Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1751.

Solve : Please help me fix my computer from randomly freezing.?

Answer»

Hi, this is the log from the MBR:


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.6 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !

THANKS!Now delete the current mbr.log file from the desktop and then follow the below instructions.

Go to Start > Run then copy and paste the following into the Open field (do not copy the word Code):

Code: [Select]"%userprofile%\desktop\mbr.exe" -f
Double click on the mbr.exe file and post the contents of the new mbr.logOk, here is the newest file

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.6 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !

Thank you OK go ahead with the FULL Dr Web scan now and post that log please.

You can delete the mbr.exe and the log file.Ok, heres my log after the full scan:

T-3877633-daddys little girl al martino - greatest hits.mp3;C:\Documents and Settings\Brad\My Documents\Incomplete;Trojan.WMALoader;Cured.;
WxBug.EXE;C:\Program Files\aim\Sysfiles;Adware.Aws;;
morpheustoolbar.exe/data001\data006;C:\Program Files\Morpheus\morpheustoolbar.exe/data001;Adware.Msearch;;
data001;C:\Program Files\Morpheus;Container contains infected objects;;
morpheustoolbar.exe;C:\Program Files\Morpheus;Container contains infected objects;;

Thanks again. OK that found a few more. How is the computer running now?As of yet I've had now problems. So far I've been up for about 24 hours. Thanks again for all your help.Still no problems, thank you very much for all your guys' help. Sorry for the delay.

Download OTMoveIt3 by OldTimer OTMoveIt3.exe and place it on your desktop. (unless you already have it installed)

1. Double click OTMoveIt3.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the INTERNET, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list DOWNLOADED, Do you want to begin cleanup process?)
5. Once complete exit out of OTMoveIt3

----------

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.

  • Go to Start > Programs > Accessories > System Tools and click System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next GIVE the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also STOP certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
1752.

Solve : Transfer avg to another computer??

Answer»

Hi,

I have AVG 8.5 on my laptop which I DOWNLOADED at a high speed site.

Home I have DIAL up on our tower computer and wonder if SOMEHOW I can transfer AVG using a flash drive from the laptop to the tower?

Is this even possible? Otherwise I DOWNLOAD 66mb by phone and wait...and wait....and wait....aaaarrrgh.

Any help much appreciated.

sampDownload the setup and copy it to the flash drive.

To do this, when you click the download link, instead of clicking RUN, click save and save it to your desktop.Thanks very much...

I will try this.

Great forum by the way.

Gracias again,
sampAnytime.

Good Luck.

1753.

Solve : Nasty virus?

Answer» Your Java is out of date.

Older versions have vulnerabilities that malicious sites can use to infect your system.

First install the new Sun Java Runtime Environment

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click Additional Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the Desktop

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

----------


Update your Adobe Reader. http://get.adobe.com/reader/

Be sure to uncheck the Free McAfee Security Scan so it isn't installed.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Now restart the computer and try updating again.

.Well I have been working on the updates recommended from the Secunia Software Inspector. I get a message that "Windows Malicious Software Removal Tool - September 2009 (KB890830)" was installed successfully. And that "Security Update for Jscript 5.7 for Windows XP (KB971961)" Failed to update. I have performed this update a number of times through the Windows Update site and get the same result everytime.

The yellow shield is still coming back with a message that I NEED to install update KB890830. It's like something is blocking the update.

Thanks again for all of the help.Try the direct download for KB890830 http://www.microsoft.com/downloads/details.aspx?familyid=ad724ae0-e72d-4f54-9ab3-75b8eb148356&displaylang=enI am sorry for being such a pain. I tried the direct download 4 times and could never get it to install. But after I tried the direct download I clicked on the yellow shield and got the message "installation complete". I did this twice and rebooted each time and the yellow shield came back with the same message - that I needed to install the update.

If this is not a remnant from the virus I can live with it and leave you alone. My PC is running fine except for the annoying yellow shield.

Thanks for all of your help. I HOPE that I do not need to ask for your assistance anytime soon. EF and SD have been an incredible help.

I can not say thank you enough.

KarenHello Karen. Could you please try this:

The MRT (Malicious Software Removal tool) is located in WINDOWS\system32 and is named MRT.EXE
To see if it's present on your system.
Go to Start > Run > copy and paste the below into the Open: line

mrt
Click OK or press Enter
Wait a little while and the tool *should* open
Click the Next button
Put a mark next to 'Full Scan',click Next, and do a full scan
Please let me know what happens.SD, I am not sure what you want me to copy and paste, I tried "mrt" and got the following message:

"Windows cannot access the specified device, PATH or file. You may not have the appropriate PERMISSIONS to access the item."

Am I missing something?That's what I wanted to know. Apparently, the download is not completing itself. Mrt should have triggered the program to run if it was there. When you download the file do you save it then install it or do you install it right away?Did you try mrt.exe ?Yes, I tried MRT.EXE - same error message.

SD, I have tried both ways. I have saved and then installed. And I have installed right away.Hello Karan. We are quite sure that the problem you're experiencing with the MRT update from MS is not caused by an infection. Your computer appears to be clean. Perhaps you could contact MS Updates to see if they can help with the MRT update problem.

NOTE: Some of these you have already done.

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the LATEST Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

Safe SurfingThanks for all of your help!
1754.

Solve : Infecton I think.?

Answer»

I downloaded a program that i thought was a audio recording program but it asked me restart and it stopped my antivirus from running and firewall then I open them up manualy and avast is finding stuff. I have ran scans with MBAM and SAS but nothing much was found.

Malwarebytes' Anti-Malware 1.41
Database version: 2916
Windows 5.1.2600 Service Pack 3

10/6/2009 6:38:01 PM
mbam-log-2009-10-06 (18-38-01).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|)
Objects scanned: 54374
Time elapsed: 15 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\ComboFix\Combo-Fix.sys (Worm.Agent) -> Quarantined and deleted successfully.

(later did a full scan and found nothing)

Sas found nothing.Sorry I forgot the HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:59 PM, on 10/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {B17324EB-1C4E-453F-BAB4-E82D5F3314C2} - (no file)
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Search - ?p=ZRfox000
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: Add to Video Converter... - C:\Program Files\MP3 Player Utilities 5.10\AVIConverter\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {3EB3B7E8-1466-405A-B5BC-44513AF85E34} - (no file) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127362109437
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149835123078
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} (YYGInstantPlay Control) - http://www.yoyogames.com/downloads/activex/YoYo.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

--
End of file - 8700 bytes1) Put a check mark against the below entries and click "Fix checked" .

Quote

O2 - BHO: (no name) - {B17324EB-1C4E-453F-BAB4-E82D5F3314C2} - (no file)
O8 - Extra context menu item: &Search - ?p=ZRfox000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {3EB3B7E8-1466-405A-B5BC-44513AF85E34} - (no file) (HKCU)


2) Next download RootRepeal.rar and unzip it to your Desktop. You'll need WinRAR to extract it

* Double click RootRepeal.exe to start the program
* Click on the Report tab at the bottom of the program window
* Click the Scan button
* In the Select Scan dialog, check:
o Drivers
o Files
o Processes
o SSDT
o Stealth Objects
o Hidden Services
* Click the OK button
* In the next dialog, select all drives showing
* Click OK to start the scan


The scan can take some time. DO NOT run any other programs while the scan is running

* When the scan is complete, the Save Report button will become available
* Click this and save the report to your Desktop as RootRepeal.txt
* Go to File, then Exit to close the program
* Attach this log in your next post.

3) Download DDS by sUBs to your desktop.
Your antivirus software might question the file. If it does, allow it.

* Double click DDS.scr to run it and wait for the scan to finish
* When finished DDS.txt will open
* A small while later, a prompt will open. Answer Yes
* DDS will continue scanning
* When done, Attach.txt will open

Copy and paste the DDS.txt and attach Attach.txtHere is my logs G.

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time:2009/10/10 11:36
Program Version:Version 1.3.5.0
Windows Version:Windows XP Media Center Edition SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF6D79000Size: 98304File Visible: NoSigned: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7B1F000Size: 8192File Visible: NoSigned: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF6767000Size: 49152File Visible: NoSigned: -
Status: -

==EOF==

_______Atach.txt_______________________


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-29.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 9/19/2005 9:16:26 PM
System Uptime: 10/10/2009 11:26:09 AM (0 hours ago)

Motherboard: ASUSTek Computer INC. | | Amberine M
Processor: AMD Athlon(tm) 64 Processor 3500+ | Socket 939 | 2200/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 223 GiB total, 52.559 GiB free.
D: is FIXED (FAT32) - 8 GiB total, 0.961 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is Removable
H: is Removable
I: is Removable
J: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1251: 7/11/2009 2:17:13 AM - System Checkpoint
RP1252: 7/12/2009 3:04:12 AM - System Checkpoint
RP1253: 7/13/2009 3:14:28 AM - System Checkpoint
RP1254: 7/14/2009 3:17:53 AM - System Checkpoint
RP1255: 7/15/2009 12:00:26 AM - Software Distribution Service 3.0
RP1256: 7/16/2009 12:19:56 AM - System Checkpoint
RP1257: 7/16/2009 9:52:43 PM - Automatic Restore Point
RP1258: 7/17/2009 10:34:34 PM - System Checkpoint
RP1259: 7/19/2009 2:15:46 AM - System Checkpoint
RP1260: 7/20/2009 2:25:56 AM - System Checkpoint
RP1261: 7/21/2009 3:19:53 AM - System Checkpoint
RP1262: 7/22/2009 12:00:15 AM - Software Distribution Service 3.0
RP1263: 7/23/2009 3:02:57 AM - System Checkpoint
RP1264: 7/24/2009 3:20:56 AM - System Checkpoint
RP1265: 7/25/2009 4:19:52 AM - System Checkpoint
RP1266: 7/26/2009 5:19:50 AM - System Checkpoint
RP1267: 7/27/2009 5:40:43 AM - System Checkpoint
RP1268: 7/28/2009 6:40:42 AM - System Checkpoint
RP1269: 7/29/2009 12:00:26 AM - Software Distribution Service 3.0
RP1270: 7/30/2009 12:40:10 AM - System Checkpoint
RP1271: 7/31/2009 4:24:54 AM - System Checkpoint
RP1272: 8/1/2009 12:00:22 AM - Software Distribution Service 3.0
RP1273: 8/2/2009 1:15:22 AM - System Checkpoint
RP1274: 8/3/2009 1:22:45 AM - System Checkpoint
RP1275: 8/3/2009 10:16:32 PM - Software Distribution Service 3.0
RP1276: 8/4/2009 10:35:21 PM - System Checkpoint
RP1277: 8/6/2009 4:53:19 AM - System Checkpoint
RP1278: 8/7/2009 5:28:57 AM - System Checkpoint
RP1279: 8/8/2009 6:28:56 AM - System Checkpoint
RP1280: 8/9/2009 7:28:55 AM - System Checkpoint
RP1281: 8/9/2009 7:30:56 PM - Installed Power Tab Editor 1.7
RP1282: 8/10/2009 7:33:26 PM - System Checkpoint
RP1283: 8/11/2009 10:55:48 PM - System Checkpoint
RP1284: 8/13/2009 12:00:37 AM - Software Distribution Service 3.0
RP1285: 8/14/2009 12:00:17 AM - Software Distribution Service 3.0
RP1286: 8/15/2009 12:11:21 AM - System Checkpoint
RP1287: 8/16/2009 12:48:57 AM - System Checkpoint
RP1288: 8/17/2009 1:11:19 AM - System Checkpoint
RP1289: 8/18/2009 4:17:03 PM - System Checkpoint
RP1290: 8/19/2009 4:25:48 PM - System Checkpoint
RP1291: 8/20/2009 4:30:38 PM - System Checkpoint
RP1292: 8/21/2009 4:45:06 PM - System Checkpoint
RP1293: 8/22/2009 11:32:56 PM - System Checkpoint
RP1294: 8/24/2009 11:31:06 AM - System Checkpoint
RP1295: 8/25/2009 12:08:37 PM - System Checkpoint
RP1296: 8/25/2009 3:41:00 PM - Installed Microsoft Money 2006 System Pack
RP1297: 8/26/2009 5:47:13 PM - System Checkpoint
RP1298: 8/27/2009 12:00:22 AM - Software Distribution Service 3.0
RP1299: 8/28/2009 12:08:35 AM - System Checkpoint
RP1300: 8/29/2009 1:58:37 AM - System Checkpoint
RP1301: 8/30/2009 2:21:03 AM - System Checkpoint
RP1302: 8/31/2009 3:21:32 AM - System Checkpoint
RP1303: 9/1/2009 6:12:00 PM - System Checkpoint
RP1304: 9/2/2009 10:42:15 PM - System Checkpoint
RP1305: 9/8/2009 10:58:00 AM - System Checkpoint
RP1306: 9/9/2009 12:00:25 AM - Software Distribution Service 3.0
RP1307: 9/10/2009 12:14:44 AM - System Checkpoint
RP1308: 9/11/2009 1:28:10 AM - System Checkpoint
RP1309: 9/12/2009 2:14:39 AM - System Checkpoint
RP1310: 9/13/2009 3:14:39 AM - System Checkpoint
RP1311: 9/14/2009 4:14:38 AM - System Checkpoint
RP1312: 9/15/2009 4:58:30 AM - System Checkpoint
RP1313: 9/15/2009 5:32:48 PM - Installed ProxyWay
RP1314: 9/16/2009 9:36:44 PM - System Checkpoint
RP1315: 9/18/2009 12:30:11 AM - System Checkpoint
RP1316: 9/19/2009 11:48:43 AM - System Checkpoint
RP1317: 9/20/2009 1:15:25 PM - System Checkpoint
RP1318: 9/21/2009 2:42:19 PM - System Checkpoint
RP1319: 9/21/2009 8:15:39 PM - Removed ProxyWay
RP1320: 9/22/2009 9:37:04 PM - System Checkpoint
RP1321: 9/23/2009 9:39:42 PM - System Checkpoint
RP1322: 9/25/2009 12:32:59 AM - System Checkpoint
RP1323: 9/26/2009 12:39:40 AM - System Checkpoint
RP1324: 9/27/2009 1:39:40 AM - System Checkpoint
RP1325: 9/28/2009 2:39:36 AM - System Checkpoint
RP1326: 9/29/2009 3:39:35 AM - System Checkpoint
RP1327: 9/30/2009 4:39:34 AM - System Checkpoint
RP1328: 10/1/2009 5:05:16 AM - System Checkpoint
RP1329: 10/2/2009 5:39:32 AM - System Checkpoint
RP1330: 10/3/2009 6:39:31 AM - System Checkpoint
RP1331: 10/4/2009 7:39:31 AM - System Checkpoint
RP1332: 10/4/2009 5:54:22 PM - Installed DirectX
RP1333: 10/4/2009 6:00:13 PM - Installed DirectX
RP1334: 10/5/2009 6:17:40 PM - System Checkpoint
RP1335: 10/6/2009 7:18:12 PM - System Checkpoint
RP1336: 10/8/2009 8:50:37 PM - System Checkpoint

==== Installed Programs ======================


2600
2600_Help
2600Trb
50 FREE MP3s +1 Free Audiobook!
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0
AIM 6
AiO_Scan
AiOSoftware
AirPlus G
ANIO Service
ANIWZCS2 Service
Anvil Studio
AOL Toolbar 5.0
AOL Uninstaller (Choose which Products to Remove)
Apple Mobile Device Support
ATI Control Panel
ATI Display Driver
avast! Antivirus
Bonjour
BufferChm
Call of Duty(R) 4 - Modern Warfare(TM)
CCScore
Centricity DICOM Viewer
Cheat Engine 5.5
Compaq Connections (remove only)
Compaq Game Console and games
Compaq Multimedia Keyboard Software
Compaq Organize
Copy
CP_AtenaShokunin1Config
cp_dwShrek2Albums1
cp_dwShrek2Cards1
CreativeProjects
CreativeProjectsTemplates
Critical Update for Windows Media Player 11 (KB959772)
CueTour
DecX Version 2.0
Destinations
Director
DocProc
DocumentViewer
Doom 3 (TM) Demo
Doom Builder
Doom Builder 2.0
DOOM Collector's Edition
Download Updater (AOL LLC)
Easy Internet Sign-up
eMusic Download Manager 4.1.3
ERUNT 1.1j
ESET Online Scanner v3
ESSBrwr
ESSCDBK
ESScore
ESSgui
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
essvatgt
Fax
fflink
Free YouTube to Mp3 Converter version 3.2
Full Tilt Poker
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Boot Optimizer
HP DigitalMedia Archive
HP Extended Capabilities 4.7
HP Image Zone 4.7
HP Image Zone Express
HP Product Assistant
HP Product Detection
HP PSC & OfficeJet 4.7
HP Software Update
HpSdpAppCoreApp
HPSystemDiagnostics
HyperCam 2
IconPackager
InstantShare
InterVideo WinDVD Player
J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 13
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
KeyNote 1.6.5
kgcbaby
kgcbase
kgchday
kgchlwn
kgcinvt
kgckids
kgcmove
kgcvday
Kodak EasyShare software
KSU
LightScribe 1.4.31.1
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2006
Microsoft Money 2006 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Standard Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Virtual PC 2007
Microsoft VISUAL C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
Motorola SM56 Speakerphone Modem
Mozilla Firefox (3.0.14)
MP3 Player Utilities 5.10
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB927977)
Myst III: Exile
netbrdg
NLOP
Notifier
Odamex 0.4.3
OfotoXMI
OpenOffice.org 3.1
Otto
PanoStandAlone
Pawsoft Fass
PC-Doctor 5 for Windows
PC Tools Firewall Plus 5.0
PhotoGallery
PokerStars
Power Tab Editor 1.7
ProductContext
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
QFolder
Readme
RealPlayer
Revo Uninstaller 1.83
Risen3D version 2.2.04
RollerCoaster Tycoon Deluxe
Scan
ScannerCopy
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
SFR
SHASTA
SKIN0001
SkinsHP1
SKINXSDK
Skulltag
SlimDX Redistributable (March 2009)
Soldat 1.4.2
Sonic Encoders
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SpywareBlaster 4.2
staticcr
Styler
SUPERAntiSpyware Free Edition
System Requirements Lab
tooltips
TrayApp
TuxGuitar
TweetDeck
UltimateBet
UltraISO Premium V9.33
Uninstall 1.0.0.1
Unload
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951618-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB953356)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
Video Convert
Viewpoint Media Player
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VPRINTOL
Warcraft II BNE
Warcraft III: All Products
WebFldrs XP
WebReg
WebSite Downloader 1.1
What's Running 2.2
Winamp
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live installer
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Media Center Edition 2005 KB890629
Windows XP Media Center Edition 2005 KB894553
Windows XP Media Center Edition 2005 KB895678
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
WinPcap 3.1
WinRAR archiver
WIRELESS
Yahoo! Messenger
ZDaemon (remove only)

==== Event Viewer Messages From Past Week ========

10/9/2009 3:04:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service ImapiService with arguments "-Service" in order to run the server: {520CCA63-51A5-11D3-9144-00104BA11C5E}
10/6/2009 6:04:01 PM, error: Service Control Manager [7031] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
10/6/2009 6:03:13 PM, error: HTTP [15005] - Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number.
10/6/2009 6:03:08 PM, error: Service Control Manager [7023] - The avast! Web Scanner service terminated with the following error: An invalid argument was supplied.
10/6/2009 6:02:41 PM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified.
10/6/2009 5:57:37 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
10/6/2009 5:50:19 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AmdK8 aswSP Fips SASDIFSV SASKUTIL vmm
10/6/2009 5:50:10 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
10/6/2009 5:49:11 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
10/6/2009 5:28:14 PM, error: Service Control Manager [7024] - The Media Center Extender Service service terminated with service-specific error 2147549183 (0x8000FFFF).
10/6/2009 5:28:09 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
10/6/2009 5:26:05 PM, error: Service Control Manager [7034] - The SeekService Service service terminated unexpectedly. It has done this 1 time(s).
10/6/2009 5:26:02 PM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s).
10/3/2009 1:02:47 AM, error: PSched [14103] - QoS [Adapter {012DDFBD-173E-40EE-AEE4-EF4EE6AE8AC0}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.

==== End Of File ===========================


________DDS.txt___________


DDS (Ver_09-09-29.01) - NTFSx86 NETWORK
Run by Compaq_Administrator at 11:55:04.59 on Sat 10/10/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.640 [GMT -7:00]

AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
AV: avast! antivirus 4.8.1351 [VPS 091006-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Compaq_Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
uURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
mRun: [00PCTFW] "c:\program files\pc tools firewall plus\FirewallGUI.exe" -s
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-us\local\search.html
IE: Add To Compaq Organize... - c:\progra~1\hewlet~1\compaq~1\bin/module.main/favorites\ie_add_to.html
IE: Add to Video Converter... - c:\program files\mp3 player utilities 5.10\aviconverter\grab.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Save YouTube Video as MP3 - c:\program files\common files\dvdvideosoft\dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127362109437
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149835123078
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - c:\program files\stardock\object desktop\iconpackager\iprepair.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
LSA: Authentication Packages = msv1_0 nwprovau

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\p1c3jbp5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.youtube.com/
FF - component: c:\program files\common files\dvdvideosoft\dll\ffcontextmenuy\components\FFContextMenu.dll
FF - plugin: c:\program files\emusic download manager\plugin\npemusic.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows PRESENTATION foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-5-6 159600]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2005-3-22 547744]
S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-14 114768]
S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-1-15 8944]
S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-1-15 55024]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-14 20560]
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-14 138680]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2004-8-10 14336]
S2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-5-6 73840]
S2 PCToolsFirewallPlus;PC Tools Firewall Plus;c:\program files\pc tools firewall plus\FWService.exe [2009-5-6 146800]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-14 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-14 352920]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-5-6 95640]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-1-15 7408]
S3 XDva037;XDva037;\??\c:\windows\system32\xdva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva167;XDva167;\??\c:\windows\system32\xdva167.sys --> c:\windows\system32\XDva167.sys [?]

=============== Created Last 30 ================

2009-10-09 16:15552a-------c:\windows\system32\d3d8caps.dat
2009-10-04 18:48--d-----c:\docume~1\compaq~1\applic~1\LimeWire
2009-09-17 16:38--d-----c:\program files\DecXv20
2009-09-17 16:37249,856--------c:\windows\Setup1.exe
2009-09-17 16:3773,216a-------c:\windows\ST6UNST.EXE

==================== Find3M ====================

2009-09-10 14:5438,224a-------c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:5319,160a-------c:\windows\system32\drivers\mbam.sys
2009-08-15 19:0234a-------c:\documents and settings\compaq_administrator\jagex_runescape_preferences.dat
2009-08-06 19:24327,896a-------c:\windows\system32\dllcache\wucltui.dll
2009-08-06 19:24209,632a-------c:\windows\system32\dllcache\wuweb.dll
2009-08-06 19:2435,552a-------c:\windows\system32\dllcache\wups.dll
2009-08-06 19:2453,472a-------c:\windows\system32\dllcache\wuauclt.exe
2009-08-06 19:2496,480a-------c:\windows\system32\dllcache\cdm.dll
2009-08-06 19:23575,704a-------c:\windows\system32\dllcache\wuapi.dll
2009-08-06 19:231,929,952a-------c:\windows\system32\dllcache\wuaueng.dll
2009-08-06 19:23274,288a-------c:\windows\system32\mucltui.dll
2009-08-06 19:23215,920a-------c:\windows\system32\muweb.dll
2009-08-05 02:01204,800a-------c:\windows\system32\mswebdvd.dll
2009-08-05 02:01204,800--------c:\windows\system32\dllcache\mswebdvd.dll
2009-07-19 18:4811,067,392--------c:\windows\system32\dllcache\ieframe.dll
2009-07-19 06:185,937,152--------c:\windows\system32\dllcache\mshtml.dll
2009-07-17 12:490a-------c:\documents and settings\compaq_administrator\settings.dat
2009-07-17 12:0158,880a-------c:\windows\system32\atl.dll
2009-07-17 12:0158,880--------c:\windows\system32\dllcache\atl.dll
2009-07-13 23:4310,841,088a-------c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43286,208a-------c:\windows\system32\wmpdxm.dll
2009-07-13 23:43286,208a-------c:\windows\system32\dllcache\wmpdxm.dll
2009-05-01 09:4424,278a-------c:\docume~1\compaq~1\applic~1\wklnhst.dat
2008-12-07 00:1522,328a-------c:\docume~1\compaq~1\applic~1\PnkBstrK.sys
2008-10-04 14:40268a---h---c:\program files\sqmdata12.sqm
2008-05-03 10:2369,120a-------c:\docume~1\compaq~1\applic~1\obgargu.exe
2007-10-22 21:20251a-------c:\program files\wt3d.ini
2008-07-31 08:2632,768a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008073120080801\index.dat

============= FINISH: 11:55:19.59 ===============
Oh I think I forgot to include that I have no internet in normal mode, only in safemode.Did you run DDS in normal mode?The below instructions should be PERFORMED in normal mode.

1) Please uninstall all viewpoint products .

*Go to control panel>>Add/Remove Programs.Select all viewpoint products such as viewpoint media player etc. and remove them.

2) Please uninstall Adobe Reader 7.Download the latest version from here.


3) Please download combofix from one of these webpages .

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe directly to your Desktop

Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are performing below portion of the instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.

a). Close any open browsers.

b). Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. (Right click on the avast icon in system tray and choose Stop On-Access Protection )

c). Open *notepad* and copy/paste the text in the quotebox below into it:



Quote
KillAll::

DDS::

FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

File::

c:\program files\sqmdata12.sqm

Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.Now drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply.




I will get it done when I get home today. And I ran DDS in safemode.Here you go, also I have internet in normal mode now!!!!

ComboFix 09-10-12.02 - Compaq_Administrator 10/12/2009 17:15.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.553 [GMT -7:00]
Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Administrator\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 091006-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}

FILE ::
"c:\program files\sqmdata12.sqm"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AVM
c:\program files\sqmdata12.sqm
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\viassary-hp.reg
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NWCWORKSTATION
-------\Service_NWCWorkstation


((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 )))))))))))))))))))))))))))))))
.

2009-10-13 00:09 . 2009-10-13 00:09--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint
2009-10-09 23:15 . 2009-10-09 23:15552----a-w-c:\windows\system32\d3d8caps.dat
2009-10-05 01:48 . 2009-10-05 02:19--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\LimeWire
2009-09-17 23:38 . 2009-09-17 23:38--------d-----w-c:\program files\DecXv20
2009-09-17 23:37 . 2009-09-17 23:37249856------w-c:\windows\Setup1.exe
2009-09-17 23:37 . 2009-09-17 23:3773216----a-w-c:\windows\ST6UNST.EXE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 00:22 . 2009-01-19 02:09--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
2009-10-12 03:02 . 2009-06-18 01:05--------d-----w-c:\program files\Skulltag
2009-10-12 00:36 . 2009-01-18 03:08--------d-----w-c:\program files\Doom Builder
2009-10-08 01:18 . 2009-09-03 04:57--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\uTorrent
2009-10-07 01:21 . 2009-01-10 00:47--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-10-06 19:40 . 2009-06-06 15:58--------d-----w-c:\program files\UltimateBet
2009-10-05 00:59 . 2009-07-06 01:28--------d-----w-c:\program files\Doom Builder 2
2009-09-24 05:34 . 2009-09-05 16:56--------d-----w-c:\program files\odamex
2009-09-23 16:25 . 2006-05-19 00:15--------d-----w-c:\program files\PokerStars
2009-09-22 02:54 . 2009-04-08 04:47--------d-----w-c:\program files\eMusic Download Manager
2009-09-10 21:54 . 2009-05-31 01:5138224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2009-05-31 01:5219160----a-w-c:\windows\system32\drivers\mbam.sys
2009-09-09 13:57 . 2005-09-22 03:54--------d-----w-c:\program files\Common Files\AOL
2009-09-09 07:10 . 2009-06-14 04:04--------d-----w-c:\program files\Microsoft Silverlight
2009-09-09 04:16 . 2005-09-22 03:55--------d-----w-c:\documents and settings\All Users\Application Data\AOL
2009-09-08 16:29 . 2009-09-07 17:28--------d-----w-c:\program files\AOL 9.0
2009-09-07 17:31 . 2005-09-22 03:56--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\AOL
2009-09-07 17:30 . 2009-09-07 17:28--------d-----w-c:\program files\Common Files\aolshare
2009-09-07 17:30 . 2005-09-22 03:56--------d-----w-c:\program files\Common Files\Nullsoft
2009-09-07 17:24 . 2006-05-14 03:58--------d-----w-c:\documents and settings\All Users\Application Data\AOL Downloads
2009-08-30 15:04 . 2009-08-30 15:04--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\PokerCreations
2009-08-30 14:47 . 2009-08-30 14:47--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\NLOP
2009-08-30 14:47 . 2009-08-30 14:47--------d-----w-c:\program files\NLOP
2009-08-25 22:47 . 2009-08-25 22:41--------d-----w-c:\program files\Microsoft Money 2006
2009-08-25 13:42 . 2005-10-14 03:2162864----a-w-c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-17 16:10 . 2009-06-14 22:321279456----a-w-c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-06-14 22:3393392----a-w-c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-06-14 22:3394160----a-w-c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-06-14 22:33114768----a-w-c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-06-14 22:3320560----a-w-c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-06-14 22:3351376----a-w-c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-06-14 22:3323152----a-w-c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-06-14 22:3326944----a-w-c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-06-14 22:3397480----a-w-c:\windows\system32\AvastSS.scr
2009-08-16 02:02 . 2008-07-03 06:1434----a-w-c:\documents and settings\Compaq_Administrator\jagex_runescape_preferences.dat
2009-08-07 02:24 . 2004-08-10 19:00327896----a-w-c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2004-08-10 19:00209632----a-w-c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2005-09-22 04:0944768----a-w-c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2004-08-10 19:0035552----a-w-c:\windows\system32\wups.dll
2009-08-07 02:24 . 2004-08-10 19:0053472----a-w-c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2004-08-10 19:0096480----a-w-c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2004-08-10 19:00575704----a-w-c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2006-06-09 23:24274288----a-w-c:\windows\system32\mucltui.dll
2009-08-07 02:23 . 2005-05-26 11:19215920----a-w-c:\windows\system32\muweb.dll
2009-08-07 02:23 . 2004-08-10 19:001929952----a-w-c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-10 19:00204800----a-w-c:\windows\system32\mswebdvd.dll
2009-07-17 19:49 . 2009-07-17 19:490----a-w-c:\documents and settings\Compaq_Administrator\settings.dat
2009-07-17 19:01 . 2004-08-10 19:0058880----a-w-c:\windows\system32\atl.dll
2009-07-15 07:00 . 2009-07-15 07:00229208----a-w-c:\windows\system32\drivers\VMM.sys
2007-10-23 04:20 . 2007-10-23 04:20251----a-w-c:\program files\wt3d.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication PackagesREG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^Styler.lnk]
path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\Styler.lnk
backup=c:\windows\pss\Styler.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Plus! Photo Story 2 LE\\PS2Trial.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"c:\\Program Files\\Warcraft II BNE\\Warcraft II BNE.exe"=
"c:\\Soldat\\Soldat.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skulltag\\Skulltag.exe"=
"c:\\Program Files\\Skulltag\\Idese.exe"=
"c:\\Program Files\\Skulltag\\Rcon_Utility.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/14/2009 3:33 PM 114768]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [5/6/2009 9:37 PM 159600]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 5:17 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 5:17 PM 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2009 3:33 PM 20560]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [8/10/2004 12:00 PM 14336]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [5/6/2009 9:37 PM 73840]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [3/22/2005 7:17 PM 547744]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [5/6/2009 9:36 PM 95640]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 2:10 PM 32512]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 5:17 PM 7408]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva167;XDva167;\??\c:\windows\system32\XDva167.sys --> c:\windows\system32\XDva167.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-10-01 c:\windows\Tasks\HPCeeSchedule.job
- c:\progra~1\EASYIN~1\Ceement\HPCEE.exe [2005-05-24 23:46]
.
.
------- SUPPLEMENTARY Scan -------
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: Add To Compaq Organize... - c:\progra~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
IE: Add to Video Converter... - c:\program files\MP3 Player Utilities 5.10\AVIConverter\grab.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\p1c3jbp5.default\
FF - component: c:\program files\Common Files\DVDVideoSoft\Dll\FFContextMenuY\components\FFContextMenu.dll
FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Centricity DICOM Viewer - c:\program files\Centricity\DICOM Viewer\3.1.1\EN-US\setupw2k



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-12 17:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3802107105-356159331-2220808391-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1736)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3376)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\program files\Stardock\Object Desktop\IconPackager\iprepair.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\AOL\acs\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\PC Tools Firewall Plus\FWService.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\Alwil Software\Avast4\Setup\avast.setup
.
**************************************************************************
.
Completion time: 2009-10-13 17:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-13 00:26

Pre-Run: 55,247,224,832 bytes free
Post-Run: 55,081,291,776 bytes free

256--- E O F ---2009-09-09 07:04

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:28:34 PM, on 10/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: Add to Video Converter... - C:\Program Files\MP3 Player Utilities 5.10\AVIConverter\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127362109437
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149835123078
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} (YYGInstantPlay Control) - http://www.yoyogames.com/downloads/activex/YoYo.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

--
End of file - 8313 bytes
Never mind, I cannot get Firefox or IE to work in normal mode.1) Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

It's IMPORTANT to carry out the instructions in the sequence listed below.
a) Close any open browsers.
b) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open *notepad* and copy/paste the text in the quotebox below into it:


Quote
file::

c:\documents and settings\All Users\Application Data\Viewpoint


Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.Now drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt in your next reply.


2) Please upload these files to virustotal (one by one ) and post the results in your next reply.

c:\windows\system32\XDva037.sys
c:\windows\system32\XDva167.sysHere is my new log. The two file could not be found.

ComboFix 09-10-13.01 - Compaq_Administrator 10/13/2009 16:58.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.573 [GMT -7:00]
Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Compaq_Administrator\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 091013-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B}
FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}

FILE ::
"c:\documents and settings\All Users\Application Data\Viewpoint"
.

((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 )))))))))))))))))))))))))))))))
.

2009-10-13 00:32 . 2009-10-13 00:32--------d-----w-c:\program files\Common Files\Adobe
2009-10-13 00:30 . 2009-10-13 04:01--------d-----w-c:\documents and settings\All Users\Application Data\NOS
2009-10-13 00:09 . 2009-10-13 00:09--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint
2009-10-09 23:15 . 2009-10-09 23:15552----a-w-c:\windows\system32\d3d8caps.dat
2009-10-05 01:48 . 2009-10-05 02:19--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\LimeWire
2009-09-17 23:38 . 2009-09-17 23:38--------d-----w-c:\program files\DecXv20
2009-09-17 23:37 . 2009-09-17 23:37249856------w-c:\windows\Setup1.exe
2009-09-17 23:37 . 2009-09-17 23:3773216----a-w-c:\windows\ST6UNST.EXE

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 23:50 . 2009-01-19 02:09--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
2009-10-13 23:32 . 2009-01-18 03:08--------d-----w-c:\program files\Doom Builder
2009-10-13 16:30 . 2009-06-06 15:58--------d-----w-c:\program files\UltimateBet
2009-10-13 14:07 . 2009-06-18 01:05--------d-----w-c:\program files\Skulltag
2009-10-08 01:18 . 2009-09-03 04:57--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\uTorrent
2009-10-07 01:21 . 2009-01-10 00:47--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2009-10-05 00:59 . 2009-07-06 01:28--------d-----w-c:\program files\Doom Builder 2
2009-09-24 05:34 . 2009-09-05 16:56--------d-----w-c:\program files\odamex
2009-09-23 16:25 . 2006-05-19 00:15--------d-----w-c:\program files\PokerStars
2009-09-22 02:54 . 2009-04-08 04:47--------d-----w-c:\program files\eMusic Download Manager
2009-09-10 21:54 . 2009-05-31 01:5138224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2009-05-31 01:5219160----a-w-c:\windows\system32\drivers\mbam.sys
2009-09-09 13:57 . 2005-09-22 03:54--------d-----w-c:\program files\Common Files\AOL
2009-09-09 07:10 . 2009-06-14 04:04--------d-----w-c:\program files\Microsoft Silverlight
2009-09-09 04:16 . 2005-09-22 03:55--------d-----w-c:\documents and settings\All Users\Application Data\AOL
2009-09-08 16:29 . 2009-09-07 17:28--------d-----w-c:\program files\AOL 9.0
2009-09-07 17:31 . 2005-09-22 03:56--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\AOL
2009-09-07 17:30 . 2009-09-07 17:28--------d-----w-c:\program files\Common Files\aolshare
2009-09-07 17:30 . 2005-09-22 03:56--------d-----w-c:\program files\Common Files\Nullsoft
2009-09-07 17:24 . 2006-05-14 03:58--------d-----w-c:\documents and settings\All Users\Application Data\AOL Downloads
2009-08-30 15:04 . 2009-08-30 15:04--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\PokerCreations
2009-08-30 14:47 . 2009-08-30 14:47--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\NLOP
2009-08-30 14:47 . 2009-08-30 14:47--------d-----w-c:\program files\NLOP
2009-08-25 22:47 . 2009-08-25 22:41--------d-----w-c:\program files\Microsoft Money 2006
2009-08-25 13:42 . 2005-10-14 03:2162864----a-w-c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-17 16:10 . 2009-06-14 22:321279456----a-w-c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-06-14 22:3393392----a-w-c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-06-14 22:3394160----a-w-c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-06-14 22:33114768----a-w-c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-06-14 22:3320560----a-w-c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-06-14 22:3351376----a-w-c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-06-14 22:3323152----a-w-c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-06-14 22:3326944----a-w-c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-06-14 22:3397480----a-w-c:\windows\system32\AvastSS.scr
2009-08-16 02:02 . 2008-07-03 06:1434----a-w-c:\documents and settings\Compaq_Administrator\jagex_runescape_preferences.dat
2009-08-07 02:24 . 2004-08-10 19:00327896----a-w-c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2004-08-10 19:00209632----a-w-c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2005-09-22 04:0944768----a-w-c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2004-08-10 19:0035552----a-w-c:\windows\system32\wups.dll
2009-08-07 02:24 . 2004-08-10 19:0053472------w-c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2004-08-10 19:0096480----a-w-c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2004-08-10 19:00575704----a-w-c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2006-06-09 23:24274288----a-w-c:\windows\system32\mucltui.dll
2009-08-07 02:23 . 2005-05-26 11:19215920----a-w-c:\windows\system32\muweb.dll
2009-08-07 02:23 . 2004-08-10 19:001929952----a-w-c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-10 19:00204800----a-w-c:\windows\system32\mswebdvd.dll
2009-07-17 19:49 . 2009-07-17 19:490----a-w-c:\documents and settings\Compaq_Administrator\settings.dat
2009-07-17 19:01 . 2004-08-10 19:0058880----a-w-c:\windows\system32\atl.dll
2007-10-23 04:20 . 2007-10-23 04:20251----a-w-c:\program files\wt3d.ini
.

((((((((((((((((((((((((((((( [emailprotected]_00.22.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-13 23:50 . 2009-10-13 23:5016384 c:\windows\Temp\Perflib_Perfdata_390.dat
+ 2005-06-07 06:55 . 2009-10-13 23:5572652 c:\windows\system32\perfc009.dat
+ 2009-10-13 00:30 . 2009-10-13 00:3020480 c:\windows\Installer\84803.msi
+ 2005-06-07 06:55 . 2009-10-13 23:55444472 c:\windows\system32\perfh009.dat
+ 2009-10-13 00:33 . 2009-10-13 00:333938816 c:\windows\Installer\84809.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="c:\program files\AOL 9.0\AOL.EXE" [2007-04-18 50736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication PackagesREG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^Styler.lnk]
path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\Styler.lnk
backup=c:\windows\pss\Styler.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Plus! Photo Story 2 LE\\PS2Trial.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"c:\\Program Files\\Warcraft II BNE\\Warcraft II BNE.exe"=
"c:\\Soldat\\Soldat.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skulltag\\Skulltag.exe"=
"c:\\Program Files\\Skulltag\\Idese.exe"=
"c:\\Program Files\\Skulltag\\Rcon_Utility.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/14/2009 3:33 PM 114768]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [5/6/2009 9:37 PM 159600]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 5:17 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 5:17 PM 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2009 3:33 PM 20560]
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [8/10/2004 12:00 PM 14336]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [5/6/2009 9:37 PM 73840]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [3/22/2005 7:17 PM 547744]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [5/6/2009 9:36 PM 95640]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 2:10 PM 32512]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 5:17 PM 7408]
S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?]
S3 XDva167;XDva167;\??\c:\windows\system32\XDva167.sys --> c:\windows\system32\XDva167.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-10-01 c:\windows\Tasks\HPCeeSchedule.job
- c:\progra~1\EASYIN~1\Ceement\HPCEE.exe [2005-05-24 23:46]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\p1c3jbp5.default\
FF - component: c:\program files\Common Files\DVDVideoSoft\Dll\FFContextMenuY\components\FFContextMenu.dll
FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-13 17:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3802107105-356159331-2220808391-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1732)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2136)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\program files\Stardock\Object Desktop\IconPackager\iprepair.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Microsoft Virtual PC\VPCShExH.DLL
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-10-14 17:06
ComboFix-quarantined-files.txt 2009-10-14 00:06
ComboFix2.txt 2009-10-13 00:26

Pre-Run: 54,755,573,760 bytes free
Post-Run: 54,760,435,712 bytes free

222--- E O F ---2009-09-09 07:04
Things are running great right now, I have full connection with Firefox in normal mode.1) Please manually delete this file

c:\documents and settings\All Users\Application Data\Viewpoint

2) * Right-Click My Computer choose Explore, click on Tools, Folder Options.
* Click the View tab.
* Place a tick next to Display content of System folders, (answer OK to warnings)
* Under Hidden files and folders, click Show hidden files and folders.
* If you see a warning message, click Yes.
* Click Apply.
* Click OK.

Now please upload these files to virustotal and post the results in your next reply.

c:\windows\system32\XDva037.sys
c:\windows\system32\XDva167.sys
1755.

Solve : spyware.ietoolbar?

Answer»

Hi there

I use Norton internet security

Regularly I get the message: malware found : spyware.ietoolbar.
It is automatically REMOVED from the PC by Norton. Sofar sogood.

But this comes up daily. How can i AVOID it?
MAYBE can I block some internet address in my browser?

1756.

Solve : Unable to access Windows Normal Mode?

Answer»

My brothers computer has started to screw around [again] and, this time, I'm unable to do anything about it.
I've identified the virus : PMROPN.exe.

Anyways, I've got the logs here. Thanks.


Code: [Select]Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:42 PM, on 10/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\PremierOpinion\pmropn.exe
C:\windows\Explorer.EXE
C:\WINDOWS\system32\wbem\unsecapp.exe
E:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5ca3d70e-1895-11cf-8e15-001234567890} - C:\windows\System32\DLA\DLASHX_W.DLL
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [DLA] C:\windows\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - Startup: [emailprotected] = %APPDATA%\Microsoft\Installer\{6B755EC3-C709-4F5C-BC58-BC0D3967B6B6}\_2377D972A0372FCB34E3F7.exe
O4 - Startup: UltraVNC Server.lnk = C:\Program Files\UltraVNC\winvnc.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm378YYHK
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1242976504280
O16 - DPF: {c3f79a2b-b9b4-4a66-b012-3ee46475b072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\system32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\windows\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\windows\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\windows\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\windows\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\windows\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\system32\mshtml.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\windows\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\windows\system32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\windows\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\windows\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\windows\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: premieropinion - C:\Program Files\PremierOpinion\pmls.dll
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\windows\
O23 - Service: Google Update Service (gupdate1ca2c76caf90b44) (gupdate1ca2c76caf90b44) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - PROLIFIC TECHNOLOGY Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: PnkBstrA (pnkbstra) - Unknown owner - C:\windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB (pnkbstrb) - Unknown owner - C:\windows\system32\PnkBstrB.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\windows\

--
End of file - 7692 bytes
Unable to get SAS to install.

MBAM log:

Code: [Select]Malwarebytes' Anti-Malware 1.41
Database version: 2973
Windows 5.1.2600 Service Pack 3 (Safe Mode)

10/17/2009 12:35:02 PM
mbam-log-2009-10-17 (12-35-02).txt

Scan type: Quick Scan
Objects scanned: 95658
Time elapsed: 3 minute(s), 2 second(s)

MEMORY Processes Infected: 1
Memory Modules Infected: 2
Registry Keys Infected: 140
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 19
Files Infected: 93

Memory Processes Infected:
C:\Program Files\PremierOpinion\pmropn.exe (Trojan.Agent) -> Unloaded PROCESS successfully.

Memory Modules Infected:
C:\Program Files\PremierOpinion\pmls.dll (Trojan.Agent) -> Delete on reboot.
C:\Program Files\PremierOpinion\components\pmxg.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{adb01e81-3c79-4272-a0f1-7b2be7a782dc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938aa51a-996c-4884-98ce-80dd16a5c9da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{eeb86aef-4a5d-4b75-9d74-f16d438fc286} (Adware.PremierOpinion) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\2e1117ed (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\2e1117ed (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\2e1117ed (Rootkit.Rustock) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\premieropinion (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) GOOD: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Shared\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\premieropinion (Trojan.Agent) -> Delete on reboot.
C:\Program Files\premieropinion\components (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\All Users\Start Menu\Programs\PremierOpinion (Adware.PremierOpinion) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\2e1117ed.sys (Rootkit.Rustock) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Local Settings\Temp\7zS3205.tmp\patch.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\000D5091 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\000D5F57 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\000D62F0.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\000D65CF.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\000D6801.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\000D6A34.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\000D6C57.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\premieropinion\chrome.manifest (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\premieropinion\install.rdf (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\premieropinion\pmls.dll (Trojan.Agent) -> Delete on reboot.
C:\Program Files\premieropinion\pmoci.bin (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\premieropinion\pmph.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\premieropinion\pmropn.exe (Trojan.Agent) -> Delete on reboot.
C:\Program Files\premieropinion\pmservice.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\premieropinion\pmxf.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\premieropinion\components\pmxg.dll (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\All Users\Start Menu\Programs\PremierOpinion\About PremierOpinion.lnk (Adware.PremierOpinion) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\PremierOpinion\Privacy Policy and User License Agreement.lnk (Adware.PremierOpinion) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\PremierOpinion\Support.lnk (Adware.PremierOpinion) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\PremierOpinion\Uninstall Instructions.lnk (Adware.PremierOpinion) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Desktop\Download 100,000 Emoticons!.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Desktop\Sherv.NET - Animated Emoticons, Winks, Display Pics, plus more!.url (Rogue.Link) -> Quarantined and deleted successfully.

1757.

Solve : a new virus ??

Answer»

If SOMETHING is corrupted in this profile a new ONE will normally fix it. To create a new user profileOk, I TRIED a new profile and it didn't fix anything.I'm out of ideas.

If you don't want to go through the reformat then you might TRY a Startup Repair. Startup Repair: frequently asked questions

1758.

Solve : Bad Image error on laptop?

Answer»

On my laptop I am receiving several pop-up boxes when I try to log on that have different title messages but the same error message within the pop-up.
These occur before I choose a user to log on under and then throughout the log on process which never finishes:
services.exe - Bad Image
lsass.exe
bcmwltry.exe
userinit.exe
explorer.exe
verclsid.exe
rundll32.exe
QTTask.exe

The application or DLL C:\WINDOWS\system32\dafonole.dll is not valid Windows image. Please check this against your installation diskette. Eventually it just times out. Can anybody help me with this?
Are you able to log on?

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.But I can't log on the laptop, I am posting from another one now. Is there anyway to download the file onto my laptop without logging on, the operating system is XP and I have tried safemode but it just locks upNo you have to log in. Instead of safe mode have you tried 'Last known good configuration'

How to start your computer by using the Last Known Good Configuration feature in Windows XPOK I will try that now.I was unable to run the dds file, far too many pop-ups that never seemed to end and no log files were ever generated. It did get to the spash screen that explained about dds but that was it, so I tried an hijackthis and it worked so I am including the log file here.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:50:38 PM, on 10/15/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Safe mode

Running PROCESSES:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
E:\PC Repairs\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061206
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061206
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061206
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [DLCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll,[emailprotected]
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [6423934b] rundll32.exe "C:\WINDOWS\system32\whiviakn.dll",b
O4 - HKLM\..\Run: [wizoguruba] Rundll32.exe "C:\WINDOWS\system32\pasagami.dll",s
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O4 - Global Startup: Dell Network Assistant.lnk = ?
O8 - Extra context MENU item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL hefpex.dll gygrhi.dll pqgugu.dll axcatz.dll uolvqo.dll ctyvfq.dll cgtcdz.dll,C:\WINDOWS\system32\dafanole.dll,C:\WINDOWS\system32\telopezo.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlci_device - - C:\WINDOWS\system32\dlcicoms.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 5664 bytes

I don't know if there is anything else I can try, I will see if I can run any of the programs suggested in the forum for malware/viruses. Maybe I can download them now as the lock ups don't seem to be as bad.If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is IMPORTANT that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix

1759.

Solve : Problem still ongoing - Malware infection Unknown type NEW INFORMATION Post#13?

Answer»

Have done so with REGARDS to Avira. I hope SOMEONE else can help me with my other problem. As I said, the slow down seems to start only be after I open the internet and start to browse but when it does, it effectively SLOWS down the whole netbook, not just the internet browser. http://www.avg.com/gb-en/download-tools


go to above to complete the removal of avg

sorry i cannot help you with the above , harryOK, if no one has an idea as to what may help this problem, I guess I will just reinstall windows. I just hated to something time consuming if I could fix it another way.


Edit: Oct. 19, 2009: Done so and COMPUTER RUNS just fine now. This can be closed.

1760.

Solve : key board shortcuts are automatically invoking?

Answer»

actually i asked the reply FRM the remaining people.Not for you Mr.Allan.If u think wrong i m sorry.
Even i am logging from DIFFERENT user i am GETTING the same problem.I want to know exactly WHATS the problem its bcoz of a virus or any hardware problem.

1761.

Solve : Please check rist log/new logs?

Answer»

The BSOD I get is 0x0000007f
Beginning dump of Physical Memory

There are no other clues. When we get finished here I will check at the XP forum.That error could be a lot of things. I don't think it's malware though. See here. http://support.microsoft.com/kb/137539

I can't remember if we asked. Do you have your install CD?

Try this also. Not sure if it works in Safe Mode but try anyway.

  • Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow)
    • Let this run undisturbed until the window with the blue progress bar goes away
SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the INCORRECT file.I tried the sfc/scannow from run. It loaded for a millisecond and then disappeared. Tried several times and got the same results.

I don't have the CD for THIS computer, and since its XP Pro I don't think my disk which is XP Home will work. My disk is an OEM disk.

It looks like the dysfunctional computer had XP Home on it at 1 time since it shows in the load menu but it was overwritten by Pro.Do you think The I386 file/folder from the Home CD will work for Pro?No they are different operating systems.

Did you put a space between the sfc and /scannow ??Yes, TYPED it exactly sa shown, sfc /scannow, space between sfc and /scannow.
I wonder if it has anything to do with the administrator prmissions thing that I didn't set. I get a warning when I try to install SAS.Please do the following:

1. Download this diagnostics tool MGADiag.exe and save this to your Desktop.
2. Double-click on MGADiag.exe and click Continue
3. When the PROGRAM has finished, click on Copy
4. Post the results in your next reply.I think I have discovered the main problem and I will not be fixing it without the original disk. IF I had had the MGADiag program I probably wouldn't have touched this system.

Diagnostic Report (1.9.0011.0):
-----------------------------------------
WGA Data-->
Validation Status: Invalid Product Key
Validation Code: 8

Cached Validation Code: N/A
Windows Product Key:
Windows Product Key Hash: Windows Product ID:
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.3.0.pro
ID: {08586C5A-82AE-407A-B371-1FF763D70C4E}(1)
Is Admin: Yes
TestCab: 0x0
WGA Version: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005
Resolution Status: N/A

WgaER Data-->
ThreatID(s): N/A
Version: N/A

WGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 109 N/A
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-230-1

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Allowed
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: {08586C5A-82AE-407A-B371-1FF763D70C4E}1.9.0011.05.1.2600.2.00010100.3.0.prox32*****-*****-*****-*****-TY9F355274-640-4940936-234921S-1-5-21-448539723-602162358-725345543Dell Computer CorporationDimension 4600i Dell Computer CorporationA1220040826000000.000000+000B1DC39E70184805304090409Central Standard Time(GMT-06:00)03109

LICENSING Data-->
N/A

HWID Data-->
N/A

OEM Activation 1.0 Data-->
BIOS string matches: yes
Marker string from BIOS: 1B1D1:Dell Inc|1B1D1:Microsoft Corporation
Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005

OEM Activation 2.0 Data-->
N/A

Quote
WGA Data-->
Validation Status: Invalid Product Key
Validation Code: 8

Yes Microsoft has made it very hard for people to use Windows when it isn't registered. Contact Microsoft and they will work with you in getting a valid key. Since you got it from work it might end up costing very little or maybe even nothing.

1-866-PCSAFETY (1-866-727-2338). This phone number is for virus and other security-related support. It is available 24 hours a day for the U.S. and Canada.

If you have valid, licensed software, then you need to go to the Windows Genuine Forum, register and post the log at Speak to us at Microsoft! If necessary, copy the original log or provide a link to this thread.

In the event you are a victim of piracy, help is available from this site: PROTECT Yourself from PiracyThanks EF. I will contact them and see what they say.Did you do the XP Pro upgrade?

Where did the license key come from?

You might have to get the original product key and/or the computer serial number and use an XP Home CD to reformat and then reinstall XP Home. This page will help you find the COA. http://www.microsoft.com/howtotell/content.aspx?pg=coa&displaylang=en. EF I did not do the upgrade and don't know where the key came from. The machine belongs to my neighbor and I told her I would see what I could do about removing the viruses. I will find out who did the upgrade and where the key came from, possibly they have the original disk.
The original HOME key is on the side of the computer case since its a Dell but I don't believe the owner has the original disks. I have MY retail disk that goes to my machine but thats all.If the disks are the same then it will work. XP Home or XP Pro. But you need to use whatever key belongs to the OS. Home or Pro.
1762.

Solve : Infected Computer According to Broni?

Answer»

It may not be compatible with 64 bit so didn't actually INSTALL. http://www.viewpoint.com/technologies/viewpoint-media-player.shtml#system-requirements

DELETE An Uninstall Entry

  • Start HijackThis
  • Click on the OPEN the Misc Tools section
  • Click on the Open Uninstall Manager button.
  • Highlight the entry you want to remove.
  • Click Delete this entry
1763.

Solve : Help get all of "security tool" from computer.?

Answer»

Yesterday I saw the yellow shield in the bottom corner telling me updates for Windows were available. So, before bed I clicked install updates and shut down. After it became apparent something was wrong I searched for solutions and finally USED Malwarebytes' AntiMalware-which seemed to fix everything. But, I'm on here because there's still a red shield in the corner of my screen that I don't think should be there. When I move my mouse over the shield it reads "Windows security alerts." Other then that being there everything seems to be WORKING great. These are my logs:


Comments, help.

An update-the yellow shield with an exclamation mark has appeared again asking me to click here to install updates.

[Saving space, attachment deleted by admin]Just double click on the shield, open Security Center, disable the alerts.Please go to VirSCAN.org FREE on-line scan service
(If more than one file needs scanned they must be done separately and logs posted for each one)

1. Copy and paste the following file path into the Suspicious files to scan box on the top of the page.
Code: [Select]C:\Documents and Settings\sharyn\Application Data\MSA\msctrlp.exe2. At the upload site, click once inside the window next to Browse.
3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
4. Click on the Upload button.
This will perform a scan across multiple different virus scanning engines.
Your file will possibly be entered into a queue which normally takes less than a minute to clear.
Important: Wait for all of the scanning engines to complete.
5. Once the Scan is completed scroll down and click on the Copy to Clipboard button. This will copy the link of the report into the Clipboard.
6. Paste the contents of the Clipboard in your next reply.

----------

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to BLOCK DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.
Copy and paste will not work! And, I cannot type the line in the box either. So, I tried using the browse feature to find the path(?) or line to the file to scan. I could not find the exact path. Using browse I get to C:\Documents and Settings\sharyn\Application Data\MSA ( I was able to copy and paste this), but after MSA there are only download.list and update.list. I could not find msctrlp.exe(again copy and pasted here). I also had to change folder options to show hidden files to see the Application Data folder. I don't understand why I cannot type or paste into this box but I can use the browse feature.

I just tried using seach entering msctrlp.exe(again I could copy and paste) and no results.OK just continue on with DSS please. I'm 99.9% certain that msctrlp.exe is a malicious file so we will take care of it shortly.OK. Info posted.

[Saving space, attachment deleted by admin]Go to Add or Remove Programs and uninstall:

  • Java 2 Runtime Environment, SE v1.4.2_03
  • Java(TM) SE Runtime Environment 6 Update 1
  • Viewpoint Media Player
.
----------

Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

DDS::
TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
uRun: [msctrlp.exe] c:\documents and settings\sharyn\application data\msa\msctrlp.exe

Folder::
c:\documents and settings\sharyn\application data\msa


3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in CASE it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeI could not remove •Java 2 Runtime Environment, SE v1.4.2_03. I get messages saying SOMETHINGS not available. I tried to attached a screen shot of the dialogue boxes but the files were too big. The other two removed no problem. I did the messenger thing and have downloaded Combofix with running.Delete An Uninstall Entry

  • Start HijackThis
  • Click on the Open the Misc Tools section
  • Click on the Open Uninstall Manager button.
  • Highlight the entry you want to remove.
  • Click Delete this entry
Done. HJT is still open.Waiting for the ComboFix log...I hadn't run combofix before my last post. I opened HJT and clicked to removed the one file and then X closed it. Then ran combofix.

[Saving space, attachment deleted by admin]Is there a reason you aren't running an antivirus?I had McAfee when I got the computer but let it expire. Actually, when this started it was the biggest problem I've ever had. Couldn't use control panel and stuff like that. To answer your question-I don't have a specific reason. If you would like to recommend one I'll take your advice.

Download the McAfee Consumer Product Removal Tool to your Desktop.

Using McAfee Consumer Product Removal tool:

* Double click the MCPR.exe
* A Command Line window will be displayed, and then close automatically.
* Wait for a second Command Line window to be displayed.

Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear.

* After the second window appears, the program will begin the cleanup.
* Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n]
* Press Y on the keyboard.
* Wait for the computer to restart.
* All McAfee products are now removed from your computer.

----------

All of these are free for life and both very reliable.

Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal

If you want a good free firewall.

1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any Ask.com options if you choose this one)
2) Online Armor
3) Sunbelt/Kerio


----------

Let me know when you get that done.

.
1764.

Solve : W32.Jeefo?

Answer»

Hi.

I have finished running the ESET Scanner.

When I started it I selected "Scan Archives" only. I DEselected "Remove Threats".

I ran the scan on my C drive only.

I have not tested the external drives that were connected when Norton
issued its warning.

The final screen gave this information :

Scanned files : 196757
Infected files : 0
Cleaned files : 0
Total scan time : 02:20:41
Scan Status : Finished

The program gave me the opportunity to "Uninstall application on close"
- I agreed and consequently can't access a full log file.

Do I need to run the scan again to get any extra information that
this text file might have contained ?

Thank you again - very much - for your help.You can download it again and scan all your drives but this time leave "Remove Threats" checked.Hi

I have started the ESET Online Scan again - this time
with my external drives attached. The program NEVER asked
me to choose from a list of drives to examine.

Will it automatically look at ALL of the drives ?

Is it O.K. for me to still have Avira active?Quote

Will it automatically look at ALL of the drives ?

Is it O.K. for me to still have Avira active?
You can select the drive you want to scan by going to Advance Settings, Under scan targets, select Change and select the drive you want to scan.
Your Avira should be disabled during the scan. Don't forget to re-enable it afterwards.ESET Online Scan Log File Results :

[emailprotected] as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=41c60b2222d87546a6fbc2722440c753
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-09-20 10:13:01
# local_time=2010-09-20 11:13:01 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service PACK 3
# compatibility_mode=512 16777215 100 0 466316 466316 0 0
# compatibility_mode=1797 16775141 100 94 221262 57615206 82556 0
# compatibility_mode=8192 67108863 100 0 85959 85959 0 0
# scanned=1299649
# found=0
# cleaned=0
# scan_time=16890If there are no other issues, we can do some CLEANUP.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

*******************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

**********************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO REPLACEMENT for a dedicated software solution. Remember to use only one firewall at the same time.
**********************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in SPYBOT - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Hi

Thank you for your on-going help.

I have removed ComboFix and run TFC.

Do you think my computer is clear of the Virus/Trojan now?

Was it a RootKit and had it blocked Avira's ability to update itself?

Should I be using a software Firewall ? I was under the impression that
the modem/router that my ISP provided offered sufficient shielding.

Perhaps this incident shows that that is not so.There was no evidence of that infection that you referred to in your opening thread. I would say that your computer is clean. I don't wish to discuss any more about these scans because hackers and malware writers also visit these site and we don't want to give them any help with their evil exploits. As for the firewalls; I'm not sure how effective your router firewall is but a third-party would probably be better. It will annoying at first until the firewall learns your routine but after a bit you'll not even know it's there. Thank you very VERY much for all of your help.You're welcome. Resolved. I will lock this topic. If you need more help, please start a new thread or pm me to unlock this thread.
1765.

Solve : Intemap mephisrnet explorer??

Answer»

Lots of problems...

Let's start with one obvious one. I believe I have a virus. I would normally just run Norton Antivirus, but that's not available to me at the moment, and I'm not having luck with online scans.

One odd thing is that my Internet Explorer (6.0) has been renamed Intemap memphisrnet explorer. Other info is that I'm running Win98.

Anyone know what this is?smirks......do you have any idea which virus you might have .......go to
http://securityresponse.symantec.com/

there a number of removal tools there to use.......
It might also be a good idea to D/L .....Zone Alarm (free fireawll) ....you MAY then be able to catch the virus attempting to send out its bugs to other computers
http://www.zonelabs.com/store/content/home.jsp
let us know how you make out.

dl65 On my 11TH attempt, I finally managed to run Norton's online virus scanner all the way without my computer crashing. Only one trojan, W32.HLLW.Chemsvy, from a file I downloaded the other day...after the onset of my computer problems. From what I've read, it's pretty benign, so I doubt it was the source of my problems.

I guess I'll have to look at software and hardware issues now.

Thanks for your help smirks.....did you manage to get rid of the trojan?
Download and run trojan remover.....it works great , but is an evaluation copy ...only good for 30 days .
http://www.simplysup.com/tremover/download.html
Does your p/c shutdown on fairly regular time frames....
because you have virus in there as well that causing that , unless you have software conficts which are causing this.

let us know ,

dl65 Oh, getting rid of that particular trojan was easy. It's just a matter of deleting the infected files. I'll KEEP that program in mind though.

I think my pc problems are unrelated to the virus. I've been having SEVERAL weird Windows problems...my quick launch toobar will disappear, or I'll start getting messages that my pc is low on resources when I'm not running a lot of programs. And for some reason, installing the new Windows update makes Explorer crash. Maybe I have a corrupted windows file or two.

Bleh.

get rid of ie 6 it the root of your problems if you have not got a zombie/worm download EITHER firefox or avant browser..forget ie6 and try shredder to keep the spys at bay>http://www.spywareinfo.com/~merijn/downloads.html and keep it on your desktop for more use if needed?Thanks for your reply. I uninstalled and reinstalled IE6. This seems to have gotten rid of the problem. (For now...) I downloaded CWShredder and everything looks okay. I was negative for trojans or worms on the online scan above and Norton AV.

1766.

Solve : help with, i think a tojan?

Answer»

ok i cant connect to the internet and i got this message when i try to start up explorer, somethign msg.121.cpy.dll, so i looked on the internet and tried to fix it it says its sometihng from spyware or something well i dont understand how to fix it so can SOMEONE here PLEASE tell me how to do it, thank you so muchHi NoHate,try running Ad-Aware to detect this,also try PANDA software's free ONLINE scan.This seems to catch most Trojans & viruses.thanks, but i'v got it already.www.trojanscan.com try Spy-Sweeper
http://download.com.com/3001-8022-10267571.htmlnohate....this may be a stupid question ......but if you can't connect ....how are you able to post here ....are you using another computer ?

Please let us know
dl65 oh well if i unistall then install the internet (that STUFF on the disk) it will work untill i restart the computer, but i fixed this whole tihng a while ago.Well i would look for a good trojan remover or a ANTIVIRUS like Nortan or go on a site like they said above. Hope it goes away

1767.

Solve : Re: manipulatingtheicesurface.com?

Answer»

help me ....Are all the utility programs you listed up to date with the latest updates ......for example are you running Ad-Aware Ver 6 build 181 .....Go to Symantec site... http://www.symantec.com/index.htm go to the Download part and select security check ......run both
Security scan and VIRUS scan.....Then I would D/l Zone Alarm ( the free version)
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp?lid=zadb_zadown

When you setup Zone Alarm ........you POPUPS will probably ask for permission to access the internet ...answer no ......
After doing the scans I would do a search using the search function in Win XP . ( but first go into the control panel ......folder options and tick " show hidden files" and untick " hide hidden operating system files ") Search all files and folders for whatever the search bar is your trying to get rid of and delete it . One more thing .....go up to the "View" button up top on your explorer and click on it ...select toolbars and see it its shows up there ....if it does make sur its not ticked

let us know how you make out ,

dl65 didnt helpmy temp internet files get deleted everyother dayand i have deleted my cookieshelp me....Is the manipulatingtheicesurface.com still showing up as your browser or is it just the pop ups.
Can you right click on the popup and see if theres any info . There has to be some referance to those things somewhere on your puter. I havent been to that site...
did you get attached by simply going to the home page or did you click on something.
let me know because I would like to see where its coming from .
When you search for it ....what perameters are you using?

DL 65
help me .....If this is a site you frequent often and dont want the pop ups ......use a pop up blocker. .........
Am I missing something ?

let me know.....

dl65 ive never visited this site i never heard of it till i got these pop-ups one day and i dont want a pop-up blocker i need something that'll remove the program

1768.

Solve : Need to remove Searchbar?

Answer»

Hi,

ONE computer in the office has downloaded an evil tool called "searchbar".

This happened a few weeks ago. All it has done is changed the home page of IE, and given SPYBOT some FITS. The computer is an old piece of junk running on a Pentium 1 @ 300mhz making installing things like firewalls impossible. OS is Windows 98.

Spybot finds files and "fixes" them but never gets rid of the "searchbar".

Does anyone have any "Free" ideas? (Besides throwing the old thing out the window and GETTING a new one)

Thanks in advance.
wizardmaster.....the search bar thing must be going around right now .......try this Trojan remover go to
http://www.simplysup.com/tremover/download.html
Its a full working evaluation prog ( 30 days ) give it a try.

laso give this a try if the above doesnt help ..
http://securityresponse.symantec.com/avcenter/venc/data/trojan.qhosts.html this sounds like whats happening on your p/c


Let us know

dl65
.............. this happened to me too. Go to one of the site he says and it should help.The first link's program didn't do anything. I don't think it's a trojan...but I'm not an expert so I'll just keep my mouth shut.

I APPRICATE the help, I'll try the second one tomorrow. I'm late for a meeting so I can't do it today. errr I hate this "searchbar"

if you run across any other ideas please let me know them.

thanks,

wmeither download shredder>http://www.spywareinfo.com/~merijn/downloads.html or spysweeper from webroot.com and this if you wish>http://www.wilderssecurity.net/bhblaster.html[glb]shredder[/glb] did it! Appreciate it!

Thanks,

[glb][glb]wm[/glb][/glb]

1769.

Solve : Re: My computer restarts for no reason!?

Answer»

its the sasser WORM its a product of the m$blaster worm TRY this >http://vil.nai.com/vil/stinger/ more info here>http://www.microsoft.com/security/incident/sasser.aspHi .....GO to http://securityresponse.symantec.com/avcenter/tools.list.html this tool will get rid of the Sasser........you may have to use another computer to get this tool as yours will keep shutting down......Download it to a disk and the install it in your computer.....It works ....I had to do that for a friend YESTERDAY ..

DL65

1770.

Solve : help! AIM virus. weird away message !!?

Answer»

please help me?!!? I have this AIM virus and what it does is that it pops up a away message saying that

OMFG LOOK http://pics99.blogsite.org/friends.scr !!!!!

or something similiar like that. The away message pops up like every one MINUTE so its REALLY really annoying. It all started when I went to that website and when a download window came up, I clicked open. I'm not 100% sure but i think when the download was completed, MS-DOS window came up for a second. So im guessing that now that thing I downloaded is running on my computer. I TRIED to shut off that program but going to Task Manager and clicking End Task, but it didnt let me. It didnt even let me open the Task Manager window. When I go to Task Manager, it would STAY on for a second or not even and go off, without giving me any chance to shut off any program.

PLEASE HELP ME THIS IS SO ANNOYING!Please Read This First - Viruses & Spyware

Install the programs recommended to scan for viruses, trojans and spyware.

1771.

Solve : HELP!! anyone who can look at a hijackthis l?

Answer»

OK, got big trouble w/ menu's and homepages that I had nothing to do with getting on my computer. Can anyone look at a hijackthis log and tell me what the problem(s) are? I can't seem to get the file on this post, so if someone could tell me how, or give me an email ADDRESS and I will send it to them. Thank you very much for your time!

Ruben LourencoCopy and paste the results.

Rather than having us look at your log, run a program such as

Adaware SE

Or Spybot Search & Destroy

They can do more for you than we can by looking at your log.Tried to copy and paste the results, but it was too long and would not post. could I put the file in the post somehow? Also, have run spybot and these menu bars keep coming up!
Again, thank you very much for your time!Copy half of the log, post it, then copy the other half and create another post.

As for REMOVING Internet Explorer Toolbars/Plugins

I recommend Advanced Uninstaller Pro 2004

It can do more than uninstall Internet Explorer Toolsbars/Plugins

Quote

This easy-to-use Windows application uninstaller makes your computer run more efficiently by removing software and files that were left behind after you uninstalled software that you no longer use. In addition, the program performs a number of cleanup activities, making your computer more secure
OK, here goes:

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\WindowsSA\omniscient.exe
C:\WINDOWS\System32\golum\services.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\dhsvr.exe
C:\Documents and Settings\Ruben\herovan.exe
C:\Documents and Settings\Ruben\xxx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ruben\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://nkvd.us (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nkvd.us (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://nkvd.us (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://nkvd.us (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://nkvd.us (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window TITLE = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.ne2.attbb.net
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://nkvd.us (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://nkvd.us (obfuscated)
R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310}_ - (no file)
R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,And Part 2:

O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O2 - BHO: (no name) - {30AF3328-E212-7ABC-8254-625579AE2D42} - C:\WINDOWS\System32\twqx.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5FB16413-03EE-4479-B39A-F641C51CCADB} - C:\WINDOWS\System32\iciddeo.dll (file missing)
O2 - BHO: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll (file missing)
O2 - BHO: (no name) - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:\WINDOWS\dealhlpr.dll
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O2 - BHO: (no name) - {FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} - C:\WINDOWS\System32\mshelper.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vprzejmoqk] C:\WINDOWS\System32\whkdkct.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [Golum] C:\WINDOWS\System32\golum\services.exe
O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [Usrr] C:\Documents and Settings\Ruben\Application Data\rncr.exe
O4 - HKCU\..\Run: [Nskutd] C:\WINDOWS\System32\egiah.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -traybootAnd now Part 3:

O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Crazy Vegas Poker (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: PartyPoker.com (HKLM)
O9 - Extra 'Tools' menuitem: PartyPoker.com (HKLM)
O9 - Extra button: ICQ 4.1 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: *.windupdates.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=230270dab455d0e176941480ba0fc85f2978d245429f93809c10f10b815c8a96c9ba5c54063f7603d4945ab86ee97ff22322f046:375a82d108ec2e9d584f880889783bc3
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio CONFERENCING) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38028.8065509259
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_225/webolr/OCX/FlashAX.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab

And what kind of problems are you experiencing even after using Adaware SE, Spybot S&D and removing the plugins/toolbars with Advanced Uninstaller Pro 2004?Okay, I get pop-up windows that lead to search engine sites (for example, search200.com) and porn sites, and they download desktop Icons to my computer. I have found .exe files in my C:\Documents and Settings folder (herovan and xxx) and have deleted them, but return time and time again. I now have Ad-aware and Spyware Guard on my computer, as well as Norton AV and Spywareblaster. Again, thank you very much for your time!I suggest you properly configure Adaware SE and allow it to BOOT at Windows start up. This will allow it to remove things it may not have been able to whilst normally running the program.Ok, I tried all that, and was STILL having problems However, I just installed Spyguard and Sygate PF and now don't seem to have any more troubles I'll update you in a couple of days and see what happens. Thanks again for your time and kudos to the best computer forum on the internet!

You uninstalled your personal Firewall and now the pop ups stopped?

What kind of popups were you referring to? Ones that required access or ads?

you need to ditch bearshare one of the main causes?p2p imho>you need these>http://www.thespykiller.co.uk/ shredder
http://vil.nai.com/vil/stinger/
trojan killer
http://www.webroot.com
spysweeper..and thats it...and disable system restore to run these programs...ok
1772.

Solve : randomly rebooting virus?

Answer»

hey guys. I am having a PROBLEM with a virus of some sort. My comp is randomly rebooting, sometimes i'm online and sometimes it's just on the desktop with the screen saver on. Aslo it randomly freezes to a blank white screen with vertical lines. When it does this I have to reboot it and then it works fine for a little while. I've tried updating all the windows 2000 updates and everything and running Norton. When I did that Norton said I had a worm in msegri32.exe. I don't know if that's a FILE or what but I tried deleting it and it supposedly did, however I found it again when i was searching for it. I don't know how else to get it to stop. Do any of you techies have any ideas? I have the installation disk but if I reintall it will I lose all the other stuff on Windows? Thanx

Chelsea Please Read This First - Viruses & Spyware

Does Norton not allow you to remove the file? If it does not, I suggest you boot into safemode and scan from there.

Look at the programs recommended in the sticky. They may be useful to you.

You might has the virus called MSBlaster and its a little hard to remove goto microsoft.com and do a search for 'msblast' and they wiull give you a step by step walkthough of how to remove it. if that does not work, you might have a boot sector virus with you can use a WIN98 bootup disk, and run without cd-rom support and type: fdisk /mbr - which will remove your master boot record of any kind of startup issues. if you are still having the problem, (if you are running winxp, win2k) goto start > run and type 'regedit' and goto Local Machine > SOFTWARE > microsoft > Windows> Run. and see if you see anyhting unusual that runs during startup.http://support.microsoft.com/default.aspx?scid=kb;en-us;190136 reboot pc and keep tapping the f8 and chose last good config.....do you have firewall on you system...and run this >http://vil.nai.com/vil/stinger/Ok I found out that it's a Randex H worm. I follwed the instructions and downloaded IDEs and some other thing and booted it in safe mode and diid the comand prompt to scan and remove it. The thing is-- it removed the file but it was still on my comp. maybe through the registry? So now I still have this thing on my comp and there are lots of files and even folders that it has created that it won't let me delete. It either says access denied, or that it's in use. So I'm gonna try what you suggested merlin. I don't have a firewall but I did go through andmake passwords for everything. OH, and can anyone tell me what a patch is and how you know it's up to date? Thanx guys Passwords are not the same as a firewall. They are not nearly as effective. Passwords are to keep people from your system that use your keyboard. Firewalls are there for people and programs that try to connect your computer.

Here is an article I suggest you read:

How Firewalls Work

Once you have done so, I suggest you obtain a firewall to prevent the worm from connecting the net.you can get avg antivirus free on the net and this will remove or QUARINTINE the trojan , it has also caught 2 for me when i have been online it is a very good freeware pakage there is also free updates as well.

1773.

Solve : computer being used to spam email to other people?

Answer»

my computer is being used to spam email to other people. Please help!Please Read This First - Viruses & Spyware

Install:

  • Adware remover
  • Virus scanner
  • Firewall


You should run both Virus and Adware scanner to remove any objects that allow other people to connect to your PC and install the Firewall to stop them from doing so now and in the future.

Read these security and Internet related articles to learn more:


How Stuff Works - Security Channel

How Stuff Works - Internet Channel

Gibson Research CorporationWhat kind of spam is it GENERATING? Are they viral? Most viruses now replicate and SPOOF the sender's address in the process, so that the emails appear to be coming from friends. If this is the case, you may not be the infected one (I'm NOT saying you shouldn't still scan and verify either way), but someone who has you on their contact list may be infected.

It's worth a try to send out a quick email to warn your friends to MAKE sure they have updated antivirus installed and have performed a full system scan. This is always a GOOD warning.
1774.

Solve : mcsmss.exe?

Answer»

Can anyone tell me what this is? mcsmss.exe?WEB.......are you certain about .... mcsmss.exe ?
Could you have typed it wrong?

let us know
dl65No, thats what was trying to access the internet. At first I thought it was msn, nut know it was not. Any idea?wardbo......I cant find anything on mcsmss.exe. how did you pick it up ....did your firewall catch it ? Have you tried doing a search of your pc for anything with that description ?
If it was your firewall that caught it is there a log file .....there may be additional info in it .

hope this helps ...let us know

dl65 I finally solved it. It was a backdoor Trojan that I somehow got. I think I got it when I was downloading or using ICQ. I knew I should not use it!ICQ does not come with Trojans or viruses. Not even Spyware.

You either DOWNLOADED it from a questionable source or you accepted a file sent by another user who you could not trust. (Even if you could, he/she should install a (better) virus sanner). In both cases you shouldn't hold ICQ RESPONSIBLE for your mistakes.I use AVG for my virus protection. Can you suggest a better one. I thought it was ICQ because it was the only program that I have down loaded. I also have a trojan in a system volume folder that I cannot get into. I have tried to get into it through safe mode but it will not allow me. AVG does not seem to clean this one out!WEB.......perhaps if you go to control panel / folder options /click VIEW and scroll down until you get to show hidden folder put a tick there ....move down to show hidden system folders ( not recomended ) tick there ...click APPLY and ok ....now you should be able to see those folders and get into them .
When your done change thing back to as they were .

Hope this helps

dl65 Quote

I use AVG for my virus protection. Can you suggest a better one. I thought it was ICQ because it was the only program that I have down loaded. I also have a trojan in a system volume folder that I cannot get into. I have tried to get into it through safe mode but it will not allow me. AVG does not seem to clean this one out!


Install a Firewall. Virus scanners donot prevent trojans, they find and/or remove them.

As for AVG, I have no experience with that program. I user Kaspersky Anti-Virus Personal and I must say I am quite pleased with it.I have experience with AVG and think that it's an EXCELLENT free anti-virus programme. Like all virus scanners you need to download updates regularlyIf it's detecting the trojan in System Volume Information, you can simply disable System Restore (which you should do anyway to eliminate the possiblity of the virus returning if you need to restore in the future).

In Windows ME:
right click My Computer -> Properties -> Performance tab -> File System button -> Troubleshooting tab -> disable system restore

In Windows XP:
right click My Computer -> Properties -> System Restore tab -> Turn off system restore
1775.

Solve : Pop Up Blocker?

Answer»

Been having TROUBLE lately with pop-up ..have run ad-aware and am STILL getting them.. I have HEARD that the GOOGLE tool bar is good for getting rid of these. Has anyone every used it and if so does it seem to help? Thanks alot!Use Firefox as a BROWSER rather than Internet Explorer:

Mozilla Firefox

google toolbar is good. MSN Tool bar also works. Also Popup stopper from Panicwaremy favorite is this one>http://www.secretmaker.com/

1776.

Solve : svchost.exe... Virus????

Answer»

I ran an online scan on Trend Micro and it FOUND a virus called the WORM_NACHI.DAM and the file was svchost located in the C:/Windows/System32/drivers. then i got another one only in the system32 folder. i checked properties of both and the one dat is not infected had a description of Generic Host Process for WIN32 Services, while the one infected had Unknown. should i got ahead and DELETE this? it does look suspicious being the only .exe file i got in the drivers folder.Delete or rename it and RERUN the virus scan.

1777.

Solve : Filter Program out of control?

Answer»

Quote

gpcii....The last entry 017....... with the two ip addresses ....can you check and see if they belong to your server , because when I googled them they dont APPEAR to be valid ....


Please FORGIVE my ignorance, but how would I go about checking if they belong to my server? I do use SBCGLOBAL.NET, but as to the series of numbers, I have no idea.

Thanks.That is most likely the IP adress your ISP has. No need to worry about that.

However, why not contact your ISP and ask them what you can do about the filter?Quote
However, why not contact your ISP and ask them what you can do about the filter?


Will do. Thanks.Those two addresses do, in fact, resolve to sbcglobal.netI've CONTACTED my ISP. They said to check my proxy settings, and that it should not be marked. (It's not)

They said that I could ALSO run a tracert in dos. (I did, but how would I know if what was traced was a problem?)
1778.

Solve : Nortons not recognizing tcp/IP?

Answer»

Help? Can anyone answer this? I'm running WINDOWS XP with both SP 1 and SP2. When Iboot up my computer a messageg COMES up that Nortons 2002 states that since I don't TCp/IP settings it won't scan my E mail. I have both the "Internet PROTOCOL tcp/IP and Microsoft TCP/IP ver 6 selected on the system. Also since I'm on cable they tell me I automatically have a TCP/IP setting through their modem. In the past Nortons used to scan both incoming and outgoing messages. What do I need to change?Before installing service packs you should uninstall your antivirus software. Try uninstalling Norton and reinstalling it. My wife had a similar problem and that cured it.

1779.

Solve : What virus scanner do you use??

Answer»

What virus scanners do you use?

I am currently using Kaspersky Anti-Virus personal. Before that I was using Kaspersky Anti-Virus 5.0 and Norton 2003.

So far, I like Kaspersky Anti-Virus Personal best. It is very small and easy to use.

Norton for myself. If I install antivirus protection on anyone elses machine for free, I use AVG from GrisoftAVG Free Raptor.....I use Norton 2004 on my machines and have never had a problem.........If I have to load a anti virus on a machine I'm servicing for a friend who doesn't have one I will load AVG.........

cheers
dl65 NAV04 and Common Sense.anti-vir personal edition ....free...Is there no registered AVG?Raptor......Yes there are registered VERSIONS........
http://www.grisoft.com/us/us_index.php

cheers
dl65 Why does everyone seem to use the free version?I guess not everyone likes to steal software.most software starts off being free till it GETS popular and then the cash barons come into play...or someone BUYS them out....like ROXIO go back ....>is now norton go back..its best to not have all you eggs in one basket....anti-virus+stinger+ shredder +spysweeper and a twist to this post who is writing them....is it an anti-virus....software...empire...no viruses.. no bussiness..makes you wonder ...?i my SELF use nortonI my self as opposed to I somebody else?Quote

and a twist to this post who is writing them....is it an anti-virus....software...empire...no viruses.. no bussiness..makes you wonder ...?


Bored German teenagers.


1780.

Solve : Results of Spybot Scan-- Virus?

Answer»

Said 173 things wrong. I'm afraid if I click to fix, I will wipe out my MACHINE. Was clean about 2 weeks ago. Is this virus? AVG doesn't pick up anything. This is only small part of listing from Spybot.

Congratulations!: No immediate threats were found. ()
Windows Registry: C:\WINDOWS\Downloaded Program Files\googlenav.dll (Missing shared DLL, nothing done)
googlenav.dll
Windows Registry: C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (Missing shared DLL, nothing done)
WinCinemaMgr.exe
Windows Registry: c:\WINDOWS\System32\msxml3a.dll (Missing shared DLL, nothing done)
msxml3a.dll
Windows Registry: logos.exe (Wrong app path, nothing done)
Windows Registry: Rrbaby.exe (Wrong app path, nothing done)
C:\Program Files\The Learning Company\Reader Rabbit Kindergarten\Rrbaby.exe
Windows Registry: SoundMAX (Wrong app path, nothing done)
C:\Program Files\Analog Devices\SoundMAX\SoundMAX
Windows Registry: SPANISH.EXE (Wrong app path, nothing done)
F:\SPANISH.EXE
Windows Registry: winnt32.exe (Wrong app path, nothing done)
Windows Registry: yourapp.Exe (Wrong app path, nothing done)
C:\Program Files\Kodak\Camera Connection Software\yourapp.Exe
Windows Registry: table30.exe (Wrong app path, nothing done)
Windows Registry: SoundMAX WDM Driver (Wrong app path, nothing done)
C:\Program Files\Analog Devices\SoundMAX WDM Driver\SoundMAX WDM Driver
Windows Registry: setup.exe (Wrong app path, nothing done)
Windows Registry: ORUN32.EXE (Wrong app path, nothing done)
C:\WINDOWS\ORUN32.EXE
Windows Registry: install.exe (Wrong app path, nothing done)
Windows Registry: cmmgr32.exe (Wrong app path, nothing done)
C:\WINDOWS\System32\cmmgr32.exe
Windows Registry: DImageViewer.exe (Wrong app path, nothing done)
C:\Program Files\DiMAGE Image Viewer Utility\DImageViewer.exe
Windows Registry: arcsoft.exe (Wrong app path, nothing done)
C:\Program Files\ArcSoft\PhotoImpression\arcsoft.exe
Windows Registry: 3dtf.exe (Wrong app path, nothing done)
C:\Program Files\hp\Photo Manager\3dtf.exe
Adobe ACROBAT Reader 5: Last selected preference panel (Registry value, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\PrefsDialog\aLastPrefsPanel
Adobe Acrobat Reader 5: Recent file #1 (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c1
Adobe Acrobat Reader 5: Recent file #2 (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c2
Adobe Acrobat Reader 5: Recent file #3 (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c3
Adobe Acrobat Reader 5: Recent file #4 (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c4
Adobe Acrobat Reader 5: Recent file #5 (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c5
Adobe Acrobat Reader 5: Recent file #6 (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c6
Adobe Acrobat Reader 5: Recent file #7 (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c7
Adobe Acrobat Reader 5: Recent file #8 (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1449542653-877864702-1017937101-1003\Software\Adobe\Acrobat Reader\5.0\AVGeneral\cRecentFiles\c8
Common Dialogs: History ( (284 files)) (Registry key, nothing done)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRUIt says no problems found. Is there something you need help with?QUOTE

Congratulations!: No immediate threats were found. ()




Please refer to the help guide if you have absolutely no idea what you're doing.Let me explain more about what's happening. I am worried because I keep getting alerts from my server (sometimes as many as three a day) saying "You have been sent a virus, but it has been removed." I really appreciate my wonderful server catching them before they get to me, but I try to keep check on my machine in case one does get through.

When I run AVG and Ad-aware, I get a good result... have clean machine. But when I run Spybot, the test result says "Congratulations" But directly under congratulations, a great many errors are listed. Some are registry problems that I'm afraid to "fool" with... some are tracks which I have deleted... no red errors yet

And sometimes I don't have a clue about this computer "stuff"; but I have decided there might be something wrong with my Spybot program. Think I will do an uninstall and then reinstall it

What do y'all think?

TIA, Patsy

If the viruses are intercepted, you have not much to worry about.

These are the things everyone should have installed:

  • Anti-virus
  • Firewall
  • Spyware scanner


And properly configured, ofcourse.

If your virus scan can find nothing and your spyware scanner is used on a regular basis, you have very little to worry about.

However, you did not mention wheter you had a Firewall installed. I suggest you read this article:

How Stuff Works - How Firewalls Work

I ASSUME when you say 'server' you mean your mailserver?

As for deleting registry entries, I never used Spybot Search & Destroy for that.

I would recommend a program such as Regseeker, Advanced System Optimizer V2 or Advanced Uninstaller Pro 2004 to clean your registry. They can create backups and, except for Regseeker (which is the only freeware tool in this list) can provide you with more services.
1781.

Solve : total shut down?

Answer»

wtoolsa and wsup have my windows 98 inoperable
in safe mode no icons even show up or the START button
scan reg didn't help
if yo have ideas with the C:/ please explain how to GET there in easy terms i'm pullin my HAIR out
Sounds like you may need to repair some of the system files, which is quite easy in Win9X.
Boot from the boot floppy. Once you get to the DOS PROMPT, type
sys c:
this will overwrite the basic system files.
When it's done, REBOOT into safe mode and run Ad-aware and Spybot.Does this work for XP?

1782.

Solve : My comp sucks?

Answer»

Ive run Adaware, Spysweep, Spybot S&D and windows washer yet my comp still randomly reebots and my internet explore home page is still bein changed to a website called "about:blank" how do i make my COMPUTER not suckThe random rebooting of your computer is not necessarily a software problem. First though, I would ensure your virus definitions are up-to-date and I would run a full system scan. Also, make sure that ALL of your drivers are good.

If that doesn't work, CHECK the fan on your processor. If you touch it and burn your finger, you need a new fan and that should fix the problem. I have also seen BAD RAM and hard drives cause the problem. Hope that helpsJanet.........What anti virus are you running and is it current and complete with all the latest updates ?.
Also ....the fact that your home page is being changed,
suggests that you may have have a hijacker present.
So ......D/l CW Shedder .........Ver 1.59.1
http://www.majorgeeks.com/download4086.html ...
when your hompage is changed to " about blank" run Shedder and it should change it back and TELL you what changed it .

If you do in fact have a hijacker ......then you will have to REMOVE it using Hijackthis......
http://www.majorgeeks.com/download3155.html ....
Now if you want to know what the hijack this log is all about goto .......... http://computercops.biz/HijackThis.html
http://computercops.biz/CLSID.html
http://computercops.biz/StartupList.html
Here's more info on the hijacker .....
http://www.richardthelionhearted.com/?url=merijn.richardthelionhearted.com

Let us know how you make out .

dl65

1783.

Solve : problems with dial up changing?

Answer»

when ever i disconnect from the internet something happens to my dial up. when i go to connect again later my user name has changed with like an IP ADDRESS at the end and the phone number i use to dial to my ISP has change to this huge string of numbers. i have done spyware checks and run ANTIVIRUS scans but i can't find ANYTHING. its really pissing me off.
please can anyone help?!?!save your username and password...delete your dial up connection and MAKE a NEW one and see if it does it again? and what operating system is this happening to?

1784.

Solve : My Computer is horrible?

Answer»

My computer has deep deep issues, it all started when my internet was FROZE to one page. I call the computer company and they basically told me to run a system recovery. I did and that did not fix the problem. It deleted everything that it intended to do, but now everytime i try to do anything i get error MESSAGES like not accessible to desktop and stuff like that. I TRIED to buy and antivirus program thinking that would do the trick but the computer says (yes it talks) that i NEED 11megabytes to load the software. I try to do that and that doesn't happen. I cant even reload my isp through the cd rom this whole thing is frustrating i am hoping somewhere someone could help me. Let me know please thank you very muchSeems to me like you're better off formatting your HDD. Take proper precautions before connection to the internet and install an Adware SCANNER, Virus scanner and a Firewall.

How Stuff Works - How Computer Viruses Work

How Stuff Works - How Firewalls Work

How Stuff Works - How Internet Cookies Work

1785.

Solve : lsess.exe?

Answer»

can anyone tell me what this PROGRAM is...You probably MEAN lsass.exe, correct?

Lsass.exe is a FILE that can be infected by the Sasser worm.

What You Should KNOW About the Sasser Worm

1786.

Solve : www.404ads.net?

Answer»

I was getting a LOT of spyware so i downloaded spybot and ad-aware now sometimes when i try to sign on the internet i get redirected to www.404ads.net... (more there) I was wondering if anyone KNOW how to stop that.Adaware SE should offer you the OPTION to lock your BROWSER and PREVENT hijacks.

1787.

Solve : Freezing XP - Help me!!!!?

Answer»

Computer appears to boot up normally - goes all the way thru to "loading personal settings" - then nothing.
All I SEE is the background - no desktop icons - no task bars - nothing. I am SURE it is a virus - trojan - etc. However, I can't run a virus scan - or can I? I tried to run in Safe Mode and got the same result - no desktop. Help me please.Try Safe mode Last known good configuration.I donot quite UNDERSTAND how you are certain that it is a virus, yet you failed to prevent the problem from happening?

I suggest you format. But before you do that, read up on Internet security.

Fresh start, more knowledge, better security.

How Stuff Works - Internet ChannelThanks for education - I is stupid. I guess I should have said I ASSUME it is a virus. I have many security measures in place - but apparently - something got by. Could I be the first VICTIM?
Sorry - your reply smacks of sarcasim and is not appreciated.
Now - try to answer the question - unless you can't (which I suspect is the case).Nothing ever gets by here.

Quote

Now - try to answer the question - unless you can't (which I suspect is the case).


You're testing me. How exciting!

Did you do as Robertmillar said?

You did not mention when the problem occured and how you made it occur.

And, last but not least, you may be able to use the repair option on your Windows XP CD-ROM.

Yes - I am testing you and I hope (as the name implies) you will oblige me.
I did try to do what Robert Millar said to no avail.
The problem occured when I booted up, as I stated in the first message. I don't recall doing anything that would have made this occur.
Let's see - I turned on the computer - went to get my morning coffee and returned to a blank (or should I say a background) with no desktop icons.
I rebooted - same result.
I have been able to go into task manager and open programs from there - so I was able to retrieve all important data and burn.
I have a new hard drive now - so problem solved. I hope.Did you have the latest Microsoft security updates installed?This is the same exact problem I am currently having on my laptop.

I'm going to have to buy a new harddrive to fix this?

*censored* no, I'm on a *censored* laptop as it is and on a college payroll. I don't have money, but I do have time. Any other suggestions on how to fix this?

By the way, how did you retrieve your information from the task manager? (I don't have a burner so I can't backup any important information)

Any advice on how to fix this will be greatly appreciated. I will try as well, but you guys are the EXPERTS!

[edit]
To answer some of those questions, I tried everything previously mentioned on this thread and I think I had XP Service Pack 1 installed, but not 2.
1788.

Solve : Tip of the week?

Answer»

Here is a super tip - Just sort your windows system32 and drivers directory according to DATE and the most recent files are on top. simply delete the files of the last four or five DAYS and you will be surprised how all the problems vanish try this safemode only....it may help people in the fight against trojans/worms/spyware etc..AH, yes, I allready see the hordes of clueless people who delete the wrong files and ask us why we'd post such tips.you would have thought by now people the own pc have the sense by now to know what to do with it if they>?DONOT YOUR USE THOSE UPDATES silly ??...some system that is keeps needing them WHY ??the question is the system is that good why do you need updates /program/fault/bad scripting/the list could be endless nice scam...but that would be then end of all fixit forums....bring on longhorn after all winxp does keep me GOING ...thou i do have a super-nap care off m$oft > that the average person needs nine.30 mins of sleep but wixp keep me awake ..wondering if it may be like the operating systems that msoft ..marking department have tried to sell the user an infalable system wake up people ...are you being conned is the question i would like to run a poll on this issue ..you can keep winxp i will stick with winme...its weird that bill gates dumped it ...the best system besides win98se...maybe is was to good !as has for the last poster it may help them concerned.... I agree with Merlin on XP; its a total suck out. Have you ever heard of Paladium or DRM or Microsofts secure computing initiative? SP2 was just the beginning. Longhorn will be the back breaker. You won't be able to run any software that has not been "approved" to run on your machine. But don't take my word for, do your own research.There are safer ways to remove redundant files..I'm agreeing with Raptor here. Methinks BEGINNERS would be a little better off with a couple of virtual dishcloths (anti-virus, anti-spyware etc) than the "pour industrial strength bleach all over everything - that'll kill all the germs" tactic.

merlin, Windows ME is four years old now (at least). It's not weird that Microsoft quit supporting it - it's good business sense.

And boys, if you're so worried about all this Palladium malarky, there are hundred's of Linux distro's avaliable for free on the internet...

1789.

Solve : Norton AntiVirus Live Update won't complete?

Answer»

Ok, it looks like my AntiVirus software has a mind of its own! The LiveUpdate just completed there with no problems. Weird or what

Thanks for the help guys, i'll be BACK if it happens again Perhaps it is due to another program you have installed that is causing Norton to behave strangly.Quote

Perhaps it is due to another program you have installed that is causing Norton to behave strangly.


Ok, well the only THING that i installed in the PAST few months was Java Web Start by Sun Microsystems. I didn't have java installed on my machine so i couldn't view some sites properly. I was told to download this to fix my PROBLEM. It has fixed it but maybe that is what's causing Norton AntiVirus to mess up.. Hmm...
Do you think i should un-install it Raptor??Are you certain there are no other programs running in your background? I doubt Java would cause that sort of problem.

Perhaps you should have a look on the Symantec webpage to see if there are any lists with programs that cause problems or E-mail technical support. (You're paying for it!)Absolutly sure. I'll leave it be for now seeing as its working again but if it does happen again, i'll email technical support. As you said, i am paying for it! Thanks
1790.

Solve : Computer help.?

Answer»

Hi. I was wondering if someone could maybe give me some ADVICE, or help about a problem that my computer seems to have.

This morning, I turned on my computer, and everything was fine for about an hour, but then there was this problem that seemed to happen. Whenever I visited a site, I WOULD get pop-up after pop-up, and even when I went to my homepage, I got numerous pop-ups.

Then, my computer got really slow, and keep disconnecting from the internet. Another problem, is that my computer kept freezing up, and I've had to restart it numerous times.

The first thing that came to my mind, is that maybe my computer has a virus?

I use to have Norton Antivirus, but it doesn't scan anymore... I do have "maintenance wizard"...

If anyone has any idea what the problem with my computer is, I would appreciate any help. My email ADDRESS is [emailprotected]

Thanks.moviefan81.......What do you mean you used to have Norton Antivirus...but it doesn't scan any more......?

Certainly sounds as if your pc is infected with who knows what ......
You must install and scan with Anti Virus ( one that works) and also I would suggest Ad-Aware and Spybot .

I would also D/L and run stinger ...just to do a quick check for a few nasties. http://vil.nai.com/vil/stinger/

Then I would got to ..... http://www.symantec.com/index.htm scroll down to downloads......then select security check ........now do the scan for viruses.

Do yourself a favour and get a good anti-virus. You can D/l Norton AV .........free for 90 days ......

let us know
dl65 Trend Micro - Free Online Virus Scan

Install a decent virus scanner, but first use this.

Scan for Spyware as well.Thank you for the advice.

Norton antivirus use to scan my computer every friday, but it stopped scanning my computer. I click on "Norton antivirus", but it doesn't do anything. Maybe I need to install Norton antivirus again.

I installed "spy sweeper" and it found some "spyware" and "adware" on my computer. My computer is a bit faster today, and I'm having no problems with pop-ups, but it still disconnects from the internet every now and then.

Once again, thank you for the advice. I'll keep you updated on how things go. Hopefully those links you provided will help fix my computer.

Thanks.moviefan81......Have you checked Norton to be sure the "Auto Protect" feature is still ENABLED? Some viruses will disable that feature ....... Have you D/L and ran stinger ? Is your Norton up to date with the latest virus definitions and is your subscription still valid .......

let us know

dl65 My computer has been running great the past two days. after scanning my computer with "Spy sweeper"... it seemed to fix my computer right up. It's running fast, and it's not disconnecting from the internet like it was last week.

I'd like to thank everyone who helped me. I really appreciate all the help, and I know if I need some computer help, I'll come to this site for the help.

Thanks again everyone.I suggest you use a browser such as Mozilla Firefox and configure it STRICTLY so that not even tracking cookies get through.

Also run your spyware scanners on a regular basis. Same goes for virus scanners.

1791.

Solve : Norton scanning Word files....stop it??

Answer»

Just installed Nortaon AV Scan 2004...
How can I turn off the scan on my Word files? Every time I go to open a file, I have to wait for it to scan first.
What a pain? Is this necessary???

Thanks.wonderer.....I'm not so sure thats a great idea.....but if you must ...open Norton and CLICK on options...then click miscellaneous.....and REMOVE the tick from ....enable office plugin.
I think that will do it .

dl65 Thanks for your reply.
So, you don't think we should take it off?

What is the risk on Word files? I don't use it much...just copy and paste text from the INTERNET onto Wordpad first and then Word. (to clean up format, etc.)It may scan for harmful macros. Macros should be disabeled from within Word, but ADDITIONAL security doesn't HURT.

1792.

Solve : BAsfIpM.exe?

Answer»

hey all,

Nothing's really WRONG with my computer, but I'd like to keep it that way and I was looking at my task manager and i NOTICED a STRANGE EXECUTABLE...BAsfIpM.exe...so I was just wondering if anyone knew what it is/does and if it's ok

thanks!Perchance, is your computer a Dell?

That is a driver for some SORT of card or chip from BASF. A visit to BASF web site might shed more light on the subject.

1793.

Solve : Privacy?

Answer»

How can I find out if someone who I share a computer with has installed any programs that might be tracking my computer USAGE or GAINING access to my EMAILS or using any other method to gain access to my privacy?http://www.keylogger.net/or buy an external hard drive...Thanks for responding Merlin_2. I hope my question was clear. I am not LOOKING for a way to spy on someone else. What I want to do is find out if any programs such as Keylogger have been installed on my PC. I understand these type programs are deliberately hidden on a computer and can even be set up to secretly email my computer activities to someone. How can I check my computer to see if any such program has been installed? Thanks, Shad.i take it you are logged in as a user...download spysweeper from www.webroot.com...it should scan the pc for all programs which maybe tracking you..like radmin..keyloggers..etc..tojans /worms..and there is this>http://www.tooto.com/keyloggerkiller/ i post the keylogger to fight FIRE with fire if you get my drift Please Read This First - Viruses & Spyware

Install the programs recommended.

How Stuff Works - Security Channel

How Stuff Works - Internet Channel

Read the articles related to what you wish to know.

1794.

Solve : AVG-NORTON ?Conflict?

Answer»

I have NORTON 2004 and AVG antivirus program INSTALLED in my computer having windows XP. I want to ask whether there will be any problem or conflict having both softwares.You should never have more than one virus scanner installed.

It may cause conflicts. even it does not, you will still use more memory than you have to, resulting in poorer PERFORMANCE.

1795.

Solve : I need help with a virus problem?

Answer»

I ran a virus scan with AVG 6.0 and this is a LIST of all that was found. I have tried to remove them with AVG and it says they can't be removed. I don't have a clue on how to get rid of them. I have tried to search the help sites with no luck. I have not found these virus names on any site. If someone knows how I can remove them please let me know. Thanks!!

Results of Complete Test, date and time 9/28/2004 1:01:40 :

Testing C:\ volume LOCAL DISK serial 3938-1B06
C:\_RESTORE\TEMP\A0043201.0 Downloader.Alchemic.A
C:\_RESTORE\TEMP\A0043208.0 Downloader.Agent.2.AA
C:\_RESTORE\TEMP\A0044523.0 Downloader.Istbar.4.AD
C:\_RESTORE\TEMP\A0044526.0 Downloader.Alchemic.A
C:\_RESTORE\TEMP\A0044527.0 Downloader.Agent.AS
C:\_RESTORE\TEMP\A0044528.0 Downloader.Istbar.4.H
C:\_RESTORE\TEMP\A0044868.0 Downloader.Dyfica.2.AB
C:\_RESTORE\TEMP\A0044871.0 Downloader.Dyfica.2.AB
C:\_RESTORE\TEMP\A0044874.CPY Downloader.Istbar.4.AM
C:\_RESTORE\TEMP\A0049167.0 Downloader.Dyfica.2.AA
C:\_RESTORE\TEMP\A0049168.0 Downloader.Agent.2.AA
C:\_RESTORE\TEMP\A0049169.0 Downloader.Dyfica.2.AC
C:\_RESTORE\TEMP\A0051764.0 Downloader.Dyfica.2.AK
C:\_RESTORE\TEMP\A0051765.0 Downloader.Dyfica.2.AE
C:\_RESTORE\TEMP\A0051766.0 Downloader.Dyfica.2.AE
C:\WINDOWS\TEMP\HPOTDD000.log Cannot open; not checked!

Test finished, duration 00:10:20.7 s
12197 objects tested, 15 found infectedtandkand3a....I do not believe the items you listed are viruses ....but rather spyware , malware , adware and possibly page hijackers. ( pests )

ISTbar is an IE toolbar, homepage- and search-hijacker provided by Integrated Search Technologies/CDT Inc.

I would suggest D/L Ad-Aware SE and Spybot and then
watch them run......lol
Have you not looked for them in the path which your AV gave you.......because thats where they are .
Have you noticed anything else odd about the way your pc is running ?
You failed to mention what operating system you have .

let us know
dl65

My OS is Windows ME. I check and install updates on a regular basis. I also run Ad-aware SE and Spybot. Both of those scans show the computer as clean. I have tried to search for the files and can't find them on the computer. They are gone or I am not looking in the right place. I have not experienced any problems with my computer, it seems to be operating normal. Should I run Hijackthis? tandkand3a......

TROJ_ALCHEMIC.A ......trojan
This memory RESIDENT Trojan is capable of downloading and installing additional applications without first notifying the user. The downloaded file may be updates to other adware programs.

It may act as a Browser Helper Object (BHO), which is ABLE to monitor all Web sites visited. It may also display popup advertisements.

It runs on Windows 95, 98, ME, NT, 2000, and XP.

Dyfica.2.AB ....... another trojan
Agent.2.AA ....... another trojan
Istbar.4.AD ........ yet another trojan

Try this:
Remove Trojan horse Downloader.Istbar.4.H this way:
*Close all programs.
*Turn off System Restore
*Run AVG Complete Scan
*Turn on System Restore.
If you can't find Trojan horse Downloader.Istbar.4.G, AVG may have moved it to the Virus Vault. Check the Virus Vault.

Disabling System Restore on Windows ME
In Windows Millenium there is System Restore. Windows ME creates backup copies of the essential system files so they can be restored if they get corrupted. Sometimes this makes the disinfection difficult since the backup files can get infected. In those cases Windows will copy the infected file in the place of the clean one.

This feature can be disabled with the following steps

1. Right-click on the My Computer icon and select Properties
2. In the System Properties windows select the Performance tab
3. Click on File System... button
4. In the Filesystem Properties window select the Troubleshooting tab
5. Check the Disable System Restore checkbox
6. Click Apply button
7. Close the windows using the Close button
8. Click Yes when prompted for reboot

The System Restore feature can be enabled again with the same steps. At step 5. you have to uncheck the Disable System Restore checkbox.

If this doesnt get rid of the trojans......then run hijackthis ....but I dont think you should have to.

let us know how you make out

dl65


I checked the Virus Vault and it is empty. I ran AVG again and tried to remove the 15 files and they could not be removed. The system restore function is turned off. I did run Hijackthis but it will not let me post the log on here. It says that the message is to large. Both Ad-aware and spybot shows the system clean. Any ideas on how to post the log or other solutions.Run AVG in Safe mode.tandkand3a........If you post your log in 2 PIECES rather than one you should be able to post it ok.
And it looks like your trojans are residing in your restore files........have you looked there ?

let us know
dl65 I have run AVG in Safe Mode and the results are the same. Here is part of the Hijackthis log.
Logfile of HijackThis v1.97.7
Scan saved at 11:07:48 PM, on 9/29/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\NORTON UTILITIES\NPROTECT.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\TPWRTRAY.EXE
C:\WINDOWS\SYSTEM\TFNCKY.EXE
C:\WINDOWS\SYSTEM\TOSHIBSU.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\PROGRAM FILES\NETGEAR\WG511\UTILITY\WG511WLU.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SOFTWARE UPDATE\HPWUSCHD.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\DIGITAL IMAGING\BIN\HPOTDD01.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\WINPATROL.EXE
C:\PROGRAM FILES\RAM\RAMBOOSTER.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\WINDOWS\DESKTOP\PC HEALTH\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://centralkansas.cox.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://members.cox.net/mycrosmith/
R3 - URLSearchHook: (no name) - _{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YCOMP5_3_12_0.DLL
O2 - BHO: (no name) - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - C:\PROGRAM FILES\POPUP MANAGER\POPUPMGR_1.0.2.1P.DLL
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN0\YCOMP5_3_12_0.DLL

Here is the second part of the log.

O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TFncky] TFncky.exe
O4 - HKLM\..\Run: [TOSHIBSU] TOSHIBSU.EXE
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [NPROTECT] C:\Program Files\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\Run: [WG511WLU] C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRAM FILES\BILLP STUDIOS\WINPATROL\winpatrol.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [NPROTECT] C:\Program Files\Norton Utilities\NPROTECT.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.e4me.com/start.html
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37893.3547569444
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: DigiChat Applet - http://albany.digi-net.com/DigiChat/DigiClasses/Client_IE.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553542500} - http://active.macromedia.com/flash2/cabs/swflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab

forget ad-aware spy-bot try this one its beat bother of them>http://www.webroot.com spysweeper... and do you use kazza or aol..or if you really get fed up re-install winme....locate the c:\windows\options\cab folder next to the scanreg icon ....is the famous icon called setup click this will re-install winme..without losing any files and disable system restore its not needed...and dont use ie6 either...Thanks Merlin_2 your advice worked. I did re-install Windows and everything is working great now. Thanks to EVERYONE who helped me. This is a great forum!!

1796.

Solve : Can't close Internet Explorer windows?

Answer»

Hey everyone. My internet explorer was working fine today. THen all of a sudden, I cant close the windows. i have to go to END task and do it and even when i go tehre it sais i have to do end now for it to close. also, when i go online my cpu usage jumps to 100%. im pretty sure its not my internet and my cpu is new its been running well for about 3 months. I can close other windows that arn't online EASILY. i think its a virus but im not sure. please help me. thanksoh yeah EVERYTHING else runs fine. i can play games and go on aim but the only problem is using internet explorer. it just wont let me close its BROWSERS and my cpu usage jumps like crazy. i ran spyware and adware programs. it detected a few but ive always had them and i dind't have problems like these. i would also delte them every DAY but today i only found about 10 of them so i dleted themScan for viruses and trojans as well.

1797.

Solve : system soap?

Answer»

don't know how, but have a program called system soap running on my pc. no MATTER what i do i cannot remove it. are you familiar with this program, and if so how do i remove it?
Scan for viruses, TROJANS and spyware.

When and how did you obtain this particulair program?Maybe it is telling you that you need a system shower..... XDJust don't DROP that soap.put it on a rope, XDI suddenly got the vision of a prison RAP song....... blehThis page might be useful.r barnett.......system soap is a cleaner......
http://www.systemsoap.com/
this MAY help you get rid of it....
http://www.kephyr.com/spywarescanner/library/systemsoappro/index.phtml

http://www.spyany.com/program/article_adw_rm_System_Soap.html

Hope this helps you get rid of it ....doesnt sound like its something you want on your pc.

dl65

1798.

Solve : to Read registry to get all the application?

Answer»

Hi Guys,

can ANYONE HELP me,I need to READ or with the help of registry i need to find out away to get all details of entire computer from registry so that i can find out what applications are running on the computer and then take a back up and RESTORE them,Please help me

thanks in advancevishnu....Perhaps you could provide a little more info as to what the ISSUE is and which operating system your using .

dl65

1799.

Solve : you guys are guna love this....?

Answer»

i have a little problem with spyware/adware sort of speak...... noticed it when my homepage turned into somthing else... i change it and it changes back... i run hijack this and remove what i knew whasnt supposed to be there, and i re-scan it comes back... i goto my Registry edit and remove the items that where there that wernt supposed to be... and the appear right back.. i run trojanhunter.. none found.. same with norton.. i run adware (lavasoft) and it finds 31 PROBLEMS, i remove and quarentine.... re-scan .... they come right back... (even after reboot) i run spyware S&D... finds CoolWWWSearch or somthing and a couple others... it removes them... and guess what They KEEP comming BACK! its like a fly that lands on the same spot everytime you shoo it away.. i wouldnt be posting this unless i was absolutly shure i couldnt handle it myself... so i need some suggestions here...

thanks... :-/I had this one too. I struggled with it for hours but no luck. Eventually I found the utility CWshredder. This is what you need to clean up your system. Available here http://www.softpedia.com/public/cat/10/17/10-17-150.shtmli did the cws shredder also... forgot to say that in my first post... i used it and it said it cleaned but they keep comming backHmmm, maybe a new varient. I can only suggest using system restore (if you are using xp?) to restore the registry back to a point before it was infected. Or...and this is DANGEROUS, edit the registry by hand to delete any references to the files reported by adaware. I know you said you have done this, but the trick is to reboot into safe mode only so that the *censored* thing doesn't autostart and begin repairing itself before you have gotten every trace of it. Good luck!its a clean install.... 1 day old. not shure where i got it first of all... but ill try the safe mode issue, only because i know reg keysshield....www.coolSearch is one bad one to get rid of....
I would suggest running hijackthis again and posting the log here so we can have a look at it......I believe you may have missed something......DO NOT, I REPEAT.....Don't....use your system restore. CW SHedder will identify it and reset your homepage .....but until; you clean it out , will keep coming back.


dl65
i ran safe mode and cws shredder and hijack this and removed those adware.... they came [emailprotected]#! its so irritating.... heres me hijack this in next post:Logfile of HijackThis v1.97.7
Scan saved at 9:34:10 AM, on 10/12/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\System32\Ati2evxx.exe
D:\Program Files\Sygate\SPF\smc.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\Ati2evxx.exe
D:\WINNT\Explorer.EXE
D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
D:\Program Files\ICQLite\ICQLite.exe
D:\WINNT\System\MSMSGSVC.exe
D:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
D:\WINNT\system32\wuauclt.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%[emailprotected]/hp/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%[emailprotected]/hp/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%[emailprotected]inder.cc/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://homepage.com%[emailprotected]/search/ (obfuscated)
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: (no name) - {834261E1-DD97-4177-853B-C907E5D5BD6E} - D:\WINNT\dpe.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SmcService] D:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [ICQ Lite] D:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [MSMsgSvc] D:\WINNT\System\MSMSGSVC.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] D:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: MemTurbo.lnk = D:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://D:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: ICQ 4 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O13 - DefaultPrefix: http://%65%68%74%74%70%2E%63%63/?
O13 - WWW Prefix: http://%65%68%74%74%70%2E%63%63/?
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38270.6357175926
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave FLASH Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabi removed the following:



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%[emailprotected]/hp/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%[emailprotected]/hp/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://homepage.com%[emailprotected]/search/ (obfuscated)




and they just keep commming back onHave you tried running all these programs in safe mode?shield....Ok here's what I would like you to do....
1 open hijackthis...and click info....now make sure that in Configuration / main there is a tick in box 2,3,4,5 and no tick in box 1.
2 In the boxes for the URLs...... enter http://www.msn.com
do this for all four.....
3 now click the back button.
4 now click Scan button

now I want you to mark for removal all the entries I have put in red


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%[emailprotected]/hp/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.com%[emailprotected]/hp/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%[emailprotected]/search/ (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://homepage.com%[emailprotected]/search/ (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://homepage.com%[emailprotected]/search/ (obfuscated) R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: (no name) - {834261E1-DD97-4177-853B-C907E5D5BD6E} - D:\WINNT\dpe.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\System32\msdxm.ocx
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - D:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [ATIPTA] D:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SmcService] D:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [ICQ Lite] D:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [MSMsgSvc] D:\WINNT\System\MSMSGSVC.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] D:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Startup: MemTurbo.lnk = D:\Program Files\Silicon Prairie Software\MemTurbo\memturbo.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://D:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: ICQ 4 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O13 - DefaultPrefix: http://%65%68%74%74%70%2E%63%63/?
O13 - WWW Prefix: http://%65%68%74%74%70%2E%63%63/? O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38270.63 57175926
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

when you have ticked the ones in red.....click the fix checked button......

I would do all of the above in the safe mode .
This should clear it .....It wouldn't hurt to scan again now with Ad-Aware and if you have it Spybot.
Do you have any kind of a registry cleaner ? ie ......system mechanic pro 5 or registry first aid .
If you have run them as well.

Then reboot back up normally and see how things are .

let us know how it goes

dl65


dl65.... i love you... it worked all clean no spyware/adware/nothing..... wanna go out for dinner? LOL thank's bud. shield.....Glad to hear your pest free......hijackthis does a great job ......the key to using it is to research each entry in the log it generates.......

cheers,

dl65 so do you wanna go for dinner or not shield.......So what did you have in mind?

Burger King or McDonalds.......lol

dl65

1800.

Solve : catch.exe?

Answer»

my daughter has a dell inspiron LAPTOP RUNNING windows xp pro. she mentioned that when she reviewed her task manager process list, there was a process running called "catch.exe". i've looked everywhere and can't find a reference to it as spyware or virus...just a reference to an old DOS 6.2 college biology program. anyone ever hear of it? my daughter has symantech 9.x and ad-aware. thanks!huxster....you QUITE correct....it is Dos SIMULATION program.....
http://www.aquanet.com/Resources/fish/topics/FS_1B_97.HTM
If its something you DONT require , use any more or don't want .......why not simlpy delete it .

let us know

dl65