Question

Locked

My computer's applications keep on closing on their own. why?

By zack247 ·
can someone please help me? i have a dell dimension 4500 with a 256mb ati radeon hd 2400 pci card, 1024mb Ram, a 40gig hdd,and a 350W PSU. lately, when im using a program, randomly a window will pop up and say: "(insert program name here) has experienced a problem and needs to close. would you like to send a error report?" it keeps on happening more frequently, and i have run virus and malware scans, but nothing has turned up. i am going to try a windows xp repair disc, but what might be wrong with my computer? can someone please help me? and fast?

This conversation is currently closed to new comments.

5 total posts (Page 1 of 1)  
| Thread display: Collapse - | Expand +

All Answers

Collapse -

applications keep on closing

by prrethish In reply to My computer's application ...

looks like virus problem

download & run combofix in safe mode
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
run SmitFraudFi in safe mode

http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

Collapse -

thanks

by zack247 In reply to applications keep on clos ...

i will run both and post the results along with the combofix log

Collapse -

results

by zack247 In reply to thanks

sosmitfraud didn't turn anything up, but combofix completed successfully and gave me the log. here it is:

ComboFix 10-07-04.04 - Owner 07/05/2010 14:36:05.1.1 - x86
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Owner\LOCALS~1\Temp\sfamcc00001.dll
c:\docume~1\Owner\LOCALS~1\Temp\sfareca00001.dll
c:\documents and settings\Owner\Local Settings\Temp\sfamcc00001.dll
c:\documents and settings\Owner\Local Settings\Temp\sfareca00001.dll
c:\documents and settings\Owner\My Documents\Backups\Windows\Windows_security_backup files
c:\documents and settings\Owner\My Documents\Backups\Windows\Windows_security_backup files\Log_Owner_DAD.txt
c:\documents and settings\Owner\My Documents\Backups\Windows\Windows_security_backup files\Windows_security_update_3475_36_d.exe
c:\documents and settings\Owner\My Documents\runningdog.txt
c:\documents and settings\Owner\Recent\Thumbs.db
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system32\Thumbs.db
c:\windows\system32\tmp.reg
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
c:\windows\wpe pro.INI
c:\windows\xpsp1hfm.log

.
((((((((((((((((((((((((( Files Created from 2010-06-05 to 2010-07-05 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-05 20:49 . 2009-12-27 19:30 -------- d-----w- c:\program files\SpeedFan
2010-07-05 19:16 . 2009-03-21 16:32 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-05 04:32 . 2009-08-02 02:42 -------- d-----w- c:\documents and settings\Owner\Application Data\gtk-2.0
2010-07-05 04:00 . 2010-07-05 04:00 -------- d-----w- c:\program files\GIMP-2.0
2010-07-04 19:22 . 2010-07-04 19:22 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2010-07-04 19:22 . 2010-07-04 19:22 -------- d-----w- c:\documents and settings\Owner\Application Data\ATI
2010-07-04 19:16 . 2010-07-04 19:10 -------- d-----w- c:\program files\ATI
2010-07-04 19:15 . 2010-07-04 19:10 -------- d-----w- c:\program files\ATI Technologies
2010-07-04 19:15 . 2010-07-04 19:15 0 ----a-w- c:\windows\ativpsrm.bin
2010-07-04 18:58 . 2010-07-03 18:24 4348 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-28 19:44 . 2009-02-19 22:05 -------- d-----w- c:\documents and settings\Owner\Application Data\DivX
2010-06-20 06:30 . 2010-06-20 06:30 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-20 06:30 . 2009-02-19 22:04 -------- d-----w- c:\program files\DivX
2010-06-20 06:29 . 2009-11-07 03:45 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-06-20 06:29 . 2010-06-20 06:29 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-06-20 06:29 . 2010-06-20 06:29 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-20 06:29 . 2010-06-20 06:17 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-06-20 06:29 . 2010-06-20 06:29 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-20 06:29 . 2010-06-20 06:29 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-06-20 06:29 . 2010-06-20 06:26 -------- d-----w- c:\program files\QuickTime
2010-06-20 06:27 . 2010-06-20 06:27 84062 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-06-20 06:26 . 2010-06-20 06:26 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-20 06:26 . 2010-06-20 06:26 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-20 06:26 . 2010-06-20 06:26 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-20 06:26 . 2010-06-20 06:26 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-20 06:26 . 2010-06-20 06:26 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-06-20 06:26 . 2009-03-27 01:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-06-20 06:26 . 2010-06-20 06:26 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-06-20 06:26 . 2010-06-20 06:26 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-20 06:26 . 2010-06-20 06:26 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-20 06:25 . 2010-06-20 06:25 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-20 06:25 . 2010-06-20 06:25 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-06-20 06:25 . 2010-06-20 06:25 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-06-20 06:25 . 2010-06-20 06:25 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-06-20 06:24 . 2010-06-20 06:24 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-06-20 06:24 . 2010-06-20 06:24 -------- d-----w- c:\program files\Common Files\Apple
2010-06-20 06:22 . 2010-06-20 06:22 -------- d-----w- c:\program files\Apple Software Update
2010-06-20 06:22 . 2010-06-20 06:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-06-20 06:21 . 2010-06-20 06:30 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-06-20 06:16 . 2010-06-20 06:30 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-06-11 23:02 . 2010-06-11 23:02 -------- d-----w- c:\program files\Dreamcatcher
2010-06-11 23:02 . 2009-02-19 07:03 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-07 00:41 . 2010-06-07 00:33 -------- d-----w- c:\documents and settings\Owner\Application Data\InfraRecorder
2010-06-02 20:19 . 2009-03-16 21:40 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-02 20:19 . 2009-03-16 21:40 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-27 17:37 . 2009-02-19 06:16 4830720 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2010-05-27 17:12 . 2010-07-04 19:11 45056 ----a-w- c:\windows\system32\aticalrt.dll
2010-05-27 17:12 . 2010-07-04 19:11 45056 ----a-w- c:\windows\system32\aticalcl.dll
2010-05-27 17:10 . 2010-07-04 19:11 4071424 ----a-w- c:\windows\system32\aticaldd.dll
2010-05-27 17:05 . 2010-07-04 19:11 15208449 ----a-w- c:\windows\system32\SET65.tmp
2010-05-27 17:02 . 2010-07-04 19:11 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2010-05-27 16:59 . 2010-07-04 19:11 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2010-05-27 16:58 . 2009-02-19 06:20 299520 ----a-w- c:\windows\system32\ati2dvag.dll
2010-05-27 16:54 . 2009-02-19 06:20 3699936 ----a-w- c:\windows\system32\ati3duag.dll
2010-05-27 16:46 . 2010-07-04 19:11 208896 ----a-w- c:\windows\system32\atipdlxx.dll
2010-05-27 16:46 . 2010-07-04 19:11 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2010-05-27 16:45 . 2010-07-04 19:11 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2010-05-27 16:45 . 2010-07-04 19:11 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2010-05-27 16:45 . 2010-07-04 19:11 159744 ----a-w- c:\windows\system32\ati2evxx.dll
2010-05-27 16:44 . 2010-07-04 19:11 602112 ----a-w- c:\windows\system32\ati2evxx.exe
2010-05-27 16:43 . 2010-07-04 19:11 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2010-05-27 16:42 . 2010-07-04 19:11 143360 ----a-w- c:\windows\system32\atiapfxx.exe
2010-05-27 16:41 . 2009-02-19 06:20 2256512 ----a-w- c:\windows\system32\ativvaxx.dll
2010-05-27 16:41 . 2010-07-04 19:11 887724 ----a-w- c:\windows\system32\ativva6x.dat
2010-05-27 16:41 . 2010-07-04 19:11 3 ----a-w- c:\windows\system32\ativva5x.dat
2010-05-27 16:39 . 2010-07-04 19:11 573440 ----a-w- c:\windows\system32\atikvmag.dll
2010-05-27 16:38 . 2010-07-04 19:11 184320 ----a-w- c:\windows\system32\atiadlxx.dll
2010-05-27 16:37 . 2010-07-04 19:11 17408 ----a-w- c:\windows\system32\atitvo32.dll
2010-05-27 16:35 . 2010-07-04 19:11 393216 ----a-w- c:\windows\system32\atiok3x2.dll
2010-05-27 16:33 . 2009-02-19 06:20 692224 ----a-w- c:\windows\system32\ati2cqag.dll
2010-05-27 16:29 . 2010-07-04 19:11 65536 ----a-w- c:\windows\system32\atimpc32.dll
2010-05-27 16:29 . 2010-07-04 19:11 65536 ----a-w- c:\windows\system32\amdpcom32.dll
2010-05-27 16:28 . 2010-07-04 19:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2010-05-22 17:47 . 2010-05-22 17:47 61440 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-148ed222-n\decora-sse.dll
2010-05-22 17:47 . 2010-05-22 17:47 503808 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-79d29dd6-n\msvcp71.dll
2010-05-22 17:47 . 2010-05-22 17:47 499712 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-79d29dd6-n\jmc.dll
2010-05-22 17:47 . 2010-05-22 17:47 348160 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-79d29dd6-n\msvcr71.dll
2010-05-22 17:47 . 2010-05-22 17:47 12800 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-148ed222-n\decora-d3d.dll
2010-05-16 18:44 . 2010-05-16 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\ArcSoft
2010-05-06 10:41 . 2003-07-16 20:51 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-03 05:47 . 2010-05-03 05:47 0 ----a-w- c:\windows\nsreg.dat
2010-05-02 05:22 . 2003-07-16 20:51 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-27 18:40 . 2009-11-07 03:47 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-04-27 18:40 . 2009-11-07 03:47 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-04-27 18:40 . 2009-11-07 03:47 45648 ------w- c:\windows\system32\drivers\PxHelp20.sys
2010-04-27 18:40 . 2009-11-07 03:47 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-04-27 18:40 . 2009-11-07 03:47 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-04-27 18:40 . 2009-11-07 03:47 133616 ------w- c:\windows\system32\pxafs.dll
2010-04-20 05:30 . 2003-07-16 20:24 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-20 02:53 . 2009-12-21 05:10 47104 ----a-w- c:\windows\system32\KMVIDC32.DLL
2010-04-12 23:29 . 2010-05-02 15:42 411368 ----a-w- c:\windows\system32\deployJava1.dll
2009-02-21 06:43 . 2009-02-20 19:28 56 -csh--r- c:\windows\system32\1B262C1D44.sys
2010-03-15 03:00 . 2009-02-20 19:27 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

------- Sigcheck -------

[7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[-] 2003-07-16 . BF3C8CF53C77B48206B39910B6D6CBCC . 49152 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\eventlog.dll

c:\windows\System32\eventlog.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MP4 Player"="c:\program files\MP4 Player\mp4Player.exe" [2007-09-19 63948
"Active Desktop Calendar"="c:\program files\XemiComputers\Active Desktop Calendar\ADC.exe" [2009-10-20 5639680]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-10-02 15564
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-10-02 118784]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2008-03-27 660136]
"lxdnamon"="c:\program files\Lexmark 2600 Series\lxdnamon.exe" [2008-03-27 16040]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 15564
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-02 206524
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 42188
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-05-27 98304]
"ATICustomerCare"="c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-03-04 311296]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\HOTSYNC.EXE [2004-4-13 29900
SpeedFan.lnk - c:\program files\SpeedFan\speedfan.exe [2009-8-9 3986552]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-12 17:01 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\WINDOWS\\system32\\lxdncoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnpswx.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdntime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdnjswx.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnlscn.exe"=
"c:\\Program Files\\ArcSoft\\PhotoImpression 4\\PhotoImpression.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\My Music\\Kelvin's music\\TRACKMANIA UNITED 2006\\TmUnitedForever\\TmForever.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56892:TCP"= 56892:TCP:Pando Media Booster
"56892:UDP"= 56892:UDP:Pando Media Booster

R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\System32\spool\DRIVERS\W32X86\3\\lxdnserv.exe [2008-02-27 98984]
R3 atirage;atirage;c:\windows\system32\DRIVERS\atiragem.sys [2001-08-17 7052
R3 mgau;mgau;c:\windows\system32\DRIVERS\mgaum.sys [2001-08-17 320384]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-12 216200]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-06-02 242896]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-03-12 308064]
S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2008-02-27 594600]

.
Contents of the 'Scheduled Tasks' folder

2010-06-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2009-08-27 c:\windows\Tasks\User_Feed_Synchronization-{F629056C-DAC9-40E2-B2CD-2427C4582BBC}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 10:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.sympatico.ca/default.aspx?lang=en-CA
uInternet Connection Wizard,ShellNext = iexplore
IE: Download Video on This Page - c:\documents and settings\Owner\My Documents\My Music\Kelvin's music\Uther\Tomato.YouTube.Video.Downloader.v2.6.2_www.dl4all.com\YouTube Video Downloader\MDIEEx.dll/211
IE: Download Video This Links To - c:\documents and settings\Owner\My Documents\My Music\Kelvin's music\Uther\Tomato.YouTube.Video.Downloader.v2.6.2_www.dl4all.com\YouTube Video Downloader\MDIEEx.dll/212
IE: {{11F19C45-9675-488A-A8E0-8E8234DC245D} - res://c:\documents and settings\Owner\My Documents\My Music\Kelvin's music\Uther\Tomato.YouTube.Video.Downloader.v2.6.2_www.dl4all.com\YouTube Video Downloader\MDIEEx.dll/211
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: google.ca\www
Trusted Zone: instructables.com\www
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\t335xcne.default\
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe


**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-05 14:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(520)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll

- - - - - - - > 'explorer.exe'(3600)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\XemiComputers\Active Desktop Calendar\MouseHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\devldr32.exe
c:\program files\Lexmark 2600 Series\lxdnMsdMon.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
.
**************************************************************************
.
Completion time: 2010-07-05 14:59:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-05 20:59

Pre-Run: 5,760,438,272 bytes free
Post-Run: 5,966,168,064 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - 9CA04E2D0C71038D31A4A690DBEF0E9B

Collapse -

A couple things.

by seanferd In reply to My computer's application ...

Is it overheating? Make sure it is dust-free on the inside, and gets proper airflow around the case.

Try a memory diagnostic: here are several.
http://oca.microsoft.com/en/windiag.asp
http://www.memtest.org/
http://www.memtest86.com/
http://hcidesign.com/memtest/

Run
chkdsk /r
from the command prompt. (You'll have to reboot - you will be notified of this.)

One more malware scan, in case you haven't tried it http://malwarebytes.org. Run it in Safe Mode.

Also, if you were to get a Live CD, like UBCD or a live Linux distro, like Knoppix, you could boot from that. If it runs without crashing or programs terminating, it is probably your Windows installation, and not your hardware.

Collapse -

already tried malwarebytes anti malware

by zack247 In reply to A couple things.

i have already tried it, no results have shown up. but in avg 9.xx there ar several files that "could not be scanned, and are vital system files" thanks for your help, i'll post back with the results

Back to Malware Forum
5 total posts (Page 1 of 1)  

Related Discussions

Related Forums