Hello.
As I was told to create a new thread, I'll now do it and I'll write exactly the same, but this time, I'll post my log files in the first post too.
Hi.
A while ago I suddenly realised that I couldn't update with Windows Update, and even though I've followed the guide precisly, it still reports errors.
Now, more recently, everytime I turn on my computer, atleast a few apps crashes. Normally it's steam or such, but it can also be something more critical as Windows or Explorer (which then needs a restart).
This results in a lot of things, for instance, I've bought a new monitor and I can't install the driver, because when I install it, the app crashes instantly.
I've also begun getting these little windows in Firefox called simply "adds" and it asks me with which program I'd like to open them. I just close them.
Also, my anti-virus-program (Panda) alerts me every 30th minute, that a virus was found and neutralized.
What do I do?? I've consulted a Microsoft supporter who wasn't very helpful.
I've used the program GMER.exe and DDR.scr and got the logs.
Thanks!
DDS (Ver_09-10-26.01) - NTFSx86
Run by Alexander at 21:13:56,85 on 27-12-2009
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.45.1030.18.2038.973 [GMT 1:00]
AV: Panda Antivirus 2008 *On-access scanning enabled* (Updated) {EEE2D94A-D4C1-421A-AB2C-2CE8FE51747A}
SP: Panda Antivirus 2008 *enabled* (Updated) {FE6602D3-1E71-4EBB-B4E3-D1C9CBDAF0A1}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Panda Security\Panda Antivirus 2008\PskSvc.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrvx86.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Windows\system32\taskeng.exe
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Windows\TEMP\e.exe
C:\Windows\TEMP\c.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Programmer\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programmer\HP\Digital Imaging\bin\hpqbam08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\psimreal.exe
C:\Users\Alexander\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Users\Alexander\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Alexander\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/sp/*
http://uk.yahoo.com
uStart Page = about
:blank
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://da.intl.acer.yahoo.com
mDefault_Page_URL = hxxp://da.intl.acer.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://uk.rd.yahoo.com/customize/ycomp/defaults/su/*
http://uk.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
mWinlogon: Userinit=\\.\globalroot\systemroot\system32\userinit.exe,
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: {C3CD744D-2FAE-4640-8297-16B5DA423104} - No File
uRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [Google Update] "c:\users\alexander\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
dRun: [ZagrebLand] c:\windows\temp\c.exe
dRun: [RegistryMonitor1] "c:\windows\temp\nnpp.tmp"
dRun: [LosAlamos] rundll32.exe c:\windows\temp\sshnas.dll,NvTaskbarInit
dRun: [cbssreg] c:\windows\temp\mhwy.tmp
StartupFolder: c:\users\alexan~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\screen clipper and launcher til onenote 2007.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\programmer\hp\digital imaging\bin\hpqtra08.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&ksporter til Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\panda security\panda antivirus 2008\pavlsp.dll
DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} - hxxp://downol.dr.dk/download/netradio/Rawflow.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldda-dk.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Notify: avldr - avldr.dll
Notify: igfxcui - igfxdev.dll
STS: COM+ Service: {3229dfcd-3eaf-4712-ed45-4876fedc170c} - c:\windows\system32\winload.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\alexan~1\appdata\roaming\mozilla\firefox\profiles\uuajdusf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.dk
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=58819&ei=utf-8&yahoo_domain=search.yahoo.com&p=
FF - component: c:\program files\mozilla firefox\extensions\info@google.com\components\FFLocal.dll
FF - component: c:\users\alexander\appdata\roaming\mozilla\firefox\profiles\uuajdusf.default\extensions\{916ab64c-bc3e-471b-8e60-29551922a7ba}\components\Engine.dll
FF - plugin: c:\program files\java\jre6\bin\npdeploytk.dll
FF - plugin: c:\program files\java\jre6\bin\npjpi160_17.dll
FF - plugin: c:\program files\java\jre6\bin\npoji610.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\alexander\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
============= SERVICES / DRIVERS ===============
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [2009-11-2 38968]
R2 AmFSM;AmFSM;c:\windows\system32\drivers\amm8660.sys [2009-11-2 46648]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Starttjeneste;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-16 30312]
R2 IAANTMON;Intel(R) Matrix Storage Event Monitor;c:\program files\intel\intel matrix storage manager\IAANTmon.exe [2007-7-11 355096]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [2009-11-2 178872]
R2 PskSvcRetail;Panda PSK service;c:\program files\panda security\panda antivirus 2008\psksvc.exe [2009-11-2 27696]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-11-2 1153368]
R2 TeamViewer4;TeamViewer 4;c:\program files\teamviewer\version4\TeamViewer_Service.exe [2008-12-15 185640]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-12-10 223232]
S3 BthAvrcp;Bluetooth AVRCP-profil;c:\windows\system32\drivers\BthAvrcp.sys [2008-7-10 15872]
S3 btnetBUs;Bluetooth PAN Bus Service;c:\windows\system32\drivers\btnetBus.sys [2009-6-17 29192]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2009-6-3 33792]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2009-5-27 29262680]
S3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [2008-5-28 23096]
S3 MusCVideo32;MusCVideo32;c:\windows\system32\drivers\MusCVideo32.sys [2008-5-28 3768]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [2008-1-25 25088]
S3 USBAAPL;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl.sys [2009-8-28 40448]
============== File Associations ===============
txtfile=%windir%\NOTEPAD.EXE %1
=============== Created Last 30 ================
2009-12-22 21:45:36 0 d-----w- c:\program files\ZC2.10
2009-12-21 18:02:22 819200 ----a-w- c:\windows\system32\xvidcore.dll
2009-12-21 18:02:22 77824 ----a-w- c:\windows\system32\xvid.ax
2009-12-21 18:02:22 180224 ----a-w- c:\windows\system32\xvidvfw.dll
2009-12-21 18:02:22 0 d-----w- c:\program files\Xvid
2009-12-19 13:30:51 0 d-----w- c:\users\alexander\.zsdx
2009-12-19 13:30:32 0 d-----w- c:\program files\Zelda Mystery of Solarus DX demo
2009-12-08 14:53:45 0 d-----w- c:\windows\system32\catroot2
2009-12-05 16:57:45 0 d-----w- c:\windows\CheckSur
==================== Find3M ====================
2009-12-27 20:03:48 51200 ----a-w- c:\windows\inf\infpub.dat
2009-12-27 20:03:48 143360 ----a-w- c:\windows\inf\infstrng.dat
2009-12-27 19:51:31 94802 ----a-w- c:\windows\system32\perfc006.dat
2009-12-27 19:51:31 510130 ----a-w- c:\windows\system32\perfh006.dat
2009-12-27 19:50:05 143360 ----a-w- c:\windows\inf\infstor.dat
2009-11-12 09:10:28 70671 ----a-w- c:\windows\Huawei ModemsUninstall.exe
2009-11-02 19:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-20 10:43:54 8256 ----a-w- c:\windows\system32\mt_32.dll
2009-10-20 10:43:50 3584 ----a-w- c:\windows\system32\fdclient.dll
2009-10-20 10:43:28 7680 ----a-w- c:\windows\system32\protect.dll
2009-10-20 10:43:20 3584 ----a-w- c:\windows\system32\pxcrt.dll
2009-10-20 10:43:08 18944 ----a-w- c:\windows\system32\browsearch.dll
2009-10-20 10:43:03 19968 ----a-w- c:\windows\system32\mshtmllib.dll
2009-10-20 10:42:36 10752 ----a-w- c:\windows\system32\browserui.dll
2009-10-20 10:42:34 13824 ----a-w- c:\windows\system32\winload.dll
2009-10-11 03:17:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-22 20:36:41 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-06-18 10:09:43 174 --sha-w- c:\program files\desktop.ini
2008-05-06 16:42:01 22 ----a-w- c:\program files\zipnew.dat
2008-05-06 16:42:01 20 ----a-w- c:\program files\rarnew.dat
2007-09-20 16:35:16 639 ----a-w- c:\program files\Uninstall.lst
2007-09-20 16:35:06 245178 ----a-w- c:\program files\WinRAR.chm
2007-09-20 16:35:02 99840 ----a-w- c:\program files\Uninstall.exe
2007-09-20 16:34:58 129024 ----a-w- c:\program files\RarExt.dll
2007-09-20 16:34:50 67584 ----a-w- c:\program files\Zip.SFX
2007-09-20 16:34:46 103424 ----a-w- c:\program files\Default.SFX
2007-09-20 16:34:32 80896 ----a-w- c:\program files\WinCon.SFX
2007-09-20 16:34:28 203776 ----a-w- c:\program files\UnRAR.exe
2007-09-20 16:34:26 317952 ----a-w- c:\program files\Rar.exe
2007-09-20 16:34:22 936960 ----a-w- c:\program files\WinRAR.exe
2007-09-20 16:34:06 502 ----a-w- c:\program files\File_Id.diz
2007-09-20 16:33:40 11616 ----a-w- c:\program files\WhatsNew.txt
2007-09-02 11:46:48 9232 ----a-w- c:\program files\TechNote.txt
2007-09-02 11:46:48 72138 ----a-w- c:\program files\Rar.txt
2007-07-11 19:15:51 36364 ----a-w- c:\windows\inf\perflib\0406\perfd.dat
2007-07-11 19:15:51 36364 ----a-w- c:\windows\inf\perflib\0406\perfc.dat
2007-07-11 19:15:51 300302 ----a-w- c:\windows\inf\perflib\0406\perfi.dat
2007-07-11 19:15:51 300302 ----a-w- c:\windows\inf\perflib\0406\perfh.dat
2007-03-31 18:40:12 6428 ----a-w- c:\program files\License.txt
2006-12-23 15:37:56 44032 ----a-w- c:\program files\RarExtLoader.exe
2006-12-11 00:14:56 43008 ----a-w- c:\program files\RarExt64.dll
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2006-10-22 09:21:24 3271 ----a-w- c:\program files\Order.htm
2006-09-18 19:13:58 1063 ----a-w- c:\program files\Descript.ion
2006-04-11 10:01:02 1088 ----a-w- c:\program files\RarFiles.lst
2005-05-12 16:02:30 90 ----a-w- c:\program files\UnrarSrc.txt
2005-05-12 16:01:32 1687 ----a-w- c:\program files\ReadMe.txt
2008-05-06 08:57:34 8192 --sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 21:16:10,33 ===============