HELP! Please review my log???

Yesterday my computer was fine. Today I turn it on and it constantly reboots without allowing you to do anything on it. I read online and changed the automatic reboot setting and now it just gives me the blue screen with STOP: ox0000008E (oxc0000005, ox8057019E, oXFS16B99C, oXoooooooo)

I was reading an older thread on here and did the Malawarebytes Antimalaware and it found 7 infected files and removed them. I thought that would do the trick, but NOPE!

Please help???? TIA!!!

Here's my Hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:33:28 PM, on 10/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - http://coupons.smartsource.com/download/cscmv5X.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

--
End of file - 6900 bytes

Comments

  • edited October 2008
    Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

    If you think you have similar problems, please post a log in the HJT forum and wait for help.

    Hello and welcome to the forums

    My name is Katana and I will be helping you to remove any infection(s) that you may have.

    Please observe these rules while we work:
    1. Please Read All Instructions Carefully
    2. If you don't understand something, stop and ask! Don't keep going on.
    3. Please do not run any other tools or scans whilst I am helping you
    4. Please continue to respond until I give you the "All Clear"
      (Just because you can't see a problem doesn't mean it isn't there)

    If you can do those few things, everything should go smoothly :D

    Please Note, your security programs may give warnings for some of the tools I will ask you to use.
    Be assured, any links I give are safe



    Hi lvmichelle99,
    I read online and changed the automatic reboot setting
    What setting did you change ?

    Please have a look for
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
    and post the contents if you find it.


    Download and Run RSIT
    • Please download Random's System Information Tool by random/random from here and save it to your desktop.
    • Double click on RSIT.exe to run RSIT.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open:
      • log.txt will be opened maximized.
      • info.txt will be opened minimized.
    • Please post the contents of both log.txt and info.txt.
  • edited October 2008
    Hi, I am Michelle and thank you so much for responding. I am on my laptop and will log on the desktop here shortly and do these steps. I just wanted to add that I can only run my computer in Safe Mode with Networking. And the setting that I changed was under My Computer I believe it was, to where I changed it so it would not restart automatically and instead would give me the "blue screen" which gives the errors. (Hope that was ok.)

    Off to run this... BRB
  • edited October 2008
    And the setting that I changed was under My Computer I believe it was, to where I changed it so it would not restart automatically and instead would give me the "blue screen" which gives the errors. (Hope that was ok.)
    Hi Michelle,

    That is fine, it's just that there are settings that can force your machine to boot to safe mode.
    Once upon a time that was not a problem, but modern malware has a habit of destroying safemode
    and a machine that has been set to force safemode ends up in a never ending cycle.
  • edited October 2008
    Hi, I am Michelle and thank you so much for responding. I am on my laptop and will log on the desktop here shortly and do these steps. I just wanted to add that I can only run my computer in Safe Mode with Networking. And the setting that I changed was under My Computer I believe it was, to where I changed it so it would not restart automatically and instead would give me the "blue screen" which gives the errors. (Hope that was ok.)

    Off to run this... BRB

    I could not find the "application data" under documents and settings, under username, etc. But I can go under the Malaware and retrieve the log. I have 3 listed there:

    NUMBER 1:

    Malwarebytes' Anti-Malware 1.30
    Database version: 1324
    Windows 5.1.2600 Service Pack 3

    10/26/2008 4:01:55 PM
    mbam-log-2008-10-26 (16-01-55).txt

    Scan type: Quick Scan
    Objects scanned: 49287
    Time elapsed: 3 minute(s), 43 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 6
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\cpbrkpie.coupon6ctrl.1 (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{a85a5e6a-de2c-4f4e-99dc-f469df5a0eec} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\TypeLib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{6e780f0b-bcd6-40cb-b2db-7af47ab4d4a4} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a750a6d862d4} (Adware.Coupons) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\CouponPrinter.ocx (Adware.Coupons) -> Quarantined and deleted successfully.

    NUMBER 2:

    Malwarebytes' Anti-Malware 1.30
    Database version: 1324
    Windows 5.1.2600 Service Pack 3

    10/26/2008 4:03:48 PM
    mbam-log-2008-10-26 (16-03-48).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 16076
    Time elapsed: 1 minute(s), 23 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Number 3:

    Malwarebytes' Anti-Malware 1.30
    Database version: 1324
    Windows 5.1.2600 Service Pack 3

    10/26/2008 4:21:47 PM
    mbam-log-2008-10-26 (16-21-47).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 81290
    Time elapsed: 12 minute(s), 11 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    AND HERE IS THE LOG FROM THE PROGRAM I DOWNLOADED:

    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Administrator at 2008-10-27 16:19:07
    Microsoft Windows XP Home Edition Service Pack 3
    System drive C: has 143 GB (94%) free of 153 GB
    Total RAM: 447 MB (11% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:19:13 PM, on 10/27/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    c:\PROGRA~1\mcafee\msc\mcuimgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\Administrator\Desktop\RSIT.exe
    C:\Documents and Settings\Administrator\Desktop\Administrator.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
    O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
    O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
    O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
    O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - http://coupons.smartsource.com/download/cscmv5X.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbtcoms.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    --
    End of file - 7105 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\McDefragTask.job
    C:\WINDOWS\tasks\McQcTask.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
    scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll [2007-11-09 58688]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-09-14 2403392]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
    Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-09-17 737776]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
    McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-09-04 121632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2008-09-04 121632]
    {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-09-14 2403392]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2004-03-04 2904064]
    "nwiz"=nwiz.exe /install []
    "NvMediaCenter"=C:\WINDOWS\System32\NvMcTray.dll [2004-03-04 46080]
    "nForce Tray Options"=sstray.exe /r []
    "CHotkey"=C:\WINDOWS\zHotkey.exe [2003-06-04 496640]
    "SunKistEM"=C:\Program Files\eMachines Bay Reader\shwiconem.exe [2004-03-12 135168]
    "Lexmark 5200 series"=C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe [2004-03-25 57344]
    "LXBTCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll []
    "FaxCenterServer"=C:\Program Files\Lexmark Fax Solutions\fm3032.exe [2004-03-23 294912]
    "mcagent_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2007-11-01 582992]
    "Microsoft Works Update Detection"=C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [2003-06-07 50688]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
    "NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-10 155648]
    "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
    "MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-13 169984]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2008-10-22 399504]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
    "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-17 68856]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    BigFix.lnk - C:\Program Files\BigFix\BigFix.exe

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=145

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\messenger\msmsgs.exe"="C:\Program Files\messenger\msmsgs.exe:*:Enabled:Windows Messenger"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    ======List of files/folders created in the last 1 months======

    2008-10-27 16:19:07 ----D---- C:\rsit
    2008-10-26 15:56:39 ----D---- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
    2008-10-26 15:56:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2008-10-26 15:56:34 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-10-26 15:31:19 ----D---- C:\Rustbfix
    2008-10-26 12:07:59 ----D---- C:\Documents and Settings\Administrator\Application Data\Macromedia
    2008-10-26 12:07:59 ----D---- C:\Documents and Settings\Administrator\Application Data\Adobe
    2008-10-26 11:10:35 ----D---- C:\Documents and Settings\Administrator\Application Data\Mozilla
    2008-10-26 10:18:30 ----ASH---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
    2008-10-26 10:18:23 ----D---- C:\Documents and Settings\Administrator\Application Data\Identities
    2008-10-26 10:18:23 ----D---- C:\Documents and Settings\Administrator\Application Data\CyberLink
    2008-10-26 10:18:22 ----SD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
    2008-10-26 10:18:22 ----D---- C:\Documents and Settings\Administrator\Application Data\Symantec
    2008-10-26 10:18:22 ----D---- C:\Documents and Settings\Administrator\Application Data\Sun
    2008-10-26 10:17:49 ----A---- C:\WINDOWS\ntbtlog.txt
    2008-10-24 22:11:38 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
    2008-10-22 16:46:36 ----A---- C:\WINDOWS\compedia.ini
    2008-10-22 16:46:02 ----D---- C:\Documents and Settings\All Users\Application Data\xpressionsmedia
    2008-10-22 16:45:32 ----SHD---- C:\WINDOWS\ftpcache
    2008-10-21 11:41:48 ----D---- C:\WINDOWS\pss
    2008-10-19 09:20:20 ----SHD---- C:\found.000
    2008-10-16 08:28:16 ----D---- C:\WINDOWS\LastGood
    2008-10-15 20:56:13 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
    2008-10-15 20:56:07 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
    2008-10-15 20:56:01 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
    2008-10-15 20:55:16 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
    2008-10-15 20:55:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
    2008-10-15 10:35:04 ----D---- C:\WINDOWS\LastGood.Tmp
    2008-10-13 17:18:44 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2008-10-13 17:18:42 ----D---- C:\Program Files\Oberon Media
    2008-10-13 17:18:42 ----D---- C:\Documents and Settings\All Users\Application Data\Oberon Media
    2008-10-03 10:41:15 ----N---- C:\WINDOWS\system32\SET94E.tmp
    2008-10-03 10:41:15 ----A---- C:\WINDOWS\system32\SET569.tmp

    ======List of files/folders modified in the last 1 months======

    2008-10-27 16:11:23 ----D---- C:\WINDOWS\Temp
    2008-10-27 16:10:49 ----D---- C:\Program Files\Mozilla Firefox
    2008-10-27 16:09:05 ----D---- C:\WINDOWS
    2008-10-27 15:35:17 ----A---- C:\WINDOWS\win.ini
    2008-10-26 16:08:51 ----D---- C:\WINDOWS\Minidump
    2008-10-26 15:56:37 ----D---- C:\WINDOWS\system32\drivers
    2008-10-26 15:56:34 ----RD---- C:\Program Files
    2008-10-26 15:44:54 ----RASH---- C:\boot.ini
    2008-10-26 15:44:54 ----A---- C:\WINDOWS\system.ini
    2008-10-26 13:20:49 ----SHD---- C:\RECYCLER
    2008-10-26 10:18:20 ----D---- C:\Documents and Settings
    2008-10-25 21:05:46 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-10-25 09:35:20 ----D---- C:\WINDOWS\Prefetch
    2008-10-25 08:17:21 ----D---- C:\WINDOWS\system32
    2008-10-24 22:11:45 ----HD---- C:\WINDOWS\inf
    2008-10-24 22:11:45 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-10-24 22:11:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2008-10-24 22:11:07 ----HD---- C:\WINDOWS\$hf_mig$
    2008-10-24 19:12:10 ----D---- C:\Program Files\Lx_cats
    2008-10-22 16:46:34 ----SHD---- C:\WINDOWS\Installer
    2008-10-22 16:46:34 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-10-22 16:46:17 ----D---- C:\WINDOWS\system
    2008-10-17 20:50:55 ----D---- C:\WINDOWS\system32\CatRoot
    2008-10-15 20:56:16 ----A---- C:\WINDOWS\imsins.BAK
    2008-10-15 20:55:44 ----D---- C:\Program Files\Internet Explorer
    2008-10-15 09:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll
    2008-10-13 03:52:04 ----A---- C:\WINDOWS\NeroDigital.ini
    2008-10-07 12:19:40 ----A---- C:\WINDOWS\system32\MRT.exe
    2008-10-05 15:02:54 ----D---- C:\Program Files\Winamp
    2008-10-03 10:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll
    2008-10-02 10:21:06 ----A---- C:\WINDOWS\winamp.ini

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2007-07-13 113952]
    R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
    R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-18 12160]
    R3 NVENET;NVIDIA nForce MCP Networking Controller Driver; C:\WINDOWS\System32\DRIVERS\NVENET.sys [2003-08-16 72771]
    R3 SunkFilt39;Alcor Micro Corp - 3239; \??\C:\WINDOWS\System32\Drivers\sunkfilt39.sys []
    R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
    R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
    R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\System32\DRIVERS\amdk7.sys [2008-04-13 37760]
    S1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2007-11-22 201320]
    S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\System32\DRIVERS\p3.sys [2008-04-13 42752]
    S2 mdmxsdk;mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [2004-01-17 12970]
    S3 HSF_DP;HSF_DP; C:\WINDOWS\System32\DRIVERS\HSF_DP.sys [2003-11-14 1042816]
    S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys [2003-11-14 210304]
    S3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2007-11-22 79304]
    S3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2007-11-22 35240]
    S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2007-11-22 33832]
    S3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2007-12-02 40488]
    S3 mxnic;Macronix MX987xx Family Fast Ethernet NT Driver; C:\WINDOWS\System32\DRIVERS\mxnic.sys [2001-08-17 19968]
    S3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2004-03-04 1893536]
    S3 nvax;Service for NVIDIA(R) nForce(TM) Audio Enumerator; C:\WINDOWS\system32\drivers\nvax.sys [2003-09-03 36864]
    S3 nvnforce;Service for NVIDIA(R) nForce(TM) Audio; C:\WINDOWS\system32\drivers\nvapu.sys [2003-09-03 312704]
    S3 SunkFilt;Alcor Micro Corp - 9360; \??\C:\WINDOWS\System32\Drivers\sunkfilt.sys []
    S3 Sunkfiltp;HP && Alcor Micro Corp for Phison; \??\C:\WINDOWS\System32\Drivers\sunkfiltp.sys []
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
    S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\System32\DRIVERS\wanatw4.sys []
    S3 winachsf;winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [2003-11-14 679808]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2008-01-09 767976]
    R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2007-07-18 856864]
    S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
    S2 McNASvc;McAfee Network Agent; c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe [2008-01-25 2458128]
    S2 McProxy;McAfee Proxy Service; c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe [2007-08-15 359248]
    S2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2007-07-24 144704]
    S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2004-03-04 77824]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-14 138168]
    S3 lxbt_device;lxbt_device; C:\WINDOWS\System32\lxbtcoms.exe [2004-02-20 421888]
    S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2007-11-07 378184]
    S3 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2007-12-05 695624]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

    EOF
  • edited October 2008
    There is nothing there that would cause boot problems ?????
    It sounds like a driver or hardware problem.

    Have you installed any new programs/hardware ?
    Have you tried system restore ?
  • edited October 2008
    Katana wrote:
    There is nothing there that would cause boot problems ?????
    It sounds like a driver or hardware problem.

    Have you installed any new programs/hardware ?
    Have you tried system restore ?

    I installed a cheap software game for my son a few days prior but it was running and working for days prior to this....

    It has been running "weird" for a while. I have received error messages in the past about memory, so I removed a bunch of stuff off it. My scrolling when using the mouse has been off... just doesn't scroll through the web pages with ease. Kinda like loading the page issues. Viewing of certain pages have all of a sudden looked different just as of late. While browsing the internet, it has been sluggish.

    Could this be a memory problem or ram problem? I just had to do a system restore about 2 months ago for issues. I am trying to avoid doing another one. I feel like it is an underlying problem and if I restore, I will just have problems again.
  • edited October 2008
    If you have been having problems for a while, then it could well be a hardware problem that is just getting worse.
    How old is the machine ?

    Let's try a last scan to see if anything is lurking.



    Download and Run ComboFix (by sUBs)
    Please visit this webpage for instructions for downloading and running ComboFix:

    Bleeping Computer ComboFix Tutorial

    Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
    This tool is not a toy and not for everyday use.
    ComboFix SHOULD NOT be used unless requested by a forum helper
  • edited October 2008
    The machine is probably 8 years old.

    I installed the combofix. But the step where you have to install the Windows Recovery Console... I put my CD in that came with my emachine and run what they have listed and it does not come up. If I go to the microsoft link it says to look for my edition and service pack....my service pack is 3 and I do not see that listed....what should I do now?
  • edited October 2008
    Disable all your security programs, and then double click ComboFix.
    It will automatically install it for you.
  • edited October 2008
    OK. Here it is:

    ComboFix 08-10-27.02 - Administrator 2008-10-27 17:18:52.1 - NTFSx86 NETWORK
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.172 [GMT -7:00]
    Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
    .
    ((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
    .
    2008-10-27 16:19 . 2008-10-27 16:19 <DIR> d
    C:\rsit
    2008-10-26 15:56 . 2008-10-26 15:56 <DIR> d
    C:\Program Files\Malwarebytes' Anti-Malware
    2008-10-26 15:56 . 2008-10-26 15:56 <DIR> d
    C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-10-26 15:56 . 2008-10-26 15:56 <DIR> d
    C:\Documents and Settings\Administrator\Application Data\Malwarebytes
    2008-10-26 15:56 . 2008-10-22 16:10 38,496 --a
    C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-10-26 15:56 . 2008-10-22 16:10 15,504 --a
    C:\WINDOWS\system32\drivers\mbam.sys
    2008-10-26 15:31 . 2008-10-26 15:31 <DIR> d
    C:\Rustbfix
    2008-10-26 10:18 . 2004-05-07 15:11 <DIR> d
    C:\Documents and Settings\Administrator\WINDOWS
    2008-10-26 10:18 . 2004-05-07 15:11 <DIR> d
    C:\Documents and Settings\Administrator\Application Data\Symantec
    2008-10-26 10:18 . 2004-05-07 15:11 <DIR> d
    C:\Documents and Settings\Administrator\Application Data\CyberLink
    2008-10-26 10:18 . 2008-10-26 10:18 <DIR> d
    C:\Documents and Settings\Administrator
    2008-10-24 09:29 . 2008-10-15 09:34 337,408
    c--- C:\WINDOWS\system32\dllcache\netapi32.dll
    2008-10-22 16:46 . 2008-10-22 16:46 <DIR> d
    C:\Documents and Settings\All Users\Application Data\xpressionsmedia
    2008-10-22 16:46 . 2008-10-22 16:46 2,525 --a
    C:\WINDOWS\compedia.ini
    2008-10-22 16:45 . 2008-10-22 16:45 <DIR> d--hs---- C:\WINDOWS\ftpcache
    2008-10-19 09:20 . 2008-10-19 09:20 <DIR> d--hs---- C:\found.000
    2008-10-16 08:28 . 2008-10-16 08:28 <DIR> d
    C:\WINDOWS\LastGood
    2008-10-15 10:35 . 2008-10-15 10:35 <DIR> d
    C:\WINDOWS\LastGood.Tmp
    2008-10-15 10:35 . 2008-09-08 03:41 333,824
    c--- C:\WINDOWS\system32\dllcache\srv.sys
    2008-10-15 10:34 . 2008-08-14 03:11 2,189,184
    c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
    2008-10-15 10:34 . 2008-08-14 03:09 2,145,280
    c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
    2008-10-15 10:34 . 2008-08-14 02:33 2,066,048
    c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
    2008-10-15 10:34 . 2008-08-14 02:33 2,023,936
    c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
    2008-10-15 10:34 . 2008-09-15 05:12 1,846,400
    c--- C:\WINDOWS\system32\dllcache\win32k.sys
    2008-10-13 17:18 . 2008-10-13 17:18 <DIR> d
    C:\Program Files\Oberon Media
    2008-10-13 17:18 . 2008-10-13 17:18 <DIR> d
    C:\Documents and Settings\Boehm Family\Application Data\Oberon Media
    2008-10-13 17:18 . 2008-10-19 11:35 <DIR> d-a
    C:\Documents and Settings\All Users\Application Data\TEMP
    2008-10-13 17:18 . 2008-10-13 17:18 <DIR> d
    C:\Documents and Settings\All Users\Application Data\Oberon Media
    2008-10-03 10:41 . 2008-10-03 10:41 6,066,176
    C:\WINDOWS\system32\SET94E.tmp
    2008-10-03 10:41 . 2008-10-03 10:41 6,066,176 --a
    C:\WINDOWS\system32\SET569.tmp
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-10-25 02:12
    d
    w C:\Program Files\Lx_cats
    2008-10-22 23:46
    d--h--w C:\Program Files\InstallShield Installation Information
    2008-10-05 22:02
    d
    w C:\Program Files\Winamp
    2008-09-27 15:55
    d
    w C:\Program Files\McAfee
    2008-09-26 22:24
    d
    w C:\Documents and Settings\LocalService\Application Data\SACore
    2008-09-23 16:55
    d
    w C:\Program Files\Java
    2008-09-15 12:12 1,846,400 ----a-w C:\WINDOWS\system32\win32k.sys
    2008-09-14 10:15
    d
    w C:\Program Files\Google
    2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
    2008-09-05 22:52
    d
    w C:\Program Files\Coupons
    2008-09-05 02:33
    d
    w C:\Program Files\NOS
    2008-09-05 02:33
    d
    w C:\Documents and Settings\All Users\Application Data\NOS
    2008-09-05 02:27
    d
    w C:\Program Files\Common Files\Adobe
    2008-09-05 02:06
    d
    w C:\Documents and Settings\All Users\Application Data\McAfee
    2008-09-05 02:03
    d
    w C:\Program Files\McAfee.com
    2008-09-05 02:03
    d
    w C:\Program Files\Common Files\McAfee
    2008-09-05 01:02
    d
    w C:\Program Files\DIFX
    2008-09-04 20:40
    d
    w C:\Documents and Settings\Boehm Family\Application Data\AdobeUM
    2008-09-03 17:30
    d
    w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
    2008-09-02 18:08
    d
    w C:\Program Files\MSN Encarta Plus
    2008-09-02 18:08
    d
    w C:\Program Files\Microsoft Picture It! 9
    2008-09-02 18:08
    d
    w C:\Program Files\ICQ
    2008-09-02 18:04
    d
    w C:\Program Files\Common Files\Real
    2008-09-02 17:55
    d
    w C:\Documents and Settings\Boehm Family\Application Data\FaxCtr
    2008-09-02 17:50
    d
    w C:\Documents and Settings\Boehm Family\Application Data\MSN6
    2008-09-02 17:50
    d
    w C:\Documents and Settings\All Users\Application Data\MSN6
    2008-09-02 17:48
    d
    w C:\Program Files\Ahead
    2008-09-02 17:48
    d
    w C:\Documents and Settings\All Users\Application Data\Symantec
    2008-09-02 17:46
    d
    w C:\Program Files\Common Files\AOL
    2008-09-02 17:46
    d
    w C:\Documents and Settings\All Users\Application Data\AOL
    2008-09-02 17:44
    d
    w C:\Program Files\Microsoft ActiveSync
    2008-09-02 17:39
    d
    w C:\Program Files\Lexmark Fax Solutions
    2008-09-02 17:39
    d
    w C:\Documents and Settings\All Users\Application Data\FaxCtr
    2008-09-02 17:38
    d
    w C:\Program Files\ABBYY FineReader 5.0 Sprint
    2008-09-02 17:35
    d
    w C:\Program Files\Lexmark 5200 series
    2008-08-27 08:24 3,593,216 ----a-w C:\WINDOWS\system32\SET561.tmp
    2008-08-26 07:24 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-08-26 07:24 63,488 ----a-w C:\WINDOWS\system32\SET570.tmp
    2008-08-26 07:24 63,488
    w C:\WINDOWS\system32\SET950.tmp
    2008-08-26 07:24 52,224 ----a-w C:\WINDOWS\system32\SET562.tmp
    2008-08-26 07:24 459,264 ----a-w C:\WINDOWS\system32\SET563.tmp
    2008-08-26 07:24 383,488 ----a-w C:\WINDOWS\system32\SET56B.tmp
    2008-08-26 07:24 383,488
    w C:\WINDOWS\system32\SET94F.tmp
    2008-08-26 07:24 267,776 ----a-w C:\WINDOWS\system32\SET567.tmp
    2008-08-26 07:24 124,928 ----a-w C:\WINDOWS\system32\SET573.tmp
    2008-08-26 07:24 124,928
    w C:\WINDOWS\system32\SET951.tmp
    2008-08-26 07:24 105,984 ----a-w C:\WINDOWS\system32\SET55B.tmp
    2008-08-14 10:11 2,189,184 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
    2008-08-14 09:33 2,066,048 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-17 68856]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-03-04 2904064]
    "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-04 46080]
    "SunKistEM"="C:\Program Files\eMachines Bay Reader\shwiconem.exe" [2004-03-12 135168]
    "Lexmark 5200 series"="C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe" [2004-03-25 57344]
    "LXBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll" [2004-03-17 65536]
    "FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2004-03-23 294912]
    "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 50688]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-10 155648]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-13 169984]
    "nwiz"="nwiz.exe" [2004-03-04 C:\WINDOWS\system32\nwiz.exe]
    "nForce Tray Options"="sstray.exe" [2003-09-03 C:\WINDOWS\system32\sstray.exe]
    "CHotkey"="zHotkey.exe" [2003-06-04 C:\WINDOWS\zHotkey.exe]
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2004-05-01 1742384]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a
    2008-04-13 17:12 15360 C:\WINDOWS\system32\ctfmon.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\messenger\\msmsgs.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
    *Newly Created Service* - PROCEXP90
    .
    Contents of the 'Scheduled Tasks' folder
    2008-09-05 C:\WINDOWS\Tasks\McDefragTask.job
    - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
    2008-09-05 C:\WINDOWS\Tasks\McQcTask.job
    - c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
    .
    .
    Supplementary Scan
    .
    FireFox -: Profile - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\x5g30w3s.default\
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
    FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    .
    **************************************************************************
    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-10-27 17:20:41
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    LXBTCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    Completion time: 2008-10-27 17:22:07
    ComboFix-quarantined-files.txt 2008-10-28 00:22:01
    Pre-Run: 149,612,900,352 bytes free
    Post-Run: 150,127,321,088 bytes free
    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional Edition" /fastdetect /NoExecute=OptIn
    165 --- E O F --- 2008-10-25 05:11:46


    ALSO MY COMPUTER IS LOADING AND SCROLLING THROUGH THE WEB PAGES DURING SAFE MODE SUPER SLOW. NOT SURE IF THAT IS COMMON IN THIS MODE OR IF IT INDICATES A PROBLEM. I JUST WANTED TO MAKE NOTE OF IT.

    THANKS SO MUCH!
  • edited October 2008
    There is no malware that would be causing your problem.
    Unfortunately you are now outside my area of knowledge, so I'm going to have to recommend that you speak to the tech team for assistance.
    But I would recommend that you backup any important data as soon as possible.


    I am just checking which team is the best to help you, and the I will move your thread to their care.

    • This will clear your System Volume Information restore points and remove all the infected files that were quarantined
    • Click START then RUN
    • Now type Combofix /u in the runbox and click OK. Note the space between the X and the /U, it needs to be there.
      • CF_Cleanup.png
  • edited October 2008
    It's probably best if you start a fresh thread because of the logs you have posted
    (we don't want other people thinking they can post HJT logs in the other rooms )

    Start a thread in the OS room, and then they can make sure it isn't just a display driver at fault.
    http://icrontic.com/forum/forumdisplay.php?f=32
  • edited October 2008
    Thank you for your assistance. I will post a new thread as you instructed. I appreciate your help.
  • edited October 2008
    Glad we could be of assistance! This topic is now closed.

    If you wish to reopen your topic, please send a Private Message (PM) to Trogan with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead :)
Sign In or Register to comment.