okay, i did have the .txt and to give you the virus name that i have on the receipt its written as follows "c: system 32 verscill.exe. - Well the errors are in the event log yes. I was getting bsod for weeks, but it was either my graphics card, or my network drivers, cuz i have updated them and still have to end program once in a while but no BSOD in 3 days. But i have this unkown address that was causing the BSOD, but now it just reports application hang, but no BSOD, also a few new ones like TCPIP and W32 time warnings. Also the one you mentioned but didnt look as serious as the others. I really think its not hardware i hope.
Geeks to go had me reinstall windows, and that started the BSOD, but was having minor issues at the time, with .net framework and active x for adobe, and a few others.
I have been doing minor changes that i seem to have lost when doing the reinstall. Such as settings in bios, which im not to familiar with, but needed to make some changes to some settings for stability(trying to read off my past post here, when i built it.)
ComboFix 11-10-21.01 - Josh Grassi 10/21/2011 10:59:00.4.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.3166 [GMT -4:00]
Running from: c:\combofix\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Josh Grassi\5d.jpg
c:\documents and settings\Josh Grassi\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2011-09-21 to 2011-10-21 )))))))))))))))))))))))))))))))
.
.
2011-10-21 13:21 . 2011-10-21 13:21 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D7AAC96E-C92C-4B1C-BEFE-0A4F7F7EA610}\offreg.dll
2011-10-20 17:43 . 2011-10-07 03:48 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D7AAC96E-C92C-4B1C-BEFE-0A4F7F7EA610}\mpengine.dll
2011-10-17 09:59 . 2011-10-17 15:53 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-15 04:16 . 2011-10-15 04:16 -------- d-----w- c:\documents and settings\Josh Grassi\Local Settings\Application Data\TechSmith
2011-10-13 23:14 . 2011-10-13 23:14 -------- d-----w- c:\program files\Common Files\Adobe AIR
2011-10-05 23:38 . 2011-10-05 23:38 -------- d-----w- c:\documents and settings\Josh Grassi\Application Data\NVIDIA
2011-10-05 23:20 . 2011-10-05 23:20 -------- d-----w- c:\documents and settings\UpdatusUser
2011-10-05 23:20 . 2011-10-05 23:20 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA
2011-10-05 23:19 . 2011-08-03 11:49 914024 ----a-w- c:\windows\system32\nvdispco32.dll
2011-10-05 23:19 . 2011-08-03 11:49 875112 ----a-w- c:\windows\system32\nvgenco32.dll
2011-10-05 22:10 . 2011-10-20 17:35 -------- d-----w- c:\program files\WhoCrashed
2011-10-05 22:00 . 2011-10-07 03:48 6668624 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-05 21:53 . 2011-10-05 21:53 -------- d-----w- c:\documents and settings\Josh Grassi\Application Data\Windows Search
2011-10-04 16:00 . 2011-10-04 16:00 -------- d-----w- c:\program files\Microsoft Security Client
2011-10-04 15:45 . 2011-10-04 15:45 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-10-04 15:45 . 2011-10-08 23:26 -------- d-----w- c:\program files\Windows Desktop Search
2011-10-02 18:21 . 2011-10-02 18:21 -------- d--h--w- c:\windows\msdownld.tmp
2011-10-02 02:19 . 2011-10-02 02:19 -------- d-----w- c:\program files\Common Files\Java
2011-10-02 02:18 . 2011-10-02 02:18 476904 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-10-02 02:18 . 2011-10-02 02:18 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-10-02 02:18 . 2011-10-02 02:18 -------- d-----w- c:\program files\Java
2011-09-26 23:07 . 2011-09-26 23:08 -------- d-----w- c:\documents and settings\Josh Grassi\Local Settings\Application Data\Deployment
2011-09-25 00:06 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-09-25 00:06 . 2011-08-22 23:48 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-09-25 00:06 . 2011-08-22 23:48 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-09-25 00:06 . 2011-08-22 23:48 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-09-25 00:06 . 2011-08-22 23:48 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-09-25 00:06 . 2011-08-22 23:48 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-09-25 00:06 . 2011-08-22 23:48 2000384 -c----w- c:\windows\system32\dllcache\iertutil.dll
2011-09-25 00:06 . 2011-08-23 21:48 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll
2011-09-24 23:57 . 2010-12-09 13:42 2148864 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-09-24 23:57 . 2010-12-09 13:38 2192768 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-09-24 23:57 . 2010-12-09 13:07 2027008 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-09-24 23:55 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2011-09-24 23:54 . 2009-08-06 23:24 44768 ----a-w- c:\windows\system32\wups2.dll
2011-09-24 22:35 . 2008-04-14 12:00 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll
2011-09-24 22:35 . 2008-04-14 12:00 76800 -c--a-w- c:\windows\system32\dllcache\wam51.dll
2011-09-24 22:35 . 2008-04-14 12:00 73728 -c--a-w- c:\windows\system32\dllcache\w3ext.dll
2011-09-24 22:35 . 2008-04-14 12:00 5632 -c--a-w- c:\windows\system32\dllcache\w3svapi.dll
2011-09-24 22:35 . 2008-04-14 12:00 53248 -c--a-w- c:\windows\system32\dllcache\wamreg51.dll
2011-09-24 22:35 . 2008-04-14 12:00 4608 -c--a-w- c:\windows\system32\dllcache\w3ctrs51.dll
2011-09-24 22:35 . 2008-04-14 12:00 364032 -c--a-w- c:\windows\system32\dllcache\w3svc.dll
2011-09-24 22:35 . 2008-04-14 12:00 86073 -c--a-w- c:\windows\system32\dllcache\voicesub.dll
2011-09-24 22:35 . 2008-04-14 12:00 48256 -c--a-w- c:\windows\system32\dllcache\w32.dll
2011-09-24 22:35 . 2008-04-14 12:00 426041 -c--a-w- c:\windows\system32\dllcache\voicepad.dll
2011-09-24 22:35 . 2008-04-14 12:00 76288 -c--a-w- c:\windows\system32\dllcache\uniime.dll
2011-09-24 22:33 . 2008-04-14 12:00 9728 -c--a-w- c:\windows\system32\dllcache\query.exe
2011-09-24 22:33 . 2008-04-14 12:00 7680 -c--a-w- c:\windows\system32\dllcache\pwsdata.dll
2011-09-24 22:33 . 2008-04-14 12:00 6144 -c--a-w- c:\windows\system32\dllcache\pmxgl.dll
2011-09-24 22:33 . 2008-04-14 12:00 131584 -c--a-w- c:\windows\system32\dllcache\pmxviceo.dll
2011-09-24 22:33 . 2008-04-14 12:00 11264 -c--a-w- c:\windows\system32\dllcache\pmxmcro.dll
2011-09-24 22:29 . 2008-04-14 12:00 53760 -c--a-w- c:\windows\system32\dllcache\pintlcsd.dll
2011-09-24 22:27 . 2008-04-14 12:00 20992 -c--a-w- c:\windows\system32\dllcache\permchk.dll
2011-09-24 22:26 . 2008-04-14 12:00 15360 -c--a-w- c:\windows\system32\dllcache\padrs804.dll
2011-09-24 22:26 . 2008-04-14 12:00 14336 -c--a-w- c:\windows\system32\dllcache\padrs412.dll
2011-09-24 22:26 . 2008-04-14 12:00 15872 -c--a-w- c:\windows\system32\dllcache\padrs404.dll
2011-09-24 22:26 . 2008-04-14 12:00 44544 -c--a-w- c:\windows\system32\dllcache\nsepm.dll
2011-09-24 22:26 . 2001-08-18 02:36 38912 -c--a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2011-09-24 22:26 . 2008-04-14 12:00 53248 -c--a-w- c:\windows\system32\dllcache\nextlink.dll
2011-09-24 22:25 . 2008-04-14 12:00 119808 -c--a-w- c:\windows\system32\dllcache\mtstocom.exe
2011-09-24 22:22 . 2008-04-14 12:00 92416 -c--a-w- c:\windows\system32\dllcache\mga.sys
2011-09-24 22:22 . 2008-04-14 12:00 92032 -c--a-w- c:\windows\system32\dllcache\mga.dll
2011-09-24 22:22 . 2008-04-14 12:00 85504 -c--a-w- c:\windows\system32\dllcache\metada51.dll
2011-09-24 22:22 . 2008-04-14 12:00 7680 -c--a-w- c:\windows\system32\dllcache\migregdb.exe
2011-09-24 22:22 . 2008-04-14 12:00 37888 -c--a-w- c:\windows\system32\dllcache\md5filt.dll
2011-09-24 22:22 . 2008-04-14 12:00 26624 -c--a-w- c:\windows\system32\dllcache\mdsync.dll
2011-09-24 22:22 . 2001-08-18 02:36 65536 -c--a-w- c:\windows\system32\dllcache\EXCH_mailmsg.dll
2011-09-24 22:22 . 2008-04-14 12:00 33792 -c--a-w- c:\windows\system32\dllcache\lmmib2.dll
2011-09-24 22:22 . 2008-04-14 12:00 22528 -c--a-w- c:\windows\system32\dllcache\lpdsvc.dll
2011-09-24 22:22 . 2008-04-14 12:00 22016 -c--a-w- c:\windows\system32\dllcache\logscrpt.dll
2011-09-24 22:22 . 2008-04-14 12:00 18944 -c--a-w- c:\windows\system32\dllcache\lprmon.dll
2011-09-24 22:22 . 2008-04-14 12:00 13312 -c--a-w- c:\windows\system32\dllcache\lonsint.dll
2011-09-24 22:13 . 2008-04-14 12:00 59904 -c--a-w- c:\windows\system32\dllcache\imkrinst.exe
2011-09-24 22:10 . 2008-04-14 12:00 45109 -c--a-w- c:\windows\system32\dllcache\imjpuex.exe
2011-09-24 21:59 . 2008-04-14 12:00 311359 -c--a-w- c:\windows\system32\dllcache\imepadsv.exe
2011-09-24 21:59 . 2008-04-14 12:00 86016 -c--a-w- c:\windows\system32\dllcache\imekrmbx.dll
2011-09-24 21:59 . 2008-04-14 12:00 44032 -c--a-w- c:\windows\system32\dllcache\imekrmig.exe
2011-09-24 21:59 . 2008-04-14 12:00 102463 -c--a-w- c:\windows\system32\dllcache\imepadsm.dll
2011-09-24 21:59 . 2008-04-14 12:00 106496 -c--a-w- c:\windows\system32\dllcache\imekrcic.dll
2011-09-24 21:57 . 2008-04-14 12:00 79872 -c--a-w- c:\windows\system32\dllcache\iislog51.dll
2011-09-24 21:57 . 2008-04-14 12:00 7168 -c--a-w- c:\windows\system32\dllcache\iisfecnv.dll
2011-09-24 21:57 . 2008-04-14 12:00 6656 -c--a-w- c:\windows\system32\dllcache\iissync.exe
2011-09-24 21:57 . 2008-04-14 12:00 60928 -c--a-w- c:\windows\system32\dllcache\iisclex4.dll
2011-09-24 21:57 . 2008-04-14 12:00 3584 -c--a-w- c:\windows\system32\dllcache\iismui.dll
2011-09-24 21:57 . 2008-04-14 12:00 19456 -c--a-w- c:\windows\system32\dllcache\iiscrmap.dll
2011-09-24 21:57 . 2008-04-14 12:00 25088 -c--a-w- c:\windows\system32\dllcache\iisadmin.dll
2011-09-24 21:57 . 2008-04-14 12:00 145408 -c--a-w- c:\windows\system32\dllcache\iische51.dll
2011-09-24 21:41 . 2008-04-14 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-09-24 21:41 . 2008-04-14 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-09-24 21:41 . 2008-04-14 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-09-24 21:41 . 2008-04-14 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2011-09-21 21:32 . 2011-09-21 21:32 -------- d-sh--w- c:\documents and settings\Josh Grassi\IECompatCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-09 01:59 . 2010-07-12 17:35 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-10-05 23:38 . 2009-08-12 21:00 189744 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-10-02 02:18 . 2010-04-15 05:39 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-09-26 15:41 . 2008-07-30 00:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2008-04-14 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2008-04-14 12:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-24 21:46 . 2010-06-16 22:45 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2011-09-09 09:12 . 2008-04-14 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2008-04-14 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2008-04-14 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-03 11:49 . 2011-07-27 18:09 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-08-03 11:49 . 2011-07-27 18:09 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:49 . 2011-07-27 18:09 2387560 ----a-w- c:\windows\system32\nvcuvid.dll
2011-08-03 11:49 . 2011-07-27 18:09 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-08-03 11:49 . 2011-07-27 18:09 17186816 ----a-w- c:\windows\system32\nvcompiler.dll
2011-08-03 11:49 . 2008-10-07 18:33 4210816 ----a-w- c:\windows\system32\nv4_disp.dll
2011-08-03 11:49 . 2008-10-07 18:33 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-08-03 11:49 . 2008-03-25 00:52 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-08-03 11:49 . 2008-03-25 00:52 2404864 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:49 . 2008-03-25 00:52 16191488 ----a-w- c:\windows\system32\nvoglnt.dll
2011-08-03 11:49 . 2008-03-25 00:52 146024 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-03 11:49 . 2008-03-25 00:52 145000 -c--a-w- c:\windows\system32\nvcolor.exe
2011-08-03 11:49 . 2008-03-25 00:52 13892200 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:49 . 2008-03-25 00:52 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:49 . 2007-12-05 06:41 5427200 ----a-w- c:\windows\system32\nvcuda.dll
2011-09-30 06:23 . 2011-09-26 20:22 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]
"NvMediaCenter"="NvMCTray.dll" [2011-08-03 111208]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-07-05 1632360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GEST]
2007-12-14 16:46 236040 ----a-w- c:\program files\GIGABYTE\GEST\run.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2011-08-03 11:49 111208 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-02-13 06:31 16857600 ------r- c:\windows\RTHDCPL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 17:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\GIMP-2.0\\lib\\gimp\\2.0\\plug-ins\\script-fu.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"4401:TCP"= 4401:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
S1 MpKsl44f8345f;MpKsl44f8345f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{50F533CF-3C37-4AEE-8F66-78703A230113}\MpKsl44f8345f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{50F533CF-3C37-4AEE-8F66-78703A230113}\MpKsl44f8345f.sys [?]
S1 MpKsl48c054b2;MpKsl48c054b2;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CCB7C237-F309-483B-94E1-6B010897320D}\MpKsl48c054b2.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CCB7C237-F309-483B-94E1-6B010897320D}\MpKsl48c054b2.sys [?]
S1 MpKsl8987112c;MpKsl8987112c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E7145321-804A-4201-92D6-82DEAEA6F93E}\MpKsl8987112c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E7145321-804A-4201-92D6-82DEAEA6F93E}\MpKsl8987112c.sys [?]
S1 MpKsl9414d5c4;MpKsl9414d5c4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E7145321-804A-4201-92D6-82DEAEA6F93E}\MpKsl9414d5c4.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E7145321-804A-4201-92D6-82DEAEA6F93E}\MpKsl9414d5c4.sys [?]
S1 MpKslbdfaa35f;MpKslbdfaa35f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E7145321-804A-4201-92D6-82DEAEA6F93E}\MpKslbdfaa35f.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E7145321-804A-4201-92D6-82DEAEA6F93E}\MpKslbdfaa35f.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [7/23/2009 10:30 PM 12184]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [10/5/2011 7:20 PM 2255464]
S3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [11/6/2008 4:16 PM 47624]
S3 io02;Hardware Access Driver;c:\windows\system32\io02.sys [11/19/2008 9:30 PM 2688]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/14/2008 8:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - LBEEPKE
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
TCP: DhcpNameServer = 192.168.2.6 24.92.226.11
FF - ProfilePath - c:\documents and settings\Josh Grassi\Application Data\Mozilla\Firefox\Profiles\r1nk3976.default\
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKU-Default-RunOnce-tscuninstall - c:\windows\system32\tscupgrd.exe
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-EvtMgr6 - c:\program files\Logitech\SetPointP\SetPoint.exe
MSConfigStartUp-nwiz - nwiz.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-10-21 11:01
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1844237615-706699826-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{04C61962-5FC5-7F82-5D9A-777B412E0332}\InProcServer32*]
"jabecckdgjclbmmlhdpa"=hex:6a,61,69,66,62,62,61,67,65,63,6e,68,61,63,63,65,70,
65,6e,68,00,fa
"iabeicpccgocefgfdc"=hex:6b,61,61,66,6f,6e,69,67,6b,70,6b,63,6e,67,6b,6c,6f,6a,
6d,6b,6b,70,00,00
.
Completion time: 2011-10-21 11:02:18
ComboFix-quarantined-files.txt 2011-10-21 15:02
.
Pre-Run: 726,546,513,920 bytes free
Post-Run: 726,524,043,264 bytes free
.
- - End Of File - - EBCA8AFF5EDBA085060409BF245397A7