Jump to content

Possible malware infection?


Recommended Posts

Dell Studio XP 1645

Windows 7 Professional 64-bit with Service Pack 1

So a few days ago, my computer suddenly failed to be able to boot. So I formatted the partition Windows was installed on and did a clean install from a Windows 7 CD. Everything appeared to be fine.

A week later, my computer is having troubles again. After an initial failure to boot (with the computer not even being able to successfully enter into start up repair), Windows does successfully start now, but the start up time is VERY long, and for about 5 to 10 minutes after reaching the desktop, the system is still very slow and unresponsive, up until a certain point where it is responsive enough to be useable but still noticeably slower with intermittent slowdowns.

I've tried to reinstall Windows from the CD again BUT, I cannot successfully boot from the CD. Like what happens when I try to access startup repair, I get a black screen for a long while and then eventually the harddrive light stops blinking which I can only assume means nothing is happening. So I try an the "upgrade" reinstall option by launching the installer from inside Windows (since a "custom" install, aka a clean install cannot be done when Windows is already running), but some time during the second stage of the installation, I get the message "Windows could not prepare the computer to boot into the next phase of installation" and I have to exit the installation.

So I considered perhaps I may have a malware infection of some sort. Avast Anti-Virus did not find anything but it gave me a message that a certain files were not able to be scanned. MBAM did not report that anything was wrong.

Here are my logs from dds:

dds.txt

DDS (Ver_2012-11-20.01) - NTFS_AMD64

Internet Explorer: 10.0.9200.16537 BrowserJavaVersion: 10.17.2

Run by Edwin at 21:30:04 on 2013-04-16

Microsoft Windows 7 Professional 6.1.7601.1.1252.2.1033.18.8180.6201 [GMT -4:00]

.

AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}

SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

============== Running Processes ===============

.

C:\Windows\system32\lsm.exe

C:\Windows\system32\svchost.exe -k DcomLaunch

C:\Windows\system32\svchost.exe -k RPCSS

C:\Windows\system32\atiesrxx.exe

C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted

C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted

C:\Windows\system32\svchost.exe -k LocalService

C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\atieclxx.exe

C:\Windows\system32\svchost.exe -k NetworkService

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskhost.exe

C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

D:\games\Steam\Steam.exe

C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe

D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Windows\system32\SearchIndexer.exe

C:\Windows\System32\svchost.exe -k secsvcs

C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation

C:\Program Files (x86)\Common Files\Steam\SteamService.exe

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Windows\system32\wuauclt.exe

D:\Program Files\AVAST Software\Avast\AvastUI.exe

D:\Program Files\AVAST Software\Avast\AvastSvc.exe

D:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Windows\system32\SearchProtocolHost.exe

C:\Windows\system32\SearchFilterHost.exe

C:\Windows\system32\wbem\wmiprvse.exe

C:\Windows\System32\cscript.exe

.

============== Pseudo HJT Report ===============

.

mWinlogon: Userinit = userinit.exe

BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll

BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll

TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll

uRun: [steam] "D:\games\Steam\Steam.exe" -silent

mRun: [avast] "D:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui

mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

StartupFolder: C:\Users\Edwin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Edwin\AppData\Roaming\Dropbox\bin\Dropbox.exe

StartupFolder: C:\Users\Edwin\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - D:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe

mPolicies-Explorer: NoActiveDesktop = dword:1

mPolicies-Explorer: NoActiveDesktopChanges = dword:1

mPolicies-System: ConsentPromptBehaviorAdmin = dword:5

mPolicies-System: ConsentPromptBehaviorUser = dword:3

mPolicies-System: EnableUIADesktopToggle = dword:0

Trusted Zone: clonewarsadventures.com

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

TCP: NameServer = 24.226.1.93 24.226.10.193 24.226.10.194

TCP: Interfaces\{C5EE701D-F005-4468-B1E3-04705012F66E} : DHCPNameServer = 24.226.1.93 24.226.10.193 24.226.10.194

TCP: Interfaces\{C5EE701D-F005-4468-B1E3-04705012F66E}\D4163634F6E6E6563647 : DHCPNameServer = 130.113.128.1 130.113.64.1

SSODL: WebCheck - <orphaned>

mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll

x64-SSODL: WebCheck - <orphaned>

.

================= FIREFOX ===================

.

FF - ProfilePath - C:\Users\Edwin\AppData\Roaming\Mozilla\Firefox\Profiles\4u9wrwqj.default\

FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll

FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll

FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll

FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll

FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll

FF - plugin: C:\Windows\SysWOW64\npmproxy.dll

FF - plugin: D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

FF - ExtSQL: 2013-04-10 17:45; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; C:\Users\Edwin\AppData\Roaming\Mozilla\Firefox\Profiles\4u9wrwqj.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

FF - ExtSQL: 2013-04-10 17:51; {73a6fe31-595d-460b-a920-fcc0f8843232}; C:\Users\Edwin\AppData\Roaming\Mozilla\Firefox\Profiles\4u9wrwqj.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi

FF - ExtSQL: 2013-04-10 22:58; {b9db16a4-6edc-47ec-a1f4-b86292ed211d}; C:\Users\Edwin\AppData\Roaming\Mozilla\Firefox\Profiles\4u9wrwqj.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

FF - ExtSQL: 2013-04-11 00:45; wrc@avast.com; D:\Program Files\AVAST Software\Avast\WebRep\FF

FF - ExtSQL: 2013-04-11 01:02; {DDC359D1-844A-42a7-9AA1-88A850A938A8}; C:\Users\Edwin\AppData\Roaming\Mozilla\Firefox\Profiles\4u9wrwqj.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi

.

============= SERVICES / DRIVERS ===============

.

R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-4-10 65336]

R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2013-4-10 1025808]

R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2013-4-10 377920]

R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2009-8-18 203264]

R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2013-4-10 33400]

R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2013-4-10 80816]

R2 avast! Antivirus;avast! Antivirus;D:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-4-11 45248]

R2 MBAMService;MBAMService;D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-4-16 701512]

R3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2009-6-10 270848]

R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-4-16 25928]

R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\netw5v64.sys [2009-6-10 5434368]

S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]

S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]

S2 MBAMScheduler;MBAMScheduler;D:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-4-16 418376]

S3 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-4-10 178624]

S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2011-4-12 71168]

S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]

S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]

S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]

S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-4-12 1255736]

.

=============== Created Last 30 ================

.

2013-04-16 21:54:29 9311288 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{EFB06ACC-B699-4C0D-AA7B-5B09E71F30D3}\mpengine.dll

2013-04-16 14:06:56 -------- d-----w- C:\Users\Edwin\AppData\Roaming\Malwarebytes

2013-04-16 14:06:49 -------- d-----w- C:\ProgramData\Malwarebytes

2013-04-16 14:06:48 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys

2013-04-13 22:28:28 -------- d-----w- C:\Windows\SysWow64\directx

2013-04-13 22:25:11 -------- d-----w- C:\Users\Edwin\AppData\Local\Package Cache

2013-04-13 16:25:48 -------- d-----w- C:\Users\Edwin\AppData\Local\Solid State Networks

2013-04-13 01:09:59 78680 ----a-w- C:\Windows\System32\XAPOFX1_4.dll

2013-04-13 01:08:57 3767504 ----a-w- C:\Windows\System32\d3dx9_26.dll

2013-04-13 01:08:57 2297552 ----a-w- C:\Windows\SysWow64\d3dx9_26.dll

2013-04-12 23:36:40 -------- d-----w- C:\Users\Edwin\AppData\Local\Programs

2013-04-12 08:01:26 -------- d-----w- C:\Windows\SysWow64\Wat

2013-04-12 08:01:26 -------- d-----w- C:\Windows\System32\Wat

2013-04-12 07:24:03 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui

2013-04-12 07:24:02 9728 ----a-w- C:\Windows\System32\Wdfres.dll

2013-04-12 07:24:02 785512 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys

2013-04-12 07:24:02 54376 ----a-w- C:\Windows\System32\drivers\WdfLdr.sys

2013-04-12 07:15:20 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-04-12 07:05:50 70656 ----a-w- C:\Windows\SysWow64\fontsub.dll

2013-04-12 07:05:50 46080 ----a-w- C:\Windows\System32\atmlib.dll

2013-04-12 07:05:50 367616 ----a-w- C:\Windows\System32\atmfd.dll

2013-04-12 07:05:50 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll

2013-04-12 07:05:50 100864 ----a-w- C:\Windows\System32\fontsub.dll

2013-04-12 07:05:49 295424 ----a-w- C:\Windows\SysWow64\atmfd.dll

2013-04-12 07:04:59 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys

2013-04-12 07:04:59 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys

2013-04-12 07:04:58 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll

2013-04-12 07:04:58 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll

2013-04-12 07:04:57 744448 ----a-w- C:\Windows\System32\WUDFx.dll

2013-04-12 07:04:57 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll

2013-04-12 07:04:57 229888 ----a-w- C:\Windows\System32\WUDFHost.exe

2013-04-12 07:02:37 81408 ----a-w- C:\Windows\System32\imagehlp.dll

2013-04-12 07:02:37 5120 ----a-w- C:\Windows\SysWow64\wmi.dll

2013-04-12 07:02:37 5120 ----a-w- C:\Windows\System32\wmi.dll

2013-04-12 07:02:37 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys

2013-04-12 07:02:37 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll

2013-04-12 06:11:10 -------- d-----w- C:\Users\Edwin\AppData\Roaming\Dropbox

2013-04-11 19:56:55 -------- d-----w- C:\Users\Edwin\AppData\Local\Adobe

2013-04-11 19:34:50 -------- d-----w- C:\Users\Edwin\AppData\Roaming\OpenOffice.org

2013-04-11 16:00:58 2048 ----a-w- C:\Windows\SysWow64\tzres.dll

2013-04-11 15:59:47 478208 ----a-w- C:\Windows\System32\dpnet.dll

2013-04-11 15:58:42 498688 ----a-w- C:\Windows\System32\drivers\afd.sys

2013-04-11 15:57:42 68608 ----a-w- C:\Windows\System32\taskhost.exe

2013-04-11 15:56:59 936960 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\ink\journal.dll

2013-04-11 15:50:28 9311288 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll

2013-04-11 15:50:20 77312 ----a-w- C:\Windows\System32\packager.dll

2013-04-11 15:50:20 67072 ----a-w- C:\Windows\SysWow64\packager.dll

2013-04-11 04:20:01 -------- d-----w- C:\Program Files (x86)\Common Files\Steam

2013-04-11 02:55:51 -------- d-----w- C:\Program Files (x86)\Mozilla Maintenance Service

2013-04-11 02:55:24 -------- d-----w- C:\Users\Edwin\AppData\Local\Google

2013-04-11 02:55:20 -------- d-----w- C:\Users\Edwin\AppData\Local\Deployment

2013-04-11 02:55:20 -------- d-----w- C:\Users\Edwin\AppData\Local\Apps

2013-04-11 02:50:04 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll

2013-04-11 02:50:04 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys

2013-04-11 02:50:04 1031680 ----a-w- C:\Windows\System32\rdpcore.dll

2013-04-11 02:46:43 2622464 ----a-w- C:\Windows\System32\wucltux.dll

2013-04-11 02:46:37 99840 ----a-w- C:\Windows\System32\wudriver.dll

2013-04-11 02:46:30 36864 ----a-w- C:\Windows\System32\wuapp.exe

2013-04-11 02:46:30 186752 ----a-w- C:\Windows\System32\wuwebv.dll

2013-04-11 00:47:09 -------- d-----w- C:\Windows\Panther

2013-04-10 22:55:48 861088 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll

2013-04-10 22:55:48 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll

2013-04-10 22:55:43 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll

2013-04-10 22:10:09 -------- d-----w- C:\Users\Edwin\AppData\Local\Macromedia

2013-04-10 22:09:28 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

2013-04-10 22:09:28 691592 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe

2013-04-10 22:04:47 70992 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys

2013-04-10 22:04:47 1025808 ----a-w- C:\Windows\System32\drivers\aswSnx.sys

2013-04-10 22:04:46 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys

2013-04-10 22:04:46 178624 ----a-w- C:\Windows\System32\drivers\aswVmm.sys

2013-04-10 22:04:42 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys

2013-04-10 22:04:13 -------- d-sh--w- C:\Windows\Installer

2013-04-10 22:04:01 41664 ------w- C:\Windows\avastSS.scr

2013-04-10 22:02:33 -------- d-----w- C:\ProgramData\AVAST Software

2013-04-10 21:47:54 -------- d-----w- C:\Users\Edwin\AppData\Roaming\uTorrent

2013-04-10 21:00:58 -------- d-----w- C:\Users\Edwin\AppData\Local\Mozilla

2013-04-10 20:49:53 0 ----a-w- C:\Windows\ativpsrm.bin

.

==================== Find3M ====================

.

2013-04-12 07:15:20 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll

2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe

2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll

2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe

2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe

2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll

2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe

2013-03-12 05:10:56 282744 ------w- C:\Windows\System32\MpSigStub.exe

2013-03-01 03:36:04 3153408 ----a-w- C:\Windows\System32\win32k.sys

2013-02-15 06:08:40 44032 ----a-w- C:\Windows\System32\tsgqec.dll

2013-02-15 06:06:11 3717632 ----a-w- C:\Windows\System32\mstscax.dll

2013-02-15 06:02:26 158720 ----a-w- C:\Windows\System32\aaclient.dll

2013-02-15 04:37:10 3217408 ----a-w- C:\Windows\SysWow64\mstscax.dll

2013-02-15 04:34:10 131584 ----a-w- C:\Windows\SysWow64\aaclient.dll

2013-02-15 03:25:51 36864 ----a-w- C:\Windows\SysWow64\tsgqec.dll

2013-02-12 05:45:24 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll

2013-02-12 05:45:22 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll

2013-02-12 05:45:22 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll

2013-02-12 05:45:22 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll

2013-02-12 04:48:31 474112 ----a-w- C:\Windows\apppatch\AcSpecfc.dll

2013-02-12 04:48:26 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll

2013-02-12 04:12:05 19968 ----a-w- C:\Windows\System32\drivers\usb8023.sys

2013-01-24 06:01:01 223752 ----a-w- C:\Windows\System32\drivers\fvevol.sys

.

============= FINISH: 21:30:26.64 ===============

Attach.txt

.

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.

IF REQUESTED, ZIP IT UP & ATTACH IT

.

DDS (Ver_2012-11-20.01)

.

Microsoft Windows 7 Professional

Boot Device: \Device\HarddiskVolume2

Install Date: 10/04/2013 4:54:33 PM

System Uptime: 16/04/2013 6:26:47 PM (3 hours ago)

.

Motherboard: Dell Inc. | | 345678

Processor: Intel® Core i7 CPU Q 720 @ 1.60GHz | U2E1 | 1600/133mhz

.

==== Disk Partitions =========================

.

C: is FIXED (NTFS) - 78 GiB total, 49.637 GiB free.

D: is FIXED (NTFS) - 186 GiB total, 168.336 GiB free.

E: is FIXED (NTFS) - 186 GiB total, 7.889 GiB free.

F: is CDROM ()

.

==== Disabled Device Manager Items =============

.

Class GUID:

Description:

Device ID: ACPI\ITE8708\4&2B6801A4&0

Manufacturer:

Name:

PNP Device ID: ACPI\ITE8708\4&2B6801A4&0

Service:

.

Class GUID:

Description: Base System Device

Device ID: PCI\VEN_1180&DEV_E230&SUBSYS_02FE1028&REV_01\4&9C93D99&0&01E4

Manufacturer:

Name: Base System Device

PNP Device ID: PCI\VEN_1180&DEV_E230&SUBSYS_02FE1028&REV_01\4&9C93D99&0&01E4

Service:

.

Class GUID:

Description: Base System Device

Device ID: PCI\VEN_1180&DEV_E852&SUBSYS_02FE1028&REV_01\4&9C93D99&0&02E4

Manufacturer:

Name: Base System Device

PNP Device ID: PCI\VEN_1180&DEV_E852&SUBSYS_02FE1028&REV_01\4&9C93D99&0&02E4

Service:

.

==== System Restore Points ===================

.

.

==== Installed Programs ======================

.

Adobe Flash Player 11 Plugin

Adobe Reader XI (11.0.02)

avast! Free Antivirus

Combined Community Codec Pack 2013-03-25

Dropbox

Google Chrome

Google Update Helper

Hawken

Java 7 Update 17

Java Auto Updater

Malwarebytes Anti-Malware version 1.75.0.1300

MechWarrior Online

Microsoft .NET Framework 4 Client Profile

Microsoft .NET Framework 4 Extended

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

Mount & Blade: Warband

Mozilla Firefox 20.0 (x86 en-US)

Mozilla Firefox 20.0.1 (x86 en-US)

Mozilla Maintenance Service

OpenOffice.org 3.4.1

PlanetSide 2

Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)

Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)

Security Update for Microsoft .NET Framework 4 Extended (KB2487367)

Security Update for Microsoft .NET Framework 4 Extended (KB2656351)

Security Update for Microsoft .NET Framework 4 Extended (KB2736428)

Security Update for Microsoft .NET Framework 4 Extended (KB2742595)

Steam

Update for Microsoft .NET Framework 4 Client Profile (KB2468871)

Update for Microsoft .NET Framework 4 Client Profile (KB2533523)

Update for Microsoft .NET Framework 4 Client Profile (KB2600217)

Update for Microsoft .NET Framework 4 Extended (KB2468871)

Update for Microsoft .NET Framework 4 Extended (KB2533523)

Update for Microsoft .NET Framework 4 Extended (KB2600217)

VLC media player 2.0.6

.

==== End Of File ===========================

Sorry about the code boxes, I just read a reply in another thread in this forum that said you prefer it to be in the same format as the rest of the text. I'll remember that from here on out, unfortunately, I don't see the button to be able to edit my first post otherwise I would do so.

Thanks for the help in advance!

Link to post
Share on other sites

Hi,

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

P.S. Do NOT use the attach option to put logs. Please always use NOTEPAD & Copy > Paste the contents directly into main body of the reply box.

Use a separate reply for each log, if needed.

Link to post
Share on other sites

log.txt

ESETSmartInstaller@High as CAB hook log:

OnlineScanner64.ocx - registred OK

OnlineScanner.ocx - registred OK

checkup.txt

Results of screen317's Security Check version 0.99.62

Windows 7 Service Pack 1 x64 (UAC is enabled)

Internet Explorer 9

``````````````Antivirus/Firewall Check:``````````````

Windows Firewall Enabled!

avast! Antivirus

Antivirus up to date! (On Access scanning disabled!)

`````````Anti-malware/Other Utilities Check:`````````

Malwarebytes Anti-Malware version 1.75.0.1300

Java 7 Update 17

Adobe Flash Player 11.7.700.169

Adobe Reader XI

Mozilla Firefox (20.0)

Google Chrome 26.0.1410.64

````````Process Check: objlist.exe by Laurent````````

windows defender MpCmdRun.exe

`````````````````System Health check`````````````````

Total Fragmentation on Drive C:

````````````````````End of Log``````````````````````

Link to post
Share on other sites

Also to add to the list of symptoms, it seems that certain services are not starting up consistently/correctly. Avast sometimes completely doesn't start, or it starts but is disabled, or it starts but is only partially enabled. Sometimes MBAM starts, sometimes it doesn't. Sometimes the sound starts disabled until I set a volume, this time, I don't even see the volume icon on the tray.

Link to post
Share on other sites

If you have the Windows 7 CD and you had "tried" a clean install just recently, seems to me it is probable you did NOT do it the right way.

and make yourself a note, to not have OpenOffice auto-start with Windows ----the next time, when you do have a new clean install.

You must place the Windows 7 CD in the primary CD drive.

Power off the computer.

Turn on the computer. and allow the computer to boot from CD. NOT to boot off the hardrive.

See this article as a sample reference.

I would suggest you see this page How to Do a Clean Installation with Windows 7.

I suggest you delete all existing partitions on the HDD as part of the new Windows 7 install.

IF you now have documents or files that you have not backed up, do so before starting the clean install.

For all the files, documents, personal stuff you backed-up..... after all is done & you have the new Windows setup, and Antivirus installed, and MBAM.....

then I would scan any files you restore with 1) antivirus, 2) MBAM.

If you have the Windows 7 operating system DVD, set pc to boot from it, restart the system and boot from DVD. You'll want to first delete the existing Wdinows 7 partition, then do a new install of Windows 7.

If you do not have the Windows 7 DVD, check with your pc maker's support site for the directions on doing a factory restore.

Once you have Windows restored, be sure if the OEM included any antivirus that you un-install it, and install your own.

Be sure you make a visit to Windows Update to insure your Windows is all up-to-date.

Keep your pc disconnected from internet before & during the Windows clean install.

Only reconnect after the antivirus program is installed.

IF and only if your OEM or vendor included a pre-installed antivirus, be sure to Uninstall it before installing your antivirus.

Backups are your pc's best friend.

Link to post
Share on other sites

My guess is that you did not set your BIOS boot setting to boot "first" from CD drive.

When you first power the system, look very closely at the monitor screen. It will show which Function key to use to get into Setup.

Also, look very closely at the reference I gave you before.

See this article as a sample reference.

I would suggest you see this page How to Do a Clean Installation with Windows 7.

In addition, if you would do some research on your computer manufacturer's support website they will have How to documents to both set BIOS boot sequence, and also how to do a clean install of Windows.

See DELL support forum http://en.community.dell.com/

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.