|
Answer» Quote Also it never asked so I never did reboot. Is this ok? Yup, that's ok.
P2P - I see you have P2P software installed on your machine. (BitLord 2.0) We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs. ************************************************** Update Your Java (JRE)
Old versions of Java have vulnerabilities that malware can use to infect your system.
First Verify your Java Version
If there are any other version(s) installed then update now.
Get the new version (if needed)
If your version is out of date install the newest version of the Sun Java Runtime Environment.
Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
Be sure to close ALL open web browsers before starting the installation.
Remove any old versions
1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA.
Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. *************************************************** Download OTL to your desktop.
* Open OTL * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.
Code: [Select]:OTL
uURLSearchHooks: H - No File BHO: Complitly: {d27fc31c-6e3d-4305-8d53-acdaefa5f862} - c:\users\johnny ola\appdata\roaming\complitly\Complitly.dll mRun: [<NO NAME>]
:COMMANDS [resethosts] [purity] [start explorer]
* Click Run Fix * OTLI2 may ask to reboot the machine. Please do so if asked. * Click OK * A report will open. Copy and Paste that report in your next reply. **************************************************************** Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.
link # 1 Link # 2 If you are using Firefox, make sure that your download settings are as follows:
* Tools->Options->Main tab * Set to "Always ask me where to Save the files".
Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.
Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
Right-click combofix.exe and select Run as Administrator and follow the prompts. When finished, ComboFix will produce a log for you. Post the ComboFix login your next reply.
NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.
Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.OK Dave, few things:
1) PC has been running fine until the issue this week, since, it has been slower and I have heard more grinding, so once we fix this issue, I'd like to know if the PC is fine or if it needs work.
2) Checked Java, was out of date, now it is up to date.
3) So can I delete: -Java RA -OTL -Combo fix?
4) Logs
OTL Quote========== OTL ========== ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully
OTL by OldTimer - Version 3.2.31.0 log created on 12292011_141813
Combofix QuoteComboFix 11-12-29.04 - Johnny Ola 12/29/2011 14:31:52.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2038.1055 [GMT -5:00] Running from: c:\users\Johnny Ola\Desktop\ComboFix.exe AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0} FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A} SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D} SP: COMODO Defense+ *Enabled/Updated* {CE351521-78FA-2048-BB22-B68A4A5CA7EC} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe c:\programdata\pswi_preloaded.exe c:\users\Johnny Ola\AppData\Local\assembly\tmp . . ((((((((((((((((((((((((( Files Created from 2011-11-28 to 2011-12-29 ))))))))))))))))))))))))))))))) . . 2011-12-29 20:18 . 2011-12-29 20:21--------d-----w-c:\users\Johnny Ola\AppData\Local\temp 2011-12-29 20:18 . 2011-12-29 20:18--------d-----w-c:\users\Guest\AppData\Local\temp 2011-12-29 20:18 . 2011-12-29 20:18--------d-----w-c:\users\Default\AppData\Local\temp 2011-12-29 19:18 . 2011-12-29 19:18--------d-----w-C:\_OTL 2011-12-21 04:56 . 2011-12-21 04:56--------d-----w-c:\program files\iPod 2011-12-21 04:56 . 2011-12-21 04:56--------d-----w-c:\program files\iTunes 2011-12-15 01:33 . 2011-11-23 13:372043904----a-w-c:\windows\system32\win32k.sys 2011-12-15 01:33 . 2011-11-08 12:102409784----a-w-c:\program files\Windows Mail\OESpamFilter.dat 2011-12-15 01:33 . 2011-10-27 08:013602816----a-w-c:\windows\system32\ntkrnlpa.exe 2011-12-15 01:33 . 2011-10-27 08:013550080----a-w-c:\windows\system32\ntoskrnl.exe 2011-12-15 01:33 . 2011-10-14 16:02429056----a-w-c:\windows\system32\EncDec.dll 2011-12-15 01:33 . 2011-10-25 15:5649152----a-w-c:\windows\system32\csrsrv.dll 2011-12-15 01:33 . 2011-11-08 14:422048----a-w-c:\windows\system32\tzres.dll 2011-12-08 18:02 . 2011-12-08 18:02--------d-----w-C:\Temp 2011-12-08 17:29 . 2011-12-15 18:06--------d-----w-c:\users\Johnny Ola\AppData\Local\LogMeIn Rescue Applet . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-12-29 19:05 . 2011-10-17 04:18472808----a-w-c:\windows\system32\deployJava1.dll 2011-12-19 18:59 . 2011-10-07 22:4782400----a-w-c:\windows\system32\drivers\inspect.sys 2011-12-19 18:59 . 2011-10-07 22:4738616----a-w-c:\windows\system32\drivers\cmdhlp.sys 2011-12-19 18:59 . 2011-10-07 22:47491816----a-w-c:\windows\system32\drivers\cmdGuard.sys 2011-12-19 18:59 . 2011-10-07 22:4719600----a-w-c:\windows\system32\drivers\cmderd.sys 2011-12-19 18:58 . 2011-10-07 22:4733984----a-w-c:\windows\system32\cmdcsr.dll 2011-12-19 18:58 . 2011-10-07 22:47301224----a-w-c:\windows\system32\guard32.dll 2011-12-10 20:24 . 2011-10-11 20:0620464----a-w-c:\windows\system32\drivers\mbam.sys 2011-11-19 21:24 . 2011-10-11 18:18414368----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-05 17:47 . 2011-11-05 17:4711264----a-r-c:\users\Johnny Ola\AppData\Roaming\Microsoft\Installer\{98613C99-1399-416C-A07C-1EE1C585D872}\Icon98613C992.exe 2011-10-29 23:10 . 2011-10-29 23:100----a-w-c:\windows\system32\ConduitEngine.tmp 2011-10-26 06:49 . 2011-10-26 06:4986528----a-w-c:\windows\system32\iesysprep.dll 2011-10-26 06:49 . 2011-10-26 06:4976800----a-w-c:\windows\system32\SetIEInstalledDate.exe 2011-10-26 06:49 . 2011-10-26 06:4974752----a-w-c:\windows\system32\RegisterIEPKEYs.exe 2011-10-26 06:49 . 2011-10-26 06:4948640----a-w-c:\windows\system32\mshtmler.dll 2011-10-26 06:49 . 2011-10-26 06:49161792----a-w-c:\windows\system32\msls31.dll 2011-10-26 06:49 . 2011-10-26 06:4963488----a-w-c:\windows\system32\tdc.ocx 2011-10-26 06:49 . 2011-10-26 06:49367104----a-w-c:\windows\system32\html.iec 2011-10-26 06:49 . 2011-10-26 06:4974752----a-w-c:\windows\system32\iesetup.dll 2011-10-26 06:49 . 2011-10-26 06:4923552----a-w-c:\windows\system32\licmgr10.dll 2011-10-26 06:49 . 2011-10-26 06:49420864----a-w-c:\windows\system32\vbscript.dll 2011-10-26 06:49 . 2011-10-26 06:49152064----a-w-c:\windows\system32\wextract.exe 2011-10-26 06:49 . 2011-10-26 06:49150528----a-w-c:\windows\system32\iexpress.exe 2011-10-26 06:49 . 2011-10-26 06:49142848----a-w-c:\windows\system32\ieUnatt.exe 2011-10-26 06:49 . 2011-10-26 06:4935840----a-w-c:\windows\system32\imgutil.dll 2011-10-26 06:49 . 2011-10-26 06:4911776----a-w-c:\windows\system32\mshta.exe 2011-10-26 06:49 . 2011-10-26 06:49110592----a-w-c:\windows\system32\IEAdvpack.dll 2011-10-26 06:49 . 2011-10-26 06:49101888----a-w-c:\windows\system32\admparse.dll 2011-10-26 06:48 . 2011-10-26 06:48979456----a-w-c:\windows\system32\MFH264Dec.dll 2011-10-26 06:48 . 2011-10-26 06:48357376----a-w-c:\windows\system32\MFHEAACdec.dll 2011-10-26 06:48 . 2011-10-26 06:48302592----a-w-c:\windows\system32\mfmp4src.dll 2011-10-26 06:48 . 2011-10-26 06:4898816----a-w-c:\windows\system32\mfps.dll 2011-10-26 06:48 . 2011-10-26 06:482873344----a-w-c:\windows\system32\mf.dll 2011-10-26 06:48 . 2011-10-26 06:48261632----a-w-c:\windows\system32\mfreadwrite.dll 2011-10-26 06:48 . 2011-10-26 06:48209920----a-w-c:\windows\system32\mfplat.dll 2011-10-26 06:48 . 2011-10-26 06:48586240----a-w-c:\windows\system32\stobject.dll 2011-10-26 06:48 . 2011-10-26 06:48667648----a-w-c:\windows\system32\printfilterpipelinesvc.exe 2011-10-26 06:48 . 2011-10-26 06:48638336----a-w-c:\windows\system32\drivers\dxgkrnl.sys 2011-10-26 06:48 . 2011-10-26 06:48478720----a-w-c:\windows\system32\dxgi.dll 2011-10-26 06:48 . 2011-10-26 06:4837376----a-w-c:\windows\system32\cdd.dll 2011-10-26 06:48 . 2011-10-26 06:4826112----a-w-c:\windows\system32\printfilterpipelineprxy.dll 2011-10-26 06:48 . 2011-10-26 06:48258048----a-w-c:\windows\system32\winspool.drv 2011-10-26 06:48 . 2011-10-26 06:48135680----a-w-c:\windows\system32\XpsRasterService.dll 2011-10-26 06:47 . 2011-10-26 06:474096----a-w-c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui 2011-10-26 06:47 . 2011-10-26 06:47369664----a-w-c:\windows\system32\WMPhoto.dll 2011-10-26 06:47 . 2011-10-26 06:47252928----a-w-c:\windows\system32\dxdiag.exe 2011-10-26 06:47 . 2011-10-26 06:47195584----a-w-c:\windows\system32\dxdiagn.dll 2011-10-26 06:47 . 2011-10-26 06:47974848----a-w-c:\windows\system32\WindowsCodecs.dll 2011-10-26 06:47 . 2011-10-26 06:47519680----a-w-c:\windows\system32\d3d11.dll 2011-10-26 06:47 . 2011-10-26 06:47321024----a-w-c:\windows\system32\PhotoMetadataHandler.dll 2011-10-26 06:47 . 2011-10-26 06:47189440----a-w-c:\windows\system32\WindowsCodecsExt.dll 2011-10-17 05:25 . 2006-11-02 10:32101888----a-w-c:\windows\system32\ifxcardm.dll 2011-10-17 05:25 . 2006-11-02 10:3282432----a-w-c:\windows\system32\axaltocm.dll 2011-10-14 07:04 . 2011-10-14 07:04377344----a-w-c:\windows\system32\winhttp.dll 2011-10-14 07:02 . 2011-10-14 07:0236864----a-w-c:\windows\system32\drivers\en-US\http.sys.mui 2011-10-13 08:09 . 2011-10-13 08:0923552----a-w-c:\windows\system32\lpk.dll 2011-10-13 08:09 . 2011-10-13 08:0910240----a-w-c:\windows\system32\dciman32.dll 2011-10-13 08:05 . 2011-10-13 08:0561440----a-w-c:\windows\system32\winipsec.dll 2011-10-13 08:05 . 2011-10-13 08:05272896----a-w-c:\windows\system32\polstore.dll 2011-10-13 08:02 . 2011-10-13 08:029728----a-w-c:\windows\system32\TCPSVCS.EXE 2011-10-13 08:02 . 2011-10-13 08:028704----a-w-c:\windows\system32\HOSTNAME.EXE 2011-10-13 08:02 . 2011-10-13 08:0211264----a-w-c:\windows\system32\MRINFO.EXE 2011-10-13 08:02 . 2011-10-13 08:02105984----a-w-c:\windows\system32\netiohlp.dll 2011-10-13 08:02 . 2011-10-13 08:0210240----a-w-c:\windows\system32\finger.exe 2011-10-13 08:02 . 2011-10-13 08:0227136----a-w-c:\windows\system32\NETSTAT.EXE 2011-10-13 08:02 . 2011-10-13 08:0219968----a-w-c:\windows\system32\ARP.EXE 2011-10-13 08:02 . 2011-10-13 08:0217920----a-w-c:\windows\system32\ROUTE.EXE 2011-10-13 07:59 . 2011-10-13 07:5965024----a-w-c:\windows\system32\wlanapi.dll 2011-10-13 07:59 . 2011-10-13 07:59127488----a-w-c:\windows\system32\L2SecHC.dll 2011-10-13 07:59 . 2011-10-13 07:5968096----a-w-c:\windows\system32\wlanhlp.dll 2011-10-13 07:59 . 2011-10-13 07:59513536----a-w-c:\windows\system32\wlansvc.dll 2011-10-13 07:59 . 2011-10-13 07:59302592----a-w-c:\windows\system32\wlansec.dll 2011-10-13 07:59 . 2011-10-13 07:59293376----a-w-c:\windows\system32\wlanmsm.dll 2011-10-13 07:59 . 2011-10-13 07:5915181----a-w-c:\windows\system32\gatherWirelessInfo.vbs 2011-10-13 07:58 . 2011-10-13 07:581401856----a-w-c:\windows\system32\msxml6.dll 2011-10-13 07:58 . 2011-10-13 07:582048----a-w-c:\windows\system32\msxml3r.dll 2011-10-13 07:58 . 2011-10-13 07:582048----a-w-c:\windows\system32\msxml6r.dll 2011-10-13 07:57 . 2011-10-13 07:57218624----a-w-c:\windows\system32\msv1_0.dll 2011-10-13 07:55 . 2011-10-13 07:5553248----a-w-c:\windows\system32\rrinstaller.exe 2011-10-13 07:55 . 2011-10-13 07:5524576----a-w-c:\windows\system32\mfpmp.exe 2011-10-13 07:55 . 2011-10-13 07:552048----a-w-c:\windows\system32\mferror.dll 2011-10-13 07:52 . 2011-10-13 07:5271680----a-w-c:\windows\system32\atl.dll 2011-10-13 07:47 . 2011-10-13 07:47160256----a-w-c:\windows\system32\wkssvc.dll 2011-10-13 07:46 . 2011-10-13 07:4653248----a-w-c:\windows\system32\tsgqec.dll 2011-10-13 07:46 . 2011-10-13 07:46136192----a-w-c:\windows\system32\aaclient.dll 2011-10-13 07:44 . 2011-10-13 07:44714240----a-w-c:\windows\system32\timedate.cpl 2011-10-13 07:36 . 2011-10-13 07:36623616----a-w-c:\windows\system32\localspl.dll 2011-10-13 07:33 . 2011-10-13 07:33499712----a-w-c:\windows\system32\kerberos.dll 2011-10-13 07:33 . 2011-10-13 07:33175104----a-w-c:\windows\system32\wdigest.dll 2011-10-13 07:33 . 2011-10-13 07:339728----a-w-c:\windows\system32\lsass.exe 2011-10-13 07:33 . 2011-10-13 07:3372704----a-w-c:\windows\system32\secur32.dll 2011-10-13 07:33 . 2011-10-13 07:33439864----a-w-c:\windows\system32\drivers\ksecdd.sys 2011-10-13 07:33 . 2011-10-13 07:331259008----a-w-c:\windows\system32\lsasrv.dll 2011-10-13 07:31 . 2011-10-13 07:316656----a-w-c:\windows\system32\kbd106n.dll 2011-10-13 07:29 . 2011-10-13 07:2962464----a-w-c:\windows\system32\l3codeca.acm 2011-10-13 07:29 . 2011-10-13 07:29220672----a-w-c:\windows\system32\l3codecp.acm 2011-10-13 07:27 . 2011-10-13 07:2730720----a-w-c:\windows\system32\drivers\tcpipreg.sys 2011-10-13 07:27 . 2011-10-13 07:2725088----a-w-c:\windows\system32\drivers\tunnel.sys 2011-10-13 07:27 . 2011-10-13 07:27200704----a-w-c:\windows\system32\iphlpsvc.dll 2011-10-13 07:27 . 2011-10-13 07:2715360----a-w-c:\windows\system32\drivers\TUNMP.SYS 2011-11-09 16:37 . 2011-10-11 17:40134104----a-w-c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-10-31 21:0294208----a-w-c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-10-31 21:0294208----a-w-c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-10-31 21:0294208----a-w-c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "iCloudServices"="c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe" [2011-11-11 59240] "ApplePhotoStreams"="c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe" [2011-11-11 59240] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RtHDVCpl.exe" [2007-04-06 4423680] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-24 138008] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-24 154392] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-24 133912] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-08 835584] "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2007-04-17 321656] "VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2007-04-02 411768] "VAIO Center Access Bar"="c:\program files\sony\VAIO Center Access Bar\VCAB.exe" [2007-03-06 36864] "VAIOSecurity"="c:\program files\Sony\VAIO Security Center\VSC.exe" [2007-03-14 2322432] "VAIOSurvey"="c:\program files\Sony\VAIO Survey\Vista VAIO Survey.exe" [2006-12-07 577536] "AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-12-21 6676808] . c:\users\Johnny Ola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Johnny Ola\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-12-5 24242056] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-3 2756608] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2011-05-04 17:54551296----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon] 2007-04-24 00:1998304----a-w-c:\windows\System32\VESWinlogon.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\System32\guard32.dll . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecuteREG_MULTI_SZ autocheck autochk *\0SsiEfr.exe\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup backupExtension=.CommonStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim] 2011-05-03 15:434321112----a-w-c:\program files\AIM\aim.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2011-11-02 04:2559240----a-w-c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\com.apple.dav.bookmarks.daemon] 2011-11-16 02:5259240----a-w-c:\program files\Common Files\Apple\Internet Services\BookmarkDAV_client.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2011-10-11 20:04136176----atw-c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2011-12-08 06:36421736----a-w-c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)] 2011-12-24 22:50981680----a-w-c:\program files\Malwarebytes' Anti-Malware\mbam.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickBooks Simple Start] 2007-01-31 05:59371712----a-w-c:\program files\Intuit\SimpleStartEntice\entice.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunSpySweeperScheduleAtStartup] 2011-10-26 06:4910752----a-w-c:\windows\System32\msfeedssync.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel] 2007-04-06 18:181822720----a-w-c:\windows\SkyTel.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2008-01-19 07:381008184----a-w-c:\program files\Windows Defender\MSASCui.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter] 2009-04-11 06:282153472----a-w-c:\windows\System32\oobefldr.dll . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 136176] R3 DIRECTIO;DIRECTIO;T:\DirectIo.sys R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 136176] R3 ICScsiSV;Image Converter SCSI Service;c:\program files\Sony\Image Converter 3\ICScsiSV.exe [2007-01-26 75952] R3 IcVzMonLauncher;IcVzMonLauncher;c:\program files\Sony\Image Converter 3\IcVzMonLauncher.exe [2007-01-26 67760] R3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 745472] R3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-01-09 397312] R3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-01-16 1089536] R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504] S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120] S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608] S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248] S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2011-12-19 491816] S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2011-12-19 38616] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248] S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776] S2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2010-12-10 29293408] S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-01-03 11032] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272] S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720] S3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2007-04-04 73472] S3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2007-04-04 43904] S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\DRIVERS\SonyImgF.sys [2007-04-05 31104] S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-02-08 807424] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 19:59] . 2011-12-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-10-11 19:59] . 2011-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-463125951-12254502-3284758742-1005Core.job - c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-11 20:04] . 2011-12-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-463125951-12254502-3284758742-1005UA.job - c:\users\Johnny Ola\AppData\Local\Google\Update\GoogleUpdate.exe [2011-10-11 20:04] . . ------- Supplementary Scan ------- . uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2818425 uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 68.105.28.12 68.105.29.12 68.105.28.11 TCP: Interfaces\{20DA44BE-98A1-475D-B8AC-88DF3AD26CDD}: NameServer = 8.26.56.26,156.154.70.22 TCP: Interfaces\{D83D5627-FB49-437C-B3E7-C61C85550B27}: NameServer = 8.26.56.26,156.154.70.22 FF - ProfilePath - c:\users\Johnny Ola\AppData\Roaming\Mozilla\Firefox\Profiles\3yu3mje6.default\ FF - prefs.js: BROWSER.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2818425&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/ FF - user.js: network.protocol-handler.warn-external.dnupdate - false . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{7aeb3efd-e564-43f1-b658-5058a7c5743b} - (no file) HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe MSConfigStartUp-COMODO - c:\program files\COMODO\COMODO GeekBuddy\CLPSLA.exe MSConfigStartUp-CPA - c:\program files\COMODO\COMODO GeekBuddy\VALA.exe MSConfigStartUp-NapsterShell - c:\program files\Napster\napster.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-12-29 15:21 Windows 6.0.6002 Service Pack 2 NTFS . detected NTDLL code modification: ZwClose . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(1112) c:\windows\system32\guard32.dll . - - - - - - - > 'lsass.exe'(1060) c:\windows\system32\guard32.dll . Completion time: 2011-12-29 15:26:46 ComboFix-quarantined-files.txt 2011-12-29 20:26 . Pre-Run: 208,664,760,320 bytes free Post-Run: 207,876,616,192 bytes free . - - End Of File - - 5F749A562566151542C7F28A2F0CEFC5
QuoteI have heard more grinding That sounds like either your hard drive or one of the fans.
QuoteJava RA -OTL -Combo fix? You can uninstall/ delete Java RA. We'll remove the others when we're finished.
SysProt Antirootkit
Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors).
http://sites.google.com/site/sysprotantirootkit/
Unzip it into a folder on your desktop.
- Double click Sysprot.exe to start the program.
- Click on the Log tab.
- In the Write to log box select the following items.
- Process << Selected
- Kernel Modules << Selected
- SSDT << Selected
- Kernel Hooks << Selected
- IRP Hooks << NOT Selected
- Ports << NOT Selected
- Hidden Files << Selected
- At the bottom of the page
- Hidden Objects Only << Selected
- Click on the Create Log button on the bottom right.
- After a few seconds a new window should appear.
- Select Scan Root Drive. Click on the Start button.
- When it is complete a new window will appear to indicate that the scan is finished.
- The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
1) PC tonight has been weird, at times very slow and uncharaterisitcally unresponsive, hope we find out why and stop it.
2) Scan:
QuoteSysProt AntiRootkit v1.0.1.0 by swatkat
****************************************************************************************** ******************************************************************************************
No Hidden Processes found
****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys Service Name: --- Module Base: 8C9F0000 Module End: 8C9FB000 Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: --- Module Base: 8E3F8000 Module End: 8E400000 Hidden: Yes
****************************************************************************************** ****************************************************************************************** SSDT: Function Name: ZwAdjustPrivilegesToken Address: 8E6E0F60 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwAlpcConnectPort Address: 8E6E114C Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwConnectPort Address: 8E6E02C0 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwCreateFile Address: 8E6E0BC6 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwCreateSection Address: 8E6E097A Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwCreateSymbolicLinkObject Address: 8E6E1CC4 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwCreateThread Address: 8E6DFCAC Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwLoadDriver Address: 8E6E16F6 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwMakeTemporaryObject Address: 8E6E0588 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwOpenFile Address: 8E6E0DA2 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwOpenProcess Address: AC925F3C Driver Base: AC925000 Driver End: AC928000 Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
Function Name: ZwOpenSection Address: 8E6E0822 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwSetSystemInformation Address: 8E6E19E2 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwShutdownSystem Address: 8E6E04F2 Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwSystemDebugControl Address: 8E6E070E Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
Function Name: ZwTerminateProcess Address: AC925FE4 Driver Base: AC925000 Driver End: AC928000 Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
Function Name: ZwTerminateThread Address: AC926080 Driver Base: AC925000 Driver End: AC928000 Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
Function Name: ZwWriteVirtualMemory Address: AC92611C Driver Base: AC925000 Driver End: AC928000 Driver Name: \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys
Function Name: ZwCreateThreadEx Address: 8E6E137A Driver Base: 8E6D3000 Driver End: 8E74E000 Driver Name: \SystemRoot\System32\DRIVERS\cmdguard.sys
****************************************************************************************** ****************************************************************************************** No Kernel Hooks found
****************************************************************************************** ****************************************************************************************** Hidden files/folders: Object: C:\Qoobox\BackEnv\AppData.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Cache.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Cookies.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Desktop.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Favorites.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\History.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Music.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\NetHood.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Personal.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Pictures.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\PrintHood.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Profiles.Folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Programs.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Recent.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\SendTo.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\SetPath.bat Status: Access denied
Object: C:\Qoobox\BackEnv\StartMenu.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\StartUp.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\SysPath.dat Status: Access denied
Object: C:\Qoobox\BackEnv\Templates.folder.dat Status: Access denied
Object: C:\Qoobox\BackEnv\VikPev00 Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl Status: Access denied
See Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
I'd like to scan your machine with ESET OnlineScan
•Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
- Click on to download the ESET Smart Installer. Save it to your desktop.
- Double click on the icon on your desktop.
•Check •Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan COMPLETES, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt I unchecked remove found threats, is that ok?I just ran it, found nothing, but it didn't open any log, when I was done it asked if I wanted the 30 day trial.So, how's your computer running now?Pretty good, it got better last Friday. Can we call it clear, or is there another scan, any, we can do, just to be sure?QuotePretty good, it got better last Friday. Can we call it clear, or is there another scan, any, we can do, just to be sure? No. That's it. Your computer is clean. We can now do some cleanup.
Update Your Java (JRE)
Old versions of Java have vulnerabilities that malware can use to infect your system.
First Verify your Java Version
If there are any other version(s) installed then update now.
Get the new version (if needed)
If your version is out of date install the newest version of the Sun Java Runtime Environment.
Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
Be sure to close ALL open web browsers before starting the installation.
Remove any old versions
1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA.
Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. ******************************************************* To uninstall ComboFix
- Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
- In the field, type in ComboFix /uninstall
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
- Then, press Enter, or click OK.
- This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
************************************************* To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
- Click the CleanUp button.
- Select Yes when the "Begin cleanup Process?" prompt appears.
- If you are prompted to Reboot during the cleanup, select Yes.
- The tool will delete itself once it finishes.
Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually. *************************************************** Clean out your temporary internet files and temp files.
Download TFC by OldTimer to your desktop.
Double-click TFC.exe to run it.
Note: If you are running on Vista, right-click on the file and choose Run As Administrator
TFC will close all programs when run, so make sure you have saved all your work before you begin.
* Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run UNINTERRUPTED until it is finished.
Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ********************************************** Go to Microsoft Windows Update and get all CRITICAL updates.
----------
I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.
SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here
Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ
Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.
Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! 1) Java is up to date 2) Typed in combofix as you requested, could not find anything 3) Ran OTL, cleared a few things, but had to go into downloads, program files, and uninstall to remove everything 4) TFC problems, first downloaded it, but had an error. Then downloaded it, get it to run, took nearly 10 minutes, did not finish, due to error.
Question: 1) Is my PC safe, and clear? 2) Do I really need TFC, or can I just use CC Cleaner. Is it alarming that it did not work?QuoteIs my PC safe, and clear? Yes. QuoteDo I really need TFC, or can I just use CC Cleaner. Yes, you can use CCleaner and also do a disk clean up occasionally on your harddrive QuoteIs it alarming that it did not work? Not really. I will lock this thread. If you need it re-opened, please send me a pm.
|