Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

2351.

Solve : My Notebook boots straight into "Asus Preload Wizard"?

Answer»

You're WELCOME. I will LOCK this THREAD. If you need it re-opened, PLEASE send me a pm.

2352.

Solve : X Vidly problems?

Answer»

Ok, let's do some clean up.

Download this program and run it Uninstall ComboFix .It will remove ComboFix for you.

*************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free SPACE in C drive)
*************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free INTERNET security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free TOOLS to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Dave as usual you've earned the "Super" Moniker. lol

All fixed, all celaned up and read one of the articles so far.
Always something new to learn.

Again thanks so much,
Happy Holidays if I don't have another problem before then.
MP.You're welcome. I will LOCK this THREAD. If you need it re-opened, please send me a pm.

2353.

Solve : MalwareBytes (MBAM) got trashed.?

Answer»

This is not a request for help. I just now restored my Windows XP tfrom an image made a MONTH ago. For some reason the past 30 days of system restore is missing. So I had to use the image I made last month. Maybe I need to make an image every week!

Anyway,. what got my attention was MalwareBytes (MBAM). Some way It got smashed. I did an UN install and installed from a copy. Same thing. I GET a message saying there was a run-time error. Also, my accessibility wizard was missing. I attempted to do a repair of Windows XP, but that did not resolve the issues.

That is way I did an images restore form last month. Now the PROBLEM gone. But I lost some settings I had in my browser. Oh WELL. MBAM now works fine.

So my question is this: Has anybody every had this happen? Has MalwareBytes (MNAM)all of a sudden got a run time error?


There are a number of reason for a run time error as explained here.You certainly know how to keep a reader entertained.Quote from: milano1234 on November 10, 2013, 09:06:02 PM

You certainly know how to keep a reader entertained.
Super Dave has lots of stuff.
2354.

Solve : Question Virus Removal Related - Not infected, but removal tool related?

Answer»

So in the past when dealing with virus removal, I generally took the hard drive out of the affected machine and placed it into an IDE or SATA dock to turn it into an external hard drive and have the virus non functional outside of its "startup and infected/affect state" rooted to the root OS of the drive it is on.

I have seen online people claim to use tools like creating a Bart PE startup CD or DVD with an antivirus on that to clean the systems as well as SOMEONE else on another google hit claimed to use a Linux Live CD with an Antivirus on that to clean the drive of malware.

Question I have is ... What are the best bootable tool methods of attacking the removal of the malware?

I am guessing its the bootable CD or DVD METHOD which introduces a read-only source to the equation of which the system also boots off of so that any viruses would not START up, cant infect the disc, and they can be detected dormant and removed. I tried to make a Bart PE disc once placing Norton Antivirus on it, but it doesnt function, and then if it did function, how do you update the DEFINITIONS on a read-only disc.

* I understand that there is the potential to infect my test station ( workstation I use for projects and data recovery and malware removal ) using my current malware/virus removal method. This is one reason why I never use my important systems to perform interaction with foreign drives to contain any infection to that of the test station which can be wiped out clean via a ghost image etc to start clean again at a baseline for next project etc. This test station is also running Windows XP Pro because Ghost 2003 works with Windows XP, but Ghost 2003 doesnt WORK with any newer OS than XP. So until I find the need to leave XP such as if the HDD becomes too big to access etc, I am sticking with XP, however if there is a good Linux option for a test station for malware removal etc, I am open at trying a distro and tool or two.

2355.

Solve : Daughter's Computer Infected with GamePlay Lab Adware?

Answer»

Hi,

Ran a scan and found she was infected with GamePlay Lab Adware. I just want to be sure it is cleaned and nothing else hanging around since there have been infections on the network.

Here are the files:

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.07.22.06

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
ADMINISTRATOR :: MICHELE-6273CB9 [administrator]

7/22/2013 2:57:47 PM
mbam-log-2013-07-22 (14-57-47).txt

Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 291550
Time elapsed: 58 minute(s), 37 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory MODULES Detected: 0
(No malicious items detected)

Registry Keys Detected: 2
HKCR\Interface\{66666666-6666-6666-6666-660066226658} (Adware.GamePlayLab) -> Quarantined and deleted successfully.
HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

-------------------------------------

# AdwCleaner v2.306 - Logfile created 07/22/2013 at 13:33:30
# Updated 19/07/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Administrator - MICHELE-6273CB9
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Administrator\My Documents\Downloads\adwcleaner(1).exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Deleted on reboot : C:\Program Files\Mozilla Firefox\extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}
File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\zj5c0w0m.default\searchplugins\Askcom.xml
File Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\zj5c0w0m.default\searchplugins\Search_Results.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\Program Files\Mozilla FireFox\searchplugins\Search_Results.xml
Folder Deleted : C:\Documents and Settings\Administrator\Application Data\Babylon
Folder Deleted : C:\Documents and Settings\Administrator\Application Data\ilividtoolbarguid
Folder Deleted : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\zj5c0w0m.default\ilividtoolbarguid
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Application Data\AVG Security Toolbar
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Application Data\Babylon
Folder Deleted : C:\Documents and Settings\Administrator\Local Settings\Application Data\Ilivid
Folder Deleted : C:\Documents and Settings\All Users\Application Data\AVG Secure Search
Folder Deleted : C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Babylon
Folder Deleted : C:\Documents and Settings\All Users\Application Data\boost_interprocess
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Tarma Installer
Folder Deleted : C:\Program Files\file scout
Folder Deleted : C:\Program Files\Search Results Toolbar
Folder Deleted : C:\Program Files\Yontoo

***** [Registry] *****

Key Deleted : HKCU\Software\AVG Security Toolbar
Key Deleted : HKCU\Software\Complitly
Key Deleted : HKCU\Software\Cr_Installer
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\I Want This
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted : HKLM\Software\SimplyGen
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow [*.crossrider.com]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://www.ask.com/?l=dis&o=41648106&gct=hp --> hxxp://www.google.com

-\\ Mozilla Firefox v22.0 (en-US)

File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\zj5c0w0m.default\prefs.js

C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\zj5c0w0m.default\user.js ... Deleted !

Deleted : user_pref("browser.search.defaultenginename", "Search Results");
Deleted : user_pref("browser.search.order.1", "Search Results");

-\\ Google Chrome v28.0.1500.72

File : C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [5362 octets] - [22/07/2013 13:33:30]

########## EOF - C:\AdwCleaner[S1].txt - [5422 octets] ##########


--------------------------------------

Results of screen317's Security Check version 0.99.70
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````[/u]
Windows Firewall Enabled!
Please wait while WMIC is being installed.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
a
v
a
s
t
!
ECHO is off.
A
n
t
i
v
i
r
u
s
ECHO is off.
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````[/u]
Out of date HijackThis installed!
Malwarebytes Anti-Malware version 1.75.0.1300
HijackThis 2.0.2
CCleaner
Adobe Flash Player 11.7.700.224
Adobe Reader XI
Mozilla Firefox (22.0)
Google Chrome 27.0.1453.116
Google Chrome 28.0.1500.72
````````Process Check: objlist.exe by Laurent````````[/u]
AVAST Software Avast AvastSvc.exe
AVAST Software Avast avastUI.exe
`````````````````System Health check`````````````````[/u]
Total Fragmentation on Drive C:: 16% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````[/u]
Quote

Total Fragmentation on Drive C:: 16% Defragment your hard drive soon! (Do NOT defrag if SSD!)
Please defrag your harddrive soon. (SSD means Solid State Drive.)

Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a LIST of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*********************************************
  • Download RogueKiller on the desktop
  • Close all the running programs
  • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
  • Otherwise just double-click on RogueKiller.exe
  • Pre-scan will start. Let it finish.
  • Click on SCAN button.
  • A report (RKreport.txt) should open. Post its content in your next reply. (RKreport could also be found on your desktop)
  • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
I ran the two scans and here are the reports. I will run the defrag as soon as we are done unless you would prefer I run it now. Thanks so much!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.2.2 (07.22.2013:2)
OS: Microsoft Windows XP x86
Ran by Administrator on Tue 07/23/2013 at 18:41:09.21
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{77777777-7777-7777-7777-770077227758}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077227758}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{480F9B7D-125E-4F11-B8D2-DA705E457E8F}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\wincert"



~~~ FireFox

Successfully deleted: [File] "C:\Program Files\Mozilla Firefox\searchplugins\avg_igeared.xml"
Failed to delete: [Folder] "C:\Program Files\Mozilla Firefox\extensions\{1fd91a9c-410c-4090-bbcc-55d3450ef433}"





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 07/23/2013 at 18:48:45.79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

---------------------------------------

RogueKiller V8.6.3 [Jul 17 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Administrator [Admin rights]
Mode : Scan -- Date : 07/23/2013 18:55:09
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 3 ¤¤¤
[HJ POL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD1200BEVE-00WZT0 +++++
--- User ---
[MBR] 490235036159349e472e6f4870112cd2
[BSP] e1bf717d93861b562449c8e79ac1fe53 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 114463 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_07232013_185509.txt >>
Yes, run the defrag any time you wish.
Please run RogueKiller again and delete those items.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
ok sounds good. I will run this scan tonight and post the results. Thanks!Sorry it has taken me so long. Our internet provider had some outages. Will get this posted asap. Thanks!
2356.

Solve : Computer Boots Into ASUS Recovery Wizard?

Answer»

Also, I don't have a system repair disk. I only have a recovery disk. Is it possible to actually burn one and use that? Or is that illegal.
If you have a Recovery Disk, boot your computer with it and see if there is a Repair option.Hello,

I got my hands on Linux and booted my PC with it. Now I can recover all my files, so I figured that I will just do a recovery.
Unfortunately, my recovery CD that came with my laptop doesn't have a repair option, here are it's options:
Recover Windows to FIRST partition only.
Recover Windows to entire HD.
Recover Windows to entire HD with 2 partitions.
What exactly do they MEAN, and what will they do?Quote

Unfortunately, my recovery CD that came with my laptop doesn't have a repair option, here are it's options:
Recover Windows to first partition only.
Recover Windows to entire HD.
Recover Windows to entire HD with 2 partitions.
What exactly do they mean, and what will they do?
Just as I thought. You will need to save your important data. Next, click on My Computer and tell me how many drives do you see. That will determine which option you will use.I have a C and a D partition, each 500 GB. Also a 26 GB recovery drive, what does this do?
To be honest, I would like to get the stuff out of there and do a full recovery as I don't need 500 GB for my C drive. 200 GB will suffice.
Also, if I recover it to a single partition, do I have to partition myself a recovery drive?Quote
I have a C and a D partition, each 500 GB. Also a 26 GB recovery drive, what does this do?
To be honest, I would like to get the stuff out of there and do a full recovery as I don't need 500 GB for my C drive. 200 GB will suffice.
Also, if I recover it to a single partition, do I have to partition myself a recovery drive?
Your OS is on the C drive and the Recovery Console is on another partition. The D drive is your third partition. Your OS should be on a drive of it's own. If you EVER have to do a repair or recovery your other data is protected because it's on another partition. In your case you should choose Quote
Recover Windows to first partition only.
. Once you have your computer running correctly, you can use a partition program to configure your partitions that whatever you want.
You can find one here. I believe this is the one I used for my computer. Use the freeware one because you probably won't have any use for it afterwards.[/COLOR]So if I use "Recover Windows to first partition only." only my first partition will be recovered? I will go ahead and do the recovery tomorrow, sort of busy today.

Thanks so much for your help, I appreciate the time and effort you've put in.

Quote
So if I use "Recover Windows to first partition only." only my first partition will be recovered? I will go ahead and do the recovery tomorrow, sort of busy today.

Thanks so much for your help, I appreciate the time and effort you've put in.
Ok, please let me know how it goes.Actually, there was a error code when recovering. My sister took over after I travelled to Canada to visit her.
Thanks for your help.Quote
Actually, there was a error code when recovering. My sister took over after I travelled to Canada to visit her.
Thanks for your help.
You're welcome. How about those Canadians eh?
2357.

Solve : I used combofix and now I can't open control panel, windows explorer etc.?

Answer»

OK don't chastise me I know I shouldn't have done it, but I ran Combofix and now I can't open my COMPUTER or programs FOLD etc. it says no such interface supported. Everything else works fine like I was able to use Firefox to open this topic. I should also add that even though it won't let me double click and open folders on my desktop it will allow me to left click and open them. The funny part is the bug I was trying to get rid of with Combofix is still there lol. Hello and welcome to GeekPolice.Net My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. ABSENCE of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*******************************************************
ComboFix is a powerful tool and should only be used under the guidance of an expert. I'm not sure that I can help fix this problem. These instructions may be different for Windows 7. Also, can you TRY booting your computer in Safe Mode and see how it's working there?

I'd like to see the removals performed by ComboFix. Click Start > Run and TYPE the following bold text into the Run box and click OK:

C:\Qoobox\ComboFix-quarantined-files.txt

The report should open for you. Please post the contents of that report in the next reply.

2358.

Solve : Novice needs advice on security software extras?

Answer»

I was in the process of buying (online as a download) security software (Trend Micro Titanium Maximum Security @ $44.95/yr) for my laptop computer. Of course, once I got to the billing page, more add-ons were offered. These included "Download Protection Service," to access the software and serial key @ $8.95; "Virus Removal Service," @ $9.95; and "Protect Your Investment," - which is a back-up CD, @ $9.95. I consider myself a novice and "computer challenged," and don't know if I should purchase or need these extras. I thought that in buying this software part of its job was to block viruses, so why would I need to add-on a virus removal service? Please help!!!

Thanks,
Jacqueline This area is notably for making recommendations, not asking.
My recommendation is to sat with what is free and go from there.

Microsoft Security Essentials is free.
Malware bytes has a free version.
Personally, I like Avast.

Avoid offers that promise a lot but have no reputation.
You can do a search on Bing for:
most popular AV programs
and find out what other people are using.



Quote from: Geek-9pm on October 31, 2013, 09:52:22 PM

This area is notably for making recommendations, not asking.

Please report threads if you feel they're in the wrong place, and the moderating team will move as required.

Jacqueline - the add-ons are just that, add-ons, and are not required for the software you're purchasing to work correctly. I would imagine the virus removal service is paying for an expert to remove malware should any sneak past your protection software.

I would advise against purchasing these extras as they are not necessary. Consider your choice of security software, you don't have to pay for it as there are several free options.Remember to only install one antivirus!

1) Avast! Home Edition
2) AVG Free Edition
3) Avira AntiVir Personal
4) MicroSoft Security Essentials All versions and all languages.
5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you CHOOSE this one)
6) PC Tools AntiVirus Free Edition

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.Hi

What they are offering is stuff you should do with with every program you download.

When downloading software always select download / not run from this location after the download transfer the file to a pen drive or better use a CD.

SAVE or PRINTOUT the page with your receipt and activation number. It's good to save these to the same place as the install file so if you need to install the program again you have all the information in the same place.

If you are buying the same software for more than 1 computer it's good to record what computer is using what registration number.

I can't advise on the "so why would I need to add-on a virus removal service?" it's a bit like the question, do I need private health insurance if there is public health included in my tax. I wouldn't pay for either but I like a complicated life lol.

2359.

Solve : Downloaded a keylogger for fun.. sometimes i think ill never learn my lesson...?

Answer»

Combofix is telling me that it wont run with AVG installed. That's CORRECT. Please download MicroSoft Security Essentials from the link below. Make sure that you install the 64 bit one. Once it's installed, remove AVG with the AVG tool REMOVER below. Now try to run ComboFix.

Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
*************************************************
AVG Antivirus - AVG Antivirus Remover utilityQuote from: SuperDave on February 11, 2011, 05:05:37 PM

That's correct. Please download MicroSoft Security Essentials from the link below. Make sure that you install the 64 bit one. Once it's installed, remove AVG with the AVG tool remover below. Now try to run ComboFix.

Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
*************************************************
AVG Antivirus - AVG Antivirus Remover utility

I did have to delete AVG. I have a problem. CommandPrompt, stops working while Combofix is running. It wont let me use it! What can i do now?


this is what it tells me

Problem signature:
Problem Event Name:APPCRASH
Application Name:CF22586.cfxxe
Application Version:6.1.7600.16385
Application Timestamp:4a5bc48d
Fault Module Name:ntdll.dll
Fault Module Version:6.1.7600.16695
Fault Module Timestamp:4cc7b325
Exception Code:c00000fd
Exception Offset:000000000005316f
OS Version:6.1.7600.2.0.0.256.48
Locale ID:1033
Additional Information 1:c5ec
Additional Information 2:c5ec62c949c41b1acf62ab7e02ba2792
Additional Information 3:8f53
Additional Information 4:8f53f0bd77fc1dd72129be33405f9dcb

Read our privacy statement online:
http://go.microsoft.com/fwlink/?linkid=104288&clcid=0x0409

If the online privacy statement is not available, please read our privacy statement offline:
C:\Windows\system32\en-US\erofflps.txt

What can i do to make it work?Quote
I have a problem. CommandPrompt, stops working while Combofix is running. It wont let me use it! What can i do now?

Why do you want to run CommandPrompt? I specifically asked you not to run anything other than the scans I requested. Please run ComboFix and post the log.Quote from: SuperDave on February 11, 2011, 07:18:14 PM
Why do you want to run CommandPrompt? I specifically asked you not to run anything other than the scans I requested. Please run ComboFix and post the log.

combofix runs in the command prompt. Then it stops working. The command prompt has a blue background though. Then it makes it so i cant get on the internet. Dude I know its crazy, but if you could, i would totally let you come into my computer and do this remotely. Im such a noob. and im freaking out.

I keep trying combofix, but its not working. Please try this:

Delete your copy of ComboFix; download a fresh copy, except before you download it, rename it to blackpudding.bat

Navigate to Start --> Run, and enter the following command EXACTLY as shown:

"%userprofile%\desktop\blackpudding.bat" /killall

See if ComboFix will run nowQuote from: SuperDave on February 12, 2011, 11:54:56 AM
Please try this:

Delete your copy of ComboFix; download a fresh copy, except before you download it, rename it to blackpudding.bat

Navigate to Start --> Run, and enter the following command exactly as shown:

"%userprofile%\desktop\blackpudding.bat" /killall

See if ComboFix will run now

i have the "run" window open..and im putting that command in. nothing is happening though. What am i doing wrong?Quote from: WiseFailure on February 12, 2011, 04:04:45 PM
i have the "run" window open..and im putting that command in. nothing is happening though. What am i doing wrong?

How do i rename it before i download it? Im using firefox. Quote
If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

When the Save file box opens up you can change the name down at the bottom of the box.Quote from: SuperDave on February 12, 2011, 07:30:32 PM
When the Save file box opens up you can change the name down at the bottom of the box.

Actually, no i cant. Whats up with that? Please download it with Internet Explorer.A software keylogger would probably record keystrokes from an O/S soft keyboard like Microsoft, depending on where exactly it hooks into the operating system.
2360.

Solve : MSE Won't Update?

Answer»

Microsoft Security Essentials has not auto-updated in the past 5 days. I only get the pop-up icon in the task bar saying updates are available. I TELL it to update, the icon goes away & nothing happens. If I open MSE & click on Update tab, & tell it to update, within a minute is says: MSE error code0x80240022

If I go here: https://www.microsoft.com/security/portal/definitions/adl.aspx
& download & save the latest update, double-click file, it updates with no problem.

Before updating, MSE taskbar icon never goes orange, indicating an update is needed.

Have you seen this on Windows XP Pro-SP3?
MBAM results:
--------------------------------------------------------------------------------------
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.10.21.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
User :: GIGABYTE [administrator]

10/21/2013 2:18:07 PM
mbam-log-2013-10-21 (14-18-07).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 223210
Time elapsed: 7 minute(s), 20 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 2
C:\Documents and Settings\All Users\Application Data\Tarma Installer (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{F60A62FE-7EBF-4A93-A889-0BDE5212A62F} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.

Files Detected: 4
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{F60A62FE-7EBF-4A93-A889-0BDE5212A62F}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{F60A62FE-7EBF-4A93-A889-0BDE5212A62F}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{F60A62FE-7EBF-4A93-A889-0BDE5212A62F}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\Tarma Installer\{F60A62FE-7EBF-4A93-A889-0BDE5212A62F}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.

(END)
--------------------------------------------------------------------------------------
MBAM says it's a PUP. I deleted them. Could this be the cause?

MBAM required computer restart. Update appears in icon tray. Click download, icon disappears.

Current Client Version is: Antimalware Client Version: 4.3.216.0
Update says: 4.3.219.0

Will try to get download applied through IE Microsoft Updates. If that doesn't work, then, I believe only option is to download MSE, uninstall MSE & reinstall with new version. This happened about 2 weeks ago, maybe have to get rid of MSE & go to Avast.

Microsoft Update found it. Update failed to install.

Downloaded MSE installer. It actually asked to upgrade whereas in the past, it said MSE was already installed. It is now asking for a restart. After restart, MSE is now updated to 4.3.216.0

Don't think the MSE issue had anything to do with the PUP. Won't know for at least another 24 hrs & the next MSE DEFINITION update.

[recovering disk space, attachment deleted by admin]MBAM found the same errors on the Win-64 machine. MSE was already updated to the latest Client Version, but had to manually update the virus defs.

This would seem to indicate a Microsoft issue with WinXP & MSE. Have they started to drop support for WinXP? Or maybe just relegated it to secondary or low priority status?My MSE on XP is up-to-date. The latest update is listed at 21/10/2013 @ 07:46 pm.

•Please download Dial-A-Fix from one of the following mirrors:

Primary mirror
Secondary mirror

•Extract the zip file to your desktop.

•Double click Dial-a-Fix.exe to start the program. Dial-A-Fix might give you a lot errors, just ignore them and Click
to continue.

•Press the green double checkmark box (Looks like this:


UNcheck Empty Temp Folders, as well as Adjust Time/Date in the prep section. The prep section should then look like this:





•Click on Go

•Wait for Dial-A-Fix to finish (All the checks marks will be all gone)

•Close Dial-A-Fix
I got 1 error after starting the program, the 1st attachment.
When it reached Group #5 - Registration Center, I had maybe 10 of the 2nd attachment.
Hit OK on each of these until completion.

Will now run from Start---Run
regsvr32 iesetup.dll

Got error in 3rd attachment.

I have IE8, but default browser is FF24.

Tried update from MSE again today, same error.
the latest definitions are: 1.161.458.0, Oct 22, 2013 01:50 PM UTC

This now does appear to be a registry error (4th attachment).

The only fix I can think of is an Admin reinstall of IE8. I have the full download of 16,488kB

Ran sfc /scannow inserted Windows CD as instructed. Kept asking to reinsert CD, maybe 15 times. Didn't say to Restart, MSE still won't update. Maybe a reboot?


[recovering disk space, attachment deleted by admin]Reinstalled IE8, then tried to update MSE. No error message this time, but it took a very long time. Still can't register iesetup.dll.
Notifier popped up in taskbar, told it to download, nothing happened. Went to Microsoft Update & it's doing nothing there, either. It's now hung, will have to kill the it with Task Manager. Send Error Report...Useless.

Is it possible you don't have enough space on your harddrive to handle the updates?

Please download and run MS Fix-it from here. Partition #1 - OS - 20GB, 3.4GB Free
Partition #2 - Data - 17.6GB, 4.1GB Free
Partition #3 - Downloads - 15.6GB, 4.1GB Free
Partition #4 - VM File, Temp Files - 7.8GB, 4.1GB Free
Partition #5 - Macrium Image storage - 171.8GB

Coincidently, just ran MS-Fixit.

I have 3 Macrium images saved:
10/18/2013 (the same issues probably exist in this one)
10/4/2013
9/20/2013

This is not good:
BITS service is not listed as a Service.
Ran msconfig, it's on selective startup. I didn't change it.
Changed to normal startup, will have to restart.

[recovering disk space, attachment deleted by admin]You really should increase the size of your OS drive. 20gb is stretching the limits. Did you run the fixes in MS-Fixit?Thanks, SD:

Yes, I ran those fixes in MS-Fixit. Didn't fix it!!
I found what the problem was, but don't know how it happened.
There was no BITS listed in SERVICES. Googled for fix, but all were for XP3-SP2 or Vista or Win7, nothing for WinXP-SP3. I tried several different ones, but nothing would return BITS to services.

I restored the 10/4/2013 image & immediately looked at Services (see pic); now it's listed as it's supposed to be. It's no wonder nothing was updating.

Updates popped right up, downloaded & then installed, so have been busy for the past couple hours. MSE updated, too. After last reboot, MSE wants to do a scan, running now.

I have no idea what killed the Background Intelligent Transfer Service (BITS) & why there is no fix for it for WinXP-SP3.

MSE finished, all MS monthly Tuesday updates installed, all other updates for the past 18 days installed. All appears to be working, now.

This isn't the fastest XP machine in the world, but not a dog either. See specs under my pic.

I don't really need Partition #5, but backing up the images from the USB 3.0 drive to the older USB 2.0 drive is faster if copied to the hard drive first. Hard Drive is 250GB, I have a spare 250GB, so can add that for image storage.

These OS folders can be safely deleted:
Software Downloads are 100MB
Update folders are 10MB

I created an image before the restore, now will create another after the restore. I've spent waaay too much time on this.

Thanks, hope I didn't waste too much of you time.

Found this (after Googling "why is BITS missing"): http://steveit.ca/2012/07/09/windows-update-fails-missing-bits-service/
He did everything I tried, except exporting from another computer.

He provides link to this site: http://www.smartestcomputing.us.com/files/file/9-registry-network-keys/
Is this "our" Broni?
Yes it is. That's his home page. http://www.smartestcomputing.us.com/index.php?app=uportal
Go figure!! Where was he when I needed him? LOL.

[recovering disk space, attachment deleted by admin]

2361.

Solve : Confirmation that system is clean?

Answer»

A friend gave me his tower to work on that was running Vista SP1 32bit that was inoperable. Instantly suspected malware due to nature of how it would boot and never get to desktop, basically black screen and pointer and never got past that point.

Steps I have done so far:

Step #1 - Removed the hard DRIVE from this computer and connected it to my SATA USB dock to turn this drive into an external and be able to work with this drive with malware dormant.

Step #2 - Scanned this 500GB drive with MSSE and it found 9 malware items, mostly trojans. Told MSSE to clean this drive and it did.

Step #3 - Placed this drive back into the Dell tower with it disconnected from the internet and turned it on. Windows Vista now came up with a message giving boot options because of an improper shutdown. This is probably because I had to force a shutdown due to the fact that while it was infected it was just a black screen with white pointer and CTRL + ALT + Delete and nothing ELSE functioned and I forced it to shutdown by holding in power button.

Step #4 - System booted to desktop but certain windows features seemed to lag, as well as unresponsive. * I thought I was going to have to perform a repair installation at this point. So I shut it down and booted off of the system recovery disc and saw that it had a memory test option. Figured might as well test the RAM before moving on just in case 2 issues since the tower hasnt been really confirmed as good running yet. Ran memtest and at some point it got through this memtest and the system rebooted itself.

Step #5 - I then figured ok its at the logon lets logon and see if the problem is still there. Now the system is very responsive and not lagging and is acting clean. Connected it to the internet over broadband and performed much needed security updates such as Service Pack 2 and all other patches. System still running fast after reboot and no noticable problems.

Step #6 - Installed, updated definitions and started MSSE scan before bed ( first time in this tower scanning itself with its Vista now SP2 OS active ) to make sure nothing is detected.

Step #7 - Woke up and checked the system and its GREEN NO Malware Detected.

---------------------------------------------------------------------------
Here is the list of the Trojans detected and cleaned:

7 Variants of Sirefef

2 Variants of Necurs

http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Win32%2FSirefef

http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=%20Trojan:Win32/Necurs

---------------------------------------------------------------------------------------

Is there any other tools I should run against this system to make sure its really clean and not a gaping hole for infection? I use to use Rootkit Revealer in the past, but its been a while since I have had to remove viruses and not up to date on the latest tools for detection, removal, and prevention. As far as prevention goes, I have had good luck with MSSE and my friend had Norton on this system but the definitions lapsed about 4 years ago.

Thanks for assistance

[recovering disk space, attachment deleted by admin]Very impressive. May I ask a question. Two questions.
Lots of questions
Would you do it again?
Was all this hard work really better that the alternatives?
Such as:

  • Buying a new PC?
  • Asking your insurance company to fix it?
  • Asking a youngster to disinfect it it as part of his/her science project?
  • Blame the slowdown non the government?
Or even wipe the drive clean and doing a full install of everything.
I would run these scans below just to make sure.
*************************************************************************
Please download AdwCleaner by Xplode onto your Desktop.
  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the scan.
  • Click on Delete.
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the CONTENT of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
*********************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to EITHER and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
*********************************************
I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Thanks for assistance ... I ended up installing Malwarebytes and ran the scan and it found some problems that MSSE did not pick up on. Removed those problems and performed a FOLLOW up scan to verify the problems were removed and it came up clean.

I was going to get to the ESET online scan portion, but he needed his computer back for college work so he took it back.

Right now he is happy with its operation and its now clean according to MSSE and Malwarebytes as well as I performed SP2 and many many updates on it. I also defragged his hard drive since the last defrag was back in 2010. He also needed security updates to MS Office 2010, so I did those.

I think he is all set now.Quote
I ended up installing Malwarebytes and ran the scan and it found some problems that MSSE did not pick up on.
That's because they don't look for the same infections.

You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2362.

Solve : Ad appears on screen on boot up?

Answer»

I tried a trial version of an INTERNET program but when the trial was over and I did not purchase the program, an ad keeps appearing on my screen whenever I boot up. I have tried everything I can think of but it still shows up. Is there a solution to this? Title is "Advanced Care System Trial Period Expired" Thank you. I am running WINDOWS 7 Home Premium 64.I have never used it before but a quick Google search provided me this:
http://www.wikihow.com/Uninstall-Advanced-Systemcare-5-from-Windows-7
Please let me know if you can't get rid of it.Well actually, I do use the free Advanced System Ware program to scan my computer..just not this internet thingy. Bob Rankin recommended it that's why I use it. Should I just uninstall the WHOLE program and try to reinstall it again? That is the one thing I did not do....
Quote from: Mi9sDixi on October 20, 2013, 07:11:27 PM

Well actually, I do use the free Advanced System Ware program to scan my computer..just not this internet thingy. Bob Rankin recommended it that's why I use it. Should I just uninstall the whole program and try to reinstall it again? That is the one thing I did not do....
It might be a worth a try.
2363.

Solve : tool for show hidden files on USB_Drive?

Answer»

Hello Here,

I want such tool or program by which i can unhide / re-correct hidden files on usb drive by some malware.

there is such problems when i connect usb drive there are everything hidden.

can u help me?

thanks in advanced.Instead you should scan it with your installed security software and / or malwarebytes.Quote from: PCdoc on October 17, 2013, 12:33:37 AM

Instead you should scan it with your installed security software and / or malwarebytes.

i did FULL scan by my security antivirus and also malwarebytes and cleaned it from infections but files even stays hidden. it takes a long time to change folder options and after uncheck hidden opotion.

Hello and welcome to COMPUTER Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB STORAGE device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
  • Please download Unhide by Grinler from here and save it to your desktop.
  • Double click unhide.exe to run the tool.
  • It will take some time to go through all your files, so please be patient.
  • If this tool doesn´t fix the problem, please let me know.
**********************************************
Please download AdwCleaner by Xplode onto your Desktop.
  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[SN].txt as well - n is the order number.
*********************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using WINDOWS Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
2364.

Solve : Possible virus from bf watching porn...?

Answer»

You're WELCOME. I will lock this THREAD. If you NEED it re-opened, PLEASE send me a pm.

2365.

Solve : Plugging in an Old External Hard Drive?

Answer»

I have a 250 GB external hard drive lying around my house that's about 4-5 years old and I'm looking to start using it again. The last time I used it, I recall copying some files to it from an old computer, which may have had some viruses on it. I'd like to reformat the drive completely, erasing any virus that would potentially be on it. However, I am hesitant to connect the drive to my current computer because I don't want to risk getting infected from it.

So I guess my questions boil down these:
1. How can I go about clearing this drive to clear it 100% of any viruses/malware that might be on it?
2. How can I clear this drive without potentially infecting my computer in the process? Or should I just reformat it using someone elses Mac (I use Windows 7) and then plug it back into my computer and reformat it again?
3. If possible is there a safe way to see what files are on this drive without potentially infecting my computer? (I'm 99.9% sure anything on this drive is either completely useless to me or already present on my current laptop so BLINDLY reformatting it is no big deal)

I already have SandBoxie installed on my computer if using a Sandbox would help. I also currently own, and use, Norton 360 and have MalwareBytes installed on my computer.

Thanks for the help.A number of Linux live CDs come with disk partitioning TOOLS which can remove, create, resize and format partitions. GParted is the name of ONE such tool, and there is a live CD specifically made for this task.

http://gparted.sourceforge.net/livecd.php

It says on that page it is for x86 computers, so you may NEED to have access to one. Also there are such tools on many Linux bootable CDs including Koppix, Ark Linux Live, Kubuntu, MEPIS, NimbleX, and others.
Make sure your AV is up-to-date, slave the drive to your computer, right-click on the drive and choose Format.

2366.

Solve : Had a few problems - think I'm clean but best to check.?

Answer»
  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller FOLDER and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.



  • If an infected file is detected, the default action will be Cure, click on Continue.



  • If a suspicious file is detected, the default action will be Skip, click on Continue.



  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.



  • Click the Report button and copy/paste the contents of it into your next reply
Note:It will also create a log in the C:\ directory..
Hi SuperDave, here you go...


22:14:09.0618 0x1468 TDSS rootkit removing tool 3.0.0.12 Oct 9 2013 14:59:22
22:14:09.0870 0x1468 ============================================================
22:14:09.0870 0x1468 Current date / time: 2013/10/11 22:14:09.0870
22:14:09.0870 0x1468 SystemInfo:
22:14:09.0870 0x1468
22:14:09.0870 0x1468 OS Version: 6.1.7601 ServicePack: 1.0
22:14:09.0870 0x1468 Product type: Workstation
22:14:09.0871 0x1468 ComputerName: bluelight
22:14:09.0871 0x1468 UserName: *****
22:14:09.0871 0x1468 Windows directory: C:\Windows
22:14:09.0871 0x1468 System windows directory: C:\Windows
22:14:09.0871 0x1468 Processor architecture: Intel x86
22:14:09.0871 0x1468 Number of processors: 2
22:14:09.0871 0x1468 Page size: 0x1000
22:14:09.0871 0x1468 Boot type: Normal boot
22:14:09.0871 0x1468 ============================================================
22:14:12.0762 0x1468 System UUID: {D2115B01-BC04-52B9-D130-A4E6153C15EB}
22:14:13.0358 0x1468 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:14:13.0370 0x1468 Drive \Device\Harddisk1\DR1 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:14:13.0383 0x1468 Drive \Device\Harddisk2\DR2 - Size: 0x1D1C1116000 (1863.02 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:14:13.0387 0x1468 ============================================================
22:14:13.0387 0x1468 \Device\Harddisk0\DR0:
22:14:13.0387 0x1468 MBR partitions:
22:14:13.0387 0x1468 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A385000
22:14:13.0387 0x1468 \Device\Harddisk1\DR1:
22:14:13.0387 0x1468 MBR partitions:
22:14:13.0387 0x1468 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x57545000
22:14:13.0387 0x1468 \Device\Harddisk2\DR2:
22:14:13.0387 0x1468 MBR partitions:
22:14:13.0387 0x1468 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07800
22:14:13.0387 0x1468 ============================================================
22:14:13.0410 0x1468 C: <-> \Device\Harddisk0\DR0\Partition1
22:14:13.0448 0x1468 D: <-> \Device\Harddisk1\DR1\Partition1
22:14:13.0483 0x1468 E: <-> \Device\Harddisk2\DR2\Partition1
22:14:13.0483 0x1468 ============================================================
22:14:13.0483 0x1468 Initialize success
22:14:13.0484 0x1468 ============================================================
22:15:24.0993 0x0e8c ============================================================
22:15:24.0993 0x0e8c Scan started
22:15:24.0993 0x0e8c Mode: Manual;
22:15:24.0993 0x0e8c ============================================================
22:15:24.0993 0x0e8c KSN ping started
22:15:27.0369 0x0e8c KSN ping finished: true
22:15:27.0954 0x0e8c ================ Scan system memory ========================
22:15:27.0954 0x0e8c System memory - ok
22:15:27.0954 0x0e8c ================ Scan services =============================
22:15:28.0121 0x0e8c [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B 6295BC19B95AE245D25B12744 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
22:15:28.0125 0x0e8c 1394ohci - ok
22:15:28.0176 0x0e8c [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F 4EBA039414123CAC52157509B ] ACPI C:\Windows\system32\drivers\ACPI.sys
22:15:28.0181 0x0e8c ACPI - ok
22:15:28.0233 0x0e8c [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26C C5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
22:15:28.0234 0x0e8c AcpiPmi - ok
22:15:28.0285 0x0e8c [ 73685E15EF8B0BD9C30F1AF413F13D49, 618087873BB867D942272A84F7875484C7BCA8D 5AEB1454FB42077C15C51B2DE ] adfs C:\Windows\system32\drivers\adfs.sys
22:15:28.0287 0x0e8c adfs - ok
22:15:28.0331 0x0e8c [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40 DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
22:15:28.0341 0x0e8c adp94xx - ok
22:15:28.0365 0x0e8c [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C8 7981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
22:15:28.0373 0x0e8c adpahci - ok
22:15:28.0391 0x0e8c [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300 A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
22:15:28.0396 0x0e8c adpu320 - ok
22:15:28.0417 0x0e8c [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF 0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:15:28.0419 0x0e8c AeLookupSvc - ok
22:15:28.0457 0x0e8c [ F81BB7E487EDCEAB630A7EE66CF23913, 7D1638FD7E388EF670FA0A421762E0413351058 A20DDF0F9988A383F05395A68 ] AFD C:\Windows\system32\drivers\afd.sys
22:15:28.0465 0x0e8c AFD - ok
22:15:28.0477 0x0e8c [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D12031 1B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\drivers\agp440.sys
22:15:28.0479 0x0e8c agp440 - ok
22:15:28.0493 0x0e8c [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1 EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
22:15:28.0496 0x0e8c aic78xx - ok
22:15:28.0512 0x0e8c [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F09 8886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe
22:15:28.0514 0x0e8c ALG - ok
22:15:28.0551 0x0e8c [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936 F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\drivers\aliide.sys
22:15:28.0553 0x0e8c aliide - ok
22:15:28.0569 0x0e8c [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0D A93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
22:15:28.0571 0x0e8c amdagp - ok
22:15:28.0600 0x0e8c [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E51 28C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\drivers\amdide.sys
22:15:28.0602 0x0e8c amdide - ok
22:15:28.0616 0x0e8c [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E 016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
22:15:28.0619 0x0e8c AmdK8 - ok
22:15:28.0659 0x0e8c [ AD8FA28D8ED0D0A689A0559085CE0F18, 75A35973D0CAED504147FC4A78F6EFA755E74EC 4A169689F279150769196744A ] AmdLLD C:\Windows\system32\DRIVERS\AmdLLD.sys
22:15:28.0661 0x0e8c AmdLLD - ok
22:15:28.0666 0x0e8c [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301 FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
22:15:28.0669 0x0e8c AmdPPM - ok
22:15:28.0730 0x0e8c [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F 407FDCE4C90E32A6638F27416 ] amdsata C:\Windows\system32\drivers\amdsata.sys
22:15:28.0733 0x0e8c amdsata - ok
22:15:28.0741 0x0e8c [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656 CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
22:15:28.0745 0x0e8c amdsbs - ok
22:15:28.0765 0x0e8c [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EF E94859947136AD06681EA8ED0 ] amdxata C:\Windows\system32\drivers\amdxata.sys
22:15:28.0766 0x0e8c amdxata - ok
22:15:28.0803 0x0e8c [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA 95CB132C20D55B98C03B4254F ] AppID C:\Windows\system32\drivers\appid.sys
22:15:28.0805 0x0e8c AppID - ok
22:15:28.0827 0x0e8c [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D 628B32D00F2B66765E6B97E4B ] AppIDSvc C:\Windows\System32\appidsvc.dll
22:15:28.0829 0x0e8c AppIDSvc - ok
22:15:28.0872 0x0e8c [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CD C9941B2BC499C2D34D83E86C3 ] Appinfo C:\Windows\System32\appinfo.dll
22:15:28.0874 0x0e8c Appinfo - ok
22:15:28.0986 0x0e8c [ 4FE5C6D40664AE07BE5105874357D2ED, 70DD05EE80B77EB2F781E0919885D1BBB1119EA 1A8955935AF5AECD05E30F14A ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
22:15:28.0988 0x0e8c Apple Mobile Device - ok
22:15:29.0017 0x0e8c [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D14 4B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt C:\Windows\System32\appmgmts.dll
22:15:29.0022 0x0e8c AppMgmt - ok
22:15:29.0036 0x0e8c [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7 FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\DRIVERS\arc.sys
22:15:29.0039 0x0e8c arc - ok
22:15:29.0054 0x0e8c [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C2910542 20BADE291044343778216F6BA ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
22:15:29.0057 0x0e8c arcsas - ok
22:15:29.0155 0x0e8c [ 776ACEFA0CA9DF0FAA51A5FB2F435705, 72DF7ED6B085BC468994F5B3189506FD726A9A1 7A9C42ACA1E420D787691361D ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
22:15:29.0178 0x0e8c aspnet_state - ok
22:15:29.0199 0x0e8c [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF406981 6E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:15:29.0201 0x0e8c AsyncMac - ok
22:15:29.0236 0x0e8c [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218 BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\drivers\atapi.sys
22:15:29.0237 0x0e8c atapi - ok
22:15:29.0315 0x0e8c [ 70F72C50D39F5AFA76C17F86223A7C4F, 9C16BAB657BB399ACE84666E981BD3913E16E21 A19DE0693B32AD4AC6A547B62 ] atksgt C:\Windows\system32\DRIVERS\atksgt.sys
22:15:29.0321 0x0e8c atksgt - ok
22:15:29.0370 0x0e8c [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E 141BA11471666E7D9EB3C93CC ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:15:29.0378 0x0e8c AudioEndpointBuilder - ok
22:15:29.0392 0x0e8c [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E 141BA11471666E7D9EB3C93CC ] Audiosrv C:\Windows\System32\Audiosrv.dll
22:15:29.0401 0x0e8c Audiosrv - ok
22:15:29.0603 0x0e8c [ 4DB93F4DB7077801D2D82013506AC1D0, 3D71655D1557021D5D828E37EAFDBA35C631061 E48D64B9D376746F8FCC760B3 ] AVGIDSAgent C:\Program Files\AVG\AVG2013\avgidsagent.exe
22:15:29.0690 0x0e8c AVGIDSAgent - ok
22:15:29.0748 0x0e8c [ 4D7E34E36E586EA26F171A258341BD80, B11B750930382B19A257A7B259EBEDAE884971A 59E649F4E346B285DCBF29D4A ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdriverx.sys
22:15:29.0752 0x0e8c AVGIDSDriver - ok
22:15:29.0799 0x0e8c [ 7C8E88549BCDAAC965B1B724C175F7A9, 86240BF965C60FFAF381879D1B2DD7190FAD597 E7534AEE9A9E48A2BDEC119BA ] AVGIDSHX C:\Windows\system32\DRIVERS\avgidshx.sys
22:15:29.0800 0x0e8c AVGIDSHX - ok
22:15:29.0835 0x0e8c [ 2717EBC35166B8793DBFFB4390B8F2E7, F04307734F7C474320353AC4109FCF3D03D0BAF AF3C52209D2A3BD9FAFE9E784 ] AVGIDSShim C:\Windows\system32\DRIVERS\avgidsshimx.sys
22:15:29.0836 0x0e8c AVGIDSShim - ok
22:15:29.0856 0x0e8c [ 2018C4E9A40B122408763A5635CF14D9, E0BF5D5C7CFDD078F8BBA9627F1F8E0434B38A2 3FA9E039B37A22D7E1AD4EFFA ] Avgldx86 C:\Windows\system32\DRIVERS\avgldx86.sys
22:15:29.0860 0x0e8c Avgldx86 - ok
22:15:29.0903 0x0e8c [ E2B9CF2CF787C6978E7CC898E9684E48, 73D5D8514EF1BF3BCC64DC158C68189D07B3940 641F1155823C6822D03BC761B ] Avglogx C:\Windows\system32\DRIVERS\avglogx.sys
22:15:29.0909 0x0e8c Avglogx - ok
22:15:29.0939 0x0e8c [ 3F59750A3AA55C46663801E7C2FD1E2B, F748EB6552889974CB1FC6F666F2D78F654CAA9 90A339C741255355295CD46E8 ] Avgmfx86 C:\Windows\system32\DRIVERS\avgmfx86.sys
22:15:29.0942 0x0e8c Avgmfx86 - ok
22:15:29.0955 0x0e8c [ CBCE8ED318DB8EA431F9D25AC9B7FF41, 14CD6A0A1FAFD37540953AE534F44378C14E43A D248DF6064E939B2ADE334F04 ] Avgrkx86 C:\Windows\system32\DRIVERS\avgrkx86.sys
22:15:29.0957 0x0e8c Avgrkx86 - ok
22:15:29.0985 0x0e8c [ 14370FB29526F593C04FA48B5D69F7F0, EE5BBE674210AC3BC4103B6D43BABDCCCE681F3 B0E93075F93CD453730C316B8 ] Avgtdix C:\Windows\system32\DRIVERS\avgtdix.sys
22:15:29.0989 0x0e8c Avgtdix - ok
22:15:30.0025 0x0e8c [ 3001E24F340D400BFF85935E5777FC5B, BA1D3B4D4EC6E4DD6C0FAE22238E37A6168067B 5E4A0E533C25B3625473A3A48 ] avgtp C:\Windows\system32\drivers\avgtpx86.sys
22:15:30.0026 0x0e8c avgtp - ok
22:15:30.0056 0x0e8c [ 48939D9F350AEF9370F03A1E49A49BE2, 889FC07FE2DC4262055F37F8EEFFE15D5F12615 FF797951BE445B42152076327 ] avgwd C:\Program Files\AVG\AVG2013\avgwdsvc.exe
22:15:30.0062 0x0e8c avgwd - ok
22:15:30.0100 0x0e8c [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F 6DE56C886B3AAD26E3347952C ] AxInstSV C:\Windows\System32\AxInstSV.dll
22:15:30.0103 0x0e8c AxInstSV - ok
22:15:30.0145 0x0e8c [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBA CD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
22:15:30.0155 0x0e8c b06bdrv - ok
22:15:30.0175 0x0e8c [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D 477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
22:15:30.0181 0x0e8c b57nd60x - ok
22:15:30.0302 0x0e8c [ F9CE9B5E049EFC66B8E6C73C18EE8438, 8B43B84F59810DAFA961EEA13E354FF9A0796A1 85E2C8D6642D8660AAC1B96F4 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys
22:15:30.0358 0x0e8c BCM43XX - ok
22:15:30.0387 0x0e8c [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05 644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll
22:15:30.0390 0x0e8c BDESVC - ok
22:15:30.0399 0x0e8c [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4F C0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys
22:15:30.0400 0x0e8c Beep - ok
22:15:30.0454 0x0e8c [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABA B460AE32E4453161C2F7B68DF ] BFE C:\Windows\System32\bfe.dll
22:15:30.0464 0x0e8c BFE - ok
22:15:30.0512 0x0e8c [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD44 74F22F13594F5EB60AA4E1CF5 ] BITS C:\Windows\system32\qmgr.dll
22:15:30.0527 0x0e8c BITS - ok
22:15:30.0541 0x0e8c [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052B FA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
22:15:30.0542 0x0e8c blbdrive - ok
22:15:30.0613 0x0e8c [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A, 10F21999FF6B1D410EBF280F7F27DEACA528973 9CF12F4293B614B8FC6C88DCC ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
22:15:30.0621 0x0e8c Bonjour Service - ok
22:15:30.0654 0x0e8c [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B87022 1E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:15:30.0655 0x0e8c bowser - ok
22:15:30.0667 0x0e8c [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE121 9FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:15:30.0674 0x0e8c BrFiltLo - ok
22:15:30.0700 0x0e8c [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA1 2232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:15:30.0701 0x0e8c BrFiltUp - ok
22:15:30.0728 0x0e8c [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C886 2FAA68F6179A3BA9D6B69AE64 ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
22:15:30.0731 0x0e8c BridgeMP - ok
22:15:30.0751 0x0e8c [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219 FEC1E15F2F1D02DDD562FC73B ] Browser C:\Windows\System32\browser.dll
22:15:30.0755 0x0e8c Browser - ok
22:15:30.0781 0x0e8c [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CED E3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys
22:15:30.0788 0x0e8c Brserid - ok
22:15:30.0794 0x0e8c [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD60 7013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
22:15:30.0796 0x0e8c BrSerWdm - ok
22:15:30.0810 0x0e8c [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B588 5D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
22:15:30.0812 0x0e8c BrUsbMdm - ok
22:15:30.0822 0x0e8c [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570 FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
22:15:30.0823 0x0e8c BrUsbSer - ok
22:15:30.0836 0x0e8c [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB2 3C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
22:15:30.0838 0x0e8c BTHMODEM - ok
22:15:30.0872 0x0e8c [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1F AA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll
22:15:30.0875 0x0e8c bthserv - ok
22:15:30.0955 0x0e8c catchme - ok
22:15:30.0984 0x0e8c [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565 B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:15:30.0987 0x0e8c cdfs - ok
22:15:31.0035 0x0e8c [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442 AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
22:15:31.0038 0x0e8c cdrom - ok
22:15:31.0071 0x0e8c [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C872199 30BFB1A7456880B7DA75B9820 ] CertPropSvc C:\Windows\System32\certprop.dll
22:15:31.0074 0x0e8c CertPropSvc - ok
22:15:31.0083 0x0e8c [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB 08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
22:15:31.0085 0x0e8c circlass - ok
22:15:31.0100 0x0e8c [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F97 85BD66C0C1E03A0F1C223A26A ] CLFS C:\Windows\system32\CLFS.sys
22:15:31.0106 0x0e8c CLFS - ok
22:15:31.0140 0x0e8c [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289 C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:15:31.0143 0x0e8c clr_optimization_v2.0.50727_32 - ok
22:15:31.0188 0x0e8c [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF2 1B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:15:31.0284 0x0e8c clr_optimization_v4.0.30319_32 - ok
22:15:31.0303 0x0e8c [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D 34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:15:31.0304 0x0e8c CmBatt - ok
22:15:31.0338 0x0e8c [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E 7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\drivers\cmdide.sys
22:15:31.0339 0x0e8c cmdide - ok
22:15:31.0378 0x0e8c [ 247B4CE2DAB1160CD422D532D5241E1F, CFE04DBE48B23B084C3F4C3D0F483B26F322E46 93176D8739A412BE5D8BE597E ] CNG C:\Windows\system32\Drivers\cng.sys
22:15:31.0387 0x0e8c CNG - ok
22:15:31.0401 0x0e8c [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD 4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
22:15:31.0403 0x0e8c Compbatt - ok
22:15:31.0443 0x0e8c [ 9704B9C442E3EF2989746D08F80A3743, 33C0E2EEE125CD760BD49DBA3C9F5CFB2EAB8DF 50EC13E4C70BD3B0D365F6A5D ] CompFilter C:\Windows\system32\DRIVERS\lvbusflt.sys
22:15:31.0445 0x0e8c CompFilter - ok
22:15:31.0462 0x0e8c [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C 63094E3C14388E147DBC3F6DF ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
22:15:31.0464 0x0e8c CompositeBus - ok
22:15:31.0478 0x0e8c COMSysApp - ok
22:15:31.0514 0x0e8c [ 3411FDF098AA20193EEE5FFA36BA43B2, 67734C7C0130DD66C964F76965F09A2290DA4B1 4C94412C0056046E700654BDC ] cpuz135 C:\Windows\system32\drivers\cpuz135_x32.sys
22:15:31.0515 0x0e8c cpuz135 - ok
22:15:31.0527 0x0e8c [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D 1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
22:15:31.0528 0x0e8c crcdisk - ok
22:15:31.0573 0x0e8c [ 7CA1BECEA5DE2643ADDAD32670E7A4C9, E3AB4CC52A97E3855D7EAB87363F807FDD2162E D8C76A036CD71549ED64E7797 ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:15:31.0576 0x0e8c CryptSvc - ok
22:15:31.0624 0x0e8c [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A 1658573550E29E74E5F7B1553 ] CSC C:\Windows\system32\drivers\csc.sys
22:15:31.0633 0x0e8c CSC - ok
22:15:31.0662 0x0e8c [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B 09F062295699131232712B558 ] CscService C:\Windows\System32\cscsvc.dll
22:15:31.0672 0x0e8c CscService - ok
22:15:31.0753 0x0e8c [ 80861969541971176E005D2C09DAE851, F82A054DE0425ACB758A3792D902A38D01BE0AD EE933B5878C8F8017C148063A ] DAUpdaterSvc D:\Games\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
22:15:31.0755 0x0e8c DAUpdaterSvc - ok
22:15:31.0826 0x0e8c [ DB66841A22E3F51030C7671F33B2D290, EAC72AB3675D4DCA35A5E1FF3AD50F4D87D3807 F0716FCB5FF01FDAB75A668A0 ] DAZContentManagementService C:\Program Files\DAZ 3D\Content Management Service\ContentManagementServer.exe
22:15:31.0827 0x0e8c DAZContentManagementService - ok
22:15:31.0852 0x0e8c [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694 AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\Windows\system32\rpcss.dll
22:15:31.0861 0x0e8c DcomLaunch - ok
22:15:31.0896 0x0e8c [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042 B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll
22:15:31.0902 0x0e8c defragsvc - ok
22:15:31.0945 0x0e8c [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF19 0954AF1C4A38B6D542CC74BD2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:15:31.0947 0x0e8c DfsC - ok
22:15:31.0980 0x0e8c [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C6 8933E6E83D37B67242706F3C4 ] Dhcp C:\Windows\system32\dhcpcore.dll
22:15:31.0985 0x0e8c Dhcp - ok
22:15:32.0009 0x0e8c [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A 5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys
22:15:32.0011 0x0e8c discache - ok
22:15:32.0033 0x0e8c [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB 463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\DRIVERS\disk.sys
22:15:32.0035 0x0e8c Disk - ok
22:15:32.0070 0x0e8c [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6 F1EA5F0F3DB6BF87EF90248EC ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:15:32.0073 0x0e8c Dnscache - ok
22:15:32.0115 0x0e8c [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A9279 63237A385A914D0B80551DC31 ] dot3svc C:\Windows\System32\dot3svc.dll
22:15:32.0121 0x0e8c dot3svc - ok
22:15:32.0168 0x0e8c [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCA AF0D453296D9FDA6B9D717071 ] DPS C:\Windows\system32\dps.dll
22:15:32.0171 0x0e8c DPS - ok
22:15:32.0221 0x0e8c [ 456E8EDEA6C96553F8420450C602D7FE, B236672C83CC0DBFECFF39BFCD9B7B982556263 A3EB01C78DB074FD48DC475B0 ] DragonSvc C:\Program Files\Common Files\Nuance\dgnsvc.exe
22:15:32.0226 0x0e8c DragonSvc - ok
22:15:32.0250 0x0e8c [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA 1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:15:32.0251 0x0e8c drmkaud - ok
22:15:32.0305 0x0e8c [ 71BC35067CABC02C9453AEAA42B2E43E, 713B19F2C08EA5E4C087F7A74A8856932CF33E1 9D63384823DD4E02ED8798619 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:15:32.0318 0x0e8c DXGKrnl - ok
22:15:32.0348 0x0e8c [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E 167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll
22:15:32.0351 0x0e8c EapHost - ok
22:15:32.0460 0x0e8c [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305 CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
22:15:32.0530 0x0e8c ebdrv - ok
22:15:32.0575 0x0e8c [ 81951F51E318AECC2D68559E47485CC4, ACF76395EF4A2ED03AB919A9DA04D3A4C03B4D0 EDC60BE123B3BE1AFE78BC71B ] EFS C:\Windows\System32\lsass.exe
22:15:32.0577 0x0e8c EFS - ok
22:15:32.0649 0x0e8c [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182 207F1C57F134B34D6A113857F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
22:15:32.0662 0x0e8c ehRecvr - ok
22:15:32.0692 0x0e8c [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C 2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe
22:15:32.0695 0x0e8c ehSched - ok
22:15:32.0725 0x0e8c [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B 4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
22:15:32.0736 0x0e8c elxstor - ok
22:15:32.0770 0x0e8c [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4 ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\drivers\errdev.sys
22:15:32.0772 0x0e8c ErrDev - ok
22:15:32.0805 0x0e8c [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD07 4D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll
22:15:32.0811 0x0e8c EventSystem - ok
22:15:32.0833 0x0e8c [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A 2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys
22:15:32.0837 0x0e8c exfat - ok
22:15:32.0857 0x0e8c [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBB E9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:15:32.0861 0x0e8c fastfat - ok
22:15:32.0897 0x0e8c [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834ED C695F8401EAB5DE307F62602D ] Fax C:\Windows\system32\fxssvc.exe
22:15:32.0910 0x0e8c Fax - ok
22:15:32.0922 0x0e8c [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD5 41A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
22:15:32.0924 0x0e8c fdc - ok
22:15:32.0951 0x0e8c [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F07 4F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll
22:15:32.0952 0x0e8c fdPHost - ok
22:15:32.0964 0x0e8c [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02 F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll
22:15:32.0966 0x0e8c FDResPub - ok
22:15:32.0982 0x0e8c [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC24221 8FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:15:32.0984 0x0e8c FileInfo - ok
22:15:32.0997 0x0e8c [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F9 7E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:15:32.0999 0x0e8c Filetrace - ok
22:15:33.0062 0x0e8c [ 8669BE94F63944E4F899C3950B520241, 9991E57B3C366D59BD186CEAA78D4590EDB2BC1 27250CF4D1522CBE413453E72 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
22:15:33.0086 0x0e8c FLEXnet Licensing Service - ok
22:15:33.0099 0x0e8c [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E35 80554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
22:15:33.0101 0x0e8c flpydisk - ok
22:15:33.0116 0x0e8c [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE 3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:15:33.0120 0x0e8c FltMgr - ok
22:15:33.0184 0x0e8c [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE8 2E8C3AD0A95F00137CC8B619F ] FontCache C:\Windows\system32\FntCache.dll
22:15:33.0201 0x0e8c FontCache - ok
22:15:33.0267 0x0e8c [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B 496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
22:15:33.0268 0x0e8c FontCache3.0.0.0 - ok
22:15:33.0290 0x0e8c [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BB D92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
22:15:33.0291 0x0e8c FsDepends - ok
22:15:33.0329 0x0e8c [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32B B6E68A012A7D7870ED24F703A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:15:33.0330 0x0e8c Fs_Rec - ok
22:15:33.0380 0x0e8c [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B9 2832D392FEBEF0C7012353091 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
22:15:33.0385 0x0e8c fvevol - ok
22:15:33.0410 0x0e8c [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C5 8328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
22:15:33.0413 0x0e8c gagp30kx - ok
22:15:33.0458 0x0e8c [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB7 51B9D77700B6B147D347DA157 ] gpsvc C:\Windows\System32\gpsvc.dll
22:15:33.0470 0x0e8c gpsvc - ok
22:15:33.0549 0x0e8c [ C1B577B2169900F4CF7190C39F085794, 73E104B96A48F4C80D8C37254ECB0891D15C0D2 F0C251B57C168F90D60316447 ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
22:15:33.0553 0x0e8c gusvc - ok
22:15:33.0565 0x0e8c [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A 6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
22:15:33.0567 0x0e8c hcw85cir - ok
22:15:33.0614 0x0e8c [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD1513 8AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:15:33.0622 0x0e8c HdAudAddService - ok
22:15:33.0639 0x0e8c [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C2 10F075C8623E138BEE6BCD41B ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
22:15:33.0642 0x0e8c HDAudBus - ok
22:15:33.0658 0x0e8c [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA05 3D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
22:15:33.0659 0x0e8c HidBatt - ok
22:15:33.0674 0x0e8c [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE1 4BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
22:15:33.0681 0x0e8c HidBth - ok
22:15:33.0702 0x0e8c [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6 314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
22:15:33.0704 0x0e8c HidIr - ok
22:15:33.0731 0x0e8c [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E5 3DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\System32\hidserv.dll
22:15:33.0733 0x0e8c hidserv - ok
22:15:33.0781 0x0e8c [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A9 4C0D0625253BB159E30642853 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
22:15:33.0795 0x0e8c HidUsb - ok
22:15:33.0880 0x0e8c [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E 0C82AA62EBC041585DA811DAF ] hkmsvc C:\Windows\system32\kmsvc.dll
22:15:33.0884 0x0e8c hkmsvc - ok
22:15:33.0923 0x0e8c [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A 53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:15:33.0929 0x0e8c HomeGroupListener - ok
22:15:33.0971 0x0e8c [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D8 55E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:15:33.0976 0x0e8c HomeGroupProvider - ok
22:15:33.0997 0x0e8c [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7 A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
22:15:34.0000 0x0e8c HpSAMD - ok
22:15:34.0048 0x0e8c [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E 77E42B5B3CC73037AD51D2987 ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:15:34.0059 0x0e8c HTTP - ok
22:15:34.0093 0x0e8c [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0A FEB4C5364835B9C42311DF0D4 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
22:15:34.0094 0x0e8c hwpolicy - ok
22:15:34.0141 0x0e8c [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908 370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
22:15:34.0144 0x0e8c i8042prt - ok
22:15:34.0188 0x0e8c [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81 E59298364A7FE4C9C56C68FF0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
22:15:34.0197 0x0e8c iaStorV - ok
22:15:34.0287 0x0e8c [ C521D7EB6497BB1AF6AFA89E322FB43C, BDDCFCBB5B76A9295669B5AC9F732D6127199ED 5C300770B554C4E4794F66BB7 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:15:34.0306 0x0e8c idsvc - ok
22:15:34.0326 0x0e8c [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5 BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
22:15:34.0328 0x0e8c iirsp - ok
22:15:34.0361 0x0e8c [ F95622F161474511B8D80D6B093AA610, F2320E25EB9B4AA9A8366BD3AA23EABEBE111A5 610D3A62EBA47D90427D5BC26 ] IKEEXT C:\Windows\System32\ikeext.dll
22:15:34.0380 0x0e8c IKEEXT - ok
22:15:34.0627 0x0e8c [ DA6EE479071883D263E75BE7A67A70B8, FEB109E031E82F47E4A5C28C86424DD9CBF1764 0D14EE32D5FEF51DE5365E930 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
22:15:34.0685 0x0e8c IntcAzAudAddService - ok
22:15:34.0727 0x0e8c [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3C E2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\drivers\intelide.sys
22:15:34.0729 0x0e8c intelide - ok
22:15:34.0754 0x0e8c [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF 963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:15:34.0764 0x0e8c intelppm - ok
22:15:34.0793 0x0e8c [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2 E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:15:34.0796 0x0e8c IPBusEnum - ok
22:15:34.0811 0x0e8c [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C 1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:15:34.0814 0x0e8c IpFilterDriver - ok
22:15:34.0852 0x0e8c [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA 292A119C76D4D795D06028F96 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:15:34.0864 0x0e8c iphlpsvc - ok
22:15:34.0900 0x0e8c [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC99086 4FE0B9E3DC70EE0B88539E964 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
22:15:34.0903 0x0e8c IPMIDRV - ok
22:15:34.0922 0x0e8c [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB 80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
22:15:34.0926 0x0e8c IPNAT - ok
22:15:34.0946 0x0e8c [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D2 93591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:15:34.0953 0x0e8c IRENUM - ok
22:15:34.0984 0x0e8c [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71 A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\drivers\isapnp.sys
22:15:34.0987 0x0e8c isapnp - ok
22:15:35.0006 0x0e8c [ CB7A9ABB12B8415BCE5D74994C7BA3AE, 464BFF3F5EEE985BE075E23E1813F5CB82A9A07 71A92C6D889B13B867BCDF647 ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
22:15:35.0013 0x0e8c iScsiPrt - ok
22:15:35.0076 0x0e8c [ 66CF3B38398CC0795B227D6CA8F69930, 9095BBBB1DF173487A3E1A2B65F38DC9BF333A5 E0DC3B99F06EDBD13D686CD76 ] ka6avs C:\Windows\system32\Drivers\ka6avs.sys
22:15:35.0083 0x0e8c ka6avs - ok
22:15:35.0114 0x0e8c [ C06BCCCB02B5024B06824E783CB8F037, 86AA296022C48C4D3C0D190C599A55400353A8B D92B47A5FD18A0EBA89E72D27 ] ka6usb_svc C:\Windows\system32\Drivers\ka6usb.sys
22:15:35.0116 0x0e8c ka6usb_svc - ok
22:15:35.0142 0x0e8c [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376D AE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
22:15:35.0144 0x0e8c kbdclass - ok
22:15:35.0167 0x0e8c [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF 4C7BAB1FD2EEF3B53C5DF770F ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
22:15:35.0168 0x0e8c kbdhid - ok
22:15:35.0179 0x0e8c [ 81951F51E318AECC2D68559E47485CC4, ACF76395EF4A2ED03AB919A9DA04D3A4C03B4D0 EDC60BE123B3BE1AFE78BC71B ] KeyIso C:\Windows\system32\lsass.exe
22:15:35.0181 0x0e8c KeyIso - ok
22:15:35.0201 0x0e8c [ B7895B4182C0D16F6EFADEB8081E8D36, BAC3BAD22207C8826125FD7721C96F2C7A23896 0FD9398A3D4573E14648E9DB9 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:15:35.0203 0x0e8c KSecDD - ok
22:15:35.0228 0x0e8c [ D30159AC9237519FBC62C6EC247D2D46, 10BDE041C95D0CCD3591ED497002043FEC3A5F7 32D7AE311FBA457E0FE16CE4B ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
22:15:35.0232 0x0e8c KSecPkg - ok
22:15:35.0263 0x0e8c [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B6 9033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll
22:15:35.0272 0x0e8c KtmRm - ok
22:15:35.0291 0x0e8c [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B0744971 2B21B50E03378BEF04AF180F9 ] LanmanServer C:\Windows\System32\srvsvc.dll
22:15:35.0305 0x0e8c LanmanServer - ok
22:15:35.0340 0x0e8c [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86 256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:15:35.0343 0x0e8c LanmanWorkstation - ok
22:15:35.0419 0x0e8c [ F8A7212D0864EF5E9185FB95E6623F4D, 277EAA06BD3D1CB31E6CD7B9ECD3A4B7D4AB7A3 69DB5FFF04EC7D749DF26E3D2 ] lirsgt C:\Windows\system32\DRIVERS\lirsgt.sys
22:15:35.0420 0x0e8c lirsgt - ok
22:15:35.0469 0x0e8c [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD 5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:15:35.0470 0x0e8c lltdio - ok
22:15:35.0499 0x0e8c [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08D EFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:15:35.0504 0x0e8c lltdsvc - ok
22:15:35.0524 0x0e8c [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295 C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll
22:15:35.0526 0x0e8c lmhosts - ok
22:15:35.0556 0x0e8c [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777 E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
22:15:35.0559 0x0e8c LSI_FC - ok
22:15:35.0576 0x0e8c [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B 22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
22:15:35.0579 0x0e8c LSI_SAS - ok
22:15:35.0591 0x0e8c [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09 BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:15:35.0593 0x0e8c LSI_SAS2 - ok
22:15:35.0613 0x0e8c [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93C F14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:15:35.0616 0x0e8c LSI_SCSI - ok
22:15:35.0626 0x0e8c [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A4 93DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys
22:15:35.0628 0x0e8c luafv - ok
22:15:35.0665 0x0e8c [ 8BE71D7EDB8C7494913722059F760DD0, BA02D1EC025BDA8ADAE34483AB6B422A75D0C11 392761F83BCB0D0ADB5B1EAE2 ] LVPr2Mon C:\Windows\system32\DRIVERS\LVPr2Mon.sys
22:15:35.0666 0x0e8c LVPr2Mon - ok
22:15:35.0725 0x0e8c [ ED643E777BA3F7151EF3F0FB6BE4F7F0, 94B96367ECF2140299F36D93C00C9FE666953BE A6A1253EEEAAC439A682D38CA ] LVRS C:\Windows\system32\DRIVERS\lvrs.sys
22:15:35.0733 0x0e8c LVRS - ok
22:15:35.0899 0x0e8c [ 5BC80451109A8DD7F2DDD35BCE2929A3, F97BAD2D43D1E199841BAE5707424B49B4451CD 486F249646E898FC7CC7AB4C8 ] LVUVC C:\Windows\system32\DRIVERS\lvuvc.sys
22:15:35.0998 0x0e8c LVUVC - ok
22:15:36.0068 0x0e8c [ 69BC2B743D723D1923FCE50EB68003CB, 7027BC0F41A8F6F31E4C072DAC7F2CA82B7BE7B 6197F4B7AA63152F4F73AACC0 ] MAUSBMIDI C:\Windows\system32\DRIVERS\MAudioUSBMIDI.sys
22:15:36.0072 0x0e8c MAUSBMIDI - ok
22:15:36.0107 0x0e8c [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027A EA3FA4075659FB088AB62B588 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
22:15:36.0111 0x0e8c Mcx2Svc - ok
22:15:36.0219 0x0e8c [ 7CF1B716372B89568AE4C0FE769F5869, 0D70A7A594BCFBB26D7249C0F4B0AF9EF874F23 18B3FDCE44648CC61279594ED ] MDM C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
22:15:36.0227 0x0e8c MDM - ok
22:15:36.0251 0x0e8c [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38 919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
22:15:36.0253 0x0e8c megasas - ok
22:15:36.0302 0x0e8c [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A2 14833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
22:15:36.0309 0x0e8c MegaSR - ok
22:15:36.0354 0x0e8c [ 123271BD5237AB991DC5C21FDF8835EB, 004F8F9228EE291A0E36CE33078D572D6173351 6F9AA5CFC832AF204C6869E89 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
22:15:36.0356 0x0e8c Microsoft Office Groove Audit Service - ok
22:15:36.0393 0x0e8c [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC08 19C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll
22:15:36.0395 0x0e8c MMCSS - ok
22:15:36.0410 0x0e8c [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE 0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys
22:15:36.0413 0x0e8c Modem - ok
22:15:36.0438 0x0e8c [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA 3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:15:36.0439 0x0e8c monitor - ok
22:15:36.0477 0x0e8c [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AE CEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:15:36.0479 0x0e8c mouclass - ok
22:15:36.0503 0x0e8c [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A649 7854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
22:15:36.0504 0x0e8c mouhid - ok
22:15:36.0542 0x0e8c [ FC8771F45ECCCFD89684E38842539B9B, 806DDF2B4830CA866582FE74A521BB7DF26CA0E 19013DAF584D3677FB48CC77A ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
22:15:36.0544 0x0e8c mountmgr - ok
22:15:36.0626 0x0e8c [ 0329A45C849C9D77901094B8FFE8BBB9, 2151C15A4185FABBC3367B8213017B45E08C43E 26E1D8942E707E217C6A5EDA7 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
22:15:36.0640 0x0e8c MozillaMaintenance - ok
22:15:36.0682 0x0e8c [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF483121 2EA2DE4FCA33BEE26EBB47420 ] mpio C:\Windows\system32\drivers\mpio.sys
22:15:36.0698 0x0e8c mpio - ok
22:15:36.0725 0x0e8c [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863B A0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:15:36.0726 0x0e8c mpsdrv - ok
22:15:36.0803 0x0e8c [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F41 5CBABB3B87DDE92C360675021 ] MpsSvc C:\Windows\system32\mpssvc.dll
22:15:36.0814 0x0e8c MpsSvc - ok
22:15:36.0859 0x0e8c [ 21F4B24ACFC79A483515BD986DD9043F, 22681907E02E0B723ABE2CEF0602D36C8EF862E 7E2B62A9B40A5EF582E58D7BA ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:15:36.0893 0x0e8c MRxDAV - ok
22:15:36.0930 0x0e8c [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A 2B618F263093D7045E4FFD65C ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:15:36.0933 0x0e8c mrxsmb - ok
22:15:36.0983 0x0e8c [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441 F3FAD75BC9E751FB814403668 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:15:36.0987 0x0e8c mrxsmb10 - ok
22:15:37.0006 0x0e8c [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F 4CEFC444382959E2061BC3B17 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:15:37.0008 0x0e8c mrxsmb20 - ok
22:15:37.0042 0x0e8c [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE3 8178FF3628EB74CB6CD37C584 ] msahci C:\Windows\system32\drivers\msahci.sys
22:15:37.0053 0x0e8c msahci - ok
22:15:37.0075 0x0e8c [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80 084065ED05363B77868397304 ] msdsm C:\Windows\system32\drivers\msdsm.sys
22:15:37.0079 0x0e8c msdsm - ok
22:15:37.0112 0x0e8c [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC 13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe
22:15:37.0116 0x0e8c MSDTC - ok
22:15:37.0167 0x0e8c [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282 A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:15:37.0173 0x0e8c Msfs - ok
22:15:37.0187 0x0e8c [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696 A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
22:15:37.0188 0x0e8c mshidkmdf - ok
22:15:37.0228 0x0e8c [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C1642 87966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
22:15:37.0230 0x0e8c msisadrv - ok
22:15:37.0289 0x0e8c [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A911 58812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:15:37.0301 0x0e8c MSiSCSI - ok
22:15:37.0306 0x0e8c msiserver - ok
22:15:37.0334 0x0e8c [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2 016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:15:37.0335 0x0e8c MSKSSRV - ok
22:15:37.0361 0x0e8c [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440 D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:15:37.0362 0x0e8c MSPCLOCK - ok
22:15:37.0383 0x0e8c [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553 FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:15:37.0394 0x0e8c MSPQM - ok
22:15:37.0432 0x0e8c [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428 F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:15:37.0436 0x0e8c MsRPC - ok
22:15:37.0448 0x0e8c [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0 BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
22:15:37.0449 0x0e8c mssmbios - ok
22:15:37.0461 0x0e8c [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC 7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:15:37.0463 0x0e8c MSTEE - ok
22:15:37.0476 0x0e8c [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EE DBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
22:15:37.0477 0x0e8c MTConfig - ok
22:15:37.0488 0x0e8c [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA0 8B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys
22:15:37.0489 0x0e8c Mup - ok
22:15:37.0533 0x0e8c [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA9 38B568FF04981E98B19BFBC5C ] napagent C:\Windows\system32\qagentRT.dll
22:15:37.0541 0x0e8c napagent - ok
22:15:37.0579 0x0e8c [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCC B744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:15:37.0583 0x0e8c NativeWifiP - ok
22:15:37.0660 0x0e8c [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8 A45196EBD965C3A355836A9C7 ] NDIS C:\Windows\system32\drivers\ndis.sys
22:15:37.0676 0x0e8c NDIS - ok
22:15:37.0754 0x0e8c [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB 8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
22:15:37.0758 0x0e8c NdisCap - ok
22:15:37.0795 0x0e8c [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2C F49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:15:37.0803 0x0e8c NdisTapi - ok
22:15:37.0842 0x0e8c [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C48 9824BD5FE95B0C20699764EF7 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:15:37.0844 0x0e8c Ndisuio - ok
22:15:37.0882 0x0e8c [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736 E14003AE1DAB081BA5C0C9B14 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:15:37.0893 0x0e8c NdisWan - ok
22:15:37.0925 0x0e8c [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE6 3528EA1E9D7E30F7138918FFA ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:15:37.0927 0x0e8c NDProxy - ok
22:15:37.0944 0x0e8c [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237 D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:15:37.0958 0x0e8c NetBIOS - ok
22:15:38.0003 0x0e8c [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D04 4D4B4784CD952910345DC2ED0 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
22:15:38.0009 0x0e8c NetBT - ok
22:15:38.0024 0x0e8c [ 81951F51E318AECC2D68559E47485CC4, ACF76395EF4A2ED03AB919A9DA04D3A4C03B4D0 EDC60BE123B3BE1AFE78BC71B ] Netlogon C:\Windows\system32\lsass.exe
22:15:38.0026 0x0e8c Netlogon - ok
22:15:38.0050 0x0e8c [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF9 5B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll
22:15:38.0057 0x0e8c Netman - ok
22:15:38.0096 0x0e8c [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697F C7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:15:38.0130 0x0e8c NetMsmqActivator - ok
22:15:38.0152 0x0e8c [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697F C7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:15:38.0155 0x0e8c NetPipeActivator - ok
22:15:38.0184 0x0e8c [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861 D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll
22:15:38.0194 0x0e8c netprofm - ok
22:15:38.0205 0x0e8c [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697F C7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:15:38.0208 0x0e8c NetTcpActivator - ok
22:15:38.0213 0x0e8c [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697F C7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:15:38.0216 0x0e8c NetTcpPortSharing - ok
22:15:38.0234 0x0e8c [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494 908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
22:15:38.0236 0x0e8c nfrd960 - ok
22:15:38.0472 0x0e8c [ 815EF9EDE6869CFF730C1DD236E519EA, BF09361BCAB6A1EB3D34257D97860078CF16DCE 811EB1A8E64F1BDD2E1530A80 ] NIHardwareService C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
22:15:38.0553 0x0e8c NIHardwareService - ok
22:15:38.0655 0x0e8c [ EA7BB4CC7C9AB8A3B70F4F696E6B3DDB, A8C56BB1ED4EFCBA6A8C0306130D77C373BF458 C968D20E1704D6B6EA178C897 ] NIWinCDEmu C:\Windows\system32\DRIVERS\NIWinCDEmu.sys
22:15:38.0657 0x0e8c NIWinCDEmu - ok
22:15:38.0693 0x0e8c [ 374071043F9E4231EE43BE2BB48DD36D, C4FA3FC40CC49DBBB91901D14210A55D3831FAC 9F9B3FF45FCA7F5CF242C9E92 ] NlaSvc C:\Windows\System32\nlasvc.dll
22:15:38.0699 0x0e8c NlaSvc - ok
22:15:38.0727 0x0e8c [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C 53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:15:38.0729 0x0e8c Npfs - ok
22:15:38.0751 0x0e8c [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B 18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll
22:15:38.0753 0x0e8c nsi - ok
22:15:38.0773 0x0e8c [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3B F42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:15:38.0775 0x0e8c nsiproxy - ok
22:15:38.0848 0x0e8c [ 5E43D2B0EE64123D4880DFA6626DEFDE, 164413A22DE58B19EA2B4120034B46D6BE1F424 B80C3421E10BE5C81153D049F ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:15:38.0875 0x0e8c Ntfs - ok
22:15:38.0892 0x0e8c [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F3 4D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys
22:15:38.0893 0x0e8c Null - ok
22:15:38.0942 0x0e8c [ ED53B817E63AFFBA328C2E9632FBF487, DF5E17B6BB8CA640415410E3134B65674F52204 F54274BB6A0AFA7D831AA6531 ] NVHDA C:\Windows\system32\drivers\nvhda32v.sys
22:15:38.0946 0x0e8c NVHDA - ok
22:15:39.0290 0x0e8c [ 75FA3DC6C2838F35B15CF45E9E0D10A8, 483062E27D167C3B56583BD0D4200919153EC5B 02D164FD78EA8AA7EB9464Please download and run MicroSoft Safety Scanner. This will take about 20 minutes to run and will produce a log if your computer was infected. Please post the log. This scanner only has a shelf life of 10 days so you will need to download a new one if you want to run a scan after the trial period has expired.

Quote
If anything it is worse now - two freezes in the last hour - i.e. mouse stops working, keyboard non-responsive and then machine reboots on its own.
This pretty much indicates a hardware problem. How does the computer WORK in Safe Mode?Nothing found.
I was prompted to run chkdsk on D:
I now have an awful lot of .chk files to go through, but the computer does seem to be free of malware
What do you reckon?Quote from: Maffu on October 11, 2013, 07:37:42 PM
Nothing found.
I was prompted to run chkdsk on D:
I now have an awful lot of .chk files to go through, but the computer does seem to be free of malware
What do you reckon?
I quite sure it's clean but those other problems with the freezing and the keyboard is another issue.Well it's been quite stable since I did Chkdsk and a windows update.
I may need to change my D: - I'll keeop an eye on it though.
Thanks for all your help Superdave.
Is there anything else I need to do?Yes, we should do some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
****************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This RUNS the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
*****************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ACTIVEX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.Done, done, done and done.
Thank you so much for your time on this SuperDave. You and the other experts on this site do a great service for complete strangers and you should be rightfully proud of it.
Have a good day Just one thing - since adding WOT and SpywareBlaster my flashplayer now crashes on every pageload and my sound is completely gone. Quote
since adding WOT and SpywareBlaster my flashplayer now crashes on every pageload and my sound is completely gone.
Try uninstalling SpywareBlaster and see if that helps. This should get your sound back.

Please download and run MS Fix-it from here. I uninstalled spywareblaster and restarted and it fixed the problems - just in time for my D: to die a messy death.
I've managed to recover pretty much all the data on it and stick it onto other drives.
Other than that my machine seems to be running fine Ok, I'm glad that worked out for you.
2367.

Solve : I think I have a PUP/virus on this drive.?

Answer» I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the FOLLOWING link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be PATIENT as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
SuperDave I ran the ESET scanner but lost my internet during the first run.
So I closed it off and it must have followed its closedown settings and deleted the potential threats (7 found).
So I ran it again and after 7 HRS it finished.

I had a look for the log files but cant find anything.
My settings didnt have facility to set where the downloads were to be sent, just the 2 tick boxes then advanced settings.

I went to program files ESET and then into log but it was empty?

Anyway, an UPDATE to performance and hijacking occurrences.
My webpages have come back to (normal?) what I've been used to seeing and the unexpected opening of ads in new windows has stopped.
All in all SuperDave I believe we have managed to cure it (or so it seems).

Quote from: evilfantasy link=topic,46313.msg286861.html#msg286861
Just because you have been cleaned of an infection, that doesn't always mean the work is over.


Do you think we need to go further or will we consider this as a successful outcome?

Many thanks for your assistance SuperDave. ImnoGuru Ok, we can do some cleanup and we'll be done.

Download this program and run it Uninstall ComboFix .It will remove ComboFix for you.

Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, VIRUSES and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thanks for your help SuperDave.

Just finalized all the cleanup and I haven't had any interference or misdirections.
All systems go here. In fact its probably the cleanest its ever been to be honest.

Many thanks for your guidance.

ImnoGuru You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
2368.

Solve : OOps install flsahplayer message?

Answer»

If this doesn't remove ComboFix, please let me know.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the WORD ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and RESETS System Restore.
***************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
***************************************
Go to Microsoft Windows UPDATE and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity THEFT, spyware, spam, viruses and unreliable shopping SITES. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.
2369.

Solve : Kindle Fire - Pop up that states a Virus Detected, ( seems fake )?

Answer»

So my wife was on her Kindle Fire the other day and a message displayed that her Kindle Fire had a virus. She gave it to me to check it out and I carefully navigated to see what was going on without making MATTERS worse.

It seems as though it was malware pop up for Kindle Fire directed to scare PEOPLE into installing an antivirus application that is not Amazon software approved. I declined the installation of this antivirus software which made claims to an infection and hadn't seen any further pop ups warning of a virus, since after all how can a virus be detected without an antivirus installed to begin with, so it seems like scareware.

Anyone else have a Kindle Fire that has seen this malware type pop up trying to scare people into downloading a questionable antivirus for Kindle Fire's which is more than likely malware itself due to the scare tactics used in trying to get people to select to download and install this non Amazon approved software?

Also is there any antivirus or other security software apps that should be RUNNING on a Kindle Fire that she might not already have running?

My daughter and my wife download all sorts of STUFF for it more games than books etc, and so if there is something that should be added to protect against an infection, they PROBABLY need it.

*My knowledge of the Kindle Fire is pretty basic. I fixed it for my wife when the digitizer got shattered, and I know how to go in and make basic config changes to it such as connect it to my wifi etc, but I have no need for it myself and played with it less than 10 minutes overall since we got it, so I am not a guru with its features etc. But if someone points out what to check out on it, I can poke around and find my way with some direction.

Thanks

2370.

Solve : Ad Aware removed trojan now exe files do not work?

Answer»

I have windows 7 and after scanning & preforming recommended operations on ad aware and restarting my exe files do not work. Please help!Please DOWNLOAD SREng

  • Extract it to Desktop and double click SREngLdr.EXE to run it
  • Select System Repair from the left pane.
  • Click on File Association
  • Select all entries that has an Error status click [Repair]
  • Refer to this image for an example:

  • In your case, it would be .EXE
  • Close SREng now.
.Thanks Dave but it won't run does the same as all the others. Circle spins for a couple seconds like it's thinking about it then back to normal cursor...Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which MAY help allow other programs to run.
Save Rkill to your desktop.

There are 7 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and CHOOSE Run as Administrator


You only need to get one of these to run, not all of them. You may get warnings from your ANTIVIRUS about this tool, ignore them or shutdown your antivirus.

* Rkill.exe
* Rkill.com
* Rkill.scr
* WiNlOgOn.exe
* uSeRiNiT.exe
* iExplore.exe
* eXplorer.exe
Once you've gotten one of them to run then try to immediately run the following.
Thanks Dave but already tried those also the black dos looking box pops up for a second then goes away & nothing... Did you try running any of these as Administrator?

Now download and Run exeHelper

•Please download exeHelper to your desktop.

•Double-click on exeHelper.com to run the fix.

•A black window should pop up, press any key to close once the fix is completed.
•Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
.
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file)
********************************
You could also try this:

Please download and run MS Fix-it from here.

Do you have the Recovery Console on that computer?
2371.

Solve : Not sure if a virus or not?

Answer»

i have been having an issue where when I click on something on the screen, my screen freezes and turns multi-colored with a white block, which is the mouse. The only way to make this go away is by restarting the PC. If I just let it sit, the screens will eventually shut off, even though the PC is processing something. I don't know if anyone has seen this before. When I run a boot-scan, with Avast, it doesn't pick anything up. I was recently infected with the conduit virus, which was left some other virus which have been isolated. Attached is a picture of what I am talking about. Didn't know if this was a virus or a hardware issue and wasn't sure where to post this. Thanks!

-Edit-
I forgot to mention that when I am running games, this issue seems to stay inactive.

[recovering disk space, attachment deleted by admin]This certainly looks like a problem with the video card or drivers. Try running your computer in Safe Mode to see how it GOES there. I don't see an issue in safe mode. Then again I really can't run anything. Like I said above, I can run high graphics games with no issue. It seems to happen right after logging in to the desktop or just browsing the Internet.Ok, let's run some scans.

Please download AdwCleaner by Xplode onto your Desktop.

  • Please close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with OK
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile in your reply.
  • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
********************************************************
Please download Malwarebytes Anti-Malware from here.
Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has LOADED, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and PASTE the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
*************************************************
Please download Junkware Removal Tool to your desktop.

•Warning! Once the scan is complete JRT will shut down your browser with NO warning.

•Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
# AdwCleaner v2.306 - Logfile created 08/20/2013 at 09:12:23
# Updated 19/07/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Admin - ADMIN-HP
# Boot Mode : Normal
# Running from : C:\Users\Admin\Downloads\adwcleaner.exe
# Option [Delete]


***** [SERVICES] *****

Stopped & Deleted : Updater By SweetPacks

***** [Files / Folders] *****

File Deleted : C:\END
File Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage
File Deleted : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.conduit.com_0.localstorage-journal
File Deleted : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\lw6ulw32.default\searchplugins\Conduit.xml
Folder Deleted : C:\Program Files (x86)\Conduit
Folder Deleted : C:\Program Files (x86)\SweetIM
Folder Deleted : C:\Program Files (x86)\TornTV.com
Folder Deleted : C:\ProgramData\APN
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\Users\Admin\AppData\Local\Conduit
Folder Deleted : C:\Users\Admin\AppData\Local\Temp\APN
Folder Deleted : C:\Users\Admin\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Admin\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Admin\AppData\LocalLow\SweetIM
Folder Deleted : C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
Folder Deleted : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\lw6ulw32.default\jetpack
Folder Deleted : C:\Windows\SysWOW64\WNLT

***** [Registry] *****

Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ImInstaller
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Key Deleted : HKLM\Software\Classes\Installer\Features\FB6D58DD787439A4995AF3C00FEA8843
Key Deleted : HKLM\Software\Classes\Installer\Products\FB6D58DD787439A4995AF3C00FEA8843
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3291326
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{DD85D6BF-4787-4A93-99A5-3F0CF0AE8834}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKLM\SOFTWARE\Tarma Installer

***** [Internet Browsers] *****

-\\ Internet Explorer v10.0.9200.16660

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (en-US)

File : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\lw6ulw32.default\prefs.js

C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\lw6ulw32.default\user.js ... Deleted !

Deleted : user_pref("CT3291326.FF19Solved", "true");
Deleted : user_pref("CT3291326.UserID", "UN38345074672021711");
Deleted : user_pref("CT3291326.addressUrlXPETakeover", "true");
Deleted : user_pref("CT3291326.autoDisableScopes", 0);
Deleted : user_pref("CT3291326.browser.search.defaultthis.en gineName", "true");
Deleted : user_pref("CT3291326.defaultSearchXPETakeover", "true");
Deleted : user_pref("CT3291326.fullUserID", "UN38345074672021711.IN.2013070183434");
Deleted : user_pref("CT3291326.installDate", "01/07/2013 8:34:34");
Deleted : user_pref("CT3291326.installSessionId", "{AA458AEE-F4B4-4283-830A-2022F5ECBAC0}");
Deleted : user_pref("CT3291326.installSp", "TRUE");
Deleted : user_pref("CT3291326.installerVersion", "1.5.4.1");
Deleted : user_pref("CT3291326.keyword", "true");
Deleted : user_pref("CT3291326.originalHomepage", "hxxp://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.100[...]
Deleted : user_pref("CT3291326.originalSearchAddressUrl", "");
Deleted : user_pref("CT3291326.originalSearchEngine", "Bing");
Deleted : user_pref("CT3291326.searchRevert", "false");
Deleted : user_pref("CT3291326.searchUserMode", "2");
Deleted : user_pref("CT3291326.smartbar.homepage", "true");
Deleted : user_pref("CT3291326.startPageXPETakeover", "true");
Deleted : user_pref("CT3291326.versionFromInstaller", "10.16.4.19");
Deleted : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Deleted : user_pref("browser.search.defaultthis.engineName", "KeyBar 1.13 Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3291326&CUI[...]
Deleted : user_pref("browser.search.selectedEngine", "KeyBar 1.13 Customized Web Search");
Deleted : user_pref("smartbar.addressBarOwnerCTID", "CT3291326");
Deleted : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3291326&CUI=UN383450746[...]
Deleted : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT[...]
Deleted : user_pref("smartbar.defaultSearchOwnerCTID", "CT3291326");
Deleted : user_pref("smartbar.homePageOwnerCTID", "CT3291326");
Deleted : user_pref("smartbar.machineId", "7BJKVFYD6GT0C+ECYPMUYQUBWOECCYHN6OFL7FTSCPUPEVFU7FWNA/ONJ76XIOQHLH+[...]
Deleted : user_pref("smartbar.originalHomepage", "hxxp://search.conduit.com/?ctid=CT3291326&CUI=UN383450746720[...]
Deleted : user_pref("{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}.ScriptData_WSG_blackList", "form=CONTLB|babsrc=too[...]
Deleted : user_pref("{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}.ScriptData_WSG_whiteList", "{\"search.babylon.com\[...]
Deleted : user_pref("{7D4F1959-3F72-49d5-8E59-F02F8AA6815D}.ScriptData_product_name", "Updater By SweetPacks")[...]

-\\ Google Chrome v28.0.1500.95

File : C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted [l.3684] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT3291326&SearchSource=48&CUI[...]

*************************

AdwCleaner[S1].txt - [8669 octets] - [20/08/2013 09:12:23]

########## EOF - C:\AdwCleaner[S1].txt - [8729 octets] ##########

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.08.19.06

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16660
Admin :: ADMIN-HP [administrator]

8/19/2013 11:10:18 PM
mbam-log-2013-08-19 (23-10-18).txt

Scan type: Full scan (C:\|E:\|Q:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 745254
Time elapsed: 2 hour(s), 20 minute(s), 10 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 27
HKLM\SYSTEM\CurrentControlSet\Services\Updater By SweetPacks (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D} (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKCR\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13} (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKCR\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB} (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKCR\Extension.ExtensionHelperObject.1 (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKCR\Extension.ExtensionHelperObject (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D} (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D} (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{7D4F1959-3F72-49D5-8E59-F02F8AA6815D} (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCR\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCR\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCR\SWEETIE.IEToolbar.1 (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCR\SWEETIE.IEToolbar (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCR\Toolbar3.SWEETIE.1 (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCR\Toolbar3.SWEETIE (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
HKCR\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
HKCR\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook.1 (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.

Registry Values Detected: 6
HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{7D4F1959-3F72-49D5-8E59-F02F8AA6815D} (PUP.Optional.SweetPacks.A) -> Data: C:\Program Files\Updater By SweetPacks\Firefox -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser|{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Data: 썛愘ᇜ犜ጀ유䞘 -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{EEE6C35B-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{7D4F1959-3F72-49d5-8E59-F02F8AA6815D} (PUP.Optional.SweetPacks.A) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\SWEETIM\TOOLBARS\INTERNET EXPLORER\MGHELPERAPP.EXE (PUP.Optional.SweetIM) -> Data: 1 -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|C:\PROGRAM FILES (X86)\SWEETIM\TOOLBARS\INTERNET EXPLORER\MGTOOLBARPROXY.DLL (PUP.Optional.SweetIM) -> Data: 1 -> Quarantined and deleted successfully.

Registry Data Items Detected: 2
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit) -> Bad: (http://search.conduit.com?SearchSource=10&CUI=UN34029507811473428&UM=2&ctid=CT3291326) Good: (http://www.google.com) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.SweetPacks) -> Bad: (http://start.sweetpacks.com/?src=10&st=12&crg=3.5000006.10042&barid={3DF2DA36-DA9E-11E2-A9A8-D0DF9AA57E02}) Good: (http://www.google.com) -> Quarantined and repaired successfully.

Folders Detected: 16
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\content (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\content\libraries (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\content\resources (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\locale (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\locale\en-US (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\skin (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\defaults (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\defaults\preferences (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\libraries (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\resources (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.

Files Detected: 73
C:\Program Files\Updater By SweetPacks\ExtensionUpdaterService.exe (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Extension32.dll (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (PUP.Optional.SweetPacks) -> Quarantined and deleted successfully.
C:\$RECYCLE.BIN\S-1-5-21-2473842194-2191913869-1839372111-1000\$R7989WJ.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\$RECYCLE.BIN\S-1-5-21-2473842194-2191913869-1839372111-1000\$RI292XM.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Program Files\Adobe\Adobe After Effects CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Program Files\Adobe\Adobe Media Encoder CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Extension64.dll (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\ClearHist.exe (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgcommon.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgconfig.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgHelperApp.exe (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mghooking.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mglogger.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgsimcommon.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgToolbarProxy.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SweetIM\Toolbars\Internet Explorer\mgxml_wrapper.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Users\Admin\.frostwire5\updates\frostwire-5.6.3.windows.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CQAK28VK\mgsqlite3[1].7z (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RA6L6EBQ\KeyBar_1.13[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T86AQCVW\KeyBar_1_13_wpf[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T86AQCVW\statisticsstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T86AQCVW\WebCakesetup[1].exe (Trojan.PUP.WebCake.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TVCL6PGU\checktbexist[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TVCL6PGU\stublogic[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\1371838432_15489308_427_4.tmp (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\1371838445_15502583_85_6.tmp (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\hsbing_717_active.exe (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\mgsqlite3.7z (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\mgsqlite3.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\Shortcut_bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\ct3291326\chLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\ct3291326\ctbe.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\ct3291326\ffLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\ct3291326\ieLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\ct3291326\spch.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\ct3291326\spff.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\ct3291326\statisticsStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\AppData\Local\Temp\ct3291326\stub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Admin\Desktop\New folder (5)\Adobe Photoshop CS6 Extended\DLL FILE\32bit\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Users\Admin\Desktop\New folder (5)\Adobe Photoshop CS6 Extended\DLL FILE\64bit\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Users\Admin\Downloads\DAEMONToolsUltra100-0068.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Admin\Downloads\frostwire-5.5.2.windows.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Admin\FrostWire\Torrent Data\Adobe Photoshop CS6\Adobe Photoshop CS6 (Patch + Instructions)\Patch\32bit\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Users\Admin\FrostWire\Torrent Data\Adobe Photoshop CS6\Adobe Photoshop CS6 (Patch + Instructions)\Patch\64bit\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Users\Admin\FrostWire\Torrent Data\Adobe.After.Effects.CS6.v11.0.1.12.Multilingual.mundomanauales.com\Crack\Adobe After Effects CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Users\Admin\FrostWire\Torrent Data\Adobe.After.Effects.CS6.v11.0.1.12.Multilingual.mundomanauales.com\Crack\Adobe BRIDGE CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Users\Admin\FrostWire\Torrent Data\Adobe.After.Effects.CS6.v11.0.1.12.Multilingual.mundomanauales.com\Crack\Adobe Media Encoder CS6\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Users\Admin\FrostWire\Torrent Data\Sony ACID Pro 7.0c+DI-KeyGen_(diMi)\Keygen (in here so Antivirus Doesn't Kill It).zip (Trojan.Agent.CK) -> Quarantined and deleted successfully.
C:\Users\Admin\FrostWire 5\frostwire-installer.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Admin\FrostWire 5\OCSetupHlp.dll (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Windows\Installer\ebe107.msi (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\InstallerHelper.dll (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\unins000.dat (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\unins000.exe (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome.manifest (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\install.rdf (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\content\main.js (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\content\main.xul (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\content\libraries\DataExchangeScript.js (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\content\resources\localscript.js (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\locale\en-US\overlay.dtd (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\chrome\skin\overlay.css (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\Firefox\defaults\preferences\defaults.js (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\libraries\DataExchangeScript.js (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Program Files\Updater By SweetPacks\resources\localscript.js (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.

(end)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.1 (08.19.2013:1)
OS: Windows 7 Home Premium x64
Ran by Admin on Tue 08/20/2013 at 9:17:59.32
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\lyricsing
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskSLib_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskSLib_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskSLib_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskSLib_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{11383C01-1BC3-4765-BCE6-9D95DE9A7A2B}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{4C058FEB-EA05-4B08-AD4D-65CC1593A338}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{11383C01-1BC3-4765-BCE6-9D95DE9A7A2B}



~~~ Files

Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npcouponprinter.dll"
Successfully deleted: [File] "C:\Program Files (x86)\mozilla firefox\plugins\npmozcouponprinter.dll"
Successfully deleted: [File] C:\Windows\syswow64\sho7165.tmp



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Admin\appdata\local\cre"
Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{0DB371AC-A9D0-45C4-9E71-19ED595E5C75}
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{2B9C7CC4-ED30-4F65-A561-9395CD18D995}
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{5AC073D7-B3F4-4CAD-9D0E-F9B3CB39EAAF}
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{6C9536DC-CEB8-4376-A577-39ED2E5B33CB}
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{74CF4FD6-7EB8-46AE-8F6E-AA593F8132A5}
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{A778FF63-03FD-4F85-82B2-1CD3211385FE}
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{B1615E73-150B-4279-9709-22A62C727055}
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{C2F118C1-EBD5-48FD-A0A9-BF75C0C6C7ED}
Successfully deleted: [Empty Folder] C:\Users\Admin\appdata\local\{E04FC13C-F641-41A4-BDDD-0920B514540B}



~~~ FireFox

Emptied folder: C:\Users\Admin\AppData\Roaming\mozilla\firefox\profiles\lw6ulw32.default\minidumps [8 files]



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bicnnkjibmphdeigoodpjlcklcnaobdj



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 08/20/2013 at 9:22:46.83
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
****************************************
Download Combofix from any of the links below, and save it to your DESKTOP.
If your version of Windows defaults to your download folder you will need to copy it to your desktop.

Link 1
Link 2
Link 3

To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
  • Close any open windows and double click ComboFix.exe to run it.

    You will see the following image:


Click I Agree to start the program.

ComboFix will then extract the necessary files and you will see this:



As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

If you did not have it installed, you will see the prompt below. Choose YES.



Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
2372.

Solve : Bootable Antivirus Rescue CDs?

Answer»

I just found this. It SEEMS to be a new list.
Comprehensive List of 26 Bootable Antivirus Rescue CDs for Offline Scanning
Many are Linux based and claim to be useful even for a WINDOWS system.

Does anybody here know more about these? Which ones work well?The only ones I've EVER USED were DOCTOR Web, Avira and OTLPE

2373.

Solve : Laptop Running Extremely Slow?

Answer»

Dave,

Is there anything else I need to do? Do I uninstall some of the programs you had me use?

Thanks.We can clean up after we REPAIR that slowness problem. Did you try ending all the processes I described in Reply #9? Yes, I did do that. The laptop got faster when I stopped one of the 4 svchost.exe's that was using about 22K. The others I stopped didn't make much difference.I would like to see what programs you have on your computer.

Please download: HiJackThis to your Desktop.

  • Double Click the HijackThis icon, located on your Desktop.
  • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
  • Accept the license agreement.
  • Click the Open the Misc Tools section button.
  • Click on the Open Uninstall Manager button.
  • Click on the Save list... button and specify where you would like to save this file. When you press Save button a Notepad will open with the contents of that file. Save the file to your desktop.
    Copy and paste this file in your next reply.
AVG is purported to be a resource hog. Please download and install MSE. Disable AVG and see if there is any change.

MicroSoft Security Essentials All versions and all languages.
Dave,

Here is the HJT log you requested. I temporarily disable AVG and the computer is running faster without it. I'm going to uninstall it and replace with Microsoft Security Essentials like you recommended. Is there any chance I had a bad install of AVG? I have it running on my work computer and my destop computer at home and never had any problems with it.

Adobe Flash Player 11 Plugin
Adobe Reader XI (11.0.03)
Apple Software Update
AVG 2013
AVG 2013
AVG 2013
CCleaner
Conexant HD Audio
DivX
GearDrvs
HDAUDIO Soft Data Fax Modem with SmartCP
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP DVD Play 2.3
HP HELP and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Software Update
HP User Guides 0037
HP User Guides--System Recovery
HP Wireless Assistant 2.00 G2
Intel(R) Graphics Media Accelerator Driver
Java 7 Update 25
Macromedia Shockwave Player
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Kernel-Mode Driver Framework FEATURE Pack 1.5
Microsoft Money 2006
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PROOF (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Standard Edition 2003
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Works
Mozilla Firefox 23.0.1 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB973686)
muvee autoProducer 5.0
NetWaiting
Quicken 2006
Revo Uninstaller 1.95
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office 2007 suites (KB2596615) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687311) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2760416) 32-Bit Edition
Security Update for Microsoft Office Excel 2007 (KB2687307) 32-Bit Edition
Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Word 2007 (KB2760421) 32-Bit Edition
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165-v2)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB982381)
Synaptics Pointing Device Driver
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
Windows Imaging Component
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows XP Service Pack 3
Wireless Home Network Setup

Quote
Is there any chance I had a bad install of AVG?
That's possible but highly unlikely. AVG always has been a resource hog and, SINCE no two computer are alike, it's difficult to say how it will work on each computer. Give MSE and try and see what happens. I see no malicious program installed. Please respond in a few days to see if there's any difference.
2374.

Solve : About malicious software?

Answer»

Why doesn't Microsoft Security Essentials detect cookies? Because they're not malicious software, and MSE is designed to detect viruses, spyware and other malicious software.
You can clear your cookies from your browser if you like.Here's a good tool to clear unwanted cookies.

SUPERAntiSpyware

If you already have SUPERAntiSpyware be sure to check for updates before scanning!

Download SuperAntispyware Free Edition (SAS)
* Double-click the icon on your desktop to run the installer.
* When asked to Update the program definitions, click YES
* If you encounter any problems while downloading the updates, manually download and unzip them from here
* Next click the Preferences BUTTON.

•Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
* Click the Scanning Control tab.
* Under Scanner Options make sure only the following are checked:

•Close browsers before scanning
•Scan for tracking cookies
•Terminate memory threats before quarantining
Please leave the others unchecked

•Click the Close button to leave the control center screen.

* On the main screen click Scan your computer
* On the left check the box for the drive you are scanning.
* On the right choose Perform Complete Scan
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete a summary box will appear. Click OK
* Make sure everything in the white box has a check next to it, then click Next
* It will quarantine what it found and if it asks if you want to reboot, click Yes

•To retrieve the removal information please do the following:
•After reboot, double-click the SUPERAntiSpyware icon on your desktop.
•Click Preferences. Click the Statistics/Logs tab.

•Under Scanner Logs, double-click SUPERAntiSpyware Scan LOG.

•It will open in your default text editor (preferably Notepad).
SAVE the notepad file to your desktop by clicking (in notepad) File > Save As...

* Save the log somewhere you can easily find it. (normally the desktop)
* Click close and close again to exit the program.
*Copy and Paste the log in your post.

2375.

Solve : Computer playing commercials several times a day?

Answer»

Download PROCESS Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program.
Click on View > Select Colunms.
In addition to already pre-selected options, make sure, the Command Line is selected, and press OK.
Go File>Save As, and save the report as Procexp.txt.
Attach the file to your next reply.ProcessCPUPrivate BytesWorking SetPIDDescriptionCompany NameCommand Line
System Idle Process23.280 K24 K0
System0.750 K55,732 K4
Interrupts0.380 K0 Kn/aHardware Interrupts and DPCs
smss.exe580 K1,092 K448
csrss.exe3,160 K7,324 K544
wininit.exe1,960 K5,296 K632
services.exe0.383,932 K8,872 K688
svchost.exe29.335,204 K9,204 K864Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k DcomLaunch
mobsync.exe8,928 K9,536 K4196Microsoft Sync CenterMicrosoft CorporationC:\Windows\System32\mobsync.exe -Embedding
wmplayer.exe1.1333,968 K46,216 K4476Windows Media PlayerMicrosoft Corporation"C:\Program Files (x86)\Windows Media Player\wmplayer.exe" /SkipFUE /RemoteOCXLaunch /SuppressDialogs
svchost.exe5,532 K9,188 K924Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k rpcss
MsMpEng.exe0.7579,076 K81,692 K976Antimalware Service ExecutableMicrosoft Corporation"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
atiesrxx.exe1,824 K4,472 K132AMD External Events Service ModuleAMDC:\Windows\system32\atiesrxx.exe
atieclxx.exe3,720 K6,528 K1912
svchost.exe21,348 K20,420 K680Host Process for Windows ServicesMicrosoft CorporationC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
audiodg.exe13,400 K16,208 K1076
svchost.exe2.63224,296 K229,760 K908Host Process for Windows ServicesMicrosoft CorporationC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
WUDFHost.exe6,352 K10,044 K1292
WUDFHost.exe5,396 K10,868 K3216
dwm.exe1,888 K4,768 K3968Desktop Window ManagerMicrosoft Corporation"C:\Windows\system32\Dwm.exe"
svchost.exe29,100 K41,940 K644Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k netsvcs
taskeng.exe3,108 K7,768 K2036
taskeng.exe11,224 K13,156 K3792Task Scheduler EngineMicrosoft Corporationtaskeng.exe {7B7A3079-ACFA-41BD-9913-81B9B023BF8E}
wuauclt.exe3,400 K6,680 K5316Windows UpdateMicrosoft Corporation"C:\Windows\system32\wuauclt.exe"
taskeng.exe2,296 K5,788 K480Task Scheduler EngineMicrosoft Corporationtaskeng.exe {ADAFDA34-10D5-428E-8D05-264F4AEA0B69}
runner.exe4,404 K9,052 K6836WebStroller runner moduleWebStroller inc."C:\Program Files (x86)\GC\Runner.exe"
chrome.exe0.7537,636 K50,732 K6888Google ChromeGoogle Inc."C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --user-data-dir=C:\Users\doug\AppData\Local\GC\Horsy
chrome.exe0.3826,320 K34,624 K2344Google ChromeGoogle Inc."C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prerender/PrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --user-data-dir="C:\Users\doug\AppData\Local\GC\Horsy" --renderer-print-preview --disable-html-notifications --disable-accelerated-video-decode --channel="6888.0.2066690245\1669816675" /prefetch:673131151
chrome.exe< 0.0123,664 K21,452 K6812Google ChromeGoogle Inc."C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prerender/PrerenderEnabled/UMA-New-Install-Uniformity-Trial/Control/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_16/UMA-Uniformity-Trial-1-Percent/group_43/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_02/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --user-data-dir="C:\Users\doug\AppData\Local\GC\Horsy" --extension-process --renderer-print-preview --disable-html-notifications --disable-accelerated-video-decode --channel="6888.1.435594069\265044850" /prefetch:673131151
chrome.exe8,220 K10,664 K6396Google ChromeGoogle Inc."C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=plugin --plugin-path="C:\Users\doug\AppData\Local\GC\Horsy\Default\Extensions\jmiibbdogibcphdfkkmlimfffneaecbc\2.4_0\plugin/convenience.dll" --lang=en-US --channel="6888.9.1660304995\784124598" --user-data-dir="C:\Users\doug\AppData\Local\GC\Horsy" /prefetch:-390060480
Clicker.exe< 0.013,756 K6,796 K2540WebStroller STROLLER moduleWebStrollerClicker.exe
svchost.exe3,084 K6,668 K1100Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k GPSvcGroup
SLsvc.exe9,184 K14,232 K1116Microsoft Software Licensing ServiceMicrosoft CorporationC:\Windows\system32\SLsvc.exe
svchost.exe12,532 K19,900 K1172Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k LocalService
svchost.exe21,416 K22,792 K1356Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k NetworkService
spoolsv.exe8,456 K14,064 K1588Spooler SubSystem AppMicrosoft CorporationC:\Windows\System32\spoolsv.exe
svchost.exe26,720 K31,256 K1612Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
PhotoshopElementsFileAgent.exe4,612 K1,292 K2028Adobe Photoshop Elements 7.0 (component)Adobe Systems IncorporatedC:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
armsvc.exe3,052 K5,932 K1896Adobe Acrobat Update ServiceAdobe Systems INCORPORATED"C:\Program Files (x86)\COMMON Files\Adobe\ARM\1.0\armsvc.exe"
Fuel.Service.exe2,508 K6,524 K956AMD Fuel ServiceAdvanced Micro Devices, Inc.C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe /launchService
AppleMobileDeviceService.exe5,012 K10,912 K1212MobileDeviceServiceApple Inc."C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
mDNSResponder.exe2,752 K6,040 K1464Bonjour ServiceApple Inc."C:\Program Files\Bonjour\mDNSResponder.exe"
BrowserDefender.exe3,852 K7,488 K1428Application ManagerPerformerSoft LLCC:\ProgramData\BrowserDefender\2.6.1562.221\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe
BrowserDefender.exe0.389,620 K13,556 K3512
cygrunsrv.exe7,688 K8,664 K2016C:\cygwin\bin\cygrunsrv.exe
dragon_updater.exe4,844 K10,884 K2088C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
ETService.exe31,064 K20,392 K2196Acer Empowering Technology Framework ServiceC:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe
LMIGuardianSvc.exe2,716 K6,668 K2280LMIGuardianSvcLogMeIn, Inc."C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe"
mbamscheduler.exe4,852 K9,176 K2448Malwarebytes Anti-MalwareMalwarebytes Corporation"C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe"
sqlservr.exe60,820 K1,476 K2504SQL Server Windows NTMicrosoft Corporation"c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS
svchost.exe3,416 K7,332 K2576Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
sqlwriter.exe4,624 K9,196 K2684SQL Server VSS Writer - 64 BitMicrosoft Corporation"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
svchost.exe4.897,156 K10,612 K2744Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k imgsvc
updateBrowseFox.exe28,332 K26,304 K2828BrowseFoxBrowseFox"C:\Program Files (x86)\BrowseFox\updateBrowseFox.exe"
vmnat.exe4,176 K7,760 K2984C:\Windows\system32\vmnat.exe
svchost.exe1,496 K3,420 K3032Host Process for Windows ServicesMicrosoft CorporationC:\Windows\System32\svchost.exe -k WerSvcGroup
SearchIndexer.exe0.75191,468 K141,972 K2108Microsoft Windows Search IndexerMicrosoft CorporationC:\Windows\system32\SearchIndexer.exe /Embedding
SearchProtocolHost.exe7,652 K12,916 K6436
SearchFilterHost.exe4,716 K8,732 K6388
XAudio64.exe1,664 K3,448 K2544Modem Audio ServiceConexant Systems, Inc.C:\Windows\system32\DRIVERS\xaudio64.exe
rundll32.exe0.385,572 K7,956 K2608RUNDLL32.EXE ykx64coinst,serviceStartProc
vmware-authd.exe7,852 K11,924 K3112VMware Authorization ServiceVMware, Inc."C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe"
vmnetdhcp.exe3,712 K7,076 K3312C:\Windows\system32\vmnetdhcp.exe
vmware-usbarbitrator64.exe5,984 K8,412 K3376VMware USB Arbitration ServiceVMware, Inc."C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe"
NisSrv.exe9,920 K4,648 K4056Microsoft Network Realtime Inspection ServiceMicrosoft Corporation"c:\Program Files\Microsoft Security Client\NisSrv.exe"
wmpnetwk.exe8,572 K15,532 K4520Windows Media Player Network Sharing ServiceMicrosoft Corporation"C:\Program Files\Windows Media Player\wmpnetwk.exe"
svchost.exe2,984 K59,448 K1344Host Process for Windows ServicesMicrosoft CorporationC:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
lsass.exe5,548 K4,556 K700Local Security Authority ProcessMicrosoft CorporationC:\Windows\system32\lsass.exe
lsm.exe3,412 K5,668 K708
csrss.exe23,832 K25,064 K652
winlogon.exe3,336 K7,968 K520
cygserver.exe5,368 K4,548 K2116
explorer.exe4.1467,584 K85,976 K240Windows ExplorerMicrosoft CorporationC:\Windows\Explorer.EXE
msseces.exe8,812 K15,012 K4020Microsoft Security Client User InterfaceMicrosoft Corporation"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
SetPoint.exe< 0.019,664 K20,076 K4012Logitech SetPoint Event Manager (UNICODE)Logitech, Inc."C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
KHALMNPR.exe< 0.017,596 K12,892 K2628Logitech KHAL Main ProcessLogitech, Inc.KHALMNPR.EXE /API
TSVNCache.exe< 0.014,208 K7,212 K3884TortoiseSVN status cachehttp://tortoisesvn.net"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
PrintScreen.exe4,044 K12,824 K2708Gadwin PrintScreenGadwin Systems, Inc"C:\Program Files (x86)\Gadwin Systems\PrintScreen\PrintScreen.exe" /nosplash
splwow64.exe2,128 K5,024 K4336Thunking Spooler APIS from 32 to 64 ProcessMicrosoft Corporationsplwow64
pidgin.exe16,536 K28,072 K1484PidginThe Pidgin developer community"C:\Program Files (x86)\Pidgin\pidgin.exe"
Skype.exe0.7590,196 K92,008 K1640Skype Skype Technologies S.A."C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
KeePass.exe< 0.017,792 K18,228 K2024KeePass Password Safe 1.26Dominik Reichl"C:\Program Files (x86)\KeePass Password Safe\KeePass.exe"
wmpnscfg.exe2,492 K6,524 K3896Windows Media Player Network Sharing Service Configuration ApplicationMicrosoft Corporation"C:\Program Files\Windows Media Player\wmpnscfg.exe"
SansaDispatch.exe5,716 K8,944 K4236Sansa DispatcherSanDisk Corporation"C:\Users\doug\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe"
Kies.exe0.3826,572 K29,620 K4244KiesSamsung"C:\Program Files (x86)\Samsung\Kies\Kies.exe" /preload
firefox.exe< 0.01354,296 K361,328 K2228FirefoxMozilla Corporation"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
dragon.exe< 0.01100,556 K125,660 K5124Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe"
dragon.exe< 0.01104,304 K108,580 K4780Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --disable-databases --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --disable-html-notifications --disable-accelerated-video-decode --channel="5124.0.1751541116\1067586024" /prefetch:673131151
dragon.exe23,884 K28,124 K4556Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.1.1555051201\492569239" /prefetch:673131151
dragon.exe23,932 K27,972 K4052Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.2.335876265\322448858" /prefetch:673131151
dragon.exe30,008 K36,252 K2704Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.3.1012085665\1144532263" /prefetch:673131151
dragon.exe23,944 K28,004 K5496Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.4.380300272\369878127" /prefetch:673131151
dragon.exe23,752 K27,260 K3436Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.5.481272259\695965767" /prefetch:673131151
dragon.exe25,512 K30,928 K4856Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.6.1860942155\79941906" /prefetch:673131151
dragon.exe23,800 K27,220 K6092Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.7.134441649\12151953" /prefetch:673131151
dragon.exe63,772 K69,768 K4808Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.8.1688867690\110531675" /prefetch:673131151
dragon.exe23,948 K27,580 K4392Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.9.586991473\168513548" /prefetch:673131151
dragon.exe25,396 K29,948 K4692Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.10.365712874\644138465" /prefetch:673131151
dragon.exe25,340 K30,960 K3848Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --extension-process --disable-html-notifications --disable-accelerated-video-decode --channel="5124.11.151482321\1251338912" /prefetch:673131151
dragon.exe58,504 K67,648 K6448Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --disable-databases --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --disable-html-notifications --disable-accelerated-video-decode --channel="5124.13.73542365\850066563" /prefetch:673131151
dragon.exe< 0.0162,824 K75,684 K5624Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --disable-databases --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --disable-html-notifications --disable-accelerated-video-decode --channel="5124.19.1330728909\1442621807" /prefetch:673131151
dragon.exe< 0.0137,252 K40,920 K6328Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=plugin --plugin-path="C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll" --lang=en-US --channel="5124.23.329830406\1095823025" /prefetch:-390060480
dragon.exe22,332 K28,232 K6584Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --disable-databases --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --disable-html-notifications --disable-accelerated-video-decode --channel="5124.24.1835325372\895175932" /prefetch:673131151
dragon.exe< 0.018,480 K14,088 K6692Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=plugin --plugin-path="C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll" --lang=en-US --channel="5124.25.1151867093\1250965280" /prefetch:-390060480
AcroRd32.exe< 0.018,144 K14,368 K1900Adobe Reader Adobe Systems Incorporated"C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe" /o /eo /L /b /id 6692
AcroRd32.exe< 0.0159,908 K67,528 K5552Adobe Reader Adobe Systems Incorporated"C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe" --channel=1900.0037F6A0.887128957 --type=renderer /o /eo /l /b /id 6692
dragon.exe< 0.0159,368 K68,148 K3720Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --disable-databases --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --disable-html-notifications --disable-accelerated-video-decode --channel="5124.26.807157130\140228043" /prefetch:673131151
dragon.exe< 0.0140,816 K50,608 K5464Comodo DragonComodo"C:\Program Files (x86)\Comodo\Dragon\dragon.exe" --type=renderer --disable-databases --lang=en-US --force-fieldtrials=ForceCompositingMode/thread/InfiniteCache/No/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderNoUse/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLoggedInPredictor/Enabled/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_11/UMA-Uniformity-Trial-1-Percent/group_59/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-20-Percent/group_03/UMA-Uniformity-Trial-5-Percent/group_15/UMA-Uniformity-Trial-50-Percent/default/ --disable-html-notifications --disable-accelerated-video-decode --channel="5124.28.459245070\1791278822" /prefetch:673131151
notepad++.exe< 0.0117,076 K23,564 K6204Notepad++ : a free (GNU) source code editorDon HO [emailprotected]"C:\Program Files (x86)\Notepad++\notepad++.exe"
7zFM.exe< 0.018,300 K15,336 K68967-Zip File ManagerIgor Pavlov"C:\Program Files (x86)\7-Zip\7zFM.exe" "C:\Users\doug\Desktop\ProcessExplorer.zip"
procexp.exe6,324 K10,496 K2416Sysinternals Process ExplorerSysinternals - www.sysinternals.com"C:\Users\doug\Desktop\procexp.exe"
procexp64.exe2.2624,328 K36,476 K2020Sysinternals Process ExplorerSysinternals - www.sysinternals.com"C:\Users\doug\Desktop\procexp.exe"
KiesTrayAgent.exe8,404 K17,148 K4432Kies TrayAgent ApplicationSamsung Electronics Co., Ltd."C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe"
jusched.exe3,436 K6,576 K4504Java(TM) Update SchedulerOracle Corporation"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
KeePass.exe26.3328,748 K21,600 K4660KeePassDominik Reichl"C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe" --preload
mHotkey.exe< 0.018,944 K10,492 K4992Multimedia Keyboard DriverC:\Windows\MHotkey.exe
ChiFuncExt.exe3,292 K6,224 K4300Input Assistant Software KernelChiconyC:\Windows\ChiFuncExt.exe
TSVNCache.exe3,784 K7,040 K5440
MpCmdRun.exe4,876 K9,220 K6012



[recovering disk space, attachment deleted by admin]Dave I had to bail out on this and do an reinstall this morning. The thing was beginning to bog down so badly it barely worked. Thanks for your help and sorry for wasting your time. Quote from: zulubanshee on September 09, 2013, 04:09:47 PM

Dave I had to bail out on this and do an reinstall this morning. The thing was beginning to bog down so badly it barely worked. Thanks for your help and sorry for wasting your time.
Hey, no problem. It was a learning experience for you and I. Good luck.
2376.

Solve : Keylogger on my computer??

Answer»

Ok, let's do some cleanup.

Download this program and run it Uninstall ComboFix .It will remove ComboFix for you.
*******************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup UTILITY along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
********************************
Go to Microsoft Windows Update and get all critical UPDATES.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will KEEP you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain COOKIES from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't KNOW what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thank you so much for all your help. I am extremely grateful, you have a fantastic service here.You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

2377.

Solve : External HDD infected?

Answer»

I've got an external hard disk drive, which has infected Windows XP on it. How to format this disk safely? Maybe using Linux or Windows installation disc?You can safely format it with L:Linux. You can use even a SMALL version pf Puppy Linux off of a USB or CD.
http://www.puppylinux.com/
Quote

Puppy's goals
Easily install to USB, Zip or hard drive media.
BOOTING from CD (or DVD), the CD drive is then free for other purposes.
Booting from CD (or DVD), save EVERYTHING back to the CD.
Booting from USB Flash drive, minimise writes to extend life indefinitely.
Extremely friendly for Linux newbies.
Boot up and run extraordinarily fast.
Have all the applications needed for daily use.
Will just work, no HASSLES.
Will breathe new life into old PCs
Load and run totally in RAM for diskless thin stations
These are extraordinary goals, yet Puppy comes close to achieving them all. The fundamental reason is that Puppy has been built from scratch, file-by-file, and is not based on any other Linux distribution. One of the most amazing features of Puppy is the range of powerful applications yet such tiny size ...and the speed.
I personally recommend it for simple teaks.Just right-click on the drive and choose format.
2378.

Solve : Yahoo Msg will not open ....can anybody sort this issue out ? w/log?

Answer»

The ESET log doesn't show that the infections were removed. Please run it again. There should be a box just above the "Scan archives" box alread checked. Please ensure that this box remains checked and run the scan. I ran the scanner again and selected both boxes this time:

C:\Desktop\Flash_Disinfector.exeprobably a variant of Win32/Agent.BWFKHA trojancleaned by deleting - quarantined
C:\Documents and Settings\User\My Documents\setupxv.exe.virprobably a variant of Win32/TrojanDownloader.Banload.KDRCNRT trojancleaned by deleting - quarantined
C:\Program Files\RegistryFix7\UninstlDll.dllWin32/Adware.ErrorClean applicationcleaned by deleting - quarantined
C:\Program Files\Sony\Welcome to VAIO life\Internet Services.exeprobably a variant of Win32/TrojanDropper.Agent.BLQHZVO trojancleaned by deleting - quarantined
C:\Program Files\Sony\Welcome to VAIO life\VAIO zone.exeprobably a variant of Win32/TrojanDropper.Agent.FYKSNPZ trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{0803D443-492F-46D4-A7CD-A0F2180414C9}\RP15\A0006085.DLLa variant of Win32/Toolbar.MyWebSearch applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{0803D443-492F-46D4-A7CD-A0F2180414C9}\RP16\A0006125.DLLWin32/Toolbar.AskSBar applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{0803D443-492F-46D4-A7CD-A0F2180414C9}\RP22\A0007280.exeprobably a variant of Win32/Agent.BWFKHA trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{0803D443-492F-46D4-A7CD-A0F2180414C9}\RP22\A0007281.dllWin32/Adware.ErrorClean applicationcleaned by deleting - quarantined
C:\System Volume Information\_restore{0803D443-492F-46D4-A7CD-A0F2180414C9}\RP22\A0007282.exeprobably a variant of Win32/TrojanDropper.Agent.BLQHZVO trojancleaned by deleting - quarantined
C:\System Volume Information\_restore{0803D443-492F-46D4-A7CD-A0F2180414C9}\RP22\A0007283.exeprobably a variant of Win32/TrojanDropper.Agent.FYKSNPZ trojancleaned by deleting - quarantined
Dave, okay so progress update at the ready. Yahoo msg now opens fine....but there are some serious time delays now from the time I startup till my browser opens .....and with closing one webpage and opening another , the closing webpage takes longer to dissappear than before and also the activity light on my pc seems to be working really hard at something all the time....I mean all the time ......what do you think?Download the Fix IE Utility to your desktop.

Before running the utility, make sure that all your Internet Explorer windows are closed!

* Extract the CONTENTS of the .zip file to your desktop.
* Double click the Fix IE Utility button to run the tool.
* Click Run Utility
* Click OK when you see 'Re-registered all files'
* Open Internet Explorer and see how it works.

******************************************
Download Process Explorer: http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
Unzip ProcessExplorer.zip, and double click on procexp.exe to run the program.
Click on View > Select Colunms.
In addition to already pre-selected options, make sure, the Command Line is selected, and press OK.
Go File>Save As, and save the report as Procexp.txt.
Attach the file to your next reply.The Procexp log as requested:

ProcessPIDCPUPrivate BytesWorking SetDescriptionCompany NameCommand Line
System Idle Process098.460 K28 K
Interruptsn/a0 K0 KHardware Interrupts
DPCsn/a0 K0 KDeferred Procedure Calls
System40 K57,188 K
smss.exe764172 K276 KWindows NT Session ManagerMicrosoft Corporation\SystemRoot\System32\smss.exe
csrss.exe8362,368 K5,928 KClient SERVER Runtime ProcessMicrosoft CorporationC:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
winlogon.exe8606,760 K4,048 KWindows NT Logon ApplicationMicrosoft Corporationwinlogon.exe
services.exe9041.541,956 K2,824 KServices and Controller appMicrosoft CorporationC:\WINDOWS\system32\services.exe
svchost.exe10803,288 K3,568 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost -k DcomLaunch
igfxext.exe6681,508 K2,396 Kigfxext ModuleIntel CorporationC:\WINDOWS\system32\igfxext.exe -Embedding
COCIManager.exe3002,848 K2,712 KCamera Control InterfaceLogitech Inc."C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe" -Embedding
wmiprvse.exe59683,092 K8,140 KWMIMicrosoft CorporationC:\WINDOWS\system32\wbem\wmiprvse.exe
SkypeNames2.exe1500888 K3,408 KSkypeNamesSkype Technologies S.A."C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe" -Embedding
svchost.exe11322,144 K3,088 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost -k rpcss
svchost.exe128026,324 K34,664 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe13481,868 K3,208 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k NetworkService
svchost.exe15961,580 K2,692 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k LocalService
spoolsv.exe18923,320 K3,268 KSpooler SubSystem AppMicrosoft CorporationC:\WINDOWS\system32\spoolsv.exe
svchost.exe7201,456 K2,400 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k LocalService
AOLacsd.exe7565,644 K4,308 KAOL Connectivity ServiceAOL LLCC:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
avgwdsvc.exe7884,824 K2,544 KAVG Watchdog ServiceAVG Technologies CZ, s.r.o.C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
avgrsx.exe152815,672 K14,068 KAVG Resident Shield ServiceAVG Technologies CZ, s.r.o.avgrsx.exe
avgnsx.exe31611,276 K792 KAVG Network scanner ServiceAVG Technologies CZ, s.r.o.avgnsx.exe
LVPrcSrv.exe10441,080 K1,864 KLogitech LVPrcSrv Module.Logitech Inc."C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe"
McciCMService.exe14922,140 K2,084 Kmcci+McciCMServiceMotive Communications, Inc."C:\Program Files\Common Files\Motive\McciCMService.exe"
RegSrvc.exe1688824 K1,456 KRegSrvc ModuleIntel Corporation"C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe"
svchost.exe16082,588 K3,316 KGeneric Host Process for Win32 ServicesMicrosoft CorporationC:\WINDOWS\system32\svchost.exe -k imgsvc
wdfmgr.exe1681,656 K1,100 KWindows User Mode Driver ManagerMicrosoft CorporationC:\WINDOWS\system32\wdfmgr.exe
VESMgr.exe2043,540 K2,668 KVAIO Event Service (Service Module)Sony Corporation"C:\Program Files\Sony\VAIO Event Service\VESMgr.exe"
VCSW.exe2483,096 K3,280 KVAIO Entertainment UPnP Client AdapterSony Corporation"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe" -RunBySCM
wanmpsvc.exe352916 K340 KWan Miniport (ATW) ServiceAmerica Online, Inc."C:\WINDOWS\wanmpsvc.exe"
YahooAUService.exe4566,420 K6,712 KAutoUpater Service ModuleYahoo! Inc."C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe"
avgemc.exe5364,252 K868 KAVG E-Mail ScannerAVG Technologies CZ, s.r.o.C:\PROGRA~1\AVG\AVG8\avgemc.exe
avgcsrvx.exe22608,912 K3,292 KAVG Scanning Core Module - Server PartAVG Technologies CZ, s.r.o. /pipeName=83687938-965e-4ed7-9ddd-566c19f0c761 /coreSdkOptions=0 /binaryPath="C:\Program Files\AVG\AVG8\"
VzCdbSvc.exe6245,752 K4,256 KVAIO Entertainment Database ServiceSony Corporation"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe"
VzFw.exe8244,524 K4,408 KVAIO Entertainment File Import ServiceSony Corporation"C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe"
alg.exe25561,292 K1,980 KApplication Layer Gateway ServiceMicrosoft CorporationC:\WINDOWS\System32\alg.exe
lsass.exe9164,112 K1,456 KLSA Shell (Export Version)Microsoft CorporationC:\WINDOWS\system32\lsass.exe
explorer.exe268022,192 K19,532 KWindows ExplorerMicrosoft CorporationC:\WINDOWS\Explorer.EXE
avgtray.exe29603,688 K796 KAVG Tray MonitorAVG Technologies CZ, s.r.o."C:\PROGRA~1\AVG\AVG8\avgtray.exe"
SearchProtection.exe29883,792 K1,524 KYahoo! ApplicationYahoo! Inc"C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
InstallService.exe30081,524 K432 KNetscape Communications Corporation"C:\Program Files\Common Files\ISPCOMP\InstallService.exe"
aolsoftware.exe30248,732 K7,392 KAOLAOL LLC"C:\Program Files\Common Files\AOL\1217722696\ee\AOLSoftware.exe"
LWS.exe304818,972 K2,532 KCamera SoftwareLogitech Inc."C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
Skype.exe138028,152 K16,292 KSkype Skype Technologies S.A."C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
skypePM.exe132816,188 K3,804 KSkype Extras ManagerSkype Technologies"C:\Program Files\Skype\Plugin Manager\skypePM.exe" /SILENT
ctfmon.exe33361,152 K2,228 KCTF LoaderMicrosoft Corporation"C:\WINDOWS\system32\ctfmon.exe"
SSScheduler.exe3360808 K80 KMcAfee Security Scanner SchedulerMcAfee, Inc."C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe"
firefox.exe221685,124 K97,740 KFirefoxMozilla Corporation"C:\Program Files\Mozilla Firefox\firefox.exe"
procexp.exe501610,828 K16,528 KSysinternals Process ExplorerSysinternals - www.sysinternals.com"C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 1 for ProcessExplorer.zip\procexp.exe"
Vid.exe2804619,868 K14,132 KLogitech Vid HDLogitech Inc."C:\Program Files\Logitech\Vid HD\Vid.exe" -installmode
YahooMessenger.exe4264109,724 K48,556 KYahoo! MessengerYahoo! Inc."C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE"
iexplore.exe12966,048 K1,004 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
iexplore.exe466822,604 K912 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:1296 CREDAT:14337
iexplore.exe33005,584 K884 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
iexplore.exe591613,372 K700 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:3300 CREDAT:14337
iexplore.exe18325,636 K896 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
iexplore.exe580813,336 K548 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:1832 CREDAT:14337
iexplore.exe51885,580 K888 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
iexplore.exe490413,512 K544 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:5188 CREDAT:14337
iexplore.exe32325,592 K896 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
iexplore.exe406813,580 K544 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:3232 CREDAT:14337
iexplore.exe49165,632 K904 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
iexplore.exe43613,516 K540 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:4916 CREDAT:14337
iexplore.exe40005,536 K1,824 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
iexplore.exe330416,040 K2,008 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:4000 CREDAT:14337
iexplore.exe42085,600 K1,756 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome
iexplore.exe510013,488 K1,704 KInternet ExplorerMicrosoft Corporation"C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:4208 CREDAT:14337
waol.exe1444118,588 K11,248 KAOL SoftwareAOL, LLC. -Brestart
shellmon.exe5716656 K2,632 KwaolmonAOL, LLC."C:\Program Files\AOL 9.1\shellmon.exe"
aoltpsd3.exe44082,456 K5,680 KAOL TopSpeedAOL LLC -p11535 -q"11536,11537,11538,11539,11540,11541,11542,11543" -S256 -G"C:\Documents and Settings\All Users\Application Data\AOL\Topspeed\3.0\vph.ph" -g"{9C6D947A-D1B5-4271-A40A-7EFA70080F11}" -e1

A quick update for you . I booted up my pc this morning and some little gremlin must have got into my system last night. My yahoo msg will not open now and it was working perfectly yesterday. I did gather this info from the error msg box in yahoo :

Checking virtual IP servers...
[VIP Raw] Connecting to Virtual IP server 98.136.48.32...
[VIP Raw] Connecting to Virtual IP server 67.195.186.241...
[VIP Raw] Connecting to Virtual IP server 68.180.217.15...
[VIP Raw] Connecting to Virtual IP server 76.13.15.38...
[VIP Raw] FAILED
*** 'COMPONENT_TYPE_YCP' YCPError: 'YMSG.ColoSelectionTimeout' ***

Checking HTTP virtual IP servers...
[VIP Http] Connecting to HTTP Virtual IP server 216.155.194.34...
[VIP Http] Connecting to HTTP Virtual IP server 98.136.112.56...
[VIP Http] Connecting to HTTP Virtual IP server 216.155.194.137...
[VIP Http] Connecting to HTTP Virtual IP server 98.136.112.142...
[VIP Http] FAILED
*** 'COMPONENT_TYPE_YCP' YCPError: 'YMSG.ColoSelectionTimeout' ***

What could have happened to the connection as my firefox is working fine . However, my aol hompage is static and as for now just shows a white screen upon sign on . The status bar at the top of the aol screen shows connected and signed on.. I wonder if the rereg of files performed yesterday had anything to do with it ?

Please re-run RootRepeal again and post the log as instructed in Reply # 9Rootrepeal log just run:


ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time:2010/09/17 11:16
Program Version:Version 1.3.5.0
Windows Version:Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA9BFE000Size: 98304File Visible: NoSigned: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7BD0000Size: 8192File Visible: NoSigned: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA8AA7000Size: 49152File Visible: NoSigned: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: c:\documents and settings\user\application data\skype\etilqs_qfyjmfnvxg56fsf6sbxi
Status: Allocation size mismatch (API: 65536, Raw: 0)

Path: c:\documents and settings\user\application data\skype\etilqs_ywj25zmdo50r3v004jnd
Status: Allocation size mismatch (API: 8192, Raw: 0)

==EOF==Your copy of ComboFix has passed it's shelf life. Please delete it, download a new one and run another scan.

Download ComboFix by sUBs from one of the below links.

Important! You MUST save ComboFix to your desktop

link # 1
Link # 2

Temporarily disable your Anti-virus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click on ComboFix.exe & follow the prompts.

Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)

Do not mouse-click ComboFix's window while it is running. That may CAUSE it to stall.

When the scan completes it will open a text window.

Post the contents of that log in your next reply.

Remember to re-enable your Anti-virus and Antispyware protection when ComboFix is complete.ComboFix 10-09-17.04 - User 09/18/2010 16:09:28.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.402 [GMT -7:00]
Running from: c:\documents and settings\User\Desktop\ComboFix1.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((( Files Created from 2010-08-18 to 2010-09-18 )))))))))))))))))))))))))))))))
.

2010-09-18 23:05 . 2010-09-18 23:05--------d-----r-C:\32788R22FWJFW
2010-09-17 18:06 . 2010-09-17 18:0642816----a-w-c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-09-17 04:25 . 2010-09-17 04:25--------d-----w-c:\documents and settings\User\Application Data\Registry Mechanic
2010-09-17 04:21 . 2010-08-05 15:4637336----a-w-c:\windows\system32\CleanMFT32.exe
2010-09-17 04:21 . 2010-09-17 04:21--------d-----w-c:\program files\Common Files\PC Tools
2010-09-15 21:28 . 2010-09-16 03:16--------d-----w-c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-09-15 21:25 . 2010-09-16 03:11--------d-----w-c:\windows\SxsCaPendDel
2010-09-12 00:29 . 2010-09-12 00:29--------d-----w-c:\program files\ESET
2010-09-10 19:58 . 2010-09-10 19:580----a-w-c:\documents and settings\User\settings.dat
2010-09-09 21:55 . 2009-10-07 08:47266008----a-r-c:\windows\system32\drivers\lvrs.sys
2010-09-09 21:55 . 2009-10-07 08:2434068----a-r-c:\windows\system32\Repository.reg
2010-09-09 21:55 . 2009-10-07 08:48539160----a-r-c:\windows\system32\LVUI2RC.dll
2010-09-09 21:55 . 2009-10-07 08:48539160----a-r-c:\windows\system32\LVUI2.dll
2010-09-09 21:55 . 2009-10-07 08:43199192----a-r-c:\windows\system32\lvci12101110.dll
2010-09-09 21:55 . 2009-10-07 08:43416280----a-r-c:\windows\system32\lvcodec2.dll
2010-09-09 21:55 . 2009-10-07 08:496756632----a-r-c:\windows\system32\drivers\lvuvc.sys
2010-09-09 21:41 . 2010-09-09 21:41--------d-----w-c:\documents and settings\User\Local Settings\Application Data\LogiShrd
2010-09-09 21:39 . 2009-10-07 08:4923832----a-r-c:\windows\system32\drivers\lvuvcflt.sys
2010-09-09 21:39 . 2010-09-09 21:40--------dc----w-c:\windows\system32\DRVSTORE
2010-09-09 21:37 . 2010-09-09 21:55--------d-----w-c:\program files\Common Files\LogiShrd
2010-09-09 21:37 . 2010-09-10 22:29--------d-----w-c:\documents and settings\All Users\Application Data\LogiShrd
2010-09-09 21:37 . 2010-09-16 03:11--------d-----w-c:\program files\Logitech
2010-09-09 21:37 . 2008-04-13 18:395504-c--a-w-c:\windows\system32\dllcache\mstee.sys
2010-09-09 21:37 . 2008-04-13 18:395504----a-w-c:\windows\system32\drivers\MSTEE.sys
2010-09-09 21:37 . 2008-04-13 18:4610880-c--a-w-c:\windows\system32\dllcache\ndisip.sys
2010-09-09 21:37 . 2008-04-13 18:4610880----a-w-c:\windows\system32\drivers\NdisIP.sys
2010-09-09 21:36 . 2008-04-13 18:4615232-c--a-w-c:\windows\system32\dllcache\streamip.sys
2010-09-09 21:36 . 2008-04-13 18:4615232----a-w-c:\windows\system32\drivers\StreamIP.sys
2010-09-09 21:36 . 2008-04-13 18:4611136-c--a-w-c:\windows\system32\dllcache\slip.sys
2010-09-09 21:36 . 2008-04-13 18:4611136----a-w-c:\windows\system32\drivers\SLIP.sys
2010-09-09 21:36 . 2008-04-13 18:4619200-c--a-w-c:\windows\system32\dllcache\wstcodec.sys
2010-09-09 21:36 . 2008-04-13 18:4619200----a-w-c:\windows\system32\drivers\WSTCODEC.SYS
2010-09-09 21:36 . 2008-04-13 18:4685248-c--a-w-c:\windows\system32\dllcache\nabtsfec.sys
2010-09-09 21:36 . 2008-04-13 18:4685248----a-w-c:\windows\system32\drivers\NABTSFEC.sys
2010-09-09 21:36 . 2008-04-13 18:4617024-c--a-w-c:\windows\system32\dllcache\ccdecode.sys
2010-09-09 21:36 . 2008-04-13 18:4617024----a-w-c:\windows\system32\drivers\CCDECODE.sys
2010-09-09 21:36 . 2008-04-13 18:4560032-c--a-w-c:\windows\system32\dllcache\usbaudio.sys
2010-09-09 21:36 . 2008-04-13 18:4560032----a-w-c:\windows\system32\drivers\USBAUDIO.sys
2010-09-09 21:35 . 2008-04-14 00:1253760-c--a-w-c:\windows\system32\dllcache\vfwwdm32.dll
2010-09-09 21:35 . 2008-04-14 00:1253760----a-w-c:\windows\system32\vfwwdm32.dll
2010-09-09 21:35 . 2008-04-13 18:4532128-c--a-w-c:\windows\system32\dllcache\usbccgp.sys
2010-09-09 21:35 . 2008-04-13 18:4532128----a-w-c:\windows\system32\drivers\usbccgp.sys
2010-09-09 00:12 . 2010-09-09 00:12--------d-----w-c:\program files\MetaStream
2010-09-07 23:48 . 2010-09-07 23:48--------d-----w-c:\documents and settings\LocalService\Application Data\McAfee
2010-09-07 03:49 . 2010-04-29 22:3938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-07 03:49 . 2010-04-29 22:3920952----a-w-c:\windows\system32\drivers\mbam.sys
2010-09-07 03:49 . 2010-09-07 03:49--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-09-07 01:09 . 2010-09-07 01:09--------d-----w-c:\documents and settings\User\Application Data\SUPERAntiSpyware.com
2010-09-07 01:09 . 2010-09-07 01:09--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-09-07 01:09 . 2010-09-07 01:09--------d-----w-c:\program files\SUPERAntiSpyware
2010-08-25 04:31 . 2010-08-25 04:31--------d-----w-c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-08-25 04:30 . 2010-08-25 04:3056---ha-w-c:\windows\system32\ezsidmv.dat
2010-08-25 04:30 . 2010-09-18 23:04--------d-----w-c:\documents and settings\User\Application Data\skypePM
2010-08-25 04:26 . 2010-09-18 23:14--------d-----w-c:\documents and settings\User\Application Data\Skype
2010-08-25 04:26 . 2010-09-18 22:31--------d-----w-c:\documents and settings\User\Local Settings\Application Data\Temp
2010-08-25 04:26 . 2010-09-08 00:28--------d-----w-c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-08-25 04:25 . 2010-08-25 04:25--------d-----w-c:\program files\Common Files\Skype
2010-08-25 04:25 . 2010-08-25 04:26--------d-----r-c:\program files\Skype
2010-08-25 04:25 . 2010-08-25 04:25--------d-----w-c:\documents and settings\All Users\Application Data\Skype

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-17 04:25 . 2008-08-03 02:45--------d---a-w-c:\documents and settings\All Users\Application Data\TEMP
2010-09-16 00:18 . 2010-09-09 21:550----a-w-c:\windows\system32\drivers\lvuvc.hs
2010-09-16 00:17 . 2010-09-09 21:390----a-w-c:\windows\system32\drivers\logiflt.iad
2010-09-15 21:32 . 2009-06-06 21:24--------d-----w-c:\documents and settings\User\Application Data\Yahoo!
2010-09-15 21:28 . 2008-08-30 21:40--------d-----w-c:\program files\Yahoo!
2010-09-14 02:30 . 2001-01-02 07:46--------d-----w-c:\program files\RegistryFix7
2010-09-13 00:34 . 2010-09-17 19:1858368----a-w-c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\extensions\{23256f20-0d9b-4323-b005-6e5de569c4b7}\components\FFExternalAlert.dll
2010-09-13 00:34 . 2010-09-17 19:18101376----a-w-c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\extensions\{23256f20-0d9b-4323-b005-6e5de569c4b7}\components\RadioWMPCore.dll
2010-09-11 14:46 . 2001-02-23 06:38--------d-----w-c:\program files\Microsoft Silverlight
2010-09-07 23:26 . 2001-01-31 21:18--------d-----w-c:\program files\McAfee Security Scan
2010-09-07 03:28 . 2008-08-03 02:22--------d-----w-c:\documents and settings\User\Application Data\Comodo
2010-09-07 03:28 . 2008-08-03 02:22--------d-----w-c:\program files\COMODO
2010-09-07 01:10 . 2010-09-07 01:1063488----a-w-c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-07 01:10 . 2010-09-07 01:1052224----a-w-c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-09-07 01:10 . 2010-09-07 01:10117760----a-w-c:\documents and settings\User\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-05 23:42 . 2010-09-17 19:1858368----a-w-c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\extensions\[emailprotected]\components\FFExternalAlert.dll
2010-09-05 23:42 . 2010-09-17 19:18101376----a-w-c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\extensions\[emailprotected]\components\RadioWMPCore.dll
2010-08-25 04:31 . 2004-11-21 02:35--------d-----w-c:\program files\Google
2010-08-23 05:46 . 2008-08-03 02:13--------d-----w-c:\documents and settings\All Users\Application Data\avg8
2010-08-17 13:17 . 2004-11-21 00:0458880----a-w-c:\windows\system32\spoolsv.exe
2010-07-31 05:47 . 2010-07-31 05:47--------d-----w-c:\program files\Microsoft CAPICOM 2.1.0.2
2010-07-22 15:49 . 2004-11-21 00:04590848----a-w-c:\windows\system32\rpcrt4.dll
2010-07-22 05:57 . 2009-04-14 20:085120----a-w-c:\windows\system32\xpsp4res.dll
2010-06-30 12:31 . 2004-11-21 00:04149504----a-w-c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2004-11-21 00:04916480----a-w-c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2004-11-21 00:041851904----a-w-c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-11-21 00:04354304----a-w-c:\windows\system32\drivers\srv.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"AOL Fast Start"="c:\program files\AOL 9.1\AOL.EXE" [2008-06-03 50528]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-05-13 26192168]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2001-02-18 2048352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-11-06 5406720]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"Netscape"="c:\program files\Common Files\ISPCOMP\InstallService.exe" [2005-09-07 173568]
"HostManager"="c:\program files\Common Files\AOL\1217722696\ee\AOLSoftware.exe" [2007-05-25 42032]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]

c:\documents and settings\User\Start Menu\Programs\Startup\
Logitech . Product Registration.lnk - c:\program files\Logitech\Logitech WebCam Software\eReg.exe [2009-10-14 517384]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2001-01-02 16:0811952----a-w-c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2004-10-27 23:4073728----a-w-c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2004-10-14 00:0057344-c--a-w-c:\windows\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2008-06-03 05:3550528----a-w-c:\program files\AOL 9.1\aol.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
2006-10-23 12:5071216----a-r-c:\program files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2003-11-08 00:21114688-c--a-w-c:\program files\Apoint\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO SafeSurf]
2008-08-03 02:23278264-c--a-w-c:\program files\COMODO\SafeSurf\cssurf.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreateCD_Reminder]
2004-07-16 19:1753248-c--a-w-c:\windows\SONYSYS\VAIO Recovery\Reminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:1215360----a-w-c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
2007-04-09 19:3219456-c--a-w-c:\windows\system32\CtHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
2007-04-09 19:3219968-c--a-w-c:\windows\system32\Ctxfihlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2007-05-25 17:1642032----a-w-c:\program files\Common Files\AOL\1217722696\ee\aolsoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-10-08 15:27126976-c--a-w-c:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-10-08 15:31155648-c--a-w-c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe]
2004-02-20 22:1232768-c--a-w-c:\program files\Sony\ISB Utility\ISBMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2004-11-06 05:055406720----a-w-c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2007-09-04 21:5254576-c--a-w-c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2008-08-02 20:5026112----a-w-c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefaultMIDI]
2007-04-09 19:1928672-c--a-w-c:\windows\system32\MIDIDEF.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonyPowerCfg]
2004-10-22 03:12184320----a-w-c:\program files\Sony\VAIO Power Management\SPMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Switcher.exe]
2004-10-26 06:20167936----a-w-c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Recovery]
2003-04-20 05:0828672-c--a-w-c:\windows\SONYSYS\VAIO Recovery\PartSeal.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
2004-09-22 02:54151552----a-w-c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2010-06-01 17:175252408----a-w-c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1217722696\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Documents and Settings\\User\\My Documents\\Downloads\\SweetImSetup.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/2/2008 7:13 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/2/2008 7:13 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 AM 67656]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/2/2008 7:13 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/2/2008 7:13 PM 297752]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [9/16/2010 9:21 PM 583640]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/24/2010 9:26 PM 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 5:49 AM 227232]
.
Contents of the 'Scheduled Tasks' folder

2010-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-25 04:26]

2010-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-25 04:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2642707&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - TranslatorBar 5.2 Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2642707&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - component: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\extensions\{23256f20-0d9b-4323-b005-6e5de569c4b7}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\extensions\{23256f20-0d9b-4323-b005-6e5de569c4b7}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\extensions\[emailprotected]\components\FFExternalAlert.dll
FF - component: c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\a1qipwmg.default\extensions\[emailprotected]\components\RadioWMPCore.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJPI150.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPOJI610.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-18 16:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(868)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\VESWinlogon.dll

- - - - - - - > 'explorer.exe'(5696)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\windows\wanmpsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\igfxext.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\AOL 9.1\waol.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\AOL 9.1\shellmon.exe
.
**************************************************************************
.
Completion time: 2010-09-18 16:31:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-18 23:31
ComboFix2.txt 2010-09-11 05:26
ComboFix3.txt 2010-09-09 00:22
ComboFix4.txt 2010-09-08 18:27

Pre-Run: 41,830,486,016 bytes free
Post-Run: 42,044,772,352 bytes free

- - End Of File - - 3E5B0F3FE448F4C9FD26029C9B93F9C4
Quote

What could have happened to the connection as my firefox is working fine . However, my aol hompage is static and as for now just shows a white screen upon sign on . The status bar at the top of the aol screen shows connected and signed on
You said Firefox is working well but what browser is your AOL homepage on? Can you please give me a screenprint.

How to post screenshots or images

Have you tried uninstalling AOL and downloading a new version?
Dave, I have resolved the issue with logging onto AOL by uninstalling and then installing the updated version. Now, the only issue left over isto do with the much increased wait time from the time I logon to windows till I can actually run any programs. Also, and more surprisingly is the time taken to open new browser windows in Firefox etc....I notice that the time taken for such processes is approx twice as much as before...We should do some cleanup and then I will give you a couple of links to try to speed up your computer while booting. You should investigate how much RAM you're running and what programs start when you boot. Also check to see how much free space you have on your C: drive. You should have at least 15/% in order for your computer to run correctly. If all these fail to speed up your computer, perhaps, you should start a new thread in the appropriate software forum.

Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
**********************************

StartupLite

Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the Disable box is checked.
Click Continue.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
Re-start your computer.
*****************************
Clean-up

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore POINT.

*********************************

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

**********************************

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- SECURE your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Safe Surfing!Super D, I have completed the steps outlined in the last post. However, it seems that there is a very long system lag issue from the time of logging on to windows to getting something to appear on screen takes close to 8 minutes. I know we have completed alot of processes to get yahoo msg up and running but this system lag is a bummer. Take for instance my AOL , at times it will just freeze on screen and requires a close down of program and reopen. What do you think can be done to rid the system of the lag?

Btw I did a system check and it seems I have adequate ram resources and no other issues were evident on the system performance diagnosis. You could try this tool. If it doesn't improve I would suggest that you start a new thread in the proper Windows software forum.

StartupLite

Download StartupLite by MalwareBytes to your Desktop.
Doubleclick StartupLite.exe to launch the program.
Ensure the Disable box is checked.
Click Continue.
A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer.
Re-start your computer.
2379.

Solve : I have not found a conclusive reason why, or how to correct it.?

Answer»
Hello.

When I open Internet Explorer 8, it appears in my task MANAGER twice (iexplore.exe X2). When I close IE, both INSTANCES of iexplore.exe disappear. Is this suppost to happen? and if it is not suppost to happen, why is it happening and how do I correct it.

I'm confused why if i have only one instance of IE running why its doubled in task manager.

I have read is another post that the following scan logs would be helpful, so here they are:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:30:21 PM, on 09/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\AVG8\avgtray.exe
C:\PROGRA~1\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG8\avgrsx.exe
C:\PROGRA~1\AVG8\avgnsx.exe
C:\PROGRA~1\AVG8\avgemc.exe
C:\Program Files\AVG8\avgcsrvx.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Dave\Local Settings\Temporary Internet Files\Content.IE5\L06CEEKQ\HiJackThis[1].exe

R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Window Washer\WashIdx.exe "Dave"
O4 - HKUS\S-1-5-21-1417066420-2678003418-1157166300-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyGammon.com - {59A861EE-32B3-42cd-8CCA-FC130EDF3A44} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1238818815717
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=29223
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - SERVICE: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG8\avgwdsvc.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Helper Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Anti-Malware\mbamservice.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Window Washer\WasherSvc.exe

--
End of file - 5392 bytes
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Malwarebytes' Anti-Malware 1.36
Database version: 1954
Windows 5.1.2600 Service Pack 3

09/04/2009 5:25:06 PM
mbam-log-2009-04-09 (17-25-06).txt

Scan type: Full Scan (C:\|)
Objects scanned: 101582
Time elapsed: 48 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 04/09/2009 at 01:55 PM

Application Version : 4.26.1000

Core Rules Database Version : 3836
Trace Rules Database Version: 1792

Scan type : Complete Scan
Total Scan Time : 00:22:48

Memory items scanned : 393
Memory threats detected : 0
Registry items scanned : 4037
Registry threats detected : 0
File items scanned : 3183
File threats detected : 0
----------------------------------------------
------------------------------------------------

I would appreciate some help on this as I am not even sure if anything is wrong. Maybe iexplore.exe is suppost to be in task manager twice?

Thank You

Cheers

T_Hip



Regarding the duplicate iexplore.exe entries, what you're seeing is default behavior for IE8; cf. http://blogs.msdn.com/ie/archive/2008/07/28/ie8-and-reliability.aspx

This is normal for IE8.Thank, I was wondering if it was correct or not, whew that could be the explanation for why none of my scans found anything...lol

Thanks again
Cheers
T_Hip
2380.

Solve : vundo??

Answer»

Just delete it.ok, i deleted it and installed and ran all of those programs. my computer is working great now. but next should i get all of the files out of the backup that i need and then delete it because its taking up a lot of space.What backup files?it was CREATED when i reinstalled windows, it has every thing in it that was on my computer be for i reinstalled it.Keeping this kind of backup file on your computer sort of defeats the purpose. If something happens then you can't get to it to restore. Iy needs to be on a CD or flash drive or somewhere.i just had it put in a backup because there were a few things that i hadnt put on a cd yet. it copied the ENTIRE C drive so now i have a bunch of backed up system filesDo you have your Windows INSTALL CD?yeaOK that contains all of your system files so all you really need to backup are documents, pictures, music etc and put that on a DISK.so should i just delete all of the extra system files and stuff thats taking up space in the backup driveYes you can since you have the install CD they are all on that already.

Just backup to a disk all of your personal files.

Free backup software

.
Or if you WANT the whole drive as a backup use a cloning tool. Something like this. http://majorgeeks.com/HDClone_Free_Edition_d3809.html

alright thanks for your help, i'll be back if anything else goes wrongYour welcome.
2381.

Solve : I'm stuck in the Malware Removal Sequence?

Answer»

I WENT through Step 1, Add/Remove Programs and found nothing suspicious.

I got through Step 2, ran CCleaner OK.

In Step 3, everything seemed to go well until I tried to Perform Complete Scan. I got a blank window and hourglass. After a few minutes I tried to close it and got "ERROR. This PROGRAM cannot be closed because it is locked by the system." Of course, I had to try more than once, including from the Task Manager.

Eventually I restarted, during which I got an "ending program" window and progress BAR. It was ending program CiceroUIWndFrame.

And of course, once rebooted, I tried the scan again with the same results.

Advice, please? thanks, Mike.If for some reason you cannot perform one of the steps, move on to the next step and make note of what happened when POSTING your LOGS.
OK.
I was able to run Malwarebytes, updated Java and ran HJT.

Here are my logs. thanks, Mike

[attachment deleted by admin]

2382.

Solve : Restore some functionality?

Answer»

LOL Whoops. I USED APT To kill the process and it stopped blocking my ACCESS... Should have done that in the FIRST place. Sorry for the random thread SPAM.

2383.

Solve : Also need help! with error loading dll 32?

Answer»
Like many others I am having the same issue. my computer was sluggish all type of pop ups. and whenever i searched yahoo i get results but then if I clicked on a link it would go to another site...

I got NORTAN antivius and ran it.... then got this erorr....at start up

error loading dll 32-The specified module can not be found....On my main user profile I can not log on to the internet.

I have updated my system with the latest windows patches as dircted. ran steps 1-4....

Here are my logs for Hijack this and MalwareB...Thank you in Advance




Malwarebytes' Anti-Malware 1.36
Database version: 1954
Windows 5.1.2600 Service Pack 3

4/9/2009 12:18:39 AM
mbam-log-2009-04-09 (00-18-39).txt

Scan type: Quick Scan
Objects scanned: 113450
Time elapsed: 9 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 3
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{6e780f0b-bcd6-40cb-b2db-7af47ab4d4a4} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a750a6d862d4} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a85a5e6a-de2c-4f4e-99dc-f469df5a0eec} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\cpbrkpie.coupon6ctrl.1 (Adware.Coupons) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Program Files\Microsoft Common (Trojan.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\CouponPrinter.ocx (Adware.Coupons) -> Quarantined and deleted successfully.
C:\WINDOWS\t55ft2803f44.dat (Trojan.KoobFace) -> Quarantined and deleted successfully.
C:\WINDOWS\t55ft2810f44.dat (Trojan.KoobFace) -> Quarantined and deleted successfully.
C:\WINDOWS\t55ft2829f44.dat (Trojan.KoobFace) -> Quarantined and deleted successfully.

========================================================================================================================================


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:18:44 AM, on 4/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\PINNACLE\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Cincinnati Bell dial-up accelerator\PropelAC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\COREL\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Corel\Suite8\Programs\DAD8.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Palo Alto Software\9.0\PAS9_UD.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Family\LOCALS~1\Temp\Google Toolbar\gtb52.tmp.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fptb-
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myspace.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/msk/en-us/msk7/setexp.asp?systempopup=true&affid=105-79&dtag=jkv3v91&langid=1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by MySpace
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0CB0AC93-9255-4FBD-AC8B-407834CB2FF6} - (no file)
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - C:\Program Files\Cincinnati Bell dial-up accelerator\prpl_IePopupBlocker.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\Cincinnati Bell dial-up accelerator\trayctl.exe" /STARTUPLAUNCH
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WindoFix] C:\Program Files\WindoFix\WindoFix.exe /fast
O4 - HKUS\S-1-5-21-1212841772-1455438428-2112602570-1006\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User '?')
O4 - HKUS\S-1-5-21-1212841772-1455438428-2112602570-1007\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User '?')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Corel Desktop Application Director 8.LNK = C:\Corel\Suite8\Programs\DAD8.EXE
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Palo Alto Software Update Manager 9.0.lnk = ?
O8 - Extra context menu item: Allow pop-ups from this site - C:\Program Files\Cincinnati Bell dial-up accelerator\pac-addwl.html
O8 - Extra context menu item: Refresh Pa≥ with Full QUALITY - C:\Program Files\Cincinnati Bell dial-up accelerator\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\Cincinnati Bell dial-up accelerator\pac-image.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://ra.53.com/CitrixSessionInit/ICAWEB/en/ica32/icaweb.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {549F957E-2F89-11D6-8CFE-00C04F52B225} (CMV5 Class) - http://coupons.smartsource.com/download/cscmv5X.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229812763789
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - Winlogon Notify: pulbhqkx - jddobup.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (file missing)
O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - c:\program files\pinnacle\shared files\programs\mediaserver\pmshost.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--
End of file - 14771 bytes
2384.

Solve : LOST ALL ICONS?

Answer»

I BELIEVE A VIRUS HAS INFECTED MY COMPUTER, IS THERE ANYWAY TO GET TO YOUR CONTROL PANEL EVEN IF YOU DO NOT HAVE ANY ICONS SHOWING ON SCREEN?

You MUST get into safe mode by tapping F8 or whatever key gets you into safe mode. Then you can access control panel hopefully.

And please lose the CAPs, no one yells in here.this happened to me - you can access the control panel by hitting START button - I also found that if I right click on the screen and click on view, I have the option to "show desktop icons" - I had to unclick it and then reopen it and click it again - icons came back.

2385.

Solve : won't let me format c drive - due to virus??

Answer»

Hi - my XP OS computer got a nasty virus that has cut me off the internet - some kind of backdoor trojan thing. so my anitvirus is out of date. I was told by the geek squad i needed to wipe my hard drive and start over - I have the OS disk and know how to get a ms-dos prompt - when I asked it to format the c drive it told me i couldn't because "the volume is in use by another process" (I'm doing the ms-dos prompt while in windows because I don't know any other way) - can someone tell me - step by step because I'm kinda slow - how i can format my c drive so I can get rid of this nasty virus? Many thanks.Put your OS disk in, and reboot your computer. Up in the right-hand corner, there should be a message of what keys to press to enter the boot options menu, USUALLY F8 or F12. Press the key indicated (the "F" keys are in a row at the top of your keyboard) until you get to the boot options menu. Then, select to boot from "CD/DVD drive" or a similar option. A blue screen with a grey bar at the bottom should come up, SHOWING the various files it is loading. After it finishes this, it will show the options to format your drive, and to install windows. First, use the format option on the partition that windows is installed on, (it should be MARKED as having the windows installation), then select to install windows when it is done formatting.awesome - thank you so much - am going to try it now I'm actually a little surprised the "Geek Squad" didn't do it for you. My local repair GUY is only too happy to wipe my disk and make a clean install instead of fix the actual problem.Quote

I'm actually a little surprised the "Geek Squad" didn't do it for you.
They would. For some ridiculous price...
2386.

Solve : trojan horse logs and notes tajv2005?

Answer»

"Malware holds endless possibilities as to what it might do. Some is easy to fix and others take some time, trial and error..."
'
EXACTLY
and the key issue is settled--by microsoft. It is done!

Kaspersky is running.

oh,and microsoft said combofix took out all infected files. So it took out some validation files for windows and for AVG. I also lost my address book and google earth.
I am not a comuter expert. I either MADE mistakes with combofix like BaRR said or it took out files like microsoft said.
evilfantasy,I am sure you are a good person, but I do not want you
doing this; "If I thought you were lying I do have ways of finding out if it is legit or not. I didn't do that so I must believe you."
That is a violation . So, thank you for not doing it without me knowing. BaRR I appreciated your post. It helped me alot.

evilfantasy, I appreciate you helping meget rid of those trojans.Quote

oh,and microsoft said combofix took out all infected files. So it took out some validation files for windows and for AVG. I also lost my address book and google earth.

This is utter nonsense.KASPERSKY ONLINE SCANNER 7.0 REPORT
Saturday, April 11, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner VERSION: 7.0.26.13
Program database last update: Saturday, April 11, 2009 20:29:03
Records in database: 2035043


Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes

Scan area My Computer
A:\
B:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\

Scan statistics
Files scanned 81583
Threat name 0
Infected objects 0
Suspicious objects 0
Duration of the scan 01:31:20

No malware has been detected. The scan area is clean.
The selected area was scanned.
You appear to be free of any malware.

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
  • Go to Start > Programs > Accessories > System Tools and CLICK System Restore
  • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
  • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Next go to Start > Run and type Cleanmgr
  • Click OK
  • Click the More Options Tab.
  • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide or Windows Vista System Restore Guide
.
----------

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to see if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you evilfantasy, evidently the problem is solved now.

If you agree, you can lock this thread. Yes it looks like you are in the clear as far as malware is CONCERNED.

2387.

Solve : Please check my logs?

Answer»

Hi all experts..
KINDLY check my logs.
im pissed off by this sedoparking.
Ive performed the necessary steps posted by evilfantasy (as i remember the name).

THANKS

[ATTACHMENT deleted by ADMIN]you have no SAS log , run it post it to , did you run ccleaner , an expert will have a look , harry

2388.

Solve : I can't seem to kill this darn thing.?

Answer»

No it wasn't lost due to the format; the "corrupt" folders and files just plain won't open or copy, etc. The only folders on the hard drive that came up as "corrupt" (that was not an anti-virus folder or exe) was these:

C:\Documents and Settings\TJ\Documents\Programming\
C:\Documents and Settings\TJ\Documents\Programming_Backup.7z
C:\Documents and Settings\TJ\Documents\Visual Studio 2008\
C:\Documents and Settings\TJ\Documents\Website\

And on my backup drives:

(Drive Letter):\Backups.7z
(Drive Letter):\Source\

Hence the reason I think somebody targeted me. How, I don't know. But I sure as am pissed off. I mean really, I don't DESIGN anything important, I just had a few encryption algorithms stored there, and my website doesn't have any "amazing" code, it's just a games website so I can play games past the firewall at work. Jeez, someone's either a REAL jerk or I'm really unlucky.

I guess it is a good IDEA to try and see if it will break another computer by plugging in my USB drive to another computer.

I'll post the results in a few minutes, I have an OLD laptop from 5 or 6 years ago I haven't used.

Okay, here's a pic of the first computer to fail, It's being formatted but it's still showing errors...



And here's a pic of the self test done by a computer that I plugged the USB hard drive into. (Sorry about the angle)



Somehow, some way, someone's managed to get the drive to physically fail (or at least think it's failed) and they put it on my computer. Curses.the first thing you should do is try to copy your source and such.


Also, when you plug in the drive, Hold shift to prevent autorun from occuring.I tried that at one point, it doesn't seem to make a difference. It apparently happens while it's installing the USB drivers for the device... So I guess the USB drive is probably a brick now, since I can't get it to format.

Well, although my problem isn't solved I'm guessing there's nothing more I can do other than buy new hard drives. Thanks for the help, at least I feel better.

EDIT: DBAN Just finished and saved the log to the A:\ drive. I don't have an A:\ drive.

Also, it sounded like it was still using the hard drive after DBAN had stopped running.

Is it possible somehow it's fooling the software into thinking it's on the A:\ drive, so the software isn't formatting a drive that would be considered a floppy? Something like that?doubt it.


Here's something you can try- most external drives simply have an IDE or SATA drive inside. You could open it up and put it inside a PC, see of that helps. Could be an issue with the USB board, since it seems to have issues after connection.


You did hold shift, right?


The A:\ drive was probably a RAM drive the boot disc created to save files.Yeah, but usually DBAN says "No removable device found" then some error about not saving the log. I've used DBAN ALOT because I'm constantly screwing up my computers with random code. I program random programs (not necessarily stable) to play with sometimes for fun. Hence the multiple backups, which I screwed up... The fact that it saved the log to a non-existent location scares me a bit lol. However, it does make me think I might be able to recover the DATA from one of my undamaged drives, if I can kill whatever the thing is running off of!!

Oh, and thanks for the tip about the external drive. That's great I had no idea you could just take it out and use it like a normal hard drive.

2389.

Solve : computer viruses?

Answer»

hello there...i'm just new here... I just wana ask how to determine what to fix on "HiJack this" software...I can't determie which of those are virusses...Here's the info...
Code: [Select]Logfile of Trend Micro HIJACKTHIS v2.0.2
Scan saved at 16:32, on 2009-04-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\GOOGLE\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\VMSnap3.EXE
C:\WINDOWS\Domino.EXE
C:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\YAHOO!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: (no name) - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - (no file)
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog1.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [VMSnap3] C:\WINDOWS\VMSnap3.EXE
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.EXE
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Zango\bin\10.3.70.0\Weather.exe" -auto
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKUS\S-1-5-19\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: ¡¡¡¡¡¡.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\CONTROL Panel present
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Family Feud 2\Images\stg_drm.ocx
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.ph/com/EGamesPlugin.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Mystery P.I. - The Lottery Ticket\Images\armhelper.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Update Service (gupdate1c967eb181c4090) (gupdate1c967eb181c4090) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7406 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:32, on 2009-04-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\VMSnap3.EXE
C:\WINDOWS\Domino.EXE
C:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: (no name) - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - (no file)
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog1.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)
O4 - HKLM\..\Run: [VMSnap3] C:\WINDOWS\VMSnap3.EXE
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.EXE
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Zango\bin\10.3.70.0\Weather.exe" -auto
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKUS\S-1-5-19\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: ¡¡¡¡¡¡.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Family Feud 2\Images\stg_drm.ocx
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.ph/com/EGamesPlugin.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Mystery P.I. - The Lottery Ticket\Images\armhelper.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Update Service (gupdate1c967eb181c4090) (gupdate1c967eb181c4090) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7406 bytes

2390.

Solve : automatic PC OFF problem?

Answer» HI,

my PC when started in any mode , be it safe mode also, GETS off suddenly after 5-10 min,
can you help me with this?

thank youIf you are comfortable working inside your case, make sure all your fans are working......make sure the fans are clean.......blow out dust with compressed air.......looks like it could be overheating..........or your power supply could be on the way out ..... swap it for a known good unit........ Please remember to touch the metal case before touching components inside so you don't cause ESD....electro-static discharge.Is this a DESK top or laptop?

Do you get any warning messages, beeps, or anything else out of the ordinary before it shuts down?

Have you noticed the com being excessively hot or that any fans aren't RUNNING?
Download, and install SpeedFan: http://www.almico.com/sfdownload.php
Post your computer temperatures:



Provide processor info (hold Windows key, and hit Pause/Break key to FIND out).My PC is desktop, I tried my best to clean the fans, but am not that comfortable in manually opening the case and working inside.

Temp 1: 53C
Temp 2:38C
Temp 3: -55C
HD0: 40C
Temp1: 41C

let me know if any problem is there with my PC temperature.

Sometimes SpeedFan's reading are not very clear to read, so....
Download, and install Everest: http://www.majorgeeks.com/download4181.html
Expand Computer section in left pane, and click on Sensor. What temperatures are listed there?

Also...
1. Right-click My Computer, and then click Properties.
2. Click the Advanced tab (Vista: click Advanced system settings).
3. Under Startup and Recovery, click Settings to open the Startup and Recovery dialog box.
4. Clear the Automatically restart check box, and click OK the necessary number of times.
5. Restart your computer for the settings to take effect.

...and...

1. Click Start, point to Settings, and then click Control Panel (Start>Control Panel in Vista).
2. Double-click System.
3. Click (Advanced system settings link in Vista, then --->)the Advanced tab, and then click Settings under Startup and Recovery.
4. In the Write debugging information list, click Small memory dump (64k).
I did all the procedures u ask me to do and the temperatures are,

motherboard: 38C
Aux: 95C
Seagate ST380011A :45CIt looks like Temp2 from The SpeedFan is consistent with Everest motherboard temperature, so we can safely assume it is your CPU temp. At 38C, it's little bit on a warmer side, but acceptable.

Keep SpeedFan open, and watch Temp2. Any changes right before the computer shuts off?

We also disabled "restart on error" feature, so, if it's not overheating, you may be able to see some error message, when the computer gets stuck.

If you see any error displayed...

Navigate to: C:\Windows\Minidump folder.
If you see any .dmp files, zip all of them, and attach zipped file to your next reply.
2391.

Solve : virus? malware? os? computer stupid??

Answer»

k??? i still have all the same probs tho ok now my comp keeps shuttin down and a pop up saying windows has expeierenced an unexpected error needs to shut down........... my comp only stays running about 15 mins and restarts...
Aslo my GREEN light that shows something is running, will not stop.... wat is GOING on?? I'm not sure but I don't think it is a malware issue. Try here http://www.bleepingcomputer.com/tutorials/tutorial148.htmli would love to try that other site, but i cant...
i need to activate my email and password, and i cant becuz my email is "sucure server...." i cant SIGN in to check emails..................
I ran another scan from dr. web, and i cant attach log but i did a print screen of wat it shows, i DONT know where or how to go from that, can you maybe still help PLEASE

[attachment deleted by admin]That's not any threat.

Why do you need your email to visit BleepingComputer?to make an account to ask for help, it says it needs to verfiy my email...
I CANT OPEN IT tho.... and the bottom of that attachment, it says VIRUSes found...........
The longer i cant get this fixed the more shhiiiiiiit, happens to my comp.I wasn't sending you there to ask for help. Read the article on the page in the link. How to automatically repair Windows Vista using Startup Repair - http://www.bleepingcomputer.com/tutorials/tutorial148.html simple but i dont have any disc's for laptop.......it was purchased second You can try posting in the Computer Help forum to see if anyone has any new ideas.

2392.

Solve : ConFicker Worm?

Answer»

I know you never did, just seems dumb that people are proclaiming it as undetectable just because a patch came out after the WORM, which doesn't preclude detection by any means. In fact, even rootkits are fairly simple to detect.

a rootkit usually patches certain windows functions, such as FindFirstFile,FindNextFile, CreateFile, etc. to make sure that the functions never find the malware folders and files.

However, this is a very trivial thing to check- simply use the GetProcAddress() API to retrieve the API addresses and compare them to the imported Function addresses; if they are different- then we have an issue.

Of course malware could hook GetProcAddress() as well to force them to return the same value as the value they likely soft-patched into the program when it started with a malware appinit_DLL. The answer to this would be to invoke a Callback-accepting API function that would likely be patched, such as EnumWindows or EnumprocessModules. (which would be patched to prevent displaying the malware windows and processes). by carefully double-popping the return addresses one can determine wether the call stack really started with program->EnumprocessModules->Callback routine. In most cases of malware, it would likely actually be program->Malware masker function->EnumprocessModules->Callback. By analyzing and popping stack frames we can go all the way back to the calling function and try to VALIDATE each function in between.

Of course one would then try to restore the stack frame to the way it was... perhaps even using the address of the malware function to grab the Module filename and displaying that as the rootkit.Conficker Botnet Stirs, with a Scareware Business Model

ZDNet Blogs, April 10, 2009
The Conficker botnet has stirred to life, using its peer-to-peer communication system to update itself and download scareware (fake anti-virus programs) to millions of infected Windows machines. The Conficker update comes a week after a heavily-hyped April 1st activation date and provides the first sign of the motivation behind this malware threat — financially motivated cybercrime.


found this to-night , harryno wonder i can't access microsoft website lately.

for those infected also, you probably can't download any fix since the virus blocking access to microsoft website and antivirus website, such as symantec, sophos, avg, etc.
then i google out and found a fix here:
http://depts.drew.edu/cns/FixDownadup.exe
version 1.0.5

download, then double click the file, oops, the virus auto-kill the FixDownadup.exe Process. rename the file so it doesn't contain the string "FixDownadup", renaming it to FixDownadupx.exe won't work, rename to something else like "x.exe" then double-click again, and click start to scan.

scanning in process.... hopefully it work

Edit:
Quote

Scan Result:
W32.Downadup has not been found on your computer

anyone with suggestion?use process explorer, DLL view, copy down malicious dll names (usually random or COMMON system file names in the wrong location). drop to recovery console. erase them. reboot. run hijackthis, remove entries.

This is what I usually do, if MBAM/hijackthis and combofix don't work. The TROUBLE is you have to get ALL of them- or else the survivors just revive the deleted ones.Not sure if its heading tword us or not last I heard it was in salt lake city. The bad thing is that the hardware tech at a school quite sortly after this.err- what the heck are you on about? viruses don't exactly take the bus...seems like the virus also block procexp.exe, so as usual rename the exe to something else.

then i kill process "svchost.exe -k networkservice", and now i can browse to microsoft website and antivirus websites. there is a few dll's attach to it, and all of them looks valid.

now searching for removal tools.

UPDATE:
i download w32.downadup removal from symantec:
http://www.symantec.com/content/en/us/global/removal_tool/threat_writeups/FixDwndp.exe

virus gone now
tomorrow have to check computers on LAN wheter also infected or not.

hmm, i wonder which one of the dll is the virus?
2393.

Solve : AVG Free anti-virus?

Answer»

AVG Free anti-virus

AVG Free Edition is the well-known antivirus protection tool. AVG Free is available free of charge to home users for the life of the PRODUCT.

Rapid virus DATABASE updates are available for the lifetime of the product, thereby providing the high level of detection capability that millions of users around the world trust to protect their computers. AVG Free is easy to use and will not slow your system down (low system resource requirements.Highlights include automatic update functionality, the AVG Resident Shield, which provides real-time protection as files are opened and programs are run, free Virus Database Updates for the lifetime of the product, and AVG Virus Vault for safe handling of INFECTED iles.Version 8.5 now includes LinkScanner Active Surf-Shield to check every Web page for threats at the only time that matters.

Jo LYNCH said,AVG has become popular virus cleaner over the past few years, and virus writers will often try to disable or evade widely used programs. That's why it's a good idea to run secondary checks either online or by using an alternative program from time to time.

Fortunately there are at least three good free clean virus programs: AVG, Avast!, and Avira AntiVir. (Comodo is another option, but I have not tried it.) Nowadays, some antivirus programs insist on being the only one installed. If so, turn it off and run Kaspersky's free standalone Virus REMOVAL Tool as a double-check. This is more comprehensive than Microsoft's Malicious Software Removal Tool.

offical site: AVG Free - Download antivirus and antispyware software for Windows XP and Vistai dont think your telling people anything they dont already know

i had avg for years until avg8 came out and now i have avast

2394.

Solve : problem with ekrn?

Answer»

i had eset nod 32 and loads of VIRUS,s got on to com so UNINSTALLED it but the ekrn file wont DELETE i think i have the virus,s under control but the auto updates wont come on on computer and the ekrn file keeps restarting this is really annoying so if anyone can help me get RID of these it would be a great help thanks chris

2395.

Solve : Virus Recovery?

Answer»

Hello

If I want to use ( file RECOVERY ), is it possible to recover any DELETED VIRUSES?

Yes it is, as well as System RESTORE.

2396.

Solve : removed "anti-virus number 1" virus: now cannot empty recycle bin?

Answer»

A friend had the Anti-virus Number 1 virus on her computer. I ran Malwarebytes Anti-Malware AND Kaspersky's AVPTool on it, and that seemed to clear it up. Spy Sweeper and McAfee both claim the computer is now clean.

However, when I tried to empty the recycle bin, I got the following error:
"Cannot delete Dc317: The request could not be performed because of an I/O device error."

I installed and ran CCleaner, but it was not able to empty the recycle bin either.

Next, I manually emptied the bin (by opening the bin and selecting files and deleting them). I deleted everything visible, and the bin icon changed to the empty recycle bin. But when I right-clicked on it and selected "empty recycle bin" I got this:

Are you sure you want to delete these two files?

Clicked yes, then got the error message about Dc317 again.

I suspect that Dc317 is left over from the virus, but I have no idea, and I have no idea what else I can do with the recycle bin.

Just for kicks, here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:41:33 PM, on 4/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet EXPLORER v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\FilmLoop Player\FilmLoop.exe
C:\Program Files\Common Files\AOL\1237914022\ee\AOLSoftware.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
D:\Jennilynn's Documents\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\wuauclt.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Java\jre1.5.0_07\bin\jucheck.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://toolbar.inbox.com/search/disp...%s&tbid=%tb_id
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.alot.com/sidebar?pr=as...-us/Suite.aspx (obfuscated)
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (FILE missing)
O2 - BHO: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: AOL Toolbar Loader - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL Toolbar\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [ezShieldProtector for PX] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\lserver\server.vbs"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [FilmLoop] "C:\Program Files\FilmLoop Player\FilmLoop.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1237914022\ee\AOLSoftware.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [Picasa Media Detector] "D:\Jennilynn's Documents\Picasa2\PicasaMediaDetector.exe"
O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Startup: is-P7ASA.lnk = C:\Documents and Settings\Jennilyn\Desktop\Virus Removal Tool\is-P7ASA\startup.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6054D082-355D-4B47-B77C-36A778899F48} - http://qmedia.xlontech.net/100348/qm...ll06061501.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1229995969109
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1152932425375
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (Application) (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Music Server\SSSvr.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\sv_httpd.exe
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (Application) (VAIOMediaPlatform-PhotoServer-AppServer) - Unknown owner - C:\Program Files\Sony\Photo Server 20\appsrv\PicAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\SV_Httpd.exe
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Media Platform\UPnPFramework.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 9111 bytes


Thanks for reading. Hope someone can help.
-wynnehttp://ccollomb.free.fr/unlocker/


if you really want it out go to the above DOWNLOAD and follow through its easy , harryThanks for the tip, HARRY. I'll let you know how it goes.You have some issues in the HJT log...might be a good idea to follow the guidelines and post the three logs.

2397.

Solve : Forgot to check "Notify me of replies"?

Answer»

Please respond here if possible to NOTIFY me of any REPLIES to "mareze2".

THANKS...In the topic, scroll down to the last POST and click on the button.

2398.

Solve : data execution prevention-microsoft front page server administrator client?

Answer»

hi folks,
Im running XP pack 3 on a toshiba laptop satelite 85. While searching a sight on auto repairs I got a message pop up from my virus program(avira) telling me there was a virus in the page and did I want to deny access-I said yes and it popped up about 5-6 more times before I could click out of page. I thought by denying access the problem was solved but I ran malwarebytes and avira to be sure.Malware found nothing but avira found 2 viruses which I chose to quarantine.Avira told me I have to restart the computer to complete the action-which I did.When it rebooted and got to my desktop page there were no icons but a small window that said -to protect your computer data execution prevention has closed microsoft front page server administrator client-it gave me no choices except to click close then another window asked if I wanted to send this error to microsoft. I did.
I rebooted in SAFE mode and ran every virus program I have to no avail-I tried backdating to another save point but it kept saying it did not go back to that point so nothing has changed. I cant figure out where to go next so Im coming to the experts for help-HELP
thank you-PeteDo you have a backup method?
At this point it would be a good idea of doing a backup, if yew can.

Other wise, reboot in safe mode. Open task manager & look for any process that MIGHT be bogus and stop it. Suspend all AV and spy ware blockers. Of course, you want to be off the network. Now run just one AV Scan program in Safe mode. Then reboot and tray again with another Scanner.
If you can not get it this way, you will have to do a Hijack log.

But first try a scan in safe mode. Yeah, I know, some will tell you that it don't work that way. Yes, it does. Trust me on this.
I would go with MalwareBytes in safe mode.hey geek
I dont have backup and I ran malwarebytes and avira virus cleaner in safe mode and they found nothing. I looked at task manager processes and they all look Greek to me-sorry. But I do have a popup alert that tells me I have a virus and starts scanning on its own from a site called bonuspromoofer.com.
I may have screwed up big time CUZ I went to safe mode as admin and ran sysdm.cpl and made dep accept front page,rebooted and computer came on perfect again,so I started malwarebytes again and as soon as I did a popup came up and said you have a security prob.-do you want to scan for viruses and before I can react it goes to a scan page and starts scanning-I cannot stop it short of physically turning off the computer.
now I cannot even start in safe mode-it goes to user page and when I click my name it says loading and then jumps to saving settings and it wont go any farther.At this point I do not have any advice.

The virus has taken over your system.

As for me, I keep a backup install for this kind of panic. At this point I would handle it this way. I would use another HDD to boot Windows after making the original DRIVE the slave. Then I would download recent versions of AV scanners and do FULL scans on the slave drive. Sometimes that works.

Others here would recommend doing a Hijack log.
pdudenhefer -
I cleaned it up today on a client's Compaq. Same symptoms as you. Go to <removed> and follow ALL the instructions to download, install, and run Combofix. It did the trick.

BWPS - You can skip the Stopzilla install advert @ <removed>
BWPlease do not send users to that website. It is not the official web site for ComboFix and we do not want users running ComboFix unless advised to do so by someone trained to use it.

Post it again and I will begin removing your posts and request that you are banned. See here > http://www.mywot.com/en/scorecard/combofixdownload.comwell evil fantasy what do you recommend-please.Right now it wont even let me get to safe mode-it comes on and goes off in 2 seconds-logs on then immediately logs off and saves settings
tried using repair disk and it started like it was gonna come on and then it did the same- sign on and offI'm not sure what to do if you can't log on.

You can try this.

Avira AntiVir Rescue System

* Download the Avira AntiVir Rescue System
* Place a blank CD in your burner and double-click on the downloaded file.
* The program will automatically burn the CD for you.
* Place the burned CD into the affected computer and start the computer with the CD in the CD tray.
* On the bottom left side of the screen there are 2 flags. Using your mouse click on the British flag to use English.
* Click on the Configuration button.

- Select Scan all files
- Select Try to repair infected files and Rename files, if they cannot be removed
- Select Scan for dialers
- Select Scan for joke programs (Jokes)
- Select Scan for games
- Select Scan for spyware (SPR)

* Click on Virus scanner
* Click on Start scanner at the bottom of the screen

Currently the program does not support saving a log. Please write down the list of items for Records, Suspect files, and Warnings then post them back here.My bad. combofix.org is the good site, highly ranked by the reference you provided.-I downloaded the rescue disk and tried to log on but it only got to opening page and then closed and saved my settings. It did this twice and then reverted to welcome user page,but when I click on my name it logs on and off by itself again. Im stymied.BW you did not link to combofix.org you linked to combofix.com - Can you read this? http://www.mywot.com/en/scorecard/combofixdownload.com

Still unless you are trained to use ComboFix and can show it then do not suggest it's use here. And then only use the official ComboFix web site which is neither combofix.org or combofix.com.

@ pdudenhefer - Try posting in the Windows forum. Maybe someone will have some IDEAS there.Yes I can read it and did. That is why I suggested the .org vs. the .com site. I have used combofix on well over 150 computers. Thanks for your Avira suggestion. I'm testing now on a machine that won't let combofix run. It has similar symptoms to the first post.

2399.

Solve : U guys r great?

Answer» THANKS for INFO...Thanks on what?Was in REFERENCE to a MESSAGE on being NOTIFIED...
2400.

Solve : avast scan help ???

Answer»

i RAN 2 SCANS to-night and got this result both times and the 3 scan buttons were pressed before the start , harry

[ATTACHMENT deleted by admin]