1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive aw snap notes

Discussion in 'Malware and Virus Removal Archive' started by bg9208, 2014/07/29.

Thread Status:
Not open for further replies.
  1. 2014/07/29
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    [Inactive] aw snap notes

    Google Chrome !Aw SNAP! etc.

    major problems with Google Chrome.

    I have Win XP SP 3. Used it for, many years with no problem until a few months ago when error messages started to appear and now they appear many times a days stopping the access to many files. I have tried many times to " load update" as prompted to solve the server security certificate but the same message appears and stopped the installing. Along with the frequence of "Aw Snap" which seems to be an allied problem.
    On searching I find hundreds of files labelled "Chrome" and hundreds of files labelled f___12, f__ etc. Any suggestions how I can either sol,e the problem which seems to and "SSL" error whatever that is.

    I would be happy to get everything Google Chrome off the PC and into the rubbish bin.

    TI
     
  2. 2014/07/29
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,890
    Likes Received:
    387

  3. to hide this advert.

  4. 2014/07/31
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    aw snap notes

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2012-11-20.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 19/05/2011 16:39:53
    System Uptime: 10/02/2012 21:44:48 (5 hours ago)
    .
    Motherboard: ASRock | | N68C-S UCC
    Processor: AMD Athlon(tm) II X2 250 Processor | CPUSocket | 3013/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 38 GiB total, 11.322 GiB free.
    E: is FIXED (NTFS) - 2 GiB total, 0.15 GiB free.
    F: is FIXED (NTFS) - 464 GiB total, 342.741 GiB free.
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: Audio Device on High Definition Audio Bus
    Device ID: HDAUDIO\FUNC_01&VEN_1106&DEV_4397&SUBSYS_18490397&REV_1000\4&1F7F6F18&0&0001
    Manufacturer:
    Name: Audio Device on High Definition Audio Bus
    PNP Device ID: HDAUDIO\FUNC_01&VEN_1106&DEV_4397&SUBSYS_18490397&REV_1000\4&1F7F6F18&0&0001
    Service:
    .
    Class GUID:
    Description:
    Device ID: ROOT\LEGACY_SASKUTIL\0000
    Manufacturer:
    Name:
    PNP Device ID: ROOT\LEGACY_SASKUTIL\0000
    Service:
    .
    ==== System Restore Points ===================
    .
    RP1272: 06/07/2014 11:23:28 - System Checkpoint
    RP1273: 07/07/2014 12:13:04 - System Checkpoint
    RP1274: 08/07/2014 12:23:50 - System Checkpoint
    RP1275: 08/07/2014 15:37:42 - Revo Uninstaller's restore point - HP Color LaserJet CP1210 Series
    RP1276: 08/07/2014 15:39:40 - Revo Uninstaller's restore point - HP Color LaserJet CP1210 Series Toolbox
    RP1277: 08/07/2014 15:39:51 - Removed HP Color LaserJet CP1210 Series Toolbox
    RP1278: 08/07/2014 15:40:44 - Revo Uninstaller's restore point - HP Update
    RP1279: 08/07/2014 15:40:52 - Removed HP Update.
    RP1280: 08/07/2014 15:41:42 - Revo Uninstaller's restore point - HPCarePackCore
    RP1281: 08/07/2014 15:43:08 - Revo Uninstaller's restore point - HPSSupply
    RP1282: 08/07/2014 15:43:15 - Removed HPSSupply
    RP1283: 08/07/2014 15:50:02 - Installed HP Color LaserJet CP1210 Series Toolbox
    RP1284: 08/07/2014 15:52:10 - Installed HP Color LaserJet CP1210 Series Toolbox
    RP1285: 08/07/2014 20:39:52 - Restore Operation
    RP1286: 09/07/2014 21:18:52 - System Checkpoint
    RP1287: 12/07/2014 13:42:17 - System Checkpoint
    RP1288: 13/07/2014 13:57:47 - System Checkpoint
    RP1289: 14/07/2014 14:40:37 - System Checkpoint
    RP1290: 15/07/2014 17:56:58 - System Checkpoint
    RP1291: 16/07/2014 18:22:34 - System Checkpoint
    RP1292: 17/07/2014 18:28:11 - System Checkpoint
    RP1293: 08/02/2012 18:45:04 - System Checkpoint
    RP1294: 08/02/2012 20:04:17 - Revo Uninstaller's restore point - Malwarebytes Anti-Malware version 1.75.0.1300
    RP1295: 09/02/2012 20:27:22 - System Checkpoint
    RP1296: 10/02/2012 20:39:49 - System Checkpoint
    RP1297: 10/02/2012 21:10:07 - avast! antivirus system restore point
    .
    ==== Installed Programs ======================
    .
    7-Zip 9.20
    Adobe Flash Player 11 Plugin
    Adobe Reader X (10.0.1)
    ArcSoft Camera Suite 1.3
    ArcSoft PhotoStudio 5.5
    ASRock InstantBoot v1.24
    avast! Free Antivirus
    Awesome Duplicate Photo Finder v. 1.0.1
    Canon CanoScan Toolbox 4.9
    CCleaner
    Compatibility Pack for the 2007 Office system
    Dropbox
    DVD Solution
    Everything 1.2.1.371
    FileParade bundle uninstaller
    FlashPeak SlimBrowser
    Free Easy Burner V 5.1
    FreeOCR v4.2
    GIMP 2.6.11
    GoldWave v5.56
    Google Chrome
    Google Earth
    Google Update Helper
    Hotfix for Windows XP (KB954708)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    HP Color LaserJet CP1210 Series
    HP Color LaserJet CP1210 Series Toolbox
    HP LaserJet Toolbox
    HP Update
    HPCarePackCore
    HPCarePackProducts
    hppusgCP1215
    HPSSupply
    IrfanView (remove only)
    Java Auto Updater
    Java(TM) 6 Update 26
    LightBox Free Image Editor
    Malwarebytes Anti-Malware version 2.0.2.1012
    Manual CanoScan LiDE 25
    MarketResearch
    Medi@Show
    Microsoft .NET Framework 2.0
    Microsoft .NET Framework 4 Client Profile
    Microsoft .NET Framework 4 Extended
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Expression Web 4
    Microsoft Office FrontPage 2003
    Microsoft Office Live Add-in 1.3
    Microsoft Office Professional Edition 2003
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    MiniTool Partition Wizard Home Edition 6.0
    MSVCRT
    msvcrt_installer
    Multimedia Launcher
    NVIDIA Control Panel 301.42
    NVIDIA Drivers
    NVIDIA Graphics Driver 301.42
    NVIDIA Install Application
    NVIDIA nView 136.27
    NVIDIA Update 1.8.15
    NVIDIA Update Components
    OpenCPN 2.5.0
    Power2Go 3.0
    PowerDirector
    PowerDVD
    PowerProducer
    RarZilla Free Unrar
    Revo Uninstaller 1.92
    ScanSoft OmniPage SE 4.0
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB941569)
    SR9600 Driver
    Tweak UI
    Ulead Photo Express 4.0 SE
    VC 9.0 Runtime
    VLC media player 2.1.3
    WebFldrs XP
    Windows PowerShell(TM) 1.0
    WinZip
    xplorer² lite 32 bit
    ZoneAlarm LTD Toolbar
    ZTE Handset USB Driver
    .
    ==== Event Viewer Messages From Past Week ========
    .
    30/06/2014 06:53:13, error: Dhcp [1002] - The IP address lease 192.168.1.17 for the Network Card with network address 00101350A343 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    29/06/2014 22:17:18, error: nvgts [5] - A parity error was detected on \Device\Scsi\nvgts2.
    29/06/2014 22:17:18, error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\D.
    29/06/2014 07:12:46, error: Dhcp [1002] - The IP address lease 192.168.1.13 for the Network Card with network address 001013501350 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
    27/06/2014 10:02:54, error: nvgts [9] - The device, \Device\Scsi\nvgts2, did not respond within the timeout period.
    15/07/2014 17:22:29, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    08/07/2014 15:46:56, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume F:.
    08/07/2014 15:46:56, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume E:.
    08/07/2014 15:46:30, error: Service Control Manager [7000] - The StarOpen service failed to start due to the following error: The system cannot find the file specified.
    08/07/2014 15:46:30, error: Service Control Manager [7000] - The PandoraService service failed to start due to the following error: The system cannot find the file specified.
    .
    ==== End Of File ===========================
     
  5. 2014/07/31
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    Aw snap log. DDS.txt

    DDS (Ver_2012-11-20.01) - NTFS_x86
    Internet Explorer: 8.0.6001.18702
    Run by brian at 2:21:53 on 2012-02-11
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1791.1060 [GMT 1:00]
    .
    AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ============== Running Processes ================
    .
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\imapi.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\system32\RunDLL32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\Everything\Everything.exe
    C:\Program Files\AVAST Software\Avast\AvastUI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    F:\Program Files\chrome-win32\chrome.exe
    F:\Program Files\chrome-win32\chrome.exe
    F:\Program Files\chrome-win32\chrome.exe
    F:\Program Files\chrome-win32\chrome.exe
    F:\Program Files\chrome-win32\chrome.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k NetworkService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\svchost.exe -k bthsvcs
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.co.uk/
    mStart Page = hxxp://www.google.com
    uURLSearchHooks: {37483b40-c254-4a72-bda4-22ee90182c1e} - <orphaned>
    BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - f:\oldprogram files 2\bitcomet\tools\BitCometBHO_1.4.8.11.dll
    BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
    BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - <orphaned>
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [Adobe Reader Synchronizer] "c:\program files\adobe\reader 10.0\reader\AdobeCollabSync.exe "
    mRun: [HPUsageTracking] "c:\program files\hewlett-packard\hp ut\bin\hppusg.exe" "c:\program files\hewlett-packard\HP UT "
    mRun: [hpbdfawep] c:\program files\hp\dfawep\bin\hpbdfawep.exe 1
    mRun: [PrnStatusMX] c:\program files\hewlett-packard\prnstatusmx\PrnStatusMX.exe
    mRun: [RemoteControl] "c:\program files\cyberlink dvd solution\powerdvd\PDVDServ.exe "
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
    mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
    mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4.0\OpwareSE4.exe "
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe "
    mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
    mRun: [Everything] "c:\program files\everything\Everything.exe" -startup
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe "
    mRun: [AvastUI.exe] "c:\program files\avast software\avast\AvastUI.exe" /nogui
    dRunOnce: [IE8] rundll32 advpack.dll,LaunchINFSection IE8.INF,FirstUserStart
    dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32
    uPolicies-Explorer: NoDriveTypeAutoRun = dword:223
    mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
    IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - f:\oldprogram files 2\bitcomet\tools\BitCometBHO_1.4.8.11.dll/206
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
    TCP: NameServer = 192.168.1.1 192.168.1.1
    TCP: Interfaces\{61E59856-5ECE-4337-B910-DE203301A8C4} : NameServer = 8.26.56.26,156.154.70.22
    TCP: Interfaces\{61E59856-5ECE-4337-B910-DE203301A8C4} : DHCPNameServer = 192.168.1.1 192.168.1.1
    TCP: Interfaces\{ED877E34-9220-4469-B4FE-B4BB5F7432DB} : DHCPNameServer = 192.168.1.1
    AppInit_DLLs= c:\progra~1\searchprotect\searchprotect\bin\SPVC32Loader.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
    mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\36.0.1985.125\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 aswRvrt;avast! Revert;c:\windows\system32\drivers\aswRvrt.sys [2012-2-10 49944]
    R0 aswVmm;avast! VM Monitor;c:\windows\system32\drivers\aswVmm.sys [2012-2-10 192352]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-2-10 779536]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswsp.sys [2012-2-10 414520]
    R2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys [2012-2-10 24184]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-2-10 67824]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-2-10 50344]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 PanService;PandoraService;c:\program files\pandora.tv\panservice\pandoraservice.exe --> c:\program files\pandora.tv\panservice\PandoraService.exe [?]
    S3 massfilter_hs;HS HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2013-4-1 15896]
    S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-8-11 16472]
    S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-8-11 11104]
    S3 SR9USB;SR9600 USB To Fast Ethernet Adapter;c:\windows\system32\drivers\sr9usb.sys [2014-6-16 14720]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== File Associations ===============
    .
    ShellExec: BitComet.exe: open= "f:\program files\bitcomet\BitComet.exe "
    .
    =============== Created Last 30 ================
    .
    2014-07-08 18:50:04 -------- d-----w- c:\windows\system32\wbem\repository\FS
    2014-07-08 18:50:04 -------- d-----w- c:\windows\system32\wbem\Repository
    2014-07-08 18:42:13 -------- d-----w- c:\program files\SlimBrowser
    2014-07-08 18:42:11 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\SlimBrowser
    2014-07-08 18:42:10 -------- d-----w- c:\program files\sweetpacks bundle uninstaller
    2014-07-08 14:08:59 -------- d-----w- c:\windows\LastGood(2)
    2014-07-01 18:54:02 -------- d-----w- c:\program files\Adobe(2)
    2014-06-27 09:20:33 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
    2014-06-22 13:14:58 -------- d-----w- c:\program files\SUPERAL Semiconductor, Inc
    2014-06-16 11:49:39 14720 ----a-w- c:\windows\system32\drivers\sr9usb.sys
    2014-05-11 09:35:33 -------- d-----w- c:\documents and settings\all users.windows\application data\MSScanAppDataDir
    2014-03-01 08:21:36 -------- d-----w- C:\epingsoft
    2014-03-01 08:01:57 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\OpenOffice
    2014-02-07 14:24:50 -------- d-----w- c:\windows\CtDrvInstall
    2014-02-07 14:24:43 -------- d-----w- C:\Live! Cam
    2014-01-13 13:35:20 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\1H1Q
    2014-01-13 13:34:07 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\cache
    2014-01-13 13:34:00 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\genienext
    2014-01-13 13:33:59 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\Mobogenie
    2014-01-13 07:47:39 -------- d-----w- c:\documents and settings\all users.windows\application data\ErrorEND
    2014-01-11 18:24:34 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\FrostWire
    2013-12-01 15:51:56 50053120 ----a-w- c:\program files\GUT2.tmp
    2013-12-01 15:51:56 -------- d-----w- c:\program files\GUM1.tmp
    2013-10-20 11:28:41 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\tixati
    2013-10-20 11:28:22 -------- d-----w- c:\program files\tixati
    2013-09-30 17:08:06 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\uTorrent
    2013-09-26 13:17:56 -------- d-----w- c:\program files\Belarc
    2013-08-21 06:43:41 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
    2013-08-20 19:26:15 14592 -c--a-w- c:\windows\system32\dllcache\kbdhid.sys
    2013-08-20 19:26:15 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
    2013-08-20 19:24:02 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\Babylon
    2013-07-07 13:44:54 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\Dropbox
    2013-05-18 17:58:03 -------- d-----w- c:\program files\Lame For Audacity
    2013-05-18 17:58:00 -------- d-----w- c:\program files\ffdshow
    2013-05-18 17:57:58 -------- d-----w- c:\documents and settings\all users.windows\application data\DivX
    2013-05-18 17:57:57 -------- d-----w- c:\program files\Haali
    2013-05-18 17:57:56 -------- d-----w- c:\program files\DSP-worx
    2013-05-18 17:57:56 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\LavFilters
    2013-05-18 17:54:35 -------- d-----w- c:\documents and settings\all users.windows\application data\BrowserProtect
    2013-05-17 10:57:05 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\CrashRpt
    2013-04-01 19:29:19 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
    2013-04-01 19:29:09 -------- d-----w- c:\windows\Logs
    2013-04-01 19:28:59 -------- d-----w- c:\program files\Microsoft Visual Studio 8
    2013-04-01 19:27:54 -------- d-----w- c:\program files\Microsoft Expression
    2013-03-27 09:55:14 -------- d-----w- c:\program files\VGA USB Camera
    2013-03-20 20:49:40 -------- d-----w- c:\program files\ZTE Handset USB Driver
    2012-12-18 10:20:37 -------- d-----w- c:\program files\Windows Live SkyDrive
    2012-12-18 10:13:38 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
    2012-12-18 09:03:47 -------- d-----w- c:\program files\Microsoft
    2012-12-18 09:02:56 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
    2012-12-18 08:47:03 74520 ----a-w- c:\program files\common files\windows live\.cache\40b4a5e41cddcfc\DSETUP.dll
    2012-12-18 08:47:03 484632 ----a-w- c:\program files\common files\windows live\.cache\40b4a5e41cddcfc\DXSETUP.exe
    2012-12-18 08:47:03 1670936 ----a-w- c:\program files\common files\windows live\.cache\40b4a5e41cddcfc\dsetup32.dll
    2012-12-18 08:46:09 1013800 ----a-w- c:\program files\common files\windows live\.cache\203fc2b21cddcfc\WindowsXP-KB954708-x86-ENU.exe
    2012-12-18 08:43:34 -------- d-----w- c:\program files\common files\Windows Live
    2012-12-16 10:01:09 -------- d-----w- c:\program files\Wolfenstein - Enemy Territory
    2012-12-05 17:27:42 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\Scansoft
    2012-12-05 17:25:06 -------- d-----w- c:\program files\Canon
    2012-12-05 17:23:40 -------- d-----w- c:\program files\common files\ScanSoft Shared
    2012-12-05 16:30:57 2680320 ----a-w- c:\windows\system32\ImageEnXLibrary.ocx
    2012-12-05 16:30:54 -------- d-----w- C:\FreeOCR
    2012-12-05 16:30:42 -------- d-----w- c:\program files\Temp
    2012-12-03 06:57:20 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\NwDocx
    2012-11-24 19:14:24 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\Docx2Rtf
    2012-11-22 11:40:23 -------- d-----w- c:\program files\ScanSoft
    2012-11-16 20:09:44 -------- d-----w- c:\windows\system32\appmgmt
    2012-11-16 19:25:52 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\APN
    2012-11-15 07:28:10 -------- d-----w- c:\program files\CCleaner
    2012-11-03 09:42:53 -------- d-----w- c:\program files\MSECache
    2012-10-30 19:12:12 -------- d-----w- c:\documents and settings\all users.windows\application data\usnbnmwubdskagi
    2012-10-15 11:03:05 200704 ----a-w- c:\windows\system32\vbalExpBar6.ocx
    2012-10-15 11:03:02 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
    2012-10-15 11:03:02 15360 ----a-w- c:\windows\system32\inetfr.DLL
    2012-10-15 11:03:02 115920 ----a-w- c:\windows\system32\msinet.OCX
    2012-10-15 11:03:01 484352 ----a-w- c:\windows\system32\lame_enc.dll
    2012-10-15 11:03:01 32768 ----a-w- c:\windows\system32\CMDLGFR.DLL
    2012-10-15 11:03:01 152848 ----a-w- c:\windows\system32\COMDLG32.OCX
    2012-10-15 11:03:01 141312 ----a-w- c:\windows\system32\MSCMCFR.DLL
    2012-10-15 11:03:01 119568 ----a-w- c:\windows\system32\VB6FR.DLL
    2012-10-15 11:03:01 101888 ----a-w- c:\windows\system32\VB6STKIT.DLL
    2012-10-15 11:03:00 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\FreeBurner
    2012-10-14 11:03:14 -------- d-----w- c:\program files\Free Easy CD DVD Burner
    2012-10-13 20:18:26 -------- d-----w- c:\documents and settings\all users.windows\application data\SweetIM(2)
    2012-10-13 18:55:43 -------- d-----w- c:\program files\SweetIM
    2012-10-13 18:06:33 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\DriverCure
    2012-10-12 18:17:30 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\SuperNZB
    2012-10-12 18:17:16 -------- d-----w- c:\program files\SuperNZB
    2012-10-08 17:45:12 -------- d-----w- C:\Dossier et diaporama (fichiers modifiables)
    2012-09-28 16:20:59 -------- d-----w- C:\Temp
    2012-09-26 09:46:36 -------- d-----w- C:\FreeOCR(2)
    2012-09-21 16:30:01 -------- d-----w- c:\program files\locr
    2012-09-21 16:16:59 -------- d-----w- C:\SiLabs
    2012-09-21 12:23:12 -------- d-----w- c:\program files\gpsPhotoTagger
    2012-09-05 15:36:26 -------- d-----w- c:\program files\Kana Reminder
    2012-09-01 19:28:24 -------- d-----w- c:\program files\19th Parallel
    2012-09-01 19:28:24 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\19th Parallel
    2012-08-26 08:43:56 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
    2012-08-26 08:43:56 8192 ----a-w- c:\windows\system32\wshirda.dll
    2012-08-26 08:43:56 28160 -c--a-w- c:\windows\system32\dllcache\irmon.dll
    2012-08-26 08:43:56 28160 ----a-w- c:\windows\system32\irmon.dll
    2012-08-26 08:43:56 151552 -c--a-w- c:\windows\system32\dllcache\irftp.exe
    2012-08-26 08:43:56 151552 ----a-w- c:\windows\system32\irftp.exe
    2012-08-15 11:55:27 -------- d-----w- c:\windows\Downloaded Installations
    2012-08-05 15:42:58 -------- d-----w- c:\documents and settings\all users.windows\application data\Premium
    2012-07-21 15:20:48 -------- d-----w- c:\documents and settings\all users.windows\application data\Ask
    2012-07-16 07:46:17 -------- d--h--w- c:\windows\PIF
    2012-07-15 16:48:40 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\NVIDIA
    2012-07-15 16:45:59 -------- d-----w- c:\documents and settings\all users.windows\application data\NVIDIA Corporation
    2012-07-15 16:45:29 164160 ----a-w- c:\windows\system32\nvsvc32.exe
    2012-07-15 16:45:29 143680 ----a-w- c:\windows\system32\nvcolor.exe
    2012-07-15 16:45:28 15504192 ----a-w- c:\windows\system32\nvcpl.dll
    2012-07-15 16:45:28 108352 ----a-w- c:\windows\system32\nvmctray.dll
    2012-07-15 16:45:27 54272 ----a-w- c:\windows\system32\nvwddi.dll
    2012-07-15 16:43:41 -------- d-----w- C:\NVIDIA
    2012-07-13 14:35:34 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\Opera
    2012-07-07 12:45:00 -------- d-----w- c:\documents and settings\all users.windows\application data\InstallMate
    2012-05-26 16:59:29 -------- d-----w- c:\program files\Jasc Software Inc
    2012-05-25 18:06:59 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\Philipp Winterberg
    2012-05-25 18:06:56 -------- d-----w- c:\program files\RarZilla Free Unrar
    2012-05-25 11:22:58 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\kompozer.net
    2012-05-25 11:22:58 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\kompozer.net
    2012-05-11 11:07:21 -------- d-----w- c:\documents and settings\all users.windows\application data\CPA_VA
    2012-05-11 11:02:25 348160 ----a-w- c:\windows\system32\msvcr71.dll
    2012-05-11 11:02:25 1060864 ----a-w- c:\windows\system32\mfc71.dll
    2012-05-09 18:52:41 -------- d-----w- c:\program files\Ulead Systems
    2012-05-03 13:31:48 -------- d-----w- c:\program files\Everything
    2012-04-08 09:11:09 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\HpUpdate
    2012-04-08 09:11:05 -------- d-----w- c:\windows\Hewlett-Packard
    2012-04-03 19:02:14 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\WMTools Downloaded Files
    2012-03-31 14:37:08 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\NCH Software
    2012-03-31 14:34:48 -------- d-----w- c:\program files\NCH Software
    2012-03-24 18:37:23 6600192 ----a-w- c:\windows\system32\LicProtector310.exe
    2012-03-24 18:37:23 2323520 ----a-w- c:\windows\system32\gdpicturepro5.ocx
    2012-03-24 18:37:20 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\local settings\application data\PackageAware
    2012-03-11 19:13:20 301224 ----a-w- c:\windows\system32\guard32.dll
    2012-02-10 20:34:55 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\DropboxMaster
    2012-02-10 20:34:23 -------- d-----w- c:\program files\Dropbox
    2012-02-10 20:21:52 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\AVAST Software
    2012-02-10 20:20:36 -------- d-----w- c:\windows\jumpshot.com
    2012-02-10 20:16:13 192352 ----a-w- c:\windows\system32\drivers\aswVmm.sys
    2012-02-10 20:16:12 779536 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2012-02-10 20:16:11 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2012-02-10 20:16:11 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
    2012-02-10 20:16:10 24184 ----a-w- c:\windows\system32\drivers\aswHwid.sys
    2012-02-10 20:16:02 43152 ----a-w- c:\windows\avastSS.scr
    2012-02-10 20:10:07 -------- d-----w- c:\program files\AVAST Software
    2012-02-10 20:09:19 -------- d-----w- c:\documents and settings\all users.windows\application data\AVAST Software
    2012-02-08 19:08:53 53208 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
    2012-02-08 18:56:32 110296 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2012-01-27 10:00:30 -------- d-----w- c:\documents and settings\brian.brian-655g42dgo\application data\OpenOffice.org
    2012-01-26 11:29:57 -------- d-----w- c:\program files\Awesome Duplicate Photo Finder
    2012-01-15 20:33:19 -------- d-sh--w- c:\documents and settings\brian.brian-655g42dgo\IECompatCache
    2012-01-12 21:27:24 4711 ------w- c:\windows\system32\dmouse.vxd
    .
    ==================== Find3M ====================
    .
    2013-10-02 10:07:53 1074636 ----a-w- c:\windows\system32\nvdrsdb0.bin
    2013-10-02 10:07:53 1 ----a-w- c:\windows\system32\nvdrssel.bin
    2012-07-30 15:06:12 1074636 ----a-w- c:\windows\system32\nvdrsdb1.bin
    2012-05-15 10:18:00 883008 ----a-w- c:\windows\system32\nvgenco32.dll
    2012-05-15 10:18:00 65536 ----a-w- c:\windows\system32\OpenCL.dll
    2012-05-15 10:18:00 6012928 ----a-w- c:\windows\system32\nvcuda.dll
    2012-05-15 10:18:00 4373248 ----a-w- c:\windows\system32\nv4_disp.dll
    2012-05-15 10:18:00 2530624 ----a-w- c:\windows\system32\nvcuvid.dll
    2012-05-15 10:18:00 2445120 ----a-w- c:\windows\system32\nvcuvenc.dll
    2012-05-15 10:18:00 2359808 ----a-w- c:\windows\system32\nvapi.dll
    2012-05-15 10:18:00 18771968 ----a-w- c:\windows\system32\nvoglnt.dll
    2012-05-15 10:18:00 17543168 ----a-w- c:\windows\system32\nvcompiler.dll
    2012-05-15 10:18:00 14014656 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
    2012-05-15 10:18:00 1000768 ----a-w- c:\windows\system32\nvdispco32.dll
    2012-01-10 18:32:48 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2004-03-11 11:27:22 40960 ----a-w- c:\program files\Uninstall_CDS.exe
    .
    ============= FINISH: 2:27:31.65 ===============
     
  6. 2014/07/31
    bg9208

    bg9208 Inactive Thread Starter

    Joined:
    2004/10/04
    Messages:
    252
    Likes Received:
    1
    aw snap notes

    Did as requested hope logs are OK.. Main problems now are 1) When i open some web pages ,I get the page but only in Text with no formatting - interaction is impossible

    2) Chrome browser says " your profile cant be used becaue from a newer version. some features unavailable. Please specify a different profile directory or use newer version "
    It wont let me update or re-install

    Numerous web page show "The servers security certificate is not valid "
    or " server has not renewed security cert ".

    Booting is much slower than usual.

    TIA
     
  7. 2014/07/31
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Do NOT create new topic to post logs.
    This time I merged both of your topics.


    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ================================

    I still need MBAM log.
     
  8. 2014/08/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Still with me?
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.