HI loyal community,
So i've been having some recent issues with my computer lately and i want to get this system runnning to its fullest potential.
Everytime i open google.com and run a seach on the search engine, i always get a black screen and i get no results. Its like the webpage freezes. Also when i try opening a website like www.google.com/maps or www.google.com/finance i get this
"404 Not Found
--------------------------------------------------------------------------------
nginx/1.2.0
eae00bb3-d172-439f-a81c-6c3c7ba87ea1
Y2:eae00bb3-d172-439f-a81c-6c3c7ba87ea1
"
Here is my DDS REPORT
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.5.1
Run by Joe at 15:52:56 on 2012-08-25
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.1599 [GMT -4:00]
.
AV: AVG Anti-Virus 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Palm, Inc\novacomd\x86\novacomd.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Joe\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\Joe\Local Settings\Application Data\Google\Update\1.3.21.115\GoogleCrashHandler.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\All Users\Application Data\WeCareReminder\ReminderHelper.exe
c:\Program Files\Microsoft Silverlight\5.1.10411.0\agcp.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - c:\program files\startnow toolbar\Toolbar32.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: WeCareReminder Class: {d824f0de-3d60-4f57-9eb1-66033ecd8abb} - c:\documents and settings\all users\application data\wecarereminder\IEHelperv2.5.0.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers runtime\YontooIEClient.dll
TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - c:\program files\startnow toolbar\Toolbar32.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\joe\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [StartNowToolbarHelper] "c:\program files\startnow toolbar\ToolbarHelper.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\joe\startm~1\programs\startup\erunta~1.lnk - c:\documents and settings\joe\desktop\help\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1320210431218
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1320215336734
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 167.206.251.129 167.206.251.130
TCP: Interfaces\{13DC235B-8EBF-4AFA-B4FD-6A3FF757B880} : DhcpNameServer = 167.206.251.129 167.206.251.130
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R2 NovacomD;Palm Novacom;c:\program files\palm, inc\novacomd\x86\novacomd.exe [2011-3-15 61440]
R2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;c:\program files\startnow toolbar\ToolbarUpdaterService.exe [2011-7-27 267488]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-11-2 136176]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2012-1-3 30312]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-11-2 136176]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2012-1-3 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2012-1-3 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2012-1-3 121576]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-08-23 14:09:15 -------- d-sh--w- C:\found.000
2012-08-17 21:24:19 -------- d-----w- c:\documents and settings\joe\local settings\application data\Deployment
2012-08-08 00:21:54 -------- d-----w- c:\documents and settings\joe\local settings\application data\Sun
2012-08-08 00:20:45 -------- d-----w- c:\program files\Oracle
2012-08-08 00:20:28 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-08 00:12:01 -------- d-----w- c:\program files\Citrix
2012-08-08 00:11:42 60304 ----a-w- c:\documents and settings\joe\g2mdlhlpx.exe
2012-07-31 17:47:28 -------- d-----w- c:\documents and settings\joe\WER6262.dir00
2012-07-31 17:46:58 -------- d-----w- c:\documents and settings\joe\WERf5bd.dir00
2012-07-31 17:46:48 -------- d-----w- c:\documents and settings\joe\WER9374.dir00
2012-07-31 17:46:45 -------- d-----w- c:\documents and settings\joe\WERb4fd.dir00
2012-07-27 20:51:30 184248 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2012-07-27 13:24:05 -------- d-----w- c:\documents and settings\joe\.swt
.
==================== Find3M ====================
.
2012-07-06 02:07:08 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-06-13 13:19:59 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50:25 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50:25 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32:08 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19:34 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:18:58 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18:58 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18:58 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22:09 599040 ----a-w- c:\windows\system32\crypt32.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD3200AAKS-75B3A0 rev.01.03A01 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A1D72E2
user & kernel MBR OK
.
============= FINISH: 16:00:14.87 ===============
ANSWMBR REPORT
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-25 16:03:09
-----------------------------
16:03:09.781 OS Version: Windows 5.1.2600 Service Pack 3
16:03:09.781 Number of processors: 2 586 0x1706
16:03:09.781 ComputerName: TRADE2WIN UserName: Joe
16:03:13.640 Initialize success
16:11:53.484 AVAST engine defs: 12082501
16:12:33.687 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-25 16:03:09
-----------------------------
16:03:09.781 OS Version: Windows 5.1.2600 Service Pack 3
16:03:09.781 Number of processors: 2 586 0x1706
16:03:09.781 ComputerName: TRADE2WIN UserName: Joe
16:03:13.640 Initialize success
16:11:53.484 AVAST engine defs: 12082501
16:12:33.687 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\aswMBR.txt"
16:13:10.656 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\aswMBR.txt"
16:14:29.812 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:14:29.828 Disk 0 Vendor: WDC_WD3200AAKS-75B3A0 01.03A01 Size: 305245MB BusType: 3
16:14:29.828 Device \Driver\atapi -> DriverStartIo 8a1d72e2
16:14:29.828 Disk 0 MBR read successfully
16:14:29.828 Disk 0 MBR scan
16:14:29.875 Disk 0 Windows XP default MBR code
16:14:29.890 Disk 0 MBR hidden
16:14:29.890 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63
16:14:29.906 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 112640
16:14:29.921 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 294949 MB offset 21084160
16:14:29.921 Disk 0 scanning sectors +625139712
16:14:30.015 Disk 0 scanning C:\WINDOWS\system32\drivers
16:14:38.703 Service scanning
16:14:49.125 Modules scanning
16:14:52.828 Disk 0 trace - called modules:
16:14:52.843 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a1d74b1]<<
16:14:52.843 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a4edab8]
16:14:52.843 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\0000005b[0x8a4ee510]
16:14:52.843 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> [0x8a4df940]
16:14:52.859 \Driver\atapi[0x8a45c5d8] -> IRP_MJ_CREATE -> 0x8a1d74b1
16:14:54.843 AVAST engine scan C:\WINDOWS
16:15:09.328 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\MBR.dat"
16:15:09.375 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-25 16:17:39
-----------------------------
16:17:39.609 OS Version: Windows 5.1.2600 Service Pack 3
16:17:39.609 Number of processors: 2 586 0x1706
16:17:39.609 ComputerName: TRADE2WIN UserName: Joe
16:17:41.250 Initialze error C000010E - driver not loaded
16:17:41.281 write error "aswCmnB.dll". The process cannot access the file because it is being used by another process.
16:17:46.750 AVAST engine defs: 12082501
16:17:51.968 Service scanning
16:18:03.125 Modules scanning
16:18:03.156 Disk 0 trace - called modules:
16:18:03.156
16:18:04.984 AVAST engine scan C:\WINDOWS
16:18:20.437 AVAST engine scan C:\WINDOWS\system32
16:20:20.312 AVAST engine scan C:\WINDOWS\system32\drivers
16:20:32.125 AVAST engine scan C:\Documents and Settings\Joe
16:21:00.828 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\aswMBR.txt"
So i've been having some recent issues with my computer lately and i want to get this system runnning to its fullest potential.
Everytime i open google.com and run a seach on the search engine, i always get a black screen and i get no results. Its like the webpage freezes. Also when i try opening a website like www.google.com/maps or www.google.com/finance i get this
"404 Not Found
--------------------------------------------------------------------------------
nginx/1.2.0
eae00bb3-d172-439f-a81c-6c3c7ba87ea1
Y2:eae00bb3-d172-439f-a81c-6c3c7ba87ea1
"
Here is my DDS REPORT
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.5.1
Run by Joe at 15:52:56 on 2012-08-25
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.1599 [GMT -4:00]
.
AV: AVG Anti-Virus 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Palm, Inc\novacomd\x86\novacomd.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Real\RealPlayer\update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Joe\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\Joe\Local Settings\Application Data\Google\Update\1.3.21.115\GoogleCrashHandler.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\All Users\Application Data\WeCareReminder\ReminderHelper.exe
c:\Program Files\Microsoft Silverlight\5.1.10411.0\agcp.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: StartNow Toolbar Helper: {6e13d095-45c3-4271-9475-f3b48227dd9f} - c:\program files\startnow toolbar\Toolbar32.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7529.1424\swg.dll
BHO: WeCareReminder Class: {d824f0de-3d60-4f57-9eb1-66033ecd8abb} - c:\documents and settings\all users\application data\wecarereminder\IEHelperv2.5.0.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers runtime\YontooIEClient.dll
TB: StartNow Toolbar: {5911488e-9d1e-40ec-8cbb-06b231cc153f} - c:\program files\startnow toolbar\Toolbar32.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\joe\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [StartNowToolbarHelper] "c:\program files\startnow toolbar\ToolbarHelper.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\joe\startm~1\programs\startup\erunta~1.lnk - c:\documents and settings\joe\desktop\help\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1320210431218
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1320215336734
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 167.206.251.129 167.206.251.130
TCP: Interfaces\{13DC235B-8EBF-4AFA-B4FD-6A3FF757B880} : DhcpNameServer = 167.206.251.129 167.206.251.130
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R2 NovacomD;Palm Novacom;c:\program files\palm, inc\novacomd\x86\novacomd.exe [2011-3-15 61440]
R2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;c:\program files\startnow toolbar\ToolbarUpdaterService.exe [2011-7-27 267488]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-11-2 136176]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2012-1-3 30312]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-11-2 136176]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2012-1-3 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2012-1-3 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2012-1-3 121576]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-08-23 14:09:15 -------- d-sh--w- C:\found.000
2012-08-17 21:24:19 -------- d-----w- c:\documents and settings\joe\local settings\application data\Deployment
2012-08-08 00:21:54 -------- d-----w- c:\documents and settings\joe\local settings\application data\Sun
2012-08-08 00:20:45 -------- d-----w- c:\program files\Oracle
2012-08-08 00:20:28 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-08 00:12:01 -------- d-----w- c:\program files\Citrix
2012-08-08 00:11:42 60304 ----a-w- c:\documents and settings\joe\g2mdlhlpx.exe
2012-07-31 17:47:28 -------- d-----w- c:\documents and settings\joe\WER6262.dir00
2012-07-31 17:46:58 -------- d-----w- c:\documents and settings\joe\WERf5bd.dir00
2012-07-31 17:46:48 -------- d-----w- c:\documents and settings\joe\WER9374.dir00
2012-07-31 17:46:45 -------- d-----w- c:\documents and settings\joe\WERb4fd.dir00
2012-07-27 20:51:30 184248 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2012-07-27 13:24:05 -------- d-----w- c:\documents and settings\joe\.swt
.
==================== Find3M ====================
.
2012-07-06 02:07:08 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-06-13 13:19:59 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50:25 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50:25 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32:08 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19:34 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:18:58 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18:58 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18:58 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22:09 599040 ----a-w- c:\windows\system32\crypt32.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD3200AAKS-75B3A0 rev.01.03A01 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A1D72E2
user & kernel MBR OK
.
============= FINISH: 16:00:14.87 ===============
ANSWMBR REPORT
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-25 16:03:09
-----------------------------
16:03:09.781 OS Version: Windows 5.1.2600 Service Pack 3
16:03:09.781 Number of processors: 2 586 0x1706
16:03:09.781 ComputerName: TRADE2WIN UserName: Joe
16:03:13.640 Initialize success
16:11:53.484 AVAST engine defs: 12082501
16:12:33.687 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-25 16:03:09
-----------------------------
16:03:09.781 OS Version: Windows 5.1.2600 Service Pack 3
16:03:09.781 Number of processors: 2 586 0x1706
16:03:09.781 ComputerName: TRADE2WIN UserName: Joe
16:03:13.640 Initialize success
16:11:53.484 AVAST engine defs: 12082501
16:12:33.687 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\aswMBR.txt"
16:13:10.656 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\aswMBR.txt"
16:14:29.812 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:14:29.828 Disk 0 Vendor: WDC_WD3200AAKS-75B3A0 01.03A01 Size: 305245MB BusType: 3
16:14:29.828 Device \Driver\atapi -> DriverStartIo 8a1d72e2
16:14:29.828 Disk 0 MBR read successfully
16:14:29.828 Disk 0 MBR scan
16:14:29.875 Disk 0 Windows XP default MBR code
16:14:29.890 Disk 0 MBR hidden
16:14:29.890 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63
16:14:29.906 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 112640
16:14:29.921 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 294949 MB offset 21084160
16:14:29.921 Disk 0 scanning sectors +625139712
16:14:30.015 Disk 0 scanning C:\WINDOWS\system32\drivers
16:14:38.703 Service scanning
16:14:49.125 Modules scanning
16:14:52.828 Disk 0 trace - called modules:
16:14:52.843 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8a1d74b1]<<
16:14:52.843 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a4edab8]
16:14:52.843 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\0000005b[0x8a4ee510]
16:14:52.843 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> [0x8a4df940]
16:14:52.859 \Driver\atapi[0x8a45c5d8] -> IRP_MJ_CREATE -> 0x8a1d74b1
16:14:54.843 AVAST engine scan C:\WINDOWS
16:15:09.328 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\MBR.dat"
16:15:09.375 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-25 16:17:39
-----------------------------
16:17:39.609 OS Version: Windows 5.1.2600 Service Pack 3
16:17:39.609 Number of processors: 2 586 0x1706
16:17:39.609 ComputerName: TRADE2WIN UserName: Joe
16:17:41.250 Initialze error C000010E - driver not loaded
16:17:41.281 write error "aswCmnB.dll". The process cannot access the file because it is being used by another process.
16:17:46.750 AVAST engine defs: 12082501
16:17:51.968 Service scanning
16:18:03.125 Modules scanning
16:18:03.156 Disk 0 trace - called modules:
16:18:03.156
16:18:04.984 AVAST engine scan C:\WINDOWS
16:18:20.437 AVAST engine scan C:\WINDOWS\system32
16:20:20.312 AVAST engine scan C:\WINDOWS\system32\drivers
16:20:32.125 AVAST engine scan C:\Documents and Settings\Joe
16:21:00.828 The log file has been saved successfully to "C:\Documents and Settings\Joe\Desktop\help\aswMBR.txt"