Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Multiple Windows XP problems

$
0
0
here and here just to name a couple. Was told to post here for Multiple Windows XP problems. Please note I don't log onto this computer very often for KVM switch reasons

UNABLE TO GET GMER LOGS, THE PROGRAM FROZE EVERY TIME IT OPENED

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 11.31.2
Run by Naked Skyla at 13:16:36 on 2015-04-10
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2039.1137 [GMT -4:00]
.
AV: Computer Security *Enabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: COMODO Firewall *Enabled*
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Frontier\fshoster32.exe
C:\Program Files\Frontier\apps\ComputerSecurity\Common\FSM32.EXE
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PeerBlock\peerblock.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\Program Files\TeamViewer\TeamViewer.exe
C:\Program Files\Frontier\fshoster32.exe
C:\Program Files\Frontier\apps\CCF_Reputation\fsorsp.exe
C:\Program Files\Frontier\apps\ComputerSecurity\Anti-Virus\FSGK32.EXE
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\TeamViewer\TeamViewer_Service.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Frontier\apps\ComputerSecurity\Common\FSMA32.EXE
C:\Program Files\TeamViewer\tv_w32.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Frontier\apps\ComputerSecurity\Anti-Virus\fssm32.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
BHO: FsIeHttps Class: {45BBE08D-81C5-4A67-AF20-B2A077C67747} - c:\program files\frontier\apps\ccf_scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.8.0_31\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre1.8.0_31\bin\jp2ssv.dll
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [F-Secure Hoster (53784)] "c:\program files\frontier\fshoster32.exe" -app -hosterid:1
mRun: [F-Secure Manager] "c:\program files\frontier\apps\computersecurity\common\FSM32.EXE" /splash
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
StartupFolder: c:\docume~1\nakeds~1\startm~1\programs\startup\peerbl~1.lnk - c:\program files\peerblock\peerblock.exe
StartupFolder: c:\documents and settings\naked skyla\start menu\programs\startup\Pokémon.txt
StartupFolder: c:\docume~1\nakeds~1\startm~1\programs\startup\powerm~1.lnk - c:\program files\powermenu\PowerMenu.exe
StartupFolder: c:\docume~1\nakeds~1\startm~1\programs\startup\teamvi~1.lnk - c:\program files\teamviewer\TeamViewer.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
TCP: NameServer = 192.168.254.254
TCP: Interfaces\{4DA23E03-D19C-49A4-BC7F-5AC6120FAFC0} : DHCPNameServer = 192.168.254.254
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\naked skyla\application data\mozilla\firefox\profiles\k89ew9lx.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/?gws_rd=ssl
FF - plugin: c:\program files\java\jre1.8.0_31\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre1.8.0_31\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_17_0_0_134.dll
.
============= SERVICES / DRIVERS ===============
.
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [2015-3-13 44240]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2014-6-27 243128]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\frontier\apps\computersecurity\hips\drivers\fshs.sys [2015-3-13 74920]
R2 fshoster;F-Secure Dll Hoster;c:\program files\frontier\fshoster32.exe [2014-2-19 187432]
R2 FSORSPClient;F-Secure ORSP Client;c:\program files\frontier\apps\ccf_reputation\fsorsp.exe [2013-6-10 60456]
R2 TeamViewer;TeamViewer 10;c:\program files\teamviewer\TeamViewer_Service.exe [2015-4-1 5448464]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\frontier\apps\computersecurity\anti-virus\minifilter\fsgk.sys [2015-3-13 152104]
R3 fsni;fsni;c:\program files\frontier\apps\ccf_scanning\bin\fsnixp32.sys [2014-6-23 51752]
R3 fsnitdi;fsnitdi;c:\program files\frontier\apps\ccf_scanning\bin\fsnitdi32.sys [2014-6-23 24104]
R3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2014-6-25 19016]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\nakeds~1\locals~1\temp\sas_selfextract\sasdifsv.sys --> c:\docume~1\nakeds~1\locals~1\temp\sas_selfextract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\nakeds~1\locals~1\temp\sas_selfextract\saskutil.sys --> c:\docume~1\nakeds~1\locals~1\temp\sas_selfextract\SASKUTIL.SYS [?]
S2 ialmnt5;Controller Hub for Intel Graphics Driver;c:\program files\intelr 82845gglgepegv graphics controller\ialmnt5.exe "c:\program files\common files\intelr 82845gglgepegv graphics controller\ialmnt5.dat" --> c:\program files\intelr 82845gglgepegv graphics controller\ialmnt5.exe c:\program files\common files\intelr 82845gglgepegv graphics controller\ialmnt5.dat [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2014-7-4 27064]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== Created Last 30 ================
.
2015-04-10 16:20:59 42096 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2015-04-10 16:04:46 -------- d-----w- c:\program files\MSXML 4.0
2015-04-10 14:31:54 265728 -c----w- c:\windows\system32\dllcache\http.sys
2015-04-10 14:31:40 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll
2015-04-10 14:27:54 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll
2015-04-10 14:27:54 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll
2015-04-10 14:15:39 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2015-04-08 23:07:28 -------- d-----w- c:\windows\system32\QuickTime
2015-04-08 23:07:19 -------- d-----w- c:\program files\OLYMPUS
2015-04-08 23:06:48 319488 ------w- c:\windows\system32\Pvmjpg21.dll
2015-04-08 23:06:45 9688 ------w- c:\windows\system32\drivers\cdrbsvsd.sys
2015-04-08 23:06:45 13184 ------w- c:\windows\system32\drivers\bsaspi32.sys
2015-04-08 23:06:31 13567 ------w- c:\windows\system32\drivers\CDRBSDRV.SYS
2015-04-08 23:01:15 -------- d-----w- c:\program files\PIXELA
2015-04-08 23:01:05 32768 ----a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2015-04-08 23:01:04 237568 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iscript.dll
2015-04-08 23:01:04 155648 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iuser.dll
2015-04-08 23:01:03 57344 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\ctor.dll
2015-04-08 23:01:03 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\DotNetInstaller.exe
2015-04-08 23:01:02 692224 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iKernel.dll
2015-04-08 23:01:00 163972 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\iGdi.dll
2015-04-08 23:00:59 282756 ----a-w- c:\program files\common files\installshield\professional\runtime\0701\intel32\setup.dll
2015-04-08 22:58:34 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2015-04-08 22:58:34 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2015-04-08 22:58:34 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2015-04-08 22:58:33 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2015-04-08 22:58:33 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2015-04-08 22:54:29 -------- d-----w- c:\documents and settings\naked skyla\local settings\application data\Apple
2015-04-08 22:53:47 -------- d-----w- c:\documents and settings\naked skyla\local settings\application data\Apple Computer
2015-04-08 22:31:23 126976 -c----w- c:\windows\system32\dllcache\ftpsvc2.dll
2015-04-01 19:32:50 188494 -c--a-w- c:\windows\system32\dllcache\fpcount.exe
2015-04-01 18:46:48 -------- d-----w- c:\program files\MSDN
2015-04-01 18:37:23 -------- d-----w- c:\documents and settings\naked skyla\local settings\application data\Microsoft Help
2015-04-01 18:19:20 -------- d-----w- c:\program files\Microsoft ACT
2015-04-01 18:19:20 -------- d-----w- c:\program files\HTML Help Workshop
2015-04-01 18:19:20 -------- d-----w- c:\program files\common files\Merge Modules
2015-04-01 18:19:20 -------- d-----w- c:\program files\common files\Crystal Decisions
2015-04-01 18:01:21 -------- d-----w- c:\windows\IIS Temporary Compressed Files
2015-04-01 17:56:54 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll
2015-04-01 17:55:25 -------- d-----w- C:\Inetpub
2015-04-01 17:06:53 3686150 ----a-w- c:\windows\Sylveon.scr
2015-04-01 17:06:52 -------- d-----w- c:\windows\Sylveon Uninstaller
2015-03-29 21:41:12 -------- d-----w- c:\documents and settings\naked skyla\local settings\application data\ApplicationHistory
2015-03-29 21:35:07 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2015-03-29 21:35:07 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2015-03-22 16:49:25 -------- d-----w- c:\documents and settings\naked skyla\local settings\application data\Thinstall
2015-03-22 16:49:25 -------- d-----w- c:\documents and settings\naked skyla\application data\Thinstall
2015-03-22 15:14:15 -------- d-----w- c:\windows\system32\URTTemp
2015-03-21 00:55:41 -------- d-----w- C:\dotnet
2015-03-13 20:36:31 44240 ----a-w- c:\windows\system32\drivers\fsbts.sys
2015-03-13 20:29:01 -------- d-sh--w- c:\documents and settings\naked skyla\PrivacIE
.
==================== Find3M ====================
.
2015-03-13 20:22:22 778928 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-03-13 20:22:21 142512 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-03-06 17:56:47 153088 ----a-w- c:\windows\system32\schannel.dll
2015-02-26 07:55:04 1891840 ----a-w- c:\windows\system32\win32k.sys
2015-02-20 02:39:25 294400 ----a-w- c:\windows\system32\atmfd.dll
2015-02-12 19:07:06 920064 ----a-w- c:\windows\system32\wininet.dll
2015-02-12 19:07:05 43520 ----a-w- c:\windows\system32\licmgr10.dll
2015-02-12 19:07:05 420864 ----a-w- c:\windows\system32\vbscript.dll
2015-02-12 19:07:05 19456 ----a-w- c:\windows\system32\corpol.dll
2015-02-12 19:07:05 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2015-02-12 06:01:36 385024 ----a-w- c:\windows\system32\html.iec
2015-02-06 17:35:29 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-02-06 17:35:23 146432 ----a-w- c:\windows\system32\javacpl.cpl
2015-02-06 07:14:36 2193536 ----a-w- c:\windows\system32\ntoskrnl.exe
2015-02-06 06:35:37 2070144 ----a-w- c:\windows\system32\ntkrnlpa.exe
2015-01-22 01:45:13 300032 ----a-w- c:\windows\system32\msctf.dll
2015-01-15 01:10:27 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
.
============= FINISH: 13:20:09.21 ===============

Attached Files
File Type: zip attach.zip (3.5 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles