Thank you for all your help. Here are the reports you requested:
CHECKUP
Results of screen317's Security Check version 0.99.7
Windows Vista Service Pack 2
(UAC is disabled!)
Internet Explorer 7
Out of date!
``````````````````````````````
Antivirus/Firewall Check:
Windows Security Center service is not running! This report may not be accurate!
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:
Malwarebytes' Anti-Malware
Java 6 Update 5
Out of date Java installed!
Adobe Flash Player
Adobe Reader 8.1.2
Out of date Adobe Reader installed!
Mozilla Firefox (x86 en-US..)
Firefox Out of Date!
````````````````````````````````
Process Check:
objlist.exe by Laurent
Windows Defender MSASCui.exe
Windows Defender MSASCui.exe
``````````End of Log````````````
MINITOOL RESULT:
MiniToolBox by Farbar
Ran by NANA (administrator) on 09-07-2011 at 16:08:43
Windows Vista Home Basic Service Pack 2 (X86)
***************************************************************************
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
========================= End of IE Proxy Settings ========================
=============== Hosts content: ============================================
# Copyright © 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
127.0.0.1 localhost
::1 localhost
=============== End of Hosts ==============================================
================= IP Configuration: =======================================
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
reset
set global icmpredirects=enabled
popd
# End of IPv4 configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : NANA-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : tampabay.rr.com
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : tampabay.rr.com
Description . . . . . . . . . . . : NVIDIA nForce 10/100 Mbps Ethernet
Physical Address. . . . . . . . . : 00-21-97-30-13-1E
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::41ee:cdc2:1b68:dcae%10(Preferred)
IPv4 Address. . . . . . . . . . . : 70.126.236.219(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.248.0
Lease Obtained. . . . . . . . . . : Saturday, July 09, 2011 4:02:51 PM
Lease Expires . . . . . . . . . . : Sunday, July 10, 2011 4:02:52 AM
Default Gateway . . . . . . . . . : 70.126.232.1
DHCP Server . . . . . . . . . . . : 10.126.128.1
DHCPv6 IAID . . . . . . . . . . . : 251666064
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-9A-AB-B5-00-21-97-30-13-1E
DNS Servers . . . . . . . . . . . : 65.32.5.111
65.32.5.112
NetBIOS over Tcpip. . . . . . . . : Enabled
Tunnel adapter Local Area Connection* 6:
Connection-specific DNS Suffix . : tampabay.rr.com
Description . . . . . . . . . . . : 6TO4 Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2002:467e:ecdb::467e:ecdb(Preferred)
Default Gateway . . . . . . . . . : 2002:c058:6301::c058:6301
DNS Servers . . . . . . . . . . . : 65.32.5.111
65.32.5.112
NetBIOS over Tcpip. . . . . . . . : Disabled
Tunnel adapter Local Area Connection* 11:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 02-00-54-55-4E-01
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:106a:273c:b981:1324(Preferred)
Link-local IPv6 Address . . . . . : fe80::106a:273c:b981:1324%12(Preferred)
Default Gateway . . . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Disabled
Tunnel adapter Local Area Connection* 12:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : tampabay.rr.com
Description . . . . . . . . . . . : isatap.tampabay.rr.com
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: dns-redir-lb-01.tampabay.rr.com
Address: 65.32.5.111
Name: google.com
Addresses: 74.125.45.99
74.125.45.103
74.125.45.104
74.125.45.105
74.125.45.106
74.125.45.147
Pinging google.com [74.125.45.147] with 32 bytes of data:
Reply from 74.125.45.147: bytes=32 time=29ms TTL=53
Reply from 74.125.45.147: bytes=32 time=40ms TTL=53
Ping statistics for 74.125.45.147:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 29ms, Maximum = 40ms, Average = 34ms
Server: dns-redir-lb-01.tampabay.rr.com
Address: 65.32.5.111
Name: yahoo.com
Addresses: 69.147.125.65
72.30.2.43
98.137.149.56
209.191.122.70
67.195.160.76
Pinging yahoo.com [69.147.125.65] with 32 bytes of data:
Reply from 69.147.125.65: bytes=32 time=55ms TTL=53
Reply from 69.147.125.65: bytes=32 time=70ms TTL=53
Ping statistics for 69.147.125.65:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 55ms, Maximum = 70ms, Average = 62ms
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
10 ...00 21 97 30 13 1e ...... NVIDIA nForce 10/100 Mbps Ethernet
1 ........................... Software Loopback Interface 1
11 ...00 00 00 00 00 00 00 e0 6TO4 Adapter
12 ...02 00 54 55 4e 01 ...... Teredo Tunneling Pseudo-Interface
13 ...00 00 00 00 00 00 00 e0 isatap.tampabay.rr.com
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 70.126.232.1 70.126.236.219 20
70.126.232.0 255.255.248.0 On-link 70.126.236.219 276
70.126.236.219 255.255.255.255 On-link 70.126.236.219 276
70.126.239.255 255.255.255.255 On-link 70.126.236.219 276
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 70.126.236.219 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 70.126.236.219 276
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
11 1125 ::/0 2002:c058:6301::c058:6301
1 306 ::1/128 On-link
12 18 2001::/32 On-link
12 266 2001:0:4137:9e76:106a:273c:b981:1324/128
On-link
11 1025 2002::/16 On-link
11 281 2002:467e:ecdb::467e:ecdb/128
On-link
10 276 fe80::/64 On-link
12 266 fe80::/64 On-link
12 266 fe80::106a:273c:b981:1324/128
On-link
10 276 fe80::41ee:cdc2:1b68:dcae/128
On-link
1 306 ff00::/8 On-link
12 266 ff00::/8 On-link
10 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
================= End of IP Configuration =================================
========================= Event log errors: ===============================
Application errors:
==================
Error: (07/09/2011 04:04:13 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/09/2011 04:03:03 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/09/2011 04:03:03 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/09/2011 04:03:03 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/09/2011 04:03:03 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0"1".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (07/09/2011 02:53:07 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/09/2011 02:49:23 PM) (Source: Application Error) (User: )
Description: Faulting application svchost.exe, version 6.0.6001.18000, time stamp 0x47918b89, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436, exception code 0xc000071b, fault offset 0x00088d15,
process id 0xdf0, application start time 0xsvchost.exe0.
Error: (07/09/2011 02:27:46 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (07/09/2011 02:22:34 PM) (Source: Application Error) (User: )
Description: Faulting application svchost.exe, version 6.0.6001.18000, time stamp 0x47918b89, faulting module ntdll.dll, version 6.0.6002.18327, time stamp 0x4cb73436, exception code 0xc000071b, fault offset 0x00088d15,
process id 0x444, application start time 0xsvchost.exe0.
Error: (07/09/2011 01:33:01 PM) (Source: System Restore) (User: )
Description: Failed to create restore point on volume (Process = C:\Windows\system32\svchost.exe -k netsvcs; Descripton = Windows Update; Hr = 0x800423f4).
System errors:
=============
Error: (07/09/2011 04:02:42 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 4:01:05 PM on 7/9/2011 was unexpected.
Error: (07/09/2011 03:34:53 PM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (07/09/2011 02:28:32 PM) (Source: Print) (User: NANA)
Description: The document
http://dealspl.us/chuckecheese-coupons/286843p, owned by NANA, failed to print on printer Canon iP3500 series. Try to print the document again, or restart the print spooler.
Data type: NT EMF 1.008. Size of the spool file in bytes: 2114984. Number of bytes printed: 2106088. Total number of pages in the document: 2. Number of pages printed: 0. Client computer: \\NANA-PC. Win32 error code returned by the print processor:
http://dealspl.us/chuckecheese-coupons/286843p0. http://dealspl.us/chuckecheese-coupons/286843p1
Error: (07/09/2011 02:27:49 PM) (Source: Service Control Manager) (User: )
Description: 1Restart the serviceWindows Management Instrumentation%%1056
Error: (07/09/2011 00:57:21 AM) (Source: Service Control Manager) (User: )
Description: 1Restart the serviceWindows Management Instrumentation%%1056
Error: (07/08/2011 11:26:18 PM) (Source: EventLog) (User: )
Description: The previous system shutdown at 11:24:34 PM on 7/8/2011 was unexpected.
Error: (07/08/2011 08:12:39 PM) (Source: Service Control Manager) (User: )
Description: 1Restart the serviceWindows Management Instrumentation%%1056
Error: (07/08/2011 05:33:20 PM) (Source: Service Control Manager) (User: )
Description: 1Restart the serviceWindows Management Instrumentation%%1056
Error: (07/08/2011 03:04:22 PM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (07/08/2011 02:44:49 PM) (Source: Service Control Manager) (User: )
Description: 1Restart the serviceWindows Management Instrumentation%%1056
Microsoft Office Sessions:
=========================
========================= End of Event log errors =========================
========================= Memory info: ====================================
Percentage of memory in use: 62%
Total physical RAM: 893.76 MB
Available physical RAM: 333.93 MB
Total Pagefile: 2051.75 MB
Available Pagefile: 1320.29 MB
Total Virtual: 2047.88 MB
Available Virtual: 1960.52 MB
======================= Partitions: =======================================
1 Drive c: (OS) (Fixed) (Total:139.05 GB) (Free:118.53 GB) NTFS
================= Users: ==================================================
User accounts for \\NANA-PC
-------------------------------------------------------------------------------
Administrator Guest NANA
The command completed successfully.
================= End of Users ============================================
MALWAREBYTES:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 7030
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
7/9/2011 4:14:14 PM
mbam-log-2011-07-09 (16-14-14).txt
Scan type: Quick scan
Objects scanned: 149680
Time elapsed: 4 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER:
GMER 1.0.15.15640 -
http://www.gmer.net
Rootkit scan 2011-07-09 22:23:18
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000032 Hitachi_ rev.GMBO
Running: p0enrv73.exe; Driver: C:\Users\NANA\AppData\Local\Temp\pxldqpow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8980D340, 0x3D9767, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\Explorer.EXE[204] ntdll.dll!NtProtectVirtualMemory 76FD4B84 5 Bytes JMP 02D4000A
.text C:\Windows\Explorer.EXE[204] ntdll.dll!NtWriteVirtualMemory 76FD54C4 5 Bytes JMP 02D5000A
.text C:\Windows\Explorer.EXE[204] ntdll.dll!KiUserExceptionDispatcher 76FD5BF8 5 Bytes JMP 02CB000A
.text C:\Windows\system32\svchost.exe[1088] ntdll.dll!NtProtectVirtualMemory 76FD4B84 5 Bytes JMP 0038000A
.text C:\Windows\system32\svchost.exe[1088] ntdll.dll!NtWriteVirtualMemory 76FD54C4 5 Bytes JMP 0039000A
.text C:\Windows\system32\svchost.exe[1088] ntdll.dll!KiUserExceptionDispatcher 76FD5BF8 5 Bytes JMP 0037000A
.text C:\Windows\system32\wuauclt.exe[3212] ntdll.dll!NtProtectVirtualMemory 76FD4B84 5 Bytes JMP 006E000A
.text C:\Windows\system32\wuauclt.exe[3212] ntdll.dll!NtWriteVirtualMemory 76FD54C4 5 Bytes JMP 006F000A
.text C:\Windows\system32\wuauclt.exe[3212] ntdll.dll!KiUserExceptionDispatcher 76FD5BF8 5 Bytes JMP 006C000A
---- Devices - GMER 1.0.15 ----
Device \Device\00000047 -> \??\SCSI#Disk&Ven_Hitachi&Prod_HDP725016GLA#4&2a8602f4&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- EOF - GMER 1.0.15 ----
Marta Mendez