Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2251.

Solve : I was hit by malware. WOT said I was diverted to trovi.com Am I clean now??

Answer»

Yes. You helped me greatly.

I'm looking for the pop up message entering your site, it's missing. Tell me something about how our elected officials are trying to hurt your cause and how I can sign up.

Quote

I'm looking for the pop up message entering your site, it's missing. Tell me something about how our elected officials are trying to hurt your cause and how I can sign up.
I have no idea what you're talking about. Do you mean that you're GETTING a popup on this site?Yes I was getting a pop up site when I was initially asking you for help. On 14 Sept, I asked you about how I can help you. Look at that dated thread.If I remember correctly, it said that congress was initiating laws preventing folks like you from the free enterprise in which you exist.

I cannot believe I am the first to bring this to your attention.

Please advise.

TomThis is the first I've heard of it. Are you still getting the pop-up?No.Ok, if there is nothing else, we can do some clean up.

This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove DISINFECTION tools
  • Create Registry backup
  • Purge System Restore Points
  • Re-set system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.
*****************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*********************************************
I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
2252.

Solve : Extremely S L O W Laptop?

Answer»

i ve got the same issue, if there is no other solution i will have to format the hard disk and SET it up new.
maybe the partition with the restore files is broken?Quote from: anabel365 on September 06, 2014, 11:44:57 PM

i ve got the same issue, if there is no other solution i will have to format the hard disk and set it up new.
maybe the partition with the restore files is broken?
It's quite possible that your problems are not related to this thread. Please start a new thread of your own and I'll help you there.Quote
Each time it takes me to the HP recvery manager where my only chices are set computer back to factory setting or go to a restore point. I tried restore point and it says there are none.
Here's how to create a disk that will allow you to boot your computer and save all your important data then will have to do the Recovery.

Download the OTLPE Standard REATOGO Windows Recovery Environment.
  • Place a BLANK CD-R disc in to your CD burning drive.
  • Download OTLPEStd.exe and double-click on it to burn to a CD using an ISO Burner. One can be found here.
  • Reboot your system using the boot CD you just created.
  • Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • Now you should be able to save all your important data to an external drive or DVD's
I did what you said. It started to boot up with the CD and I could see the LOADING of the RealX paltform, then....the blue screen of death ! LOL ! Basically telling me a problem has been detected with window and is shutting down to prevent damage to my computer.BSOD's usually result from hardware or driver problems. Here are some instructions about how to test your hard drive and the RAM.

Run hard drive diagnostics: tacktech.com
Make SURE, you select tool, which is appropriate for the brand of your hard drive.
Depending on the program, it'll create bootable floppy, or bootable CD.
If downloaded file is of .iso type, use ImgBurn: imgburn to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable.
For Toshiba hard drives, see here:

Note : If you do not know how to set your computer to boot from CD follow the steps here
***********************************************
That could be a problem with bad RAM. Please run this check just to eliminate that possibility.
Test your RAM here.
I downloaded the file, but its a EXE file. I transfered it to a CD and tried to boot from the infected laptop but it wouldnt run.
Some of info that may help. I did try Kaspersky Rescue 10 program. It came up with over 1200 trojans and viruses and deleted them.

ANy other suggestions...?You will need to download the ISO for creating a bootable CD of the other one for USB for Windows.
2253.

Solve : Three Questions about IP attacks?

Answer»

I am browsing in the public library .

1. May be the conduit virus dued to an indirect attack to the public library server with a static IP ?
2. When I abandon the public library i don't observ any problem after removing the viruses. So may be more difficult to infect if you have a dynamic IP ?
3. When I return to the public library and inmediately after LOG in in the wifi connection i observ my system stressed, but I have no virus from the day before. So how can i protect against this situation ?

Best Regards
Quote

2. When I abandon the public library i don't observ any problem after removing the viruses. So may be more difficult to infect if you have a dynamic IP ?
3. When I return to the public library and inmediately after log in in the wifi connection i observ my system stressed, but I have no virus from the day before. So how can i protect against this situation ?
How do you know you have removed the infections? What protection do you have on your computer?I am trying.
But you don't answer any question ?....
Can you answer please

I am trying with AVG 2014
malware bytes , adwcleaner, SAS, all the complete CH antivirus recommended tools.
The only thing I can do is ask you to do these scans and post the logs to make sure the computer is clean.

Please download AdwCleaner by Xplode onto your Desktop.

Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon.



If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run.
When the AdwCleaner program will open, click on the SCAN button as shown below.



AdwCleaner will now start to search for malicious files that may be installed on your computer.
To remove the files that were detected in the previous step, please click on the Clean button.



AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer.
Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply.
*********************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.
  • It should update automatically if the computer is connected to the internet.
  • Click on Threat Scan and click on Scan Now.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete make sure all the infections have "QUARANTINE" selected in the Action box.
  • Click on "Apply actions" You may be asked to Restart your computer to completely remove the infections.
  • When DISINFECTION is completed you can click on "Copy to Clipboard".
  • Paste the log in you next reply (CTRL+ V)
*************************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.I have done these steps a million times.
And I would LIKE to see the logs.
2254.

Solve : Multiple processes of wmpnscfg.exe??

Answer»

Used space is 47.6 GB
Free Space is 399 GB

Speed test
Ping - 155 ms
Download speed : 9.22 ms
Upload speed: .92 ms


That is much too slow. You should contact your ISP. What should I say to them?

off TOPIC: I've NOTICED that sometimes wmpnscfg.exe still pops up for a second when my WIFI cuts off.
Sometimes when I'm next to the router the bars on wifi icon disappear?
And still iexplore, avg tune up pop up Tell them that you did a speedtest and it was very slow. If you want to RUN speedtest again you can rate your ISP by clicking down in the lower left HAND corner. I'm sure it will be rated very low. Also tell them that you keep losing your connection.

2255.

Solve : Slow computer and internet problems. Think Infected??

Answer»

Hello Superdave!
Just thought I would update you on what I have found out. went out and bought a new hard drive and reinstalled OS. A bit tedious, but got all windows updates done, plus all the programs and applications that my mother uses, all updated. also restored files from back-ups taken from old hard drive. After all was said and done computer was running like a dream for about 3 WEEKS and then mom calls me and says she has a problem.
Well I noticed right off it was pretty much doing everything that I started this thread for (slow boot up, programs taking over a minute to open, getting page cannot be displayed in IE, and hanging in firefox. just a slow and sick computer again. first off I ask her if she had downloaded or installed any new programs or applications. She told me that she had trouble with her online banking and had to call them and I guess they told her it would be in her best interest to install an application called Trusteer Rapport and PROCEEDED to walk her through installing it. my thought was to restore the computer to an earlier time before she installed Trusteer Rapport. Once in restore points I noticed that there was a restore point for everyday and even several times a day that said "installed Rapport". I then went back to a restore point before the install of Rapport and it was successful. After that the computer started running like a charm again.
Told Mom it could have been a bad install, so proceeded to install it again and the same problem's started occurring again. So just uninstalled it and things went back to normal again. Told Mom to GO into her bank and see if she had any problems with getting in and doing things. She had no problems, so I figure she didn't have to have that application.. so it will be left off her computer. She is happy now again !
I noticed by going through this thread that she had Trusteer Rapport on her old hard drive installed too,(dunno why I didn't question it then ). We did have old hard drive tested and was told it was starting to fail, but I started thinking maybe this Rapport app could have been a prominent cause of her problems also, as this hard drive is brand new and experienced much of the same problems! Started doing some research on Trusteer and noticed a lot of other people had the same problems after installing it, with slow and sluggish computers.
Anyhow Just thought I would update you with this information and possibly maybe help someone else on how this was solved. Thanks again for all your help!! Have a great day !
Quote

I guess they told her it would be in her best interest to install an application called Trusteer Rapport and proceeded to walk her through installing it.
I have that on my computers and it's a great protection and you can USE it protect not only your banking sites but any SITE you wish. I don't have any problems with my computers. This is the first time I've heard of this. I'm sure the people at Trusteer could give you some insight into this problem. Thanks for the update.
2256.

Solve : Anybody know about Arcade Yum??

Answer»

This was a particular game which was clicked on by accident. I began seeing double underlined words in my text I couldn't get rid of. I just recently removed Google Chrome from my system, now the underlines seem to be gone. However, is this just a game, or is it a virus of some sort they don't tell you about? Is there more I need to do? I hate to lose Google Chrome since I need it for so many applications. Any other suggestions?I can't find too much info about that program that indicates that it is malicious. Why not re-install Chrome and see what happens. We can always run some scans to see what's on your computer.My wifes computer recently started doing the same thing... "Double Underlined Words in text of websites etc". And I am glad i read your post here. While I am not authorized to make any suggestions here in this thread, I have some info on the Arcade YUM, as well as now KNOW what to target on my wifes system that is having the same issue.

On Arcade YUM .... My wife saw an ad for Donkey Kong Arcade Classic for free play through YUM. She installed that and then it left her at here: http://www.arcadeyum.com/ where Donkey Kong was nowhere to be found, until you manually search for it and come up here: http://www.arcadeyum.com/Search?term=donkey

She has AVG Antivirus as well as MalwareBytes Free editions. Both come up with no problems detected.

The double underlined text on the website that seems to happen now ever since she installed that game have hyperlinks to www.coupons.com and the links are just as reported at this site here: http://malwaretips.com/blogs/green-double-underlined-ads-removal/

Last night i was looking into this problem and didnt put this problem together with Arcade YUM that she installed a few days prior. So I want to thank you for sharing this info as for now I know what i will be uninstalling right away as well as hopefully the hyperlink hijacker type of adware can be easily removed with its uninstallation.

The scary part is that MalwareBytes and AVG detected no problems, yet there is a definite problem!

Please download AdwCleaner by Xplode onto your Desktop.

Before starting AdwCleaner, close all open programs and INTERNET browsers, then double-click on the AdwCleaner icon.



If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run.
When the AdwCleaner program will open, click on the Scan button as shown below.



AdwCleaner will now start to search for malicious files that may be installed on your computer.
To remove the files that were detected in the previous step, please click on the Clean button.



AdwCleaner will now prompt you to save any open files or data as the program will need to REBOOT the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer.
Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply.
*********************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows VISTA or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.

2257.

Solve : PUP.Optional.MySearchDial.A?

Answer»

Please give me an update on how your computer is working now.malwarebytes is still picking up the PUP.Optional.MySearchDial.A

Well I found out how to look at the invisible folders through "Folder Options" and traced it to "C:\Users\Saajuk\AppData\Local\Google\Chrome\User Data\Default\Prefrences" which is where malwarebytes is telling me "MySearchDial" is located at (pls look at picture)


http://i928.photobucket.com/albums/ad126/Saajuk/Capture227_zps1efcdf39.png


There are 2 preferences. Ones "Preferences~RF4cf33.TEMP" (which looks weird to me) and the others just "Preferences". Is it safe to delete one? or is one of those not suppose to be there?Could this be an add-on in Chrome?do idea, how can I check?Open Chrome and open Tools. You should see something there about add-ons where you can disabled or enable them.The only addon I had was Google Docs and I disabled it. Still did not fix the issue.Please delete that temp folder and run MBAM again and post the log.Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/26/2014
Scan Time: 4:28:33 PM
Logfile: log 1.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.26.09
Rootkit Database: v2014.07.17.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8
CPU: x64
File System: NTFS
User: Saajuk

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 317203
Time ELAPSED: 9 min, 3 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
PUP.Optional.MySearchDial.A, C:\Users\Saajuk\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "startup_urls": [ "http://start.mysearchdial.com/?f=1&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0EzztAzy0D0FtCyE0CtByByCyC0AzzyDtN0D0Tzu0SyBzztDtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=1943442087&ir=" ],), ,[653ca1ffd0abf73ff4162dbae71d28d8]

Physical Sectors: 0
(No malicious items detected)


(end)







seems to not WORK. I tested on another pc with a older version of MBAM (not sure exactly which version but it was 82 days out of date) and it did not detect it. When I updated to latest version it started to pick it up. I deleted it from prefrences like you said and ran the scan a few time and it did not pick it up, I thought it was fixed but I just did it again and it picked it back up in the same location. I went back to see if the Temp file was some how restored but it was gone.

EDIT: Anyways I found an option to turn off the pop up for PUPs so that was really the only annoyances I had. Nothing seems to be affecting my laptops performance so I think we can say its fixed. thanks.

Do you use Chrome and MBAM? I am interested if you would get the same thing, just curious.

using MBAM ver 2.0.2.1012Quote

Do you use Chrome and MBAM? I am interested if you would get the same thing, just curious
No, I don't use Chrome.

This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create Registry backup
  • Purge System Restore Points
  • Re-set system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.
**************************************
Click Start> Computer> right click the C Drive and CHOOSE Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
****************************************
Go to Microsoft Windows Update and get all critical updates.
----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you INTERACT with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
2258.

Solve : Avast installs SafePrice adware without asking?

Answer»

Read this, starting at the big BUT...
http://blogs.angloinfo.com/i-ve-lost-my-internet/2014/04/27/avast-safeprice-how-to-remove-that-flippin-pest/I found it funny that it only allows you to DISABLE it for 24 hr period and then its enabled again.. Quote from: DaveLembke on July 19, 2014, 03:30:19 PM

I found it funny that it only allows you to disable it for 24 hr period and then its enabled again..
You didn't read far enough.

So, here is how to disable Avast SafePrice in Mozilla Firefox and Google Chrome
In Mozilla Firefox:

Enter the following into your address bar: chrome://wrc/content/options.html
This GIVES you access to the “avast! Online Security SETTINGS” screen.
Scroll down to the bottom and uncheck “SafePrice Receive SafePrice shopping recommendations on relevant sites.”
CLICK on the “Save” button.

If this add-on is not installed, nothing HAPPENS. Why it's on one computer & not another is unknown.
2259.

Solve : Trojans in External Drive System Volume Information?

Answer»

If an anti-virus SOFTWARE such as Avira tells you that it has detected Trojans in the System VOLUME Information of an external USB hard drive and gives you the opportunity to quarantine them - if you agree to do that will you still be able to open the drive and access your data properly ? I don't want to take a rash decision and lose access to my information.

Please advise.Quarantining the infections shouldn't affect your ability to access the drive. Why is there a System Volume on that drive?I don't know why there is a System Volume on the drive. I have read that Windows will put them on all drives if you haven't instructed it not to. The drive that has shown this is connected to the XP machine that you were helping me with recently.

I had some initial trouble with that computer yesterday when I couldn't get Control Panel to display anything when I wanted to install a program. A second try let me and I thought it was a temporary glith and that everything was OK.

Later on, when the Firefox browser was getting unresponsive and complaining about Silverlight, I decided I would try to uninstall that plug-in. Control Panel was very slow and then I couldn't get the list of installed programs to display. I wanted to select the Silverlight plug-in from there to get rid of it.

I then tried to turn off the machine but couldn't get it to switch off even when I asked via Task Manager.

In the end I had to long-press the physical computer power button.

I re-booted and it got to the log-in screen but my cursor was inoperative (this happens a LOT with both of my Lenovo T61s so I don't know if it is just a Lenovo quirk). I plugged a mouse in to request that the machine shut down again.

It said something about br_funcs.exe (0XC000142) function failed something and then closed.

I re-booted and decided to log in as a different USER to see if Control Panel and program removal would be functional under another profile. They were. I removed Silverlight from that profile and deleted some media files that I don't need. Then I took the dog for a walk and thought the machine had settled.

When I got home Avira was reporting that it had blocked access to a file in G:\SystemVolumeInformation

the file is A0068235.exe containing the virus or unwanted program TR/Drop.TDss.aeag

I am not familiar with what A0068235.exe is but the named Trojan is the same one that was identified as being linked to HoldemIndicatorSetup.exe

This is the Windows XP machine you were helping me with in an earlier thread. Avira's Real Time Protection is offering the Action "Move to quarantine". My choices are "Apply now" or "Cancel".

What do you recommend ?

Could I have been infected by a Trojan last week that got in via my mail program on drive F and then changed itself into a fake Dr Watson that is trying to regenerate itself via the System Volume Information on the G drive?

Googling System Volume Information made it look as though it is something that Windows places on all drives by default and that it is to do with Restore Points. I don't know why anyone would want restore points or unemptied trash cans on EXTERNAL drives.

Some of the random forum posts I have found regarding the topic of System Volume Information on external drives make it look like they are a route for lurgies and that they are hard to eliminate. Some people were talking about using Linux CDs to access the System Volume Information Folders in order to delete them and to stop them constantly regenerating with the same virus.Quote

Avira's Real Time Protection is offering the Action "Move to quarantine". My choices are "Apply now" or "Cancel".

What do you recommend ?
Apply now.
Quote
Some of the random forum posts I have found regarding the topic of System Volume Information on external drives make it look like they are a route for lurgies and that they are hard to eliminate. Some people were talking about using Linux CDs to access the System Volume Information Folders in order to delete them and to stop them constantly regenerating with the same virus.
Infections are usually placed in the System Volume so that when someone run System Restore they get infected again. You can delete all your Restore Points by going to My Computer, right-click Disk Cleanup and click other options. You can also scan the external drive with your AV, MBAM and AdwCleaner.Why did Avira see the rogue file in the System Volume Information of an external drive when I wasn't doing anything ?

Is it normal for external drives to be accessed from time to time?

I have a USB key where the initial infection was spotted by Avira and "Denied Access" before the Dr Watson files were "Allowed Access" by the same AV software.
It has a light on it so I can see when it is communicating with the computer. Since the problem, I have stopped actively using it but, from time to time, its light flashes so SOMETHING is going on.

Is that normal ?Quote
Why did Avira see the rogue file in the System Volume Information of an external drive when I wasn't doing anything ?
The infection doesn't have to be active in order for it to be detected.
Quote
Is it normal for external drives to be accessed from time to time?
It will scan any drive that is connected.
Quote
It has a light on it so I can see when it is communicating with the computer. Since the problem, I have stopped actively using it but, from time to time, its light flashes so SOMETHING is going on.
Is that normal ?
Download Panda USB and AutoRun Vaccine and save it to your desktop.

* Extract (unzip) the file to your desktop and a folder named USBVaccine will be created.
* Open that folder and double-click on USBVaccine.exe to start the program.
* Click Run
* Click the button to Vaccinate computer.
* Insert your USB flash drive.
* When the name of the drive appears in the dialog box, click the button to Vaccinate USB drive(s).
* Exit Panda USB and AutoRun Vaccine when done.

Note: Computer AutoRun Vaccination will prevent any AutoRun file from running, regardless of whether the removable device is infected or not. USB Vaccination disables the autorun file so it cannot be read, modified or replaced by malicious code. The Panda Resarch Blog advises that once USB drives have been vaccinated, they cannot be REVERSED except with a format. If you do this, be sure to back up your data files first or they will be lost during the formatting process.
Thank you so much for all of your help.

I wonder if I may have been hit by a browser hi-jacking of some kind when the peculiarities with this Windows XP machine began with the file detected on drive F and then the alteration (?) of the Dr Windows file(s).

What do you think ?

I noticed that when I was re-starting Firefox periodically when it got very slow as RAM allocations became extremely high and/or the Silverlight plug-in stopped working - I would be brought back to a screen that lets you "Restore" your last session.

At the top right of the Firefox browser screen there is a downward pointing arrow that indicates downloads - it would animate turning green and descending.

This was happening with no TABS open except the one inviting you to restore your tabs from last time - where it lets you select from a list of pages that might have crashed.

I observed this occur repeatedly after the infection.

I have since managed to uninstall Silverlight.

I ran CCleaner and opened Firefox again. The arrow came down again.

I uninstalled Firefox, ran CCleaner and installed a fresh copy of Firefox but kept all my settings.

The arrow came down again.

I uninstalled Firefox - told it to FORGET ALL MY SETTINGS AND PREFERENCES, ran CCleaner and then REINSTALLED Firefox.

It opened with no peculiar download animations.

How foolish is it to continue to connect to the internet with Windows XP at all ?

I have read some reports that say you really shouldn't do it. This would mean an old machine couldn't even be used to watch YouTube videos or stream from Spotify - and that's a real shame.

Quote
I wonder if I may have been hit by a browser hi-jacking of some kind when the peculiarities with this Windows XP machine began with the file detected on drive F and then the alteration (?) of the Dr Windows file(s).

What do you think ?
I seriously doubt it but it's impossible for me to say for sure.
Quote
How foolish is it to continue to connect to the internet with Windows XP at all ?
MS and a lot of other experts say it's a bad idea but I'm using it myself and I haven't seen any uptakes in infections in XP. One thing I would recommend is that you don't use MSE as your AV. I'm using Avira at the moment.As MSE is no longer updated for XP, do you mean you recommend against choosing MSE on more modern OSes like Windows 7 ?Quote from: Tatterdemalion on June 29, 2014, 11:44:59 AM
As MSE is no longer updated for XP, do you mean you recommend against choosing MSE on more modern OSes like Windows 7 ?
MSE is perfectly ok on any OS above XP such as Vista, Windows 7, Windows 8 and 8.1and how experienced are you Efodagin you said WE.. I do not see you as a malware specialist? not much I would say.. just let malware specialist deal with his problem. thank you!
2260.

Solve : PC suddenly turns all the files on ANY usb plugged in into shortcuts?

Answer»

Just this morning, i was just transferring huge FILES on my hdd NORMALLY.
But just this night, plugged in my player, saw all the files and folders turned into shortcuts. I COULD still open them though. But that messed up my mp3 player. GREAT. So now i have 2 problems.

Ive asked for help and did CCleaner scan, MalwareBytes scan, adwcleaner and avira scan.

Still nothing. Every time i copy a file to a sub, gets turned to shortcuts.

What should i do?How did you transfer the files?Do you think that was to blame? When i transferred those files?
Well i transferred them normally. Just a USB connector. The other one is a bit complicated cause it is an internal hdd. i just used a sata to usb connector.

I thought everythings gonna be fine when i wake up today but its still the same. What I meant was did you copy and paste or something like that to transfer the files.Yeah I cut and paste from one DRIVE to another. Thats it. And copied one file from my desktop to the other drive. Why?Cut and paste is not a good way to do that. If something goes wrong, you've lost the file.
Quote

i was just transferring huge files on my hdd normally.
Were you transferring them to another place on your hard drive or to somewhere else?
If you transferred them to an external or USB memory drive you can learn more about this problem here.
2261.

Solve : Confusing Avira Results. Is it RIGHT ??

Answer»

Having got in a pickle lately, as my other threads illustrate, I have run an Avira scan on hard DRIVES connected to a Windows 7 PC that I hope has no problems. It has stopped 82.5% of the way through the scan but has shown some detections that it is offering to quarantine.

It has identified a program called DeFX095.exe as "TR/Agent.65519.2"

When I click on Avira's "Virus Information" link, it opens a panel where you can type in the named threat. When I do this - NO information is returned. How can Avira IDENTIFY something that then has no entry in their database ?

I Googled the program name and it looks like it is a Plug-In for the WinAmp music player. I think it was designed to add reverb and I think I can remember downloading it and using it SEVERAL YEARS AGO on a computer I no longer use.

I won't need to install it again so I may as well DELETE the original installer - but is it REALLY a Trojan ? Did someone find out that it was a Trojan disguised as an audio effect add-on and then blacklist it ?

Other threats it has found are within "ProCalculatem.exe" and "HoldemIndicatorSetup.exe"

These sound a bit dodgy. ProCalculatem might be an odds CALCULATOR and I imagine the latter is something to do with Poker.

Are these NOT dangerous unless I run them ? I have no intention of ever installing them.

Oh - just searched for "ProCalculatem" and it may be an "essential file".

Should I just trust Avira and let it quarantine all it has found.

It got stuck at 82.5% of the scan looking at the "Q" drive - which is Lenovo's factory recovery area. Perhaps it can't get access to that and is not supposed to.

Any knowledgable insights will be much appreciated.

Probably not the done thing to reply to your own message. I have done some hard drive searching and located all the three named files. DeFX095.exe is stored as a Win-Amp plug in and both ProCalculatem and HoldemIndicatorSetup CAME bundled with a dodgy money-making audiobook. Would it be a good idea for me to "Cancel" Avira's offer to quarantine these files and for me to DELETE the original folders that contain them and THEN run the Avira scan from scratch again ?Quote

Would it be a good idea for me to "Cancel" Avira's offer to quarantine these files and for me to DELETE the original folders that contain them and THEN run the Avira scan from scratch again ?
Just ignore those warnings unless your computer starts ACTING up.So - can you confirm that I don't even need to quarantine those files and that I can just press "Cancel" and close Avira's virus scan as if it had found nothing ??Yes, just ignore them unless your computer starts acting up.Thank you. I know WHAT the flagged files were. They are Poker calculator programs that were "bundled" with what seems like otherwise harmless (and slightly unrelated) audiobooks. I suppose they are no threat at all so long as I don't run them (I never will) and there is no way they could be run without my permission.Quote
I suppose they are no threat at all so long as I don't run them (I never will) and there is no way they could be run without my permission.
If you don't intend to use them you should uninstall them.Thanks. I'll do so.
2262.

Solve : I have malware "Computer Support Online" popups?

Answer»

Quote

I have another question that I don't know if it is related or not. When I boot up I get a dialog box named Content Adviser asking me if I want to use the "starthelp.exe" located on the hard drive. It's publisher is unknown. The location of it is C:\program files (x86)\privoxy\starthelp.exe. I haven't been letting it start SINCE I have no clue what it is. Is this ok and how can I keep it from popping up when I boot up?
Please try uninstalling that program.I tried to uninstall it with Windows and Revo Uninstaller, however the program did not show up in either. I went into the file and there is no uninstall feature. Do I simply delete the file? Yes, please.I deleted the program. I have to go out of town until Friday when I can check back for any other actions you recommend I take.Did removing that program have any effect?I believe it has helped although I still get some of the same pop ups that Adblock Plus cannot block. I will try running some of the programs to see if they help. We got some company for the weekend and I can't work on it until next week. I apologize for the delay and I really do appreciate your help and patience in this issue. Quote
I apologize for the delay and I really do appreciate your help and patience in this issue.
Not a problem. We'll go at your pace. In the meantime, try running AdwCleaner and MBAM to see if it picks up anything. I'm curious about those pop-ups. Could you please post a screenshot of one of them?

How to post screenshots or images
I haven't had much improvement as I thought. I ran AdwCleaner and MBAM and both show no detections. I hope I have attached the copies of pop ups and web pages that open up in new tabs continually. Now the Content Advisor is dealing me fits in IE notifying me several times for each web page that loads and I have to enter my password before I can load the page. I am thinking about wiping the hard drive and reloading Windows. Let me know what you think.

Thank you.



Download DDS from HERE or HERE and save it to your desktop.

Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

* XP users Double click on dds to run it.
* If your antivirus or firewall try to block DDS then please allow it to run.
* When finished DDS will open two (2) logs.
* Save both reports to your desktop.
* The instructions here ask you to attach the Attach.txt.



1) DDS.txt
2) Attach.txt
Instead of attaching, please copy/past both logs into your Thread

Note: DDS will INSTRUCT you to post the Attach.txt log as an attachment.
Please just post it as you would any other log by copying and pasting it into the reply.

•Close the program window, and delete the program from your desktop.

Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )
Here are the logs you requested. Before running DDS I ran MBAM, AdwCleaner, and Super Anti-Spyware Pro and all three found some infections and quarantined them. Ran Microsoft Security Essentials and found no infections.

DDS.txt

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17126 BrowserJavaVersion: 10.60.2
Run by Char - Bill at 22:55:10 on 2014-06-25
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4056.2701 [GMT -5:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\STacSV64.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE
C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\ADOBE\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe
C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\System32\alg.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\SUPERAntiSpyware\d721cbab-1ddc-4c44-8db9-1bb46169e7e5.com
C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe
C:\Windows\system32\RunDll32.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\WordWeb\wweb32.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\HP\HP Officejet 4620 series\bin\HPNetworkCommunicator.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\HP\HP Officejet 4620 series\Bin\HPNetworkCommunicator.exe
C:\Program Files\Condusiv TECHNOLOGIES\Diskeeper\DkService.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.nbcnews.com/
uSearch Bar = Preserve
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} -
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} -
BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: LastPass Browser Helper Object: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -
TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll
TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\d721cbab-1ddc-4c44-8db9-1bb46169e7e5.com
uRun: [HP Officejet 4620 series (NET)] "C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN2AO2323905RT:NW" -scfn "HP Officejet 4620 series (NET)" -AutoStart 1
uRun: [IDMSQ] C:\Program Files (x86)\IDMSQ\idmsq.exe /startup
mRun: [WordWeb] "C:\Program Files (x86)\WordWeb\wweb32.exe" -startup
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\CHAR-B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MONITO~1.LNK - C:\Windows\System32\RunDll32.exe
StartupFolder: C:\Users\CHAR-B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll
.
INFO: HKCU has more than 50 listed DOMAINS.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{9E4B9493-F1B6-46F8-A5E8-5DA4308457EE} : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{9E4B9493-F1B6-46F8-A5E8-5DA4308457EE}\4527164656027596E6463702D4F64756C6 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{9E4B9493-F1B6-46F8-A5E8-5DA4308457EE}\C496E6B63597370254D243230303D27657563747 : DHCPNameServer = 192.168.3.1
SSODL: WebCheck -
x64-BHO: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} -
x64-BHO: LastPass Browser Helper Object: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar64.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar64.dll
x64-TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} -
x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
x64-Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
x64-Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
x64-Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [ISW]
x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar64.dll
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
x64-DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
x64-Notify: GoToAssist - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck -
Hosts: 127.0.0.1www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Char - Bill\AppData\Roaming\Mozilla\Firefox\Profiles\dqytkgi0.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.nbcnews.com
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=BDT3DF&PC=BDT3&dt=061414&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll
.
============= SERVICES / DRIVERS ===============
.
R0 DKDFM;Device Filter Manager Driver;C:\Windows\System32\drivers\DKDFM.sys [2012-9-30 40752]
R0 DKTLFSMF;Telemetry File System Mini Filter Driver;C:\Windows\System32\drivers\DKTLFSMF.sys [2012-9-30 106832]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2014-1-25 268512]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-11-23 55280]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-5-4 128384]
R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe [2010-7-22 89600]
R2 BingDesktopUpdate;Bing Desktop Update service;C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [2014-6-3 173792]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
R3 DKRtWrt;DKRtWrt;C:\Windows\System32\drivers\DKRtWrt.sys [2012-9-30 52048]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2009-11-23 215552]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S3 cricutexpression2;cricutexpression2;C:\Windows\System32\drivers\cricutexpression2_x64.sys [2011-9-2 70672]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-6-11 111616]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2014-3-11 133928]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-3-11 347872]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;C:\Windows\System32\svchost.exe -k nosGetPlusHelper [2009-7-13 27136]
S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe [2009-6-26 1124848]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-4-17 59392]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-20 1255736]
.
=============== Created Last 30 ================
.
2014-06-26 03:27:15122584----a-w-C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-06-26 03:26:5463704----a-w-C:\Windows\System32\drivers\mwac.sys
2014-06-26 03:26:54--------d-----w-C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-26 02:14:3810779000----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{94A14231-87B8-467B-8388-93BE1C33221E}\mpengine.dll
2014-06-26 01:57:47--------d-----w-C:\ProgramData\OEM Links
2014-06-26 01:57:47--------d-----w-C:\MININT
2014-06-26 00:51:101031560----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CB7EEFF3-2DB9-4EE9-8432-684020541B65}\gapaengine.dll
2014-06-24 01:36:2610779000----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-06-21 12:20:24404992----a-w-C:\Windows\SysWow64\CommonDlg.dll
2014-06-14 16:34:2494432----a-w-C:\ProgramData\Microsoft\BingDesktop\Updater\BingDesktopRestarter.exe
2014-06-13 22:36:55--------d-----w-C:\ProgramData\PC-Doctor for Windows
2014-06-13 22:36:27--------d-----w-C:\Program Files\My Dell
2014-06-13 06:18:311031560----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-06-13 06:17:1898216----a-w-C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-06-11 02:21:2593808----a-w-C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe
2014-06-08 21:44:53--------d-sh--w-C:\Users\Char - Bill\AppData\Local\EmieUserList
2014-06-08 21:44:53--------d-sh--w-C:\Users\Char - Bill\AppData\Local\EmieSiteList
2014-06-08 16:59:40--------d-s---w-C:\Windows\SysWow64\Microsoft
2014-06-08 14:01:07--------d-----w-C:\ProgramData\PCDr
2014-06-08 01:21:49--------d-----w-C:\Program Files (x86)\Microsoft Security Client
2014-06-08 01:21:44--------d-----w-C:\Program Files\Microsoft Security Client
2014-06-08 00:36:41--------d-----w-C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-06-08 00:26:3791352----a-w-C:\Windows\System32\drivers\mbamchameleon.sys
2014-06-07 23:59:53--------d-----w-C:\Windows\ERUNT
2014-06-07 16:44:06--------d-----w-C:\AdwCleaner
2014-06-07 16:01:40--------d-----w-C:\Program Files (x86)\ESET
2014-06-07 05:28:33--------d-s---w-C:\Windows\System32\CompatTel
2014-06-07 04:49:01167424----a-w-C:\Program Files\Windows Media Player\wmplayer.exe
2014-06-07 04:49:01164864----a-w-C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-06-07 04:48:5812625920----a-w-C:\Windows\System32\wmploc.DLL
2014-06-07 04:48:5712625408----a-w-C:\Windows\SysWow64\wmploc.DLL
2014-06-07 04:38:52--------d-----w-C:\Windows\Migration
2014-06-07 04:33:35155584----a-w-C:\Windows\System32\drivers\ataport.sys
2014-06-07 04:33:31461312----a-w-C:\Windows\System32\scavengeui.dll
2014-06-07 04:33:21223752----a-w-C:\Windows\System32\drivers\fvevol.sys
2014-06-07 04:33:01658432----a-w-C:\Windows\System32\RMActivate_isv.exe
2014-06-07 04:33:00626176----a-w-C:\Windows\System32\RMActivate.exe
2014-06-07 04:33:00594944----a-w-C:\Windows\SysWow64\RMActivate_isv.exe
2014-06-07 04:31:5927584----a-w-C:\Windows\System32\drivers\Diskdump.sys
2014-06-07 04:31:59190912----a-w-C:\Windows\System32\drivers\storport.sys
2014-06-07 04:31:582048----a-w-C:\Windows\SysWow64\iologmsg.dll
2014-06-07 04:31:572048----a-w-C:\Windows\System32\iologmsg.dll
2014-06-07 04:31:4848640----a-w-C:\Windows\System32\wwanprotdim.dll
2014-06-07 04:31:48228864----a-w-C:\Windows\System32\wwansvc.dll
2014-06-07 04:31:46335360----a-w-C:\Windows\System32\msieftp.dll
2014-06-07 04:31:45301568----a-w-C:\Windows\SysWow64\msieftp.dll
2014-06-07 04:31:431684928----a-w-C:\Windows\System32\drivers\ntfs.sys
2014-06-07 02:32:08--------d-----w-C:\Users\Char - Bill\AppData\Roaming\IDM2
2014-06-06 20:56:41--------d-----w-C:\Users\Char - Bill\AppData\Local\Programs
2014-06-06 19:05:33878080----a-w-C:\Windows\System32\advapi32.dll
2014-06-06 19:05:33859648----a-w-C:\Windows\System32\tdh.dll
2014-06-06 19:05:331732032----a-w-C:\Windows\System32\ntdll.dll
2014-06-06 19:05:32640512----a-w-C:\Windows\SysWow64\advapi32.dll
2014-06-06 19:05:32619520----a-w-C:\Windows\SysWow64\tdh.dll
2014-06-06 19:05:321292192----a-w-C:\Windows\SysWow64\ntdll.dll
2014-06-06 19:03:52327168----a-w-C:\Windows\System32\mswsock.dll
2014-06-06 19:03:51231424----a-w-C:\Windows\SysWow64\mswsock.dll
2014-06-06 19:02:541887232----a-w-C:\Windows\System32\d3d11.dll
2014-06-06 19:02:541505280----a-w-C:\Windows\SysWow64\d3d11.dll
2014-06-06 17:46:3581408----a-w-C:\Windows\System32\imagehlp.dll
2014-06-06 17:46:35159232----a-w-C:\Windows\SysWow64\imagehlp.dll
2014-06-06 17:46:34484864----a-w-C:\Windows\System32\wer.dll
2014-06-06 17:46:34381440----a-w-C:\Windows\SysWow64\wer.dll
2014-06-06 17:45:432048----a-w-C:\Windows\SysWow64\tzres.dll
2014-06-06 17:45:432048----a-w-C:\Windows\System32\tzres.dll
2014-06-06 17:43:10230400----a-w-C:\Windows\System32\drivers\portcls.sys
2014-06-06 17:43:10116736----a-w-C:\Windows\System32\drivers\drmk.sys
2014-06-06 17:43:093156480----a-w-C:\Windows\System32\win32k.sys
2014-06-06 17:43:0699840----a-w-C:\Windows\System32\drivers\usbccgp.sys
2014-06-06 17:43:067808----a-w-C:\Windows\System32\drivers\usbd.sys
2014-06-06 17:43:0653248----a-w-C:\Windows\System32\drivers\usbehci.sys
2014-06-06 17:43:06343040----a-w-C:\Windows\System32\drivers\usbhub.sys
2014-06-06 17:43:06325120----a-w-C:\Windows\System32\drivers\usbport.sys
2014-06-06 17:43:0630720----a-w-C:\Windows\System32\drivers\usbuhci.sys
2014-06-06 17:43:0625600----a-w-C:\Windows\System32\drivers\usbohci.sys
2014-06-06 17:34:0010702536----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BB63539-C2A8-4B17-AA07-638F54BE86D2}\mpengine.dll
2014-06-03 19:02:0810993664----a-w-C:\ProgramData\Microsoft\BingDesktop\Updater\BingDesktop.msi
.
==================== Find3M ====================
.
2014-06-06 19:18:4970832----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-06-06 19:18:49692400----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe
2014-05-30 10:02:372724864----a-w-C:\Windows\System32\mshtml.tlb
2014-05-30 10:02:094096----a-w-C:\Windows\System32\ieetwcollectorres.dll
2014-05-30 09:39:43548352----a-w-C:\Windows\System32\vbscript.dll
2014-05-30 09:39:2366048----a-w-C:\Windows\System32\iesetup.dll
2014-05-30 09:38:2948640----a-w-C:\Windows\System32\ieetwproxystub.dll
2014-05-30 09:21:23139264----a-w-C:\Windows\System32\ieUnatt.exe
2014-05-30 09:21:05111616----a-w-C:\Windows\System32\ieetwcollector.exe
2014-05-30 09:20:36752640----a-w-C:\Windows\System32\jscript9diag.dll
2014-05-30 09:11:24940032----a-w-C:\Windows\System32\MsSpellCheckingFacility.exe
2014-05-30 09:08:225782528----a-w-C:\Windows\System32\jscript9.dll
2014-05-30 09:02:392724864----a-w-C:\Windows\SysWow64\mshtml.tlb
2014-05-30 08:55:3638400----a-w-C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-05-30 08:44:28455168----a-w-C:\Windows\SysWow64\vbscript.dll
2014-05-30 08:43:0661952----a-w-C:\Windows\SysWow64\iesetup.dll
2014-05-30 08:42:1651200----a-w-C:\Windows\SysWow64\ieetwproxystub.dll
2014-05-30 08:28:33112128----a-w-C:\Windows\SysWow64\ieUnatt.exe
2014-05-30 08:27:56592896----a-w-C:\Windows\SysWow64\jscript9diag.dll
2014-05-30 08:24:191249280----a-w-C:\Windows\System32\mshtmlmedia.dll
2014-05-30 08:23:222040832----a-w-C:\Windows\System32\inetcpl.cpl
2014-05-30 08:10:4632256----a-w-C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-05-30 07:56:562266112----a-w-C:\Windows\System32\wininet.dll
2014-05-30 07:56:504244992----a-w-C:\Windows\SysWow64\jscript9.dll
2014-05-30 07:50:091068032----a-w-C:\Windows\SysWow64\mshtmlmedia.dll
2014-05-30 07:49:381964544----a-w-C:\Windows\SysWow64\inetcpl.cpl
2014-05-30 07:21:101790976----a-w-C:\Windows\SysWow64\wininet.dll
2014-05-12 12:25:5625816----a-w-C:\Windows\System32\drivers\mbam.sys
2014-05-09 06:14:03477184----a-w-C:\Windows\System32\aepdu.dll
2014-05-09 06:11:23424448----a-w-C:\Windows\System32\aeinv.dll
2014-04-25 02:34:59801280----a-w-C:\Windows\System32\usp10.dll
2014-04-25 02:06:17626688----a-w-C:\Windows\SysWow64\usp10.dll
2014-04-12 02:22:0595680----a-w-C:\Windows\System32\drivers\ksecdd.sys
2014-04-12 02:22:05155072----a-w-C:\Windows\System32\drivers\ksecpkg.sys
2014-04-12 02:19:3829184----a-w-C:\Windows\System32\sspisrv.dll
2014-04-12 02:19:38136192----a-w-C:\Windows\System32\sspicli.dll
2014-04-12 02:19:3728160----a-w-C:\Windows\System32\secur32.dll
2014-04-12 02:19:321460736----a-w-C:\Windows\System32\lsasrv.dll
2014-04-12 02:19:0531232----a-w-C:\Windows\System32\lsass.exe
2014-04-12 02:12:0622016----a-w-C:\Windows\SysWow64\secur32.dll
2014-04-12 02:10:5696768----a-w-C:\Windows\SysWow64\sspicli.dll
2014-04-05 02:47:201903552----a-w-C:\Windows\System32\drivers\tcpip.sys
2014-04-05 02:47:09288192----a-w-C:\Windows\System32\drivers\FWPKCLNT.SYS
2014-03-31 14:35:08270496------w-C:\Windows\System32\MpSigStub.exe
.
============= FINISH: 22:55:43.80 ===============


Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 12/23/2009 10:38:39 PM
System Uptime: 6/25/2014 10:43:44 PM (0 hours ago)
.
Motherboard: Dell Inc. | | 0G848F
Processor: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz | Microprocessor | 2200/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 289 GiB total, 232.615 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP292: 6/8/2014 8:09:41 AM - Windows Update
RP293: 6/8/2014 8:39:25 AM - Revo Uninstaller's restore point - avast! Free Antivirus
RP294: 6/8/2014 11:58:59 AM - avast! Free Antivirus Setup
RP295: 6/8/2014 12:01:28 PM - Revo Uninstaller's restore point - avast! Free Antivirus
RP296: 6/8/2014 5:49:45 PM - Installed Microsoft Fix it 50566
RP297: 6/8/2014 11:45:33 PM - Windows Update
RP298: 6/11/2014 10:40:42 PM - Windows Update
RP299: 6/13/2014 1:15:17 AM - Installed Java 7 Update 60
RP300: 6/14/2014 11:16:56 AM - Windows Update
RP301: 6/14/2014 11:40:06 AM - Revo Uninstaller's restore point - Bing Desktop
RP302: 6/14/2014 11:43:35 AM - Revo Uninstaller's restore point - Bing Bar
RP303: 6/23/2014 7:52:32 PM - Windows Update
.
==== Installed Programs ======================
.
AccuChef
Adobe AIR
Adobe Download Manager
Adobe Flash Player 13 ActiveX
Adobe Flash Player 13 Plugin
Adobe Help Center 2.1
Adobe Photoshop Elements 5.0
Adobe Reader X (10.1.10)
CCleaner
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Compatibility Pack for the 2007 Office system
Cricut Expression 2 (TM) Driver v1.01
CricutSync
Dell Dock
Dell Edoc Viewer
Dell Touchpad
Dell Wireless WLAN Card Utility
DirectXInstallService
Diskeeper 12 Home
EMC 10 Content
EMCGadgets64
ESET Online Scanner v3
Google Earth
Google Update Helper
GoToAssist 8.0.0.514
Hoyle Puzzle Games 2005
HP Officejet 4620 series Basic Device Software
HP Officejet 4620 series Help
HP Officejet 4620 series Product Improvement Study
HP Update
I.R.I.S. OCR
IDT Audio
Intel(R) Graphics Media Accelerator Driver
Intel(R) Rapid Storage Technology
Intel® Matrix Storage Manager
Internet Download Manager² 1.0
Java 7 Update 60
Java Auto Updater
Java(TM) 6 Update 14 (64-bit)
Java(TM) 6 Update 18
Java(TM) 6 Update 22
Junk Mail filter update
LastPass (uninstall only)
Malwarebytes Anti-Malware version 2.0.2.1012
Microsoft .NET Framework 4.5.1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office Access database engine 2007 (English)
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Streets & Trips 2010
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable (x64)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable Package
Microsoft Works
Mozilla Firefox 30.0 (x86 en-US)
Mozilla Maintenance Service
Mozilla Thunderbird 12.0.1 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
My Dell
Octoshape add-in for Adobe Flash Player
OpenOffice.org 3.4.1
PowerDVD DX
Pradis 5.0
Quickset64
Revo Uninstaller 1.92
Roxio Activation Module
Roxio BackOnTrack
Roxio Burn
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio Easy CD and DVD Burning
Roxio Express Labeler 3
Roxio File Backup
Roxio Update Manager
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Security Update for Microsoft .NET Framework 4.5.1 (KB2931368)
Sonic CinePlayer Decoder Pack
SUPERAntiSpyware
System Requirements Lab for Intel
VD64Inst
Web Protect for Windows
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows Media Player Firefox Plugin
WordWeb
.
==== Event Viewer Messages From Past Week ========
.
6/25/2014 8:03:58 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Inspiron1545\Char - Bill SID (S-1-5-21-4193595447-3364358048-133568859-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
6/25/2014 8:03:58 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Inspiron1545\Char - Bill SID (S-1-5-21-4193595447-3364358048-133568859-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
6/25/2014 7:40:21 PM, Error: Microsoft-Windows-SharedAccess_NAT [30013] - The DHCP allocator has disabled itself on IP address 169.254.49.123, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.
6/25/2014 10:44:26 PM, Error: Microsoft-Windows-SharedAccess_NAT [34001] - The ICS_IPV6 failed to configure IPv6 stack.
6/25/2014 10:44:26 PM, Error: Microsoft-Windows-SharedAccess_NAT [30013] - The DHCP allocator has disabled itself on IP address 192.168.1.6, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope.
.
==== End Of File ===========================


I can't see anything malicious on your computer that would cause this. I think it's time to save your important data and re-format and re-install your OS.Well I have to agree because it is frustrating being on the internet. I want to thank you for your time and patience with me. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2263.

Solve : Possible Trojan? Search Conduit won't leave my laptop! LOTS OF CONFLICTS?

Answer»

You're WELCOME. I will LOCK this thread. If you need it re-opened, please SEND me a pm.

2264.

Solve : TR/Crypt.XPACK.Gen [Trojan] and Avira's Response?

Answer»

I hope not. Thank you for all of your help. Do you think the machine is clear now and I can carry on using it as normal ? Do I tell the ESET program to remove itself ?Quote

Do you think the machine is clear now and I can carry on using it as normal ? Do I tell the ESET program to remove itself ?
As clean as I can make it being THOUSANDS of kilometers away from you. You can uninstall the ESET scanner.
Let's do some cleanup. You may keep MBAM and AdwCleaner on your computer, if you wish. Update them and run them on a regular basis.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
***************************************
Go to Microsoft Windows Update and GET all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable SHOPPING sites. WOT WARNS you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
THANK YOU for all of your help.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2265.

Solve : MRT.exe?

Answer»

Just sitting using my computer only to suddenly here the PC get a little loud! So I immediately check my task manager to find a file named mrt.exe running at 30%+ CAPACITY of my PROCESSING. Following this, I found some other FILES like svchost.exe, and another that I ended the process for.....also running after mrt.exe was finished running.

I then did a file SEARCH on my computer for mrt.exe and did find the file is windows system 32 file. However, I then find a windows prefetch file mrt.exe-1b4a8d49.pf file. The LATTER file shows as a being modified today right at the time when the computer started this. Any idea if this is a virus going on, or is this a normal modification occuring?MRT stands for Malicious removal tool and is a product of MS. It's installed with almost every OS.

2266.

Solve : AVG anti-virus reporting off?

Answer»

Try clicking on "Visit our solution center".OK, I WENT over and clicked.
It says to choose one of several problem areas options.
I choose "Top Solutions" and here is a screenshot of the options:

I also choose "Windows" problem areas, did not know what to select.

[recovering disk space, attachment deleted by admin]Select any one of them and let it run.This is not going smooth.
I downloaded:

-Diagnose and fix Windows FIREWALL service problems automatically
-Fix security issues to protect and secure Windows automatically
-Automatically fix Windows security settings to keep your PC safe

I tried to run, but got this message:

Quote

The program encountered an error trying to contact the server.
To download a utility to troubleshoot the problem, click here.
Code 80072EE7

I clicked the link, but could not download because the browser is not connected to the internet.

Is it time to call this computer FINISHED?Quote
Is it time to call this computer finished?
No, it's just a glitch. I would suggest that you try all the sites here to see if you can find a solution to that problem. But first, please run the Farbar Service Scanner in Reply # 5 and post the log.Quote from: SuperDave on May 29, 2014, 07:11:48 PM
No, it's just a glitch. I would suggest that you try all the sites here to see if you can find a solution to that problem. But first, please run the Farbar Service Scanner in Reply # 5 and post the log.

1. Here is the log.


2. As of now, the PC cannot even detect a wireless network. So I am not connected at all, internet or local.

Quote
Farbar Service Scanner Version: 21-05-2014
Ran by Johnny Ola (administrator) on 01-06-2014 at 12:00:32
Running from "G:\"
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86)
Boot MODE: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
There is no connection to network.
Attempt to access Google IP returned error. Google IP is unreachable
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo.com returned error: Other errors


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****
Please do this even if you don't have the OS disk.

Do you have your OS CD/DVD?

If so,

1/ Click the Start button.

2/ From the Start MENU, Click All programs followed by Accessories.

3/ In the Accessories menu, Right Click on the Command Prompt option.

4/ From the drop down menu that appears, Click on the Run as administrator option.

5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc.

6/ In the Command Prompt window, type: sfc /scannow and then press Enter.

7/ A message will appear stating that the system scan will begin.

8/ Be patient because the scan may take some time.

9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue.

10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations.

11/ After the scan has completed, Close the command prompt window.
I don't......Run it anyway. If there are any problems with the OS files it will prompt you for the disk.
2267.

Solve : Is This PC Clean??

Answer»

I just got a used PC, and wanted to see if everything is clear.
I have pasted the logs below:


Adware
Quote

# AdwCleaner v3.211 - Report created 28/05/2014 at 20:55:26
# Updated 26/05/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Trent - HAYLEY-VAIO
# Running from : C:\Users\Trent\Downloads\adwcleaner_3.211.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKCU\Software\AppDataLow\Software

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17041


-\\ Mozilla Firefox v17.0.1 (en-US)

[ File : C:\Users\hayley\AppData\Roaming\Mozilla\Firefox\Profiles\2k18ffwk.default\prefs.js ]


[ File : C:\Users\Trent\AppData\Roaming\Mozilla\Firefox\Profiles\f35rwurz.default\prefs.js ]


*************************

AdwCleaner[R0].txt - [4339 octets] - [27/05/2014 22:45:43]
AdwCleaner[R1].txt - [1050 octets] - [28/05/2014 20:54:42]
AdwCleaner[S0].txt - [4492 octets] - [27/05/2014 22:46:33]
AdwCleaner[S1].txt - [975 octets] - [28/05/2014 20:55:26]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1034 octets] ##########



mware
Quote
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 5/28/2014
Scan Time: 9:09:44 PM
Logfile: mware.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.05.28.09
Rootkit Database: v2014.05.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Trent

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 334910
Time Elapsed: 10 min, 57 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious ITEMS detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

security
Quote
Sh Results of screen317's Security Check version 0.99.83
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````[/u]
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2014
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````[/u]
Java 7 Update 60
Java version out of Date!
ADOBE Flash Player 13.0.0.214
Adobe Reader 10.1.4 Adobe Reader out of Date!
Mozilla Firefox 17.0.1 Firefox out of Date!
Google Chrome 34.0.1847.116
Google Chrome 35.0.1916.114
````````Process Check: objlist.exe by Laurent````````[/u]
AVG avgwdsvc.exe
`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C: 2%
````````````````````End of Log``````````````````````[/u]
It looks good.

Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.

First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete EXIT JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to IMPROVE the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
***********************************************
Update your Adobe Reader. get.adobe.com/reader.

Be sure to uncheck the Free McAfee Security Scan so it isn't installed.Java is up to date, old versions removed.
Adobe is up to date.

Anything else just to double check?Not if it's working well.
2268.

Solve : How to add folder, relevant file or URL exceptions to AVG scans??

Answer»

I am using AVG antivirus for my computer. I want to exclude a various necessary folder , FILE or URL from relevant detection by AVG. Also set the exception for a viral file such as Trojan horse, I-Worm, Worm, W32 etc.

Can anybody TELL me How to add folder , file or URL exceptions to AVG scans?

Since I don't use AVG I cannot give you a PRECISE answer but you can probably FIND that information here.

2269.

Solve : Scan query?

Answer»
In scan reports/summaries the number of objects scanned is usually shown. What is an "object" in this context?What scanner are you talking about?Thanks for INTEREST, SuperDave.
I regularly run system security scans (Avira, MalwareBytes, etc) and the scan logs always show "objects scanned:" and show some figure in the hundreds of thousands and I am curious as to what these objects are - I presume they are bits of information stored in the computer, but I'm not sure what that means.Depending on the TYPE of scan that you run it could every file that's on your computer.I understand that the number of objects VARIES with the range of the scan - do you mean that 1 object = 1 file?Quote from: silkie on May 19, 2014, 11:43:22 AM
I understand that the number of objects varies with the range of the scan - do you mean that 1 object = 1 file?
I would assume that's what they mean.OK - I was curious because it seems an odd word to use about SOMETHING as amorphous as info kept by a computer. Thanks again.You're welcome. I will lock this thread. If you need it re-opened, please send me a PM.
2270.

Solve : PUPs?

Answer»

hello all,

is there a WAY to get rid of PUPS PERMANENTLY ?

thank you.One way is to DISCONNECT from the internet but that's not really an option. You can try increasing the security of your BROWSER. I USE Avira and Emisoft Antimalware and I never get them.

2271.

Solve : Banned from AVAST Forum for no known reason?

Answer»

I am 76 and retired,with limited knowledge and use of computers.I had Microsoft Sec.Ess.AV on my desktop(XP Home).I changed this to Avast Free.Next DAY I registered in Avast Forum to post a simple question:I have a laptop(Vista Home 64 b.)and a netbook (Win 7 34 b.)and asked Forum whether I could download Avast Free on these other two computers,using the same email address and password.Next day I wanted to check if there was any answer,but I found to my amazement,that I WAS BANNED FROM ENTERING THE FORUM FOREVER!UNBELIEVABLE!I have done nothing to deserve this,I am not a cybercriminal!I called their UK tel.#,called tech support,they directed me to Customer Support.Since May 5,I have 4 different "tickets',that come automatically re the above complaint,BUT NO ANSWER AT ALL FROM AVAST and of course no solution.
Can anyone help please???It would be greatly appreciated.Of course I have not downloaded Avast on my other computers,and likely won't do it-will choose another free AV.
Thank you so much for your attention to this! Go with Avira for a no-hassles installation.

Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) MicroSoft Security Essentials All versions and all languages.
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.Quote from: macko1944 on May 10, 2014, 12:58:20 PM

I am 76 and retired,with limited knowledge and use of computers.I had Microsoft Sec.Ess.AV on my desktop(XP Home).I changed this to Avast Free.Next day I registered in Avast Forum to post a simple question:I have a laptop(Vista Home 64 b.)and a netbook (Win 7 34 b.)and asked Forum whether I could download Avast Free on these other two computers,using the same email address and password.Next day I wanted to check if there was any answer,but I found to my amazement,that I WAS BANNED FROM ENTERING THE FORUM FOREVER!Unbelievable!I have done nothing to deserve this,I am not a cybercriminal!I called their UK tel.#,called tech support,they directed me to Customer Support.Since May 5,I have 4 different "tickets',that come automatically re the above complaint,BUT NO ANSWER AT ALL FROM AVAST and of course no solution.
Being banned from their forum seems very strange. Is that forum at http://forum.avast.com/?

I have avast Free installed on 3 computers at home. I am not absolutely sure about registering multiple computers but, if I recall correctly, you do not need a different email address and password for each computer. I do have a note to myself that I have two email addresses associated with my avast registrations. Since I have it installed on 3 computers, my recording of 2 email addresses either indicates a separate address for each registration is not necessary or I have failed to record the address used for one of my registrations. So, I suggest simply trying multiple registrations with the same email address and password. If it is not allowed, you will get an indication of that in some way.

I suggest you not reject avast due to your negative experience with that forum. Avast is a very good antivirus program. Thank you so much for your response.Yes,the link is the same that will ban me and the text makes it clear that the ban is not set to expire(their text).
And because I can not enter at all,I have no way that I can think of to register with a different user name and password.This is part of what is so unbelievable.The other part of course,that other than the automatic giving of new ticket numbers every time(I now have 4 different ones from different days)they do not answer my complaint.I marked it urgent,doesn't help.They just seem to ignore it.So,for now,I am leaving Avast on my XP desktop(along with other defenses and use that computer rarely and for very limited purposes),but I am really reluctant to download Avast on my other 2 computers,even though I would like to.I will probably settle on AVG,but I am STILL waiting a few days in the hope that one of my complaint letters will be responded to.Amazing,that there is never a dull moment with computers and one can always EXPECT the unexpected!
In the meantime,thank Heavens for smart people like you,who are taking the time and are devoted to council people like me!
Thank you again!!!
2272.

Solve : My machine frequentlty goes off to "La-la land" for an undetermined period?

Answer»

I was recently able to get rid of a thing called "Tuvaro" through the help of SuperDave. I am very thankful to him for that. However a bug or something was LEFT behind that wasn't too much of a pain at first but is getting impossible to work around. Very frequently when I am on the internet, or using "Office" features or just "Logging off" the machine goes into a mode where it just runs indefinitely and I am unable to control it or do anything except Power off. I doesn't happen if I am playing a game or on "Skype" just when I am using Word or Excel or Internet Explorer. Thanks for reading. Appreciate any help that I can get. JIMGEEK: Thanks for your reply. Yes I am pretty well backed up. I recently had to reformat my ENTIRE OS and I thought that I had everything backed up but later found that I had lost most of my pictures [ouch]. I will check out the Seagate tools. I am hoping that I will not have to reformat again. It was shortly after I reformatted the last time that I picked up the "TUVARO" thing, what ever it was, it was causing me a lot of grief.
I removed Geek's POST. This is the malware forum and nobody should be responding other than CH staff.Ok, Jim. Let's run the usual scans and we'll see what turns up.

Please download AdwCleaner by Xplode onto your Desktop.

Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon.

[/URL]

If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run.
When the AdwCleaner program will open, click on the Scan button as shown below.

[/URL]

AdwCleaner will now start to search for malicious files that may be installed on your computer.
To remove the files that were detected in the previous step, please click on the Clean button.

[/URL]

AdwCleaner will now prompt you to save any open files or data as the program will NEED to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer.
Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply.
*********************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.SUPER DAVE: Okay, I ran Adware and MBAM. MBAM took 2 1/2 hours to run and found no items. Logs follow. Will do JRT tomorrow.

# AdwCleaner v3.022 - Report created 28/03/2014 at 12:53:13
# Updated 13/03/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Jim - JIM-PC
# Running from : C:\Users\Jim\Downloads\adwcleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files (x86)\HiDefMedia
Folder Deleted : C:\Windows\Installer\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Folder Deleted : C:\Windows\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219}
Folder Deleted : C:\Users\Jim\AppData\Roaming\Systweak
File Deleted : C:\Windows\System32\roboot64.exe

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL
Key Deleted : HKLM\SOFTWARE\Classes\nctaudiocdwriter2.audiocdwriter2
Key Deleted : HKLM\SOFTWARE\Classes\nctaudiocdwriter2.audiocdwriter2.1
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0BBF19A5-BE50-4E06-A340-6777A505E490}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{869E753F-BD0D-4832-8131-94FEEE058AE3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458E-AE16-1C1D8255C28A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0BBF19A5-BE50-4E06-A340-6777A505E490}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{869E753F-BD0D-4832-8131-94FEEE058AE3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458E-AE16-1C1D8255C28A}
Key Deleted : HKCU\Software\systweak
Key Deleted : HKLM\Software\systweak
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1}
Key Deleted : [x64] HKLM\SOFTWARE\Savings Bull
Key Deleted : [x64] HKLM\SOFTWARE\SavingsBull Filter
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{813BA625-B0FA-48D8-9B75-59759C88C219}
Key Deleted : HKLM\Software\Classes\Installer\Features\1708EDD6AB4EB164A86999D0AF0ABE1D
Key Deleted : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Key Deleted : HKLM\Software\Classes\Installer\Products\1708EDD6AB4EB164A86999D0AF0ABE1D
Key Deleted : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16521


*************************

AdwCleaner[R0].txt - [7307 octets] - [08/02/2014 13:10:56]
AdwCleaner[R1].txt - [1939 octets] - [11/02/2014 15:20:39]
AdwCleaner[R2].txt - [1505 octets] - [12/02/2014 10:55:40]
AdwCleaner[R3].txt - [2258 octets] - [13/02/2014 10:43:25]
AdwCleaner[R4].txt - [1402 octets] - [14/02/2014 14:54:08]
AdwCleaner[R5].txt - [2798 octets] - [28/02/2014 09:38:45]
AdwCleaner[R6].txt - [1648 octets] - [28/02/2014 09:47:03]
AdwCleaner[R7].txt - [5652 octets] - [28/03/2014 12:52:39]
AdwCleaner[S0].txt - [7093 octets] - [08/02/2014 13:11:40]
AdwCleaner[S1].txt - [1759 octets] - [11/02/2014 17:40:56]
AdwCleaner[S2].txt - [3927 octets] - [11/02/2014 17:44:05]
AdwCleaner[S3].txt - [1354 octets] - [14/02/2014 14:54:37]
AdwCleaner[S4].txt - [2683 octets] - [28/02/2014 09:42:14]
AdwCleaner[S5].txt - [5456 octets] - [28/03/2014 12:53:13]

########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [5516 octets] ##########

Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org

Database version: v2014.03.28.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16521
Jim :: JIM-PC [administrator]

Protection: Enabled

3/28/2014 12:59:30 PM
mbam-log-2014-03-28 (12-59-30).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 760618
Time elapsed: 3 hour(s), 7 minute(s), 42 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry VALUES Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


SUPERDAVE: The JRT log:

JRT log 3/29/2014

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by Jim on Sat 03/29/2014 at 9:51:58.75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values


~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smallfrogs studio


~~~ Files


~~~ Folders


~~~ Event Viewer Logs were cleared


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 03/29/2014 at 9:57:01.95
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Malwarebytes' Anti-Rootkit

Please download Malwarebytes' Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.
SUPERDAVE; OKAY, I ran the Malwarebytes ANTI-ROOTKIT and "No malware found" and "No clean up required" resulted.

Then I got e-mail from malwarebytes advising me to upgrade my Pro Malwarebytes vs 1.75 to vs. 2.0 {no cost} which I did and I ran a quick scan and found two more PUPs which were quarantined.

NOTE: The suspect malfunction has not reoccurred since JRT deleted that one registry key. Could that have been the problem?Yes, that may have been the problem. Give it a few days to see how it runs and then get back to me.SUPERDAVE: Okay, will do. Thank you very very much. SUPERDAVE: OK, it has been one month since the last posting and I thought that I would give you an update. Occasionally the machine will still "LOOP" off while running Internet Explorer or Shop 2000. Since I added Shop 2000 to the startup menu it (shop 2000) has been all right however it still does it once in a while on Internet Explorer. The only way I can get it to stop is to RESTART the machine. I can live with that. If you have any further ideas I would appreciate hearing about them, Otherwise I guess the post should be closed. Thanks again for all of your help. Have a great day, JIMCould you please explain "loop off"?Could you please explain "Loop off"?SUPERDAVE: "loop off" Sorry! that is an expression that I haven't used for many many years. It applied to old transistor/diode logic circuits that would get hung up in a "race" condition, due to slow solid state switching devices, and just keep recycling in that state indefinitely. We called it looping. The only way to stop it was to power down or physically introduce a "glitch". Then the guilty component had to be located and replaced. Anyway, it is those times in that past that I remember when my computer starts doing that. I don't think that modern circuits can do that but maybe, with a little adjusting, software can do that. I remember that, using machine language, I could make some of the old Solid State computers chase themselves. I dunno I'm too old to try to learn new technology. Thanks for the memory.....JIM

P.S. I hope that I haven't said anything that was in-appropriate here. If so, it was not intended.Ok. So the wheels were just spinning. Please try this: Open Taskmanager and keep it open. When it starts to loop try to determine how much memory is being used and which process is using it.
2273.

Solve : do you need firewall and antivirus for windows 8.1??

Answer»

got windows 8.1 and currently just USE AVG, should I get a firewall too? (which free version do you recommend?)

what else do I need? DO i need an anti SPYWARE program too?Windows 8 comes with its own Anti-virus and anti-spyware program called Windows Defender. If you're GOING to use AVG you will need to DISABLE Windows Defender. You can use the Windows Firewall which should already be on your computer. You would be better off USING Windows Defender.

2274.

Solve : Spam Sent from Hotmail, but Account Not Hacked?

Answer»

My partners HOTMAIL account keeps sending emails to her contacts list with URLs - SPAM in other words.

This keeps happening, even though her account has NOT been hacked. Many of her contacts are work related and this is a real problem for her.

After the first occasion with my help she setup two factor authentication, and her password has never been changed without her knowledge. The emails do not appear in her sent items.

So how is it someone keeps sending emails as her, to her contacts, and how can we stop it?

Thanks allHer account has been hacked. She should change her password and make it a strong alpha/numeric password.Sorry Dave, but I think you are wrong.

She reset her password to a strong password after the first time (uppercase lowercase number special characters). How would someone hack an account that has two factor authentication? Quote from: MikhailCompo on March 30, 2014, 03:56:11 AM

Sorry Dave, but I think you are wrong.

She reset her password to a strong password after the first time (uppercase lowercase number special characters). How would someone hack an account that has two factor authentication?
Accounts are "hacked" by figuring out the password. 2-factor authentication does absolutely nothing to prevent this because the password is usually acquired through a malware infection. Keyloggers can acquire both the E-mail address and password, and they can also determine and send back any saved passwords in most major browsers.

2-Factor authentication is only used for logging into webmail. IMAP outgoing servers cannot use 2-factor authentication because then they wouldn't be IMAP servers. Additionally, by controlling a piece of software on the users machine (the trojan) a person can easily just send the E-mail from their machine.

TL;DR: It's a malware infection.We can run some scans to make sure the computer is clean then we take it from there.

Please download AdwCleaner by Xplode onto your Desktop.

Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon.

[/URL]

If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run.
When the AdwCleaner program will open, click on the Scan button as shown below.

[/URL]

AdwCleaner will now start to search for malicious files that may be installed on your computer.
To remove the files that were detected in the previous STEP, please click on the Clean button.

[/URL]

AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer.
Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply.
************************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that EVERYTHING is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM PROCEED with the disinfection process. If ASKED to restart the computer, please do so immediately.
*************************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.Quote from: MarkAClarkson on April 26, 2014, 05:57:48 AM
Microsoft SELL to SPAM hackers all of your contact lists and then SELL you the software to prevent this occurring. Recently purchased a Luma 1020 running Win8. You MUST have a Outlook Account and MUST upload all of your contacts details including email address and phone numbers. More data for Microsoft to sell. I closed my Hotmail account 5 years ago, because that is the ONLY way to prevent SPAM being sent to all your contacts as if it came from you. Got an email today from someone else's Hotmail account. BIG BILL needs the revenue streams to fund his works of supererogation.

  • This thread hasn't been posted in in almost a month.
  • You have absolutely no evidence for what you are claiming.
Quote from: MarkAClarkson on April 26, 2014, 05:57:48 AM
Microsoft SELL to SPAM hackers all of your contact lists and then SELL you the software to prevent this occurring.
Almost everybody uses their E-mail address to sign up for stuff. Most sites that take an E-mail address will sell it to third parties. Microsoft doesn't sell any products for Anti-malware/spyware purposes.

Quote
Recently purchased a Luma 1020 running Win8. You MUST have a Outlook Account and MUST upload all of your contacts details including email address and phone numbers.
This is false.

Quote
because that is the ONLY way to prevent SPAM being sent to all your contacts as if it came from you. Got an email today from someone else's Hotmail account.
E-mails can be dead-simple to compromise. People use easily predictable passwords or select poor security questions- (There are only so many flavours of ice cream), or their machine get's infected.

Quote
BIG BILL needs the revenue streams to fund his works of supererogation.
This expresses a strong ignorance in the area of how corporations and organizations work.
2275.

Solve : File footprints?

Answer»

Here's a copy of the JRT.txt file. I am working on backing up my pc before I install and run Malwarebytes' Anti-Rootkit. Again, PLEASE let me know if you think any of this information might be indicative of someone putting something on my pc to monitor my activities. Thanks!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal TOOL (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Libby on Sat 04/12/2014 at 13:49:19.07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~ Services

~~~ Registry Values

Successfully REPAIRED: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-626533540-2267483260-4042443749-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page


~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\yt.ytnavassistplugin.1
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D97887C1-33F2-4518-B157-EBD20FFDA49C}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{D97887C1-33F2-4518-B157-EBD20FFDA49C}

~~~ Files

Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npcouponprinter.dll"
Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npmozcouponprinter.dll"

~~~ Folders

Successfully deleted: [FOLDER] "C:\Program Files (x86)\coupons"

~~~ FireFox

Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\{1c43baf1-00c2-40a8-a09e-f84cfd79546d}
Successfully deleted the following from C:\Users\Libby\AppData\Roaming\mozilla\firefox\profiles\0t1jpq6p.default\prefs.js

user_pref("id_couponscom.variablecashedNotificatio ns", "%7B%22hxxp%3A//www.dickssportinggoods.com/home/index.jsp%22%3A%22%3CTOOLBAR%3E%5Cr%5Cn%3CSETTINGS%20scope%3D%5C%220%5C%
user_pref("id_couponscom.variables.Var1", "hxxp%3A//cdn.coupons.com/couponbar.coupons.com");
user_pref("id_couponscom.variables.Var2", "hxxp%3A//couponbar.coupons.com");
user_pref("id_couponscom.variables.Var3", "hxxp%3A//www.coupons.com/coupon-codes/");
Emptied folder: C:\Users\Libby\AppData\Roaming\mozilla\firefox\profiles\0t1jpq6p.default\minidumps [21 files]

~~~ Event Viewer Logs were cleared


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 04/12/2014 at 13:55:51.85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Quote

Again, please let me know if you think any of this information might be indicative of someone putting something on my pc to monitor my activities.
There's no evidence of that yet. Were you able to run the MBAM rootkit scanner?
2276.

Solve : I need help fast! ICE Cyber Crime Center has blocked computer?

Answer»

Malwarebytes' Anti-Rootkit

Please download Malwarebytes' Anti-Rootkit and save it to your desktop.

  • Be sure to print out and follow the instructions PROVIDED on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and REPEAT the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other SYSTEM issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be CREATED and saved within that same folder.
  • Copy and paste the CONTENTS of these two log files in your next reply.
2277.

Solve : problem with keyboards?

Answer»

Hi, my computer was good to go this morning, then for some reasons the keyboard starts becoming messed up, i tried to reboot to see if that worked however each time i rebooted,the problem still persist and become worse, now all my keys stop working ,some keys when i pressed will become something irrevalant (ex: backspace = 83j, esc=$57) and even when i did nothing, my computer would keep spamming some random characters, first it was 4444444 then 9999 then hj or even spam enter or space ) , my backspace and some numbers still worked earlier but after numerous attempt to reboots, they became messed up too.

[recovering disk space, attachment deleted by admin]Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a NEW topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
You could start with trying another keyboard on the computer. That one could be defective. Please let me know if that solves the problem.
I've never seen a MBAM log like that one. Could you please run it again.
It APPEARS that you have two AV's on your computer; Windows Defender and Symantec Endpoint Protection. One will have to be de-activated or uninstall. Only one AV and one Firewall allowed on any computer.

*********************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*****************************************
Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.

First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked TOOLBAR and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > ADVANCED > MISCELLANEOUS and uncheck the box for Java Quick Starter. Click OK and reboot your computer.

2278.

Solve : Lost WiFi Since Infection?

Answer»

Sorry, I've been under the weather the last few days and I missed your response. Let's try a couple of things. First, try booting your computer in Safe Mode with Networking and see if you can connect. Next, try these two and see if they fix the problem.

Please download and run MS Fix-it from here.
******************************************
To Run the SFC /SCANNOW Command in Windows 7
1. Open an elevated command prompt.

2. To Scan and Repair System Files
NOTE: Scans the integrity of all protected system files and repairs the system files if needed.
A) In the elevated command prompt, type sfc /scannow and press Enter. (see screenshot below)
NOTE: This may take some time to finish.



B) Go to step 4.

3. To Only Verify if the System Files are Corrupted
NOTE: Scans and only verifies the integrity of all proteced system files only.
A) In the elevated command prompt, type sfc /verifyonly and press Enter.

4. When the scan is COMPLETE, hopefully you will see all is ok like the screenshot below.
NOTE: If not, then you can attempt to run a System Restore using a restore POINT dated before the bad file occured to fix it. You may need to repeat doing a System Restore until you find a older restore point that may work.



5. When DONE, close the elevated command prompt.I hope you are feeling better SD. I have tried to copy and paste the log and also attach the log but it said it was too large.
It did find a corrupted file. I did a restore point BACK one MONTH and the Wifi started working again ! That's good right..? LOLL!
Let me know if there is anything else I should do. As always THANKS ! ! ! ! !

Quote

Let me know if there is anything else I should do. As always THANKS
You're welcome. You can run diskcleanup and we're finished.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
2279.

Solve : Backing up files to upgrade XP to Windows 7?

Answer»

Hello,
With support for XP ending NEXT month and after much browsing, researching, etc. apparently the only option I have with this PC is to upgrade from XP to Windows 7.. were thinking about using Windows Easy Transfer to save files, etc.. the tutorial referred to using cds, but with the limited space on the cds, were thinking about using a flash drive.. I have ONE that is 32 GB..

LarryA flashdrive or DVD's would work. I'm sticking with XP and I forsee no problems.Hello SuperDave,
Thanks a bunch for you input!!.. smile.. I am at present backing up my files and will have the Windows 7 CD at the ready in case the WORST case scenario happens and need to update..
Again, thank you for your help!!

Larry Woller
“If there is any kindness I can show, or any good I can do to any fellow being, let me do it now, and not defer or neglect it, as I shall not pass this way again” William Penn
Retired, Independent...
Veteran, SGT, USMC (Vietnam, in country 1965-66, 12th Marine REGIMENT).
COOP/SWOP Observer (since 2001 to present), NWS, ILX, NOAA, Dept of Commerce.
Member National Preparedness Coalition (Dept of Homeland Security/FEMA).
Member (since 2005 to present) BOINC Project (University of Berkeley, Calif.); Princess Margaret Cancer Center/World Community Grid, SIMAP ( Biology, Universities of Munich and Vienna)/ [emailprotected] (Biology and Medicine, University of Karlsruhe, Germany/protein research), Docking (Scripps Institute/University of Delaware)
You were lucky to get your hands on Windows 7. They're quite scarce nowdays.Got the Windows 7 Home Premium 32 bit ordered from WalMart online...had toyed with the idea of Windows 8 but after research, this computer would be borderline as to compatibility, too new to throw away, getting a new one not an option, so opted for Windows 7..have files backed up on a Kingston 32GB flash drive (using Windows Easy Transfer and some on my own) along with Norton 360...hopefully will have all my ducks in a row should the need to upgrade happen...smile

Again, thanks for your reply and input!..

Larry WollerYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

2280.

Solve : Need help removing Panda AV program?

Answer»

I have used Panda AV on my Dell Optima running Windows (now XP) since 2007. I have decided to try Vipre instead, and had no problem loading it on my Samsung laptop with Windows 8. But when I try to run the program (from the same link) on my Dell, It is finding that I have Panda 2011 on the computer. I had uninstalled the 2013 version using Panda's uninstall program, and also did a search to find any other files associated, and deleted those, yet Vipre is still detecting the program. I also tried Cclean to try to get rid of any orphan files, but that did not clear the problem, either. I called Panda tech support and was told I would need to get a "SPECIALIST" to fully uninstall the program. Any ideas?Vipre tech support PROVIDED the following solution:
download and use this program called microsoft fixit tool to try to remove panda from the computer
you can download it from this link
http://support.microsoft.com/mats/Program_Install_and_Uninstall
Here are some instructions on running this tool:

1. Click the green Run Now button on the site linked above.
2. Run the program downloaded
3. Click the Accept button
4. Microsoft Fix It will scan the machine for Windows Install and Uninstall issues
5. Select DETECT problems and let me select the fixes to apply
6. Select Uninstalling
7. Select Panda Antivirus from the programs listed and click Next
8. Select Yes, try uninstall
9. Make sure all the Listed issues are checked and click Next
10. You will get a result status notifying you that the PROCESS succeeded.
11. Select one of the feedback options and click Next
12. Click the Close button
restart the computer

This solution worked perfectly for me! Don't forget that Windows 8 comes with it's on AV called Windows Defender. If you're going to use another AV, Windows Defender will have to be deactivated otherwise, it will CAUSE conflicts.

2281.

Solve : Someone is hacking into my computer via cell phone:?

Answer»

Hello & Thanks ,
SOMEONE is hacking into my computer using their phone .
They are coming in thru my TimeWarnerCable Router/Modem .
I notice them in Network Folder .
They keep changing their MAC address .

Is there a way to stop them ?
Is there a way to track them ?

Thanks..VmHere is some INFORMATION about routers being hacked. If you're sure it's happening through your router, you should contact the company.

2282.

Solve : BlueScreen ntoskrnl.exe?

Answer»

Hi everyone
I have an HP PAVILLON DV6 notebook with i7-2670 processor running Win-7. Outside of the fan working quite frequently, have not had any issues until couple of months ago when BLUE screen popped up and forced a reboot. Have attached the bluescreen-text information. Realize that it has something to do with drivers but not sure how to proceed.
Thanks


[recovering disk SPACE, attachment deleted by admin]Download BlueScreenView:
http://www.nirsoft.net/utils/blue_screen_view.html
unzip downloaded file and double click on BlueScreenView.exe to run the program.
when scanning is done, go to EDIT - Select All
Go to FILE - SAVE Selected Items, and save the report as BSOD.txt
Open BSOD.txt in Notepad, copy all of the content, and paste it into your next reply

2283.

Solve : Problems with soundcard, control panel and apps. Found Misleading.FakeAV??

Answer»

You may as WELL try one of the RESTORE POINT to before these problems started.

2284.

Solve : How do I get rid of TUVARO??

Answer»

DAVE: Achh, How simple is that? It worked. I had already un-installed Firefox and Chrome so all I had to mess with was Internet Explorer. Machine is working like a charm, thank you again Question; I have purchased the Malwarebytes Pro. Is it ok to RUN that together with Avast?
I can't begin to tell you how appreciative I am for your help. Thanks JIMQuote

I have purchased the Malwarebytes Pro. Is it ok to run that together with Avast?
Yes, MBAM Pro will go well with any AV. MBAM Pro is now a full-time scanner and a very good choice. Let's do some cleanup.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore POINTS, you will see a significant change in the free space in C drive)
**************************************
Go to Microsoft Windows Update and get all critical updates.

I SUGGEST using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!DAVE:
Thank you. Well something else has reared it's ugly head. And it has been doing it for some time. I though that we had gotten rid of it but NO. Very frequently, when I am on line OR offline, my screen will fog up and I get the message that "internet Explorer has stopped responding", online or "Widows Explorer has stopped responding", off line or "Microsoft Office has stopped responding. Depending on what I am doing at the time. Once that happens the computer is locked up for who knows how long? I have waited for hours and it never recovered. I go to Task manager and try to shut it down to no avail. The only thing that I can do is do a Power forced shut down and REBOOT. Did I miss something? Other than that, the computer is running very well.To Run the SFC /SCANNOW Command in Windows 7
1. Open an elevated command prompt.

2. To Scan and Repair System Files
NOTE: Scans the INTEGRITY of all protected system files and repairs the system files if needed.
A) In the elevated command prompt, type sfc /scannow and press Enter. (see screenshot below)
NOTE: This may take some time to finish.



B) Go to step 4.

3. To Only Verify if the System Files are Corrupted
NOTE: Scans and only verifies the integrity of all proteced system files only.
A) In the elevated command prompt, type sfc /verifyonly and press Enter.

4. When the scan is complete, hopefully you will see all is ok like the screenshot below.
NOTE: If not, then you can attempt to run a System Restore using a restore point dated before the bad file occured to fix it. You may need to repeat doing a System Restore until you find a older restore point that may work.



5. When done, close the elevated command prompt.DAVE: Well the sfc scan did not reveal anything. It is still acting up. Usually it goes into a perpetual loop when calling up a site and/or it often does it when either shutting down or logging off. Then I have to do forced or power off.. I don't think that I have a retour point that goes back far enough...NOw it is doing it when I try to use WORD or EXCEL.How does your computer work in Safe Mode?DAVE: Thanks for sticking with me. Well it seems to work fine. I am writing this in the safe mode (with networking) now. however, it often works quite well for long periods in NORMAL mode. Right now it is working, it did take a long time to respond when I clicked on REPLY thoughQuote
Right now it is working, it did take a long time to respond when I clicked on REPLY though
Yes, it does that on my computer also but only on this site.

Please download SREng
  • Extract it to Desktop and double click SREngLdr.EXE to run it
  • Select System Repair from the left pane.
  • Click on File Association
  • Select all entries that has an Error status click [Repair]
  • Refer to this image for an example:

  • In your case, it would be .EXE
  • Close SREng now.
.DAVE: Thank you. Well I did it. The machine seems to be running fine. Only time will tell. Thanks again.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2285.

Solve : Windows Update Service?

Answer»

Hi All,
I have a machine, windows 7 64 bit home, that had a viruses in it. I was able to clean them out with malware bytes but it deleted the windows update service. I have scrolled down the list and its not there. I was trying to restart it so I could down LOAD the lastest updates for the machine.

Anyone KNOW of a fix for this?

Thanks
http://www.microsoft.com from here have you tried to manually INSTALL latest security updates? You should be able to re-enable auto updates in properties of my computer. If I had a Windows 7 machine in front of me, I'd point out where to get to it. If no one has responded by the time I get home from work, I will describe from my Windows 7 system. Im stuck behind Windows XP Pro right now. You might have to perform a Repair Install of 7 if the Virus really killed that service, that is if its enabled, but non FUNCTIONAL!Try running your Action Center.

2286.

Solve : DNT for FireFox?

Answer»

I started using Do NotTrack 3 days AGO. Over the past 2 days SAS has detected 166 cookies (94 yesterday, 72 today) -- with a 'quick' SCAN. Preceding this, all of my scans were clean after a 'complete' scan.

I'm starting to think there's a correlation here

Cookies are not a bad thing. Most of the time they just help to make your connection QUICKER.

2287.

Solve : Virus help please?

Answer» QUOTE from: gracette17 on August 28, 2012, 07:37:54 PM
I just tried it again and it turned back on. I chose to open in safe mode... should I run aswMBR?
Boot in Normal mode if you can and run that scan.aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-08-29 08:27:28
-----------------------------
08:27:28.158 OS Version: Windows x64 6.1.7601 Service Pack 1
08:27:28.158 Number of processors: 2 586 0x602
08:27:28.158 ComputerName: JESSICA-PC UserName: Jessica
08:27:29.952 Initialize success
08:27:39.140 AVAST engine defs: 12082800
08:28:58.373 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
08:28:58.373 Disk 0 Vendor: WDC_WD3200BEKT-60V5T1 12.01A12 Size: 305245MB BusType: 11
08:28:58.388 Device \Driver\atapi -> MajorFunction fffffa80047855e8
08:28:58.404 Disk 0 MBR read successfully
08:28:58.404 Disk 0 MBR scan
08:28:58.404 Disk 0 Windows 7 default MBR code
08:28:58.419 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
08:28:58.435 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 289291 MB offset 409600
08:28:58.451 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 15650 MB offset 592877568
08:28:58.529 Disk 0 scanning C:\Windows\system32\drivers
08:29:15.579 Service scanning
08:29:24.409 Service MpKsla7657f45 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A3E08EE5-A537-4FD2-B389-B7BC6D041EC5}\MpKsla7657f45.sys **LOCKED** 32
08:29:42.177 Modules scanning
08:29:42.692 Disk 0 trace - called modules:
08:29:42.692 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
08:29:42.692 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004332790]
08:29:42.708 3 CLASSPNP.SYS[fffff8800195643f] -> nt!IofCallDriver -> [0xfffffa8004331520]
08:29:42.708 5 hpdskflt.sys[fffff880018fd289] -> nt!IofCallDriver -> [0xfffffa8003dbc790]
08:29:42.723 7 ACPI.sys[fffff88000e0d7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80042af060]
08:29:42.723 \Driver\atapi[0xfffffa800476cdf0] -> IRP_MJ_CREATE -> 0xfffffa80047855e8
08:29:44.096 AVAST engine scan C:\Windows
08:29:55.531 AVAST engine scan C:\Windows\system32
08:34:13.560 AVAST engine scan C:\Windows\system32\drivers
08:34:26.801 AVAST engine scan C:\Users\Jessica
08:38:30.757 AVAST engine scan C:\ProgramData
08:39:58.146 Scan finished successfully
08:40:16.180 Disk 0 MBR has been saved successfully to "C:\Users\Jessica\Desktop\MBR.dat"
08:40:16.195 The log file has been saved successfully to "C:\Users\Jessica\Desktop\aswMBR.after scan.txt"
08:40:25.030 Verifying
08:40:35.061 Disk 0 Windows 601 MBR fixed successfully
08:40:50.271 Disk 0 MBR has been saved successfully to "C:\Users\Jessica\Desktop\MBR.dat"
08:40:50.287 The log file has been saved successfully to "C:\Users\Jessica\Desktop\aswMBR. after fix.txt"


I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate BROWSERS only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
I did this and it said it found "no threats" I can't find the log anywhere, even where you SPECIFIED. Quote from: gracette17 on August 30, 2012, 03:01:50 PM
I did this and it said it found "no threats" I can't find the log anywhere, even where you specified.
That's ok. How's your computer running now? Any other issues?It still says Microsoft essentials cannot protect my computer because of a threat. It says it called "Tojan:DOS/Alureon.a" Re-run MBAM:

Code:
Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply..

********************************************
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.



  • If an infected file is detected, the default action will be Cure, click on Continue.



  • If a suspicious file is detected, the default action will be Skip, click on Continue.



  • It MAY ask you to reboot the computer to complete the process. Click on Reboot Now.



  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory..
**********************************************************
  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
2288.

Solve : Program not responding...unable to detect any malware or virus so far?

Answer»

UPDATE!
I think I've found the problem.
I was occasionaly seeing werfault.exe or wermgr.exe (windows prob reporting) in the Taskmgr, so I decided to turn off Windows reporting as well as HP Assist. reporting.
For some reason I decided to unplug the external backup drive after a reboot. Suddenly, everything was fine. No slowdowns or HANGS. I plugged the ext. drive back in,
bam, problems again. Unplug and reboot, no problems!

Here's the back story. A few days back, I discovered the ext. drive which is kept on top of the computer, back behind it on the floor. It must have gotten knocked down and there's an issue with the drive. Maybe that's why I also saw MS Search Indexer running in the tskmgr. Maybe it was hanging on the bad drive?

I'm going to keep it disconnected and continue to monitor things. Is there anything I should cleanup from our scans? Assuming everything continues to run well, do you
have any suggestions as far as utilities to run on the ext. drive to see if I can salvage it? Its a Seagate backup Plus.
Dave, I really appreciate your help and I've gained some addt'l knowledge thru this process.Quote

do you
have any suggestions as far as utilities to run on the ext. drive to see if I can salvage it? Its a Seagate backup Plus.
You could try running a hard drive diagnostic on it.

Run hard drive diagnostics: tacktech.com
Make sure, you SELECT tool, which is appropriate for the brand of your hard drive.
Depending on the program, it'll create bootable floppy, or bootable CD.
If downloaded file is of .iso type, use ImgBurn: imgburn to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable.
For Toshiba hard drives, see here:

Note : If you do not know how to set your computer to boot from CD follow the steps here
************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other SELECTIONS if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe SURFING!
SuperDave,
I thought I was ok, but the problem is back. Not as bad but still locks up and I'm not using the Seagate backup drive.
On a hard boot due to system lockup I had and error..something like
Windows failed to star. A recent hardware or software change might be the cause."
1) Launch startup repair (recommend)
2) Start windows normally

I started windows normally. It will operate fine for a while and then something happens. Seems like a Windows process, but i'm surprised SFC/scanow didn't find anything. There are errors in the windows EVENT viewer that I can post if that helps.
I went thru Evilfantasy's blog about maint. and tried everything, but I'm at a loss right now, short of a system restore or
OS repair.I can't really help with the software/hardware problem. You could try running a diagnostic on your own harddrive and following that, a repair of the OS.
2289.

Solve : .rar.exe files?

Answer»

An ONLINE friend gave me an address from which to dload his pics. I have 7zip that allows me to open RAR files. However at the site the file is LISTED as rar.exe. Is it safe to dload files with exe extensions? Will my 7zip open it?

Thanks in advanceFiles with double extensions (especially if the second one is .exe) are very SUSPICIOUS and almost always dangerous - they are INTENDED to trick you into double clicking them. Many people don't change the default Windows Explorer behaviour of hiding extensions (many people don't even know about it or understand what an extension is) and these are easy targets for malware. This online person does not SOUND like much of a 'friend'.

2290.

Solve : Removing 'Text Enhance' Adware?

Answer»

Sometime in the last few weeks, I've picked up some sort of Adware called "Text Enhance". It follows me everywhere on the web, REGARDLESS of whether I'm using IE, Chrome of Firefox. It makes itself known by underlining certain words in the text of a webpage. If I move your curser on to the word, the adware jumps out at me. How should I go about removing it from my system? I WOULD very much appreciate any help.

See if either of these links help:

http://answers.microsoft.com/en-us/ie/forum/ie8-windows_xp/how-can-i-remove-the-malware-text-enhance-that/654cedb8-9b9d-402e-aa30-bd8299266429

http://botcrawl.com/how-to-remove-text-enhance/Removing "Text Enhance" I found this link on the web which might be very helpful:
Removal Options:
1. Block &(or) Disable & Remove Extension
2. Disallow Third PARTY Flash Storage
3. Manual Removal
4. Anti Malware
5. Restore your computer to a date and TIME before infection.

Source: http://botcrawl.com/how-to-remove-text-enhance/

2291.

Solve : Virus or worm has disabled internet, hidden program and other files?

Answer»

I am sorry but since the PC will not connect to the internet I cannot run an online scan

I receive an error message "no connection to the internet is currently available." work offline is the only option

Do I have to wipe this PC "clean" and start from scratch?

I reran Security Check 317 and here is the log:

Results of screen317's Security Check version 0.99.50
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````[/u]
Windows Firewall Disabled!
AVG Anti-Virus Free Edition 2012
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````[/u]
SpywareBlaster 4.4
SUPERAntiSpyware Free Edition
CCleaner
Java(TM) 6 Update 29
Java version out of Date!
Adobe Flash Player 11.3.300.270
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (14.0.1)
````````Process Check: objlist.exe by Laurent````````[/u]
IObit IObit Malware Fighter IMFsrv.exe
PC TOOLS Firewall Plus FWService.exe
PC Tools Firewall Plus FirewallGUI.exe
iolo Common LIB ioloServiceManager.exe
`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C:: 24% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````[/u]








Quote

I am sorry but since the PC will not connect to the internet I cannot run an online scan

I receive an error message "no connection to the internet is currently available." work offline is the only option

Do I have to wipe this PC "clean" and start from scratch?
Let's see if we can fix the connectin problem.

Please download MiniToolBox to Desktop and run it.



Checkmark the following boxes:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • List content of Hosts
    • List IP Configuration
    • Lst Last 10 Event Viewer Errors
    • List Users, Partitions and Memory Size
    • [/b]
    Click Go and copy/paste the log (Result.txt) into your next post.
    **************************************************************
    Please download Farbar Service Scanner and run it on the computer with the issue.
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.
    *******************************************************
    Total Fragmentation on Drive C:: 24% Defragment your hard drive soon! (Do NOT defrag if SSD!)
    Please take time to defrag your harddrive.
    how do I "defrag"?

    here is the minitoolbox log:

    MiniToolBox by Farbar Version: 23-07-2012
    Ran by Patrick (administrator) on 04-09-2012 at 19:29:46
    Microsoft Windows XP Professional Service Pack 3 (X86)
    Boot Mode: Normal
    ***************************************************************************

    ========================= Flush DNS: ===================================


    Windows IP Configuration



    Successfully flushed the DNS Resolver Cache.


    ========================= IE Proxy Settings: ==============================

    Proxy is not enabled.
    No Proxy Server is set.

    "Reset IE Proxy Settings": IE Proxy Settings were reset.
    ========================= Hosts content: =================================

    127.0.0.1 localhost

    ========================= IP Configuration: ================================

    Intel(R) 82566DC Gigabit Network Connection = Local Area Connection (Media disconnected)


    # ----------------------------------
    # Interface IP Configuration
    # ----------------------------------
    pushd interface ip


    # Interface IP Configuration for "Local Area Connection"

    set address name="Local Area Connection" source=dhcp
    set dns name="Local Area Connection" source=dhcp register=PRIMARY
    set wins name="Local Area Connection" source=dhcp


    popd
    # End of interface IP configuration




    Windows IP Configuration



    Host Name . . . . . . . . . . . . : FamilyRoom

    Primary Dns Suffix . . . . . . . :

    Node Type . . . . . . . . . . . . : Broadcast

    IP Routing Enabled. . . . . . . . : No

    WINS Proxy Enabled. . . . . . . . : No



    Ethernet adapter Local Area Connection:



    Media State . . . . . . . . . . . : Media disconnected

    Description . . . . . . . . . . . : Intel(R) 82566DC Gigabit Network Connection

    Physical Address. . . . . . . . . : 00-19-D1-1A-C7-71

    Server: UnKnown
    Address: 127.0.0.1

    Ping request could not find host google.com. Please check the name and try again.

    Server: UnKnown
    Address: 127.0.0.1

    Ping request could not find host yahoo.com. Please check the name and try again.

    Server: UnKnown
    Address: 127.0.0.1

    Ping request could not find host bleepingcomputer.com. Please check the name and try again.



    Pinging 127.0.0.1 with 32 bytes of data:



    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

    Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



    Ping statistics for 127.0.0.1:

    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

    Approximate round trip times in milli-seconds:

    Minimum = 0ms, Maximum = 0ms, Average = 0ms

    ===========================================================================
    Interface List
    0x1 ........................... MS TCP Loopback interface
    0x2 ...00 19 d1 1a c7 71 ...... Intel(R) 82566DC Gigabit Network Connection - Packet Scheduler Miniport
    ===========================================================================
    ===========================================================================
    Active Routes:
    Network Destination Netmask Gateway Interface Metric
    127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
    255.255.255.255 255.255.255.255 255.255.255.255 2 1
    ===========================================================================
    Persistent Routes:
    None

    ========================= Event log errors: ===============================

    Application errors:
    ==================
    Error: (09/03/2012 07:59:11 PM) (Source: Application Hang) (User: )
    Description: Hanging application SysProt.exe, version 1.0.1.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

    Error: (09/03/2012 10:08:05 AM) (Source: MsiInstaller) (User: FAMILYROOM)FAMILYROOM
    Description: Product: Microsoft Office Professional 2007 -- Error 1706.Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM.(NULL)(NULL)(NULL)(NULL)

    Error: (09/01/2012 08:28:00 AM) (Source: WinMgmt) (User: )
    Description: WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

    Error: (08/28/2012 00:56:36 AM) (Source: WinMgmt) (User: )
    Description: WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

    Error: (08/26/2012 09:40:27 PM) (Source: WinMgmt) (User: )
    Description: WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.

    Error: (08/26/2012 00:36:41 PM) (Source: MsiInstaller) (User: FAMILYROOM)FAMILYROOM
    Description: Product: Microsoft Office Professional 2007 -- Error 1706.Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM.(NULL)(NULL)(NULL)(NULL)

    Error: (08/26/2012 00:36:12 PM) (Source: Application Hang) (User: )
    Description: Hanging application WINWORD.EXE, version 11.0.8345.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

    Error: (08/26/2012 00:35:44 PM) (Source: MsiInstaller) (User: FAMILYROOM)FAMILYROOM
    Description: Product: Microsoft Office Professional 2007 -- Error 1706.Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM.(NULL)(NULL)(NULL)(NULL)

    Error: (08/26/2012 00:24:31 PM) (Source: MsiInstaller) (User: FAMILYROOM)FAMILYROOM
    Description: Product: Microsoft Office Professional 2007 -- Error 1706.Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM.(NULL)(NULL)(NULL)(NULL)

    Error: (08/25/2012 07:11:09 AM) (Source: WinMgmt) (User: )
    Description: WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory.


    System errors:
    =============
    Error: (09/04/2012 03:19:03 PM) (Source: Service Control Manager) (User: )
    Description: The crd service failed to start due to the following error:
    %%1053

    Error: (09/04/2012 03:19:03 PM) (Source: Service Control Manager) (User: )
    Description: Timeout (30000 milliseconds) waiting for the crd service to connect.

    Error: (09/03/2012 09:51:37 AM) (Source: Service Control Manager) (User: )
    Description: The following boot-start or system-start driver(s) failed to load:
    AVGIDSHX

    Error: (09/03/2012 09:51:31 AM) (Source: Service Control Manager) (User: )
    Description: The Vsapint service failed to start due to the following error:
    %%2

    Error: (09/03/2012 09:50:34 AM) (Source: DCOM) (User: NT AUTHORITY)
    Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
    in order to run the server:
    {1BE1F766-5536-11D1-B726-00C04FB926AF}

    Error: (09/03/2012 09:40:15 AM) (Source: DCOM) (User: FAMILYROOM)
    Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
    in order to run the server:
    {A1F4E726-8CF1-11D1-BF92-0060081ED811}

    Error: (09/03/2012 09:40:09 AM) (Source: DCOM) (User: FAMILYROOM)
    Description: DCOM got error "%%1084" attempting to start the service netman with arguments ""
    in order to run the server:
    {BA126AE5-2166-11D1-B1D0-00805FC1270E}

    Error: (09/03/2012 09:39:53 AM) (Source: DCOM) (User: FAMILYROOM)
    Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
    in order to run the server:
    {A1F4E726-8CF1-11D1-BF92-0060081ED811}

    Error: (09/03/2012 09:39:40 AM) (Source: DCOM) (User: FAMILYROOM)
    Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
    in order to run the server:
    {A1F4E726-8CF1-11D1-BF92-0060081ED811}

    Error: (09/02/2012 10:59:39 PM) (Source: DCOM) (User: FAMILYROOM)
    Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments ""
    in order to run the server:
    {A1F4E726-8CF1-11D1-BF92-0060081ED811}


    Microsoft Office Sessions:
    =========================

    ========================= Memory info: ===================================

    Percentage of memory in use: 52%
    Total physical RAM: 1021.83 MB
    Available physical RAM: 484.08 MB
    Total Pagefile: 2458.33 MB
    Available Pagefile: 1795.52 MB
    Total Virtual: 2047.88 MB
    Available Virtual: 1966.93 MB

    ========================= Partitions: =====================================

    2 Drive c: () (Fixed) (Total:171.43 GB) (Free:111.66 GB) NTFS
    3 Drive d: (Backup) (Fixed) (Total:57.63 GB) (Free:23 GB) NTFS
    7 Drive h: (HP SimpleSave) (Fixed) (Total:465.11 GB) (Free:261.06 GB) NTFS
    8 Drive i: (My Passport) (Fixed) (Total:931.48 GB) (Free:547.54 GB) NTFS
    9 Drive j: (USB20FD) (Removable) (Total:7.53 GB) (Free:6.6 GB) FAT32

    ========================= Users: ========================================

    User accounts for \\FAMILYROOM

    Administrator Anna Guest
    HelpAssistant Patrick SUPPORT_388945a0


    **** End of log ****


    and the FSS log:


    Farbar Service Scanner Version: 06-08-2012
    Ran by Patrick (administrator) on 04-09-2012 at 19:30:38
    Running from "C:\Documents and Settings\Patrick\Desktop"
    Microsoft Windows XP Professional Service Pack 3 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    There is no connection to network.
    Attempt to access Google IP returned error: Google IP is unreachable
    Attempt to access Google.com returned error: Other errors
    Attempt to access Yahoo IP returned error: Yahoo IP is unreachable
    Attempt to access Yahoo.com returned error: Other errors


    File Check:
    ========
    C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
    C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
    C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
    C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
    C:\WINDOWS\system32\svchost.exe => MD5 is legit
    C:\WINDOWS\system32\rpcss.dll => MD5 is legit
    C:\WINDOWS\system32\services.exe => MD5 is legit

    Extra List:
    =======
    Gpc(6) hnmwrlspkt(9) IPSec(4) NetBT(5) Packet( pctgntdi(12) pctNDIS(11) PSched(7) Tcpip(3) wsppkt(10)
    0x0F00000004000000010000000200000003000 0000C0000000D0000000E0000000F0000000500 0000060000000700000008000000090000000A0 000000B000000
    IpSec Tag value is correct.

    **** End of log ****after a search on how to do it, I am defragmenting the hard drivemy employment takes me out of town for these next three days in which I will not have access to the infected PC.

    I will be offline until Friday PM.Quote from: padraig on September 04, 2012, 06:01:44 PM
    my employment takes me out of town for these next three days in which I will not have access to the infected PC.

    I will be offline until Friday PM.
    Ok. Is this computer hardwired to the modem? Did you try re-setting the modem? Disconnect the power supply for 30 secs. and then connect it.PC and the laptop that I am using to post to this thread are hard cabled to ubee modem. Time Warner Cable replaced modem two weeks ago to restore telephone service. This was no less than two weeks after the virus blocked access to the internet for the PC only. I did disconnect the power supply to the new modem, WAITED about 1 minute, reconnected and internet service was restored to the laptop only. The PC will not connect to internet through IE8 or Firefox.

    C: defragmentation has been completed. Quote
    The PC will not connect to internet through IE8 or Firefox.
    Did you try another cable?

    You will have to download this on your laptop and transfer it to your PC using a memory stick or disk.

    Please download LSPFix © 2002-2006 Cexx.org.
    Save it to your desktop. Alternate download site available here
    Run LSPFix - Repair LSP Chain
    PRINT these instructions... then disconnect from the Internet and close all browser windows.
    • Double click the LSPFix.exe icon on your desktop.
    • If you had to use the alternate download...double click the "lspfix.zip" file on your desktop.
    • Use XPs Compressed File Extraction Wizard or your own 3RD party zip file program.
    • Extract the "LSPFix.exe" file to your desktop... double click to start the program.
    • Press the "Finish... button.
    • Now...Reboot your computer, normally, to complete the process.
    internet connection has been restored!!! Super Anti-Spy scan returned 33 threats, all Adware, no trojan or worm found

    still have issue with empty program list or "shortcuts" in start menu and USB drive not able to stop to safely eject Good news and bad news. It's good that your internet access is repaired. You could try running Rkill again. And now, the bad news. I'm required to give you this warning.

    It appears your system is infected with a rootkit. A rootkit is a powerful piece of malware, that allows hackers full control over your computer for means of sending attacks over the Internet, or using your computer to generate revenue.

    Malware experts have recommended that we make it clear that with the system under control of a hacker, your computer might become impossible to clean 100%.

    Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. They can disable your antivirus and security tools to prevent detection and removal. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is sent back to the hacker. To learn more about these types of infections, you can refer to:

    What danger is presented by rootkits?
    Rootkits and how to combat them
    r00tkit Analysis: What Is A Rootkit

    If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references:
    How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
    What Should I Do If I've Become A Victim Of Identity Theft?
    Identity Theft Victims Guide - What to do
    It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot
    be completely cleaned or repaired so you can never be sure that you have completely removed a rootkit. The malware may leave so many remnants behind that security tools cannot find them. Tools that claim to be able to remove rootkits cannot guarantee that all traces of it will be removed. Many experts in the security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety. Making this decision is based on what the computer is used for, and what information can be accessed from it. For more information, please read these references very carefully:
    When should I re-format? How should I reinstall?
    Help: I Got Hacked. Now What Do I Do?
    Help: I Got Hacked. Now What Do I Do? Part II
    Where to draw the line? When to recommend a format and reinstall?

    Guides for format and reinstall:

    how-to-reformat-and-reinstall-your-operating-system-the-easy-way

    However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat.
    If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful.

    Please let me know what you have decided to do in your next post. Should you have any questions, please feel free to ask.
    2292.

    Solve : AVG Anti-Virus 2013 compatible with Malwarebytes??

    Answer»

    I have used AVG Anti-Virus Free for years but the newest 2013 version no longer OFFERS Identity Protection. I want to maintain a high level of security while web surfing and paying my BILLS online. So I have decided to pay and switch to AVG Anti-Virus 2013. This antivirus program offers everything AVG Free does plus it adds identity protection, a firewall, and anti-malware capability. My question is: if I install AVG Anti-Virus 2013 with built-in anti-malware protection, can I still use Malwarebytes' AntiMalware? Or WOULD those two programs be incompatible. Any advice will be appreciated. Thank you.

    jandal

    I use Windows XP Pro SP3, an Intel PENTIUM 3 processor, with 1.00 GHz, 384 MB RAMInstall MBAM but only use it for the occasional scan. It's not NECESSARY to have it scanning full-time.

    2293.

    Solve : Need help removing the Luhe.Sirefef trojan.?

    Answer»

    My computer recently became infected with the Luhe.Sirefef. No anti-virus software I have tried has WORKED. AVG said it was there, and that it removed it, but it pops again SECONDS LATER saying its there. I was wondering if anyone would be able to assist me, it would greatly be appreciated. Never mind, I have RESOLVED the issue. measures were pretty drastic, but it's no problem. All I did was delete my user account on the computer, start another admin PROFILE. Ran multiple sweeps of my system and nothing has been found.

    2294.

    Solve : Random music and program problems?

    Answer»

    Hi folks, hope your summer went well.

    I was called to a client because they said there was a security scan that was running and it showed hundreds of viruses, problems with the hard drive and Windows vulnerabilities. I knew it was a fake and went in to do battle. I was able to remove the Babylon toolbar and the fake security program. I used Security Essentials, Malwarebytes and ESET's online scanner.

    I went back because the client said that there were no programs in the start menu. That was a setting in the start menu properties.

    The random music started after all of the scanning was done and the computer was restarted. It LASTS 10-30 seconds and is either English, Spanish or Chinese. It plays even if there are no browsers open. It plays even if there are no music programs open. I started up Task Manager and waited for the music to play, but it did not show up in Applications or Processes.

    Now to top it off they tried to use PrintShop and the program would not start. Tried to repair from the install disk and it would not start. Uninstalled and reinstalled and still the program would not start. And the kicker is the office manager says the owner installed some $500 Adobe program and they do not see it on the computer.

    The computer is in a real estate office that is very busy, I can not take the machine with me.

    1. has anyone had the music problem?
    2. what might cause the problem with the programs not starting even after reinstallation?
    3. why did the program disappear?

    Thanks for any answers.Hi there...

    AdwCleaner Scan
    Please download AdwCleaner by Xplode onto your Desktop.

    • Double CLICK on AdwCleaner.exe to run the tool.
    • Click on Search.
    • A logfile will automatically open after the scan has finished.
    • Please post the content of that logfile in your reply.
    • You can find the logfile at C:\AdwCleaner[Rn].txt as well - N is the order number.
    Thanks, but now I don't have access to the machine. I warned them that it might take a few hours of scans or to be really sure, a complete re-installation of Windows. Luckily they had a backup in place and she has all of her documents saved. They are calling in the other tech that set it up to make sure that all the documents are really backed up. I will keep that program in mind, but I think my part in this sad tale is done.

    I might have another shot at it and I will let you know if I do.Yeah let us know. Sorry to HEAR that.
    2295.

    Solve : I think that my daughter has at least one bug in her machine but I can't find it?

    Answer»

    SuperDave: Thank you OK. I did that. It seems to have disabled my ability to open up Firefox. So I am using ie. Here is the log;
    # AdwCleaner v2.001 - Logfile created 09/14/2012 at 18:14:44
    # Updated 09/09/2012 by Xplode
    # Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
    # User : jim - PC1
    # Boot Mode : NORMAL
    # Running from : C:\Documents and Settings\jim\Desktop\clean computer\adwcleaner.exe
    # Option [Delete]


    ***** [Services] *****


    ***** [Files / Folders] *****

    FILE Deleted : C:\Documents and Settings\jim\Application Data\Mozilla\Firefox\Profiles\ssxm3h3j.default\searchplugins\Askcom.xml
    File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
    Folder Deleted : C:\DOCUME~1\jim\LOCALS~1\Temp\[emailprotected]
    Folder Deleted : C:\Documents and Settings\All Users\Application Data\Ask
    Folder Deleted : C:\Documents and Settings\All Users\Application Data\Trymedia

    ***** [Registry] *****

    Key Deleted : HKCU\Software\IGearSettings
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    Key Deleted : HKLM\Software\Conduit
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v8.0.6001.18702

    Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
    Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]

    -\\ Mozilla Firefox v15.0.1 (en-US)

    Profile name : default
    File : C:\Documents and Settings\test\Application Data\Mozilla\Firefox\Profiles\qxwqi1gg.default\prefs.js

    Deleted : user_pref("avg.install.installDirPath", "C:\\Documents and Settings\\All Users\\Application Data\\AV[...]
    Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
    Deleted : user_pref("extensions.RadioRage_4j.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opense[...]
    Deleted : user_pref("keyword.URL", "hxxp://isearch.avg.com/search?cid=%7B62e0721e-525b-4a03-ac1f-cd7839cd95be%[...]

    Profile name : default
    File : C:\Documents and Settings\jim\Application Data\Mozilla\Firefox\Profiles\ssxm3h3j.default\prefs.js

    Deleted : user_pref("browser.search.defaultengine", "Ask.com");
    Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
    Deleted : user_pref("browser.search.order.1", "Ask.com");
    Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");
    Deleted : user_pref("extensions.RadioRage_4j.openSearchURL", "hxxp://search.mywebsearch.com/mywebsearch/opense[...]
    Deleted : user_pref("keyword.URL", "hxxps://isearch.avg.com/search?cid={BEB0AF7D-1E02-4C09-9612-9B62F9CBA4FF}&[...]

    -\\ Google Chrome v [UNABLE to get version]

    File : C:\Documents and Settings\jim\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

    [OK] File is clean.

    *************************

    AdwCleaner[R1].txt - [3778 octets] - [13/09/2012 18:34:02]
    AdwCleaner[R2].txt - [3838 octets] - [14/09/2012 08:47:37]
    AdwCleaner[S1].txt - [4246 octets] - [14/09/2012 18:14:44]

    ########## EOF - C:\AdwCleaner[S1].txt - [4306 octets] ##########
    SuperDave: OOOPS sorry, belay that last comment. I can get firefox just fine.Any more problems?SUperDave: The machine is running much better. Except for the funny business with Office 2000, it is running very well.
    Also she has to stay away from uisng Internet Explorer as her browser.
    It is time for me to end my visit and return to Arizona and my own problems. So what happens from now on is her problem.
    I think she is happy. Thank you once again for all your patient help. You guys are great... Keep up the good work. JIMOk, thanks. We can do some cleanup now.

    To uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall


    (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
    If this doesn't remove ComboFix, please let me know.
    ***************************************************************
    Click Start> Computer> right click the C Drive and choose Properties> enter
    Click Disk Cleanup from there.



    Click OK on the Disk Cleanup Screen.
    Click Yes on the Confirmation screen.



    This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
    ******************************************************
    Go to Microsoft Windows Update and get all critical updates.

    ----------

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers LIKE Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    2296.

    Solve : File Recovery program? Has highjacked my computer, please help....?

    Answer»

    I downloaded the Eset ONLINE scanner and completed the scan. This was the only log that came up:

    C:\Users\Hainstocks\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0\7618c040-2098c837
    Java/Exploit.CVE-2012-4681.P trojandeleted - quarantined


    As for how my computer is running, well none of the icons on my desktop have come back, nor have the files that are all blank come back to normal. Seems they are till hidden or moved elsewhere. As well the file recovery program is still on the computer, however it is not trying to scan everytime the computer is turned on now. Its just listed in the program files on the start menu.

    How can we get all the files and icons back in the same place they were prior to this hijacking??

    • Please download Unhide by Grinler from here and save it to your desktop.
    • Double click unhide.exe to run the tool.
    • It will take some time to go through all your files, so please be patient.
    • If this tool doesn´t fix the problem, please let me know.
    ***********************************************************
    Please download: HiJackThis to your Desktop.
    • Double Click the HijackThis icon, located on your Desktop.
    • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
    • Accept the license agreement.
    • Click the Open the Misc Tools section button.
    • Click on the Open Uninstall Manager button.
    • Click on the Save list... button and specify where you would like to save this file. When you press Save button a Notepad will open with the contents of that file. Save the file to your desktop.
      Copy and paste this file in your next reply.
    I ran intalled the Unhide program and alot of my stuff came back. I did notice that system tools is still missing things like system retore, and other scanners and debug type things that were there before. I dont remember if exactly everything on other programs etc are there, but all appears ok i think. I ran it twice once with mcafee working as usual and once with it disabled. I rebooted both times as well.

    Here is the list from the trend micro hijacker program you had me install:

    Adobe AIR
    Adobe AIR
    Adobe Flash Player 11 ActiveX
    Adobe Reader 9.5.2
    Apple Application Support
    Apple Software Update
    Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
    Atheros Driver Installation Program
    Canon MP Navigator EX 2.0
    Canon Utilities Easy-PhotoPrint EX
    Canon Utilities My Printer
    Canon Utilities Solution Menu
    Catalyst Control Center - Branding
    D3DX10
    ESET Online Scanner v3
    Google Earth Plug-in
    Google Update Helper
    HijackThis 2.0.2
    Inkjet Printer/Scanner Extended Survey Program
    Java(TM) 6 Update 35
    Junk Mail filter update
    LEGO Universe
    Malwarebytes Anti-Malware version 1.65.0.1400
    McAfee AntiVirus Plus
    Mesh Runtime
    Messenger Companion
    Microsoft SQL SERVER 2005 Compact EDITION [ENU]
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
    Microsoft Works
    MotoHelper MergeModules
    MSVCRT
    MSVCRT_amd64
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    OpenOffice.org 3.3
    QuickTime
    Raptr
    Realtek USB 2.0 Card Reader
    Safari
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
    TOSHIBA Assist
    TOSHIBA Bulletin Board
    TOSHIBA ConfigFree
    TOSHIBA Face Recognition
    TOSHIBA Hardware Setup
    TOSHIBA HDD/SSD Alert
    TOSHIBA Media CONTROLLER
    TOSHIBA Media Controller Plug-in
    TOSHIBA ReelTime
    TOSHIBA Service Station
    TOSHIBA Speech System Applications
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    TOSHIBA Supervisor Password
    TOSHIBA Value Added Package
    TOSHIBA Web Camera Application
    TurboTax 2010
    TurboTax 2011
    Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
    Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
    Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
    VLC media player 1.0.1
    Vuze
    Windows Live Communications PLATFORM
    Windows Live Essentials
    Windows Live Essentials
    Windows Live Installer
    Windows Live Mail
    Windows Live Mail
    Windows Live Mesh
    Windows Live Mesh
    Windows Live Mesh ActiveX Control for Remote Connections
    Windows Live Messenger
    Windows Live Messenger
    Windows Live Messenger Companion Core
    Windows Live Movie Maker
    Windows Live Movie Maker
    Windows Live Photo Common
    Windows Live Photo Common
    Windows Live Photo Gallery
    Windows Live Photo Gallery
    Windows Live PIMT Platform
    Windows Live SOXE
    Windows Live SOXE Definitions
    Windows Live Sync
    Windows Live UX Platform
    Windows Live UX Platform Language Pack
    Windows Live Writer
    Windows Live Writer
    Windows Live Writer
    Windows Live Writer Resources
    Wondershare Photo Collage Studio 4.2.16.1

    I appreciate all your help for sure, at very worst at least i can back up my files and reformat if i need too at a later time. Unless we can get everything back to normal etc.

    Update Your Java (JRE)

    Old versions of Java have vulnerabilities that malware can use to infect your system.

    First Verify your Java Version

    If there are any other version(s) installed then update now.

    Get the new version (if needed)

    If your version is out of date install the newest version of the Sun Java Runtime Environment.

    Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Be sure to close ALL open web browsers before starting the installation.

    Remove any old versions

    1. Download JavaRa and unzip the file to your Desktop.
    2. Open JavaRA.exe and choose Remove Older Versions
    3. Once complete exit JavaRA.

    Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
    **************************************************
    Quote
    As well the file recovery program is still on the computer
    I still can't find that program you're talking about.
    Can you give me more information about it or a screenshot?

    Please try this new tool from MS. It's supposed to fix a number of problems.

    Please download and run MS Fix-it from here. Ok i downloaded the most current JavaRE and I also ran the Microsoft fixit.

    I went through the start button where all the program files are listed and the names of all the programs on the computer are listed, however when i click on the files, they are "empty". If i do a search for the program it seems to be still on the computer, but the program file list is not updated so to get into any programs i have to do a windows search to find it.

    I did also notice that the File Recovery Program that hijacked my computer to begin with is no longer listed in my program file list. So it seems to be removed from what i can tell.

    Any ideas on how i can get the programs listed back in the start button like they normally were etc.? Also there is no system restore listed under accessories --->system tools nor is there disk defrag or disk cleanup etc. But if i search for system restore in the windows explorer it does pop up to start doing a system restore. You can try running Unhide.exe again. If that doesn't work, back up all your important data and do a Repair from the Recovery
    Console below. This is for Vista but it should work for Win7.

    1. Eject and remove any discs or memory cards from your computer.

    2. Click the "Start" button on the desktop to open the Start menu, click the small arrow icon to the right of the lock icon and select "Restart".

    3. Hold the "F8" key on your computer's keyboard as Windows reboots.

    4. Highlight and select "Repair your computer" choose your keyboard type and click "Next".

    5. Choose your user name, type your password if prompted and click "OK" to access the System Recovery Options menu.[/COLOR]
    2297.

    Solve : How do I get a virus intentionally to test this potential anti-virus program??

    Answer»

    My buddy SAYS his AV software will protect my machine from any virus and repair anything in the event a virus does penetrate his protection.
    So I made a wager with him that he may be right, but if not, he will pay for this machine. So, what's a preferable link to click to put this issue to the test?
    I'm serious, he has the $ and I'm using one of my old PC's that is worth way less than his wager.
    I'll post the results - maybe on one of my other machines lol!
    Thanks,
    Mike Call up a computer repair shop, ask for the viruses from their quarantine and they might be nice enough to give them to you, assuming they don't care about liability. You COULD also search for programs online that promise to hack online games, those are almost a sure bet to have viruses in them.

    Just make sure the computer you run them on is offline -- you don't want your computer to be used by the viruses to spread themselves or be involved in credit card fraud.. or worse.I used to have a link to a site that had an RSS feed of viruses (intentionally), but it's on my home PC. I'll look for it later.Check out this site. The files are harmless but will (or should) trip your AV software into action.

    Good luck. Here it is:

    http://malc0de.com/rss/

    Basically each exe in those links CONTAINS malware.Going to check into those links myself for malware for testing. I use to host honeypots to snag hackers and get them to plant tools etc. Then after they have taken over a system, offline it and analyze further. I would intentionally put a system up that looked like a legit business system etc and intentionally have an exploit vulnerability on it for point of entry and let them in and infect it etc. Lots used the Black VNC exploit for easy entry. After the system is done from checking into what they did, I'd push ghost image to it off of a DVD-R and bring it back to clean running with exploit ready for the next hacker to use the same way in. Lots of EXE's were snagged thru that process, but mostly kiddie scripts, malware written by someone other than the hacker. The most COMMON TSR's were keyloggers, although I stopped servving up honeypots when someone tried to turn my honeypot into a relay point for P2P. When I SAW that, I was like ok it was fun baiting them, but its now too dangerous if my honeypot can come back and bite me.

    2298.

    Solve : Suspected Malware Cause of Multiple DLL Errors.?

    Answer»

    Okay, thank-you once again for all your help.Download Windows Repair (all in one) from this site
    Install the program then run it.

    Go to Step 2 and allow it to run CheckDisk by clicking on Do It button:



    Once that is DONE then go to Step 3 and allow it to run System File Check by clicking on Do It button:



    Go to Step 4 and under "System Restore" click on Create button:



    Go to Start Repairs tab and click Start button.



    Please ensure that ONLY items SEEN in the image below are ticked as indicated (they're all CHECKED by default):



    Click on box next to the Restart System when FINISHED. Then click on Start.Thanks for the new suggestion.

    Unfortunately, I was unable to run the program. I first tried with the installer version. It installed with no errors, but then, on launching the application, a message box appeared with message 'Unexpected error'. I then tried the portable version, but the same error occurred on launching the tool. Perhaps it is reliant on a damaged windows DLL? I will schedule another check disk now, via the normal windows interface.Sorry for the delay. I'm going to try one more thing and if it doesn't work I will move this topic to The Windows 7 forum.
    Please go to this site and it will instruct you how to run the Action center. It's suppose to fix a lot of problems.

    2299.

    Solve : computer hangs when trying to follow directions for malware removal?

    Answer»

    Hi: I don't know how to run it in safe mode. Can you explain that to me please and I will try


    DrDHere's how to get into Safe Mode.Hi Dave: I'm just about giving up here. I should say that this is a computer that I use for work. As a virtual employee it's very important to me, as you can imagine. You have been very generous with your time and patient. However,, you and I are in different time zones, I think, so it's like you tell me what to do, and I do it 12 hours later, and then you tell me the next thing, and that takes another 12 hours.

    ANYWAY, I can't get the computer to go into Safe Mode. It doesn't really obey commands and stuff.

    Question: I have copied all my documents and desktop stuff onto an external drive. Can I just do something like reformat or whatever else would work? Whatever has gotten into the computer is still there after all this time. And I'm ready to try something drastic to fix it.

    What do you think?

    Dr. DOK: So I was able to start it in Safe Mode. There is not audio. I guess that's normal for safe mode? Is there anything else I should be looking for in particular? It seems to be working at a normal speed.

    Thanks. What next?

    Dr. D
    Quote

    Can I just do something like reformat or whatever else would work? Whatever has gotten into the computer is still there after all this time. And I'm ready to try something drastic to fix it.
    Yes, a system recovery should take your computer back to the day it was purchased. If you don't have the OS disk here's some information that may be helpful.
    Also here.Hi: did you see the note that said that it works fine in safe mode? Will system recovery still be the best thing to do?

    thanks

    Dr. DQuote
    Hi: did you see the note that said that it works fine in safe mode? Will system recovery still be the best thing to do?
    Only a mimimal amount of services run in Safe Mode. That's why it worked better in safe mode.

    Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
    Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program.
    Click on VIEW > Select Colunms.
    In addition to already pre-selected options, make sure, the Command Line is selected, and PRESS OK.
    Go File>Save As, and save the report as Procexp.txt.
    Attach the file to your next reply.Dave: In safe mode I don't have any internet to do the things you mentioned. Outside of Safe Mode, I don't think I can actually do all of that. I'm a bit stumped.

    Dr. DQuote from: Drd on February 11, 2014, 09:04:56 AM
    Dave: In safe mode I don't have any internet to do the things you mentioned. Outside of Safe Mode, I don't think I can actually do all of that. I'm a bit stumped.

    Dr. D
    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift KEY down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    Thanks, Dave. I will try this.

    Dr. D
    2300.

    Solve : Different photo opens when I try to open picture?

    Answer»

    Yesterday I was placing copies of some pictures into a different folder. I GOT the warning that there was one with the same name in the folder and did I want to replace it with the new one. I chose to do so. Every since then, when I open the one that was to replace the other one-the other once APPEARS! When the thumbnail is on my DESKTOP it looks correct but as soon as I open it, it is the wrong one!

    I ran all my adware and malware scans. I TRIED opening it in a different program. Same trouble.

    Anyone know how I can fix this??

    Thank you

    SIt sounds like TWO different photos had the same name and you replaced one with the other.