InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2301. |
Solve : Nasty Bug - No Access Allowed to Fix It.? |
Answer» YUP, formatting is the way to go now that you have saved your important data. BTW, the use of DVD-RW's is a less expensive way to backup your data. Good luck.Good suggestion! Thanks.So now I have tried to reformat via factory files within the computer and it has seized up, maybe because of the virus, I don't KNOW. I don't think he has a disc supplied at purchase. Quote from: copespeak on February 04, 2014, 07:03:25 PMSo now I have tried to reformat via factory files within the computer and it has seized up, maybe because of the virus, I don't know. I don't think he has a disc supplied at purchase.No, it shouldn't freeze up during a reformat because of INFECTIONS. Perhaps a hardware problem is causing it to freeze. He can always borrow a disk as long as it's the same version as what's installed on the machine.I can't get it to progress past the point where it says there is an error.Quote from: copespeak on February 04, 2014, 07:03:25 PM So now I have tried to reformat via factory files within the computerWhat does that mean? You cannot format the system drive from within Windows. EXACTLY what are you doing?I have chosen the option to 'recover' (not system restore)? Maybe the virus extends into that, I don't know.I'm sorry - but I really don't know what you mean. From where have you chosen that option. PLEASE KEEP in mind we can't see your screen - you need to describe to us what you are doing.I chose 'restore to factory settings', and it proceeded for a while, then I got this notice (see attachment). Then it just loops ... you click OK and then it starts again. Thanks for your patience! [recovering disk space, attachment deleted by admin]If there is a major bug in the system it could potentially prevent you from returning to factory settings. SuperDave's suggestion of a format and reinstall is your best bet. If I were you I'd boot to a Windows disc, delete the system partition, recreate it, format, and install Windows from scratch.Thanks Allan, yes, I am trying to find someone who has one we can borrow! Nothing like a fresh start. |
|
| 2302. |
Solve : Screen Flashes Red and White After a not Responding Program? |
|
Answer» I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser.
•Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a UNIQUE name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Here's the log: [emailprotected] as DOWNLOADER log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=ce424a03787b5a449a8f843cacaa48cb # engine=13635 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-04-17 12:06:41 # local_time=2013-04-17 10:06:41 (+1000, AUS Eastern Standard Time) # country="Australia" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1799 16775165 100 96 0 0 0 0 # compatibility_mode=5893 16776573 100 94 0 117833851 0 0 # compatibility_mode=6657 16777214 0 14 23114310 23114310 0 0 # scanned=265839 # found=5 # CLEANED=3 # scan_time=8117 sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\Users\All Users\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" sh=75DFDC05C5D5F0C3B930B5B6871B6528EC9C22EA ft=1 fh=cff868ace0c06f1a vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\Users\All Users\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll" sh=410B32FD3FE4642644AD91AC60C69B86EC2762DD ft=1 fh=0e378a435beab91a vn="a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll" sh=75DFDC05C5D5F0C3B930B5B6871B6528EC9C22EA ft=1 fh=cff868ace0c06f1a vn="a variant of Win32/Adware.Yontoo.B application (cleaned by deleting - quarantined)" ac=C fn="C:\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll" sh=800E4F9CAD354DBEF9E64F23375C61DB3107C290 ft=1 fh=cd4294964f0acafb vn="multiple threats (cleaned by deleting - quarantined)" ac=C fn="C:\TDDownload\SpeedyComputer.exe"Please run ESET and see if anything shows up.Hi Dave, I ran ESET but nothing came up. No threats was found. I found that my computer is not bad now, and programs are running okay. Except AVG kept saying that C:/program files/autoguarder/autoguarder.exe is still there. I cannot find it in the location provided.Ok, download and install MSE and run a scan and see if it finds the same thing as AVG. Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download Ni Dave, MSE says that Autoguarder.exe is still there, but in a different location. It looks like it copied itself to another location at c:/system32/autoguarder.exe. Now I know that system32 is a very important file so I tried to remove it with MSE. It did, but somehow the virus file come up again after reboot or shutting down. Also I realised that a file(C:/program files/Autoguarder/Folder.bat) was created by something, and my AVG keep detecting them but failed to remove them completely. I opened the batch file in notepad and found that it tries to delete all "dll" files in system32. So everytime My pc boots up a cmd window shows up. But most of the action were denied. However I think 5 dll files were still deleted by the virus.somehow it's not affecting my system mch, but I am very worried. thanks! Ok Please uninstall this program: C:/program files/Autoguarder Please download aswMBR.exe ( 511KB ) to your desktop. Double click the aswMBR.exe to run it Click the "Scan" button to start scan Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives On completion of the scan click save log, save it to your desktop and post in your next reply Hi Dave, I tried to uninstall Autoguarder.exe, but it say's access denied. I tried changing the security settings on access, but it didn't work. Anyways heres the log: aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-04-22 11:34:16 ----------------------------- 11:34:16.420 OS Version: Windows x64 6.1.7600 11:34:16.420 Number of processors: 4 586 0x2A07 11:34:16.421 ComputerName: JIANSFAMLIY-PC UserName: jian's famliy 11:34:18.848 Initialize success 11:35:16.930 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 11:35:16.936 Disk 0 Vendor: Size: 0MB BusType: 0 11:35:17.053 Disk 0 MBR read successfully 11:35:17.058 Disk 0 MBR scan 11:35:17.063 Disk 0 Windows 7 default MBR code 11:35:17.070 Disk 0 MBR hidden 11:35:17.077 Disk 0 Partition 1 00 1C Hidd FAT32 LBA MSDOS5.0 22003 MB offset 63 11:35:17.096 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 152618 MB offset 45062325 11:35:17.104 Disk 0 Partition - 00 0F Extended LBA 435857 MB offset 357625856 11:35:17.149 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 435856 MB offset 357627904 11:35:17.187 Disk 0 scanning C:\Windows\system32\drivers 11:35:29.094 Service scanning 11:35:45.144 Modules scanning 11:35:45.169 Disk 0 trace - called modules: 11:35:45.518 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys hal.dll 11:35:45.530 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006992060] 11:35:45.541 3 CLASSPNP.SYS[fffff880010bf43f] -> nt!IofCallDriver -> [0xfffffa8004a62200] 11:35:45.552 5 ACPI.sys[fffff88000f9a781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004ac0050] 11:35:45.561 Scan finished successfully 11:36:21.976 Disk 0 MBR has been saved successfully to "C:\Users\jian's famliy\Documents\MBR.dat" 11:36:21.979 The log file has been saved successfully to "C:\Users\jian's famliy\Documents\aswMBR.txt"By the way I cannot find Autoguarder.exe in the Programfiles folder, but 2 other locations, and each of them has a batch file contained called Folder.bat. That's the batch file which tried to delete important files. It says Access Denied when I try to delete it. You could try UnLocker. You can download and install Unlocker . Hello Dave, I got Unlocker and deleted the batch file. :)Thank you very much for helping me through this problem! My computer is running fine now. Good, let's do some cleanup and we'll be finished. Download this program and run it Uninstall ComboFix .It will remove ComboFix for you. ****************************************** To set a new Restore Point. Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode. Click the Start button , click Control Panel, click System and Maintenance, and then click System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK. This will give you a new, clean Restore Point. *************************************** Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click YES on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) *************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Hey Dave, after doing the INSTRUCTIONS you gave me in the last post, my computer got a lot faster:). Thankyou very much for helping me with malware this time, and I learnt a lot. I am thinking of installing WOT instead of AVG too. Whitebeard1Quote from: Whitebeard1 on April 23, 2013, 07:03:35 PM Hey Dave, after doing the instructions you gave me in the last post, my computer got a lot faster:). Thankyou very much for helping me with malware this time, and I learnt a lot. I am thinking of installing WOT instead of AVG too.You're welcome. Just one note. WOT is not an Anti-Virus program. It's just an aid to keep you from clicking on some dangerous sites. If you want to dump AVG, I would suggest MSE. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2303. |
Solve : Getting pop - ups? |
|
Answer» DisregardQuote Just became aware that the pop-ups are only occurring in firefox. Please try uninstalling and re-installing FF.
RougeKiller log (did not delete files) RogueKiller V8.0.4 [09/19/2012] by Tigzy mail: tigzyRKgmailcom Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/ Blog: http://tigzyrk.blogspot.com Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : LATHEM [Admin rights] Mode : Scan -- Date : 09/22/2012 13:43:38 ¤¤¤ Bad processes : 0 ¤¤¤ ¤¤¤ Registry Entries : 6 ¤¤¤ [TASK][SUSP PATH] CandyUpdater.job : C:\Users\LATHEM\AppData\Local\ArcadeCandy\candyUpdater.exe -> FOUND [TASK][SUSP PATH] CandyUpdater : C:\Users\LATHEM\AppData\Local\ArcadeCandy\candyUpdater.exe -> FOUND [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND ¤¤¤ Particular Files / Folders: ¤¤¤ ¤¤¤ Driver : [NOT LOADED] ¤¤¤ ¤¤¤ Infection : ¤¤¤ ¤¤¤ HOSTS File: ¤¤¤ --> C:\Windows\system32\drivers\etc\hosts 127.0.0.1 localhost ¤¤¤ MBR Check: ¤¤¤ +++++ PhysicalDrive0: WDC WD10 EADS-65M2B1 SCSI Disk Device +++++ --- User --- [MBR] d174627bc1fc2952cc573f0e3dd70439 [BSP] 838f2511e631effad20ac3f836e9fe9c : Windows 7 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 31 Mo 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 64260 | Size: 941802 Mo 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1928876355 | Size: 12033 Mo User = LL1 ... OK! Error reading LL2 MBR! +++++ PhysicalDrive1: HP Photosmart C4600 USB Device +++++ Error reading User MBR! User = LL1 ... OK! Error reading LL2 MBR! Finished : << RKreport[1].txt >> RKreport[1].txt Quote Unistalled and re-installed FirefoxAny change?Was waiting a few days to be sure - problem solved. I cannot thank you enough for your time, patience and expertise. Dave you really are Super!Good. We can do some cleanup and we'll be finished. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ***************************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I SUGGEST using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, VIRUSES and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations ALWAYS update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 2304. |
Solve : Computer slow, freezesup will not shut down normally? |
|
Answer» Did MS Fix-It do any good?
•Click the button. •Accept any security warnings from your browser.
•Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a UNIQUE name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt MBAM finished a scan in normasl mode and I ran ESET, it said no threats were found and did not give me a list of found threats but I will post its log file along with the MBAM log. Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.04.28.03 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 9.0.8112.16421 kkoliiiiiiiiiiiiiiii :: HOME [administrator] 4/28/2013 9:29:55 AM mbam-log-2013-04-28 (09-29-55).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 226919 Time elapsed: 5 minute(s), 37 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) [emailprotected] as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3fd56864b064234c9c3f8362eb6d5c7b # engine=13713 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-04-28 02:04:54 # local_time=2013-04-28 10:04:54 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5892 16777213 88 94 5153759 8352350 0 0 # scanned=24229 # found=0 # cleaned=0 # scan_time=910 [emailprotected] as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3fd56864b064234c9c3f8362eb6d5c7b # engine=13713 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-04-28 02:16:05 # local_time=2013-04-28 10:16:05 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5892 16777213 88 94 5154430 8353021 0 0 # scanned=2911 # found=0 # cleaned=0 # scan_time=119 That looks good. How's your computer RUNNING now?Running better I can go from site to site without freezing and my last shut down went normally. I still have an ALLSEARCH that comes up when I start Google Chrome. Is there a way to get rid of it.Quote I still have an ALLSEARCH that comes up when I start Google Chrome. Is there a way to get rid of it.It's probably an add-on in Google Chrome. Check your add-ons. Download this program and run it Uninstall ComboFix .It will remove ComboFix for you. ********************************************* To set a new Restore Point. Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode. Click the Start button , click Control Panel, click System and Maintenance, and then click System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK. This will give you a new, clean Restore Point. *************************************************** Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) *********************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, IDENTITY theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Thank you sir you have saved me money and agravation.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2305. |
Solve : audio advertisements? |
|
Answer» No adds since we ran the junk removal!! I HOPE all is well. Thank you!!No adds since we ran the junk removal!! I hope all is well. Thank you!!No adds since we ran the junk removal!! I hope all is well. Thank you!! |
|
| 2306. |
Solve : I need help getting rid of Bettersurf? |
|
Answer» Up to now, I've been combing the internet for the solution to this problem, and even with all the solutions I've been offered, I've turned up empty handed. Nothing has worked. The problem is, even after DELETING all FILES associated with it, that I could find, there is STILL this one shady extension on my browser. It was "installed by enterprise policy" as it says right next to it, as seen here: |
|
| 2307. |
Solve : FBI???? bumpkus !!!? |
|
Answer» Hi Dave, followed all steps from last post..... Can't tell you enough how GRATEFUL i am, you all do a great service for computer illiterate FOLKS like myself. THANK You very much !!!!You're welcome. I will lock this thread. If you need it re-opened, please SEND me a pm. |
|
| 2308. |
Solve : adyeild banners in browsers? |
|
Answer» How's your computer running now?
•Click the button. •Accept any security warnings from your browser.
•Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. PLEASE be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Well we have done allot, seems we have cleaned up some stuff. I have completed avoided using the computer for any web browsing while we are working on it. So this is the first time I have open any browser on it. The original problem remains, where in using Google on either CHROME or IE there is a small banner add in the middle of the page with some wording to the side saying "ads not by this site". In addition the other problem remains in that PERIODICALLY when you click on a button on any web page it pops up another window that takes you to a URL that is trying to impersonate adobe flashes site asking to download flash. I have always just closed this window. But running avast or rogue killer or malware bytes returns no infections or bad cookies, something I would get every time I used a browser then ran Malware bytes or spy hunter 4. So whatever is happening is not longer able to modify any settings but it is still embedded in my web browser under this profile. I say that because if I create a new user profile the problem does not exist at all. IM thinking about just deleting the old profile and sticking with the new one I made since it seems to run fine. I ran ESET with no infections found. Quote IM thinking about just deleting the old profile and sticking with the new one I made since it seems to run fine. I ran ESET with no infections found.That would be a good idea. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ************************************************ Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's EASY and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Thanks for all your help and patience!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2309. |
Solve : Antivirus is not enough? |
|
Answer» I discussed with a IT friend of mine, and he said Antivirus is not enough, but I THINK an Antivirus + malware SOFTWARE will be better. However, he provided the this link http://secureconnexion.wordpress.com/2012/09/13/second-opinion-malware-scanners-why-buy-one/ Most AV's also have a malware component. This is what I use on all my computers. But the website states i need to use a genuine window, but what if my window is not geniune, can i still use it. Also how do i know whether my window is genuine, thanksIf you couldn't install MSE then your copy of Windows is not legal. If your OS is not legal then you're not receiving your updates and therefore, your computer is more susceptible to infections. Run this tool and post the log to see if it's legit. 1. Download this diagnostics tool MGADiag.ext and save this to your Desktop. 2. Double-click on MGADiag.exe and click Continue 3. When the program has FINISHED, click on Copy 4. Post the results in your next reply. If you do not have a legal version of Windows we can no longer be of assistance to you.Quote from: Allan on September 28, 2012, 01:49:07 PM If you do not have a legal version of Windows we can no longer be of assistance to you. Actually in malware removal forums we will only once help an unlicensed Windows user clean their computer of malware then strongly encourage them to buy a license. Reason being it is not wise to license a computer that is infected with malware. But ultimately it's up to the helper. Thanks EF Hi John, please post your questions to me only, not look for help in the wild. That is the rules of training. Thanks...and closed. |
|
| 2310. |
Solve : Corrupted executable file?? |
|
Answer» The other day, while doing an AVG virus scan, I was informed that a "corrupted executable file" had been detected and placed in the virus vault. It seems to have SOMETHING to do with flashplayer. |
|
| 2311. |
Solve : Action Center confusing advice? |
|
Answer» Ok, how's your computer running now?Action Center report now is that there are no issues. I will see if "Not Responding" message now occurs with Firefox and report on this issue in a day or so. The "Not Responding" in Excel was probably due to the workbook being very large and the AutoRecovery set for 10 minutes and the slow response due to automatically running a large number of the RAND() functions. I know what to do to improve the Excel response. You could try uninstalling and re-installing FireFox.Super Dave. I have reinstalled Firefox. I will report on what is happening in a couple of days. Super Dave. I have reinstalled Firefox. I will report on what is happening in a couple of days.Yes, please run it to see what turns up.I ran Anti-Malware. The scan took 70 minutes and examined over 437000 objects. 40 objects were identified in Show Results and removed. The PC was then rebooted. The Notepad log follows Malwarebytes Anti-Malware (Trial) 1.75.0.1300 www.malwarebytes.org Database version: v2014.01.07.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 denisaf :: DENISAF-PC [administrator] Protection: Enabled 8/01/2014 9:16:37 AM mbam-log-2014-01-08 (09-16-37).txt Scan type: Full scan (C:\|I:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 437597 Time elapsed: 1 hour(s), 10 minute(s), 5 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 10 HKCU\Software\BrowseSmart (PUP.Optional.BrowseSmart.A) -> Quarantined and deleted successfully. HKCU\Software\jzipmusictoolbarmo (PUP.Optional.JZipMusicToolbar.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Classes\AppID\DynConIE.DLL (PUP.Optional.DynConIE.A) -> Quarantined and deleted successfully. HKLM\Software\BrowseSmart (PUP.Optional.BrowseSmart.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser HELPER Objects\{251ef57c-0612-478c-978e-c86d3879caa4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully. HKCR\CLSID\{251ef57c-0612-478c-978e-c86d3879caa4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{251EF57C-0612-478C-978E-C86D3879CAA4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{251EF57C-0612-478C-978E-C86D3879CAA4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{251EF57C-0612-478C-978E-C86D3879CAA4} (PUP.Optional.MusicToolBar.A) -> Quarantined and deleted successfully. Registry Values Detected: 2 HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: 1763663117034848255 -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{251EF57C-0612-478C-978E-C86D3879CAA4} (PUP.Optional.MusicToolBar.A) -> Data: Music Toolbar (Dist. by Bandoo Media, Inc.) -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 3 C:\ProgramData\Datamngr (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\CT3317209 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\CT3317212 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. Files Detected: 40 C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\Datamngr.dll.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\DatamngrCoordinator.exe.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\DatamngrUI.exe.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\IEBHO.dll.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\SRTOOL~1\IE\uninstall.exe.vir (PUP.Optional.MusicToolbar.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\x64\Datamngr.dll.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Music Toolbar\Datamngr\x64\IEBHO.dll.vir (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\CltMngSvc.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\SPTool.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\Main\bin\uninstall.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\cltmng.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPTool64.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC32.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC32Loader.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC64.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\SearchProtect\bin\SPVC64Loader.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\AdwCleaner\Quarantine\C\Program Files (x86)\Searchprotect\UI\bin\cltmngui.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\581ZV0BY\spstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RC0HIJAR\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\nsh5842.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\nsh9B4B.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\nsm9D8D.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\nsr55C1.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\Yyv9z_vN.exe.part (PUP.Optional.DomaIQ) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\AdwCleaner_TSV16311.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\installer_avira_antivir_personal_-_free_antivirus_English.exe (PUP.Optional.Freemium.A) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\Java(1).exe (PUP.Optional.DomaIQ) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\Java.exe (PUP.Optional.DomaIQ) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\Java7(1).exe (PUP.Optional.Domalq) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\Java7.exe (PUP.Optional.Domalq) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\jZipSetup-r250-w-bf.exe (PUP.Optional.Bandoo.A) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\MailNotifierAUSetup(2).exe (PUP.Optional.Inbox) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\SoftonicDownloader_for_stellarium(1).exe (PUP.Optional.Softonic.A) -> Quarantined and deleted successfully. C:\Users\denisaf\Downloads\SoftonicDownloader_for_stellarium.exe (PUP.Optional.Softonic.A) -> Quarantined and deleted successfully. C:\ProgramData\Datamngr\coordinator.cfg (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully. C:\ProgramData\Datamngr\general.cfg (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully. C:\ProgramData\Datamngr\S-1-5-21-3023884638-2710209032-2036161082-1000.cfg (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully. C:\ProgramData\Datamngr\S-1-5-32.cfg (PUP.Optional.Datamngr.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\CT3317209\ddt.csf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. C:\Users\denisaf\AppData\Local\Temp\CT3317212\ddt.csf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully. (end) Wow, that was a lot of infections. How's your computer running now?SuperDave Occasionally the message "Warning: Unresponsive PLUGIN Shockwave Flash - stop or continue" appears and holds things up. I understand that it is a sound process and I could cancel that message without causing any problems although there will be a slow response on occasions.Why not disable that plugin? Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to INFECT your system. First Verify your Java Version If there are any other version(s) installed then update now. Get the new version (if needed) If your version is out of date install the newest version of the Sun Java Runtime Environment. Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close ALL open web browsers before starting the installation. Remove any old versions 1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA. Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. ***************************************** Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) Latest Java is installed and an old version uninstalled. Disk clean up freed up quite a slice.Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Thank you, SuperDave for all your help. I will record your last post as it provides advice on how to ensure this pc is being used soundly. I need this record to refer to periodically as I am too old to remember how to handle the increasing complexity.You're welcome. I will LOCK this THREAD. If you need it re-opened, please send me a pm. |
|
| 2312. |
Solve : Computer virus that controlls my mouse.? |
|
Answer» This is so annoying.
I noticed that it only affects the mouse. I am thinking of re-downloading Windows, but I'm afraid it'll slip through. I haven't told my parents YET that there's a virus. The log: 22:43:09.0140 3596 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 22:43:09.0609 3596 ============================================================ 22:43:09.0609 3596 Current date / time: 2013/05/09 22:43:09.0609 22:43:09.0609 3596 SystemInfo: 22:43:09.0609 3596 22:43:09.0609 3596 OS Version: 5.1.2600 ServicePack: 3.0 22:43:09.0609 3596 Product type: Workstation 22:43:09.0609 3596 ComputerName: PC 22:43:09.0609 3596 UserName: My Pc 22:43:09.0609 3596 Windows directory: C:\WINDOWS 22:43:09.0609 3596 System windows directory: C:\WINDOWS 22:43:09.0609 3596 Processor architecture: Intel x86 22:43:09.0609 3596 Number of processors: 2 22:43:09.0609 3596 Page size: 0x1000 22:43:09.0609 3596 BOOT type: Normal boot 22:43:09.0609 3596 ============================================================ 22:43:10.0828 3596 Drive \Device\Harddisk0\DR0 - Size: 0x25432CDE00 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 22:43:10.0828 3596 ============================================================ 22:43:10.0828 3596 \Device\Harddisk0\DR0: 22:43:10.0828 3596 MBR partitions: 22:43:10.0828 3596 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x3A962B1 22:43:10.0843 3596 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x3A9632F, BlocksNum 0xEF7E8D1 22:43:10.0843 3596 ============================================================ 22:43:10.0937 3596 E: <-> \Device\Harddisk0\DR0\Partition2 22:43:10.0968 3596 C: <-> \Device\Harddisk0\DR0\Partition1 22:43:10.0968 3596 ============================================================ 22:43:10.0968 3596 Initialize success 22:43:10.0968 3596 ============================================================ 22:43:22.0218 0276 ============================================================ 22:43:22.0218 0276 Scan started 22:43:22.0218 0276 Mode: Manual; 22:43:22.0218 0276 ============================================================ 22:43:22.0796 0276 ================ Scan system memory ======================== 22:43:22.0796 0276 System memory - ok 22:43:22.0796 0276 ================ Scan services ============================= 22:43:22.0859 0276 Abiosdsk - ok 22:43:22.0859 0276 abp480n5 - ok 22:43:22.0906 0276 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys 22:43:22.0906 0276 ACPI - ok 22:43:22.0953 0276 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys 22:43:22.0953 0276 ACPIEC - ok 22:43:22.0968 0276 adpu160m - ok 22:43:23.0031 0276 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys 22:43:23.0031 0276 aec - ok 22:43:23.0062 0276 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys 22:43:23.0078 0276 AFD - ok 22:43:23.0078 0276 Aha154x - ok 22:43:23.0109 0276 aic78u2 - ok 22:43:23.0125 0276 aic78xx - ok 22:43:23.0156 0276 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll 22:43:23.0156 0276 Alerter - ok 22:43:23.0171 0276 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe 22:43:23.0171 0276 ALG - ok 22:43:23.0187 0276 AliIde - ok 22:43:23.0203 0276 amsint - ok 22:43:23.0265 0276 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 22:43:23.0265 0276 AppMgmt - ok 22:43:23.0281 0276 asc - ok 22:43:23.0296 0276 asc3350p - ok 22:43:23.0312 0276 asc3550 - ok 22:43:23.0343 0276 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys 22:43:23.0343 0276 AsyncMac - ok 22:43:23.0375 0276 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys 22:43:23.0375 0276 atapi - ok 22:43:23.0375 0276 Atdisk - ok 22:43:23.0406 0276 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys 22:43:23.0406 0276 Atmarpc - ok 22:43:23.0421 0276 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll 22:43:23.0437 0276 AudioSrv - ok 22:43:23.0468 0276 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys 22:43:23.0468 0276 audstub - ok 22:43:23.0515 0276 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys 22:43:23.0531 0276 Beep - ok 22:43:23.0562 0276 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll 22:43:23.0609 0276 BITS - ok 22:43:23.0640 0276 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll 22:43:23.0640 0276 Browser - ok 22:43:23.0718 0276 catchme - ok 22:43:23.0750 0276 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys 22:43:23.0750 0276 cbidf2k - ok 22:43:23.0765 0276 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 22:43:23.0781 0276 CCDECODE - ok 22:43:23.0781 0276 cd20xrnt - ok 22:43:23.0828 0276 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys 22:43:23.0828 0276 Cdaudio - ok 22:43:23.0875 0276 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys 22:43:23.0875 0276 Cdfs - ok 22:43:23.0921 0276 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys 22:43:23.0921 0276 Cdrom - ok 22:43:23.0937 0276 Changer - ok 22:43:23.0968 0276 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe 22:43:23.0968 0276 CiSvc - ok 22:43:24.0000 0276 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe 22:43:24.0000 0276 ClipSrv - ok 22:43:24.0015 0276 CmdIde - ok 22:43:24.0031 0276 COMSysApp - ok 22:43:24.0078 0276 Cpqarray - ok 22:43:24.0109 0276 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll 22:43:24.0109 0276 CryptSvc - ok 22:43:24.0125 0276 dac2w2k - ok 22:43:24.0140 0276 dac960nt - ok 22:43:24.0203 0276 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 22:43:24.0203 0276 DcomLaunch - ok 22:43:24.0234 0276 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll 22:43:24.0234 0276 Dhcp - ok 22:43:24.0250 0276 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys 22:43:24.0250 0276 Disk - ok 22:43:24.0265 0276 dmadmin - ok 22:43:24.0328 0276 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys 22:43:24.0328 0276 dmboot - ok 22:43:24.0359 0276 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys 22:43:24.0359 0276 dmio - ok 22:43:24.0375 0276 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys 22:43:24.0375 0276 dmload - ok 22:43:24.0390 0276 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll 22:43:24.0390 0276 dmserver - ok 22:43:24.0437 0276 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys 22:43:24.0437 0276 DMusic - ok 22:43:24.0453 0276 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 22:43:24.0468 0276 Dnscache - ok 22:43:24.0484 0276 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll 22:43:24.0484 0276 Dot3svc - ok 22:43:24.0500 0276 dpti2o - ok 22:43:24.0515 0276 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys 22:43:24.0515 0276 drmkaud - ok 22:43:24.0546 0276 [ D4F94D45E25D764462A5B95BC426C8D0 ] eamon C:\WINDOWS\system32\DRIVERS\eamon.sys 22:43:24.0546 0276 eamon - ok 22:43:24.0562 0276 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll 22:43:24.0578 0276 EapHost - ok 22:43:24.0609 0276 [ 9456462C1425D2BBF1616EDABFABA5F4 ] ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys 22:43:24.0609 0276 ehdrv - ok 22:43:24.0703 0276 [ 98B73963E8D2B89A9D5227FB6D245A00 ] EhttpSrv C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe 22:43:24.0703 0276 EhttpSrv - ok 22:43:24.0750 0276 [ 73B0195E0405051CC2B69E84EC3F64D1 ] ekrn C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe 22:43:24.0750 0276 ekrn - ok 22:43:24.0796 0276 [ 4B308624FADF5BB6490D8F8D7AEBF5DF ] epfwtdir C:\WINDOWS\system32\DRIVERS\epfwtdir.sys 22:43:24.0796 0276 epfwtdir - ok 22:43:24.0828 0276 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll 22:43:24.0828 0276 ERSvc - ok 22:43:24.0875 0276 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe 22:43:24.0875 0276 Eventlog - ok 22:43:24.0921 0276 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll 22:43:24.0921 0276 EventSystem - ok 22:43:24.0968 0276 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys 22:43:24.0968 0276 Fastfat - ok 22:43:24.0984 0276 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll 22:43:25.0000 0276 FastUserSwitchingCompatibility - ok 22:43:25.0031 0276 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys 22:43:25.0031 0276 Fdc - ok 22:43:25.0046 0276 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys 22:43:25.0046 0276 Fips - ok 22:43:25.0062 0276 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys 22:43:25.0062 0276 Flpydisk - ok 22:43:25.0109 0276 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys 22:43:25.0109 0276 FltMgr - ok 22:43:25.0125 0276 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 22:43:25.0125 0276 Fs_Rec - ok 22:43:25.0140 0276 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys 22:43:25.0156 0276 Ftdisk - ok 22:43:25.0171 0276 gdrv - ok 22:43:25.0218 0276 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys 22:43:25.0218 0276 Gpc - ok 22:43:25.0281 0276 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe 22:43:25.0296 0276 gupdate - ok 22:43:25.0296 0276 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe 22:43:25.0312 0276 gupdatem - ok 22:43:25.0359 0276 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 22:43:25.0359 0276 HDAudBus - ok 22:43:25.0421 0276 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll 22:43:25.0421 0276 helpsvc - ok 22:43:25.0453 0276 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll 22:43:25.0453 0276 HidServ - ok 22:43:25.0484 0276 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys 22:43:25.0484 0276 hidusb - ok 22:43:25.0531 0276 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll 22:43:25.0546 0276 hkmsvc - ok 22:43:25.0562 0276 hpn - ok 22:43:25.0593 0276 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys 22:43:25.0593 0276 HTTP - ok 22:43:25.0625 0276 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll 22:43:25.0640 0276 HTTPFilter - ok 22:43:25.0656 0276 i2omgmt - ok 22:43:25.0671 0276 i2omp - ok 22:43:25.0703 0276 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys 22:43:25.0703 0276 i8042prt - ok 22:43:25.0718 0276 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys 22:43:25.0718 0276 Imapi - ok 22:43:25.0781 0276 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe 22:43:25.0781 0276 ImapiService - ok 22:43:25.0796 0276 ini910u - ok 22:43:25.0937 0276 [ 08BAF30F6DE95814F58AF9CE7BBC5614 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys 22:43:25.0968 0276 IntcAzAudAddService - ok 22:43:25.0984 0276 IntelIde - ok 22:43:26.0031 0276 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys 22:43:26.0031 0276 intelppm - ok 22:43:26.0062 0276 [ DF74775766FE0D833FF5A4D705E6B146 ] ioFakDrv C:\WINDOWS\system32\DRIVERS\ioFakDrv.sys 22:43:26.0062 0276 ioFakDrv - ok 22:43:26.0093 0276 [ F171522B16EF9AEB1C79179051302B6F ] ioFakMap C:\WINDOWS\system32\DRIVERS\ioFakMap.sys 22:43:26.0093 0276 ioFakMap - ok 22:43:26.0125 0276 [ D048C1E4D5908B2D042AAEF4F1AF82A4 ] ioTablet C:\WINDOWS\system32\DRIVERS\ioTablet.sys 22:43:26.0125 0276 ioTablet - ok 22:43:26.0140 0276 [ 5AE2A50C8A07FF30FA48388E3F28DC8A ] ioTblMap C:\WINDOWS\system32\DRIVERS\ioTblMap.sys 22:43:26.0156 0276 ioTblMap - ok 22:43:26.0171 0276 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 22:43:26.0171 0276 Ip6Fw - ok 22:43:26.0203 0276 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 22:43:26.0203 0276 IpFilterDriver - ok 22:43:26.0218 0276 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys 22:43:26.0218 0276 IpInIp - ok 22:43:26.0281 0276 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys 22:43:26.0281 0276 IpNat - ok 22:43:26.0312 0276 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys 22:43:26.0312 0276 IPSec - ok 22:43:26.0343 0276 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys 22:43:26.0343 0276 IRENUM - ok 22:43:26.0390 0276 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys 22:43:26.0390 0276 isapnp - ok 22:43:26.0546 0276 [ 5739F2821D49975CEDE6BF0153D0CF01 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe 22:43:26.0546 0276 JavaQuickStarterService - ok 22:43:26.0578 0276 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys 22:43:26.0578 0276 Kbdclass - ok 22:43:26.0609 0276 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys 22:43:26.0625 0276 kbdhid - ok 22:43:26.0656 0276 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys 22:43:26.0656 0276 kmixer - ok 22:43:26.0718 0276 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys 22:43:26.0718 0276 KSecDD - ok 22:43:26.0750 0276 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll 22:43:26.0765 0276 LanmanServer - ok 22:43:26.0781 0276 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll 22:43:26.0812 0276 lanmanworkstation - ok 22:43:26.0828 0276 lbrtfdc - ok 22:43:26.0890 0276 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll 22:43:26.0890 0276 LmHosts - ok 22:43:26.0921 0276 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll 22:43:26.0921 0276 Messenger - ok 22:43:26.0984 0276 [ 7C4C76B39D5525C4A465E0BE32528E19 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 22:43:26.0984 0276 Microsoft Office Groove Audit Service - ok 22:43:27.0031 0276 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys 22:43:27.0031 0276 mnmdd - ok 22:43:27.0062 0276 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe 22:43:27.0062 0276 mnmsrvc - ok 22:43:27.0093 0276 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys 22:43:27.0093 0276 Modem - ok 22:43:27.0109 0276 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys 22:43:27.0109 0276 Mouclass - ok 22:43:27.0140 0276 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys 22:43:27.0140 0276 mouhid - ok 22:43:27.0171 0276 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys 22:43:27.0171 0276 MountMgr - ok 22:43:27.0218 0276 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 22:43:27.0234 0276 MozillaMaintenance - ok 22:43:27.0234 0276 mraid35x - ok 22:43:27.0265 0276 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys 22:43:27.0265 0276 MRxDAV - ok 22:43:27.0312 0276 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 22:43:27.0312 0276 MRxSmb - ok 22:43:27.0343 0276 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe 22:43:27.0359 0276 MSDTC - ok 22:43:27.0359 0276 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 22:43:27.0359 0276 Msfs - ok 22:43:27.0406 0276 MSIServer - ok 22:43:27.0437 0276 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys 22:43:27.0437 0276 MSKSSRV - ok 22:43:27.0453 0276 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys 22:43:27.0453 0276 MSPCLOCK - ok 22:43:27.0484 0276 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys 22:43:27.0484 0276 MSPQM - ok 22:43:27.0515 0276 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys 22:43:27.0531 0276 mssmbios - ok 22:43:27.0562 0276 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE C:\WINDOWS\system32\drivers\MSTEE.sys 22:43:27.0562 0276 MSTEE - ok 22:43:27.0609 0276 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys 22:43:27.0609 0276 Mup - ok 22:43:27.0625 0276 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 22:43:27.0640 0276 NABTSFEC - ok 22:43:27.0656 0276 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll 22:43:27.0656 0276 napagent - ok 22:43:27.0687 0276 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys 22:43:27.0703 0276 NDIS - ok 22:43:27.0734 0276 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP C:\WINDOWS\system32\DRIVERS\NdisIP.sys 22:43:27.0734 0276 NdisIP - ok 22:43:27.0765 0276 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 22:43:27.0765 0276 NdisTapi - ok 22:43:27.0812 0276 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys 22:43:27.0812 0276 Ndisuio - ok 22:43:27.0828 0276 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys 22:43:27.0828 0276 NdisWan - ok 22:43:27.0875 0276 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys 22:43:27.0875 0276 NDProxy - ok 22:43:27.0968 0276 [ 2AAE889742376EDC5C3203DFB74F28FD ] Nero BackItUp Scheduler 3 C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe 22:43:27.0984 0276 Nero BackItUp Scheduler 3 - ok 22:43:28.0015 0276 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys 22:43:28.0015 0276 NetBIOS - ok 22:43:28.0031 0276 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 22:43:28.0046 0276 NetBT - ok 22:43:28.0078 0276 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe 22:43:28.0078 0276 NetDDE - ok 22:43:28.0093 0276 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe 22:43:28.0093 0276 NetDDEdsdm - ok 22:43:28.0125 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe 22:43:28.0140 0276 Netlogon - ok 22:43:28.0156 0276 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll 22:43:28.0156 0276 Netman - ok 22:43:28.0171 0276 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll 22:43:28.0187 0276 Nla - ok 22:43:28.0250 0276 [ CB992AE1506985D9167E85883B4C3240 ] NMIndexingService C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe 22:43:28.0265 0276 NMIndexingService - ok 22:43:28.0281 0276 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 22:43:28.0281 0276 Npfs - ok 22:43:28.0328 0276 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 22:43:28.0343 0276 Ntfs - ok 22:43:28.0359 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe 22:43:28.0359 0276 NtLmSsp - ok 22:43:28.0406 0276 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll 22:43:28.0406 0276 NtmsSvc - ok 22:43:28.0437 0276 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys 22:43:28.0437 0276 Null - ok 22:43:28.0468 0276 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 22:43:28.0468 0276 NwlnkFlt - ok 22:43:28.0500 0276 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 22:43:28.0500 0276 NwlnkFwd - ok 22:43:28.0578 0276 [ 1F0E05DFF4F5A833168E49BE1256F002 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 22:43:28.0593 0276 odserv - ok 22:43:28.0625 0276 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 22:43:28.0640 0276 ose - ok 22:43:28.0671 0276 [ 3F24EAEB165328E00D687BF3B60A448A ] PAC207 C:\WINDOWS\system32\DRIVERS\pfc027.sys 22:43:28.0671 0276 PAC207 - ok 22:43:28.0703 0276 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys 22:43:28.0703 0276 Parport - ok 22:43:28.0718 0276 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys 22:43:28.0734 0276 PartMgr - ok 22:43:28.0765 0276 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys 22:43:28.0765 0276 ParVdm - ok 22:43:28.0781 0276 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys 22:43:28.0781 0276 PCI - ok 22:43:28.0796 0276 PCIDump - ok 22:43:28.0812 0276 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys 22:43:28.0812 0276 PCIIde - ok 22:43:28.0875 0276 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys 22:43:28.0875 0276 Pcmcia - ok 22:43:28.0890 0276 PDCOMP - ok 22:43:28.0906 0276 PDFRAME - ok 22:43:28.0921 0276 PDRELI - ok 22:43:28.0937 0276 PDRFRAME - ok 22:43:28.0968 0276 perc2 - ok 22:43:28.0984 0276 perc2hib - ok 22:43:29.0078 0276 [ 875E4E0661F3A5994DF9E5E3A0A4F96B ] PLFlash DeviceIoControl Service C:\WINDOWS\system32\IoctlSvc.exe 22:43:29.0078 0276 PLFlash DeviceIoControl Service - ok 22:43:29.0093 0276 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe 22:43:29.0093 0276 PlugPlay - ok 22:43:29.0109 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe 22:43:29.0109 0276 PolicyAgent - ok 22:43:29.0140 0276 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys 22:43:29.0140 0276 PptpMiniport - ok 22:43:29.0156 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe 22:43:29.0156 0276 ProtectedStorage - ok 22:43:29.0171 0276 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys 22:43:29.0171 0276 PSched - ok 22:43:29.0187 0276 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys 22:43:29.0203 0276 Ptilink - ok 22:43:29.0218 0276 ql1080 - ok 22:43:29.0234 0276 Ql10wnt - ok 22:43:29.0250 0276 ql12160 - ok 22:43:29.0281 0276 ql1240 - ok 22:43:29.0296 0276 ql1280 - ok 22:43:29.0328 0276 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 22:43:29.0328 0276 RasAcd - ok 22:43:29.0343 0276 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll 22:43:29.0359 0276 RasAuto - ok 22:43:29.0390 0276 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 22:43:29.0390 0276 Rasl2tp - ok 22:43:29.0406 0276 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll 22:43:29.0406 0276 RasMan - ok 22:43:29.0421 0276 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 22:43:29.0421 0276 RasPppoe - ok 22:43:29.0437 0276 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys 22:43:29.0437 0276 Raspti - ok 22:43:29.0468 0276 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 22:43:29.0484 0276 Rdbss - ok 22:43:29.0484 0276 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 22:43:29.0484 0276 RDPCDD - ok 22:43:29.0546 0276 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys 22:43:29.0562 0276 rdpdr - ok 22:43:29.0625 0276 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys 22:43:29.0625 0276 RDPWD - ok 22:43:29.0656 0276 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe 22:43:29.0656 0276 RDSessMgr - ok 22:43:29.0671 0276 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys 22:43:29.0671 0276 redbook - ok 22:43:29.0718 0276 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 22:43:29.0718 0276 RemoteAccess - ok 22:43:29.0750 0276 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 22:43:29.0750 0276 RemoteRegistry - ok 22:43:29.0781 0276 [ D8B0B4ADE32574B2D9C5CC34DC0DBBE7 ] ROOTMODEM C:\WINDOWS\system32\Drivers\RootMdm.sys 22:43:29.0796 0276 ROOTMODEM - ok 22:43:29.0812 0276 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe 22:43:29.0828 0276 RpcLocator - ok 22:43:29.0859 0276 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll 22:43:29.0859 0276 RpcSs - ok 22:43:29.0890 0276 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe 22:43:29.0890 0276 RSVP - ok 22:43:29.0921 0276 [ 89619EF503F949FAE09252A8B883EE11 ] RTLE8023xp C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys 22:43:29.0921 0276 RTLE8023xp - ok 22:43:29.0937 0276 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe 22:43:29.0937 0276 SamSs - ok 22:43:29.0984 0276 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe 22:43:29.0984 0276 SCardSvr - ok 22:43:30.0031 0276 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll 22:43:30.0031 0276 Schedule - ok 22:43:30.0046 0276 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys 22:43:30.0046 0276 Secdrv - ok 22:43:30.0093 0276 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll 22:43:30.0093 0276 seclogon - ok 22:43:30.0109 0276 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll 22:43:30.0109 0276 SENS - ok 22:43:30.0125 0276 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys 22:43:30.0125 0276 serenum - ok 22:43:30.0156 0276 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys 22:43:30.0156 0276 Serial - ok 22:43:30.0171 0276 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys 22:43:30.0187 0276 Sfloppy - ok 22:43:30.0203 0276 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 22:43:30.0218 0276 SharedAccess - ok 22:43:30.0234 0276 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 22:43:30.0234 0276 ShellHWDetection - ok 22:43:30.0250 0276 Simbad - ok 22:43:30.0281 0276 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP C:\WINDOWS\system32\DRIVERS\SLIP.sys 22:43:30.0281 0276 SLIP - ok 22:43:30.0296 0276 Sparrow - ok 22:43:30.0343 0276 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys 22:43:30.0343 0276 splitter - ok 22:43:30.0375 0276 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe 22:43:30.0375 0276 Spooler - ok 22:43:30.0421 0276 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys 22:43:30.0421 0276 sr - ok 22:43:30.0437 0276 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll 22:43:30.0453 0276 srservice - ok 22:43:30.0484 0276 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys 22:43:30.0484 0276 Srv - ok 22:43:30.0531 0276 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 22:43:30.0531 0276 SSDPSRV - ok 22:43:30.0562 0276 [ ED78DFAD8EFCDFBC89500492C4D14645 ] STI Simulator C:\WINDOWS\System32\PAStiSvc.exe 22:43:30.0562 0276 STI Simulator - ok 22:43:30.0609 0276 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll 22:43:30.0609 0276 stisvc - ok 22:43:30.0640 0276 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip C:\WINDOWS\system32\DRIVERS\StreamIP.sys 22:43:30.0640 0276 streamip - ok 22:43:30.0671 0276 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys 22:43:30.0671 0276 swenum - ok 22:43:30.0687 0276 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys 22:43:30.0687 0276 swmidi - ok 22:43:30.0703 0276 SwPrv - ok 22:43:30.0718 0276 symc810 - ok 22:43:30.0750 0276 symc8xx - ok 22:43:30.0765 0276 sym_hi - ok 22:43:30.0781 0276 sym_u3 - ok 22:43:30.0812 0276 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys 22:43:30.0812 0276 sysaudio - ok 22:43:30.0843 0276 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe 22:43:30.0859 0276 SysmonLog - ok 22:43:30.0906 0276 [ E11E477B5E2B8CC52E528AE9F491C678 ] TabletService C:\Genius\ioTablet\TabletService.exe 22:43:30.0906 0276 TabletService - ok 22:43:30.0953 0276 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 22:43:30.0953 0276 TapiSrv - ok 22:43:31.0000 0276 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys 22:43:31.0015 0276 Tcpip - ok 22:43:31.0046 0276 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys 22:43:31.0046 0276 TDPIPE - ok 22:43:31.0062 0276 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys 22:43:31.0062 0276 TDTCP - ok 22:43:31.0093 0276 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys 22:43:31.0093 0276 TermDD - ok 22:43:31.0125 0276 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll 22:43:31.0125 0276 TermService - ok 22:43:31.0156 0276 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll 22:43:31.0156 0276 Themes - ok 22:43:31.0187 0276 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe 22:43:31.0187 0276 TlntSvr - ok 22:43:31.0203 0276 TosIde - ok 22:43:31.0250 0276 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll 22:43:31.0250 0276 TrkWks - ok 22:43:31.0281 0276 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys 22:43:31.0281 0276 Udfs - ok 22:43:31.0296 0276 ultra - ok 22:43:31.0343 0276 [ C81B8635DEE0D3EF5F64B3DD643023A5 ] UMWdf C:\WINDOWS\system32\wdfmgr.exe 22:43:31.0343 0276 UMWdf - ok 22:43:31.0390 0276 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys 22:43:31.0390 0276 Update - ok 22:43:31.0453 0276 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll 22:43:31.0453 0276 upnphost - ok 22:43:31.0468 0276 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe 22:43:31.0484 0276 UPS - ok 22:43:31.0515 0276 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys 22:43:31.0515 0276 usbehci - ok 22:43:31.0546 0276 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys 22:43:31.0562 0276 usbhub - ok 22:43:31.0593 0276 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 22:43:31.0593 0276 usbstor - ok 22:43:31.0625 0276 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys 22:43:31.0625 0276 usbuhci - ok 22:43:31.0656 0276 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys 22:43:31.0656 0276 VgaSave - ok 22:43:31.0671 0276 ViaIde - ok 22:43:31.0687 0276 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys 22:43:31.0687 0276 VolSnap - ok 22:43:31.0750 0276 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe 22:43:31.0750 0276 VSS - ok 22:43:31.0796 0276 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll 22:43:31.0796 0276 W32Time - ok 22:43:31.0828 0276 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 22:43:31.0828 0276 Wanarp - ok 22:43:31.0859 0276 [ D918617B46457B9AC28027722E30F647 ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys 22:43:31.0875 0276 Wdf01000 - ok 22:43:31.0875 0276 WDICA - ok 22:43:31.0921 0276 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys 22:43:31.0921 0276 wdmaud - ok 22:43:31.0937 0276 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll 22:43:31.0953 0276 WebClient - ok 22:43:32.0031 0276 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 22:43:32.0031 0276 winmgmt - ok 22:43:32.0093 0276 [ A477391B7A8B0A0DAABADB17CF533A4B ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll 22:43:32.0093 0276 WmdmPmSN - ok 22:43:32.0140 0276 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll 22:43:32.0156 0276 Wmi - ok 22:43:32.0203 0276 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe 22:43:32.0203 0276 WmiApSrv - ok 22:43:32.0234 0276 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys 22:43:32.0250 0276 WS2IFSL - ok 22:43:32.0281 0276 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll 22:43:32.0281 0276 wscsvc - ok 22:43:32.0312 0276 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 22:43:32.0312 0276 WSTCODEC - ok 22:43:32.0343 0276 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll 22:43:32.0343 0276 wuauserv - ok 22:43:32.0375 0276 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll 22:43:32.0375 0276 WZCSVC - ok 22:43:32.0421 0276 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll 22:43:32.0421 0276 xmlprov - ok 22:43:32.0515 0276 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 22:43:32.0531 0276 YahooAUService - ok 22:43:32.0546 0276 ================ Scan global =============================== 22:43:32.0562 0276 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll 22:43:32.0593 0276 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 22:43:32.0593 0276 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll 22:43:32.0625 0276 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe 22:43:32.0625 0276 [Global] - ok 22:43:32.0625 0276 ================ Scan MBR ================================== 22:43:32.0656 0276 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0 22:43:32.0796 0276 \Device\Harddisk0\DR0 - ok 22:43:32.0796 0276 ================ Scan VBR ================================== 22:43:32.0796 0276 [ 3F816EFEDF17BCA5617110FCDC7A2030 ] \Device\Harddisk0\DR0\Partition1 22:43:32.0812 0276 \Device\Harddisk0\DR0\Partition1 - ok 22:43:32.0843 0276 [ 4A6142DAFE4EC98DC6F02FEE851DAC2B ] \Device\Harddisk0\DR0\Partition2 22:43:32.0843 0276 \Device\Harddisk0\DR0\Partition2 - ok 22:43:32.0843 0276 ============================================================ 22:43:32.0843 0276 Scan finished 22:43:32.0843 0276 ============================================================ 22:43:32.0875 3904 Detected object count: 0 22:43:32.0875 3904 Actual detected object count: 0 22:43:41.0750 2552 Deinitialize success I forgot. Did you try a new mouse?I borrowed one from my neighbour, but didn't work ( It didn't even move! ) Then I plugged my mouse back and the problem disappeared SINCE I didn't write a reply in this forum! Do you know any other effective malware/trojan removals?Quote Do you know any other effective malware/trojan removals?I don't believe that your problem with the mouse if malware related. |
|
| 2313. |
Solve : Master boot Record? |
|
Answer» Thank you Dave for all your help, At this point, since I don't know what you have done with the computer,What I did was very simple I ran - Bootrec / fixmbr from the recovery console on my Vista CD - I don't know if the Trojan somehow prevented the task or for some reason the vista copy of the boot record was incompatible (I'm not sure what it is that utility does) but immediately upon reboot nothing was working properly. You can see by the logs I posted "service not loaded "came up alot. Quote I would advise you to save your important data to disks and re-format and re-install your OS I have been working on that right along. My problem now lies in the recovery program I have found it on my recovery CD, Unfortunately the program NEEDS to reboot my system in order to continue and whenever I do that the problems with my boot take over. If you don't have any further Ideas would you mind if I took this problem to another forum? And regardless thank you very much DuncanDid you TRY SETTING your BIOS to boot from the CD first and then boot with the Recovery CD in the drive? If you do not know how to set your computer to boot from CD follow the steps hereYes it is set to boot from the CD. This is a different issue. I think. Somewhere along the line I lost my factory installed recovery program from my hard drive (Gateway Recovery CENTER) Because it is not properly installed I have no recovery option on the advanced boot options menu and can not access my Recovery partition. Well I found it included on my "program and drivers" CD but it is not a bootable CD. I can run the program but the first thing it wants to do is reboot. I suspect it needs to run from its own environment? Anyway I think it might run if windows wasn't struggling to boot? I don't know maybe it has to be run from the harddrive but I don't know how to install it. You can run a Repair if you borrow a Vista disk from someone but it must be the same as what you PRESENTLY have on your computer |
|
| 2314. |
Solve : Monitoring virus? |
|
Answer» I dont know any specification Please run RogueKiller again and delete those items. I dont know any specificationCan you provide me with a screenshot? How to post screenshots or images I'd like to scan your MACHINE with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate BROWSERS only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser.
•Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop USING a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Ok SuperDave I must add when I wanted to PASTE Print Screen in the paint I saw an error then I used snipping tools And I saw the other error. Other problems are I cant uninstall or install any program in the Normal Mode, I have deal with a lot of problems in normal mode, my windows photo viewer doesnt work at all and . . . I attach these photos. [recovering disk space, attachment deleted by admin]Do you have any accounts on this computer?No I dont .This will probably help. |
|
| 2315. |
Solve : Dealing with Malware (Having Followed the Guide)? |
|
Answer» Quote Obviously the malicious IPs are still trying to gain access. What do you suggest I do? And is MBAM blocking the IPs the reason for my Comodo Firewall not notifying me?Yes, MBAM is blocking them first otherwise, your Firewall would block them. Could you please try to run ComboFix again. If it won't work, try doing it in Safe Mode.This is what I GOT when ComboFix was extracting files. When I clicked on retry the same message came up, and when I clicked on ignore I got another similar message about something else. Ok, let's see if we can get rid of those tracking cookies. SUPERAntiSpyware If you already have SUPERAntiSpyware be sure to check for updates before scanning! Download SuperAntispyware Free Edition (SAS) * Double-click the icon on your desktop to run the installer. * When asked to Update the program definitions, click Yes * If you encounter any problems while downloading the updates, manually download and unzip them from here * Next click the Preferences button. •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts * Click the Scanning Control tab. * Under Scanner Options make sure only the following are checked: •Close browsers before scanning •Scan for tracking cookies •Terminate memory threats before quarantining •Please leave the others unchecked •Click the Close button to leave the control center screen. * On the main screen click Scan your computer * On the left check the box for the drive you are scanning. * On the right choose Perform Complete Scan * Click Next to start the scan. Please be patient while it scans your computer. * After the scan is complete a summary box will appear. Click OK * Make sure everything in the white box has a check next to it, then click Next * It will quarantine what it found and if it asks if you want to reboot, click Yes •To retrieve the removal information please do the following: •After reboot, double-click the SUPERAntiSpyware icon on your desktop. •Click Preferences. Click the Statistics/Logs tab. •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. •It will open in your default text editor (preferably Notepad). •Save the notepad file to your desktop by clicking (in notepad) File > Save As... * Save the log somewhere you can easily find it. (normally the desktop) * Click close and close again to exit the program. *Copy and Paste the log in your post. ************************************** Also please try running the below online scan: SuperAntiSpyware on-line scan If you can post the log it created then please do so. SUPERAntiSpyware was different to how you described it in your instructions. 16 tracking cookies were DETECTED. Once the scan was finished, it gave me the option to view the scan log (below) and remove detected threats. Having ensured everything was checked, I removed the threats from my computer. It didn't prompt me to reboot my computer; after the threats were removed, it just went back to the "home" screen. Once on the home screen, I checked the "Manage Quarantine" section, where the following were listed. I assume I should just check all 4 and delete? Here's the log: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 05/14/2013 at 00:03 AM Application Version : 5.6.1018 Core Rules Database Version : 10394 Trace Rules Database Version: 8206 Scan type : Quick Scan Total Scan Time : 00:07:59 Operating System Information Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601) UAC On - Limited User Memory items scanned : 749 Memory threats detected : 0 Registry items scanned : 63428 Registry threats detected : 0 File items scanned : 21475 File threats detected : 16 ADWARE.Tracking Cookie accounts.youtube.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ] accounts.google.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ] accounts.google.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ] .imrworldwide.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ] .trackalyzer.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ] .s.clickability.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ] .s.clickability.com [ C:\USERS\SHIRLEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\I7FFKC4L.DEFAULT\COOKIES.SQLITE ] C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Cookies\1ST8EC77.txt [ /c.atdmt.com ] C:\Users\Shirley\AppData\Roaming\Microsoft\Windows\Cookies\GGV9FZ8O.txt [ /serving-sys.com ] C:\USERS\SHIRLEY\Cookies\1ST8EC77.txt [ Cookie:[emailprotected]/ ] C:\USERS\SHIRLEY\Cookies\GGV9FZ8O.txt [ Cookie:[emailprotected]/ ] .invitemedia.com [ C:\USERS\SHIRLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] .invitemedia.com [ C:\USERS\SHIRLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] accounts.google.com [ C:\USERS\SHIRLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] accounts.google.com [ C:\USERS\SHIRLEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ] I tried running the online scan but it didn't work. I downloaded the scanner, clicked 'yes' to the security warning - but nothing happened afterwards. No alert from my antivirus, so I don't think that was blocking it. Do you know of any reason why this is the case?Quote SUPERAntiSpyware was different to how you described it in your instructions.That's possible. It's been some time since I've used it. Quote Once on the home screen, I checked the "Manage Quarantine" section, where the following were listed. I assume I should just check all 4 and delete?Yes, please do that. Quote Do you know of any reason why this is the case?This is the first time I've tried this scanner. I'll have to test it to see what's happening. Have you noticed any activity from MBAM?Okay, I deleted the 4 files. I've also ran a second scan (this is ~2 hours after the first) and a few more adware tracking cookies were found. I've deleted these as well. Does this mean these files were added to my computer in the 2 hours between doing the two scans? 2 of the newly found files were LABELLED "imrworldwide.com" - is this particularly malicious? I also haven't visited this site, so I'm guessing it's very common on a lot of other websites? Quote from: SuperDave on May 13, 2013, 06:49:48 PM Have you noticed any activity from MBAM?No activity - MBAM scans continue to come back with no threats found, and I haven't received any notifications of malicious IPs trying to gain access. I think this is due to the uninstalling (and then reinstalling) of Google Chrome. Once I did this, I haven't received any further notifications from MBAM. I will continue to monitor this and update you in the next couple of days. In the meantime, are there any further checks I should be carrying out? I run daily anti-virus and MBAM scans. Out of all the various different scans I've done since first starting this thread, which (if any) do you recommend I do at least once a day? I've just ran another scan and 13 new threats have popped up - all similar tracking cookies to the ones I've already deleted. Why do they keep coming back, and how can I stop this happening? Quote Does this mean these files were added to my computer in the 2 hours between doing the two scans? 2 of the newly found files were labelled "imrworldwide.com" - is this particularly malicious? IThat's possible to acquire those cookies. imrworldwide.com Quote In the meantime, are there any further checks I should be carrying out?Not at the moment. Quote I run daily anti-virus and MBAM scans. Out of all the various different scans I've done since first starting this thread, which (if any) do you recommend I do at least once a day?It shouldn't be necessary to do that every day. Quote Why do they keep coming back, and how can I stop this happening?What browser are you using?Quote from: SuperDave on May 14, 2013, 03:29:19 PM What browser are you using?I use Google Chrome and Firefox. I'd use Firefox for everything, but I prefer Chrome's layout + some sites run slowly on Firefox, but fine on Chrome. Is the issue using Google Chrome?Quote from: LiquidTension on May 14, 2013, 03:38:56 PM I use Google Chrome and Firefox. I'd use Firefox for everything, but I prefer Chrome's layout + some sites run slowly on Firefox, but fine on Chrome.Yes, it could be a security issue with Chrome. Check the options to raise the security level.Quote from: SuperDave on May 14, 2013, 04:18:52 PM Yes, it could be a security issue with Chrome. Check the options to raise the security level.I've set it to block any websites from setting data/cookies. Do you think this should the tracking cookies from being added? Where do you suggest I go from here? You mentioned clean up a couple of days ago? Quote I've set it to block any websites from setting data/cookies. Do you think this should the tracking cookies from being added?That should do it. Let's do some cleanup in the meantime. Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ********************************************* Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest IMMUNIZATIONS always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.Okay, thanks very much Dave. I've done the clean up as instructed above. I really appreciate all the help you've given me.Quote from: LiquidTension on May 15, 2013, 06:04:29 AM Okay, thanks very much Dave. I've done the clean up as instructed above. I really appreciate all the help you've given me.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2316. |
Solve : FBI Virus scam? |
|
Answer» Thank you for helping. I am EXPERIENCING the FBI scam virus where they are asking for payment. I have TWO logins on my computer, mine and my wife. Mine is the admin. I tried to log on using SAFE mode with networking in order to download malware removal but when I do Windows keeps shutting down and reverts to normal windows login. I can still access the internet and use the computer normally using my wife's login.Will anti malware uploaded onto my wife's account delete files from the entire C drive or just her account?Your best bet would be to create a NEW account for yourself then delete your old, infected one. Once that's done we can run some scans on the computer to make sure it's clean.I just ran SuperAntiSpyware Free and Malwarebytes Antimalware on this user and neither worked. My home screen has a huge FBI warning and payment request with a black screen in the background. How do I delete my account and create a new one? I cannot get into the admin account in a safe mode.I booted the computer in "Safe Mode with Command Prompt" and created an additional admin account. I logged onto that account in regular mode and installed/ran Malwarebytes. I was prompted to restart to REMOVE Trojans and then logged back into my original account without issue. I then deleted the temporary admin account. problem solved. Thanks for the help.We should run a few more scans just to make sure it's clean, if you don't mind. Infections like usually leave some residue.
|
|
| 2317. |
Solve : Win32 EVO-gen [susp] - While downloading SP3 ISO for XP?? |
|
Answer» Was downloading Service Pack 3 ISO for XP from Microsoft and got this alert. I am hoping its a false positive and Microsoft is not offering a ISO that came with an infection. Are you sure you downloaded it from MS and not a bogus site. I believe the download was direct from Microsoft, since I was at Microsofts site when I selected the download and it told me that others that downloaded this also downloaded 2 other updates etc, which I chose not to download the other 2 updates since I just needed SP2 and SP3. In the attached image at my first post, it specifies the URL path. I knew that the origin would be in QUESTION if I didnt supply the screenshot showing the URL path of DATA origin. I was able to bring my XP Home SP0 to slipstream of SP2, and then use SP2 to slipstream to SP3 since you cant slipstream to SP3 directly from SP0, and then used this info I found at www.bleepingcomputer.com where I am also a active member under the username of goldfist, where a person pointed a prior information inquiry to http://xdot.tk/updates.html and this patch/hotfix downloader worked awesome. Now I just need to install XP Home SP3 with hotfixed slipstream to this Pentium 4 3Ghz HT with 2GB RAM, and everything should be good. I am curious as to if there will be any updates or not after the install. Would be cool if there are few to COMPLETE or none if the patch/hotfix downloader list is up to date before creating the slipstream. This site for the patch/hotfix downloader for use with nLite claims: Quote Latest Patch Tuesday Update: December 10, 2013 So I am guessing not many additional updates needed if any.Quote I am curious as to if there will be any updates or not after the install.I would imagine there would be some updates. |
|
| 2318. |
Solve : White screen when trying to boot? |
|
Answer» Hello, |
|
| 2319. |
Solve : Is this safe? Or should I do differently?? |
|
Answer» A client brought me his virus-infected laptop, an HP Pavilion dv9627cl. He wants me to backup the Users' files, wipe Vista and install 7, then copy back the Users' files. Is it safe to do the backup to my laptop, from the infected hdd while it is connected as an external, then delete/create/format using diskmgmt.msc? Or is there a better approach? Any suggestions will be greatly APPRECIATED. Thanks. I WOULD suggest backing up his files to DVD-RW's and make sure you scan them with at least two good AV's programs before PUTTING them back on the re-formatted computer.If you slave his HD to your computer, and you have a WORLD class AV program running, (like AVG) you won't be able to OPEN, copy of move any file without it being scanned. If in doubt just right click on the drive and SCAN it. Again I'm talking about a program like AVG where you can tell it to scan a file, a folder or even a drive. That's what I do. I will scan it with Trojan Hunter and Malware Bytes too, while I'm at it. The more the better! Eh? |
|
| 2320. |
Solve : Is my MS Window Genunie?? |
|
Answer» Last time SuperDave suggested me to use diagnostics tool MGADiag.ext to check whether my window is genuine? I finished the log and PLEASE advice me whether it is genuine? I think it is Genuine because it has Validation Status: Genuine, is that the way we decide that, It would appear that it was not validated. Please read here how to validate it. Oh, but why my system will still update while it is not validate, is it bad if my window does not validate? thanksThere will be certain programs and updates that you will not receive.but what if the validation is not sucessful, then can i still use that. at the moment, i am using Eset + microsoft security essential, do they crash together? thanksQuote from: johnha169 on October 03, 2012, 03:22:36 PM but what if the validation is not sucessful, then can i still use that.More than one Anti-Virus active on your computer is not recommended.ok, the delete the Microsoft one, well, I think my final decision is to keep my window verified, because I am afraid once the verification does not succeed, it may prevent me from doing something, thanks SuperDave |
|
| 2321. |
Solve : Comodo Security Alert !!? |
|
Answer» My Comodo Firewall tells me i'm infected after Windows (7) loads. The name of the infection is - [emailprotected] It popped up after i downloaded some drum machine software from CNET here - http://download.cnet.com/HammerHead-Rhythm-Station/3000-2170_4-906069.html The Comodo alert has a link to this page http://cima.security.comodo.com/report/3a4bb6dffff1848f3a2bdc3cd1186ca0e0d3dab4.htm I've run Avast Anti-virus (Free), Anti-Malware and Super Anti-spyware, both with full scans, with no result. Yet the alert still pops up. http://forums.comodo.com/empty-t74716.0.html Yeah, seen that, it doesn't HELP MUCH thoughBased on that thread it is a false positive not detected by the LATEST definitions. SINCE your other malware / AV software do not detect it I suggest you submit it to the Commodo forum for them to evaluate. It can't seem to find it. |
|
| 2322. |
Solve : Boot from AVG repair on USB Didn't Work? |
|
Answer» Well, it's been a difficult time TRYING to get the computer to recognise a disc or a USB stick. After worrying myself sick about losing all my huge collection of PHOTOS and digital art if it crashed totally, I ended up having a guy do a home visit. He took out the Hard Drive and we copied as much info as we could onto my laptop. It was also scanned and we hoped, fixed errors on the disc. Then we put it back in and tried to get it running and the problem was still there. That disc was not recognised, or it was locked, and so on, we just couldn't repair it. |
|
| 2323. |
Solve : Computer starts automatically only in safe mode, registry attack?? |
|
Answer» Quote I am mostly concerned now about possible infection of the laptop VIA the backup and also the use of a USB flash drive in the previous clean up steps, as well as our home NETWORK.If you're laptop became infected, you would soon know it. Run your AV scan on it and also on your flash drive.I scanned the hard drive and the flash drive and they are both okay.Just to be on the safe side, run another scan with this scanner.No need to post the logs. Please download and run MicroSoft Safety Scanner. This will take about 20 minutes to run and will produce a log if your computer was infected. Please post the log. This scanner only has a shelf life of 10 days so you will need to download a new one if you want to run a scan after the trial period has expired.I ran the quick scan and it found no infections. I ORIGINALLY started the full scan but at 28 minutes it was barely a quarter finished so I quit and did the quickie instead which took about the 20 minutes that you had estimated. Thank you. What NEXT?Quote from: raygill on May 29, 2013, 03:34:12 PM I ran the quick scan and it found no infections. I originally started the full scan but at 28 minutes it was barely a quarter finished so I quit and did the quickie instead which took about the 20 minutes that you had estimated. Thank you. What next?That's it unless you've changed your mind about reformatting your harddrive.Well, even though the news has been bad, I want to thank you and everybody at this site in helping me to learn more about the mess I have gotten myself into and hopefully how to avoid it happening again. This is really an excellent resource for someone like me with a modest amount of knowledge about computers, just enough to get myself into trouble, but a DESIRE to learn more without really knowing how to go about it. This forum seems like a good learning tool. Thanks again and .You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. |
|
| 2324. |
Solve : Trying to see if this is true malware? |
|
Answer» So TODAY I did a quick SCAN with malware bytes and was looking for malware slowing down my PC. |
|
| 2325. |
Solve : Virus killing all application on both dual booted win OS? |
|
Answer» Greetings CH! Ok but which program can i use super dave? I have no anti virusIt's dangerous to go on-line with no AV on your computer. You're just asking for trouble. Remember to only install one antivirus! 1) Avast! Home Edition 2) AVG Free Edition 3) Avira AntiVir Personal 4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download 4-a) Microsoft Security Essentials for Windows XP 5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one) 6) PC Tools AntiVirus Free Edition It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses ADDITIONAL RESOURCES and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time. |
|
| 2326. |
Solve : Is multi commander file explorer dangerous ?? |
|
Answer» Hello , |
|
| 2327. |
Solve : Had a close call with a virus/malware, is Free AVG enough? Or the cause?? |
|
Answer» I ENDED up with some virus/malware file(s) that Microsoft security caught, and an AVG warning came up to offer to fix before continuing. But it wasn't my free version, it wanted $59.99 for 30 days, 79.99 for 6 months and 99.99 for the year. I wasn't able to do much and the warnings kept coming up. I ran my Anti malware program and it wasn't able to remove EVERY threat. I tried to install a different free antivirus program (avira, I think it was). The warning popped up every click, finally when the avira page was loading, it would redirect me to facebook. I tried this multiple times, it was weird, I never had something lik ethat. I was like held hostage by AVG, I was almost about ready to pay, but didn't want to give out credit card info. I decided to go to my laptop and look ONLINE on how to fix. One post had said it wasn't a virus but some sort of malware and just to do a system restore and it should go away. And it did, for now. So my question is, is the free AVG antivirus enough? Should I do away with AVG completely and use someone else. I had a paid subscription to PC tools antivirus and tools, but it EXPIRED and I didn't renew since they are retiring in December. I run the Antimalware program and CC cleaner also. Hope this makes sense. Thanks I would try using Malwarebytes to remove your issue. Thats just where I start. Here's a comparative list of all AV's.Thank you for that, added to bookmarksIf your ever having a problem with a virus already on your computer, a good way to prepare before that happens is to download norton power eraser, and the Norton bootable recovery tool. The power eraser is free, but the recovery tool can only be used if you have/had a norton disk with the code. https://security.symantec.com/nbrt/ |
|
| 2328. |
Solve : Can someone hack into your copy and paste?? |
|
Answer» Hi Writing something in notepad or word and copying it into an email.As stated before, I seriously doubt that someone took the time to create malware in order to put something on your clipboard. Someone could have put this on the clipboard but they would have to have access to your computer either directly or remotely.Thanks EVERYONE for your answers. |
|
| 2329. |
Solve : Wifes system - Strange - Not sure if malware, 50-60% CPU when idle? |
|
Answer» My wife complained that her computer was running slow yesterday, and I saw that at idle the dual-core CPU showed that it was running around 50-60% on both cores. I went to task manager and looked at Processes and sorted the CPU column so that the most active processes show at the top, but there was only 3 processes that showed like 05%, 03%, and 02% and rest of them 00%. And that adds up to just 10%, so what is going on to make the CPU run both of its cores at 50-60%Run task Manager as administrator by clicking the "Show Processes from All Users" button.Thanks for responses, also forgot about the fact that my wife is a user and not an admin of her system and so BC's suggestion to check the show process from all users I forgot about. Oddly the issue was gone when I went to check on her computer last night. It was back to 6 to 15% CPU usage on both cores. She thanked me for fixing the problem and I didnt do anything to fix it, it fixed itself and yet it wasnt powered down or rebooted since the odd behavior the other night. But if I see the problem again, I will remember this time to check on show for all users since she is just a user and I did not give her admin rights to keep the computer from getting installed with junk like she did in the past with coupon programs etc that have spyware etc with them. For her to install anything, or anything wanting to install, it pops up requiring admin password and she doesnt know that password yet so odds of her getting infected are slim unless there is some sort of exploit that can infect a computer with just user privileges. I guess we can close this ticket for assistance as for the problem is gone for now. *Also maybe I will set up a scheduled task to reboot her computer at 4am etc every day so that it can be refreshed on a daily basis.Problem came back and I found the process that is wasting CPU at 50-60%. Its Spoolsv.exe that is wasting the CPU. When I showed process for all users it showed that the SYSTEM had this service running at 50 to 60%. Did a search on Google and came up with this hit that looks like an exact match even down to the Core 2 Duo CPU that this other guy had. http://answers.microsoft.com/en-us/windows/forum/windows_7-performance/spoolsvexe-process-is-running-all-the-time-and/8268f671-51b8-42a3-9ce8-708e9686052d Going to try this fix and see what happens: Quote Hey Here is what the initial user posted for a problem: Quote spoolsv.exe process is running all the time and wasting 50% CPU's power (one of two cores). * Only difference between this persons post and my wifes system is that they claimed only a single core of the 2 cores running at 50%, and they are running Windows 7 Pro x86 with polish language set and my wife is running Windows 7 Home Premium 32-bit ( x86 ) English US language set. Also oddly this issue was reported back in 2009, so strange that she all of a sudden got hit with it now, but it looks like a problem is in the printer folder at this location that causes this behavior a corruption etc. Hopefully this is the solution. Time will tell. Attached screenshot of what I found at C:\windows\system32\spool\printers ..... wasnt expecting to find shockwave files in there... very odd. Also even though I told spoolsv.exe to stop in task manager including all process trees related to it, it mysteriously started itself back up locking these shockwave files from deletion because they were in use. With the window open to their location i once again told task manager to kill the spoolsv.exe process and all related tree processes and then quickly went to this location and DELETED the files successfully. Going to monitor the systems behavior today and ask for help if it mysteriously kicks back on again and starts eating 50% CPU again. Right now after 5 minutes it hasnt started back up yet like before. Did an additional search and came up with this: http://support.microsoft.com/kb/264662 Quote SYMPTOMS Malwarebytes and MSSE are still happy reporting system clean [recovering disk space, attachment deleted by admin] |
|
| 2330. |
Solve : Trying to get rid of ad.yieldmanager/allmplayerdownloads.com popup ads :(? |
|
Answer» Quote Still having some crazy ad issues (like random text words being linked to ads when I run the mouse over them) Here'smore about that. Only certain sites use them. Quote What should I do next?Please let me know how your computer is working.Ok. Well, in that case, most site I visit (including this one) have the in-text advertising. I also still have the popups (just got another one as I accessed this website) What browser do you see the pop-ups on? Here's some more information about in-text advertising.
Mozilla firefox. TDSSKiller log: (no hits ) ) 22:20:20.0372 24452 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 22:20:21.0401 24452 ============================================================ 22:20:21.0401 24452 Current date / time: 2013/05/21 22:20:21.0401 22:20:21.0401 24452 SystemInfo: 22:20:21.0401 24452 22:20:21.0401 24452 OS Version: 6.1.7601 ServicePack: 1.0 22:20:21.0401 24452 Product type: Workstation 22:20:21.0401 24452 ComputerName: TOSHIBAP870 22:20:21.0401 24452 UserName: Lynny 22:20:21.0401 24452 Windows directory: C:\windows 22:20:21.0401 24452 System windows directory: C:\windows 22:20:21.0401 24452 Running under WOW64 22:20:21.0401 24452 Processor architecture: Intel x64 22:20:21.0401 24452 Number of processors: 8 22:20:21.0401 24452 Page size: 0x1000 22:20:21.0402 24452 BOOT type: Normal boot 22:20:21.0402 24452 ============================================================ 22:20:23.0308 24452 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:20:23.0341 24452 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 22:20:23.0371 24452 ============================================================ 22:20:23.0371 24452 \Device\Harddisk0\DR0: 22:20:23.0371 24452 MBR partitions: 22:20:23.0371 24452 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x72C68800 22:20:23.0371 24452 \Device\Harddisk1\DR1: 22:20:23.0371 24452 MBR partitions: 22:20:23.0371 24452 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A385000 22:20:23.0371 24452 ============================================================ 22:20:23.0388 24452 C: <-> \Device\Harddisk0\DR0\Partition1 22:20:23.0405 24452 D: <-> \Device\Harddisk1\DR1\Partition1 22:20:23.0405 24452 ============================================================ 22:20:23.0405 24452 Initialize success 22:20:23.0405 24452 ============================================================ 22:23:18.0257 28324 ============================================================ 22:23:18.0257 28324 Scan started 22:23:18.0257 28324 Mode: Manual; 22:23:18.0257 28324 ============================================================ 22:23:18.0677 28324 ================ Scan system memory ======================== 22:23:18.0677 28324 System memory - ok 22:23:18.0677 28324 ================ Scan services ============================= 22:23:19.0087 28324 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys 22:23:19.0087 28324 1394ohci - ok 22:23:19.0157 28324 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\windows\system32\drivers\ACPI.sys 22:23:19.0167 28324 ACPI - ok 22:23:19.0187 28324 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys 22:23:19.0187 28324 AcpiPmi - ok 22:23:19.0567 28324 [ F040037B149FD0F5A5044AE563390FA7 ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 22:23:19.0567 28324 AdobeFlashPlayerUpdateSvc - ok 22:23:19.0637 28324 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\windows\system32\drivers\adp94xx.sys 22:23:19.0637 28324 adp94xx - ok 22:23:19.0746 28324 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\windows\system32\drivers\adpahci.sys 22:23:19.0750 28324 adpahci - ok 22:23:19.0778 28324 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\windows\system32\drivers\adpu320.sys 22:23:19.0780 28324 adpu320 - ok 22:23:19.0832 28324 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\windows\System32\aelupsvc.dll 22:23:19.0833 28324 AeLookupSvc - ok 22:23:19.0913 28324 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\windows\system32\drivers\afd.sys 22:23:19.0917 28324 AFD - ok 22:23:19.0954 28324 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\windows\system32\drivers\agp440.sys 22:23:19.0955 28324 agp440 - ok 22:23:19.0967 28324 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\windows\System32\alg.exe 22:23:19.0969 28324 ALG - ok 22:23:19.0993 28324 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\windows\system32\drivers\aliide.sys 22:23:19.0993 28324 aliide - ok 22:23:20.0053 28324 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\windows\system32\drivers\amdide.sys 22:23:20.0053 28324 amdide - ok 22:23:20.0093 28324 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\windows\system32\drivers\amdk8.sys 22:23:20.0093 28324 AmdK8 - ok 22:23:20.0123 28324 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\windows\system32\drivers\amdppm.sys 22:23:20.0123 28324 AmdPPM - ok 22:23:20.0153 28324 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\windows\system32\drivers\amdsata.sys 22:23:20.0153 28324 amdsata - ok 22:23:20.0203 28324 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\windows\system32\drivers\amdsbs.sys 22:23:20.0203 28324 amdsbs - ok 22:23:20.0233 28324 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\windows\system32\drivers\amdxata.sys 22:23:20.0233 28324 amdxata - ok 22:23:20.0263 28324 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\windows\system32\drivers\appid.sys 22:23:20.0263 28324 AppID - ok 22:23:20.0283 28324 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\windows\System32\appidsvc.dll 22:23:20.0283 28324 AppIDSvc - ok 22:23:20.0323 28324 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\windows\System32\appinfo.dll 22:23:20.0323 28324 Appinfo - ok 22:23:20.0423 28324 [ F401929EE0CC92BFE7F15161CA535383 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 22:23:20.0423 28324 Apple Mobile Device - ok 22:23:20.0473 28324 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\windows\system32\drivers\arc.sys 22:23:20.0473 28324 arc - ok 22:23:20.0513 28324 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\windows\system32\drivers\arcsas.sys 22:23:20.0513 28324 arcsas - ok 22:23:20.0583 28324 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys 22:23:20.0583 28324 AsyncMac - ok 22:23:20.0603 28324 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\windows\system32\drivers\atapi.sys 22:23:20.0603 28324 atapi - ok 22:23:20.0653 28324 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll 22:23:20.0663 28324 AudioEndpointBuilder - ok 22:23:20.0673 28324 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\windows\System32\Audiosrv.dll 22:23:20.0683 28324 AudioSrv - ok 22:23:20.0753 28324 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\windows\System32\AxInstSV.dll 22:23:20.0763 28324 AxInstSV - ok 22:23:20.0803 28324 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\windows\system32\drivers\bxvbda.sys 22:23:20.0813 28324 b06bdrv - ok 22:23:20.0833 28324 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys 22:23:20.0843 28324 b57nd60a - ok 22:23:20.0863 28324 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\windows\System32\bdesvc.dll 22:23:20.0863 28324 BDESVC - ok 22:23:20.0893 28324 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\windows\system32\drivers\Beep.sys 22:23:20.0893 28324 Beep - ok 22:23:20.0933 28324 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\windows\System32\bfe.dll 22:23:20.0943 28324 BFE - ok 22:23:20.0983 28324 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\windows\system32\qmgr.dll 22:23:21.0003 28324 BITS - ok 22:23:21.0023 28324 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys 22:23:21.0023 28324 blbdrive - ok 22:23:21.0093 28324 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 22:23:21.0103 28324 Bonjour Service - ok 22:23:21.0143 28324 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\windows\system32\DRIVERS\bowser.sys 22:23:21.0143 28324 bowser - ok 22:23:21.0173 28324 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys 22:23:21.0173 28324 BrFiltLo - ok 22:23:21.0193 28324 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys 22:23:21.0193 28324 BrFiltUp - ok 22:23:21.0223 28324 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\windows\system32\DRIVERS\bridge.sys 22:23:21.0223 28324 BridgeMP - ok 22:23:21.0253 28324 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\windows\System32\browser.dll 22:23:21.0263 28324 Browser - ok 22:23:21.0273 28324 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\windows\System32\Drivers\Brserid.sys 22:23:21.0273 28324 Brserid - ok 22:23:21.0293 28324 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys 22:23:21.0293 28324 BrSerWdm - ok 22:23:21.0313 28324 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys 22:23:21.0313 28324 BrUsbMdm - ok 22:23:21.0323 28324 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys 22:23:21.0323 28324 BrUsbSer - ok 22:23:21.0353 28324 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys 22:23:21.0353 28324 BTHMODEM - ok 22:23:21.0403 28324 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\windows\system32\bthserv.dll 22:23:21.0403 28324 bthserv - ok 22:23:21.0433 28324 catchme - ok 22:23:21.0463 28324 [ B8BD2BB284668C84865658C77574381A ] CDFS C:\windows\system32\DRIVERS\cdfs.sys 22:23:21.0463 28324 cdfs - ok 22:23:21.0493 28324 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys 22:23:21.0493 28324 cdrom - ok 22:23:21.0533 28324 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\windows\System32\certprop.dll 22:23:21.0533 28324 CertPropSvc - ok 22:23:21.0583 28324 [ 8FC9A59353F2C5D257613952AD697A2E ] CFUACProxy_boxsoftware C:\ProgramData\Clickfree\BoxSoftware\UACProxy.exe 22:23:21.0593 28324 CFUACProxy_boxsoftware - ok 22:23:21.0653 28324 [ B641F0302D444EB94509CFD998CF9FD8 ] cfWiMAXService C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe 22:23:21.0653 28324 cfWiMAXService - ok 22:23:21.0683 28324 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\windows\system32\drivers\circlass.sys 22:23:21.0683 28324 circlass - ok 22:23:21.0713 28324 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\windows\system32\CLFS.sys 22:23:21.0723 28324 CLFS - ok 22:23:21.0783 28324 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 22:23:21.0783 28324 clr_optimization_v2.0.50727_32 - ok 22:23:21.0813 28324 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 22:23:21.0813 28324 clr_optimization_v2.0.50727_64 - ok 22:23:21.0883 28324 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 22:23:21.0883 28324 clr_optimization_v4.0.30319_32 - ok 22:23:21.0933 28324 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 22:23:21.0933 28324 clr_optimization_v4.0.30319_64 - ok 22:23:21.0983 28324 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys 22:23:21.0983 28324 CmBatt - ok 22:23:21.0993 28324 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\windows\system32\drivers\cmdide.sys 22:23:21.0993 28324 cmdide - ok 22:23:22.0033 28324 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\windows\system32\Drivers\cng.sys 22:23:22.0043 28324 CNG - ok 22:23:22.0123 28324 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\windows\system32\drivers\compbatt.sys 22:23:22.0123 28324 Compbatt - ok 22:23:22.0143 28324 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\windows\system32\DRIVERS\CompositeBus.sys 22:23:22.0143 28324 CompositeBus - ok 22:23:22.0153 28324 COMSysApp - ok 22:23:22.0173 28324 [ 1263760C5F62674934C709C3EC31869D ] ConfigFree Service C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe 22:23:22.0173 28324 ConfigFree Service - ok 22:23:22.0273 28324 [ 723E3512D6D1FF75E5398981B38FCEF7 ] cphs C:\windows\SysWow64\IntelCpHeciSvc.exe 22:23:22.0273 28324 cphs - ok 22:23:22.0293 28324 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\windows\system32\drivers\crcdisk.sys 22:23:22.0293 28324 crcdisk - ok 22:23:22.0343 28324 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\windows\system32\cryptsvc.dll 22:23:22.0353 28324 CryptSvc - ok 22:23:22.0443 28324 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE 22:23:22.0443 28324 cvhsvc - ok 22:23:22.0473 28324 [ 066B4AD6534D1C36CB6E6E342DB05ED2 ] CXPOLARIS C:\windows\system32\drivers\cxRDU253S.sys 22:23:22.0473 28324 CXPOLARIS - ok 22:23:22.0513 28324 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\windows\system32\rpcss.dll 22:23:22.0523 28324 DcomLaunch - ok 22:23:22.0553 28324 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\windows\System32\defragsvc.dll 22:23:22.0563 28324 defragsvc - ok 22:23:22.0593 28324 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\windows\system32\Drivers\dfsc.sys 22:23:22.0593 28324 DfsC - ok 22:23:22.0623 28324 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\windows\system32\dhcpcore.dll 22:23:22.0623 28324 Dhcp - ok 22:23:22.0633 28324 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\windows\system32\drivers\discache.sys 22:23:22.0633 28324 discache - ok 22:23:22.0653 28324 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\windows\system32\drivers\disk.sys 22:23:22.0653 28324 Disk - ok 22:23:22.0673 28324 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\windows\System32\dnsrslvr.dll 22:23:22.0673 28324 Dnscache - ok 22:23:22.0713 28324 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\windows\System32\dot3svc.dll 22:23:22.0713 28324 dot3svc - ok 22:23:22.0733 28324 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\windows\system32\dps.dll 22:23:22.0733 28324 DPS - ok 22:23:22.0773 28324 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\windows\system32\drivers\drmkaud.sys 22:23:22.0773 28324 drmkaud - ok 22:23:22.0823 28324 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys 22:23:22.0853 28324 DXGKrnl - ok 22:23:22.0913 28324 [ D00EAE9C735A7DEE8049E50D73D25434 ] eamonm C:\windows\system32\DRIVERS\eamonm.sys 22:23:22.0913 28324 eamonm - ok 22:23:22.0943 28324 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\windows\System32\eapsvc.dll 22:23:22.0943 28324 EapHost - ok 22:23:23.0003 28324 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\windows\system32\drivers\evbda.sys 22:23:23.0063 28324 ebdrv - ok 22:23:23.0093 28324 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\windows\System32\lsass.exe 22:23:23.0093 28324 EFS - ok 22:23:23.0143 28324 [ E5EDDE3C8158DD0CBC5812F201DCDED0 ] ehdrv C:\windows\system32\DRIVERS\ehdrv.sys 22:23:23.0143 28324 ehdrv - ok 22:23:23.0203 28324 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\windows\ehome\ehRecvr.exe 22:23:23.0213 28324 ehRecvr - ok 22:23:23.0233 28324 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\windows\ehome\ehsched.exe 22:23:23.0233 28324 ehSched - ok 22:23:23.0333 28324 [ AD4FAADE819E0DA9933BEA7C01D2C763 ] ekrn C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe 22:23:23.0353 28324 ekrn - ok 22:23:23.0383 28324 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\windows\system32\drivers\elxstor.sys 22:23:23.0393 28324 elxstor - ok 22:23:23.0443 28324 [ 587F0F4145A1536A6E37EFD769B7665F ] epfw C:\windows\system32\DRIVERS\epfw.sys 22:23:23.0453 28324 epfw - ok 22:23:23.0463 28324 [ D2F812358EE8EE23CBB5C4DAFFB5B819 ] EpfwLWF C:\windows\system32\DRIVERS\EpfwLWF.sys 22:23:23.0463 28324 EpfwLWF - ok 22:23:23.0473 28324 [ 34BF55D69AB74D14C7E7A17259CB7DF8 ] epfwwfp C:\windows\system32\DRIVERS\epfwwfp.sys 22:23:23.0473 28324 epfwwfp - ok 22:23:23.0493 28324 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\windows\system32\drivers\errdev.sys 22:23:23.0493 28324 ErrDev - ok 22:23:23.0563 28324 [ DF96C3CD6AE15F6D0A6BCB70F9C1E88D ] esgiguard C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys 22:23:23.0563 28324 esgiguard - ok 22:23:23.0583 28324 [ 3B32CAA07D672F8A2E0DF5CB3A873F45 ] EsgScanner C:\windows\system32\DRIVERS\EsgScanner.sys 22:23:23.0583 28324 EsgScanner - ok 22:23:23.0613 28324 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\windows\system32\es.dll 22:23:23.0613 28324 EventSystem - ok 22:23:23.0653 28324 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\windows\system32\drivers\exfat.sys 22:23:23.0663 28324 exfat - ok 22:23:23.0693 28324 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\windows\system32\drivers\fastfat.sys 22:23:23.0703 28324 fastfat - ok 22:23:23.0743 28324 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\windows\system32\fxssvc.exe 22:23:23.0753 28324 Fax - ok 22:23:23.0783 28324 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\windows\system32\drivers\fdc.sys 22:23:23.0783 28324 fdc - ok 22:23:23.0803 28324 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\windows\system32\fdPHost.dll 22:23:23.0803 28324 fdPHost - ok 22:23:23.0813 28324 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\windows\system32\fdrespub.dll 22:23:23.0813 28324 FDResPub - ok 22:23:23.0833 28324 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\windows\system32\drivers\fileinfo.sys 22:23:23.0833 28324 FileInfo - ok 22:23:23.0843 28324 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\windows\system32\drivers\filetrace.sys 22:23:23.0843 28324 Filetrace - ok 22:23:23.0863 28324 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\windows\system32\drivers\flpydisk.sys 22:23:23.0863 28324 flpydisk - ok 22:23:23.0903 28324 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\windows\system32\drivers\fltmgr.sys 22:23:23.0903 28324 FltMgr - ok 22:23:24.0013 28324 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\windows\system32\FntCache.dll 22:23:24.0023 28324 FontCache - ok 22:23:24.0073 28324 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 22:23:24.0083 28324 FontCache3.0.0.0 - ok 22:23:24.0093 28324 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\windows\system32\drivers\FsDepends.sys 22:23:24.0093 28324 FsDepends - ok 22:23:24.0123 28324 [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr C:\windows\system32\DRIVERS\fssfltr.sys 22:23:24.0123 28324 fssfltr - ok 22:23:24.0173 28324 [ 4CE9DAC1518FF7E77BD213E6394B9D77 ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe 22:23:24.0193 28324 fsssvc - ok 22:23:24.0223 28324 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys 22:23:24.0223 28324 Fs_Rec - ok 22:23:24.0273 28324 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys 22:23:24.0273 28324 fvevol - ok 22:23:24.0313 28324 [ 60ACB128E64C35C2B4E4AAB1B0A5C293 ] FwLnk C:\windows\system32\DRIVERS\FwLnk.sys 22:23:24.0313 28324 FwLnk - ok 22:23:24.0333 28324 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys 22:23:24.0333 28324 gagp30kx - ok 22:23:24.0363 28324 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe 22:23:24.0383 28324 GamesAppService - ok 22:23:24.0423 28324 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys 22:23:24.0423 28324 GEARAspiWDM - ok 22:23:24.0443 28324 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\windows\System32\gpsvc.dll 22:23:24.0453 28324 gpsvc - ok 22:23:24.0543 28324 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:23:24.0543 28324 gupdate - ok 22:23:24.0553 28324 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 22:23:24.0563 28324 gupdatem - ok 22:23:24.0583 28324 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 22:23:24.0593 28324 gusvc - ok 22:23:24.0603 28324 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys 22:23:24.0603 28324 hcw85cir - ok 22:23:24.0623 28324 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys 22:23:24.0633 28324 HdAudAddService - ok 22:23:24.0653 28324 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\windows\system32\DRIVERS\HDAudBus.sys 22:23:24.0653 28324 HDAudBus - ok 22:23:24.0663 28324 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\windows\system32\drivers\HidBatt.sys 22:23:24.0663 28324 HidBatt - ok 22:23:24.0683 28324 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\windows\system32\drivers\hidbth.sys 22:23:24.0683 28324 HidBth - ok 22:23:24.0693 28324 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\windows\system32\drivers\hidir.sys 22:23:24.0703 28324 HidIr - ok 22:23:24.0713 28324 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\windows\System32\hidserv.dll 22:23:24.0713 28324 hidserv - ok 22:23:24.0743 28324 [ 794868B22EC45220F91D077FEC3EB1F8 ] hidshim C:\windows\system32\DRIVERS\hidshim.sys 22:23:24.0753 28324 hidshim - ok 22:23:24.0783 28324 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\windows\system32\DRIVERS\hidusb.sys 22:23:24.0793 28324 HidUsb - ok 22:23:24.0813 28324 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\windows\system32\kmsvc.dll 22:23:24.0813 28324 hkmsvc - ok 22:23:24.0823 28324 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\windows\system32\ListSvc.dll 22:23:24.0833 28324 HomeGroupListener - ok 22:23:24.0853 28324 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\windows\system32\provsvc.dll 22:23:24.0853 28324 HomeGroupProvider - ok 22:23:24.0873 28324 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys 22:23:24.0873 28324 HpSAMD - ok 22:23:24.0923 28324 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\windows\system32\drivers\HTTP.sys 22:23:24.0933 28324 HTTP - ok 22:23:24.0943 28324 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys 22:23:24.0953 28324 hwpolicy - ok 22:23:24.0983 28324 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys 22:23:24.0983 28324 i8042prt - ok 22:23:25.0033 28324 [ C224331A54571C8C9162F7714400BBBD ] iaStor C:\windows\system32\DRIVERS\iaStor.sys 22:23:25.0033 28324 iaStor - ok 22:23:25.0073 28324 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\windows\system32\drivers\iaStorV.sys 22:23:25.0083 28324 iaStorV - ok 22:23:25.0113 28324 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 22:23:25.0153 28324 idsvc - ok 22:23:25.0393 28324 [ 9AA61DC7AA32C1D1260C4267FF07E0C1 ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys 22:23:25.0613 28324 igfx - ok 22:23:25.0623 28324 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\windows\system32\drivers\iirsp.sys 22:23:25.0623 28324 iirsp - ok 22:23:25.0653 28324 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\windows\System32\ikeext.dll 22:23:25.0683 28324 IKEEXT - ok 22:23:25.0783 28324 [ 8BD7EB761F4341E6F9FD066099F24B01 ] IntcAzAudAddService C:\windows\system32\drivers\RTKVHD64.sys 22:23:25.0853 28324 IntcAzAudAddService - ok 22:23:25.0913 28324 [ 6C9FFFECA9FED31347D211C5D1FFBD2D ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys 22:23:25.0923 28324 IntcDAud - ok 22:23:26.0003 28324 [ 7C76466F4E0F76CE259C6005D161E9E8 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe 22:23:26.0013 28324 Intel(R) Capability Licensing Service Interface - ok 22:23:26.0053 28324 [ D7467E57549960468E0CA85C17185B12 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 22:23:26.0053 28324 Intel(R) ME Service - ok 22:23:26.0073 28324 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\windows\system32\drivers\intelide.sys 22:23:26.0073 28324 intelide - ok 22:23:26.0103 28324 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys 22:23:26.0103 28324 intelppm - ok 22:23:26.0133 28324 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\windows\system32\ipbusenum.dll 22:23:26.0133 28324 IPBusEnum - ok 22:23:26.0143 28324 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys 22:23:26.0143 28324 IpFilterDriver - ok 22:23:26.0183 28324 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\windows\System32\iphlpsvc.dll 22:23:26.0213 28324 iphlpsvc - ok 22:23:26.0243 28324 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys 22:23:26.0243 28324 IPMIDRV - ok 22:23:26.0253 28324 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\windows\system32\drivers\ipnat.sys 22:23:26.0263 28324 IPNAT - ok 22:23:26.0313 28324 [ A9AB99EE7D39725EAFEC82732D2B3271 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 22:23:26.0333 28324 iPod Service - ok 22:23:26.0363 28324 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\windows\system32\drivers\irenum.sys 22:23:26.0363 28324 IRENUM - ok 22:23:26.0363 28324 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\windows\system32\drivers\isapnp.sys 22:23:26.0363 28324 isapnp - ok 22:23:26.0393 28324 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys 22:23:26.0393 28324 iScsiPrt - ok 22:23:26.0433 28324 [ 846354992EBB373F452EB9182D501B08 ] iusb3hcs C:\windows\system32\DRIVERS\iusb3hcs.sys 22:23:26.0433 28324 iusb3hcs - ok 22:23:26.0453 28324 [ 1D88A23853387D34D52CC8F9DDBFC56C ] iusb3hub C:\windows\system32\DRIVERS\iusb3hub.sys 22:23:26.0453 28324 iusb3hub - ok 22:23:26.0483 28324 [ FC5EFD7C797DF19DFB999F0605A7924E ] iusb3xhc C:\windows\system32\DRIVERS\iusb3xhc.sys 22:23:26.0503 28324 iusb3xhc - ok 22:23:26.0533 28324 [ 604A8615BB3D7064197A0563C799B938 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe 22:23:26.0543 28324 jhi_service - ok 22:23:26.0563 28324 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys 22:23:26.0563 28324 kbdclass - ok 22:23:26.0583 28324 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\windows\system32\DRIVERS\kbdhid.sys 22:23:26.0583 28324 kbdhid - ok 22:23:26.0593 28324 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\windows\system32\lsass.exe 22:23:26.0593 28324 KeyIso - ok 22:23:26.0623 28324 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys 22:23:26.0623 28324 KSecDD - ok 22:23:26.0643 28324 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys 22:23:26.0643 28324 KSecPkg - ok 22:23:26.0673 28324 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\windows\system32\drivers\ksthunk.sys 22:23:26.0673 28324 ksthunk - ok 22:23:26.0703 28324 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\windows\system32\msdtckrm.dll 22:23:26.0703 28324 KtmRm - ok 22:23:26.0733 28324 [ 3CE6A9BEF066BF9488E6BC4D6C62F77E ] L1C C:\windows\system32\DRIVERS\L1C62x64.sys 22:23:26.0733 28324 L1C - ok 22:23:26.0773 28324 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\windows\System32\srvsvc.dll 22:23:26.0773 28324 LanmanServer - ok 22:23:26.0783 28324 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\windows\System32\wkssvc.dll 22:23:26.0783 28324 LanmanWorkstation - ok 22:23:26.0813 28324 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys 22:23:26.0823 28324 lltdio - ok 22:23:26.0863 28324 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\windows\System32\lltdsvc.dll 22:23:26.0863 28324 lltdsvc - ok 22:23:26.0883 28324 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\windows\System32\lmhsvc.dll 22:23:26.0893 28324 lmhosts - ok 22:23:26.0933 28324 [ AB41542FA180CB3317F597ED7E7D5C5D ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 22:23:26.0933 28324 LMS - ok 22:23:26.0973 28324 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys 22:23:26.0973 28324 LSI_FC - ok 22:23:26.0993 28324 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys 22:23:26.0993 28324 LSI_SAS - ok 22:23:27.0003 28324 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys 22:23:27.0013 28324 LSI_SAS2 - ok 22:23:27.0013 28324 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys 22:23:27.0023 28324 LSI_SCSI - ok 22:23:27.0053 28324 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\windows\system32\drivers\luafv.sys 22:23:27.0063 28324 luafv - ok 22:23:27.0113 28324 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\windows\system32\drivers\mbam.sys 22:23:27.0113 28324 MBAMProtector - ok 22:23:27.0193 28324 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe 22:23:27.0193 28324 MBAMScheduler - ok 22:23:27.0223 28324 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe 22:23:27.0233 28324 MBAMService - ok 22:23:27.0273 28324 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll 22:23:27.0273 28324 Mcx2Svc - ok 22:23:27.0293 28324 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\windows\system32\drivers\megasas.sys 22:23:27.0293 28324 megasas - ok 22:23:27.0343 28324 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\windows\system32\drivers\MegaSR.sys 22:23:27.0353 28324 MegaSR - ok 22:23:27.0383 28324 [ 6B01B7414A105B9E51652089A03027CF ] MEIx64 C:\windows\system32\DRIVERS\HECIx64.sys 22:23:27.0383 28324 MEIx64 - ok 22:23:27.0423 28324 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\windows\system32\mmcss.dll 22:23:27.0423 28324 MMCSS - ok 22:23:27.0453 28324 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\windows\system32\drivers\modem.sys 22:23:27.0463 28324 Modem - ok 22:23:27.0483 28324 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\windows\system32\DRIVERS\monitor.sys 22:23:27.0483 28324 monitor - ok 22:23:27.0513 28324 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys 22:23:27.0513 28324 mouclass - ok 22:23:27.0543 28324 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\windows\system32\DRIVERS\mouhid.sys 22:23:27.0543 28324 mouhid - ok 22:23:27.0563 28324 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\windows\system32\drivers\mountmgr.sys 22:23:27.0563 28324 mountmgr - ok 22:23:27.0603 28324 [ 7EDBBB9351A38C6BB0FE98CFD44DB430 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 22:23:27.0603 28324 MozillaMaintenance - ok 22:23:27.0623 28324 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\windows\system32\drivers\mpio.sys 22:23:27.0623 28324 mpio - ok 22:23:27.0643 28324 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys 22:23:27.0643 28324 mpsdrv - ok 22:23:27.0673 28324 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\windows\system32\mpssvc.dll 22:23:27.0693 28324 MpsSvc - ok 22:23:27.0713 28324 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\windows\system32\drivers\mrxdav.sys 22:23:27.0713 28324 MRxDAV - ok 22:23:27.0723 28324 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys 22:23:27.0723 28324 mrxsmb - ok 22:23:27.0763 28324 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys 22:23:27.0763 28324 mrxsmb10 - ok 22:23:27.0773 28324 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys 22:23:27.0773 28324 mrxsmb20 - ok 22:23:27.0783 28324 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\windows\system32\DRIVERS\msahci.sys 22:23:27.0783 28324 msahci - ok 22:23:27.0803 28324 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\windows\system32\drivers\msdsm.sys 22:23:27.0803 28324 msdsm - ok 22:23:27.0823 28324 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\windows\System32\msdtc.exe 22:23:27.0823 28324 MSDTC - ok 22:23:27.0833 28324 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\windows\system32\drivers\Msfs.sys 22:23:27.0833 28324 Msfs - ok 22:23:27.0853 28324 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys 22:23:27.0853 28324 mshidkmdf - ok 22:23:27.0863 28324 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\windows\system32\drivers\msisadrv.sys 22:23:27.0863 28324 msisadrv - ok 22:23:27.0913 28324 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\windows\system32\iscsiexe.dll 22:23:27.0913 28324 MSiSCSI - ok 22:23:27.0913 28324 msiserver - ok 22:23:27.0963 28324 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys 22:23:27.0963 28324 MSKSSRV - ok 22:23:27.0973 28324 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys 22:23:27.0973 28324 MSPCLOCK - ok 22:23:27.0993 28324 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\windows\system32\drivers\MSPQM.sys 22:23:27.0993 28324 MSPQM - ok 22:23:28.0023 28324 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\windows\system32\drivers\MsRPC.sys 22:23:28.0023 28324 MsRPC - ok 22:23:28.0043 28324 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\windows\system32\DRIVERS\mssmbios.sys 22:23:28.0043 28324 mssmbios - ok 22:23:28.0086 28324 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\windows\system32\drivers\MSTEE.sys 22:23:28.0109 28324 MSTEE - ok 22:23:28.0119 28324 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\windows\system32\drivers\MTConfig.sys 22:23:28.0120 28324 MTConfig - ok 22:23:28.0135 28324 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\windows\system32\Drivers\mup.sys 22:23:28.0136 28324 Mup - ok 22:23:28.0160 28324 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\windows\system32\qagentRT.dll 22:23:28.0165 28324 napagent - ok 22:23:28.0205 28324 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys 22:23:28.0209 28324 NativeWifiP - ok 22:23:28.0261 28324 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\windows\system32\drivers\ndis.sys 22:23:28.0284 28324 NDIS - ok 22:23:28.0317 28324 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys 22:23:28.0318 28324 NdisCap - ok 22:23:28.0332 28324 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys 22:23:28.0333 28324 NdisTapi - ok 22:23:28.0354 28324 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys 22:23:28.0354 28324 Ndisuio - ok 22:23:28.0364 28324 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys 22:23:28.0364 28324 NdisWan - ok 22:23:28.0384 28324 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\windows\system32\drivers\NDProxy.sys 22:23:28.0384 28324 NDProxy - ok 22:23:28.0435 28324 [ 6F4607E2333FE21E9E3FF8133A88B35B ] Netaapl C:\windows\system32\DRIVERS\netaapl64.sys 22:23:28.0436 28324 Netaapl - ok 22:23:28.0460 28324 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys 22:23:28.0462 28324 NetBIOS - ok 22:23:28.0481 28324 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\windows\system32\DRIVERS\netbt.sys 22:23:28.0483 28324 NetBT - ok 22:23:28.0499 28324 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\windows\system32\lsass.exe 22:23:28.0500 28324 Netlogon - ok 22:23:28.0533 28324 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\windows\System32\netman.dll 22:23:28.0538 28324 Netman - ok 22:23:28.0553 28324 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\windows\System32\netprofm.dll 22:23:28.0558 28324 netprofm - ok 22:23:28.0576 28324 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe 22:23:28.0578 28324 NetTcpPortSharing - ok 22:23:28.0607 28324 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys 22:23:28.0609 28324 nfrd960 - ok 22:23:28.0639 28324 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\windows\System32\nlasvc.dll 22:23:28.0643 28324 NlaSvc - ok 22:23:28.0680 28324 Norton PC Checkup Application Launcher - ok 22:23:28.0707 28324 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\windows\system32\drivers\Npfs.sys 22:23:28.0708 28324 Npfs - ok 22:23:28.0729 28324 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\windows\system32\nsisvc.dll 22:23:28.0731 28324 nsi - ok 22:23:28.0745 28324 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys 22:23:28.0746 28324 nsiproxy - ok 22:23:28.0799 28324 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\windows\system32\drivers\Ntfs.sys 22:23:28.0822 28324 Ntfs - ok 22:23:28.0852 28324 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\windows\system32\drivers\Null.sys 22:23:28.0852 28324 Null - ok 22:23:28.0861 28324 [ E00CC5F0D26316190FA4BA19B393E37C ] nuvotonhidcir C:\windows\system32\DRIVERS\nuvotonhidcir.sys 22:23:28.0862 28324 nuvotonhidcir - ok 22:23:29.0289 28324 [ 12E18E5F438AAD55DAF77E127C0EA25B ] nvlddmkm C:\windows\system32\DRIVERS\nvlddmkm.sys 22:23:29.0509 28324 nvlddmkm - ok 22:23:29.0529 28324 [ 186290C63FEB79C199A620E36705F9EE ] nvpciflt C:\windows\system32\DRIVERS\nvpciflt.sys 22:23:29.0529 28324 nvpciflt - ok 22:23:29.0559 28324 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\windows\system32\drivers\nvraid.sys 22:23:29.0569 28324 nvraid - ok 22:23:29.0589 28324 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\windows\system32\drivers\nvstor.sys 22:23:29.0589 28324 nvstor - ok 22:23:29.0629 28324 [ 33A2052D60D4EA6599CEE1D6853D0A42 ] nvsvc C:\windows\system32\nvvsvc.exe 22:23:29.0649 28324 nvsvc - ok 22:23:29.0725 28324 [ FD6F5B42DB429FD1AE1A4483DB4DD2E0 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 22:23:29.0760 28324 nvUpdatusService - ok 22:23:29.0775 28324 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\windows\system32\drivers\nv_agp.sys 22:23:29.0777 28324 nv_agp - ok 22:23:29.0808 28324 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys 22:23:29.0810 28324 ohci1394 - ok 22:23:29.0852 28324 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE 22:23:29.0854 28324 ose - ok 22:23:30.0028 28324 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 22:23:30.0108 28324 osppsvc - ok 22:23:30.0148 28324 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\windows\system32\pnrpsvc.dll 22:23:30.0158 28324 p2pimsvc - ok 22:23:30.0168 28324 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\windows\system32\p2psvc.dll 22:23:30.0178 28324 p2psvc - ok 22:23:30.0268 28324 [ F9AAE0A3C086DB9E83F38BDA4C7C61E2 ] PACSPTISVR-Sound_Organizer C:\Program Files (x86)\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe 22:23:30.0268 28324 PACSPTISVR-Sound_Organizer - ok 22:23:30.0298 28324 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\windows\system32\drivers\parport.sys 22:23:30.0308 28324 Parport - ok 22:23:30.0338 28324 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\windows\system32\drivers\partmgr.sys 22:23:30.0338 28324 partmgr - ok 22:23:30.0358 28324 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\windows\System32\pcasvc.dll 22:23:30.0358 28324 PcaSvc - ok 22:23:30.0388 28324 [ 2F86BE1818C2D7AC90478E3323EE7FCB ] PCCUJobMgr C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.15.77\ccSvcHst.exe 22:23:30.0388 28324 PCCUJobMgr - ok 22:23:30.0418 28324 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\windows\system32\drivers\pci.sys 22:23:30.0418 28324 pci - ok 22:23:30.0428 28324 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\windows\system32\DRIVERS\pciide.sys 22:23:30.0428 28324 pciide - ok 22:23:30.0438 28324 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\windows\system32\drivers\pcmcia.sys 22:23:30.0438 28324 pcmcia - ok 22:23:30.0458 28324 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\windows\system32\drivers\pcw.sys 22:23:30.0458 28324 pcw - ok 22:23:30.0478 28324 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\windows\system32\drivers\peauth.sys 22:23:30.0498 28324 PEAUTH - ok 22:23:30.0558 28324 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\windows\SysWow64\perfhost.exe 22:23:30.0558 28324 PerfHost - ok 22:23:30.0588 28324 [ 91111CEBBDE8015E822C46120ED9537C ] PGEffect C:\windows\system32\DRIVERS\pgeffect.sys 22:23:30.0608 28324 PGEffect - ok 22:23:30.0639 28324 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\windows\system32\pla.dll 22:23:30.0659 28324 pla - ok 22:23:30.0699 28324 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\windows\system32\umpnpmgr.dll 22:23:30.0709 28324 PlugPlay - ok 22:23:30.0719 28324 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll 22:23:30.0719 28324 PNRPAutoReg - ok 22:23:30.0729 28324 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\windows\system32\pnrpsvc.dll 22:23:30.0729 28324 PNRPsvc - ok 22:23:30.0759 28324 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\windows\System32\ipsecsvc.dll 22:23:30.0759 28324 PolicyAgent - ok 22:23:30.0789 28324 [ A2CCA4FB273E6050F17A0A416CFF2FCD ] Power C:\windows\system32\umpo.dll 22:23:30.0789 28324 Power - ok 22:23:30.0819 28324 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys 22:23:30.0819 28324 PptpMiniport - ok 22:23:30.0839 28324 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\windows\system32\drivers\processr.sys 22:23:30.0839 28324 Processor - ok 22:23:30.0889 28324 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\windows\system32\profsvc.dll 22:23:30.0889 28324 ProfSvc - ok 22:23:30.0909 28324 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\windows\system32\lsass.exe 22:23:30.0909 28324 ProtectedStorage - ok 22:23:30.0929 28324 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\windows\system32\DRIVERS\pacer.sys 22:23:30.0929 28324 Psched - ok 22:23:30.0969 28324 [ F036CFB275D0C55F4E45FBBF5F98B3C8 ] PSI_SVC_2 c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe 22:23:30.0979 28324 PSI_SVC_2 - ok 22:23:31.0039 28324 [ 07D57B890DD5693A6AB660CBAE8F91B4 ] PxHlpa64 C:\windows\system32\Drivers\PxHlpa64.sys 22:23:31.0039 28324 PxHlpa64 - ok 22:23:31.0069 28324 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\windows\system32\drivers\ql2300.sys 22:23:31.0089 28324 ql2300 - ok 22:23:31.0109 28324 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\windows\system32\drivers\ql40xx.sys 22:23:31.0109 28324 ql40xx - ok 22:23:31.0129 28324 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\windows\system32\qwave.dll 22:23:31.0139 28324 QWAVE - ok 22:23:31.0149 28324 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys 22:23:31.0149 28324 QWAVEdrv - ok 22:23:31.0159 28324 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys 22:23:31.0159 28324 RasAcd - ok 22:23:31.0199 28324 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys 22:23:31.0199 28324 RasAgileVpn - ok 22:23:31.0209 28324 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\windows\System32\rasauto.dll 22:23:31.0209 28324 RasAuto - ok 22:23:31.0229 28324 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys 22:23:31.0229 28324 Rasl2tp - ok 22:23:31.0249 28324 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\windows\System32\rasmans.dll 22:23:31.0249 28324 RasMan - ok 22:23:31.0259 28324 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys 22:23:31.0259 28324 RasPppoe - ok 22:23:31.0279 28324 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys 22:23:31.0279 28324 RasSstp - ok 22:23:31.0299 28324 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\windows\system32\DRIVERS\rdbss.sys 22:23:31.0309 28324 rdbss - ok 22:23:31.0319 28324 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\windows\system32\drivers\rdpbus.sys 22:23:31.0319 28324 rdpbus - ok 22:23:31.0329 28324 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys 22:23:31.0329 28324 RDPCDD - ok 22:23:31.0359 28324 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys 22:23:31.0359 28324 RDPENCDD - ok 22:23:31.0369 28324 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys 22:23:31.0369 28324 RDPREFMP - ok 22:23:31.0409 28324 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\windows\system32\drivers\RDPWD.sys 22:23:31.0429 28324 RDPWD - ok 22:23:31.0469 28324 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\windows\system32\drivers\rdyboost.sys 22:23:31.0469 28324 rdyboost - ok 22:23:31.0499 28324 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\windows\System32\mprdim.dll 22:23:31.0499 28324 RemoteAccess - ok 22:23:31.0509 28324 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\windows\system32\regsvc.dll 22:23:31.0519 28324 RemoteRegistry - ok 22:23:31.0529 28324 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\windows\System32\RpcEpMap.dll 22:23:31.0539 28324 RpcEptMapper - ok 22:23:31.0549 28324 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\windows\system32\locator.exe 22:23:31.0559 28324 RpcLocator - ok 22:23:31.0569 28324 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\windows\system32\rpcss.dll 22:23:31.0569 28324 RpcSs - ok 22:23:31.0609 28324 [ 40447D89F56780C49AC2EC22A05D5727 ] RSP2STOR C:\windows\system32\DRIVERS\RtsP2Stor.sys 22:23:31.0609 28324 RSP2STOR - ok 22:23:31.0639 28324 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\windows\system32\DRIVERS\rspndr.sys 22:23:31.0639 28324 rspndr - ok 22:23:31.0679 28324 [ B708BBAB80C60EE613DEE52A1A0A8538 ] RtkBtFilter C:\windows\system32\DRIVERS\RtkBtfilter.sys 22:23:31.0679 28324 RtkBtFilter - ok 22:23:31.0739 28324 [ 8328468053CEDFD7198BEE178C501989 ] RTL8192Ce C:\windows\system32\DRIVERS\rtwlane.sys 22:23:31.0779 28324 RTL8192Ce - ok 22:23:31.0799 28324 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\windows\system32\lsass.exe 22:23:31.0799 28324 SamSs - ok 22:23:31.0829 28324 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\windows\system32\drivers\sbp2port.sys 22:23:31.0829 28324 sbp2port - ok 22:23:31.0879 28324 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\windows\System32\SCardSvr.dll 22:23:31.0879 28324 SCardSvr - ok 22:23:31.0889 28324 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\windows\system32\DRIVERS\scfilter.sys 22:23:31.0889 28324 scfilter - ok 22:23:31.0909 28324 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\windows\system32\schedsvc.dll 22:23:31.0929 28324 Schedule - ok 22:23:31.0949 28324 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\windows\System32\certprop.dll 22:23:31.0949 28324 SCPolicySvc - ok 22:23:31.0969 28324 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\windows\System32\SDRSVC.dll 22:23:31.0969 28324 SDRSVC - ok 22:23:31.0999 28324 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\windows\system32\drivers\secdrv.sys 22:23:31.0999 28324 secdrv - ok 22:23:32.0009 28324 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\windows\system32\seclogon.dll 22:23:32.0009 28324 seclogon - ok 22:23:32.0019 28324 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\windows\system32\sens.dll 22:23:32.0019 28324 SENS - ok 22:23:32.0049 28324 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\windows\system32\sensrsvc.dll 22:23:32.0049 28324 SensrSvc - ok 22:23:32.0079 28324 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\windows\system32\drivers\serenum.sys 22:23:32.0079 28324 Serenum - ok 22:23:32.0109 28324 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] SERIAL C:\windows\system32\drivers\serial.sys 22:23:32.0109 28324 Serial - ok 22:23:32.0129 28324 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\windows\system32\drivers\sermouse.sys 22:23:32.0129 28324 sermouse - ok 22:23:32.0169 28324 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\windows\system32\sessenv.dll 22:23:32.0169 28324 SessionEnv - ok 22:23:32.0179 28324 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\windows\system32\drivers\sffdisk.sys 22:23:32.0179 28324 sffdisk - ok 22:23:32.0209 28324 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys 22:23:32.0209 28324 sffp_mmc - ok 22:23:32.0229 28324 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys 22:23:32.0249 28324 sffp_sd - ok 22:23:32.0259 28324 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\windows\system32\drivers\sfloppy.sys 22:23:32.0259 28324 sfloppy - ok 22:23:32.0389 28324 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\windows\system32\DRIVERS\Sftfslh.sys 22:23:32.0409 28324 Sftfs - ok 22:23:32.0469 28324 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe 22:23:32.0479 28324 sftlist - ok 22:23:32.0499 28324 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\windows\system32\DRIVERS\Sftplaylh.sys 22:23:32.0499 28324 Sftplay - ok 22:23:32.0529 28324 [ 617E29A0B0A2807466560Have you configured FireFox to not allow pop-ups?Yes. I've also placed yieldmanager and ads.yieldmanager on my block list, but to no availAre you getting pop-ups with Internet Explorer? If the answer is no then I would suggest your uninstall and re-install FireFox.IE... kind of doesn't work, which is scary. It just doesn't load any new pages. In-text ads now appearing on http://www.smh.com.au/ articles and some of my university websites, which I'm pretty sure didn't happen before.Those in-text ads are probably caused by add-ons. Disable all your add-ons to see if they disappear. MS Fix-It should repair IE. Please download and run MS Fix-it from here. I ran MS-Fix-it, and IE still appears to not work/doesn't load anything. #^#$^ I now have a Superfish popup too I haven't downloaded anything new in the past few weeks, I swear! I have no idea where this is coming from. * Googled how to remove Addons - there was something called "videosaver" there. Disabled this. Touch wood, so far so good on Firefox (IE still not working)... no popup adds so far and a lot of the mysterious in-text advertising has gone away (I checked some of the usual "as of recently, always some here" haunts like Wikipedia and my university web page just to be sure)When you say IE will not work, what exactly does it do? Did you try running it as Admin? |
|
| 2331. |
Solve : using ubuntu to remove malware? |
|
Answer» Whenever I suspect that my flash drive has been infected what I GENERALLY do is, boot my system in Ubuntu, plug the flash drive, look out for suspicious files and delete them. This route has been fail safe for me. If there is a .exe file I open them using gedit and if I feel that it looks weird I delete it right away. can you name some companies/organisations who can restore the data professionally? (I'm looking for ones like Kroll Ontrack)Sorry, no. Quote The infected pendrive has been formatted and filled with the PARTIALLY recovered data (only images). Is it still possible to try and recover the original data(docs and ppts)?If it has been reformatted they're probably gone. Quote What could be the possible reasons for the partial recovery?I can't say since I wasn't there. Quote Are there malware that can work on both Windows AND Ubuntu?Hackers don't usually create malware for OS's like Ubuntu or Apple because they are not that popular.Thank you for previous post. I still require some clarifications. 1. you can't name them because there aren't any or is it because of the forum restrictions? (Trust me I have googled for such centers but having a TOUGH time finding any reliable sources) 2. I've heard of 'data restoration' wherein people try to recover data from burnt/damaged hard disks. And that, eventhough a disk has been reformatted, it is still possible to recover the data. Is it applicable only to hard disks and not flash drives? Additional Question : Is my method of using ubuntu to delete suspicious looking files from my affected flash drive, potentially dangerous?Quote 2. I've heard of 'data restoration' wherein people try to recover data from burnt/damaged hard disks. And that, eventhough a disk has been reformatted, it is still possible to recover the data. Is it applicable only to hard disks and not flash drives?Yes, it's possible. Please read this. Quote Is my method of using ubuntu to delete suspicious looking files from my affected flash drive, potentially dangerous?It's not a very good method of cleaning a computer since you don't know the function of the files you are deleting. |
|
| 2332. |
Solve : What Avast site is real?? |
|
Answer» Avast has given good free protection. But I had to install WINDOWS 7 again on this laptop.So I went to Google to find the Avast write. I was not sure which was the RIGHT one. I wanted the free version of 2013, the the 2014 paid version. Well, I made the wrong choice. I stopped the installation, but too late. I loaded Malearebytes from a Flash CARD. Ran it. Got 71 puppies. Found a COPY of Avast on by desktop, put it on the laptop. Now I am OK. Close call. So my quotation is, Why does Google let the criminals do that? The crooks were allowed to advertise with the good name of Avast to LOAD up a bunch of trash. Is this sort of deception g ever going to stop? Google is just a search engine. You should use WOT to keep you safe from dangerous sites. WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. |
|
| 2333. |
Solve : msngames says your browser or operating system does not meet min rquirements? |
|
Answer» here ya go. thanks. R2 CLKMSVC10_9EC60124;CyberLink Product - 2011/12/02 12:23;c:\program files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe;c:\program files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe R2 X5XSEx_Pr143;X5XSEx_Pr143;c:\program files (x86)\Free Ride Games\X5XSEx_Pr143.Sys;c:\program files (x86)\Free Ride Games\X5XSEx_Pr143.Sys R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys;c:\windows\SYSNATIVE\drivers\HipShieldK.sys R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe R3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys;c:\windows\SYSNATIVE\drivers\Impcd.sys R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe;c:\progra~1\mcafee\msc\mcawfwk.exe R3 mfencrk;McAfee Inc. mfencrk;c:\windows\system32\DRIVERS\mfencrk.sys;c:\windows\SYSNATIVE\DRIVERS\mfencrk.sys R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys;c:\windows\SYSNATIVE\drivers\mfewfpk.sys S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe S2 dlee_device;dlee_device;c:\windows\system32\dleecoms.exe;c:\windows\SYSNATIVE\dleecoms.exe S2 dleeCATSCustConnectService;dleeCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\dleeserv.exe;c:\windows\SYSNATIVE\spool\DRIVERS\x64\3\\dleeserv.exe S2 HomeNetSvc;McAfee Home Network;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe S2 McAPExe;McAfee AP Service;c:\program files\McAfee\MSC\McAPExe.exe;c:\program files\McAfee\MSC\McAPExe.exe S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe S2 mcpltsvc;McAfee Platform Services;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe;c:\program files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe S2 mfecore;McAfee Anti-Malware Core;c:\program files\Common Files\McAfee\AMCore\mcshield.exe;c:\program files\Common Files\McAfee\AMCore\mcshield.exe S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe;c:\windows\SYSNATIVE\mfevtps.exe S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe;c:\program files (x86)\Nero\Update\NASvc.exe S2 NOBU;Dell DataSafe Online;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE;c:\program files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe SERVICE S2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe;c:\program files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe;c:\program files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys;c:\windows\SYSNATIVE\drivers\cfwids.sys S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys;c:\windows\SYSNATIVE\drivers\mfefirek.sys S3 mfencbdc;McAfee Inc. mfencbdc;c:\windows\system32\DRIVERS\mfencbdc.sys;c:\windows\SYSNATIVE\DRIVERS\mfencbdc.sys S3 PCDSRVC{D3412D80-CF3B4A27-06020200}_0;PCDSRVC{D3412D80-CF3B4A27-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\my dell\pcdsrvc_x64.pkms;c:\program files\my dell\pcdsrvc_x64.pkms . . --- Other Services/Drivers In Memory --- . *Deregistered* - CLKMDRV10_9EC60124 . Contents of the 'Scheduled Tasks' folder . 2013-12-09 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-22 18:16] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5e7c3693-318c-4f0f-9ff2-db485880944c}] 2013-11-08 15:53131712----a-w-c:\program files (x86)\msn_en\encyclopediabritannicagamesbarX64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{5e7c3693-318c-4f0f-9ff2-db485880944c}"= "c:\program files (x86)\msn_en\encyclopediabritannicagamesbarX64.dll" [2013-11-08 131712] . [HKEY_CLASSES_ROOT\CLSID\{5e7c3693-318c-4f0f-9ff2-db485880944c}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-23 10920552] "RunDLLEntry_THXCfg"="c:\windows\system32\THXCfg64.dll" [2009-10-15 17920] "RunDLLEntry_EptMon"="c:\windows\system32\EptMon64.dll" [2009-10-15 21504] "dleemon.exe"="c:\program files (x86)\Dell V715w\dleemon.exe" [2011-01-24 770728] "EzPrint"="c:\program files (x86)\Dell V715w\ezprint.exe" [2011-01-24 139944] "DellStage"="c:\program files (x86)\Dell Stage\Dell Stage\stage_primary.exe" [2012-02-01 2195824] . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-{238d4b4c-d63c-42a7-b6d8-dc96c8c0f5b9} - (no file) Toolbar-Locked - (no file) Wow6432Node-HKCU-Run-Exetender - c:\program files (x86)\Free Ride Games\GPlayer.exe Wow6432Node-HKLM-Run-Adobe Reader Speed Launcher - c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe Wow6432Node-HKU-Default-Run-Exetender - c:\program files (x86)\Free Ride Games\GPlayer.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) WebBrowser-{238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9} - (no file) AddRemove-toolbar2 - c:\program files (x86)\toolbar2\uninstall.exe AddRemove-WildTangent CDA - c:\program files (x86)\WildTangent\Apps\CDA\CDAUninstall.exe . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{D3412D80-CF3B4A27-06020200}_0] "ImagePath"="\??\c:\program files\my dell\pcdsrvc_x64.pkms" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\ELEVATION] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_152_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_152_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_152.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee] "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-12-08 22:05:21 ComboFix-quarantined-files.txt 2013-12-09 06:05 . Pre-Run: 904,289,697,792 bytes free Post-Run: 904,133,697,536 bytes free . - - End Of File - - E788921858CE60A018A19E5F6E330A64 i am so confused, after the combo fix, mcafee said there was a Trojan (artemis something or other) from comboxfix and needed to restart my system and since I ran combofix I get a window popping up which says you are about to leave a secure internet connection, it will be possible for others to view info you send. I didn't have this before, am I doing something wrong? I am following ur instructions. thanksThis is where you're getting the shwiconxp error. Did you install this program? c:\program files (x86)\Multimedia Card Reader(9106) Quote comboxfix and needed to restart my system and since I ran combofix I get a window popping up which says you are about to leave a secure internet connection, it will be possible for others to view info you send. I didn't have this before, am I doing something wrong?That's a normal warning on some sites.i don't recall installing it, i think it came with the system. but if it's normal then I'm relieved.shwiconxp.exe is malware but in this case it looks legitimate but let's check it just to make sure. Please go to Jotti's malware scan (If more than one file needs scanned they must be done separately and links posted for each one) * Copy the file path in the below Code box: Code: [Select]c:\program files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe * At the upload site, click once inside the window next to Browse. * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. * Next click Submit file * Your file will possibly be entered into a queue which normally takes less than a minute to clear. * This will perform a scan across multiple different virus scanning engines. * Important: Wait for all of the scanning engines to complete. * Once the scan is FINISHED, Copy and then Paste the link in the address bar into your next reply. http://virusscan.jotti.org/en/scanresult/842dff0e7417a4b7a9ebea4de07eb17c6e198a89/e594cd826611d7726b7de5928635f651061b426a I hope this is what you were looking for.I thought I was onto something but it turns out that the file is good so we're back to square one. I don't understand why. The only thing I can suggest at this point is to try another browser such as FireFox and see if you still recieve that message.okay, i'll see what happens.well, i downloaded firefox, went to msn games and seems to be working just fine, but my wife will know more than i as she plays it. As for ie, not sure why it doesn't like that particualr site, cuz it seems to be fine for everything else. i may go to microsfot and see if they have any ideas, but for now, my computer is clean, and for that i am grateful. You're a true genius Superdave,go ahead an close this unless there is any cleanup you need me to . if i need something else, i'll come back. thanks for all your helpQuote i may go to microsfot and see if they have any ideas,That would be a good idea. Let's do some cleanup and we'll finished. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ****************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you SAFE from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!thanks superdave for all your help. i'm clean and will continue to pursue the through microsoft (msngames). close it out, and thanks again. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2334. |
Solve : adobe flash request on youtube? |
|
Answer» Does anybody know what is going on if anything with Youtube popping up a screen REQUESTING the user update to the latest version of ADOBE Flash Player? This has happened to me two or three times in the past. As I remember it I have to back up the computer to an earlier DATE. That's what happened just two days ago when the youtube problem occured but now it's back. I can't watch any videos on Youtube with the exception that sometimes the video is there but there's no sound and no volume slider showing. This latest occured right after I tried to install Bit Torrent. That installation failed and then the computer nearly froze up or extreemly slowed and lost the internet connection. I restored it to an earlier date which cured the slowness but then the youtube thing was back. Also I can't download the Flash Player from Adobe. That just hangs up in mid download. I think maybe Malwarebytes or other is blocking it so I'll try again. And clicking on the request to update from the Youtube screen just runs you in circles and you get nowhere. I got it! You need to disable Active X by going, in Explorer 9 anyway to the CONTROL icon in the upper right corner -little gear- hover over safety and in the menu you will see Active X. Uncheck this. I STILL haven't tried to download Flash Player but now I can watch Youtubes. |
|
| 2335. |
Solve : Pop-under prevention.? |
|
Answer» Hi, I am interested to find out what programs are available to prevent pop-unders appearing when using either Internet Explorer 10 or Firefox v21 with Windows 7. I have had a look at some of the free pop-up ad removers but there is little or no information refering to pop-unders. I don't mind admitting to having the occasional foray into adult websites, but I GET fed up with finding sites like "Live Jasmin" and others sitting on the desktop when I close Firefox, for example. Can anyone give me any advice on this ? Hi, thanks Superdave, for the IE settings, I will put those into Explorer.Good Luck. |
|
| 2336. |
Solve : Is There a Difference for Virus Protection for a Server and a Home Computer ..?? |
|
Answer» I was looking at our server at school and realized that there is no ANTIVIRUS SOFTWARE. It does GO through a open DNS, but I can't find and anti Spyware or Antivirus. I'm very "techie" with HOME computers, but not that familiar with Servers. This is a Windows Server 2003. Any help would be greatly appreciated. According to this there is a need for an AV |
|
| 2337. |
Solve : Malwarebytes not working? |
|
Answer» Hi - |
|
| 2338. |
Solve : AVG Nightmare? |
|
Answer» System info: Desktop: Dell, XPS 630, Running Windows 7; 16GB RAM; Office 365; Photoshop CS6; |
|
| 2339. |
Solve : The message from ESET - I have no clue? |
|
Answer» Yesterday on my computer I had installed LinuxLive USB Creator (Lili) to make my USB device bootable. Yet before installation of this program when I click on its setup file the message from ESET Smart Security came on on the screen: An application running on this computer is attempting to communicate over encrypted SSL channel. If you want to check the encrypted channel content, mark the certificate as trusted.I have installed this ANYWAY. And now, every time when I open the program the same message reappears. Even being more careless I put the program to work and made my USB stick Live bootable. It boots up and works with no problem. Anyway, have I done something stupid by disregarding the message from ESET? ESET is a very trusted AV and you should have investigated the warning more closely.Lately I googled for this one and hadn't found anything. Well, I'm going to uninstall this program and run a deep scan then. Quote from: doer on June 26, 2013, 09:37:11 PM Lately I googled for this one and hadn't found anything. Well, I'm going to uninstall this program and run a deep scan then.Good idea. Let me know if you find anything.Found 0 threats.We can run a couple more quick scans just to clean out any junk you may have picked up. Please download AdwCleaner by Xplode onto your Desktop.
Please download Malwarebytes Anti-Malware from here. Double Click mbam-setup.exe to INSTALL the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. ************************************************ Please download Junkware Removal Tool to your desktop. •Warning! Once the scan is complete JRT will shut down your browser with NO warning. •Shut down your protection software now to avoid potential conflicts. •Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. •Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator •The tool will open and start scanning your system. •Please be patient as this can take a while to complete depending on your system's specifications. •On completion, a log (JRT.txt) is saved to your desktop and will automatically open. •Copy and Paste the JRT.txt log into your next message.Quote # AdwCleaner v2.303 - Logfile created 06/28/2013 at 21:03:12 Quote Malwarebytes Anti-Malware 1.75.0.1300 Quote ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ I see there still was some trash. Thank you for your help Appreciated. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2340. |
Solve : PC lag+Program not responding? |
|
Answer» dave i think i receive another virus, because when i check task manager, i found some process of weird program, pev.3XE,PEV.3XE, and sev.3XE. is this a virus or not? cause i experience another freeze.Quote i found some process of weird program, pev.3XE,PEV.3XE, and sev.3XE. is this a virus or not? cause i experience another freeze.It depends on where it's running. Please run MBAM again and POST the log.okay hey dave and im sorry if im not active for these past days because i was on HOLIDAY and i couldnt use my PC cause i was going away. so i kinda experience a new issue, this time it happens when i turn on my PC. it lags so much and my firefox keeps crashing. so should i do scan with MBAM?Quote it lags so much and my firefox keeps crashing. so should i do scan with MBAM?Yes, please run another scan with MBAM and post the log if it finds anything. Also, UNINSTALL and re-install FireFox. Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program. Click on View > Select Colunms. In addition to already pre-selected options, make sure, the Command LINE is selected, and press OK. Go File>Save As, and save the report as Procexp.txt. Attach the file to your next reply. |
|
| 2341. |
Solve : File Recovery Virus? |
|
Answer» The link for BitDefender takes me to what becomes Quickscan which shows no errors. It doesn't produce a report, and there are no tabs on the online display.Quote from: dc4580 on October 09, 2012, 09:16:11 PM The link for BitDefender takes me to what becomes Quickscan which shows no errors. It doesn't produce a report, and there are no tabs on the online display.Ok, how's your computer running now? Any other issues?No. Boot-up and processing seem to be going fine. Seems like no after-effects from the two infections. So, just two more items: 1.) Was my inability to do some of these scans due to anything other than changes to websites that might have recently taken place? and 2.) I need to dump McAfee as it couldn't catch a cold much less a virus, so I will need suggestions for software that will handle AV and Firewall. If you would have a recommendation of a suite or mix-and-match, I am all ears. Quote Was my inability to do some of these scans due to anything other than changes to websites that might have recently taken place?It's difficult to say without SITTING down in front of the computer. Quote I need to dump McAfee as it couldn't catch a cold much less a virus, so I will need suggestions for software that will handle AV and Firewall. If you would have a recommendation of a suite or mix-and-match, I am all ears.We'll do some cleanup and I'll also provide that information. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Click Start> Computer> right click the C Drive and choose Properties> enter Click DISK Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ************************************************************** Remember to only install one ANTIVIRUS! 1) Avast! Home Edition 2) AVG Free Edition 3) Avira AntiVir Personal 4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download 4-a) Microsoft Security Essentials for Windows XP 5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one) 6) PC Tools AntiVirus Free Edition 7) ThreatFire It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time. I'm very pleased with MicroSoft Security Essentials. Very effective and very lightweight. *************************************************************** Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ********************************************************************** Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't KNOW what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Ok Dave. McAfee suite is gone. My choices were Microsoft Security Essentials AV and Online Armor Firewall. I installed WOT and SpywareBlaster, and I will be getting Spybot down in the next few days. Thanks for all your help again. Much appreciated. If you don't have anything else for me to do, please feel free to close this issue. DC You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2342. |
Solve : Problem with Virus and/or spyware : please help? |
|
Answer» Ok, let's do some cleanup.
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Click Start> Computer> right click the C DRIVE and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ***************************************** Go to Microsoft WINDOWS Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, IDENTITY theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.Thanks, I don't think we used comboFix?! I performed disk cleanup as you suggested, thanks.Quote from: MNMAN on November 29, 2013, 02:46:56 PM Thanks, I don't think we used comboFix?!Yup, there is a CF log in Reply # 2 You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 2343. |
Solve : Cheap AV software or freeware - which is better?? |
|
Answer» I was looking for anti-virus software options and I came across stuff like Panda and AVG on this site: |
|
| 2344. |
Solve : Suspicious Link Info Needed? |
|
Answer» I don't think I am infected.. but what can ONE tell me about the following link an email wants me to click --- |
|
| 2345. |
Solve : Computer can no longer handle full screen videos, multiple tabs, and has popups? |
|
Answer» Ok. Run AdwCleaner and MBAM again and post the logs.
Please download Malwarebytes Anti-Malware from here. Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. # AdwCleaner v2.304 - Logfile created 07/10/2013 at 15:26:04 # Updated 03/07/2013 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : ADMINISTRATOR - LENOVO_XP # Boot Mode : Normal # Running from : C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\adwcleaner_2.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** File Deleted : C:\Program Files\Mozilla Firefox\.autoreg ***** [Registry] ***** Key Deleted : HKLM\Software\SProtector ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [OK] Registry is clean. -\\ Mozilla Firefox v22.0 (en-US) File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\weh874hs.default\prefs.js [OK] File is clean. -\\ Google Chrome v27.0.1453.116 File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [30416 octets] - [04/07/2013 10:01:16] AdwCleaner[R2].txt - [1281 octets] - [10/07/2013 15:21:30] AdwCleaner[S1].txt - [30880 octets] - [04/07/2013 12:51:02] AdwCleaner[S2].txt - [1216 octets] - [10/07/2013 15:26:04] ########## EOF - C:\AdwCleaner[S2].txt - [1276 octets] ########## Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4052 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 7/10/2013 4:10:27 PM mbam-log-2013-07-10 (16-10-27).txt Scan type: Full scan (C:\|) Objects scanned: 310586 Time elapsed: 41 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
RogueKiller V8.6.2 [Jul 5 2013] by Tigzy mail : tigzyRKgmailcom Feedback : http://www.adlice.com/forum/ Website : http://www.adlice.com/softwares/roguekiller/ Blog : http://tigzyrk.blogspot.com/ Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version Started in : Normal mode User : Administrator [Admin rights] Mode : Scan -- Date : 07/10/2013 23:40:58 | ARK || FAK || MBR | ¤¤¤ Bad processes : 2 ¤¤¤ [SUSP PATH] Lightshot.exe -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Skillbrains\lightshot\4.3.0.0\LightShot.exe [7] -> KILLED [TermProc] [SUSP PATH] Badoo.Desktop.exe -- C:\Documents and Settings\All Users\Application Data\Badoo\Badoo Desktop\1.6.58.1220\Badoo.Desktop.exe [7] -> KILLED [TermProc] ¤¤¤ Registry Entries : 17 ¤¤¤ [RUN][SUSP PATH] HKCU\[...]\Run : LightShot (C:\Documents and Settings\Administrator\Local Settings\Application Data\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue [7]
[RUN][SUSP PATH] HKUS\S-1-5-21-2025429265-861567501-1417001333-500\[...]\Run : LightShot (C:\Documents and Settings\Administrator\Local Settings\Application Data\Skillbrains\lightshot\LightShot.exe Flags: uninsdeletevalue [7]
[DNS] HKLM\[...]\CCSet\[...]\{06956AD2-24F6-46CB-954E-A1507AE22562} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [DNS] HKLM\[...]\CCSet\[...]\{C5F3C407-F0CD-40C7-8E5E-54F1B199F2FD} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [DNS] HKLM\[...]\CCSet\[...]\{F26FE20F-BA46-4770-8889-15F4E1B67646} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [DNS] HKLM\[...]\CS001\[...]\{06956AD2-24F6-46CB-954E-A1507AE22562} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [DNS] HKLM\[...]\CS001\[...]\{C5F3C407-F0CD-40C7-8E5E-54F1B199F2FD} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [DNS] HKLM\[...]\CS001\[...]\{F26FE20F-BA46-4770-8889-15F4E1B67646} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [DNS] HKLM\[...]\CS002\[...]\{06956AD2-24F6-46CB-954E-A1507AE22562} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [DNS] HKLM\[...]\CS002\[...]\{C5F3C407-F0CD-40C7-8E5E-54F1B199F2FD} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [DNS] HKLM\[...]\CS002\[...]\{F26FE20F-BA46-4770-8889-15F4E1B67646} : NameServer (107.6.133.8,23.23.180.210) -> FOUND [HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND [HJ SMENU] HKCU\[...]\Advanced : Start_ShowHelp (0) -> FOUND [HJ SMENU] HKCU\[...]\Advanced : Start_ShowPrinters (0) -> FOUND [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND ¤¤¤ Scheduled TASKS : 0 ¤¤¤ ¤¤¤ Startup Entries : 0 ¤¤¤ ¤¤¤ Web browsers : 0 ¤¤¤ ¤¤¤ Particular Files / Folders: ¤¤¤ ¤¤¤ Driver : [LOADED] ¤¤¤ ¤¤¤ External Hives: ¤¤¤ ¤¤¤ Infection : ¤¤¤ ¤¤¤ HOSTS File: ¤¤¤ --> %SystemRoot%\System32\drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 updates.presonus.com ¤¤¤ MBR Check: ¤¤¤ +++++ PhysicalDrive0: +++++ --- User --- [MBR] 4f75e196dd3c1b2c4a302dfe238a8d94 [BSP] 7a13bb6a8558b48e73bab4a19efcb5bb : Windows XP MBR Code Partition table: 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo User = LL1 ... OK! User = LL2 ... OK! FINISHED : << RKreport[0]_S_07102013_234058.txt >> Please run RogueKiller again and delete those items. I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser.
•Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part05.rarprobably a variant of Win32/Autorun.NEWCBCX worm C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070974.dlla variant of Win32/Adware.MultiPlug.I application C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070976.dlla variant of Win32/Adware.MultiPlug.I application C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070980.dlla variant of Win32/Adware.MultiPlug.I application C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070997.exea variant of MSIL/Adware.iBryte.A application C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\weh874hs.default\extensions\[emailprotected]\content\bg.jsWin32/Adware.MultiPlug.H applicationcleaned by deleting - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\dap_pre.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\d_a_p.v8.6.6.2-mkdev.team_by_cyborg.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d3.part32.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d3.part33.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d3.part34.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d3.part35.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d5.part29.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d5.part30.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d5.part31.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d5.part32.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d6.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d6.part17.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\KEY\bv\pcz2\ssos_d6.part18.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\Desktop\VSTS\mpc\ssos_d6.part33.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Documents and Settings\Administrator\My Documents\Downloads\Compressed\VSO.Convert.X.To.DVD.3.6.4.158.Full\VSO.Convert.X.To.DVD.3.6.4.158.Full\Keygen.rarmultiple threatsdeleted - quarantined C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\downloadmanager_Setup.exea variant of Win32/Adware.iBryte.G applicationcleaned by deleting - quarantined C:\Documents and Settings\Administrator\My Documents\Downloads\Programs\Extreme_Flash_Player_Setup.exea variant of Win32/Adware.iBryte.G applicationcleaned by deleting - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_1.part09.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_1.part10.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_1.part11.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_2.part04.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_2.part15.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\fantom_x_facsimile_2.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\parkrd1.part06.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\parkrd1.part07.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\parkrd1.part08.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\parkrd1.part09.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Demo Songs\ssos_d4.part14.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\New Folder\korg triton refill.part41.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\HiFi Kit\fantom_x_facsimile_2.part05.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit1\parkrd1.part10.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_2.part06.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_2.part07.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_2.part08.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_2.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\fantom_x_facsimile_3.part01.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\parkrd1.part11.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\parkrd1.part12.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\Refills\WAV's\Hip Hop Kit2\parkrd1.part13.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Binary Finary\Redrum\Subtle Effects\korg triton refill.part42.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_2.part09.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_2.part10.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_2.part11.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_2.part12.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_3.part01.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_3.part02.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\fantom_x_facsimile_3.part03.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\parkrd1.part14.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\parkrd1.part15.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\parkrd1.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\parkrd1.part17.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Chemical Comedown NN-19\Pads & Themes 3\ssos_d4.part15.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_2.part13.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_2.part14.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_2.part15.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_3.part02.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\fantom_x_facsimile_3.part04.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\parkrd1.part18.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\parkrd1.part19.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\NN-XT\parkrd1.part20.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\Redrum\Hat\fantom_x_facsimile_2.part16.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\G-Funk-Era\Redrum\Hat\parkrd2.part01.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Organic Chemistry\Rex2\Electro Acoustic Beats\100bpm\korg triton refill.part43.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\110bpm\fantom_x_facsimile_3.part01.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\fantom_x_facsimile_3.part02.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\fantom_x_facsimile_3.part03.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\fantom_x_facsimile_3.part05.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\fantom_x_facsimile_3.part06.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\lip-max_payne_dvdrip.part1.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part02.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part03.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part04.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined Wow, that was a lot of infections. Please run ESET again to make sure we got all of it. Are you using a P2P program to download music?no p2p apps on my computer, those files that say Reason, that's a music program i bought at Guitar Center, now those refills were legally DOWNLOADED online, but i've had all those on my computer for at least 3 years and haven't used them recently so i don't see how that could be the problem. i'm still getting all of these coupon popups. i'm running again! thanksC:\Program Files\Propellerhead\Reason\give me a Reason\The Big Reason\Planet Bliss Loops Rex2\120bpm 1\parkrd2.part05.rarprobably a variant of Win32/Autorun.NEWCBCX wormdeleted - quarantined C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070974.dlla variant of Win32/Adware.MultiPlug.I applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070976.dlla variant of Win32/Adware.MultiPlug.I applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070980.dlla variant of Win32/Adware.MultiPlug.I applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{4394E035-A384-4F8C-8CD5-D37F35EDE2EA}\RP594\A0070997.exea variant of MSIL/Adware.iBryte.A applicationcleaned by deleting - quarantined Also as I mentioned at the start of the thread, when i right click my computer/properties it no longer told me how much ram i had but everything else showed up. I decided to go inside since I did recently move, everything seemed intact but i pulled my 4 sticks (two 1 gb sticks and 2 smaller ones). I placed them back in and rebooted, now it says 2.00GHZ and 2.99gb of Ram! That's what its suppose to say but i played some videos and again, when i put it in full screen or ever double the size, it starts stuttering, pausing and the video becomes distorted. The ram did appear a little warm when i pulled it. thanksDid you run the RAM test?thanks Dave, sorry for my late response, remember i tried running it on the first page but it wouldn't work, after looking into things, looks like i'll need to burn it on cd and run it. i'll pick up some tomorrow. thanks |
|
| 2346. |
Solve : Sh4ldr removal help windows 7? |
|
Answer» ESET Online Scan Please run a free online scan with the ESET Online Scanner
Any more issues? We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here. Many of the things to note for US would be:
DMJ: Follow up questions. How do I safely remove the malicious SpyHunter 4 program I got tricked into downloading to fix the original sh4ldr virus? I've read that 'Enigma' created both the virus and then the fake fix program. I've heard uninstalling normally can cause it to erase my BIOS? Also, the sh4ldr folder is still in my C: as well as it's accompaning temp file. I know I need to safely remove them from my computer as well. Lastly, are there registry files that will need to be cleaned? Thanks again!!!! From TDSSKiller report: 13:02:44.0098 6932 [ 2ED464C8CBC399E69FBF776A8EBC3302 ] SpyHunter 4 Service C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE 13:02:44.0134 6932 SpyHunter 4 Service - ok In Combo Fix posted report: 2012-10-14 11:02 . 2012-10-14 11:02 -------- d-----w- C:\sh4ldr 2012-10-14 11:02 . 2012-10-14 11:02 -------- d-----w- c:\program files\Enigma Software GroupEnigma Software Group is legitimate software company that have a lot of hating people. It's their fault they ruined their own reputation, but it's not a big deal. I think you can uninstall it via the Control Panel and be in good hands. Here is a VirusTotal scan of that file that was running in the processes list from SpyHunter: https://www.virustotal.com/file/4a0df1d6220c3d93d0502a576b758705f554af3ae32f65ca5d0208336afa43b4/analysis/ This is a SpyHunter folder: sh4ldr, literally "SpyHunter Folder". However, your computer was infected by a serious rootkit, which had nothing to do with SpyHunter, Enigma Software Group, or the like. We will finish up now to make sure your computer is protected from malware in the future. Clean up System Restore Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
Purge old temporary files Download CCleaner Slim and save it to your Desktop - Alternate download link When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe Follow the prompts to install the program. * Double-click the CCleaner shortcut on the desktop to start the program. * Click on the Options block on the left, then choose Cookies. * Under Cookies to Delete, highlight any cookies you would like to retain permanently * Click the right arrow > to move them to the Cookies to Keep window. * Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours * Click Cleaner on the left then Run Cleaner on the right to run the program. * Important: Make sure that ALL BROWSER windows are closed before selecting Run Cleaner Caution: Only use the Registry FEATURE if you are very familiar with the registry. Always back up your registry before making any changes. Exit CCleaner after it has completed it's process. Security Check Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
|
|
| 2347. |
Solve : How do I make a Batch file remove Viruses from my computer?? |
|
Answer» Team, |
|
| 2348. |
Solve : [PROMOTE HERE] is spam or worse? |
|
Answer» turn off or on smartscreen filter - tools/internet options/advanced/security/ and turn if off Did a search and FOUND sevenforums.com and that's where i got this info Quote from: darcomputer on October 11, 2012, 05:09:18 PM turn off or on smartscreen filter - tools/internet options/advanced/security/ and turn if off Did a search and found sevenforums.com and that's where i got this infoCould I please see the log from adwCleaner? I provided the instructions to clean the temp files in my previous post. there are two of them. # AdwCleaner v2.003 - Logfile created 09/30/2012 at 19:00:49 # Updated 23/09/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : owner - OWNER-PC # Boot Mode : Normal # Running from : C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FBI3BDF3\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : WajamUpdater ***** [Files / Folders] ***** Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search Folder Deleted : C:\Program Files (x86)\AVG Secure Search Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\Wajam Folder Deleted : C:\ProgramData\AVG Secure Search Folder Deleted : C:\ProgramData\Partner Folder Deleted : C:\Users\owner\AppData\Local\AVG Secure Search Folder Deleted : C:\Users\owner\AppData\Local\Conduit Folder Deleted : C:\Users\owner\AppData\Local\Wajam Folder Deleted : C:\Users\owner\AppData\LocalLow\AVG Secure Search Folder Deleted : C:\Users\owner\AppData\LocalLow\Conduit Folder Deleted : C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AVG Secure Search Key Deleted : HKCU\Software\Cr_Installer Key Deleted : HKCU\Software\IGearSettings Key Deleted : HKCU\Software\InstalledBrowserExtensions Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Wajam Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\Software\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.BHO Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.BHO.1 Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.Sandbox Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.Sandbox.1 Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\S Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3244149 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1 Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLM\Software\Wajam Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wajam Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Software Key Deleted : HKU\S-1-5-21-2605971270-3625370099-2031170598-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[emailprotected]] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 Restored : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-21-2605971270-3625370099-2031170598-1000\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=DOWNLOAD&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search BAR] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com -\\ Google Chrome v [Unable to get version] File : C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [11546 octets] - [15/09/2012 20:29:12] AdwCleaner[R2].txt - [9987 octets] - [30/09/2012 18:57:11] AdwCleaner[R2]snap.do.txt - [9987 octets] - [30/09/2012 18:58:58] AdwCleaner[R3].txt - [10116 octets] - [30/09/2012 19:00:35] AdwCleaner[S1].txt - [10895 octets] - [30/09/2012 19:00:49] ########## EOF - C:\AdwCleaner[S1].txt - [10956 octets] ########## # AdwCleaner v2.003 - Logfile created 09/30/2012 at 19:00:49 # Updated 23/09/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : owner - OWNER-PC # Boot Mode : Normal # Running from : C:\Users\owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FBI3BDF3\adwcleaner.exe # Option [Delete] ***** [Services] ***** Stopped & Deleted : WajamUpdater ***** [Files / Folders] ***** Deleted on reboot : C:\Program Files (x86)\Common Files\AVG Secure Search Folder Deleted : C:\Program Files (x86)\AVG Secure Search Folder Deleted : C:\Program Files (x86)\Conduit Folder Deleted : C:\Program Files (x86)\Wajam Folder Deleted : C:\ProgramData\AVG Secure Search Folder Deleted : C:\ProgramData\Partner Folder Deleted : C:\Users\owner\AppData\Local\AVG Secure Search Folder Deleted : C:\Users\owner\AppData\Local\Conduit Folder Deleted : C:\Users\owner\AppData\Local\Wajam Folder Deleted : C:\Users\owner\AppData\LocalLow\AVG Secure Search Folder Deleted : C:\Users\owner\AppData\LocalLow\Conduit Folder Deleted : C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\Conduit Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar Key Deleted : HKCU\Software\AVG Secure Search Key Deleted : HKCU\Software\Cr_Installer Key Deleted : HKCU\Software\IGearSettings Key Deleted : HKCU\Software\InstalledBrowserExtensions Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Wajam Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\Software\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.BHO Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.BHO.1 Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.Sandbox Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0005058.Sandbox.1 Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\S Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3244149 Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamBHO.1 Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader Key Deleted : HKLM\SOFTWARE\Classes\wajam.WajamDownloader.1 Key Deleted : HKLM\Software\Conduit Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Key Deleted : HKLM\Software\Wajam Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Wajam Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Software Key Deleted : HKU\S-1-5-21-2605971270-3625370099-2031170598-1000\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[emailprotected]] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}] ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 Restored : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-21-2605971270-3625370099-2031170598-1000\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Page] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Search Bar] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - Default_Search_URL] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com Replaced : [HKCU\Software\Microsoft\Internet Explorer\Search - SearchAssistant] = hxxp://feed.snap.do/?publisher=Download&dpid=Download&co=CA&userid=d620ae34-29ab-4339-8401-cc99cb45a631&searchtype=ds&q={searchTerms} --> hxxp://www.google.com -\\ Google Chrome v [Unable to get version] File : C:\Users\owner\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [11546 octets] - [15/09/2012 20:29:12] AdwCleaner[R2].txt - [9987 octets] - [30/09/2012 18:57:11] AdwCleaner[R2]snap.do.txt - [9987 octets] - [30/09/2012 18:58:58] AdwCleaner[R3].txt - [10116 octets] - [30/09/2012 19:00:35] AdwCleaner[S1].txt - [10895 octets] - [30/09/2012 19:00:49] ########## EOF - C:\AdwCleaner[S1].txt - [10956 octets] ########## i cleaned the temp files, all, even in my computerC/windows/temp this is new been playing Rescue Frenzy for awhile, never any problems till right now, i now have Bing Desktop if that matters The GAME freezes, windows tries to repair it and i get: Error: Access violation at 0x0050285A (tried to read from 0x44149C45) program terminated. tried and froze twice and here i am helphere we go again, the spam emails are back eg Promote Here, not this exact one but the other ones i've also been getting 5 in email, only one email account, box so far Quote here we go again, the spam emails are back eg Promote Here, not this exact one but the other ones i've also been getting 5 in email, only one email account, box so farEveryone gets spam. It doesn't mean that the computer is infected. Why not download and install MailWasher?downloaded mailwasher, we shall see. Observation, my title PROMOTE HERE has had alotttt of views, and the same emails i'm getting have used this name Promote here, same - spam or worse.... we will see ok I have never had to deal with spam, can you help me.Quote I have never had to deal with spam, can you help me.The only way I know of is to install a spam filter or MailWasher.mailwasher is now my email provider for the spam email which turns out to be great but how to I change it to Outlook or at least windows live mail. i do not sign into windows live mail but it thinks i have. Everytime i get mail, i have to make mailwasher WASH these same emails sent by different ppl. help i don't want to do this everytime. |
|
| 2349. |
Solve : Firewall turned off? |
|
Answer» Whenever I start my PC my FIREWALL setting is turned off. I have no trouble turning it back on, but should I worry?MAKE sure the Windows Firewall Service is set to: automatic. If still no joy, look here: How do I set it to automatic?Start - Run - services.msc Double click on the service, set it to AUTOMATIC, click on APPLY & OK |
|
| 2350. |
Solve : Trend Micro Antispyware + Webroot?? |
|
Answer» I have had my laptop for five years now and never had a virus on it. When I purchased it from BEST Buy they installed both Trend Micro and Webroot on it, and I have had both set up for automatic renewal. Last year when they both RENEWED, Trend Micro updated me to Trend Micro with Antispyware. My computer was also acting funky because of it, but I was able to solve it on my own and both have been working fine for the year. There may be free antivirus programs available, but they're not enough!I would disagree with this pretty strongly. Throughout many years, I have repaired computers that had a variety of anti-malware suites on them and the difference I've seen between free and paid anti-virus is about 10%. A lot of anti-virus companies heap a bunch of features onto their software which I honestly don't think do anything including "identity protection" whatever that means. The sandbox is also not such an amazing tool, Windows already does this to some extent and many viruses do routinely break through the security provided by paid anti-virus software with such a feature. Paid anti-virus products are focused on one thing: sales. They want to sell as many products as possible and that's why you see "features" that don't actually give users any additional protection. It's the "Geek Squad" model for computer security -- make as much money off every customer regardless of what you actually do for them. Free anti-virus products, on the other hand, are focused on fighting viruses and "upgrading" users to their pro versions which give them benefits like online backup, being able to use the program for business purposes, etc. As a result, many free anti-virus programs are way more lightweight than their paid competitors. Once a user has bought a one year norton subscription, they're stuck with it and would feel like they wasted their money if they uninstalled it. If they are using a free anti-virus and it's slowing their computer down, they'll quickly un-install it but you can't say the same for paid anti-virus where they are locked in. Overall, the most important anti-virus doesn't even require any installation: it's the user. If they go around clicking on every link they see and running programs from un-reputable sources then yeah, they're going to get viruses and it doesn't matter which anti-virus they have. If they're smart, anti-virus is more like a "failsafe" and the most cautious users don't even need antivirus.You may disagree with this pretty strongly, but look at the evidence (I'll link to my blog so you know that my computer security knowledge is authentic)... Another Java vulnerability, 30 holes Many antivirus companies fail to block Java exploit See the swell of computer security Most free antivirus products do not include the intrusion detection system that many paid antivirus programs have. Which is bad, because IDS helps to protect files and the Registry from unwanted modification. The computer security industry is booming big time, because there are millions of computer security workers still needed in order to keep up with the constant vulnerabilities, threat of cyberwar, etc. My experience with paid antivirus is that I felt more secure knowing that I had an antivirus program that was protecting me. Why do you think Kaspersky software is so popular, even though they DON'T have a free antivirus? AVG, Avira, Microsoft, Avast, ZoneAlarm, Comodo, and Lavasoft provide a free antivirus as a temporary means, and as a relief for those who cannot currently buy an antivirus product. When I had Avast! Free, I tried many occasions to download a malware file, and was successful on getting it to my Desktop, but once it got there, the scanner detected it and warned me. HOWEVER, when I got paid Avast Internet Security for reduced price of $20 (thanks to an awesome special), it blocked the malware at the connection. It wouldn't even allow me to TRY to download it. The web shield was lightning fast. The scanning engine on paid antivirus is so much fast, and less resource intensive, that it made for a beautiful thing. Further, without a defense-in-depth PC strategy, consumers run extreme risk of having their identity stolen (yes with just a single virus), and the threat is real! Computer security threats and malware are punishable by law now. It's gotten serious. Open your eyes! Actual statistics show social network security hazards are real and becoming a real problem. That's why Facebook has allied with key antivirus companies, to provide a PAID antivirus solution or internet security solution. The ones offered, except for Microsoft Security Essentials, are PAID versions. Don't believe me security holes are a problem to users? Take a look at Google grants, which gives away money to find security holes in its products, such as Chrome. Meanwhile, there are so many security problems in popular browsers, like Firefox, and the users of these browsers need extra protection to protect from the vulnerability of the bugs. And with many people suffering data loss, it is important to have a security system that helps salvage your important data. Read more on the difficulty of malware threats in the 2010+ era: http://secureconnexion.wordpress.com/2012/06/22/running-virtual-analysis-on-malware-is-failing-these-days/ http://secureconnexion.wordpress.com/2012/09/28/fall-malware-threats-2012/ http://secureconnexion.wordpress.com/2012/09/19/zeroaccesssirefef-infects-up-to-9-million-pcs/ http://secureconnexion.wordpress.com/2012/07/27/rakshasa-case-study-really-undetectable/ http://secureconnexion.wordpress.com/2012/06/18/six-arrested-in-japan-for-android-malware/ http://secureconnexion.wordpress.com/2012/06/14/watch-out-this-android-malware-is-top-game/ Please make sure to check out all the appropriate links, before coming back with your rebuttal. And make sure to keep it ethical, or I will close this topic. And think twice before arguing with a computer security student/professional. Quote from: DragonMaster Jay on October 19, 2012, 02:18:46 AM You may disagree with this pretty strongly, but look at the evidence (I'll link to my blog so you know that my computer security knowledge is authentic)... The java links are irelevat to the anti-virus discussion. If java has a security hole and Sun or the user fail to update, anti-virus shouldn't protect them from that. Anti-virus should, however, protect them from any payloads delivered through that vulnerability. Many people get viruses not because their anti-virus couldn't protect them, but because they continually ignored warnings to upgrade their software including the anti-virus software itself! I'm not saying viruses and security holes aren't a threat here, they certainly are and user education can prevent a whole lot more than a $10 a month subscription to a service that by design can only prevents threats that are known about and already out in the wild. Again, agree to disagree none of the links you provided showed that paid anti-virus programs actually block significantly more threats than free ones. Here are reasons why you don't know what you're talking about... Quote If java has a security hole and Sun or the user fail to update, anti-virus shouldn't protect them from that. If Java has a security hole? How about many security holes? Have you not heard? It's Oracle that owns the Java product line, not Sun [Microsystems] anymore. If antivirus shouldn't protect my computer from vulnerabilities, then what will? If a real life virus got in my body, it was because of a vulnerability, so I take a vaccine (antivirus) to protect me from the vulnerability next time to avoid the virus. Get the analogy? That's why vulnerability management and prevention is so important, because it would prevent the virus from even having a chance at getting installed. Further, vulnerability prevention in antivirus software is just as important as blocking viruses themselves. Quote Many people get viruses not because their anti-virus couldn't protect them, but because they continually ignored warnings to upgrade their software including the anti-virus software itself! Many people get viruses through vulnerabilities. If people would read the news, and not skip over the security section, they could LEARN how to protect themselves. They may fail to upgrade the antivirus software, but there are measures being taken by both antivirus companies AND operating system companies (such as Microsoft, Apple, Ubuntu, etc.) to manage the vulnerabilities associated with that (by forming a strategic alliance with security companies), in hopes to help update/upgrade those products. Quote I'm not saying viruses and security holes aren't a threat here, they certainly are and user education can prevent a whole lot more than a $10 a month subscription to a service that by design can only prevents threats that are known about and already out in the wild. This makes no sense. Re-read the sentence, and tell me if you would understand this. Why would somebody want to prevent a $10 a month service? By design, antivirus was originally supposed to prevent viruses from doing anymore damage, by scanning the system and looking for bad code. Then, it was the ability to prevent the install of viruses by scanning the threats in real-time (which was only allowed Windows XP and up). Now, heuristics and other algorithms spot more viruses/malware because they rely on behavior of the file, which they run in a self-contained sandbox, called virtualization. If malware is found by the analyzer built in to most antivirus programs these days, the program is marked as malware if it relates to other threats, or labeled new malware if it is suspicious. We've come a long way, in which now vulnerability prevention is in play, which is strengthening heuristics and algorithms. I would hate to give my product away for free, if I knew I spent 800-1000 man hours writing code, and double that in researching malware. Quote Again, agree to disagree none of the links you provided showed that paid anti-virus programs actually block significantly more threats than free ones. I don't agree to disagree to people that think they know what they're talking about, and don't listen to experts. I agree to disagree to people that made a solid, rational opinion. All you have done was contradict myself, because you are part of a community of people that think all software should be free. You lack the ability to believe in solid, awesome software, such as Adobe Creative Suite, Kaspersky PURE or Antivirus or Internet Security, etc. As I explained above, it's not about blocking [known] threats, it's about discovering unknown threats and vulnerabilities and being ahead of the game. Free antivirus does a job that paid antivirus cannot do, provide a temporary means, so that people don't have to go without antivirus software. However, the astute person can save themselves from computer heartache, by getting a paid antivirus software. Many people, some who claim to have not had problems with viruses, are big supporters of free antivirus. Meanwhile, they are promoting free antivirus like the black plague, putting users at risk for zero-day vulnerabilities. Anyway, I've had enough trying to explain this, but at least the data is here so people can learn from a security teacher. |
|