Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

hjt log


  • This topic is locked This topic is locked
21 replies to this topic

#1 lowgie

lowgie

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 27 March 2009 - 09:20 AM

I am getting 4 to 6 blue screen crashes per day
my internet is extremly slow
i am hoping by looking at my log someone can help
i posted this once before but got busy with work and couldn't check back
here is the log from today


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:02 PM, on 18/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Users\MDG User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Imgtask.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Trend Micro\Internet Security\UfNavi.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\msfeedssync.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.canoe.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mdg.ca
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {85D9F1D1-CE24-47C3-AB33-67C25132DF86} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: TransactionProtector BHO - {C1656CCA-D2EA-4A32-94AE-AE0B180E6449} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Transaction Protector - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [ImgTask] C:\Users\MDG User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Imgtask.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-3928497073-1406973687-2268716054-1003\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'kodak')
O4 - Startup: Imgtask.exe
O4 - Global Startup: Logitech SetPoint.lnk = Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = Microsoft Office\Office10\OSA.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\MDG User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - (no file)
O13 - Gopher Prefix:
O15 - Trusted Zone: www.ctv.ca
O15 - Trusted Zone: www.ctvdigital.com
O15 - Trusted Zone: http://sympatico.zone.msn.com
O15 - Trusted Zone: http://broadband.tsn.ca
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/dow...llerControl.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://209.226.48.74:81/activex/AMC.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O18 - Protocol: skyline - {3A4F9195-65A8-11D5-85C1-0001023952C1} - C:\Program Files\Skyline\TerraExplorer\TerraExplorerX.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Intel® AMT System Status Service (atchksrv) - Intel Corporation - C:\Program Files\Intel\AMT\atchksrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KodakDigitalDisplayService - Orb Networks, Inc. - C:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Intel® Active Management Technology LMS Service (LMS) - Intel - C:\Program Files\Intel\AMT\LMS.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP2\RpcAgentSrv.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

BC AdBot (Login to Remove)

 


#2 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Staff Emeritus
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the "Logic Free Zone", in Md, USA
  • Local time:02:07 AM

Posted 05 April 2009 - 04:12 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

R,
K
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)

#3 lowgie

lowgie
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 06 April 2009 - 10:48 PM

I hope I did this right
My internet connection has really been slow latly as well as the blue screen crashes





DDS (Ver_09-03-16.01) - NTFSx86
Run by MDG User at 21:39:56.09 on 06/04/2009
Internet Explorer: 8.0.6001.18372
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.91.1033.18.2029.928 [GMT -6:00]

AV: Trend Micro Internet Security Pro *On-access scanning disabled* (Updated)

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Users\MDG User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Imgtask.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kodak\Digital Display\OrbKodakLauncher\DllStartupService.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\MDG User\Desktop\dds.scr
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.canoe.ca/
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.mdg.ca
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: FCToolbarURLSearchHook Class: {d85adc0e-d2f6-45f6-b037-941a2c96c4ae} - c:\program files\icn gaming bar\Helper.dll
uURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: {85D9F1D1-CE24-47C3-AB33-67C25132DF86} - No File
BHO: FCTBPos00Pos Class: {8c7add44-d01f-4d04-b525-ae372b98afd2} - c:\program files\icn gaming bar\Toolbar.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: TSToolbarBHO: {c1656cca-d2ea-4a32-94ae-ae0b180e6449} - c:\program files\trend micro\trendsecure\transactionprotector\TSToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: Transaction Protector: {e7620c98-fccc-40e5-92ec-c7685d2e1e40} - c:\program files\trend micro\trendsecure\transactionprotector\TSToolbar.dll
TB: ICN Gaming Bar: {30bf4cea-a50c-4947-a685-48d697938bd3} - c:\program files\icn gaming bar\Toolbar.dll
uRun: [OE] c:\program files\trend micro\internet security\tmas_oe\TMAS_OEMon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [UfSeAgnt.exe] c:\program files\trend micro\internet security\UfSeAgnt.exe
mRun: [ImgTask] c:\users\mdg user\appdata\roaming\microsoft\windows\start menu\programs\startup\Imgtask.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
StartupFolder: c:\users\mdg user\appdata\roaming\microsoft\windows\start menu\programs\startup\Imgtask.exe
StartupFolder: c:\users\mdguse~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\users\mdg user\appdata\roaming\microsoft\windows\start menu\programs\imvu\Run IMVU.lnk
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D}
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
Trusted Zone: ctv.ca\www
Trusted Zone: ctvdigital.com\www
Trusted Zone: msn.com\sympatico.zone
Trusted Zone: tsn.ca\broadband
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\quicktax 2007\ic2007pp.dll
Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - c:\program files\quicktax 2008\ic2008pp.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\puresp.dll
Handler: skyline - {3a4f9195-65a8-11d5-85c1-0001023952c1} - c:\program files\skyline\terraexplorer\TerraExplorerX.dll
Notify: igfxcui - igfxdev.dll
SEH: {BA2A2046-75A4-47C0-A09C-F0DCC706D39B} - No File
LSA: Authentication Packages = msv1_0 c:\windows\system32\khfDVmJy

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-3-3 64160]
R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\drivers\tmlwf.sys [2007-9-18 141840]
R2 KodakDigitalDisplayService;KodakDigitalDisplayService;c:\program files\kodak\digital display\orbkodaklauncher\DllStartupService.exe [2008-8-8 98304]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 951632]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-9-18 36368]
R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\drivers\tmwfp.sys [2007-9-18 234512]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-8-18 52240]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-8-22 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-8-22 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-6-18 23680]
S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2008-8-18 488768]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2008-8-18 648456]
S4 h7yerotyeyiba;Print Spooler Service; [x]

=============== Created Last 30 ================

2009-03-25 21:09 <DIR> --d----- c:\program files\Hasbro Interactive
2009-03-25 18:08 144 a------- c:\windows\tmpcpyis.bat
2009-03-25 18:08 122 a------- c:\windows\tmpdelis.bat
2009-03-25 18:08 26 a------- c:\windows\winstart.bat
2009-03-25 01:54 <DIR> --d----- c:\users\mdguse~1\appdata\roaming\Malwarebytes
2009-03-25 01:54 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-03-25 01:54 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-25 01:54 <DIR> --d----- c:\programdata\Malwarebytes
2009-03-25 01:54 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-03-25 01:54 <DIR> --d----- c:\progra~2\Malwarebytes
2009-03-19 16:15 <DIR> --d----- c:\program files\common files\Windows Live
2009-03-16 12:08 <DIR> --d----- c:\program files\QuickTax 2008
2009-03-10 22:32 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-03-10 22:32 7,680 a------- c:\windows\system32\spwmp.dll
2009-03-10 22:32 4,096 a------- c:\windows\system32\msdxm.ocx
2009-03-10 22:32 4,096 a------- c:\windows\system32\dxmasf.dll
2009-03-10 22:30 268,288 a------- c:\windows\system32\schannel.dll
2009-03-10 22:30 2,033,152 a------- c:\windows\system32\win32k.sys
2009-03-10 22:18 <DIR> --d----- c:\program files\TELUS
2009-03-10 22:17 <DIR> --d----- c:\programdata\Motive
2009-03-10 22:17 <DIR> --d----- c:\program files\common files\Motive
2009-03-10 20:17 289,111,465 a------- c:\windows\MEMORY.DMP
2009-03-09 23:28 606 a------- c:\windows\Uninstall Manager.INI
2009-03-09 20:53 <DIR> --d----- c:\windows\Repair
2009-03-09 20:51 <DIR> --d----- c:\users\mdguse~1\appdata\roaming\Systweak
2009-03-09 20:51 <DIR> --d----- c:\program files\Advanced System Optimizer

==================== Find3M ====================

2009-04-06 21:20 29,634 a------- c:\users\mdguse~1\appdata\roaming\wklnhst.dat
2009-03-03 15:00 15,688 a------- c:\windows\system32\lsdelete.exe
2009-03-03 14:56 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-02-04 13:45 96,736 a------- c:\users\mdguse~1\appdata\roaming\GDIPFONTCACHEV1.DAT
2009-01-28 22:19 143,360 a------- c:\windows\inf\infstrng.dat
2009-01-28 22:19 51,200 a------- c:\windows\inf\infpub.dat
2009-01-28 22:19 86,016 a------- c:\windows\inf\infstor.dat
2009-01-15 04:05 911,872 a------- c:\windows\system32\wininet.dll
2009-01-15 04:05 43,008 a------- c:\windows\system32\licmgr10.dll
2009-01-15 04:04 18,944 a------- c:\windows\system32\corpol.dll
2009-01-15 04:04 109,056 a------- c:\windows\system32\iesysprep.dll
2009-01-15 04:04 132,096 a------- c:\windows\system32\ieUnatt.exe
2009-01-15 04:04 109,568 a------- c:\windows\system32\PDMSetup.exe
2009-01-15 04:04 107,520 a------- c:\windows\system32\RegisterIEPKEYs.exe
2009-01-15 04:04 107,008 a------- c:\windows\system32\SetIEInstalledDate.exe
2009-01-15 04:04 103,936 a------- c:\windows\system32\SetDepNx.exe
2009-01-15 04:03 420,352 a------- c:\windows\system32\vbscript.dll
2009-01-15 04:03 72,704 a------- c:\windows\system32\admparse.dll
2009-01-15 04:03 71,680 a------- c:\windows\system32\iesetup.dll
2009-01-15 04:03 66,560 a------- c:\windows\system32\wextract.exe
2009-01-15 04:02 169,472 a------- c:\windows\system32\iexpress.exe
2009-01-15 04:01 34,304 a------- c:\windows\system32\imgutil.dll
2009-01-15 04:00 48,128 a------- c:\windows\system32\mshtmler.dll
2009-01-15 04:00 45,568 a------- c:\windows\system32\mshta.exe
2009-01-15 03:50 156,160 a------- c:\windows\system32\msls31.dll
2009-01-12 15:49 111,928 a------- c:\windows\system32\PnkBstrB.exe
2009-01-11 17:22 22,328 a------- c:\users\mdguse~1\appdata\roaming\PnkBstrK.sys
2009-01-11 17:22 682,280 a------- c:\windows\system32\pbsvc.exe
2009-01-11 17:22 66,872 a------- c:\windows\system32\PnkBstrA.exe
2008-09-11 16:07 174 a--sh--- c:\program files\desktop.ini
2008-09-11 15:57 665,600 a------- c:\windows\inf\drvindex.dat
2008-06-27 14:09 553 a------- c:\users\mdg user\64.bat
2007-06-10 18:05 774,144 a------- c:\program files\RngInterstitial.dll
2006-11-02 06:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2008-04-23 20:41 16,384 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-04-23 20:41 32,768 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-11-04 11:01 16,384 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-07-05 04:28 557,353 a--sh--- c:\windows\system32\yJmVDfhk.ini2

============= FINISH: 21:40:15.75 ===============

#4 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:02:07 AM

Posted 07 April 2009 - 10:51 AM

Howdy, my name is Hoov, and I will be helping you with your dilemma.

Please make sure you watch this thread for responses. If you click the options tab at the top of your first post, you can select to track this thread.

Here is what I am asking you to do during the repair of your computer

*Tell me everything that you have done, if anything, to try and fix this problem.

*Please only use 1 forum to help clear up your problem. Posting on more than 1 and following instructions from more than 1 forum will cause those helping you to pull out thier hair.

*Follow my instructions - If you can't for some reason, or if you don't understand something, please tell me. If you deviate from my instructions, tell me, it may make a difference on where we go. Don't install anything, even other programs that have nothing to do with security or malware, it could cause things to change, and I would never know it.

*Have faith. I will do all I can to get your computer working, and if I can't - someone else here will know something else to try.

*Stick with me to the end. My aim is to fix your problems, and give you the tools and knowledge to keep this from happening again.

Now onto trying to fix your computer.

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Do you remember any of the stop codes and files from the blue screen? If not the next time you get one, write down the stop code and file associated with the crash and let me know.
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#5 lowgie

lowgie
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 08 April 2009 - 10:13 PM

Hey Hoov

I have been useing Reg Cure,Systweak Advanced System Optimizer And Malwarebytes
The problems seems to have started happening after I upgraded my processor to a core two duo and my video card to an ATI Radeon 4800 I also added a wireless router even though this computer is still wired
Also I have 4117 Quarintined files in my anti virus but when I try to look at them Trend stops responding
As for the stop codes I will try to get them on the next crash

Lowgie

#6 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:02:07 AM

Posted 09 April 2009 - 12:12 AM

You can uninstall your antivirus, and it should ask you if you want to delete the quarantine folder. Tell it yes. Then reinstall the AV scanner.
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#7 lowgie

lowgie
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 09 April 2009 - 08:33 AM

Hey Hoov

I had two crashes so far this morning
First stop was:
0X0000008E (0XC0000005, 0X8224723C, 0X95C49BDC, 0X00000000)

Then I reset my computer and got another blue screen

REFERENCE_BY_POINTER
0X00000018 (0X807BFC18, 0X97EADBF8, 0X00000002, 0X97EADBF7)
Lbd.sys - Address 807bfc18 base at 807BE000, DateStamp 49abe6f6

#8 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:02:07 AM

Posted 09 April 2009 - 11:47 AM

You say you updated the video card and the processor, do you still have the old one around? Did you update the drivers for both when you installed them?
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#9 lowgie

lowgie
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 09 April 2009 - 02:32 PM

I don't have the old processor a friend from work installed the new one. the video card is an onboard card

The drivers have been updated for the new processor and video card

Had another blue screen

MEMORY _MANAGEMENT

0X0000001A (0X00041201, 0XC0387C08, 0X353A3035, 0X8722AD50)

#10 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:02:07 AM

Posted 09 April 2009 - 02:56 PM

When you installed the new parts, did you reinstall Windows or just use the same install on the old harddrive?
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#11 lowgie

lowgie
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 09 April 2009 - 03:42 PM

Its still the same original install

But I never got a disk to reinstall windows

#12 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:02:07 AM

Posted 09 April 2009 - 03:51 PM

what is the make and model of your computer?
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#13 lowgie

lowgie
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 09 April 2009 - 10:23 PM

An MDG Apton

Another blue screen

BAD_POOL_CALLER
0X000000C2 (0X0000007, 0X0000110B, 0X00000000, 0X8545C668)

#14 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:02:07 AM

Posted 09 April 2009 - 10:34 PM

Did you get any CD's or DVD's with the computer?
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#15 lowgie

lowgie
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:12:07 AM

Posted 09 April 2009 - 10:45 PM

Nope I procrastinated and never went back to the store to get the disk its been about two and a half years since I bought this computer so not much chance of getting the disk now

Oh and guess what just after my last post another blue screen

0X0000008E (0XC0000005, 0X8246185D, 0XAAAC9C18, 0X00000000)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users