click the Driver tab and provide the details there (provider, driver date and driver version).
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline debralcola

  • Newbie
  • *
  • Posts: 31
Re: slllllloooooooooowwwwwww help
« Reply #8 on: February 19, 2012, 11:56:34 PM »
Sorry it took so long to post... I haven't been home.

ATI MOBILITY RADEON 9700 Series
Driver Provider: ATI Technologies Inc.
Driver Date: 1/19/2005
Driver Version: 6.14.10.6512

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: slllllloooooooooowwwwwww help
« Reply #9 on: February 20, 2012, 01:17:21 AM »
Hi, debracola.

Not to worry.  We'll be here. 

Let's see if updating the driver solves the BSOD problem.

Even though drivers can be rolled back, first, create a restore point. 
Click Start > Control Panel > Device Manager.  Expand Display adapters.
Double-click the ATI RADEON device shown
Click Update Driver

Shutdown/restart your computer. 

Then, please post a fresh RSIT log.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.