mom26gr8kids
Posts: 574 +0
I have Windows Vista 32 bit and despite all the complaints about Vista it hasn't given me any trouble until December. In December I tried to install several programs that I could not get to work. After contacting tech support I gave up and figured that it was just one of the disadvantages of having Vista and I set the programs aside to install on my laptop (I am waiting on a new hard drive). I had some previous problems also, I thought perhaps the display driver. I replaced the monitor in December and it has been better, but I am still having some issues with the computer, and the last couple days my Comodo has really been giving me problems, which caused me to think that I may have a virus.
Here are my issues:
1--on occasion the computer freezes up and has to be manually turned off, there have also been several occasions when I booted up (or rebooted and got a message saying that Windows needed to be repaired and I have been sent to this screen where Windows attempts to correct my issues. I also did a system restore once when Windows kept saying that it couldn't repair my computer.
2--I have been unable to download games from a site that I have used frequently (Acer Gamezone by Oberon Media). In addition all games that I have previously purchased, played and had no trouble with no longer work. If my computer hadn't been having other issues then I would have contacted them first.
3--When attempting to download new programs my Comodo will repeatedly ask me if it should allow launch.exe for whatever program I am attempting to download. The problem is it asks me that over and over and never actually downloads the program even though I click on allow. I had to turn Comodo off to even run the 8 steps.
Here are my logs, I hope that you can help.
.
2011-03-19 23:05:12 -------- d-----w- c:\users\dad\appdata\roaming\Malwarebytes
2011-03-19 23:05:00 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-19 23:05:00 -------- d-----w- c:\progra~2\Malwarebytes
2011-03-19 23:04:57 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-19 23:04:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-19 21:21:31 758784 ----a-w- c:\windows\system32\cohelper.dll
2011-03-19 21:20:49 -------- d-----w- c:\program files\LSI SoftModem
2011-03-18 15:47:57 -------- d-----w- c:\program files\iPod
2011-03-18 15:47:53 -------- d-----w- c:\program files\iTunes
2011-03-18 15:41:28 -------- d-----w- c:\program files\Bonjour
2011-03-09 19:20:01 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-03-09 19:19:58 723456 ----a-w- c:\windows\system32\sbe.dll
2011-03-09 19:19:58 605184 ----a-w- c:\windows\system32\CPFilters.dll
2011-03-09 19:19:58 190976 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-09 19:19:55 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-03-09 19:19:55 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-03-08 22:01:05 -------- d-----w- c:\program files\Application Updater
2011-03-08 22:01:04 -------- d-----w- c:\program files\common files\Spigot
2011-03-04 18:56:54 15256 ----a-w- c:\users\dad\appdata\roaming\microsoft\identitycrl\production\ppcrlconfig.dll
2011-02-18 22:36:58 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 22:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
.
==================== Find3M ====================
.
2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 ----a-w- c:\windows\system32\FntCache.dll
2011-01-08 08:47:50 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-01-04 01:47:01 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-12-31 13:57:01 2039808 ----a-w- c:\windows\system32\win32k.sys
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-12-27 21:43:41 286720 ----a-w- c:\windows\iun506.exe
2010-12-20 16:36:20 834048 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 15:37:57 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 14:55:46 389632 ----a-w- c:\windows\system32\html.iec
.
============= FINISH: 18:05:16.47 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 10/10/2006 7:16:20 PM
System Uptime: 3/19/2011 5:24:45 PM (1 hours ago)
.
Motherboard: Acer | | WMCP78M
Processor: AMD Athlon(tm) 7450 Dual-Core Processor | Socket AM2 | 2400/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 142 GiB total, 48.264 GiB free.
D: is FIXED (NTFS) - 142 GiB total, 141.567 GiB free.
E: is CDROM (CDFS)
I: is Removable
K: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1446: 3/10/2011 3:00:13 AM - Windows Update
RP1448: 3/10/2011 1:04:15 PM - Configured Microsoft Office Home and Student 2007
RP1449: 3/11/2011 8:08:47 AM - Windows Update
RP1450: 3/12/2011 3:00:13 AM - Windows Update
RP1451: 3/13/2011 4:00:12 AM - Windows Update
RP1452: 3/14/2011 3:00:11 AM - Windows Update
RP1453: 3/15/2011 3:00:13 AM - Windows Update
RP1454: 3/16/2011 3:00:11 AM - Windows Update
RP1455: 3/17/2011 9:13:25 AM - Windows Update
RP1456: 3/18/2011 9:13:02 AM - Windows Update
RP1457: 3/18/2011 9:42:13 AM - Device Driver Package Install: Apple, Inc. Universal Serial Bus controllers
RP1458: 3/19/2011 3:00:13 AM - Windows Update
RP1459: 3/19/2011 3:19:33 PM - Windows Update
.
==== Installed Programs ======================
.
2002 Games
Acer Arcade Live Main Page
Acer Assist
Acer DV Magician
Acer DVDivine
Acer eDataSecurity Management
Acer Empowering Technology
Acer eRecovery Management
Acer HomeMedia
Acer HomeMedia Connect
Acer HomeMedia Trial Creator
Acer Registration
Acer ScreenSaver
Acer SlideShow DVD
Acer VideoMagician
Acrobat.com
Adobe Acrobat 4.0
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.2
Adobe Shockwave Player 11.5
Agere Systems PCI-SV92EX Soft Modem
Alice Greenfingers
Alien Shooter
Amazon MP3 Downloader 1.0.10
Anna`s Ice Cream
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
AV Input Selection
Avenue Flo - Special Delivery
AVG 2011
Babysitting Mania
Blood Ties
Bonjour
Bookworm Adventures
Build In Time
Burger Shop
C:\Program Files\Acer GameZone\GameConsole
Cake Mania
Chicken Invaders 2
Chocolatier
Choice Guard
COMODO Internet Security
Cookie Domination
Cooking Academy
Cooking Dash
Cooking Dash Diner Town Studios
Coupon Printer for Windows
Dairy Dash
Direct Show Ogg Vorbis Filter (remove only)
Doggie Dash
Double Play Jojo’s Fashion Show 1 & 2
Dream Day First Home
Dream Day Wedding
Dream Day Wedding Married in Manhattan
eMusic Download Manager 4.1.4
EPSON TWAIN 5
Family Feud 3
Fashion Dash
Free Realms
Free Realms Installer
Galapago
Garfield's Typing Pal
Go-Go Gourmet
Go Go Gourmet Chef of the Year
Google Desktop
Google SketchUp 8
Guitar Praise
Hax264 Codec 2.1.0.8
Heroes of Hellas
Home Sweet Home
Hotel Dash Suite Success
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
igLoader
ijji REACTOR
iTunes
Java Auto Updater
Java(TM) 6 Update 23
Jessicas Cupcake Cafe
Jewelleria
Junk Mail filter update
Kelly Green Garden Queen
Kitchen Brigade
LEGO Universe
Lizard Safeguard - PDF Viewer 2.5.137
LSI PCI-SV92EX Soft Modem
Magic Farm
Magic Match Adventures
Malwarebytes' Anti-Malware
Math Missions Grades 3-5
Math Missions Grades K-2
Mavis Beacon Teaches Typing 15
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Edition 2003
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Train Simulator
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Mozilla Firefox (3.5.17)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mystery Solitaire - Secret Island
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA Stereoscopic 3D Driver
OGA Notifier 2.0.0048.0
Orchard
Passport to Perfume™
PDFCreator
pdfforge Toolbar v4.3
Picasa 3
PlayReady PC runtime
Puzzle and Board XP Championship
QuickTime
Roblox
ScanToWeb
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Media Encoder (KB2447961)
Shopmania
Spelling Dictionaries Support For Adobe Reader 9
SpywareBlaster 4.2
Sunshine Acres
SUPERAntiSpyware Free Edition
System Requirements Lab
Teach Yourself to Play Guitar 1.8.1
Timez Attack
U.B. Funkeys
Uninstall Dual Mode Camera
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Wedding Dash 2
Wedding Dash Ready Aim Love
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows Media Encoder 9 Series
Yard Sale Junkie
Year 2 year-plan
Year 3 Curriculum
Year 3 Interface
.
==== Event Viewer Messages From Past Week ========
.
3/19/2011 5:26:56 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt
3/19/2011 4:42:04 AM, Error: nvstor32 [5] - A parity error was detected on \Device\RaidPort0.
3/19/2011 3:21:08 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80246007: Windows Live Essentials 2011 (KB2434419).
3/19/2011 3:02:35 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Windows Live Sign-In Assistant (KB 967912).
3/18/2011 9:43:11 AM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/18/2011 9:41:51 AM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/18/2011 10:41:11 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
3/18/2011 10:41:11 AM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/18/2011 10:41:11 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
3/16/2011 12:16:35 AM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume ACER.
.
==== End Of File ===========================
GMER 1.0.15.15565 - http://www.gmer.net
Rootkit quick scan 2011-03-19 17:51:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000005c Hitachi_ rev.ST2O
Running: hirnpq9w.exe; Driver: C:\Users\Dad\AppData\Local\Temp\kxtdapow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\tdx \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- EOF - GMER 1.0.15 ----
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6108
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
3/19/2011 5:23:14 PM
mbam-log-2011-03-19 (17-23-14).txt
Scan type: Quick scan
Objects scanned: 155159
Time elapsed: 4 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Delete on reboot.
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AppDataLow\gvtl (Adware.GameVance) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com (Adware.GamesVance) -> Delete on reboot.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\chrome (Adware.GamesVance) -> Delete on reboot.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\components (Adware.GamesVance) -> Quarantined and deleted successfully.
Files Infected:
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Delete on reboot.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\chrome.manifest (Adware.GamesVance) -> Quarantined and deleted successfully.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\install.rdf (Adware.GamesVance) -> Quarantined and deleted successfully.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\chrome\gvtextlinks.jar (Adware.GamesVance) -> Delete on reboot.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\components\gvtlf.xpt (Adware.GamesVance) -> Quarantined and deleted successfully.
Here are my issues:
1--on occasion the computer freezes up and has to be manually turned off, there have also been several occasions when I booted up (or rebooted and got a message saying that Windows needed to be repaired and I have been sent to this screen where Windows attempts to correct my issues. I also did a system restore once when Windows kept saying that it couldn't repair my computer.
2--I have been unable to download games from a site that I have used frequently (Acer Gamezone by Oberon Media). In addition all games that I have previously purchased, played and had no trouble with no longer work. If my computer hadn't been having other issues then I would have contacted them first.
3--When attempting to download new programs my Comodo will repeatedly ask me if it should allow launch.exe for whatever program I am attempting to download. The problem is it asks me that over and over and never actually downloads the program even though I click on allow. I had to turn Comodo off to even run the 8 steps.
Here are my logs, I hope that you can help.
.
2011-03-19 23:05:12 -------- d-----w- c:\users\dad\appdata\roaming\Malwarebytes
2011-03-19 23:05:00 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-19 23:05:00 -------- d-----w- c:\progra~2\Malwarebytes
2011-03-19 23:04:57 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-19 23:04:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-19 21:21:31 758784 ----a-w- c:\windows\system32\cohelper.dll
2011-03-19 21:20:49 -------- d-----w- c:\program files\LSI SoftModem
2011-03-18 15:47:57 -------- d-----w- c:\program files\iPod
2011-03-18 15:47:53 -------- d-----w- c:\program files\iTunes
2011-03-18 15:41:28 -------- d-----w- c:\program files\Bonjour
2011-03-09 19:20:01 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-03-09 19:19:58 723456 ----a-w- c:\windows\system32\sbe.dll
2011-03-09 19:19:58 605184 ----a-w- c:\windows\system32\CPFilters.dll
2011-03-09 19:19:58 190976 ----a-w- c:\windows\system32\mpg2splt.ax
2011-03-09 19:19:55 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-03-09 19:19:55 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-03-08 22:01:05 -------- d-----w- c:\program files\Application Updater
2011-03-08 22:01:04 -------- d-----w- c:\program files\common files\Spigot
2011-03-04 18:56:54 15256 ----a-w- c:\users\dad\appdata\roaming\microsoft\identitycrl\production\ppcrlconfig.dll
2011-02-18 22:36:58 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 22:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
.
==================== Find3M ====================
.
2011-01-20 16:08:16 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 ----a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 ----a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 ----a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 ----a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:32 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24:26 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44:05 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44:03 797184 ----a-w- c:\windows\system32\FntCache.dll
2011-01-08 08:47:50 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 ----a-w- c:\windows\system32\atmfd.dll
2011-01-04 01:47:01 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-12-31 13:57:01 2039808 ----a-w- c:\windows\system32\win32k.sys
2010-12-28 15:55:03 413696 ----a-w- c:\windows\system32\odbc32.dll
2010-12-27 21:43:41 286720 ----a-w- c:\windows\iun506.exe
2010-12-20 16:36:20 834048 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 15:37:57 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-12-20 14:55:46 389632 ----a-w- c:\windows\system32\html.iec
.
============= FINISH: 18:05:16.47 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 10/10/2006 7:16:20 PM
System Uptime: 3/19/2011 5:24:45 PM (1 hours ago)
.
Motherboard: Acer | | WMCP78M
Processor: AMD Athlon(tm) 7450 Dual-Core Processor | Socket AM2 | 2400/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 142 GiB total, 48.264 GiB free.
D: is FIXED (NTFS) - 142 GiB total, 141.567 GiB free.
E: is CDROM (CDFS)
I: is Removable
K: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1446: 3/10/2011 3:00:13 AM - Windows Update
RP1448: 3/10/2011 1:04:15 PM - Configured Microsoft Office Home and Student 2007
RP1449: 3/11/2011 8:08:47 AM - Windows Update
RP1450: 3/12/2011 3:00:13 AM - Windows Update
RP1451: 3/13/2011 4:00:12 AM - Windows Update
RP1452: 3/14/2011 3:00:11 AM - Windows Update
RP1453: 3/15/2011 3:00:13 AM - Windows Update
RP1454: 3/16/2011 3:00:11 AM - Windows Update
RP1455: 3/17/2011 9:13:25 AM - Windows Update
RP1456: 3/18/2011 9:13:02 AM - Windows Update
RP1457: 3/18/2011 9:42:13 AM - Device Driver Package Install: Apple, Inc. Universal Serial Bus controllers
RP1458: 3/19/2011 3:00:13 AM - Windows Update
RP1459: 3/19/2011 3:19:33 PM - Windows Update
.
==== Installed Programs ======================
.
2002 Games
Acer Arcade Live Main Page
Acer Assist
Acer DV Magician
Acer DVDivine
Acer eDataSecurity Management
Acer Empowering Technology
Acer eRecovery Management
Acer HomeMedia
Acer HomeMedia Connect
Acer HomeMedia Trial Creator
Acer Registration
Acer ScreenSaver
Acer SlideShow DVD
Acer VideoMagician
Acrobat.com
Adobe Acrobat 4.0
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.2
Adobe Shockwave Player 11.5
Agere Systems PCI-SV92EX Soft Modem
Alice Greenfingers
Alien Shooter
Amazon MP3 Downloader 1.0.10
Anna`s Ice Cream
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
AV Input Selection
Avenue Flo - Special Delivery
AVG 2011
Babysitting Mania
Blood Ties
Bonjour
Bookworm Adventures
Build In Time
Burger Shop
C:\Program Files\Acer GameZone\GameConsole
Cake Mania
Chicken Invaders 2
Chocolatier
Choice Guard
COMODO Internet Security
Cookie Domination
Cooking Academy
Cooking Dash
Cooking Dash Diner Town Studios
Coupon Printer for Windows
Dairy Dash
Direct Show Ogg Vorbis Filter (remove only)
Doggie Dash
Double Play Jojo’s Fashion Show 1 & 2
Dream Day First Home
Dream Day Wedding
Dream Day Wedding Married in Manhattan
eMusic Download Manager 4.1.4
EPSON TWAIN 5
Family Feud 3
Fashion Dash
Free Realms
Free Realms Installer
Galapago
Garfield's Typing Pal
Go-Go Gourmet
Go Go Gourmet Chef of the Year
Google Desktop
Google SketchUp 8
Guitar Praise
Hax264 Codec 2.1.0.8
Heroes of Hellas
Home Sweet Home
Hotel Dash Suite Success
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
igLoader
ijji REACTOR
iTunes
Java Auto Updater
Java(TM) 6 Update 23
Jessicas Cupcake Cafe
Jewelleria
Junk Mail filter update
Kelly Green Garden Queen
Kitchen Brigade
LEGO Universe
Lizard Safeguard - PDF Viewer 2.5.137
LSI PCI-SV92EX Soft Modem
Magic Farm
Magic Match Adventures
Malwarebytes' Anti-Malware
Math Missions Grades 3-5
Math Missions Grades K-2
Mavis Beacon Teaches Typing 15
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Small Business Edition 2003
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Train Simulator
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Mozilla Firefox (3.5.17)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mystery Solitaire - Secret Island
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
NVIDIA Stereoscopic 3D Driver
OGA Notifier 2.0.0048.0
Orchard
Passport to Perfume™
PDFCreator
pdfforge Toolbar v4.3
Picasa 3
PlayReady PC runtime
Puzzle and Board XP Championship
QuickTime
Roblox
ScanToWeb
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2289158)
Security Update for 2007 Microsoft Office System (KB2344875)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft Office Excel 2007 (KB2345035)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office PowerPoint Viewer (KB2413381)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Media Encoder (KB2447961)
Shopmania
Spelling Dictionaries Support For Adobe Reader 9
SpywareBlaster 4.2
Sunshine Acres
SUPERAntiSpyware Free Edition
System Requirements Lab
Teach Yourself to Play Guitar 1.8.1
Timez Attack
U.B. Funkeys
Uninstall Dual Mode Camera
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Wedding Dash 2
Wedding Dash Ready Aim Love
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows Media Encoder 9 Series
Yard Sale Junkie
Year 2 year-plan
Year 3 Curriculum
Year 3 Interface
.
==== Event Viewer Messages From Past Week ========
.
3/19/2011 5:26:56 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: i8042prt
3/19/2011 4:42:04 AM, Error: nvstor32 [5] - A parity error was detected on \Device\RaidPort0.
3/19/2011 3:21:08 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80246007: Windows Live Essentials 2011 (KB2434419).
3/19/2011 3:02:35 AM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Update for Windows Live Sign-In Assistant (KB 967912).
3/18/2011 9:43:11 AM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/18/2011 9:41:51 AM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/18/2011 10:41:11 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
3/18/2011 10:41:11 AM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/18/2011 10:41:11 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
3/16/2011 12:16:35 AM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume ACER.
.
==== End Of File ===========================
GMER 1.0.15.15565 - http://www.gmer.net
Rootkit quick scan 2011-03-19 17:51:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000005c Hitachi_ rev.ST2O
Running: hirnpq9w.exe; Driver: C:\Users\Dad\AppData\Local\Temp\kxtdapow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\tdx \Device\Ip cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- EOF - GMER 1.0.15 ----
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6108
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
3/19/2011 5:23:14 PM
mbam-log-2011-03-19 (17-23-14).txt
Scan type: Quick scan
Objects scanned: 155159
Time elapsed: 4 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Delete on reboot.
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AppDataLow\gvtl (Adware.GameVance) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com (Adware.GamesVance) -> Delete on reboot.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\chrome (Adware.GamesVance) -> Delete on reboot.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\components (Adware.GamesVance) -> Quarantined and deleted successfully.
Files Infected:
c:\program files\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Delete on reboot.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\chrome.manifest (Adware.GamesVance) -> Quarantined and deleted successfully.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\install.rdf (Adware.GamesVance) -> Quarantined and deleted successfully.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\chrome\gvtextlinks.jar (Adware.GamesVance) -> Delete on reboot.
c:\Users\Dad\AppData\Roaming\Mozilla\extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@gamevance.com\components\gvtlf.xpt (Adware.GamesVance) -> Quarantined and deleted successfully.