InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1751. |
Solve : Please help me fix my computer from randomly freezing.? |
|
Answer» Hi, this is the log from the MBR:
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also STOP certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 1752. |
Solve : Transfer avg to another computer?? |
|
Answer» Hi, |
|
| 1753. |
Solve : Nasty virus? |
|
Answer» Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. First install the new Sun Java Runtime Environment Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close all browser windows before beginning the install. Remove the old version(s) Download JavaRa * Unzip the file and open the JavaRa.exe * Click Remove Older Versions * JavaRa will search for and remove any outdated version of Java and remove any that are found. * Click Additional Tasks * Place a check next to Remove Useless JRE Files and click Go * Exit JavaRa * Delete the JavaRa files from the Desktop Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer. ---------- Update your Adobe Reader. http://get.adobe.com/reader/ Be sure to uncheck the Free McAfee Security Scan so it isn't installed. ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Now restart the computer and try updating again. .Well I have been working on the updates recommended from the Secunia Software Inspector. I get a message that "Windows Malicious Software Removal Tool - September 2009 (KB890830)" was installed successfully. And that "Security Update for Jscript 5.7 for Windows XP (KB971961)" Failed to update. I have performed this update a number of times through the Windows Update site and get the same result everytime. The yellow shield is still coming back with a message that I NEED to install update KB890830. It's like something is blocking the update. Thanks again for all of the help.Try the direct download for KB890830 http://www.microsoft.com/downloads/details.aspx?familyid=ad724ae0-e72d-4f54-9ab3-75b8eb148356&displaylang=enI am sorry for being such a pain. I tried the direct download 4 times and could never get it to install. But after I tried the direct download I clicked on the yellow shield and got the message "installation complete". I did this twice and rebooted each time and the yellow shield came back with the same message - that I needed to install the update. If this is not a remnant from the virus I can live with it and leave you alone. My PC is running fine except for the annoying yellow shield. Thanks for all of your help. I HOPE that I do not need to ask for your assistance anytime soon. EF and SD have been an incredible help. I can not say thank you enough. KarenHello Karen. Could you please try this: The MRT (Malicious Software Removal tool) is located in WINDOWS\system32 and is named MRT.EXE To see if it's present on your system. Go to Start > Run > copy and paste the below into the Open: line mrt Click OK or press Enter Wait a little while and the tool *should* open Click the Next button Put a mark next to 'Full Scan',click Next, and do a full scan Please let me know what happens.SD, I am not sure what you want me to copy and paste, I tried "mrt" and got the following message: "Windows cannot access the specified device, PATH or file. You may not have the appropriate PERMISSIONS to access the item." Am I missing something?That's what I wanted to know. Apparently, the download is not completing itself. Mrt should have triggered the program to run if it was there. When you download the file do you save it then install it or do you install it right away?Did you try mrt.exe ?Yes, I tried MRT.EXE - same error message. SD, I have tried both ways. I have saved and then installed. And I have installed right away.Hello Karan. We are quite sure that the problem you're experiencing with the MRT update from MS is not caused by an infection. Your computer appears to be clean. Perhaps you could contact MS Updates to see if they can help with the MRT update problem. NOTE: Some of these you have already done. Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the LATEST Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth. Safe SurfingThanks for all of your help! |
|
| 1754. |
Solve : Infecton I think.? |
|
Answer» I downloaded a program that i thought was a audio recording program but it asked me restart and it stopped my antivirus from running and firewall then I open them up manualy and avast is finding stuff. I have ran scans with MBAM and SAS but nothing much was found. O2 - BHO: (no name) - {B17324EB-1C4E-453F-BAB4-E82D5F3314C2} - (no file) 2) Next download RootRepeal.rar and unzip it to your Desktop. You'll need WinRAR to extract it * Double click RootRepeal.exe to start the program * Click on the Report tab at the bottom of the program window * Click the Scan button * In the Select Scan dialog, check: o Drivers o Files o Processes o SSDT o Stealth Objects o Hidden Services * Click the OK button * In the next dialog, select all drives showing * Click OK to start the scan The scan can take some time. DO NOT run any other programs while the scan is running * When the scan is complete, the Save Report button will become available * Click this and save the report to your Desktop as RootRepeal.txt * Go to File, then Exit to close the program * Attach this log in your next post. 3) Download DDS by sUBs to your desktop. Your antivirus software might question the file. If it does, allow it. * Double click DDS.scr to run it and wait for the scan to finish * When finished DDS.txt will open * A small while later, a prompt will open. Answer Yes * DDS will continue scanning * When done, Attach.txt will open Copy and paste the DDS.txt and attach Attach.txtHere is my logs G. ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time:2009/10/10 11:36 Program Version:Version 1.3.5.0 Windows Version:Windows XP Media Center Edition SP3 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF6D79000Size: 98304File Visible: NoSigned: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7B1F000Size: 8192File Visible: NoSigned: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xF6767000Size: 49152File Visible: NoSigned: - Status: - ==EOF== _______Atach.txt_______________________ UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-09-29.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 9/19/2005 9:16:26 PM System Uptime: 10/10/2009 11:26:09 AM (0 hours ago) Motherboard: ASUSTek Computer INC. | | Amberine M Processor: AMD Athlon(tm) 64 Processor 3500+ | Socket 939 | 2200/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 223 GiB total, 52.559 GiB free. D: is FIXED (FAT32) - 8 GiB total, 0.961 GiB free. E: is CDROM () F: is CDROM () G: is Removable H: is Removable I: is Removable J: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1251: 7/11/2009 2:17:13 AM - System Checkpoint RP1252: 7/12/2009 3:04:12 AM - System Checkpoint RP1253: 7/13/2009 3:14:28 AM - System Checkpoint RP1254: 7/14/2009 3:17:53 AM - System Checkpoint RP1255: 7/15/2009 12:00:26 AM - Software Distribution Service 3.0 RP1256: 7/16/2009 12:19:56 AM - System Checkpoint RP1257: 7/16/2009 9:52:43 PM - Automatic Restore Point RP1258: 7/17/2009 10:34:34 PM - System Checkpoint RP1259: 7/19/2009 2:15:46 AM - System Checkpoint RP1260: 7/20/2009 2:25:56 AM - System Checkpoint RP1261: 7/21/2009 3:19:53 AM - System Checkpoint RP1262: 7/22/2009 12:00:15 AM - Software Distribution Service 3.0 RP1263: 7/23/2009 3:02:57 AM - System Checkpoint RP1264: 7/24/2009 3:20:56 AM - System Checkpoint RP1265: 7/25/2009 4:19:52 AM - System Checkpoint RP1266: 7/26/2009 5:19:50 AM - System Checkpoint RP1267: 7/27/2009 5:40:43 AM - System Checkpoint RP1268: 7/28/2009 6:40:42 AM - System Checkpoint RP1269: 7/29/2009 12:00:26 AM - Software Distribution Service 3.0 RP1270: 7/30/2009 12:40:10 AM - System Checkpoint RP1271: 7/31/2009 4:24:54 AM - System Checkpoint RP1272: 8/1/2009 12:00:22 AM - Software Distribution Service 3.0 RP1273: 8/2/2009 1:15:22 AM - System Checkpoint RP1274: 8/3/2009 1:22:45 AM - System Checkpoint RP1275: 8/3/2009 10:16:32 PM - Software Distribution Service 3.0 RP1276: 8/4/2009 10:35:21 PM - System Checkpoint RP1277: 8/6/2009 4:53:19 AM - System Checkpoint RP1278: 8/7/2009 5:28:57 AM - System Checkpoint RP1279: 8/8/2009 6:28:56 AM - System Checkpoint RP1280: 8/9/2009 7:28:55 AM - System Checkpoint RP1281: 8/9/2009 7:30:56 PM - Installed Power Tab Editor 1.7 RP1282: 8/10/2009 7:33:26 PM - System Checkpoint RP1283: 8/11/2009 10:55:48 PM - System Checkpoint RP1284: 8/13/2009 12:00:37 AM - Software Distribution Service 3.0 RP1285: 8/14/2009 12:00:17 AM - Software Distribution Service 3.0 RP1286: 8/15/2009 12:11:21 AM - System Checkpoint RP1287: 8/16/2009 12:48:57 AM - System Checkpoint RP1288: 8/17/2009 1:11:19 AM - System Checkpoint RP1289: 8/18/2009 4:17:03 PM - System Checkpoint RP1290: 8/19/2009 4:25:48 PM - System Checkpoint RP1291: 8/20/2009 4:30:38 PM - System Checkpoint RP1292: 8/21/2009 4:45:06 PM - System Checkpoint RP1293: 8/22/2009 11:32:56 PM - System Checkpoint RP1294: 8/24/2009 11:31:06 AM - System Checkpoint RP1295: 8/25/2009 12:08:37 PM - System Checkpoint RP1296: 8/25/2009 3:41:00 PM - Installed Microsoft Money 2006 System Pack RP1297: 8/26/2009 5:47:13 PM - System Checkpoint RP1298: 8/27/2009 12:00:22 AM - Software Distribution Service 3.0 RP1299: 8/28/2009 12:08:35 AM - System Checkpoint RP1300: 8/29/2009 1:58:37 AM - System Checkpoint RP1301: 8/30/2009 2:21:03 AM - System Checkpoint RP1302: 8/31/2009 3:21:32 AM - System Checkpoint RP1303: 9/1/2009 6:12:00 PM - System Checkpoint RP1304: 9/2/2009 10:42:15 PM - System Checkpoint RP1305: 9/8/2009 10:58:00 AM - System Checkpoint RP1306: 9/9/2009 12:00:25 AM - Software Distribution Service 3.0 RP1307: 9/10/2009 12:14:44 AM - System Checkpoint RP1308: 9/11/2009 1:28:10 AM - System Checkpoint RP1309: 9/12/2009 2:14:39 AM - System Checkpoint RP1310: 9/13/2009 3:14:39 AM - System Checkpoint RP1311: 9/14/2009 4:14:38 AM - System Checkpoint RP1312: 9/15/2009 4:58:30 AM - System Checkpoint RP1313: 9/15/2009 5:32:48 PM - Installed ProxyWay RP1314: 9/16/2009 9:36:44 PM - System Checkpoint RP1315: 9/18/2009 12:30:11 AM - System Checkpoint RP1316: 9/19/2009 11:48:43 AM - System Checkpoint RP1317: 9/20/2009 1:15:25 PM - System Checkpoint RP1318: 9/21/2009 2:42:19 PM - System Checkpoint RP1319: 9/21/2009 8:15:39 PM - Removed ProxyWay RP1320: 9/22/2009 9:37:04 PM - System Checkpoint RP1321: 9/23/2009 9:39:42 PM - System Checkpoint RP1322: 9/25/2009 12:32:59 AM - System Checkpoint RP1323: 9/26/2009 12:39:40 AM - System Checkpoint RP1324: 9/27/2009 1:39:40 AM - System Checkpoint RP1325: 9/28/2009 2:39:36 AM - System Checkpoint RP1326: 9/29/2009 3:39:35 AM - System Checkpoint RP1327: 9/30/2009 4:39:34 AM - System Checkpoint RP1328: 10/1/2009 5:05:16 AM - System Checkpoint RP1329: 10/2/2009 5:39:32 AM - System Checkpoint RP1330: 10/3/2009 6:39:31 AM - System Checkpoint RP1331: 10/4/2009 7:39:31 AM - System Checkpoint RP1332: 10/4/2009 5:54:22 PM - Installed DirectX RP1333: 10/4/2009 6:00:13 PM - Installed DirectX RP1334: 10/5/2009 6:17:40 PM - System Checkpoint RP1335: 10/6/2009 7:18:12 PM - System Checkpoint RP1336: 10/8/2009 8:50:37 PM - System Checkpoint ==== Installed Programs ====================== 2600 2600_Help 2600Trb 50 FREE MP3s +1 Free Audiobook! Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 7.0 AIM 6 AiO_Scan AiOSoftware AirPlus G ANIO Service ANIWZCS2 Service Anvil Studio AOL Toolbar 5.0 AOL Uninstaller (Choose which Products to Remove) Apple Mobile Device Support ATI Control Panel ATI Display Driver avast! Antivirus Bonjour BufferChm Call of Duty(R) 4 - Modern Warfare(TM) CCScore Centricity DICOM Viewer Cheat Engine 5.5 Compaq Connections (remove only) Compaq Game Console and games Compaq Multimedia Keyboard Software Compaq Organize Copy CP_AtenaShokunin1Config cp_dwShrek2Albums1 cp_dwShrek2Cards1 CreativeProjects CreativeProjectsTemplates Critical Update for Windows Media Player 11 (KB959772) CueTour DecX Version 2.0 Destinations Director DocProc DocumentViewer Doom 3 (TM) Demo Doom Builder Doom Builder 2.0 DOOM Collector's Edition Download Updater (AOL LLC) Easy Internet Sign-up eMusic Download Manager 4.1.3 ERUNT 1.1j ESET Online Scanner v3 ESSBrwr ESSCDBK ESScore ESSgui ESSini ESSPCD ESSPDock ESSSONIC ESSTOOLS essvatgt Fax fflink Free YouTube to Mp3 Converter version 3.2 Full Tilt Poker High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) HP Boot Optimizer HP DigitalMedia Archive HP Extended Capabilities 4.7 HP Image Zone 4.7 HP Image Zone Express HP Product Assistant HP Product Detection HP PSC & OfficeJet 4.7 HP Software Update HpSdpAppCoreApp HPSystemDiagnostics HyperCam 2 IconPackager InstantShare InterVideo WinDVD Player J2SE Runtime Environment 5.0 J2SE Runtime Environment 5.0 Update 6 Java(TM) 6 Update 13 Java(TM) 6 Update 3 Java(TM) 6 Update 5 Java(TM) 6 Update 7 KeyNote 1.6.5 kgcbaby kgcbase kgchday kgchlwn kgcinvt kgckids kgcmove kgcvday Kodak EasyShare software KSU LightScribe 1.4.31.1 Malwarebytes' Anti-Malware MarketResearch Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2006 Microsoft Money 2006 System Pack Microsoft National Language Support Downlevel APIs Microsoft Office Standard Edition 2003 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Virtual PC 2007 Microsoft VISUAL C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works Motorola SM56 Speakerphone Modem Mozilla Firefox (3.0.14) MP3 Player Utilities 5.10 MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser (KB927977) Myst III: Exile netbrdg NLOP Notifier Odamex 0.4.3 OfotoXMI OpenOffice.org 3.1 Otto PanoStandAlone Pawsoft Fass PC-Doctor 5 for Windows PC Tools Firewall Plus 5.0 PhotoGallery PokerStars Power Tab Editor 1.7 ProductContext Python 2.2 pywin32 extensions (build 203) Python 2.2.3 QFolder Readme RealPlayer Revo Uninstaller 1.83 Risen3D version 2.2.04 RollerCoaster Tycoon Deluxe Scan ScannerCopy Security Update for CAPICOM (KB931906) Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) SFR SHASTA SKIN0001 SkinsHP1 SKINXSDK Skulltag SlimDX Redistributable (March 2009) Soldat 1.4.2 Sonic Encoders Sonic Express Labeler Sonic MyDVD Plus Sonic RecordNow Audio Sonic RecordNow Copy Sonic RecordNow Data Sonic Update Manager SpywareBlaster 4.2 staticcr Styler SUPERAntiSpyware Free Edition System Requirements Lab tooltips TrayApp TuxGuitar TweetDeck UltimateBet UltraISO Premium V9.33 Uninstall 1.0.0.1 Unload Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB972636) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951618-v2) Update for Windows XP (KB951978) Update for Windows XP (KB953356) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 Video Convert Viewpoint Media Player Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 VPRINTOL Warcraft II BNE Warcraft III: All Products WebFldrs XP WebReg WebSite Downloader 1.1 What's Running 2.2 Winamp Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage v1.3.0254.0 Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live installer Windows Live Sign-in Assistant Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player Firefox Plugin Windows XP Media Center Edition 2005 KB890629 Windows XP Media Center Edition 2005 KB894553 Windows XP Media Center Edition 2005 KB895678 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WinPcap 3.1 WinRAR archiver WIRELESS Yahoo! Messenger ZDaemon (remove only) ==== Event Viewer Messages From Past Week ======== 10/9/2009 3:04:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service ImapiService with arguments "-Service" in order to run the server: {520CCA63-51A5-11D3-9144-00104BA11C5E} 10/6/2009 6:04:01 PM, error: Service Control Manager [7031] - The Media Center Receiver Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 10/6/2009 6:03:13 PM, error: HTTP [15005] - Unable to bind to the underlying transport for 0.0.0.0:2869. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number. 10/6/2009 6:03:08 PM, error: Service Control Manager [7023] - The avast! Web Scanner service terminated with the following error: An invalid argument was supplied. 10/6/2009 6:02:41 PM, error: Service Control Manager [7023] - The Windows Firewall/Internet Connection Sharing (ICS) service terminated with the following error: The system cannot find the file specified. 10/6/2009 5:57:37 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 10/6/2009 5:50:19 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AmdK8 aswSP Fips SASDIFSV SASKUTIL vmm 10/6/2009 5:50:10 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 10/6/2009 5:49:11 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 10/6/2009 5:28:14 PM, error: Service Control Manager [7024] - The Media Center Extender Service service terminated with service-specific error 2147549183 (0x8000FFFF). 10/6/2009 5:28:09 PM, error: Service Control Manager [7031] - The Media Center Extender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 10/6/2009 5:26:05 PM, error: Service Control Manager [7034] - The SeekService Service service terminated unexpectedly. It has done this 1 time(s). 10/6/2009 5:26:02 PM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s). 10/3/2009 1:02:47 AM, error: PSched [14103] - QoS [Adapter {012DDFBD-173E-40EE-AEE4-EF4EE6AE8AC0}]: The netcard driver failed the query for OID_GEN_LINK_SPEED. ==== End Of File =========================== ________DDS.txt___________ DDS (Ver_09-09-29.01) - NTFSx86 NETWORK Run by Compaq_Administrator at 11:55:04.59 on Sat 10/10/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.640 [GMT -7:00] AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B} AV: avast! antivirus 4.8.1351 [VPS 091006-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Documents and Settings\Compaq_Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser uURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aol toolbar 5.0\aoltb.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 5.0\aoltb.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto mRun: [00PCTFW] "c:\program files\pc tools firewall plus\FirewallGUI.exe" -s mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-us\local\search.html IE: Add To Compaq Organize... - c:\progra~1\hewlet~1\compaq~1\bin/module.main/favorites\ie_add_to.html IE: Add to Video Converter... - c:\program files\mp3 player utilities 5.10\aviconverter\grab.html IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: Save YouTube Video as MP3 - c:\program files\common files\dvdvideosoft\dll\IEContextMenuY.dll/scriptY2MP3.htm IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127362109437 DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149835123078 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: AtiExtEvent - Ati2evxx.dll SSODL: IconPackager Repair - {1799460C-0BC8-4865-B9DF-4A36CD703FF0} - c:\program files\stardock\object desktop\iconpackager\iprepair.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, LSA: Authentication Packages = msv1_0 nwprovau ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\p1c3jbp5.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.youtube.com/ FF - component: c:\program files\common files\dvdvideosoft\dll\ffcontextmenuy\components\FFContextMenu.dll FF - plugin: c:\program files\emusic download manager\plugin\npemusic.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows PRESENTATION foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-5-6 159600] R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2005-3-22 547744] S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-14 114768] S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-1-15 8944] S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-1-15 55024] S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-14 20560] S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-14 138680] S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] S2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [2004-8-10 14336] S2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-5-6 73840] S2 PCToolsFirewallPlus;PC Tools Firewall Plus;c:\program files\pc tools firewall plus\FWService.exe [2009-5-6 146800] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-14 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-14 352920] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512] S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-5-6 95640] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-1-15 7408] S3 XDva037;XDva037;\??\c:\windows\system32\xdva037.sys --> c:\windows\system32\XDva037.sys [?] S3 XDva167;XDva167;\??\c:\windows\system32\xdva167.sys --> c:\windows\system32\XDva167.sys [?] =============== Created Last 30 ================ 2009-10-09 16:15552a-------c:\windows\system32\d3d8caps.dat 2009-10-04 18:48--d-----c:\docume~1\compaq~1\applic~1\LimeWire 2009-09-17 16:38--d-----c:\program files\DecXv20 2009-09-17 16:37249,856--------c:\windows\Setup1.exe 2009-09-17 16:3773,216a-------c:\windows\ST6UNST.EXE ==================== Find3M ==================== 2009-09-10 14:5438,224a-------c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 14:5319,160a-------c:\windows\system32\drivers\mbam.sys 2009-08-15 19:0234a-------c:\documents and settings\compaq_administrator\jagex_runescape_preferences.dat 2009-08-06 19:24327,896a-------c:\windows\system32\dllcache\wucltui.dll 2009-08-06 19:24209,632a-------c:\windows\system32\dllcache\wuweb.dll 2009-08-06 19:2435,552a-------c:\windows\system32\dllcache\wups.dll 2009-08-06 19:2453,472a-------c:\windows\system32\dllcache\wuauclt.exe 2009-08-06 19:2496,480a-------c:\windows\system32\dllcache\cdm.dll 2009-08-06 19:23575,704a-------c:\windows\system32\dllcache\wuapi.dll 2009-08-06 19:231,929,952a-------c:\windows\system32\dllcache\wuaueng.dll 2009-08-06 19:23274,288a-------c:\windows\system32\mucltui.dll 2009-08-06 19:23215,920a-------c:\windows\system32\muweb.dll 2009-08-05 02:01204,800a-------c:\windows\system32\mswebdvd.dll 2009-08-05 02:01204,800--------c:\windows\system32\dllcache\mswebdvd.dll 2009-07-19 18:4811,067,392--------c:\windows\system32\dllcache\ieframe.dll 2009-07-19 06:185,937,152--------c:\windows\system32\dllcache\mshtml.dll 2009-07-17 12:490a-------c:\documents and settings\compaq_administrator\settings.dat 2009-07-17 12:0158,880a-------c:\windows\system32\atl.dll 2009-07-17 12:0158,880--------c:\windows\system32\dllcache\atl.dll 2009-07-13 23:4310,841,088a-------c:\windows\system32\dllcache\wmp.dll 2009-07-13 23:43286,208a-------c:\windows\system32\wmpdxm.dll 2009-07-13 23:43286,208a-------c:\windows\system32\dllcache\wmpdxm.dll 2009-05-01 09:4424,278a-------c:\docume~1\compaq~1\applic~1\wklnhst.dat 2008-12-07 00:1522,328a-------c:\docume~1\compaq~1\applic~1\PnkBstrK.sys 2008-10-04 14:40268a---h---c:\program files\sqmdata12.sqm 2008-05-03 10:2369,120a-------c:\docume~1\compaq~1\applic~1\obgargu.exe 2007-10-22 21:20251a-------c:\program files\wt3d.ini 2008-07-31 08:2632,768a--sh---c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008073120080801\index.dat ============= FINISH: 11:55:19.59 =============== Oh I think I forgot to include that I have no internet in normal mode, only in safemode.Did you run DDS in normal mode?The below instructions should be PERFORMED in normal mode. 1) Please uninstall all viewpoint products . *Go to control panel>>Add/Remove Programs.Select all viewpoint products such as viewpoint media player etc. and remove them. 2) Please uninstall Adobe Reader 7.Download the latest version from here. 3) Please download combofix from one of these webpages . http://download.bleepingcomputer.com/sUBs/ComboFix.exe http://www.forospyware.com/sUBs/ComboFix.exe * IMPORTANT !!! Save ComboFix.exe directly to your Desktop Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are performing below portion of the instructions. It's IMPORTANT to carry out the instructions in the sequence listed below. a). Close any open browsers. b). Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. (Right click on the avast icon in system tray and choose Stop On-Access Protection ) c). Open *notepad* and copy/paste the text in the quotebox below into it: Quote KillAll:: Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.Now drag CFScript.txt into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply. I will get it done when I get home today. And I ran DDS in safemode.Here you go, also I have internet in normal mode now!!!! ComboFix 09-10-12.02 - Compaq_Administrator 10/12/2009 17:15.1.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.553 [GMT -7:00] Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Compaq_Administrator\Desktop\CFScript.txt AV: avast! antivirus 4.8.1351 [VPS 091006-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B} FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52} FILE :: "c:\program files\sqmdata12.sqm" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\AVM c:\program files\sqmdata12.sqm c:\windows\Downloaded Program Files\bdcore.dll c:\windows\Downloaded Program Files\libfn.dll c:\windows\viassary-hp.reg D:\Autorun.inf . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_NWCWORKSTATION -------\Service_NWCWorkstation ((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 ))))))))))))))))))))))))))))))) . 2009-10-13 00:09 . 2009-10-13 00:09--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint 2009-10-09 23:15 . 2009-10-09 23:15552----a-w-c:\windows\system32\d3d8caps.dat 2009-10-05 01:48 . 2009-10-05 02:19--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\LimeWire 2009-09-17 23:38 . 2009-09-17 23:38--------d-----w-c:\program files\DecXv20 2009-09-17 23:37 . 2009-09-17 23:37249856------w-c:\windows\Setup1.exe 2009-09-17 23:37 . 2009-09-17 23:3773216----a-w-c:\windows\ST6UNST.EXE . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-13 00:22 . 2009-01-19 02:09--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP 2009-10-12 03:02 . 2009-06-18 01:05--------d-----w-c:\program files\Skulltag 2009-10-12 00:36 . 2009-01-18 03:08--------d-----w-c:\program files\Doom Builder 2009-10-08 01:18 . 2009-09-03 04:57--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\uTorrent 2009-10-07 01:21 . 2009-01-10 00:47--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2009-10-06 19:40 . 2009-06-06 15:58--------d-----w-c:\program files\UltimateBet 2009-10-05 00:59 . 2009-07-06 01:28--------d-----w-c:\program files\Doom Builder 2 2009-09-24 05:34 . 2009-09-05 16:56--------d-----w-c:\program files\odamex 2009-09-23 16:25 . 2006-05-19 00:15--------d-----w-c:\program files\PokerStars 2009-09-22 02:54 . 2009-04-08 04:47--------d-----w-c:\program files\eMusic Download Manager 2009-09-10 21:54 . 2009-05-31 01:5138224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 21:53 . 2009-05-31 01:5219160----a-w-c:\windows\system32\drivers\mbam.sys 2009-09-09 13:57 . 2005-09-22 03:54--------d-----w-c:\program files\Common Files\AOL 2009-09-09 07:10 . 2009-06-14 04:04--------d-----w-c:\program files\Microsoft Silverlight 2009-09-09 04:16 . 2005-09-22 03:55--------d-----w-c:\documents and settings\All Users\Application Data\AOL 2009-09-08 16:29 . 2009-09-07 17:28--------d-----w-c:\program files\AOL 9.0 2009-09-07 17:31 . 2005-09-22 03:56--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\AOL 2009-09-07 17:30 . 2009-09-07 17:28--------d-----w-c:\program files\Common Files\aolshare 2009-09-07 17:30 . 2005-09-22 03:56--------d-----w-c:\program files\Common Files\Nullsoft 2009-09-07 17:24 . 2006-05-14 03:58--------d-----w-c:\documents and settings\All Users\Application Data\AOL Downloads 2009-08-30 15:04 . 2009-08-30 15:04--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\PokerCreations 2009-08-30 14:47 . 2009-08-30 14:47--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\NLOP 2009-08-30 14:47 . 2009-08-30 14:47--------d-----w-c:\program files\NLOP 2009-08-25 22:47 . 2009-08-25 22:41--------d-----w-c:\program files\Microsoft Money 2006 2009-08-25 13:42 . 2005-10-14 03:2162864----a-w-c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-08-17 16:10 . 2009-06-14 22:321279456----a-w-c:\windows\system32\aswBoot.exe 2009-08-17 16:06 . 2009-06-14 22:3393392----a-w-c:\windows\system32\drivers\aswmon.sys 2009-08-17 16:06 . 2009-06-14 22:3394160----a-w-c:\windows\system32\drivers\aswmon2.sys 2009-08-17 16:05 . 2009-06-14 22:33114768----a-w-c:\windows\system32\drivers\aswSP.sys 2009-08-17 16:05 . 2009-06-14 22:3320560----a-w-c:\windows\system32\drivers\aswFsBlk.sys 2009-08-17 16:04 . 2009-06-14 22:3351376----a-w-c:\windows\system32\drivers\aswTdi.sys 2009-08-17 16:04 . 2009-06-14 22:3323152----a-w-c:\windows\system32\drivers\aswRdr.sys 2009-08-17 16:03 . 2009-06-14 22:3326944----a-w-c:\windows\system32\drivers\aavmker4.sys 2009-08-17 16:02 . 2009-06-14 22:3397480----a-w-c:\windows\system32\AvastSS.scr 2009-08-16 02:02 . 2008-07-03 06:1434----a-w-c:\documents and settings\Compaq_Administrator\jagex_runescape_preferences.dat 2009-08-07 02:24 . 2004-08-10 19:00327896----a-w-c:\windows\system32\wucltui.dll 2009-08-07 02:24 . 2004-08-10 19:00209632----a-w-c:\windows\system32\wuweb.dll 2009-08-07 02:24 . 2005-09-22 04:0944768----a-w-c:\windows\system32\wups2.dll 2009-08-07 02:24 . 2004-08-10 19:0035552----a-w-c:\windows\system32\wups.dll 2009-08-07 02:24 . 2004-08-10 19:0053472----a-w-c:\windows\system32\wuauclt.exe 2009-08-07 02:24 . 2004-08-10 19:0096480----a-w-c:\windows\system32\cdm.dll 2009-08-07 02:23 . 2004-08-10 19:00575704----a-w-c:\windows\system32\wuapi.dll 2009-08-07 02:23 . 2006-06-09 23:24274288----a-w-c:\windows\system32\mucltui.dll 2009-08-07 02:23 . 2005-05-26 11:19215920----a-w-c:\windows\system32\muweb.dll 2009-08-07 02:23 . 2004-08-10 19:001929952----a-w-c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2004-08-10 19:00204800----a-w-c:\windows\system32\mswebdvd.dll 2009-07-17 19:49 . 2009-07-17 19:490----a-w-c:\documents and settings\Compaq_Administrator\settings.dat 2009-07-17 19:01 . 2004-08-10 19:0058880----a-w-c:\windows\system32\atl.dll 2009-07-15 07:00 . 2009-07-15 07:00229208----a-w-c:\windows\system32\drivers\VMM.sys 2007-10-23 04:20 . 2007-10-23 04:20251----a-w-c:\program files\wt3d.ini . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication PackagesREG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk backup=c:\windows\pss\Compaq Connections.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk] path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^Styler.lnk] path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\Styler.lnk backup=c:\windows\pss\Styler.lnkStartup [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"= "c:\\WINDOWS\\system32\\fxsclnt.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Microsoft Plus! Photo Story 2 LE\\PS2Trial.exe"= "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"= "c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"= "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"= "c:\\Program Files\\Warcraft II BNE\\Warcraft II BNE.exe"= "c:\\Soldat\\Soldat.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Skulltag\\Skulltag.exe"= "c:\\Program Files\\Skulltag\\Idese.exe"= "c:\\Program Files\\Skulltag\\Rcon_Utility.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "67:UDP"= 67:UDP:DHCP Discovery Service "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/14/2009 3:33 PM 114768] R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [5/6/2009 9:37 PM 159600] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 5:17 PM 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 5:17 PM 55024] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2009 3:33 PM 20560] R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [8/10/2004 12:00 PM 14336] R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [5/6/2009 9:37 PM 73840] R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [3/22/2005 7:17 PM 547744] R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [5/6/2009 9:36 PM 95640] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 2:10 PM 32512] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 5:17 PM 7408] S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?] S3 XDva167;XDva167;\??\c:\windows\system32\XDva167.sys --> c:\windows\system32\XDva167.sys [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-10-01 c:\windows\Tasks\HPCeeSchedule.job - c:\progra~1\EASYIN~1\Ceement\HPCEE.exe [2005-05-24 23:46] . . ------- SUPPLEMENTARY Scan ------- . uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html IE: Add To Compaq Organize... - c:\progra~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html IE: Add to Video Converter... - c:\program files\MP3 Player Utilities 5.10\AVIConverter\grab.html IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\p1c3jbp5.default\ FF - component: c:\program files\Common Files\DVDVideoSoft\Dll\FFContextMenuY\components\FFContextMenu.dll FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - AddRemove-Centricity DICOM Viewer - c:\program files\Centricity\DICOM Viewer\3.1.1\EN-US\setupw2k ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-12 17:22 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-3802107105-356159331-2220808391-1008\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1736) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3376) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\program files\Stardock\Object Desktop\IconPackager\iprepair.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Microsoft Virtual PC\VPCShExH.DLL c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\windows\system32\ati2evxx.exe c:\program files\Common Files\AOL\acs\AOLacsd.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\ehome\ehrecvr.exe c:\windows\ehome\ehSched.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\PC Tools Firewall Plus\FWService.exe c:\windows\system32\HPZipm12.exe c:\windows\system32\PnkBstrA.exe c:\windows\system32\PnkBstrB.exe c:\windows\ehome\mcrdsvc.exe c:\program files\Alwil Software\Avast4\ashMaiSv.exe c:\program files\Alwil Software\Avast4\ashWebSv.exe c:\windows\system32\dllhost.exe c:\windows\system32\wscntfy.exe c:\program files\Alwil Software\Avast4\Setup\avast.setup . ************************************************************************** . Completion time: 2009-10-13 17:26 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-13 00:26 Pre-Run: 55,247,224,832 bytes free Post-Run: 55,081,291,776 bytes free 256--- E O F ---2009-09-09 07:04 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:28:34 PM, on 10/12/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\PC Tools Firewall Plus\FWService.exe C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\PnkBstrA.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html O8 - Extra context menu item: Add to Video Converter... - C:\Program Files\MP3 Player Utilities 5.10\AVIConverter\grab.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Save YouTube Video as MP3 - res://C:\Program Files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/srl_bin/sysreqlab_srl.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1127362109437 O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1149835123078 O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} (YYGInstantPlay Control) - http://www.yoyogames.com/downloads/activex/YoYo.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe -- End of file - 8313 bytes Never mind, I cannot get Firefox or IE to work in normal mode.1) Please copy this page to *Notepad* and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. It's IMPORTANT to carry out the instructions in the sequence listed below. a) Close any open browsers. b) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Open *notepad* and copy/paste the text in the quotebox below into it: Quote file:: Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.Now drag CFScript.txt into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt Please copy and paste the ComboFix.txt in your next reply. 2) Please upload these files to virustotal (one by one ) and post the results in your next reply. c:\windows\system32\XDva037.sys c:\windows\system32\XDva167.sysHere is my new log. The two file could not be found. ComboFix 09-10-13.01 - Compaq_Administrator 10/13/2009 16:58.2.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.573 [GMT -7:00] Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Compaq_Administrator\Desktop\CFScript.txt AV: avast! antivirus 4.8.1351 [VPS 091013-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: COMODO Antivirus *On-access scanning enabled* (Updated) {043803A5-4F86-4ef7-AFC5-F6E02A79969B} FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52} FILE :: "c:\documents and settings\All Users\Application Data\Viewpoint" . ((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 ))))))))))))))))))))))))))))))) . 2009-10-13 00:32 . 2009-10-13 00:32--------d-----w-c:\program files\Common Files\Adobe 2009-10-13 00:30 . 2009-10-13 04:01--------d-----w-c:\documents and settings\All Users\Application Data\NOS 2009-10-13 00:09 . 2009-10-13 00:09--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint 2009-10-09 23:15 . 2009-10-09 23:15552----a-w-c:\windows\system32\d3d8caps.dat 2009-10-05 01:48 . 2009-10-05 02:19--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\LimeWire 2009-09-17 23:38 . 2009-09-17 23:38--------d-----w-c:\program files\DecXv20 2009-09-17 23:37 . 2009-09-17 23:37249856------w-c:\windows\Setup1.exe 2009-09-17 23:37 . 2009-09-17 23:3773216----a-w-c:\windows\ST6UNST.EXE . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-13 23:50 . 2009-01-19 02:09--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP 2009-10-13 23:32 . 2009-01-18 03:08--------d-----w-c:\program files\Doom Builder 2009-10-13 16:30 . 2009-06-06 15:58--------d-----w-c:\program files\UltimateBet 2009-10-13 14:07 . 2009-06-18 01:05--------d-----w-c:\program files\Skulltag 2009-10-08 01:18 . 2009-09-03 04:57--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\uTorrent 2009-10-07 01:21 . 2009-01-10 00:47--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2009-10-05 00:59 . 2009-07-06 01:28--------d-----w-c:\program files\Doom Builder 2 2009-09-24 05:34 . 2009-09-05 16:56--------d-----w-c:\program files\odamex 2009-09-23 16:25 . 2006-05-19 00:15--------d-----w-c:\program files\PokerStars 2009-09-22 02:54 . 2009-04-08 04:47--------d-----w-c:\program files\eMusic Download Manager 2009-09-10 21:54 . 2009-05-31 01:5138224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-10 21:53 . 2009-05-31 01:5219160----a-w-c:\windows\system32\drivers\mbam.sys 2009-09-09 13:57 . 2005-09-22 03:54--------d-----w-c:\program files\Common Files\AOL 2009-09-09 07:10 . 2009-06-14 04:04--------d-----w-c:\program files\Microsoft Silverlight 2009-09-09 04:16 . 2005-09-22 03:55--------d-----w-c:\documents and settings\All Users\Application Data\AOL 2009-09-08 16:29 . 2009-09-07 17:28--------d-----w-c:\program files\AOL 9.0 2009-09-07 17:31 . 2005-09-22 03:56--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\AOL 2009-09-07 17:30 . 2009-09-07 17:28--------d-----w-c:\program files\Common Files\aolshare 2009-09-07 17:30 . 2005-09-22 03:56--------d-----w-c:\program files\Common Files\Nullsoft 2009-09-07 17:24 . 2006-05-14 03:58--------d-----w-c:\documents and settings\All Users\Application Data\AOL Downloads 2009-08-30 15:04 . 2009-08-30 15:04--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\PokerCreations 2009-08-30 14:47 . 2009-08-30 14:47--------d-----w-c:\documents and settings\Compaq_Administrator\Application Data\NLOP 2009-08-30 14:47 . 2009-08-30 14:47--------d-----w-c:\program files\NLOP 2009-08-25 22:47 . 2009-08-25 22:41--------d-----w-c:\program files\Microsoft Money 2006 2009-08-25 13:42 . 2005-10-14 03:2162864----a-w-c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-08-17 16:10 . 2009-06-14 22:321279456----a-w-c:\windows\system32\aswBoot.exe 2009-08-17 16:06 . 2009-06-14 22:3393392----a-w-c:\windows\system32\drivers\aswmon.sys 2009-08-17 16:06 . 2009-06-14 22:3394160----a-w-c:\windows\system32\drivers\aswmon2.sys 2009-08-17 16:05 . 2009-06-14 22:33114768----a-w-c:\windows\system32\drivers\aswSP.sys 2009-08-17 16:05 . 2009-06-14 22:3320560----a-w-c:\windows\system32\drivers\aswFsBlk.sys 2009-08-17 16:04 . 2009-06-14 22:3351376----a-w-c:\windows\system32\drivers\aswTdi.sys 2009-08-17 16:04 . 2009-06-14 22:3323152----a-w-c:\windows\system32\drivers\aswRdr.sys 2009-08-17 16:03 . 2009-06-14 22:3326944----a-w-c:\windows\system32\drivers\aavmker4.sys 2009-08-17 16:02 . 2009-06-14 22:3397480----a-w-c:\windows\system32\AvastSS.scr 2009-08-16 02:02 . 2008-07-03 06:1434----a-w-c:\documents and settings\Compaq_Administrator\jagex_runescape_preferences.dat 2009-08-07 02:24 . 2004-08-10 19:00327896----a-w-c:\windows\system32\wucltui.dll 2009-08-07 02:24 . 2004-08-10 19:00209632----a-w-c:\windows\system32\wuweb.dll 2009-08-07 02:24 . 2005-09-22 04:0944768----a-w-c:\windows\system32\wups2.dll 2009-08-07 02:24 . 2004-08-10 19:0035552----a-w-c:\windows\system32\wups.dll 2009-08-07 02:24 . 2004-08-10 19:0053472------w-c:\windows\system32\wuauclt.exe 2009-08-07 02:24 . 2004-08-10 19:0096480----a-w-c:\windows\system32\cdm.dll 2009-08-07 02:23 . 2004-08-10 19:00575704----a-w-c:\windows\system32\wuapi.dll 2009-08-07 02:23 . 2006-06-09 23:24274288----a-w-c:\windows\system32\mucltui.dll 2009-08-07 02:23 . 2005-05-26 11:19215920----a-w-c:\windows\system32\muweb.dll 2009-08-07 02:23 . 2004-08-10 19:001929952----a-w-c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2004-08-10 19:00204800----a-w-c:\windows\system32\mswebdvd.dll 2009-07-17 19:49 . 2009-07-17 19:490----a-w-c:\documents and settings\Compaq_Administrator\settings.dat 2009-07-17 19:01 . 2004-08-10 19:0058880----a-w-c:\windows\system32\atl.dll 2007-10-23 04:20 . 2007-10-23 04:20251----a-w-c:\program files\wt3d.ini . ((((((((((((((((((((((((((((( [emailprotected]_00.22.39 ))))))))))))))))))))))))))))))))))))))))) . + 2009-10-13 23:50 . 2009-10-13 23:5016384 c:\windows\Temp\Perflib_Perfdata_390.dat + 2005-06-07 06:55 . 2009-10-13 23:5572652 c:\windows\system32\perfc009.dat + 2009-10-13 00:30 . 2009-10-13 00:3020480 c:\windows\Installer\84803.msi + 2005-06-07 06:55 . 2009-10-13 23:55444472 c:\windows\system32\perfh009.dat + 2009-10-13 00:33 . 2009-10-13 00:333938816 c:\windows\Installer\84809.msi . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AOL Fast Start"="c:\program files\AOL 9.0\AOL.EXE" [2007-04-18 50736] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication PackagesREG_MULTI_SZ msv1_0 nwprovau [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk backup=c:\windows\pss\Compaq Connections.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk] path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup [HKLM\~\startupfolder\C:^Documents and Settings^Compaq_Administrator^Start Menu^Programs^Startup^Styler.lnk] path=c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\Styler.lnk backup=c:\windows\pss\Styler.lnkStartup [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"= "c:\\WINDOWS\\system32\\fxsclnt.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Microsoft Plus! Photo Story 2 LE\\PS2Trial.exe"= "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"= "c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"= "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"= "c:\\Program Files\\Warcraft II BNE\\Warcraft II BNE.exe"= "c:\\Soldat\\Soldat.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Skulltag\\Skulltag.exe"= "c:\\Program Files\\Skulltag\\Idese.exe"= "c:\\Program Files\\Skulltag\\Rcon_Utility.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "67:UDP"= 67:UDP:DHCP Discovery Service "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/14/2009 3:33 PM 114768] R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [5/6/2009 9:37 PM 159600] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 5:17 PM 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 5:17 PM 55024] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2009 3:33 PM 20560] R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [8/10/2004 12:00 PM 14336] R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [5/6/2009 9:37 PM 73840] R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [3/22/2005 7:17 PM 547744] R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [5/6/2009 9:36 PM 95640] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 2:10 PM 32512] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 5:17 PM 7408] S3 XDva037;XDva037;\??\c:\windows\system32\XDva037.sys --> c:\windows\system32\XDva037.sys [?] S3 XDva167;XDva167;\??\c:\windows\system32\XDva167.sys --> c:\windows\system32\XDva167.sys [?] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-10-01 c:\windows\Tasks\HPCeeSchedule.job - c:\progra~1\EASYIN~1\Ceement\HPCEE.exe [2005-05-24 23:46] . . ------- Supplementary Scan ------- . uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = iexplore uSearchURL,(Default) = hxxp://www.google.com/keyword/%s DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\p1c3jbp5.default\ FF - component: c:\program files\Common Files\DVDVideoSoft\Dll\FFContextMenuY\components\FFContextMenu.dll FF - plugin: c:\program files\eMusic Download Manager\plugin\npemusic.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - Toolbar-Locked - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-13 17:04 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-3802107105-356159331-2220808391-1008\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1732) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2136) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\program files\Stardock\Object Desktop\IconPackager\iprepair.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Microsoft Virtual PC\VPCShExH.DLL c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2009-10-14 17:06 ComboFix-quarantined-files.txt 2009-10-14 00:06 ComboFix2.txt 2009-10-13 00:26 Pre-Run: 54,755,573,760 bytes free Post-Run: 54,760,435,712 bytes free 222--- E O F ---2009-09-09 07:04 Things are running great right now, I have full connection with Firefox in normal mode.1) Please manually delete this file c:\documents and settings\All Users\Application Data\Viewpoint 2) * Right-Click My Computer choose Explore, click on Tools, Folder Options. * Click the View tab. * Place a tick next to Display content of System folders, (answer OK to warnings) * Under Hidden files and folders, click Show hidden files and folders. * If you see a warning message, click Yes. * Click Apply. * Click OK. Now please upload these files to virustotal and post the results in your next reply. c:\windows\system32\XDva037.sys c:\windows\system32\XDva167.sys |
|
| 1755. |
Solve : spyware.ietoolbar? |
|
Answer» Hi there |
|
| 1756. |
Solve : Unable to access Windows Normal Mode? |
|
Answer» My brothers computer has started to screw around [again] and, this time, I'm unable to do anything about it. |
|
| 1757. |
Solve : a new virus ?? |
|
Answer» If SOMETHING is corrupted in this profile a new ONE will normally fix it. To create a new user profileOk, I TRIED a new profile and it didn't fix anything.I'm out of ideas. |
|
| 1758. |
Solve : Bad Image error on laptop? |
|
Answer» On my laptop I am receiving several pop-up boxes when I try to log on that have different title messages but the same error message within the pop-up. |
|
| 1759. |
Solve : Problem still ongoing - Malware infection Unknown type NEW INFORMATION Post#13? |
|
Answer» Have done so with REGARDS to Avira. I hope SOMEONE else can help me with my other problem. As I said, the slow down seems to start only be after I open the internet and start to browse but when it does, it effectively SLOWS down the whole netbook, not just the internet browser. http://www.avg.com/gb-en/download-tools |
|
| 1760. |
Solve : key board shortcuts are automatically invoking? |
|
Answer» actually i asked the reply FRM the remaining people.Not for you Mr.Allan.If u think wrong i m sorry. |
|
| 1761. |
Solve : Please check rist log/new logs? |
|
Answer» The BSOD I get is 0x0000007f
I don't have the CD for THIS computer, and since its XP Pro I don't think my disk which is XP Home will work. My disk is an OEM disk. It looks like the dysfunctional computer had XP Home on it at 1 time since it shows in the load menu but it was overwritten by Pro.Do you think The I386 file/folder from the Home CD will work for Pro?No they are different operating systems. Did you put a space between the sfc and /scannow ??Yes, TYPED it exactly sa shown, sfc /scannow, space between sfc and /scannow. I wonder if it has anything to do with the administrator prmissions thing that I didn't set. I get a warning when I try to install SAS.Please do the following: 1. Download this diagnostics tool MGADiag.exe and save this to your Desktop. 2. Double-click on MGADiag.exe and click Continue 3. When the PROGRAM has finished, click on Copy 4. Post the results in your next reply.I think I have discovered the main problem and I will not be fixing it without the original disk. IF I had had the MGADiag program I probably wouldn't have touched this system. Diagnostic Report (1.9.0011.0): ----------------------------------------- WGA Data--> Validation Status: Invalid Product Key Validation Code: 8 Cached Validation Code: N/A Windows Product Key: Windows Product Key Hash: Windows Product ID: Windows Product ID Type: 1 Windows License Type: Volume Windows OS version: 5.1.2600.2.00010100.3.0.pro ID: {08586C5A-82AE-407A-B371-1FF763D70C4E}(1) Is Admin: Yes TestCab: 0x0 WGA Version: N/A, hr = 0x80070002 Signed By: N/A, hr = 0x80070002 Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005 Resolution Status: N/A WgaER Data--> ThreatID(s): N/A Version: N/A WGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data--> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data--> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-230-1 Browser Data--> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Allowed Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data--> Other data--> Office Details: {08586C5A-82AE-407A-B371-1FF763D70C4E}1.9.0011.05.1.2600.2.00010100.3.0.prox32*****-*****-*****-*****-TY9F355274-640-4940936-234921S-1-5-21-448539723-602162358-725345543Dell Computer CorporationDimension 4600i Dell Computer CorporationA1220040826000000.000000+000B1DC39E70184805304090409Central Standard Time(GMT-06:00)03109 LICENSING Data--> N/A HWID Data--> N/A OEM Activation 1.0 Data--> BIOS string matches: yes Marker string from BIOS: 1B1D1:Dell Inc|1B1D1:Microsoft Corporation Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005 OEM Activation 2.0 Data--> N/A Quote WGA Data--> Yes Microsoft has made it very hard for people to use Windows when it isn't registered. Contact Microsoft and they will work with you in getting a valid key. Since you got it from work it might end up costing very little or maybe even nothing. 1-866-PCSAFETY (1-866-727-2338). This phone number is for virus and other security-related support. It is available 24 hours a day for the U.S. and Canada. If you have valid, licensed software, then you need to go to the Windows Genuine Forum, register and post the log at Speak to us at Microsoft! If necessary, copy the original log or provide a link to this thread. In the event you are a victim of piracy, help is available from this site: PROTECT Yourself from PiracyThanks EF. I will contact them and see what they say.Did you do the XP Pro upgrade? Where did the license key come from? You might have to get the original product key and/or the computer serial number and use an XP Home CD to reformat and then reinstall XP Home. This page will help you find the COA. http://www.microsoft.com/howtotell/content.aspx?pg=coa&displaylang=en. EF I did not do the upgrade and don't know where the key came from. The machine belongs to my neighbor and I told her I would see what I could do about removing the viruses. I will find out who did the upgrade and where the key came from, possibly they have the original disk. The original HOME key is on the side of the computer case since its a Dell but I don't believe the owner has the original disks. I have MY retail disk that goes to my machine but thats all.If the disks are the same then it will work. XP Home or XP Pro. But you need to use whatever key belongs to the OS. Home or Pro. |
|
| 1762. |
Solve : Infected Computer According to Broni? |
|
Answer» It may not be compatible with 64 bit so didn't actually INSTALL. http://www.viewpoint.com/technologies/viewpoint-media-player.shtml#system-requirements
|
|
| 1763. |
Solve : Help get all of "security tool" from computer.? |
|
Answer» Yesterday I saw the yellow shield in the bottom corner telling me updates for Windows were available. So, before bed I clicked install updates and shut down. After it became apparent something was wrong I searched for solutions and finally USED Malwarebytes' AntiMalware-which seemed to fix everything. But, I'm on here because there's still a red shield in the corner of my screen that I don't think should be there. When I move my mouse over the shield it reads "Windows security alerts." Other then that being there everything seems to be WORKING great. These are my logs:
---------- Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the desktop. ---------- If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: DDS:: TB: {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File uRun: [msctrlp.exe] c:\documents and settings\sharyn\application data\msa\msctrlp.exe Folder:: c:\documents and settings\sharyn\application data\msa 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in CASE it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeI could not remove •Java 2 Runtime Environment, SE v1.4.2_03. I get messages saying SOMETHINGS not available. I tried to attached a screen shot of the dialogue boxes but the files were too big. The other two removed no problem. I did the messenger thing and have downloaded Combofix with running.Delete An Uninstall Entry
[Saving space, attachment deleted by admin]Is there a reason you aren't running an antivirus?I had McAfee when I got the computer but let it expire. Actually, when this started it was the biggest problem I've ever had. Couldn't use control panel and stuff like that. To answer your question-I don't have a specific reason. If you would like to recommend one I'll take your advice. Download the McAfee Consumer Product Removal Tool to your Desktop. Using McAfee Consumer Product Removal tool: * Double click the MCPR.exe * A Command Line window will be displayed, and then close automatically. * Wait for a second Command Line window to be displayed. Note: Do not double-click MCPR.exe again, you may have to wait up to 1 minute for the next window to appear. * After the second window appears, the program will begin the cleanup. * Observe the installation, which could take several minutes. The following message will be displayed in the Command Line window: The machine must reboot to complete the un-installation. Reboot now? [y.n] * Press Y on the keyboard. * Wait for the computer to restart. * All McAfee products are now removed from your computer. ---------- All of these are free for life and both very reliable. Remember to only install one antivirus! 1) Avast! Home Edition 2) AVG Free Edition 3) Avira AntiVir Personal If you want a good free firewall. 1) Comodo (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any Ask.com options if you choose this one) 2) Online Armor 3) Sunbelt/Kerio ---------- Let me know when you get that done. . |
|
| 1764. |
Solve : W32.Jeefo? |
|
Answer» Hi. Will it automatically look at ALL of the drives ?You can select the drive you want to scan by going to Advance Settings, Under scan targets, select Change and select the drive you want to scan. Your Avira should be disabled during the scan. Don't forget to re-enable it afterwards.ESET Online Scan Log File Results : [emailprotected] as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=41c60b2222d87546a6fbc2722440c753 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-09-20 10:13:01 # local_time=2010-09-20 11:13:01 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service PACK 3 # compatibility_mode=512 16777215 100 0 466316 466316 0 0 # compatibility_mode=1797 16775141 100 94 221262 57615206 82556 0 # compatibility_mode=8192 67108863 100 0 85959 85959 0 0 # scanned=1299649 # found=0 # cleaned=0 # scan_time=16890If there are no other issues, we can do some CLEANUP. * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ******************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ********************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO REPLACEMENT for a dedicated software solution. Remember to use only one firewall at the same time. ********************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in SPYBOT - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Hi Thank you for your on-going help. I have removed ComboFix and run TFC. Do you think my computer is clear of the Virus/Trojan now? Was it a RootKit and had it blocked Avira's ability to update itself? Should I be using a software Firewall ? I was under the impression that the modem/router that my ISP provided offered sufficient shielding. Perhaps this incident shows that that is not so.There was no evidence of that infection that you referred to in your opening thread. I would say that your computer is clean. I don't wish to discuss any more about these scans because hackers and malware writers also visit these site and we don't want to give them any help with their evil exploits. As for the firewalls; I'm not sure how effective your router firewall is but a third-party would probably be better. It will annoying at first until the firewall learns your routine but after a bit you'll not even know it's there. Thank you very VERY much for all of your help.You're welcome. Resolved. I will lock this topic. If you need more help, please start a new thread or pm me to unlock this thread. |
|
| 1765. |
Solve : Intemap mephisrnet explorer?? |
|
Answer» Lots of problems... |
|
| 1766. |
Solve : help with, i think a tojan? |
|
Answer» ok i cant connect to the internet and i got this message when i try to start up explorer, somethign msg.121.cpy.dll, so i looked on the internet and tried to fix it it says its sometihng from spyware or something well i dont understand how to fix it so can SOMEONE here PLEASE tell me how to do it, thank you so muchHi NoHate,try running Ad-Aware to detect this,also try PANDA software's free ONLINE scan.This seems to catch most Trojans & viruses.thanks, but i'v got it already.www.trojanscan.com try Spy-Sweeper |
|
| 1767. |
Solve : Re: manipulatingtheicesurface.com? |
|
Answer» help me ....Are all the utility programs you listed up to date with the latest updates ......for example are you running Ad-Aware Ver 6 build 181 .....Go to Symantec site... http://www.symantec.com/index.htm go to the Download part and select security check ......run both |
|
| 1768. |
Solve : Need to remove Searchbar? |
|
Answer» Hi, |
|
| 1769. |
Solve : Re: My computer restarts for no reason!? |
|
Answer» its the sasser WORM its a product of the m$blaster worm TRY this >http://vil.nai.com/vil/stinger/ more info here>http://www.microsoft.com/security/incident/sasser.aspHi .....GO to http://securityresponse.symantec.com/avcenter/tools.list.html this tool will get rid of the Sasser........you may have to use another computer to get this tool as yours will keep shutting down......Download it to a disk and the install it in your computer.....It works ....I had to do that for a friend YESTERDAY .. |
|
| 1770. |
Solve : help! AIM virus. weird away message !!? |
|
Answer» please help me?!!? I have this AIM virus and what it does is that it pops up a away message saying that |
|
| 1771. |
Solve : HELP!! anyone who can look at a hijackthis l? |
|
Answer» OK, got big trouble w/ menu's and homepages that I had nothing to do with getting on my computer. Can anyone look at a hijackthis log and tell me what the problem(s) are? I can't seem to get the file on this post, so if someone could tell me how, or give me an email ADDRESS and I will send it to them. Thank you very much for your time! This easy-to-use Windows application uninstaller makes your computer run more efficiently by removing software and files that were left behind after you uninstalled software that you no longer use. In addition, the program performs a number of cleanup activities, making your computer more secureOK, here goes: Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\BearShare\BearShare.exe C:\Program Files\ICQLite\ICQLite.exe C:\Program Files\WindowsSA\omniscient.exe C:\WINDOWS\System32\golum\services.exe C:\Program Files\BearShare\BearShare.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\System32\ScsiAccess.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\dhsvr.exe C:\Documents and Settings\Ruben\herovan.exe C:\Documents and Settings\Ruben\xxx.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Ruben\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://nkvd.us (obfuscated) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://nkvd.us (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://nkvd.us (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearch.biz R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://nkvd.us (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window TITLE = Microsoft Internet Explorer provided by Comcast High-Speed Internet R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q= R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.ne2.attbb.net R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.emachines.com/ R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://nkvd.us (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://nkvd.us (obfuscated) R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310}_ - (no file) R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file) R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,And Part 2: O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: (no name) - {30AF3328-E212-7ABC-8254-625579AE2D42} - C:\WINDOWS\System32\twqx.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5FB16413-03EE-4479-B39A-F641C51CCADB} - C:\WINDOWS\System32\iciddeo.dll (file missing) O2 - BHO: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\Program Files\TV Media\TvmBho.dll O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll (file missing) O2 - BHO: (no name) - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll O2 - BHO: (no name) - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - C:\WINDOWS\dealhlpr.dll O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll O2 - BHO: (no name) - {FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} - C:\WINDOWS\System32\mshelper.dll (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe O4 - HKLM\..\Run: [VTPreset] VTPreset.exe O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [vprzejmoqk] C:\WINDOWS\System32\whkdkct.exe O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe O4 - HKLM\..\Run: [Golum] C:\WINDOWS\System32\golum\services.exe O4 - HKLM\..\Run: [conscorr] C:\WINDOWS\conscorr.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe O4 - HKCU\..\Run: [Usrr] C:\Documents and Settings\Ruben\Application Data\rncr.exe O4 - HKCU\..\Run: [Nskutd] C:\WINDOWS\System32\egiah.exe O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -traybootAnd now Part 3: O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe O9 - Extra button: ICQ (HKLM) O9 - Extra 'Tools' menuitem: ICQ (HKLM) O9 - Extra button: Crazy Vegas Poker (HKLM) O9 - Extra button: AIM (HKLM) O9 - Extra button: PartyPoker.com (HKLM) O9 - Extra 'Tools' menuitem: PartyPoker.com (HKLM) O9 - Extra button: ICQ 4.1 (HKLM) O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net O15 - Trusted Zone: *.windupdates.com O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=230270dab455d0e176941480ba0fc85f2978d245429f93809c10f10b815c8a96c9ba5c54063f7603d4945ab86ee97ff22322f046:375a82d108ec2e9d584f880889783bc3 O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio CONFERENCING) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38028.8065509259 O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_225/webolr/OCX/FlashAX.cab O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab And what kind of problems are you experiencing even after using Adaware SE, Spybot S&D and removing the plugins/toolbars with Advanced Uninstaller Pro 2004?Okay, I get pop-up windows that lead to search engine sites (for example, search200.com) and porn sites, and they download desktop Icons to my computer. I have found .exe files in my C:\Documents and Settings folder (herovan and xxx) and have deleted them, but return time and time again. I now have Ad-aware and Spyware Guard on my computer, as well as Norton AV and Spywareblaster. Again, thank you very much for your time!I suggest you properly configure Adaware SE and allow it to BOOT at Windows start up. This will allow it to remove things it may not have been able to whilst normally running the program.Ok, I tried all that, and was STILL having problems However, I just installed Spyguard and Sygate PF and now don't seem to have any more troubles I'll update you in a couple of days and see what happens. Thanks again for your time and kudos to the best computer forum on the internet! You uninstalled your personal Firewall and now the pop ups stopped? What kind of popups were you referring to? Ones that required access or ads? you need to ditch bearshare one of the main causes?p2p imho>you need these>http://www.thespykiller.co.uk/ shredder http://vil.nai.com/vil/stinger/ trojan killer http://www.webroot.com spysweeper..and thats it...and disable system restore to run these programs...ok |
|
| 1772. |
Solve : randomly rebooting virus? |
|
Answer» hey guys. I am having a PROBLEM with a virus of some sort. My comp is randomly rebooting, sometimes i'm online and sometimes it's just on the desktop with the screen saver on. Aslo it randomly freezes to a blank white screen with vertical lines. When it does this I have to reboot it and then it works fine for a little while. I've tried updating all the windows 2000 updates and everything and running Norton. When I did that Norton said I had a worm in msegri32.exe. I don't know if that's a FILE or what but I tried deleting it and it supposedly did, however I found it again when i was searching for it. I don't know how else to get it to stop. Do any of you techies have any ideas? I have the installation disk but if I reintall it will I lose all the other stuff on Windows? Thanx |
|
| 1773. |
Solve : computer being used to spam email to other people? |
|
Answer» my computer is being used to spam email to other people. Please help!Please Read This First - Viruses & Spyware
You should run both Virus and Adware scanner to remove any objects that allow other people to connect to your PC and install the Firewall to stop them from doing so now and in the future. Read these security and Internet related articles to learn more: How Stuff Works - Security Channel How Stuff Works - Internet Channel Gibson Research CorporationWhat kind of spam is it GENERATING? Are they viral? Most viruses now replicate and SPOOF the sender's address in the process, so that the emails appear to be coming from friends. If this is the case, you may not be the infected one (I'm NOT saying you shouldn't still scan and verify either way), but someone who has you on their contact list may be infected. It's worth a try to send out a quick email to warn your friends to MAKE sure they have updated antivirus installed and have performed a full system scan. This is always a GOOD warning. |
|
| 1774. |
Solve : mcsmss.exe? |
|
Answer» Can anyone tell me what this is? mcsmss.exe?WEB.......are you certain about .... mcsmss.exe ? I use AVG for my virus protection. Can you suggest a better one. I thought it was ICQ because it was the only program that I have down loaded. I also have a trojan in a system volume folder that I cannot get into. I have tried to get into it through safe mode but it will not allow me. AVG does not seem to clean this one out! Install a Firewall. Virus scanners donot prevent trojans, they find and/or remove them. As for AVG, I have no experience with that program. I user Kaspersky Anti-Virus Personal and I must say I am quite pleased with it.I have experience with AVG and think that it's an EXCELLENT free anti-virus programme. Like all virus scanners you need to download updates regularlyIf it's detecting the trojan in System Volume Information, you can simply disable System Restore (which you should do anyway to eliminate the possiblity of the virus returning if you need to restore in the future). In Windows ME: right click My Computer -> Properties -> Performance tab -> File System button -> Troubleshooting tab -> disable system restore In Windows XP: right click My Computer -> Properties -> System Restore tab -> Turn off system restore |
|
| 1775. |
Solve : Pop Up Blocker? |
|
Answer» Been having TROUBLE lately with pop-up ..have run ad-aware and am STILL getting them.. I have HEARD that the GOOGLE tool bar is good for getting rid of these. Has anyone every used it and if so does it seem to help? Thanks alot!Use Firefox as a BROWSER rather than Internet Explorer: |
|
| 1776. |
Solve : svchost.exe... Virus???? |
|
Answer» I ran an online scan on Trend Micro and it FOUND a virus called the WORM_NACHI.DAM and the file was svchost located in the C:/Windows/System32/drivers. then i got another one only in the system32 folder. i checked properties of both and the one dat is not infected had a description of Generic Host Process for WIN32 Services, while the one infected had Unknown. should i got ahead and DELETE this? it does look suspicious being the only .exe file i got in the drivers folder.Delete or rename it and RERUN the virus scan. |
|
| 1777. |
Solve : Filter Program out of control? |
|
Answer» Quote gpcii....The last entry 017....... with the two ip addresses ....can you check and see if they belong to your server , because when I googled them they dont APPEAR to be valid .... Please FORGIVE my ignorance, but how would I go about checking if they belong to my server? I do use SBCGLOBAL.NET, but as to the series of numbers, I have no idea. Thanks.That is most likely the IP adress your ISP has. No need to worry about that. However, why not contact your ISP and ask them what you can do about the filter?Quote However, why not contact your ISP and ask them what you can do about the filter? Will do. Thanks.Those two addresses do, in fact, resolve to sbcglobal.netI've CONTACTED my ISP. They said to check my proxy settings, and that it should not be marked. (It's not) They said that I could ALSO run a tracert in dos. (I did, but how would I know if what was traced was a problem?) |
|
| 1778. |
Solve : Nortons not recognizing tcp/IP? |
|
Answer» Help? Can anyone answer this? I'm running WINDOWS XP with both SP 1 and SP2. When Iboot up my computer a messageg COMES up that Nortons 2002 states that since I don't TCp/IP settings it won't scan my E mail. I have both the "Internet PROTOCOL tcp/IP and Microsoft TCP/IP ver 6 selected on the system. Also since I'm on cable they tell me I automatically have a TCP/IP setting through their modem. In the past Nortons used to scan both incoming and outgoing messages. What do I need to change?Before installing service packs you should uninstall your antivirus software. Try uninstalling Norton and reinstalling it. My wife had a similar problem and that cured it. |
|
| 1779. |
Solve : What virus scanner do you use?? |
|
Answer» What virus scanners do you use? and a twist to this post who is writing them....is it an anti-virus....software...empire...no viruses.. no bussiness..makes you wonder ...? Bored German teenagers. |
|
| 1780. |
Solve : Results of Spybot Scan-- Virus? |
|
Answer» Said 173 things wrong. I'm afraid if I click to fix, I will wipe out my MACHINE. Was clean about 2 weeks ago. Is this virus? AVG doesn't pick up anything. This is only small part of listing from Spybot. Congratulations!: No immediate threats were found. () Please refer to the help guide if you have absolutely no idea what you're doing.Let me explain more about what's happening. I am worried because I keep getting alerts from my server (sometimes as many as three a day) saying "You have been sent a virus, but it has been removed." I really appreciate my wonderful server catching them before they get to me, but I try to keep check on my machine in case one does get through. When I run AVG and Ad-aware, I get a good result... have clean machine. But when I run Spybot, the test result says "Congratulations" But directly under congratulations, a great many errors are listed. Some are registry problems that I'm afraid to "fool" with... some are tracks which I have deleted... no red errors yet And sometimes I don't have a clue about this computer "stuff"; but I have decided there might be something wrong with my Spybot program. Think I will do an uninstall and then reinstall it What do y'all think? TIA, Patsy If the viruses are intercepted, you have not much to worry about. These are the things everyone should have installed:
And properly configured, ofcourse. If your virus scan can find nothing and your spyware scanner is used on a regular basis, you have very little to worry about. However, you did not mention wheter you had a Firewall installed. I suggest you read this article: How Stuff Works - How Firewalls Work I ASSUME when you say 'server' you mean your mailserver? As for deleting registry entries, I never used Spybot Search & Destroy for that. I would recommend a program such as Regseeker, Advanced System Optimizer V2 or Advanced Uninstaller Pro 2004 to clean your registry. They can create backups and, except for Regseeker (which is the only freeware tool in this list) can provide you with more services. |
|
| 1781. |
Solve : total shut down? |
|
Answer» wtoolsa and wsup have my windows 98 inoperable |
|
| 1782. |
Solve : My comp sucks? |
|
Answer» Ive run Adaware, Spysweep, Spybot S&D and windows washer yet my comp still randomly reebots and my internet explore home page is still bein changed to a website called "about:blank" how do i make my COMPUTER not suckThe random rebooting of your computer is not necessarily a software problem. First though, I would ensure your virus definitions are up-to-date and I would run a full system scan. Also, make sure that ALL of your drivers are good. |
|
| 1783. |
Solve : problems with dial up changing? |
|
Answer» when ever i disconnect from the internet something happens to my dial up. when i go to connect again later my user name has changed with like an IP ADDRESS at the end and the phone number i use to dial to my ISP has change to this huge string of numbers. i have done spyware checks and run ANTIVIRUS scans but i can't find ANYTHING. its really pissing me off. |
|
| 1784. |
Solve : My Computer is horrible? |
|
Answer» My computer has deep deep issues, it all started when my internet was FROZE to one page. I call the computer company and they basically told me to run a system recovery. I did and that did not fix the problem. It deleted everything that it intended to do, but now everytime i try to do anything i get error MESSAGES like not accessible to desktop and stuff like that. I TRIED to buy and antivirus program thinking that would do the trick but the computer says (yes it talks) that i NEED 11megabytes to load the software. I try to do that and that doesn't happen. I cant even reload my isp through the cd rom this whole thing is frustrating i am hoping somewhere someone could help me. Let me know please thank you very muchSeems to me like you're better off formatting your HDD. Take proper precautions before connection to the internet and install an Adware SCANNER, Virus scanner and a Firewall. |
|
| 1785. |
Solve : lsess.exe? |
|
Answer» can anyone tell me what this PROGRAM is...You probably MEAN lsass.exe, correct? |
|
| 1786. |
Solve : www.404ads.net? |
|
Answer» I was getting a LOT of spyware so i downloaded spybot and ad-aware now sometimes when i try to sign on the internet i get redirected to www.404ads.net... (more there) I was wondering if anyone KNOW how to stop that.Adaware SE should offer you the OPTION to lock your BROWSER and PREVENT hijacks. |
|
| 1787. |
Solve : Freezing XP - Help me!!!!? |
|
Answer» Computer appears to boot up normally - goes all the way thru to "loading personal settings" - then nothing. Now - try to answer the question - unless you can't (which I suspect is the case). You're testing me. How exciting! Did you do as Robertmillar said? You did not mention when the problem occured and how you made it occur. And, last but not least, you may be able to use the repair option on your Windows XP CD-ROM. Yes - I am testing you and I hope (as the name implies) you will oblige me. I did try to do what Robert Millar said to no avail. The problem occured when I booted up, as I stated in the first message. I don't recall doing anything that would have made this occur. Let's see - I turned on the computer - went to get my morning coffee and returned to a blank (or should I say a background) with no desktop icons. I rebooted - same result. I have been able to go into task manager and open programs from there - so I was able to retrieve all important data and burn. I have a new hard drive now - so problem solved. I hope.Did you have the latest Microsoft security updates installed?This is the same exact problem I am currently having on my laptop. I'm going to have to buy a new harddrive to fix this? *censored* no, I'm on a *censored* laptop as it is and on a college payroll. I don't have money, but I do have time. Any other suggestions on how to fix this? By the way, how did you retrieve your information from the task manager? (I don't have a burner so I can't backup any important information) Any advice on how to fix this will be greatly appreciated. I will try as well, but you guys are the EXPERTS! [edit] To answer some of those questions, I tried everything previously mentioned on this thread and I think I had XP Service Pack 1 installed, but not 2. |
|
| 1788. |
Solve : Tip of the week? |
|
Answer» Here is a super tip - Just sort your windows system32 and drivers directory according to DATE and the most recent files are on top. simply delete the files of the last four or five DAYS and you will be surprised how all the problems vanish try this safemode only....it may help people in the fight against trojans/worms/spyware etc..AH, yes, I allready see the hordes of clueless people who delete the wrong files and ask us why we'd post such tips.you would have thought by now people the own pc have the sense by now to know what to do with it if they>?DONOT YOUR USE THOSE UPDATES silly ??...some system that is keeps needing them WHY ??the question is the system is that good why do you need updates /program/fault/bad scripting/the list could be endless nice scam...but that would be then end of all fixit forums....bring on longhorn after all winxp does keep me GOING ...thou i do have a super-nap care off m$oft > that the average person needs nine.30 mins of sleep but wixp keep me awake ..wondering if it may be like the operating systems that msoft ..marking department have tried to sell the user an infalable system wake up people ...are you being conned is the question i would like to run a poll on this issue ..you can keep winxp i will stick with winme...its weird that bill gates dumped it ...the best system besides win98se...maybe is was to good !as has for the last poster it may help them concerned.... I agree with Merlin on XP; its a total suck out. Have you ever heard of Paladium or DRM or Microsofts secure computing initiative? SP2 was just the beginning. Longhorn will be the back breaker. You won't be able to run any software that has not been "approved" to run on your machine. But don't take my word for, do your own research.There are safer ways to remove redundant files..I'm agreeing with Raptor here. Methinks BEGINNERS would be a little better off with a couple of virtual dishcloths (anti-virus, anti-spyware etc) than the "pour industrial strength bleach all over everything - that'll kill all the germs" tactic. |
|
| 1789. |
Solve : Norton AntiVirus Live Update won't complete? |
|
Answer» Ok, it looks like my AntiVirus software has a mind of its own! The LiveUpdate just completed there with no problems. Weird or what Perhaps it is due to another program you have installed that is causing Norton to behave strangly. Ok, well the only THING that i installed in the PAST few months was Java Web Start by Sun Microsystems. I didn't have java installed on my machine so i couldn't view some sites properly. I was told to download this to fix my PROBLEM. It has fixed it but maybe that is what's causing Norton AntiVirus to mess up.. Hmm... Do you think i should un-install it Raptor??Are you certain there are no other programs running in your background? I doubt Java would cause that sort of problem. Perhaps you should have a look on the Symantec webpage to see if there are any lists with programs that cause problems or E-mail technical support. (You're paying for it!)Absolutly sure. I'll leave it be for now seeing as its working again but if it does happen again, i'll email technical support. As you said, i am paying for it! Thanks |
|
| 1790. |
Solve : Computer help.? |
|
Answer» Hi. I was wondering if someone could maybe give me some ADVICE, or help about a problem that my computer seems to have. |
|
| 1791. |
Solve : Norton scanning Word files....stop it?? |
|
Answer» Just installed Nortaon AV Scan 2004... |
|
| 1792. |
Solve : BAsfIpM.exe? |
|
Answer» hey all, |
|
| 1793. |
Solve : Privacy? |
|
Answer» How can I find out if someone who I share a computer with has installed any programs that might be tracking my computer USAGE or GAINING access to my EMAILS or using any other method to gain access to my privacy?http://www.keylogger.net/or buy an external hard drive...Thanks for responding Merlin_2. I hope my question was clear. I am not LOOKING for a way to spy on someone else. What I want to do is find out if any programs such as Keylogger have been installed on my PC. I understand these type programs are deliberately hidden on a computer and can even be set up to secretly email my computer activities to someone. How can I check my computer to see if any such program has been installed? Thanks, Shad.i take it you are logged in as a user...download spysweeper from www.webroot.com...it should scan the pc for all programs which maybe tracking you..like radmin..keyloggers..etc..tojans /worms..and there is this>http://www.tooto.com/keyloggerkiller/ i post the keylogger to fight FIRE with fire if you get my drift Please Read This First - Viruses & Spyware |
|
| 1794. |
Solve : AVG-NORTON ?Conflict? |
|
Answer» I have NORTON 2004 and AVG antivirus program INSTALLED in my computer having windows XP. I want to ask whether there will be any problem or conflict having both softwares.You should never have more than one virus scanner installed. |
|
| 1795. |
Solve : I need help with a virus problem? |
|
Answer» I ran a virus scan with AVG 6.0 and this is a LIST of all that was found. I have tried to remove them with AVG and it says they can't be removed. I don't have a clue on how to get rid of them. I have tried to search the help sites with no luck. I have not found these virus names on any site. If someone knows how I can remove them please let me know. Thanks!! |
|
| 1796. |
Solve : Can't close Internet Explorer windows? |
|
Answer» Hey everyone. My internet explorer was working fine today. THen all of a sudden, I cant close the windows. i have to go to END task and do it and even when i go tehre it sais i have to do end now for it to close. also, when i go online my cpu usage jumps to 100%. im pretty sure its not my internet and my cpu is new its been running well for about 3 months. I can close other windows that arn't online EASILY. i think its a virus but im not sure. please help me. thanksoh yeah EVERYTHING else runs fine. i can play games and go on aim but the only problem is using internet explorer. it just wont let me close its BROWSERS and my cpu usage jumps like crazy. i ran spyware and adware programs. it detected a few but ive always had them and i dind't have problems like these. i would also delte them every DAY but today i only found about 10 of them so i dleted themScan for viruses and trojans as well. |
|
| 1797. |
Solve : system soap? |
|
Answer» don't know how, but have a program called system soap running on my pc. no MATTER what i do i cannot remove it. are you familiar with this program, and if so how do i remove it? |
|
| 1798. |
Solve : to Read registry to get all the application? |
|
Answer» Hi Guys, |
|
| 1799. |
Solve : you guys are guna love this....? |
|
Answer» i have a little problem with spyware/adware sort of speak...... noticed it when my homepage turned into somthing else... i change it and it changes back... i run hijack this and remove what i knew whasnt supposed to be there, and i re-scan it comes back... i goto my Registry edit and remove the items that where there that wernt supposed to be... and the appear right back.. i run trojanhunter.. none found.. same with norton.. i run adware (lavasoft) and it finds 31 PROBLEMS, i remove and quarentine.... re-scan .... they come right back... (even after reboot) i run spyware S&D... finds CoolWWWSearch or somthing and a couple others... it removes them... and guess what They KEEP comming BACK! its like a fly that lands on the same spot everytime you shoo it away.. i wouldnt be posting this unless i was absolutly shure i couldnt handle it myself... so i need some suggestions here... |
|
| 1800. |
Solve : catch.exe? |
|
Answer» my daughter has a dell inspiron LAPTOP RUNNING windows xp pro. she mentioned that when she reviewed her task manager process list, there was a process running called "catch.exe". i've looked everywhere and can't find a reference to it as spyware or virus...just a reference to an old DOS 6.2 college biology program. anyone ever hear of it? my daughter has symantech 9.x and ad-aware. thanks!huxster....you QUITE correct....it is Dos SIMULATION program..... |
|