TechSpot

[Closed] IE slow performance wlnotify.dll

By bcrens7
Jul 7, 2011
Topic Status:
Not open for further replies.
  1. i want to check if i have a virus or anything because when i start my laptop now at the login it says exucuting wlnotify.dll for a while befor it logs in and my ie is very slow


    im still working on getting the logs
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    There are many reasons for slow startup or 'slow' computer. But I'll be glad to review your logs for malware when you finish the scans. Take your time an follow the instructions in the Preliminary Virus and Malware Removal thread HERE.

    NOTE: If you already have any of the scanning programs on the computer, please remove them and download the versions in these links.

    When you have finished, leave the logs for review in your next reply .
    NOTE: Logs must be pasted in the replies. Attached logs will not be reviewed.
    ======================================
    My Guidelines: please read and follow:
    • Be patient. Malware cleaning takes time and I am also working with other members while I am helping you.
    • Read my instructions carefully. If you don't understand or have a problem, ask me.
    • If you have questions, or if a program doesn't work, stop and tell me about it. Don't try to get around it yourself.
    • Follow the order of the tasks I give you. Order is crucial in cleaning process.
    • File sharing programs should be uninstalled or disabled during the cleaning process..
    • Observe these:
      [o] Don't use any other cleaning programs or scans while I'm helping you.
      [o] Don't use a Registry cleaner or make any changes in the Registry.
      [o] Don't download and install new programs- except those I give you.
    • Please let me know if there is any change in the system.
    If I have not replied for 2 days, you can send me a PM reminder. Include the URL of your thread. Please do not send me a PM to tell me your logs are up.
    If I don't get a reply from you in 5 days, the thread will be closed. If your problem persist, you can send a PM to reopen it.
    =====================================
  3. bcrens7

    bcrens7 TS Rookie Topic Starter Posts: 40

    Malwarebytes' Anti-Malware 1.51.0.1200
    www.malwarebytes.org

    Database version: 7042

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    7/7/2011 10:09:39 AM
    mbam-log-2011-07-07 (10-09-39).txt

    Scan type: Quick scan
    Objects scanned: 143164
    Time elapsed: 13 minute(s), 10 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Value: ForceClassicControlPanel -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    GMER

    nothing to copy

    Attach
    DDS (Ver_2011-06-23.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/6/2011 11:49:52 PM
    System Uptime: 7/7/2011 10:49:06 AM (1 hours ago)
    .
    Motherboard: Acer, Inc. | | Prespa M
    Processor: AMD Turion(tm) 64 X2 Mobile Technology TL-50 | Socket M2/S1G1 | 1599/133mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 112 GiB total, 100.946 GiB free.
    D: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: USB20 Camera
    Device ID: USB\VID_0C45&PID_6260\5&25791493&0&3
    Manufacturer:
    Name: USB20 Camera
    PNP Device ID: USB\VID_0C45&PID_6260\5&25791493&0&3
    Service:
    .
    Class GUID:
    Description: Modem Device on High Definition Audio Bus
    Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_1025010F&REV_0900\4&104FD401&0&0002
    Manufacturer:
    Name: Modem Device on High Definition Audio Bus
    PNP Device ID: HDAUDIO\FUNC_02&VEN_14F1&DEV_2BFA&SUBSYS_1025010F&REV_0900\4&104FD401&0&0002
    Service:
    .
    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: PCI FLASH Memory
    Device ID: PCI\VEN_1524&DEV_0530&SUBSYS_010F1025&REV_01\4&FCF0450&0&09A4
    Manufacturer:
    Name: PCI FLASH Memory
    PNP Device ID: PCI\VEN_1524&DEV_0530&SUBSYS_010F1025&REV_01\4&FCF0450&0&09A4
    Service:
    .
    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: PCI FLASH Memory
    Device ID: PCI\VEN_1524&DEV_0520&SUBSYS_010F1025&REV_01\4&FCF0450&0&0BA4
    Manufacturer:
    Name: PCI FLASH Memory
    PNP Device ID: PCI\VEN_1524&DEV_0520&SUBSYS_010F1025&REV_01\4&FCF0450&0&0BA4
    Service:
    .
    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: PCI FLASH Memory
    Device ID: PCI\VEN_1524&DEV_0551&SUBSYS_010F1025&REV_01\4&FCF0450&0&0CA4
    Manufacturer:
    Name: PCI FLASH Memory
    PNP Device ID: PCI\VEN_1524&DEV_0551&SUBSYS_010F1025&REV_01\4&FCF0450&0&0CA4
    Service:
    .
    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: Network Controller
    Device ID: PCI\VEN_14E4&DEV_4318&SUBSYS_03121468&REV_02\4&FCF0450&0&20A4
    Manufacturer:
    Name: Network Controller
    PNP Device ID: PCI\VEN_14E4&DEV_4318&SUBSYS_03121468&REV_02\4&FCF0450&0&20A4
    Service:
    .
    ==== System Restore Points ===================
    .
    RP1: 7/6/2011 11:51:46 PM - System Checkpoint
    RP2: 7/7/2011 12:10:43 AM - Software Distribution Service 3.0
    RP3: 7/7/2011 12:23:42 AM - Installed EasyCleaner
    RP4: 7/7/2011 12:25:34 AM - fresh
    RP5: 7/7/2011 1:01:10 AM - Software Distribution Service 3.0
    RP6: 7/7/2011 1:35:17 AM - Software Distribution Service 3.0
    RP7: 7/7/2011 2:08:39 AM - Software Distribution Service 3.0
    RP8: 7/7/2011 8:26:46 AM - Software Distribution Service 3.0
    RP9: 7/7/2011 9:13:21 AM - Software Distribution Service 3.0
    RP10: 7/7/2011 9:22:41 AM - Software Distribution Service 3.0
    .
    ==== Installed Programs ======================
    .
    Atheros Wireless LAN
    ATI - Software Uninstall Utility
    ATI Catalyst Control Center
    ATI Display Driver
    ATI Parental Control & Encoder
    EasyCleaner
    HiJackThis
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 10 (KB903157)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB981793)
    Malwarebytes' Anti-Malware version 1.51.0.1200
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Base Smart Card Cryptographic Service Provider Package
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    MSXML 6.0 Parser (KB933579)
    Realtek High Definition Audio Driver
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Windows Internet Explorer 8 (KB2530548)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2412687)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476490)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2481109)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485663)
    Security Update for Windows XP (KB2503665)
    Security Update for Windows XP (KB2506212)
    Security Update for Windows XP (KB2506223)
    Security Update for Windows XP (KB2507618)
    Security Update for Windows XP (KB2508272)
    Security Update for Windows XP (KB2508429)
    Security Update for Windows XP (KB2509553)
    Security Update for Windows XP (KB2510581)
    Security Update for Windows XP (KB2524375)
    Security Update for Windows XP (KB2530548)
    Security Update for Windows XP (KB2535512)
    Security Update for Windows XP (KB2536276)
    Security Update for Windows XP (KB2544521)
    Security Update for Windows XP (KB2544893)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982381)
    Security Update for Windows XP (KB982665)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Windows (KB971513)
    Update for Windows Internet Explorer 8 (KB2447568)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB2492386)
    Update for Windows XP (KB2541763)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971029)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update Rollup 2 for Windows XP Media Center Edition 2005
    WebFldrs XP
    Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (04/28/2006 1.3.1.0)
    Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Internet Explorer 8
    Windows Management Framework Core
    Windows Media Format 11 runtime
    Windows Media Format SDK Hotfix - KB891122
    Windows Media Player 11
    Windows XP Media Center Edition 2005 KB2502898
    Windows XP Media Center Edition 2005 KB925766
    Windows XP Media Center Edition 2005 KB973768
    Windows XP Service Pack 3
    .
    ==== Event Viewer Messages From Past Week ========
    .
    7/7/2011 9:18:02 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x800706be: Internet Explorer 8 for Windows XP.
    7/7/2011 9:18:02 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x800706ba: Windows PowerShell 2.0 and WinRM 2.0 for Windows XP and Windows Embedded (KB968930).
    7/7/2011 9:18:02 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x800706ba: Update for Windows XP (KB971513).
    7/7/2011 9:18:02 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x800706ba: Update for Windows XP (KB2492386).
    7/7/2011 9:18:02 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x800706ba: Update for Root Certificates [June 2011] (KB931125).
    7/7/2011 9:18:02 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x800706ba: Security Update for .NET Framework 2.0 SP2 and 3.5 SP1 on Windows Server 2003 and Windows XP x86 (KB2518864).
    7/7/2011 2:06:17 AM, error: ati2mtag [4] - You are running different builds of the miniport and display driver. Please use a matched pair.
    7/7/2011 10:55:29 AM, error: System Error [1003] - Error code 100000d1, parameter1 00000002, parameter2 00000002, parameter3 00000000, parameter4 f732079c.
    7/7/2011 10:31:46 AM, error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort0.
    7/7/2011 10:11:43 AM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
    7/6/2011 11:50:06 PM, error: Setup [60055] - Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information.
    .
    ==== End Of File ===========================

    DDS
    .
    DDS (Ver_2011-06-23.01) - NTFSx86
    Internet Explorer: 8.0.6001.18702
    Run by New User at 11:04:23 on 2011-07-07
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.574 [GMT -7:00]
    .
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uRun: [DriverUpdaterPro] c:\program files\xpc tools\driver updater pro\DriverUpdaterPro.exe -t
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [INPROCOMMWireless] c:\program files\atheros\wireless\utility\WlanUtil.exe
    mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [Alcmtr] ALCMTR.EXE
    mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
    dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
    uPolicies-explorer: NoResolveTrack = 1 (0x1)
    dPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
    dPolicies-explorer: NoResolveTrack = 1 (0x1)
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1310021726023
    TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    TCP: Interfaces\{3CFCD144-3B2F-4C5A-80FF-B06CB9865BBE} : DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    Notify: Antiwpa - activenexus.DLL
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-7 366640]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-7-7 22712]
    S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-7-7 39984]
    S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-9 14336]
    .
    =============== Created Last 30 ================
    .
    2011-07-07 16:54:41 -------- d-sh--w- c:\documents and settings\new user\IECompatCache
    2011-07-07 16:54:11 -------- d-sh--w- c:\documents and settings\new user\PrivacIE
    2011-07-07 16:53:23 -------- d-----w- c:\documents and settings\new user\application data\Malwarebytes
    2011-07-07 16:53:15 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-07-07 16:53:14 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
    2011-07-07 16:53:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-07-07 16:53:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-07-07 16:52:22 -------- d-sh--w- c:\documents and settings\new user\IETldCache
    2011-07-07 16:29:50 -------- d-----w- c:\windows\system32\winrm
    2011-07-07 16:29:50 -------- d-----w- c:\windows\system32\GroupPolicy
    2011-07-07 16:29:47 -------- dc-h--w- c:\windows\$968930Uinstall_KB968930$
    2011-07-07 16:28:42 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
    2011-07-07 16:28:26 -------- d-----w- c:\windows\ie8updates
    2011-07-07 16:27:45 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
    2011-07-07 16:27:44 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
    2011-07-07 16:27:44 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
    2011-07-07 16:27:44 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
    2011-07-07 16:27:44 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
    2011-07-07 16:27:44 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll
    2011-07-07 16:27:44 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
    2011-07-07 16:26:16 -------- dc-h--w- c:\windows\ie8
    2011-07-07 16:15:41 -------- d-----w- C:\48d7abccc1a0a36a8b
    2011-07-07 16:15:18 -------- d-----w- c:\program files\XPC Tools
    2011-07-07 16:15:18 -------- d-----w- c:\program files\Windows Media Connect 2
    2011-07-07 16:14:07 -------- d-----w- c:\windows\system32\LogFiles
    2011-07-07 16:07:51 0 ----a-w- c:\windows\ativpsrm.bin
    2011-07-07 16:02:16 -------- d-----w- C:\ATI
    2011-07-07 15:57:53 49664 ----a-w- c:\windows\system32\amdpcom32.dll
    2011-07-07 15:57:53 45056 ----a-w- c:\windows\system32\aticalrt.dll
    2011-07-07 15:57:53 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
    2011-07-07 15:57:53 3227648 ----a-w- c:\windows\system32\aticaldd.dll
    2011-07-07 15:57:53 118784 ----a-w- c:\windows\system32\atibrtmon.exe
    2011-07-07 15:57:52 45056 ----a-w- c:\windows\system32\aticalcl.dll
    2011-07-07 15:57:52 290816 ----a-w- c:\windows\system32\atiok3x2.dll
    2011-07-07 15:57:52 126976 ----a-w- c:\windows\system32\atiadlxx.dll
    2011-07-07 15:44:40 -------- d-----w- c:\documents and settings\new user\local settings\application data\Innovative Solutions
    2011-07-07 15:44:40 -------- d-----w- c:\documents and settings\all users\application data\Innovative Solutions
    2011-07-07 15:37:39 388096 ----a-r- c:\documents and settings\new user\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-07-07 15:37:38 -------- d-----w- c:\program files\Trend Micro
    2011-07-07 15:25:48 -------- d-----w- c:\windows\system32\Lang
    2011-07-07 09:10:24 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
    2011-07-07 09:10:11 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
    2011-07-07 09:09:53 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
    2011-07-07 09:07:16 -------- d-----w- c:\windows\system32\RTCOM
    2011-07-07 09:07:14 4096 -c--a-w- c:\windows\system32\dllcache\ksuser.dll
    2011-07-07 09:07:14 4096 ----a-w- c:\windows\system32\ksuser.dll
    2011-07-07 09:07:14 146048 -c--a-w- c:\windows\system32\dllcache\portcls.sys
    2011-07-07 09:07:14 146048 ----a-w- c:\windows\system32\drivers\portcls.sys
    2011-07-07 09:07:14 129536 ----a-w- c:\windows\system32\ksproxy.ax
    2011-07-07 09:07:13 60160 -c--a-w- c:\windows\system32\dllcache\drmk.sys
    2011-07-07 09:07:13 60160 ----a-w- c:\windows\system32\drivers\drmk.sys
    2011-07-07 09:06:44 759296 -c--a-w- c:\windows\system32\dllcache\VGX.dll
    2011-07-07 09:05:46 45568 -c----w- c:\windows\system32\dllcache\wab.exe
    2011-07-07 09:03:59 -------- d-----w- c:\documents and settings\new user\local settings\application data\ATI
    2011-07-07 08:56:38 -------- d-----w- c:\windows\pss
    2011-07-07 08:48:46 -------- d-----w- c:\windows\system32\scripting
    2011-07-07 08:48:44 -------- d-----w- c:\windows\system32\en
    2011-07-07 08:48:44 -------- d-----w- c:\windows\system32\bits
    2011-07-07 08:48:44 -------- d-----w- c:\windows\l2schemas
    2011-07-07 08:43:22 192512 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iuser.dll
    2011-07-07 08:43:21 729088 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iKernel.dll
    2011-07-07 08:43:21 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\ctor.dll
    2011-07-07 08:43:21 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
    2011-07-07 08:43:21 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iscript.dll
    2011-07-07 08:43:21 188548 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\iGdi.dll
    2011-07-07 08:43:20 311428 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\setup.dll
    2011-07-07 08:43:10 -------- d-----w- c:\windows\network diagnostic
    2011-07-07 08:42:57 -------- d-----w- c:\program files\ATI Technologies
    2011-07-07 08:34:14 36864 ----a-w- c:\windows\system32\drivers\AmdK8.sys
    2011-07-07 08:33:16 25471 ------w- c:\windows\system32\drivers\watv10nt.sys
    2011-07-07 08:33:16 22271 ------w- c:\windows\system32\drivers\watv06nt.sys
    2011-07-07 08:33:16 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys
    2011-07-07 08:33:16 11871 ------w- c:\windows\system32\drivers\wadv09nt.sys
    2011-07-07 08:33:16 11807 ------w- c:\windows\system32\drivers\wadv07nt.sys
    2011-07-07 08:33:16 11295 ------w- c:\windows\system32\drivers\wadv08nt.sys
    2011-07-07 08:33:10 166912 ------w- c:\windows\system32\drivers\s3gnbm.sys
    2011-07-07 08:33:09 1897408 ------w- c:\windows\system32\drivers\nv4_mini.sys
    2011-07-07 08:33:08 452736 ------w- c:\windows\system32\drivers\mtxparhm.sys
    2011-07-07 08:03:49 212992 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ILog.dll
    2011-07-07 07:53:52 -------- d-----w- c:\windows\ServicePackFiles
    2011-07-07 07:49:22 -------- d-----w- c:\windows\system32\XPSViewer
    2011-07-07 07:48:53 89088 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    2011-07-07 07:48:47 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
    2011-07-07 07:48:47 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
    2011-07-07 07:48:47 597504 ------w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
    2011-07-07 07:48:47 117760 ------w- c:\windows\system32\prntvpt.dll
    2011-07-07 07:48:46 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
    2011-07-07 07:48:46 575488 ------w- c:\windows\system32\xpsshhdr.dll
    2011-07-07 07:48:46 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
    2011-07-07 07:48:46 1676288 ------w- c:\windows\system32\xpssvcs.dll
    2011-07-07 07:48:46 -------- d-----w- C:\bfae1990a4cd88c8e0293afe60122cf3
    2011-07-07 07:46:46 -------- d-----w- c:\program files\MSXML 6.0
    2011-07-07 07:41:26 46592 ------w- c:\windows\system32\drivers\irbus.sys
    2011-07-07 07:41:26 19200 ------w- c:\windows\system32\drivers\hidir.sys
    2011-07-07 07:39:47 -------- d-----w- c:\documents and settings\new user\local settings\application data\ApplicationHistory
    2011-07-07 07:38:59 -------- d-----w- c:\windows\system32\ReinstallBackups
    2011-07-07 07:38:46 47616 ----a-w- c:\program files\windows media player\msoobci.dll
    2011-07-07 07:38:46 1669120 ----a-w- c:\program files\windows media player\wmsetsdk.exe
    2011-07-07 07:38:25 -------- d-----w- c:\windows\RegisteredPackages
    2011-07-07 07:37:16 -------- d-----w- c:\windows\system32\URTTemp
    2011-07-07 07:36:50 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
    2011-07-07 07:34:42 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
    2011-07-07 07:34:30 357888 -c----w- c:\windows\system32\dllcache\srv.sys
    2011-07-07 07:34:03 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
    2011-07-07 07:34:03 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
    2011-07-07 07:33:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
    2011-07-07 07:29:36 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
    2011-07-07 07:28:41 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
    2011-07-07 07:28:41 272128 ------w- c:\windows\system32\drivers\bthport.sys
    2011-07-07 07:28:39 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
    2011-07-07 07:23:43 -------- d-----w- c:\program files\ToniArts
    2011-07-07 07:23:33 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\ctor.dll
    2011-07-07 07:23:33 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
    2011-07-07 07:23:33 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\iscript.dll
    2011-07-07 07:23:33 172032 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\iuser.dll
    2011-07-07 07:23:32 733184 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\iKernel.dll
    2011-07-07 07:23:32 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\DotNetInstaller.exe
    2011-07-07 07:23:31 303236 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\setup.dll
    2011-07-07 07:23:31 180356 ----a-w- c:\program files\common files\installshield\professional\runtime\10\01\intel32\iGdi.dll
    2011-07-07 07:11:12 -------- d-----w- c:\windows\system32\PreInstall
    2011-07-07 07:11:11 26144 ----a-w- c:\windows\system32\spupdsvc.exe
    2011-07-07 07:11:10 -------- d--h--w- c:\windows\$hf_mig$
    .
    ==================== Find3M ====================
    .
    2011-07-07 08:42:07 6684672 ----a-w- c:\windows\system32\atioglx1.dll
    2011-07-07 08:42:06 303104 ----a-w- c:\windows\system32\ATIDEMGR.dll
    2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
    2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-04-25 16:11:12 916480 ----a-w- c:\windows\system32\wininet.dll
    2011-04-25 16:11:11 43520 ------w- c:\windows\system32\licmgr10.dll
    2011-04-25 16:11:11 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2011-04-25 12:01:22 385024 ------w- c:\windows\system32\html.iec
    2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
    .
    ============= FINISH: 11:06:44.21 ===============
  4. bcrens7

    bcrens7 TS Rookie Topic Starter Posts: 40

    for the gmer to make a log do i need to click scan or should the first scan when opened make one
  5. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Please download GMER: Go to this site http://www.gmer.net/files.php and click on Download EXE. Save the file to your desktop
    Two other links for the download should you need one:
    Link 2
    Link 3
    • Double click on downloaded .exe file on the desktop
    • Select Rootkit tab> click Scan
      You may see this display>> Click No
      [​IMG]
    • When scan is completed, >>>>
      [o]click Save button, and
      [o] save the results as gmer.log

    This screenshot HERE will show you how the display will come up.

    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log.
  6. bcrens7

    bcrens7 TS Rookie Topic Starter Posts: 40

    can i post diffrent logs from a diffrent computer i just want to make sure my computer is still clean the previous computer that i had the problems with i sold
  7. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Sorry- I have no idea what you mean by this. Of you want to check a computer for malware, the scans have to be done on that computer.
  8. bcrens7

    bcrens7 TS Rookie Topic Starter Posts: 40

    new logs these are the ones i would like checked

    Malwarebytes' Anti-Malware 1.51.0.1200
    www.malwarebytes.org

    Database version: 7091

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    7/12/2011 1:58:34 PM
    mbam-log-2011-07-12 (13-58-34).txt

    Scan type: Quick scan
    Objects scanned: 182286
    Time elapsed: 9 minute(s), 20 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    gmer
    GMER 1.0.15.15640 - http://www.gmer.net
    Rootkit quick scan 2011-07-12 13:47:44
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Scsi\nvgts1Port2Path0Target0Lun0 Hitachi_ rev.V5CO
    Running: ixgptk21.exe; Driver: D:\DOCUME~1\crenshaw\LOCALS~1\Temp\fwryqpow.sys


    ---- System - GMER 1.0.15 ----

    SSDT spao.sys ZwEnumerateKey [0xF72ACDA4]
    SSDT spao.sys ZwEnumerateValueKey [0xF72AD132]

    ---- Devices - GMER 1.0.15 ----

    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F720EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort0 [F720EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort1 [F720EB40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\nvgts \Device\Scsi\nvgts1Port2Path0Target0Lun0 89D601F8
    Device \Driver\nvgts \Device\Scsi\nvgts1 89D601F8
    Device \Driver\nvgts \Device\Scsi\nvgts2 89D601F8
    Device \FileSystem\Ntfs \Ntfs 89D5F1F8

    ---- EOF - GMER 1.0.15 ----

    dds
    .
    DDS (Ver_2011-06-23.01) - NTFSx86
    Internet Explorer: 8.0.6001.18702
    Run by crenshaw at 14:00:57 on 2011-07-12
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.643 [GMT -7:00]
    .
    AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
    .
    ============== Running Processes ===============
    .
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    d:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
    D:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    D:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    D:\Program Files\Java\jre6\bin\jqs.exe
    D:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
    D:\WINDOWS\system32\Ati2evxx.exe
    D:\WINDOWS\Explorer.EXE
    D:\Program Files\Microsoft Security Client\msseces.exe
    D:\Program Files\Common Files\Java\Java Update\jusched.exe
    D:\WINDOWS\RTHDCPL.EXE
    D:\Program Files\Unlocker\UnlockerAssistant.exe
    D:\Program Files\real\realplayer\update\realsched.exe
    D:\WINDOWS\system32\ctfmon.exe
    D:\Program Files\Motorola\MotoConnectService\MotoConnect.exe
    D:\Program Files\MagicDisc\MagicDisc.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\Program Files\Internet Explorer\iexplore.exe
    D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
    D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
    D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
    D:\WINDOWS\system32\wuauclt.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uWindow Title = Windows Internet Explorer provided by MSN & Bing
    uURLSearchHooks: H - No File
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - d:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
    BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
    BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - d:\program files\ask.com\GenericAskToolbar.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
    TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - d:\program files\ask.com\GenericAskToolbar.dll
    uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
    mRun: [MSC] "d:\program files\microsoft security client\msseces.exe" -hide -runkey
    mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe"
    mRun: [amd_dc_opt] d:\program files\amd\dual-core optimizer\amd_dc_opt.exe
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [AzMixerSel] d:\program files\realtek\audio\drivers\AzMixerSel.exe
    mRun: [<NO NAME>]
    mRun: [UnlockerAssistant] "d:\program files\unlocker\UnlockerAssistant.exe"
    mRun: [TkBellExe] "d:\program files\real\realplayer\update\realsched.exe" -osboot
    mRun: [Malwarebytes' Anti-Malware] "d:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
    mRunOnce: [Malwarebytes' Anti-Malware] d:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
    StartupFolder: d:\docume~1\crenshaw\startm~1\programs\startup\magicd~1.lnk - d:\program files\magicdisc\MagicDisc.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {A5A76EA0-7B92-4707-9DBF-6F6FE56A6800} - hxxp://nmreports.linksys.com/nmscan/download/WebDiag.4.5.8056.1-ship-WD.V1.cab
    DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    TCP: Interfaces\{94B55605-9BB2-439B-A164-29A55559B626} : DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R1 MpFilter;Microsoft Malware Protection Driver;d:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
    R1 MpKsl51c03b83;MpKsl51c03b83;d:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3d716634-de9c-4ee1-999a-bbe6d1bcbb93}\MpKsl51c03b83.sys [2011-7-12 28752]
    R2 acedrv11;acedrv11;d:\windows\system32\drivers\acedrv11.sys [2010-2-24 185472]
    R2 MBAMService;MBAMService;d:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-12 366640]
    R2 MotoConnect Service;MotoConnect Service;d:\program files\motorola\motoconnectservice\MotoConnectService.exe [2011-5-15 91392]
    R3 MBAMProtector;MBAMProtector;d:\windows\system32\drivers\mbam.sys [2011-7-12 22712]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;d:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 gupdate;Google Update Service (gupdate);d:\program files\google\update\googleupdate.exe /svc --> d:\program files\google\update\GoogleUpdate.exe [?]
    S3 Ambfilt;Ambfilt;d:\windows\system32\drivers\Ambfilt.sys [2011-6-25 1691480]
    S3 androidusb;ADB Interface Driver;d:\windows\system32\drivers\motoandroid.sys [2011-5-15 25856]
    S3 gupdatem;Google Update Service (gupdatem);d:\program files\google\update\googleupdate.exe /medsvc --> d:\program files\google\update\GoogleUpdate.exe [?]
    S3 motccgp;Motorola USB Composite Device Driver;d:\windows\system32\drivers\motccgp.sys [2011-5-15 19712]
    S3 motccgpfl;MotCcgpFlService;d:\windows\system32\drivers\motccgpfl.sys [2011-5-15 8320]
    S3 pwdrvio;pwdrvio;d:\windows\system32\pwdrvio.sys [2011-6-28 16472]
    S3 pwdspio;pwdspio;d:\windows\system32\pwdspio.sys [2011-6-28 11104]
    S3 WinRM;Windows Remote Management (WS-Management);d:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;d:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
    .
    =============== Created Last 30 ================
    .
    2011-07-12 20:48:30 -------- d-----w- d:\documents and settings\crenshaw\application data\Malwarebytes
    2011-07-12 20:48:24 39984 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
    2011-07-12 20:48:19 22712 ----a-w- d:\windows\system32\drivers\mbam.sys
    2011-07-12 20:48:19 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
    2011-07-12 19:28:07 28752 ----a-w- d:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3d716634-de9c-4ee1-999a-bbe6d1bcbb93}\MpKsl51c03b83.sys
    2011-07-12 17:20:35 7074640 ----a-w- d:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3d716634-de9c-4ee1-999a-bbe6d1bcbb93}\mpengine.dll
    2011-07-07 04:19:49 691696 ----a-w- d:\windows\system32\drivers\sptd.sys
    2011-07-07 04:19:41 -------- d-----w- d:\program files\LSoft Technologies
    2011-07-06 02:40:00 6144 -c--a-w- d:\windows\system32\dllcache\kbd106.dll
    2011-07-06 02:40:00 6144 ----a-w- d:\windows\system32\kbd106.dll
    2011-07-03 19:25:45 404640 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
    2011-06-30 23:03:41 -------- d-----w- d:\documents and settings\all users\application data\Malwarebytes
    2011-06-30 05:21:02 -------- d-----w- d:\documents and settings\all users\application data\Trymedia
    2011-06-30 05:19:57 -------- d-----w- d:\program files\Bejeweled 3
    2011-06-29 00:06:07 -------- d-----w- d:\documents and settings\crenshaw\application data\FrostWire
    2011-06-29 00:05:16 -------- d-----w- d:\program files\FrostWire
    2011-06-28 17:58:12 725064 ----a-w- d:\windows\system32\pwNative.exe
    2011-06-28 17:58:11 16472 ------w- d:\windows\system32\pwdrvio.sys
    2011-06-28 17:58:11 11104 ------w- d:\windows\system32\pwdspio.sys
    2011-06-28 17:46:32 -------- d-----w- d:\documents and settings\crenshaw\application data\wsInspector
    2011-06-28 17:44:42 -------- d-----w- d:\program files\Startup Inspector for Windows
    2011-06-28 17:41:30 -------- d-----w- d:\program files\ToniArts
    2011-06-28 17:41:24 172032 ----a-w- d:\program files\common files\installshield\professional\runtime\10\01\intel32\iuser.dll
    2011-06-28 17:41:23 733184 ----a-w- d:\program files\common files\installshield\professional\runtime\10\01\intel32\iKernel.dll
    2011-06-28 17:41:23 69715 ----a-w- d:\program files\common files\installshield\professional\runtime\10\01\intel32\ctor.dll
    2011-06-28 17:41:23 5632 ----a-w- d:\program files\common files\installshield\professional\runtime\10\01\intel32\DotNetInstaller.exe
    2011-06-28 17:41:23 266240 ----a-w- d:\program files\common files\installshield\professional\runtime\10\01\intel32\iscript.dll
    2011-06-28 17:41:22 303236 ----a-w- d:\program files\common files\installshield\professional\runtime\10\01\intel32\setup.dll
    2011-06-28 17:41:22 180356 ----a-w- d:\program files\common files\installshield\professional\runtime\10\01\intel32\iGdi.dll
    2011-06-28 17:30:19 -------- d-----w- d:\program files\Unlocker
    2011-06-28 15:52:50 -------- d-----w- d:\documents and settings\crenshaw\local settings\application data\AskToolbar
    2011-06-28 01:25:21 -------- d-----w- d:\program files\Ask.com
    2011-06-25 17:04:21 -------- d-----w- d:\program files\Marvell
    2011-06-25 16:33:22 -------- d-----w- d:\program files\SlimStar R610
    2011-06-25 16:23:18 -------- d-----w- d:\documents and settings\all users\application data\QMI
    2011-06-25 16:13:42 -------- d-----w- d:\documents and settings\crenshaw\local settings\application data\SlimWare Utilities Inc
    2011-06-25 16:04:14 -------- d-----w- d:\program files\common files\xing shared
    2011-06-24 08:37:09 537600 ----a-w- d:\documents and settings\all users\application data\microsoft\microsoft antimalware\localcopy\{6AD82807-D6EB-4234-AFC7-168FF4D67A7E}-CNC4.exe
    2011-06-24 08:36:37 537600 ----a-w- d:\documents and settings\all users\application data\microsoft\microsoft antimalware\localcopy\{0EE8AB05-E8BC-4265-9072-35C516558C56}-CNC4.exe
    2011-06-23 23:41:24 -------- d-----w- d:\documents and settings\crenshaw\local settings\application data\Quadriga Games
    2011-06-23 23:39:21 -------- d-----w- d:\program files\ProtectDisc Driver Installer
    2011-06-23 23:39:04 -------- d-----w- d:\documents and settings\crenshaw\application data\ProtectDISC
    2011-06-23 21:58:22 -------- d-----w- d:\windows\SxsCaPendDel
    2011-06-23 20:20:55 34304 ----a-w- d:\windows\system32\drivers\AmdLLD.sys
    2011-06-23 20:20:43 -------- d-----w- d:\documents and settings\crenshaw\local settings\application data\Downloaded Installations
    2011-06-23 20:18:12 -------- d-----w- d:\program files\AMD
    2011-06-23 20:18:11 -------- d-----w- d:\documents and settings\all users\application data\PC Drivers HeadQuarters
    2011-06-23 20:13:45 74072 ----a-w- d:\windows\system32\XAPOFX1_4.dll
    2011-06-23 20:13:45 528216 ----a-w- d:\windows\system32\XAudio2_6.dll
    2011-06-23 20:13:44 515416 ----a-w- d:\windows\system32\XAudio2_5.dll
    2011-06-23 20:13:44 238936 ----a-w- d:\windows\system32\xactengine3_6.dll
    2011-06-23 20:13:44 238936 ----a-w- d:\windows\system32\xactengine3_5.dll
    2011-06-23 20:13:44 22360 ----a-w- d:\windows\system32\X3DAudio1_7.dll
    2011-06-23 20:13:44 1974616 ----a-w- d:\windows\system32\D3DCompiler_42.dll
    2011-06-23 20:13:43 5501792 ----a-w- d:\windows\system32\d3dcsx_42.dll
    2011-06-23 20:12:25 -------- d-----w- d:\program files\common files\Wise Installation Wizard
    2011-06-23 20:03:29 -------- d-----w- d:\program files\Quadriga Games
    2011-06-23 03:49:12 -------- d-----w- d:\documents and settings\crenshaw\local settings\application data\Focus Home Interactive
    2011-06-23 03:43:26 -------- d-----w- d:\program files\Playboy - The Mansion
    2011-06-23 03:38:31 -------- d-----w- d:\program files\Focus Home Interactive
    2011-06-23 01:53:03 208896 ------w- d:\windows\system32\nvuide.exe
    2011-06-23 01:52:49 453152 ----a-w- d:\windows\system32\NVUNINST.EXE
    2011-06-23 01:46:36 36864 ----a-w- d:\windows\system32\drivers\AmdK8.sys
    2011-06-23 01:30:22 -------- d-----w- d:\program files\AMD APP
    2011-06-23 00:02:28 -------- d-----w- d:\program files\StarCraft II
    2011-06-23 00:02:28 -------- d-----w- d:\program files\common files\Blizzard Entertainment
    2011-06-23 00:02:28 -------- d-----w- d:\documents and settings\all users\application data\Blizzard Entertainment
    2011-06-22 07:12:10 1594544 ----a-w- d:\windows\WANEUninstaller.exe
    2011-06-22 06:48:01 -------- d-----w- d:\documents and settings\crenshaw\application data\Tropico 3
    2011-06-22 06:44:46 -------- d-----w- d:\program files\Kalypso
    2011-06-19 20:21:38 7074640 ----a-w- d:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
    2011-06-19 04:08:17 -------- d-----w- d:\program files\Cities In Motion
    2011-06-18 06:43:06 -------- d-----w- d:\documents and settings\crenshaw\local settings\application data\ATI
    2011-06-18 04:12:05 266240 ----a-w- d:\program files\common files\installshield\professional\runtime\09\01\intel32\iscript.dll
    2011-06-18 04:12:05 192512 ----a-w- d:\program files\common files\installshield\professional\runtime\09\01\intel32\iuser.dll
    2011-06-18 04:12:04 729088 ----a-w- d:\program files\common files\installshield\professional\runtime\09\01\intel32\iKernel.dll
    2011-06-18 04:12:04 69715 ----a-w- d:\program files\common files\installshield\professional\runtime\09\01\intel32\ctor.dll
    2011-06-18 04:12:04 5632 ----a-w- d:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
    2011-06-18 04:12:04 311428 ----a-w- d:\program files\common files\installshield\professional\runtime\09\01\intel32\setup.dll
    2011-06-18 04:12:04 188548 ----a-w- d:\program files\common files\installshield\professional\runtime\09\01\intel32\iGdi.dll
    2011-06-18 04:11:53 593920 ------w- d:\windows\system32\ati2sgag.exe
    2011-06-18 04:11:02 212992 ----a-w- d:\program files\common files\installshield\engine\6\intel 32\ILog.dll
    2011-06-18 04:09:29 -------- d-----w- d:\program files\ATI Technologies
    2011-06-18 04:09:27 -------- d-----w- d:\program files\ATI
    2011-06-18 04:08:56 -------- d-----w- D:\ATI
    2011-06-18 04:02:41 0 ----a-w- d:\windows\ativpsrm.bin
    2011-06-17 00:36:54 105472 -c----w- d:\windows\system32\dllcache\mup.sys
    .
    ==================== Find3M ====================
    .
    2011-06-25 16:03:48 499712 ----a-w- d:\windows\system32\msvcp71.dll
    2011-06-25 16:03:48 348160 ----a-w- d:\windows\system32\msvcr71.dll
    2011-06-23 01:51:31 363008 ----a-w- d:\windows\system32\idecoiins.dll
    2011-06-23 01:51:31 363008 ----a-w- d:\windows\system32\idecoi.dll
    2011-06-23 01:51:31 35840 ----a-w- d:\windows\system32\NVCOI.DLL
    2011-06-23 01:51:31 105088 ----a-w- d:\windows\system32\drivers\nvata.sys
    2011-05-25 06:44:26 59904 ----a-w- d:\windows\system32\OVDecode.dll
    2011-05-25 06:43:50 12798976 ----a-w- d:\windows\system32\amdocl.dll
    2011-05-25 04:21:44 6554624 ----a-w- d:\windows\system32\drivers\ati2mtag.sys
    2011-05-25 04:15:14 311296 ----a-w- d:\windows\system32\atiiiexx.dll
    2011-05-25 03:53:14 57344 ----a-w- d:\windows\system32\aticalrt.dll
    2011-05-25 03:53:06 53248 ----a-w- d:\windows\system32\aticalcl.dll
    2011-05-25 03:47:42 17989632 ----a-w- d:\windows\system32\atioglxx.dll
    2011-05-25 03:42:42 5922816 ----a-w- d:\windows\system32\aticaldd.dll
    2011-05-25 03:14:06 4059328 ----a-w- d:\windows\system32\ati3duag.dll
    2011-05-25 03:07:40 956160 ----a-w- d:\windows\system32\ativvamv.dll
    2011-05-25 03:05:18 503808 ----a-w- d:\windows\system32\atiok3x2.dll
    2011-05-25 02:58:28 53248 ----a-w- d:\windows\system32\drivers\ati2erec.dll
    2011-05-25 02:56:58 462848 ----a-w- d:\windows\system32\ATIDEMGX.dll
    2011-05-25 02:55:58 302592 ----a-w- d:\windows\system32\ati2dvag.dll
    2011-05-25 02:54:56 3152384 ----a-w- d:\windows\system32\ativvaxx.dll
    2011-05-25 02:39:28 212992 ----a-w- d:\windows\system32\atipdlxx.dll
    2011-05-25 02:39:16 155648 ----a-w- d:\windows\system32\Oemdspif.dll
    2011-05-25 02:39:08 26112 ----a-w- d:\windows\system32\Ati2mdxx.exe
    2011-05-25 02:39:00 43520 ----a-w- d:\windows\system32\ati2edxx.dll
    2011-05-25 02:38:52 64512 ----a-w- d:\windows\system32\atimpc32.dll
    2011-05-25 02:38:52 64512 ----a-w- d:\windows\system32\amdpcom32.dll
    2011-05-25 02:38:50 188416 ----a-w- d:\windows\system32\ati2evxx.dll
    2011-05-25 02:37:34 643072 ----a-w- d:\windows\system32\ati2evxx.exe
    2011-05-25 02:36:10 53248 ----a-w- d:\windows\system32\ATIDDC.DLL
    2011-05-25 02:34:52 151552 ----a-w- d:\windows\system32\atiapfxx.exe
    2011-05-25 02:31:28 651264 ----a-w- d:\windows\system32\atikvmag.dll
    2011-05-25 02:27:52 200704 ----a-w- d:\windows\system32\atiadlxx.dll
    2011-05-25 02:27:36 17408 ----a-w- d:\windows\system32\atitvo32.dll
    2011-05-25 02:22:34 856064 ----a-w- d:\windows\system32\ati2cqag.dll
    2011-05-21 17:07:18 252316 ----a-w- d:\windows\system32\nvdrsdb0.bin
    2011-05-21 17:07:18 1 ----a-w- d:\windows\system32\nvdrssel.bin
    2011-05-21 17:06:34 252316 ----a-w- d:\windows\system32\nvdrsdb1.bin
    2011-05-15 23:45:59 73728 ----a-w- d:\windows\system32\javacpl.cpl
    2011-05-15 23:45:58 472808 ----a-w- d:\windows\system32\deployJava1.dll
    2011-05-02 15:31:52 692736 ----a-w- d:\windows\system32\inetcomm.dll
    2011-04-29 17:25:27 151552 ----a-w- d:\windows\system32\schannel.dll
    2011-04-29 16:19:43 456320 ----a-w- d:\windows\system32\drivers\mrxsmb.sys
    2011-04-25 16:11:12 916480 ----a-w- d:\windows\system32\wininet.dll
    2011-04-25 16:11:11 43520 ------w- d:\windows\system32\licmgr10.dll
    2011-04-25 16:11:11 1469440 ------w- d:\windows\system32\inetcpl.cpl
    2011-04-25 12:01:22 385024 ------w- d:\windows\system32\html.iec
    2011-04-21 13:37:43 105472 ----a-w- d:\windows\system32\drivers\mup.sys
    2011-04-20 05:10:18 51712 ----a-w- d:\windows\system32\OpenCL.dll
    .
    ============= FINISH: 14:01:13.62 ===============
    attach
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-06-23.01)
    .
    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 4/10/2011 5:14:30 PM
    System Uptime: 7/12/2011 12:50:05 PM (2 hours ago)
    .
    Motherboard: Acer | | EM61SM/EM61PM
    Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4800+ | Socket M2 | 2511/201mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 181 GiB total, 158.269 GiB free.
    D: is FIXED (NTFS) - 191 GiB total, 86.39 GiB free.
    E: is Removable
    F: is Removable
    G: is Removable
    H: is Removable
    I: is CDROM ()
    J: is CDROM ()
    K: is CDROM ()
    L: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
    Description: PS/2 Compatible Mouse
    Device ID: ACPI\PNP0F13\3&2411E6FE&0
    Manufacturer: Microsoft
    Name: PS/2 Compatible Mouse
    PNP Device ID: ACPI\PNP0F13\3&2411E6FE&0
    Service: i8042prt
    .
    ==== System Restore Points ===================
    .
    RP128: 6/28/2011 10:35:44 AM - Removed Playboy - The Mansion
    RP129: 6/28/2011 10:35:56 AM - Removed Steam
    RP130: 6/28/2011 10:36:18 AM - Removed WolfQuest
    RP131: 6/28/2011 10:41:30 AM - Installed EasyCleaner
    RP132: 6/29/2011 11:15:27 AM - System Checkpoint
    RP133: 6/29/2011 10:06:03 PM - Removed Command & Conquer™ 4 Tiberian Twilight
    RP134: 6/30/2011 1:00:03 AM - Software Distribution Service 3.0
    RP135: 6/30/2011 7:35:05 AM - Software Distribution Service 3.0
    RP136: 7/1/2011 8:13:37 AM - Software Distribution Service 3.0
    RP137: 7/2/2011 9:43:35 AM - Software Distribution Service 3.0
    RP138: 7/3/2011 12:27:13 PM - Software Distribution Service 3.0
    RP139: 7/5/2011 12:05:00 AM - Software Distribution Service 3.0
    RP140: 7/6/2011 8:22:54 AM - Software Distribution Service 3.0
    RP141: 7/6/2011 9:19:40 PM - Installed Active@ ISO Burner
    RP142: 7/6/2011 9:19:49 PM - SPTD setup V1.62
    RP143: 7/7/2011 10:39:57 AM - Software Distribution Service 3.0
    RP144: 7/8/2011 11:39:02 AM - Software Distribution Service 3.0
    RP145: 7/10/2011 5:32:46 PM - Software Distribution Service 3.0
    RP146: 7/11/2011 6:49:06 PM - System Checkpoint
    RP147: 7/12/2011 10:20:29 AM - Software Distribution Service 3.0
    .
    ==== Installed Programs ======================
    .
    µTorrent
    Active@ ISO Burner
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Reader X (10.1.0)
    AMD APP SDK Runtime
    AMD Processor Driver
    ATI Catalyst Install Manager
    Bejeweled 3
    Catalyst Control Center
    Catalyst Control Center - Branding
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center InstallProxy
    ccc-utility
    CCC Help English
    Cities In Motion
    Cities XL 2011
    Cole2k Media - Codec Pack (Advanced) 7.9.5
    Dual-Core Optimizer
    EasyCleaner
    Emergency 2012
    EVE Online (remove only)
    Free RAR Extract Frog
    FrostWire 4.21.8
    Google Update Helper
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB981793)
    InstallIQ Updater
    Java Auto Updater
    Java DB 10.6.2.1
    Java(TM) 6 Update 25
    Java(TM) SE Development Kit 6 Update 25
    Linksys Wireless-G PCI Network Adapter with SpeedBooster
    MagicDisc 2.7.106
    Malwarebytes' Anti-Malware version 1.51.0.1200
    Marvell Miniport Driver
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 4 Client Profile
    Microsoft Antimalware
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    Microsoft Security Client
    Microsoft Security Essentials
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Motorola Driver Installation 4.2.0
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6.0 Parser (KB933579)
    NVIDIA Control Panel 267.24
    NVIDIA Drivers
    NVIDIA Graphics Driver 267.24
    NVIDIA Install Application
    NVIDIA nView 135.50
    NVIDIA nView Desktop Manager
    NVIDIA PhysX
    ProtectDisc Driver, Version 11
    RealNetworks - Microsoft Visual C++ 2008 Runtime
    RealPlayer
    Realtek High Definition Audio Driver
    RealUpgrade 1.1
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Windows Internet Explorer 8 (KB2482017)
    Security Update for Windows Internet Explorer 8 (KB2497640)
    Security Update for Windows Internet Explorer 8 (KB2510531)
    Security Update for Windows Internet Explorer 8 (KB2530548)
    Security Update for Windows Internet Explorer 8 (KB2544521)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2412687)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476490)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2479943)
    Security Update for Windows XP (KB2481109)
    Security Update for Windows XP (KB2482017)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB2485663)
    Security Update for Windows XP (KB2503658)
    Security Update for Windows XP (KB2503665)
    Security Update for Windows XP (KB2506212)
    Security Update for Windows XP (KB2506223)
    Security Update for Windows XP (KB2507618)
    Security Update for Windows XP (KB2508272)
    Security Update for Windows XP (KB2508429)
    Security Update for Windows XP (KB2509553)
    Security Update for Windows XP (KB2511455)
    Security Update for Windows XP (KB2524375)
    Security Update for Windows XP (KB2535512)
    Security Update for Windows XP (KB2536276)
    Security Update for Windows XP (KB2544893)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981349)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982381)
    Security Update for Windows XP (KB982665)
    SPORE™
    SPORE™ Galactic Adventures
    StarCraft II
    Tropico 3 1.00
    Unlocker 1.9.1
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Windows (KB971513)
    Update for Windows Internet Explorer 8 (KB2447568)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB2492386)
    Update for Windows XP (KB2541763)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971029)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    VLC media player 1.1.7
    WebFldrs XP
    Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Imaging Component
    Windows Internet Explorer 8
    Windows Management Framework Core
    Windows Media Format 11 runtime
    Windows Media Format SDK Hotfix - KB891122
    Windows Media Player 11
    Windows XP Service Pack 3
    Worms Armageddon - New Edition
    .
    ==== Event Viewer Messages From Past Week ========
    .
    7/10/2011 11:18:44 PM, error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The system cannot find the file specified.
    .
    ==== End Of File ===========================
  9. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    We do only one computer on a thread. You can't just decide to run another system through. The system you had the originsl problem with, the one you apparently sold had illegal Windows.
    Here's you problem> Notify: Antiwpa - activenexus.DLL
    Antiwpa %SYSDIR%\antiwpa.dll Illegal Windows crack> Winlogon Notify

    =======================================
    I am going to close this thread. Please start a new thread with current logs and give as description of the problem and reason malware is suspected.

    And since this is the second system, please include in the new thread the source of these different systems.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.