Hi all,
I’m working on a machine which has shown some weird behaviour, but I can’t nail which bug is at work here. I’ve run through the standard process and attached appropriate logs, but there’s some extra info which might be helpful here:
(System is a Toshiba lappy running WinXP Pro SP3.)
-
Initially the DVD wasn’t working, showing an exclamation in device manager.
-
ASWMBR reported Alureon-FZ in atapi.sys, and seems to have fixed it. The DVD is now working, however…
-
If I insert a Huawei E173 USB modem the system becomes unusable. There is a CDFS partition on this device which contains the software and driver. Once this device is removed the system responds normally again.
-
The list of drivers for the internal DVD is quite long, apparently each burning and media player software installs its own:
C:\Windows\system32\drivers\GEARAspiWDM.sys GEAR Software
C:\Windows\system32\drivers\imapi.sys Microsoft
C:\Windows\system32\drivers\incdrm.sys Ahead Software
C:\Windows\system32\drivers\PxHelp20.sys Sonic Solutions
C:\Windows\system32\drivers\redbook.sys Microsoft
C:\Windows\system32\storprop.dll Microsoft
This may all seem OT, but I provide this info as backdrop to the following:
-
A registry key is being removed by something, this is apparent when msconfig and Help Centre won’t run… the key is
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\
I restored this key from the initial registry backup yesterday, but it’s been removed again. Currently the only entries are those of new programs installed today (Avast and MBAM).
MBAM log is below, ASWMBR log attached, OTL log to follow. Thanks in advance, mbouy.
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.08.23.02
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Kath :: BARCLAY [administrator]
23/08/2012 3:03:03 PM
mbam-log-2012-08-23 (15-03-03).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 301627
Time elapsed: 13 minute(s), 16 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Downloads\setupwavtomp3-c.exe (PUP.Installer.WH) → Quarantined and deleted successfully.
C:\Documents and Settings\Kath\Local Settings\Temporary Internet Files\Content.IE5\GAUSHS3P\Anvir_5457[1].exe (PUP.Adware.Agent) → Quarantined and deleted successfully.