TechSpot

[Ref. for BSOD] Computer really slow, blue screen errors

Resolved
By Tbal45
May 16, 2012
  1. I formatted my computer a month ago, but its been acting slow. Today it started acting really slowly and as soon as I tried to get on this site to follow the instructions it started working completely slow and freezing and I had to restart it several times in order to run the malwarebytes scan.
    Then when I tried running GMER, the program and my computer froze and gave me a blue screen saying there was an error with windows. After that I tried restarting several times and going on safe mode but it still wouldn't boot normally and kept giving me the blue screen or the "last good configuration" screen.
    After trying to enter "last good configuration" or any of the other options it would freeze and then give the error "Load needed DLLs for kernal" or can't boot windows.
    I somehow got it to boot normally now but I only have the Malwarebytes log and DDS logs because I'm scared to try running GMER again.
    I don't know if this is from a virus because malwarebyte's and AVG didn't detect anything.

    Thank You


    Malwarebytes Anti-Malware 1.61.0.1400
    www.malwarebytes.org

    Database version: v2012.05.15.04

    Windows XP Service Pack 2 x86 NTFS
    Internet Explorer 6.0.2900.2180
    HP_Administrator :: ALEJANDRO [administrator]

    5/15/2012 8:16:48 PM
    mbam-log-2012-05-15 (20-16-48).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 209369
    Time elapsed: 40 minute(s), 57 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
    .
    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 6.0.2900.2180
    Run by HP_Administrator at 22:39:09 on 2012-05-15
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.465 [GMT -7:00]
    .
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\Program Files\Tablet\Pen\Pen_TouchService.exe
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Tablet\Pen\Pen_Tablet.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
    C:\Program Files\AVG\AVG2012\avgidsagent.exe
    C:\Program Files\Tablet\Pen\Pen_Tablet.exe
    C:\Program Files\AVG\AVG2012\avgnsx.exe
    C:\Program Files\AVG\AVG2012\avgemcx.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\AVG\AVG2012\avgrsx.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
    C:\Program Files\AVG\AVG2012\avgtray.exe
    C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\WINDOWS\system32\wuauclt.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
    BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - c:\program files\avg\avg2012\avgdtiex.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [D-Link D-Link DWA-125] c:\program files\d-link\dwa-125 reva\AirGCFG.exe
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
    mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\avg\avg2012\avgdtiex.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
    Notify: igfxcui - igfxsrvc.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-4-19 24896]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-1-31 31952]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-2-22 235216]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-12-23 41040]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-2-22 301248]
    R2 ANPD;ANPD Service;c:\windows\system32\ANPD.SYS [2012-4-14 29411]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\avgidsagent.exe [2012-4-30 5106744]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2012-2-14 193288]
    R2 D_Link_DWA-125;D_Link_DWA-125 Service;c:\program files\d-link\dwa-125 reva\ANIWZCSdS.exe [2012-4-14 126976]
    R2 TabletServicePen;TabletServicePen;c:\program files\tablet\pen\Pen_Tablet.exe [2012-4-15 5554552]
    R2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\tablet\pen\Pen_TouchService.exe [2012-4-15 451960]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2011-12-23 139856]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [2011-12-23 24144]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2011-12-23 17232]
    S2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;c:\program files\d-link\dwa-125 reva\ANIWConnService.exe [2012-4-14 40960]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-22 257696]
    S3 rt2870;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Drt2870.sys [2012-4-14 779136]
    S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2012-4-15 10752]
    .
    =============== Created Last 30 ================
    .
    2012-05-16 01:41:40--------d-----w-C:\e
    2012-05-16 01:41:39--------d-----w-C:\Data
    2012-05-15 18:50:18--------d-----w-c:\documents and settings\hp_administrator\local settings\application data\visi_coupon
    2012-05-09 01:03:14--------d-----w-c:\documents and settings\hp_administrator\local settings\application data\MediaMonkey
    2012-05-09 01:02:56--------d-----w-c:\documents and settings\hp_administrator\application data\MediaMonkey
    2012-05-09 01:02:45--------d-----w-c:\documents and settings\all users\application data\MediaMonkey
    2012-05-09 01:02:43--------d-----w-c:\documents and settings\hp_administrator\application data\TeraCopy
    2012-05-09 01:02:41--------d-----w-c:\program files\MediaMonkey
    2012-05-09 01:02:31--------d-----w-c:\program files\TeraCopy
    2012-05-09 00:59:03--------d-----w-c:\documents and settings\hp_administrator\local settings\application data\Adobe
    2012-05-09 00:50:03--------d-----w-c:\program files\WinDirStat
    2012-04-26 00:00:21--------d-----w-c:\documents and settings\hp_administrator\application data\Malwarebytes
    2012-04-25 23:59:58--------d-----w-c:\documents and settings\all users\application data\Malwarebytes
    2012-04-25 23:59:5722344----a-w-c:\windows\system32\drivers\mbam.sys
    2012-04-25 23:59:57--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2012-04-23 00:34:44--------d-----w-c:\windows\XSxS
    2012-04-22 23:37:0370304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-04-22 23:37:03419488----a-w-c:\windows\system32\FlashPlayerApp.exe
    2012-04-22 23:32:58--------d-----w-c:\program files\Yahoo!
    2012-04-22 10:05:30--------d-----w-c:\windows\system32\XPSViewer
    2012-04-22 10:05:0389088----a-w-c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    2012-04-22 10:04:4789088------w-c:\windows\system32\dllcache\filterpipelineprintproc.dll
    2012-04-22 10:04:47597504------w-c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
    2012-04-22 10:04:47597504------w-c:\windows\system32\dllcache\printfilterpipelinesvc.exe
    2012-04-22 10:04:47117760------w-c:\windows\system32\prntvpt.dll
    2012-04-22 10:04:46575488------w-c:\windows\system32\xpsshhdr.dll
    2012-04-22 10:04:46575488------w-c:\windows\system32\dllcache\xpsshhdr.dll
    2012-04-22 10:04:461676288------w-c:\windows\system32\xpssvcs.dll
    2012-04-22 10:04:461676288------w-c:\windows\system32\dllcache\xpssvcs.dll
    2012-04-22 10:04:45--------d-----w-C:\6e157358c889cdc1fcfa89deb68b68
    2012-04-22 10:01:21--------d-----w-c:\program files\MSXML 6.0
    2012-04-21 20:05:34--------d-----w-c:\program files\Sims2Pack Clean Installer
    2012-04-21 18:48:10--------d-----w-c:\program files\EA GAMES
    2012-04-21 18:48:09442368----a-r-c:\windows\system32\vp6vfw.dll
    2012-04-21 18:44:37--------d-----w-c:\program files\Elaborate Bytes
    2012-04-21 05:31:46--------d-----w-c:\documents and settings\hp_administrator\application data\AVG2012
    2012-04-21 05:30:42--------d--h--w-c:\documents and settings\all users\application data\Common Files
    2012-04-21 05:30:05--------d--h--w-C:\$AVG
    2012-04-21 05:30:04--------d-----w-c:\windows\system32\drivers\AVG
    2012-04-21 05:30:04--------d-----w-c:\documents and settings\all users\application data\AVG2012
    2012-04-21 05:29:33--------d-----w-c:\program files\AVG
    2012-04-21 05:19:57--------d-----w-c:\documents and settings\all users\application data\MFAData
    2012-04-21 05:13:51--------d-----w-c:\program files\uTorrent
    2012-04-21 05:13:29--------d-----w-c:\documents and settings\hp_administrator\application data\uTorrent
    2012-04-21 02:52:11159744----a-w-c:\program files\internet explorer\plugins\npqtplugin3.dll
    2012-04-21 02:52:11159744----a-w-c:\program files\internet explorer\plugins\npqtplugin2.dll
    2012-04-21 02:52:11159744----a-w-c:\program files\internet explorer\plugins\npqtplugin.dll
    2012-04-21 02:39:21--------d-----w-c:\documents and settings\hp_administrator\local settings\application data\Apple
    2012-04-19 11:50:2624896----a-w-c:\windows\system32\drivers\avgidshx.sys
    2012-04-17 07:44:305632----a-w-c:\windows\system32\ptpusb.dll
    2012-04-17 07:44:29159232----a-w-c:\windows\system32\ptpusd.dll
    2012-04-17 07:44:2915104----a-w-c:\windows\system32\drivers\usbscan.sys
    2012-04-17 07:44:2915104----a-w-c:\windows\system32\dllcache\usbscan.sys
    2012-04-16 10:04:36--------d-----w-c:\windows\ServicePackFiles
    2012-04-16 10:01:51--------d-----w-c:\program files\MSXML 4.0
    .
    ==================== Find3M ====================
    .
    2012-04-15 09:01:5973728----a-w-c:\windows\system32\javacpl.cpl
    2012-04-15 09:01:59472808----a-w-c:\windows\system32\deployJava1.dll
    2012-04-15 05:02:5648640----a-w-c:\windows\system32\ANPD64.SYS
    2012-04-15 05:02:5634008----a-w-c:\windows\system32\ANPD.VXD
    2012-04-15 05:02:56315392----a-w-c:\windows\system32\ANPDApi.dll
    2012-04-15 05:02:5629411----a-w-c:\windows\system32\ANPD.SYS
    2012-03-19 12:17:28301248----a-w-c:\windows\system32\drivers\avgtdix.sys
    2012-02-22 12:25:32235216----a-w-c:\windows\system32\drivers\avgldx86.sys
    .
    ============= FINISH: 22:40:47.09 ===============
    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-08-26.01)
    .
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume2
    Install Date: 4/14/2012 9:57:32 PM
    System Uptime: 5/15/2012 10:33:46 PM (0 hours ago)
    .
    Motherboard: ASUSTeK Computer INC. | | Goldfish3
    Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | CPU 1 | 3000/200mhz
    Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | CPU 1 | 3000/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 180 GiB total, 151.078 GiB free.
    D: is FIXED (FAT32) - 6 GiB total, 0.368 GiB free.
    E: is CDROM ()
    F: is CDROM (CDFS)
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    K: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: D-Link DWA-125 Wireless N 150 USB Adapter(rev.A2)
    Device ID: USB\VID_07D1&PID_3C16\1.0
    Manufacturer: D-Link Corporation
    Name: D-Link DWA-125 Wireless N 150 USB Adapter(rev.A2)
    PNP Device ID: USB\VID_07D1&PID_3C16\1.0
    Service: rt2870
    .
    ==== System Restore Points ===================
    .
    RP1: 4/14/2012 10:02:48 PM - Installed D-Link DWA-125
    RP2: 4/14/2012 10:19:30 PM - Configured easy Internet sign-up
    RP3: 4/14/2012 10:20:42 PM - Removed Microsoft Plus! Dancer LE
    RP4: 4/14/2012 10:20:50 PM - Removed Microsoft Plus! Digital Media Edition Installer
    RP5: 4/14/2012 10:20:58 PM - Removed Microsoft Plus! Photo Story 2 LE
    RP6: 4/14/2012 10:22:22 PM - Removed Norton Security Center
    RP7: 4/14/2012 10:23:07 PM - Configured iTunes
    RP9: 4/15/2012 1:55:29 AM - Removed Java 2 Runtime Environment, SE v1.4.2_03
    RP10: 4/15/2012 2:01:50 AM - Installed Java(TM) 6 Update 31
    RP11: 4/15/2012 3:00:19 AM - Software Distribution Service 3.0
    RP12: 4/16/2012 3:00:22 AM - Software Distribution Service 3.0
    RP13: 4/17/2012 3:00:19 AM - Software Distribution Service 3.0
    RP14: 4/18/2012 3:21:56 AM - System Checkpoint
    RP15: 4/19/2012 4:21:56 AM - System Checkpoint
    RP16: 4/20/2012 5:21:56 AM - System Checkpoint
    RP17: 4/20/2012 7:40:14 PM - Installed QuickTime
    RP18: 4/20/2012 7:50:13 PM - Removed QuickTime
    RP19: 4/20/2012 7:51:36 PM - Installed QuickTime
    RP20: 4/20/2012 10:13:02 PM - Before Utorrent
    RP21: 4/20/2012 10:29:31 PM - Installed AVG 2012
    RP22: 4/20/2012 10:29:54 PM - Installed AVG 2012
    RP23: 4/21/2012 10:57:54 PM - System Checkpoint
    RP24: 4/22/2012 3:00:20 AM - Software Distribution Service 3.0
    RP25: 4/22/2012 4:35:34 PM - Installed Windows XP KB915865.
    RP26: 4/23/2012 3:00:22 AM - Software Distribution Service 3.0
    RP27: 4/23/2012 12:29:35 PM - Software Distribution Service 3.0
    RP28: 4/24/2012 1:14:46 PM - System Checkpoint
    RP29: 4/25/2012 1:41:07 PM - System Checkpoint
    RP30: 4/26/2012 8:20:34 AM - Removed AVG 2012
    RP31: 4/27/2012 8:32:21 AM - System Checkpoint
    RP32: 4/28/2012 9:32:19 AM - System Checkpoint
    RP33: 4/29/2012 10:32:21 AM - System Checkpoint
    RP34: 4/30/2012 11:32:22 AM - System Checkpoint
    RP35: 5/1/2012 12:32:22 PM - System Checkpoint
    RP36: 5/2/2012 1:32:21 PM - System Checkpoint
    RP37: 5/3/2012 8:11:10 AM - Removed AVG 2012
    RP38: 5/4/2012 8:14:28 AM - Removed AVG 2012
    RP39: 5/5/2012 8:32:31 AM - System Checkpoint
    RP40: 5/6/2012 8:34:08 AM - System Checkpoint
    RP41: 5/7/2012 8:35:00 AM - System Checkpoint
    RP42: 5/8/2012 9:34:26 AM - System Checkpoint
    RP43: 5/9/2012 10:09:27 AM - System Checkpoint
    RP44: 5/10/2012 3:00:16 AM - Software Distribution Service 3.0
    RP45: 5/11/2012 3:09:26 AM - System Checkpoint
    RP46: 5/12/2012 4:09:27 AM - System Checkpoint
    RP47: 5/13/2012 5:09:28 AM - System Checkpoint
    RP48: 5/14/2012 6:09:28 AM - System Checkpoint
    RP49: 5/15/2012 7:09:29 AM - System Checkpoint
    RP50: 5/15/2012 9:56:32 AM - Removed AVG 2012
    .
    ==== Installed Programs ======================
    .
    µTorrent
    Adobe Acrobat - Reader 6.0.2 Update
    Adobe Flash Player 11 ActiveX
    Adobe Reader 6.0.1
    Agere Systems PCI Soft Modem
    AiO_Scan
    AiOSoftware
    Apple Application Support
    Apple Software Update
    AVG 2012
    Bamboo
    BufferChm
    CameraDrivers
    CCleaner
    CEP (Color Enable Package) v.9.2 (beta)
    Copy
    CP_AtenaShokunin1Config
    cp_dwSharkTaleAlbums1
    cp_dwSharkTaleCards1
    cp_dwShrek2Albums1
    cp_dwShrek2Cards1
    CP_PLSBusinessFlyers
    CreativeProjects
    CreativeProjectsTemplates
    CueTour
    D-Link DWA-125
    Destinations
    Director
    DocProc
    DocumentViewer
    Fax
    GIMP 2.6.11
    Google Chrome
    Help and Support Additions
    High Definition Audio Driver Package - KB835221
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB981793)
    HP Deskjet Preloaded Printer Drivers
    HP Diagnostic Assistant
    HP Image Zone 4.5.3
    HP Image Zone for Media Center PC
    HP Image Zone Plus 4.5.3
    HP Photosmart Cameras 4.0
    HP PSC & OfficeJet 4.0
    HP Software Update
    HP Tunes
    HPIZplus450
    HpSdpAppCoreApp
    InstantShare
    Intel(R) Graphics Media Accelerator Driver
    IntelliMover Data Transfer Demo
    InterVideo DiscLabel
    InterVideo WinDVD Creator
    InterVideo WinDVD Player
    Java Auto Updater
    Java(TM) 6 Update 31
    KBD
    Last.fm 1.5.4.27091
    LS_HSI
    Malwarebytes Anti-Malware version 1.61.0.1400
    MediaMonkey 4.0
    Microsoft .NET Framework 1.0 Hotfix (KB953295)
    Microsoft .NET Framework 1.0 Hotfix (KB979904)
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Office Standard Edition 2003
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Works
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6 Service Pack 2 (KB973686)
    muvee autoProducer 3.5 magicMoments - HPD
    muvee autoProducer unPlugged - HPD
    ooVoo
    PanoStandAlone
    PC-Doctor for Windows
    PhotoGallery
    Photosmart 320,370,7400,8100,8400 Series
    PrintScreen
    PS2
    PSPrinters06
    Python 2.2 pywin32 extensions (build 203)
    Python 2.2.3
    QFolder
    QuickProjects
    QuickTime
    Readme
    RealPlayer
    Scan
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB944338-v2)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB958470)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971032)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB981350)
    Security Update for Windows XP (KB982381)
    Sims2Pack Clean Installer
    SkinsHP1
    Sonic Encoders
    Sonic Express Labeler
    Sonic RecordNow!
    TeraCopy 2.27
    The Sims 2
    The Sims 2 Pets
    TrayApp
    Unload
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB925720)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update Rollup 1 for Windows XP Media Center Edition 2005 with HDTV Support (KB873369)
    Updates from HP
    VirtualCloneDrive
    Visual J# .NET Redistributable Package
    WebFldrs XP
    WebReg
    WebTablet FB Plugin
    WebTablet IE Plugin
    WebTablet Netscape Plugin
    WinDirStat 1.1.2
    Windows Imaging Component
    Windows Installer 3.1 (KB893803)
    Windows Media Player 10 Hotfix [See KB889858 for more information]
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB883667
    Windows XP Hotfix - KB885354
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB890175
    Windows XP Media Center Edition 2005 KB888316
    Windows XP Media Center Edition 2005 KB973768
    WinRAR 4.11 (32-bit)
    Yahoo! Software Update
    Yahoo! Toolbar
    .
    ==== Event Viewer Messages From Past Week ========
    .
    5/8/2012 9:08:04 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
    5/15/2012 9:55:00 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVGIDSAgent service to connect.
    5/15/2012 9:55:00 PM, error: Service Control Manager [7000] - The AVGIDSAgent service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    5/15/2012 9:39:18 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx86 Avgmfx86 ElbyCDIO Fips intelppm
    5/15/2012 9:33:36 PM, error: System Error [1003] - Error code 1000007e, parameter1 c0000005, parameter2 8054ad6f, parameter3 f79cfacc, parameter4 f79cf7c8.
    5/15/2012 8:26:15 PM, error: atapi [9] - The device, \Device\Ide\IdePort2, did not respond within the timeout period.
    5/15/2012 10:21:41 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    5/15/2012 10:21:04 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    .
    ==== End Of File ===========================
     
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Question: In the past 7 days, you have downloaded the following:

    WinDirStat is a disk usage statistics viewer and cleanup tool

    MediaMonkey is a music manager and jukebox for serious music collectors and iPod users

    TeraCopy is a software application that moves or copies computer files

    And you also have these::
    Gimp 2.6.11 ... GIMP is an acronym for GNU Image Manipulation Program
    Virtual CloneDrive is a disk image emulator. It is designed for mounting images created by the SlySoft programs CloneCD

    Media files are resource intensive. Can you relate the problems starting within the last week?
    Why did you reformat?>>> Install Date: 4/14/2012
    If you thought a reformat was going to help the system and put the same resource intensive programs back, it's only a matter of time before you slow down, them freeze again.

    How much RAM do you have installed?
    ==============================================

    I can check the system for malware- and you may have some we can remove. But it may not the the root cause of the slowdown/freeze.
    I'd like you to run Combofix- but it won't run with AVG. You will need to temporarily uninstall AVG as follows:

    Download AppRemoverand save to the desktop
    1. Double click the setup on the desktop> click Next
    2. Select “Remove Security Application”
    3. Let scan finish to determine security apps
    4. A screen like below will appear:
      [​IMG]
    5. Click on Next after choice has been made
    6. Check the AVG program you want to uninstall
    7. After uninstall shows complete, follow online prompts to Exit the program.
    Temporary AV: Use one:
    Microsoft Security Essentials
    Comodo AV
    Avast! Free Antivirus
    =============================
    Please note: If you have previously run Combofix and it's still on the system, please uninstall it. Then download the current version and do the scan: Uninstall directions, if needed
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    --------------------------------------

    • Download Combofix from HERE or HEREand save to the desktop
      • Double click combofix.exe [​IMG]& follow the prompts.
      • If prompted for Recovery Console, please allow.
      • Once installed, you should see a blue screen prompt that says:
      • Note: If Combofix was downloaded to a flash drive, the Recovery Console will not install- just bypass and go on.[/b]
      • Note: No query will be made if the Recovery Console is already on the system.
    • Close any open browsers.
    • Before you run the Combofix scan, please disable any security software you have running.
      (If you need help with this, please see HERE)
    • Click on Yes, to continue scanning for malware
    • If Combofix asks you to update the program, allow
    • When the scan completes , a report will be generated-it will open a text window. Please paste the C:\ComboFix.txt in next reply..
    Re-enable your Antivirus software.
    Note 1:Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    Note 2:If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion", restart the computer.
    Note 3:CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficultyand terminates prematurely, the connection can be manually restored by restarting your machine.
    ==========================================
    To run the Eset Online Virus Scan:
    If you use Internet Explorer:
    1. Open the ESETOnlineScan
    2. Skip to #4 to "Continue with the directions"

      If you are using a browser other than Internet Explorer
    3. Open Eset Smart Installer
      [o] Click on the esetsmartinstaller_enu.exelink and save to the desktop.
      [o] Double click on the desktop icon to run.
      [o] After successful installation of the ESET Smart Installer, the ESET Online Scanner will be launched in a new Window
    4. Continue with the directions.
    5. Check 'Yes I accept terms of use.'
    6. Click Start button
    7. Accept any security warnings from your browser.
      [​IMG]
    8. Uncheck 'Remove found threats'
    9. Check 'Scan archives/
    10. Leave remaining settings as is.
    11. Press the Start button.
    12. ESET will then download updates for itself, install itself, and begin scanning your computer. Please wait for the scan to finish.
    13. When the scan completes, press List of found threats
    14. Push Export of text file and save the file to your desktop using a unique name, such as ESETScan. Paste this log in your next reply.
    15. Push the Back button, then Finish
    NOTE: If no malware is found then no log will be produced. Let me know if this is the case.
    ===============================================
    My Guidelines: please read and follow:
    • Be patient. Malware cleaning takes time. I am also working with other members while I am helping you.
    • Read my instructions carefully. If you don't understand or have a problem, ask me. Follow the order of the tasks I give you. Order is crucial in cleaning process.
    • If you have questions, or if a program doesn't work, stop and tell me about it. Don't try to get around it yourself.
    • File sharing programs should be uninstalled or disabled during the cleaning process..
    • Observe these:
      [o] Don't follow directions given to someone else
      [o] Don't use any other cleaning programs or scans while I'm helping you.
      [o] Don't use a Registry cleaner or make any changes in the Registry.
      [o] Don't download and install new programs- except those I give you.
    Threads are closed after 5 days if there is no reply.

    ---------------------------------------------
    Please leave logs for Combofix and Eset in your next reply.
     
  3. Tbal45

    Tbal45 TS Rookie Topic Starter

    I have been noticing my computer being slow after a day or two after reformatting it, but it has gotten worse the last couple of days. and I reformatted it before because it was running really slowly.
    I have .99 GB of RAM.
    And I don't get what you mean by media files. I took out all my music files from the computer last time when I formatted it and I haven't put them back since then, the only files on my computer are pictures and documents.

    When I tried running Combofix the first time my computer gave the blue screen again, but it worked the second time I tried. Same thing with Eset. I don't get what is causing the blue screens.

    Also Eset didn't detect anything.



    ComboFix 12-05-16.02 - HP_Administrator 05/16/2012 15:03:59.2.2 - x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.695 [GMT -7:00]
    Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\data
    c:\data\default\us_sres.data
    c:\documents and settings\Administrator.ALEJANDRO.000\WINDOWS
    c:\documents and settings\Administrator.ALEJANDRO\WINDOWS
    c:\documents and settings\Administrator\WINDOWS
    c:\documents and settings\Default User\WINDOWS
    c:\documents and settings\HP_Administrator\WINDOWS
    c:\windows\system32\config\systemprofile\WINDOWS
    c:\windows\system32\ps2.bat
    c:\windows\system32\sp
    c:\windows\XSxS
    D:\Autorun.inf
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-04-16 to 2012-05-16 )))))))))))))))))))))))))))))))
    .
    .
    2012-05-16 04:38 . 2012-05-16 22:08--------d-----w-c:\documents and settings\Administrator.ALEJANDRO
    2012-05-16 01:41 . 2012-05-16 01:41--------d-----w-C:\e
    2012-05-15 18:50 . 2012-05-15 18:50--------d-----w-c:\documents and settings\HP_Administrator\Local Settings\Application Data\visi_coupon
    2012-05-09 01:03 . 2012-05-09 01:03--------d-----w-c:\documents and settings\HP_Administrator\Local Settings\Application Data\MediaMonkey
    2012-05-09 01:02 . 2012-05-09 03:56--------d-----w-c:\documents and settings\HP_Administrator\Application Data\MediaMonkey
    2012-05-09 01:02 . 2012-05-09 01:02--------d-----w-c:\documents and settings\All Users\Application Data\MediaMonkey
    2012-05-09 01:02 . 2012-05-09 01:05--------d-----w-c:\documents and settings\HP_Administrator\Application Data\TeraCopy
    2012-05-09 01:02 . 2012-05-09 01:02--------d-----w-c:\program files\MediaMonkey
    2012-05-09 01:02 . 2012-05-09 01:02--------d-----w-c:\program files\TeraCopy
    2012-05-09 00:59 . 2012-05-09 00:59--------d-----w-c:\documents and settings\HP_Administrator\Application Data\AdobeUM
    2012-05-09 00:59 . 2012-05-09 00:59--------d-----w-c:\documents and settings\HP_Administrator\Local Settings\Application Data\Adobe
    2012-05-09 00:58 . 2012-05-09 00:58--------d-----w-c:\program files\Common Files\Adobe
    2012-05-09 00:50 . 2012-05-09 00:50--------d-----w-c:\program files\WinDirStat
    2012-04-26 00:00 . 2012-04-26 00:00--------d-----w-c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
    2012-04-25 23:59 . 2012-04-25 23:59--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
    2012-04-25 23:59 . 2012-04-26 00:00--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2012-04-25 23:59 . 2012-04-04 22:5622344----a-w-c:\windows\system32\drivers\mbam.sys
    2012-04-22 23:37 . 2012-05-15 18:50--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2012-04-22 23:37 . 2012-04-22 23:38--------d-----w-c:\documents and settings\HP_Administrator\Application Data\Yahoo!
    2012-04-22 23:37 . 2012-05-15 18:5770304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-04-22 23:37 . 2012-05-15 18:57419488----a-w-c:\windows\system32\FlashPlayerApp.exe
    2012-04-22 23:36 . 2012-04-27 05:02--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo!
    2012-04-22 23:32 . 2012-04-27 05:02--------d-----w-c:\program files\Yahoo!
    2012-04-22 10:05 . 2012-04-22 10:05--------d-----w-c:\windows\system32\XPSViewer
    2012-04-22 10:01 . 2012-04-22 10:01--------d-----w-c:\program files\MSXML 6.0
    2012-04-21 18:48 . 2012-04-21 19:41--------d-----w-c:\program files\EA GAMES
    2012-04-21 18:48 . 2004-08-18 08:34442368----a-r-c:\windows\system32\vp6vfw.dll
    2012-04-21 18:44 . 2012-04-21 18:44--------d-----w-c:\program files\Elaborate Bytes
    2012-04-21 05:30 . 2012-04-21 05:30--------d--h--w-c:\documents and settings\All Users\Application Data\Common Files
    2012-04-21 05:30 . 2012-04-21 05:30--------d-----w-C:\$AVG
    2012-04-21 05:30 . 2012-05-16 22:01--------d-----w-c:\windows\system32\drivers\AVG
    2012-04-21 05:13 . 2012-04-21 05:13--------d-----w-c:\program files\uTorrent
    2012-04-21 05:13 . 2012-04-27 05:35--------d-----w-c:\documents and settings\HP_Administrator\Application Data\uTorrent
    2012-04-21 02:52 . 2012-04-21 02:52159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
    2012-04-21 02:52 . 2012-04-21 02:52159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
    2012-04-21 02:52 . 2012-04-21 02:52159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
    2012-04-21 02:51 . 2012-04-21 02:52--------d-----w-c:\program files\QuickTime
    2012-04-21 02:40 . 2012-04-21 02:51--------d-----w-c:\documents and settings\All Users\Application Data\Apple Computer
    2012-04-21 02:39 . 2012-04-21 02:39--------d-----w-c:\program files\Common Files\Apple
    2012-04-21 02:39 . 2012-04-21 02:39--------d-----w-c:\documents and settings\HP_Administrator\Local Settings\Application Data\Apple
    2012-04-21 02:39 . 2012-04-21 02:39--------d-----w-c:\program files\Apple Software Update
    2012-04-21 02:39 . 2012-04-21 02:39--------d-----w-c:\documents and settings\All Users\Application Data\Apple
    2012-04-17 07:44 . 2001-08-18 05:365632----a-w-c:\windows\system32\ptpusb.dll
    2012-04-17 07:44 . 2004-08-04 07:56159232----a-w-c:\windows\system32\ptpusd.dll
    2012-04-17 07:44 . 2004-08-04 05:5815104----a-w-c:\windows\system32\drivers\usbscan.sys
    2012-04-17 07:44 . 2004-08-04 05:5815104----a-w-c:\windows\system32\dllcache\usbscan.sys
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-04-15 09:01 . 2012-04-15 09:0273728----a-w-c:\windows\system32\javacpl.cpl
    2012-04-15 09:01 . 2012-04-15 09:02472808----a-w-c:\windows\system32\deployJava1.dll
    2012-04-15 05:02 . 2012-04-15 05:0248640----a-w-c:\windows\system32\ANPD64.SYS
    2012-04-15 05:02 . 2012-04-15 05:0234008----a-w-c:\windows\system32\ANPD.VXD
    2012-04-15 05:02 . 2012-04-15 05:02315392----a-w-c:\windows\system32\ANPDApi.dll
    2012-04-15 05:02 . 2012-04-15 05:0229411----a-w-c:\windows\system32\ANPD.SYS
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
    "D-Link D-Link DWA-125"="c:\program files\D-Link\DWA-125 revA\AirGCFG.exe" [2009-10-20 995328]
    "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
    "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
    .
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
    backup=c:\windows\pss\Updates from HP.lnkCommon Startup
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
    2004-06-29 17:0688363----a-w-c:\windows\AGRSMMSG.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    2004-10-13 23:0057344----a-w-c:\windows\ALCMTR.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
    2004-10-13 23:172742272----a-w-c:\windows\ALCWZRD.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2004-08-10 13:0015360----a-w-c:\windows\system32\ctfmon.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
    2004-08-10 18:0459392----a-w-c:\windows\ehome\ehtray.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2012-04-15 05:04116648----atw-c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
    2004-03-18 06:1061952----a-w-c:\windows\system32\Hdaudpropshortcut.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2004-12-01 17:55126976----a-w-c:\windows\system32\hkcmd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon06]
    2004-06-07 18:42659456----a-w-c:\windows\system32\hphmon06.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
    2004-06-07 18:5349152----a-w-c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
    1998-05-07 16:0452736----a-w-c:\windows\system\hpsysdrv.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
    2003-02-11 19:0261440----a-w-c:\hp\KBD\kbd.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
    2004-10-14 21:54253952----a-w-c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ooVoo.exe]
    2012-02-08 02:0122465104----a-w-c:\program files\ooVoo\ooVoo.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
    2004-10-25 21:1790112----a-w-c:\windows\system32\ps2.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
    2004-04-14 20:43233472----a-w-c:\windows\SMINST\Recguard.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\regcmdcons]
    1999-11-07 06:1127136----a-w-c:\hp\bin\cloaker.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\secondintel]
    1999-11-07 06:1127136----a-w-c:\hp\bin\cloaker.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    2004-10-13 21:0177824----a-w-c:\windows\SOUNDMAN.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2005-04-22 01:55180269----a-w-c:\program files\Common Files\Real\Update_OB\realsched.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WZCSLDR2]
    2009-10-20 01:39122880----a-w-c:\program files\D-Link\DWA-125 revA\WZCSLDR2.exe
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
    "c:\\Program Files\\ooVoo\\ooVoo.exe"=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "443:TCP"= 443:TCP:eek:oVoo TCP port 443
    "443:UDP"= 443:UDP:eek:oVoo UDP port 443
    "37674:TCP"= 37674:TCP:eek:oVoo TCP port 37674
    "37674:UDP"= 37674:UDP:eek:oVoo UDP port 37674
    "37675:UDP"= 37675:UDP:eek:oVoo UDP port 37675
    .
    R2 ANPD;ANPD Service;c:\windows\system32\ANPD.SYS [4/14/2012 10:02 PM 29411]
    R2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;c:\program files\D-Link\DWA-125 revA\ANIWConnService.exe [4/14/2012 10:02 PM 40960]
    R2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [4/15/2012 7:07 PM 5554552]
    R2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [4/15/2012 7:08 PM 451960]
    S2 D_Link_DWA-125;D_Link_DWA-125 Service;c:\program files\D-Link\DWA-125 revA\ANIWZCSdS.exe [4/14/2012 10:02 PM 126976]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/22/2012 4:37 PM 257696]
    S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [4/15/2012 7:07 PM 10752]
    .
    --- Other Services/Drivers In Memory ---
    .
    *NewlyCreated* - WS2IFSL
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-05-16 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-22 18:58]
    .
    2012-05-14 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
    .
    2012-05-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-506743443-3154843362-4232336127-1008Core.job
    - c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-15 05:04]
    .
    2012-05-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-506743443-3154843362-4232336127-1008UA.job
    - c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-15 05:04]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    IE: {{68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\AVG\AVG2012\avgdtiex.dll
    TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
    .
    - - - - ORPHANS REMOVED - - - -
    .
    MSConfigStartUp-isDeleteMe - c:\docume~1\HP_ADM~1\LOCALS~1\Temp\isDel.bat
    AddRemove-AVG - c:\program files\AVG\AVG2012\avgmfapx.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2012-05-16 15:08
    Windows 5.1.2600 Service Pack 2 NTFS
    .
    scanning hidden processes ...
    .
    scanning hidden autostart entries ...
    .
    scanning hidden files ...
    .
    scan completed successfully
    hidden files: 0
    .
    **************************************************************************
    .
    Completion time: 2012-05-16 15:10:31
    ComboFix-quarantined-files.txt 2012-05-16 22:10
    .
    Pre-Run: 162,071,457,792 bytes free
    Post-Run: 163,263,995,904 bytes free
    .
    - - End Of File - - CF53A41DDF41683F6D0288B1134BE4EB
     
  4. Tbal45

    Tbal45 TS Rookie Topic Starter

    Please help, I don't know what to do anymore. It's been more than a week and there has been no reply to this.
    In the meantime my computer completely stopped working, as in not being able to boot anymore, I tried ways to fix it but nothing works and now I just want to reformat it but that's not working either. I ran a chkdsk and it says that it found one or more unrecoverable errors, and when I format it, it goes up to around 80% and stops and gives me a blue screen error. Whenever I try to put in an xp cd or recovery cd in it gives me a "load needed DLLs for kernal" and when I try to format it it says "kernal data inpage error". I can't buy another hard drive, what can I do?
     
  5. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    I have not been well and a, running several days behind.

    What were the files like this> c:\documents and settings\Administrator\WINDOWS

    I am helping 3 people right now, all complaining of a slow compouter, all doing a reformat because it's slow. What happens when you do this is that you do not learn how to troubleshoot for a cause. There is a good chance that a RAM chip may be bad, so no matter how many reformats you do, the problem will either continue or recur.

    I am going to refer you to one of our other forums for help: Here is the link:
    Windows BSOD, Freezing, Restarting Help
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.