Unsolved

This post is more than 5 years old

5525

March 25th, 2011 15:00

Memory usage gradually builds while laptop is powered up even if no applications are being run

Hi My name is Shaun. I have an Alienware M17x. When I power it up the Memory usage while doing nothing would already be at 1.12 Gb or so. Gradually the memory rises until it is up to 3.9 Gb, I only have 4 Gb(remember this is even if no applications are being run). At this point and before it the laptop begins to freeze for everything. I was wondering if the usage of Memory effects the processor, as I have a quad core and when the memory usage is high the cpu can be 40% or more even when I don't ask the computer to do anything.

Thanks and here is my log

 

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 02:18:21, on 25/03/2011

Platform: Windows 7  (WinNT 6.00.3504)

MSIE: Internet Explorer v8.00 (8.00.7600.16722)

Boot mode: Normal

 

Running processes:

C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe

C:\Program Files\OSD\Launch_CC.exe

C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

C:\Program Files (x86)\CyberLink\Shared Files\brs.exe

C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe

C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe

C:\Program Files\Alienware\Command Center\AlienSense\FATrayAlert.exe

C:\Program Files (x86)\Java\jre6\bin\jusched.exe

C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe

C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe

C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 

F2 - REG:system.ini: UserInit=userinit.exe

O1 - Hosts: ::1 localhost

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll

O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110226160312.dll

O2 - BHO: FAIESSO Helper Object - {A2F122DA-055F-4df7-8F24-7354DBDBA85B} - C:\Program Files\Alienware\Command Center\AlienSense\FAIESSO.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe"

O4 - HKLM\..\Run: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe

O4 - HKLM\..\Run: [OSD] c:\Program Files\OSD\Launch.exe

O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey

O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent

O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [Google Update] "C:\Users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000

O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')

O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE

O4 - Global Startup: Bluetooth.lnk = ?

O4 - Global Startup: Philips SA19xx Device Manager.lnk = C:\Program Files (x86)\Philips\GoGear SA19xx Device Manager\main.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Shaun Naughton\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll

O20 - Winlogon Notify: FastAccess - C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll

O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\AESTSr64.exe

O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)

O23 - Service: Alienware Fusion Service (AlienFusionService) - Alienware - C:\Program Files\Alienware\Command Center\AlienFusionService.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

O23 - Service: Vista Session Launcher Service (CustomSvc) - Unknown owner - C:\Program Files\OSD\Service1.exe

O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)

O23 - Service: FAService - Sensible Vision  - C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe

O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe

O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe

O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe

O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe

O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe

O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe

O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)

O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)

O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)

O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\STacSV64.exe

O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)

O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)

O23 - Service: Vodafone Mobile Broadband Service (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe

O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)

O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)

O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)

O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

O23 - Service: Windows Presentation Foundation Font Cache 4.0.0.0 (WPFFontCache_v0400) - Unknown owner - C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe (file missing)

 

--

End of file - 12789 bytes

2 Intern

 • 

1.5K Posts

March 27th, 2011 11:00

Hi TheTripJunkie1,

Is this the same system that you posted about a month ago? An analyst replied to the thread within 24 hours.

Please let me know you are still with this thread and are going to be until the end before we continue.

Thanks.

March 27th, 2011 18:00

Thanks for replying. No this is a different system. Sorry about not replying to the last thread, a lot happened between the time I posted and the three days I had to reply, by the time I got sorted it was too late to reply. Yes I will follow this thread through.

Thanks again

Shaun

2 Intern

 • 

1.5K Posts

March 28th, 2011 04:00

Hi,

Thank you for letting me know. If you need longer than three days, just let me know.

 

 

Download and scan with CCleaner
1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:

  • Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
  • Clean all the entries in the "Windows Explorer" section.
  • Clean all entries in the "System" section.
  • Clean all entries in the "Advanced" section.
  • Clean any others that you choose.

In the Applications Tab:

  • Clean all except cookies in the Firefox/Mozilla section if you use it.
  • Clean all in the Opera section if you use it.
  • Clean Sun Java in the Internet Section.
  • Clean any others that you choose.

4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

 

 

Then Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2

MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.

  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.

MBAM will automatically start and you will be asked to update the program before performing a scan.

  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.

On the Scanner tab:

  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.

Back at the main Scanner screen:

  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.

Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

 

 

 

I then need to see some additional information about what is happening in your machine.
Please perform the following scan:

  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.
  • When done, DDS will open two (2) logs
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop.
  • The instructions here ask you to attach the Attach.txt.
    DDS.jpg
  • Instead of attaching, please copy/past both logs into your next reply.

     

     

  • Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE

 

Please copy/paste back the MBAM log and BOTH DDS logs for review.

Thanks.

March 28th, 2011 06:00

Thanks again heres the MalwareBytes log

 

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

 

Database version: 6191

 

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

 

28/03/2011 12:49:23

mbam-log-2011-03-28 (12-49-23).txt

 

Scan type: Quick scan

Objects scanned: 161849

Time elapsed: 3 minute(s), 18 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 1

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

c:\program files (x86)\Vodafone\vodafone mobile broadband\Bin\vodafone.view.taskbar.dll (Trojan.Dropper) -> Delete on reboot.

 

Registry Keys Infected:

(No malicious items detected)

 

Registry Values Infected:

(No malicious items detected)

 

Registry Data Items Infected:

(No malicious items detected)

 

Folders Infected:

(No malicious items detected)

 

Files Infected:

c:\program files (x86)\Vodafone\vodafone mobile broadband\Bin\vodafone.view.taskbar.dll (Trojan.Dropper) -> Quarantined and deleted successfully.

And heres the dds attach log
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows 7 Ultimate 
Boot Device: \Device\HarddiskVolume1
Install Date: 26/07/2010 14:28:12
System Uptime: 28/03/2011 12:55:25 (1 hours ago)
.
Motherboard: Alienware |  |       
Processor: Intel(R) Core(TM)2 Quad  CPU   Q9000  @ 2.00GHz | Socket 479 | 2001/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 134 GiB total, 81.739 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP4: 11/08/2010 15:03:48 - Windows Update
RP5: 25/02/2011 18:26:15 - Scheduled Checkpoint
RP6: 25/02/2011 23:33:31 - Windows Update
RP7: 26/02/2011 02:56:57 - Installed Microsoft Visual C++ 2005 Redistributable (x64)
RP8: 26/02/2011 14:30:10 - ##IDS_ERROR_1715##
RP9: 08/03/2011 20:19:34 - Windows Update
RP10: 24/03/2011 00:11:50 - Installed NETGEAR WNA1100 wireless USB 2.0 adapter
RP11: 24/03/2011 03:01:11 - Windows Update
RP12: 24/03/2011 03:19:28 - Installed HiJackThis
RP13: 25/03/2011 01:36:43 - ##IDS_ERROR_1717##
RP14: 25/03/2011 01:46:06 - Removed Thief Gold
RP15: 28/03/2011 02:24:29 - Installed M-Audio Micro Driver 6.0.3 (x64)
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Adobe Reader 8.1.3
Advanced Audio FX Engine
Advertising Center
Akamai NetSession Interface
AlienRespawn v2.0
Apple Application Support
Apple Software Update
ASIO4ALL
AVerMedia HC82 Express-Card Hybrid Analog
AVerMedia MCE Encoder x64 3.0.1.0
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Command Center
CyberLink PowerDVD 8
CyberLink YouCam
Dell Driver Download Manager
FL Studio 8
Free Audio CD Burner version 1.4.7
Free YouTube to MP3 Converter version 3.9.35.324
GoGear SA19xx Device Manager
Google Chrome
HiJackThis
IDT Audio
IL Download Manager
ImagXpress
Indeo® Software
ITECIR
iZotope Vinyl
Java(TM) 6 Update 13
Java(TM) SE Development Kit 6 Update 13
Malwarebytes' Anti-Malware
McAfee SecurityCenter
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 9 Essentials
Nero BurnRights
Nero ControlCenter
Nero CoverDesigner
Nero CoverDesigner Help
Nero Disc Copy Gadget
Nero Disc Copy Gadget Help
Nero DiscSpeed
Nero DriveSpeed
Nero Express Help
Nero InfoTool
Nero Installer
Nero Online Upgrade
Nero Rescue Agent
Nero StartSmart
Nero StartSmart Help
NeroExpress
neroxml
NVIDIA ForceWare Network Access Manager
Oblivion
QuickTime
RealPlayer
RealUpgrade 1.0
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.57.01
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Sonitex STX-1260 v1.0
Switch Sound File Converter
Thief - Deadly Shadows
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Vodafone Mobile Broadband
.
==== Event Viewer Messages From Past Week ========
.
28/03/2011 12:57:25, Error: Service Control Manager [7022]  - The Alienware Fusion Service service hung on starting.
28/03/2011 12:55:57, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Akamai NetSession Interface service to connect.
28/03/2011 12:55:56, Error: Microsoft-Windows-WLAN-AutoConfig [10000]  - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\system32\athExt.dll Error Code: 126
28/03/2011 04:46:07, Error: Service Control Manager [7011]  - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AlienFusionService service.
27/03/2011 18:45:50, Error: Service Control Manager [7043]  - The Group Policy Client service did not shut down properly after receiving a preshutdown control.
25/03/2011 21:07:19, Error: Service Control Manager [7009]  - A timeout was reached (30000 milliseconds) while waiting for the Alienware Fusion Service service to connect.
25/03/2011 21:07:19, Error: Service Control Manager [7000]  - The Alienware Fusion Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
Finally here's the dds DDS log
.
DDS (Ver_11-03-05.01) - NTFS_AMD64  
Run by Shaun Naughton at 13:34:41.87 on 28/03/2011
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Ultimate   6.1.7600.0.1252.353.1033.18.3838.2011 [GMT 1:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\STacSV64.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\AESTSr64.exe
C:\Program Files\Alienware\Command Center\AlienFusionService.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\OSD\Service1.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
C:\Program Files\OSD\Launch_CC.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\M-AudioTaskBarIcon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files (x86)\CyberLink\Shared Files\brs.exe
C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Alienware\Command Center\AlienSense\FATrayAlert.exe
C:\Program Files\OSD\OSD_Main.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
C:\Program Files\Alienware\Command Center\AlienFXHook32Mngr.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Alienware\Command Center\AlienFXHook64Mngr.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\bmctl.exe
C:\Program Files\Common Files\McAfee\Core\mchost.exe
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Shaun Naughton\Downloads\dds.com
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110226160312.dll
BHO: FAIESSOHelper Class: {a2f122da-055f-4df7-8f24-7354dbdba85b} - C:\Program Files\Alienware\Command Center\AlienSense\FAIESSO.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [Google Update] "C:\Users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [RegistryBooster] "C:\Program Files (x86)\Uniblue\RegistryBooster\launcher.exe" delay 20000
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
mRun: [BDRegion] "C:\Program Files (x86)\Cyberlink\Shared Files\brs.exe"
mRun: [FAStartup] 
mRun: [FATrayAlert] C:\Program Files\Alienware\Command Center\AlienSense\FATrayMon.exe
mRun: [OSD] c:\Program Files\OSD\Launch.exe
mRun: [PDVD8LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [RemoteControl8] "C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRun: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot
mRun: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
mRun: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
StartupFolder: C:\Users\SHAUNN~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ONENOT~1.LNK - C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\PHILIP~1.LNK - C:\Program Files (x86)\Philips\GoGear SA19xx Device Manager\main.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Free YouTube to Mp3 Converter - C:\Users\Shaun Naughton\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
LSP: C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: FastAccess - C:\Program Files\Alienware\Command Center\AlienSense\FALogNot.dll
LSA: Notification Packages = scecli FAPassSync
BHO-X64: scriptproxy: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110226160310.dll
BHO-X64:     scriptproxy - No File
mRun-x64: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray64.exe
mRun-x64: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
mRun-x64: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
mRun-x64: [AlienFX Controller] "C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe"
mRun-x64: [OSD CC] %ProgramFiles%\OSD\Launch_CC.exe
mRun-x64: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [M-Audio Taskbar Icon] C:\Windows\system32\M-AudioTaskBarIcon.exe
IE-X64: {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
============= SERVICES / DRIVERS ===============
.
R?2 AlienFusionService;Alienware Fusion Service;C:\Program Files\Alienware\Command Center\AlienFusionService.exe [2009-5-22 14136]
R0 BMLoad;Bytemobile Boot Time Load Driver;C:\Windows\System32\drivers\BMLoad.sys [2011-2-26 16512]
R0 mfehidk;McAfee Inc. mfehidk;C:\Windows\System32\drivers\mfehidk.sys [2010-8-16 529128]
R1 mfenlfk;McAfee NDIS Light Filter;C:\Windows\System32\drivers\mfenlfk.sys [2010-8-16 75032]
R1 mfewfpk;McAfee Inc. mfewfpk;C:\Windows\System32\drivers\mfewfpk.sys [2010-8-16 283360]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\System32\drivers\vwififlt.sys [2009-7-14 59904]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2009/09/16 11:33:57];C:\Program Files (x86)\CyberLink\PowerDVD8\000.fcl [2009-3-5 146928]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\AESTSr64.exe [2009-9-16 89600]
R2 CustomSvc;Vista Session Launcher Service;C:\Program Files\OSD\Service1.exe [2009-9-16 13312]
R2 FAService;FAService;C:\Program Files\Alienware\Command Center\AlienSense\FAService.exe [2009-5-9 2360584]
R2 McMPFSvc;McAfee Personal Firewall Service;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2010-8-16 355440]
R2 McNaiAnn;McAfee VirusScan Announcer;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2010-8-16 355440]
R2 McProxy;McAfee Proxy Service;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [2010-8-16 355440]
R2 McShield;McShield;C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe [2010-8-16 200056]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [2010-8-16 245352]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-8-16 149032]
R2 VmbService;Vodafone Mobile Broadband Service;C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]
R3 athur;Atheros AR9271 Wireless Network Adapter Service;C:\Windows\System32\drivers\athurx.sys [2011-3-24 1849856]
R3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\System32\drivers\btwl2cap.sys [2009-9-16 36392]
R3 cfwids;McAfee Inc. cfwids;C:\Windows\System32\drivers\cfwids.sys [2010-8-16 62800]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2011-2-26 85504]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\System32\drivers\itecir.sys [2010-2-24 67616]
R3 MAUSBMICRO;Service for M-Audio Micro;C:\Windows\System32\drivers\MAudioMicro.sys [2010-3-26 187912]
R3 mfeavfk;McAfee Inc. mfeavfk;C:\Windows\System32\drivers\mfeavfk.sys [2010-8-16 190136]
R3 mfefirek;McAfee Inc. mfefirek;C:\Windows\System32\drivers\mfefirek.sys [2010-8-16 441328]
R3 OA007Vid;Creative Camera OA007 Function Driver;C:\Windows\System32\drivers\OA007Vid.sys [2009-7-2 310208]
R3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;C:\Windows\System32\drivers\vodafone_K3805-z_dc_enum.sys [2010-9-1 75776]
R3 WinRing0_1_2_0;WinRing0_1_2_0;C:\Program Files\OSD\WinRing0x64.sys [2009-9-16 14544]
S2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 mferkdet;McAfee Inc. mferkdet;C:\Windows\System32\drivers\mferkdet.sys [2010-8-16 94864]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;C:\Windows\System32\drivers\nwusbser2.sys [2011-2-26 213120]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-7-26 1255736]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe --> C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [?]
S4 ahcix64;ahcix64;C:\Windows\System32\drivers\ahcix64.sys [2008-8-4 146944]
S4 mv61xx;mv61xx;C:\Windows\System32\drivers\mv61xx.sys [2008-8-4 163736]
.
=============== Created Last 30 ================
.
2011-03-28 11:42:56 -------- d-----w- C:\Users\SHAUNN~1\AppData\Roaming\Malwarebytes
2011-03-28 11:42:52 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-03-28 11:42:52 -------- d-----w- C:\PROGRA~3\Malwarebytes
2011-03-28 11:42:49 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-03-28 11:42:48 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-03-28 11:08:31 -------- d-----w- C:\Program Files\CCleaner
2011-03-28 01:24:55 -------- d-----w- C:\Program Files\M-Audio
2011-03-28 01:24:55 -------- d-----w- C:\Program Files (x86)\Common Files\Digidesign
2011-03-24 03:24:36 388096 ----a-r- C:\Users\SHAUNN~1\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-03-24 03:24:32 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-03-24 00:12:11 1849856 ----a-w- C:\Windows\System32\drivers\athurx.sys
2011-03-08 19:38:57 961024 ----a-w- C:\Windows\System32\CPFilters.dll
2011-03-08 19:38:57 723968 ----a-w- C:\Windows\System32\EncDec.dll
2011-03-08 19:38:57 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2011-03-08 19:38:56 850432 ----a-w- C:\Windows\SysWow64\sbe.dll
2011-03-08 19:38:56 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-03-08 19:38:56 259072 ----a-w- C:\Windows\System32\mpg2splt.ax
2011-03-08 19:38:56 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2011-03-08 19:38:56 1118720 ----a-w- C:\Windows\System32\sbe.dll
2011-03-08 19:38:39 3138048 ----a-w- C:\Windows\System32\mstscax.dll
2011-03-08 19:38:39 2690560 ----a-w- C:\Windows\SysWow64\mstscax.dll
2011-03-08 19:38:38 1097216 ----a-w- C:\Windows\System32\mstsc.exe
2011-03-08 19:38:38 1034240 ----a-w- C:\Windows\SysWow64\mstsc.exe
2011-03-03 02:45:08 257024 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\hpzppw72.dll
2011-03-02 12:40:43 -------- d-----w- C:\Users\SHAUNN~1\AppData\Roaming\FLEXnet
2011-03-02 12:35:22 -------- d-----w- C:\PROGRA~3\Novatel Wireless
2011-03-02 12:25:35 -------- d-----w- C:\Users\SHAUNN~1\AppData\Roaming\Vodafone
2011-02-26 14:35:09 85504 ----a-w- C:\Windows\System32\drivers\ew_jubusenum.sys
2011-02-26 14:35:09 1490656 ----a-w- C:\Windows\System32\wdfcoinstaller01007.dll
2011-02-26 14:34:58 213120 ----a-w- C:\Windows\System32\drivers\nwusbser2.sys
2011-02-26 14:34:57 213120 ----a-w- C:\Windows\System32\drivers\nwusbser.sys
2011-02-26 14:34:55 213120 ----a-w- C:\Windows\System32\drivers\nwusbmdm.sys
2011-02-26 14:33:13 39552 ----a-w- C:\Windows\System32\drivers\tcpipBM.sys
2011-02-26 14:33:13 16512 ----a-w- C:\Windows\System32\drivers\BMLoad.sys
2011-02-26 14:31:21 -------- d-----w- C:\PROGRA~3\Vodafone
2011-02-26 14:31:08 -------- d-----w- C:\Program Files (x86)\Vodafone
2011-02-26 14:29:22 -------- d-----w- C:\Users\SHAUNN~1\AppData\Local\Downloaded Installations
.
==================== Find3M  ====================
.
2011-01-07 08:06:50 46080 ----a-w- C:\Windows\System32\atmlib.dll
2011-01-07 07:27:11 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-01-07 05:49:20 366080 ----a-w- C:\Windows\System32\atmfd.dll
2011-01-07 05:33:11 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-01-05 06:20:30 612352 ----a-w- C:\Windows\System32\vbscript.dll
2011-01-05 05:37:33 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-01-05 04:00:16 3127808 ----a-w- C:\Windows\System32\win32k.sys
2010-12-30 13:16:22 458752 ----a-r- C:\Windows\SysWow64\HHActiveX.dll
.
============= FINISH: 13:35:02.25 ===============
Thanks for your help so far

2 Intern

 • 

1.5K Posts

March 28th, 2011 17:00

Hi,

 

Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)

 

Go here to run an online scannner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Click the "Show Results" button
  • Then click the "Export to Text File" button and save the log to the desktop
  • Copy and paste that log as a reply to this topic and also let me know how things are now.

 

March 29th, 2011 19:00

Hi, I turned off all Anti-Vius, Spyware & firewall. The scan found no threats but after 2.5 hours running my memory is at 3.5Gb of 4. My cpu is also at 40% when only running Internet Explorer. What do you think the next step should be??

Thanks again for all your help its really appreciated:)

Shaun

2 Intern

 • 

1.5K Posts

March 30th, 2011 14:00

Hi,

Run the system for a little while so the memory usage is high and then run the following tool:

 

 

  • Please download Process Explorer from HERE
  • Save Process Explorer to your DESKTOP
  • Right click the Process Explorer zip file and Extract the contents to the Desktop

  • Run the procexp.exe file in the extracted folded
  • Answer yes to the prompts for running the program

 

You will now be presented with a screen showing all the running processes on your machine.

 

  • Please click the save icon aapha.jpg on the top tool bar
  • Save the log to your DESKTOP
  • COPY/PASTE the log results back to this thread

 

Thanks.

March 30th, 2011 19:00

HI

Here's a lthe log after almost 2 hours of running the computer

 

Process PID CPU Private Bytes Working Set Description Company Name

System Idle Process 0 63.99 0 K 24 K

System 4 0.84 112 K 928 K

 Interrupts n/a 7.74 0 K 0 K Hardware Interrupts and DPCs

 smss.exe 304 520 K 108 K

csrss.exe 512 < 0.01 2,352 K 1,944 K

 conhost.exe 1552 1,064 K 192 K

wininit.exe 596 1,912 K 528 K

 services.exe 652 8,056 K 7,120 K

  svchost.exe 784 6.74 5,112 K 4,084 K Host Process for Windows Services Microsoft Corporation

   WmiPrvSE.exe 2460 1.59 6,280 K 5,248 K

   BTStackServer.exe 5132 < 0.01 11,800 K 3,136 K Bluetooth Stack COM Server Broadcom Corporation.

    BluetoothHeadsetProxy.exe 5292 1,332 K 728 K Bluetooth Headset Skype Proxy Broadcom Corporation.

  nvvsvc.exe 848 1,512 K 524 K NVIDIA Driver Helper Service, Version 179.85 NVIDIA Corporation

   rundll32.exe 1268 < 0.01 3,248 K 936 K

  svchost.exe 884 < 0.01 6,196 K 5,204 K Host Process for Windows Services Microsoft Corporation

  svchost.exe 948 0.06 19,148 K 11,988 K Host Process for Windows Services Microsoft Corporation

   audiodg.exe 3928 14,516 K 15,500 K

  svchost.exe 988 < 0.01 115,692 K 108,652 K Host Process for Windows Services Microsoft Corporation

   wlanext.exe 1544 2,180 K 1,056 K

   dwm.exe 3080 0.31 47,628 K 32,640 K Desktop Window Manager Microsoft Corporation

  svchost.exe 1016 0.08 28,788 K 21,584 K Host Process for Windows Services Microsoft Corporation

  stacsv64.exe 336 0.01 7,952 K 2,228 K IDT PC Audio IDT, Inc.

  svchost.exe 1164 7,368 K 5,576 K Host Process for Windows Services Microsoft Corporation

  svchost.exe 1352 0.71 13,340 K 8,624 K Host Process for Windows Services Microsoft Corporation

  spoolsv.exe 1536 8,180 K 2,768 K Spooler SubSystem App Microsoft Corporation

  FAService.exe 1588 0.01 15,636 K 4,488 K FastAccess Sensible Vision 

  svchost.exe 1648 13,500 K 7,944 K Host Process for Windows Services Microsoft Corporation

  AESTSr64.exe 1756 1,316 K 176 K Andrea filters APO access service (64-bit) Andrea Electronics Corporation

  AlienFusionService.exe 1792 16.52 3,006,296 K 2,823,532 K AlienFusionService Alienware

  AppleMobileDeviceService.exe 1836 1,884 K 660 K Apple Mobile Device Service Apple Inc.

  mDNSResponder.exe 1856 2,108 K 1,456 K Bonjour Service Apple Inc.

  btwdins.exe 1884 2,484 K 528 K Bluetooth Support Server Broadcom Corporation.

  Service1.exe 1932 1,708 K 596 K

   OSD_Main.exe 3936 2,380 K 2,652 K

  svchost.exe 1964 0.02 5,936 K 4,780 K Host Process for Windows Services Microsoft Corporation

  mfevtps.exe 2004 6,216 K 1,732 K McAfee Process Validation Service McAfee, Inc.

  NBService.exe 328 3,056 K 1,472 K Nero BackItUp Nero AG

  svchost.exe 1380 1,972 K 1,196 K Host Process for Windows Services Microsoft Corporation

  nSvcAppFlt.exe 1480 2,408 K 1,420 K app_filter Module

  mcshield.exe 1452 0.01 169,552 K 40,068 K McAfee On-Access Scanner service McAfee, Inc.

  mfefire.exe 2168 4,636 K 3,576 K McAfee Core Firewall Service McAfee, Inc.

  nSvcIp.exe 2212 3,344 K 1,084 K NVIDIA Corporation

  VmbService.exe 2288 < 0.01 19,000 K 4,300 K VmbService Vodafone

  McSvHost.exe 2484 < 0.01 31,708 K 22,724 K McAfee Service Host McAfee, Inc.

  taskhost.exe 3040 8,548 K 3,812 K Host Process for Windows Tasks Microsoft Corporation

  SearchIndexer.exe 5068 < 0.01 49,260 K 30,676 K Microsoft Windows Search Indexer Microsoft Corporation

   SearchProtocolHost.exe 5272 < 0.01 3,716 K 8,736 K

   SearchFilterHost.exe 5844 3,260 K 7,236 K

  svchost.exe 2196 3,332 K 3,080 K Host Process for Windows Services Microsoft Corporation

  svchost.exe 1564 1,956 K 1,220 K Host Process for Windows Services Microsoft Corporation

 lsass.exe 672 < 0.01 5,556 K 4,888 K Local Security Authority Process Microsoft Corporation

 lsm.exe 680 2,892 K 1,480 K

csrss.exe 616 0.04 7,764 K 4,460 K

 conhost.exe 3420 1,708 K 564 K Console Window Host Microsoft Corporation

 conhost.exe 4112 1,712 K 548 K Console Window Host Microsoft Corporation

winlogon.exe 472 3,360 K 1,384 K

explorer.exe 3160 0.09 34,640 K 46,416 K Windows Explorer Microsoft Corporation

 sttray64.exe 3408 7,876 K 2,008 K IDT PC Audio IDT, Inc.

 rundll32.exe 3440 2,556 K 644 K Windows host process (Rundll32) Microsoft Corporation

 AlienwareAlienFXController.exe 3452 < 0.01 30,912 K 3,016 K Alienware AlienFX Controller Alienware Corporation

  AlienFXHook32Mngr.exe 3544 < 0.01 9,328 K 880 K AlienFXHook32 Manager Alienware

  AlienFXHook64Mngr.exe 3736 32,928 K 1,016 K AlienFXHook64 Manager Alienware

 Launch_CC.exe 3460 1,860 K 952 K Alienware Corporation

 SynTPEnh.exe 3472 0.09 4,500 K 2,876 K Synaptics TouchPad Enhancements Synaptics Incorporated

  SynTPHelper.exe 2244 1,572 K 432 K

 M-AudioTaskBarIcon.exe 3480 3,952 K 876 K M-Audio Task Bar Icon Applet Avid Technology, Inc.

 sidebar.exe 3488 33,976 K 9,616 K Windows Desktop Gadgets Microsoft Corporation

 BTTray.exe 3708 0.02 6,132 K 4,608 K Bluetooth Tray Application Broadcom Corporation.

 ONENOTEM.EXE 4080 1,136 K 792 K Microsoft Office OneNote Quick Launcher Microsoft Corporation

 procexp.exe 2352 1,856 K 5,960 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com

  procexp64.exe 5148 1.07 20,632 K 40,120 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com

brs.exe 4036 1,096 K 616 K brs cyberlink

FATrayMon.exe 4052 1,596 K 1,120 K FATrayMon Sensible Vision 

 FATrayAlert.exe 3304 0.03 4,800 K 3,124 K FATrayAlert Application Sensible Vision 

PDVD8Serv.exe 728 1,460 K 1,356 K PowerDVD RC Service CyberLink Corp.

jusched.exe 1420 2,296 K 4,504 K Java(TM) Platform SE binary Sun Microsystems, Inc.

realsched.exe 3720 2,412 K 388 K RealNetworks Scheduler RealNetworks, Inc.

mcagent.exe 3268 53,012 K 3,896 K McAfee Security Center McAfee, Inc.

MobileBroadband.exe 1044 0.01 86,988 K 14,612 K MobileBroadband Vodafone

 bmctl.exe 4332 2,132 K 2,068 K Control Process Bytemobile, Inc.

 

 

Thanks again:)

2 Intern

 • 

1.5K Posts

April 1st, 2011 12:00

Hi,

Let disable some of them unneeded programs from running at start and see if that makes a difference. Although nothing is physically running, there is an awfal lot running in the background.

 

 

Lets run a tool to disable some unneeded programs from starting when the system starts and see if it makes a difference to your speed problems,

Please download Startups@Ease by AbuIbrahim12

  • On the web page click the Download button and save the S@E.exe file to your Desktop
  • Close all open Browsers and Double click the S@E desktop icon to start the tool
  • When the tool has opened click the Begin button
  • S@E will then analyze your system for unneeded startup programs
  • You will then be presented with a series of questions
  • Please read these carefully and check the appropriate box (Yes/No/I Don't Know) and click Next
  • Answer each question until you are presented with the review box listing each question that was asked and the answer you gave
  • Please review your answers and click the Confirm
  • If you made a mistake or are not happy with the answers you gave, click the Cancel button and start again
  • After clicking confirm, please click the View Logfile button and save the log to your desktop
  • Then please reboot the system

 

NOTE: If after running startup@Ease you feel as if you have made a mistake, please open the tool and click the "Restore Backups" button, this will re-enable all of the programs you disabled at startup on the next reboot.

Please post the Startups@Ease log back to me for review

 

Thanks,

April 3rd, 2011 10:00

Hi 

I think the S@E system has changed since you used it last there is no longer a begin button. Now you choose to startup, services or windows services. I ran them all & stopped some startups & some services. There is no longer a log file button. My computer is still using way too much ram & cpu. If I reinstall my OS do you think it might make a difference?? 

 

Thanks again, 

2 Intern

 • 

1.5K Posts

April 4th, 2011 01:00

Hi,

With these kinds of problems it could be numerous things causing the RAM/CPU spike, it could be a faulty piece of hardware, an infection or a program that is over resourceful. The trouble is, its a process of elimation, it could take weeks or even months trying to trouble shoot via a forum, A reinstall would certainly be quicker but then you would have to make all the relevant backups before you reinstalled and then reinstall all your programs again. You would at least be able to reinstall each program one at a time and see if one was causing the issue.

 

Lets run one more tool and see what that unearths and then we will go from there.

 

 

Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)

 

Please download ComboFix.exe. Please visit THIS webpage for download links, and instructions for running the tool:

ComboFix MUST be saved to your desktop before running the tool

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

When prompted to install the recovery console please make sure to do so as this is a VERY IMPORTANT backup of ComboFix (XP only, Vista/Windows 7 will NOT be propmted to install the recovery console)

You will need to be conected to the net to install the recovery console, if you can not install it DO NOT run ComboFix,
Post back and we will install it manually.

DO NOT mouse click when ComboFix is running as this will cause ComboFix to Stall and it will not work as it should

EXTRA NOTES:

  • If Combofix detects a Rootkit on the system it will give a warning and prompt for a reboot, please allow it to do so.
  • If Combofix reboot's due to a rootkit, the screen may stay black for a few minutes on reboot, this is normal
  • On some Vista machines, after running Combofix, you may receive a warning message about registry key's being listed for deletion, when trying to open certain programs. Please reboot the system and this will fix the issue (These certain items will not be deleted)

 

Please include the C:\ComboFix.txt in your next reply for further review.

Thanks,
K27.

April 4th, 2011 04:00

Here's the ComboFix logfile

 

 

ComboFix 11-04-03.03 - Shaun Naughton 04/04/2011  11:23:47.1.4 - x64

Microsoft Windows 7 Ultimate   6.1.7600.0.1252.353.1033.18.3838.1147 [GMT 1:00]

Running from: c:\users\Shaun Naughton\Desktop\ComboFix.exe

AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}

FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}

SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}

SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

 * Created a new restore point

.

.

(((((((((((((((((((((((((   Files Created from 2011-03-04 to 2011-04-04  )))))))))))))))))))))))))))))))

.

.

2011-04-04 10:30 . 2011-04-04 10:30 -------- d-----w- c:\users\Default\AppData\Local\temp

2011-04-03 16:02 . 2011-04-03 16:05 -------- d-----w- C:\S@E_backups

2011-03-30 01:27 . 2010-06-18 18:50 205376 ------w- c:\windows\system32\US-122_MKII_US-144_MKII.CPL

2011-03-30 01:27 . 2011-03-30 01:27 -------- d-----w- c:\windows\usb-audio.deTascam

2011-03-30 01:24 . 2010-06-18 18:50 31296 ----a-w- c:\windows\system32\drivers\tscusb2m.sys

2011-03-30 01:24 . 2010-06-18 18:50 50240 ----a-w- c:\windows\system32\drivers\tscusb2a.sys

2011-03-30 01:24 . 2010-06-18 18:50 409664 ----a-w- c:\windows\system32\drivers\tascusb2.sys

2011-03-29 23:47 . 2011-03-29 23:47 -------- d-----w- c:\program files (x86)\ESET

2011-03-28 11:42 . 2011-03-28 11:42 -------- d-----w- c:\users\Shaun Naughton\AppData\Roaming\Malwarebytes

2011-03-28 11:42 . 2011-03-28 11:42 -------- d-----w- c:\programdata\Malwarebytes

2011-03-28 11:42 . 2010-12-20 17:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys

2011-03-28 11:42 . 2010-12-20 17:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-03-28 11:42 . 2011-03-28 11:42 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2011-03-28 11:08 . 2011-03-28 11:08 -------- d-----w- c:\program files\CCleaner

2011-03-28 01:24 . 2011-03-28 01:24 -------- d-----w- c:\program files\M-Audio

2011-03-28 01:24 . 2011-03-28 01:24 -------- d-----w- c:\program files (x86)\Common Files\Digidesign

2011-03-24 03:24 . 2011-03-24 03:24 388096 ----a-r- c:\users\Shaun Naughton\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe

2011-03-24 03:24 . 2011-03-24 03:24 -------- d-----w- c:\program files (x86)\Trend Micro

2011-03-24 00:12 . 2010-03-09 16:33 1849856 ----a-w- c:\windows\system32\drivers\athurx.sys

2011-03-08 19:38 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll

2011-03-08 19:38 . 2010-12-23 06:07 723968 ----a-w- c:\windows\system32\EncDec.dll

2011-03-08 19:38 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll

2011-03-08 19:38 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll

2011-03-08 19:38 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax

2011-03-08 19:38 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll

2011-03-08 19:38 . 2010-12-23 05:28 534528 ----a-w- c:\windows\SysWow64\EncDec.dll

2011-03-08 19:38 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax

2011-03-08 19:38 . 2010-12-18 06:12 3138048 ----a-w- c:\windows\system32\mstscax.dll

2011-03-08 19:38 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\SysWow64\mstscax.dll

2011-03-08 19:38 . 2010-12-18 06:08 1097216 ----a-w- c:\windows\system32\mstsc.exe

2011-03-08 19:38 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\SysWow64\mstsc.exe

.

.

((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-02-26 14:33 . 2011-02-26 14:33 39552 ----a-w- c:\windows\system32\drivers\tcpipBM.sys

2011-02-26 14:33 . 2011-02-26 14:33 16512 ----a-w- c:\windows\system32\drivers\BMLoad.sys

2011-01-07 08:06 . 2011-02-25 14:01 46080 ----a-w- c:\windows\system32\atmlib.dll

2011-01-07 07:27 . 2011-02-25 14:01 34304 ----a-w- c:\windows\SysWow64\atmlib.dll

2011-01-07 05:49 . 2011-02-25 14:01 366080 ----a-w- c:\windows\system32\atmfd.dll

2011-01-07 05:33 . 2011-02-25 14:01 294400 ----a-w- c:\windows\SysWow64\atmfd.dll

2011-01-05 06:20 . 2011-02-25 14:04 612352 ----a-w- c:\windows\system32\vbscript.dll

2011-01-05 05:37 . 2011-02-25 14:04 428032 ----a-w- c:\windows\SysWow64\vbscript.dll

2011-01-05 04:00 . 2011-02-25 14:07 3127808 ----a-w- c:\windows\system32\win32k.sys

.

.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown 

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Google Update"="c:\users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-10-04 133104]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2009-05-01 75048]

"FATrayAlert"="c:\program files\Alienware\Command Center\AlienSense\FATrayMon.exe" [2009-05-09 95496]

"OSD"="c:\program files\OSD\Launch.exe" [2009-05-12 36864]

"RemoteControl8"="c:\program files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-10-17 91432]

"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-01-17 1484856]

"MobileBroadband"="c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2010-12-31 398848]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-6-6 1025576]

Philips SA19xx Device Manager.lnk - c:\program files (x86)\Philips\GoGear SA19xx Device Manager\main.exe [2009-12-11 119296]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 5 (0x5)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableUIADesktopToggle"= 0 (0x0)

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\FastAccess]

2009-05-09 17:48 140552 ----a-w- c:\program files\Alienware\Command Center\AlienSense\FALogNot.dll

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

@=""

.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

@=""

.

2;2 AlienFusionService;Alienware Fusion Service;c:\program files\Alienware\Command Center\AlienFusionService.exe

R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys

R3 MAUSBMICRO;Service for M-Audio Micro;c:\windows\system32\DRIVERS\MAudioMicro.sys

R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys

R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\DRIVERS\nwusbser2.sys

R3 TASCAM_US122144;TASCAM USB 2.0 Audio Device driver;c:\windows\system32\Drivers\tascusb2.sys

R3 TASCAM_US144_MIDI;TASCAM US-144 WDM MIDI Device;c:\windows\system32\drivers\tscusb2m.sys

R3 TASCAM_US144_WDM;TASCAM US-144 WDM;c:\windows\system32\drivers\tscusb2a.sys

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe

R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe

R4 ahcix64;ahcix64;c:\windows\system32\drivers\ahcix64.sys

R4 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys

S0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys

S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys

S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys

S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys

S2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};Power Control [2009/09/16 11:33];c:\program files (x86)\CyberLink\PowerDVD8\000.fcl [2009-03-05 08:47 146928]

S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_41ddbdc34da78989\AESTSr64.exe [2009-03-02 89600]

S2 CustomSvc;Vista Session Launcher Service;c:\program files\OSD\Service1.exe [2009-02-20 13312]

S2 FAService;FAService;c:\program files\Alienware\Command Center\AlienSense\FAService.exe [2009-05-09 2360584]

S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]

S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]

S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-13 245352]

S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-10-13 149032]

S2 VmbService;Vodafone Mobile Broadband Service;c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2010-12-31 9216]

S3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athurx.sys

S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys

S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys

S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys

S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys

S3 OA007Vid;Creative Camera OA007 Function Driver;c:\windows\system32\DRIVERS\OA007Vid.sys

S3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys

S3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files\OSD\WinRing0x64.sys [2008-07-25 14544]

.

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - WINRING0_1_2_0

*Deregistered* - mfeavfk01

*Deregistered* - mfesmfk

*Deregistered* - MPFP

.

Contents of the 'Scheduled Tasks' folder

.

2011-03-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2566811811-2272734622-3803116043-1003Core.job

- c:\users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-04 21:15]

.

2011-04-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2566811811-2272734622-3803116043-1003UA.job

- c:\users\Shaun Naughton\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-04 21:15]

.

.

--------- x86-64 -----------

.

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"combofix"="c:\combofix\CF14345.cfxxe"

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-23 15961632]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-23 82464]

"AlienFX Controller"="c:\program files\Alienware\Command Center\AlienwareAlienFXController.exe" [2009-05-22 52480]

"M-Audio Taskbar Icon"="c:\windows\system32\M-AudioTaskBarIcon.exe" [2010-03-26 798728]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"LoadAppInit_DLLs"=0x0

.

------- Supplementary Scan -------

.

uLocal Page = c:\windows\system32\blank.htm

mLocal Page = c:\windows\SysWOW64\blank.htm

IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000

IE: Free YouTube to Mp3 Converter - c:\users\Shaun Naughton\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm

IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

LSP: c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll

.

- - - - ORPHANS REMOVED - - - -

.

Wow6432Node-HKCU-Run-RegistryBooster - c:\program files (x86)\Uniblue\RegistryBooster\launcher.exe

Wow6432Node-HKLM-Run-FAStartup - (no file)

HKLM-Run-OSD CC - %ProgramFiles%\OSD\Launch_CC.exe

HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe

.

.

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]

"ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD8\000.fcl"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]

"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,

   00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

@Denied: (A) (Users)

@Denied: (A) (Everyone)

@Allowed: (B 1 2 3 4 5) (S-1-5-20)

"BlindDial"=dword:00000000

.

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files\OSD\Launch_CC.exe

c:\program files\OSD\OSD_Main.exe

c:\program files\Alienware\Command Center\AlienSense\FATrayAlert.exe

c:\program files\Alienware\Command Center\AlienFXHook32Mngr.exe

c:\program files (x86)\Vodafone\Vodafone Mobile Broadband\Optimization Client\bmctl.exe

.

**************************************************************************

.

Completion time: 2011-04-04  11:38:43 - machine was rebooted

ComboFix-quarantined-files.txt  2011-04-04 10:38

.

Pre-Run: 84,202,987,520 bytes free

Post-Run: 83,895,074,816 bytes free

.

- - End Of File - - 8F9B05387FFA04D9FC0C2806E0225F79

Thanks K27

2 Intern

 • 

1.5K Posts

April 5th, 2011 13:00

Hi,

The log is clean, lets try this.

Please uninstall McAfee via "Remove Programs" in Control Panel and then please run the McAfee Removal Tool

Once McAfee is removed, please post a fresh HJT log.

Thanks.

April 6th, 2011 15:00

Hi before I uninstall I was wondering how I reinstall on the same license as my McAfee came pre-installed on my machine?? I still have a year and a half left on my license.

 

Thanks again:):)

2 Intern

 • 

1.5K Posts

April 7th, 2011 00:00

Hi,

If McAfee was preinstalled then you should have a disk with McAfee on and that will have the product key on it. If not, look around the tower case and see if there is a sticker on the side/top/bottom with a McAfee product key sticker.

Thanks.

No Events found!

Top