[Ref. for BSOD] Computer really slow, blue screen errors

By Tbal45
May 16, 2012
  1. I formatted my computer a month ago, but its been acting slow. Today it started acting really slowly and as soon as I tried to get on this site to follow the instructions it started working completely slow and freezing and I had to restart it several times in order to run the malwarebytes scan.
    Then when I tried running GMER, the program and my computer froze and gave me a blue screen saying there was an error with windows. After that I tried restarting several times and going on safe mode but it still wouldn't boot normally and kept giving me the blue screen or the "last good configuration" screen.
    After trying to enter "last good configuration" or any of the other options it would freeze and then give the error "Load needed DLLs for kernal" or can't boot windows.
    I somehow got it to boot normally now but I only have the Malwarebytes log and DDS logs because I'm scared to try running GMER again.
    I don't know if this is from a virus because malwarebyte's and AVG didn't detect anything.

    Thank You

    Malwarebytes Anti-Malware

    Database version: v2012.05.15.04

    Windows XP Service Pack 2 x86 NTFS
    Internet Explorer 6.0.2900.2180
    HP_Administrator :: ALEJANDRO [administrator]

    5/15/2012 8:16:48 PM
    mbam-log-2012-05-15 (20-16-48).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 209369
    Time elapsed: 40 minute(s), 57 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    DDS (Ver_2011-08-26.01) - NTFSx86
    Internet Explorer: 6.0.2900.2180
    Run by HP_Administrator at 22:39:09 on 2012-05-15
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.465 [GMT -7:00]
    AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    ============== Running Processes ===============
    C:\WINDOWS\system32\svchost -k DcomLaunch
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\Program Files\Tablet\Pen\Pen_TouchService.exe
    C:\Program Files\AVG\AVG2012\avgwdsvc.exe
    C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe
    C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Tablet\Pen\Pen_Tablet.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
    C:\Program Files\AVG\AVG2012\avgidsagent.exe
    C:\Program Files\Tablet\Pen\Pen_Tablet.exe
    C:\Program Files\AVG\AVG2012\avgnsx.exe
    C:\Program Files\AVG\AVG2012\avgemcx.exe
    C:\Program Files\AVG\AVG2012\avgrsx.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
    C:\Program Files\AVG\AVG2012\avgtray.exe
    C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
    C:\Program Files\AVG\AVG2012\avgcsrvx.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
    ============== Pseudo HJT Report ===============
    uStart Page = hxxp://
    uSearch Page = hxxp://
    uDefault_Page_URL = hxxp://
    uDefault_Search_URL = hxxp://
    uSearch Bar = hxxp://
    mDefault_Page_URL = hxxp://
    mDefault_Search_URL = hxxp://
    mSearch Page = hxxp://
    mStart Page = hxxp://
    mSearch Bar = hxxp://
    uInternet Connection Wizard,ShellNext = hxxp://
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
    BHO: AVG Do Not Track: {31332eef-cb9f-458f-afeb-d30e9a66b6ba} - c:\program files\avg\avg2012\avgdtiex.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
    BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [D-Link D-Link DWA-125] c:\program files\d-link\dwa-125 reva\AirGCFG.exe
    mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
    mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\avg\avg2012\avgdtiex.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://
    DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
    Notify: igfxcui - igfxsrvc.dll
    ============= SERVICES / DRIVERS ===============
    R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-4-19 24896]
    R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-1-31 31952]
    R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-2-22 235216]
    R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-12-23 41040]
    R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2012-2-22 301248]
    R2 ANPD;ANPD Service;c:\windows\system32\ANPD.SYS [2012-4-14 29411]
    R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\avgidsagent.exe [2012-4-30 5106744]
    R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2012-2-14 193288]
    R2 D_Link_DWA-125;D_Link_DWA-125 Service;c:\program files\d-link\dwa-125 reva\ANIWZCSdS.exe [2012-4-14 126976]
    R2 TabletServicePen;TabletServicePen;c:\program files\tablet\pen\Pen_Tablet.exe [2012-4-15 5554552]
    R2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\tablet\pen\Pen_TouchService.exe [2012-4-15 451960]
    R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2011-12-23 139856]
    R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [2011-12-23 24144]
    R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2011-12-23 17232]
    S2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;c:\program files\d-link\dwa-125 reva\ANIWConnService.exe [2012-4-14 40960]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-22 257696]
    S3 rt2870;D-Link dnetr28u USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\Drt2870.sys [2012-4-14 779136]
    S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2012-4-15 10752]
    =============== Created Last 30 ================
    2012-05-16 01:41:40--------d-----w-C:\e
    2012-05-16 01:41:39--------d-----w-C:\Data
    2012-05-15 18:50:18--------d-----w-c:\documents and settings\hp_administrator\local settings\application data\visi_coupon
    2012-05-09 01:03:14--------d-----w-c:\documents and settings\hp_administrator\local settings\application data\MediaMonkey
    2012-05-09 01:02:56--------d-----w-c:\documents and settings\hp_administrator\application data\MediaMonkey
    2012-05-09 01:02:45--------d-----w-c:\documents and settings\all users\application data\MediaMonkey
    2012-05-09 01:02:43--------d-----w-c:\documents and settings\hp_administrator\application data\TeraCopy
    2012-05-09 01:02:41--------d-----w-c:\program files\MediaMonkey
    2012-05-09 01:02:31--------d-----w-c:\program files\TeraCopy
    2012-05-09 00:59:03--------d-----w-c:\documents and settings\hp_administrator\local settings\application data\Adobe
    2012-05-09 00:50:03--------d-----w-c:\program files\WinDirStat
    2012-04-26 00:00:21--------d-----w-c:\documents and settings\hp_administrator\application data\Malwarebytes
    2012-04-25 23:59:58--------d-----w-c:\documents and settings\all users\application data\Malwarebytes
    2012-04-25 23:59:5722344----a-w-c:\windows\system32\drivers\mbam.sys
    2012-04-25 23:59:57--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2012-04-23 00:34:44--------d-----w-c:\windows\XSxS
    2012-04-22 23:37:0370304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-04-22 23:37:03419488----a-w-c:\windows\system32\FlashPlayerApp.exe
    2012-04-22 23:32:58--------d-----w-c:\program files\Yahoo!
    2012-04-22 10:05:30--------d-----w-c:\windows\system32\XPSViewer
    2012-04-22 10:05:0389088----a-w-c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
    2012-04-22 10:04:4789088------w-c:\windows\system32\dllcache\filterpipelineprintproc.dll
    2012-04-22 10:04:47597504------w-c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
    2012-04-22 10:04:47597504------w-c:\windows\system32\dllcache\printfilterpipelinesvc.exe
    2012-04-22 10:04:47117760------w-c:\windows\system32\prntvpt.dll
    2012-04-22 10:04:46575488------w-c:\windows\system32\xpsshhdr.dll
    2012-04-22 10:04:46575488------w-c:\windows\system32\dllcache\xpsshhdr.dll
    2012-04-22 10:04:461676288------w-c:\windows\system32\xpssvcs.dll
    2012-04-22 10:04:461676288------w-c:\windows\system32\dllcache\xpssvcs.dll
    2012-04-22 10:04:45--------d-----w-C:\6e157358c889cdc1fcfa89deb68b68
    2012-04-22 10:01:21--------d-----w-c:\program files\MSXML 6.0
    2012-04-21 20:05:34--------d-----w-c:\program files\Sims2Pack Clean Installer
    2012-04-21 18:48:10--------d-----w-c:\program files\EA GAMES
    2012-04-21 18:48:09442368----a-r-c:\windows\system32\vp6vfw.dll
    2012-04-21 18:44:37--------d-----w-c:\program files\Elaborate Bytes
    2012-04-21 05:31:46--------d-----w-c:\documents and settings\hp_administrator\application data\AVG2012
    2012-04-21 05:30:42--------d--h--w-c:\documents and settings\all users\application data\Common Files
    2012-04-21 05:30:05--------d--h--w-C:\$AVG
    2012-04-21 05:30:04--------d-----w-c:\windows\system32\drivers\AVG
    2012-04-21 05:30:04--------d-----w-c:\documents and settings\all users\application data\AVG2012
    2012-04-21 05:29:33--------d-----w-c:\program files\AVG
    2012-04-21 05:19:57--------d-----w-c:\documents and settings\all users\application data\MFAData
    2012-04-21 05:13:51--------d-----w-c:\program files\uTorrent
    2012-04-21 05:13:29--------d-----w-c:\documents and settings\hp_administrator\application data\uTorrent
    2012-04-21 02:52:11159744----a-w-c:\program files\internet explorer\plugins\npqtplugin3.dll
    2012-04-21 02:52:11159744----a-w-c:\program files\internet explorer\plugins\npqtplugin2.dll
    2012-04-21 02:52:11159744----a-w-c:\program files\internet explorer\plugins\npqtplugin.dll
    2012-04-21 02:39:21--------d-----w-c:\documents and settings\hp_administrator\local settings\application data\Apple
    2012-04-19 11:50:2624896----a-w-c:\windows\system32\drivers\avgidshx.sys
    2012-04-17 07:44:305632----a-w-c:\windows\system32\ptpusb.dll
    2012-04-17 07:44:29159232----a-w-c:\windows\system32\ptpusd.dll
    2012-04-17 07:44:2915104----a-w-c:\windows\system32\drivers\usbscan.sys
    2012-04-17 07:44:2915104----a-w-c:\windows\system32\dllcache\usbscan.sys
    2012-04-16 10:04:36--------d-----w-c:\windows\ServicePackFiles
    2012-04-16 10:01:51--------d-----w-c:\program files\MSXML 4.0
    ==================== Find3M ====================
    2012-04-15 09:01:5973728----a-w-c:\windows\system32\javacpl.cpl
    2012-04-15 09:01:59472808----a-w-c:\windows\system32\deployJava1.dll
    2012-04-15 05:02:5648640----a-w-c:\windows\system32\ANPD64.SYS
    2012-04-15 05:02:5634008----a-w-c:\windows\system32\ANPD.VXD
    2012-04-15 05:02:56315392----a-w-c:\windows\system32\ANPDApi.dll
    2012-04-15 05:02:5629411----a-w-c:\windows\system32\ANPD.SYS
    2012-03-19 12:17:28301248----a-w-c:\windows\system32\drivers\avgtdix.sys
    2012-02-22 12:25:32235216----a-w-c:\windows\system32\drivers\avgldx86.sys
    ============= FINISH: 22:40:47.09 ===============
    DDS (Ver_2011-08-26.01)
    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume2
    Install Date: 4/14/2012 9:57:32 PM
    System Uptime: 5/15/2012 10:33:46 PM (0 hours ago)
    Motherboard: ASUSTeK Computer INC. | | Goldfish3
    Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | CPU 1 | 3000/200mhz
    Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | CPU 1 | 3000/200mhz
    ==== Disk Partitions =========================
    C: is FIXED (NTFS) - 180 GiB total, 151.078 GiB free.
    D: is FIXED (FAT32) - 6 GiB total, 0.368 GiB free.
    E: is CDROM ()
    F: is CDROM (CDFS)
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    K: is CDROM ()
    ==== Disabled Device Manager Items =============
    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: D-Link DWA-125 Wireless N 150 USB Adapter(rev.A2)
    Device ID: USB\VID_07D1&PID_3C16\1.0
    Manufacturer: D-Link Corporation
    Name: D-Link DWA-125 Wireless N 150 USB Adapter(rev.A2)
    PNP Device ID: USB\VID_07D1&PID_3C16\1.0
    Service: rt2870
    ==== System Restore Points ===================
    RP1: 4/14/2012 10:02:48 PM - Installed D-Link DWA-125
    RP2: 4/14/2012 10:19:30 PM - Configured easy Internet sign-up
    RP3: 4/14/2012 10:20:42 PM - Removed Microsoft Plus! Dancer LE
    RP4: 4/14/2012 10:20:50 PM - Removed Microsoft Plus! Digital Media Edition Installer
    RP5: 4/14/2012 10:20:58 PM - Removed Microsoft Plus! Photo Story 2 LE
    RP6: 4/14/2012 10:22:22 PM - Removed Norton Security Center
    RP7: 4/14/2012 10:23:07 PM - Configured iTunes
    RP9: 4/15/2012 1:55:29 AM - Removed Java 2 Runtime Environment, SE v1.4.2_03
    RP10: 4/15/2012 2:01:50 AM - Installed Java(TM) 6 Update 31
    RP11: 4/15/2012 3:00:19 AM - Software Distribution Service 3.0
    RP12: 4/16/2012 3:00:22 AM - Software Distribution Service 3.0
    RP13: 4/17/2012 3:00:19 AM - Software Distribution Service 3.0
    RP14: 4/18/2012 3:21:56 AM - System Checkpoint
    RP15: 4/19/2012 4:21:56 AM - System Checkpoint
    RP16: 4/20/2012 5:21:56 AM - System Checkpoint
    RP17: 4/20/2012 7:40:14 PM - Installed QuickTime
    RP18: 4/20/2012 7:50:13 PM - Removed QuickTime
    RP19: 4/20/2012 7:51:36 PM - Installed QuickTime
    RP20: 4/20/2012 10:13:02 PM - Before Utorrent
    RP21: 4/20/2012 10:29:31 PM - Installed AVG 2012
    RP22: 4/20/2012 10:29:54 PM - Installed AVG 2012
    RP23: 4/21/2012 10:57:54 PM - System Checkpoint
    RP24: 4/22/2012 3:00:20 AM - Software Distribution Service 3.0
    RP25: 4/22/2012 4:35:34 PM - Installed Windows XP KB915865.
    RP26: 4/23/2012 3:00:22 AM - Software Distribution Service 3.0
    RP27: 4/23/2012 12:29:35 PM - Software Distribution Service 3.0
    RP28: 4/24/2012 1:14:46 PM - System Checkpoint
    RP29: 4/25/2012 1:41:07 PM - System Checkpoint
    RP30: 4/26/2012 8:20:34 AM - Removed AVG 2012
    RP31: 4/27/2012 8:32:21 AM - System Checkpoint
    RP32: 4/28/2012 9:32:19 AM - System Checkpoint
    RP33: 4/29/2012 10:32:21 AM - System Checkpoint
    RP34: 4/30/2012 11:32:22 AM - System Checkpoint
    RP35: 5/1/2012 12:32:22 PM - System Checkpoint
    RP36: 5/2/2012 1:32:21 PM - System Checkpoint
    RP37: 5/3/2012 8:11:10 AM - Removed AVG 2012
    RP38: 5/4/2012 8:14:28 AM - Removed AVG 2012
    RP39: 5/5/2012 8:32:31 AM - System Checkpoint
    RP40: 5/6/2012 8:34:08 AM - System Checkpoint
    RP41: 5/7/2012 8:35:00 AM - System Checkpoint
    RP42: 5/8/2012 9:34:26 AM - System Checkpoint
    RP43: 5/9/2012 10:09:27 AM - System Checkpoint
    RP44: 5/10/2012 3:00:16 AM - Software Distribution Service 3.0
    RP45: 5/11/2012 3:09:26 AM - System Checkpoint
    RP46: 5/12/2012 4:09:27 AM - System Checkpoint
    RP47: 5/13/2012 5:09:28 AM - System Checkpoint
    RP48: 5/14/2012 6:09:28 AM - System Checkpoint
    RP49: 5/15/2012 7:09:29 AM - System Checkpoint
    RP50: 5/15/2012 9:56:32 AM - Removed AVG 2012
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Question: In the past 7 days, you have downloaded the following:

    WinDirStat is a disk usage statistics viewer and cleanup tool

    MediaMonkey is a music manager and jukebox for serious music collectors and iPod users

    TeraCopy is a software application that moves or copies computer files

    And you also have these::
    Gimp 2.6.11 ... GIMP is an acronym for GNU Image Manipulation Program
    Virtual CloneDrive is a disk image emulator. It is designed for mounting images created by the SlySoft programs CloneCD

    Media files are resource intensive. Can you relate the problems starting within the last week?
    Why did you reformat?>>> Install Date: 4/14/2012
    If you thought a reformat was going to help the system and put the same resource intensive programs back, it's only a matter of time before you slow down, them freeze again.

    How much RAM do you have installed?

    I can check the system for malware- and you may have some we can remove. But it may not the the root cause of the slowdown/freeze.
    I'd like you to run Combofix- but it won't run with AVG. You will need to temporarily uninstall AVG as follows:

    Download AppRemoverand save to the desktop
    1. Double click the setup on the desktop> click Next
    2. Select “Remove Security Application”
    3. Let scan finish to determine security apps
    4. A screen like below will appear:
    5. Click on Next after choice has been made
    6. Check the AVG program you want to uninstall
    7. After uninstall shows complete, follow online prompts to Exit the program.
    Temporary AV: Use one:
    Microsoft Security Essentials
    Comodo AV
    Avast! Free Antivirus
    Please note: If you have previously run Combofix and it's still on the system, please uninstall it. Then download the current version and do the scan: Uninstall directions, if needed
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • Download Combofix from HERE or HEREand save to the desktop
      • Double click combofix.exe [​IMG]& follow the prompts.
      • If prompted for Recovery Console, please allow.
      • Once installed, you should see a blue screen prompt that says:
      • Note: If Combofix was downloaded to a flash drive, the Recovery Console will not install- just bypass and go on.[/b]
      • Note: No query will be made if the Recovery Console is already on the system.
    • Close any open browsers.
    • Before you run the Combofix scan, please disable any security software you have running.
      (If you need help with this, please see HERE)
    • Click on Yes, to continue scanning for malware
    • If Combofix asks you to update the program, allow
    • When the scan completes , a report will be generated-it will open a text window. Please paste the C:\ComboFix.txt in next reply..
    Re-enable your Antivirus software.
    Note 1:Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    Note 2:If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion", restart the computer.
    Note 3:CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficultyand terminates prematurely, the connection can be manually restored by restarting your machine.
    To run the Eset Online Virus Scan:
    If you use Internet Explorer:
    1. Open the ESETOnlineScan
    2. Skip to #4 to "Continue with the directions"

      If you are using a browser other than Internet Explorer
    3. Open Eset Smart Installer
      [o] Click on the esetsmartinstaller_enu.exelink and save to the desktop.
      [o] Double click on the desktop icon to run.
      [o] After successful installation of the ESET Smart Installer, the ESET Online Scanner will be launched in a new Window
    4. Continue with the directions.
    5. Check 'Yes I accept terms of use.'
    6. Click Start button
    7. Accept any security warnings from your browser.
    8. Uncheck 'Remove found threats'
    9. Check 'Scan archives/
    10. Leave remaining settings as is.
    11. Press the Start button.
    12. ESET will then download updates for itself, install itself, and begin scanning your computer. Please wait for the scan to finish.
    13. When the scan completes, press List of found threats
    14. Push Export of text file and save the file to your desktop using a unique name, such as ESETScan. Paste this log in your next reply.
    15. Push the Back button, then Finish
    NOTE: If no malware is found then no log will be produced. Let me know if this is the case.
    My Guidelines: please read and follow:
    • Be patient. Malware cleaning takes time. I am also working with other members while I am helping you.
    • Read my instructions carefully. If you don't understand or have a problem, ask me. Follow the order of the tasks I give you. Order is crucial in cleaning process.
    • If you have questions, or if a program doesn't work, stop and tell me about it. Don't try to get around it yourself.
    • File sharing programs should be uninstalled or disabled during the cleaning process..
    • Observe these:
      [o] Don't follow directions given to someone else
      [o] Don't use any other cleaning programs or scans while I'm helping you.
      [o] Don't use a Registry cleaner or make any changes in the Registry.
      [o] Don't download and install new programs- except those I give you.
    Threads are closed after 5 days if there is no reply.

    Please leave logs for Combofix and Eset in your next reply.
  3. Tbal45

    Tbal45 Newcomer, in training Topic Starter

    I have been noticing my computer being slow after a day or two after reformatting it, but it has gotten worse the last couple of days. and I reformatted it before because it was running really slowly.
    I have .99 GB of RAM.
    And I don't get what you mean by media files. I took out all my music files from the computer last time when I formatted it and I haven't put them back since then, the only files on my computer are pictures and documents.

    When I tried running Combofix the first time my computer gave the blue screen again, but it worked the second time I tried. Same thing with Eset. I don't get what is causing the blue screens.

    Also Eset didn't detect anything.

    ComboFix 12-05-16.02 - HP_Administrator 05/16/2012 15:03:59.2.2 - x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.695 [GMT -7:00]
    Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    c:\documents and settings\Administrator.ALEJANDRO.000\WINDOWS
    c:\documents and settings\Administrator.ALEJANDRO\WINDOWS
    c:\documents and settings\Administrator\WINDOWS
    c:\documents and settings\Default User\WINDOWS
    c:\documents and settings\HP_Administrator\WINDOWS
    ((((((((((((((((((((((((( Files Created from 2012-04-16 to 2012-05-16 )))))))))))))))))))))))))))))))
    2012-05-16 04:38 . 2012-05-16 22:08--------d-----w-c:\documents and settings\Administrator.ALEJANDRO
    2012-05-16 01:41 . 2012-05-16 01:41--------d-----w-C:\e
    2012-05-15 18:50 . 2012-05-15 18:50--------d-----w-c:\documents and settings\HP_Administrator\Local Settings\Application Data\visi_coupon
    2012-05-09 01:03 . 2012-05-09 01:03--------d-----w-c:\documents and settings\HP_Administrator\Local Settings\Application Data\MediaMonkey
    2012-05-09 01:02 . 2012-05-09 03:56--------d-----w-c:\documents and settings\HP_Administrator\Application Data\MediaMonkey
    2012-05-09 01:02 . 2012-05-09 01:02--------d-----w-c:\documents and settings\All Users\Application Data\MediaMonkey
    2012-05-09 01:02 . 2012-05-09 01:05--------d-----w-c:\documents and settings\HP_Administrator\Application Data\TeraCopy
    2012-05-09 01:02 . 2012-05-09 01:02--------d-----w-c:\program files\MediaMonkey
    2012-05-09 01:02 . 2012-05-09 01:02--------d-----w-c:\program files\TeraCopy
    2012-05-09 00:59 . 2012-05-09 00:59--------d-----w-c:\documents and settings\HP_Administrator\Application Data\AdobeUM
    2012-05-09 00:59 . 2012-05-09 00:59--------d-----w-c:\documents and settings\HP_Administrator\Local Settings\Application Data\Adobe
    2012-05-09 00:58 . 2012-05-09 00:58--------d-----w-c:\program files\Common Files\Adobe
    2012-05-09 00:50 . 2012-05-09 00:50--------d-----w-c:\program files\WinDirStat
    2012-04-26 00:00 . 2012-04-26 00:00--------d-----w-c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
    2012-04-25 23:59 . 2012-04-25 23:59--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
    2012-04-25 23:59 . 2012-04-26 00:00--------d-----w-c:\program files\Malwarebytes' Anti-Malware
    2012-04-25 23:59 . 2012-04-04 22:5622344----a-w-c:\windows\system32\drivers\mbam.sys
    2012-04-22 23:37 . 2012-05-15 18:50--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2012-04-22 23:37 . 2012-04-22 23:38--------d-----w-c:\documents and settings\HP_Administrator\Application Data\Yahoo!
    2012-04-22 23:37 . 2012-05-15 18:5770304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl
    2012-04-22 23:37 . 2012-05-15 18:57419488----a-w-c:\windows\system32\FlashPlayerApp.exe
    2012-04-22 23:36 . 2012-04-27 05:02--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo!
    2012-04-22 23:32 . 2012-04-27 05:02--------d-----w-c:\program files\Yahoo!
    2012-04-22 10:05 . 2012-04-22 10:05--------d-----w-c:\windows\system32\XPSViewer
    2012-04-22 10:01 . 2012-04-22 10:01--------d-----w-c:\program files\MSXML 6.0
    2012-04-21 18:48 . 2012-04-21 19:41--------d-----w-c:\program files\EA GAMES
    2012-04-21 18:48 . 2004-08-18 08:34442368----a-r-c:\windows\system32\vp6vfw.dll
    2012-04-21 18:44 . 2012-04-21 18:44--------d-----w-c:\program files\Elaborate Bytes
    2012-04-21 05:30 . 2012-04-21 05:30--------d--h--w-c:\documents and settings\All Users\Application Data\Common Files
    2012-04-21 05:30 . 2012-04-21 05:30--------d-----w-C:\$AVG
    2012-04-21 05:30 . 2012-05-16 22:01--------d-----w-c:\windows\system32\drivers\AVG
    2012-04-21 05:13 . 2012-04-21 05:13--------d-----w-c:\program files\uTorrent
    2012-04-21 05:13 . 2012-04-27 05:35--------d-----w-c:\documents and settings\HP_Administrator\Application Data\uTorrent
    2012-04-21 02:52 . 2012-04-21 02:52159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
    2012-04-21 02:52 . 2012-04-21 02:52159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
    2012-04-21 02:52 . 2012-04-21 02:52159744----a-w-c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
    2012-04-21 02:51 . 2012-04-21 02:52--------d-----w-c:\program files\QuickTime
    2012-04-21 02:40 . 2012-04-21 02:51--------d-----w-c:\documents and settings\All Users\Application Data\Apple Computer
    2012-04-21 02:39 . 2012-04-21 02:39--------d-----w-c:\program files\Common Files\Apple
    2012-04-21 02:39 . 2012-04-21 02:39--------d-----w-c:\documents and settings\HP_Administrator\Local Settings\Application Data\Apple
    2012-04-21 02:39 . 2012-04-21 02:39--------d-----w-c:\program files\Apple Software Update
    2012-04-21 02:39 . 2012-04-21 02:39--------d-----w-c:\documents and settings\All Users\Application Data\Apple
    2012-04-17 07:44 . 2001-08-18 05:365632----a-w-c:\windows\system32\ptpusb.dll
    2012-04-17 07:44 . 2004-08-04 07:56159232----a-w-c:\windows\system32\ptpusd.dll
    2012-04-17 07:44 . 2004-08-04 05:5815104----a-w-c:\windows\system32\drivers\usbscan.sys
    2012-04-17 07:44 . 2004-08-04 05:5815104----a-w-c:\windows\system32\dllcache\usbscan.sys
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    2012-04-15 09:01 . 2012-04-15 09:0273728----a-w-c:\windows\system32\javacpl.cpl
    2012-04-15 09:01 . 2012-04-15 09:02472808----a-w-c:\windows\system32\deployJava1.dll
    2012-04-15 05:02 . 2012-04-15 05:0248640----a-w-c:\windows\system32\ANPD64.SYS
    2012-04-15 05:02 . 2012-04-15 05:0234008----a-w-c:\windows\system32\ANPD.VXD
    2012-04-15 05:02 . 2012-04-15 05:02315392----a-w-c:\windows\system32\ANPDApi.dll
    2012-04-15 05:02 . 2012-04-15 05:0229411----a-w-c:\windows\system32\ANPD.SYS
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    *Note* empty entries & legit default entries are not shown
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
    "D-Link D-Link DWA-125"="c:\program files\D-Link\DWA-125 revA\AirGCFG.exe" [2009-10-20 995328]
    "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
    "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
    backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
    backup=c:\windows\pss\Updates from HP.lnkCommon Startup
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
    2004-06-29 17:0688363----a-w-c:\windows\AGRSMMSG.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    2004-10-13 23:0057344----a-w-c:\windows\ALCMTR.EXE
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
    2004-10-13 23:172742272----a-w-c:\windows\ALCWZRD.EXE
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    2004-08-10 13:0015360----a-w-c:\windows\system32\ctfmon.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
    2004-08-10 18:0459392----a-w-c:\windows\ehome\ehtray.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
    2012-04-15 05:04116648----atw-c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
    2004-03-18 06:1061952----a-w-c:\windows\system32\Hdaudpropshortcut.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
    2004-12-01 17:55126976----a-w-c:\windows\system32\hkcmd.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon06]
    2004-06-07 18:42659456----a-w-c:\windows\system32\hphmon06.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
    2004-06-07 18:5349152----a-w-c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
    1998-05-07 16:0452736----a-w-c:\windows\system\hpsysdrv.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
    2003-02-11 19:0261440----a-w-c:\hp\KBD\kbd.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LSBWatcher]
    2004-10-14 21:54253952----a-w-c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ooVoo.exe]
    2012-02-08 02:0122465104----a-w-c:\program files\ooVoo\ooVoo.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
    2004-10-25 21:1790112----a-w-c:\windows\system32\ps2.EXE
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
    2004-04-14 20:43233472----a-w-c:\windows\SMINST\Recguard.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\regcmdcons]
    1999-11-07 06:1127136----a-w-c:\hp\bin\cloaker.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\secondintel]
    1999-11-07 06:1127136----a-w-c:\hp\bin\cloaker.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    2004-10-13 21:0177824----a-w-c:\windows\SOUNDMAN.EXE
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2005-04-22 01:55180269----a-w-c:\program files\Common Files\Real\Update_OB\realsched.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WZCSLDR2]
    2009-10-20 01:39122880----a-w-c:\program files\D-Link\DWA-125 revA\WZCSLDR2.exe
    "EnableFirewall"= 0 (0x0)
    "c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
    "c:\\Program Files\\ooVoo\\ooVoo.exe"=
    "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "443:TCP"= 443:TCP:eek:oVoo TCP port 443
    "443:UDP"= 443:UDP:eek:oVoo UDP port 443
    "37674:TCP"= 37674:TCP:eek:oVoo TCP port 37674
    "37674:UDP"= 37674:UDP:eek:oVoo UDP port 37674
    "37675:UDP"= 37675:UDP:eek:oVoo UDP port 37675
    R2 ANPD;ANPD Service;c:\windows\system32\ANPD.SYS [4/14/2012 10:02 PM 29411]
    R2 D_Link_DWA-125_WPS;D_Link_DWA-125_WPS Service;c:\program files\D-Link\DWA-125 revA\ANIWConnService.exe [4/14/2012 10:02 PM 40960]
    R2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [4/15/2012 7:07 PM 5554552]
    R2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [4/15/2012 7:08 PM 451960]
    S2 D_Link_DWA-125;D_Link_DWA-125 Service;c:\program files\D-Link\DWA-125 revA\ANIWZCSdS.exe [4/14/2012 10:02 PM 126976]
    S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/22/2012 4:37 PM 257696]
    S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [4/15/2012 7:07 PM 10752]
    --- Other Services/Drivers In Memory ---
    *NewlyCreated* - WS2IFSL
    Contents of the 'Scheduled Tasks' folder
    2012-05-16 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-22 18:58]
    2012-05-14 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
    2012-05-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-506743443-3154843362-4232336127-1008Core.job
    - c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-15 05:04]
    2012-05-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-506743443-3154843362-4232336127-1008UA.job
    - c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-04-15 05:04]
    ------- Supplementary Scan -------
    uStart Page = hxxp://
    uDefault_Search_URL = hxxp://
    mStart Page = hxxp://
    mSearch Bar = hxxp://
    uInternet Connection Wizard,ShellNext = hxxp://
    IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    IE: {{68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - c:\program files\AVG\AVG2012\avgdtiex.dll
    TCP: DhcpNameServer =
    - - - - ORPHANS REMOVED - - - -
    MSConfigStartUp-isDeleteMe - c:\docume~1\HP_ADM~1\LOCALS~1\Temp\isDel.bat
    AddRemove-AVG - c:\program files\AVG\AVG2012\avgmfapx.exe
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
    Rootkit scan 2012-05-16 15:08
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    Completion time: 2012-05-16 15:10:31
    ComboFix-quarantined-files.txt 2012-05-16 22:10
    Pre-Run: 162,071,457,792 bytes free
    Post-Run: 163,263,995,904 bytes free
    - - End Of File - - CF53A41DDF41683F6D0288B1134BE4EB
  4. Tbal45

    Tbal45 Newcomer, in training Topic Starter

    Please help, I don't know what to do anymore. It's been more than a week and there has been no reply to this.
    In the meantime my computer completely stopped working, as in not being able to boot anymore, I tried ways to fix it but nothing works and now I just want to reformat it but that's not working either. I ran a chkdsk and it says that it found one or more unrecoverable errors, and when I format it, it goes up to around 80% and stops and gives me a blue screen error. Whenever I try to put in an xp cd or recovery cd in it gives me a "load needed DLLs for kernal" and when I try to format it it says "kernal data inpage error". I can't buy another hard drive, what can I do?
  5. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    I have not been well and a, running several days behind.

    What were the files like this> c:\documents and settings\Administrator\WINDOWS

    I am helping 3 people right now, all complaining of a slow compouter, all doing a reformat because it's slow. What happens when you do this is that you do not learn how to troubleshoot for a cause. There is a good chance that a RAM chip may be bad, so no matter how many reformats you do, the problem will either continue or recur.

    I am going to refer you to one of our other forums for help: Here is the link:
    Windows BSOD, Freezing, Restarting Help
