1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Seeing a lag when i open Chrome

Discussion in 'Malware and Virus Removal Archive' started by flyboy1565, 2012/07/30.

  1. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    [Resolved] Seeing a lag when i open Chrome

    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.07.27.11

    Windows 7 Service Pack 1 x86 NTFS
    Internet Explorer 9.0.8112.16421
    Mini :: MINI-PC [administrator]

    7/30/2012 9:33:45 AM
    mbam-log-2012-07-30 (09-33-45).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 196763
    Time elapsed: 18 minute(s), 58 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  2. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-07-30 08:53:02
    -----------------------------
    08:53:03.000 OS Version: Windows 6.1.7601 Service Pack 1
    08:53:03.000 Number of processors: 2 586 0x1C02
    08:53:03.008 ComputerName: MINI-PC UserName: Mini
    08:53:15.254 Initialize success
    08:53:20.370 AVAST engine defs: 12073000
    08:53:43.867 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
    08:53:43.884 Disk 0 Vendor: SAMSUNG_ HH10 Size: 152627MB BusType: 3
    08:53:43.913 Disk 0 MBR read successfully
    08:53:43.933 Disk 0 MBR scan
    08:53:43.965 Disk 0 unknown MBR code
    08:53:44.001 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 140769 MB offset 2048
    08:53:44.048 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 11654 MB offset 288296960
    08:53:44.090 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 201 MB offset 312164352
    08:53:44.118 Disk 0 scanning sectors +312576000
    08:53:44.207 Disk 0 scanning C:\Windows\system32\drivers
    08:54:08.512 Service scanning
    08:54:24.746 Service MpKslfe017136 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6CACC627-DD43-48E8-9C18-7C85E672B41C}\MpKslfe017136.sys **LOCKED** 32
    08:54:47.535 Modules scanning
    08:55:03.043 Disk 0 trace - called modules:
    08:55:03.091 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll
    08:55:03.114 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84e56030]
    08:55:03.141 3 CLASSPNP.SYS[86b7259e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x84058028]
    08:55:03.991 AVAST engine scan C:\Windows
    08:55:09.373 AVAST engine scan C:\Windows\system32
    09:00:15.581 AVAST engine scan C:\Windows\system32\drivers
    09:00:43.372 AVAST engine scan C:\Users\Mini
    09:24:23.455 AVAST engine scan C:\ProgramData
    09:28:24.898 Scan finished successfully
    09:29:09.562 Disk 0 MBR has been saved successfully to "C:\Users\Mini\Documents\virus logs\MBR.dat "
    09:29:09.824 The log file has been saved successfully to "C:\Users\Mini\Documents\virus logs\aswMBR.txt "
     

  3. to hide this advert.

  4. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    tried to run GMER but was having issue, sent broni a pm.
    also having trouble getting DDS to download. I tried to use Mirror 1 and 2 neither would start to download.

    broni please let me know how i can get you the info you need to finish the logs. MBR did highlight an issue i believe
     
  5. 2012/07/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  6. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    well i have had avast tell me i have a threat that i pm you about. and so i've run malwarebytes and it said i have backdoor.bot then i used malware to clean.. also had everytime i open chrome, it lags takes about 1-2 minutes before i can browse..

    gmer ran in safe


    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2012-07-30 16:44:57
    Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 SAMSUNG_ rev.HH10
    Running: y4k1jwml.exe; Driver: C:\Users\Mini\AppData\Local\Temp\kxldypod.sys


    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 81C523C9 1 Byte [06]
    .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81C8BD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [744924CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [7447562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [744756EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74492546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [744885AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74484D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74485105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [744851DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [74486707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74488301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74488850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [744890B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7448E254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74484C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
    AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)

    Device \Driver\ACPI_HAL \Device\00000054 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

    AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001a6b2af2e9
    Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001a6b2af2e9 (not active ControlSet)

    ---- EOF - GMER 1.0.15 ----
     
  7. 2012/07/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    .....
     
  8. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    also i have a bunch of random icons or something that showed up on my desktop that say desktop.ini or thumbs.db.. they have transparent cogs sort of as their icon
     
  9. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.5.1
    Run by Mini at 17:09:58 on 2012-07-30
    Microsoft Windows 7 Starter 6.1.7601.1.1252.1.1033.18.1015.173 [GMT -7:00]
    .
    AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
    AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
    SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k RPCSS
    c:\Program Files\Microsoft Security Client\MsMpEng.exe
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\STacSV.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_fa0513b7754bf240\aestsrv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Microsoft\BingBar\SeaPort.EXE
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Users\Mini\AppData\Local\CrossLoop\CrossLoopService.exe
    C:\SPLASH.SYS\config\DVMExportService.exe
    C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
    c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\taskhost.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\HPBTWD.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Program Files\Hewlett-Packard\HP QuickSync\QuickSync.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Program Files\Hewlett-Packard\HP QuickSync\jre\bin\javaw.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\IDT\WDM\sttray.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\HP\HP Software Update\hpwuschd2.exe
    C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe
    C:\Program Files\Microsoft Security Client\msseces.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\Program Files\Malwarebytes\mbamgui.exe
    C:\Windows\system32\svchost.exe -k HPService
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Users\Mini\AppData\Local\CrossLoop\CrossLoopConnect.exe
    C:\Users\Mini\AppData\Roaming\Dropbox\bin\Dropbox.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Malwarebytes\mbamservice.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Users\Mini\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
    C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
    C:\Users\Mini\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mini\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mini\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mini\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Users\Mini\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\svchost.exe -k SDRSVC
    C:\Windows\system32\rundll32.exe
    C:\Users\Mini\AppData\Local\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cnnb
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cnnb
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_US&c=94&bd=Pavilion&pf=cnnb
    uInternet Settings,ProxyOverride = *.local
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
    BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: hpBHO Class: {abd3b5e1-b268-407b-a150-2641dab8d898} - c:\program files\common files\homepage protection\HomepageProtection.dll
    BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll "
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
    TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll "
    TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
    TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [Google Update] "c:\users\mini\appdata\local\google\update\GoogleUpdate.exe" /c
    uRun: [Power2GoExpress]
    uRun: [CrossLoop] "c:\users\mini\appdata\local\crossloop\CrossLoopConnect.exe" -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server -noprompts -minimize
    mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    mRun: [HP BTW Detect Program] c:\program files\hp\HPBTWD.exe
    mRun: [HP] c:\program files\hewlett-packard\hp quicksync\QuickSync.exe
    mRun: [UpdatePRCShortCut] "c:\program files\hewlett-packard\recovery\muitransfer\muistartmenu.exe" "c:\program files\hewlett-packard\recovery" updatewithcreateonce "software\cyberlink\PowerRecover "
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe "
    mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [VMM Mode Selection] c:\program files\htc\modeselection\VMMModeSelection.exe
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [<NO NAME>]
    mRun: [Anti-phishing Domain Advisor] "c:\programdata\anti-phishing domain advisor\visicom_antiphishing.exe "
    mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [HTC Sync Loader] "c:\program files\htc\htc sync 3.0\htcUPCTLoader.exe" -startup
    mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
    mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes\mbamgui.exe" /starttray
    StartupFolder: c:\users\mini\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\mini\appdata\roaming\dropbox\bin\Dropbox.exe
    uPolicies-system: WallpaperStyle = 2
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: SoftwareSASGeneration = 3 (0x3)
    dPolicies-system: WallpaperStyle = 2
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    TCP: DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{75D516F2-6DFF-4821-87B4-E2A4A964AD97} : DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{75D516F2-6DFF-4821-87B4-E2A4A964AD97}\2375942554234323 : DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{75D516F2-6DFF-4821-87B4-E2A4A964AD97}\2375942554634333 : DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{75D516F2-6DFF-4821-87B4-E2A4A964AD97}\2375942554730313 : DhcpNameServer = 192.168.1.254
    TCP: Interfaces\{75D516F2-6DFF-4821-87B4-E2A4A964AD97}\74F6373756C696E6 : DhcpNameServer = 192.168.2.1 192.168.0.1
    TCP: Interfaces\{75D516F2-6DFF-4821-87B4-E2A4A964AD97}\779696E676 : DhcpNameServer = 192.168.2.1
    TCP: Interfaces\{75D516F2-6DFF-4821-87B4-E2A4A964AD97}\D697365756374716 : DhcpNameServer = 10.202.3.25 10.202.3.26 10.102.0.2
    TCP: Interfaces\{D301397C-5E83-4834-956A-D46447082277} : DhcpNameServer = 192.168.42.129
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
    Notify: igfxcui - igfxdev.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-6-17 721000]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-6-17 353688]
    R1 DVMIO;DVMIO;c:\splash.sys\config\dvmio.sys [2009-7-27 16984]
    R1 MpKslfe017136;MpKslfe017136;c:\programdata\microsoft\microsoft antimalware\definition updates\{6cacc627-dd43-48e8-9c18-7c85e672b41c}\MpKslfe017136.sys [2012-7-30 29904]
    R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
    R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_fa0513b7754bf240\AEstSrv.exe [2009-3-2 81920]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-6-17 21256]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-6-17 57656]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-7-5 44808]
    R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-6-15 249648]
    R2 CrossLoopService;CrossLoop Service;c:\users\mini\appdata\local\crossloop\CrossLoopService.exe [2011-1-10 569072]
    R2 DvmMDES;DeviceVM Meta Data Export Service;c:\splash.sys\config\DVMExportService.exe [2009-7-8 323584]
    R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\L1C62x86.sys [2009-11-13 58368]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-2-12 22344]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
    S3 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-7-7 195336]
    S3 fssfltr;fssfltr;c:\windows\system32\drivers\fssfltr.sys [2010-11-1 39272]
    S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2009-10-26 25088]
    S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-23 23040]
    S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 74112]
    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-10-19 167424]
    S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-13 207360]
    S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-13 980992]
    S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-13 661504]
    S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-3-9 52224]
    S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2009-7-13 17920]
    S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
    .
    =============== Created Last 30 ================
    .
    2012-07-30 23:51:33 -------- d-----w- c:\users\mini\appdata\local\{4B5A3999-B307-4D55-A1AA-70A410D5D9D6}
    2012-07-30 23:50:34 -------- d-----w- c:\users\mini\appdata\local\{7324C45D-2F52-47D7-9F12-16D046A29BF2}
    2012-07-30 15:53:15 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6cacc627-dd43-48e8-9c18-7c85e672b41c}\MpKslfe017136.sys
    2012-07-30 15:36:18 6891424 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{6cacc627-dd43-48e8-9c18-7c85e672b41c}\mpengine.dll
    2012-07-30 04:50:14 -------- d-----w- c:\users\mini\appdata\local\{025AC507-0FC0-4E9D-AD3D-EE7505991761}
    2012-07-30 04:49:45 -------- d-----w- c:\users\mini\appdata\local\{438CC63D-B554-47F7-A31B-DA5BB44FC443}
    2012-07-29 06:10:06 6891424 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
    2012-07-25 07:41:15 -------- d-----w- c:\users\mini\appdata\local\{122D22A6-ADB4-4CBF-936F-0E422C52FEFE}
    2012-07-25 05:24:00 -------- d-----w- c:\users\mini\appdata\local\{AB855DCA-D4B5-4433-AC63-816C1E7DA1BE}
    2012-07-13 04:32:24 -------- d-----w- c:\users\mini\appdata\local\{0021C3D3-6E0D-443B-877C-6FA009B094E6}
    2012-07-13 04:32:03 -------- d-----w- c:\users\mini\appdata\local\{7E7DF293-CC7D-4AD4-8CAB-F4779A7D8185}
    2012-07-11 15:59:26 2382848 ----a-w- c:\windows\system32\mshtml.tlb
    2012-07-11 15:59:19 194560 ----a-w- c:\program files\internet explorer\ieproxy.dll
    2012-07-11 15:59:19 140920 ----a-w- c:\program files\internet explorer\sqmapi.dll
    2012-07-11 15:59:12 194048 ----a-w- c:\program files\internet explorer\IEShims.dll
    2012-07-11 15:59:07 142848 ----a-w- c:\windows\system32\ieUnatt.exe
    2012-07-11 15:59:02 1129472 ----a-w- c:\windows\system32\wininet.dll
    2012-07-11 15:58:53 1800192 ----a-w- c:\windows\system32\jscript9.dll
    2012-07-11 15:58:42 748664 ----a-w- c:\program files\internet explorer\iexplore.exe
    2012-07-11 15:58:37 387584 ----a-w- c:\program files\internet explorer\jsdbgui.dll
    2012-07-11 15:58:32 678912 ----a-w- c:\program files\internet explorer\iedvtool.dll
    2012-07-11 15:58:13 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
    2012-07-11 06:14:16 2345984 ----a-w- c:\windows\system32\win32k.sys
    2012-07-11 06:09:09 369336 ----a-w- c:\windows\system32\drivers\cng.sys
    2012-07-11 06:09:08 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
    2012-07-11 06:09:06 219136 ----a-w- c:\windows\system32\ncrypt.dll
    2012-07-11 06:09:04 225280 ----a-w- c:\windows\system32\schannel.dll
    2012-07-11 06:09:02 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2012-07-11 06:08:53 1390080 ----a-w- c:\windows\system32\msxml6.dll
    2012-07-11 06:08:48 2048 ----a-w- c:\windows\system32\msxml3r.dll
    2012-07-11 06:08:48 1236992 ----a-w- c:\windows\system32\msxml3.dll
    2012-07-11 06:08:37 1019904 ----a-w- c:\program files\common files\system\ado\msado15.dll
    2012-07-11 06:08:36 805376 ----a-w- c:\windows\system32\cdosys.dll
    2012-07-11 06:08:32 352256 ----a-w- c:\program files\common files\system\ado\msadomd.dll
    2012-07-11 06:08:30 57344 ----a-w- c:\program files\common files\system\ado\msador15.dll
    2012-07-11 06:08:28 212992 ----a-w- c:\program files\common files\system\msadc\msadco.dll
    2012-07-11 06:08:27 143360 ----a-w- c:\program files\common files\system\ado\msjro.dll
    2012-07-11 06:08:25 372736 ----a-w- c:\program files\common files\system\ado\msadox.dll
    2012-07-09 16:58:38 -------- d-----w- c:\users\mini\appdata\local\{A5370D66-F54A-493C-A271-BD7D1804CB28}
    2012-07-09 16:58:06 -------- d-----w- c:\users\mini\appdata\local\{DECBEC6D-5358-4D1E-BDAD-FEEA0B6E3F25}
    2012-07-08 06:06:29 -------- d-----w- c:\users\mini\appdata\local\{39B7237D-4536-44AD-A163-9ED24906CCCE}
    2012-07-08 06:06:07 -------- d-----w- c:\users\mini\appdata\local\{836220FE-7D31-492C-B052-853843174BFC}
    2012-07-06 19:53:17 -------- d-----w- c:\users\mini\appdata\local\{60D3D960-7B6E-4EE0-848E-C14D57A3BC8A}
    2012-07-06 19:52:38 -------- d-----w- c:\users\mini\appdata\local\{F4CC7843-4E4C-43B5-94DE-CE1929885211}
    2012-07-04 18:23:19 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{36e00cbd-6276-4aca-b0e2-8284cc7b64ea}\gapaengine.dll
    2012-07-04 00:24:36 -------- d-----w- c:\users\mini\appdata\local\{27416276-F55F-4BE7-B3C7-51000E4AF767}
    2012-07-04 00:19:13 -------- d-----w- c:\users\mini\appdata\local\{83BCD8B0-FF04-4C80-8AE2-651037947F4E}
    2012-07-03 06:04:02 -------- d-----w- c:\users\mini\appdata\local\{781BB073-0AC7-429A-84C4-7C106285D565}
    2012-07-03 06:03:17 -------- d-----w- c:\users\mini\appdata\local\{E6F654E4-5F97-47A0-938F-2B04D6AF0225}
    .
    ==================== Find3M ====================
    .
    2012-07-03 20:46:44 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
    2012-07-03 16:21:53 721000 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2012-07-03 16:21:53 57656 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2012-07-03 16:21:53 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
    2012-07-03 16:21:32 41224 ----a-w- c:\windows\avastSS.scr
    2012-06-25 23:04:24 1394248 ----a-w- c:\windows\system32\msxml4.dll
    2012-06-02 22:19:42 171904 ----a-w- c:\windows\system32\wuwebv.dll
    2012-06-02 22:12:32 2422272 ----a-w- c:\windows\system32\wucltux.dll
    2012-06-02 22:12:20 33792 ----a-w- c:\windows\system32\wuapp.exe
    2012-06-02 22:12:13 88576 ----a-w- c:\windows\system32\wudriver.dll
    2012-05-24 21:18:40 4472832 ----a-w- c:\windows\system32\GPhotos.scr
    2012-05-05 02:29:22 772504 ----a-w- c:\windows\system32\npDeployJava1.dll
    2012-05-05 02:29:16 687504 ----a-w- c:\windows\system32\deployJava1.dll
    .
    ============= FINISH: 17:13:08.23 ===============
     
  10. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    umm opened ie and works fine unless i open facebook.. it took a little while but not as long and chrome...


    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows 7 Starter
    Boot Device: \Device\HarddiskVolume3
    Install Date: 11/27/2009 10:13:07 AM
    System Uptime: 7/30/2012 4:45:26 PM (1 hours ago)
    .
    Motherboard: Hewlett-Packard | | 308F
    Processor: Intel(R) Atom(TM) CPU N270 @ 1.60GHz | CPU 1 | 1328/133mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 137 GiB total, 76.261 GiB free.
    D: is FIXED (NTFS) - 11 GiB total, 1.906 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Officejet J6400 series
    Device ID: ROOT\MULTIFUNCTION\0000
    Manufacturer: HP
    Name: Officejet J6400 series
    PNP Device ID: ROOT\MULTIFUNCTION\0000
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Photosmart C6200 series
    Device ID: ROOT\MULTIFUNCTION\0001
    Manufacturer: HP
    Name: Photosmart C6200 series
    PNP Device ID: ROOT\MULTIFUNCTION\0001
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Officejet 4500 G510n-z
    Device ID: ROOT\MULTIFUNCTION\0002
    Manufacturer: HP
    Name: Officejet 4500 G510n-z
    PNP Device ID: ROOT\MULTIFUNCTION\0002
    Service:
    .
    Class GUID: {4d36e971-e325-11ce-bfc1-08002be10318}
    Description: Photosmart Prem C310 series
    Device ID: ROOT\MULTIFUNCTION\0003
    Manufacturer: HP
    Name: Photosmart Prem C310 series
    PNP Device ID: ROOT\MULTIFUNCTION\0003
    Service:
    .
    ==== System Restore Points ===================
    .
    RP459: 7/4/2012 11:08:46 AM - Windows Update
    RP460: 7/7/2012 11:21:57 PM - Windows Update
    RP461: 7/10/2012 11:10:48 PM - Windows Update
    RP462: 7/15/2012 10:16:41 PM - Windows Update
    RP463: 7/20/2012 12:10:48 AM - Windows Update
    RP464: 7/23/2012 11:07:49 PM - Windows Update
    RP466: 7/28/2012 11:06:49 PM - Windows Update
    .
    ==== Installed Programs ======================
    .
    32 Bit HP CIO Components Installer
    6400_Help
    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 11 ActiveX
    Adobe Reader 9.5.1 MUI
    Adobe Shockwave Player
    Amazon Kindle
    Amazon Kindle For PC
    Amazon MP3 Downloader 1.0.9
    Android SDK Tools
    Anti-phishing Domain Advisor
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft WebCam Companion 3
    Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
    avast! Free Antivirus
    Battlelog Web Plugins
    Bing Bar
    Bonjour
    bpd_scan
    BPDSoftware
    BPDSoftware_Ini
    Broadcom 802.11 Wireless LAN Adapter
    Compatibility Pack for the 2007 Office system
    CrossLoop 2.82
    CyberLink DVD Suite
    D3DX10
    Dropbox
    ESN Sonar
    Google Chrome
    Hewlett-Packard ACLM.NET v1.1.2.0
    Homepage Protection
    Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB945282)
    Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946040)
    Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB946308)
    Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947540)
    Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB947789)
    Hotfix for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB948127)
    HP Customer Experience Enhancements
    HP Games
    HP Instant Web
    HP Officejet J6400 Series
    HP Product Detection
    HP QuickSync
    HP Setup
    HP Support Assistant
    HP Update
    HP User Guides 0166
    HP Wireless Assistant
    HTC BMP USB Driver
    HTC Driver Installer
    HTC Sync
    IDT Audio
    Intel(R) Graphics Media Accelerator Driver
    Intel® Matrix Storage Manager
    iTunes
    J6400_Basic
    Java Auto Updater
    Java SE Development Kit 7 Update 5
    Java(TM) 6 Update 31
    Java(TM) 7 Update 5
    JavaFX 2.1.1
    JavaFX 2.1.1 SDK
    Junk Mail filter update
    Malwarebytes Anti-Malware version 1.62.0.1300
    Microsoft .NET Framework 4 Client Profile
    Microsoft Application Error Reporting
    Microsoft Live Search Toolbar
    Microsoft Mathematics
    Microsoft Office Home and Student 60 day trial
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Security Client
    Microsoft Security Essentials
    Microsoft Silverlight
    Microsoft Small Basic v1.0
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft SQL Server 2008
    Microsoft SQL Server 2008 Browser
    Microsoft SQL Server 2008 Common Files
    Microsoft SQL Server 2008 Database Engine Services
    Microsoft SQL Server 2008 Database Engine Shared
    Microsoft SQL Server 2008 Management Objects
    Microsoft SQL Server 2008 Native Client
    Microsoft SQL Server 2008 RsFx Driver
    Microsoft SQL Server 2008 Setup Support Files
    Microsoft SQL Server Compact 3.5 SP1 Design Tools English
    Microsoft SQL Server Compact 3.5 SP1 English
    Microsoft SQL Server VSS Writer
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Express Edition with SP1 - ENU
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
    Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
    Microsoft Works
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP3 Parser
    MSXML 4.0 SP3 Parser (KB2721691)
    MSXML 4.0 SP3 Parser (KB973685)
    Network
    OGA Notifier 2.0.0048.0
    Oracle VM VirtualBox 4.1.10
    Picasa 3
    Power2Go
    PowerRecover
    QuickTime
    Realtek USB 2.0 Card Reader
    Roxio Video Capture USB Driver
    Scan
    Scratch
    Screenshot It Enabler
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    Security Update for Microsoft Visual C++ 2008 Express Edition with SP1 - ENU (KB2251487)
    Service Pack 1 for SQL Server 2008 (KB968369)
    Sql Server Customer Experience Improvement Program
    SQL Server System CLR Types
    Synaptics Pointing Device Driver
    Toolbox
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    Video Capture USB
    WebReg
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live ID Sign-in Assistant
    Windows Live Installer
    Windows Live Mail
    Windows Live Messenger
    Windows Live MIME IFilter
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer Resources
    Windows Media Player Firefox Plugin
    WModem Driver Installer
    Yahoo! BrowserPlus
    Yahoo! Messenger
    Yahoo! Software Update
    Yahoo! Toolbar
    .
    ==== Event Viewer Messages From Past Week ========
    .
    7/30/2012 8:46:58 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.
    7/30/2012 7:04:13 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
    7/30/2012 4:50:55 PM, Error: Service Control Manager [7022] - The HP Network Devices Support service hung on starting.
    7/30/2012 4:47:14 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
    7/30/2012 4:46:17 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom
    7/30/2012 4:44:38 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
    7/30/2012 3:04:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments " " in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
    7/30/2012 3:04:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments " " in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
    7/30/2012 3:03:53 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments " " in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    7/30/2012 3:03:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments " " in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
    7/30/2012 3:03:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments " " in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
    7/30/2012 3:03:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments " " in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    7/30/2012 3:03:50 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    7/30/2012 3:03:44 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments " " in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    7/30/2012 3:03:13 PM, Error: Service Control Manager [7001] - The PnP-X IP Bus Enumerator service depends on the Function Discovery Provider Host service which failed to start because of the following error: The dependency service or group failed to start.
    7/30/2012 3:01:13 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD aswRdr aswSnx aswSP aswTdi cdrom DfsC discache DVMIO MpFilter NetBIOS NetBT nsiproxy Psched rdbss spldr tdx VBoxDrv VBoxUSBMon vwififlt Wanarpv6 WfpLwf
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service driver. service which failed to start because of the following error: A device attached to the system is not functioning.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    7/30/2012 3:01:12 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancillary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
    7/30/2012 2:26:54 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the IPBusEnum service.
    7/30/2012 11:35:00 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
    7/30/2012 1:37:08 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Wlansvc service.
    7/29/2012 9:42:07 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0x00000034, 0x00000002, 0x00000000, 0x866621f9). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 072912-21808-01.
    7/29/2012 5:51:41 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
    7/29/2012 10:46:16 PM, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80070420'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
    7/28/2012 11:14:13 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.
    7/27/2012 7:48:15 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.
    7/27/2012 7:47:36 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.
    7/27/2012 7:14:46 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.131.649.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8601.0 Error code: 0x8024402f Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
    7/25/2012 8:00:01 AM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.
    7/25/2012 7:37:17 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service sdrsvc with arguments " " in order to run the server: {687E55CA-6621-4C41-B9F1-C0EDDC94BB05}
    7/25/2012 7:37:14 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Backup service to connect.
    7/25/2012 7:37:14 AM, Error: Service Control Manager [7000] - The Windows Backup service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    7/24/2012 11:39:05 PM, Error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.131.548.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8601.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
    7/24/2012 11:28:24 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0x00000034, 0x00000002, 0x00000000, 0x8664d1f9). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 072412-18798-01.
    7/24/2012 10:22:27 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Microsoft .NET Framework NGEN v4.0.30319_X86 service to connect.
    7/24/2012 10:19:20 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Internet Pass-Through Service service to connect.
    7/24/2012 10:19:20 PM, Error: Service Control Manager [7000] - The Internet Pass-Through Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    7/24/2012 10:18:26 PM, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xc4000008, 0x00000000, 0xaa7853b3, 0x00000002). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 072412-26878-01.
    7/23/2012 11:21:35 PM, Error: Microsoft Antimalware [3002] - Microsoft Antimalware Real-Time Protection feature has encountered an error and failed. Feature: On Access Error Code: 0x80004005 Error description: Unspecified error Reason: The filter driver skipped scanning items and is in pass through mode. This may be due to low resource conditions.
    .
    ==== End Of File ===========================
     
  11. 2012/07/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    1. You didn't answer my question I asked three times already:
    [​IMG]

    2.
    Open Windows Explorer, go Tools>Folder options>View tab and checkmark "Hide protected operating system files ".

    3. You've been to this forum before and you should know that you can NOT be running more than one AV programs.
    You're running two of them, Avast and MSE.
    You must uninstall one of them.
     
  12. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    sorry i thought i deleted mse, i'll delete avast...
     
  13. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    ok avast has been deleted, everything else looks good? and random folders gone thanks for that
     
  14. 2012/07/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall Chrome completely...


    Go to Start > All Programs > Google Chrome > Uninstall Google Chrome.
    Delete your user profile information, like your browser preferences, bookmarks, and history, by selecting the "Also delete browser data" checkbox.
    Select the default browser you'd like to use.
    Click OK in the confirmation prompt.

    The uninstall process will begin.

    Install fresh copy.
     
  15. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    ok will do thanks broni
     
  16. 2012/07/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    :)....
     
  17. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    all right broni, fresh copy of chrome... almost forgot what the stock chrome looked like...

    anything else or are you giving me a clean bill of health?
     
  18. 2012/07/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I didn't see anything malicious at all so you should be good to go :)
     
  19. 2012/07/30
    flyboy1565

    flyboy1565 Inactive Thread Starter

    Joined:
    2009/12/09
    Messages:
    184
    Likes Received:
    2
    thanks broni, still waiting on GeekU to let me know if they are going to let me study with them..
     
  20. 2012/07/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good luck :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.