InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 651. |
Solve : How do I get rid of the DLL malware file that Avast is saying that is malware?? |
|
Answer» Avast keeps on telling me that it has blocked a file which has malware on it. How do I remove it because I have tried the following: That's because it has been blocked. Have you installed and new programs prior to this happening? Yes, I have.We can do some scans, if you wish, to make sure your computer is clean. Please indicate yes or no. Quote from: SuperDave on June 15, 2015, 04:21:20 PM We can do some scans, if you wish, to make sure your computer is clean. Please indicate yes or no. 1. What time will the scan happen? 2. Will I be able to use my PC during the scan? 3. Do I need to keep the PC on and online? Quote 1. What time will the scan happen?You may start the scans anytime after you receive them. It's best not to use the computer while the scans are running but they shouldn't TAKE too long and your computer should remain connected the internet. Please download AdwCleaner by Xplode onto your Desktop. Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon. If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run. When the AdwCleaner program will open, click on the Scan button as shown below. AdwCleaner will now start to search for malicious files that may be installed on your computer. To remove the files that were detected in the previous step, please click on the Clean button. AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer. Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply. ********************************************* Please download Malwarebytes Anti-Malware from here. Double Click mbam-setup.exe to install the application.
Please download Junkware Removal Tool to your desktop. •Warning! Once the scan is complete JRT will shut down your BROWSER with NO warning. •Shut down your protection software now to avoid potential conflicts. •Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. •Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator •The tool will open and start scanning your system. •Please be patient as this can take a while to complete depending on your system's specifications. •On completion, a log (JRT.txt) is saved to your desktop and will automatically open. •Copy and Paste the JRT.txt log into your next message.I've done the scans as requested and the info is as follows: Junkware Removal Tool: Junkware Removal Tool (JRT) by Thisisu Version: 7.0.3 (06.19.2015:1) OS: Windows 7 Home Premium x64 Ran by TARDIS on 20/06/2015 at 18:00:00.93 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Tasks ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{D5974A72-C81C-4DC3-BE77-A8A7BBC8864E} ~~~ Files Successfully deleted: [File] C:\users\public\desktop\jzip.lnk Successfully deleted: [File] C:\users\public\desktop\ytd video downloader.lnk Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxp_lyrics.wikia.com_0.localstorage Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxp_lyrics.wikia.com_0.localstorage-journal Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxp_www.azlyrics.com_0.localstorage Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxp_www.azlyrics.com_0.localstorage-journal Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxp_www.lyricsmode.com_0.localstorage Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxp_www.lyricsmode.com_0.localstorage-journal Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxp_www.metrolyrics.com_0.localstorage Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxp_www.metrolyrics.com_0.localstorage-journal Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxps_static.olark.com_0.localstorage Successfully deleted: [File] C:\Users\TARDIS\appdata\local\google\chrome\user data\default\local storage\hxxps_static.olark.com_0.localstorage-journal Successfully deleted: [File] C:\Users\TARDIS\AppData\Roaming\microsoft\internet explorer\quick launch\jzip.lnk ~~~ Folders Successfully deleted: [Folder] C:\ProgramData\microsoft\windows\start menu\programs\ytd video downloader ~~~ Chrome [C:\Users\TARDIS\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\TARDIS\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: [C:\Users\TARDIS\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\TARDIS\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: [] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20/06/2015 at 18:09:44.32 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Adw Cleaner: # AdwCleaner v4.206 - Logfile created 20/06/2015 at 17:04:44 # Updated 01/06/2015 by Xplode # Database : 2015-06-17.1 [Server] # Operating system : Windows 7 Home Premium Service Pack 1 (x64) # Username : TARDIS - TARDIS-PC # Running from : C:\Users\TARDIS\Downloads\adwcleaner_4.206.exe # Option : Cleaning ***** [ Services ] *****
Service Deleted : netfilter2 ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\Reimage Protector Folder Deleted : C:\ProgramData\ytd video downloader Folder Deleted : C:\ProgramData\95bce84300006d5a Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jZip Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader Folder Deleted : C:\Program Files (x86)\GreenTree Applications Folder Deleted : C:\Program Files (x86)\jZip Folder Deleted : C:\Program Files\Reimage Folder Deleted : C:\Users\TARDIS\AppData\Local\jZip Folder Deleted : C:\Users\TARDIS\AppData\LocalLow\jZip Folder Deleted : C:\Users\TARDIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb [/!\] Not Deleted ( Junction ) : C:\Users\TARDIS\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb File Deleted : C:\Users\Public\Desktop\jZip.lnk File Deleted : C:\Users\Public\Desktop\YTD Video Downloader.lnk File Deleted : C:\Windows\Reimage.ini File Deleted : C:\Users\TARDIS\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\jZip.lnk File Deleted : C:\Users\TARDIS\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage File Deleted : C:\Users\TARDIS\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_st.chatango.com_0.localstorage-journal ***** [ Scheduled tasks ] ***** Task Deleted : ReimageUpdater ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ffdcfjdljhbehggjdkdioajnknjcpbjb Key Deleted : HKLM\SOFTWARE\Classes\jZip.file Key Deleted : HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine.1 Key Deleted : HKLM\SOFTWARE\Classes\REI_AxControl.ReiEngine Key Deleted : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546} Key Deleted : HKCU\Software\Conduit Key Deleted : HKCU\Software\Reimage Key Deleted : HKCU\Software\SpeedBit Key Deleted : HKCU\Software\PRODUCTSETUP Key Deleted : HKLM\SOFTWARE\DeviceVM Key Deleted : HKLM\SOFTWARE\jZip Key Deleted : HKLM\SOFTWARE\SpeedBit Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\jZip Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7} Key Deleted : [x64] HKLM\SOFTWARE\DeviceVM Key Deleted : [x64] HKLM\SOFTWARE\Reimage Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Protector ***** [ Web browsers ] ***** -\\ Internet Explorer v11.0.9600.17840 -\\ Pale Moon v -\\ Google Chrome v43.0.2357.124 [C:\Users\TARDIS\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://uk.ask.com/web?q={searchTerms} [C:\Users\TARDIS\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.speedbit.com/search.aspx?s=F4Oa&q={searchTerms} ************************* AdwCleaner[R0].txt - [5282 bytes] - [20/06/2015 15:38:50] AdwCleaner[S0].txt - [5054 bytes] - [20/06/2015 17:04:44] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5113 bytes] ########## Malwarebytes found none-malware threats. [attachment deleted by admin to conserve space]Malwarebytes' Anti-Rootkit Please download Malwarebytes' Anti-Rootkit and save it to your desktop.
Malwarebytes Anti-Rootkit BETA 1.09.1.1004 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 11.0.9600.17843 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 1.236000 GHz Memory total: 3184775168, free: 2109329408 Downloaded database version: v2015.06.27.03 Downloaded database version: v2015.06.26.01 Downloaded database version: v2015.06.26.01 ======================================= Initializing... ------------ Kernel report ------------ 06/27/2015 20:34:11 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\DRIVERS\compbatt.sys \SystemRoot\system32\DRIVERS\BATTC.SYS \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\pciide.sys \SystemRoot\system32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\DRIVERS\iaStor.sys \SystemRoot\system32\drivers\atapi.sys \SystemRoot\system32\drivers\ataport.SYS \SystemRoot\system32\drivers\msahci.sys \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\System32\Drivers\aswVmm.sys \SystemRoot\System32\Drivers\aswRvrt.sys \SystemRoot\system32\drivers\aswSnx.sys \SystemRoot\system32\drivers\aswSP.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\drivers\netfilter2.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\system32\drivers\aswRdr2.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\termdd.sys \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\mssmbios.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\igdkmd64.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\athrx.sys \SystemRoot\system32\DRIVERS\vwifibus.sys \SystemRoot\system32\DRIVERS\L1C62x64.sys \SystemRoot\system32\drivers\i8042prt.sys \SystemRoot\system32\DRIVERS\kbfiltr.sys \SystemRoot\system32\drivers\kbdclass.sys \SystemRoot\system32\DRIVERS\ETD.sys \SystemRoot\system32\drivers\mouclass.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\ATK64AMD.sys \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\tapSF0901.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\RTKVHD64.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\system32\drivers\IntcHdmi.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\snp2uvc.sys \SystemRoot\system32\DRIVERS\STREAM.SYS \SystemRoot\system32\DRIVERS\sncduvc.SYS \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_iaStor.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\aswMonFlt.sys \??\C:\Windows\system32\drivers\mbam.sys \SystemRoot\system32\drivers\aswStm.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \??\C:\Program Files\ATKGFNEX\ASMMAP64.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\aswHwid.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\Drivers\fastfat.SYS \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe \Windows\System32\shell32.dll \Windows\System32\advapi32.dll \Windows\System32\msctf.dll \Windows\System32\gdi32.dll \Windows\System32\clbcatq.dll \Windows\System32\user32.dll \Windows\System32\psapi.dll \Windows\System32\usp10.dll \Windows\System32\msvcrt.dll \Windows\System32\normaliz.dll \Windows\System32\difxapi.dll \Windows\System32\iertutil.dll \Windows\System32\nsi.dll \Windows\System32\imagehlp.dll \Windows\System32\rpcrt4.dll \Windows\System32\oleaut32.dll \Windows\System32\urlmon.dll \Windows\System32\sechost.dll \Windows\System32\ole32.dll \Windows\System32\setupapi.dll \Windows\System32\ws2_32.dll \Windows\System32\Wldap32.dll \Windows\System32\shlwapi.dll \Windows\System32\kernel32.dll \Windows\System32\imm32.dll \Windows\System32\wininet.dll \Windows\System32\lpk.dll \Windows\System32\comdlg32.dll \Windows\System32\userenv.dll \Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll \Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll \Windows\System32\comctl32.dll \Windows\System32\wintrust.dll \Windows\System32\KernelBase.dll \Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll \Windows\System32\cfgmgr32.dll \Windows\System32\crypt32.dll \Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll \Windows\System32\devobj.dll \Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll \Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll \Windows\System32\msasn1.dll \Windows\System32\profapi.dll \Windows\SysWOW64\normaliz.dll ----------- End ----------- Done! Scan started Database versions: main: v2015.06.27.03 rootkit: v2015.06.26.01 <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa8002fe9060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa8002fe9b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa8002fe9060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa8002476ac0, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xfffffa8002e7b050, DeviceName: \Device\Ide\IAAStorageDevice-0\, DriverName: \Driver\iaStor\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... Done! Drive 0 This is a System drive Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: D9B3496E Partition information: Partition 0 type is Other (0x1c) Partition is NOT ACTIVE. Partition starts at LBA: 2048 Numsec = 30713856 Partition 1 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 30715904 Numsec = 594423808 Partition file system is NTFS Partition is bootable Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 320072933376 bytes Sector size: 512 bytes Done! File "C:\ProgramData\AVAST Software\Avast\log\AvastSvc.log" is compressed (flags = 1) File "C:\ProgramData\AVAST Software\Avast\log\AvastUI.log" is compressed (flags = 1) File "C:\ProgramData\AVAST Software\Avast\log\CommChannel.Protocol.log" is compressed (flags = 1) File "C:\ProgramData\AVAST Software\Avast\log\Grimefighter.log" is compressed (flags = 1) File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EFD49C4E5794FCF1A856420317D3DF153D140234.bin.VE1" is compressed (flags = 1) File "C:\ProgramData\Microsoft\Windows Defender\Scans\mpcache-EFD49C4E5794FCF1A856420317D3DF153D140234.bin.VF" is compressed (flags = 1) Scan finished ======================================= Removal queue found; removal started Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-1-30715904-i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam... Removal finished Malwarebytes Anti-Rootkit Log: Malwarebytes Anti-Rootkit BETA 1.09.1.1004 www.malwarebytes.org Database version: main: v2015.06.27.03 rootkit: v2015.06.26.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.17843 TARDIS :: TARDIS-PC [administrator] 27/06/2015 20:34:45 mbar-log-2015-06-27 (20-34-45).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 346356 Time elapsed: 29 minute(s), 28 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security WARNINGS from your browser.
•Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt The eset txt: C:\Users\TARDIS\Downloads\BatteryMeterVersion23.exe a variant of Win32/OpenInstall potentially unwanted application C:\Users\TARDIS\Downloads\CR_Downloader_for_epsxe.exe a variant of Win32/InstallCore.YV potentially unwanted application C:\Users\TARDIS\Downloads\CR_Downloader_for_metal-gear-solid-(disc-1)-(v1.1).exe a variant of Win32/InstallCore.YV potentially unwanted application The eset log: [email protected] as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=969f43983d87ad43bfdf573f8b8730bd # end=init # utc_time=2015-06-29 02:18:42 # local_time=2015-06-29 03:18:42 (+0000, GMT Daylight Time) # country="United Kingdom" # osver=6.1.7601 NT Service Pack 1 Update Init Update Download Update Finalize Updated modules version: 24557 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # EOSSerial=969f43983d87ad43bfdf573f8b8730bd # end=updated # utc_time=2015-06-29 02:21:28 # local_time=2015-06-29 03:21:28 (+0000, GMT Daylight Time) # country="United Kingdom" # osver=6.1.7601 NT Service Pack 1 # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7777 # api_version=3.1.1 # EOSSerial=969f43983d87ad43bfdf573f8b8730bd # engine=24557 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-06-29 03:31:19 # local_time=2015-06-29 04:31:19 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Internet Security' # compatibility_mode=779 16777213 85 72 87540 200015969 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 0 188056929 0 0 # scanned=145720 # found=3 # cleaned=0 # scan_time=4191 sh=B21FD453CC650641C949068A0EA597B1914AEAC1 ft=1 fh=7783b92a0e2cbc12 vn="a variant of Win32/OpenInstall potentially unwanted application" ac=I fn="C:\Users\TARDIS\Downloads\BatteryMeterVersion23.exe" sh=3E4692EBB5E813BAE3E38BAA5BD41741B7A028C1 ft=1 fh=c82c2ad8b563db73 vn="a variant of Win32/InstallCore.YV potentially unwanted application" ac=I fn="C:\Users\TARDIS\Downloads\CR_Downloader_for_epsxe.exe" sh=B44819D7EA4BE8AC172215D59AC2BAAEA6F903D2 ft=1 fh=c82c2ad8c0d31fbd vn="a variant of Win32/InstallCore.YV potentially unwanted application" ac=I fn="C:\Users\TARDIS\Downloads\CR_Downloader_for_metal-gear-solid-(disc-1)-(v1.1).exe" How's your computer running now? Any other issues?The computer is running fine, apart from the same message popping up.Ok. Let's try this. Download, install and run a scan with MSE (below) and see if it finds anything. MicroSoft Security Essentials All versions and all languages. |
|
| 652. |
Solve : Empty folder won't delete? |
|
Answer» I downloaded a program the other day, now the folder it was in won't delete. I deleted everything that was inside and it still says the folder is being used and can't be deleted. Did you try uninstalling the program? That's usually the best way to get rid of unwanted programs.You could try Unlocker.uninstall Flash player or the program that was originally in the contained in the folder? The program that was originally contained in the folder was an .exe program that didn't require being installed. It deleted without any issues, leaving the folder empty, but undeleteable. Will it delete with Unlocker?Unlocker is the best solution for this kind of issues. I have used it more then 1000 times. Definitely it will work. Try it.Hey, sorry was away for a few days. my computer has SINCE been restarted and the file is able to be deleted now. Guess I was worried over nothing, but it was odd. |
|
| 653. |
Solve : CloudScout Removal? |
|
Answer» I've downloaded a program and was in a rush, didn't use custom install. Afterwards, I noticed ads that weren't blocked by an ad-blocker inside the underlined text that were by CloudScout; looked around for how to remove it, AdwCleaner did not help (will use again if need be), uninstalling the CloudScout parental control did not help; Ontop of these, I also used CCLEANER and it did not help either. I've also uninstalled and reinstalled chrome, as well as resetting the settings, and neither have removed them. PLEASE help me.I managed to fix it on CHrome by saving a BACKUP of the "Default" folder, and then deleting it and opening chrome. |
|
| 654. |
Solve : Blue Screen of Death in the last two days.? |
|
Answer» I have had the blue screen of death appear two times over the last two days. After I restart, it seems to be slow but ok. I am afraid there is something going on that I need to correct. Also, it seems to take forever to restart my computer. Here are the logs you requested. Thanks! |
|
| 655. |
Solve : Comcast/computer hacked? |
|
Answer» My Comcast DVR has been acting up for the last couple months in that i had a hard time deleting taped items. Anyhow I googled comcast help and got a live chat person who said a tech would call me back and help. My wife got on the phone with him, as i'm hard of hearing, and was on the phone for 1 1/2 hrs and he accessed the computer remotely and told us their records showed we had some 40 units connected on our service {we have a DESKTOP, laptop, a phone with a remote phone and thats it] and that was disrupting our Dvr. Said someone had hacked into our computer and it would take an outside source to correct the problem. He connected us with a company called ORION, which said would cost 239 dollars to correct the problem, and 6 months protection would be 439. Sounds kinda fishy to me. Legit or scam? I have AVG on the desktop and Avast on the laptop. Everythingseems to working OK except for the DVR deleting.I really don't understand how your DVR can be connected to your computer. It sounds like a scam to me. Do you receive your internet access from Comcast?Yes, Comcast furnishes TV, internet, and telephone.It is almost certainly a scam. You should have been furnished with their tech support phone line when you got their service. It will likely be on your bills as well, so use that. |
|
| 656. |
Solve : Need help for ransomware virus? |
|
Answer» I have a huge problem, my dads computer got infected by CTB-locker a ransomware but he made the mistake to restore his files to the same date his computer got infected, I REMOVED the virus but, can't restore the files I've already TRIED CHECKING OLDER versions and shadowexplorer and differentent decrypting softwares, what can I do to retrieve the crypted data..? |
|
| 657. |
Solve : Any free software can clean up slow Archos 80 G9 Tablet? |
|
Answer» Can anybody advise any free D/L software can clean up the SLOW Archos 80 G9 Tablet. Can anybody advise any free D/L software can clean up theWhy do you think it is slow? And if there was a way to make if go faster, why would the manufacture not offer it first? This review was done some time ago. BACK then that tablet was said to be good thing. Performance was near AVERAGE. Quote Editor's note:http://www.cnet.com/products/archos-80-g9/ If you have not done so already, you could consider doing the 4.o upgrade and expect some improvement. |
|
| 658. |
Solve : Google redirect Adware? |
|
Answer» Hey guys its me again, I'm afraid I can't help very much unless your computer is infected. Okay |
|
| 659. |
Solve : Adware removal from MAC OS X Yosemite? |
|
Answer» New to this forum, somehow I have an adware virus on my MAC OS X Yosemite. At least I THINK that is what it is. It puts HYPERLINKS on random items, which if CLICKED on says to CALL a number for removal. How do I remove this adware? |
|
| 660. |
Solve : How to increase backlinks?? |
|
Answer» I am working on a PC Optimizer WEBSITE. The name of website is SystHeal. It has very few back links and not has GOOD quality back links. I want to increase the no of good quality back links. What activity should I do. |
|
| 661. |
Solve : How can I remove virus from my mobile chip?? |
|
Answer» I have a MICROMAX mobile. I am using 2GB chip in my mobile. Before some days I saw that the data(audio and video) in my chip is CONVERTED in text file and COULD not PLAY. I format chip and insert data again but it is not working. Tell me reason?Replace the chip. |
|
| 662. |
Solve : Best way to filter out IP addresses with hardware..?? |
|
Answer» I am looking to filter out IP addresses using hardware external to the computer itself. |
|
| 663. |
Solve : Normal.dot message and I'm not using Word? |
|
Answer» There may not be a problem here, but I have had a MESSAGE 'Normal.dotm was being edited by another Word session'. Word was not running on my computer. Should I worry? |
|
| 664. |
Solve : Dueling AV systems?? |
|
Answer» I have both MS Essentials and free 2015 Avast on my PC. Real time PROTECTION is turned off on MSE. Is that ENOUGH to allow Avast to OPERATE ok or do I need to UNINSTALL MSE to make sure I have no conflict between the two systems? Thanks.Disabling MSE is all you will need to do. |
|
| 665. |
Solve : My start incredimail? |
|
Answer» I have incredimail installed somewhere i cannot FIND it, i have ran sas, mbam and my av, below is another log with it SHOWING up.
I'm here often but don't ask to my questions because i don't seem to get much help nowadays This is the log that came up on screen. # AdwCleaner v2.101 - Logfile created 12/22/2012 at 19:31:16 # Updated 16/12/2012 by Xplode # Operating system : Windows 7 Ultimate Service Pack 1 (64 bits) # User : harry - HARRY-PC # Boot Mode : Normal # Running from : C:\Users\harry\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CA74P2VD\adwcleaner (1).exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\user.js Folder Deleted : C:\Program Files (x86)\Perion Folder Deleted : C:\ProgramData\Ask Folder Deleted : C:\ProgramData\Tarma Installer ***** [Registry] ***** Key Deleted : HKCU\Software\IM Key Deleted : HKCU\Software\ImInstaller Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826} Key Deleted : HKLM\Software\IB Updater Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_install_RASMANCS Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd Key Deleted : HKLM\SOFTWARE\Tarma Installer Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16457 [OK] Registry is clean. -\\ Google Chrome v23.0.1271.97 File : C:\Users\harry\AppData\Local\Google\Chrome\User Data\Default\Preferences Deleted [l.12] : homepage = "hxxp://uk.ask.com/?l=dis&o=102865&gct=hp", Deleted [l.36] : icon_url = "hxxp://www.ask.com/favicon.ico", Deleted [l.39] : keyword = "ask.com", Deleted [l.42] : search_url = "hxxp://websearch.ask.com/redirect?client=cr&src=kw&tb=ORJ&o=102865&locale=en_UK[...] Deleted [l.43] : suggest_url = "hxxp://ss.websearch.ask.com/query?qsrc=2922&li=ff&sstype=prefix&q={searchTerms[...] Deleted [l.1664] : homepage = "hxxp://uk.ask.com/?l=dis&o=102865&gct=hp", ************************* AdwCleaner[R1].txt - [2937 octets] - [22/12/2012 19:29:48] AdwCleaner[S1].txt - [2553 octets] - [22/12/2012 19:31:16] ########## EOF - C:\AdwCleaner[S1].txt - [2613 octets] ########## Ok. I want to wish you and yours a Merry Christmas and a Happy New Year. Quote from: SuperDave on December 22, 2012, 12:36:16 PM Ok. I want to wish you and yours a Merry Christmas and a Happy New Year. Same to you and yours and enjoy the holidays. I'm keeping my pc very clean this good while now |
|
| 666. |
Solve : Am I being monitored?? |
|
Answer» I suspect that some is MONITORING my pc. |
|
| 667. |
Solve : Google search bar? |
|
Answer» Why do I get words from previously written emails or Word docs appearing in my google search BAR ? |
|
| 668. |
Solve : Unwanted File? |
|
Answer» Whenever I log off, I get a MESSAGE that a certain file is keeping my system from CLOSING. This file is by AnySend. I have searched, ran sutoruns, deleted files from the Control Panel, everything I can think of. The only help I get from AnySend is "That's really weird." The logs report everything is clean. Oddly, it doesn't appear in IE8 but it does in Chrome, my preferred browser. |
|
| 669. |
Solve : BSOD :( - Multiple errors? |
|
Answer» First off...here are my specs. First off...here are my specs. Sorry this is windows 7 ultimate 64I'd run memtest86 on this system for starters just to make sure that its not memory related. I have had brand new RAM act up before and it was a good name brand too. My issue was that the 2 sticks of RAM I bought even though same make/model/size didnt play WELL with each other. Later I found out that I could have purchased a matched pair, but I sent back 1 stick and the replacement stick played well with the other stick. When testing with the 2 sticks installed for 1GB RAM I would get memory errors running Memtest86. The system was having all sorts of issues including BSOD's. Running each stick on its own through this memtest86 passed with no problems. Replaced one stick SENDING 1 back and getting another fixed this. |
|
| 670. |
Solve : RunDLL on USB Flashdisk. I need quick help please? |
|
Answer» I cannot open my USB Flashdisk, note: it's an MP3 player too, SANDISK Sansa e140 |
|
| 671. |
Solve : Security Programs? |
|
Answer» For security, I use MSE, a firewall, M.Bytes, & am careful to DEFRAG, do scans, UPDATES, WHATEVER. Is there more i should be doing, more programs I should be using? I once had Windows Defender, don't have it now. |
|
| 672. |
Solve : Scanning with antivirus/malware? |
|
Answer» I have Avira Antivirus, SUPER Anti-Spyware and Malwarebytes Anti-Malware - I run a FULL scan with each of these about once a MONTH, running each scan separately. Would it matter if I ran the scans at the same time, or would this cause some sort of conflict? |
|
| 673. |
Solve : Bootmgr and multiple errors.? |
|
Answer» TreeHello. |
|
| 674. |
Solve : Is there any virus or something else?? |
|
Answer» I usually send and receive attachments through mail. Now I am facing a problem, my computer is generating automatic attachments to all documents when I compose a mail.
One of my friends suggested me to install Immunet antivirus as it provides full protection, now I’m confused what should I install in my PC, Immunet or Malwarebytes? Please help. |
|
| 675. |
Solve : How to remove virus without using antivirus.? |
|
Answer» SIR if there is virus in the computer how to find it manually and remove without using antivirus. And mostly virus is hidden in which file.Scan for malware Please download Malwarebytes Anti-Malware from HERE. Double Click mbam-setup.exe to install the application.
Malwarebytes' Anti-Rootkit Please download Malwarebytes' Anti-Rootkit and save it to your desktop.
|
|
| 676. |
Solve : Warning about "Windows Live Virus"? |
|
Answer» Just received an urgent EMAIL about virus called "windows live virus". Couldn't find anything on the internet about this except a DEBUNK by Snopes in September, 2012. Has ANYONE else heard this? Right here is the closest related to Windows Essentials (fake) Antivirus: HTTP://www.bleepingcomputer.com/virus-removal/remove-fake-microsoft-security-essentials-alertThanks for the info DMJ. I ALWAYS know I can get the proper info here. |
|
| 677. |
Solve : Computer wont boot programs? |
|
Answer» I cannot get my LAPTOP to ACCESS MALWAREBYTES ...from the Hope site.Hi there. WELCOME to the forums. |
|
| 678. |
Solve : malware/virus started with ransom from moneypak now won't boot safe mode? |
|
Answer» My computer won't boot in safe mode it keeps returning to the screen that wants to know if I want safe mode or whatever. If I don't select normal it keeps going in circles. It started with moneypak ransom note now shows can't find web page. Will not let me do anything, goes quickly to the page and freezes out. Can some one please save me?
Safe Mode: If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there. (To boot into Safe Mode, tap F8 after BIOS, and just before the Windows logo appears. A list of options will appear, select "Safe Mode.") Re-downloading: If this doesn't work either, try the same method (above method), but try to download it again, except name ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe. Malware is KNOWN for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe. NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.thanks for responding, but I can not do anything once I get to the windows because the screen is blocked. Also I can't get to safe mode, it keeps sending me in a circle until I push normalOTLPE + Farbar Recovery Scan Tool
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-10-2012 Ran by SYSTEM at 31-10-2012 13:32:07 Running from J:\ Microsoft Windows XP (X86) OS Language: English(US) The current controlset is ControlSet004 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [CHotkey] zHotkey.exe HKLM\...\Run: [QuickTime Task] "C:\program files\quicktime\qttask.exe" -atboottime [98304 2010-01-21] (Apple Computer, Inc.) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [919008 2012-07-27] (Adobe Systems Incorporated) HKLM\...\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot [296056 2012-07-02] (RealNetworks, Inc.) HKLM\...\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252296 2012-01-17] (Sun Microsystems, Inc.) HKLM\...\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe [135168 2004-10-18] (Alcor Micro, Corp.) HKLM\...\Run: [SoundMan] SOUNDMAN.EXE HKLM\...\Run: [ShowWnd] ShowWnd.exe HKLM\...\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE [212992 2002-09-13] () HKLM\...\Run: [Philips Device Listener] "C:\Program Files\Philips\Philips Songbird Resources\Autolauncher\PhilipsDeviceListener.exe" [375296 2010-05-27] () HKLM\...\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [50688 2003-06-07] (Microsoft® Corporation) HKLM\...\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe HKLM\...\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon [86016 2012-10-01] (alch) HKLM\...\Run: [AllShareAgent] C:\Program Files\Samsung\AllShare\AllShareAgent.exe [282512 2011-07-16] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [AlcWzrd] ALCWZRD.EXE HKLM\...\Run: [Alcmtr] ALCMTR.EXE HKLM\...\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard) HKLM\...\Run: [SearchSettings] "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe" [1111432 2012-10-16] (Spigot, Inc.) HKLM\...\Run: [Windows Service] C:\Documents and Settings\Owner\Application Data\ukovn\ukovn.exe [154624 2012-10-29] (Auslogics) HKU\Owner\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [15360 2008-04-13] (Microsoft Corporation) HKU\Owner\...\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [1695232 2008-04-13] (Microsoft Corporation) HKU\Owner\...\Run: [Google Update] "C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [116648 2012-09-20] (Google Inc.) HKU\Owner\...\Run: [Windows Service] C:\Documents and Settings\Owner\Application Data\ukovn\ukovn.exe [154624 2012-10-29] (Auslogics) Winlogon\Notify\igfxcui: igfxsrvc.dll (Intel Corporation) AppInit_DLLs: Tcpip\..\Interfaces\{F7274D1D-E0A8-433A-937A-57259744774F}: [NameServer]156.154.70.22,156.154.71.22 Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DisplayKEY eSYNC Info.lnk ShortcutTarget: DisplayKEY eSYNC Info.lnk -> C:\dKEYUSBCradle\SyncInfoApp.exe (Supra) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WPN111 Smart Wizard.lnk ShortcutTarget: NETGEAR WPN111 Smart Wizard.lnk -> C:\Program Files\NETGEAR\WPN111\wpn111.exe (NETGEAR) Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe () ==================== Services (Whitelisted) =================== 2 AdvancedSystemCareService6; C:\Program Files\IObit\Advanced SystemCare 6\ASCService.exe [1026432 2012-10-12] (IObit) 2 Application Updater; "C:\Program Files\Application Updater\ApplicationUpdater.exe" [799112 2012-10-09] (Spigot, Inc.) 3 AppMgmt; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation) 2 dKeySync; C:\dKEYUSBCradle\SyncService.exe [42496 2011-11-11] (Supra) 2 Eventlog; C:\Windows\System32\services.exe [110592 2009-02-06] (Microsoft Corporation) 4 HidServ; C:\Windows\System32\svchost.exe -k netsvcs [14336 2008-04-13] (Microsoft Corporation) 2 IMFservice; C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe [820568 2011-07-20] (IObit) 2 MSSQL$OASIS; "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sOASIS [29293408 2010-12-10] (Microsoft Corporation) 2 SamsungAllShareV2.0; "C:\Program Files\Samsung\AllShare\AllShareDMS\AllShareDMS.exe" [24992 2011-07-16] (Samsung Electronics Co., Ltd.) 3 SimpleSlideShowServer; "C:\Program Files\Samsung\AllShare\AllShareSlideShowService.exe" [27584 2011-07-16] (Samsung Electronics Co., Ltd.) 3 FontCache3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe 3 idsvc; "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows COMMUNICATION Foundation\infocard.exe" 2 JavaQuickStarterService; "C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe" -service -config "C:\Program Files\Oracle\JavaFX 2.1 Runtime\lib\deploy\jqs\jqs.conf" 4 NetTcpPortSharing; "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" ==================== Drivers (Whitelisted) ==================== 2 AegisP; C:\Windows\System32\DRIVERS\AegisP.sys [21275 2010-01-29] (Meetinghouse Data Communications) 3 DNINDIS5; \??\C:\WINDOWS\system32\DNINDIS5.SYS [17149 2003-07-24] (Printing Communications Assoc., Inc. (PCAUSA)) 4 FileMonitor; \??\C:\Program Files\IObit\IObit Malware Fighter\Drivers\wxp_x86\FileMonitor.sys [239600 2011-07-11] () 3 HdAudAddService; C:\Windows\System32\drivers\HdAudio.sys [113664 2004-03-17] (Windows (R) Server 2003 DDK provider) 3 HDAudBus; C:\Windows\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider) 3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21568 2007-01-17] (HP) 3 ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [737874 2004-08-20] (Intel Corporation) 3 mxnic; C:\Windows\System32\DRIVERS\mxnic.sys [19968 2001-08-17] (Macronix International Co., Ltd. ) 1 P3; C:\Windows\System32\DRIVERS\p3.sys [42752 2008-04-13] (Microsoft Corporation) 2 PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [172032 2010-01-21] (New Boundary Technologies, Inc.) 3 RegFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\regfilter.sys [30368 2011-03-23] (IObit.com) 3 ROCKEYNT; C:\Windows\System32\DRIVERS\Rockey4.sys [22016 2004-02-13] (Feitian Technologies Co., Ltd.) 3 Rockey_USB; C:\Windows\System32\DRIVERS\Rockey4USB.sys [12928 2004-02-13] (Feitian Technologies Co., Ltd.) 1 SBRE; \??\C:\WINDOWS\system32\drivers\SBREdrv.sys [93872 2009-08-05] (Sunbelt Software) 3 silabenm; C:\Windows\System32\DRIVERS\silabenm.sys [49416 2011-11-11] (Silicon Laboratories) 3 silabser; C:\Windows\System32\DRIVERS\silabser.sys [66568 2011-11-11] (Silicon Laboratories) 0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [13496 2011-02-23] () 3 SunkFilt; \??\C:\WINDOWS\System32\Drivers\sunkfilt.sys [40724 2004-10-20] (Alcor Micro Corp.) 3 SunkFilt39; \??\C:\WINDOWS\System32\Drivers\sunkfilt39.sys [42968 2004-10-18] (Alcor Micro Corp.) 3 UrlFilter; \??\C:\Program Files\IObit\IObit Malware Fighter\drivers\wxp_x86\UrlFilter.sys [16080 2011-03-23] (IObit.com) 3 WPN111; C:\Windows\System32\DRIVERS\WPN111.sys [384608 2008-04-18] (Atheros Communications, Inc.) 4 Abiosdsk; 4 Atdisk; 1 Changer; 3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys 3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys 1 lbrtfdc; 1 PCIDump; 3 PDCOMP; 3 PDFRAME; 3 PDRELI; 3 PDRFRAME; 4 Simbad; 3 slabbus; C:\Windows\System32\DRIVERS\slabbus.sys 3 slabser; C:\Windows\System32\DRIVERS\slabser.sys 3 Sunkfiltp; 3 wanatw; C:\Windows\System32\DRIVERS\wanatw4.sys 3 WDICA; ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2012-10-31 11:23 - 2012-10-31 11:23 - 00000000 ____D C:\FRST 2012-10-29 17:47 - 2012-10-29 17:47 - 00000000 ____D C:\Documents and Settings\Owner\Application Data\ukovn 2012-10-28 16:50 - 2012-10-30 10:22 - 00014662 ____A C:\Windows\setupapi.log 2012-10-28 13:30 - 2012-10-28 13:33 - 00000000 ____D C:\Documents and Settings\Owner\My Documents\taftplan1_files 2012-10-24 11:24 - 2012-10-24 11:24 - 00000874 ____A C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 6.lnk 2012-10-24 11:24 - 2012-10-24 11:24 - 00000000 ____D C:\Documents and Settings\LocalService\Application Data\IObit 2012-10-20 13:22 - 2012-10-20 13:22 - 00000000 ____D C:\Program Files\IObit Toolbar 2012-10-20 13:22 - 2012-10-20 13:22 - 00000000 ____D C:\Program Files\Common Files\Spigot 2012-10-20 13:22 - 2012-10-20 13:22 - 00000000 ____D C:\Program Files\Application Updater 2012-10-20 13:22 - 2012-10-20 13:22 - 00000000 ____D C:\Documents and Settings\Owner\Application Data\Search Settings 2012-10-17 19:11 - 2007-11-06 22:10 - 00271704 ___RA (Hewlett-Packard) C:\Windows\System32\hpzids01.dll 2012-10-17 19:10 - 2007-10-31 06:35 - 00729088 ___RA (Hewlett-Packard) C:\Windows\System32\hpwwiax4.dll 2012-10-17 19:10 - 2007-10-31 06:35 - 00593920 ___RA (Hewlett-Packard Co.) C:\Windows\System32\hpwtscl3.dll 2012-10-17 19:10 - 2007-01-17 12:37 - 00364544 ___RA (Hewlett-Packard) C:\Windows\System32\hppldcoi.dll 2012-10-17 19:10 - 2007-01-17 12:37 - 00309760 ___RA (Microsoft Corporation) C:\Windows\System32\difxapi.dll 2012-10-17 19:10 - 2007-01-17 12:31 - 00294912 ___RA (Hewlett-Packard Co.) C:\Windows\System32\hpovst11.dll 2012-10-17 19:07 - 2012-10-17 19:07 - 00001968 ____A C:\Documents and Settings\All Users\Desktop\HP Document Manager.lnk 2012-10-17 19:07 - 2012-10-17 19:07 - 00001858 ____A C:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 2.5.lnk 2012-10-17 19:06 - 2012-10-17 19:06 - 00000984 ____A C:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk 2012-10-17 19:06 - 2012-10-17 19:06 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\HP Product Assistant 2012-10-17 19:04 - 2012-10-17 19:04 - 00000000 ____D C:\Program Files\Common Files\HP 2012-10-17 18:58 - 2012-10-17 19:15 - 00178364 ____A C:\Windows\hpwins20.dat 2012-10-17 18:58 - 2008-01-08 08:42 - 00002428 ___RA C:\Windows\hpwmdl20.dat 2012-10-10 12:38 - 2012-10-10 12:38 - 00000000 __HDC C:\Windows\$NtUninstallKB2724197$ 2012-10-10 12:36 - 2012-10-10 12:36 - 00000000 __HDC C:\Windows\$NtUninstallKB2756822$ 2012-10-10 12:36 - 2012-10-10 12:36 - 00000000 __HDC C:\Windows\$NtUninstallKB2749655$ 2012-10-10 12:35 - 2012-10-10 12:35 - 00000000 __HDC C:\Windows\$NtUninstallKB2661254-v2$ 2012-10-10 11:51 - 2012-10-10 11:51 - 00197908 ____A C:\Documents and Settings\Owner\My Documents\verification WORKSHEET - Dep.prn 2012-10-09 16:53 - 2012-10-09 16:53 - 00018944 ____A C:\Documents and Settings\Owner\My Documents\ltr painter remae.wps 2012-10-08 15:28 - 2012-10-08 15:28 - 10220472 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe 2012-10-04 13:57 - 2012-10-04 13:57 - 08429932 ____A C:\Documents and Settings\Owner\My Documents\hooperbankdocs7 ==================== 3 Months Modified Files ================== 2012-10-31 12:54 - 2010-02-01 13:55 - 00000274 ____A C:\Windows\wiadebug.log 2012-10-31 12:54 - 2010-02-01 13:55 - 00000050 ____A C:\Windows\wiaservc.log 2012-10-31 12:54 - 2010-01-22 23:49 - 00000374 ____A C:\Windows\System32\Drivers\etc\hosts.ics 2012-10-31 12:54 - 2004-08-26 14:09 - 00000178 __ASH C:\Documents and Settings\Owner\ntuser.ini 2012-10-31 12:54 - 2004-08-26 14:08 - 00031904 ____A C:\Windows\SchedLgU.Txt 2012-10-31 12:54 - 2004-08-26 14:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-10-31 12:54 - 2004-08-26 14:02 - 01360477 ____A C:\Windows\WindowsUpdate.log 2012-10-31 12:53 - 2011-07-27 13:24 - 00000280 ____A C:\Windows\Tasks\SmartDefrag_Startup.job 2012-10-31 12:52 - 2012-01-01 18:28 - 00000278 ____A C:\Windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2615104831-1368381422-192617974-1003.job 2012-10-31 12:52 - 2004-08-26 14:09 - 00000062 __ASH C:\Documents and Settings\Owner\Local Settings\desktop.ini 2012-10-31 12:52 - 2004-08-26 14:08 - 00000062 __ASH C:\Documents and Settings\NetworkService\Local Settings\desktop.ini 2012-10-31 12:52 - 2004-08-26 14:08 - 00000062 __ASH C:\Documents and Settings\LocalService\Local Settings\desktop.ini 2012-10-30 10:22 - 2012-10-28 16:50 - 00014662 ____A C:\Windows\setupapi.log 2012-10-30 09:41 - 2004-08-26 12:12 - 00001170 ____A C:\Windows\System32\wpa.dbl 2012-10-29 19:41 - 2012-09-20 12:31 - 00000978 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2615104831-1368381422-192617974-1003UA.job 2012-10-29 16:25 - 2012-05-11 12:16 - 00000392 ___AH C:\Windows\Tasks\User_Feed_Synchronization-{B1DA1CAD-FBC4-4C41-8FEF-946DF398194F}.job 2012-10-28 16:42 - 2010-02-01 13:55 - 00000000 ____A C:\Windows\Sti_Trace.log 2012-10-28 13:08 - 2011-10-09 15:38 - 00000286 ____A C:\Windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2615104831-1368381422-192617974-1003.job 2012-10-27 11:15 - 2012-09-13 12:45 - 00149168 ____A C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2012-10-27 10:41 - 2012-09-20 12:31 - 00000926 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2615104831-1368381422-192617974-1003Core.job 2012-10-24 11:24 - 2012-10-24 11:24 - 00000874 ____A C:\Documents and Settings\All Users\Desktop\Advanced SystemCare 6.lnk 2012-10-18 16:33 - 2012-07-02 12:20 - 29356032 ____A C:\Windows\System32\config\software.iobit 2012-10-18 16:33 - 2012-07-02 12:20 - 09592832 ____A C:\Windows\System32\config\system.iobit 2012-10-18 16:33 - 2012-07-02 12:20 - 00651264 ____A C:\Windows\System32\config\default.iobit 2012-10-18 16:33 - 2012-07-02 12:20 - 00061440 ____A C:\Windows\System32\config\SECURITY.iobit 2012-10-18 16:33 - 2012-07-02 12:20 - 00028672 ____A C:\Windows\System32\config\SAM.iobit 2012-10-17 19:15 - 2012-10-17 18:58 - 00178364 ____A C:\Windows\hpwins20.dat 2012-10-17 19:15 - 2010-02-04 12:23 - 00008916 ____A C:\Documents and Settings\All Users\Application Data\hpzinstall.log 2012-10-17 19:14 - 2004-08-26 12:12 - 00000616 ____A C:\Windows\win.ini 2012-10-17 19:07 - 2012-10-17 19:07 - 00001968 ____A C:\Documents and Settings\All Users\Desktop\HP Document Manager.lnk 2012-10-17 19:07 - 2012-10-17 19:07 - 00001858 ____A C:\Documents and Settings\All Users\Desktop\HP Photosmart Essential 2.5.lnk 2012-10-17 19:06 - 2012-10-17 19:06 - 00000984 ____A C:\Documents and Settings\All Users\Desktop\HP Solution Center.lnk 2012-10-11 16:13 - 2010-05-06 00:25 - 00019968 ____A C:\Documents and Settings\Owner\My Documents\Ltr Head.wps 2012-10-11 16:13 - 2010-02-09 18:50 - 00001618 ____A C:\Documents and Settings\Owner\Application Data\wklnhst.dat 2012-10-11 11:51 - 2012-09-20 12:32 - 00002284 ____A C:\Documents and Settings\Owner\Desktop\Google Chrome.lnk 2012-10-10 12:36 - 2010-01-31 05:04 - 00035396 ____A C:\Windows\System32\TZLog.log 2012-10-10 12:36 - 2010-01-30 11:36 - 62968832 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2012-10-10 11:51 - 2012-10-10 11:51 - 00197908 ____A C:\Documents and Settings\Owner\My Documents\verification worksheet - Dep.prn 2012-10-09 16:53 - 2012-10-09 16:53 - 00018944 ____A C:\Documents and Settings\Owner\My Documents\ltr painter remae.wps 2012-10-08 15:28 - 2012-10-08 15:28 - 10220472 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerInstaller.exe 2012-10-08 15:28 - 2012-03-30 10:20 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2012-10-08 15:28 - 2011-05-18 18:42 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2012-10-04 14:48 - 2012-03-04 18:00 - 00000682 ____A C:\Documents and Settings\All Users\Desktop\CCleaner.lnk 2012-10-04 13:57 - 2012-10-04 13:57 - 08429932 ____A C:\Documents and Settings\Owner\My Documents\hooperbankdocs7 2012-09-30 09:29 - 2012-03-30 10:20 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-09-26 15:43 - 2012-04-06 12:47 - 00054156 ___AH C:\Windows\QTFont.qfn 2012-09-11 21:14 - 2004-08-26 12:12 - 00000227 ____A C:\Windows\system.ini 2012-09-11 21:14 - 2004-08-26 12:12 - 00000211 _RASH C:\boot.ini 2012-09-11 08:34 - 2008-04-13 20:12 - 00046080 ____N (Microsoft Corporation) C:\Windows\System32\tzchange.exe 2012-08-28 21:44 - 2010-01-30 11:51 - 11111424 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieframe.dll 2012-08-28 21:44 - 2009-03-08 06:39 - 11111424 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-08-28 11:14 - 2012-07-12 19:41 - 00521728 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\jsdbgui.dll 2012-08-28 11:14 - 2010-11-22 11:47 - 00743424 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iedvtool.dll 2012-08-28 11:14 - 2010-01-30 11:52 - 00012800 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\xpshims.dll 2012-08-28 11:14 - 2010-01-30 11:51 - 02000384 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iertutil.dll 2012-08-28 11:14 - 2010-01-30 11:51 - 00630272 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msfeeds.dll 2012-08-28 11:14 - 2010-01-30 11:51 - 00247808 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ieproxy.dll 2012-08-28 11:14 - 2010-01-30 11:51 - 00055296 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\msfeedsbs.dll 2012-08-28 11:14 - 2009-03-08 06:32 - 02000384 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-08-28 11:14 - 2009-03-08 06:32 - 00630272 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-08-28 11:14 - 2009-03-08 06:31 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 06008832 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\mshtml.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 06008832 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 01212416 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\urlmon.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 01212416 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00916992 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wininet.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00916992 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00611840 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\mstime.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00611840 ____A (Microsoft Corporation) C:\Windows\System32\mstime.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00206848 ____N (Microsoft Corporation) C:\Windows\System32\occache.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00206848 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\occache.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00105984 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\url.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00105984 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00067072 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\mshtmled.dll 2012-08-28 11:14 - 2004-08-26 12:12 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-08-28 11:14 - 2004-08-26 12:11 - 01469440 ____N (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-08-28 11:14 - 2004-08-26 12:11 - 01469440 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\inetcpl.cpl 2012-08-28 11:14 - 2004-08-26 12:11 - 00387584 ____N (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2012-08-28 11:14 - 2004-08-26 12:11 - 00387584 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iedkcs32.dll 2012-08-28 11:14 - 2004-08-26 12:11 - 00184320 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\iepeers.dll 2012-08-28 11:14 - 2004-08-26 12:11 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2012-08-28 11:14 - 2004-08-26 12:11 - 00043520 ___AC (Microsoft Corporation) C:\Windows\System32\dllcache\licmgr10.dll 2012-08-28 11:14 - 2004-08-26 12:11 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2012-08-28 11:14 - 2004-08-26 12:11 - 00025600 ____N (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-08-28 11:14 - 2004-08-26 12:11 - 00025600 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\jsproxy.dll 2012-08-28 08:07 - 2004-08-26 12:11 - 00385024 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2012-08-28 08:07 - 2004-08-26 12:11 - 00174080 ____N (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2012-08-28 08:07 - 2004-08-26 12:11 - 00174080 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ie4uinit.exe 2012-08-24 09:53 - 2009-12-24 02:59 - 00177664 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\wintrust.dll 2012-08-24 09:53 - 2004-08-26 12:12 - 00177664 ____A (Microsoft Corporation) C:\Windows\System32\wintrust.dll 2012-08-21 09:33 - 2010-01-30 05:29 - 02148864 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrnlmp.exe 2012-08-21 09:29 - 2010-01-30 05:29 - 02192896 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntoskrnl.exe 2012-08-21 09:29 - 2004-08-26 12:12 - 02192896 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe 2012-08-21 08:58 - 2010-01-30 05:29 - 02027520 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrpamp.exe 2012-08-21 08:58 - 2009-02-07 21:02 - 02069632 ____C (Microsoft Corporation) C:\Windows\System32\dllcache\ntkrnlpa.exe 2012-08-21 08:58 - 2004-08-04 01:59 - 02069632 ____A (Microsoft Corporation) C:\Windows\System32\ntkrnlpa.exe 2012-08-15 19:07 - 2004-08-26 06:54 - 00245512 ____A C:\Windows\System32\FNTCACHE.DAT 2012-08-13 12:13 - 2012-08-13 12:13 - 00622003 ____A C:\Documents and Settings\Owner\My Documents\annuitygpdisclesaud.zip ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points (XP) ===================== RP: -> 2012-10-29 19:53 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP281 RP: -> 2012-10-27 20:20 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP280 RP: -> 2012-10-26 19:46 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP279 RP: -> 2012-10-25 15:30 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP278 RP: -> 2012-10-23 18:45 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP277 RP: -> 2012-10-21 19:37 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP276 RP: -> 2012-10-17 19:14 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP275 RP: -> 2012-10-17 18:01 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP274 RP: -> 2012-10-16 15:42 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP273 RP: -> 2012-10-11 17:52 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP272 RP: -> 2012-10-10 12:35 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP271 RP: -> 2012-10-09 18:24 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP270 RP: -> 2012-10-08 18:12 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP269 RP: -> 2012-10-07 15:01 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP268 RP: -> 2012-10-05 12:00 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP267 RP: -> 2012-10-04 11:29 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP266 RP: -> 2012-10-03 14:40 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP265 RP: -> 2012-10-01 19:58 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP264 RP: -> 2012-09-30 11:24 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP263 RP: -> 2012-09-28 10:35 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP262 RP: -> 2012-09-26 16:59 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP261 RP: -> 2012-09-25 14:51 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP260 RP: -> 2012-09-24 09:56 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP259 RP: -> 2012-09-22 20:57 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP258 RP: -> 2012-09-21 19:20 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP257 RP: -> 2012-09-21 13:49 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP256 RP: -> 2012-09-20 13:31 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP255 RP: -> 2012-09-18 20:19 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP254 RP: -> 2012-09-17 19:45 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP253 RP: -> 2012-09-16 12:06 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP252 RP: -> 2012-09-14 17:48 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP251 RP: -> 2012-09-12 21:52 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP250 RP: -> 2012-09-11 21:44 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP249 RP: -> 2012-09-11 14:28 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP248 RP: -> 2012-09-10 12:33 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP247 RP: -> 2012-09-09 11:00 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP246 RP: -> 2012-09-07 14:22 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP245 RP: -> 2012-09-06 11:30 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP244 RP: -> 2012-09-05 11:16 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP243 RP: -> 2012-09-03 16:41 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP242 RP: -> 2012-09-01 19:26 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP241 RP: -> 2012-08-30 21:02 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP240 RP: -> 2012-08-29 20:36 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP239 RP: -> 2012-08-21 17:31 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP238 RP: -> 2012-08-20 16:35 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP237 RP: -> 2012-08-18 16:40 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP236 RP: -> 2012-08-17 00:07 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP235 RP: -> 2012-08-16 12:19 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP234 RP: -> 2012-08-15 11:18 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP233 RP: -> 2012-08-15 11:18 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP232 RP: -> 2012-08-15 11:17 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP231 RP: -> 2012-08-15 11:16 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP230 RP: -> 2012-08-15 11:15 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP229 RP: -> 2012-08-14 13:15 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP228 RP: -> 2012-08-13 12:56 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP227 RP: -> 2012-08-12 11:44 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP226 RP: -> 2012-08-11 10:14 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP225 RP: -> 2012-08-09 18:44 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP224 RP: -> 2012-08-07 18:14 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP223 RP: -> 2012-08-06 17:17 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP222 RP: -> 2012-08-04 21:38 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP221 RP: -> 2012-08-03 20:48 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP220 RP: -> 2012-08-02 13:07 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP219 RP: -> 2012-07-31 18:35 - 028672 _restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP218 ==================== Memory info =========================== Percentage of memory in use: 42% Total physical RAM: 501.75 MB Available physical RAM: 288.37 MB Total Pagefile: 453.51 MB Available Pagefile: 319.86 MB Total Virtual: 2047.88 MB Available Virtual: 2002.54 MB ==================== Partitions ============================= 1 Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS 2 Drive c: () (Fixed) (Total:144.83 GB) (Free:79.16 GB) NTFS ==>[Drive with boot components (Windows XP)] 7 Drive h: () (Fixed) (Total:4.2 GB) (Free:1.68 GB) FAT32 9 Drive j: (USB MEMORY) (Removable) (Total:0.06 GB) (Free:0.06 GB) FAT 10 Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS Disk ### Status Size Free Dyn Gpt -------- ---------- ------- ------- --- --- Disk 0 Online 149 GB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 4314 MB 32 KB Partition 2 Primary 145 GB 4314 MB ========================================================= Disk: 0 Partition 1 Type : 0B Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 H FAT32 Partition 4314 MB Healthy ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 C NTFS Partition 145 GB Healthy =========================================================FRST Fixlist Please run the following: Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste). Save it on the flashdrive as fixlist.txt Quote start NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system Now, please enter OTLPE and access the flash drive. Run FRST and press the Fix button just once and wait. The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply. Now restart, let it boot normally and tell me how it went.You are amazing, thank you so very much. What could I do to prevent this in the future? Here is the fixlog Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 30-10-2012 Ran by SYSTEM at 2012-10-31 17:12:35 Run:1 Running from J:\ ============================================== C:\Documents and Settings\Owner\Application Data\ukovn moved successfully. C:\Program Files\IObit Toolbar moved successfully. C:\Program Files\Common Files\Spigot moved successfully. C:\Program Files\Application Updater moved successfully. C:\Documents and Settings\Owner\Application Data\Search Settings moved successfully. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings Value deleted successfully. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Service Value deleted successfully. HKEY_USERS\Owner\Software\Microsoft\Windows\CurrentVersion\Run\\Windows Service Value deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs Value was restored successfully . Application Updater service deleted successfully. ==== End of Fixlog ====It's good that it helped fix the main issue, but I want to make sure the other viruses are gone too that may have come "bundled" with this threat (MoneyPak FBI) ComboFix scan Please download ComboFix by sUBs From BleepingComputer.com Please save the file to your Desktop. Important information about ComboFix After the download:
Safe Mode: If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there. (To boot into Safe Mode, tap F8 after BIOS, and just before the Windows logo appears. A list of options will appear, select "Safe Mode.") Re-downloading: If this doesn't work either, try the same method (above method), but try to download it again, except name ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe. Malware is known for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe. NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error. |
|
| 679. |
Solve : Remote Computer Access Worries? |
|
Answer» Hi, Could the techy have done any of this without my friend seeing it on the monitor?Something could have been downloaded on the computer. Quote Also, what are the chances that the techy could gain access to my friend's computer again without his permission/knowledge and what are the chances that the techy could "watch" what my friend does in the future?You actually have to give permission for someone to have remote control. Just be sure that permission is turned off. Quote As my friend is worried about this issue, we tried looking up more information on this topic but could not find definitive answers.Tell him to install a good third-party firewall. That should catch and in-bound or out-bound traffic. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you CHOOSE this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are USING the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO REPLACEMENT for a dedicated software solution. Remember to use only one firewall at the same time. |
|
| 680. |
Solve : pc constantly restarts prob malware related?? |
|
Answer» uh ohh it restarted after like 45 minutes on longest i been on without restart its still RUNNING real fast but what the f**k is making it restart? should i just try the remove cards and ram 1 at a time then seeing what happens when i run it? That's what I suggested yesterday. Please reread ALL the posts. i know U did but i was just reinforcing it i guess u could call it, i wasnt trying to TAKE u idea I was wanting price to take my idea.lol my bad |
|
| 681. |
Solve : ClamWin and Bitdefender? |
|
Answer» Has anyone ever used CLAMWIN free and Bitdefender Free Edition? I've READ about them from VARIOUS places, but am not sure about them. I've also heard that Bitdefender Free expires after a year...is that true?I believe BitDefender free only lasts 30 days as a trial (From what I read). Clamwin is okay, yet still no comparison to a full subscribed antivirus, which is what you should be looking for if you want maximum protection.Not sure why you WOULD want to use fringe products when there are so many better known ones, and free to boot.Well, I just want to see if they're worth using at all. I already use avast! and plan to get AntiVir.One antivirus running at a time is all you need. More than that causes PROBLEMS. |
|
| 682. |
Solve : Out of system resources? |
|
Answer» Aagh. Just when you think you're safe, you get hit again. (As an aside, I have a question about SpywareBlaster. Does it need to be running while I browse the net to work, or does it work "behind-the-scenes"?) It has to be running to be doing it's job, by definition.Oh, I thought it was supposed to run in the background like too many programs today do. Ah, I had to ask that stupid question sometime. AVG and the hosts file... http://forum.zonelabs.org/zonelabs/board/message?board.id=AllAboutPorts&message.id=7982 patio. 8-) Quote Oh, I thought it was supposed to run in the background like too many programs today do. Ah, I had to ask that stupid question sometime.I don't use SpywareBlaster but, surely, if it's running in the background, then it IS running and IS providing protection, same as anti-virus or other programs that run in the background. Quote Dilbert, lol yea i put linux on the family comp but it ask you to choose an operating system with u first start the computer so i couldnt hide it lol..Try accessing the website through http://www.ninjaproxy.com/ worth a shot. |
|
| 683. |
Solve : cannot delete file?? |
|
Answer» i have a big bropbleme here my bro downloaded some pron of limewire and that file does not want to be deleted? |
|
| 684. |
Solve : Can't remove program? |
|
Answer» Hi everyone. I need help. My son downloaded "Morpheus" and I can't get rid of it. It has an Uninstall feature that won't work and I also tried GOING thru "Add and Remove" PROGRAMS. Nothing happens, computer just hangs. How do I get rid of this program? Thanks to all. Sometimes things get broken in the uninstaller, and a reinstall THEN an uninstall works wonders.ahhhh morpheus .....should have used LIMEWIRE.................GX1_man is right, reinstalling usually works....or try to get rid of it in safe mode. |
|
| 685. |
Solve : Constant Choking Every Few Seconds... Why?? |
|
Answer» I've had my computer for a couple years, and as long as I can remember, it's stalled for about a half-second once every 10 seconds. But not always. Most often when I'm playing a game or watching a movie, and sometimes after a while it'll go AWAY. I've noticed also that (what I think is) the hard drive LED on my case flashes at the same times the computer stalls. This leads me to think it's a hard drive problem, but I still have no idea where to go from there. Does it stall in safe mode?Quote Trust me, it's clean.BTW,... O2 - BHO: Windows Resources CLSID: {2D38A51A-23C9-48a1-A33C-48675AA2B494} STATUS: X BHO TB Filename(s): winres.dll Object name: Windows Resources Description: CoolWebSearch O2 - BHO: ATLDistrib Object CLSID: {83A5F7B7-DC75-44CE-9195-264F41709FA9} Status: X BHO TB Filename(s): *****.dll (* = random character) Object name: ATLDistrib Object Description: Virtumonde/Vundo antonaros..... Quote Trust me, it's clean. I had the latest Panda trial recently....... TRUST ME IT'S NOT CLEAN , in fact far from it ...... In addition to what Fed has already pointed out .......... You don't appear to have any sort of anti virus installed or running . You have no firewall installed . then mark for removal : The 2 items that Fed has listed as well as ...... the following : O2 - BHO: (no name) - {B930BA63-9E5A-11D3-A288-0000E80E2EDE} - (no file) O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - (no file) O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O4 - HKCU\..\Run: [WhatPulse] C:\Program Files\WhatPulse\WhatPulse.exe [highlight]Remove it unless you really need it [/highlight] O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Admin\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing) O18 - Filter: text/html - {994D478A-2BD0-4DB4-AE77-288B1E346E99} - C:\Program Files\FCHelp\FCHelp.dll O20 - Winlogon Notify: ddabx - C:\WINDOWS\system32\ddabx.dll O20 - Winlogon Notify: wingsa32 - C:\WINDOWS\SYSTEM32\wingsa32.dll O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing) O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing) O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing In addition to this , you had better fix....... this one : O10 - Broken Internet access because of LSP provider 'xfire_lsp_8742.dll' missing Try and fix it by running LSPFix So other than whats listed , your machine is squeaky clean dl65 |
|
| 686. |
Solve : Someone is probing my ports....? |
|
Answer» Hi |
|
| 687. |
Solve : IAMDB.RDB.......What is it? |
|
Answer» Under the windows folder i have found a folder CALLED "internet Logs" containing "IAMDB.RDB" and a text file for each day with my internet logs. No Nothing to hide........ But i'm always concerned with my actions being tracked whether on a computer, cctv or the travel card i use on the underground.... its 1984 and big brother is watching Big brother has someone more important to worry about than you or me. Relax! But if you want more protection, try using a ROUTER with a built-in hardware firewall. This way, you will have the added protection of a software and hardware firewall. Relax, relax, How can you say that when theres a satilellite tracking my every movement.... wheres my tin foil helmet I guess the point that i was making is that a programme is recording my ACTIVITIES which i wasn't really aware of (as i only came across these files by chance) and is acting in a similar way to spyware. Which makes me wonder what other applications i have that are doing similar things (and before you say it, I run windows and guess they pretty much track everything) Good idea though on the router These are known as keyloggers...Google it for more info and steps to protect yourself. patio. 8-) |
|
| 688. |
Solve : Help installing MS02-039 Patch? |
|
Answer» I need someone to explain these installation instructions to me as I try to install this patch. I know very little about where to find THINGS like SQL Servers. I have done searches on the internet to find what pack of SQL I have but I don't know where to run what that tell me to run. I dont even have the path where it tells me to install this patch at. This patch is to stop attacks from Helkerns which Kaspersky keeps repelling more than 10+ while I'm surfing the net. If someone could help me I would be so grateful. |
|
| 689. |
Solve : Search Pop up? |
|
Answer» Hi guys. Download and install ShootTheMessenger and turn off messenger service...would updating his host FILES help the pop up problem too? it did with my grandma's alil |
|
| 690. |
Solve : Rogue/Suspect Anti-Spyware List? |
|
Answer» Just because this needs to be POSTED every now and then: |
|
| 691. |
Solve : AVG or NORTON,, which is best..? |
|
Answer» hi, I am currently running 2 virus programs but have been told to delete one.. but which one... |
|
| 692. |
Solve : somethings very fishy here? |
|
Answer» nope its still doing it, but i talked to dell and they are sending me a xp dixc so i can reformat... nope its still doing it, but i talked to dell and they are sending me a xp dixc so i can reformat... GOOD for them! You will be better off with a real XP CD for a lot of reasons. What model do you have?a dell dimension 5100 i ordered it for her a year AGO so it due for a reformat anywaysDownload and install and run the following removal tool in SafeMode... LET me know how it goes... patio. 8-) http://noahdfear.geekstogo.com/click%20counter/click.php?id=1ok i think that fixed the problem. when i start ie up it goes start to google.com thanks a million where do you find these programs??Sadly we never got to the end of the little FACT finding mission, not to worry, can you post a fresh HJT log just to be sure you are OK. Quote Sadly we never got to the end of the little fact finding mission, not to worry, can you post a fresh HJT log just to be sure you are OK. what do you mean finding mission? ill post one when i get HOME from workExactly what did you do to fix the problem unlovedwarrior? |
|
| 693. |
Solve : whats type of computer infection? |
|
Answer» Nothing major, just some datamining cookies that Ad-Aware usually finds. My AV, AntiVir may be a bit overly aggressive though. It has flagged simple utility programs (pskill.exe, ntregopt.exe and the MAGICAL Jellybean Key Finder) as viral activity. cuz if he hasnt done any scans laely then he WONT really know whats in his computer...unlovedwarrior, I think you MUST have failed Logic 101 miserably. Again, what does that have to do with SP2? what do those programs do?maybe cuz with sp1 it leaves his computer open... i never took logic im just starting college in like 11 days Quote what do those programs do?Are you not aware of Service Pack 2 (SP2) for Windows XP? It's a major update to Windows. If I recall correctly, it added the Security Center to the Windows Control Panel. It tightened security with IE, blocking popups, prompting the user to allow downloads, prompting the user to install ActiveX when visiting websites that use it, etc. And, it tightened security with Outlook EXPRESS for users who use it for email. You're talking about using adware/spyware tools to scan for adware/spyware. That's a separate matter from SP2. Make sense?yea, but whatever all i know is he probably has infection like no otherTrue but, again, SP2 makes a computer more SECURE and helps prevent getting nasty infections.ok, i guess |
|
| 694. |
Solve : how can i prevent icecold? |
|
Answer» like you know the application is called "IceCold" is a SMALL app. to prevent msn login (it use (maybe) Brute FORCE attack) Actually the app is called IceCold Reloaded. Why would you use such a product? The web site is listed as www.crapware.tk and the email address is [email protected]. Shouldn't this tell you something? my e-mail is frozen by someone which i do not know. i am certainly sure that it is made by icecold because i login hotmail but not login msn messenger see ? Quote see ? Not really. Can you not go to Icecold, download the application and defreeze your account? After visiting the site I would do some AV scans. Sites like this give programmers a bad name. 8-)Do you have a real Windows CD to reinstall if NECESSARY? |
|
| 695. |
Solve : can my website hack into my computer? |
|
Answer» i have a website set up on an external server, can any program be placed on my website that would then enable it to hack into my computer - i hope this makes sense. |
|
| 696. |
Solve : definition, please. . .? |
|
Answer» Can SOMEONE give me a plain-language definition of "HIJACKER" or "hijack" so i can EXPLAIN it to a customer? This person, until a week ago, was not aware that it was possible for the browser or computer to be hijacked and doesn't see the point of having hijack DETECTOR program. |
|
| 697. |
Solve : At a loss. Popups invading my brain.? |
|
Answer» So. I used spybot, ccleaner, norton, ad-aware in safemode. Norton and ad-aware found nothing, but spybot and ccleaner found over 150 issues, programs, files, etc. Yet, my computer still is driving me crazy with the same popups. I use Mozilla and they open up new tabs and RESIZE my internet window. The popups are from partypoker (I've never been there), heavy.com, telling me I need disk cleaners, stopzilla, etc. What else can I do? I work out of my home and this only began last Friday [highlight]when I let my mother do something-or-other on it.[/highlight] I also tried a system restore, but that didn't do anything. Not that I really expected it to ... |
|
| 698. |
Solve : spybot querie? |
|
Answer» Hi All |
|
| 699. |
Solve : HELP VERY MUCH NEEDED!? |
|
Answer» it might just be easier to do a reformat.... but lets see what the experts sayhave figures out (i think) where the problem is! The game i was playing at the time it first crashed is football manager. I have been trying to uninstall it but everytime i do it crashes! is there anyway to get it off my computer or am i stuck with formatting it?The whole thing SOUNDS FUBAR'ed. A good format and reinstal would have fixed it by now. How did you TRY and do the memtest86 test? |
|
| 700. |
Solve : Internet security package for small business? |
|
Answer» Hi, |
|