Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2151.

Solve : What is p4s.exe??

Answer»

The other day my anti-virus popped up asking me if i will allow access to p4s.exe...I denied it because I had no idea what it is...
Can anyone here shed some light on it?

ThanksQuote

The process BELONGS to the software p4s.exe or Perforce Core Components by unknown.
DESCRIPTION: p4s.exe is LOCATED in a subfolder of "C:\Program Files". Known file sizes on Windows XP are 1,216,512 bytes (50% of all occurrence), 847,872 bytes, 979,001 bytes.
The application has no file description. The program has no visible window. It is not a Windows core file. Program uses ports to connect to LAN or Internet. Therefore the technical security rating is 74% dangerous, however ALSO read the users reviews.


Taken from http://www.file.net/process/p4s.exe.html on 16/7/09


BUT on another website, it says that it is a vital component of Perforce Software. If you have any Perforce software on your computer, it would either be advisable to unblock p4s.exe (only if you trust it) or uninstall the software.

hxxp://www.anti-spy.info/process/p4s.exe.html <- Link disabled Click
http://perforce.com/>> How to scan SUSPICIOUS files <
2152.

Solve : Can you take a quick look at my logs to see if I'm infected? Thanks!?

Answer»

Hi,

Can you please take a look at my logs to see if I was infected when Facebook's "Bumper Sticker" application TRIED to get me to download a virus with a spoof Windows WARNING?

MalwareBytes Log:

Malwarebytes' Anti-Malware 1.39
Database version: 2427
Windows 5.1.2600 Service Pack 3

7/14/2009 12:51:18 PM
mbam-log-2009-07-14 (12-51-18).txt

Scan type: Full Scan (C:\|)
OBJECTS scanned: 150783
Time elapsed: 1 hour(s), 4 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)





HJT Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:21:00 PM, on 7/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Trend Micro\ABCThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy:8080
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Resolution Assistant.lnk = C:\Program Files\Dell\Resolution Assistant\MotiveAssistant\bin\matcli.exe
O4 - Global Startup: Windows Media PowerPoint Helper.lnk = C:\Program Files\Windows Media Components\Tools\nsppthlp.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install-ie/alttiff.cab
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} (Auctiva Image Uploader Control) - http://www.auctiva.com/Aurigma/ImageUploader57.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.auctiva.com/hostedimages/activex/xupload/XUpload.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: WUSB54Gv2SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 6674 bytes


THANKS SO MUCH!i'm not an expert but nothing sticks out if it DOE's an expert will soon let me know ( i hope )

if you only tried to download it , there was no harm done , harry

2153.

Solve : Too many programs??

Answer»

This is more of a question, rather than a problem. Currently, I am using AVG Anti VIRUS. I have Comodo FIREWALL with Defense+, I have Prevx 3.0, which only scans my computer but won't remove MALWARE unless I pay for it, so kinda useless. I also have MalwareBytes Anti Malware and Spybot Search and Destroy.

So, my question is, do I have too many of these antivirus, malware removal PROGRAMS? If so, which ones would you recommend deleting?

Thanks for anyone's help.You can never have too many, IMO.

Just make sure you don't have more than one real-time antivirus or antispyware program running. More than one firewall isn't a good idea either, so if you use Windows Firewall be sure to turn it off.

Sorry for the delay in replying, BTW.Okay, thanks for the reply. AVG is the only antivirus I have. Prevx acts sort of like a firewall because it uses the realtime infection monitoring. Don't really see the need of prevx as it can only scan but not remove anything with the free version.

2154.

Solve : win32 heur?

Answer»

can this *censored* put itself into my motherboard? Had a clean install of XP+SP3 and only visited MS update and by God it was back again.....what now?

AMD Athlon 64, 3200+, 3Gb RAM, XP+SP3 and all the other gadgets, IE8, XP Firewall, AVG 8.5 free version , wireless Internet via D-Linkno. It can't.

Are you behind a hardware firewall?only firewall present is the XP firewall, its a standalone machineQuote

clean install of XP+SP3
Did you reformat and reinstall? You have to do both.

Do you use filesharing often? Torrents, Limewire, Frostwire etc.?

Download, install, and run Dr.Web CureIt! Post the log it creates.yup, did both, the slow formatting type while installing new xp...only site I CONNECTED to was ms update...had not connected to any sites at all besides this MS one... You have to remember to turn on Windows firewall before you connect to the internet for the first time after a reinstall.....It's as if every malicious piece of garbage is sitting there waiting for an opening into your computer...... were you protected from the moment you WENT online?yup, xp firewall was on and I had a look at the exceptions... Quote
Do you use filesharing often? Torrents, Limewire, Frostwire etc.?

Download, install, and run Dr.Web CureIt! Post the log it creates.
kpac, I'm sorry, you are right....lol'
No, I dont use that garbage, pay for what i wanna hear or see...
that site wont open for me...Download DDS from |HERE| or |HERE| or |HERE| and save it to your DESKTOP.

Vista users right click on dds and select Run as ADMINISTRATOR (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.
thanks evilfantasy, I did a clean install, but will certainly follow your advise, you never know...problem was that this win32 heur virus had to COME from MS Update, that was the only site I visited before i got oerwhelmed by all these bloody virusses...
2155.

Solve : Stuck, logs attached still waiting for help :)?

Answer»

I am still WAITING for SOMEONE to look at my logs. It has been a MONTH. Is this normal or did I do something WRONG?

2156.

Solve : the sleep refuses to work?

Answer»

...my sleep on Vista Home Premium used to work.....it stopped working, over time......I did my bit with power options, etc...and it will wake up....but never again touching the mouse nor keyboard...I have to hit the on/off buttom on my Dell desktop.....my solution went LIKE this......start, control panel, classic view, DOUBLE click power options, click CHANGE when computer GOES to sleep, SELECT change advanced power settings, click+ next to sleep, click+ to allow hybrid sleep, click ok when finished.....well, this solved it.....but the sleep option is gone from keyboard and touching mouse to awake the computer from power save.....these two things cannot be done again to wake it up........or the other option to put to sleep and wake up computer at same page......that quit working too......this is not life and death...but the original options disappeared, and how do I get them back...or are they gone with the wind ?

2157.

Solve : 300+ viruses. windows installer is missing.?

Answer»

so like the tittle says, this computer has more than 300worms, trojans , adware, and others i have 2 / 3 requested logs, cannot install super anti spyware because miexecis missing.

WINDOWS Xp Professional
VERSION 2002.
SP3
512 mb of Physical ram.
intel Pentium III processor


so heres the hijackthis:
Code: [Select]Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:14:55 PM, on 7/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\Program Files\The Skins FACTORY\Hyperdesk\Common\HdThemeEnabler.exe
C:\windows\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\UTSCSI.EXE
C:\windows\system32\wscntfy.exe
C:\windows\explorer.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60001
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60001
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60001
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {035EE524-3B69-4721-B8DE-7E5A2ABB7D48} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [RelevantKnowledge] C:\Program Files\RelevantKnowledge\rlvknlg.exe -boot
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [gtsrp] C:\Program Files\gtsrp\gtsrp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: taksman.exe
O8 - Extra context menu item: CUSTOMIZE Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: Identities Editor - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditIdent.html
O8 - Extra context menu item: RoboForm TaskBar Icon - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: TaskBar - {320AF880-6646-11D3-ABEE-C5DBF3571F51} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html
O9 - Extra 'Tools' menuitem: RoboForm TaskBar Icon - {320AF880-6646-11D3-ABEE-C5DBF3571F51} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html
O9 - Extra button: Identities - {45DB34C3-955C-11D3-ABEF-444553540000} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditIdent.html
O9 - Extra 'Tools' menuitem: Identities Editor - {45DB34C3-955C-11D3-ABEF-444553540000} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditIdent.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\windows\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {7417F730-7BAB-409E-8BB7-6936D361B869} (MLauncher Class) - http://csweb.netgame.com/yulgang/MLauncher.cab
O16 - DPF: {7C564BC7-73BD-4750-A90A-8FF2D8C8C64B} (SysInfo Control) - https://secure.cabal.co.kr/cabalweb/Include/SysInfo.cab
O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/download/MusaLauncherNew.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://chill.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\dfrgsnap32.dll
O20 - Winlogon Notify: 9cd717d5619 - C:\WINDOWS\System32\dfrgsnap32.dll (file missing)
O20 - Winlogon Notify: ssqQkKcy - ssqQkKcy.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
O23 - Service: Hyperdesk Theme Enabler (HdThemeEnabler) - The Skins Factory, Inc. - C:\Program Files\The Skins Factory\Hyperdesk\Common\HdThemeEnabler.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KeenfinderSrch Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\KeenfinderSrch\keenfinder136.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: Windows Installer (MSIServer) - Unknown owner - C:\WINDOWS\system32\msiexec.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\windows\System32\TuneUpDefragService.exe
O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE

--
End of file - 12214 bytes
And here is mbam
Code: [Select]Malwarebytes' Anti-Malware 1.39
Database version: 2421
Windows 5.1.2600 Service Pack 3

7/13/2009 3:31:58 PM
mbam-log-2009-07-13 (15-31-58).txt
A
Scan type: Quick Scan
Objects scanned: 92895
Time elapsed: 18 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory MODULES Infected: 9
Registry Keys Infected: 38
Registry Values Infected: 13
Registry Data Items Infected: 5
Folders Infected: 28
Files Infected: 279

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\Temp\uia6.tmp (Worm.Parite) -> Delete on reboot.
C:\WINDOWS\Temp\fiaA.tmp (Worm.Parite) -> Delete on reboot.
C:\WINDOWS\Temp\tha6.tmp (Worm.Parite) -> Delete on reboot.
C:\WINDOWS\Temp\hia7.tmp (Worm.Parite) -> Delete on reboot.
C:\WINDOWS\Temp\lia9.tmp (Worm.Parite) -> Delete on reboot.
C:\Documents and Settings\LocalService\Local Settings\Temp\djaB.tmp (Worm.Parite) -> Delete on reboot.
C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.Marketscore) -> Delete on reboot.
C:\WINDOWS\system32\MPK\Mpk.dll (Refog.Keylogger) -> Delete on reboot.
C:\WINDOWS\system32\__c0034C40.dat (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\bndshell3.bho (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bndshell3.bho.1 (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\imeshmediabar.stockbar (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{6c380604-92b2-4633-becb-bde03fa45980} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4481c34a-10df-4c96-92a6-0ef31b6b95d6} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f9c23cd1-6da9-4e0b-8367-c6f9f1f78baf} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\imeshmediabar.stockbar.1 (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\imon.tieadvbho (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{94bc3d1d-22e9-4744-8ed1-3e08a3b74078} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{875a1348-7674-42aa-adac-b4f36a004a2d} (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0d39a900-0f3a-4c29-a254-3e65244fdc34} (Adware.PlayaZ) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d032570a-5f63-4812-a094-87d007c23012} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227d9c-0efe-4f8a-aa55-30386a3f5686} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{94bc3d1d-22e9-4744-8ed1-3e08a3b74078} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{875a1348-7674-42aa-adac-b4f36a004a2d} (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0d39a900-0f3a-4c29-a254-3e65244fdc34} (Adware.PlayaZ) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94bc3d1d-22e9-4744-8ed1-3e08a3b74078} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{875a1348-7674-42aa-adac-b4f36a004a2d} (Adware.AdBand) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0d39a900-0f3a-4c29-a254-3e65244fdc34} (Adware.PlayaZ) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\contexttool (Adware.PlayaZ) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\relevantknowledge (Spyware.Marketscore) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0034c40 (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\AppID\Sidebar.dll (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\superiorads (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\QdrDrive (Adware.ISM) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Refog Software (Refog.Keylogger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Adware.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{41c29b07-6f91-4966-91be-2e2841643c83} (Adware.Adssite) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{94bc3d1d-22e9-4744-8ed1-3e08a3b74078} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\c:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Salestart (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cp-kr (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cp-kr (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spa_start (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00f46d9732.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00f10891a37.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00f19f0ae.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SystemManger (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Refog.Keylogger) -> Data: c:\windows\system32\mpk\mpk.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Refog.Keylogger) -> Data: system32\mpk\mpk.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Trojan.Agent) -> Data: c:\windows\config\csrss.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe C:\WINDOWS\Config\csrss.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Refog.Keylogger) -> Bad: (c:\windows\system32\userinit.exe,C:\WINDOWS\system32\MPK\MPK.exe) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\contexttool (Adware.PlayaZ) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge (Spyware.Marketscore) -> Quarantined and deleted successfully.
C:\Program Files\RelevantKnowledge (Spyware.Marketscore) -> Delete on reboot.
C:\Program Files\QdrDrive (Adware.AdBand) -> Quarantined and deleted successfully.
C:\Program Files\QdrModule (Adware.ISM) -> Quarantined and deleted successfully.
C:\Program Files\Advantage (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{A89AED22-9133-424c-88E7-C8235C5FF302} (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale\en-US (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\components (Adware.Advantage) -> Quarantined and deleted successfully.
C:\Documents and Settings\Mark Cook\Application Data\ErrorSmart (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
c:\documents and settings\mark cook\application data\errorsmart\Log (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MPK (Refog.Keylogger) -> Delete on reboot.
c:\WINDOWS\system32\MPK\Help (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Images (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\MPK (Refog.Keylogger) -> Delete on reboot.
c:\documents and settings\all users\application data\MPK\1 (Refog.Keylogger) -> Delete on reboot.
c:\documents and settings\all users\application data\MPK\1 (Refog.Keylogger) -> Files: 3666 -> Delete on reboot.
c:\documents and settings\all users\application data\MPK\2 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\3 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\4 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\CPDA (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\CPDM (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\REFOG Personal Monitor (Refog.Keylogger) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\Temp\uia6.tmp (Worm.Parite) -> Delete on reboot.
C:\WINDOWS\Temp\fiaA.tmp (Worm.Parite) -> Delete on reboot.
C:\WINDOWS\Temp\tha6.tmp (Worm.Parite) -> Delete on reboot.
C:\WINDOWS\Temp\hia7.tmp (Worm.Parite) -> Delete on reboot.
C:\WINDOWS\Temp\lia9.tmp (Worm.Parite) -> Delete on reboot.
C:\Documents and Settings\LocalService\Local Settings\Temp\djaB.tmp (Worm.Parite) -> Delete on reboot.
C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll (Adware.SoftMate) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\155.tmp (Worm.P2P) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\local settings\Temp\cpaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\local settings\Temp\fpaE.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\local settings\Temp\wiaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\local settings\Temp\woaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\pbe7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ppj498.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\pwa6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\pyk3CD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\qbu22.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\qep1BA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\qsu17A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\qxx2C1.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\rdi5EA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\rit1C9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\eav231.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\edi68.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\enn3F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\eoj497.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\fbaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\fcg105.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\fna4.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\fwd118.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\gia6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ana9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\arp10F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\bcl9F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\bdd1A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\bha5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\bqa3.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\bwaE.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\bwu133.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\vla7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\vru2F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\wkj496.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\wys262.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\wzs263.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\xcg107.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\xla7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\xma2.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\xms1F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\xqcE4.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\xtaC.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\xup517.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\xyi5E9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ybe8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\yck79.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ydi66.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\yfu24.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\yla5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ylu132.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\yma9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\yna2.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\yth2E5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\yvaD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\zdt1C7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\zmy37.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\zna8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\znaB.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\zpt1C6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\lia6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\lku71C.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\lqa7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\lqcE6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\mdp1B8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\mma3.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\mou719.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\mqa6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\mtaB.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\mxl137.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\mya7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\nhaD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\njc25.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\nxn41.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\oba9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\odk3CF.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ofv233.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ohu135.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\oka1.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\otaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ots261.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\rov726.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\rrf4F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\rsu17B.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ryu21.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\sad119.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ssa8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\sua5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tfi5EB.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tha5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tns20.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tun40.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tvp519.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tzg1EF.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\uew733.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\uhp1BD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\uqf4D.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\usl135.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\uta4.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\uwl136.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\vah2E7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\vfw34.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\vgv234.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\hgu31.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\hla7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\hzw732.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ibl9E.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ibn383.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ico10B.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\idi67.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\iep51A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ifn385.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ifw734.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ila1.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ioa9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ipu71B.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\iuaC.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\iyg1ED.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\jclA0.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\jfn384.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\jma8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\jsv727.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\jua6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\kht1C8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\kia5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\kou179.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\kpa2.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\kxe6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\laa8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\lbw32.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\cea7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\cep51C.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\cfa8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\cgc24.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\abd11A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\aco10C.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\afu23.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\aia8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\clu71E.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\cna8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\cta9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ctv728.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\cyo109.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\czh2E6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\dev232.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\dgn266.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\dhp1BB.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\dhy35.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\dis1E.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\dma5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\dxaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ammB9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\byn267.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\cgr33.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\dyu134.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\grf4E.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\ldk3CE.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\pas264.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\rkc26.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\vha9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
c:\program files\contexttool\ContextHelper.dat (Adware.PlayaZ) -> Quarantined and deleted successfully.
c:\program files\contexttool\pcre3.dll (Adware.PlayaZ) -> Quarantined and deleted successfully.
c:\program files\contexttool\uninstall.exe (Adware.PlayaZ) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\relevantknowledge\About RelevantKnowledge.lnk (Spyware.Marketscore) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\relevantknowledge\Privacy Policy and User License Agreement.lnk (Spyware.Marketscore) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\relevantknowledge\Support.lnk (Spyware.Marketscore) -> Quarantined and deleted successfully.
c:\documents and settings\all users\start menu\Programs\relevantknowledge\Uninstall Instructions.lnk (Spyware.Marketscore) -> Quarantined and deleted successfully.
c:\program files\relevantknowledge\rlls.dll (Spyware.Marketscore) -> Delete on reboot.
c:\program files\relevantknowledge\rloci.bin (Spyware.Marketscore) -> Quarantined and deleted successfully.
c:\program files\relevantknowledge\rlph.dll (Spyware.Marketscore) -> Quarantined and deleted successfully.
c:\program files\relevantknowledge\rlservice.exe (Spyware.Marketscore) -> Quarantined and deleted successfully.
c:\program files\relevantknowledge\rlxf.dll (Spyware.Marketscore) -> Quarantined and deleted successfully.
c:\program files\QdrDrive\qdrloader.exe (Adware.AdBand) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\advantage.png (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\contents.rdf (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\overlay.js (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\overlay.xul (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\vssver2.scc (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale\en-US\overlay.dtd (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale\en-US\vssver2.scc (Adware.Advantage) -> Quarantined and deleted successfully.
c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\components\MeMedia_FF.dll (Adware.Advantage) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\French.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\German.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\icon_1.ico (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\key.bin (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\libeay32.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\logstart.vbs (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\loguninstall.vbs (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Mpk.dll (Refog.Keylogger) -> Delete on reboot.
c:\WINDOWS\system32\MPK\MPK.exe (Refog.Keylogger) -> Delete on reboot.
c:\WINDOWS\system32\MPK\Mpk64.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\MpkNetInstall.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\MPKView.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Romanian.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Spanish.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\sqlite3.dll (Refog.Keylogger) -> Delete on reboot.
c:\WINDOWS\system32\MPK\ssleay32.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\temp1.bin (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\trial_pro.ini (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\unins000.dat (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\unins000.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\zlib1.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\file.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\imhelp.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\need_update_net.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\update.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\English\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Help\Spanish\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Images\english.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Images\german.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Images\russian.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Images\vista_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\MPK\Images\xp_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\key.bin (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\M0000 (Refog.Keylogger) -> Delete on reboot.
c:\documents and settings\all users\application data\MPK\REFOG Personal Monitor.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\2\D0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\2\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\3\D0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\3\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\4\D0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\4\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\CPDM\cpfm.bin (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\refog personal monitor\Order now!.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\refog personal monitor\REFOG Personal Monitor on the Web.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\refog personal monitor\REFOG Personal Monitor.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\MPK\refog personal monitor\Uninstall REFOG Personal Monitor.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\ErrorProtector Free\startmon.exe (Rogue.Multiple) -> Delete on reboot.
c:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\Config\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\__c0034C40.dat (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\superiorads-uninst.exe (Adware.BHO) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\__c0020A9D.dat (Trojan.Agent) -> QuarantineAd and deleted successfully.
c:\WINDOWS\system32\__c002515C.dat (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\__c00328F9.dat (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\__c00728BE.dat (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\__c008D819.dat (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\__c00B3F50.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Explorer\msn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Explorer\ods.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Explorer\stm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Internet Explorer\iexplorer.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
re-run mbam to see if its clean and post the log

2158.

Solve : Which antivirus is better??

Answer»

do u know w/c antivirus is better, AVAST or AVG? PLEASE advise...

Best regards,
Jennifer
Internet Marketing Officer
[link REMOVED - Violation of Forum Rules]How long is a PIECE of string?

Personally, I would use AVG. Everyone's opinion would be different.Hmmm... I tried them both, and caught VIRUS using both too.. LoL...
Now Im not sure which one at least gets less virus...


Best regards,
Jenn
Internet Marketing Officer
[link Removed - Violation of Forum Rules]Why the link in your signature?

2159.

Solve : Can you increase the size of the archive folder in AVG?

Answer»

Hello and thank you for looking at my thread.

I have AVG 8.5 free edition, it has all the UPDATES so far and runs automatically at a certain time each day.

Recently it found some threats and infections and sent most of them to the vault.
There are 4 (four) infections however that I cant remove.
When I try to EITHER heal or remove them, I get a message that the item/s is/are bigger than the archive SIZE limit.
I've looked AROUND the menu but I cant find anything RELATING to the archive size limits.

Can someone please help me with how I might delete these files please.
Thank you ImnoGuruhttp://ccollomb.free.fr/unlocker/

go to above download and run , it will remove anything , read it first , harryThank you harry 48 for your reply.
I have been too busy to get back to read here for a while sorry.
I have unlocker now and will read the details of how to use it tonight.
Once again thank you ImnoGuru.

2160.

Solve : msnmgnr.exe problem..?

Answer»

hello, everyone...i'm a newbie. can anybody help me with this worm. missing file msnmgnr.exe keeps showing up every start up. at first i thought i need to replace my BIOS battery because my date and time setting always resets.and then after some time my monitor turns on and off when it is only a month old. here is my LOG:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:17:07 PM, on 7/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SEARCH Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe msnmgnr.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {86053272-2825-7434-6472-5599ca323026} - (no file)
O2 - BHO: SBCONVERT - {A1056498-D09A-41E4-864B-505EDD640D9E} - C:\Program Files\SpeedBit Video Downloader\Toolbar\SpeedBitVideoDownloader.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll
O2 - BHO: GrabberObj Class - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\SPEEDB~2\Toolbar\grabber.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: SpeedBit Video Downloader - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\SpeedBitVideoDownloader.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.23.0\gears.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office GENUINE Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/BookWorm/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative TOOLBOX Plug-in) - http://ak.imgag.com/imgag/cp/install/Crusher.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/BookWorm/Images/armhelper.ocx
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe LTD. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9a059b2e3af89) (gupdate1c9a059b2e3af89) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: USBest Service Zero (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/XP2/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

--
End of file - 10562 bytes


THANK YOU VERY MUCH .. SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/14/2009 at 01:49 PM

Application Version : 4.26.1006

Core Rules Database Version : 3992
Trace Rules Database Version: 1932

Scan type : Quick Scan
Total Scan Time : 00:16:36

Memory items scanned : 488
Memory threats detected : 0
Registry items scanned : 493
Registry threats detected : 11
File items scanned : 5793
File threats detected : 4

Adware.Tracking Cookie
C:\Documents and Settings\XP2\Cookies\[emailprotected][8].txt
C:\Documents and Settings\XP2\Cookies\[emailprotected][11].txt
ads.revsci.net [ C:\Documents and Settings\XP2\Application Data\Mozilla\Firefox\Profiles\k10ihc17.default\cookies.txt ]
counter.hitslink.com [ C:\Documents and Settings\XP2\Application Data\Mozilla\Firefox\Profiles\k10ihc17.default\cookies.txt ]

Adware.HBHelper
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32#ThreadingModel
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\ProgID
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\TypeLib
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\VersionIndependentProgID

Browser Hijacker.Deskbar
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version

2161.

Solve : Here are logs that bonui asked for.?

Answer»

i ATTACHED them frist ONE superantispyware secound hijack and THIRD mbam

[attachment deleted by admin]who is "bonui"? LOL anyway... hope you get your problem solved, I'm sure Broni or one of the other malware specialists will be visiting QUITE soon to help you get your computer healthy again

2162.

Solve : unknown issue in XP (possible virus)-actually an issue with security center?

Answer»

Periodically (and only when my internet is plugged in) a quick bubble will pop up and disappear in the notifcations area on my desktop. I barely have time to make out any icon (it appears to be a red SYMBOL with a white 'x' inside it) and cannot make anything out in the actual 'chat bubble' that appears. Again this things happens appox every 30 seconds or so on average (sometimes faster, sometimes slower). I don't even KNOW if I would have NOTICED it except it makes the 'bubble' sound everytime it happenes.

I have run Hijackthis and removed all the BHO files and run AVG and run my local malware SW (malwarebytes)-though I first noticed the issue soon after running the malware SW the first time. Thanks for the input everyone.

JarrodTry LEAVING your mouse cursor over the exact SPOT where the bubble appears. It's possible the bubble will remain "up" if the cursor is there.I have tried leaving the cursor over the spot and even massive clicking to try and 'activate' the icon. Alas this does not work. Any other tips/tricks? Thanks for the help. The balloon appearing once doesn't bother me, but the fact that it continues is interesting.It is possible that it may do with your antivirus. I dont have the one you run, but its possible that when it updates it may look like to the computer that the antivirus is out of date/turned off at that moment, or only for a split second. This happens to me, but not so quickly. Ok I have discovered this is something to do with security center. I had the window open and the pop up occured and it flashed inside the window of security center. I am still unable to see what it says or is alerting me to. It is red in color so I would assume it is some kind of alert that something is failing or needs updated.

All the items are 'on' (firewall, updates and virus)-I switched to avast!

Any ideas?

2163.

Solve : Multiple Infections?

Answer» DISREGARD - FOUND HELP elsewhere.Disregard.
2164.

Solve : windows System Defender Access denied?

Answer»

I have found the FILE which pops up that Windows defender has detected Trojans and other VIRUS ' in my computer is planted in my application data sub directory.
when I attempt to del the .exe it gives me access denied.
I removed the attrib,

I /F and/Q the file with delete, to no avail. All other files associated with this deleted.

any suggestions on getting this file deleted?

the file name is WS1c6e.exe just over 1.5 meg in size.

thank you

Atmguy1Why don't you go to this LINK, FOLLOW the directions PRECISELY and post the three req'd logs to see if you are infected or clean.

2165.

Solve : Black box the reads: "Your System is Infected!"?

Answer»

First of all, thank you for helping people like me! The initial steps have already helped out my system.

I am essentially computer illiterate so please bear with me. Yesterday I got a message in a black BOX on my desktop that said "Your System is Infected!" It goes on to say that spyware has been detected and I need some special anti spyware. I also got a red circle with a white "X" in my icon tray in the bottom right corner of my screen that had a bubble that would pop up and tell me to "click here to protect your computer from spyware." I didn't click on either of those icons but in my panic I downloaded Microsoft Security Essentials and ran that since my McAfee was outdated. It found about 30 "worms" and I had those cleaned off. This didn't solve the problems which is when I found this site.

I completed all of your required steps. I am running Windows XP with SP2. I have removed: Logitech Desktop Messanger, my old McAfee, Shopper reports, and Viewpoint media player. After running SUPERantispy the red circle in the icon tray went away. Then after running Malware bytes anti-malware the black box went away and my system is running much faster.

My logs are attached. What is the next step?

Thank you,

Jeremy

[Saving space, attachment deleted by admin]Welcome to CH jermil32.

Looks good so far but we need to fix a few things and then run another scan to make sure nothing was missed.

Open HIJACKTHIS and select Do a system scan only

Place a check mark next to the following entries: (if there)

  • R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
  • O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
  • O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Miller\LOCALS~1\Temp\200911185340_mcinfo.exe /insfin
  • O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\Miller\LOCALS~1\Temp\200911185411_mcappins.exe /v=3 /cleanup
  • O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
  • O9 - Extra \'Tools\' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
.
Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be DISABLED and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix USAGE, see How to use ComboFixI've attached the ComboFix log.

[Saving space, attachment deleted by admin]That found more than I thought it would.

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

----------

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

----------

ESET Online Scan

Scan your computer with the ESET FREE Online Virus Scan

* Click the ESET Online Scanner button.

* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
* Double click on the esetsmartinstaller_enu.exe icon on your desktop.
* Place a check mark next to YES, I accept the Terms of Use.

* Click the Start button.
* Accept any security warnings from your browser.
* Leave the check mark next to Remove found threats and place a check next to Scan ARCHIVES.
* Click the Start button.
* ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List of found threats.
* Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
* Click the <<Back button then click Finish.

In your next reply please include the ESET Online Scan LogI've attached the ESETscan results.

[Saving space, attachment deleted by admin]If there are no more malware issues we can finish up now.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you very much. My computer is running much faster and doesn't have any of the problems from before. This is a great service you provide and I really appreciate your help!

Thanks again,

JeremyYour welcome.

Safe surfing...
2166.

Solve : Computer help please!!?

Answer»

Hello everyone! My COMPUTER is acting up. I keep getting a "security tool" pop-up. My anti-virus software has expired and I cannot install a NEW one because the CD drive will not run. All the icons disappear after login and I cannot run any tools (ie. ad/remove programs, system restore, etc.).When trying to download anything from the internet the widnow disapears after pressing the run or save buttons. The internet works fine as does word and excel. Any ideas out there?
Thanks
CoryWelcome to CH.

Prior to POSTING for help we ask that you please read and follow all instructions in the pinned topic titled Please read this before requesting malware removal help. Following the steps in the GUIDE will allow for us to QUICKLY help you with specific fixes for your system.

Post the 3 logs back in this topic.

2167.

Solve : BTIN.DLL - TROJAN HORSE IN MY COMPUTER?

Answer» HELLO,

I am using antivirus program - NOD32 on my computer and since 1-2 weeks it shows me every day warning message that a BTIN.DLL file,a variant of Win32/Trojandownloader.Mebload.H trojan is caught on my computer and moved to quarantine. And even I delete it,it shows up every day,sometimes few times a day.I runed few different antivirus programs, but noone helped. Finally I found this forum and followed the Malware Removal Guide of this forum. And I have no idea what to do now.Iwill attach here the 3 logs required.

Please,please for your help!
Thanks a lot in advance!

[Saving space, attachment deleted by admin]Welcome to CH.

I need to get some more information before MOVING forward.

Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will RECEIVE a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall TRY to block DDS then please allow it to run.
* When finished DDS will open TWO (2) logs.

1) DDS.txt
2) Attach.txt

* Save both logs to your desktop.
* Please copy and paste the entire contents of both logs in your next reply.

Note: DDS will instruct you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copy and pasting it into the reply.

2168.

Solve : Important: For Vista Users?

Answer»

I normally wait for updates for a week or so and scan all the Forums for issues before installing them.
Other than the CASUAL user i'd suggest this for most knowledgable users.

That being said today i grabbed the latest updates ( 4 ) from the last PATCH Tuesday...
These require a re-boot and the system will appear to hang in the PROCESS...NOTE...be patient and let it finish.
On the Benchtest machine the wait was over 12 minutes...which may ALARM some casual users.
To test i repeated the process on the same machine but a different build of VISTA...2nd build was close to that...approx. 9 1/2 minutes.

Just as a heads up...always let the update process finish...no matter if it appears to hang or not.

These are the Updates:

KB915597
KB890830
KB969947
KB973565

If you run into this as i said let it complete...and pass the word to any Vista users you may know.

patio.Good stuff Patio, thanks for the heads up.

2169.

Solve : Hijackthis, Im almost 100% sure i have a keylogger, or virus... please help?

Answer»

Logfile of HijackThis v1.99.1
Scan saved at 10:54:30 AM, on 10/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no NAME) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O8 - Extra CONTEXT menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O11 - Options group: [TABS] Tabbed Browsing
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: M-Audio Series II MIDI Installer (MA_CMIDI_InstallerService) - Unknown owner - C:\Program Files\M-Audio\M-Audio Series II MIDI\MA_CMIDI_Inst.exe
O23 - Service: NVIDIA Display DRIVER Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Virus scans with malware bytes detect nothing. You have an out-dated HJT log. You should go to this link and follow the DIRECTIONS PRECISELY.

2170.

Solve : May have a Boot Sector Virus??

Answer»

So I did a Factory Restore on my Computer cause it was goin slow, DVD Back Ups going slow, DVD Shrink Going Slow. When I open a program it sometimes opens slow. So After it restored it and installed windows, It said on the Screen Boot Sector Virus.

This may the reason Been having Computer Problems. I DOWNLOADED this the Avira Boot Sector Repair Tool and burned the ISO to CD and did a REBOOT to that. But all it did was stay on a black screen, so I didnt know if it was working or what it was doing,

The Computer is pretty New. Got it in Late January 09. Its a Gateway Model RS780. Im also RUNNING Windows Vista.

So Im hoping someone here with more knowledge about Virus can Help me out. Any help is GREAT. thanks. Boot sector viruses are very rare. WHAT gave you a message saying you have one?

2171.

Solve : Can 2 anti-virus softwares be used simultaneously??

Answer»

This PC CAME with Avira antivirus software already loaded in. It was ineffective. My dentist told me to use Skybot as well as Avira; so now I have 2. Is that OK? Do the systems counteract each other? Also, after downloading Skybot, my PC CRASHED and NOTHING was responding. The machine could not even log-off for about 7 hours. Should I delete Avira or leave it?No it is not okay and please stop starting new threads every time you logon here. Haven't you noticed the mods keep closing them?
You need to either:
1) follow directions or
2) stop posting or
3) reformat and start from scratch (probably your best bet at this POINT)4) stop taking advice on PC maintenance from your dentist. 5)LOL...

It is better to use one antivirus than two. It may slow your pc performance.ADVICE cmatt give out


Running two anti-virus problems can cause several problems. The main concern is that the programs will "*censored* heads" and this can cause them to not PROPERLY scan, detect, and remove infections. Also, running the two together can hog up a lot of resources. Having more than one program on your computer is fine, but you should only be running one of them at a time.

2172.

Solve : some thing funny in my hjt log please have a look?

Answer»

checked my hjt log and theres a few funny things in it

=======================================
cannot find out what this is
adobearm.exe"
=======================================

the 2 below look like something to do with folding but not the CH folding i have joined

http://www.threatexpert.com/files/Home.exe.html
http://www.file.net/process/[emailprotected]
================================================


HijackThis Detected potential protocol hijack (protocol: trendprotect - {bc3a5f6f-12a0-4b14-a184-32939f413823} - c:\program files\trend micro\trendprotect\msie\wrs.dll). Unless you recognize or want this change we suggest it be fixed.

HijackThis Blank Internet Explorer value for customizesearch.
HijackThis Blank Internet Explorer value for searchassistant.


i tried twice to remove the 2 above but cannot
==============================================
Logfile of Trend Micro HijackThis v2.0.2
SCAN saved at 20:31:49, on 19/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running PROCESSES:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVIRA\AntiVir Desktop\sched.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\FKMonitor\fkmon.exe
C:\Program Files\[emailprotected]\[emailprotected]\[emailprotected]
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Documents and Settings\harold mullan\Application Data\[emailprotected]\FahCore_78.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://uk.search.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://uk.search.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://uk.search.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://uk.search.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TrendProtect - {E3578B37-6346-4EC1-A82B-38273A100DCF} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: TrendProtect - {F83BE649-1CC3-48EE-B2E2-0826CEF3822A} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [fkmon.exe] C:\Program Files\FKMonitor\fkmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: [emailprotected] = ?
O8 - Extra CONTEXT menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.timecomputers.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/Dcode/ActiveX/MSDcode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1219531497140
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178998938015
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179009861625
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/prequal/MotivePreQual.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\wrs.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Google Update Service (gupdate1c99aa9e4bae958) (gupdate1c99aa9e4bae958) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 9192 bytes

Hello Harry. Check this out. It's something new.
Quote

Adobe has released Version 9.2 of the Adobe Reader software for viewing PDF documents. The changes include addressing security vulnerabilities and providing several fixes.

Update: Aside from the normal Adobe Reader Speed Launcher Reader_sl.exe startup entry, Version 9.2 of Reader now also adds an Adobe ARM AdobeARM.exe startup entry. Both are unnecessary and can be safely disabled.

Here's some info. on [emailprotected]hi dave , do you mean delete both of these

Update: Aside from the normal Adobe Reader Speed Launcher Reader_sl.exe startup entry, Version 9.2 of Reader now also adds an Adobe ARM AdobeARM.exe startup entry. Both are unnecessary and can be safely disabled.

my adobe is up to date

i had a look at the folding sight and think i spotted some thing

it is these 2 , i cannot delete them using hjt tool

HijackThis Blank Internet Explorer value for customizesearch.
HijackThis Blank Internet Explorer value for searchassistant.

i think the hjt log looks ok , do you


EDIT; i watched the video i will try it , as i make out i MUST remove anything google and then they will go away
2173.

Solve : Virus Blocks My Following Directions?

Answer»

When going to CONTROL Panel, the virus prevents me from going to Add or Remove Programs so how can I remove spyware? It also has PREVENTED me from removing spyware when I enter "Windows TASK Manager". Certain sites, such as sched.exe, cannot be ended a MESSAGE says.It cannot be terminated and when I attempt to terminate another, the PC gets shut-down completely and re-boots.Closed.

2174.

Solve : McAfee auto unprotecting: followed Read this . . .?

Answer»

So, I had trouble with McAfee auto unprotecting, found your website and FOLLOWED the Read this steps 2-6. Found and removed some viruses, and malware. Attached are my log files. What next?


[Saving space, attachment DELETED by admin]delete your mbam log , re-run your malware and delete what cames up then post a clean log , the log says no action taken Let's SEE if I did it right this time. No ITEMS came up on the malware to delete.

[Saving space, attachment deleted by admin]thats ok now , you have a few items to take out but wait for an expert to help you , harry

2175.

Solve : Question about spyware terminator?

Answer»

Is spyware terminator with virus scan enough to have running for protection and if not what other scanner program is good to USE with spware terminator. On the description page of spyware terminator it says: Spyware Terminator includes Real-Time Protection, HIPS, and antivirus. Effectively remove spyware, adware, trojans, keyloggers, home page hijackers, and malware threats even dangerous threats like Conficker, Mail Skinner or Trojan Vundo. Spyware Terminator is easy-to-use, requires minimal PC resources, and performs ultra fast scans. PROTECT your computer with powerful real-time protection shield, advanced system scanning and safe quarantine for found spyware. Scan your computer manually or SCHEDULE FULL system sweeps. Perform in-depth scans of your computer's hard drives, memory, process, registry and COOKIES to seek out and remove all known spyware threats.NO

You must run a good Anti Virus utililty and keep the definitions up to date. The program you named is not a good av utility. Any additional malware protection is a bonus. Personally I run Kaspersky AV with spyware blaster as passive spyware protection and I scan with MalwareBytes and Super AntiSpyware once a month.

2176.

Solve : hijackthis log but sniper.exe?

Answer»

Logfile of Trend MICRO HIJACKTHIS v2.0.2
Scan saved at 9:27:16 AM, on 10/19/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\SecureIT\SCControlPanel.exe
C:\Windows\System32\mobsync.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80203
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80203
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://toolbar.inbox.com/search/ie.aspx?tbid=80203
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://toolbar.inbox.com/help/sa_customize.aspx?tbid=80203
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - HOSTS: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - (no file)
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: SecurityCoverage Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\Program Files\SecureIT\PopupBlocker.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: ShopAtHomeIEHelper Class - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (file missing)
O3 - Toolbar: ShopAtHome Toolbar - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SCControlPanel] C:\Program Files\SecureIT\SCControlPanel.exe
O4 - HKLM\..\Run: [Lexmark 3100 Series] "C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QUICKTIME Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Garza\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/CursorManiaFWBInitialSetup1.0.1.0.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SecureIT Monitor (SCMonitor) - SecurityCoverage Inc. - C:\Program Files\SecureIT\scmonitor\SCMonitorService.exe
O23 - Service: SecureIT Update Service (scupdateservice) - SecurityCoverage Inc. - C:\Program Files\SecureIT\scmonitor\SCUpdateService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10719 bytes

2177.

Solve : Re:Internet browsers>Yahoo Mail advertisements?

Answer»

I TRIED to CARRY out the Malware Removal process. I ran SPYBOT. Tea Times was not in. I have Avast! so Step A was bypassed. I did Step 1 to remove programs using the provided list of malware. There were none of these to remove. I ran Ccleaner. I tried to run SUPERANTISPYWARE and Malwarebytes but it would not work, presumedly because the SYSTEM is Windows 98. The resident version of Java was noted as being out of date but I could not update it. As the result of these failures, I did not attempt Step 6.

2178.

Solve : newest facebook worm, i just found out... pls help?

Answer»

i have modified this post but i still have basically the same problem. my desktop is now quite ok (though i suspect it is still infected by this new FACEBOOK WORM attached on that sexy lady picture) after i followed the steps advised by your HJT tool. i am using a wifi router and my other desktop (actually my cousin´s) still cannot access yahoo. also, my netbook (an asus EEEPC) experiences connection problems aside from the fact it also cannot access yahoo. whenever i open this notebook (which runs on a LINUX platform while my desktop is windows), i cannot connect to the internet unless i unplug/re-plug my wifi router. i cannot find a HJT which runs on linux because whenever i search for an anti-virus on google (remember, i CANT open yahoo), it takes forever to load-up the page i want to download from. i am only using an anti-virus software which came with this netbook. i truly hope that someone will look into my problem coz it´s already DRIVING me crazy. thank you and more power to this site.

[Saving space, attachment deleted by admin]im really desperate here. my yahoo messenger won´t log-in (but skype go online), yahoo won´t perform searches (internet connection failed) even though i am online, sometimes my internet connection fails (i have to disconnect-reconnect my router), my firewall is on but HJT says it doesn´t detect any firewall, avg free won´t update so i switched to avast. both of my desktop experience the same problem. MBAM and SuperAntivirus doesn´t detect any virus.what should i do? i´ve misplaced my original OS disc so re-installing will be a major no-no... hope you can help me... thanks!Good luck getting a response on here. I posted my problem a couple days ago and still have'nt any kind of response. locotrucker, if you go to your thread there was a response yesterday, Nov.22Sorry. I somehow missed that. Forgive me. I did'nt mean to sound so negative, but I am just frustrated by this problem. Thanks again. reinstall yahoo messenger bro.

avg not updating? look at your update manager if it was disable.
check automatic update

you dont need to reformat your disk just for yahoo.

ym10 is out try it . video calling is one of the new feature
i saw just a couple of hours ago about this new facebook virus. i think my pc is infected with it. it's about this picture of a sexy lady and i think someone from our house clicked on it (my nephews are yougn and may not know what they are clicking at). anyway, it seems like a worm and it doesn't bother me much anymore. still, i like to be sure about it. thanks for the response and more power!

2179.

Solve : My Infected PC Using Netscape?

Answer»

My Windows XP seems to be infected when I use Internet Explorer and Firefox. Just now, I tried using Netscape 7 and it seems to be OK. Except for a balloon in the lower corner saying "Windows Security alert" I am not getting pop=up blockers nor *censored* sites I was getting using IE or Firefox. Why is Netscape not infected? Strange. This is great.Either your pc is infected or it isn't. Using a different browser doesn't get rid of the viruses - it simply hasn't been EFFECTED yet because it's so outdated. The rest of your system is crawling with malware.

Look friend, you've had numerous threads on this forum asking for help with your virus infections and have received some great advice. To date it appears you are doing everything EXCEPT what you are being told to do. Please - either follow the instructions in the other thread(s) to post your hijack this log and take the other steps in the malware section of this forum or don't - but stop with these other nonsense threads.Thanks. I have tried whatever was told to me that I could however pop-ups are blocking certain operations I was ASKED to do so don't say I haven't tried. I scanned my PC using the mrt feature. I did that twice. The program scanned my PC twice and said that the PC had no infected files. It's true the PC came used but it was loaded with Avira antivira to keep-out infections as well as firewall, pop-up blocker and anti-pfishing filters. To be honest, the virus has SPREAD since I have done these operations. I am now getting *censored* sites without typing them in. My postings today were interrupted with *censored* sites appearing out-of-the-blue. You are very right, when I switched over to Netscape 7, the virus appeared to be cleaned-out but within a half-hour, *censored* sites started appearing there too. I might have to hire a professional since I am losing sleep. I guess I should buy an APPLE iMac; they told me they don't get viruses and don't crash. Thanks again for your understanding.

2180.

Solve : Update! My computer is now a doorstop.?

Answer»

I managed to download and run malwarebytes to my infected computer after running a full scan and "fixing" selected items, and there were more than 300 infected files, it restarted and upon restarting I get a message saying: NTLDR is missing, press CTL*alt*DELETE to restart. After doing this, the computer comes right back to the same message. It will not boot back up. I am completely blank as to what to do. Can someone please help? Thanks. http://www.google.com/search?hl=en&rlz=1T4GGLL_enUS304US305&q=ntldr+missing&aq=f&oq=&aqi=g10Hello locotrucker. Here's a link to MS to help with the missing NTLDR problem. If that wasn't bad enough, I have some more bad NEWS. I've checked the HJT log from your other thread and here it is.

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many EXPERTS in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall?

We can attempt to clean this machine but i can't guarantee that it will be 100% SECURE afterwards.

Should you have any questions, please feel free to ask.

Please let us know what you have decided to do in your next post

2181.

Solve : Vista Wierd Messages?

Answer»

I'm on my mom's laptop, because EVEN though the guide is practically idiot-proof, she needs help. I walked her through the scanning process and all the logs are attached. She says that after she updated her JRE that she got these wierd messages, I didn't GET to see the actual messages, but she googled the file in question, a .dll (very helpful), and she read it was a virus. I did the scans and MBAM and SAS both picked up viruses, so it's probably not completely clean right now even after scanning/fixing. I can get any other required information as needed.

We followed ALL the steps, including JRE 6 - 17.

[Saving space, attachment deleted by admin]If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your ANTIVIRUS and any antispyware REAL time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixSomething really bad happened after finishing the combofix scan. She can't get on IE because when she runs it, she gets an Illegal operation error due to a registry key marked for deletion. The shortcut on the desktop does nothing and the one in the start menu says the same, but then after it says "The item you selecte is unavailable. It might have been moved, renamed, or removed. Do you want to remove it from the list?"

She has no other browsers, but I can probably get firefox portable on it.

FF portable gets the same error message as trying to run IE from the quick launch. Nevermind...she just did a factory restore. A restore won't get rid of malware.

Did CF create a log you can post? Look in C:\combofix.txtQuote from: evilfantasy on November 22, 2009, 06:47:23 PM

A restore won't get rid of malware.

Did CF create a log you can post? Look in C:\combofix.txt
Doesn't a factory restore turn the computer back to the way it was when it was MADE? With no user files? Combofix did make a log, but she did the restore before I got a chance to post it. And evil, that wasn't a system restore, it was a factory restore cd provided by Lenovo. Yes you should be good to go. I would run an online scan from BitDefender or ESET just to be sure.Quote from: evilfantasy on November 23, 2009, 09:58:33 AM
Yes you should be good to go. I would run an online scan from BitDefender or ESET just to be sure.
It comes with a 90 day trial of Norton, she's run a full scan after updating, went off without a hitch.
2182.

Solve : is it possible for...?

Answer»

a virus to block access to a hard drive prevent you from booting up into windows?

If so how would go about fixing it?So are you having problems booting into windows or is this just a hypothetical question?yes im having problems booting into windows and im TRYING to get help on fixing this problem because I'd rather not buy a new HD just yet.You need to post the FULL details of your problem.1) Yes it's possible, but not in your case.
2) I told you that you need a sata driver. Starting a new thread won't change that.just remembered that i have a COUPLE custom xp install cds around with sata drivers SLIPSTREAMED so im trying those now.

2183.

Solve : Browser search hijack, SAS, MBAM, HJT inop?

Answer»

Let's TRY this again.

SAS, MBAM, HJT are basically inop. Might be able to start a scan or update, and then they close out. Either don't get results from scan or cannot SAVE them without the PROGRAM closing out.

Eset is updated and scan run, but still have issues. Java is updated and all old Javas have been deleted.

Some errors include:
[emailprotected]:windows\system\32\oledlg.dll
Installer error 1321
Lots of insufficient privaleges when trying to install new anti-? SOFTWARE. I'm not sure what else to do and I'm not sure what else information I can give you.

About the only results I can give is from rootrepeal. Don't know if it will help or not, but it is pasted below.

Thanks in advance for any help. Maybe we can find whoever wrote this and send the to Afghanistan or Iran or something.

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time:2009/11/24 06:12
Program Version:Version 1.3.5.0
Windows Version:Windows XP SP3
==================================================

Drivers
-------------------
Name: 1394BUS.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\1394BUS.SYS
Address: 0xF784E000Size: 57344File Visible: -Signed: -
Status: -

Name: 3xHybrid.sys
Image Path: C:\WINDOWS\system32\DRIVERS\3xHybrid.sys
Address: 0xF679B000Size: 907136File Visible: -Signed: -
Status: -

Name: ACPI.sys
Image Path: ACPI.sys
Address: 0xF77DF000Size: 187776File Visible: -Signed: -
Status: -

Name: ACPI_HAL
Image Path: \Driver\ACPI_HAL
Address: 0x804D7000Size: 2189056File Visible: -Signed: -
Status: -

Name: afd.sys
Image Path: C:\WINDOWS\System32\drivers\afd.sys
Address: 0xF5493000Size: 138496File Visible: -Signed: -
Status: -

Name: ALCXWDM.SYS
Image Path: C:\WINDOWS\system32\drivers\ALCXWDM.SYS
Address: 0xF689D000Size: 4122368File Visible: -Signed: -
Status: -

Name: arp1394.sys
Image Path: C:\WINDOWS\System32\DRIVERS\arp1394.sys
Address: 0xF7A6E000Size: 60800File Visible: -Signed: -
Status: -

Name: atapi.sys
Image Path: atapi.sys
Address: 0xF7797000Size: 96512File Visible: -Signed: -
Status: -

Name: audstub.sys
Image Path: C:\WINDOWS\System32\DRIVERS\audstub.sys
Address: 0xF7ECB000Size: 3072File Visible: -Signed: -
Status: -

Name: BdaSup.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\BdaSup.SYS
Address: 0xF7652000Size: 12288File Visible: -Signed: -
Status: -

Name: Beep.SYS
Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS
Address: 0xF7D5E000Size: 4224File Visible: -Signed: -
Status: -

Name: BOOTVID.dll
Image Path: C:\WINDOWS\system32\BOOTVID.dll
Address: 0xF7C3E000Size: 12288File Visible: -Signed: -
Status: -

Name: Cdfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Address: 0xF78EE000Size: 63744File Visible: -Signed: -
Status: -

Name: cdrom.sys
Image Path: C:\WINDOWS\System32\DRIVERS\cdrom.sys
Address: 0xF794E000Size: 62976File Visible: -Signed: -
Status: -

Name: CLASSPNP.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS
Address: 0xF788E000Size: 53248File Visible: -Signed: -
Status: -

Name: disk.sys
Image Path: disk.sys
Address: 0xF787E000Size: 36352File Visible: -Signed: -
Status: -

Name: DLKRTS.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\DLKRTS.SYS
Address: 0xF798E000Size: 45568File Visible: -Signed: -
Status: -

Name: drmk.sys
Image Path: C:\WINDOWS\system32\drivers\drmk.sys
Address: 0xF797E000Size: 61440File Visible: -Signed: -
Status: -

Name: Dxapi.sys
Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys
Address: 0xF7D1A000Size: 12288File Visible: -Signed: -
Status: -

Name: dxg.sys
Image Path: C:\WINDOWS\System32\drivers\dxg.sys
Address: 0xBF000000Size: 73728File Visible: -Signed: -
Status: -

Name: dxgthk.sys
Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys
Address: 0xF7F2B000Size: 4096File Visible: -Signed: -
Status: -

Name: eamon.sys
Image Path: C:\WINDOWS\system32\DRIVERS\eamon.sys
Address: 0xF2873000Size: 315392File Visible: -Signed: -
Status: -

Name: easdrv.sys
Image Path: C:\WINDOWS\system32\DRIVERS\easdrv.sys
Address: 0xF7A8E000Size: 61440File Visible: -Signed: -
Status: -

Name: epfwtdir.sys
Image Path: C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
Address: 0xF7A2E000Size: 49152File Visible: -Signed: -
Status: -

Name: Fastfat.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fastfat.SYS
Address: 0xF411C000Size: 143744File Visible: -Signed: -
Status: -

Name: fdc.sys
Image Path: C:\WINDOWS\System32\DRIVERS\fdc.sys
Address: 0xF7ACE000Size: 27392File Visible: -Signed: -
Status: -

Name: Fips.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS
Address: 0xF7A7E000Size: 44544File Visible: -Signed: -
Status: -

Name: flpydisk.sys
Image Path: C:\WINDOWS\System32\DRIVERS\flpydisk.sys
Address: 0xF7AFE000Size: 20480File Visible: -Signed: -
Status: -

Name: fltmgr.sys
Image Path: fltmgr.sys
Address: 0xF7777000Size: 129792File Visible: -Signed: -
Status: -

Name: Fs_Rec.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Address: 0xF7D5C000Size: 7936File Visible: -Signed: -
Status: -

Name: ftdisk.sys
Image Path: ftdisk.sys
Address: 0xF77AF000Size: 125056File Visible: -Signed: -
Status: -

Name: gameenum.sys
Image Path: C:\WINDOWS\System32\DRIVERS\gameenum.sys
Address: 0xF764A000Size: 10624File Visible: -Signed: -
Status: -

Name: GEARAspiWDM.sys
Image Path: C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
Address: 0xF796E000Size: 40960File Visible: -Signed: -
Status: -

Name: hal.dll
Image Path: C:\WINDOWS\system32\hal.dll
Address: 0x806EE000Size: 131840File Visible: -Signed: -
Status: -

Name: HIDCLASS.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS
Address: 0xF7229000Size: 36864File Visible: -Signed: -
Status: -

Name: HIDPARSE.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\HIDPARSE.SYS
Address: 0xF7B0E000Size: 28672File Visible: -Signed: -
Status: -

Name: hidusb.sys
Image Path: C:\WINDOWS\System32\DRIVERS\hidusb.sys
Address: 0xF7CEE000Size: 10368File Visible: -Signed: -
Status: -

Name: HTTP.sys
Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys
Address: 0xF138D000Size: 264832File Visible: -Signed: -
Status: -

Name: imapi.sys
Image Path: C:\WINDOWS\System32\DRIVERS\imapi.sys
Address: 0xF793E000Size: 42112File Visible: -Signed: -
Status: -

Name: intelppm.sys
Image Path: C:\WINDOWS\System32\DRIVERS\intelppm.sys
Address: 0xF792E000Size: 36352File Visible: -Signed: -
Status: -

Name: ipnat.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ipnat.sys
Address: 0xF53A8000Size: 152832File Visible: -Signed: -
Status: -

Name: ipsec.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ipsec.sys
Address: 0xF5536000Size: 75264File Visible: -Signed: -
Status: -

Name: isapnp.sys
Image Path: isapnp.sys
Address: 0xF782E000Size: 37248File Visible: -Signed: -
Status: -

Name: kbdclass.sys
Image Path: C:\WINDOWS\System32\DRIVERS\kbdclass.sys
Address: 0xF7AEE000Size: 24576File Visible: -Signed: -
Status: -

Name: kbdhid.sys
Image Path: C:\WINDOWS\System32\DRIVERS\kbdhid.sys
Address: 0xF7CFE000Size: 14592File Visible: -Signed: -
Status: -

Name: KDCOM.DLL
Image Path: C:\WINDOWS\system32\KDCOM.DLL
Address: 0xF7D2E000Size: 8192File Visible: -Signed: -
Status: -

Name: kmixer.sys
Image Path: C:\WINDOWS\system32\drivers\kmixer.sys
Address: 0xF1107000Size: 172416File Visible: -Signed: -
Status: -

Name: KMW_Lib.sys
Image Path: C:\WINDOWS\system32\DRIVERS\KMW_Lib.sys
Address: 0xF7D64000Size: 8192File Visible: -Signed: -
Status: -

Name: KMW_SYS.sys
Image Path: C:\WINDOWS\system32\DRIVERS\KMW_SYS.sys
Address: 0xF52CE000Size: 92032File Visible: -Signed: -
Status: -

Name: KMW_USB.sys
Image Path: C:\WINDOWS\system32\DRIVERS\KMW_USB.sys
Address: 0xF7CF2000Size: 10496File Visible: -Signed: -
Status: -

Name: ks.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ks.sys
Address: 0xF6C8C000Size: 143360File Visible: -Signed: -
Status: -

Name: KSecDD.sys
Image Path: KSecDD.sys
Address: 0xF774E000Size: 92288File Visible: -Signed: -
Status: -

Name: mcdbus.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mcdbus.sys
Address: 0xF6707000Size: 116736File Visible: -Signed: -
Status: -

Name: mnmdd.SYS
Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Address: 0xF7D60000Size: 4224File Visible: -Signed: -
Status: -

Name: mouclass.sys
Image Path: C:\WINDOWS\System32\DRIVERS\mouclass.sys
Address: 0xF7AF6000Size: 23040File Visible: -Signed: -
Status: -

Name: mouhid.sys
Image Path: C:\WINDOWS\System32\DRIVERS\mouhid.sys
Address: 0xF7D02000Size: 12160File Visible: -Signed: -
Status: -

Name: MountMgr.sys
Image Path: MountMgr.sys
Address: 0xF785E000Size: 42368File Visible: -Signed: -
Status: -

Name: mrxdav.sys
Image Path: C:\WINDOWS\System32\DRIVERS\mrxdav.sys
Address: 0xF2A72000Size: 180608File Visible: -Signed: -
Status: -

Name: mrxsmb.sys
Image Path: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
Address: 0xF530D000Size: 455296File Visible: -Signed: -
Status: -

Name: Msfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS
Address: 0xF7B1E000Size: 19072File Visible: -Signed: -
Status: -

Name: msgpc.sys
Image Path: C:\WINDOWS\System32\DRIVERS\msgpc.sys
Address: 0xF79DE000Size: 35072File Visible: -Signed: -
Status: -

Name: msmpu401.sys
Image Path: C:\WINDOWS\system32\drivers\msmpu401.sys
Address: 0xF7ECA000Size: 2944File Visible: -Signed: -
Status: -

Name: mssmbios.sys
Image Path: C:\WINDOWS\System32\DRIVERS\mssmbios.sys
Address: 0xF7636000Size: 15488File Visible: -Signed: -
Status: -

Name: Mup.sys
Image Path: Mup.sys
Address: 0xF767A000Size: 105344File Visible: -Signed: -
Status: -

Name: NDIS.sys
Image Path: NDIS.sys
Address: 0xF7694000Size: 182656File Visible: -Signed: -
Status: -

Name: ndistapi.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ndistapi.sys
Address: 0xF7646000Size: 10112File Visible: -Signed: -
Status: -

Name: ndisuio.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ndisuio.sys
Address: 0xF40B8000Size: 14592File Visible: -Signed: -
Status: -

Name: ndiswan.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ndiswan.sys
Address: 0xF6770000Size: 91520File Visible: -Signed: -
Status: -

Name: NDProxy.SYS
Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Address: 0xF79FE000Size: 40576File Visible: -Signed: -
Status: -

Name: netbios.sys
Image Path: C:\WINDOWS\System32\DRIVERS\netbios.sys
Address: 0xF7A3E000Size: 34688File Visible: -Signed: -
Status: -

Name: netbt.sys
Image Path: C:\WINDOWS\System32\DRIVERS\netbt.sys
Address: 0xF54B5000Size: 162816File Visible: -Signed: -
Status: -

Name: nic1394.sys
Image Path: C:\WINDOWS\System32\DRIVERS\nic1394.sys
Address: 0xF78DE000Size: 61824File Visible: -Signed: -
Status: -

Name: Npfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS
Address: 0xF7B26000Size: 30848File Visible: -Signed: -
Status: -

Name: Ntfs.sys
Image Path: Ntfs.sys
Address: 0xF76C1000Size: 574976File Visible: -Signed: -
Status: -

Name: ntoskrnl.exe
Image Path: C:\WINDOWS\system32\ntoskrnl.exe
Address: 0x804D7000Size: 2189056File Visible: -Signed: -
Status: -

Name: Null.SYS
Image Path: C:\WINDOWS\System32\Drivers\Null.SYS
Address: 0xF7E38000Size: 2944File Visible: -Signed: -
Status: -

Name: nv4_disp.dll
Image Path: C:\WINDOWS\System32\nv4_disp.dll
Address: 0xBF012000Size: 4276224File Visible: -Signed: -
Status: -

Name: nv4_mini.sys
Image Path: C:\WINDOWS\System32\DRIVERS\nv4_mini.sys
Address: 0xF6CE7000Size: 1897408File Visible: -Signed: -
Status: -

Name: ohci1394.sys
Image Path: ohci1394.sys
Address: 0xF783E000Size: 61696File Visible: -Signed: -
Status: -

Name: parport.sys
Image Path: C:\WINDOWS\System32\DRIVERS\parport.sys
Address: 0xF6787000Size: 80128File Visible: -Signed: -
Status: -

Name: PartMgr.sys
Image Path: PartMgr.sys
Address: 0xF7AB6000Size: 19712File Visible: -Signed: -
Status: -

Name: ParVdm.SYS
Image Path: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Address: 0xF7DE4000Size: 6784File Visible: -Signed: -
Status: -

Name: pci.sys
Image Path: pci.sys
Address: 0xF77CE000Size: 68224File Visible: -Signed: -
Status: -

Name: pciide.sys
Image Path: pciide.sys
Address: 0xF7DF6000Size: 3328File Visible: -Signed: -
Status: -

Name: PCIIDEX.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS
Address: 0xF7AAE000Size: 28672File Visible: -Signed: -
Status: -

Name: PnpManager
Image Path: \Driver\PnpManager
Address: 0x804D7000Size: 2189056File Visible: -Signed: -
Status: -

Name: portcls.sys
Image Path: C:\WINDOWS\system32\drivers\portcls.sys
Address: 0xF6879000Size: 147456File Visible: -Signed: -
Status: -

Name: psched.sys
Image Path: C:\WINDOWS\System32\DRIVERS\psched.sys
Address: 0xF675F000Size: 69120File Visible: -Signed: -
Status: -

Name: ptilink.sys
Image Path: C:\WINDOWS\System32\DRIVERS\ptilink.sys
Address: 0xF7ADE000Size: 17792File Visible: -Signed: -
Status: -

Name: PxHelp20.sys
Image Path: PxHelp20.sys
Address: 0xF789E000Size: 35712File Visible: -Signed: -
Status: -

Name: rasacd.sys
Image Path: C:\WINDOWS\System32\DRIVERS\rasacd.sys
Address: 0xF7CCE000Size: 8832File Visible: -Signed: -
Status: -

Name: rasl2tp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
Address: 0xF79AE000Size: 51328File Visible: -Signed: -
Status: -

Name: raspppoe.sys
Image Path: C:\WINDOWS\System32\DRIVERS\raspppoe.sys
Address: 0xF79BE000Size: 41472File Visible: -Signed: -
Status: -

Name: raspptp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\raspptp.sys
Address: 0xF79CE000Size: 48384File Visible: -Signed: -
Status: -

Name: raspti.sys
Image Path: C:\WINDOWS\System32\DRIVERS\raspti.sys
Address: 0xF7AE6000Size: 16512File Visible: -Signed: -
Status: -

Name: RAW
Image Path: \FileSystem\RAW
Address: 0x804D7000Size: 2189056File Visible: -Signed: -
Status: -

Name: rdbss.sys
Image Path: C:\WINDOWS\System32\DRIVERS\rdbss.sys
Address: 0xF537D000Size: 175744File Visible: -Signed: -
Status: -

Name: RDPCDD.sys
Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Address: 0xF7D62000Size: 4224File Visible: -Signed: -
Status: -

Name: redbook.sys
Image Path: C:\WINDOWS\System32\DRIVERS\redbook.sys
Address: 0xF795E000Size: 57600File Visible: -Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF0EB7000Size: 49152File Visible: NoSigned: -
Status: -

Name: SASDIFSV.SYS
Image Path: C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Address: 0xF7B2E000Size: 24576File Visible: -Signed: -
Status: -

Name: SASKUTIL.sys
Image Path: C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Address: 0xF53CE000Size: 151552File Visible: -Signed: -
Status: -

Name: SCSIPORT.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\SCSIPORT.SYS
Address: 0xF66EF000Size: 98304File Visible: -Signed: -
Status: -

Name: serenum.sys
Image Path: C:\WINDOWS\System32\DRIVERS\serenum.sys
Address: 0xF764E000Size: 15744File Visible: -Signed: -
Status: -

Name: serial.sys
Image Path: C:\WINDOWS\System32\DRIVERS\serial.sys
Address: 0xF799E000Size: 64512File Visible: -Signed: -
Status: -

Name: sisagp.sys
Image Path: sisagp.sys
Address: 0xF78AE000Size: 40960File Visible: -Signed: -
Status: -

Name: sr.sys
Image Path: sr.sys
Address: 0xF7765000Size: 73472File Visible: -Signed: -
Status: -

Name: srv.sys
Image Path: C:\WINDOWS\System32\DRIVERS\srv.sys
Address: 0xF17B6000Size: 333952File Visible: -Signed: -
Status: -

Name: swenum.sys
Image Path: C:\WINDOWS\System32\DRIVERS\swenum.sys
Address: 0xF7D54000Size: 4352File Visible: -Signed: -
Status: -

Name: sysaudio.sys
Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys
Address: 0xF4380000Size: 60800File Visible: -Signed: -
Status: -

Name: tcpip.sys
Image Path: C:\WINDOWS\System32\DRIVERS\tcpip.sys
Address: 0xF54DD000Size: 361600File Visible: -Signed: -
Status: -

Name: TDI.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\TDI.SYS
Address: 0xF7AD6000Size: 20480File Visible: -Signed: -
Status: -

Name: termdd.sys
Image Path: C:\WINDOWS\System32\DRIVERS\termdd.sys
Address: 0xF79EE000Size: 40704File Visible: -Signed: -
Status: -

Name: tmcomm.sys
Image Path: C:\WINDOWS\system32\drivers\tmcomm.sys
Address: 0xF0CF9000Size: 180224File Visible: -Signed: -
Status: -

Name: update.sys
Image Path: C:\WINDOWS\System32\DRIVERS\update.sys
Address: 0xF6691000Size: 384768File Visible: -Signed: -
Status: -

Name: usbccgp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\usbccgp.sys
Address: 0xF7B36000Size: 32128File Visible: -Signed: -
Status: -

Name: USBD.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\USBD.SYS
Address: 0xF7D5A000Size: 8192File Visible: -Signed: -
Status: -

Name: usbhub.sys
Image Path: C:\WINDOWS\System32\DRIVERS\usbhub.sys
Address: 0xF7A0E000Size: 59520File Visible: -Signed: -
Status: -

Name: usbohci.sys
Image Path: C:\WINDOWS\System32\DRIVERS\usbohci.sys
Address: 0xF7C36000Size: 17152File Visible: -Signed: -
Status: -

Name: USBPORT.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS
Address: 0xF6CAF000Size: 147456File Visible: -Signed: -
Status: -

Name: usbscan.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbscan.sys
Address: 0xF7CDE000Size: 15104File Visible: -Signed: -
Status: -

Name: USBSTOR.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
Address: 0xF7B3E000Size: 26368File Visible: -Signed: -
Status: -

Name: vga.sys
Image Path: C:\WINDOWS\System32\drivers\vga.sys
Address: 0xF7B16000Size: 20992File Visible: -Signed: -
Status: -

Name: VIDEOPRT.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS
Address: 0xF6CD3000Size: 81920File Visible: -Signed: -
Status: -

Name: VolSnap.sys
Image Path: VolSnap.sys
Address: 0xF786E000Size: 52352File Visible: -Signed: -
Status: -

Name: wanarp.sys
Image Path: C:\WINDOWS\System32\DRIVERS\wanarp.sys
Address: 0xF7A5E000Size: 34560File Visible: -Signed: -
Status: -

Name: watchdog.sys
Image Path: C:\WINDOWS\System32\watchdog.sys
Address: 0xF7B56000Size: 20480File Visible: -Signed: -
Status: -

Name: wdmaud.sys
Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys
Address: 0xF2D97000Size: 83072File Visible: -Signed: -
Status: -

Name: Win32k
Image Path: \Driver\Win32k
Address: 0xBF800000Size: 1847296File Visible: -Signed: -
Status: -

Name: win32k.sys
Image Path: C:\WINDOWS\System32\win32k.sys
Address: 0xBF800000Size: 1847296File Visible: -Signed: -
Status: -

Name: win32k.sys:1
Image Path: C:\WINDOWS\win32k.sys:1
Address: 0xF7B6E000Size: 20480File Visible: NoSigned: -
Status: -

Name: win32k.sys:2
Image Path: C:\WINDOWS\win32k.sys:2
Address: 0xF5403000Size: 61440File Visible: NoSigned: -
Status: -

Name: WMILIB.SYS
Image Path: C:\WINDOWS\System32\DRIVERS\WMILIB.SYS
Address: 0xF7D30000Size: 8192File Visible: -Signed: -
Status: -

Name: WMIxWDM
Image Path: \Driver\WMIxWDM
Address: 0x804D7000Size: 2189056File Visible: -Signed: -
Status: -

2184.

Solve : Hijacked browser won't let me download Highjack this?

Answer»

I am posting this from my work computer, which won't LET me download anything to my thumb drive.
I can go to my home PAGE and that is about it. How do I get highjack this if my browser won't let me go there?
THANKS in ADVANCE for your help. If you are having problems with your work computer do you have an IT department/person that you can get to look at it?It is my home computer that is the problem, i was just saying i am posting this from work and i am not allowed to dl anything for security reasons.Oh ok.

Can you go to a friends house and see if they will let you down load the needed items or have you tried Safe Mode with Networking to see if you can download it that way?I did try safe mode and that didnt work, i guess i have to ASK someone to use their computer

2185.

Solve : autorun viruse?

Answer»

hi i have autorun.inf and recycler viruse in my computer and usb flash drive that DONT CLEAN please help me
2.i want serial number for activation adware ALERT 2009 v4.03618.838.thank for your help. 189-731E
For number 2, we don't give out activation codes for programs. And more importantly, adware alert 2009 is a virus. More specifically, it is a rogue AV program. Please follow the instructions on the Read This First thread in this SECTION and a specialist will help you.

2186.

Solve : Help with search engine redirect virus?

Answer»

Hi, have picked up along the way something that has affected my searches and redirects them to liveliving.com or something like that (i immediately blocked it so any further links wouldn't load up the site).

I have gone through all the steps as requested and have posted the logs below - the hijack this log shows the ISSUE (redirections in a proxyoverride for any searches in google/yahoo) but I'm not quite computer savvy enough to know how to fix it. These logs are after I had run a spybotsearch and destroy, CCleaner, and AVIRA scan over my computer which got rid of most of the stuff affecting my computer but not this redirect one (the one that made me go searching for solutions in the first place that got me here!). Any help will be greatly appreciated, thanks!

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/23/2009 at 09:03 PM

Application Version : 4.30.1004

Core Rules Database Version : 4302
Trace Rules Database Version: 2170

Scan type : Complete Scan
Total Scan Time : 01:11:46

Memory items scanned : 538
Memory threats detected : 0
Registry items scanned : 5395
Registry threats detected : 0
File items scanned : 79596
File threats detected : 7

Adware.Tracking Cookie
C:\DOCUMENTS and Settings\user\Cookies\[emailprotected][1].txt
C:\Documents and Settings\user\Cookies\[emailprotected][1].txt
C:\Documents and Settings\user\Cookies\[emailprotected][1].txt
C:\Documents and Settings\user\Cookies\[emailprotected][2].txt
C:\Documents and Settings\user\Cookies\[emailprotected][1].txt
C:\Documents and Settings\user\Cookies\[emailprotected][1].txt
C:\Documents and Settings\user\Cookies\[emailprotected][2].txt


Malwarebytes' Anti-Malware 1.41
Database version: 3212
Windows 5.1.2600 Service Pack 3

23/11/2009 9:46:00 PM
mbam-log-2009-11-23 (21-46-00).txt

Scan type: Quick Scan
Objects scanned: 116244
Time elapsed: 3 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:49:21 PM, on 23/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\BONJOUR\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Logitech\Easy Synchronization\servicestub.exe
C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\SetPoint\LBTWiz.exe
C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: 78.159.125.60 us.search.yahoo.com
O1 - Hosts: 78.159.125.60 uk.search.yahoo.com
O1 - Hosts: 78.159.125.60 search.yahoo.com
O1 - Hosts: 78.159.125.60 www.google.com.br
O1 - Hosts: 78.159.125.60 www.google.it
O1 - Hosts: 78.159.125.60 www.google.es
O1 - Hosts: 78.159.125.60 www.google.co.jp
O1 - Hosts: 78.159.125.60 www.google.com.mx
O1 - Hosts: 78.159.125.60 www.google.ca
O1 - Hosts: 78.159.125.60 www.google.com.au
O1 - Hosts: 78.159.125.60 www.google.nl
O1 - Hosts: 78.159.125.60 www.google.co.za
O1 - Hosts: 78.159.125.60 www.google.be
O1 - Hosts: 78.159.125.60 www.google.gr
O1 - Hosts: 78.159.125.60 www.google.at
O1 - Hosts: 78.159.125.60 www.google.se
O1 - Hosts: 78.159.125.60 www.google.ch
O1 - Hosts: 78.159.125.60 www.google.pt
O1 - Hosts: 78.159.125.60 www.google.dk
O1 - Hosts: 78.159.125.60 www.google.fi
O1 - Hosts: 78.159.125.60 www.google.ie
O1 - Hosts: 78.159.125.60 www.google.no
O1 - Hosts: 78.159.125.60 www.google.com
O1 - Hosts: 78.159.125.60 www.google.de
O1 - Hosts: 78.159.125.60 www.google.fr
O1 - Hosts: 78.159.125.60 www.google.co.uk
O1 - Hosts: 78.159.125.60
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech BT Wizard] LBTWiz.exe -silent
O4 - HKLM\..\Run: [Easy Synchronization] C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe
O4 - HKLM\..\Run: [basicsmssmenu] "C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Easy Synchronization] C:\Program Files\Logitech\Easy Synchronization\LogitechEasySync.exe --ports
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: SEND to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8921FA45-1637-40A6-937A-60FF4C55A095}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{8921FA45-1637-40A6-937A-60FF4C55A095}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{8921FA45-1637-40A6-937A-60FF4C55A095}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CS3\Services\Tcpip\..\{8921FA45-1637-40A6-937A-60FF4C55A095}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CS4\Services\Tcpip\..\{8921FA45-1637-40A6-937A-60FF4C55A095}: NameServer = 4.2.2.1,4.2.2.2
O18 - PROTOCOL: bw+0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: offline-8876480 - {38B9FEE1-F30C-40AA-BD86-C5C9E55423FE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Basics Service - Seagate Technology LLC - C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: Logitech Easy Synchronization - Unknown owner - C:\Program Files\Logitech\Easy Synchronization\servicestub.exe

--
End of file - 23342 bytes

Hi Guys, this can be closed I managed to fix it myself - seems I am computer savvy enough :-)Lack of symptoms does not mean your computer is clean.

2187.

Solve : BIOS virus question?

Answer»

Ok here it goes. I just wanted to confirm if bios VIRUS can be removed without flashing the bios. Two days ago, the boss' friend called for our help with his computer infected by a virus. One of my co-workers handled it(superior) and claimed to remove the virus. DAY after, the boss' friend called saying he now had a blue screen. Then just now, the boss called that he'll call back after an hour to help him up with that same computer. He said that my co-worker said that it has a bios virus.

My orientation with BIOS virus is this: do a clean install after flashing..

but my co-worker wanted me to do repair install for he already had removed the bios virus.

well, is it possible to remove a BIOS virus without flashing?Quote

well, is it possible to remove a BIOS virus without flashing?

Whoever said it was a BIOS virus might not know exactly what they were talking about. BIOS virus are extremely rare and the chances of getting one without someone physically setting at the computer and putting it there is extremely unlikely. Your not going to GET one from a bad download or malicious website.

A boot sector virus is more likely. All you need to do to find out if it's clean is this.

Download the MBR Rootkit Detector to your desktop.

Go to Start > Run then copy and paste the following red text into the Open field:

"%userprofile%\desktop\mbr.exe" -f

Next, double click on the mbr.exe file and let it finish. A log will come up telling you if an infection is there or not.
that makes my mind clear now. THANK you!

the boss just called. and its having a 0x7b BSOD now.And its kinda rush so i just set aside the bios virus issue.. i did a repair install instead.

I'll do the scan that you mentioned if he still have ISSUES later.Have him run Malwarebytes' Anti-Malware (MBAM) on it. MBAM is free to scan and remove malware with. You only have to pay if you want the full version which blocks malware. The free scanner is very good and if there is something there it should find and remove it.
2188.

Solve : Please help me identify this annoying virus..?

Answer»

OTM asked to reboot directly after processing.. hence, this log came from notepad that popped up afterwards, not from results window:

Quote

All processes killed
========== PROCESSES ==========
Process explorer.exe killed successfully!
========== FILES ==========
C:\ComboFix\N_ folder moved successfully.
C:\ComboFix folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 5287 bytes
->Temporary Internet Files folder emptied: 1257709 bytes
->Java cache emptied: 13696300 bytes
->FireFox cache emptied: 22048708 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 81920 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 2672312 bytes

Total Files Cleaned = 37,95 mb


OTM by OldTimer - Version 3.1.2.0 log created on 11242009_230447

Files moved on Reboot...
C:\WINDOWS\temp\Perflib_Perfdata_494.dat moved successfully.

Registry entries deleted on Reboot...

You should be good to go now.

1. Double click OTM to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. When finished EXIT out of OTM.

----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security ADDON for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before IMMUNIZING. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.I still need to confirm a few things - about multiple programs that has been installed so far, is it safe to delete/uninstall 'em?

here is the list:

- TFC
- HJT
- CCleaner
- malwarebytes
- superantispyware

coz isn't it better to have just one anti spyware/malware to avoid slowdown? which one do you recommend so far: malwarebytes, superantispyware, spywareblaster, spybot - that I should use?

I ran Secunia:
Detection Statistics:
0 Programs Detected in Total
0 Insecure Versions Detected
0 Updated Versions Detected

and installed WOT

and GOT TuneUp utilities from my friend. {it should be sufficient to have all-in-one maintenance tool}

Quote
coz isn't it better to have just one anti spyware/malware to avoid slowdown?

Update and run both SAS and MBAM now and then. The free versions don't run in real time so they won't interfere with anything. You can uninstall HJT. TFC is very good for cleaning out temp files. Use CCleaner daily (or so) and use TFC once a week or every other week.
2189.

Solve : can i remove these files?

Answer»

can i remove these from hjt safely as i do not use bebo and have nothing in the pc for google

O23 - SERVICE: Google UPDATE Service (gupdate1c99aa9e4bae958) (gupdate1c99aa9e4bae958) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cabI'm really looking forward to the movie "The Men Who Stare At Goats". It's about these guys who can do various thing with just their minds. Yes, I'm looking forward to seeing it, but I'm not in it.

i wish you were you would MAKE a good actor , post edited I don't know what bebo is but the first two are for Google toolbar updates and yes, you can remove them.

BTW - let's point out to anyone reading this thread that when I made the first post above, HARRY had forgotten to include the HJT info in his original post. And further btw, I did do some acting in my younger days - but that's a whole other story thanks ALAN , bebo is a social web site that i do not use so its out

quote by alan ; And further btw, I did do some acting in my younger days - but that's a whole other story

and if you keep it up you might have been a big star
You're welcome haryallan There you go i have tried 3 times to remove the google files and rebooted they will not go away they are not in add/

remove also a google updater file in add/remove , when you click it the remove button is not thereYeah, they are like glue. You might want to install the Google toolbar and then uninstall it. See if that helps.i'll try that to-morrow , thank you Sure

2190.

Solve : is the web access protection of eset nod32 v4 good??

Answer»

i m using nod32 v4 for 2 days,i m CONFUSED that is that SCANNING web? database show 4641 (20091127)
,i was using avira security suite 2009 (paid one),avira's web guard WARN me 3 or 4 time in a day and stop web page when it found virus,but nod32 v4 not warn me yet,,,,,,,i have SELECTED two browser in web access protection of nod32 they are ie6 and my default browser opera 10,,,,,,,,,,,and also tell me AVTIVE MODE feature of nod32,,,,thanks

2191.

Solve : My log files for malware/spyware help?

Answer»

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/27/2009 at 11:25 PM

Application Version : 4.31.1000

Core Rules Database Version : 4315
Trace Rules Database Version: 2177

Scan TYPE : Complete Scan
Total Scan Time : 03:19:39

Memory items scanned : 462
Memory threats detected : 0
Registry items scanned : 5946
Registry threats detected : 2
File items scanned : 78152
File threats detected : 3

Rootkit.TDSServ
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDSSserv.sys

Adware.ToolBar888
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SPYBOT - SEARCH & DESTROY\LOGS\CHECKS.080222-2304.TXT

Trojan.Vundo-Variant/F
C:\WINDOWS\SYSTEM32\AZIPCONTMN.DLL
C:\WINDOWS\SYSTEM32\SYSFOLDERAZIPCNT.DLL



Malwarebytes' Anti-Malware 1.41
Database version: 3251
Windows 5.1.2600 Service Pack 2

11/28/2009 5:06:56 PM
mbam-log-2009-11-28 (17-06-56).txt

Scan type: Quick Scan
Objects scanned: 112042
Time elapsed: 13 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
FILES Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:26:22 PM, on 11/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot MODE: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neopets.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O1 - Hosts: 91.121.97.18 thepiratebay.org
O1 - Hosts: 91.121.97.18 www.thepiratebay.org
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3A7814F6-1739-4330-A77B-AD8BD2C341DD} - (no file)
O2 - BHO: (no name) - {3C679BCB-7326-7EFE-0262-2C00CEBFDB9B} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: (no name) - {812D5084-C7D8-4D77-94F9-F3EF0B860216} - (no file)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: {cf6116b7-b4d5-f259-3fb4-ea575ac7a2ba} - {ab2a7ca5-75ae-4bf3-952f-5d4b7b6116fc} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E46E4B5A-0D08-41A8-91C8-85F15C2A1010} - (no file)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.9.0\IEViewBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QT Lite\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: MESSENGER - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.8.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/check/netset/install/gtdownls.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: gydmusvc - gydmusvc.dll (file missing)
O20 - Winlogon Notify: opnljij - opnljij.dll (file missing)
O20 - Winlogon Notify: qomlmmn - qomlmmn.dll (file missing)
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 11976 bytes



My computer is performing poorly and i wanted to do this to help it otu, any help is much appreciated thank you. My computer is an older dell that I'm running XP on.more info please
and wait for an expert Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

  • O1 - Hosts: 91.121.97.18 thepiratebay.org
  • O1 - Hosts: 91.121.97.18 www.thepiratebay.org
  • O2 - BHO: (no name) - {3A7814F6-1739-4330-A77B-AD8BD2C341DD} - (no file)
  • O2 - BHO: (no name) - {3C679BCB-7326-7EFE-0262-2C00CEBFDB9B} - (no file)
  • O2 - BHO: (no name) - {812D5084-C7D8-4D77-94F9-F3EF0B860216} - (no file)
  • O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.9.0\ViewBarBHO.dll
  • O2 - BHO: {cf6116b7-b4d5-f259-3fb4-ea575ac7a2ba} - {ab2a7ca5-75ae-4bf3-952f-5d4b7b6116fc} - (no file)
  • O2 - BHO: (no name) - {E46E4B5A-0D08-41A8-91C8-85F15C2A1010} - (no file)
  • O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
  • O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.9.0\IEViewBar.dll
  • O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] \"C:\Program Files\Malwarebytes\' Anti-Malware\mbam.exe\" /runcleanupscript
  • O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
  • O20 - Winlogon Notify: gydmusvc - gydmusvc.dll (file missing)
  • O20 - Winlogon Notify: opnljij - opnljij.dll (file missing)
  • O20 - Winlogon Notify: qomlmmn - qomlmmn.dll (file missing)
.
Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

----------

You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed WITHOUT users approval but doesn't spy or do anything "bad".

More information:

* ViewMgr.exe - Useless
* Viewpoint to Plunge Into Adware

It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

* Viewpoint
* Viewpoint Manager
* Viewpoint Media Player
* Viewpoint Toolbar
* Viewpoint Experience Technology

----------

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFix
2192.

Solve : repeated virus warning?

Answer» ALRIGHTY. WELL thanks for all your help! i really appreciate it!Your welcome.

SAFE surfing...Quote
alrighty. well thanks for all your help! i really appreciate it!
I hope you realise its taken 2 days to sort out your problem ,and not one so called expert as advised you to back up regularly ,
and reinstall if necessary 2 hours tops Are you saying that what we do is unreliable skyblue?

Also, you might educate yourself a little before shooting off untrue comments.

Quote from: evilfantasy on November 27, 2009, 05:19:50 PM
Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Quote from: Keeping Yourself Safe On The Web
System Restore and Backups

Do a complete virus scan before creating any backups

* System Restore is a component of Microsoft’s Windows Me, Windows XP and Windows VISTA Operating Systems that allows for the rolling back of system files, registry keys, installed programs, etc., to a previous state in the event of a failure.
o How to CREATE a manual Restore Point in System Restore

* Backup refers to making copies of data so that these additional copies may be used to restore the original after a data loss event.


Backup software

Backups can be a invaluable resource

* ERUNT & NTREGOPT A useful freeware utility for users of Windows 2000/XP.
* It’s made up of two parts, ERUNT & NTREGOPT.
o ERUNT will create daily complete backups of your computer’s Registry. Whilst System Restore does the same thing, a corrupt registry file may prevent Windows from booting & this effectively disables System Restore. With ERUNT, you’re able to restore the damaged Registry.
o NTREGOPT works by recreating each registry hive “from scratch”, thus removing any slack space that may be left from previously modified or deleted keys. In other words, it compacts the Registry to a small size which allows Windows to load & perform faster.

* Karen’s Port Replicator is a fantastic freeware backup program that’s easy to use, and it allows scheduled backups.

* Acronis True Image is a very attractive and reasonably priced hard drive imaging program, that can save you in the event your hard drive fails unexpectedly. Acronis supports Microsoft Windows Vista and offers a 15 day trial version.
Quote
Are you saying that what we do is unreliable skyblue?
no a complete waste of time ,if you back up regularly,and reinstall every time, get a lifeYour trolling and telling me to get a life? Ironic...no? Quote
Your trolling and telling me to get a life? Ironic...no?

No No my friend just saying how it is, combo fix this ,combo fix that ,its not rocket science back up regularly and reinstall 2 hours tops
trolling no not me ,look at my previous post,seen the light.
by the way ,you haven't sorted out my logs,check my post, to difficult for you
Quote from: skyblue on November 28, 2009, 05:40:27 PM
by the way ,you haven't sorted out my logs,check my post, to difficult for you

Reinstall then use your backup... Solved.
2193.

Solve : Dell laptop not running like it should(Everything is slow and takes forever!!!)?

Answer»

So back in February I received a Dell Inspirion E1505 laptop from my sister. She had the thing loaded down with crap, all KINDS of messengers, every browser in the book, stupid programs like virtual dj and crap. Anyways I went on and recieved help on this forum which took me step by step eradicating all the *censored* and really made the computer seem brand new. Now I don't know what the *censored* I did but ever since bout middle of August everything just started to seem bogged down. I tried to restore but to no avail. Google Chrome isnt as fast as it USED to be, in fact rather slow to tell the truth, alond with every other thing i try and open and use. Please help me, you GUYS were so great last time and i really do respect you guys for that.

Thanx,

DBZo12I'd start with a full system scan with both your AV utility (with current definitions) AND either Malware Bytes or Super AntiSpyware. Let's see what happens after that.Thenx for talking to me Allan. I appreciate it. Uh could you by chance tell me how to go about that. Sorry man, I guess I'm not the brightest bulb in the lamp. Im very good at following instructions and am knowledgeable enough to navigate around my pc. Thnx AllanOkay
I'll assume you have an anti virus utility installed and resident (if you don't, that's a problem). Open the av utility and run a full scan

Then go to MalwareBytes website (http://www.malwarebytes.org/mbam.php) and download and install the free utility. Then update it and run a full system scan with it.

If you do not have an av installed, let us know.Yea i have avg anti virus, do u think thats a good softwre to be using?http://www.oemsoftwaresource.com

Chances are you will need to RELOAD and restore your PC. You will need your Recovery Disk, save all of your important files, and have a driver disk ready. You can get Recovery Disks at the link provided. Good luck!I'm not a big fan of AVG, but it's okay. I think Avira and Avast are better choices if you want SOMETHING that's free.

2194.

Solve : Please Check Logs?

Answer»

Over the last couple of days i have been experiencing a couple of problems .
Windows 7
Asus laptop x71q series
1, updates not installing (please do not switch of updates installing etc)
2 IE 8 browser ,top half of the browser missing i have to hover with the mouse over browser to bring it into view.
Logs added
skyblue

[Saving space, attachment DELETED by admin]Thanks for the help from you KNOWLEDGABLE so called experts
Waited 2 days nothing, so joined another forum where the malware virus experts are a bit more helpful !!!!.
No no a LOT more helpful ,obviously my problem was not worthy of a reply or to difficult for you lot.
see yaWe don't work for you.

Follow your own advice in the other topic you HIJACKED.

2195.

Solve : Ran HijackThis for the first time,,,,?

Answer»
Hello,

This is the first time I have ran this program. Anyone see anything I need to FIX?

Tom

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:31:41 AM, on 10/16/2009
Platform: WINDOWS XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows DESKTOP Search\WindowsSearch.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop UTILITY) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} (System Requirements Lab) - http://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} (BoardCtl Class) - http://www.intel.com/design/motherbd/boardid/BoardID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 5746 bytes

This needs fixing

[Moderated Message: Please only post advice in the Computer Virus and Spyware Section if you are a Malware Specialist. Thank you.]ankur16 is cleared to post HJT instructions.

Thanks.Just got the memo - understood, Evilfantasy. My apologies, Ankur16.No worries.
2196.

Solve : plugplay svchost.exe constant 50-90% CPU usage?

Answer»

It stopped at 68%, and I got an error message, with this explanation:

Problem signature:
Problem Event Name:APPCRASH
Application Name:OnlineCmdLineScanner.exe
Application Version:0.0.0.0
Application Timestamp:4ae5b372
Fault Module Name:ntdll.dll
Fault Module Version:6.0.6002.18005
Fault Module Timestamp:49e03824
Exception Code:c0000005
Exception Offset:0002a536
OS Version:6.0.6002.2.2.0.768.3
Locale ID:1033
Additional Information 1:255e
Additional Information 2:f9ff8be78a045ca4e1ab55594ec97bdd
Additional Information 3:335d
Additional Information 4:9f2ebf2a6f4386adc8aee72b591c8c2e

Trying one more time.Okay it froze at 68% again, this time I have the file it froze on. SUPER is an open source file audio/video converter. Should I uninstall it and try again?

C:\Program Files (x86)\eRightSoft\SUPER\cygz.dll

Here is the Problem Details log, in case you may need it.

Application Timestamp:4ae5b372
Fault Module Name:ntdll.dll
Fault Module Version:6.0.6002.18005
Fault Module Timestamp:49e03824
Exception Code:c0000005
Exception Offset:0002a536
OS Version:6.0.6002.2.2.0.768.3
Locale ID:1033
Additional Information 1:255e
Additional Information 2:f9ff8be78a045ca4e1ab55594ec97bdd
Additional Information 3:335d
Additional Information 4:9f2ebf2a6f4386adc8aee72b591c8c2eQuote

Should I uninstall it and try again?

Yes please do.Okay, it took a while, but it's finally DONE. It detected 0 malware. When it was finished scanning it never gave me an option for a log. It just gave me an ad for their software.
With a 64bit OS we can't use our normal tools so we have to rely more on the scanners to tell us what's still wrong rather than finding it ourselves which is more thorough. I do still have a few tricks if needed.

How is the computer doing now?
Much better. Svchost (DcomLaunch) is still using around 60% CPU, but that's better than the 80%-100% it was before. I still have no audio even though it says the audio drivers were installed successfully. At the bottom right, next to the clock, it says no audio output device installed. When the svchost problem first occurred I had no sound even though an audio output device was installed. I read that uninstalling and installing the audio device would fix my problem. No luck as of yet.

I ran a Malwarebytes full scan last night and here's the log:

Malwarebytes' Anti-Malware 1.41
Database version: 3251
Windows 6.0.6002 Service Pack 2

12/2/2009 8:37:32 AM
mbam-log-2009-12-02 (08-37-09).txt

Scan type: Full Scan (C:\|)
Objects scanned: 331148
Time elapsed: 8 hour(s), 8 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\partner service (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\partner service (Trojan.BHO) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\ProgramData\Partner\partner.exe (Trojan.BHO) -> No action taken.

I have removed these 3 trojans.

Download OTL to your desktop.

* Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
* When the window appears, underneath Output at the top change it to Minimal Output.
* Check the boxes beside LOP Check and Purity Check.
* Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy and pate the contents of these files, one at a time, into your next reply.

Note: You may need two or more posts to fit them all in.OTL Extras logfile created on: 12/2/2009 9:39:14 AM - Run 1
OTL by OldTimer - Version 3.1.11.4 Folder = C:\Users\Jessica\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.50 Gb Available Physical Memory | 66.79% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 586.40 Gb Total Space | 305.28 Gb Free Space | 52.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: AJKK
Current User Name: Jessica
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] -- "%SystemRoot%\hh.exe" %1
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "%SystemRoot%\hh.exe" %1 File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
chm.file [open] -- "%SystemRoot%\hh.exe" %1
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~2\MICROS~2\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 51 65 25 BD AB 40 CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0324B965-D846-478B-891A-813DDB24501D}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{0A590022-9314-467C-8054-851B62DE173D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1A3A9A13-C805-41DD-B679-2A0929C5E3C1}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{1D4B1889-C629-4F29-B31C-6FB63DDDB71D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{38F56280-66F3-46F0-A955-24F0F7B4DF22}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3A0C1004-687F-4C17-B905-CAED751259A7}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{3BDCE857-9ABF-4B42-99EF-ED7ACE349824}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{3DDE5B14-F56B-4216-A6DF-77E86343CCEB}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{43ABE8BF-3AFF-4051-B383-50734F0DD83D}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{7BAF4D4F-3B3A-492D-B009-FD85BECC0135}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{8491A49C-889F-46F2-A827-143C58014323}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{8FB3570A-BB58-443C-800C-6521A3808228}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{999A109F-94AB-4D17-9176-19AADD4C6775}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{9A3A14D4-75D7-4562-A171-77ACC32D3FD7}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A8F28879-5403-48CD-BC06-C633B0D8DACE}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{AB0D726F-B4F2-43B4-A11A-2F9F9B10AAF9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B919D6B6-8945-4A6C-9CC8-93719EFE69CB}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{BBC38F07-2963-41BF-AB6D-C86103E37FAB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E04EF03B-E884-4763-B953-CF9AD941973D}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{EC218AD9-DBBB-4040-BF85-0DF645B845B8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EFB533C6-588A-4879-89B6-9EB70409AEAE}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0C97C446-8D92-40ED-9736-1D7DF5673014}" = protocol=17 | dir=in | app=c:\users\owner\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{12DB2E64-2940-4A49-8CB4-FE2B9A0BF03D}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{1A9C2D0A-D91C-443A-BF74-7FB23985D560}" = protocol=58 | dir=out | [emailprotected],-203 |
"{25A6E19C-AC11-431E-967D-3985F9C5CFF2}" = protocol=6 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{3222F967-AE98-4A6D-A8D1-9EEDFBD8BA9F}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{375C1985-F843-435E-B5C6-5E43292724A6}" = dir=in | app=c:\program files (x86)\myspace\im\myspaceim.exe |
"{3C6E91EA-06B2-46CE-BB0C-772B4994A410}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5036CC9C-DFD8-4EE0-81AB-BB740AE618BE}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{60963526-0667-46C2-9979-42479DA90341}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{68F56D28-ABB4-4F49-9D41-CF3D0FE65D71}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{69AB3525-C8C4-4627-A887-B25C1270F022}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{6A0F1805-34ED-4463-A10B-6F975E5A5AD6}" = protocol=17 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{772498A6-C972-47F6-B77C-4942812B61B5}" = protocol=6 | dir=in | app=c:\program files (x86)\COMMON files\aol\loader\aolload.exe |
"{88F173AB-CB1A-4F12-BA14-DA1B34EEB07B}" = protocol=6 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{8BDD0E9E-08EE-4DA8-9B4B-4EBBE453AB34}" = protocol=58 | dir=in | app=system |
"{8BE3AC01-C834-4F0F-B71C-18E2F8B5B27C}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{90E57B42-1546-4F43-B18F-D69C5A92D769}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{94D16C12-C5D6-46DC-9F42-321FD34CFFF8}" = protocol=6 | dir=in | app=c:\users\owner\appdata\local\temp\wzse0.tmp\symnrt.exe |
"{96EE35E1-1B54-45DD-B3B2-4228586DA8D0}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{9DE80E45-EC6A-4F75-9542-13D7BDA99733}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{A490E25E-C0D4-468C-B775-A4D63E10C249}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{ACB751B1-8A71-4E58-95B4-60A060418EA1}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{BDD44A77-9375-4837-975F-59E670CC4A3F}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C07C4F28-CB48-441B-A115-79F0B1AB26D0}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{C1331E84-E248-4BCE-BE31-D87A0513EFBC}" = protocol=17 | dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{D2924E90-7A3A-4784-A624-DF4556480B6B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{EA97D10B-217E-499C-B373-8864CF8180B9}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{F8F676C7-08AF-4528-BCA4-65C93A1ED50B}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{FA349BF1-F935-4F58-B3A4-05AA46536FFA}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{FC946A4B-DB03-4929-8416-7E2E93CDB9DF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"TCP Query User{4B4566F5-D4D4-4EDE-A2CD-198D36CDE1F3}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{A63B1E1A-F6DC-4C9B-9137-C7D8AF04B31E}C:\games\summoner\sum.exe" = protocol=6 | dir=in | app=c:\games\summoner\sum.exe |
"TCP Query User{CF0F5477-4B7F-42F5-A2C1-EDB926E5E58A}C:\program files (x86)\microsoft games\close combat iii\cc3.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\close combat iii\cc3.exe |
"TCP Query User{D30D56BD-7444-47BB-B027-6F2D009D0B91}C:\windows\syswow64\dplaysvr.exe" = protocol=6 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"TCP Query User{EF283F6D-2AF9-4CB7-B82B-B5DF0C1C670E}C:\program files (x86)\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |
"UDP Query User{1A0F8AFC-3060-4B7E-A176-A82B59801969}C:\windows\syswow64\dplaysvr.exe" = protocol=17 | dir=in | app=c:\windows\syswow64\dplaysvr.exe |
"UDP Query User{4A32AE20-3269-4D93-B38F-071AEAB93FB2}C:\games\summoner\sum.exe" = protocol=17 | dir=in | app=c:\games\summoner\sum.exe |
"UDP Query User{890BFAE2-20A2-4A58-831E-912EAAE245FA}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{C9A2B3D6-549B-4D20-B6FD-5DF96FF5E2BE}C:\program files (x86)\microsoft games\close combat iii\cc3.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\close combat iii\cc3.exe |
"UDP Query User{E9E7CF27-5637-4129-9421-363AA22E7A86}C:\program files (x86)\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_iP2600_series" = Canon iP2600 series
"{1264D259-A741-4DEE-4898-C4D52DE3ACC5}" = ATI Catalyst Install Manager
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{5759E649-E281-46C2-BB4B-50413623DCDF}" = iTunes
"{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{8E388E35-590A-4600-B19F-66BDE288D386}" = Sun xVM VirtualBox
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9EFC40E3-5F31-4F75-8445-286273F74D8E}" = Apple Mobile Device Support
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D7745F7A-E007-40F4-22AF-6B2F4A936328}" = ccc-utility64
"{DAE239CE-EB9D-4EB3-B0D4-528D6BAA48FD}" = Bonjour
"Agere Systems Soft Modem" = Agere Systems PCI-SV92PP Soft Modem
"CanonMyPrinter" = Canon My Printer
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0C34B801-6AEC-4667-B053-03A67E2D0415}" = Apple Application Support
"{174D5678-D941-433C-BD23-58A5C7B0D36D}" = Jasc Animation Shop 3
"{1B27D1D2-2A46-0D22-02B6-4C968CDADBA5}" = Catalyst Control Center Graphics Full New
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java(TM) 6 Update 16
"{35DE6548-BEF5-6023-2595-28B7AF97C7A1}" = Catalyst Control Center Core Implementation
"{374C2648-1985-FA76-D2DA-4D196DB815F1}" = Catalyst Control Center InstallProxy
"{3949DD93-2AA3-4F88-6DF2-3A474E7C9F20}" = Skins
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{49DC0DD3-1370-41E4-B82C-552EB4985F89}" = Geneforge 4
"{4DDFEC43-2656-9A57-4480-3597422C3738}" = CCC Help English
"{52F67F21-CD2D-B159-8343-0C47211F83A2}" = ccc-core-static
"{54AE3C08-D7D8-45FF-9348-0B4BE0D5A6CB}" = Comcast Universal Installer v1.2
"{5F00DF7E-418B-4CD9-8EC5-781156BCC49E}" = Microsoft Money Shared Libraries
"{605333A6-963F-480C-A358-1301CAA6CFF6}" = TES Construction Set
"{64893225-ADBA-469E-B114-F3B2C1FBBA77}" = RTKXI
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}" = Power Tab Editor 1.7
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{943B6738-4801-4982-90EC-0442EF7AEB16}" = Kaspersky Anti-Virus 2010
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{9759DCDF-3A65-597F-67EB-1EA6E797D39A}" = Catalyst Control Center Graphics Previews Vista
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{AC76BA86-7AD7-5760-0000-800000000003}" = Japanese Fonts Support For Adobe Reader 8
"{AEC0CEBC-0FC7-4716-8222-1C4A742719B1}" = Samsung Master
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{CB0ED3FB-2C23-4D46-536E-9F2DBB965F81}" = Catalyst Control Center HydraVision Full
"{CB11A659-62A8-D40F-AFE1-ECAC8CACAC93}" = Catalyst Control Center Graphics Full Existing
"{D3B1C799-CB73-42DE-BA0F-2344793A095C}" = Catalyst Control Center - Branding
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DC24971E-1946-445D-8A82-CE685433FA7D}" = Realtek USB 2.0 Card Reader
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{ED5DCA6F-5FEA-47CB-83DB-210A468C298B}" = KB0817 Keyboard Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FDC70DF6-69E3-FAB3-DC74-682557A1AD9F}" = Catalyst Control Center Graphics Light
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"Bejeweled 2 Deluxe 1.1.3.2523" = Bejeweled 2 Deluxe 1.1.3.2523
"Canon iP2600 series User Registration" = Canon iP2600 series User Registration
"CanonSolutionMenu" = Canon Utilities Solution Menu
"CCleaner" = CCleaner (remove only)
"Celestia_is1" = Celestia 1.5.1
"Close Combat 3.00" = Microsoft Close Combat III
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"DVD Flick_is1" = DVD Flick 1.3.0.7
"Easy-PhotoPrint EX" = Canon Utilities Easy-PhotoPrint EX
"ENTERPRISE" = Microsoft Office Enterprise 2007
"ESET Online Scanner" = ESET Online Scanner v3
"Fallout" = Fallout
"Fallout2" = Fallout2
"Free Sound Recorder_is1" = Free Sound Recorder v7.9.5
"Guitar Pro 5_is1" = Guitar Pro 5.2
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{80E158EA-7181-40FE-A701-301CE6BE64AB}" = CyberLink MediaShow
"InstallWIX_{943B6738-4801-4982-90EC-0442EF7AEB16}" = Kaspersky Anti-Virus 2010
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.3.0
"Magic ISO Maker v5.5 (build 0276)" = Magic ISO Maker v5.5 (build 0276)
"Magic Video Converter_is1" = Magic Video Converter Trial Version (English) 8.0.1.18
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Marvell Miniport Driver" = Marvell Miniport Driver
"Monkey's Audio_is1" = Monkey's Audio
"Mozilla Firefox (3.5.5)" = Mozilla Firefox (3.5.5)
"Product_Name" = Blades of Avernum
"Smart Copy" = Smart Copy 3.1.1.1
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent gateway Master Uninstall" = Gateway Games
"Winamp" = Winamp
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"InstallShield_{64893225-ADBA-469E-B114-F3B2C1FBBA77}" = RTKXI
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 11/11/2009 10:23:54 AM | Computer Name = AJKK | Source = Application Error | ID = 1000
Description = Faulting application Ati2evxx.exe, version 6.14.10.4213, time stamp
0x49344cdc, faulting module Ati2evxx.exe, version 6.14.10.4213, time stamp 0x49344cdc,
exception code 0xc0000005, fault offset 0x0000000000046458, process id 0x1004, application
start time 0x01ca62da851ca630.

Error - 11/11/2009 10:07:09 PM | Computer Name = AJKK | Source = Application Error | ID = 1000
Description = Faulting application VirtualBox.exe, version 2.2.4.0, time stamp 0x4a202184,
faulting module VBoxOGLrenderspu.dll_unloaded, version 0.0.0.0, time stamp 0x4a202148,
exception code 0xc0000005, fault offset 0x0000000002813c98, process id 0x114, application
start time 0x01ca6333a00bbd60.

Error - 11/11/2009 10:18:08 PM | Computer Name = AJKK | Source = System Restore | ID = 8193
Description =

Error - 11/11/2009 10:28:23 PM | Computer Name = AJKK | Source = System Restore | ID = 8193
Description =

Error - 11/11/2009 10:49:36 PM | Computer Name = AJKK | Source = System Restore | ID = 8193
Description =

Error - 11/11/2009 11:07:46 PM | Computer Name = AJKK | Source = WinMgmt | ID = 10
Description =

Error - 11/14/2009 2:21:50 PM | Computer Name = AJKK | Source = WinMgmt | ID = 10
Description =

Error - 11/16/2009 9:49:19 AM | Computer Name = AJKK | Source = EventSystem | ID = 4621
Description =

Error - 11/16/2009 7:44:49 PM | Computer Name = AJKK | Source = EventSystem | ID = 4621
Description =

Error - 11/17/2009 1:05:47 AM | Computer Name = AJKK | Source = EventSystem | ID = 4621
Description =

[ Media Center Events ]
Error - 6/22/2009 5:32:02 AM | Computer Name = AJKK | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 8/3/2009 3:30:41 AM | Computer Name = AJKK | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/7/2009 5:52:26 PM | Computer Name = AJKK | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 10/8/2009 5:36:02 PM | Computer Name = AJKK | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 8/27/2009 11:29:59 PM | Computer Name = AJKK | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/27/2009 11:30:14 PM | Computer Name = AJKK | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/27/2009 11:30:20 PM | Computer Name = AJKK | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/27/2009 11:30:29 PM | Computer Name = AJKK | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/27/2009 11:30:41 PM | Computer Name = AJKK | Source = cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 8/28/2009 12:09:49 AM | Computer Name = AJKK | Source = Service Control Manager | ID = 7011
Description =

Error - 8/28/2009 12:51:29 AM | Computer Name = AJKK | Source = HTTP | ID = 15016
Description =

Error - 8/28/2009 12:52:49 AM | Computer Name = AJKK | Source = Service Control Manager | ID = 7000
Description =

Error - 8/28/2009 12:52:49 AM | Computer Name = AJKK | Source = Service Control Manager | ID = 7000
Description =

Error - 8/28/2009 12:52:49 AM | Computer Name = AJKK | Source = Service Control Manager | ID = 7000
Description =


< End of report >
OTL logfile created on: 12/2/2009 9:39:14 AM - Run 1
OTL by OldTimer - Version 3.1.11.4 Folder = C:\Users\Jessica\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6002.18005)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.75 Gb Total Physical Memory | 2.50 Gb Available Physical Memory | 66.79% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 586.40 Gb Total Space | 305.28 Gb Free Space | 52.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: AJKK
Current User Name: Jessica
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\Jessica\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
PRC - C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Windows\mHotkey.exe ()
PRC - C:\Windows\ChiFuncExt.exe (Chicony)
PRC - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)


========== Modules (SafeList) ==========

MOD - C:\Users\Jessica\Desktop\OTL.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV:64bit: - (FontCache) -- C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:64bit: - (iPod Service) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV:64bit: - (Ati External Event Utility) -- C:\Windows\SysNative\Ati2evxx.exe (ATI Technologies Inc.)
SRV:64bit: - (ETService) -- C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe ()
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AgereModemAudio) -- C:\Windows\SysNative\agr64svc.exe (Agere Systems)
SRV:64bit: - (yksvc) -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
SRV - (AVP) -- C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Apple Mobile Device) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_64) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (gusvc) -- C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (Bonjour Service) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (Microsoft Office Groove Audit Service) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (RichVideo) Cyberlink RichVideo Service(CRVS) -- C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe ()
SRV - (GameConsoleService) -- C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (StarWindServiceAE) -- C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (Viewpoint Manager Service) -- C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (MSDTC) -- C:\Windows\SysWOW64\Msdtc [2006/11/02 07:34:14 | 00,000,000 | ---D | M]
SRV - (vds) -- C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) -- C:\Windows\SysWOW64\wbem\vss.mof ()


========== Driver Services (SafeList) ==========

DRV:64bit: - (KLIF) -- C:\Windows\SysNative\DRIVERS\klif.sys (Kaspersky Lab)
DRV:64bit: - (KLBG) -- C:\Windows\SysNative\DRIVERS\klbg.sys (Kaspersky Lab)
DRV:64bit: - (klmouflt) -- C:\Windows\SysNative\DRIVERS\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (WpdUsb) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (KLIM6) -- C:\Windows\SysNative\DRIVERS\klim6.sys (Kaspersky Lab)
DRV:64bit: - (kl1) -- C:\Windows\SysNative\DRIVERS\kl1.sys (Kaspersky Lab)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (sptd) -- C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RMCAST) RMCAST (Pgm) -- C:\Windows\SysNative\DRIVERS\RMCAST.sys (Microsoft Corporation)
DRV:64bit: - (HdAudAddService) -- C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:64bit: - (mcdbus) -- C:\Windows\SysNative\DRIVERS\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\DRIVERS\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (yukonx64) -- C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV:64bit: - (RTSTOR) -- C:\Windows\SysNative\drivers\RTSTOR64.SYS (Realtek Semiconductor Corp.)
DRV:64bit: - (AtiPcie) ATI PCI Express (3GIO) -- C:\Windows\SysNative\DRIVERS\AtiPcie.sys (ATI Technologies Inc.)
DRV:64bit: - (AgereSoftModem) -- C:\Windows\SysNative\DRIVERS\agrsm64.sys (Agere Systems)
DRV - (mcdbus) -- C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (int15) -- C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)
DRV - (Tcpip) -- C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) -- C:\Windows\SysWOW64\wbem\mpsdrv.mof ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=1&o=vp64&d=0209&m=dx4200-09
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&s=1&o=vp64&d=0209&m=dx4200-09

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.richarddawkins.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.en gineName: "web-radio Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT168755&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "web-radio Customized Web Search"
FF - prefs.js..browser.search.suggest.enable d: false
FF - prefs.js..browser.startup.homepage: "http://richarddawkins.net/forum/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: [emailprotected]:1.1
FF - prefs.js..extensions.enabledItems: {1395baf2-3aa6-4d0f-83d6-1d9b66a9420d}:0.9.2
FF - prefs.js..extensions.enabledItems: {f01f4cbe-b8a8-4c37-94b3-119d8779e7e0}:1.5.1
FF - prefs.js..extensions.enabledItems: [emailprotected]:2.1
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20090920.2
FF - prefs.js..extensions.enabledItems: *Blocked Russian URL*:9.0.0.736
FF - prefs.js..extensions.enabledItems: {86009AEF-9162-4EBC-B698-FF71D7B6B049}:1.0
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.52
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.2
FF - prefs.js..extensions.enabledItems: [emailprotected]:3.5
FF - prefs.js..extensions.enabledItems: [emailprotected]:2.1
FF - prefs.js..extensions.enabledItems: [emailprotected]:3.8
FF - prefs.js..extensions.enabledItems: {c1dffba0-628e-11d9-9669-0800200c9a66}:3.5.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/11/29 14:04:59 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/11/29 14:04:57 | 00,000,000 | ---D | M]

[2009/03/19 15:33:00 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Extensions
[2009/12/01 17:25:33 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions
[2009/08/29 11:13:15 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\{1395baf2-3aa6-4d0f-83d6-1d9b66a9420d}
[2009/10/31 20:55:07 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2009/11/15 11:22:59 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}
[2009/08/29 11:16:31 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2009/10/28 19:08:01 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2009/10/08 22:09:21 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009/06/02 20:25:56 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\{f01f4cbe-b8a8-4c37-94b3-119d8779e7e0}
[2009/10/08 22:23:52 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\[emailprotected]
[2009/06/26 19:24:35 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\[emailprotected]
[2009/11/08 12:11:48 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\[emailprotected]
[2009/09/23 13:22:15 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\[emailprotected]
[2009/09/28 20:29:03 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\mozilla\Firefox\Profiles\fugfpru6.default\extensions\[emailprotected]
[2009/03/18 10:04:06 | 00,000,878 | ---- | M] () -- C:\Users\Jessica\AppData\Roaming\Mozilla\FireFox\Profiles\fugfpru6.default\searchplugins\conduit.xml
[2009/11/28 15:47:49 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2009/10/10 13:24:59 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions\{86009AEF-9162-4EBC-B698-FF71D7B6B049}
[2009/11/06 08:58:25 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla *Blocked Russian URL*
[2008/06/18 00:43:04 | 00,086,016 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/05/01 20:47:11 | 00,239,432 | ---- | M] (Pando Networks) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npPandoWebInst.dll
[2007/04/16 11:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\plugins\npViewpoint.dll

O1 HOSTS File: (761 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\ievkbd.dll (Kaspersky Lab)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O2 - BHO: (no name) - MRI_DISABLED - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avp] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - Startup: C:\Users\Jessica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O9:64bit: - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll (Kaspersky Lab)
O9:64bit: - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\x64\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.68.166 68.87.74.166
O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~2\mzvkbd3.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 2010\mzvkbd3.dll (Kaspersky Lab)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - Reg Error: Key error. - C:\Windows\SysNative\klogon.dll File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{53084f0e-13bf-11de-86fc-0022684911df}\Shell - "" = AutoRun
O33 - MountPoints2\{53084f0e-13bf-11de-86fc-0022684911df}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
64bit: O35 - comfile [open] -- "%1" %* File not found
64bit: O35 - exefile [open] -- "%1" %* File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2009/12/02 09:31:57 | 00,535,552 | ---- | C] (OldTimer Tools) -- C:\Users\Jessica\Desktop\OTL.exe
[2009/12/02 09:10:08 | 00,000,000 | ---D | C] -- C:\Windows\LastGood
[2009/12/01 11:54:00 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2009/12/01 11:34:46 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2009/11/30 16:17:56 | 00,000,000 | ---D | C] -- C:\Program Files\Realtek
[2009/11/29 21:58:25 | 02,714,112 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
[2009/11/29 21:58:23 | 00,332,320 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll
[2009/11/29 21:58:23 | 00,149,536 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll
[2009/11/29 21:58:22 | 00,363,008 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2009/11/29 21:58:22 | 00,304,640 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2009/11/29 21:58:22 | 00,304,640 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2009/11/29 21:58:22 | 00,198,656 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2009/11/29 21:58:22 | 00,095,744 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2009/11/29 21:58:22 | 00,073,216 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2009/11/29 21:58:21 | 02,191,872 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
[2009/11/29 21:58:19 | 00,166,400 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAC64.dll
[2009/11/29 21:58:19 | 00,108,032 | ---- | C] (Andrea Electronics Corporation) -- C:\Windows\SysNative\AERTAR64.dll
[2009/11/29 21:58:17 | 00,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2009/11/29 19:14:28 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2009/11/29 19:08:39 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2009/11/29 19:08:33 | 00,831,488 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
[2009/11/29 18:26:12 | 01,826,816 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SkyTel.exe
[2009/11/29 18:26:12 | 01,364,480 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\RtlUpd64.exe
[2009/11/29 18:26:12 | 01,261,056 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkAPO64.dll
[2009/11/29 18:26:12 | 00,765,440 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtPgEx64.dll
[2009/11/29 18:26:12 | 00,598,528 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RTSnMg64.cpl
[2009/11/29 18:26:12 | 00,368,672 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkApi64.dll
[2009/11/29 18:26:11 | 06,296,064 | ---- | C] (Realtek Semiconductor) -- C:\Windows\RAVCpl64.exe
[2009/11/29 18:26:11 | 00,245,248 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2009/11/29 18:26:11 | 00,160,768 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\Windows\SysNative\FMAPO64.dll
[2009/11/29 18:26:11 | 00,040,960 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RCoInst64.dll
[2009/11/29 18:24:37 | 00,000,000 | ---D | C] -- C:\Users\Jessica\Desktop\AUDIO_Realtek_ALC888S_Vx64
[2009/11/28 13:37:54 | 00,000,000 | ---D | C] -- C:\Users\Jessica\AppData\Roaming\Malwarebytes
[2009/11/28 13:37:32 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2009/11/28 13:37:30 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/11/28 13:37:20 | 00,022,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2009/11/28 13:37:20 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2009/11/28 13:11:47 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2009/11/28 10:53:15 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2009/11/28 01:14:34 | 06,216,032 | ---- | C] (Microsoft Corporation) -- C:\windowsupdateagent30-x86.exe
[2009/11/27 23:58:32 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Uniblue
[2009/11/25 05:59:08 | 00,880,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\timedate.cpl
[2009/11/25 05:59:07 | 00,714,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\timedate.cpl
[2009/11/24 05:08:12 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Portable DEVICES
[2009/11/24 05:08:12 | 00,000,000 | ---D | C] -- C:\Windows\SysWow64\spool
[2009/11/24 05:08:08 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Portable Devices
[2009/11/24 04:34:51 | 00,449,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMPhoto.dll
[2009/11/24 04:34:51 | 00,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMPhoto.dll
[2009/11/24 04:34:51 | 00,342,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winspool.drv
[2009/11/24 04:34:31 | 00,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2009/11/24 04:34:16 | 01,548,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2009/11/24 04:34:16 | 00,829,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10warp.dll
[2009/11/24 04:34:16 | 00,035,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printfilterpipelineprxy.dll
[2009/11/24 04:34:13 | 00,981,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2009/11/24 04:34:13 | 00,828,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1.dll
[2009/11/24 04:34:13 | 00,189,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WindowsCodecsExt.dll
[2009/11/24 04:34:12 | 00,974,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WindowsCodecs.dll
[2009/11/24 04:34:12 | 00,245,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecsExt.dll
[2009/11/24 04:34:11 | 01,209,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WindowsCodecs.dll
[2009/11/24 04:34:11 | 00,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2009/11/24 04:34:11 | 00,280,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2009/11/24 04:34:11 | 00,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2009/11/24 04:34:11 | 00,135,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2009/11/24 04:34:10 | 00,566,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10level9.dll
[2009/11/24 04:34:10 | 00,411,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PhotoMetadataHandler.dll
[2009/11/24 04:34:10 | 00,328,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxdiag.exe
[2009/11/24 04:34:10 | 00,321,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PhotoMetadataHandler.dll
[2009/11/24 04:34:10 | 00,262,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxdiagn.dll
[2009/11/24 04:34:10 | 00,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxdiag.exe
[2009/11/24 04:34:10 | 00,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxdiagn.dll
[2009/11/24 04:34:09 | 00,519,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d11.dll
[2009/11/24 04:34:09 | 00,486,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10level9.dll
[2009/11/24 04:34:09 | 00,481,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dxgi.dll
[2009/11/24 04:34:09 | 00,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1core.dll
[2009/11/24 04:34:09 | 00,190,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10core.dll
[2009/11/24 04:34:08 | 00,792,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d11.dll
[2009/11/24 04:34:08 | 00,625,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxgi.dll
[2009/11/24 04:34:08 | 00,351,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2009/11/24 04:34:08 | 00,326,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2009/11/24 04:34:08 | 00,287,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10core.dll
[2009/11/24 04:34:07 | 01,554,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\xpsservices.dll
[2009/11/24 04:34:07 | 01,032,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\printfilterpipelinesvc.exe
[2009/11/24 04:34:07 | 00,847,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\OpcServices.dll
[2009/11/24 04:34:06 | 03,068,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xpsservices.dll
[2009/11/24 04:34:06 | 01,548,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2009/11/24 04:34:06 | 01,461,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\OpcServices.dll
[2009/11/24 04:34:06 | 01,142,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\FntCache.dll
[2009/11/24 04:34:06 | 01,064,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DWrite.dll
[2009/11/24 04:34:06 | 01,030,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10.dll
[2009/11/24 04:34:06 | 00,643,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2009/11/24 04:34:06 | 00,161,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1.dll
[2009/11/24 04:34:05 | 01,269,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10.dll
[2009/11/24 04:34:05 | 00,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2009/11/24 04:27:04 | 00,034,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WPDShextAutoplay.exe
[2009/11/24 04:27:04 | 00,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WPDShextAutoplay.exe
[2009/11/24 04:26:58 | 00,037,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\BthMtpContextHandler.dll
[2009/11/24 04:25:56 | 00,077,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceConnectApi.dll
[2009/11/24 04:25:54 | 00,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WpdConns.dll
[2009/11/24 04:25:53 | 02,727,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpdshext.dll
[2009/11/24 04:25:53 | 02,537,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wpdshext.dll
[2009/11/24 04:25:53 | 00,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WpdMtpUS.dll
[2009/11/24 04:25:53 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\WpdUsb.sys
[2009/11/24 04:25:52 | 00,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wpd_ci.dll
[2009/11/24 04:25:51 | 00,110,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WPDShServiceObj.dll
[2009/11/24 04:25:51 | 00,060,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceConnectApi.dll
[2009/11/24 04:25:49 | 00,295,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WpdMtp.dll
[2009/11/24 04:25:48 | 00,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceTypes.dll
[2009/11/24 04:25:48 | 00,100,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceClassExtension.dll
[2009/11/24 04:25:47 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceApi.dll
[2009/11/24 04:25:47 | 00,334,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceApi.dll
[2009/11/24 04:25:46 | 00,433,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WPDSp.dll
[2009/11/24 04:25:46 | 00,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceTypes.dll
[2009/11/24 04:25:46 | 00,113,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceClassExtension.dll
[2009/11/24 04:25:45 | 00,350,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WPDSp.dll
[2009/11/24 04:25:45 | 00,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\PortableDeviceWMDRM.dll
[2009/11/24 04:25:45 | 00,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PortableDeviceWMDRM.dll
[2009/11/24 04:10:33 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\oleaccrc.dll
[2009/11/24 04:10:33 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaccrc.dll
[2009/11/24 04:10:32 | 00,736,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\UIAutomationCore.dll
[2009/11/24 04:10:32 | 00,555,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\UIAutomationCore.dll
[2009/11/24 04:10:32 | 00,315,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll
[2009/11/23 10:47:04 | 00,544,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msvcr71d.dll
[2009/11/23 10:46:13 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Magic Video Converter
[2009/11/15 14:03:40 | 00,609,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comctl32.ocx
[2009/11/15 14:03:40 | 00,164,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\comct232.ocx
[2009/11/15 14:03:40 | 00,040,960 | ---- | C] (vbAccelerator) -- C:\Windows\SysWow64\ssubtmr6.dll
[2009/11/15 14:03:40 | 00,036,864 | ---- | C] (Robdogg Inc.) -- C:\Windows\SysWow64\trayicon_handler.ocx
[2009/11/15 14:03:40 | 00,028,672 | ---- | C] (-) -- C:\Windows\SysWow64\mousewheel.ocx
[2009/11/15 14:03:39 | 00,662,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mscomct2.ocx
[2009/11/15 14:03:39 | 00,212,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\richtx32.ocx
[2009/11/15 14:03:38 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\DVD Flick
[2009/11/07 10:08:16 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe

========== Files - Modified Within 30 Days ==========

[2009/12/02 09:44:04 | 02,883,584 | -HS- | M] () -- C:\Users\Jessica\NTUSER.DAT
[2009/12/02 09:31:59 | 00,535,552 | ---- | M] (OldTimer Tools) -- C:\Users\Jessica\Desktop\OTL.exe
[2009/12/02 08:46:24 | 00,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl
[2009/12/02 08:46:06 | 00,003,344 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/12/02 08:46:06 | 00,003,344 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/12/02 08:46:06 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/12/02 08:45:55 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/12/02 08:43:07 | 00,524,288 | -HS- | M] () -- C:\Users\Jessica\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2009/12/02 08:43:07 | 00,065,536 | -HS- | M] () -- C:\Users\Jessica\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2009/12/02 08:42:54 | 04,092,172 | -H-- | M] () -- C:\Users\Jessica\AppData\Local\IconCache.db
[2009/12/01 11:51:34 | 02,672,312 | ---- | M] () -- C:\Users\Jessica\Desktop\esetsmartinstaller_enu.exe
[2009/12/01 11:02:59 | 03,574,016 | ---- | M] () -- C:\Users\Jessica\Desktop\ComboFix.exe
[2009/11/30 16:10:14 | 00,093,184 | ---- | M] () -- C:\Users\Jessica\Documents\Untitled Document.wps
[2009/11/30 16:10:14 | 00,000,216 | ---- | M] () -- C:\Users\Jessica\AppData\Roaming\wklnhst.dat
[2009/11/30 08:21:40 | 00,100,864 | ---- | M] () -- C:\Users\Jessica\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/29 21:58:31 | 00,525,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\DIFxAPI.dll
[2009/11/29 18:12:15 | 44,377,846 | ---- | M] () -- C:\Users\Jessica\Desktop\AUDIO_Realtek_ALC888S_Vx64.zip
[2009/11/29 16:39:27 | 00,690,960 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2009/11/29 16:39:27 | 00,595,446 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2009/11/29 16:39:27 | 00,101,144 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2009/11/29 14:05:12 | 00,001,780 | ---- | M] () -- C:\Users\Jessica\Desktop\Mozilla Firefox.lnk
[2009/11/29 13:41:00 | 02,603,675 | ---- | M] () -- C:\Users\Jessica\LightningKickingAss.gif
[2009/11/29 13:22:04 | 00,048,525 | ---- | M] () -- C:\Users\Jessica\Physics Bumper Sticker.jpg
[2009/11/29 12:33:00 | 00,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2009/11/29 11:58:51 | 00,000,366 | ---- | M] () -- C:\Windows\tasks\Driver Robot.job
[2009/11/29 11:58:39 | 00,392,400 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2009/11/29 10:18:54 | 00,000,727 | ---- | M] () -- C:\Users\Jessica\Desktop\procexp64 - Shortcut.lnk
[2009/11/28 13:37:35 | 00,000,850 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/11/28 10:53:16 | 00,001,930 | ---- | M] () -- C:\Users\Jessica\Desktop\HijackThis.lnk
[2009/11/28 01:14:38 | 06,216,032 | ---- | M] (Microsoft Corporation) -- C:\windowsupdateagent30-x86.exe
[2009/11/28 00:20:41 | 00,000,732 | ---- | M] () -- C:\Users\Jessica\AppData\Local\d3d9caps64.dat
[2009/11/24 05:06:00 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2009/11/24 04:57:12 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009/11/23 12:57:28 | 00,000,244 | ---- | M] () -- C:\Windows\win.ini
[2009/11/19 16:32:53 | 00,000,016 | ---- | M] () -- C:\Windows\popcinfo.dat
[2009/11/17 20:47:36 | 00,332,320 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtlCPAPI64.dll
[2009/11/17 20:47:36 | 00,149,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SysNative\RtkCfg64.dll
[2009/11/16 11:09:27 | 00,353,296 | ---- | M] (Kaspersky Lab) -- C:\Windows\SysNative\drivers\klif.sys
[2009/11/13 15:16:02 | 00,363,008 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2009/11/13 15:16:02 | 00,198,656 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2009/11/13 15:16:02 | 00,095,744 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2009/11/13 15:16:02 | 00,073,216 | ---- | M] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2009/11/10 16:33:44 | 02,191,872 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
[2009/11/10 16:32:14 | 02,714,112 | ---- | M] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
[2009/11/07 10:08:44 | 00,001,919 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/11/06 08:59:36 | 08,074,812 | -HS- | M] () -- C:\Windows\SysNative\drivers\fidbox.dat
[2009/11/06 08:59:36 | 00,933,948 | -HS- | M] () -- C:\Windows\SysNative\drivers\fidbox2.dat
[2009/11/06 08:59:36 | 00,074,228 | -HS- | M] () -- C:\Windows\SysNative\drivers\fidbox.idx
[2009/11/06 08:59:36 | 00,005,780 | -HS- | M] () -- C:\Windows\SysNative\drivers\fidbox2.idx
[2009/11/06 08:46:37 | 00,143,387 | ---- | M] () -- C:\Windows\SysNative\drivers\klin.dat
[2009/11/06 08:46:37 | 00,104,987 | ---- | M] () -- C:\Windows\SysNative\drivers\klick.dat
[2009/11/03 13:12:38 | 00,000,587 | ---- | M] () -- C:\Users\Jessica\Desktop\zsnesw - Shortcut.lnk
[2009/11/02 13:48:02 | 00,831,488 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll

========== Files Created - No Company Name ==========

[2009/12/01 11:51:34 | 02,672,312 | ---- | C] () -- C:\Users\Jessica\Desktop\esetsmartinstaller_enu.exe
[2009/12/01 11:02:59 | 03,574,016 | ---- | C] () -- C:\Users\Jessica\Desktop\ComboFix.exe
[2009/11/30 16:10:13 | 00,093,184 | ---- | C] () -- C:\Users\Jessica\Documents\Untitled Document.wps
[2009/11/29 18:26:11 | 00,659,968 | ---- | C] () -- C:\Windows\SysNative\RTCOM64.dll
[2009/11/29 18:09:40 | 44,377,846 | ---- | C] () -- C:\Users\Jessica\Desktop\AUDIO_Realtek_ALC888S_Vx64.zip
[2009/11/29 13:40:58 | 02,603,675 | ---- | C] () -- C:\Users\Jessica\LightningKickingAss.gif
[2009/11/29 13:22:00 | 00,048,525 | ---- | C] () -- C:\Users\Jessica\Physics Bumper Sticker.jpg
[2009/11/29 12:33:00 | 00,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/11/29 10:51:10 | 00,000,366 | ---- | C] () -- C:\Windows\tasks\Driver Robot.job
[2009/11/29 10:18:54 | 00,000,727 | ---- | C] () -- C:\Users\Jessica\Desktop\procexp64 - Shortcut.lnk
[2009/11/28 13:37:35 | 00,000,850 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/11/28 10:53:16 | 00,001,930 | ---- | C] () -- C:\Users\Jessica\Desktop\HijackThis.lnk
[2009/11/28 00:20:41 | 00,000,732 | ---- | C] () -- C:\Users\Jessica\AppData\Local\d3d9caps64.dat
[2009/11/24 05:06:00 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2009/11/24 04:57:12 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2009/11/07 10:08:44 | 00,001,919 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/11/03 13:07:29 | 00,000,587 | ---- | C] () -- C:\Users\Jessica\Desktop\zsnesw - Shortcut.lnk
[2009/10/30 10:11:28 | 00,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2009/10/30 10:11:27 | 00,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2009/10/30 10:11:25 | 00,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009/10/30 10:11:24 | 03,596,288 | ---- | C] () -- C:\Windows\SysWow64\qt-dx331.dll
[2009/10/30 10:11:24 | 00,205,824 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009/10/30 10:11:21 | 00,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2009/10/30 10:11:21 | 00,000,547 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll.manifest
[2009/09/17 18:17:14 | 00,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/09/17 18:15:57 | 00,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/09/15 21:03:47 | 00,027,648 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2009/08/27 22:38:56 | 00,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll
[2009/04/27 07:49:26 | 00,230,752 | ---- | C] () -- C:\Windows\patchw32.dll
[2009/03/20 19:21:57 | 00,000,736 | ---- | C] () -- C:\Windows\SamsungMaster.INI
[2009/03/20 08:29:18 | 00,000,228 | ---- | C] () -- C:\Windows\wininit.ini
[2009/03/16 17:02:18 | 00,000,216 | ---- | C] () -- C:\Users\Jessica\AppData\Roaming\wklnhst.dat
[2009/03/16 12:18:34 | 00,100,864 | ---- | C] () -- C:\Users\Jessica\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/03/15 16:23:42 | 00,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2009/03/15 16:23:42 | 00,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2009/03/15 16:23:42 | 00,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2009/02/10 03:42:27 | 00,294,912 | ---- | C] () -- C:\Windows\PIC.dll
[2009/02/10 03:42:27 | 00,000,870 | ---- | C] () -- C:\Windows\mhotkey_reg.ini
[2008/01/20 20:50:05 | 00,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini

========== LOP Check ==========

[2009/09/07 17:15:26 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\Atari
[2009/06/08 10:23:18 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\Azureus
[2009/08/09 13:45:12 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\Bitsoft
[2009/06/15 11:35:18 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\DAEMON Tools Lite
[2009/06/08 12:53:33 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\DAEMON Tools Pro
[2009/05/20 12:00:21 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\Downloaded Installations
[2009/08/09 08:38:24 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\gtk-2.0
[2009/08/11 17:38:36 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\Jasc
[2009/08/01 21:49:29 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\Leadertech
[2009/09/15 19:51:52 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\NCH Swift Sound
[2009/07/15 23:01:27 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\Template
[2009/11/27 23:58:50 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\uniblue
[2009/11/29 10:58:01 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\uTorrent
[2009/03/16 17:13:19 | 00,000,000 | ---D | M] -- C:\Users\Jessica\AppData\Roaming\WildTangent
[2009/11/29 11:58:51 | 00,000,366 | ---- | M] () -- C:\Windows\Tasks\Driver Robot.job
[2009/12/02 08:44:08 | 00,032,618 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data STREAMS ==========

@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:0E799D7F
< End of report >
Okay, let me update you briefly.

Svchost.exe isn't taking a significant amount of processing power any more. My computer is running much better as far as speed is concerned. My only remaining problem is having no sound. I never thought it would be a virus though. I thought having Kaspersky on it's highest setting would stop any viruses. A little naive of me, I admit.

During this little problem, I've been scouring the web for advice or a solution. I've read that Vista and anti-malware programs don't get along very well. Has this problem been fixed in Windows 7?Quote
During this little problem, I've been scouring the web for advice or a solution. I've read that Vista and anti-malware programs don't get along very well. Has this problem been fixed in Windows 7?

I've ran both Vista and now Windows 7 64bit and not had a problem with any anti-malware program and I've tested a bunch of them...

I don't see anything in the logs. I suggest starting a topic in the Microsoft Windows forum for some suggestions on the sound driver. You have already tried everything I can think of. Alright, well let me thank you then. Thank you!!! My comp is running like it first did when we purchased it. evilfantasy for prez!!Your welcome.

Safe surfing...

Here are a few more suggestions to help you tighten up your security.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.
2197.

Solve : I keep getting hacked into wireless?

Answer»

How can i stop a person from hacking into my wireless internet which has a password allready ?? I know if i change my password but i dont want to keep changing it daily is there a why to make him work HARDER or to shut him down with out calling some authority this is a friend of my son....lol some friend huh
thanks
Frank
use WPA/WPA2 and a long passphrase; a "passphrase" is often easier to remember then a password, and is almost always longer, too. Something obvious even- like "my DOG has a BLACK spot on her left ear". Or mix it up with symbols, like "I can't $%^& believe this password!"

WRITE it down and put it in a safe place, just in case you forget. remember you only need to put the passphrase in once for each PC, they usually remember them, which brings up another method by which your sons friend is getting the pw... is he using ONE of your PCs? Because it is likely in that case he isn't really doing anything and the PC is simply "remembering" the password that was used last time for the access point. If not, he may be acquiring the password through one of the PCs that connects to your network; AP passwords are are stored plaintext in the registry.Quote from: fjd2358 on November 29, 2009, 07:42:49 PM

this is a friend of my son

I would suggest you follow the advice of BC.

How do you know he is hacking? Could your son be giving him the password to your wireless?
2198.

Solve : Stubborn google re-direct problem?

Answer»

I notice that there are a lot of issues re google redirects and i am faced with the same problem
I am constantly being redirect to ad sites pertaining to the subject I type in and many TIMES am unable to BACK out of this site

I have on the computer and have used the following programs
spy no more
malwarebytes
avast
SUPERANTISPYWARE
spybot
spyware doctor

all will not find anything

am currantly using laptop for fear of using main computer

if I could get explicit instructions as to remove this problem and as to what SOFTWARE i use to prevent future issues would be a great help

thanking u in advance

I am also informed that if you have a 64 b computer not to use hijack this???


Requested Logs;

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/02/2009 at 09:35 PM

Application Version : 4.31.1000

Core Rules Database Version : 4330
Trace Rules Database Version: 2185

Scan type : Complete Scan
Total Scan Time : 01:02:24

Memory items scanned : 638
Memory threats detected : 0
Registry items scanned : 9254
Registry threats detected : 0
File items scanned : 37184
File threats detected : 0



Malwarebytes' Anti-Malware 1.41
Database version: 3284
Windows 5.1.2600 Service Pack 3

12/03/09 8:23:50 AM
mbam-log-2009-12-03 (08-23-50).txt

Scan type: Quick Scan
Objects scanned: 125639
Time ELAPSED: 7 minute(s), 7 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Please Help

2199.

Solve : Trojan SHeur.AWKY?

Answer»

Hi,

I found your site yesterday and I'm hoping you can help me.

We've had this virus for a while but it was in the userinit file so we couldn't delete it and didn't know how to get rid of it.

I have followed the "read this before requesting malware..." and here are the logs.

It doesn't seem to have stopped the computer working but it can't be good to have it.

Thanks for giving your time to help

Jane McDonald

.................................
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/30/2009 at 02:59 PM

Application Version : 4.31.1000

Core Rules Database Version : 4319
Trace Rules Database Version: 2177

Scan type : Complete Scan
Total Scan Time : 02:38:21

Memory items scanned : 523
Memory threats detected : 0
Registry items scanned : 6486
Registry threats detected : 22
File items scanned : 120017
File threats detected : 149

Adware.HotBar/ShopperReports (Low Risk)
HKU\.DEFAULT\Software\MICROSOFT\Windows\CurrentVersion\Ext\Stats\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{100EB1FD-D03E-47FD-81F3-EE91287F9465}

Trojan.Agent/Gen
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F88A6F5-908C-4C28-9A81-829953C5F5C5}
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F88A6F5-908C-4C28-9A81-829953C5F5C5}

Unclassified.Unknown Origin
HKCR\PROTOCOLS\Filter\text/html
HKCR\PROTOCOLS\Filter\text/html#CLSID

Adware.Tracking Cookie
C:\Documents and Settings\User\Cookies\[emailprotected][2].txt
C:\Documents and Settings\User\Cookies\[emailprotected][4].txt
C:\Documents and Settings\User\Cookies\[emailprotected][2].txt
C:\Documents and Settings\User\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User\Cookies\[emailprotected][1].txt
C:\Documents and Settings\User\Cookies\[emailprotected][1].txt

Registry Cleaner Trial
HKCR\Install.Install
HKCR\Install.Install\CLSID
HKCR\Install.Install\CurVer
HKCR\Install.Install.1
HKCR\Install.Install.1\CLSID

Adware.MyWebSearch/FunWebProducts
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE\0000#DeviceDesc

Adware.Zango Toolbar/Hb
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\1070503.sdf
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\2633103.sdf
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\ASPL1.dat
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\hstat\34f0.dat
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\hstat
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\127887
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\13546
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\221757
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\23149
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\23901
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\26340
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\27503
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\29115
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\32242
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\34123
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\34137
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\34186
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\345676
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\34632
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44228
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44293
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44323
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44750
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\44878
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\45820
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\52335
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\540999
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\54473
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\59844
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\61837
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\67215
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\67226
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\67466
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\751219
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\751227
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\7521
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\79257
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\87439
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\87579
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\94407
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95676
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95803
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95825
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\95828
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\97741
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML\98248
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\TooltipXML
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic\ustat
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\dynamic
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\btntrans1.dat
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\buttondir.txt
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\components.cdf
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\default.cdf
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_511745-514279.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_bidzC_ZT_IE-ca.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_bidzC_ZT_IE-us.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_categorize.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_comparison.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_explorer-Mails.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_explorer-people.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_favorites.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_Games.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_Hide.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_hotbarcom.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_Hotmail.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_hsskin.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_jemster.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_jemsterie.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_jemsteruk.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_jobsearch.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_Mails.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_MobileSidewalk.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_MobileSW-US.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_new.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_premium.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_reun.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_ringtones.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_SearchBoxTrapper.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_searchfor.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_searchgo.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_weather.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Default_yellowpages.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_1000.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_2000.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_3000.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_bar.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_bbar1.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_logos.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\d_icons_buttons_other.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\email-def-511724-548964.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\email-def-511724-9595.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\email-t1-bg.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\icons2.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\keywords.idx
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\keywords1.dat
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\layout.cdf
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\linkpathlegal.txt
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\progress.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\sales_buttons.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\s_icons_buttons.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\t2_bg.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\theweb.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\top7.cdf
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\Top7_theweb.mnu
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\tsd_bg.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1\zango.res
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\1
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\BtnTrans.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\BtnTrans1.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\buttondir.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\default.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_1000.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_2000.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_3000.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_bar.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_bbar1.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_logos.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\d_icons_buttons_other.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\email-t1-bg.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\icons2.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\keywords.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\keywords1.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\layout.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\linkpathlegal.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\progress.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\sales_buttons.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\samplegroups2.txt
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\samplegroups2.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\s_icons_buttons.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\t2_bg.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\top7.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\tsd_bg.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad\zango.xip
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static\DownLoad
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar\static
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0\ZangoToolbar
C:\Documents and Settings\User\Application Data\ZangoToolbar\v3.0
C:\Documents and Settings\User\Application Data\ZangoToolbar\zbar.log
C:\Documents and Settings\User\Application Data\ZangoToolbar

Trojan.Unclassified/BraviaX
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run#braviax
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run#braviax

....................................... ...............
Malwarebytes' Anti-Malware 1.41
Database version: 3261
Windows 5.1.2600 Service Pack 3

30/11/2009 16:07:06
mbam-log-2009-11-30 (16-07-06).txt

Scan type: Quick Scan
Objects scanned: 105302
Time elapsed: 8 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
....................................... ...................
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:01:59, on 30/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\system32\atwtusb.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\OLYMPUS\DeviceDetector\DevDtct2.exe
C:\Program Files\SAGEM\SAGEM [emailprotected] 800-840\dslmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\Sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://uk.search.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://uk.search.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1150595.exe -Update -1150595 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322)" -"http://www.arcadetown.com/nannymania/playiframe.asp"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\OLYMPUS\DeviceDetector\DevDtct2.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM [emailprotected] 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\User\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://toolbar.imageshack.us
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload WRAPPER) - http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.ezarchive.com/zbox/app/ImageUploader3.cab/_file-/ImageUploader3.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photobox.co.uk/sg/common/uploader_uni.cab
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://upload.mediamax.com/Upload/XUpload.ocx
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - PROTOCOL: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: cru629.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 12772 bytes

2200.

Solve : Here are my 3 logs. Virus or something else I need to delete ??

Answer»

Quote

EarthLink Accelerator
EarthLink Common Authentication
EarthLink MailBox
EarthLink Wireless High Speed

Have you tried using Revo uninstaller to remove these?

Download Revo Uninstaller

* Open Revo and let the list populate (can take several seconds to finish).
* Right click what you want to uninstall and choose Uninstall
* Next choose Advanced then click Next
* This will (try to) launch the programs built in uninstaller and go through the normal uninstall process.
* If the uninstaller fails just continue on with the Revo instructions.
* Once complete: In Revo Uninstaller click Next and Revo will scan the registry for leftovers.
* This scan can take several seconds.
* Once the results are shown LOOK at each one to ENSURE they are all related to the program that was uninstalled.
* Choose Select All then click Delete
* Click Next and Revo will scan for any files or folders that were not removed.
* If any files/folders are found choose Select all > DeleteOk, I think I was successful. I only found one Earthlink program to uninstall. Did I miss anything ? I tried to uninstall Earthlink toolbar, but it gave me a message that said something like, "the uninstaller can only be USED with programs that are currently installed".

I was also having a problem with Logitech.....is that still there, too? Thanks in advance !Quote from: TriciaM on November 14, 2009, 07:33:47 PM
Ok, I think I was successful. I only found one Earthlink program to uninstall. Did I miss anything ? I tried to uninstall Earthlink toolbar, but it gave me a message that said something like, "the uninstaller can only be used with programs that are currently installed".

If you already have ComboFix be sure to delete it and download a new copy.

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is IMPORTANT that it is saved directly to your Desktop

DO NOT run it yet!

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Driver::
ADSFilter
ADSMonitor
EarthLinkSafeConnectDriver
EarthLinkSafeConnectFilter
EarthLinkSafeConnectShim

Folder::
c:\program files\earthlink

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze


Quote from: TriciaM on November 14, 2009, 07:33:47 PM
I was also having a problem with Logitech.....is that still there, too? Thanks in advance !

What problem?

What model of Logitech QuickCam is it?Hopefully the combofix log is attached....

[Saving space, attachment deleted by admin]Ref to Logitech quickcam, I think it is the Fusion. I cannot find the software, but I will look further.Quote from: TriciaM on November 21, 2009, 07:12:40 PM
Ref to Logitech quickcam, I think it is the Fusion.

If that's it then this is the software.

QuickCam® Fusion http://www.logitech.com/pub/techsupport/quickcam/qc1051enu.exe

If not then the rest of the downloads are here. Webcam software and driver support for Windows


* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /Uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.
The above was done. Thanks.Ok, I thought I was done....I just got an error message stating that it is not safe to continue and that I may be infected with the file patching virus called "virut"......the error message is the tan/blue window.....Download Dr.Web CureIt and save it to your desktop.

Scan with DrWeb-CureIt as follows:

  • Double-click on drweb-cureit.exe and then click Start
  • An information notice will appear, click OK.
  • This starts a short scan that will scan the files currently running in memory.
  • If you get a prompt to buy the full version just exit out of the window. The scanner will still work without buying the full version
  • If or when something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Settings > Change Settings
  • Under the Scanning tab UNcheck Heuristic analysis and click OK
  • Back at the main window, select the Complete scan button and then click the Green Arrow Start Scanning button on the right and the scan will start.
  • Click Yes to all if it asks if you want to cure/move any file(s).
  • When the scan is done.
  • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
.
* After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
* Copy and paste that log in the next replyIt's not done scanning...however...it found this: C:\windows\system32\DSRIRREM.EXE and told me that it is infected with Trojan.Downloader.origin and cannot be cured.DSRIRREM.EXE;C:\WINDOWS\system32;Trojan.DownLoader.origin;Incurable.Moved.;
gtdownde_110.ocx;C:\WINDOWS\system32;Probably DLOADER.Trojan;Incurable.Deleted.;
RegUBP2b-Tricia & Roger.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.;
DSRIRREM.EXE;C:\I386;Trojan.DownLoader.origin;Incurable.Moved.;
A0216056.EXE;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1818;Trojan.DownLoader.origin;Incurable.Moved.;
A0216058.reg;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1818;Trojan.StartPage.1505;Deleted.;
A0216059.EXE;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1818;Trojan.DownLoader.origin;Incurable.Moved.;
There is no indication of a Virut infection.When the Dr. Web program scanned and moved items (viruses), did I need to do something to those? And hopefully, this isn't a dumb question, but where exactly does the Dr. Web move them to? Thanks for all your help !Also, I wanted to ask, is it safe to say that these viruses are ALLOWED in by me, by opening attachments, "accepting" on Zone Alarm, or downloading games, etc. ? Thanks again !I believe the quarantined files go to C:\Program Files\DrWeb\Quarantine or C:\{user profile}\DrWeb\Quarantine

Quote from: TriciaM on November 30, 2009, 07:26:53 PM
Also, I wanted to ask, is it safe to say that these viruses are allowed in by me, by opening attachments, "accepting" on Zone Alarm, or downloading games, etc. ? Thanks again !

Yes usually they get in by clicking on something. Not all antivirus will stop a rouge program since it isn't actually a virus.