InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2251. |
Solve : I was hit by malware. WOT said I was diverted to trovi.com Am I clean now?? |
|
Answer» Yes. You helped me greatly. I'm looking for the pop up message entering your site, it's missing. Tell me something about how our elected officials are trying to hurt your cause and how I can sign up.I have no idea what you're talking about. Do you mean that you're GETTING a popup on this site?Yes I was getting a pop up site when I was initially asking you for help. On 14 Sept, I asked you about how I can help you. Look at that dated thread.If I remember correctly, it said that congress was initiating laws preventing folks like you from the free enterprise in which you exist. I cannot believe I am the first to bring this to your attention. Please advise. TomThis is the first I've heard of it. Are you still getting the pop-up?No.Ok, if there is nothing else, we can do some clean up. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments... This is a very crucial step so make sure you don't skip it. Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles. Double-click Delfix.exe to start the tool. Make sure the following items are checked:
Once finished a logfile will be created. You don't have to attach it to your next reply. ***************************************** Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ********************************************* I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 2252. |
Solve : Extremely S L O W Laptop? |
|
Answer» i ve got the same issue, if there is no other solution i will have to format the hard disk and SET it up new. i ve got the same issue, if there is no other solution i will have to format the hard disk and set it up new.It's quite possible that your problems are not related to this thread. Please start a new thread of your own and I'll help you there.Quote Each time it takes me to the HP recvery manager where my only chices are set computer back to factory setting or go to a restore point. I tried restore point and it says there are none.Here's how to create a disk that will allow you to boot your computer and save all your important data then will have to do the Recovery. Download the OTLPE Standard REATOGO Windows Recovery Environment.
Run hard drive diagnostics: tacktech.com Make SURE, you select tool, which is appropriate for the brand of your hard drive. Depending on the program, it'll create bootable floppy, or bootable CD. If downloaded file is of .iso type, use ImgBurn: imgburn to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable. For Toshiba hard drives, see here: Note : If you do not know how to set your computer to boot from CD follow the steps here *********************************************** That could be a problem with bad RAM. Please run this check just to eliminate that possibility. Test your RAM here. I downloaded the file, but its a EXE file. I transfered it to a CD and tried to boot from the infected laptop but it wouldnt run. Some of info that may help. I did try Kaspersky Rescue 10 program. It came up with over 1200 trojans and viruses and deleted them. ANy other suggestions...?You will need to download the ISO for creating a bootable CD of the other one for USB for Windows. |
|
| 2253. |
Solve : Three Questions about IP attacks? |
|
Answer» I am browsing in the public library . 2. When I abandon the public library i don't observ any problem after removing the viruses. So may be more difficult to infect if you have a dynamic IP ?How do you know you have removed the infections? What protection do you have on your computer?I am trying. But you don't answer any question ?.... Can you answer please I am trying with AVG 2014 malware bytes , adwcleaner, SAS, all the complete CH antivirus recommended tools. The only thing I can do is ask you to do these scans and post the logs to make sure the computer is clean. Please download AdwCleaner by Xplode onto your Desktop. Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon. If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run. When the AdwCleaner program will open, click on the SCAN button as shown below. AdwCleaner will now start to search for malicious files that may be installed on your computer. To remove the files that were detected in the previous step, please click on the Clean button. AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer. Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply. ********************************************* Please download Malwarebytes Anti-Malware from here. Double Click mbam-setup.exe to install the application.
Please download Junkware Removal Tool to your desktop. •Warning! Once the scan is complete JRT will shut down your browser with NO warning. •Shut down your protection software now to avoid potential conflicts. •Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. •Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator •The tool will open and start scanning your system. •Please be patient as this can take a while to complete depending on your system's specifications. •On completion, a log (JRT.txt) is saved to your desktop and will automatically open. •Copy and Paste the JRT.txt log into your next message.I have done these steps a million times. And I would LIKE to see the logs. |
|
| 2254. |
Solve : Multiple processes of wmpnscfg.exe?? |
|
Answer» Used space is 47.6 GB |
|
| 2255. |
Solve : Slow computer and internet problems. Think Infected?? |
|
Answer» Hello Superdave! I guess they told her it would be in her best interest to install an application called Trusteer Rapport and proceeded to walk her through installing it.I have that on my computers and it's a great protection and you can USE it protect not only your banking sites but any SITE you wish. I don't have any problems with my computers. This is the first time I've heard of this. I'm sure the people at Trusteer could give you some insight into this problem. Thanks for the update. |
|
| 2256. |
Solve : Anybody know about Arcade Yum?? |
|
Answer» This was a particular game which was clicked on by accident. I began seeing double underlined words in my text I couldn't get rid of. I just recently removed Google Chrome from my system, now the underlines seem to be gone. However, is this just a game, or is it a virus of some sort they don't tell you about? Is there more I need to do? I hate to lose Google Chrome since I need it for so many applications. Any other suggestions?I can't find too much info about that program that indicates that it is malicious. Why not re-install Chrome and see what happens. We can always run some scans to see what's on your computer.My wifes computer recently started doing the same thing... "Double Underlined Words in text of websites etc". And I am glad i read your post here. While I am not authorized to make any suggestions here in this thread, I have some info on the Arcade YUM, as well as now KNOW what to target on my wifes system that is having the same issue. |
|
| 2257. |
Solve : PUP.Optional.MySearchDial.A? |
|
Answer» Please give me an update on how your computer is working now.malwarebytes is still picking up the PUP.Optional.MySearchDial.A Do you use Chrome and MBAM? I am interested if you would get the same thing, just curiousNo, I don't use Chrome. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments... This is a very crucial step so make sure you don't skip it. Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles. Double-click Delfix.exe to start the tool. Make sure the following items are checked:
Once finished a logfile will be created. You don't have to attach it to your next reply. ************************************** Click Start> Computer> right click the C Drive and CHOOSE Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) **************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you INTERACT with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 2258. |
Solve : Avast installs SafePrice adware without asking? |
|
Answer» Read this, starting at the big BUT... I found it funny that it only allows you to disable it for 24 hr period and then its enabled again..You didn't read far enough. So, here is how to disable Avast SafePrice in Mozilla Firefox and Google Chrome In Mozilla Firefox: Enter the following into your address bar: chrome://wrc/content/options.html This GIVES you access to the “avast! Online Security SETTINGS” screen. Scroll down to the bottom and uncheck “SafePrice Receive SafePrice shopping recommendations on relevant sites.” CLICK on the “Save” button. If this add-on is not installed, nothing HAPPENS. Why it's on one computer & not another is unknown. |
|
| 2259. |
Solve : Trojans in External Drive System Volume Information? |
|
Answer» If an anti-virus SOFTWARE such as Avira tells you that it has detected Trojans in the System VOLUME Information of an external USB hard drive and gives you the opportunity to quarantine them - if you agree to do that will you still be able to open the drive and access your data properly ? I don't want to take a rash decision and lose access to my information. Avira's Real Time Protection is offering the Action "Move to quarantine". My choices are "Apply now" or "Cancel".Apply now. Quote Some of the random forum posts I have found regarding the topic of System Volume Information on external drives make it look like they are a route for lurgies and that they are hard to eliminate. Some people were talking about using Linux CDs to access the System Volume Information Folders in order to delete them and to stop them constantly regenerating with the same virus.Infections are usually placed in the System Volume so that when someone run System Restore they get infected again. You can delete all your Restore Points by going to My Computer, right-click Disk Cleanup and click other options. You can also scan the external drive with your AV, MBAM and AdwCleaner.Why did Avira see the rogue file in the System Volume Information of an external drive when I wasn't doing anything ? Is it normal for external drives to be accessed from time to time? I have a USB key where the initial infection was spotted by Avira and "Denied Access" before the Dr Watson files were "Allowed Access" by the same AV software. It has a light on it so I can see when it is communicating with the computer. Since the problem, I have stopped actively using it but, from time to time, its light flashes so SOMETHING is going on. Is that normal ?Quote Why did Avira see the rogue file in the System Volume Information of an external drive when I wasn't doing anything ?The infection doesn't have to be active in order for it to be detected. Quote Is it normal for external drives to be accessed from time to time?It will scan any drive that is connected. Quote It has a light on it so I can see when it is communicating with the computer. Since the problem, I have stopped actively using it but, from time to time, its light flashes so SOMETHING is going on.Download Panda USB and AutoRun Vaccine and save it to your desktop. * Extract (unzip) the file to your desktop and a folder named USBVaccine will be created. * Open that folder and double-click on USBVaccine.exe to start the program. * Click Run * Click the button to Vaccinate computer. * Insert your USB flash drive. * When the name of the drive appears in the dialog box, click the button to Vaccinate USB drive(s). * Exit Panda USB and AutoRun Vaccine when done. Note: Computer AutoRun Vaccination will prevent any AutoRun file from running, regardless of whether the removable device is infected or not. USB Vaccination disables the autorun file so it cannot be read, modified or replaced by malicious code. The Panda Resarch Blog advises that once USB drives have been vaccinated, they cannot be REVERSED except with a format. If you do this, be sure to back up your data files first or they will be lost during the formatting process. Thank you so much for all of your help. I wonder if I may have been hit by a browser hi-jacking of some kind when the peculiarities with this Windows XP machine began with the file detected on drive F and then the alteration (?) of the Dr Windows file(s). What do you think ? I noticed that when I was re-starting Firefox periodically when it got very slow as RAM allocations became extremely high and/or the Silverlight plug-in stopped working - I would be brought back to a screen that lets you "Restore" your last session. At the top right of the Firefox browser screen there is a downward pointing arrow that indicates downloads - it would animate turning green and descending. This was happening with no TABS open except the one inviting you to restore your tabs from last time - where it lets you select from a list of pages that might have crashed. I observed this occur repeatedly after the infection. I have since managed to uninstall Silverlight. I ran CCleaner and opened Firefox again. The arrow came down again. I uninstalled Firefox, ran CCleaner and installed a fresh copy of Firefox but kept all my settings. The arrow came down again. I uninstalled Firefox - told it to FORGET ALL MY SETTINGS AND PREFERENCES, ran CCleaner and then REINSTALLED Firefox. It opened with no peculiar download animations. How foolish is it to continue to connect to the internet with Windows XP at all ? I have read some reports that say you really shouldn't do it. This would mean an old machine couldn't even be used to watch YouTube videos or stream from Spotify - and that's a real shame. Quote I wonder if I may have been hit by a browser hi-jacking of some kind when the peculiarities with this Windows XP machine began with the file detected on drive F and then the alteration (?) of the Dr Windows file(s).I seriously doubt it but it's impossible for me to say for sure. Quote How foolish is it to continue to connect to the internet with Windows XP at all ?MS and a lot of other experts say it's a bad idea but I'm using it myself and I haven't seen any uptakes in infections in XP. One thing I would recommend is that you don't use MSE as your AV. I'm using Avira at the moment.As MSE is no longer updated for XP, do you mean you recommend against choosing MSE on more modern OSes like Windows 7 ?Quote from: Tatterdemalion on June 29, 2014, 11:44:59 AM As MSE is no longer updated for XP, do you mean you recommend against choosing MSE on more modern OSes like Windows 7 ?MSE is perfectly ok on any OS above XP such as Vista, Windows 7, Windows 8 and 8.1and how experienced are you Efodagin you said WE.. I do not see you as a malware specialist? not much I would say.. just let malware specialist deal with his problem. thank you! |
|
| 2260. |
Solve : PC suddenly turns all the files on ANY usb plugged in into shortcuts? |
|
Answer» Just this morning, i was just transferring huge FILES on my hdd NORMALLY. i was just transferring huge files on my hdd normally.Were you transferring them to another place on your hard drive or to somewhere else? If you transferred them to an external or USB memory drive you can learn more about this problem here. |
|
| 2261. |
Solve : Confusing Avira Results. Is it RIGHT ?? |
|
Answer» Having got in a pickle lately, as my other threads illustrate, I have run an Avira scan on hard DRIVES connected to a Windows 7 PC that I hope has no problems. It has stopped 82.5% of the way through the scan but has shown some detections that it is offering to quarantine. Would it be a good idea for me to "Cancel" Avira's offer to quarantine these files and for me to DELETE the original folders that contain them and THEN run the Avira scan from scratch again ?Just ignore those warnings unless your computer starts ACTING up.So - can you confirm that I don't even need to quarantine those files and that I can just press "Cancel" and close Avira's virus scan as if it had found nothing ??Yes, just ignore them unless your computer starts acting up.Thank you. I know WHAT the flagged files were. They are Poker calculator programs that were "bundled" with what seems like otherwise harmless (and slightly unrelated) audiobooks. I suppose they are no threat at all so long as I don't run them (I never will) and there is no way they could be run without my permission.Quote I suppose they are no threat at all so long as I don't run them (I never will) and there is no way they could be run without my permission.If you don't intend to use them you should uninstall them.Thanks. I'll do so. |
|
| 2262. |
Solve : I have malware "Computer Support Online" popups? |
|
Answer» Quote I have another question that I don't know if it is related or not. When I boot up I get a dialog box named Content Adviser asking me if I want to use the "starthelp.exe" located on the hard drive. It's publisher is unknown. The location of it is C:\program files (x86)\privoxy\starthelp.exe. I haven't been letting it start SINCE I have no clue what it is. Is this ok and how can I keep it from popping up when I boot up?Please try uninstalling that program.I tried to uninstall it with Windows and Revo Uninstaller, however the program did not show up in either. I went into the file and there is no uninstall feature. Do I simply delete the file? Yes, please.I deleted the program. I have to go out of town until Friday when I can check back for any other actions you recommend I take.Did removing that program have any effect?I believe it has helped although I still get some of the same pop ups that Adblock Plus cannot block. I will try running some of the programs to see if they help. We got some company for the weekend and I can't work on it until next week. I apologize for the delay and I really do appreciate your help and patience in this issue. Quote I apologize for the delay and I really do appreciate your help and patience in this issue.Not a problem. We'll go at your pace. In the meantime, try running AdwCleaner and MBAM to see if it picks up anything. I'm curious about those pop-ups. Could you please post a screenshot of one of them? How to post screenshots or images I haven't had much improvement as I thought. I ran AdwCleaner and MBAM and both show no detections. I hope I have attached the copies of pop ups and web pages that open up in new tabs continually. Now the Content Advisor is dealing me fits in IE notifying me several times for each web page that loads and I have to enter my password before I can load the page. I am thinking about wiping the hard drive and reloading Windows. Let me know what you think. Thank you. Download DDS from HERE or HERE and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. * Save both reports to your desktop. * The instructions here ask you to attach the Attach.txt. 1) DDS.txt 2) Attach.txt Instead of attaching, please copy/past both logs into your Thread Note: DDS will INSTRUCT you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copying and pasting it into the reply. •Close the program window, and delete the program from your desktop. Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt ) Here are the logs you requested. Before running DDS I ran MBAM, AdwCleaner, and Super Anti-Spyware Pro and all three found some infections and quarantined them. Ran Microsoft Security Essentials and found no infections. DDS.txt DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 11.0.9600.17126 BrowserJavaVersion: 10.60.2 Run by Char - Bill at 22:55:10 on 2014-06-25 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.4056.2701 [GMT -5:00] . AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\MsMpEng.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\STacSV64.exe C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE C:\Program Files (x86)\ADOBE\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Windows\System32\alg.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\IDT\WDM\sttray64.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\SUPERAntiSpyware\d721cbab-1ddc-4c44-8db9-1bb46169e7e5.com C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe C:\Windows\system32\RunDll32.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe C:\Program Files (x86)\WordWeb\wweb32.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\HP\HP Officejet 4620 series\bin\HPNetworkCommunicator.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\HP\HP Officejet 4620 series\Bin\HPNetworkCommunicator.exe C:\Program Files\Condusiv TECHNOLOGIES\Diskeeper\DkService.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.nbcnews.com/ uSearch Bar = Preserve BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll BHO: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll BHO: LastPass Browser Helper Object: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\d721cbab-1ddc-4c44-8db9-1bb46169e7e5.com uRun: [HP Officejet 4620 series (NET)] "C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN2AO2323905RT:NW" -scfn "HP Officejet 4620 series (NET)" -AutoStart 1 uRun: [IDMSQ] C:\Program Files (x86)\IDMSQ\idmsq.exe /startup mRun: [WordWeb] "C:\Program Files (x86)\WordWeb\wweb32.exe" -startup mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" StartupFolder: C:\Users\CHAR-B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\MONITO~1.LNK - C:\Windows\System32\RunDll32.exe StartupFolder: C:\Users\CHAR-B~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe mPolicies-Explorer: NoActiveDesktop = dword:1 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 mPolicies-System: PromptOnSecureDesktop = dword:0 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll . INFO: HKCU has more than 50 listed DOMAINS. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} - hxxp://i.dell.com/images/global/js/scanner/SysProExe.cab DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab TCP: NameServer = 192.168.1.1 TCP: Interfaces\{9E4B9493-F1B6-46F8-A5E8-5DA4308457EE} : DHCPNameServer = 192.168.1.1 TCP: Interfaces\{9E4B9493-F1B6-46F8-A5E8-5DA4308457EE}\4527164656027596E6463702D4F64756C6 : DHCPNameServer = 192.168.0.1 TCP: Interfaces\{9E4B9493-F1B6-46F8-A5E8-5DA4308457EE}\C496E6B63597370254D243230303D27657563747 : DHCPNameServer = 192.168.3.1 SSODL: WebCheck - x64-BHO: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - x64-BHO: LastPass Browser Helper Object: {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar64.dll x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll x64-TB: LastPass Toolbar: {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar64.dll x64-TB: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - x64-Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe x64-Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe x64-Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe x64-Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe x64-Run: [ISW] x64-IE: {43699cd0-e34f-11de-8a39-0800200c9a66} - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar64.dll . INFO: x64-HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . x64-DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab x64-DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab x64-DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab x64-Notify: GoToAssist - C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - Hosts: 127.0.0.1www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\Char - Bill\AppData\Roaming\Mozilla\Firefox\Profiles\dqytkgi0.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.nbcnews.com FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=BDT3DF&PC=BDT3&dt=061414&q= FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\NOS\bin\np_gp.dll FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll . ============= SERVICES / DRIVERS =============== . R0 DKDFM;Device Filter Manager Driver;C:\Windows\System32\drivers\DKDFM.sys [2012-9-30 40752] R0 DKTLFSMF;Telemetry File System Mini Filter Driver;C:\Windows\System32\drivers\DKTLFSMF.sys [2012-9-30 106832] R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2014-1-25 268512] R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-11-23 55280] R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-5-4 128384] R2 AESTFilters;Andrea ST Filters Service;C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_7f58c91b65c73836\AESTSr64.exe [2010-7-22 89600] R2 BingDesktopUpdate;Bing Desktop Update service;C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [2014-6-3 173792] R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2008-12-18 155648] R3 DKRtWrt;DKRtWrt;C:\Windows\System32\drivers\DKRtWrt.sys [2012-9-30 52048] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\drivers\RtsUStor.sys [2009-11-23 215552] R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk62x64.sys [2009-9-28 395264] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088] S3 cricutexpression2;cricutexpression2;C:\Windows\System32\drivers\cricutexpression2_x64.sys [2011-9-2 70672] S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-6-11 111616] S3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2014-3-11 133928] S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2014-3-11 347872] S3 nosGetPlusHelper;getPlus(R) Helper 3004;C:\Windows\System32\svchost.exe -k nosGetPlusHelper [2009-7-13 27136] S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe [2009-6-26 1124848] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-4-17 59392] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-20 1255736] . =============== Created Last 30 ================ . 2014-06-26 03:27:15122584----a-w-C:\Windows\System32\drivers\MBAMSwissArmy.sys 2014-06-26 03:26:5463704----a-w-C:\Windows\System32\drivers\mwac.sys 2014-06-26 03:26:54--------d-----w-C:\Program Files (x86)\Malwarebytes Anti-Malware 2014-06-26 02:14:3810779000----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{94A14231-87B8-467B-8388-93BE1C33221E}\mpengine.dll 2014-06-26 01:57:47--------d-----w-C:\ProgramData\OEM Links 2014-06-26 01:57:47--------d-----w-C:\MININT 2014-06-26 00:51:101031560----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{CB7EEFF3-2DB9-4EE9-8432-684020541B65}\gapaengine.dll 2014-06-24 01:36:2610779000----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2014-06-21 12:20:24404992----a-w-C:\Windows\SysWow64\CommonDlg.dll 2014-06-14 16:34:2494432----a-w-C:\ProgramData\Microsoft\BingDesktop\Updater\BingDesktopRestarter.exe 2014-06-13 22:36:55--------d-----w-C:\ProgramData\PC-Doctor for Windows 2014-06-13 22:36:27--------d-----w-C:\Program Files\My Dell 2014-06-13 06:18:311031560----a-w-C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2014-06-13 06:17:1898216----a-w-C:\Windows\SysWow64\WindowsAccessBridge-32.dll 2014-06-11 02:21:2593808----a-w-C:\Program Files (x86)\Mozilla Firefox\webapprt-stub.exe 2014-06-08 21:44:53--------d-sh--w-C:\Users\Char - Bill\AppData\Local\EmieUserList 2014-06-08 21:44:53--------d-sh--w-C:\Users\Char - Bill\AppData\Local\EmieSiteList 2014-06-08 16:59:40--------d-s---w-C:\Windows\SysWow64\Microsoft 2014-06-08 14:01:07--------d-----w-C:\ProgramData\PCDr 2014-06-08 01:21:49--------d-----w-C:\Program Files (x86)\Microsoft Security Client 2014-06-08 01:21:44--------d-----w-C:\Program Files\Microsoft Security Client 2014-06-08 00:36:41--------d-----w-C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-06-08 00:26:3791352----a-w-C:\Windows\System32\drivers\mbamchameleon.sys 2014-06-07 23:59:53--------d-----w-C:\Windows\ERUNT 2014-06-07 16:44:06--------d-----w-C:\AdwCleaner 2014-06-07 16:01:40--------d-----w-C:\Program Files (x86)\ESET 2014-06-07 05:28:33--------d-s---w-C:\Windows\System32\CompatTel 2014-06-07 04:49:01167424----a-w-C:\Program Files\Windows Media Player\wmplayer.exe 2014-06-07 04:49:01164864----a-w-C:\Program Files (x86)\Windows Media Player\wmplayer.exe 2014-06-07 04:48:5812625920----a-w-C:\Windows\System32\wmploc.DLL 2014-06-07 04:48:5712625408----a-w-C:\Windows\SysWow64\wmploc.DLL 2014-06-07 04:38:52--------d-----w-C:\Windows\Migration 2014-06-07 04:33:35155584----a-w-C:\Windows\System32\drivers\ataport.sys 2014-06-07 04:33:31461312----a-w-C:\Windows\System32\scavengeui.dll 2014-06-07 04:33:21223752----a-w-C:\Windows\System32\drivers\fvevol.sys 2014-06-07 04:33:01658432----a-w-C:\Windows\System32\RMActivate_isv.exe 2014-06-07 04:33:00626176----a-w-C:\Windows\System32\RMActivate.exe 2014-06-07 04:33:00594944----a-w-C:\Windows\SysWow64\RMActivate_isv.exe 2014-06-07 04:31:5927584----a-w-C:\Windows\System32\drivers\Diskdump.sys 2014-06-07 04:31:59190912----a-w-C:\Windows\System32\drivers\storport.sys 2014-06-07 04:31:582048----a-w-C:\Windows\SysWow64\iologmsg.dll 2014-06-07 04:31:572048----a-w-C:\Windows\System32\iologmsg.dll 2014-06-07 04:31:4848640----a-w-C:\Windows\System32\wwanprotdim.dll 2014-06-07 04:31:48228864----a-w-C:\Windows\System32\wwansvc.dll 2014-06-07 04:31:46335360----a-w-C:\Windows\System32\msieftp.dll 2014-06-07 04:31:45301568----a-w-C:\Windows\SysWow64\msieftp.dll 2014-06-07 04:31:431684928----a-w-C:\Windows\System32\drivers\ntfs.sys 2014-06-07 02:32:08--------d-----w-C:\Users\Char - Bill\AppData\Roaming\IDM2 2014-06-06 20:56:41--------d-----w-C:\Users\Char - Bill\AppData\Local\Programs 2014-06-06 19:05:33878080----a-w-C:\Windows\System32\advapi32.dll 2014-06-06 19:05:33859648----a-w-C:\Windows\System32\tdh.dll 2014-06-06 19:05:331732032----a-w-C:\Windows\System32\ntdll.dll 2014-06-06 19:05:32640512----a-w-C:\Windows\SysWow64\advapi32.dll 2014-06-06 19:05:32619520----a-w-C:\Windows\SysWow64\tdh.dll 2014-06-06 19:05:321292192----a-w-C:\Windows\SysWow64\ntdll.dll 2014-06-06 19:03:52327168----a-w-C:\Windows\System32\mswsock.dll 2014-06-06 19:03:51231424----a-w-C:\Windows\SysWow64\mswsock.dll 2014-06-06 19:02:541887232----a-w-C:\Windows\System32\d3d11.dll 2014-06-06 19:02:541505280----a-w-C:\Windows\SysWow64\d3d11.dll 2014-06-06 17:46:3581408----a-w-C:\Windows\System32\imagehlp.dll 2014-06-06 17:46:35159232----a-w-C:\Windows\SysWow64\imagehlp.dll 2014-06-06 17:46:34484864----a-w-C:\Windows\System32\wer.dll 2014-06-06 17:46:34381440----a-w-C:\Windows\SysWow64\wer.dll 2014-06-06 17:45:432048----a-w-C:\Windows\SysWow64\tzres.dll 2014-06-06 17:45:432048----a-w-C:\Windows\System32\tzres.dll 2014-06-06 17:43:10230400----a-w-C:\Windows\System32\drivers\portcls.sys 2014-06-06 17:43:10116736----a-w-C:\Windows\System32\drivers\drmk.sys 2014-06-06 17:43:093156480----a-w-C:\Windows\System32\win32k.sys 2014-06-06 17:43:0699840----a-w-C:\Windows\System32\drivers\usbccgp.sys 2014-06-06 17:43:067808----a-w-C:\Windows\System32\drivers\usbd.sys 2014-06-06 17:43:0653248----a-w-C:\Windows\System32\drivers\usbehci.sys 2014-06-06 17:43:06343040----a-w-C:\Windows\System32\drivers\usbhub.sys 2014-06-06 17:43:06325120----a-w-C:\Windows\System32\drivers\usbport.sys 2014-06-06 17:43:0630720----a-w-C:\Windows\System32\drivers\usbuhci.sys 2014-06-06 17:43:0625600----a-w-C:\Windows\System32\drivers\usbohci.sys 2014-06-06 17:34:0010702536----a-w-C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{0BB63539-C2A8-4B17-AA07-638F54BE86D2}\mpengine.dll 2014-06-03 19:02:0810993664----a-w-C:\ProgramData\Microsoft\BingDesktop\Updater\BingDesktop.msi . ==================== Find3M ==================== . 2014-06-06 19:18:4970832----a-w-C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2014-06-06 19:18:49692400----a-w-C:\Windows\SysWow64\FlashPlayerApp.exe 2014-05-30 10:02:372724864----a-w-C:\Windows\System32\mshtml.tlb 2014-05-30 10:02:094096----a-w-C:\Windows\System32\ieetwcollectorres.dll 2014-05-30 09:39:43548352----a-w-C:\Windows\System32\vbscript.dll 2014-05-30 09:39:2366048----a-w-C:\Windows\System32\iesetup.dll 2014-05-30 09:38:2948640----a-w-C:\Windows\System32\ieetwproxystub.dll 2014-05-30 09:21:23139264----a-w-C:\Windows\System32\ieUnatt.exe 2014-05-30 09:21:05111616----a-w-C:\Windows\System32\ieetwcollector.exe 2014-05-30 09:20:36752640----a-w-C:\Windows\System32\jscript9diag.dll 2014-05-30 09:11:24940032----a-w-C:\Windows\System32\MsSpellCheckingFacility.exe 2014-05-30 09:08:225782528----a-w-C:\Windows\System32\jscript9.dll 2014-05-30 09:02:392724864----a-w-C:\Windows\SysWow64\mshtml.tlb 2014-05-30 08:55:3638400----a-w-C:\Windows\System32\JavaScriptCollectionAgent.dll 2014-05-30 08:44:28455168----a-w-C:\Windows\SysWow64\vbscript.dll 2014-05-30 08:43:0661952----a-w-C:\Windows\SysWow64\iesetup.dll 2014-05-30 08:42:1651200----a-w-C:\Windows\SysWow64\ieetwproxystub.dll 2014-05-30 08:28:33112128----a-w-C:\Windows\SysWow64\ieUnatt.exe 2014-05-30 08:27:56592896----a-w-C:\Windows\SysWow64\jscript9diag.dll 2014-05-30 08:24:191249280----a-w-C:\Windows\System32\mshtmlmedia.dll 2014-05-30 08:23:222040832----a-w-C:\Windows\System32\inetcpl.cpl 2014-05-30 08:10:4632256----a-w-C:\Windows\SysWow64\JavaScriptCollectionAgent.dll 2014-05-30 07:56:562266112----a-w-C:\Windows\System32\wininet.dll 2014-05-30 07:56:504244992----a-w-C:\Windows\SysWow64\jscript9.dll 2014-05-30 07:50:091068032----a-w-C:\Windows\SysWow64\mshtmlmedia.dll 2014-05-30 07:49:381964544----a-w-C:\Windows\SysWow64\inetcpl.cpl 2014-05-30 07:21:101790976----a-w-C:\Windows\SysWow64\wininet.dll 2014-05-12 12:25:5625816----a-w-C:\Windows\System32\drivers\mbam.sys 2014-05-09 06:14:03477184----a-w-C:\Windows\System32\aepdu.dll 2014-05-09 06:11:23424448----a-w-C:\Windows\System32\aeinv.dll 2014-04-25 02:34:59801280----a-w-C:\Windows\System32\usp10.dll 2014-04-25 02:06:17626688----a-w-C:\Windows\SysWow64\usp10.dll 2014-04-12 02:22:0595680----a-w-C:\Windows\System32\drivers\ksecdd.sys 2014-04-12 02:22:05155072----a-w-C:\Windows\System32\drivers\ksecpkg.sys 2014-04-12 02:19:3829184----a-w-C:\Windows\System32\sspisrv.dll 2014-04-12 02:19:38136192----a-w-C:\Windows\System32\sspicli.dll 2014-04-12 02:19:3728160----a-w-C:\Windows\System32\secur32.dll 2014-04-12 02:19:321460736----a-w-C:\Windows\System32\lsasrv.dll 2014-04-12 02:19:0531232----a-w-C:\Windows\System32\lsass.exe 2014-04-12 02:12:0622016----a-w-C:\Windows\SysWow64\secur32.dll 2014-04-12 02:10:5696768----a-w-C:\Windows\SysWow64\sspicli.dll 2014-04-05 02:47:201903552----a-w-C:\Windows\System32\drivers\tcpip.sys 2014-04-05 02:47:09288192----a-w-C:\Windows\System32\drivers\FWPKCLNT.SYS 2014-03-31 14:35:08270496------w-C:\Windows\System32\MpSigStub.exe . ============= FINISH: 22:55:43.80 =============== Attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 12/23/2009 10:38:39 PM System Uptime: 6/25/2014 10:43:44 PM (0 hours ago) . Motherboard: Dell Inc. | | 0G848F Processor: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz | Microprocessor | 2200/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 289 GiB total, 232.615 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP292: 6/8/2014 8:09:41 AM - Windows Update RP293: 6/8/2014 8:39:25 AM - Revo Uninstaller's restore point - avast! Free Antivirus RP294: 6/8/2014 11:58:59 AM - avast! Free Antivirus Setup RP295: 6/8/2014 12:01:28 PM - Revo Uninstaller's restore point - avast! Free Antivirus RP296: 6/8/2014 5:49:45 PM - Installed Microsoft Fix it 50566 RP297: 6/8/2014 11:45:33 PM - Windows Update RP298: 6/11/2014 10:40:42 PM - Windows Update RP299: 6/13/2014 1:15:17 AM - Installed Java 7 Update 60 RP300: 6/14/2014 11:16:56 AM - Windows Update RP301: 6/14/2014 11:40:06 AM - Revo Uninstaller's restore point - Bing Desktop RP302: 6/14/2014 11:43:35 AM - Revo Uninstaller's restore point - Bing Bar RP303: 6/23/2014 7:52:32 PM - Windows Update . ==== Installed Programs ====================== . AccuChef Adobe AIR Adobe Download Manager Adobe Flash Player 13 ActiveX Adobe Flash Player 13 Plugin Adobe Help Center 2.1 Adobe Photoshop Elements 5.0 Adobe Reader X (10.1.10) CCleaner Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Compatibility Pack for the 2007 Office system Cricut Expression 2 (TM) Driver v1.01 CricutSync Dell Dock Dell Edoc Viewer Dell Touchpad Dell Wireless WLAN Card Utility DirectXInstallService Diskeeper 12 Home EMC 10 Content EMCGadgets64 ESET Online Scanner v3 Google Earth Google Update Helper GoToAssist 8.0.0.514 Hoyle Puzzle Games 2005 HP Officejet 4620 series Basic Device Software HP Officejet 4620 series Help HP Officejet 4620 series Product Improvement Study HP Update I.R.I.S. OCR IDT Audio Intel(R) Graphics Media Accelerator Driver Intel(R) Rapid Storage Technology Intel® Matrix Storage Manager Internet Download Manager² 1.0 Java 7 Update 60 Java Auto Updater Java(TM) 6 Update 14 (64-bit) Java(TM) 6 Update 18 Java(TM) 6 Update 22 Junk Mail filter update LastPass (uninstall only) Malwarebytes Anti-Malware version 2.0.2.1012 Microsoft .NET Framework 4.5.1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Office Access database engine 2007 (English) Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Security Client Microsoft Security Essentials Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Streets & Trips 2010 Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable (x64) Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable Package Microsoft Works Mozilla Firefox 30.0 (x86 en-US) Mozilla Maintenance Service Mozilla Thunderbird 12.0.1 (x86 en-US) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) My Dell Octoshape add-in for Adobe Flash Player OpenOffice.org 3.4.1 PowerDVD DX Pradis 5.0 Quickset64 Revo Uninstaller 1.92 Roxio Activation Module Roxio BackOnTrack Roxio Burn Roxio Central Audio Roxio Central Copy Roxio Central Core Roxio Central Data Roxio Central Tools Roxio Easy CD and DVD Burning Roxio Express Labeler 3 Roxio File Backup Roxio Update Manager Security Update for Microsoft .NET Framework 4.5.1 (KB2898869) Security Update for Microsoft .NET Framework 4.5.1 (KB2901126) Security Update for Microsoft .NET Framework 4.5.1 (KB2931368) Sonic CinePlayer Decoder Pack SUPERAntiSpyware System Requirements Lab for Intel VD64Inst Web Protect for Windows Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Movie Maker Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Live Writer Windows Media Player Firefox Plugin WordWeb . ==== Event Viewer Messages From Past Week ======== . 6/25/2014 8:03:58 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} and APPID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user Inspiron1545\Char - Bill SID (S-1-5-21-4193595447-3364358048-133568859-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 6/25/2014 8:03:58 PM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} and APPID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user Inspiron1545\Char - Bill SID (S-1-5-21-4193595447-3364358048-133568859-1000) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. 6/25/2014 7:40:21 PM, Error: Microsoft-Windows-SharedAccess_NAT [30013] - The DHCP allocator has disabled itself on IP address 169.254.49.123, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope. 6/25/2014 10:44:26 PM, Error: Microsoft-Windows-SharedAccess_NAT [34001] - The ICS_IPV6 failed to configure IPv6 stack. 6/25/2014 10:44:26 PM, Error: Microsoft-Windows-SharedAccess_NAT [30013] - The DHCP allocator has disabled itself on IP address 192.168.1.6, since the IP address is outside the 192.168.137.0/255.255.255.0 scope from which addresses are being allocated to DHCP clients. To enable the DHCP allocator on this IP address, change the scope to include the IP address, or change the IP address to fall within the scope. . ==== End Of File =========================== I can't see anything malicious on your computer that would cause this. I think it's time to save your important data and re-format and re-install your OS.Well I have to agree because it is frustrating being on the internet. I want to thank you for your time and patience with me. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2263. |
Solve : Possible Trojan? Search Conduit won't leave my laptop! LOTS OF CONFLICTS? |
|
Answer» You're WELCOME. I will LOCK this thread. If you need it re-opened, please SEND me a pm. |
|
| 2264. |
Solve : TR/Crypt.XPACK.Gen [Trojan] and Avira's Response? |
|
Answer» I hope not. Thank you for all of your help. Do you think the machine is clear now and I can carry on using it as normal ? Do I tell the ESET program to remove itself ?Quote Do you think the machine is clear now and I can carry on using it as normal ? Do I tell the ESET program to remove itself ?As clean as I can make it being THOUSANDS of kilometers away from you. You can uninstall the ESET scanner. Let's do some cleanup. You may keep MBAM and AdwCleaner on your computer, if you wish. Update them and run them on a regular basis. Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) *************************************** Go to Microsoft Windows Update and GET all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable SHOPPING sites. WOT WARNS you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! THANK YOU for all of your help.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2265. |
Solve : MRT.exe? |
|
Answer» Just sitting using my computer only to suddenly here the PC get a little loud! So I immediately check my task manager to find a file named mrt.exe running at 30%+ CAPACITY of my PROCESSING. Following this, I found some other FILES like svchost.exe, and another that I ended the process for.....also running after mrt.exe was finished running. |
|
| 2266. |
Solve : AVG anti-virus reporting off? |
|
Answer» Try clicking on "Visit our solution center".OK, I WENT over and clicked. The program encountered an error trying to contact the server. I clicked the link, but could not download because the browser is not connected to the internet. Is it time to call this computer FINISHED?Quote Is it time to call this computer finished?No, it's just a glitch. I would suggest that you try all the sites here to see if you can find a solution to that problem. But first, please run the Farbar Service Scanner in Reply # 5 and post the log.Quote from: SuperDave on May 29, 2014, 07:11:48 PM No, it's just a glitch. I would suggest that you try all the sites here to see if you can find a solution to that problem. But first, please run the Farbar Service Scanner in Reply # 5 and post the log. 1. Here is the log. 2. As of now, the PC cannot even detect a wireless network. So I am not connected at all, internet or local. Quote Farbar Service Scanner Version: 21-05-2014Please do this even if you don't have the OS disk. Do you have your OS CD/DVD? If so, 1/ Click the Start button. 2/ From the Start MENU, Click All programs followed by Accessories. 3/ In the Accessories menu, Right Click on the Command Prompt option. 4/ From the drop down menu that appears, Click on the Run as administrator option. 5/ If you have the User Account Control (UAC) enabled you will be asked for authorisation prior to the command prompt opening. You may simply need to press the Continue button if you are the administrator or insert the administrator password etc. 6/ In the Command Prompt window, type: sfc /scannow and then press Enter. 7/ A message will appear stating that the system scan will begin. 8/ Be patient because the scan may take some time. 9/ If any files require replacing SFC will replace them. You may be asked to insert your Vista DVD for this process to continue. 10/ If everything is okay you should, after the scan, see the following message Windows resource protection did not find any integrity violations. 11/ After the scan has completed, Close the command prompt window. I don't......Run it anyway. If there are any problems with the OS files it will prompt you for the disk. |
|
| 2267. |
Solve : Is This PC Clean?? |
|
Answer» I just got a used PC, and wanted to see if everything is clear. # AdwCleaner v3.211 - Report created 28/05/2014 at 20:55:26 mware Quote Malwarebytes Anti-Malware security Quote Sh Results of screen317's Security Check version 0.99.83It looks good. Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system. First Verify your Java Version If there are any other version(s) installed then update now. Get the new version (if needed) If your version is out of date install the newest version of the Sun Java Runtime Environment. Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close ALL open web browsers before starting the installation. Remove any old versions 1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete EXIT JavaRA. Additional Note: The Java Quick Starter (JQS.exe) adds a service to IMPROVE the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. *********************************************** Update your Adobe Reader. get.adobe.com/reader. Be sure to uncheck the Free McAfee Security Scan so it isn't installed.Java is up to date, old versions removed. Adobe is up to date. Anything else just to double check?Not if it's working well. |
|
| 2268. |
Solve : How to add folder, relevant file or URL exceptions to AVG scans?? |
|
Answer» I am using AVG antivirus for my computer. I want to exclude a various necessary folder , FILE or URL from relevant detection by AVG. Also set the exception for a viral file such as Trojan horse, I-Worm, Worm, W32 etc. |
|
| 2269. |
Solve : Scan query? |
|
Answer» In scan reports/summaries the number of objects scanned is usually shown. What is an "object" in this context?What scanner are you talking about?Thanks for INTEREST, SuperDave. I regularly run system security scans (Avira, MalwareBytes, etc) and the scan logs always show "objects scanned:" and show some figure in the hundreds of thousands and I am curious as to what these objects are - I presume they are bits of information stored in the computer, but I'm not sure what that means.Depending on the TYPE of scan that you run it could every file that's on your computer.I understand that the number of objects VARIES with the range of the scan - do you mean that 1 object = 1 file?Quote from: silkie on May 19, 2014, 11:43:22 AM I understand that the number of objects varies with the range of the scan - do you mean that 1 object = 1 file?I would assume that's what they mean.OK - I was curious because it seems an odd word to use about SOMETHING as amorphous as info kept by a computer. Thanks again.You're welcome. I will lock this thread. If you need it re-opened, please send me a PM. |
|
| 2270. |
Solve : PUPs? |
|
Answer» hello all, |
|
| 2271. |
Solve : Banned from AVAST Forum for no known reason? |
|
Answer» I am 76 and retired,with limited knowledge and use of computers.I had Microsoft Sec.Ess.AV on my desktop(XP Home).I changed this to Avast Free.Next DAY I registered in Avast Forum to post a simple question:I have a laptop(Vista Home 64 b.)and a netbook (Win 7 34 b.)and asked Forum whether I could download Avast Free on these other two computers,using the same email address and password.Next day I wanted to check if there was any answer,but I found to my amazement,that I WAS BANNED FROM ENTERING THE FORUM FOREVER!UNBELIEVABLE!I have done nothing to deserve this,I am not a cybercriminal!I called their UK tel.#,called tech support,they directed me to Customer Support.Since May 5,I have 4 different "tickets',that come automatically re the above complaint,BUT NO ANSWER AT ALL FROM AVAST and of course no solution. I am 76 and retired,with limited knowledge and use of computers.I had Microsoft Sec.Ess.AV on my desktop(XP Home).I changed this to Avast Free.Next day I registered in Avast Forum to post a simple question:I have a laptop(Vista Home 64 b.)and a netbook (Win 7 34 b.)and asked Forum whether I could download Avast Free on these other two computers,using the same email address and password.Next day I wanted to check if there was any answer,but I found to my amazement,that I WAS BANNED FROM ENTERING THE FORUM FOREVER!Unbelievable!I have done nothing to deserve this,I am not a cybercriminal!I called their UK tel.#,called tech support,they directed me to Customer Support.Since May 5,I have 4 different "tickets',that come automatically re the above complaint,BUT NO ANSWER AT ALL FROM AVAST and of course no solution.Being banned from their forum seems very strange. Is that forum at http://forum.avast.com/? I have avast Free installed on 3 computers at home. I am not absolutely sure about registering multiple computers but, if I recall correctly, you do not need a different email address and password for each computer. I do have a note to myself that I have two email addresses associated with my avast registrations. Since I have it installed on 3 computers, my recording of 2 email addresses either indicates a separate address for each registration is not necessary or I have failed to record the address used for one of my registrations. So, I suggest simply trying multiple registrations with the same email address and password. If it is not allowed, you will get an indication of that in some way. I suggest you not reject avast due to your negative experience with that forum. Avast is a very good antivirus program. Thank you so much for your response.Yes,the link is the same that will ban me and the text makes it clear that the ban is not set to expire(their text). And because I can not enter at all,I have no way that I can think of to register with a different user name and password.This is part of what is so unbelievable.The other part of course,that other than the automatic giving of new ticket numbers every time(I now have 4 different ones from different days)they do not answer my complaint.I marked it urgent,doesn't help.They just seem to ignore it.So,for now,I am leaving Avast on my XP desktop(along with other defenses and use that computer rarely and for very limited purposes),but I am really reluctant to download Avast on my other 2 computers,even though I would like to.I will probably settle on AVG,but I am STILL waiting a few days in the hope that one of my complaint letters will be responded to.Amazing,that there is never a dull moment with computers and one can always EXPECT the unexpected! In the meantime,thank Heavens for smart people like you,who are taking the time and are devoted to council people like me! Thank you again!!! |
|
| 2272. |
Solve : My machine frequentlty goes off to "La-la land" for an undetermined period? |
|
Answer» I was recently able to get rid of a thing called "Tuvaro" through the help of SuperDave. I am very thankful to him for that. However a bug or something was LEFT behind that wasn't too much of a pain at first but is getting impossible to work around. Very frequently when I am on the internet, or using "Office" features or just "Logging off" the machine goes into a mode where it just runs indefinitely and I am unable to control it or do anything except Power off. I doesn't happen if I am playing a game or on "Skype" just when I am using Word or Excel or Internet Explorer. Thanks for reading. Appreciate any help that I can get. JIMGEEK: Thanks for your reply. Yes I am pretty well backed up. I recently had to reformat my ENTIRE OS and I thought that I had everything backed up but later found that I had lost most of my pictures [ouch]. I will check out the Seagate tools. I am hoping that I will not have to reformat again. It was shortly after I reformatted the last time that I picked up the "TUVARO" thing, what ever it was, it was causing me a lot of grief.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. ************************************************* Please download Junkware Removal Tool to your desktop. •Warning! Once the scan is complete JRT will shut down your browser with NO warning. •Shut down your protection software now to avoid potential conflicts. •Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. •Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator •The tool will open and start scanning your system. •Please be patient as this can take a while to complete depending on your system's specifications. •On completion, a log (JRT.txt) is saved to your desktop and will automatically open. •Copy and Paste the JRT.txt log into your next message.SUPER DAVE: Okay, I ran Adware and MBAM. MBAM took 2 1/2 hours to run and found no items. Logs follow. Will do JRT tomorrow. # AdwCleaner v3.022 - Report created 28/03/2014 at 12:53:13 # Updated 13/03/2014 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Jim - JIM-PC # Running from : C:\Users\Jim\Downloads\adwcleaner.exe # Option : Clean ***** [ Services ] ***** ***** [ Files / Folders ] ***** Folder Deleted : C:\Program Files (x86)\HiDefMedia Folder Deleted : C:\Windows\Installer\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1} Folder Deleted : C:\Windows\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219} Folder Deleted : C:\Users\Jim\AppData\Roaming\Systweak File Deleted : C:\Windows\System32\roboot64.exe ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\NCTAudioCDGrabber2.DLL Key Deleted : HKLM\SOFTWARE\Classes\nctaudiocdwriter2.audiocdwriter2 Key Deleted : HKLM\SOFTWARE\Classes\nctaudiocdwriter2.audiocdwriter2.1 Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0BBF19A5-BE50-4E06-A340-6777A505E490} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{869E753F-BD0D-4832-8131-94FEEE058AE3} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2D77AC8A-0A4C-40D0-9557-51907A575E45} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458E-AE16-1C1D8255C28A} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0BBF19A5-BE50-4E06-A340-6777A505E490} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2BEF239C-752E-4001-8048-F256E0D8CD93} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{49C00A51-6E59-41FE-B3FA-2D2157FAD67B} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{6DFF5DBA-AE3A-46DB-B301-ECFFC6DB2982} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{869E753F-BD0D-4832-8131-94FEEE058AE3} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DE34CD67-F1C8-4001-9A23-B8A68F63F377} Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7F4EFF06-7032-458E-AE16-1C1D8255C28A} Key Deleted : HKCU\Software\systweak Key Deleted : HKLM\Software\systweak Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6DDE8071-E4BA-461B-8A96-990DFAA0EBD1} Key Deleted : [x64] HKLM\SOFTWARE\Savings Bull Key Deleted : [x64] HKLM\SOFTWARE\SavingsBull Filter Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{813BA625-B0FA-48D8-9B75-59759C88C219} Key Deleted : HKLM\Software\Classes\Installer\Features\1708EDD6AB4EB164A86999D0AF0ABE1D Key Deleted : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91 Key Deleted : HKLM\Software\Classes\Installer\Products\1708EDD6AB4EB164A86999D0AF0ABE1D Key Deleted : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91 ***** [ Browsers ] ***** -\\ Internet Explorer v11.0.9600.16521 ************************* AdwCleaner[R0].txt - [7307 octets] - [08/02/2014 13:10:56] AdwCleaner[R1].txt - [1939 octets] - [11/02/2014 15:20:39] AdwCleaner[R2].txt - [1505 octets] - [12/02/2014 10:55:40] AdwCleaner[R3].txt - [2258 octets] - [13/02/2014 10:43:25] AdwCleaner[R4].txt - [1402 octets] - [14/02/2014 14:54:08] AdwCleaner[R5].txt - [2798 octets] - [28/02/2014 09:38:45] AdwCleaner[R6].txt - [1648 octets] - [28/02/2014 09:47:03] AdwCleaner[R7].txt - [5652 octets] - [28/03/2014 12:52:39] AdwCleaner[S0].txt - [7093 octets] - [08/02/2014 13:11:40] AdwCleaner[S1].txt - [1759 octets] - [11/02/2014 17:40:56] AdwCleaner[S2].txt - [3927 octets] - [11/02/2014 17:44:05] AdwCleaner[S3].txt - [1354 octets] - [14/02/2014 14:54:37] AdwCleaner[S4].txt - [2683 octets] - [28/02/2014 09:42:14] AdwCleaner[S5].txt - [5456 octets] - [28/03/2014 12:53:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [5516 octets] ########## Malwarebytes Anti-Malware (PRO) 1.75.0.1300 www.malwarebytes.org Database version: v2014.03.28.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16521 Jim :: JIM-PC [administrator] Protection: Enabled 3/28/2014 12:59:30 PM mbam-log-2014-03-28 (12-59-30).txt Scan type: Full scan (C:\|D:\|E:\|F:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 760618 Time elapsed: 3 hour(s), 7 minute(s), 42 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry VALUES Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) SUPERDAVE: The JRT log: JRT log 3/29/2014 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.3 (03.23.2014:1) OS: Windows 7 Home Premium x64 Ran by Jim on Sat 03/29/2014 at 9:51:58.75 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smallfrogs studio ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sat 03/29/2014 at 9:57:01.95 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes' Anti-Rootkit Please download Malwarebytes' Anti-Rootkit and save it to your desktop.
Then I got e-mail from malwarebytes advising me to upgrade my Pro Malwarebytes vs 1.75 to vs. 2.0 {no cost} which I did and I ran a quick scan and found two more PUPs which were quarantined. NOTE: The suspect malfunction has not reoccurred since JRT deleted that one registry key. Could that have been the problem?Yes, that may have been the problem. Give it a few days to see how it runs and then get back to me.SUPERDAVE: Okay, will do. Thank you very very much. SUPERDAVE: OK, it has been one month since the last posting and I thought that I would give you an update. Occasionally the machine will still "LOOP" off while running Internet Explorer or Shop 2000. Since I added Shop 2000 to the startup menu it (shop 2000) has been all right however it still does it once in a while on Internet Explorer. The only way I can get it to stop is to RESTART the machine. I can live with that. If you have any further ideas I would appreciate hearing about them, Otherwise I guess the post should be closed. Thanks again for all of your help. Have a great day, JIMCould you please explain "loop off"?Could you please explain "Loop off"?SUPERDAVE: "loop off" Sorry! that is an expression that I haven't used for many many years. It applied to old transistor/diode logic circuits that would get hung up in a "race" condition, due to slow solid state switching devices, and just keep recycling in that state indefinitely. We called it looping. The only way to stop it was to power down or physically introduce a "glitch". Then the guilty component had to be located and replaced. Anyway, it is those times in that past that I remember when my computer starts doing that. I don't think that modern circuits can do that but maybe, with a little adjusting, software can do that. I remember that, using machine language, I could make some of the old Solid State computers chase themselves. I dunno I'm too old to try to learn new technology. Thanks for the memory.....JIM P.S. I hope that I haven't said anything that was in-appropriate here. If so, it was not intended.Ok. So the wheels were just spinning. Please try this: Open Taskmanager and keep it open. When it starts to loop try to determine how much memory is being used and which process is using it. |
|
| 2273. |
Solve : do you need firewall and antivirus for windows 8.1?? |
|
Answer» got windows 8.1 and currently just USE AVG, should I get a firewall too? (which free version do you recommend?) |
|
| 2274. |
Solve : Spam Sent from Hotmail, but Account Not Hacked? |
|
Answer» My partners HOTMAIL account keeps sending emails to her contacts list with URLs - SPAM in other words. Sorry Dave, but I think you are wrong.Accounts are "hacked" by figuring out the password. 2-factor authentication does absolutely nothing to prevent this because the password is usually acquired through a malware infection. Keyloggers can acquire both the E-mail address and password, and they can also determine and send back any saved passwords in most major browsers. 2-Factor authentication is only used for logging into webmail. IMAP outgoing servers cannot use 2-factor authentication because then they wouldn't be IMAP servers. Additionally, by controlling a piece of software on the users machine (the trojan) a person can easily just send the E-mail from their machine. TL;DR: It's a malware infection.We can run some scans to make sure the computer is clean then we take it from there. Please download AdwCleaner by Xplode onto your Desktop. Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon. [/URL] If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run. When the AdwCleaner program will open, click on the Scan button as shown below. [/URL] AdwCleaner will now start to search for malicious files that may be installed on your computer. To remove the files that were detected in the previous STEP, please click on the Clean button. [/URL] AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now delete all detected adware from your computer. When it is done it will display an alert that explains what PUPs (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer. Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply. ************************************************ Please download Malwarebytes Anti-Malware from here. Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM PROCEED with the disinfection process. If ASKED to restart the computer, please do so immediately. ************************************************* Please download Junkware Removal Tool to your desktop. •Warning! Once the scan is complete JRT will shut down your browser with NO warning. •Shut down your protection software now to avoid potential conflicts. •Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. •Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator •The tool will open and start scanning your system. •Please be patient as this can take a while to complete depending on your system's specifications. •On completion, a log (JRT.txt) is saved to your desktop and will automatically open. •Copy and Paste the JRT.txt log into your next message.Quote from: MarkAClarkson on April 26, 2014, 05:57:48 AM Microsoft SELL to SPAM hackers all of your contact lists and then SELL you the software to prevent this occurring. Recently purchased a Luma 1020 running Win8. You MUST have a Outlook Account and MUST upload all of your contacts details including email address and phone numbers. More data for Microsoft to sell. I closed my Hotmail account 5 years ago, because that is the ONLY way to prevent SPAM being sent to all your contacts as if it came from you. Got an email today from someone else's Hotmail account. BIG BILL needs the revenue streams to fund his works of supererogation.
Microsoft SELL to SPAM hackers all of your contact lists and then SELL you the software to prevent this occurring.Almost everybody uses their E-mail address to sign up for stuff. Most sites that take an E-mail address will sell it to third parties. Microsoft doesn't sell any products for Anti-malware/spyware purposes. Quote Recently purchased a Luma 1020 running Win8. You MUST have a Outlook Account and MUST upload all of your contacts details including email address and phone numbers.This is false. Quote because that is the ONLY way to prevent SPAM being sent to all your contacts as if it came from you. Got an email today from someone else's Hotmail account.E-mails can be dead-simple to compromise. People use easily predictable passwords or select poor security questions- (There are only so many flavours of ice cream), or their machine get's infected. Quote BIG BILL needs the revenue streams to fund his works of supererogation.This expresses a strong ignorance in the area of how corporations and organizations work. |
|
| 2275. |
Solve : File footprints? |
|
Answer» Here's a copy of the JRT.txt file. I am working on backing up my pc before I install and run Malwarebytes' Anti-Rootkit. Again, PLEASE let me know if you think any of this information might be indicative of someone putting something on my pc to monitor my activities. Thanks! Again, please let me know if you think any of this information might be indicative of someone putting something on my pc to monitor my activities.There's no evidence of that yet. Were you able to run the MBAM rootkit scanner? |
|
| 2276. |
Solve : I need help fast! ICE Cyber Crime Center has blocked computer? |
|
Answer» Malwarebytes' Anti-Rootkit
|
|
| 2277. |
Solve : problem with keyboards? |
|
Answer» Hi, my computer was good to go this morning, then for some reasons the keyboard starts becoming messed up, i tried to reboot to see if that worked however each time i rebooted,the problem still persist and become worse, now all my keys stop working ,some keys when i pressed will become something irrevalant (ex: backspace = 83j, esc=$57) and even when i did nothing, my computer would keep spamming some random characters, first it was 4444444 then 9999 then hj or even spam enter or space ) , my backspace and some numbers still worked earlier but after numerous attempt to reboots, they became messed up too. |
|
| 2278. |
Solve : Lost WiFi Since Infection? |
|
Answer» Sorry, I've been under the weather the last few days and I missed your response. Let's try a couple of things. First, try booting your computer in Safe Mode with Networking and see if you can connect. Next, try these two and see if they fix the problem. Let me know if there is anything else I should do. As always THANKSYou're welcome. You can run diskcleanup and we're finished. Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ************************************************ Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 2279. |
Solve : Backing up files to upgrade XP to Windows 7? |
|
Answer» Hello, |
|
| 2280. |
Solve : Need help removing Panda AV program? |
|
Answer» I have used Panda AV on my Dell Optima running Windows (now XP) since 2007. I have decided to try Vipre instead, and had no problem loading it on my Samsung laptop with Windows 8. But when I try to run the program (from the same link) on my Dell, It is finding that I have Panda 2011 on the computer. I had uninstalled the 2013 version using Panda's uninstall program, and also did a search to find any other files associated, and deleted those, yet Vipre is still detecting the program. I also tried Cclean to try to get rid of any orphan files, but that did not clear the problem, either. I called Panda tech support and was told I would need to get a "SPECIALIST" to fully uninstall the program. Any ideas?Vipre tech support PROVIDED the following solution: |
|
| 2281. |
Solve : Someone is hacking into my computer via cell phone:? |
|
Answer» Hello & Thanks , |
|
| 2282. |
Solve : BlueScreen ntoskrnl.exe? |
|
Answer» Hi everyone |
|
| 2283. |
Solve : Problems with soundcard, control panel and apps. Found Misleading.FakeAV?? |
|
Answer» You may as WELL try one of the RESTORE POINT to before these problems started. |
|
| 2284. |
Solve : How do I get rid of TUVARO?? |
|
Answer» DAVE: Achh, How simple is that? It worked. I had already un-installed Firefox and Chrome so all I had to mess with was Internet Explorer. Machine is working like a charm, thank you again Question; I have purchased the Malwarebytes Pro. Is it ok to RUN that together with Avast? I have purchased the Malwarebytes Pro. Is it ok to run that together with Avast?Yes, MBAM Pro will go well with any AV. MBAM Pro is now a full-time scanner and a very good choice. Let's do some cleanup. Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore POINTS, you will see a significant change in the free space in C drive) ************************************** Go to Microsoft Windows Update and get all critical updates. I SUGGEST using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!DAVE: Thank you. Well something else has reared it's ugly head. And it has been doing it for some time. I though that we had gotten rid of it but NO. Very frequently, when I am on line OR offline, my screen will fog up and I get the message that "internet Explorer has stopped responding", online or "Widows Explorer has stopped responding", off line or "Microsoft Office has stopped responding. Depending on what I am doing at the time. Once that happens the computer is locked up for who knows how long? I have waited for hours and it never recovered. I go to Task manager and try to shut it down to no avail. The only thing that I can do is do a Power forced shut down and REBOOT. Did I miss something? Other than that, the computer is running very well.To Run the SFC /SCANNOW Command in Windows 7 1. Open an elevated command prompt. 2. To Scan and Repair System Files NOTE: Scans the INTEGRITY of all protected system files and repairs the system files if needed. A) In the elevated command prompt, type sfc /scannow and press Enter. (see screenshot below) NOTE: This may take some time to finish. B) Go to step 4. 3. To Only Verify if the System Files are Corrupted NOTE: Scans and only verifies the integrity of all proteced system files only. A) In the elevated command prompt, type sfc /verifyonly and press Enter. 4. When the scan is complete, hopefully you will see all is ok like the screenshot below. NOTE: If not, then you can attempt to run a System Restore using a restore point dated before the bad file occured to fix it. You may need to repeat doing a System Restore until you find a older restore point that may work. 5. When done, close the elevated command prompt.DAVE: Well the sfc scan did not reveal anything. It is still acting up. Usually it goes into a perpetual loop when calling up a site and/or it often does it when either shutting down or logging off. Then I have to do forced or power off.. I don't think that I have a retour point that goes back far enough...NOw it is doing it when I try to use WORD or EXCEL.How does your computer work in Safe Mode?DAVE: Thanks for sticking with me. Well it seems to work fine. I am writing this in the safe mode (with networking) now. however, it often works quite well for long periods in NORMAL mode. Right now it is working, it did take a long time to respond when I clicked on REPLY thoughQuote Right now it is working, it did take a long time to respond when I clicked on REPLY thoughYes, it does that on my computer also but only on this site. Please download SREng
|
|
| 2285. |
Solve : Windows Update Service? |
|
Answer» Hi All, |
|
| 2286. |
Solve : DNT for FireFox? |
|
Answer» I started using Do NotTrack 3 days AGO. Over the past 2 days SAS has detected 166 cookies (94 yesterday, 72 today) -- with a 'quick' SCAN. Preceding this, all of my scans were clean after a 'complete' scan. |
|
| 2287. |
Solve : Virus help please? |
Answer» QUOTE from: gracette17 on August 28, 2012, 07:37:54 PMI just tried it again and it turned back on. I chose to open in safe mode... should I run aswMBR?Boot in Normal mode if you can and run that scan.aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-08-29 08:27:28 ----------------------------- 08:27:28.158 OS Version: Windows x64 6.1.7601 Service Pack 1 08:27:28.158 Number of processors: 2 586 0x602 08:27:28.158 ComputerName: JESSICA-PC UserName: Jessica 08:27:29.952 Initialize success 08:27:39.140 AVAST engine defs: 12082800 08:28:58.373 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 08:28:58.373 Disk 0 Vendor: WDC_WD3200BEKT-60V5T1 12.01A12 Size: 305245MB BusType: 11 08:28:58.388 Device \Driver\atapi -> MajorFunction fffffa80047855e8 08:28:58.404 Disk 0 MBR read successfully 08:28:58.404 Disk 0 MBR scan 08:28:58.404 Disk 0 Windows 7 default MBR code 08:28:58.419 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048 08:28:58.435 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 289291 MB offset 409600 08:28:58.451 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 15650 MB offset 592877568 08:28:58.529 Disk 0 scanning C:\Windows\system32\drivers 08:29:15.579 Service scanning 08:29:24.409 Service MpKsla7657f45 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{A3E08EE5-A537-4FD2-B389-B7BC6D041EC5}\MpKsla7657f45.sys **LOCKED** 32 08:29:42.177 Modules scanning 08:29:42.692 Disk 0 trace - called modules: 08:29:42.692 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ACPI.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys 08:29:42.692 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004332790] 08:29:42.708 3 CLASSPNP.SYS[fffff8800195643f] -> nt!IofCallDriver -> [0xfffffa8004331520] 08:29:42.708 5 hpdskflt.sys[fffff880018fd289] -> nt!IofCallDriver -> [0xfffffa8003dbc790] 08:29:42.723 7 ACPI.sys[fffff88000e0d7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa80042af060] 08:29:42.723 \Driver\atapi[0xfffffa800476cdf0] -> IRP_MJ_CREATE -> 0xfffffa80047855e8 08:29:44.096 AVAST engine scan C:\Windows 08:29:55.531 AVAST engine scan C:\Windows\system32 08:34:13.560 AVAST engine scan C:\Windows\system32\drivers 08:34:26.801 AVAST engine scan C:\Users\Jessica 08:38:30.757 AVAST engine scan C:\ProgramData 08:39:58.146 Scan finished successfully 08:40:16.180 Disk 0 MBR has been saved successfully to "C:\Users\Jessica\Desktop\MBR.dat" 08:40:16.195 The log file has been saved successfully to "C:\Users\Jessica\Desktop\aswMBR.after scan.txt" 08:40:25.030 Verifying 08:40:35.061 Disk 0 Windows 601 MBR fixed successfully 08:40:50.271 Disk 0 MBR has been saved successfully to "C:\Users\Jessica\Desktop\MBR.dat" 08:40:50.287 The log file has been saved successfully to "C:\Users\Jessica\Desktop\aswMBR. after fix.txt" I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate BROWSERS only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt I did this and it said it found "no threats" I can't find the log anywhere, even where you SPECIFIED. Quote from: gracette17 on August 30, 2012, 03:01:50 PM I did this and it said it found "no threats" I can't find the log anywhere, even where you specified.That's ok. How's your computer running now? Any other issues?It still says Microsoft essentials cannot protect my computer because of a threat. It says it called "Tojan:DOS/Alureon.a" Re-run MBAM: Code: Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.. ********************************************
**********************************************************
|
|
| 2288. |
Solve : Program not responding...unable to detect any malware or virus so far? |
|
Answer» UPDATE! do youYou could try running a hard drive diagnostic on it. Run hard drive diagnostics: tacktech.com Make sure, you SELECT tool, which is appropriate for the brand of your hard drive. Depending on the program, it'll create bootable floppy, or bootable CD. If downloaded file is of .iso type, use ImgBurn: imgburn to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable. For Toshiba hard drives, see here: Note : If you do not know how to set your computer to boot from CD follow the steps here ************************************************ Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other SELECTIONS if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ************************************************* Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe SURFING! SuperDave, I thought I was ok, but the problem is back. Not as bad but still locks up and I'm not using the Seagate backup drive. On a hard boot due to system lockup I had and error..something like Windows failed to star. A recent hardware or software change might be the cause." 1) Launch startup repair (recommend) 2) Start windows normally I started windows normally. It will operate fine for a while and then something happens. Seems like a Windows process, but i'm surprised SFC/scanow didn't find anything. There are errors in the windows EVENT viewer that I can post if that helps. I went thru Evilfantasy's blog about maint. and tried everything, but I'm at a loss right now, short of a system restore or OS repair.I can't really help with the software/hardware problem. You could try running a diagnostic on your own harddrive and following that, a repair of the OS. |
|
| 2289. |
Solve : .rar.exe files? |
|
Answer» An ONLINE friend gave me an address from which to dload his pics. I have 7zip that allows me to open RAR files. However at the site the file is LISTED as rar.exe. Is it safe to dload files with exe extensions? Will my 7zip open it? |
|
| 2290. |
Solve : Removing 'Text Enhance' Adware? |
|
Answer» Sometime in the last few weeks, I've picked up some sort of Adware called "Text Enhance". It follows me everywhere on the web, REGARDLESS of whether I'm using IE, Chrome of Firefox. It makes itself known by underlining certain words in the text of a webpage. If I move your curser on to the word, the adware jumps out at me. How should I go about removing it from my system? I WOULD very much appreciate any help. |
|
| 2291. |
Solve : Virus or worm has disabled internet, hidden program and other files? |
|
Answer» I am sorry but since the PC will not connect to the internet I cannot run an online scan I am sorry but since the PC will not connect to the internet I cannot run an online scanLet's see if we can fix the connectin problem. Please download MiniToolBox to Desktop and run it. Checkmark the following boxes:
************************************************************** Please download Farbar Service Scanner and run it on the computer with the issue.
Total Fragmentation on Drive C:: 24% Defragment your hard drive soon! (Do NOT defrag if SSD!) Please take time to defrag your harddrive. how do I "defrag"? here is the minitoolbox log: MiniToolBox by Farbar Version: 23-07-2012 Ran by Patrick (administrator) on 04-09-2012 at 19:29:46 Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= Hosts content: ================================= 127.0.0.1 localhost ========================= IP Configuration: ================================ Intel(R) 82566DC Gigabit Network Connection = Local Area Connection (Media disconnected) # ---------------------------------- # Interface IP Configuration # ---------------------------------- pushd interface ip # Interface IP Configuration for "Local Area Connection" set address name="Local Area Connection" source=dhcp set dns name="Local Area Connection" source=dhcp register=PRIMARY set wins name="Local Area Connection" source=dhcp popd # End of interface IP configuration Windows IP Configuration Host Name . . . . . . . . . . . . : FamilyRoom Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Broadcast IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No Ethernet adapter Local Area Connection: Media State . . . . . . . . . . . : Media disconnected Description . . . . . . . . . . . : Intel(R) 82566DC Gigabit Network Connection Physical Address. . . . . . . . . : 00-19-D1-1A-C7-71 Server: UnKnown Address: 127.0.0.1 Ping request could not find host google.com. Please check the name and try again. Server: UnKnown Address: 127.0.0.1 Ping request could not find host yahoo.com. Please check the name and try again. Server: UnKnown Address: 127.0.0.1 Ping request could not find host bleepingcomputer.com. Please check the name and try again. Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 0x1 ........................... MS TCP Loopback interface 0x2 ...00 19 d1 1a c7 71 ...... Intel(R) 82566DC Gigabit Network Connection - Packet Scheduler Miniport =========================================================================== =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1 255.255.255.255 255.255.255.255 255.255.255.255 2 1 =========================================================================== Persistent Routes: None ========================= Event log errors: =============================== Application errors: ================== Error: (09/03/2012 07:59:11 PM) (Source: Application Hang) (User: ) Description: Hanging application SysProt.exe, version 1.0.1.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (09/03/2012 10:08:05 AM) (Source: MsiInstaller) (User: FAMILYROOM)FAMILYROOM Description: Product: Microsoft Office Professional 2007 -- Error 1706.Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM.(NULL)(NULL)(NULL)(NULL) Error: (09/01/2012 08:28:00 AM) (Source: WinMgmt) (User: ) Description: WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory. Error: (08/28/2012 00:56:36 AM) (Source: WinMgmt) (User: ) Description: WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory. Error: (08/26/2012 09:40:27 PM) (Source: WinMgmt) (User: ) Description: WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory. Error: (08/26/2012 00:36:41 PM) (Source: MsiInstaller) (User: FAMILYROOM)FAMILYROOM Description: Product: Microsoft Office Professional 2007 -- Error 1706.Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM.(NULL)(NULL)(NULL)(NULL) Error: (08/26/2012 00:36:12 PM) (Source: Application Hang) (User: ) Description: Hanging application WINWORD.EXE, version 11.0.8345.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (08/26/2012 00:35:44 PM) (Source: MsiInstaller) (User: FAMILYROOM)FAMILYROOM Description: Product: Microsoft Office Professional 2007 -- Error 1706.Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM.(NULL)(NULL)(NULL)(NULL) Error: (08/26/2012 00:24:31 PM) (Source: MsiInstaller) (User: FAMILYROOM)FAMILYROOM Description: Product: Microsoft Office Professional 2007 -- Error 1706.Setup cannot find the required files. Check your connection to the network, or CD-ROM drive. For other potential solutions to this problem, see SETUP.CHM.(NULL)(NULL)(NULL)(NULL) Error: (08/25/2012 07:11:09 AM) (Source: WinMgmt) (User: ) Description: WinMgmt could not initialize the core parts. This could be due to a badly installed version of WinMgmt, WinMgmt repository upgrade failure, insufficient disk space or insufficient memory. System errors: ============= Error: (09/04/2012 03:19:03 PM) (Source: Service Control Manager) (User: ) Description: The crd service failed to start due to the following error: %%1053 Error: (09/04/2012 03:19:03 PM) (Source: Service Control Manager) (User: ) Description: Timeout (30000 milliseconds) waiting for the crd service to connect. Error: (09/03/2012 09:51:37 AM) (Source: Service Control Manager) (User: ) Description: The following boot-start or system-start driver(s) failed to load: AVGIDSHX Error: (09/03/2012 09:51:31 AM) (Source: Service Control Manager) (User: ) Description: The Vsapint service failed to start due to the following error: %%2 Error: (09/03/2012 09:50:34 AM) (Source: DCOM) (User: NT AUTHORITY) Description: DCOM got error "%%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error: (09/03/2012 09:40:15 AM) (Source: DCOM) (User: FAMILYROOM) Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error: (09/03/2012 09:40:09 AM) (Source: DCOM) (User: FAMILYROOM) Description: DCOM got error "%%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error: (09/03/2012 09:39:53 AM) (Source: DCOM) (User: FAMILYROOM) Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error: (09/03/2012 09:39:40 AM) (Source: DCOM) (User: FAMILYROOM) Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error: (09/02/2012 10:59:39 PM) (Source: DCOM) (User: FAMILYROOM) Description: DCOM got error "%%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Microsoft Office Sessions: ========================= ========================= Memory info: =================================== Percentage of memory in use: 52% Total physical RAM: 1021.83 MB Available physical RAM: 484.08 MB Total Pagefile: 2458.33 MB Available Pagefile: 1795.52 MB Total Virtual: 2047.88 MB Available Virtual: 1966.93 MB ========================= Partitions: ===================================== 2 Drive c: () (Fixed) (Total:171.43 GB) (Free:111.66 GB) NTFS 3 Drive d: (Backup) (Fixed) (Total:57.63 GB) (Free:23 GB) NTFS 7 Drive h: (HP SimpleSave) (Fixed) (Total:465.11 GB) (Free:261.06 GB) NTFS 8 Drive i: (My Passport) (Fixed) (Total:931.48 GB) (Free:547.54 GB) NTFS 9 Drive j: (USB20FD) (Removable) (Total:7.53 GB) (Free:6.6 GB) FAT32 ========================= Users: ======================================== User accounts for \\FAMILYROOM Administrator Anna Guest HelpAssistant Patrick SUPPORT_388945a0 **** End of log **** and the FSS log: Farbar Service Scanner Version: 06-08-2012 Ran by Patrick (administrator) on 04-09-2012 at 19:30:38 Running from "C:\Documents and Settings\Patrick\Desktop" Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. There is no connection to network. Attempt to access Google IP returned error: Google IP is unreachable Attempt to access Google.com returned error: Other errors Attempt to access Yahoo IP returned error: Yahoo IP is unreachable Attempt to access Yahoo.com returned error: Other errors File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= Gpc(6) hnmwrlspkt(9) IPSec(4) NetBT(5) Packet( pctgntdi(12) pctNDIS(11) PSched(7) Tcpip(3) wsppkt(10) 0x0F00000004000000010000000200000003000 0000C0000000D0000000E0000000F0000000500 0000060000000700000008000000090000000A0 000000B000000 IpSec Tag value is correct. **** End of log ****after a search on how to do it, I am defragmenting the hard drivemy employment takes me out of town for these next three days in which I will not have access to the infected PC. I will be offline until Friday PM.Quote from: padraig on September 04, 2012, 06:01:44 PM my employment takes me out of town for these next three days in which I will not have access to the infected PC.Ok. Is this computer hardwired to the modem? Did you try re-setting the modem? Disconnect the power supply for 30 secs. and then connect it.PC and the laptop that I am using to post to this thread are hard cabled to ubee modem. Time Warner Cable replaced modem two weeks ago to restore telephone service. This was no less than two weeks after the virus blocked access to the internet for the PC only. I did disconnect the power supply to the new modem, WAITED about 1 minute, reconnected and internet service was restored to the laptop only. The PC will not connect to internet through IE8 or Firefox. C: defragmentation has been completed. Quote The PC will not connect to internet through IE8 or Firefox.Did you try another cable? You will have to download this on your laptop and transfer it to your PC using a memory stick or disk. Please download LSPFix © 2002-2006 Cexx.org. Save it to your desktop. Alternate download site available here Run LSPFix - Repair LSP Chain PRINT these instructions... then disconnect from the Internet and close all browser windows.
still have issue with empty program list or "shortcuts" in start menu and USB drive not able to stop to safely eject Good news and bad news. It's good that your internet access is repaired. You could try running Rkill again. And now, the bad news. I'm required to give you this warning. It appears your system is infected with a rootkit. A rootkit is a powerful piece of malware, that allows hackers full control over your computer for means of sending attacks over the Internet, or using your computer to generate revenue. Malware experts have recommended that we make it clear that with the system under control of a hacker, your computer might become impossible to clean 100%. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. They can disable your antivirus and security tools to prevent detection and removal. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is sent back to the hacker. To learn more about these types of infections, you can refer to: What danger is presented by rootkits? Rootkits and how to combat them r00tkit Analysis: What Is A Rootkit If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? What Should I Do If I've Become A Victim Of Identity Theft? Identity Theft Victims Guide - What to do It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired so you can never be sure that you have completely removed a rootkit. The malware may leave so many remnants behind that security tools cannot find them. Tools that claim to be able to remove rootkits cannot guarantee that all traces of it will be removed. Many experts in the security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety. Making this decision is based on what the computer is used for, and what information can be accessed from it. For more information, please read these references very carefully: When should I re-format? How should I reinstall? Help: I Got Hacked. Now What Do I Do? Help: I Got Hacked. Now What Do I Do? Part II Where to draw the line? When to recommend a format and reinstall? Guides for format and reinstall: how-to-reformat-and-reinstall-your-operating-system-the-easy-way However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat. If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful. Please let me know what you have decided to do in your next post. Should you have any questions, please feel free to ask. |
|
| 2292. |
Solve : AVG Anti-Virus 2013 compatible with Malwarebytes?? |
|
Answer» I have used AVG Anti-Virus Free for years but the newest 2013 version no longer OFFERS Identity Protection. I want to maintain a high level of security while web surfing and paying my BILLS online. So I have decided to pay and switch to AVG Anti-Virus 2013. This antivirus program offers everything AVG Free does plus it adds identity protection, a firewall, and anti-malware capability. My question is: if I install AVG Anti-Virus 2013 with built-in anti-malware protection, can I still use Malwarebytes' AntiMalware? Or WOULD those two programs be incompatible. Any advice will be appreciated. Thank you. |
|
| 2293. |
Solve : Need help removing the Luhe.Sirefef trojan.? |
|
Answer» My computer recently became infected with the Luhe.Sirefef. No anti-virus software I have tried has WORKED. AVG said it was there, and that it removed it, but it pops again SECONDS LATER saying its there. I was wondering if anyone would be able to assist me, it would greatly be appreciated. Never mind, I have RESOLVED the issue. measures were pretty drastic, but it's no problem. All I did was delete my user account on the computer, start another admin PROFILE. Ran multiple sweeps of my system and nothing has been found. |
|
| 2294. |
Solve : Random music and program problems? |
|
Answer» Hi folks, hope your summer went well.
I might have another shot at it and I will let you know if I do.Yeah let us know. Sorry to HEAR that. |
|
| 2295. |
Solve : I think that my daughter has at least one bug in her machine but I can't find it? |
|
Answer» SuperDave: Thank you OK. I did that. It seems to have disabled my ability to open up Firefox. So I am using ie. Here is the log;
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
*************************************************************** Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ****************************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers LIKE Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 2296. |
Solve : File Recovery program? Has highjacked my computer, please help....? |
|
Answer» I downloaded the Eset ONLINE scanner and completed the scan. This was the only log that came up:
Please download: HiJackThis to your Desktop.
Here is the list from the trend micro hijacker program you had me install: Adobe AIR Adobe AIR Adobe Flash Player 11 ActiveX Adobe Reader 9.5.2 Apple Application Support Apple Software Update Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver Atheros Driver Installation Program Canon MP Navigator EX 2.0 Canon Utilities Easy-PhotoPrint EX Canon Utilities My Printer Canon Utilities Solution Menu Catalyst Control Center - Branding D3DX10 ESET Online Scanner v3 Google Earth Plug-in Google Update Helper HijackThis 2.0.2 Inkjet Printer/Scanner Extended Survey Program Java(TM) 6 Update 35 Junk Mail filter update LEGO Universe Malwarebytes Anti-Malware version 1.65.0.1400 McAfee AntiVirus Plus Mesh Runtime Messenger Companion Microsoft SQL SERVER 2005 Compact EDITION [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Works MotoHelper MergeModules MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) OpenOffice.org 3.3 QuickTime Raptr Realtek USB 2.0 Card Reader Safari Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) TOSHIBA Assist TOSHIBA Bulletin Board TOSHIBA ConfigFree TOSHIBA Face Recognition TOSHIBA Hardware Setup TOSHIBA HDD/SSD Alert TOSHIBA Media CONTROLLER TOSHIBA Media Controller Plug-in TOSHIBA ReelTime TOSHIBA Service Station TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA Supervisor Password TOSHIBA Value Added Package TOSHIBA Web Camera Application TurboTax 2010 TurboTax 2011 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) VLC media player 1.0.1 Vuze Windows Live Communications PLATFORM Windows Live Essentials Windows Live Essentials Windows Live Installer Windows Live Mail Windows Live Mail Windows Live Mesh Windows Live Mesh Windows Live Mesh ActiveX Control for Remote Connections Windows Live Messenger Windows Live Messenger Windows Live Messenger Companion Core Windows Live Movie Maker Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Common Windows Live Photo Gallery Windows Live Photo Gallery Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live Sync Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Windows Live Writer Windows Live Writer Resources Wondershare Photo Collage Studio 4.2.16.1 I appreciate all your help for sure, at very worst at least i can back up my files and reformat if i need too at a later time. Unless we can get everything back to normal etc. Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system. First Verify your Java Version If there are any other version(s) installed then update now. Get the new version (if needed) If your version is out of date install the newest version of the Sun Java Runtime Environment. Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close ALL open web browsers before starting the installation. Remove any old versions 1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA. Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. ************************************************** Quote As well the file recovery program is still on the computerI still can't find that program you're talking about. Can you give me more information about it or a screenshot? Please try this new tool from MS. It's supposed to fix a number of problems. Please download and run MS Fix-it from here. Ok i downloaded the most current JavaRE and I also ran the Microsoft fixit. I went through the start button where all the program files are listed and the names of all the programs on the computer are listed, however when i click on the files, they are "empty". If i do a search for the program it seems to be still on the computer, but the program file list is not updated so to get into any programs i have to do a windows search to find it. I did also notice that the File Recovery Program that hijacked my computer to begin with is no longer listed in my program file list. So it seems to be removed from what i can tell. Any ideas on how i can get the programs listed back in the start button like they normally were etc.? Also there is no system restore listed under accessories --->system tools nor is there disk defrag or disk cleanup etc. But if i search for system restore in the windows explorer it does pop up to start doing a system restore. You can try running Unhide.exe again. If that doesn't work, back up all your important data and do a Repair from the Recovery Console below. This is for Vista but it should work for Win7. 1. Eject and remove any discs or memory cards from your computer. 2. Click the "Start" button on the desktop to open the Start menu, click the small arrow icon to the right of the lock icon and select "Restart". 3. Hold the "F8" key on your computer's keyboard as Windows reboots. 4. Highlight and select "Repair your computer" choose your keyboard type and click "Next". 5. Choose your user name, type your password if prompted and click "OK" to access the System Recovery Options menu.[/COLOR] |
|
| 2297. |
Solve : How do I get a virus intentionally to test this potential anti-virus program?? |
|
Answer» My buddy SAYS his AV software will protect my machine from any virus and repair anything in the event a virus does penetrate his protection. |
|
| 2298. |
Solve : Suspected Malware Cause of Multiple DLL Errors.? |
|
Answer» Okay, thank-you once again for all your help.Download Windows Repair (all in one) from this site |
|
| 2299. |
Solve : computer hangs when trying to follow directions for malware removal? |
|
Answer» Hi: I don't know how to run it in safe mode. Can you explain that to me please and I will try Can I just do something like reformat or whatever else would work? Whatever has gotten into the computer is still there after all this time. And I'm ready to try something drastic to fix it.Yes, a system recovery should take your computer back to the day it was purchased. If you don't have the OS disk here's some information that may be helpful. Also here.Hi: did you see the note that said that it works fine in safe mode? Will system recovery still be the best thing to do? thanks Dr. DQuote Hi: did you see the note that said that it works fine in safe mode? Will system recovery still be the best thing to do?Only a mimimal amount of services run in Safe Mode. That's why it worked better in safe mode. Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program. Click on VIEW > Select Colunms. In addition to already pre-selected options, make sure, the Command Line is selected, and PRESS OK. Go File>Save As, and save the report as Procexp.txt. Attach the file to your next reply.Dave: In safe mode I don't have any internet to do the things you mentioned. Outside of Safe Mode, I don't think I can actually do all of that. I'm a bit stumped. Dr. DQuote from: Drd on February 11, 2014, 09:04:56 AM Dave: In safe mode I don't have any internet to do the things you mentioned. Outside of Safe Mode, I don't think I can actually do all of that. I'm a bit stumped.If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift KEY down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line. Thanks, Dave. I will try this. Dr. D |
|
| 2300. |
Solve : Different photo opens when I try to open picture? |
|
Answer» Yesterday I was placing copies of some pictures into a different folder. I GOT the warning that there was one with the same name in the folder and did I want to replace it with the new one. I chose to do so. Every since then, when I open the one that was to replace the other one-the other once APPEARS! When the thumbnail is on my DESKTOP it looks correct but as soon as I open it, it is the wrong one! |
|