Hi, Boopme.
1- Results from MiniToolBox:
MiniToolBox by Farbar
Ran by Me (administrator) on 01-01-2012 at 14:34:10
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************
========================= Flush DNS: ===================================
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================
802.11b/g Mini Card Wireless Adapter = Wireless Network Connection (Connected)
Realtek RTL8102E Family PCI-E Fast Ethernet NIC = Local Area Connection (Media disconnected)
# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip
# Interface IP Configuration for "Wireless Network Connection"
set address name="Wireless Network Connection" source=dhcp
set dns name="Wireless Network Connection" source=dhcp register=PRIMARY
set wins name="Wireless Network Connection" source=dhcp
# Interface IP Configuration for "Local Area Connection"
set address name="Local Area Connection" source=dhcp
set dns name="Local Area Connection" source=dhcp register=PRIMARY
set wins name="Local Area Connection" source=dhcp
popd
# End of interface IP configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : your-0d10610b06
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : hsd1.fl.comcast.net.
Ethernet adapter Wireless Network Connection:
Connection-specific DNS Suffix . : hsd1.fl.comcast.net.
Description . . . . . . . . . . . : 802.11b/g Mini Card Wireless Adapter
Physical Address. . . . . . . . . : 00-21-85-86-86-F9
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.5.108
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.5.1
DHCP Server . . . . . . . . . . . : 192.168.5.1
DNS Servers . . . . . . . . . . . : 75.75.75.75
75.75.76.76
Lease Obtained. . . . . . . . . . : Sunday, January 01, 2012 1:50:10 PM
Lease Expires . . . . . . . . . . : Monday, January 02, 2012 1:50:10 PM
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Realtek RTL8102E Family PCI-E Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-21-85-E4-A3-5C
Server: cdns01.comcast.net
Address: 75.75.75.75
Name: google.com
Addresses: 74.125.115.106, 74.125.115.103, 74.125.115.147, 74.125.115.99
74.125.115.105, 74.125.115.104
Pinging google.com [74.125.113.147] with 32 bytes of data:
Reply from 74.125.113.147: bytes=32 time=43ms TTL=52
Reply from 74.125.113.147: bytes=32 time=44ms TTL=52
Ping statistics for 74.125.113.147:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 43ms, Maximum = 44ms, Average = 43ms
Server: cdns01.comcast.net
Address: 75.75.75.75
Name: yahoo.com
Addresses: 72.30.2.43, 98.137.149.56, 98.139.180.149, 209.191.122.70
Pinging yahoo.com [72.30.2.43] with 32 bytes of data:
Reply from 72.30.2.43: bytes=32 time=94ms TTL=50
Reply from 72.30.2.43: bytes=32 time=95ms TTL=50
Ping statistics for 72.30.2.43:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 94ms, Maximum = 95ms, Average = 94ms
Server: cdns01.comcast.net
Address: 75.75.75.75
Name: bleepingcomputer.com
Address: 208.43.87.2
Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.
Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 21 85 86 86 f9 ...... 802.11b/g Mini Card Wireless Adapter - Packet Scheduler Miniport
0x3 ...00 21 85 e4 a3 5c ...... Realtek RTL8102E Family PCI-E Fast Ethernet NIC - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.5.1 192.168.5.108 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.5.0 255.255.255.0 192.168.5.108 192.168.5.108 25
192.168.5.108 255.255.255.255 127.0.0.1 127.0.0.1 25
192.168.5.255 255.255.255.255 192.168.5.108 192.168.5.108 25
224.0.0.0 240.0.0.0 192.168.5.108 192.168.5.108 25
255.255.255.255 255.255.255.255 192.168.5.108 192.168.5.108 1
255.255.255.255 255.255.255.255 192.168.5.108 3 1
Default Gateway: 192.168.5.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 18 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 19 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
========================= Event log errors: ===============================
Application errors:
==================
Error: (12/31/2011 08:20:10 AM) (Source: Application Error) (User: )
Description: Faulting application services.exe, version 5.1.2600.5755, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x00065848.
Processing media-specific event for [services.exe!ws!]
Error: (12/29/2011 05:13:51 AM) (Source: Application Error) (User: )
Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module mshtml.dll, version 8.0.6001.19170, fault address 0x00067978.
Processing media-specific event for [explorer.exe!ws!]
Error: (12/26/2011 10:23:00 PM) (Source: Application Error) (User: )
Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module mshtml.dll, version 8.0.6001.19170, fault address 0x00067978.
Processing media-specific event for [explorer.exe!ws!]
Error: (12/26/2011 06:41:21 PM) (Source: Microsoft Office 11) (User: )
Description: Rejected Safe Mode action : Microsoft Office Word.
Error: (12/25/2011 03:08:12 PM) (Source: Application Hang) (User: )
Description: Fault bucket 1180947459.
Error: (12/25/2011 03:08:09 PM) (Source: Application Hang) (User: )
Description: Hanging application iexplore.exe, version 8.0.6001.18702, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
System errors:
=============
Error: (01/01/2012 01:50:27 PM) (Source: Windows Update Agent) (User: )
Description: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
Error: (12/30/2011 10:45:45 PM) (Source: 0) (User: )
Description: MSHOME :1d192.168.5.108192.168.5.102
Error: (12/30/2011 10:40:35 PM) (Source: 0) (User: )
Description: MSHOME :1d192.168.5.108192.168.5.102
Error: (12/30/2011 10:35:25 PM) (Source: 0) (User: )
Description: MSHOME :1d192.168.5.108192.168.5.102
Error: (12/30/2011 10:44:48 AM) (Source: Windows Update Agent) (User: )
Description: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the set schedule. Windows will continue to try to establish a connection.
Error: (12/29/2011 11:31:31 AM) (Source: Dhcp) (User: )
Description: The IP address lease 192.168.5.108 for the Network Card with network address 002185E4A35C has been
denied by the DHCP server 192.168.5.1 (The DHCP Server sent a DHCPNACK message).
Error: (12/29/2011 06:18:48 AM) (Source: SideBySide) (User: )
Description: Generate Activation Context failed for C:\DOCUME~1\Me\LOCALS~1\Temp\nssD.tmp\NasDetectPlugin.dll.
Reference error message: The operation completed successfully.
.
Error: (12/29/2011 06:18:47 AM) (Source: SideBySide) (User: )
Description: Resolve Partial Assembly failed for Microsoft.VC90.CRT.
Reference error message: The referenced assembly is not installed on your system.
.
Error: (12/29/2011 06:18:47 AM) (Source: SideBySide) (User: )
Description: Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
Error: (12/29/2011 04:37:42 AM) (Source: System Error) (User: )
Description: Error code 1000000a, parameter1 967cd4f2, parameter2 00000002, parameter3 00000001, parameter4 80522d11.
Microsoft Office Sessions:
=========================
=========================== Installed Programs ============================
Adobe Flash Player 11 ActiveX (Version: 11.1.102.55)
Adobe Photoshop Elements 2.0 (Version: 2.0)
Adobe Reader 8.1.2 (Version: 8.1.2)
Bluetooth Stack for Windows by Toshiba (Version: v6.00.03)
BurnRecovery (Version: 1.00.0613)
Intel® Graphics Media Accelerator Driver
LaserJet 1020 series
MagicCute Data Recovery 2011.1
Malwarebytes Anti-Malware version 1.60.0.1800 (Version: 1.60.0.1800)
Memeo Instant Backup (Version: 4.60.0.7916)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft Office Professional Edition 2003 (Version: 11.0.5614.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
MiniTool Partition Wizard Home Edition 7.0
Norton Security Suite (Version: 5.1.0.29)
REALTEK GbE & FE Ethernet PCI-E NIC Driver (Version: 1.16.0001)
Realtek High Definition Audio Driver (Version: 5.10.0.5618)
Seagate Dashboard (Version: 1.1.0.1548)
System Control Manager (Version: 2.0208.0807.001)
Ulead Burn.Now 4.5 (Version: 4.5.0)
Ulead Burn.Now 4.5 SE (Version: 4.5.0)
USB 2.0 Card Reader (Version: 1.0.0.0)
WebFldrs XP (Version: 9.50.7523)
Windows Driver Package - Atheros (AR5416) Net (04/08/2008 7.6.0.200) (Version: 04/08/2008 7.6.0.200)
Windows Driver Package - Ralink Technology, Corp. (RT80x86) Net (05/19/2008 1.01.03.0000) (Version: 05/19/2008 1.01.03.0000)
Windows Driver Package - Realtek (rtl8187Se) Net (07/10/2008 5.9067.0710.2008) (Version: 07/10/2008 5.9067.0710.2008)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Internet Explorer 8 (Version: 20090308.140743)
WinRAR archiver
WinTree
WinZip 11.1 (Version: 11.1.7466)
========================= Devices: ================================
========================= Memory info: ===================================
Percentage of memory in use: 41%
Total physical RAM: 2037.23 MB
Available physical RAM: 1192.73 MB
Total Pagefile: 3929.42 MB
Available Pagefile: 3137.92 MB
Total Virtual: 2047.88 MB
Available Virtual: 1961.28 MB
========================= Partitions: =====================================
1 Drive c: (OS_Install) (Fixed) (Total:107.88 GB) (Free:16.18 GB) NTFS
2 Drive d: (USB20FD) (Removable) (Total:7.53 GB) (Free:7.43 GB) FAT32
3 Drive x: (GoFlex Home Public) (Network) (Total:1863.01 GB) (Free:1861.75 GB) NTFS
4 Drive y: (GoFlex Home Backup) (Network) (Total:1863.01 GB) (Free:1861.75 GB) NTFS
5 Drive z: (GoFlex Home Personal) (Network) (Total:1863.01 GB) (Free:1861.75 GB) NTFS
========================= Users: ========================================
User accounts for \\YOUR-0D10610B06
Administrator Guest HelpAssistant
Me SUPPORT_388945a0
========================= Minidump Files ==================================
C:\WINDOWS\Minidump\Mini122911-01.dmp
**** End of log ****
2- The program TDSSKiller refuses to run on this laptop, neither from the desktop nor from an external drive. When I double-click it, nothing happens. It runs fine in other computers in the house, though.
3- The log from MBAM is as follows:
Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org
Database version: v2011.12.31.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Me :: YOUR-0D10610B06 [administrator]
Protection: Enabled
1/1/2012 3:15:35 PM
mbam-log-2012-01-01 (15-15-35).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 179923
Time elapsed: 4 minute(s), 41 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
4- As a final note, MalwareBytes keeps popping this message:
Malwarebytes Anti-Malware
Successfully blocked access to a potential malicious website: 206.161.121.2
These IP addresses varies from 206.161.121.3 to 206.161.121.4
Thank-you,
Dilson.