Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2301.

Solve : Nasty Bug - No Access Allowed to Fix It.?

Answer» YUP, formatting is the way to go now that you have saved your important data. BTW, the use of DVD-RW's is a less expensive way to backup your data. Good luck.Good suggestion! Thanks.So now I have tried to reformat via factory files within the computer and it has seized up, maybe because of the virus, I don't KNOW. I don't think he has a disc supplied at purchase. Quote from: copespeak on February 04, 2014, 07:03:25 PM
So now I have tried to reformat via factory files within the computer and it has seized up, maybe because of the virus, I don't know. I don't think he has a disc supplied at purchase.
No, it shouldn't freeze up during a reformat because of INFECTIONS. Perhaps a hardware problem is causing it to freeze. He can always borrow a disk as long as it's the same version as what's installed on the machine.I can't get it to progress past the point where it says there is an error.Quote from: copespeak on February 04, 2014, 07:03:25 PM
So now I have tried to reformat via factory files within the computer
What does that mean? You cannot format the system drive from within Windows. EXACTLY what are you doing?I have chosen the option to 'recover' (not system restore)? Maybe the virus extends into that, I don't know.I'm sorry - but I really don't know what you mean. From where have you chosen that option. PLEASE KEEP in mind we can't see your screen - you need to describe to us what you are doing.I chose 'restore to factory settings', and it proceeded for a while, then I got this notice (see attachment). Then it just loops ... you click OK and then it starts again.

Thanks for your patience!

[recovering disk space, attachment deleted by admin]If there is a major bug in the system it could potentially prevent you from returning to factory settings. SuperDave's suggestion of a format and reinstall is your best bet. If I were you I'd boot to a Windows disc, delete the system partition, recreate it, format, and install Windows from scratch.Thanks Allan, yes, I am trying to find someone who has one we can borrow! Nothing like a fresh start.
2302.

Solve : Screen Flashes Red and White After a not Responding Program?

Answer» I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a UNIQUE name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Here's the log:
[emailprotected] as DOWNLOADER log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=ce424a03787b5a449a8f843cacaa48cb
# engine=13635
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-04-17 12:06:41
# local_time=2013-04-17 10:06:41 (+1000, AUS Eastern Standard Time)
# country="Australia"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=1799 16775165 100 96 0 0 0 0
# compatibility_mode=5893 16776573 100 94 0 117833851 0 0
# compatibility_mode=6657 16777214 0 14 23114310 23114310 0 0
# scanned=265839
# found=5
# CLEANED=3
# scan_time=8117
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\Users\All Users\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll"
sh=75DFDC05C5D5F0C3B930B5B6871B6528EC9C22EA ft=1 fh=cff868ace0c06f1a vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll"
sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll"
sh=75DFDC05C5D5F0C3B930B5B6871B6528EC9C22EA ft=1 fh=cff868ace0c06f1a vn="a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll"
sh=800E4F9CAD354DBEF9E64F23375C61DB3107C290 ft=1 fh=cd4294964f0acafb vn="multiple threats (cleaned by deleting - quarantined)" ac=C fn="C:\TDDownload\SpeedyComputer.exe"Please run ESET and see if anything shows up.Hi Dave, I ran ESET but nothing came up. No threats was found. I found that my computer is not bad now, and programs are running okay. Except AVG kept saying that C:/program files/autoguarder/autoguarder.exe is still there. I cannot find it in the location provided.Ok, download and install MSE and run a scan and see if it finds the same thing as AVG.

Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
Ni Dave, MSE says that Autoguarder.exe is still there, but in a different location. It looks like it copied itself to another location at c:/system32/autoguarder.exe.
Now I know that system32 is a very important file so I tried to remove it with MSE. It did, but somehow the virus file come up again after reboot or shutting down. Also I realised that a file(C:/program files/Autoguarder/Folder.bat) was created by something, and my AVG keep detecting them but failed to remove them completely. I opened the batch file in notepad and found that it tries to delete all "dll" files in system32. So everytime My pc boots up a cmd window shows up. But most of the action were denied. However I think 5 dll files were still deleted by the virus.somehow it's not affecting my system mch, but I am very worried.
thanks!
Ok Please uninstall this program: C:/program files/Autoguarder

Please download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it



Click the "Scan" button to start scan

Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives



On completion of the scan click save log, save it to your desktop and post in your next reply
Hi Dave, I tried to uninstall Autoguarder.exe, but it say's access denied. I tried changing the security settings on access, but it didn't work.
Anyways heres the log:
aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software
Run date: 2013-04-22 11:34:16
-----------------------------
11:34:16.420 OS Version: Windows x64 6.1.7600
11:34:16.420 Number of processors: 4 586 0x2A07
11:34:16.421 ComputerName: JIANSFAMLIY-PC UserName: jian's famliy
11:34:18.848 Initialize success
11:35:16.930 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
11:35:16.936 Disk 0 Vendor: Size: 0MB BusType: 0
11:35:17.053 Disk 0 MBR read successfully
11:35:17.058 Disk 0 MBR scan
11:35:17.063 Disk 0 Windows 7 default MBR code
11:35:17.070 Disk 0 MBR hidden
11:35:17.077 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 22003 MB offset 63
11:35:17.096 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152618 MB offset 45062325
11:35:17.104 Disk 0 Partition - 00 0F Extended LBA 435857 MB offset 357625856
11:35:17.149 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 435856 MB offset 357627904
11:35:17.187 Disk 0 scanning C:\Windows\system32\drivers
11:35:29.094 Service scanning
11:35:45.144 Modules scanning
11:35:45.169 Disk 0 trace - called modules:
11:35:45.518 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll
11:35:45.530 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006992060]
11:35:45.541 3 CLASSPNP.SYS[fffff880010bf43f] -> nt!IofCallDriver -> [0xfffffa8004a62200]
11:35:45.552 5 ACPI.sys[fffff88000f9a781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004ac0050]
11:35:45.561 Scan finished successfully
11:36:21.976 Disk 0 MBR has been saved successfully to "C:\Users\jian's famliy\Documents\MBR.dat"
11:36:21.979 The log file has been saved successfully to "C:\Users\jian's famliy\Documents\aswMBR.txt"By the way I cannot find Autoguarder.exe in the Programfiles folder, but 2 other locations, and each of them has a batch file contained called Folder.bat. That's the batch file which tried to delete important files. It says Access Denied when I try to delete it. You could try UnLocker.

You can download and install Unlocker .
Hello Dave, I got Unlocker and deleted the batch file. :)Thank you very much for helping me through this problem! My computer is running fine now. Good, let's do some cleanup and we'll be finished.

Download this program and run it Uninstall ComboFix .It will remove ComboFix for you.

******************************************
To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
This will give you a new, clean Restore Point.
***************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click YES on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
***************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Hey Dave, after doing the INSTRUCTIONS you gave me in the last post, my computer got a lot faster:). Thankyou very much for helping me with malware this time, and I learnt a lot. I am thinking of installing WOT instead of AVG too.

Whitebeard1Quote from: Whitebeard1 on April 23, 2013, 07:03:35 PM
Hey Dave, after doing the instructions you gave me in the last post, my computer got a lot faster:). Thankyou very much for helping me with malware this time, and I learnt a lot. I am thinking of installing WOT instead of AVG too.

Whitebeard1
You're welcome. Just one note. WOT is not an Anti-Virus program. It's just an aid to keep you from clicking on some dangerous sites. If you want to dump AVG, I would suggest MSE.
I will lock this thread. If you need it re-opened, please send me a pm.
2303.

Solve : Getting pop - ups?

Answer»

DisregardQuote

Just became aware that the pop-ups are only occurring in firefox.

Please try uninstalling and re-installing FF.

  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. LET it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
Unistalled and re-installed Firefox

RougeKiller log (did not delete files)

RogueKiller V8.0.4 [09/19/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : LATHEM [Admin rights]
Mode : Scan -- Date : 09/22/2012 13:43:38

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 6 ¤¤¤
[TASK][SUSP PATH] CandyUpdater.job : C:\Users\LATHEM\AppData\Local\ArcadeCandy\candyUpdater.exe -> FOUND
[TASK][SUSP PATH] CandyUpdater : C:\Users\LATHEM\AppData\Local\ArcadeCandy\candyUpdater.exe -> FOUND
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
[HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD10 EADS-65M2B1 SCSI Disk Device +++++
--- User ---
[MBR] d174627bc1fc2952cc573f0e3dd70439
[BSP] 838f2511e631effad20ac3f836e9fe9c : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 31 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 64260 | Size: 941802 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1928876355 | Size: 12033 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

+++++ PhysicalDrive1: HP Photosmart C4600 USB Device +++++
Error reading User MBR!
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[1].txt >>
RKreport[1].txt



Quote
Unistalled and re-installed Firefox
Any change?Was waiting a few days to be sure - problem solved. I cannot thank you enough for your time, patience and expertise. Dave you really are Super!Good. We can do some cleanup and we'll be finished.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
******************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*****************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I SUGGEST using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, VIRUSES and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations ALWAYS update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
2304.

Solve : Computer slow, freezesup will not shut down normally?

Answer»

Did MS Fix-It do any good?

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can SKIP these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a UNIQUE name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
MBAM finished a scan in normasl mode and I ran ESET, it said no threats were found and did not give me a list of found threats but I will post its log file along with the MBAM log.

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.04.28.03

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
kkoliiiiiiiiiiiiiiii :: HOME [administrator]

4/28/2013 9:29:55 AM
mbam-log-2013-04-28 (09-29-55).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 226919
Time elapsed: 5 minute(s), 37 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

[emailprotected] as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=3fd56864b064234c9c3f8362eb6d5c7b
# engine=13713
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-04-28 02:04:54
# local_time=2013-04-28 10:04:54 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5892 16777213 88 94 5153759 8352350 0 0
# scanned=24229
# found=0
# cleaned=0
# scan_time=910
[emailprotected] as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=3fd56864b064234c9c3f8362eb6d5c7b
# engine=13713
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-04-28 02:16:05
# local_time=2013-04-28 10:16:05 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5892 16777213 88 94 5154430 8353021 0 0
# scanned=2911
# found=0
# cleaned=0
# scan_time=119

That looks good. How's your computer RUNNING now?Running better I can go from site to site without freezing and my last shut down went normally. I still have an ALLSEARCH that comes up when I start Google Chrome. Is there a way to get rid of it.Quote
I still have an ALLSEARCH that comes up when I start Google Chrome. Is there a way to get rid of it.
It's probably an add-on in Google Chrome. Check your add-ons.

Download this program and run it Uninstall ComboFix .It will remove ComboFix for you.

*********************************************
To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
This will give you a new, clean Restore Point.
***************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
***********************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, IDENTITY theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Thank you sir you have saved me money and agravation.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2305.

Solve : audio advertisements?

Answer»

No adds since we ran the junk removal!! I HOPE all is well. Thank you!!No adds since we ran the junk removal!! I hope all is well. Thank you!!No adds since we ran the junk removal!! I hope all is well. Thank you!!
Sorry I REPLIED three times. I didn't see that there was a second page. Ok, LET's clean up.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other SELECTIONS if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*****************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you SAFE from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

2306.

Solve : I need help getting rid of Bettersurf?

Answer»

Up to now, I've been combing the internet for the solution to this problem, and even with all the solutions I've been offered, I've turned up empty handed. Nothing has worked. The problem is, even after DELETING all FILES associated with it, that I could find, there is STILL this one shady extension on my browser. It was "installed by enterprise policy" as it says right next to it, as seen here:

Notice how the delete button is gone? Me, too. How am I supposed to get rid of it!? I just have this gut feeling, that this thing is the root of all my Bettersurf issues. While waiting for our Malware Specialist to reply, please do the following if you have not already done so:

1) Open PROGRAMS & Features (or Add/Remove if you are running XP) from the CONTROL panel. Sort on the DATE column. Uninstall anything recently installed that relates to BetterSurf

2) Download and run the free version of MalwareBytes.

If after doing the above the problem persists, please wait for SuperDave (our malware specialist) to respond.I think I resolved the problem on my own... Thank you for your help, though!That was quick, but okay - glad you got it sorted out - I'm going to lock this thread. If the problem reappears please pm me and I'll reopen it.

2307.

Solve : FBI???? bumpkus !!!?

Answer»

Hi Dave, followed all steps from last post..... Can't tell you enough how GRATEFUL i am, you all do a great service for computer illiterate FOLKS like myself. THANK You very much !!!!You're welcome. I will lock this thread. If you need it re-opened, please SEND me a pm.

2308.

Solve : adyeild banners in browsers?

Answer»

How's your computer running now?

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. PLEASE be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Well we have done allot, seems we have cleaned up some stuff. I have completed avoided using the computer for any web browsing while we are working on it. So this is the first time I have open any browser on it. The original problem remains, where in using Google on either CHROME or IE there is a small banner add in the middle of the page with some wording to the side saying "ads not by this site". In addition the other problem remains in that PERIODICALLY when you click on a button on any web page it pops up another window that takes you to a URL that is trying to impersonate adobe flashes site asking to download flash. I have always just closed this window.

But running avast or rogue killer or malware bytes returns no infections or bad cookies, something I would get every time I used a browser then ran Malware bytes or spy hunter 4. So whatever is happening is not longer able to modify any settings but it is still embedded in my web browser under this profile. I say that because if I create a new user profile the problem does not exist at all.

IM thinking about just deleting the old profile and sticking with the new one I made since it seems to run fine. I ran ESET with no infections found. Quote
IM thinking about just deleting the old profile and sticking with the new one I made since it seems to run fine. I ran ESET with no infections found.
That would be a good idea. Let's do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
*************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's EASY and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thanks for all your help and patience!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2309.

Solve : Antivirus is not enough?

Answer»

I discussed with a IT friend of mine, and he said Antivirus is not enough, but I THINK an Antivirus + malware SOFTWARE will be better. However, he provided the this link http://secureconnexion.wordpress.com/2012/09/13/second-opinion-malware-scanners-why-buy-one/

But after reading that, I still not quite understand why he said antivirus is enough

Could anyone please help, if possible, please give me more references on why antivirus is enough in the system, thank youHere's what I use:

Kaspersky Anti Virus
SpywareBlaster (updated weekly)
MalwareBytes (manual scans monthly)
WinPatrol Plus

But no matter how much protection you have installed, NOTHING will replace common sense (ie., do not open email from unknown sources or click on links in email unless you are 100% certain you know what they are, do not visit QUESTIONABLE websites, do not click on links in websites unless you are certain you know what they are, always download the latest updates from Microsoft to keep your OS and browser secure, etc.).Thanks for your quick reply Allan, say if you only use Kaspersky Anti Virus, but not the rest program, will your system as strong as when u use all those 4 programs, thank youNook, I got it, thank you very muchYou're welcome.Most AV's also have a malware component. This is what I use on all my computers.

Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
Microsoft Security Essentials for Windows XPQuote from: SuperDave on September 27, 2012, 04:07:24 PM

Most AV's also have a malware component. This is what I use on all my computers.

Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
Microsoft Security Essentials for Windows XP

But the website states i need to use a genuine window, but what if my window is not geniune, can i still use it. Also how do i know whether my window is genuine, thanksIf you couldn't install MSE then your copy of Windows is not legal. If your OS is not legal then you're not receiving your updates and therefore, your computer is more susceptible to infections. Run this tool and post the log to see if it's legit.

1. Download this diagnostics tool MGADiag.ext and save this to your Desktop.
2. Double-click on MGADiag.exe and click Continue
3. When the program has FINISHED, click on Copy
4. Post the results in your next reply.
If you do not have a legal version of Windows we can no longer be of assistance to you.Quote from: Allan on September 28, 2012, 01:49:07 PM
If you do not have a legal version of Windows we can no longer be of assistance to you.

Actually in malware removal forums we will only once help an unlicensed Windows user clean their computer of malware then strongly encourage them to buy a license. Reason being it is not wise to license a computer that is infected with malware.

But ultimately it's up to the helper. Thanks EF Hi John, please post your questions to me only, not look for help in the wild. That is the rules of training.

Thanks...and closed.
2310.

Solve : Corrupted executable file??

Answer»

The other day, while doing an AVG virus scan, I was informed that a "corrupted executable file" had been detected and placed in the virus vault. It seems to have SOMETHING to do with flashplayer.

Although I'm reasonably CONFIDENT that AVG did its job and blocked this-I'm confused as to where it came from and how DANGEROUS it potentially was/is.

Any info anyone could provide would be greatly appreciated."Corrupted executables" are generally not dangerous, what it's saying is that the checksum or signature of that file didn't match what the file was supposed to be. This can be CAUSED by lots of things such as file system damage, pausing/canceling the download of a file midway through, etc. Unless you have other symptoms of infection, I wouldn't worry about it.Thanks for the input-I appreciate it.

2311.

Solve : Action Center confusing advice?

Answer»

Ok, how's your computer running now?Action Center report now is that there are no issues. I will see if "Not Responding" message now occurs with Firefox and report on this issue in a day or so. The "Not Responding" in Excel was probably due to the workbook being very large and the AutoRecovery set for 10 minutes and the slow response due to automatically running a large number of the RAND() functions. I know what to do to improve the Excel response. You could try uninstalling and re-installing FireFox.Super Dave. I have reinstalled Firefox. I will report on what is happening in a couple of days.
I have not run the Malwarebytes Anti-Malware that you originally listed in the program. Is it necessary to run it now or has that issue been resolved by the subsequent tests?Quote from: denisaf on January 01, 2014, 02:07:31 PM

Super Dave. I have reinstalled Firefox. I will report on what is happening in a couple of days.
I have not run the Malwarebytes Anti-Malware that you originally listed in the program. Is it necessary to run it now or has that issue been resolved by the subsequent tests?
Yes, please run it to see what turns up.I ran Anti-Malware. The scan took 70 minutes and examined over 437000 objects. 40 objects were identified in Show Results and removed. The PC was then rebooted. The Notepad log follows

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.07.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
denisaf :: DENISAF-PC [administrator]

Protection: Enabled

8/01/2014 9:16:37 AM
mbam-log-2014-01-08 (09-16-37).txt

Scan type: Full scan (C:\|I:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 437597
Time elapsed: 1 hour(s), 10 minute(s), 5 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 10
HKCU\Software\BrowseSmart (PUP.Optional.BrowseSmart.A) -> Quarantined and deleted successfully.
HKCU\Software\jzipmusictoolbarmo (PUP.Optional.JZipMusicToolbar.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Classes\AppID\DynConIE.DLL (PUP.Optional.DynConIE.A) -> Quarantined and deleted successfully.
HKLM\Software\BrowseSmart (PUP.Optional.BrowseSmart.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser HELPER Objects\{251ef57c-0612-478c-978e-c86d3879caa4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{251ef57c-0612-478c-978e-c86d3879caa4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{251EF57C-0612-478C-978E-C86D3879CAA4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{251EF57C-0612-478C-978E-C86D3879CAA4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{251EF57C-0612-478C-978E-C86D3879CAA4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully.

Registry Values Detected: 2
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: 1763663117034848255 -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{251EF57C-0612-478C-978E-C86D3879CAA4} (PUP.Optional.MusicToolBar.A) -> Data: Music Toolbar (Dist. by Bandoo Media, Inc.) -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 3
C:\ProgramData\Datamngr (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\CT3317209 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\CT3317212 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

Files Detected: 40
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\Datamngr.dll.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\DatamngrCoordinator.exe.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\DatamngrUI.exe.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\IEBHO.dll.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\SRTOOL~1\IE\uninstall.exe.vir (PUP.Optional.MusicToolbar.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\x64\Datamngr.dll.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\x64\IEBHO.dll.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\CltMngSvc.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\SPTool.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\uninstall.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\cltmng.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPTool64.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC32.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC32Loader.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC64.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC64Loader.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\UI\bin\cltmngui.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\581ZV0BY\spstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RC0HIJAR\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\nsh5842.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\nsh9B4B.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\nsm9D8D.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\nsr55C1.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\Yyv9z_vN.exe.part (PUP.Optional.DomaIQ) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\AdwCleaner_TSV16311.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\installer_avira_antivir_personal_-_free_antivirus_English.exe (PUP.Optional.Freemium.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\Java(1).exe (PUP.Optional.DomaIQ) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\Java.exe (PUP.Optional.DomaIQ) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\Java7(1).exe (PUP.Optional.Domalq) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\Java7.exe (PUP.Optional.Domalq) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\jZipSetup-r250-w-bf.exe (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\MailNotifierAUSetup(2).exe (PUP.Optional.Inbox) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\SoftonicDownloader_for_stellarium(1).exe (PUP.Optional.Softonic.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\Downloads\SoftonicDownloader_for_stellarium.exe (PUP.Optional.Softonic.A) -> Quarantined and deleted successfully.
C:\ProgramData\Datamngr\coordinator.cfg (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully.
C:\ProgramData\Datamngr\general.cfg (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully.
C:\ProgramData\Datamngr\S-1-5-21-3023884638-2710209032-2036161082-1000.cfg (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully.
C:\ProgramData\Datamngr\S-1-5-32.cfg (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\CT3317209\ddt.csf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\denisaf\AppData\Local\Temp\CT3317212\ddt.csf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

(end)
Wow, that was a lot of infections. How's your computer running now?SuperDave
Occasionally the message
"Warning: Unresponsive PLUGIN
Shockwave Flash - stop or continue" appears and holds things up. I understand that it is a sound process and I could cancel that message without causing any problems although there will be a slow response on occasions.Why not disable that plugin?

Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to INFECT your system.

First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
*****************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
Latest Java is installed and an old version uninstalled. Disk clean up freed up quite a slice.Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thank you, SuperDave for all your help. I will record your last post as it provides advice on how to ensure this pc is being used soundly. I need this record to refer to periodically as I am too old to remember how to handle the increasing complexity.You're welcome. I will LOCK this THREAD. If you need it re-opened, please send me a pm.
2312.

Solve : Computer virus that controlls my mouse.?

Answer»

This is so annoying.
I don't know why, it stopped for a while, then it began now.
I even had a redirection chrome problem, but it stopped and the mouse moving by itself started.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.



  • If an infected file is detected, the default action will be Cure, click on Continue.



  • If a suspicious file is detected, the default action will be Skip, click on Continue.



  • It may ASK you to reboot the computer to complete the process. Click on Reboot Now.



  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory..

I noticed that it only affects the mouse.
I am thinking of re-downloading Windows, but I'm afraid it'll slip through.
I haven't told my parents YET that there's a virus.
The log:
22:43:09.0140 3596 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
22:43:09.0609 3596 ============================================================
22:43:09.0609 3596 Current date / time: 2013/05/09 22:43:09.0609
22:43:09.0609 3596 SystemInfo:
22:43:09.0609 3596
22:43:09.0609 3596 OS Version: 5.1.2600 ServicePack: 3.0
22:43:09.0609 3596 Product type: Workstation
22:43:09.0609 3596 ComputerName: PC
22:43:09.0609 3596 UserName: My Pc
22:43:09.0609 3596 Windows directory: C:\WINDOWS
22:43:09.0609 3596 System windows directory: C:\WINDOWS
22:43:09.0609 3596 Processor architecture: Intel x86
22:43:09.0609 3596 Number of processors: 2
22:43:09.0609 3596 Page size: 0x1000
22:43:09.0609 3596 BOOT type: Normal boot
22:43:09.0609 3596 ============================================================
22:43:10.0828 3596 Drive \Device\Harddisk0\DR0 - Size: 0x25432CDE00 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
22:43:10.0828 3596 ============================================================
22:43:10.0828 3596 \Device\Harddisk0\DR0:
22:43:10.0828 3596 MBR partitions:
22:43:10.0828 3596 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A962B1
22:43:10.0843 3596 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x3A9632F, BlocksNum 0xEF7E8D1
22:43:10.0843 3596 ============================================================
22:43:10.0937 3596 E: <-> \Device\Harddisk0\DR0\Partition2
22:43:10.0968 3596 C: <-> \Device\Harddisk0\DR0\Partition1
22:43:10.0968 3596 ============================================================
22:43:10.0968 3596 Initialize success
22:43:10.0968 3596 ============================================================
22:43:22.0218 0276 ============================================================
22:43:22.0218 0276 Scan started
22:43:22.0218 0276 Mode: Manual;
22:43:22.0218 0276 ============================================================
22:43:22.0796 0276 ================ Scan system memory ========================
22:43:22.0796 0276 System memory - ok
22:43:22.0796 0276 ================ Scan services =============================
22:43:22.0859 0276 Abiosdsk - ok
22:43:22.0859 0276 abp480n5 - ok
22:43:22.0906 0276 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
22:43:22.0906 0276 ACPI - ok
22:43:22.0953 0276 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
22:43:22.0953 0276 ACPIEC - ok
22:43:22.0968 0276 adpu160m - ok
22:43:23.0031 0276 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
22:43:23.0031 0276 aec - ok
22:43:23.0062 0276 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
22:43:23.0078 0276 AFD - ok
22:43:23.0078 0276 Aha154x - ok
22:43:23.0109 0276 aic78u2 - ok
22:43:23.0125 0276 aic78xx - ok
22:43:23.0156 0276 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
22:43:23.0156 0276 Alerter - ok
22:43:23.0171 0276 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
22:43:23.0171 0276 ALG - ok
22:43:23.0187 0276 AliIde - ok
22:43:23.0203 0276 amsint - ok
22:43:23.0265 0276 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
22:43:23.0265 0276 AppMgmt - ok
22:43:23.0281 0276 asc - ok
22:43:23.0296 0276 asc3350p - ok
22:43:23.0312 0276 asc3550 - ok
22:43:23.0343 0276 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
22:43:23.0343 0276 AsyncMac - ok
22:43:23.0375 0276 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
22:43:23.0375 0276 atapi - ok
22:43:23.0375 0276 Atdisk - ok
22:43:23.0406 0276 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
22:43:23.0406 0276 Atmarpc - ok
22:43:23.0421 0276 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
22:43:23.0437 0276 AudioSrv - ok
22:43:23.0468 0276 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
22:43:23.0468 0276 audstub - ok
22:43:23.0515 0276 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
22:43:23.0531 0276 Beep - ok
22:43:23.0562 0276 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
22:43:23.0609 0276 BITS - ok
22:43:23.0640 0276 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
22:43:23.0640 0276 Browser - ok
22:43:23.0718 0276 catchme - ok
22:43:23.0750 0276 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
22:43:23.0750 0276 cbidf2k - ok
22:43:23.0765 0276 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
22:43:23.0781 0276 CCDECODE - ok
22:43:23.0781 0276 cd20xrnt - ok
22:43:23.0828 0276 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
22:43:23.0828 0276 Cdaudio - ok
22:43:23.0875 0276 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
22:43:23.0875 0276 Cdfs - ok
22:43:23.0921 0276 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
22:43:23.0921 0276 Cdrom - ok
22:43:23.0937 0276 Changer - ok
22:43:23.0968 0276 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
22:43:23.0968 0276 CiSvc - ok
22:43:24.0000 0276 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
22:43:24.0000 0276 ClipSrv - ok
22:43:24.0015 0276 CmdIde - ok
22:43:24.0031 0276 COMSysApp - ok
22:43:24.0078 0276 Cpqarray - ok
22:43:24.0109 0276 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
22:43:24.0109 0276 CryptSvc - ok
22:43:24.0125 0276 dac2w2k - ok
22:43:24.0140 0276 dac960nt - ok
22:43:24.0203 0276 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
22:43:24.0203 0276 DcomLaunch - ok
22:43:24.0234 0276 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
22:43:24.0234 0276 Dhcp - ok
22:43:24.0250 0276 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
22:43:24.0250 0276 Disk - ok
22:43:24.0265 0276 dmadmin - ok
22:43:24.0328 0276 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
22:43:24.0328 0276 dmboot - ok
22:43:24.0359 0276 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
22:43:24.0359 0276 dmio - ok
22:43:24.0375 0276 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
22:43:24.0375 0276 dmload - ok
22:43:24.0390 0276 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
22:43:24.0390 0276 dmserver - ok
22:43:24.0437 0276 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
22:43:24.0437 0276 DMusic - ok
22:43:24.0453 0276 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
22:43:24.0468 0276 Dnscache - ok
22:43:24.0484 0276 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
22:43:24.0484 0276 Dot3svc - ok
22:43:24.0500 0276 dpti2o - ok
22:43:24.0515 0276 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
22:43:24.0515 0276 drmkaud - ok
22:43:24.0546 0276 [ D4F94D45E25D764462A5B95BC426C8D0 ] eamon C:\WINDOWS\system32\DRIVERS\eamon.sys
22:43:24.0546 0276 eamon - ok
22:43:24.0562 0276 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
22:43:24.0578 0276 EapHost - ok
22:43:24.0609 0276 [ 9456462C1425D2BBF1616EDABFABA5F4 ] ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys
22:43:24.0609 0276 ehdrv - ok
22:43:24.0703 0276 [ 98B73963E8D2B89A9D5227FB6D245A00 ] EhttpSrv C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
22:43:24.0703 0276 EhttpSrv - ok
22:43:24.0750 0276 [ 73B0195E0405051CC2B69E84EC3F64D1 ] ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
22:43:24.0750 0276 ekrn - ok
22:43:24.0796 0276 [ 4B308624FADF5BB6490D8F8D7AEBF5DF ] epfwtdir C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
22:43:24.0796 0276 epfwtdir - ok
22:43:24.0828 0276 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
22:43:24.0828 0276 ERSvc - ok
22:43:24.0875 0276 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
22:43:24.0875 0276 Eventlog - ok
22:43:24.0921 0276 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
22:43:24.0921 0276 EventSystem - ok
22:43:24.0968 0276 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
22:43:24.0968 0276 Fastfat - ok
22:43:24.0984 0276 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
22:43:25.0000 0276 FastUserSwitchingCompatibility - ok
22:43:25.0031 0276 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
22:43:25.0031 0276 Fdc - ok
22:43:25.0046 0276 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
22:43:25.0046 0276 Fips - ok
22:43:25.0062 0276 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
22:43:25.0062 0276 Flpydisk - ok
22:43:25.0109 0276 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
22:43:25.0109 0276 FltMgr - ok
22:43:25.0125 0276 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
22:43:25.0125 0276 Fs_Rec - ok
22:43:25.0140 0276 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
22:43:25.0156 0276 Ftdisk - ok
22:43:25.0171 0276 gdrv - ok
22:43:25.0218 0276 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
22:43:25.0218 0276 Gpc - ok
22:43:25.0281 0276 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
22:43:25.0296 0276 gupdate - ok
22:43:25.0296 0276 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
22:43:25.0312 0276 gupdatem - ok
22:43:25.0359 0276 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
22:43:25.0359 0276 HDAudBus - ok
22:43:25.0421 0276 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
22:43:25.0421 0276 helpsvc - ok
22:43:25.0453 0276 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
22:43:25.0453 0276 HidServ - ok
22:43:25.0484 0276 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
22:43:25.0484 0276 hidusb - ok
22:43:25.0531 0276 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
22:43:25.0546 0276 hkmsvc - ok
22:43:25.0562 0276 hpn - ok
22:43:25.0593 0276 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
22:43:25.0593 0276 HTTP - ok
22:43:25.0625 0276 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
22:43:25.0640 0276 HTTPFilter - ok
22:43:25.0656 0276 i2omgmt - ok
22:43:25.0671 0276 i2omp - ok
22:43:25.0703 0276 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
22:43:25.0703 0276 i8042prt - ok
22:43:25.0718 0276 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
22:43:25.0718 0276 Imapi - ok
22:43:25.0781 0276 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
22:43:25.0781 0276 ImapiService - ok
22:43:25.0796 0276 ini910u - ok
22:43:25.0937 0276 [ 08BAF30F6DE95814F58AF9CE7BBC5614 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
22:43:25.0968 0276 IntcAzAudAddService - ok
22:43:25.0984 0276 IntelIde - ok
22:43:26.0031 0276 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
22:43:26.0031 0276 intelppm - ok
22:43:26.0062 0276 [ DF74775766FE0D833FF5A4D705E6B146 ] ioFakDrv C:\WINDOWS\system32\DRIVERS\ioFakDrv.sys
22:43:26.0062 0276 ioFakDrv - ok
22:43:26.0093 0276 [ F171522B16EF9AEB1C79179051302B6F ] ioFakMap C:\WINDOWS\system32\DRIVERS\ioFakMap.sys
22:43:26.0093 0276 ioFakMap - ok
22:43:26.0125 0276 [ D048C1E4D5908B2D042AAEF4F1AF82A4 ] ioTablet C:\WINDOWS\system32\DRIVERS\ioTablet.sys
22:43:26.0125 0276 ioTablet - ok
22:43:26.0140 0276 [ 5AE2A50C8A07FF30FA48388E3F28DC8A ] ioTblMap C:\WINDOWS\system32\DRIVERS\ioTblMap.sys
22:43:26.0156 0276 ioTblMap - ok
22:43:26.0171 0276 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
22:43:26.0171 0276 Ip6Fw - ok
22:43:26.0203 0276 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
22:43:26.0203 0276 IpFilterDriver - ok
22:43:26.0218 0276 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
22:43:26.0218 0276 IpInIp - ok
22:43:26.0281 0276 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
22:43:26.0281 0276 IpNat - ok
22:43:26.0312 0276 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
22:43:26.0312 0276 IPSec - ok
22:43:26.0343 0276 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
22:43:26.0343 0276 IRENUM - ok
22:43:26.0390 0276 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
22:43:26.0390 0276 isapnp - ok
22:43:26.0546 0276 [ 5739F2821D49975CEDE6BF0153D0CF01 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
22:43:26.0546 0276 JavaQuickStarterService - ok
22:43:26.0578 0276 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
22:43:26.0578 0276 Kbdclass - ok
22:43:26.0609 0276 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
22:43:26.0625 0276 kbdhid - ok
22:43:26.0656 0276 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
22:43:26.0656 0276 kmixer - ok
22:43:26.0718 0276 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
22:43:26.0718 0276 KSecDD - ok
22:43:26.0750 0276 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
22:43:26.0765 0276 LanmanServer - ok
22:43:26.0781 0276 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
22:43:26.0812 0276 lanmanworkstation - ok
22:43:26.0828 0276 lbrtfdc - ok
22:43:26.0890 0276 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
22:43:26.0890 0276 LmHosts - ok
22:43:26.0921 0276 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
22:43:26.0921 0276 Messenger - ok
22:43:26.0984 0276 [ 7C4C76B39D5525C4A465E0BE32528E19 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
22:43:26.0984 0276 Microsoft Office Groove Audit Service - ok
22:43:27.0031 0276 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
22:43:27.0031 0276 mnmdd - ok
22:43:27.0062 0276 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
22:43:27.0062 0276 mnmsrvc - ok
22:43:27.0093 0276 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
22:43:27.0093 0276 Modem - ok
22:43:27.0109 0276 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
22:43:27.0109 0276 Mouclass - ok
22:43:27.0140 0276 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
22:43:27.0140 0276 mouhid - ok
22:43:27.0171 0276 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
22:43:27.0171 0276 MountMgr - ok
22:43:27.0218 0276 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
22:43:27.0234 0276 MozillaMaintenance - ok
22:43:27.0234 0276 mraid35x - ok
22:43:27.0265 0276 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
22:43:27.0265 0276 MRxDAV - ok
22:43:27.0312 0276 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
22:43:27.0312 0276 MRxSmb - ok
22:43:27.0343 0276 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
22:43:27.0359 0276 MSDTC - ok
22:43:27.0359 0276 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
22:43:27.0359 0276 Msfs - ok
22:43:27.0406 0276 MSIServer - ok
22:43:27.0437 0276 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
22:43:27.0437 0276 MSKSSRV - ok
22:43:27.0453 0276 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
22:43:27.0453 0276 MSPCLOCK - ok
22:43:27.0484 0276 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
22:43:27.0484 0276 MSPQM - ok
22:43:27.0515 0276 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
22:43:27.0531 0276 mssmbios - ok
22:43:27.0562 0276 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys
22:43:27.0562 0276 MSTEE - ok
22:43:27.0609 0276 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
22:43:27.0609 0276 Mup - ok
22:43:27.0625 0276 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
22:43:27.0640 0276 NABTSFEC - ok
22:43:27.0656 0276 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
22:43:27.0656 0276 napagent - ok
22:43:27.0687 0276 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
22:43:27.0703 0276 NDIS - ok
22:43:27.0734 0276 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys
22:43:27.0734 0276 NdisIP - ok
22:43:27.0765 0276 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
22:43:27.0765 0276 NdisTapi - ok
22:43:27.0812 0276 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
22:43:27.0812 0276 Ndisuio - ok
22:43:27.0828 0276 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
22:43:27.0828 0276 NdisWan - ok
22:43:27.0875 0276 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
22:43:27.0875 0276 NDProxy - ok
22:43:27.0968 0276 [ 2AAE889742376EDC5C3203DFB74F28FD ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
22:43:27.0984 0276 Nero BackItUp Scheduler 3 - ok
22:43:28.0015 0276 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
22:43:28.0015 0276 NetBIOS - ok
22:43:28.0031 0276 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
22:43:28.0046 0276 NetBT - ok
22:43:28.0078 0276 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
22:43:28.0078 0276 NetDDE - ok
22:43:28.0093 0276 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
22:43:28.0093 0276 NetDDEdsdm - ok
22:43:28.0125 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
22:43:28.0140 0276 Netlogon - ok
22:43:28.0156 0276 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
22:43:28.0156 0276 Netman - ok
22:43:28.0171 0276 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
22:43:28.0187 0276 Nla - ok
22:43:28.0250 0276 [ CB992AE1506985D9167E85883B4C3240 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
22:43:28.0265 0276 NMIndexingService - ok
22:43:28.0281 0276 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
22:43:28.0281 0276 Npfs - ok
22:43:28.0328 0276 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
22:43:28.0343 0276 Ntfs - ok
22:43:28.0359 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
22:43:28.0359 0276 NtLmSsp - ok
22:43:28.0406 0276 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
22:43:28.0406 0276 NtmsSvc - ok
22:43:28.0437 0276 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
22:43:28.0437 0276 Null - ok
22:43:28.0468 0276 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
22:43:28.0468 0276 NwlnkFlt - ok
22:43:28.0500 0276 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
22:43:28.0500 0276 NwlnkFwd - ok
22:43:28.0578 0276 [ 1F0E05DFF4F5A833168E49BE1256F002 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
22:43:28.0593 0276 odserv - ok
22:43:28.0625 0276 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:43:28.0640 0276 ose - ok
22:43:28.0671 0276 [ 3F24EAEB165328E00D687BF3B60A448A ] PAC207 C:\WINDOWS\system32\DRIVERS\pfc027.sys
22:43:28.0671 0276 PAC207 - ok
22:43:28.0703 0276 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
22:43:28.0703 0276 Parport - ok
22:43:28.0718 0276 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
22:43:28.0734 0276 PartMgr - ok
22:43:28.0765 0276 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
22:43:28.0765 0276 ParVdm - ok
22:43:28.0781 0276 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
22:43:28.0781 0276 PCI - ok
22:43:28.0796 0276 PCIDump - ok
22:43:28.0812 0276 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
22:43:28.0812 0276 PCIIde - ok
22:43:28.0875 0276 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
22:43:28.0875 0276 Pcmcia - ok
22:43:28.0890 0276 PDCOMP - ok
22:43:28.0906 0276 PDFRAME - ok
22:43:28.0921 0276 PDRELI - ok
22:43:28.0937 0276 PDRFRAME - ok
22:43:28.0968 0276 perc2 - ok
22:43:28.0984 0276 perc2hib - ok
22:43:29.0078 0276 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\WINDOWS\system32\IoctlSvc.exe
22:43:29.0078 0276 PLFlash DeviceIoControl Service - ok
22:43:29.0093 0276 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
22:43:29.0093 0276 PlugPlay - ok
22:43:29.0109 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
22:43:29.0109 0276 PolicyAgent - ok
22:43:29.0140 0276 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
22:43:29.0140 0276 PptpMiniport - ok
22:43:29.0156 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
22:43:29.0156 0276 ProtectedStorage - ok
22:43:29.0171 0276 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
22:43:29.0171 0276 PSched - ok
22:43:29.0187 0276 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
22:43:29.0203 0276 Ptilink - ok
22:43:29.0218 0276 ql1080 - ok
22:43:29.0234 0276 Ql10wnt - ok
22:43:29.0250 0276 ql12160 - ok
22:43:29.0281 0276 ql1240 - ok
22:43:29.0296 0276 ql1280 - ok
22:43:29.0328 0276 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
22:43:29.0328 0276 RasAcd - ok
22:43:29.0343 0276 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
22:43:29.0359 0276 RasAuto - ok
22:43:29.0390 0276 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
22:43:29.0390 0276 Rasl2tp - ok
22:43:29.0406 0276 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
22:43:29.0406 0276 RasMan - ok
22:43:29.0421 0276 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
22:43:29.0421 0276 RasPppoe - ok
22:43:29.0437 0276 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
22:43:29.0437 0276 Raspti - ok
22:43:29.0468 0276 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
22:43:29.0484 0276 Rdbss - ok
22:43:29.0484 0276 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
22:43:29.0484 0276 RDPCDD - ok
22:43:29.0546 0276 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
22:43:29.0562 0276 rdpdr - ok
22:43:29.0625 0276 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
22:43:29.0625 0276 RDPWD - ok
22:43:29.0656 0276 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
22:43:29.0656 0276 RDSessMgr - ok
22:43:29.0671 0276 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
22:43:29.0671 0276 redbook - ok
22:43:29.0718 0276 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
22:43:29.0718 0276 RemoteAccess - ok
22:43:29.0750 0276 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
22:43:29.0750 0276 RemoteRegistry - ok
22:43:29.0781 0276 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7 ] ROOTMODEM C:\WINDOWS\system32\Drivers\RootMdm.sys
22:43:29.0796 0276 ROOTMODEM - ok
22:43:29.0812 0276 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
22:43:29.0828 0276 RpcLocator - ok
22:43:29.0859 0276 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
22:43:29.0859 0276 RpcSs - ok
22:43:29.0890 0276 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
22:43:29.0890 0276 RSVP - ok
22:43:29.0921 0276 [ 89619EF503F949FAE09252A8B883EE11 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
22:43:29.0921 0276 RTLE8023xp - ok
22:43:29.0937 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
22:43:29.0937 0276 SamSs - ok
22:43:29.0984 0276 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
22:43:29.0984 0276 SCardSvr - ok
22:43:30.0031 0276 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
22:43:30.0031 0276 Schedule - ok
22:43:30.0046 0276 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
22:43:30.0046 0276 Secdrv - ok
22:43:30.0093 0276 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
22:43:30.0093 0276 seclogon - ok
22:43:30.0109 0276 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
22:43:30.0109 0276 SENS - ok
22:43:30.0125 0276 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
22:43:30.0125 0276 serenum - ok
22:43:30.0156 0276 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
22:43:30.0156 0276 Serial - ok
22:43:30.0171 0276 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
22:43:30.0187 0276 Sfloppy - ok
22:43:30.0203 0276 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
22:43:30.0218 0276 SharedAccess - ok
22:43:30.0234 0276 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
22:43:30.0234 0276 ShellHWDetection - ok
22:43:30.0250 0276 Simbad - ok
22:43:30.0281 0276 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys
22:43:30.0281 0276 SLIP - ok
22:43:30.0296 0276 Sparrow - ok
22:43:30.0343 0276 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
22:43:30.0343 0276 splitter - ok
22:43:30.0375 0276 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
22:43:30.0375 0276 Spooler - ok
22:43:30.0421 0276 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
22:43:30.0421 0276 sr - ok
22:43:30.0437 0276 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
22:43:30.0453 0276 srservice - ok
22:43:30.0484 0276 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
22:43:30.0484 0276 Srv - ok
22:43:30.0531 0276 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
22:43:30.0531 0276 SSDPSRV - ok
22:43:30.0562 0276 [ ED78DFAD8EFCDFBC89500492C4D14645 ] STI Simulator C:\WINDOWS\System32\PAStiSvc.exe
22:43:30.0562 0276 STI Simulator - ok
22:43:30.0609 0276 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
22:43:30.0609 0276 stisvc - ok
22:43:30.0640 0276 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys
22:43:30.0640 0276 streamip - ok
22:43:30.0671 0276 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
22:43:30.0671 0276 swenum - ok
22:43:30.0687 0276 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
22:43:30.0687 0276 swmidi - ok
22:43:30.0703 0276 SwPrv - ok
22:43:30.0718 0276 symc810 - ok
22:43:30.0750 0276 symc8xx - ok
22:43:30.0765 0276 sym_hi - ok
22:43:30.0781 0276 sym_u3 - ok
22:43:30.0812 0276 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
22:43:30.0812 0276 sysaudio - ok
22:43:30.0843 0276 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
22:43:30.0859 0276 SysmonLog - ok
22:43:30.0906 0276 [ E11E477B5E2B8CC52E528AE9F491C678 ] TabletService C:\Genius\ioTablet\TabletService.exe
22:43:30.0906 0276 TabletService - ok
22:43:30.0953 0276 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
22:43:30.0953 0276 TapiSrv - ok
22:43:31.0000 0276 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
22:43:31.0015 0276 Tcpip - ok
22:43:31.0046 0276 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
22:43:31.0046 0276 TDPIPE - ok
22:43:31.0062 0276 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
22:43:31.0062 0276 TDTCP - ok
22:43:31.0093 0276 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
22:43:31.0093 0276 TermDD - ok
22:43:31.0125 0276 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
22:43:31.0125 0276 TermService - ok
22:43:31.0156 0276 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
22:43:31.0156 0276 Themes - ok
22:43:31.0187 0276 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
22:43:31.0187 0276 TlntSvr - ok
22:43:31.0203 0276 TosIde - ok
22:43:31.0250 0276 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
22:43:31.0250 0276 TrkWks - ok
22:43:31.0281 0276 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
22:43:31.0281 0276 Udfs - ok
22:43:31.0296 0276 ultra - ok
22:43:31.0343 0276 [ C81B8635DEE0D3EF5F64B3DD643023A5 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe
22:43:31.0343 0276 UMWdf - ok
22:43:31.0390 0276 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
22:43:31.0390 0276 Update - ok
22:43:31.0453 0276 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
22:43:31.0453 0276 upnphost - ok
22:43:31.0468 0276 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
22:43:31.0484 0276 UPS - ok
22:43:31.0515 0276 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
22:43:31.0515 0276 usbehci - ok
22:43:31.0546 0276 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
22:43:31.0562 0276 usbhub - ok
22:43:31.0593 0276 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
22:43:31.0593 0276 usbstor - ok
22:43:31.0625 0276 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
22:43:31.0625 0276 usbuhci - ok
22:43:31.0656 0276 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
22:43:31.0656 0276 VgaSave - ok
22:43:31.0671 0276 ViaIde - ok
22:43:31.0687 0276 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
22:43:31.0687 0276 VolSnap - ok
22:43:31.0750 0276 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
22:43:31.0750 0276 VSS - ok
22:43:31.0796 0276 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
22:43:31.0796 0276 W32Time - ok
22:43:31.0828 0276 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
22:43:31.0828 0276 Wanarp - ok
22:43:31.0859 0276 [ D918617B46457B9AC28027722E30F647 ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys
22:43:31.0875 0276 Wdf01000 - ok
22:43:31.0875 0276 WDICA - ok
22:43:31.0921 0276 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
22:43:31.0921 0276 wdmaud - ok
22:43:31.0937 0276 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
22:43:31.0953 0276 WebClient - ok
22:43:32.0031 0276 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
22:43:32.0031 0276 winmgmt - ok
22:43:32.0093 0276 [ A477391B7A8B0A0DAABADB17CF533A4B ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
22:43:32.0093 0276 WmdmPmSN - ok
22:43:32.0140 0276 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
22:43:32.0156 0276 Wmi - ok
22:43:32.0203 0276 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
22:43:32.0203 0276 WmiApSrv - ok
22:43:32.0234 0276 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
22:43:32.0250 0276 WS2IFSL - ok
22:43:32.0281 0276 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
22:43:32.0281 0276 wscsvc - ok
22:43:32.0312 0276 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
22:43:32.0312 0276 WSTCODEC - ok
22:43:32.0343 0276 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
22:43:32.0343 0276 wuauserv - ok
22:43:32.0375 0276 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
22:43:32.0375 0276 WZCSVC - ok
22:43:32.0421 0276 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
22:43:32.0421 0276 xmlprov - ok
22:43:32.0515 0276 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
22:43:32.0531 0276 YahooAUService - ok
22:43:32.0546 0276 ================ Scan global ===============================
22:43:32.0562 0276 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
22:43:32.0593 0276 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll
22:43:32.0593 0276 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll
22:43:32.0625 0276 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
22:43:32.0625 0276 [Global] - ok
22:43:32.0625 0276 ================ Scan MBR ==================================
22:43:32.0656 0276 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
22:43:32.0796 0276 \Device\Harddisk0\DR0 - ok
22:43:32.0796 0276 ================ Scan VBR ==================================
22:43:32.0796 0276 [ 3F816EFEDF17BCA5617110FCDC7A2030 ] \Device\Harddisk0\DR0\Partition1
22:43:32.0812 0276 \Device\Harddisk0\DR0\Partition1 - ok
22:43:32.0843 0276 [ 4A6142DAFE4EC98DC6F02FEE851DAC2B ] \Device\Harddisk0\DR0\Partition2
22:43:32.0843 0276 \Device\Harddisk0\DR0\Partition2 - ok
22:43:32.0843 0276 ============================================================
22:43:32.0843 0276 Scan finished
22:43:32.0843 0276 ============================================================
22:43:32.0875 3904 Detected object count: 0
22:43:32.0875 3904 Actual detected object count: 0
22:43:41.0750 2552 Deinitialize success
I forgot. Did you try a new mouse?I borrowed one from my neighbour, but didn't work ( It didn't even move! )
Then I plugged my mouse back and the problem disappeared SINCE I didn't write a reply in this forum!
Do you know any other effective malware/trojan removals?Quote
Do you know any other effective malware/trojan removals?
I don't believe that your problem with the mouse if malware related.
2313.

Solve : Master boot Record?

Answer»

Thank you Dave for all your help,
Quote

At this point, since I don't know what you have done with the computer,
What I did was very simple I ran - Bootrec / fixmbr from the recovery console on my Vista CD - I don't know if the Trojan somehow prevented the task or for some reason the vista copy of the boot record was incompatible (I'm not sure what it is that utility does) but immediately upon reboot nothing was working properly. You can see by the logs I posted "service not loaded "came up alot.

Quote
I would advise you to save your important data to disks and re-format and re-install your OS

I have been working on that right along. My problem now lies in the recovery program I have found it on my recovery CD, Unfortunately the program NEEDS to reboot my system in order to continue and whenever I do that the problems with my boot take over. If you don't have any further Ideas would you mind if I took this problem to another forum? And regardless thank you very much
DuncanDid you TRY SETTING your BIOS to boot from the CD first and then boot with the Recovery CD in the drive?

If you do not know how to set your computer to boot from CD follow the steps hereYes it is set to boot from the CD. This is a different issue. I think. Somewhere along the line I lost my factory installed recovery program from my hard drive (Gateway Recovery CENTER) Because it is not properly installed I have no recovery option on the advanced boot options menu and can not access my Recovery partition. Well I found it included on my "program and drivers" CD but it is not a bootable CD. I can run the program but the first thing it wants to do is reboot. I suspect it needs to run from its own environment? Anyway I think it might run if windows wasn't struggling to boot? I don't know maybe it has to be run from the harddrive but I don't know how to install it. You can run a Repair if you borrow a Vista disk from someone but it must be the same as what you PRESENTLY have on your computer
2314.

Solve : Monitoring virus?

Answer»

I dont know any specification Please run RogueKiller again and delete those items.

Quote

I dont know any specification
Can you provide me with a screenshot?

How to post screenshots or images

I'd like to scan your MACHINE with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate BROWSERS only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop USING a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Ok SuperDave I must add when I wanted to PASTE Print Screen in the paint I saw an error then I used snipping tools And I saw the other error.
Other problems are I cant uninstall or install any program in the Normal Mode, I have deal with a lot of problems in normal mode, my windows photo viewer doesnt work at all and . . .
I attach these photos.

[recovering disk space, attachment deleted by admin]Do you have any accounts on this computer?No I dont .This will probably help.
2315.

Solve : Dealing with Malware (Having Followed the Guide)?

Answer»

Quote

Obviously the malicious IPs are still trying to gain access. What do you suggest I do? And is MBAM blocking the IPs the reason for my Comodo Firewall not notifying me?
Yes, MBAM is blocking them first otherwise, your Firewall would block them.
Could you please try to run ComboFix again. If it won't work, try doing it in Safe Mode.This is what I GOT when ComboFix was extracting files. When I clicked on retry the same message came up, and when I clicked on ignore I got another similar message about something else.

Ok, let's see if we can get rid of those tracking cookies.

SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click Yes
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences button.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

•It will open in your default text editor (preferably Notepad).
•Save the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.
**************************************
Also please try running the below online scan:

SuperAntiSpyware on-line scan

If you can post the log it created then please do so.
SUPERAntiSpyware was different to how you described it in your instructions.

16 tracking cookies were DETECTED. Once the scan was finished, it gave me the option to view the scan log (below) and remove detected threats. Having ensured everything was checked, I removed the threats from my computer. It didn't prompt me to reboot my computer; after the threats were removed, it just went back to the "home" screen.

Once on the home screen, I checked the "Manage Quarantine" section, where the following were listed. I assume I should just check all 4 and delete?



Here's the log:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/14/2013 at 00:03 AM

Application Version : 5.6.1018

Core Rules Database Version : 10394
Trace Rules Database Version: 8206

Scan type : Quick Scan
Total Scan Time : 00:07:59

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC On - Limited User

Memory items scanned : 749
Memory threats detected : 0
Registry items scanned : 63428
Registry threats detected : 0
File items scanned : 21475
File threats detected : 16

ADWARE.Tracking Cookie
accounts.youtube.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ]
accounts.google.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ]
.trackalyzer.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ]
.s.clickability.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ]
.s.clickability.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ]
C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Cookies\1ST8EC77.txt [ /c.atdmt.com ]
C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Cookies\GGV9FZ8O.txt [ /serving-sys.com ]
C:\USERS\SHIRLEY\Cookies\1ST8EC77.txt [ Cookie:[emailprotected]/ ]
C:\USERS\SHIRLEY\Cookies\GGV9FZ8O.txt [ Cookie:[emailprotected]/ ]
.invitemedia.com [ C:\USERS\SHIRLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.invitemedia.com [ C:\USERS\SHIRLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
accounts.google.com [ C:\USERS\SHIRLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
accounts.google.com [ C:\USERS\SHIRLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
I tried running the online scan but it didn't work. I downloaded the scanner, clicked 'yes' to the security warning - but nothing happened afterwards. No alert from my antivirus, so I don't think that was blocking it. Do you know of any reason why this is the case?Quote
SUPERAntiSpyware was different to how you described it in your instructions.
That's possible. It's been some time since I've used it.
Quote
Once on the home screen, I checked the "Manage Quarantine" section, where the following were listed. I assume I should just check all 4 and delete?
Yes, please do that.
Quote
Do you know of any reason why this is the case?
This is the first time I've tried this scanner. I'll have to test it to see what's happening.

Have you noticed any activity from MBAM?Okay, I deleted the 4 files. I've also ran a second scan (this is ~2 hours after the first) and a few more adware tracking cookies were found. I've deleted these as well. Does this mean these files were added to my computer in the 2 hours between doing the two scans? 2 of the newly found files were LABELLED "imrworldwide.com" - is this particularly malicious? I also haven't visited this site, so I'm guessing it's very common on a lot of other websites?

Quote from: SuperDave on May 13, 2013, 06:49:48 PM
Have you noticed any activity from MBAM?
No activity - MBAM scans continue to come back with no threats found, and I haven't received any notifications of malicious IPs trying to gain access. I think this is due to the uninstalling (and then reinstalling) of Google Chrome. Once I did this, I haven't received any further notifications from MBAM. I will continue to monitor this and update you in the next couple of days.

In the meantime, are there any further checks I should be carrying out?

I run daily anti-virus and MBAM scans. Out of all the various different scans I've done since first starting this thread, which (if any) do you recommend I do at least once a day? I've just ran another scan and 13 new threats have popped up - all similar tracking cookies to the ones I've already deleted.

Why do they keep coming back, and how can I stop this happening? Quote
Does this mean these files were added to my computer in the 2 hours between doing the two scans? 2 of the newly found files were labelled "imrworldwide.com" - is this particularly malicious? I
That's possible to acquire those cookies.
imrworldwide.com
Quote
In the meantime, are there any further checks I should be carrying out?
Not at the moment.
Quote
I run daily anti-virus and MBAM scans. Out of all the various different scans I've done since first starting this thread, which (if any) do you recommend I do at least once a day?
It shouldn't be necessary to do that every day.
Quote
Why do they keep coming back, and how can I stop this happening?
What browser are you using?Quote from: SuperDave on May 14, 2013, 03:29:19 PM
What browser are you using?
I use Google Chrome and Firefox. I'd use Firefox for everything, but I prefer Chrome's layout + some sites run slowly on Firefox, but fine on Chrome.

Is the issue using Google Chrome?Quote from: LiquidTension on May 14, 2013, 03:38:56 PM
I use Google Chrome and Firefox. I'd use Firefox for everything, but I prefer Chrome's layout + some sites run slowly on Firefox, but fine on Chrome.

Is the issue using Google Chrome?
Yes, it could be a security issue with Chrome. Check the options to raise the security level.Quote from: SuperDave on May 14, 2013, 04:18:52 PM
Yes, it could be a security issue with Chrome. Check the options to raise the security level.
I've set it to block any websites from setting data/cookies. Do you think this should the tracking cookies from being added?

Where do you suggest I go from here? You mentioned clean up a couple of days ago? Quote
I've set it to block any websites from setting data/cookies. Do you think this should the tracking cookies from being added?
That should do it. Let's do some cleanup in the meantime.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*********************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest IMMUNIZATIONS always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.Okay, thanks very much Dave. I've done the clean up as instructed above. I really appreciate all the help you've given me.Quote from: LiquidTension on May 15, 2013, 06:04:29 AM
Okay, thanks very much Dave. I've done the clean up as instructed above. I really appreciate all the help you've given me.
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2316.

Solve : FBI Virus scam?

Answer»

Thank you for helping. I am EXPERIENCING the FBI scam virus where they are asking for payment. I have TWO logins on my computer, mine and my wife. Mine is the admin. I tried to log on using SAFE mode with networking in order to download malware removal but when I do Windows keeps shutting down and reverts to normal windows login. I can still access the internet and use the computer normally using my wife's login.Will anti malware uploaded onto my wife's account delete files from the entire C drive or just her account?Your best bet would be to create a NEW account for yourself then delete your old, infected one. Once that's done we can run some scans on the computer to make sure it's clean.I just ran SuperAntiSpyware Free and Malwarebytes Antimalware on this user and neither worked. My home screen has a huge FBI warning and payment request with a black screen in the background. How do I delete my account and create a new one? I cannot get into the admin account in a safe mode.I booted the computer in "Safe Mode with Command Prompt" and created an additional admin account. I logged onto that account in regular mode and installed/ran Malwarebytes. I was prompted to restart to REMOVE Trojans and then logged back into my original account without issue. I then deleted the temporary admin account. problem solved. Thanks for the help.We should run a few more scans just to make sure it's clean, if you don't mind. Infections like usually leave some residue.

Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*****************************************
Please download AdwCleaner by Xplode onto your Desktop.

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
2317.

Solve : Win32 EVO-gen [susp] - While downloading SP3 ISO for XP??

Answer»

Was downloading Service Pack 3 ISO for XP from Microsoft and got this alert. I am hoping its a false positive and Microsoft is not offering a ISO that came with an infection.

Anyone know if this is a false positive? I am guessing that [susp] means suspicious as in it could be a false positive.

Attached is screenshot showing detection.

Here is the link that I was using from Microsoft http://www.microsoft.com/en-us/download/details.aspx?id=25129

Need to create a SP3 Slipstream, but on hold until i GET a confirmation that its a false positive.

[recovering disk space, attachment deleted by admin]Did they provide a check sum to verify the purity nth file?
It looks like one of the SP3 HP Printer DRIVERS trigger a false positive in Avast 8 (and later?)





Thanks for the response. I'll fetch it from quarantine and burn the iso to use for my slipstream then.Are you sure you downloaded it from MS and not a bogus site.Quote

Are you sure you downloaded it from MS and not a bogus site.

I believe the download was direct from Microsoft, since I was at Microsofts site when I selected the download and it told me that others that downloaded this also downloaded 2 other updates etc, which I chose not to download the other 2 updates since I just needed SP2 and SP3. In the attached image at my first post, it specifies the URL path. I knew that the origin would be in QUESTION if I didnt supply the screenshot showing the URL path of DATA origin.

I was able to bring my XP Home SP0 to slipstream of SP2, and then use SP2 to slipstream to SP3 since you cant slipstream to SP3 directly from SP0, and then used this info I found at www.bleepingcomputer.com where I am also a active member under the username of goldfist, where a person pointed a prior information inquiry to http://xdot.tk/updates.html and this patch/hotfix downloader worked awesome.

Now I just need to install XP Home SP3 with hotfixed slipstream to this Pentium 4 3Ghz HT with 2GB RAM, and everything should be good. I am curious as to if there will be any updates or not after the install. Would be cool if there are few to COMPLETE or none if the patch/hotfix downloader list is up to date before creating the slipstream.

This site for the patch/hotfix downloader for use with nLite claims:

Quote
Latest Patch Tuesday Update: December 10, 2013
Last Updated: December 12, 2013


So I am guessing not many additional updates needed if any.Quote
I am curious as to if there will be any updates or not after the install.
I would imagine there would be some updates.
2318.

Solve : White screen when trying to boot?

Answer»

Hello,

I have some trouble with my HP Pavilion dv6700. When I try to turn it on, the screen goes all white. I THINK it is a virus, because I've tried connecting it to another screen, but it's still the same thing. I managed to reboot Windows Vista VIA the DOS once, but when I'd been using it for about an hour, the screen WENT all fluffy with red and orange colors, and after a while it just went white.

Is there any way for me to completely erase the harddisk and then maybe install Linux on it (I don't have a windows CD) ?

THANK you in advance
Why do you think it's a virus?It sounds more LIKE a graphics card.

2319.

Solve : Is this safe? Or should I do differently??

Answer»

A client brought me his virus-infected laptop, an HP Pavilion dv9627cl. He wants me to backup the Users' files, wipe Vista and install 7, then copy back the Users' files. Is it safe to do the backup to my laptop, from the infected hdd while it is connected as an external, then delete/create/format using diskmgmt.msc? Or is there a better approach? Any suggestions will be greatly APPRECIATED. Thanks. I WOULD suggest backing up his files to DVD-RW's and make sure you scan them with at least two good AV's programs before PUTTING them back on the re-formatted computer.If you slave his HD to your computer, and you have a WORLD class AV program running, (like AVG) you won't be able to OPEN, copy of move any file without it being scanned. If in doubt just right click on the drive and SCAN it. Again I'm talking about a program like AVG where you can tell it to scan a file, a folder or even a drive. That's what I do. I will scan it with Trojan Hunter and Malware Bytes too, while I'm at it. The more the better! Eh?

Then copy the files to a folder on your own drive and then burn them to DVD (s) for archival purposes.
After restoring the files to the new OS, give the DVD to your customer. They will love you for the courtesy.

Cheers Mate
Shadow I would hardly call AVG world class.

2320.

Solve : Is my MS Window Genunie??

Answer»

Last time SuperDave suggested me to use diagnostics tool MGADiag.ext to check whether my window is genuine? I finished the log and PLEASE advice me whether it is genuine? I think it is Genuine because it has Validation Status: Genuine, is that the way we decide that,

Just an additional question, what are the rest for since we have Validation Status: Genuine, thank you


Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Status: Genuine
Validation Code: 0
Cached Validation Code: N/A
Windows Product Key: *****-*****-FG9T4-48V9V-4GWKY
Windows Product Key Hash: eR8LE1lxRYvCWev9o8QRQeYBBco=
Windows Product ID: 76487-640-9636121-23585
Windows Product ID Type: 1
Windows License Type: Volume
Windows OS version: 5.1.2600.2.00010100.3.0.pro
ID: {6E2DABC6-6A36-4BC2-9369-E21FC4A320E1}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: Registered, 1.9.40.0
Signed By: Microsoft
Product Name: N/A
Architecture: N/A
Build lab: N/A
TTS Error: N/A
Validation Diagnostic: 025D1FF3-230-1
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A
Version: N/A

Windows XP Notifications Data-->
Cached Result: 0
File Exists: Yes
Version: 1.9.40.0
WgaTray.exe Signed By: Microsoft
WgaLogon.dll Signed By: Microsoft

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 114 Blocked VLK 2
Microsoft Office PROFESSIONAL Edition 2003 - 114 Blocked VLK 2
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-230-1

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Documents and Settings\noname\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: {6E2DABC6-6A36-4BC2-9369-E21FC4A320E1}1.9.0027.05.1.2600.2.00010100.3.0.prox32*****-*****-*****-*****-4GWKY76487-640-9636121-235851S-1-5-21-1202660629-329068152-1177238915Samsung ElectronicsSX20SPhoenix Technologies LTD08ZE20050623000000.000000+000C6F03107018400E204090409AUS Eastern Standard Time(GMT+10:00)03114114Microsoft Office Professional Edition 20031159D1605114E3500vfZmaSmFPIYrLWTcZSZErUQg+Fo=73931-640-0000106-5788514

Licensing Data-->
N/A

Windows ACTIVATION Technologies-->
N/A

HWID Data-->
N/A

OEM Activation 1.0 Data-->
BIOS string matches: yes
Marker string from BIOS: 1E710:Samsung Electronics CO., LTD
Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005

OEM Activation 2.0 Data-->
N/A
Has your copy of Windows ever been validated?What do you mean "last time"? How MANY times do you need to check if you Windows is genuine?@SuperDave: In fact I am not sure, because the system I have got was from my brother Ghost file

@Allan: sorry, last time, I asked another question but suddenly, you guys mentioned window genuine, but my previous post was closed by my tutor due to training purpose, so I start one here

Thank you guysIt would APPEAR that it was not validated. Please read here how to validate it.Quote from: SuperDave on October 02, 2012, 01:18:21 PM

It would appear that it was not validated. Please read here how to validate it.

Oh, but why my system will still update while it is not validate, is it bad if my window does not validate? thanksThere will be certain programs and updates that you will not receive.but what if the validation is not sucessful, then can i still use that.

at the moment, i am using Eset + microsoft security essential, do they crash together? thanksQuote from: johnha169 on October 03, 2012, 03:22:36 PM
but what if the validation is not sucessful, then can i still use that.

at the moment, i am using Eset + microsoft security essential, do they crash together? thanks
More than one Anti-Virus active on your computer is not recommended.ok, the delete the Microsoft one, well, I think my final decision is to keep my window verified, because I am afraid once the verification does not succeed, it may prevent me from doing something, thanks SuperDave
2321.

Solve : Comodo Security Alert !!?

Answer»
My Comodo Firewall tells me i'm infected after Windows (7) loads. The name of the infection is - [emailprotected]

It popped up after i downloaded some drum machine software from CNET here -
http://download.cnet.com/HammerHead-Rhythm-Station/3000-2170_4-906069.html

The Comodo alert has a link to this page
http://cima.security.comodo.com/report/3a4bb6dffff1848f3a2bdc3cd1186ca0e0d3dab4.htm

I've run Avast Anti-virus (Free), Anti-Malware and Super Anti-spyware, both with full scans, with no result. Yet the alert still pops up. http://forums.comodo.com/empty-t74716.0.html
Yeah, seen that, it doesn't HELP MUCH thoughBased on that thread it is a false positive not detected by the LATEST definitions. SINCE your other malware / AV software do not detect it I suggest you submit it to the Commodo forum for them to evaluate.
It can't seem to find it.
2322.

Solve : Boot from AVG repair on USB Didn't Work?

Answer»

Well, it's been a difficult time TRYING to get the computer to recognise a disc or a USB stick. After worrying myself sick about losing all my huge collection of PHOTOS and digital art if it crashed totally, I ended up having a guy do a home visit. He took out the Hard Drive and we copied as much info as we could onto my laptop. It was also scanned and we hoped, fixed errors on the disc. Then we put it back in and tried to get it running and the problem was still there. That disc was not recognised, or it was locked, and so on, we just couldn't repair it.

This 'sometimes' beautiful Dell is only six MONTHS old and needed a new motherboard almost from day 1 because it wouldn't boot, the CD drive mechanism replaced a couple of months later, it wouldn't (and still doesn't) turn on on first press on the switch, but will on the second, and now there seems to be a connection issue from the hard drive that has caused the current problem.

We just about gave up and had one last try with my OS disc, and after 10 MINUTES, it recognised it and went on to install...... but didn't do a full one (?). I didn't need to put the drivers in and my desktop image from before came up! Weird!

Goodness knows what the hours my man spent will cost me. He is writing all the details on his invoice, and his opinion that my Dell is a 'lemon' and should be replaced. I will be writing to Dell and asking for a replacement.

Thank you for your assistance, I tell evreyone how great this forum is.

You're welcome. I will lock this thread. If you need it re-opened, PLEASE send me a pm.

2323.

Solve : Computer starts automatically only in safe mode, registry attack??

Answer»

Quote

I am mostly concerned now about possible infection of the laptop VIA the backup and also the use of a USB flash drive in the previous clean up steps, as well as our home NETWORK.
If you're laptop became infected, you would soon know it. Run your AV scan on it and also on your flash drive.I scanned the hard drive and the flash drive and they are both okay.Just to be on the safe side, run another scan with this scanner.No need to post the logs.

Please download and run MicroSoft Safety Scanner. This will take about 20 minutes to run and will produce a log if your computer was infected. Please post the log. This scanner only has a shelf life of 10 days so you will need to download a new one if you want to run a scan after the trial period has expired.I ran the quick scan and it found no infections. I ORIGINALLY started the full scan but at 28 minutes it was barely a quarter finished so I quit and did the quickie instead which took about the 20 minutes that you had estimated. Thank you. What NEXT?Quote from: raygill on May 29, 2013, 03:34:12 PM
I ran the quick scan and it found no infections. I originally started the full scan but at 28 minutes it was barely a quarter finished so I quit and did the quickie instead which took about the 20 minutes that you had estimated. Thank you. What next?
That's it unless you've changed your mind about reformatting your harddrive.Well, even though the news has been bad, I want to thank you and everybody at this site in helping me to learn more about the mess I have gotten myself into and hopefully how to avoid it happening again. This is really an excellent resource for someone like me with a modest amount of knowledge about computers, just enough to get myself into trouble, but a DESIRE to learn more without really knowing how to go about it. This forum seems like a good learning tool. Thanks again and .You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.
2324.

Solve : Trying to see if this is true malware?

Answer»

So TODAY I did a quick SCAN with malware bytes and was looking for malware slowing down my PC.
So I Scanned 60,000+ Items And Left it for 15 Min it pulled up malware but I NEED to be sure it is safe to delete Log is Below

FILES THAT WERE CONDEMNED AS MALWARE:
===================================
Reg Keys:
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A)
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF190686-9E72-403C-B99D-682ABDB63C5B} (PUP.Optional.TopArcadeHits.A)
HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A)
===================================

DLL Files:
C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll (PUP.Optional.Conduit)



Code: [Select]Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.01.01

Windows 7 Service Pack 1 x64 NTFS
rac :: RAC-HP [administrator]

1/1/2014 12:34:50 AM
MBAM-log-2014-01-01 (00-50-14).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 57113
Time elapsed: 15 minute(s), 4 second(s) [aborted]

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 3
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF190686-9E72-403C-B99D-682ABDB63C5B} (PUP.Optional.TopArcadeHits.A) -> No action taken.
HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} (PUP.Optional.OptimzerPro.A) -> No action taken.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Program Files (x86)\Conduit\Community Alerts\Alert.dll (PUP.Optional.Conduit) -> No action taken.

(end)
ARE THESE FILES BAD CAN I DELETE THEM? YES

2325.

Solve : Virus killing all application on both dual booted win OS?

Answer»

Greetings CH!

Last week i downloaded some sort of Virus that has terrorized my system. Ill boot into windows 7 Ultimate and i get all my login applications showing ".... has stopped working" and every program i try and open is the same thing. ON the windows XP partition i open an application and get "...has encountered a problem"

So i don't care much for trying to get RID of the Virus. Im going to do a clean install as it needed one anyways.
What im concerned about is the files and folder that i have on the drive.
I have a Sata To usb kit i wanna use to transfer all the stuff i need to my macbook and then back to my restored PC. However i want to be sure that the virus hasn't infected any of those files. What piece of software would work for me? I have another PC laptop i can use it on if the whole mac/Pc software is an issue.

Just wanna scan my stuff (preferably free) to make sure no virus is in it.
Let me know thanksYour best bet would be to save you important data to DVD-RW's which can be reused afterwards and scan them with two good Anti-Virus programs before putting them back on the re-formatted computer. Ok but which program can i use super dave? I have no anti virus and therefore i dunno which one to use to check the files hence the point of this thread. Quote

Ok but which program can i use super dave? I have no anti virus
It's dangerous to go on-line with no AV on your computer. You're just asking for trouble.

Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses ADDITIONAL RESOURCES and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
2326.

Solve : Is multi commander file explorer dangerous ??

Answer»

Hello ,

I just downloaded the MULTI COMMANDER file explorer from home PAGE and avast just warned me that this file is dangerous and is present on a few other computers in world and it recommends me to abort the DOWNLOAD and remove the file .

This thing looked to me like a bad joke ), i believe that avast is wrong here and i should continue the installation, but STILL i thought that is better to discuss this, anyone else had this problem ?

Thanks !

Check this site to learn more about that program.

2327.

Solve : Had a close call with a virus/malware, is Free AVG enough? Or the cause??

Answer»

I ENDED up with some virus/malware file(s) that Microsoft security caught, and an AVG warning came up to offer to fix before continuing. But it wasn't my free version, it wanted $59.99 for 30 days, 79.99 for 6 months and 99.99 for the year. I wasn't able to do much and the warnings kept coming up. I ran my Anti malware program and it wasn't able to remove EVERY threat. I tried to install a different free antivirus program (avira, I think it was). The warning popped up every click, finally when the avira page was loading, it would redirect me to facebook. I tried this multiple times, it was weird, I never had something lik ethat. I was like held hostage by AVG, I was almost about ready to pay, but didn't want to give out credit card info. I decided to go to my laptop and look ONLINE on how to fix. One post had said it wasn't a virus but some sort of malware and just to do a system restore and it should go away. And it did, for now. So my question is, is the free AVG antivirus enough? Should I do away with AVG completely and use someone else. I had a paid subscription to PC tools antivirus and tools, but it EXPIRED and I didn't renew since they are retiring in December. I run the Antimalware program and CC cleaner also. Hope this makes sense. Thanks I would try using Malwarebytes to remove your issue. Thats just where I start.

Now next to my opinion, because trust me every one has one when it comes to anti-virus.

I am an avid AVG user. I manage over 200 PC and have it on every one of them, but I pay for it, business edition. I would not put a free version of anything on a PC I support or my personal ones. You get more for the paid versions. Now with that said, AVG might not be for you. I would look at all the power players in the antivirus game; McAfee, Symantec, Kypersky, and AVG. When you ask someone what their favorite it is, they will tell you and tell you why the others suck, but for every person who THINKS Symantec sucks is an avid symantec user/lover.

So to sum up:
Research whats best for you.
You get what you pay for.
I prefer AVG.

Hope this helps.I have been cleaning computers for over 5 years and I get as many infected computers that use a commercial (paid for) AV as those that use free versions. I would suggest your download and use MicroSoft Security Essentials. It's easy on resources and very effective.

MicroSoft Security Essentials All versions and all languages.

Here's a comparative list of all AV's. Quote from: SuperDave on November 13, 2013, 01:12:23 PM

Here's a comparative list of all AV's.
Thank you for that, added to bookmarksIf your ever having a problem with a virus already on your computer, a good way to prepare before that happens is to download norton power eraser, and the Norton bootable recovery tool. The power eraser is free, but the recovery tool can only be used if you have/had a norton disk with the code.

https://security.symantec.com/nbrt/
2328.

Solve : Can someone hack into your copy and paste??

Answer»

Hi

I found a letter on my copy and PASTE that I did not write and my husband said he did not write it.
My husband is telling me someone hacked into our computer and put on our copy and paste.
Is this even possible or total BS?
Thanks.
Quest
You're going to have to explain what your "copy paste" is.It's possible she's referring to the clipboard. I've never heard of such a thing as hacking to get into the clipboard.Hi,
Writing something in notepad or word and copying it into an email.
Can that be hacked into?While THEORETICALLY it is possible for a virus on your computer to put stuff in your clipboard (copy and paste), there is no reason why this would ever be done - People will only write viruses if there is some sort of gain to the creator, this is not the case with this.

I have also never heard of any virus that could cause this.Quote

Writing something in notepad or word and copying it into an email.
Can that be hacked into?
As stated before, I seriously doubt that someone took the time to create malware in order to put something on your clipboard. Someone could have put this on the clipboard but they would have to have access to your computer either directly or remotely.Thanks EVERYONE for your answers.
2329.

Solve : Wifes system - Strange - Not sure if malware, 50-60% CPU when idle?

Answer»

My wife complained that her computer was running slow yesterday, and I saw that at idle the dual-core CPU showed that it was running around 50-60% on both cores.

I WENT to task manager and looked at Processes and sorted the CPU column so that the most active processes show at the top, but there was only 3 processes that showed like 05%, 03%, and 02% and rest of them 00%. And that adds up to just 10%, so what is going on to make the CPU run both of its cores at 50-60% and making the system slightly slower than normal.

Hard Drive Activity LED was only showing an occasional flicker.

Microsoft Security Essentials I ran a Full Scan as well as Malwarebytes ran a full scan and they both came up clean.

* I am about to wipe the hard drive and install a clean Windows 7 build to it since its been running for almost 2 years without rebuild and PROGRAMS have been installed and removed through this time and its probably time to clean it up... but what really gets me is why the CPU a Core 2 Duo E6600 2.4Ghz is running at 50-60% when it use to idle between 10-20%

Her system also takes automatic microsoft updates and runs 24/7 most of the time because she is too lazy to shut it down and turn it back on like I do to my system. She thinks that the system started running slower since Tuesday. *Tuesday also just happens to be Patch Tuesday for this month. So not SURE if its related or not. I am just stumped as to how a process or processes can hide and use CPU and cant find the culrpit in Task Manager to target the problem directly. Also I am not sure if I am dealing with a malware or something else, so I figured I'd ask here for suggestions to find the processes that are making the CPU busy. Is there a better tool than task manager for windows to see all processes including what I believe is a hidden process that is running causing the CPU activity?
Here are her system specs:

Core 2 Duo E6600 (2.4Ghz)
2GB DDR2 667Mhz
160GB IDE HDD ( OS + Software + Personal Data )
40 GB SSD SATA II ( Games Only )
Windows 7 Home Premium 32-bit


**If I rebuild her system I am going to make the SSD the boot drive with Windows 7 on it and I have an 80GB SATA II drive that I can upgrade her away from the slower IDE HDD that is limited to ATA100. Also at some point I should probably upgrade her to 3GB RAM although when she games she still has 25% free memory at the 2GB ( @500MB free RAM ).Restarting the computer is sometimes the best thing you can do the computer. Is it slow in Safe Mode.Quote from: DaveLembke on November 14, 2013, 04:23:29 PM

I went to task manager and looked at Processes and sorted the CPU column so that the most active processes show at the top, but there was only 3 processes that showed like 05%, 03%, and 02% and rest of them 00%. And that adds up to just 10%, so what is going on to make the CPU run both of its cores at 50-60%
Run task Manager as administrator by clicking the "Show Processes from All Users" button.Thanks for responses, also forgot about the fact that my wife is a user and not an admin of her system and so BC's suggestion to check the show process from all users I forgot about.

Oddly the issue was gone when I went to check on her computer last night. It was back to 6 to 15% CPU usage on both cores. She thanked me for fixing the problem and I didnt do anything to fix it, it fixed itself and yet it wasnt powered down or rebooted since the odd behavior the other night. But if I see the problem again, I will remember this time to check on show for all users since she is just a user and I did not give her admin rights to keep the computer from getting installed with junk like she did in the past with coupon programs etc that have spyware etc with them. For her to install anything, or anything wanting to install, it pops up requiring admin password and she doesnt know that password yet so odds of her getting infected are slim unless there is some sort of exploit that can infect a computer with just user privileges.

I guess we can close this ticket for assistance as for the problem is gone for now. *Also maybe I will set up a scheduled task to reboot her computer at 4am etc every day so that it can be refreshed on a daily basis.Problem came back and I found the process that is wasting CPU at 50-60%. Its Spoolsv.exe that is wasting the CPU. When I showed process for all users it showed that the SYSTEM had this service running at 50 to 60%.

Did a search on Google and came up with this hit that looks like an exact match even down to the Core 2 Duo CPU that this other guy had.

http://answers.microsoft.com/en-us/windows/forum/windows_7-performance/spoolsvexe-process-is-running-all-the-time-and/8268f671-51b8-42a3-9ce8-708e9686052d


Going to try this fix and see what happens:

Quote
Hey

Yeah Spoolsv.exe is a service that Uses a lot of cache even when its not required.

Here is a fix for that :->

1 - Go to Start, Settings and click Control Panel
2 - In the Control Panel window, first double-click on Administrative Tools and then on Services.
3 - In the right pane of the Services window locate and right-click on Print Spooler and then select Stop.
4 - After you have stopped this process, leave the Service window open. Now open My Computer and navigate to the following folder.
c:\windows\system32\spool\PRINTERS - in Windows Vista, XP, 98/95/ME
or
c:\winnt\system32\spool\PRINTERS - in Windows NT\2000
5 - Delete all the files in the Printers folder. After deleting the files in this folder, go back to Services window, right-click on Print Spooler, and then select start to re-enable the service.

Here is what the initial user posted for a problem:

Quote
spoolsv.exe process is running all the time and wasting 50% CPU's power (one of two cores).
I've found that spoolsv.exe is accorded to printing. When this process is killed or service "Printing cache/buffor" is stopped, printing is impossible. I tried to switch automatic initialization to manual (in services.msc), but this process doesn't start even I ask any application to print.
spoolsv.exe takes all power of one core from mu CPU (core 2 duo). I've got Windows 7 Professional x86 Polish. I attached some screenshoots that could be helpful. Sorry for my poor english.

* Only difference between this persons post and my wifes system is that they claimed only a single core of the 2 cores running at 50%, and they are running Windows 7 Pro x86 with polish language set and my wife is running Windows 7 Home Premium 32-bit ( x86 ) English US language set. Also oddly this issue was reported back in 2009, so strange that she all of a sudden got hit with it now, but it looks like a problem is in the printer folder at this location that causes this behavior a corruption etc. Hopefully this is the solution. Time will tell.

Attached screenshot of what I found at C:\windows\system32\spool\printers ..... wasnt expecting to find shockwave files in there... very odd. Also even though I told spoolsv.exe to stop in task manager including all process trees related to it, it mysteriously started itself back up locking these shockwave files from deletion because they were in use. With the window open to their location i once again told task manager to kill the spoolsv.exe process and all related tree processes and then quickly went to this location and DELETED the files successfully.

Going to monitor the systems behavior today and ask for help if it mysteriously kicks back on again and starts eating 50% CPU again. Right now after 5 minutes it hasnt started back up yet like before.

Did an additional search and came up with this:

http://support.microsoft.com/kb/264662

Quote
SYMPTOMS
After all print jobs are completed, you have several SPL, SHD, and TMP files left over in the C:\Winnt\System32\Spool\Printers directory.

WORKAROUND
You can safely delete leftover files that have an .spl, .shd, or .tmp extension from the C:\Winnt\System32\Spool\Printers directory. These files should have been automatically deleted when the print job was printed.

Malwarebytes and MSSE are still happy reporting system clean





[recovering disk space, attachment deleted by admin]
2330.

Solve : Trying to get rid of ad.yieldmanager/allmplayerdownloads.com popup ads :(?

Answer»

Quote

Still having some crazy ad issues (like random text words being linked to ads when I run the mouse over them)

Here'smore about that. Only certain sites use them.

Quote
What should I do next?
Please let me know how your computer is working.Ok. Well, in that case, most site I visit (including this one) have the in-text advertising. I also still have the popups (just got another one as I accessed this website) What browser do you see the pop-ups on?
Here's some more information about in-text advertising.


  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

  • If an infected file is detected, the default action will be Cure, click on Continue.

  • If a suspicious file is detected, the default action will be Skip, click on Continue.

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory..
Mozilla firefox.

TDSSKiller log: (no hits ) )

22:20:20.0372 24452 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
22:20:21.0401 24452 ============================================================
22:20:21.0401 24452 Current date / time: 2013/05/21 22:20:21.0401
22:20:21.0401 24452 SystemInfo:
22:20:21.0401 24452
22:20:21.0401 24452 OS Version: 6.1.7601 ServicePack: 1.0
22:20:21.0401 24452 Product type: Workstation
22:20:21.0401 24452 ComputerName: TOSHIBAP870
22:20:21.0401 24452 UserName: Lynny
22:20:21.0401 24452 Windows directory: C:\windows
22:20:21.0401 24452 System windows directory: C:\windows
22:20:21.0401 24452 Running under WOW64
22:20:21.0401 24452 Processor architecture: Intel x64
22:20:21.0401 24452 Number of processors: 8
22:20:21.0401 24452 Page size: 0x1000
22:20:21.0402 24452 BOOT type: Normal boot
22:20:21.0402 24452 ============================================================
22:20:23.0308 24452 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:20:23.0341 24452 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:20:23.0371 24452 ============================================================
22:20:23.0371 24452 \Device\Harddisk0\DR0:
22:20:23.0371 24452 MBR partitions:
22:20:23.0371 24452 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x72C68800
22:20:23.0371 24452 \Device\Harddisk1\DR1:
22:20:23.0371 24452 MBR partitions:
22:20:23.0371 24452 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A385000
22:20:23.0371 24452 ============================================================
22:20:23.0388 24452 C: <-> \Device\Harddisk0\DR0\Partition1
22:20:23.0405 24452 D: <-> \Device\Harddisk1\DR1\Partition1
22:20:23.0405 24452 ============================================================
22:20:23.0405 24452 Initialize success
22:20:23.0405 24452 ============================================================
22:23:18.0257 28324 ============================================================
22:23:18.0257 28324 Scan started
22:23:18.0257 28324 Mode: Manual;
22:23:18.0257 28324 ============================================================
22:23:18.0677 28324 ================ Scan system memory ========================
22:23:18.0677 28324 System memory - ok
22:23:18.0677 28324 ================ Scan services =============================
22:23:19.0087 28324 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
22:23:19.0087 28324 1394ohci - ok
22:23:19.0157 28324 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\windows\system32\drivers\ACPI.sys
22:23:19.0167 28324 ACPI - ok
22:23:19.0187 28324 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
22:23:19.0187 28324 AcpiPmi - ok
22:23:19.0567 28324 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:23:19.0567 28324 AdobeFlashPlayerUpdateSvc - ok
22:23:19.0637 28324 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\windows\system32\drivers\adp94xx.sys
22:23:19.0637 28324 adp94xx - ok
22:23:19.0746 28324 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\windows\system32\drivers\adpahci.sys
22:23:19.0750 28324 adpahci - ok
22:23:19.0778 28324 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\windows\system32\drivers\adpu320.sys
22:23:19.0780 28324 adpu320 - ok
22:23:19.0832 28324 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
22:23:19.0833 28324 AeLookupSvc - ok
22:23:19.0913 28324 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\windows\system32\drivers\afd.sys
22:23:19.0917 28324 AFD - ok
22:23:19.0954 28324 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\windows\system32\drivers\agp440.sys
22:23:19.0955 28324 agp440 - ok
22:23:19.0967 28324 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\windows\System32\alg.exe
22:23:19.0969 28324 ALG - ok
22:23:19.0993 28324 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\windows\system32\drivers\aliide.sys
22:23:19.0993 28324 aliide - ok
22:23:20.0053 28324 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\windows\system32\drivers\amdide.sys
22:23:20.0053 28324 amdide - ok
22:23:20.0093 28324 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
22:23:20.0093 28324 AmdK8 - ok
22:23:20.0123 28324 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\windows\system32\drivers\amdppm.sys
22:23:20.0123 28324 AmdPPM - ok
22:23:20.0153 28324 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\windows\system32\drivers\amdsata.sys
22:23:20.0153 28324 amdsata - ok
22:23:20.0203 28324 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\windows\system32\drivers\amdsbs.sys
22:23:20.0203 28324 amdsbs - ok
22:23:20.0233 28324 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\windows\system32\drivers\amdxata.sys
22:23:20.0233 28324 amdxata - ok
22:23:20.0263 28324 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\windows\system32\drivers\appid.sys
22:23:20.0263 28324 AppID - ok
22:23:20.0283 28324 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\windows\System32\appidsvc.dll
22:23:20.0283 28324 AppIDSvc - ok
22:23:20.0323 28324 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\windows\System32\appinfo.dll
22:23:20.0323 28324 Appinfo - ok
22:23:20.0423 28324 [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
22:23:20.0423 28324 Apple Mobile Device - ok
22:23:20.0473 28324 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\windows\system32\drivers\arc.sys
22:23:20.0473 28324 arc - ok
22:23:20.0513 28324 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\windows\system32\drivers\arcsas.sys
22:23:20.0513 28324 arcsas - ok
22:23:20.0583 28324 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
22:23:20.0583 28324 AsyncMac - ok
22:23:20.0603 28324 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\windows\system32\drivers\atapi.sys
22:23:20.0603 28324 atapi - ok
22:23:20.0653 28324 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
22:23:20.0663 28324 AudioEndpointBuilder - ok
22:23:20.0673 28324 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\windows\System32\Audiosrv.dll
22:23:20.0683 28324 AudioSrv - ok
22:23:20.0753 28324 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\windows\System32\AxInstSV.dll
22:23:20.0763 28324 AxInstSV - ok
22:23:20.0803 28324 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\windows\system32\drivers\bxvbda.sys
22:23:20.0813 28324 b06bdrv - ok
22:23:20.0833 28324 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys
22:23:20.0843 28324 b57nd60a - ok
22:23:20.0863 28324 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\windows\System32\bdesvc.dll
22:23:20.0863 28324 BDESVC - ok
22:23:20.0893 28324 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\windows\system32\drivers\Beep.sys
22:23:20.0893 28324 Beep - ok
22:23:20.0933 28324 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\windows\System32\bfe.dll
22:23:20.0943 28324 BFE - ok
22:23:20.0983 28324 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\windows\system32\qmgr.dll
22:23:21.0003 28324 BITS - ok
22:23:21.0023 28324 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
22:23:21.0023 28324 blbdrive - ok
22:23:21.0093 28324 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
22:23:21.0103 28324 Bonjour Service - ok
22:23:21.0143 28324 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\windows\system32\DRIVERS\bowser.sys
22:23:21.0143 28324 bowser - ok
22:23:21.0173 28324 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
22:23:21.0173 28324 BrFiltLo - ok
22:23:21.0193 28324 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
22:23:21.0193 28324 BrFiltUp - ok
22:23:21.0223 28324 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\windows\system32\DRIVERS\bridge.sys
22:23:21.0223 28324 BridgeMP - ok
22:23:21.0253 28324 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\windows\System32\browser.dll
22:23:21.0263 28324 Browser - ok
22:23:21.0273 28324 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\windows\System32\Drivers\Brserid.sys
22:23:21.0273 28324 Brserid - ok
22:23:21.0293 28324 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
22:23:21.0293 28324 BrSerWdm - ok
22:23:21.0313 28324 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
22:23:21.0313 28324 BrUsbMdm - ok
22:23:21.0323 28324 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
22:23:21.0323 28324 BrUsbSer - ok
22:23:21.0353 28324 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
22:23:21.0353 28324 BTHMODEM - ok
22:23:21.0403 28324 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\windows\system32\bthserv.dll
22:23:21.0403 28324 bthserv - ok
22:23:21.0433 28324 catchme - ok
22:23:21.0463 28324 [ B8BD2BB284668C84865658C77574381A ] CDFS C:\windows\system32\DRIVERS\cdfs.sys
22:23:21.0463 28324 cdfs - ok
22:23:21.0493 28324 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
22:23:21.0493 28324 cdrom - ok
22:23:21.0533 28324 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\windows\System32\certprop.dll
22:23:21.0533 28324 CertPropSvc - ok
22:23:21.0583 28324 [ 8FC9A59353F2C5D257613952AD697A2E ] CFUACProxy_boxsoftware C:\ProgramData\Clickfree\BoxSoftware\UACProxy.exe
22:23:21.0593 28324 CFUACProxy_boxsoftware - ok
22:23:21.0653 28324 [ B641F0302D444EB94509CFD998CF9FD8 ] cfWiMAXService C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
22:23:21.0653 28324 cfWiMAXService - ok
22:23:21.0683 28324 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\windows\system32\drivers\circlass.sys
22:23:21.0683 28324 circlass - ok
22:23:21.0713 28324 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\windows\system32\CLFS.sys
22:23:21.0723 28324 CLFS - ok
22:23:21.0783 28324 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:23:21.0783 28324 clr_optimization_v2.0.50727_32 - ok
22:23:21.0813 28324 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
22:23:21.0813 28324 clr_optimization_v2.0.50727_64 - ok
22:23:21.0883 28324 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:23:21.0883 28324 clr_optimization_v4.0.30319_32 - ok
22:23:21.0933 28324 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
22:23:21.0933 28324 clr_optimization_v4.0.30319_64 - ok
22:23:21.0983 28324 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
22:23:21.0983 28324 CmBatt - ok
22:23:21.0993 28324 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\windows\system32\drivers\cmdide.sys
22:23:21.0993 28324 cmdide - ok
22:23:22.0033 28324 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\windows\system32\Drivers\cng.sys
22:23:22.0043 28324 CNG - ok
22:23:22.0123 28324 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\windows\system32\drivers\compbatt.sys
22:23:22.0123 28324 Compbatt - ok
22:23:22.0143 28324 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\windows\system32\DRIVERS\CompositeBus.sys
22:23:22.0143 28324 CompositeBus - ok
22:23:22.0153 28324 COMSysApp - ok
22:23:22.0173 28324 [ 1263760C5F62674934C709C3EC31869D ] ConfigFree Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
22:23:22.0173 28324 ConfigFree Service - ok
22:23:22.0273 28324 [ 723E3512D6D1FF75E5398981B38FCEF7 ] cphs C:\windows\SysWow64\IntelCpHeciSvc.exe
22:23:22.0273 28324 cphs - ok
22:23:22.0293 28324 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
22:23:22.0293 28324 crcdisk - ok
22:23:22.0343 28324 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\windows\system32\cryptsvc.dll
22:23:22.0353 28324 CryptSvc - ok
22:23:22.0443 28324 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
22:23:22.0443 28324 cvhsvc - ok
22:23:22.0473 28324 [ 066B4AD6534D1C36CB6E6E342DB05ED2 ] CXPOLARIS C:\windows\system32\drivers\cxRDU253S.sys
22:23:22.0473 28324 CXPOLARIS - ok
22:23:22.0513 28324 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\windows\system32\rpcss.dll
22:23:22.0523 28324 DcomLaunch - ok
22:23:22.0553 28324 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\windows\System32\defragsvc.dll
22:23:22.0563 28324 defragsvc - ok
22:23:22.0593 28324 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\windows\system32\Drivers\dfsc.sys
22:23:22.0593 28324 DfsC - ok
22:23:22.0623 28324 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\windows\system32\dhcpcore.dll
22:23:22.0623 28324 Dhcp - ok
22:23:22.0633 28324 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\windows\system32\drivers\discache.sys
22:23:22.0633 28324 discache - ok
22:23:22.0653 28324 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\windows\system32\drivers\disk.sys
22:23:22.0653 28324 Disk - ok
22:23:22.0673 28324 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\windows\System32\dnsrslvr.dll
22:23:22.0673 28324 Dnscache - ok
22:23:22.0713 28324 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\windows\System32\dot3svc.dll
22:23:22.0713 28324 dot3svc - ok
22:23:22.0733 28324 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\windows\system32\dps.dll
22:23:22.0733 28324 DPS - ok
22:23:22.0773 28324 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
22:23:22.0773 28324 drmkaud - ok
22:23:22.0823 28324 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
22:23:22.0853 28324 DXGKrnl - ok
22:23:22.0913 28324 [ D00EAE9C735A7DEE8049E50D73D25434 ] eamonm C:\windows\system32\DRIVERS\eamonm.sys
22:23:22.0913 28324 eamonm - ok
22:23:22.0943 28324 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\windows\System32\eapsvc.dll
22:23:22.0943 28324 EapHost - ok
22:23:23.0003 28324 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\windows\system32\drivers\evbda.sys
22:23:23.0063 28324 ebdrv - ok
22:23:23.0093 28324 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\windows\System32\lsass.exe
22:23:23.0093 28324 EFS - ok
22:23:23.0143 28324 [ E5EDDE3C8158DD0CBC5812F201DCDED0 ] ehdrv C:\windows\system32\DRIVERS\ehdrv.sys
22:23:23.0143 28324 ehdrv - ok
22:23:23.0203 28324 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\windows\ehome\ehRecvr.exe
22:23:23.0213 28324 ehRecvr - ok
22:23:23.0233 28324 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\windows\ehome\ehsched.exe
22:23:23.0233 28324 ehSched - ok
22:23:23.0333 28324 [ AD4FAADE819E0DA9933BEA7C01D2C763 ] ekrn C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
22:23:23.0353 28324 ekrn - ok
22:23:23.0383 28324 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\windows\system32\drivers\elxstor.sys
22:23:23.0393 28324 elxstor - ok
22:23:23.0443 28324 [ 587F0F4145A1536A6E37EFD769B7665F ] epfw C:\windows\system32\DRIVERS\epfw.sys
22:23:23.0453 28324 epfw - ok
22:23:23.0463 28324 [ D2F812358EE8EE23CBB5C4DAFFB5B819 ] EpfwLWF C:\windows\system32\DRIVERS\EpfwLWF.sys
22:23:23.0463 28324 EpfwLWF - ok
22:23:23.0473 28324 [ 34BF55D69AB74D14C7E7A17259CB7DF8 ] epfwwfp C:\windows\system32\DRIVERS\epfwwfp.sys
22:23:23.0473 28324 epfwwfp - ok
22:23:23.0493 28324 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\windows\system32\drivers\errdev.sys
22:23:23.0493 28324 ErrDev - ok
22:23:23.0563 28324 [ DF96C3CD6AE15F6D0A6BCB70F9C1E88D ] esgiguard C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys
22:23:23.0563 28324 esgiguard - ok
22:23:23.0583 28324 [ 3B32CAA07D672F8A2E0DF5CB3A873F45 ] EsgScanner C:\windows\system32\DRIVERS\EsgScanner.sys
22:23:23.0583 28324 EsgScanner - ok
22:23:23.0613 28324 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\windows\system32\es.dll
22:23:23.0613 28324 EventSystem - ok
22:23:23.0653 28324 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\windows\system32\drivers\exfat.sys
22:23:23.0663 28324 exfat - ok
22:23:23.0693 28324 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\windows\system32\drivers\fastfat.sys
22:23:23.0703 28324 fastfat - ok
22:23:23.0743 28324 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\windows\system32\fxssvc.exe
22:23:23.0753 28324 Fax - ok
22:23:23.0783 28324 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\windows\system32\drivers\fdc.sys
22:23:23.0783 28324 fdc - ok
22:23:23.0803 28324 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\windows\system32\fdPHost.dll
22:23:23.0803 28324 fdPHost - ok
22:23:23.0813 28324 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\windows\system32\fdrespub.dll
22:23:23.0813 28324 FDResPub - ok
22:23:23.0833 28324 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
22:23:23.0833 28324 FileInfo - ok
22:23:23.0843 28324 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\windows\system32\drivers\filetrace.sys
22:23:23.0843 28324 Filetrace - ok
22:23:23.0863 28324 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\windows\system32\drivers\flpydisk.sys
22:23:23.0863 28324 flpydisk - ok
22:23:23.0903 28324 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
22:23:23.0903 28324 FltMgr - ok
22:23:24.0013 28324 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\windows\system32\FntCache.dll
22:23:24.0023 28324 FontCache - ok
22:23:24.0073 28324 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
22:23:24.0083 28324 FontCache3.0.0.0 - ok
22:23:24.0093 28324 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\windows\system32\drivers\FsDepends.sys
22:23:24.0093 28324 FsDepends - ok
22:23:24.0123 28324 [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr C:\windows\system32\DRIVERS\fssfltr.sys
22:23:24.0123 28324 fssfltr - ok
22:23:24.0173 28324 [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
22:23:24.0193 28324 fsssvc - ok
22:23:24.0223 28324 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
22:23:24.0223 28324 Fs_Rec - ok
22:23:24.0273 28324 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
22:23:24.0273 28324 fvevol - ok
22:23:24.0313 28324 [ 60ACB128E64C35C2B4E4AAB1B0A5C293 ] FwLnk C:\windows\system32\DRIVERS\FwLnk.sys
22:23:24.0313 28324 FwLnk - ok
22:23:24.0333 28324 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
22:23:24.0333 28324 gagp30kx - ok
22:23:24.0363 28324 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
22:23:24.0383 28324 GamesAppService - ok
22:23:24.0423 28324 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys
22:23:24.0423 28324 GEARAspiWDM - ok
22:23:24.0443 28324 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\windows\System32\gpsvc.dll
22:23:24.0453 28324 gpsvc - ok
22:23:24.0543 28324 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:23:24.0543 28324 gupdate - ok
22:23:24.0553 28324 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
22:23:24.0563 28324 gupdatem - ok
22:23:24.0583 28324 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
22:23:24.0593 28324 gusvc - ok
22:23:24.0603 28324 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
22:23:24.0603 28324 hcw85cir - ok
22:23:24.0623 28324 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
22:23:24.0633 28324 HdAudAddService - ok
22:23:24.0653 28324 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\windows\system32\DRIVERS\HDAudBus.sys
22:23:24.0653 28324 HDAudBus - ok
22:23:24.0663 28324 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\windows\system32\drivers\HidBatt.sys
22:23:24.0663 28324 HidBatt - ok
22:23:24.0683 28324 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\windows\system32\drivers\hidbth.sys
22:23:24.0683 28324 HidBth - ok
22:23:24.0693 28324 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\windows\system32\drivers\hidir.sys
22:23:24.0703 28324 HidIr - ok
22:23:24.0713 28324 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\windows\System32\hidserv.dll
22:23:24.0713 28324 hidserv - ok
22:23:24.0743 28324 [ 794868B22EC45220F91D077FEC3EB1F8 ] hidshim C:\windows\system32\DRIVERS\hidshim.sys
22:23:24.0753 28324 hidshim - ok
22:23:24.0783 28324 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys
22:23:24.0793 28324 HidUsb - ok
22:23:24.0813 28324 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\windows\system32\kmsvc.dll
22:23:24.0813 28324 hkmsvc - ok
22:23:24.0823 28324 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\windows\system32\ListSvc.dll
22:23:24.0833 28324 HomeGroupListener - ok
22:23:24.0853 28324 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\windows\system32\provsvc.dll
22:23:24.0853 28324 HomeGroupProvider - ok
22:23:24.0873 28324 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
22:23:24.0873 28324 HpSAMD - ok
22:23:24.0923 28324 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\windows\system32\drivers\HTTP.sys
22:23:24.0933 28324 HTTP - ok
22:23:24.0943 28324 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
22:23:24.0953 28324 hwpolicy - ok
22:23:24.0983 28324 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
22:23:24.0983 28324 i8042prt - ok
22:23:25.0033 28324 [ C224331A54571C8C9162F7714400BBBD ] iaStor C:\windows\system32\DRIVERS\iaStor.sys
22:23:25.0033 28324 iaStor - ok
22:23:25.0073 28324 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
22:23:25.0083 28324 iaStorV - ok
22:23:25.0113 28324 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
22:23:25.0153 28324 idsvc - ok
22:23:25.0393 28324 [ 9AA61DC7AA32C1D1260C4267FF07E0C1 ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys
22:23:25.0613 28324 igfx - ok
22:23:25.0623 28324 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\windows\system32\drivers\iirsp.sys
22:23:25.0623 28324 iirsp - ok
22:23:25.0653 28324 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\windows\System32\ikeext.dll
22:23:25.0683 28324 IKEEXT - ok
22:23:25.0783 28324 [ 8BD7EB761F4341E6F9FD066099F24B01 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHD64.sys
22:23:25.0853 28324 IntcAzAudAddService - ok
22:23:25.0913 28324 [ 6C9FFFECA9FED31347D211C5D1FFBD2D ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
22:23:25.0923 28324 IntcDAud - ok
22:23:26.0003 28324 [ 7C76466F4E0F76CE259C6005D161E9E8 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
22:23:26.0013 28324 Intel(R) Capability Licensing Service Interface - ok
22:23:26.0053 28324 [ D7467E57549960468E0CA85C17185B12 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
22:23:26.0053 28324 Intel(R) ME Service - ok
22:23:26.0073 28324 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\windows\system32\drivers\intelide.sys
22:23:26.0073 28324 intelide - ok
22:23:26.0103 28324 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys
22:23:26.0103 28324 intelppm - ok
22:23:26.0133 28324 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\windows\system32\ipbusenum.dll
22:23:26.0133 28324 IPBusEnum - ok
22:23:26.0143 28324 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
22:23:26.0143 28324 IpFilterDriver - ok
22:23:26.0183 28324 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
22:23:26.0213 28324 iphlpsvc - ok
22:23:26.0243 28324 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
22:23:26.0243 28324 IPMIDRV - ok
22:23:26.0253 28324 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\windows\system32\drivers\ipnat.sys
22:23:26.0263 28324 IPNAT - ok
22:23:26.0313 28324 [ A9AB99EE7D39725EAFEC82732D2B3271 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
22:23:26.0333 28324 iPod Service - ok
22:23:26.0363 28324 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\windows\system32\drivers\irenum.sys
22:23:26.0363 28324 IRENUM - ok
22:23:26.0363 28324 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\windows\system32\drivers\isapnp.sys
22:23:26.0363 28324 isapnp - ok
22:23:26.0393 28324 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
22:23:26.0393 28324 iScsiPrt - ok
22:23:26.0433 28324 [ 846354992EBB373F452EB9182D501B08 ] iusb3hcs C:\windows\system32\DRIVERS\iusb3hcs.sys
22:23:26.0433 28324 iusb3hcs - ok
22:23:26.0453 28324 [ 1D88A23853387D34D52CC8F9DDBFC56C ] iusb3hub C:\windows\system32\DRIVERS\iusb3hub.sys
22:23:26.0453 28324 iusb3hub - ok
22:23:26.0483 28324 [ FC5EFD7C797DF19DFB999F0605A7924E ] iusb3xhc C:\windows\system32\DRIVERS\iusb3xhc.sys
22:23:26.0503 28324 iusb3xhc - ok
22:23:26.0533 28324 [ 604A8615BB3D7064197A0563C799B938 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
22:23:26.0543 28324 jhi_service - ok
22:23:26.0563 28324 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
22:23:26.0563 28324 kbdclass - ok
22:23:26.0583 28324 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\windows\system32\DRIVERS\kbdhid.sys
22:23:26.0583 28324 kbdhid - ok
22:23:26.0593 28324 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\windows\system32\lsass.exe
22:23:26.0593 28324 KeyIso - ok
22:23:26.0623 28324 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
22:23:26.0623 28324 KSecDD - ok
22:23:26.0643 28324 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
22:23:26.0643 28324 KSecPkg - ok
22:23:26.0673 28324 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\windows\system32\drivers\ksthunk.sys
22:23:26.0673 28324 ksthunk - ok
22:23:26.0703 28324 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\windows\system32\msdtckrm.dll
22:23:26.0703 28324 KtmRm - ok
22:23:26.0733 28324 [ 3CE6A9BEF066BF9488E6BC4D6C62F77E ] L1C C:\windows\system32\DRIVERS\L1C62x64.sys
22:23:26.0733 28324 L1C - ok
22:23:26.0773 28324 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\windows\System32\srvsvc.dll
22:23:26.0773 28324 LanmanServer - ok
22:23:26.0783 28324 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\windows\System32\wkssvc.dll
22:23:26.0783 28324 LanmanWorkstation - ok
22:23:26.0813 28324 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
22:23:26.0823 28324 lltdio - ok
22:23:26.0863 28324 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\windows\System32\lltdsvc.dll
22:23:26.0863 28324 lltdsvc - ok
22:23:26.0883 28324 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\windows\System32\lmhsvc.dll
22:23:26.0893 28324 lmhosts - ok
22:23:26.0933 28324 [ AB41542FA180CB3317F597ED7E7D5C5D ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:23:26.0933 28324 LMS - ok
22:23:26.0973 28324 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
22:23:26.0973 28324 LSI_FC - ok
22:23:26.0993 28324 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
22:23:26.0993 28324 LSI_SAS - ok
22:23:27.0003 28324 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
22:23:27.0013 28324 LSI_SAS2 - ok
22:23:27.0013 28324 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
22:23:27.0023 28324 LSI_SCSI - ok
22:23:27.0053 28324 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\windows\system32\drivers\luafv.sys
22:23:27.0063 28324 luafv - ok
22:23:27.0113 28324 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\windows\system32\drivers\mbam.sys
22:23:27.0113 28324 MBAMProtector - ok
22:23:27.0193 28324 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
22:23:27.0193 28324 MBAMScheduler - ok
22:23:27.0223 28324 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
22:23:27.0233 28324 MBAMService - ok
22:23:27.0273 28324 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
22:23:27.0273 28324 Mcx2Svc - ok
22:23:27.0293 28324 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\windows\system32\drivers\megasas.sys
22:23:27.0293 28324 megasas - ok
22:23:27.0343 28324 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
22:23:27.0353 28324 MegaSR - ok
22:23:27.0383 28324 [ 6B01B7414A105B9E51652089A03027CF ] MEIx64 C:\windows\system32\DRIVERS\HECIx64.sys
22:23:27.0383 28324 MEIx64 - ok
22:23:27.0423 28324 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\windows\system32\mmcss.dll
22:23:27.0423 28324 MMCSS - ok
22:23:27.0453 28324 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\windows\system32\drivers\modem.sys
22:23:27.0463 28324 Modem - ok
22:23:27.0483 28324 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\windows\system32\DRIVERS\monitor.sys
22:23:27.0483 28324 monitor - ok
22:23:27.0513 28324 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
22:23:27.0513 28324 mouclass - ok
22:23:27.0543 28324 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
22:23:27.0543 28324 mouhid - ok
22:23:27.0563 28324 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\windows\system32\drivers\mountmgr.sys
22:23:27.0563 28324 mountmgr - ok
22:23:27.0603 28324 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:23:27.0603 28324 MozillaMaintenance - ok
22:23:27.0623 28324 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\windows\system32\drivers\mpio.sys
22:23:27.0623 28324 mpio - ok
22:23:27.0643 28324 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
22:23:27.0643 28324 mpsdrv - ok
22:23:27.0673 28324 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\windows\system32\mpssvc.dll
22:23:27.0693 28324 MpsSvc - ok
22:23:27.0713 28324 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
22:23:27.0713 28324 MRxDAV - ok
22:23:27.0723 28324 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
22:23:27.0723 28324 mrxsmb - ok
22:23:27.0763 28324 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
22:23:27.0763 28324 mrxsmb10 - ok
22:23:27.0773 28324 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
22:23:27.0773 28324 mrxsmb20 - ok
22:23:27.0783 28324 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\windows\system32\DRIVERS\msahci.sys
22:23:27.0783 28324 msahci - ok
22:23:27.0803 28324 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\windows\system32\drivers\msdsm.sys
22:23:27.0803 28324 msdsm - ok
22:23:27.0823 28324 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\windows\System32\msdtc.exe
22:23:27.0823 28324 MSDTC - ok
22:23:27.0833 28324 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\windows\system32\drivers\Msfs.sys
22:23:27.0833 28324 Msfs - ok
22:23:27.0853 28324 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
22:23:27.0853 28324 mshidkmdf - ok
22:23:27.0863 28324 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\windows\system32\drivers\msisadrv.sys
22:23:27.0863 28324 msisadrv - ok
22:23:27.0913 28324 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\windows\system32\iscsiexe.dll
22:23:27.0913 28324 MSiSCSI - ok
22:23:27.0913 28324 msiserver - ok
22:23:27.0963 28324 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
22:23:27.0963 28324 MSKSSRV - ok
22:23:27.0973 28324 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
22:23:27.0973 28324 MSPCLOCK - ok
22:23:27.0993 28324 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
22:23:27.0993 28324 MSPQM - ok
22:23:28.0023 28324 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\windows\system32\drivers\MsRPC.sys
22:23:28.0023 28324 MsRPC - ok
22:23:28.0043 28324 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\windows\system32\DRIVERS\mssmbios.sys
22:23:28.0043 28324 mssmbios - ok
22:23:28.0086 28324 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
22:23:28.0109 28324 MSTEE - ok
22:23:28.0119 28324 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\windows\system32\drivers\MTConfig.sys
22:23:28.0120 28324 MTConfig - ok
22:23:28.0135 28324 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\windows\system32\Drivers\mup.sys
22:23:28.0136 28324 Mup - ok
22:23:28.0160 28324 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\windows\system32\qagentRT.dll
22:23:28.0165 28324 napagent - ok
22:23:28.0205 28324 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
22:23:28.0209 28324 NativeWifiP - ok
22:23:28.0261 28324 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\windows\system32\drivers\ndis.sys
22:23:28.0284 28324 NDIS - ok
22:23:28.0317 28324 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
22:23:28.0318 28324 NdisCap - ok
22:23:28.0332 28324 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
22:23:28.0333 28324 NdisTapi - ok
22:23:28.0354 28324 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
22:23:28.0354 28324 Ndisuio - ok
22:23:28.0364 28324 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
22:23:28.0364 28324 NdisWan - ok
22:23:28.0384 28324 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
22:23:28.0384 28324 NDProxy - ok
22:23:28.0435 28324 [ 6F4607E2333FE21E9E3FF8133A88B35B ] Netaapl C:\windows\system32\DRIVERS\netaapl64.sys
22:23:28.0436 28324 Netaapl - ok
22:23:28.0460 28324 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
22:23:28.0462 28324 NetBIOS - ok
22:23:28.0481 28324 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
22:23:28.0483 28324 NetBT - ok
22:23:28.0499 28324 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\windows\system32\lsass.exe
22:23:28.0500 28324 Netlogon - ok
22:23:28.0533 28324 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\windows\System32\netman.dll
22:23:28.0538 28324 Netman - ok
22:23:28.0553 28324 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\windows\System32\netprofm.dll
22:23:28.0558 28324 netprofm - ok
22:23:28.0576 28324 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
22:23:28.0578 28324 NetTcpPortSharing - ok
22:23:28.0607 28324 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
22:23:28.0609 28324 nfrd960 - ok
22:23:28.0639 28324 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\windows\System32\nlasvc.dll
22:23:28.0643 28324 NlaSvc - ok
22:23:28.0680 28324 Norton PC Checkup Application Launcher - ok
22:23:28.0707 28324 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\windows\system32\drivers\Npfs.sys
22:23:28.0708 28324 Npfs - ok
22:23:28.0729 28324 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\windows\system32\nsisvc.dll
22:23:28.0731 28324 nsi - ok
22:23:28.0745 28324 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
22:23:28.0746 28324 nsiproxy - ok
22:23:28.0799 28324 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
22:23:28.0822 28324 Ntfs - ok
22:23:28.0852 28324 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\windows\system32\drivers\Null.sys
22:23:28.0852 28324 Null - ok
22:23:28.0861 28324 [ E00CC5F0D26316190FA4BA19B393E37C ] nuvotonhidcir C:\windows\system32\DRIVERS\nuvotonhidcir.sys
22:23:28.0862 28324 nuvotonhidcir - ok
22:23:29.0289 28324 [ 12E18E5F438AAD55DAF77E127C0EA25B ] nvlddmkm C:\windows\system32\DRIVERS\nvlddmkm.sys
22:23:29.0509 28324 nvlddmkm - ok
22:23:29.0529 28324 [ 186290C63FEB79C199A620E36705F9EE ] nvpciflt C:\windows\system32\DRIVERS\nvpciflt.sys
22:23:29.0529 28324 nvpciflt - ok
22:23:29.0559 28324 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\windows\system32\drivers\nvraid.sys
22:23:29.0569 28324 nvraid - ok
22:23:29.0589 28324 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\windows\system32\drivers\nvstor.sys
22:23:29.0589 28324 nvstor - ok
22:23:29.0629 28324 [ 33A2052D60D4EA6599CEE1D6853D0A42 ] nvsvc C:\windows\system32\nvvsvc.exe
22:23:29.0649 28324 nvsvc - ok
22:23:29.0725 28324 [ FD6F5B42DB429FD1AE1A4483DB4DD2E0 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
22:23:29.0760 28324 nvUpdatusService - ok
22:23:29.0775 28324 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\windows\system32\drivers\nv_agp.sys
22:23:29.0777 28324 nv_agp - ok
22:23:29.0808 28324 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
22:23:29.0810 28324 ohci1394 - ok
22:23:29.0852 28324 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:23:29.0854 28324 ose - ok
22:23:30.0028 28324 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
22:23:30.0108 28324 osppsvc - ok
22:23:30.0148 28324 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\windows\system32\pnrpsvc.dll
22:23:30.0158 28324 p2pimsvc - ok
22:23:30.0168 28324 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\windows\system32\p2psvc.dll
22:23:30.0178 28324 p2psvc - ok
22:23:30.0268 28324 [ F9AAE0A3C086DB9E83F38BDA4C7C61E2 ] PACSPTISVR-Sound_Organizer C:\Program Files (x86)\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe
22:23:30.0268 28324 PACSPTISVR-Sound_Organizer - ok
22:23:30.0298 28324 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\windows\system32\drivers\parport.sys
22:23:30.0308 28324 Parport - ok
22:23:30.0338 28324 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\windows\system32\drivers\partmgr.sys
22:23:30.0338 28324 partmgr - ok
22:23:30.0358 28324 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\windows\System32\pcasvc.dll
22:23:30.0358 28324 PcaSvc - ok
22:23:30.0388 28324 [ 2F86BE1818C2D7AC90478E3323EE7FCB ] PCCUJobMgr C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.77\ccSvcHst.exe
22:23:30.0388 28324 PCCUJobMgr - ok
22:23:30.0418 28324 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\windows\system32\drivers\pci.sys
22:23:30.0418 28324 pci - ok
22:23:30.0428 28324 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\windows\system32\DRIVERS\pciide.sys
22:23:30.0428 28324 pciide - ok
22:23:30.0438 28324 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\windows\system32\drivers\pcmcia.sys
22:23:30.0438 28324 pcmcia - ok
22:23:30.0458 28324 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\windows\system32\drivers\pcw.sys
22:23:30.0458 28324 pcw - ok
22:23:30.0478 28324 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\windows\system32\drivers\peauth.sys
22:23:30.0498 28324 PEAUTH - ok
22:23:30.0558 28324 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\windows\SysWow64\perfhost.exe
22:23:30.0558 28324 PerfHost - ok
22:23:30.0588 28324 [ 91111CEBBDE8015E822C46120ED9537C ] PGEffect C:\windows\system32\DRIVERS\pgeffect.sys
22:23:30.0608 28324 PGEffect - ok
22:23:30.0639 28324 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\windows\system32\pla.dll
22:23:30.0659 28324 pla - ok
22:23:30.0699 28324 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\windows\system32\umpnpmgr.dll
22:23:30.0709 28324 PlugPlay - ok
22:23:30.0719 28324 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
22:23:30.0719 28324 PNRPAutoReg - ok
22:23:30.0729 28324 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\windows\system32\pnrpsvc.dll
22:23:30.0729 28324 PNRPsvc - ok
22:23:30.0759 28324 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
22:23:30.0759 28324 PolicyAgent - ok
22:23:30.0789 28324 [ A2CCA4FB273E6050F17A0A416CFF2FCD ] Power C:\windows\system32\umpo.dll
22:23:30.0789 28324 Power - ok
22:23:30.0819 28324 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
22:23:30.0819 28324 PptpMiniport - ok
22:23:30.0839 28324 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\windows\system32\drivers\processr.sys
22:23:30.0839 28324 Processor - ok
22:23:30.0889 28324 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\windows\system32\profsvc.dll
22:23:30.0889 28324 ProfSvc - ok
22:23:30.0909 28324 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\windows\system32\lsass.exe
22:23:30.0909 28324 ProtectedStorage - ok
22:23:30.0929 28324 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\windows\system32\DRIVERS\pacer.sys
22:23:30.0929 28324 Psched - ok
22:23:30.0969 28324 [ F036CFB275D0C55F4E45FBBF5F98B3C8 ] PSI_SVC_2 c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
22:23:30.0979 28324 PSI_SVC_2 - ok
22:23:31.0039 28324 [ 07D57B890DD5693A6AB660CBAE8F91B4 ] PxHlpa64 C:\windows\system32\Drivers\PxHlpa64.sys
22:23:31.0039 28324 PxHlpa64 - ok
22:23:31.0069 28324 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\windows\system32\drivers\ql2300.sys
22:23:31.0089 28324 ql2300 - ok
22:23:31.0109 28324 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\windows\system32\drivers\ql40xx.sys
22:23:31.0109 28324 ql40xx - ok
22:23:31.0129 28324 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\windows\system32\qwave.dll
22:23:31.0139 28324 QWAVE - ok
22:23:31.0149 28324 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
22:23:31.0149 28324 QWAVEdrv - ok
22:23:31.0159 28324 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
22:23:31.0159 28324 RasAcd - ok
22:23:31.0199 28324 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
22:23:31.0199 28324 RasAgileVpn - ok
22:23:31.0209 28324 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\windows\System32\rasauto.dll
22:23:31.0209 28324 RasAuto - ok
22:23:31.0229 28324 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
22:23:31.0229 28324 Rasl2tp - ok
22:23:31.0249 28324 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\windows\System32\rasmans.dll
22:23:31.0249 28324 RasMan - ok
22:23:31.0259 28324 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
22:23:31.0259 28324 RasPppoe - ok
22:23:31.0279 28324 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
22:23:31.0279 28324 RasSstp - ok
22:23:31.0299 28324 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
22:23:31.0309 28324 rdbss - ok
22:23:31.0319 28324 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\windows\system32\drivers\rdpbus.sys
22:23:31.0319 28324 rdpbus - ok
22:23:31.0329 28324 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
22:23:31.0329 28324 RDPCDD - ok
22:23:31.0359 28324 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
22:23:31.0359 28324 RDPENCDD - ok
22:23:31.0369 28324 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
22:23:31.0369 28324 RDPREFMP - ok
22:23:31.0409 28324 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\windows\system32\drivers\RDPWD.sys
22:23:31.0429 28324 RDPWD - ok
22:23:31.0469 28324 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
22:23:31.0469 28324 rdyboost - ok
22:23:31.0499 28324 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\windows\System32\mprdim.dll
22:23:31.0499 28324 RemoteAccess - ok
22:23:31.0509 28324 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\windows\system32\regsvc.dll
22:23:31.0519 28324 RemoteRegistry - ok
22:23:31.0529 28324 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
22:23:31.0539 28324 RpcEptMapper - ok
22:23:31.0549 28324 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\windows\system32\locator.exe
22:23:31.0559 28324 RpcLocator - ok
22:23:31.0569 28324 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\windows\system32\rpcss.dll
22:23:31.0569 28324 RpcSs - ok
22:23:31.0609 28324 [ 40447D89F56780C49AC2EC22A05D5727 ] RSP2STOR C:\windows\system32\DRIVERS\RtsP2Stor.sys
22:23:31.0609 28324 RSP2STOR - ok
22:23:31.0639 28324 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
22:23:31.0639 28324 rspndr - ok
22:23:31.0679 28324 [ B708BBAB80C60EE613DEE52A1A0A8538 ] RtkBtFilter C:\windows\system32\DRIVERS\RtkBtfilter.sys
22:23:31.0679 28324 RtkBtFilter - ok
22:23:31.0739 28324 [ 8328468053CEDFD7198BEE178C501989 ] RTL8192Ce C:\windows\system32\DRIVERS\rtwlane.sys
22:23:31.0779 28324 RTL8192Ce - ok
22:23:31.0799 28324 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\windows\system32\lsass.exe
22:23:31.0799 28324 SamSs - ok
22:23:31.0829 28324 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\windows\system32\drivers\sbp2port.sys
22:23:31.0829 28324 sbp2port - ok
22:23:31.0879 28324 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\windows\System32\SCardSvr.dll
22:23:31.0879 28324 SCardSvr - ok
22:23:31.0889 28324 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
22:23:31.0889 28324 scfilter - ok
22:23:31.0909 28324 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\windows\system32\schedsvc.dll
22:23:31.0929 28324 Schedule - ok
22:23:31.0949 28324 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\windows\System32\certprop.dll
22:23:31.0949 28324 SCPolicySvc - ok
22:23:31.0969 28324 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\windows\System32\SDRSVC.dll
22:23:31.0969 28324 SDRSVC - ok
22:23:31.0999 28324 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\windows\system32\drivers\secdrv.sys
22:23:31.0999 28324 secdrv - ok
22:23:32.0009 28324 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\windows\system32\seclogon.dll
22:23:32.0009 28324 seclogon - ok
22:23:32.0019 28324 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\windows\system32\sens.dll
22:23:32.0019 28324 SENS - ok
22:23:32.0049 28324 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\windows\system32\sensrsvc.dll
22:23:32.0049 28324 SensrSvc - ok
22:23:32.0079 28324 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\windows\system32\drivers\serenum.sys
22:23:32.0079 28324 Serenum - ok
22:23:32.0109 28324 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] SERIAL C:\windows\system32\drivers\serial.sys
22:23:32.0109 28324 Serial - ok
22:23:32.0129 28324 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\windows\system32\drivers\sermouse.sys
22:23:32.0129 28324 sermouse - ok
22:23:32.0169 28324 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\windows\system32\sessenv.dll
22:23:32.0169 28324 SessionEnv - ok
22:23:32.0179 28324 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\windows\system32\drivers\sffdisk.sys
22:23:32.0179 28324 sffdisk - ok
22:23:32.0209 28324 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
22:23:32.0209 28324 sffp_mmc - ok
22:23:32.0229 28324 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
22:23:32.0249 28324 sffp_sd - ok
22:23:32.0259 28324 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
22:23:32.0259 28324 sfloppy - ok
22:23:32.0389 28324 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\windows\system32\DRIVERS\Sftfslh.sys
22:23:32.0409 28324 Sftfs - ok
22:23:32.0469 28324 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
22:23:32.0479 28324 sftlist - ok
22:23:32.0499 28324 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\windows\system32\DRIVERS\Sftplaylh.sys
22:23:32.0499 28324 Sftplay - ok
22:23:32.0529 28324 [ 617E29A0B0A2807466560Have you configured FireFox to not allow pop-ups?Yes. I've also placed yieldmanager and ads.yieldmanager on my block list, but to no availAre you getting pop-ups with Internet Explorer? If the answer is no then I would suggest your uninstall and re-install FireFox.IE... kind of doesn't work, which is scary. It just doesn't load any new pages.

In-text ads now appearing on http://www.smh.com.au/ articles and some of my university websites, which I'm pretty sure didn't happen before.Those in-text ads are probably caused by add-ons. Disable all your add-ons to see if they disappear.
MS Fix-It should repair IE.

Please download and run MS Fix-it from here. I ran MS-Fix-it, and IE still appears to not work/doesn't load anything.

#^#$^ I now have a Superfish popup too I haven't downloaded anything new in the past few weeks, I swear! I have no idea where this is coming from.

* Googled how to remove Addons - there was something called "videosaver" there. Disabled this. Touch wood, so far so good on Firefox (IE still not working)... no popup adds so far and a lot of the mysterious in-text advertising has gone away (I checked some of the usual "as of recently, always some here" haunts like Wikipedia and my university web page just to be sure)When you say IE will not work, what exactly does it do? Did you try running it as Admin?
2331.

Solve : using ubuntu to remove malware?

Answer»

Whenever I suspect that my flash drive has been infected what I GENERALLY do is, boot my system in Ubuntu, plug the flash drive, look out for suspicious files and delete them. This route has been fail safe for me. If there is a .exe file I open them using gedit and if I feel that it looks weird I delete it right away.
However, a friend recently reported that he encountered a problem in this method. His drive was infected. All the folders present in the drive disappeared and was replaced with a single file that cannot be opened. He tried opening it in Unix but couldn't. (!!) The same situation persisted. A single file that an't be opened. He's not sure of the file type. But can this really happen? I believe .exe , .inf , .bat files are incapable of RUNNING on ubuntu. Clarification required.

OS Info : Windows7/ubuntu 12.04 DUAL bootHe approached a data recovery center. They were unable to recover the data either. Only images were retrieved. (the drive contained docs and ppts.. the images were actually a part of the docs) They have formatted the drive and have written the recovered data on top of it. My question : is it possible to retrieve the original docs and ppts now?Here is a link where you download some safe recovery tools.Thank you superdave. But your post doesn't answer my question. Stellar Phoenix, recuva and various other softwares were tried to recover the data but to no avail.

My questions :
1. can you NAME some companies/organisations who can restore the data professionally? (I'm looking for ones like Kroll Ontrack)
2. The infected pendrive has been formatted and filled with the PARTIALLY recovered data (only images). Is it still possible to try and recover the original data(docs and ppts)?
3. What could be the possible reasons for the partial recovery?
4. Are there malware that can work on both Windows AND Ubuntu?

PS sorry for my late reply. Was caught up in several stuff. Quote

can you name some companies/organisations who can restore the data professionally? (I'm looking for ones like Kroll Ontrack)
Sorry, no.
Quote
The infected pendrive has been formatted and filled with the PARTIALLY recovered data (only images). Is it still possible to try and recover the original data(docs and ppts)?
If it has been reformatted they're probably gone.
Quote
What could be the possible reasons for the partial recovery?
I can't say since I wasn't there.
Quote
Are there malware that can work on both Windows AND Ubuntu?
Hackers don't usually create malware for OS's like Ubuntu or Apple because they are not that popular.Thank you for previous post. I still require some clarifications.

1. you can't name them because there aren't any or is it because of the forum restrictions? (Trust me I have googled for such centers but having a TOUGH time finding any reliable sources)
2. I've heard of 'data restoration' wherein people try to recover data from burnt/damaged hard disks. And that, eventhough a disk has been reformatted, it is still possible to recover the data. Is it applicable only to hard disks and not flash drives?

Additional Question : Is my method of using ubuntu to delete suspicious looking files from my affected flash drive, potentially dangerous?Quote
2. I've heard of 'data restoration' wherein people try to recover data from burnt/damaged hard disks. And that, eventhough a disk has been reformatted, it is still possible to recover the data. Is it applicable only to hard disks and not flash drives?
Yes, it's possible. Please read this.
Quote
Is my method of using ubuntu to delete suspicious looking files from my affected flash drive, potentially dangerous?
It's not a very good method of cleaning a computer since you don't know the function of the files you are deleting.
2332.

Solve : What Avast site is real??

Answer» Avast has given good free protection. But I had to install WINDOWS 7 again on this laptop.So I went to Google to find the Avast write. I was not sure which was the RIGHT one. I wanted the free version of 2013, the the 2014 paid version.
Well, I made the wrong choice. I stopped the installation, but too late.

I loaded Malearebytes from a Flash CARD. Ran it. Got 71 puppies. Found a COPY of Avast on by desktop, put it on the laptop. Now I am OK. Close call.

So my quotation is, Why does Google let the criminals do that? The crooks were allowed to advertise with the good name of Avast to LOAD up a bunch of trash.

Is this sort of deception g ever going to stop?


Google is just a search engine. You should use WOT to keep you safe from dangerous sites.
WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.
2333.

Solve : msngames says your browser or operating system does not meet min rquirements?

Answer»

here ya go. thanks.

ComboFix 13-12-08.01 - papa 12/08/2013 21:58:35.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.12270.9971 [GMT -8:00]
Running from: c:\users\papa\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
FW: McAfee Firewall *Disabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\PCDr\6361\AddOnDownloaded\02d6010d-b288-4157-bbcc-a3d510d3fba5.dll
c:\programdata\PCDr\6361\AddOnDownloaded\143c46ba-b979-4e38-9815-2373de9333aa.dll
c:\programdata\PCDr\6361\AddOnDownloaded\409161a3-28c9-4482-9613-e7ca2e306fef.dll
c:\programdata\PCDr\6361\AddOnDownloaded\4c09e0ec-d531-4d04-a038-3dd30a795474.dll
c:\programdata\PCDr\6361\AddOnDownloaded\61c13bfc-28f4-44bc-beec-efa429fa40f0.dll
c:\programdata\PCDr\6361\AddOnDownloaded\6edf11af-92e6-490d-af58-febeeb0cdb04.dll
c:\programdata\PCDr\6361\AddOnDownloaded\9e7391aa-d9c2-4547-bdb7-737a833083a2.dll
c:\programdata\PCDr\6361\AddOnDownloaded\9ed1246c-39a1-403b-9134-f313ebd75cb8.dll
c:\programdata\PCDr\6361\AddOnDownloaded\b347630c-35c1-4199-a3e2-2eea8f11e228.dll
c:\programdata\PCDr\6361\AddOnDownloaded\c6ca3141-c4ef-404d-b1c2-840d38395e80.dll
c:\programdata\PCDr\6361\AddOnDownloaded\f586fa98-17b8-498c-9c59-24de5750efab.dll
c:\programdata\PCDr\6361\AddOnDownloaded\f63e05a5-1f40-4c42-b80a-d0995b6e38a7.dll
c:\programdata\SPLCEB.tmp
c:\programdata\SPLDBFC.tmp
c:\programdata\SPLEC41.tmp
c:\programdata\SPLF476.tmp
c:\programdata\SPLF695.tmp
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2013-11-09 to 2013-12-09 )))))))))))))))))))))))))))))))
.
.
2013-12-09 06:03 . 2013-12-09 06:03--------d-----w-c:\users\Default\AppData\Local\temp
2013-12-06 03:13 . 2013-12-06 03:15--------d-----w-c:\users\papa\AppData\Local\ElevatedDiagnostics
2013-12-04 07:55 . 2013-12-04 07:55--------d-----w-c:\program files (x86)\ESET
2013-12-03 20:17 . 2013-12-03 20:3091352----a-w-c:\windows\system32\drivers\mbamchameleon.sys
2013-12-03 01:59 . 2013-12-03 01:59--------d-----w-c:\windows\ERUNT
2013-12-03 01:48 . 2013-12-07 01:37--------d-----w-C:\AdwCleaner
2013-12-02 20:52 . 2013-12-02 20:52--------d-----w-c:\users\papa\AppData\Roaming\Malwarebytes
2013-12-02 20:51 . 2013-12-02 20:51--------d-----w-c:\programdata\Malwarebytes
2013-12-02 20:51 . 2013-12-02 20:51--------d-----w-c:\program files (x86)\Malwarebytes' Anti-Malware
2013-12-02 20:51 . 2013-04-04 22:5025928----a-w-c:\windows\system32\drivers\mbam.sys
2013-12-02 20:51 . 2013-12-02 20:51--------d-----w-c:\users\papa\AppData\Local\Programs
2013-12-02 15:13 . 2013-12-02 15:13--------d-----w-c:\program files\CCleaner
2013-11-27 21:23 . 2013-11-27 21:23--------d-----w-c:\program files (x86)\Oberon Media SIDR
2013-11-27 21:22 . 2013-11-27 21:23--------d-----w-c:\program files (x86)\msn_en
2013-11-26 11:03 . 2013-10-15 02:0028368----a-w-c:\windows\system32\IEUDINIT.EXE
2013-11-14 11:01 . 2013-11-14 11:03--------d-----w-C:\a052c3cea54cb0cea1
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-26 18:16 . 2012-04-22 14:37692616----a-w-c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 18:16 . 2011-12-02 18:0471048----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-11-14 11:01 . 2012-01-25 22:1082896128----a-w-c:\windows\system32\MRT.exe
2013-11-05 00:51 . 2011-03-13 17:2070112----a-w-c:\windows\system32\drivers\cfwids.sys
2013-11-05 00:46 . 2011-03-13 17:20343696----a-w-c:\windows\system32\drivers\mfewfpk.sys
2013-11-05 00:46 . 2011-12-02 18:33182752----a-w-c:\windows\system32\mfevtps.exe
2013-11-05 00:43 . 2011-03-13 17:20782360----a-w-c:\windows\system32\drivers\mfehidk.sys
2013-11-05 00:41 . 2011-03-13 17:20519576----a-w-c:\windows\system32\drivers\mfefirek.sys
2013-11-05 00:40 . 2011-03-13 17:20311120----a-w-c:\windows\system32\drivers\mfeavfk.sys
2013-11-05 00:39 . 2011-03-13 17:20179792----a-w-c:\windows\system32\drivers\mfeapfk.sys
2013-10-08 14:50 . 2013-10-20 17:3296168----a-w-c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-09-30 23:50 . 2013-09-30 23:501121538----a-w-c:\programdata\SPLAA09.tmp
2013-09-27 22:48 . 2011-12-02 18:22499712----a-w-c:\windows\SysWow64\msvcp71.dll
2013-09-23 20:49 . 2013-10-16 22:26197704----a-w-c:\windows\system32\drivers\HipShieldK.sys
2013-09-20 16:38 . 2013-09-20 16:3810856----a-w-c:\windows\system32\drivers\mfeclnrk.sys
2013-09-20 16:38 . 2013-09-20 16:3895984----a-w-c:\windows\system32\drivers\mfencrk.sys
2013-09-20 16:37 . 2013-09-20 16:37390552----a-w-c:\windows\system32\drivers\mfencbdc.sys
2013-01-17 03:27 . 2013-01-17 03:27464----a-w-c:\program files (x86)\0116201319273618.bat
2012-11-18 19:15 . 2012-11-18 19:15465----a-w-c:\program files (x86)\1118201211152934.bat
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{5e7c3693-318c-4f0f-9ff2-db485880944c}]
2013-11-08 15:53115840----a-w-c:\program files (x86)\msn_en\encyclopediabritannicagamesbarX.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{5e7c3693-318c-4f0f-9ff2-db485880944c}"= "c:\program files (x86)\msn_en\encyclopediabritannicagamesbarX.dll" [2013-11-08 115840]
.
[HKEY_CLASSES_ROOT\clsid\{5e7c3693-318c-4f0f-9ff2-db485880944c}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 283160]
"ShwiconXP9106"="c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe" [2010-03-10 237568]
"THX Audio Control Panel"="c:\program files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe" [2009-12-01 963584]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"RemoteControl9"="c:\program files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [2010-10-01 87336]
"PDVD9LanguageShortcut"="c:\program files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [2010-09-18 50472]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared Files\brs.exe" [2011-08-12 75048]
"Dell DataSafe Online"="c:\program files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe" [2010-08-26 1117528]
"RoxWatchTray"="c:\program files (x86)\Common Files\ROXIO Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-11-25 240112]
"Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-11-17 514544]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-09-24 537512]
"NeroLauncher"="c:\program files (x86)\Nero\SyncUP\NeroLauncher.exe" [2012-08-21 67496]
"Dell V715w"="c:\program files (x86)\Dell V715w\fm3032.exe" [2011-01-24 316072]
"AccuWeatherWidget"="c:\program files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" [2012-02-01 968048]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\Update\realsched.exe" [2013-09-27 295512]
"mcpltui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2013-09-24 537512]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-09-05 958576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""
.
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.exe;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\BBSvc.exe


R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/12/02 12:23;c:\program files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe;c:\program files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe

R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe

R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe

R2 X5XSEx_Pr143;X5XSEx_Pr143;c:\program files (x86)\Free Ride Games\X5XSEx_Pr143.Sys;c:\program files (x86)\Free Ride Games\X5XSEx_Pr143.Sys

R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys;c:\windows\SYSNATIVE\drivers\HipShieldK.sys

R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe

R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys;c:\windows\SYSNATIVE\drivers\Impcd.sys

R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe;c:\progra~1\mcafee\msc\mcawfwk.exe

R3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\DRIVERS\mfencrk.sys;c:\windows\SYSNATIVE\DRIVERS\mfencrk.sys

R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe

R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys

R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe

R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe

S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys

S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe

S2 dlee_device;dlee_device;c:\windows\system32\dleecoms.exe;c:\windows\SYSNATIVE\dleecoms.exe

S2 dleeCATSCustConnectService;dleeCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\dleeserv.exe;c:\windows\SYSNATIVE\spool\DRIVERS\x64\3\\dleeserv.exe

S2 HomeNetSvc;McAfee Home Network;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe

S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe

S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe

S2 McAPExe;McAfee AP Service;c:\program files\McAfee\MSC\McAPExe.exe;c:\program files\McAfee\MSC\McAPExe.exe

S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe

S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe

S2 mcpltsvc;McAfee Platform Services;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe

S2 mfecore;McAfee Anti-Malware Core;c:\program files\Common Files\McAfee\AMCore\mcshield.exe;c:\program files\Common Files\McAfee\AMCore\mcshield.exe

S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe

S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe

S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe

S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE

S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys

S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe

S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys

S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys

S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys

S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys

S3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\DRIVERS\mfencbdc.sys;c:\windows\SYSNATIVE\DRIVERS\mfencbdc.sys

S3 PCDSRVC{D3412D80-CF3B4A27-06020200}_0;PCDSRVC{D3412D80-CF3B4A27-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\my dell\pcdsrvc_x64.pkms;c:\program files\my dell\pcdsrvc_x64.pkms

.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - CLKMDRV10_9EC60124
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-09 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-22 18:16]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e7c3693-318c-4f0f-9ff2-db485880944c}]
2013-11-08 15:53131712----a-w-c:\program files (x86)\msn_en\encyclopediabritannicagamesbarX64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{5e7c3693-318c-4f0f-9ff2-db485880944c}"= "c:\program files (x86)\msn_en\encyclopediabritannicagamesbarX64.dll" [2013-11-08 131712]
.
[HKEY_CLASSES_ROOT\CLSID\{5e7c3693-318c-4f0f-9ff2-db485880944c}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-23 10920552]
"RunDLLEntry_THXCfg"="c:\windows\system32\THXCfg64.dll" [2009-10-15 17920]
"RunDLLEntry_EptMon"="c:\windows\system32\EptMon64.dll" [2009-10-15 21504]
"dleemon.exe"="c:\program files (x86)\Dell V715w\dleemon.exe" [2011-01-24 770728]
"EzPrint"="c:\program files (x86)\Dell V715w\ezprint.exe" [2011-01-24 139944]
"DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2012-02-01 2195824]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{238d4b4c-d63c-42a7-b6d8-dc96c8c0f5b9} - (no file)
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-Exetender - c:\program files (x86)\Free Ride Games\GPlayer.exe
Wow6432Node-HKLM-Run-Adobe Reader Speed Launcher - c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe
Wow6432Node-HKU-Default-Run-Exetender - c:\program files (x86)\Free Ride Games\GPlayer.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
WebBrowser-{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9} - (no file)
AddRemove-toolbar2 - c:\program files (x86)\toolbar2\uninstall.exe
AddRemove-WildTangent CDA - c:\program files (x86)\WildTangent\Apps\CDA\CDAUninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{D3412D80-CF3B4A27-06020200}_0]
"ImagePath"="\??\c:\program files\my dell\pcdsrvc_x64.pkms"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\ELEVATION]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-12-08 22:05:21
ComboFix-quarantined-files.txt 2013-12-09 06:05
.
Pre-Run: 904,289,697,792 bytes free
Post-Run: 904,133,697,536 bytes free
.
- - End Of File - - E788921858CE60A018A19E5F6E330A64
i am so confused, after the combo fix, mcafee said there was a Trojan (artemis something or other) from comboxfix and needed to restart my system and since I ran combofix I get a window popping up which says you are about to leave a secure internet connection, it will be possible for others to view info you send. I didn't have this before, am I doing something wrong? I am following ur instructions. thanksThis is where you're getting the shwiconxp error. Did you install this program? c:\program files (x86)\Multimedia Card Reader(9106)
Quote
comboxfix and needed to restart my system and since I ran combofix I get a window popping up which says you are about to leave a secure internet connection, it will be possible for others to view info you send. I didn't have this before, am I doing something wrong?
That's a normal warning on some sites.i don't recall installing it, i think it came with the system. but if it's normal then I'm relieved.shwiconxp.exe is malware but in this case it looks legitimate but let's check it just to make sure.

Please go to Jotti's malware scan
(If more than one file needs scanned they must be done separately and links posted for each one)

* Copy the file path in the below Code box:

Code: [Select]c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
* At the upload site, click once inside the window next to Browse.
* Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
* Next click Submit file
* Your file will possibly be entered into a queue which normally takes less than a minute to clear.
* This will perform a scan across multiple different virus scanning engines.
* Important: Wait for all of the scanning engines to complete.
* Once the scan is FINISHED, Copy and then Paste the link in the address bar into your next reply.
http://virusscan.jotti.org/en/scanresult/842dff0e7417a4b7a9ebea4de07eb17c6e198a89/e594cd826611d7726b7de5928635f651061b426a

I hope this is what you were looking for.I thought I was onto something but it turns out that the file is good so we're back to square one. I don't understand why. The only thing I can suggest at this point is to try another browser such as FireFox and see if you still recieve that message.okay, i'll see what happens.well, i downloaded firefox, went to msn games and seems to be working just fine, but my wife will know more than i as she plays it. As for ie, not sure why it doesn't like that particualr site, cuz it seems to be fine for everything else. i may go to microsfot and see if they have any ideas, but for now, my computer is clean, and for that i am grateful. You're a true genius Superdave,go ahead an close this unless there is any cleanup you need me to . if i need something else, i'll come back. thanks for all your helpQuote
i may go to microsfot and see if they have any ideas,
That would be a good idea. Let's do some cleanup and we'll finished.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
**************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
******************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you SAFE from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!thanks superdave for all your help. i'm clean and will continue to pursue the through microsoft (msngames). close it out, and thanks again. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2334.

Solve : adobe flash request on youtube?

Answer»

Does anybody know what is going on if anything with Youtube popping up a screen REQUESTING the user update to the latest version of ADOBE Flash Player? This has happened to me two or three times in the past. As I remember it I have to back up the computer to an earlier DATE. That's what happened just two days ago when the youtube problem occured but now it's back. I can't watch any videos on Youtube with the exception that sometimes the video is there but there's no sound and no volume slider showing. This latest occured right after I tried to install Bit Torrent. That installation failed and then the computer nearly froze up or extreemly slowed and lost the internet connection. I restored it to an earlier date which cured the slowness but then the youtube thing was back. Also I can't download the Flash Player from Adobe. That just hangs up in mid download. I think maybe Malwarebytes or other is blocking it so I'll try again. And clicking on the request to update from the Youtube screen just runs you in circles and you get nowhere. I got it! You need to disable Active X by going, in Explorer 9 anyway to the CONTROL icon in the upper right corner -little gear- hover over safety and in the menu you will see Active X. Uncheck this. I STILL haven't tried to download Flash Player but now I can watch Youtubes.

2335.

Solve : Pop-under prevention.?

Answer»

Hi, I am interested to find out what programs are available to prevent pop-unders appearing when using either Internet Explorer 10 or Firefox v21 with Windows 7. I have had a look at some of the free pop-up ad removers but there is little or no information refering to pop-unders. I don't mind admitting to having the occasional foray into adult websites, but I GET fed up with finding sites like "Live Jasmin" and others sitting on the desktop when I close Firefox, for example. Can anyone give me any advice on this ?
Regards, parkman.Those are not pop-ups; they are sites that open up automatically. I don't know of any program that will stop them. Just make sure your pop-up blocker is enabled in each of your browser.Hi, thanks to Superdave for the response. I don't know a lot about these pop-up or pop-unders, so I assumed that a page that opened behind the current browser page was a pop-under.
As SUGGESTED by Superdave it LOOKS like I will just have to put up with them.
Thanks very much,
regards, parkman•Make your Internet Explorer more secure - This can be done by following these simple instructions:

•From within Internet Explorer click on the Tools menu and then click on Options.

•Click once on the Security tab

•Click once on the Internet ICON so it becomes highlighted.

•Click once on the Custom Level button.

•Change the Download signed ActiveX controls to Prompt

•Change the Download unsigned ActiveX controls to Disable

•Change the INITIALIZE and script ActiveX controls not marked as safe to Disable

•Change the Installation of desktop items to Prompt

•Change the Launching programs and files in an IFRAME to Prompt

•Change the Navigate sub-frames across different domains to Prompt

•When all these settings have been made, click on the OK button

•If it prompts you as to whether or not you want to save the settings, press the Yes button.

•Next press the Apply button and then the OK to exit the Internet Properties page.
Hi, thanks Superdave, for the IE settings, I will put those into Explorer.
Best regards, parkmanQuote from: parkman on June 18, 2013, 03:49:00 AM

Hi, thanks Superdave, for the IE settings, I will put those into Explorer.
Best regards, parkman
Good Luck.
2336.

Solve : Is There a Difference for Virus Protection for a Server and a Home Computer ..??

Answer»
I was looking at our server at school and realized that there is no ANTIVIRUS SOFTWARE. It does GO through a open DNS, but I can't find and anti Spyware or Antivirus.
I'm very "techie" with HOME computers, but not that familiar with Servers. This is a Windows Server 2003.

Any help would be greatly appreciated. According to this there is a need for an AV
2337.

Solve : Malwarebytes not working?

Answer»

Hi -
I have Windows 7 64 bit. When I run Malwarebytes Antimalware (free edition) everything looks OK. It finds 29 items detected and which I have it delete. However if I run it again the same items COMES up. How can the same items come up if they have been removed previously? I have even shut down my computer between runs just in case that made any DIFFERENCE. It does not. All of the repeat items are PUP items.
Any help will be appreciated. Bob We need to know what the items are. MBAM will identify some perfectly safe registry entries and files as malware, delete them, and they will be recreated on the next boot.Allan -
You may mark this post as completed. This morning I contacted Malwarebytes and found out I was not following the correct procedure. After running the SCAN and getting a list a person must CHECK which (are all) of the items that are to be removed. My fault.
Thanks for your time. Bob

2338.

Solve : AVG Nightmare?

Answer»

System info: Desktop: Dell, XPS 630, Running Windows 7; 16GB RAM; Office 365; Photoshop CS6;
Laptop: Dell, Inspiron, 17R – OS: Windows 8; 8GB RAM; Office 365

Hi All – I have an odd issue with AVG that has created a nightmarish issue on my systems. On the ADVICE of several folks here and on other sites, as well as a tech savvy friend, I loaded the trial version of AVG security. As soon as the system rebooted, the system became very unstable. Screen freezes, very slow performance, very slow Internet responses and multiple crashes. Believing that something had occurred during the installation, I decided to uninstall and reinstall the software. This is where the nightmare began. It is impossible to remove this program from either system! I followed the instructions on the AVG site and used Windows uninstall utility and then used the AVG command PROMPT utility to remove the program. As soon as I rebooted, there was AVG again. At this point, I contacted AVG and a tech tried to walk me through another method to remove the program. I downloaded, installed and then used a second command prompt utility that the tech told me to use. During the process of the uninstall, I was disconnected from this tech. (I was informed that this would occur and told to reconnect and let him know if the fix worked.) When the system rebooted, it was immediately apparent that AVG had not uninstalled. I reconnected to AVG tech support; however, this time the tech seemed unfamiliar with my case (I had a case #) and equally unfamiliar with the program. She suggested using the uninstall tools I had already used previously – multiple times – without success. I explained this and the tech became quite rude and, after I asked if she could pull up my case so that we didn't have to repeat the same things again, she terminated our connection.

I am now working with two computers that are held hostage to AVG. Because AVG remains in shell form only, I have no active anti-virus/security program on either computer. I cannot load another program because…of AVG. I’ve tried restoring both systems to previous good points, but this has not helped remove AVG. After two phone calls and numerous e-mails, I have yet to receive help from AVG – other than being told to once again use the utilities that have not worked. (I have tried several more times) I know that many folks here are extremely knowledgeable and I am desperately hoping someone can help me get this blasted thing off my systems. Thank you for any help!
Use this tool to remove AVG.

AVG Antivirus - AVG Antivirus Remover utility

Download and install MicroSoft Security Essentials. Make sure to install the correct one for your computers ie 32 bit or 64 bit.

MicroSoft Security Essentials All versions and all languages.Hi - I apologize for posting my question and then disappearing without ever answering to your response. A family emergency took me away for ten days and I just read the response. The AVG removal tool is what I have already used, several times and for some reason it has not worked. In several of my contacts with AVG they have supplied both the tool you mention and a second command prompt tool. Neither of these tools has worked to remove the entire program. I'm very frustrated not just because nothing has worked, but because the people at AVG have been so useless in helping resolve the issue. I had heard so many great things about the company and, in particular, this software. They are highly rated by many tech sites, but obviously, ratings aren't ALWAYS honest. Now that I'm back to WORK, I'm probably just going to reformat the drive, thus removing everything, including this POS software. Thank you for your efforts.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

2339.

Solve : The message from ESET - I have no clue?

Answer»

Yesterday on my computer I had installed LinuxLive USB Creator (Lili) to make my USB device bootable. Yet before installation of this program when I click on its setup file the message from ESET Smart Security came on on the screen:
Quote

An application running on this computer is attempting to communicate over encrypted SSL channel. If you want to check the encrypted channel content, mark the certificate as trusted.
Do you consider the remote computer's certificate trusted?
I have installed this ANYWAY. And now, every time when I open the program the same message reappears. Even being more careless I put the program to work and made my USB stick Live bootable. It boots up and works with no problem.
Anyway, have I done something stupid by disregarding the message from ESET? ESET is a very trusted AV and you should have investigated the warning more closely.Lately I googled for this one and hadn't found anything. Well, I'm going to uninstall this program and run a deep scan then. Quote from: doer on June 26, 2013, 09:37:11 PM
Lately I googled for this one and hadn't found anything. Well, I'm going to uninstall this program and run a deep scan then.
Good idea. Let me know if you find anything.Found 0 threats.We can run a couple more quick scans just to clean out any junk you may have picked up.

Please download AdwCleaner by Xplode onto your Desktop.
  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
********************************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to INSTALL the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click REMOVE Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
************************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.Quote
# AdwCleaner v2.303 - Logfile created 06/28/2013 at 21:03:12
# Updated 08/06/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Mark - MARK-PC
# Boot Mode : Normal
# Running from : C:\Users\Mark\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\khgb4rwd.default\searchplugins\web-search.xml
Folder Deleted : C:\Program Files (x86)\BringMeSports_1c
Folder Deleted : C:\Program Files (x86)\InfoAtoms
Folder Deleted : C:\Program Files (x86)\Wondershare
Folder Deleted : C:\ProgramData\APN
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\ProgramData\SoftSafe
Folder Deleted : C:\ProgramData\visualbee
Folder Deleted : C:\Users\Mark\AppData\Local\visualbeeexe
Folder Deleted : C:\Users\Mark\AppData\LocalLow\BringMeSports_1c
Folder Deleted : C:\Users\Mark\AppData\LocalLow\visualbee
Folder Deleted : C:\Users\Mark\AppData\Roaming\Babylon

***** [Registry] *****

Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\StartSearch
Key Deleted : HKLM\Software\ExpressFiles
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16611

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://startsear.ch/?aff=1&cf=2390a736-17c4-11e2-869f-90e6bad66c02 --> hxxp://www.google.com

-\\ Mozilla Firefox v18.0.2 (en-US)

File : C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\khgb4rwd.default\prefs.js

Deleted : user_pref("browser.search.defaultengine", "Web Search");
Deleted : user_pref("browser.search.defaultenginename", "Web Search");
Deleted : user_pref("browser.search.order.1", "Web Search");
Deleted : user_pref("browser.search.selectedEngine", "Web Search");
Deleted : user_pref("browser.startup.homepage", "hxxp://startsear.ch/?aff=1&cf=2390a736-17c4-11e2-869f-90e6bad[...]
Deleted : user_pref("keyword.URL", "hxxp://startsear.ch/?aff=1&src=sp&cf=2390a736-17c4-11e2-869f-90e6bad66c02&[...]

*************************

AdwCleaner[S1].txt - [3128 octets] - [28/06/2013 21:03:12]

########## EOF - C:\AdwCleaner[S1].txt - [3188 octets] ##########

Quote
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.06.28.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16618
Mark :: MARK-PC [administrator]

6/28/2013 11:31:55 PM
mbam-log-2013-06-28 (23-31-55).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 348552
Time elapsed: 36 minute(s), 52 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry DATA Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Quote
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Home Premium x64
Ran by Mark on Sat 06/29/2013 at 0:20:17.58
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\strongvault online backup"
Successfully deleted: [Folder] "C:\Users\Mark\AppData\Roaming\goforfiles"
Successfully deleted: [Folder] "C:\Users\Mark\AppData\Roaming\strongvault"
Successfully deleted: [Folder] "C:\Users\Mark\appdata\local\strongvault"
Successfully deleted: [Folder] "C:\Users\Mark\appdata\local\visualbeeclient"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ FireFox

Successfully deleted: [Folder] "C:\Program Files (x86)\Mozilla Firefox\extensions\[emailprotected]"
Emptied folder: C:\Users\Mark\AppData\Roaming\mozilla\firefox\profiles\khgb4rwd.default\minidumps [175 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 06/29/2013 at 0:22:50.23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I see there still was some trash.
Thank you for your help Appreciated. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2340.

Solve : PC lag+Program not responding?

Answer»

dave i think i receive another virus, because when i check task manager, i found some process of weird program, pev.3XE,PEV.3XE, and sev.3XE. is this a virus or not? cause i experience another freeze.Quote

i found some process of weird program, pev.3XE,PEV.3XE, and sev.3XE. is this a virus or not? cause i experience another freeze.
It depends on where it's running. Please run MBAM again and POST the log.okay hey dave and im sorry if im not active for these past days because i was on HOLIDAY and i couldnt use my PC cause i was going away. so i kinda experience a new issue, this time it happens when i turn on my PC. it lags so much and my firefox keeps crashing. so should i do scan with MBAM?Quote
it lags so much and my firefox keeps crashing. so should i do scan with MBAM?
Yes, please run another scan with MBAM and post the log if it finds anything. Also, UNINSTALL and re-install FireFox.

Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program.
Click on View &GT; Select Colunms.
In addition to already pre-selected options, make sure, the Command LINE is selected, and press OK.
Go File>Save As, and save the report as Procexp.txt.
Attach the file to your next reply.
2341.

Solve : File Recovery Virus?

Answer»

The link for BitDefender takes me to what becomes Quickscan which shows no errors. It doesn't produce a report, and there are no tabs on the online display.Quote from: dc4580 on October 09, 2012, 09:16:11 PM

The link for BitDefender takes me to what becomes Quickscan which shows no errors. It doesn't produce a report, and there are no tabs on the online display.
Ok, how's your computer running now? Any other issues?No. Boot-up and processing seem to be going fine. Seems like no after-effects from the two infections. So, just two more items: 1.) Was my inability to do some of these scans due to anything other than changes to websites that might have recently taken place? and 2.) I need to dump McAfee as it couldn't catch a cold much less a virus, so I will need suggestions for software that will handle AV and Firewall. If you would have a recommendation of a suite or mix-and-match, I am all ears.
Quote
Was my inability to do some of these scans due to anything other than changes to websites that might have recently taken place?
It's difficult to say without SITTING down in front of the computer.
Quote
I need to dump McAfee as it couldn't catch a cold much less a virus, so I will need suggestions for software that will handle AV and Firewall. If you would have a recommendation of a suite or mix-and-match, I am all ears.
We'll do some cleanup and I'll also provide that information.

To uninstall ComboFix

  • CLICK the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
************************************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click DISK Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
**************************************************************
Remember to only install one ANTIVIRUS!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
4-a) Microsoft Security Essentials for Windows XP
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
6) PC Tools AntiVirus Free Edition
7) ThreatFire

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.
I'm very pleased with MicroSoft Security Essentials. Very effective and very lightweight.
***************************************************************
Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
**********************************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't KNOW what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Ok Dave. McAfee suite is gone. My choices were Microsoft Security Essentials AV and Online Armor Firewall. I installed WOT and SpywareBlaster, and I will be getting Spybot down in the next few days. Thanks for all your help again. Much appreciated. If you don't have anything else for me to do, please feel free to close this issue.


DC You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2342.

Solve : Problem with Virus and/or spyware : please help?

Answer»

Ok, let's do some cleanup.

To uninstall ComboFix

  • Click the START button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the FIELD, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
******************************************
Click Start> Computer> right click the C DRIVE and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*****************************************
Go to Microsoft WINDOWS Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, IDENTITY theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.Thanks, I don't think we used comboFix?!

I performed disk cleanup as you suggested, thanks.Quote from: MNMAN on November 29, 2013, 02:46:56 PM
Thanks, I don't think we used comboFix?!

I performed disk cleanup as you suggested, thanks.
Yup, there is a CF log in Reply # 2
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2343.

Solve : Cheap AV software or freeware - which is better??

Answer»

I was looking for anti-virus software options and I came across stuff like Panda and AVG on this site:

http://www.outletpc.com/software---os-antivirus-software.html

I BEGAN to wonder, will anti-virus software that costs me as little as $10 WORK ANY better than something else I can GET for free? What do you think? I'm curious what more well-versed people think.I'd say to look for trusted antivirus vendors. Antivirus freeware is definitely not as effective as a paid antivirus program.

Feel free to get a good review on AV software from my company blog: http://secureconnexion.wordpress.com/2012/06/14/antivirus-software-toplist-top-20-summer-2012/

I HOPE this helps. However, this topic is closed, because the discussion can get long, and we have plenty of posts in this forum asking about what antivirus to use, and whether freeware or paid is better.

We appreciate you stopping by, and hope to see you POSTING more.

2344.

Solve : Suspicious Link Info Needed?

Answer»

I don't think I am infected.. but what can ONE tell me about the following link an email wants me to click ---

link deleted by Allan

What does it do? Here is the header info...

------------------------------------------------------------


Your Email Has Been Re-ported SPAM
From: Member Service <[emailprotected]&GT;
To: Recipients <[emailprotected]>
Date: Sun, Oct 14, 2012 12:08 pm

--------------------------------------------

I don't KNOW how to access more of the header info with web based aol email


Here is the text of the message ---

--------------------------------------------------
Your e-mail account was re-ported to us as Abused e-mail. VERIFY NOW

Can any one give me some insight into this link/message?

Thanks!
Do not POST potentially harmful links.

2345.

Solve : Computer can no longer handle full screen videos, multiple tabs, and has popups?

Answer»

Ok. Run AdwCleaner and MBAM again and post the logs.

Please download AdwCleaner by Xplode onto your Desktop.

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
**************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and LAUNCH Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
# AdwCleaner v2.304 - Logfile created 07/10/2013 at 15:26:04
# Updated 03/07/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : ADMINISTRATOR - LENOVO_XP
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\adwcleaner_2.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Program Files\Mozilla Firefox\.autoreg

***** [Registry] *****

Key Deleted : HKLM\Software\SProtector

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v22.0 (en-US)

File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\weh874hs.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v27.0.1453.116

File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [30416 octets] - [04/07/2013 10:01:16]
AdwCleaner[R2].txt - [1281 octets] - [10/07/2013 15:21:30]
AdwCleaner[S1].txt - [30880 octets] - [04/07/2013 12:51:02]
AdwCleaner[S2].txt - [1216 octets] - [10/07/2013 15:26:04]

########## EOF - C:\AdwCleaner[S2].txt - [1276 octets] ##########





Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

7/10/2013 4:10:27 PM
mbam-log-2013-07-10 (16-10-27).txt

Scan type: Full scan (C:\|)
Objects scanned: 310586
Time elapsed: 41 minute(s), 36 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
Thanks Dave





RogueKiller V8.6.2 [Jul 5 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Administrator [Admin rights]
Mode : Scan -- Date : 07/10/2013 23:40:58
| ARK || FAK || MBR |

¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH] Lightshot.exe -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Skillbrains\lightshot\4.3.0.0\LightShot.exe [7] -> KILLED [TermProc]
[SUSP PATH] Badoo.Desktop.exe -- C:\Documents and Settings\All Users\Application Data\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7] -> KILLED [TermProc]

¤¤¤ Registry Entries : 17 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : LightShot (C:\Documents and Settings\Administrator\Local Settings\Application Data\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue [7]
  • ) -> FOUND
[RUN][SUSP PATH] HKCU\[...]\Run : Badoo Desktop (C:\Documents and Settings\All Users\Application Data\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-2025429265-861567501-1417001333-500\[...]\Run : LightShot (C:\Documents and Settings\Administrator\Local Settings\Application Data\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue [7]
  • ) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-2025429265-861567501-1417001333-500\[...]\Run : Badoo Desktop (C:\Documents and Settings\All Users\Application Data\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7]) -> FOUND
[DNS] HKLM\[...]\CCSet\[...]\{06956AD2-24F6-46CB-954E-A1507AE22562} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[DNS] HKLM\[...]\CCSet\[...]\{C5F3C407-F0CD-40C7-8E5E-54F1B199F2FD} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[DNS] HKLM\[...]\CCSet\[...]\{F26FE20F-BA46-4770-8889-15F4E1B67646} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[DNS] HKLM\[...]\CS001\[...]\{06956AD2-24F6-46CB-954E-A1507AE22562} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[DNS] HKLM\[...]\CS001\[...]\{C5F3C407-F0CD-40C7-8E5E-54F1B199F2FD} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[DNS] HKLM\[...]\CS001\[...]\{F26FE20F-BA46-4770-8889-15F4E1B67646} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[DNS] HKLM\[...]\CS002\[...]\{06956AD2-24F6-46CB-954E-A1507AE22562} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[DNS] HKLM\[...]\CS002\[...]\{C5F3C407-F0CD-40C7-8E5E-54F1B199F2FD} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[DNS] HKLM\[...]\CS002\[...]\{F26FE20F-BA46-4770-8889-15F4E1B67646} : NameServer (107.6.133.8,23.23.180.210) -> FOUND
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowHelp (0) -> FOUND
[HJ SMENU] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled TASKS : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost
127.0.0.1 updates.presonus.com


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 4f75e196dd3c1b2c4a302dfe238a8d94
[BSP] 7a13bb6a8558b48e73bab4a19efcb5bb : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo
User = LL1 ... OK!
User = LL2 ... OK!

FINISHED : << RKreport[0]_S_07102013_234058.txt >>




Please run RogueKiller again and delete those items.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part05.rarprobably a variant of Win32/Autorun.NEWCBCX worm
C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070974.dlla variant of Win32/Adware.MultiPlug.I application
C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070976.dlla variant of Win32/Adware.MultiPlug.I application
C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070980.dlla variant of Win32/Adware.MultiPlug.I application
C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070997.exea variant of MSIL/Adware.iBryte.A application
C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\weh874hs.default\extensions\[emailprotected]\content\bg.jsWin32/Adware.MultiPlug.H applicationcleaned by deleting - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\dap_pre.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\d_a_p.v8.6.6.2-mkdev.team_by_cyborg.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d3.part32.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d3.part33.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d3.part34.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d3.part35.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d5.part29.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d5.part30.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d5.part31.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d5.part32.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d6.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d6.part17.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d6.part18.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\Desktop\VSTS\mpc\ssos_d6.part33.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Documents and Settings\Administrator\My Documents\Downloads\Compressed\VSO.Convert.X.To.DVD.3.6.4.158.Full\VSO.Convert.X.To.DVD.3.6.4.158.Full\Keygen.rarmultiple threatsdeleted - quarantined
C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\downloadmanager_Setup.exea variant of Win32/Adware.iBryte.G applicationcleaned by deleting - quarantined
C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\Extreme_Flash_Player_Setup.exea variant of Win32/Adware.iBryte.G applicationcleaned by deleting - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_1.part09.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_1.part10.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_1.part11.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_2.part04.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_2.part15.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_2.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\parkrd1.part06.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\parkrd1.part07.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\parkrd1.part08.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\parkrd1.part09.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\ssos_d4.part14.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\New Folder\korg triton refill.part41.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\HiFi Kit\fantom_x_facsimile_2.part05.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit1\parkrd1.part10.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_2.part06.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_2.part07.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_2.part08.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_2.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_3.part01.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\parkrd1.part11.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\parkrd1.part12.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\parkrd1.part13.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Binary Finary\Redrum\Subtle Effects\korg triton refill.part42.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_2.part09.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_2.part10.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_2.part11.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_2.part12.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_3.part01.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_3.part02.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_3.part03.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\parkrd1.part14.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\parkrd1.part15.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\parkrd1.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\parkrd1.part17.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\ssos_d4.part15.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_2.part13.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_2.part14.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_2.part15.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_3.part02.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_3.part04.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\parkrd1.part18.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\parkrd1.part19.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\parkrd1.part20.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\Redrum\Hat\fantom_x_facsimile_2.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\Redrum\Hat\parkrd2.part01.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Organic Chemistry\Rex2\Electro Acoustic Beats\100bpm\korg triton refill.part43.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\110bpm\fantom_x_facsimile_3.part01.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\fantom_x_facsimile_3.part02.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\fantom_x_facsimile_3.part03.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\fantom_x_facsimile_3.part05.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\fantom_x_facsimile_3.part06.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\lip-max_payne_dvdrip.part1.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part02.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part03.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part04.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
Wow, that was a lot of infections. Please run ESET again to make sure we got all of it. Are you using a P2P program to download music?no p2p apps on my computer, those files that say Reason, that's a music program i bought at Guitar Center, now those refills were legally DOWNLOADED online, but i've had all those on my computer for at least 3 years and haven't used them recently so i don't see how that could be the problem. i'm still getting all of these coupon popups.

i'm running again! thanksC:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part05.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined
C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070974.dlla variant of Win32/Adware.MultiPlug.I applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070976.dlla variant of Win32/Adware.MultiPlug.I applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070980.dlla variant of Win32/Adware.MultiPlug.I applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070997.exea variant of MSIL/Adware.iBryte.A applicationcleaned by deleting - quarantined
Also as I mentioned at the start of the thread, when i right click my computer/properties it no longer told me how much ram i had but everything else showed up.


I decided to go inside since I did recently move, everything seemed intact but i pulled my 4 sticks (two 1 gb sticks and 2 smaller ones). I placed them back in and rebooted, now it says 2.00GHZ and 2.99gb of Ram!


That's what its suppose to say but i played some videos and again, when i put it in full screen or ever double the size, it starts stuttering, pausing and the video becomes distorted.

The ram did appear a little warm when i pulled it. thanksDid you run the RAM test?thanks Dave, sorry for my late response, remember i tried running it on the first page but it wouldn't work, after looking into things, looks like i'll need to burn it on cd and run it. i'll pick up some tomorrow. thanks
2346.

Solve : Sh4ldr removal help windows 7?

Answer» ESET Online Scan

Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install, or it will ask to download an installer. Please do so an install it.
  • Click Start or wait for the scanner to load.
  • Make sure that the options Remove found threats and the option Scan unwanted applications are checked.
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, there are a couple of things to keep in mind:
  • 1. If NO threats were found, allow the scanner to Uninstall on close and then close the Window.
  • 2. If threats WERE detected, click on List of Threats Found, Export to Text File...save it as ESET-Scan-Log.txt. Click the back button/link, put a checkmark to Uninstall Application on Close and then close the window.
  • Open the logfile from wherever you saved it
  • Copy and paste the contents in your next reply.

Any more issues?

We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here.

Many of the things to note for US would be:

  • Slow computer
  • Error messages
  • Fake antivirus alerts or the icon in the system tray
  • svchost.exe running at 100%
  • System crashes or blue screen of death
Yay! No threats found! And, so far, i'm not being redirected anywhere. Now can i safely uninstall Spyhunter?

DMJ:

Follow up questions. How do I safely remove the malicious SpyHunter 4 program I got tricked into downloading to fix the original sh4ldr virus? I've read that 'Enigma' created both the virus and then the fake fix program. I've heard uninstalling normally can cause it to erase my BIOS?

Also, the sh4ldr folder is still in my C: as well as it's accompaning temp file. I know I need to safely remove them from my computer as well. Lastly, are there registry files that will need to be cleaned?

Thanks again!!!!


From TDSSKiller report:

13:02:44.0098 6932 [ 2ED464C8CBC399E69FBF776A8EBC3302 ] SpyHunter 4 Service C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
13:02:44.0134 6932 SpyHunter 4 Service - ok



In Combo Fix posted report:

2012-10-14 11:02 . 2012-10-14 11:02 -------- d-----w- C:\sh4ldr
2012-10-14 11:02 . 2012-10-14 11:02 -------- d-----w- c:\program files\Enigma Software GroupEnigma Software Group is legitimate software company that have a lot of hating people. It's their fault they ruined their own reputation, but it's not a big deal. I think you can uninstall it via the Control Panel and be in good hands.

Here is a VirusTotal scan of that file that was running in the processes list from SpyHunter: https://www.virustotal.com/file/4a0df1d6220c3d93d0502a576b758705f554af3ae32f65ca5d0208336afa43b4/analysis/

This is a SpyHunter folder: sh4ldr, literally "SpyHunter Folder".

However, your computer was infected by a serious rootkit, which had nothing to do with SpyHunter, Enigma Software Group, or the like.


We will finish up now to make sure your computer is protected from malware in the future.

Clean up System Restore

Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."
  • Select Start > All PROGRAMS > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done
Run OTC to remove our tools

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to REBOOT during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note:If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

Purge old temporary files

Download CCleaner Slim and save it to your Desktop - Alternate download link

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.

* Double-click the CCleaner shortcut on the desktop to start the program.
* Click on the Options block on the left, then choose Cookies.
* Under Cookies to Delete, highlight any cookies you would like to retain permanently
* Click the right arrow > to move them to the Cookies to Keep window.
* Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours
* Click Cleaner on the left then Run Cleaner on the right to run the program.
* Important: Make sure that ALL BROWSER windows are closed before selecting Run Cleaner

Caution: Only use the Registry FEATURE if you are very familiar with the registry.
Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

Security Check

Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
2347.

Solve : How do I make a Batch file remove Viruses from my computer??

Answer»

Team,

Please help me with this at the earliest...

I need ONLY a batch file to remove the virus from my COMPUTER and How do I make a Batch file to do so?

Need ur help &AMP; suggestions... A batch file will not remove INFECTIONS from your computer especially if you don't KNOW what infections are there. Do you need help CLEANING the computer?

2348.

Solve : [PROMOTE HERE] is spam or worse?

Answer»

turn off or on smartscreen filter - tools/internet options/advanced/security/ and turn if off Did a search and FOUND sevenforums.com and that's where i got this info Quote from: darcomputer on October 11, 2012, 05:09:18 PM

turn off or on smartscreen filter - tools/internet options/advanced/security/ and turn if off Did a search and found sevenforums.com and that's where i got this info
Could I please see the log from adwCleaner?
I provided the instructions to clean the temp files in my previous post.
there are two of them.

# AdwCleaner v2.003 - Logfile created 09/30/2012 at 19:00:49
# Updated 23/09/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : owner - OWNER-PC
# Boot Mode : Normal
# Running from : C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FBI3BDF3\adwcleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : WajamUpdater

***** [Files / Folders] *****

Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\Wajam
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Users\owner\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\owner\AppData\Local\Conduit
Folder Deleted : C:\Users\owner\AppData\Local\Wajam
Folder Deleted : C:\Users\owner\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\owner\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Wajam
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3244149
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\Wajam
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Software
Key Deleted : HKU\S-1-5-21-2605971270-3625370099-2031170598-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[emailprotected]]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Restored : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-21-2605971270-3625370099-2031170598-1000\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=DOWNLOAD&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search BAR] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com

-\\ Google Chrome v [Unable to get version]

File : C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [11546 octets] - [15/09/2012 20:29:12]
AdwCleaner[R2].txt - [9987 octets] - [30/09/2012 18:57:11]
AdwCleaner[R2]snap.do.txt - [9987 octets] - [30/09/2012 18:58:58]
AdwCleaner[R3].txt - [10116 octets] - [30/09/2012 19:00:35]
AdwCleaner[S1].txt - [10895 octets] - [30/09/2012 19:00:49]

########## EOF - C:\AdwCleaner[S1].txt - [10956 octets] ##########





# AdwCleaner v2.003 - Logfile created 09/30/2012 at 19:00:49
# Updated 23/09/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : owner - OWNER-PC
# Boot Mode : Normal
# Running from : C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FBI3BDF3\adwcleaner.exe
# Option [Delete]


***** [Services] *****

Stopped & Deleted : WajamUpdater

***** [Files / Folders] *****

Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\Wajam
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\Partner
Folder Deleted : C:\Users\owner\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\owner\AppData\Local\Conduit
Folder Deleted : C:\Users\owner\AppData\Local\Wajam
Folder Deleted : C:\Users\owner\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\owner\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\AVG Secure Search
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\IGearSettings
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Wajam
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.BHO
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.BHO.1
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.Sandbox
Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.Sandbox.1
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3244149
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader
Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\Software\Wajam
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wajam
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Software
Key Deleted : HKU\S-1-5-21-2605971270-3625370099-2031170598-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[emailprotected]]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

Restored : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Restored : [HKU\S-1-5-21-2605971270-3625370099-2031170598-1000\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope]
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com
Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com

-\\ Google Chrome v [Unable to get version]

File : C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [11546 octets] - [15/09/2012 20:29:12]
AdwCleaner[R2].txt - [9987 octets] - [30/09/2012 18:57:11]
AdwCleaner[R2]snap.do.txt - [9987 octets] - [30/09/2012 18:58:58]
AdwCleaner[R3].txt - [10116 octets] - [30/09/2012 19:00:35]
AdwCleaner[S1].txt - [10895 octets] - [30/09/2012 19:00:49]

########## EOF - C:\AdwCleaner[S1].txt - [10956 octets] ##########
i cleaned the temp files, all, even in my computerC/windows/temp
this is new been playing Rescue Frenzy for awhile, never any problems till right now, i now have Bing Desktop if that matters The GAME freezes, windows tries to repair it and i get: Error: Access violation at 0x0050285A (tried to read from 0x44149C45) program terminated. tried and froze twice and here i am helphere we go again, the spam emails are back eg Promote Here, not this exact one but the other ones i've also been getting 5 in email, only one email account, box so far Quote
here we go again, the spam emails are back eg Promote Here, not this exact one but the other ones i've also been getting 5 in email, only one email account, box so far
Everyone gets spam. It doesn't mean that the computer is infected. Why not download and install MailWasher?downloaded mailwasher, we shall see. Observation, my title PROMOTE HERE has had alotttt of views, and the same emails i'm getting have used this name Promote here, same - spam or worse.... we will see ok I have never had to deal with spam, can you help me.Quote
I have never had to deal with spam, can you help me.
The only way I know of is to install a spam filter or MailWasher.mailwasher is now my email provider for the spam email which turns out to be great but how to I change it to Outlook or at least windows live mail. i do not sign into windows live mail but it thinks i have. Everytime i get mail, i have to make mailwasher WASH these same emails sent by different ppl. help i don't want to do this everytime.
2349.

Solve : Firewall turned off?

Answer»

Whenever I start my PC my FIREWALL setting is turned off. I have no trouble turning it back on, but should I worry?MAKE sure the Windows Firewall Service is set to: automatic. If still no joy, look here:

http://technet.microsoft.com/en-us/library/cc749262%28v=ws.10%29.aspxHow do I set it to automatic? Right-click on My COMPUTER and select MANAGE. Click on Services and Applications and select Services. Find a Right-click on Windows Firewall and select Properties. Click on startup type and select Automatic then, select Apply and close the window.Quote from: alexandraxerta on JULY 17, 2013, 10:48:50 AM

How do I set it to automatic?
Start - Run - services.msc
Double click on the service, set it to AUTOMATIC, click on APPLY & OK
2350.

Solve : Trend Micro Antispyware + Webroot??

Answer»

I have had my laptop for five years now and never had a virus on it. When I purchased it from BEST Buy they installed both Trend Micro and Webroot on it, and I have had both set up for automatic renewal. Last year when they both RENEWED, Trend Micro updated me to Trend Micro with Antispyware. My computer was also acting funky because of it, but I was able to solve it on my own and both have been working fine for the year.

My renewal is coming up next month, should I renew both or will I be okay with just one over the other (Trend Micro over Webroot).

Note, I have never ever had a virus on this laptop and its a Gateway running Vista. I suspect that you may be running too much realtime protection of security programs. Keep in mind that running too much realtime protection can cause more problems rather than prevent them. Also, can cause system crashes, and even false positives.

It is probably best if Trend Micro's protection is running. Unless you have Webroot SecureAnywhere, then go with that.

It seems pretty weird that Best Buy "techies" would do that. Shows you how much they know. Its Webroot Internet Security Essentials and Trend Micro Antivirus plus Antispyware.

+ I also have Malwarebytes that I do run every week in safe mode (free version). I'd say Webroot Internet Security Essentials. Go with that only. Even though its not Anti-virus? The people at Best Buy EXPLAINED it to me as being one is for Spyware only (Webroot) and one is Anti-virus (Trend Micro).

That's incorrect.

Trend Micro Antivirus plus Antispyware is a combined solution.

Webroot Internet Security Essentials involves a group of solutions: antivirus, antispyware, firewall, etc. However, it is now known as Webroot SecureAnywhere: http://www.webroot.com/En_US/consumer-products-secureanywhere-internet-security-plus.html

Chat with an agent of Webroot and see if you are upgrade-eligible for SecureAnywhere at the renewal price.I think I might be, if I can even get a small discount it would be worth to me instead of paying for two products which contradict one another...Indeed. Kudos!If you're going to renew, I'd suggest checking online for discounts and coupons (retailmenot.com often has some good ones). I often suggest to clients that they not pay for antivirus. There's plenty of free antivirus programs out there (AVG, avira, just to name a few) that do the job just fine.There may be free antivirus programs available, but they're not enough!

Premium antivirus software provides the best antivirus protection and safeguards your computer, your identity, and all of your personal information saved on the computer. Some programs provide extra features, such as free online backup, auto-sandbox (which runs your programs in a safe environment to make sure they are not malicious), and social networking protection. Without these core features, you run the risk of having your identity stolen.

What a free antivirus program does not provide is identity protection, which is a critical component in today's malware world!Quote from: DragonMaster Jay on October 18, 2012, 09:46:11 AM

There may be free antivirus programs available, but they're not enough!

Premium antivirus software provides the best antivirus protection and safeguards your computer, your identity, and all of your personal information saved on the computer. Some programs provide extra features, such as free online backup, auto-sandbox (which runs your programs in a safe environment to make sure they are not malicious), and social networking protection. Without these core features, you run the risk of having your identity stolen.

What a free antivirus program does not provide is identity protection, which is a critical component in today's malware world!
I would disagree with this pretty strongly. Throughout many years, I have repaired computers that had a variety of anti-malware suites on them and the difference I've seen between free and paid anti-virus is about 10%. A lot of anti-virus companies heap a bunch of features onto their software which I honestly don't think do anything including "identity protection" whatever that means. The sandbox is also not such an amazing tool, Windows already does this to some extent and many viruses do routinely break through the security provided by paid anti-virus software with such a feature.

Paid anti-virus products are focused on one thing: sales. They want to sell as many products as possible and that's why you see "features" that don't actually give users any additional protection. It's the "Geek Squad" model for computer security -- make as much money off every customer regardless of what you actually do for them. Free anti-virus products, on the other hand, are focused on fighting viruses and "upgrading" users to their pro versions which give them benefits like online backup, being able to use the program for business purposes, etc. As a result, many free anti-virus programs are way more lightweight than their paid competitors. Once a user has bought a one year norton subscription, they're stuck with it and would feel like they wasted their money if they uninstalled it. If they are using a free anti-virus and it's slowing their computer down, they'll quickly un-install it but you can't say the same for paid anti-virus where they are locked in.

Overall, the most important anti-virus doesn't even require any installation: it's the user. If they go around clicking on every link they see and running programs from un-reputable sources then yeah, they're going to get viruses and it doesn't matter which anti-virus they have. If they're smart, anti-virus is more like a "failsafe" and the most cautious users don't even need antivirus.You may disagree with this pretty strongly, but look at the evidence (I'll link to my blog so you know that my computer security knowledge is authentic)...

Another Java vulnerability, 30 holes

Many antivirus companies fail to block Java exploit

See the swell of computer security


Most free antivirus products do not include the intrusion detection system that many paid antivirus programs have. Which is bad, because IDS helps to protect files and the Registry from unwanted modification.

The computer security industry is booming big time, because there are millions of computer security workers still needed in order to keep up with the constant vulnerabilities, threat of cyberwar, etc.

My experience with paid antivirus is that I felt more secure knowing that I had an antivirus program that was protecting me. Why do you think Kaspersky software is so popular, even though they DON'T have a free antivirus?

AVG, Avira, Microsoft, Avast, ZoneAlarm, Comodo, and Lavasoft provide a free antivirus as a temporary means, and as a relief for those who cannot currently buy an antivirus product.

When I had Avast! Free, I tried many occasions to download a malware file, and was successful on getting it to my Desktop, but once it got there, the scanner detected it and warned me. HOWEVER, when I got paid Avast Internet Security for reduced price of $20 (thanks to an awesome special), it blocked the malware at the connection. It wouldn't even allow me to TRY to download it. The web shield was lightning fast.

The scanning engine on paid antivirus is so much fast, and less resource intensive, that it made for a beautiful thing.

Further, without a defense-in-depth PC strategy, consumers run extreme risk of having their identity stolen (yes with just a single virus), and the threat is real! Computer security threats and malware are punishable by law now. It's gotten serious. Open your eyes!

Actual statistics show social network security hazards are real and becoming a real problem. That's why Facebook has allied with key antivirus companies, to provide a PAID antivirus solution or internet security solution. The ones offered, except for Microsoft Security Essentials, are PAID versions.

Don't believe me security holes are a problem to users? Take a look at Google grants, which gives away money to find security holes in its products, such as Chrome.

Meanwhile, there are so many security problems in popular browsers, like Firefox, and the users of these browsers need extra protection to protect from the vulnerability of the bugs.

And with many people suffering data loss, it is important to have a security system that helps salvage your important data.

Read more on the difficulty of malware threats in the 2010+ era:
http://secureconnexion.wordpress.com/2012/06/22/running-virtual-analysis-on-malware-is-failing-these-days/
http://secureconnexion.wordpress.com/2012/09/28/fall-malware-threats-2012/
http://secureconnexion.wordpress.com/2012/09/19/zeroaccesssirefef-infects-up-to-9-million-pcs/
http://secureconnexion.wordpress.com/2012/07/27/rakshasa-case-study-really-undetectable/
http://secureconnexion.wordpress.com/2012/06/18/six-arrested-in-japan-for-android-malware/
http://secureconnexion.wordpress.com/2012/06/14/watch-out-this-android-malware-is-top-game/


Please make sure to check out all the appropriate links, before coming back with your rebuttal. And make sure to keep it ethical, or I will close this topic.

And think twice before arguing with a computer security student/professional. Quote from: DragonMaster Jay on October 19, 2012, 02:18:46 AM
You may disagree with this pretty strongly, but look at the evidence (I'll link to my blog so you know that my computer security knowledge is authentic)...

Another Java vulnerability, 30 holes

Many antivirus companies fail to block Java exploit

See the swell of computer security


Most free antivirus products do not include the intrusion detection system that many paid antivirus programs have. Which is bad, because IDS helps to protect files and the Registry from unwanted modification.

The computer security industry is booming big time, because there are millions of computer security workers still needed in order to keep up with the constant vulnerabilities, threat of cyberwar, etc.

My experience with paid antivirus is that I felt more secure knowing that I had an antivirus program that was protecting me. Why do you think Kaspersky software is so popular, even though they DON'T have a free antivirus?

AVG, Avira, Microsoft, Avast, ZoneAlarm, Comodo, and Lavasoft provide a free antivirus as a temporary means, and as a relief for those who cannot currently buy an antivirus product.

When I had Avast! Free, I tried many occasions to download a malware file, and was successful on getting it to my Desktop, but once it got there, the scanner detected it and warned me. HOWEVER, when I got paid Avast Internet Security for reduced price of $20 (thanks to an awesome special), it blocked the malware at the connection. It wouldn't even allow me to TRY to download it. The web shield was lightning fast.

The scanning engine on paid antivirus is so much fast, and less resource intensive, that it made for a beautiful thing.

Further, without a defense-in-depth PC strategy, consumers run extreme risk of having their identity stolen (yes with just a single virus), and the threat is real! Computer security threats and malware are punishable by law now. It's gotten serious. Open your eyes!

Actual statistics show social network security hazards are real and becoming a real problem. That's why Facebook has allied with key antivirus companies, to provide a PAID antivirus solution or internet security solution. The ones offered, except for Microsoft Security Essentials, are PAID versions.

Don't believe me security holes are a problem to users? Take a look at Google grants, which gives away money to find security holes in its products, such as Chrome.

Meanwhile, there are so many security problems in popular browsers, like Firefox, and the users of these browsers need extra protection to protect from the vulnerability of the bugs.

And with many people suffering data loss, it is important to have a security system that helps salvage your important data.

Read more on the difficulty of malware threats in the 2010+ era:
http://secureconnexion.wordpress.com/2012/06/22/running-virtual-analysis-on-malware-is-failing-these-days/
http://secureconnexion.wordpress.com/2012/09/28/fall-malware-threats-2012/
http://secureconnexion.wordpress.com/2012/09/19/zeroaccesssirefef-infects-up-to-9-million-pcs/
http://secureconnexion.wordpress.com/2012/07/27/rakshasa-case-study-really-undetectable/
http://secureconnexion.wordpress.com/2012/06/18/six-arrested-in-japan-for-android-malware/
http://secureconnexion.wordpress.com/2012/06/14/watch-out-this-android-malware-is-top-game/


Please make sure to check out all the appropriate links, before coming back with your rebuttal. And make sure to keep it ethical, or I will close this topic.

And think twice before arguing with a computer security student/professional.

The java links are irelevat to the anti-virus discussion. If java has a security hole and Sun or the user fail to update, anti-virus shouldn't protect them from that. Anti-virus should, however, protect them from any payloads delivered through that vulnerability. Many people get viruses not because their anti-virus couldn't protect them, but because they continually ignored warnings to upgrade their software including the anti-virus software itself!

I'm not saying viruses and security holes aren't a threat here, they certainly are and user education can prevent a whole lot more than a $10 a month subscription to a service that by design can only prevents threats that are known about and already out in the wild.

Again, agree to disagree none of the links you provided showed that paid anti-virus programs actually block significantly more threats than free ones.
Here are reasons why you don't know what you're talking about...

Quote
If java has a security hole and Sun or the user fail to update, anti-virus shouldn't protect them from that.


If Java has a security hole? How about many security holes? Have you not heard? It's Oracle that owns the Java product line, not Sun [Microsystems] anymore.

If antivirus shouldn't protect my computer from vulnerabilities, then what will? If a real life virus got in my body, it was because of a vulnerability, so I take a vaccine (antivirus) to protect me from the vulnerability next time to avoid the virus. Get the analogy? That's why vulnerability management and prevention is so important, because it would prevent the virus from even having a chance at getting installed. Further, vulnerability prevention in antivirus software is just as important as blocking viruses themselves.

Quote
Many people get viruses not because their anti-virus couldn't protect them, but because they continually ignored warnings to upgrade their software including the anti-virus software itself!

Many people get viruses through vulnerabilities. If people would read the news, and not skip over the security section, they could LEARN how to protect themselves. They may fail to upgrade the antivirus software, but there are measures being taken by both antivirus companies AND operating system companies (such as Microsoft, Apple, Ubuntu, etc.) to manage the vulnerabilities associated with that (by forming a strategic alliance with security companies), in hopes to help update/upgrade those products.

Quote
I'm not saying viruses and security holes aren't a threat here, they certainly are and user education can prevent a whole lot more than a $10 a month subscription to a service that by design can only prevents threats that are known about and already out in the wild.

This makes no sense. Re-read the sentence, and tell me if you would understand this. Why would somebody want to prevent a $10 a month service?

By design, antivirus was originally supposed to prevent viruses from doing anymore damage, by scanning the system and looking for bad code. Then, it was the ability to prevent the install of viruses by scanning the threats in real-time (which was only allowed Windows XP and up).

Now, heuristics and other algorithms spot more viruses/malware because they rely on behavior of the file, which they run in a self-contained sandbox, called virtualization. If malware is found by the analyzer built in to most antivirus programs these days, the program is marked as malware if it relates to other threats, or labeled new malware if it is suspicious.

We've come a long way, in which now vulnerability prevention is in play, which is strengthening heuristics and algorithms. I would hate to give my product away for free, if I knew I spent 800-1000 man hours writing code, and double that in researching malware.

Quote
Again, agree to disagree none of the links you provided showed that paid anti-virus programs actually block significantly more threats than free ones.

I don't agree to disagree to people that think they know what they're talking about, and don't listen to experts. I agree to disagree to people that made a solid, rational opinion. All you have done was contradict myself, because you are part of a community of people that think all software should be free. You lack the ability to believe in solid, awesome software, such as Adobe Creative Suite, Kaspersky PURE or Antivirus or Internet Security, etc.

As I explained above, it's not about blocking [known] threats, it's about discovering unknown threats and vulnerabilities and being ahead of the game. Free antivirus does a job that paid antivirus cannot do, provide a temporary means, so that people don't have to go without antivirus software. However, the astute person can save themselves from computer heartache, by getting a paid antivirus software.

Many people, some who claim to have not had problems with viruses, are big supporters of free antivirus. Meanwhile, they are promoting free antivirus like the black plague, putting users at risk for zero-day vulnerabilities.

Anyway, I've had enough trying to explain this, but at least the data is here so people can learn from a security teacher.