OK, lately my computer has been going Threw allot of issue's, first of which for some reason Microsoft Silverlight was no longer installed and would always give a error when try to reinstall,after 2 weeks of correspondence with Microsoft(trying this and that and anything under the moon) like a fluke it just magically installed from a link I clicked in my Hotmail web page and has worked great since. So now I have been trying to cure the other issue's with total failure on all attempts(a2AntiMalware, Microsoft Fix It Center, Hi-Jack This ect...) What it is still doing is randomly IE Explorer will pop-up a second window with some random ad page(funny mainly it's a wal-mart ad but others also...lol) my sound keeps dropping out and I have to go Control Panel>SoundsAndAudioDevices>Hardware>LegacyAudioDrivers>Properties>Driver>Update Driver>InstallFromList>Don'tSearchIWillChose>LegacyAudioDriver's and manually reinstall and then it will work for awhile. Secondly my Task Bar at bottom of window will change from windows standard blue in color to white and third my IE Explorer will change from shown below:
[IMG]http://i191.photobucket.com/albums/z27/r8er4ever/ieexplore_1.jpg[/IMG]
To this:
[IMG]http://i191.photobucket.com/albums/z27/r8er4ever/ieexplore_2.jpg[/IMG]
Oh one last thing is that it will at times like get stuck or something cause the hard-drive will be running like crazy and after minutes and minutes of trying finally I get Task Manager to come up and the process "spoolsv.exe" will be running at 98-100 CPU usage.
OK, Now I have tried to properly do all that the posting requirements ask for(downloaded everything, and ran scans like it says)Except the ATF-Cleaner kept switching to a "Not-Responding" state so couldn't run that completely. But here are the 2 GMER log's you needed.(hope this is enough info to help you to help me.
GMER 1.0.15.15530 - http://www.gmer.net
Root kit quick scan 2010-12-28 23:56:53
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 ST3120022A rev.3.06
Running: 619m87ll.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\axlyikow.sys
GMER_1.log
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00 (MBR): rootkit-like behavior; TDL4 <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 08: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sectors 234441392 (+255): rootkit-like behavior;
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 86EEA292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 86EEA292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 86EEA292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 86EEA292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP3T0L0-7 86EEA292
Device \Device\Ide\IdeDeviceP2T0L0-12 -> \??\IDE#DiskST3120022A______________________________3.06____#4a3531544a39305a202020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- EOF - GMER 1.0.15 ----
GMER_2.log
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2010-12-29 00:28:42
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort2 ST3120022A rev.3.06
Running: 619m87ll.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\axlyikow.sys
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 86EEA292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 86EEA292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 86EEA292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 86EEA292
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP3T0L0-7 86EEA292
Device \Device\Ide\IdeDeviceP2T0L0-12 -> \??\IDE#DiskST3120022A______________________________3.06____#4a3531544a39305a202020202020202020202020#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport@ CWebTransport Object
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport\CLSID
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport\CLSID@ {74870B39-2651-4A6C-A59B-2F66602FDC67}
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport\CurVer
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport\CurVer@ CWebTransport.CWebTransport.1.0
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport.1.0@ CWebTransport Object
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport.1.0\CLSID@ {74870B39-2651-4A6C-A59B-2F66602FDC67}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core@ Windows Live OneCare safety scanner Core Module
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core\CLSID@ {55265A35-B335-44FE-BFB4-854E3461004D}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core\CurVer@ Microsoft.wlsc.Core.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core.1@ Windows Live OneCare safety scanner Core Module
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core.1\CLSID@ {55265A35-B335-44FE-BFB4-854E3461004D}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.AVAS@ Windows Live OneCare safety scanner AV/AS Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.AVAS\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.AVAS\CLSID@ {D53096B8-0786-4cd4-894D-7632EB477881}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.AVAS\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.AVAS\CurVer@ Microsoft.wlsc.Scanner.AVAS.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.AVAS.1@ Windows Live OneCare safety scanner AV/AS Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.AVAS.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.AVAS.1\CLSID@ {D53096B8-0786-4cd4-894D-7632EB477881}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag@ Windows Live OneCare safety scanner Disk Fragmentation Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag\CLSID@ {A4123DCA-30C3-4DD6-9B50-4D395813BE5A}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag\CurVer@ Microsoft.wlsc.Scanner.Defrag.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag.1@ Windows Live OneCare safety scanner Disk Fragmentation Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag.1\CLSID@ {A4123DCA-30C3-4DD6-9B50-4D395813BE5A}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth@ Windows Live OneCare safety scanner Disk Health Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth\CLSID@ {5134461D-7247-42CF-90DF-EBE7B8E207EC}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth\CurVer@ Microsoft.wlsc.Scanner.DiskHealth.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth.1@ Windows Live OneCare safety scanner Disk Health Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth.1\CLSID@ {5134461D-7247-42CF-90DF-EBE7B8E207EC}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety@ Windows Live OneCare safety scanner Network Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety\CLSID@ {88627655-CA82-4095-B972-31BE3EA352AA}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety\CurVer@ Microsoft.wlsc.Scanner.NetSafety.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety.1@ Windows Live OneCare safety scanner Network Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety.1\CLSID@ {88627655-CA82-4095-B972-31BE3EA352AA}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo@ Windows Live OneCare safety scanner Platform Info Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo\CLSID@ {5E7FBD8F-7AEA-4E7C-81E1-E8F660A80379}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo\CurVer@ Microsoft.wlsc.Scanner.PlatformInfo.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo.1@ Windows Live OneCare safety scanner Platform Info Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo.1\CLSID@ {5E7FBD8F-7AEA-4E7C-81E1-E8F660A80379}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner@ Windows Live OneCare safety scanner Registry Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner\CLSID@ {9E5B9899-39DD-4225-B2E8-C3FD1DA67079}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner\CurVer@ Microsoft.wlsc.Scanner.RegCleaner.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner.1@ Windows Live OneCare safety scanner Registry Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner.1\CLSID@ {9E5B9899-39DD-4225-B2E8-C3FD1DA67079}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.wlscInstall@ Windows Live Safety Center Base Module
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.wlscInstall\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.wlscInstall\CLSID@ {5ED80217-570B-4DA9-BF44-BE107C0EC166}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.wlscInstall\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.wlscInstall\CurVer@ Microsoft.wlsc.wlscInstall.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.wlscInstall.1@ Windows Live Safety Center Base Module
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.wlscInstall.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.wlscInstall.1\CLSID@ {5ED80217-570B-4DA9-BF44-BE107C0EC166}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.WrapperAX@ Windows Live Safety Center Control Module
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.WrapperAX\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.WrapperAX\CLSID@ {8E5C8BEE-1887-414C-8AC9-7C3951F28476}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.WrapperAX\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.WrapperAX\CurVer@ Microsoft.wlsc.WrapperAX.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.WrapperAX.1@ Windows Live Safety Center Control Module
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.WrapperAX.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.WrapperAX.1\CLSID@ {8E5C8BEE-1887-414C-8AC9-7C3951F28476}
Reg HKLM\SOFTWARE\Classes\wlscUploader.FileUploader@ Windows Live OneCare safety scanner Malware Submission Module
Reg HKLM\SOFTWARE\Classes\wlscUploader.FileUploader\CLSID
Reg HKLM\SOFTWARE\Classes\wlscUploader.FileUploader\CLSID@ {37FBC1D9-8FB9-4E5D-A1C2-FE9401CAD56A}
Reg HKLM\SOFTWARE\Classes\wlscUploader.FileUploader\CurVer
Reg HKLM\SOFTWARE\Classes\wlscUploader.FileUploader\CurVer@ wlscUploader.FileUploader.1
Reg HKLM\SOFTWARE\Classes\wlscUploader.FileUploader.1@ Windows Live OneCare safety scanner Malware Submission Module
Reg HKLM\SOFTWARE\Classes\wlscUploader.FileUploader.1\CLSID
Reg HKLM\SOFTWARE\Classes\wlscUploader.FileUploader.1\CLSID@ {37FBC1D9-8FB9-4E5D-A1C2-FE9401CAD56A}
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00 (MBR): rootkit-like behavior; TDL4 <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 08: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sectors 234441392 (+255): rootkit-like behavior;
---- EOF - GMER 1.0.15 ----